GUEST OPINION: Every security operations centre is drowning in data.
Security platforms generate thousands of alerts every day, while artificial intelligence (AI) is making it easier than ever to identify patterns, summarise activity, and recommend actions. Organisations have more visibility into their environments than ever before.
Yet, despite that visibility, attackers continue to move faster. According to LevelBlue’s Q2 2026 TTP Briefing, business email compromise (BEC) accounted for 45 per cent of incidents investigated, while phishing and social engineering remained the leading initial intrusion vector, responsible for 65 per cent of attacks. At the same time, threat actors are compressing the intrusion path, moving from initial access to data exfiltration in days rather than weeks, reducing the time defenders have to detect, investigate, and respond.
The cybersecurity industry doesn’t have a data shortage. It has a judgement shortage.
For years, organisations have treated more data as the path to better security. Add another dashboard. Deploy another tool. Subscribe to another threat feed. The assumption has been that more visibility will naturally lead to better decisions.
However, more information doesn’t automatically create more clarity.
Jo Salisbury, regional director of growth and performance, APAC, LevelBlue, said, “Most organisations already have access to an enormous amount of security data. The challenge isn’t collecting more information. It’s understanding which information matters and knowing what action to take.”
Security teams can monitor identities, endpoints, cloud environments, and networks in real time. Boards receive regular reports on vulnerabilities, risk scores, and emerging threats. AI can rapidly identify anomalies and recommend next steps.
However, technology can only answer one question: What happened? It can’t answer the question that matters most: What should we do next? That still depends on context, experience, and judgement.
As attackers continue to shorten the time between compromise and impact, that judgement becomes even more valuable. Organisations no longer have the luxury of investigating every alert with the same level of scrutiny. They need the confidence to identify which signals represent genuine business risk, which demand immediate action, and which can safely be deprioritised.
Clarity isn’t a byproduct of more data. It’s the result of asking the right question at the right time.
Instead of asking how many vulnerabilities exist, security leaders should ask which vulnerabilities could realistically disrupt critical business operations.
Advertisement
Instead of measuring how many attacks were blocked, they should ask which attacks almost succeeded, and what those attempts reveal about weaknesses in the organisation’s defences.
Instead of asking how many alerts they received, they should ask which alerts changed a security decision.
Jo Salisbury said, “These questions move cybersecurity beyond technical reporting and towards business decision-making.
“The organisations seeing the strongest outcomes aren’t necessarily the ones collecting the most telemetry. They’re the ones using the information they already have to make faster, more confident decisions.”
This is becoming increasingly important as organisations look to maximise the value of existing security investments.
Many businesses already own sophisticated security capabilities. The opportunity isn’t always to buy another tool. More often, it’s to better understand the capabilities they already have, make better use of the insights those tools already provide, and ensure those insights translate into meaningful action.
Jo Salisbury said, “Meaningful security metrics should support decisions, not simply report activity. If a dashboard doesn’t influence risk priorities, investment decisions, or operational improvements, it’s providing information without delivering value.”
Artificial intelligence makes this distinction even more important.
AI can analyse vast amounts of information in seconds, identify patterns that humans might miss, and recommend actions faster than any analyst. However, it can’t determine an organisation’s appetite for risk, understand commercial priorities, or decide which trade-offs are acceptable. Those remain leadership decisions.
Jo Salisbury said, “AI is becoming incredibly effective at surfacing insights. However, organisations shouldn’t simply accept every recommendation at face value. They should ask whether the insight is relevant to their environment, whether it aligns with business priorities, and whether there’s sufficient evidence to support the decision.”
As cybersecurity continues to evolve, judgement will become one of the most important capabilities organisations can develop. The organisations that build resilience won’t necessarily be those with the most dashboards or the largest technology estates. They’ll be the ones that create a culture of curiosity, challenge assumptions, and focus on turning insights into action.
Jo Salisbury said, “The next time the conversation turns to another dashboard, another threat feed, or another security tool, it’s worth asking a simpler question first: What decision are we trying to make that we can’t make today? If that question can’t be answered, more data is unlikely to solve the problem.”
Advertisement
