Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Cisco Secure Firewall Management Critical 0-Day Actively Exploited CVE-2024-20353
July 30, 2026
Critical Home Assistant FFmpeg Bug Allows File Theft, Root Commands
July 30, 2026
AI Security Planning: Managing Resources and Mitigating Risks
July 30, 2026
Home/CyberSecurity News/AI Security Planning: Managing Resources and Mitigating Risks
CyberSecurity News

AI Security Planning: Managing Resources and Mitigating Risks

Key Takeaways Cybersecurity leaders are significantly increasing investments in AI for Security Operations Centers (SOCs) to combat rising threat volumes and sophisticated attacker behaviors. AI is...

Jennifer sherman
Jennifer sherman
July 30, 2026 5 Min Read
4 0

Key Takeaways

  • Cybersecurity leaders are significantly increasing investments in AI for Security Operations Centers (SOCs) to combat rising threat volumes and sophisticated attacker behaviors.
  • AI is primarily being adopted for early-stage threat detection and triage (82%), with a smaller but growing percentage (37%) for automating ticketing and response.
  • A critical, often overlooked resource constraint for AI in security is “tokenomics,” the cost associated with the computational units (tokens) consumed by AI models.
  • Threat actors may exploit token consumption by designing attacks specifically to exhaust defender AI budgets, impacting response capabilities.
  • Effective AI integration requires a strategic understanding of token costs, process optimization, and a balance between agentic AI for rapid response and traditional AI/ML for pattern matching.

AI’s Growing Role in Cybersecurity and the Unseen Cost

The integration of Artificial Intelligence into Security Operations Centers (SOCs) is rapidly accelerating, driven by the escalating volume and complexity of cyber threats. According to EY, the proportion of senior security leaders allocating at least a quarter of their cybersecurity budget to AI solutions is projected to surge from nine percent to 48 percent within the next two years. This substantial increase reflects a critical need for security teams to enhance their capabilities against evolving threat actor tactics and the recent advancements in AI-driven vulnerability investigation and exploit generation.

Table Of Content

  • Key Takeaways
  • AI’s Growing Role in Cybersecurity and the Unseen Cost
  • AI’s Impact on SOC Efficiency
  • The Hidden Economic Realities of AI: Tokenomics
  • Threats to Token Budgets: A New Attack Vector
  • Optimizing AI Workflows and Cost-Effectiveness
  • AI in Attack Scenarios and Defender Strategy
  • What You Should Do

AI’s Impact on SOC Efficiency

Research conducted by Daniel Boughton and Iain Reid at the University of Portsmouth, detailed in a study on AI SOC deployments, highlights AI’s significant potential to streamline security operations. Their findings indicate that AI can dramatically reduce the number of alerts analysts must address, allowing human experts to focus on high-impact incidents. The study revealed that approximately 82 percent of SOCs deploying AI utilize it for initial threat detection and triage, while 37 percent leverage AI to automate ticketing and response workflows.

AI serves as a powerful augmentation to human analysts, providing tireless support for deeper investigations and efficient parsing of alerts. Unlike human personnel, AI systems operate continuously, unaffected by shift changes or other operational demands, creating a perception of an indefatigable security asset.

The Hidden Economic Realities of AI: Tokenomics

While AI offers immense benefits, a significant, often overlooked constraint impacting agent activity is “tokens.” These are the fundamental units of work that AI models consume to process requests. Deloitte’s report on AI spend dynamics, which introduces the concept of ‘tokenomics’, underscores this challenge. More intricate queries or larger data requests necessitate a greater exchange of tokens, directly correlating to higher operational costs. In cybersecurity, where investigations are inherently complex and increasing in volume, a single inquiry can consume a substantial number of tokens, each carrying a tangible real-world cost.

For security teams planning AI integration, a thorough understanding of these token-related costs is paramount. Each investigation presents a unique scenario, making it difficult to assign a standardized price. Although AI is poised to enhance SOC productivity and maintain an advantage over adversaries, the operational expenses associated with running these systems will become a growing line item in security budgets.

Threats to Token Budgets: A New Attack Vector

A concerning development is the potential for threat actors to weaponize token consumption. Attackers, aware that target companies utilize AI in their SOCs, could devise attacks specifically designed to deplete or maximize token usage. Just as developers employ “tokenmaxxing” to optimize software processes, malicious actors might adopt a similar strategy against IT security defenses. Burning through a defender’s AI budget could severely compromise the quality and scale of security responses, especially for organizations heavily reliant on AI for timely incident resolution.

Jeremy Powell, CISO at Sumo Logic, emphasizes the importance of proactively addressing this potential issue by analyzing token consumption in conjunction with existing processes to gain a realistic view of long-term expenditure. He highlights the need for organizations to prepare for a future where AI token costs significantly influence security performance. This involves scrutinizing how SOC teams process alerts and responses, and the specific role agentic AI systems play in these procedures.

Optimizing AI Workflows and Cost-Effectiveness

Understanding the intrinsic mechanics of a SOC and how AI supports these processes is crucial. This includes identifying human-in-the-loop processes where AI can accelerate responses, and evaluating whether alternative AI or machine learning techniques might be better suited than generative or agentic AI for specific tasks. Organizations should also compare the cost of token consumption against the time saved by an entry-level analyst. If the token expenditure outweighs the efficiency gains, the AI implementation may not be delivering its intended value, potentially increasing overall costs rather than reducing them. A comprehensive understanding of workflows and objectives enables the creation of optimized processes for both teams and budgets.

Agentic AI excels in delivering rapid responses and facilitating human interaction during threat analysis. Conversely, traditional AI and machine learning are more effective at reducing the costs associated with pattern matching and investigating large datasets, such as log data, while simultaneously mitigating analyst alert fatigue. Combining both technologies can significantly decrease investigation times and improve analyst prioritization, all while managing the additional costs of token consumption. Ultimately, the goal is to enhance the overall effectiveness of the security team.

AI in Attack Scenarios and Defender Strategy

The reality is that AI models will inevitably be leveraged for offensive purposes. The AI Security Institute (AISI) released research demonstrating AI models’ capability to execute multiple steps within attack paths autonomously. The average cost for these attacks was approximately $80 / £60 for 10 million tokens. Following releases like Anthropic Mythos, the AISI has updated its guidance, noting Mythos’s ability to complete full Capture The Flag scenarios with an average consumption of 50 million tokens per run.

These scenarios underscore AI’s performance potential, which is directly tied to token availability. Attackers are likely to bypass budgetary constraints by utilizing stolen access or fraudulent credit cards. For defenders, therefore, understanding the economics of AI security involves a holistic view of token usage, task effectiveness, and the development of realistic processes that strategically deploy agentic AI where it offers the greatest impact. The underlying technological infrastructure, particularly data pipelines, plays a critical role in how data is processed and utilized by these AI systems.

SOC teams must establish a clear strategy for integrating these technologies, considering current processes, necessary changes, and the potential evolution of costs. While using AI for triage and prioritization is an excellent starting point, its true value will be realized when it can implement higher-order security responses autonomously.

What You Should Do

  • Audit AI Token Consumption: Regularly monitor and analyze token usage across all AI-driven security tools to understand actual operational costs and identify potential inefficiencies.
  • Optimize AI Workflows: Design and refine security workflows to maximize the efficiency of AI systems, ensuring that token expenditure aligns with desired outcomes and avoids unnecessary consumption.
  • Implement Hybrid AI Strategies: Leverage agentic AI for rapid, high-impact responses and traditional AI/ML for cost-effective pattern matching, log analysis, and alert fatigue reduction.
  • Educate Teams on Tokenomics: Ensure security personnel understand the economic implications of AI token usage and how their queries and interactions impact overall costs.
  • Prepare for Token-Based Attacks: Develop strategies to detect and mitigate potential attacks designed to exhaust your AI token budget, which could degrade security response capabilities.
  • Review and Adapt Processes: Continuously evaluate current SOC processes in light of AI integration, identifying areas for improvement, automation, and cost optimization.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCybersecurityExploitSecurityThreatVulnerability

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Analog Devices Confirms Data Breach After Cyberattack

Next Post

Critical Home Assistant FFmpeg Bug Allows File Theft, Root Commands

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical CosmosEscape Vulnerability Exposes Azure Cosmos DB Instances
July 30, 2026
Google Chrome 115 Patches 37 Vulnerabilities, 7 Critical
July 30, 2026
GenieLocker Ransomware Targets Windows, ESXi, and Linux Systems
July 30, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us