Socwise logo
Expert at SOCWISE
06/11/2026

Security teams' new adversary isn't hackers, but speed

Expert at SOCWISE
Gartner and Frost & Sullivan signal the same shift: cybersecurity can no longer rely on old SIEM tools and annual awareness training. AI, automation, and secure behavior now shape real resilience.

In 2026, cybersecurity leaders will face a two-pronged challenge. On the one hand, the attack surface is growing rapidly: due to the cloud, hybrid infrastructures, remote work, and increasingly complex digital ecosystems, there is more data, more systems, and more user interactions to protect. On the other hand, artificial intelligence is no longer just a defensive tool but also part of the attackers’ arsenal. Frost & Sullivan’s summary of the modern SIEM market and Gartner’s analysis of GenAI risks both point to the same turning point: security operations cannot remain rule-based, reactive, and campaign-driven. There is a need for smarter platforms, faster response times, and more informed management of user behavior.

SIEM is no longer just a log collection system

Today, security operations centers no longer simply monitor events; instead, they attempt to filter out the few signals that indicate a genuine attack from an ever-increasing volume of digital noise. In this environment, traditional security operations based on retrospective analysis can easily fall behind attackers.

According to Frost & Sullivan, modern SIEM is therefore no longer a “logging tool running in the background,” but rather a central nervous system for security decision-making. Its value lies in its ability to connect seemingly unrelated events, recognize unusual behavioral patterns, and help determine which alerts require immediate intervention. The focus thus shifts from mere data collection to context, prediction, and rapid action.

This shift is also striking from a business perspective. According to a report by Frost & Sullivan, the modern SIEM market was valued at $7.13 billion in 2024 and could grow to $13.55 billion by 2029, representing a compound annual growth rate of approximately 13.7 percent. This growth is driven not only by technological innovation but also by a very practical necessity: organizations must simultaneously manage cloud environments, regulatory requirements, ransomware risks, attacks through supply chains, and increasingly sophisticated phishing attacks.

Source: Frost & Sullivan 2026

Cloud, Automation, and Convergence

One of the most significant trends in the modern SIEM market is cloud-native and SaaS-based operations. For many organizations, traditional on-premises systems are difficult to scale, impose a significant operational burden, and adapt more slowly to changing IT environments. Cloud-based SIEM, on the other hand, is more flexible to scale, faster to deploy, and better suited to hybrid or multi-cloud architectures.

This is particularly important where security teams are already overburdened. The volume of alerts is high, false positives consume a lot of time, and there is a persistent shortage of skilled cybersecurity professionals. In such an environment, automation is not a convenience feature but an operational necessity. If a platform can perform repetitive investigative steps, provide context for an incident, or prepare response actions, it directly reduces the workload on analysts.

The other defining trend is technological convergence. SIEM is becoming increasingly integrated with SOAR, UEBA, XDR, and AI-based analytical capabilities. The goal is for organizations to manage detection, investigation, and response not through separate tools and fragmented processes, but within a unified security operations ecosystem. This is also transforming vendor competition: the winner is not the one who offers more standalone features, but the one who provides a scalable, integrated, and truly usable operational model.

Source: Frost & Sullivan 2026

Meanwhile, GenAI is changing the nature of human risk

While AI is becoming a key tool for defense, this same technological wave is also creating new risks. According to a Gartner report, traditional cybersecurity awareness programs are no longer sufficient in a work environment permeated by GenAI. The old logic was simple: train employees to reduce risk. Generative AI, however, has changed the game.

More than 86 percent of organizations are already experimenting with or using GenAI tools. Employees often don’t wait for official approval: they use personal AI accounts for work tasks, enter sensitive data into public tools, or download unapproved applications. According to a survey cited by Gartner, more than 57 percent of employees use a personal GenAI account for work, and 33 percent admit to having entered sensitive workplace information into a public or unapproved GenAI tool.

This is no longer classic “user negligence.” It is, rather, a new operational reality. People use AI tools because they are faster, more convenient, and make them feel more productive. If the organization responds only with bans, usage can easily go underground. This is one of the main dangers of so-called shadow AI: the risk does not disappear; it simply moves outside the controlled environment.

Phishing is also reaching new heights

GenAI isn’t just an internal risk. Attackers can also use it more effectively. In the past, phishing emails could often be spotted due to poor language, awkward phrasing, or generic messages. However, AI-generated attacks can be more precise, personalized, and believable. Deepfakes, voice- and video-based deceptions, and AI-powered social engineering attacks further reduce the likelihood that a user will recognize the threat based on intuition alone.

According to a Gartner summary, 35 percent of organizations have already been hit by a deepfake attack, and the number of AI-powered phishing emails has doubled over the past two years. This is particularly important because traditional awareness training often relies on static advice: don’t click on suspicious links, verify the sender, watch for poor wording. These aren’t useless, but they aren’t enough on their own. If the attack is well-written, fits the context, and may even appear to be an instruction from management, then the user needs not only knowledge but also practiced behavior and clear decision-making rules.

Behavior and culture instead of awareness

The essence of the shift in direction highlighted by Gartner is that cybersecurity programs must move beyond mere awareness to focus on developing secure behavior and culture. The main question isn’t whether an employee can define phishing at the end of a training session. What matters is what they do when they receive an urgent-seeming transfer request, when they use an AI-generated summary to prepare for a decision, or when a productivity tool requests sensitive customer data.

In practice, this requires a more continuous, embedded approach. Instead of campaign-style training, we need simulations that model real-world situations, short and regular learning modules, clear rules for using GenAI, and fast reporting channels. Employees need to know which tools are authorized, what data they cannot input into AI systems, how to verify an AI-generated response, and when to seek human approval.

It is important to note that this is not solely an IT security task. GenAI risk simultaneously impacts legal, compliance, data protection, HR, and business management areas. If the rules are too general, they will be unusable. If they are too strict, employees may circumvent them. However, if they are built into business processes, security will not be an obstacle but a prerequisite for the safe use of AI.

The two trends point in the same direction

At first glance, Frost & Sullivan’s analysis of the SIEM market and Gartner’s approach to GenAI awareness may seem like two separate topics. One focuses on technology platforms, market size, and security operations. The other focuses on human risk, employee behavior, and AI usage. In reality, they represent two sides of the same transformation.

Modern defense requires a stronger technological foundation: SIEM and security operations platforms capable of handling large volumes of data, supporting analysts with AI, automating response actions, and providing a unified view of the hybrid environment. However, this alone is not enough. Attackers continue to rely on human trust, urgency, and habit, while GenAI opens up new avenues for deception. Therefore, defense must address both technology and behavior simultaneously.

Successful organizations are likely to be those that do not view AI, SIEM modernization, and cybersecurity culture as separate projects. These three areas are interconnected. SIEM signals what is happening. Automation accelerates the response. AI supports analysis. And a well-established culture reduces the likelihood that risky decisions will slip unnoticed into day-to-day operations.

Source: Frost & Sullivan 2026

Conclusion

In the next phase of cybersecurity, AI will play a dual role. On the defensive side, it can help reduce noise, speed up incident response, and make detection more accurate. On the offensive side, however, it enables more convincing phishing attacks, deepfake-based deception, and new types of user errors. For this reason, organizations must simultaneously modernize their security operations and rethink how they manage human risk.

The old model, in which SIEM primarily collected logs and the awareness program consisted of a few training sessions a year, no longer fits the current threat landscape. The security operations of the future will be cloud-native, automated, AI-powered, and behavior-centric. The goal is not to eliminate all risk, but to enable the organization to see faster, make better decisions, and respond more securely in critical moments.

crossmenu
SOCWISE
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.