The New Rules of Machine Speed Defense

  • Global security frameworks are evolving: Security organizations are increasingly leveraging global frameworks to navigate the complexities of AI-enabled threats, balancing the need for standardized best practices with the necessity of business-specific risk decisions.
  • Intelligence-led defense is essential: Modern, intelligence-led defense generally requires operationalizing security at machine speed by integrating enriched, contextual threat data, which better enables strategic, risk-based vulnerability prioritization rather than reacting to every threat.
  • Effective security requires data quality and relevance: Organizations must prioritize the quality and "fit for purpose" of the intelligence feeding into their threat intelligence solutions so they can make quick, accurate decisions and avoid the risks of moving fast with bad information.

As both human-directed and autonomous AI-powered attacks accelerate, security organizations, policymakers, and industry groups around the world are rethinking traditional approaches to defense.

Recorded Future CISO Jason Steer and Mastercard VP of Government Affairs and Policy Christian Ohanian recently sat down with Recorded Future’s Jon Miller to discuss how to build threat intelligence programs that can defend at machine speed, how emerging policy frameworks can help, and why high-quality intelligence is increasingly essential in this new era.

This blog offers highlights from the discussion. Watch the full event.

Evolving security standards and frameworks
Globally, security frameworks like the National Institute of Standards and Technology (NIST) Cyber AI Profile and Singapore’s cybersecurity guidelines are evolving to help organizations keep pace with new threats. According to Christian Ohanian, the goal is to encourage the adoption of AI to bolster resilience while also providing guidance on the kinds of AI-enabled threats organizations now face.

However, Ohanian pointed out that creating these standards involves debate. While some argue that frameworks should provide a clear, prioritized checklist to help resource-strapped teams improve their security programs, others believe that a "one-size-fits-all" approach fails to account for the unique risk profiles of different industries and organizations.

Jason Steer noted that while standards create a helpful taxonomy, the burden remains on CISOs to translate that language into business-specific risk decisions. “This is why intelligence is important,” he noted. “Every industry, every geography, has its own subtleties of attack, so leaning into ‘What are the real risks to my business?’ becomes the hardest part.”

The role of high-quality, purpose-fit intelligence
Ohanian noted that global security standards increasingly recognize that threat intelligence is a foundational component of modern defense. They’re also beginning to acknowledge that security organizations need to use AI and other autonomous solutions to improve the way they operationalize their intelligence. Framework discussions, he said, are now focused on “the importance of organizations looking really closely at how they can increase the speed of the way they’re using threat intelligence, how they can increase the accuracy of the prioritization of the alerts and warnings they’re getting.”

Ohanian emphasized that organizations must move beyond the simple acquisition of data and evaluate the intelligence sources feeding into their threat intelligence solutions. They need to look at "fit for purpose," ensuring that the intelligence aligns with the organization’s specific risk profile and governance requirements.

Steer agreed. “Coverage and collection at fast speed enable information to be brought together for people to assess the impact to their business,” he said. “But then it's only good if that information gets to the right people in the right tools.”

When it does, he said, high-quality intelligence can better fulfill its ultimate goal of providing “decision advantage”—enabling even less experienced SOC analysts to make quick, effective decisions.

Operationalizing security at machine speed
To begin operationalizing intelligence, organizations need to first know what they’re defending. Do they run software on-premise, in the cloud, or a combination of the two? Once they have a complete picture of the mission-critical systems they need to defend, Steer said, they’ll better understand the threats that might be targeting them.

Then, in order to achieve machine-speed defense against AI-driven attacks, organizations need the right API integrations. That way, they can send enriched, contextual threat data to their vulnerability tools and use AI to identify the clusters of high-risk activity where vulnerabilities intersect with active exploitation.

Steer noted that this shift will eventually allow security leaders to move away from trying to patch every single vulnerability—an impossible task—and toward a strategic, risk-based prioritization model. “Vulnerability prioritization is absolutely primed for AI to streamline and accelerate contextual decision-making at executive levels,” he said.

Driving toward an intelligence-led defense future
The consensus from the panel was clear: The future of cybersecurity lies in the convergence of AI, intelligence-led defense, and robust governance. While the X-factor of new threats—the ones that disrupt even the best-laid plans—will always exist, the goal is to reduce reactive panic and focus on strategic risk reduction.

For security practitioners, the takeaway is two-fold. First, they need to keep a close watch on the evolution of global security frameworks, as these documents will define industry expectations and communication standards, and they’ll give organizations a better understanding of where modern security is going in light of AI.

Second, practitioners need to focus on the quality of intelligence over quantity. By ensuring that their tools are enriched with actionable context, they can empower their teams to move from a state of constant, reactive chaos to one of calculated, proactive defense.

As Jon Miller noted, intelligence-led defense is the best way to ensure that when you move at machine speed, you’re moving in the right direction. “Speed without intelligence just means you're wrong, faster,” he said.

To get a customized walkthrough of Recorded Future’s machine-speed defense in action, take our interactive tour.