Scully Tom, Director for Government and Critical Infrastructure for Asia-Pacific and Japan at Palo Alto Networks, gives a keynote address at SMARTCLOUD SHOW 2026 at the Westin Josun Hotel in Sogong-dong, Seoul, on the 26th. /Courtesy of ChosunBiz

In the very near future, cyberattacks using artificial intelligence (AI) will happen in real time. Realistically, the only way to respond is to meet AI with AI.

Tom Scully, director for government and critical infrastructure in Asia-Pacific and Japan at Palo Alto Networks, said this in a keynote at the country's largest tech conference, SMARTCLOUD SHOW 2026, held at the Westin Josun Hotel in Sogong-dong, Seoul, on the 26th.

Director Scully said, As time goes by, the window for security teams to find and block attacks and restore systems before damage occurs is shrinking, and attackers in the real world are already using AI to increase the speed, scale and sophistication of their attacks.

According to Palo Alto Networks' threat intelligence organization Unit 42, it takes just 15 minutes from the time a major vulnerability in corporations is disclosed to when attackers begin large-scale scanning to target it. In particular, in cases where network intrusion succeeded, 25% progressed to data exfiltration in only 72 minutes.

Attackers are using AI at every step in this process. In the reconnaissance phase, they collect and process public information at scale, and create previously undiscovered command-and-control (C2) domains or new malware. After intrusion, they also use AI to reduce the likelihood of detection while finding paths for lateral movement.

Malware that uses AI to evade detection by existing security systems has also emerged. Director Scully cited Black Mamba, which generates new malware every time it runs, as a representative example. When a user executes malicious Python code, Black Mamba uses AI to create new malware in memory. The newly generated malware has no existing registered signature and runs in memory, making it difficult for conventional endpoint security solutions to detect.

It was also noted as a problem that security architectures have become overly complex as corporations add point solutions whenever a security issue arises. According to Director Scully, corporations operate an average of 83 security tools. In an architecture where each tool must be installed and integrated and personnel must aggregate data generated across multiple systems to make judgments, it is difficult to respond to the high-speed attacks executed by AI.

Director Scully proposed platformization as a way to solve this. It consolidates data generated by multiple security tools into a single platform and applies AI and Machine Learning to automate detection, analysis and response.

Palo Alto Networks is applying this approach to its own Security Operation Center (SOC). According to Director Scully, the Palo Alto Networks SOC compresses as many as 90 billion security events a day into 26,000 detections using AI and ML, and further narrows them down to an average of 75 response cases.

Director Scully said, Of these, only 65 go through a semi-automated process where a person makes the final decision, and incidents that an actual security analyst must handle directly are at the level of a single case, adding, The Palo Alto Networks SOC reduced mean time to detect and mean time to respond to 7 minutes and 1 minute, respectively.

However, problems also arise as AI agents take on security roles. Because AI agents access corporate systems directly and act on behalf of users, there is a risk of abuse if they are granted excessive privileges.

As a countermeasure, he proposed granting AI agents only the minimum necessary privileges, and only temporarily. Director Scully explained, After defining the intent and tasks the agent must perform, privileges should be granted so it can access only the systems and data required for those tasks, and when the tasks are finished, those privileges should be terminated.

※ This article has been translated by AI. Share your feedback here.