Park Song, head of the SK shieldus Cybersecurity AI Lab (executive director), stated accordingly at a lecture at the Westin Josun Hotel in Sogong-dong, Seoul, on the 26th, held under the theme "AI moves the world" at the SMARTCLOUD SHOW 2026. Park gave a lecture that day on the theme "A new paradigm of cybersecurity in the era of agentic AI."

Park Song, head of the Cybersecurity AI Lab at SK shieldus, gives a lecture titled "The New Cybersecurity Paradigm in the Age of Agentic AI" at SMARTCLOUD SHOW 2026 at the Westin Josun Hotel in Sogong-dong, Seoul, on the 26th./Courtesy of ChosunBiz

Park assessed that as generative artificial intelligence (AI) evolves into "agentic AI" that judges and acts on its own, the structure of cyber offense and defense is fundamentally changing. If AI in the past was a static reasoning tool that classified data and answered questions, today's AI has become an autonomous actor that interacts with the external environment and directly invokes various tools.

Park said, "Tens of millions of AI agents are expected to emerge soon," adding, "If this happens, an extremely asymmetric war could break out in which each defender faces about 1,000 AI agents." He continued, "Attackers relentlessly strike the kill chain network while defenders remain stuck in manual analysis and ticket processing," emphasizing, "This cannot be solved by simply adding security personnel; we must fundamentally change the response structure."

Cyberattack capabilities using AI are already advancing rapidly. Park introduced a case in which AI solved 73% of high-difficulty penetration testing tasks that AI models had previously failed to crack. He also presented an analysis showing that while defenders spend an average of 55 days finding high-risk vulnerabilities in corporate applications and application programming interfaces (API), attackers complete their exploits seven days before the vulnerabilities are patched.

The speed of attack also outpaces human response capabilities. Park said, "The top 25% of advanced attack groups complete internal network scanning just 15 minutes after initial access and exfiltrate final secrets in 72 minutes," adding, "The traditional human-centered patch defense cycle has completely collapsed."

In particular, he assessed that the focus of attacks is shifting from the network itself to users' "identity" and "privileges." Rather than directly targeting technical loopholes in systems, a growing approach is to use stolen account information to access systems as if they were legitimate users. Park said, "Hackers no longer labor to hack systems. They log in like legitimate users with stolen credentials," adding, "The focus of our security is moving from the network perimeter to identity itself."

Park emphasized that in the agentic AI era, rather than perfectly blocking attacks, organizations must build an "autonomous cyber resilience" system that responds and recovers quickly even when attacked. To that end, he presented three defense systems: proactive exposure management, active defense based on deep reasoning, and autonomous response based on an agentic security operations center (SOC).

First, he explained that instead of conducting manual penetration tests once a year as before, AI should continuously validate vulnerabilities by mimicking hackers' attack tactics. After an attack begins, rather than analyzing individual security events separately, multiple events should be linked into a single, continuous attack flow for detection.

He also stressed that security monitoring should shift from people manually analyzing countless alerts to a model where multiple AI agents and human experts collaborate. Park said, "Traditional SOCs have been constrained by fatigue and analytic bottlenecks caused by tens of millions of alerts," adding, "We must build a next-generation security model in which numerous security-specialized agents and human analysts collaborate."

SK shieldus is also applying AI to security monitoring. According to Park, SK shieldus' threat assessment system uses AI Deep Learning and Machine Learning to make a first-pass risk determination when tens of millions of threat events come in. The performance at this stage is around 95%. High-difficulty threats that are hard to classify automatically are analyzed by operators, and even in this process, a security-specialized small language model (sLLM) provides deep analysis results. Park said the explanatory power of the sLLM's deep analysis is about 94.5%.

The integrated security monitoring platform "Secudium" of SK shieldus handles an average of 17 billion threat events per day. The company said it has reduced processing time by 75% compared with the past by using AI. SK shieldus plans to transform Secudium into an "agentic SOC" in which multiple AI agents autonomously respond to threats 24/7/365.

Park said, "AI and humans must collaborate to move toward an autonomous cyber resilience system," adding, "The survival of corporations depends on a cyber resilience system that can recover on its own even after taking a hit."

※ This article has been translated by AI. Share your feedback here.