What happens when a security team receives 50,000 alerts but only 50 genuinely need human attention?
In this episode of The Business of Cybersecurity, I speak with Harman Kaur, CTO of Tanium and a reserve cyber officer in the U.S. Air Force, about how AI is changing the pace, structure, and responsibilities of modern security operations.

The long-running cybersecurity talent shortage has not disappeared, but Harman believes the conversation is changing. Security teams now have tools that can assist with specialist work, which places greater weight on processes, interpretation, and decision-making. Training increasingly includes knowing how to ask the right question, assess an AI-generated response, and decide whether the proposed action makes sense.
That change matters because the old pattern of threat response is becoming too slow. Security teams once had time to identify a threat trend, respond to it, and prepare for the next one. Harman says those cycles can now collapse to seconds as AI helps attackers find vulnerabilities and develop exploits. Defenders therefore need to consider whether the same technology can support remediation and patch creation at a comparable pace.
We discuss why traditional scripted automation cannot solve this problem by making the existing workflow slightly faster. If an analyst can manually process 100 alerts and automation raises that number to 200, the improvement offers little comfort when the queue reaches thousands or hundreds of thousands. Harman argues that organizations need to reconsider how the security operation itself is designed while retaining people as judges for decisions with meaningful consequences.
Autonomy, in her view, should be treated as a spectrum rather than an all-or-nothing destination. One process may be suitable for full automation, another may require approval, and a third may remain entirely human-led. That approach also helps CIOs and CTOs respond to pressure for rapid AI adoption without pretending that a single governance model can answer every risk.
Harman also warns against allowing the AI conversation to distract teams from familiar security weaknesses. Shadow AI matters, and companies need visibility into the models and tools being used across the organization. At the same time, phishing, compromised credentials, unpatched machines, end-of-life devices, unused applications, and exposed ports remain common sources of risk. AI may amplify those weaknesses, but it does not erase the need to address them.
The episode’s clearest example concerns alert fatigue. Harman describes an AI system that processes and triages alerts while reporting its confidence and showing how it reached its conclusion. Verification mechanisms can then ask what additional context should be considered. The goal is to narrow 50,000 alerts to perhaps 50 that deserve manual investigation, giving analysts a manageable decision set without asking them to trust a model blindly.
We also discuss operational resilience and why prevention must begin before a security alert appears. Harman challenges organizations to explain why routine patching is not automated in 2026, while recognizing that no company can apply every patch instantly. Reducing the attack surface by removing unused applications and closing unnecessary ports can make the business a smaller target while teams address the vulnerabilities that matter most.
Finally, Harman asks leaders to question why they are applying AI to a given problem. Some tasks can be handled by established automation. If the organization chart, business processes, and toolset look exactly the same after an AI program, the company may have added technology without redesigning the work. Where should your organization allow AI to act, where should it advise, and where must a person make the final decision? Listen to the episode and share your thoughts.
Useful Links
Connect with Harman Kaur
Learn more about Tanium
[00:00:00] Scale your business with agentic AI with limited risk. With Denodo's AI data layer, your agents are provided with real-time company data and guardrails for company protection. Create the business you always dreamed of with Denodo, and you can do that by simply visiting denodo.com to learn more. But now, back to my guest.
[00:00:28] What happens when threat cycles that once unfolded over weeks collapse into seconds? Well, security teams cannot answer that pace by processing yesterday's alerts faster. And my guest is the CTO of Tanium that's going to be joining me today. And she's also a reserve cyber officer in the US Air Force. And she's going to join me on Business of Cybersecurity today to examine what must change.
[00:00:58] And we're going to discuss why scripted automation has reached its limits, and how endpoint security must respond locally. And where autonomous systems can actually reduce 50,000 alerts to 50 that just deserve immediate human judgment. And she will also explain why AI governance cannot distract organizations from patching, identity protection, application removal, and attack surface reduction.
[00:01:27] Let's be honest, nobody joined cybersecurity because they dreamed of managing an even larger alert queue and monitoring dashboards. So instead, today, I want to look at a route towards faster defense while also keeping people accountable for their decisions. Decisions that carry very real consequences. With that scene set, let me introduce you to my guest.
[00:01:55] So thank you for joining me on the podcast today. Can you tell everyone listening a little about who you are and what you do? I am Harman Carr. I'm thrilled to be here. A little bit about me. I'm currently the CTO of Tanium. I've also spent about 13 years in the U.S. Air Force. I'm currently also a reserve officer, so cyber officer in the U.S. Air Force as well. Incredibly cool. I'd love to dig a little bit deeper on that, but you probably can't tell me anything.
[00:02:24] So we will stick with cybersecurity. And I think it's always been a race between attackers and defenders. That's the way it's always been. But AI seems to be changing that pace entirely. So from what you're seeing, how has the threat landscape changed over the past year? And what should security leaders be most concerned about now? I think it's a couple of things. It's interesting to see the trends.
[00:02:52] We saw there was a concern for a long time about talent and security, right? I think everyone talked about it and said we can't hire enough people into security, domain experts, deep domain experts into security for a long time. Pace of threats has also changed. So there's these trends that we've been seeing. And right now, what we're seeing sort of emerging is we're seeing sort of talent conversation actually go down because you have these tools that can assist.
[00:03:21] But you also have to build the processes around these tools for your team to be able to actually use these tools, right? You'd be able to leverage AI. So that's the other really shift. We're going from a conversation where everyone thought hire, hire, hire, right, train. And now, really, training is effectively a prompt, right? And reading the output and reacting to that output. And you have the right decision-making skills to do that.
[00:03:45] Not so much do you know exactly how to use this, you know, very niche security tools to do everything. So that kind of pendulum is also swinging. And then in terms of like actual threats, we used to see cycles, right? So we used to see like a rise of a threat that would be in the news for a while. Everyone would react to that. And then another one would come. And now, like we're seeing sort of that cycle has collapsed pretty much down to seconds, right?
[00:04:10] So there's so, you can see sort of the rise of number of vulnerabilities that are out there. What's not what, you know, everyone's sort of grappling with now is what's the remediation side of that? What's the other side of that equation? Are these tools just as effective at writing a patch just as much as they are, right, helping write an exit and actually helping us do the fix as well? So it's an interesting sort of world right now to kind of see these trends sort of kind of ship on their head. There's so many great points there.
[00:04:40] And before you joined me today, I was doing a little research on you. And I was reading how you've said that the traditional scripted automation methods are no longer enough. So why is that approach reaching its limits now? And what role do AI and autonomous systems, what do they really need to play in the modern security operation? Yeah, I think the traditional like automation tools, what you were doing is you were taking this existing process.
[00:05:04] So let's say Harman could process 100 alerts a day manually, then you were trying to see if I could stretch that to about 200 alerts a day using automation, using sort of these traditional tools. Now it's no longer about can you do 200 alerts, right? The alerts have sort of gone into thousands, hundreds of thousands. So how do you now you have to fundamentally think differently about the approach to that problem as well?
[00:05:28] Not just automation, right? Historically is make the work of the human faster, make the existing processes faster. Now we have to actually go back to the fundamentals and think, right, how do we re-architect and think about security differently for our entire organization? As if we were kind of starting from scratch, to be honest with you. And I think these systems can play a really, really critical role. But where humans are still going to be really critical is that decision making piece.
[00:05:56] That's what I keep going back to is like humans are still going to help make key decisions in these functions. They're still going to have to serve as these effective judges to say, is this a path we want an autonomous systems to take? And the last point on autonomous systems is it can sound like a scary sort of concept for organizations too. You know, I like to also think about it as a spectrum. It's not binary. It's not that you have an organization where you've applied all these autonomous systems and everything's autonomous.
[00:06:25] It's sort of a spectrum. Are we making progress to go down that path, right? It's not just on or off. And I suspect we will have people listening from organizations that are constantly under pressure to adopt AI, but at the same time manage the risks that AI introduces. So how can any CIOs or CTOs listening balance innovation with governance without slowing the business down? Always being a balancing act.
[00:06:53] But any tips or advice here? Oh, yeah. I think this is like the million dollar question for everyone right now. Look, I don't know if there is one single approach to this. And I think anyone that's sort of selling the one approach that fixes all of your problems in this domain is probably selling stretching a little bit. But I don't think we all have the answers to that.
[00:07:17] You know, I think the first thing I think a lot about is just like the shadow AI problem is do we have awareness of what AI tools are even being used across our organization? Right. Starting with something as fundamental as that. And then the other thing I keep going back to is people were really worried about AI governance and we should be rightfully so. But let's not forget the fundamental things of cybersecurity. Let's not forget the hygiene of organizations that's still needed. Right.
[00:07:45] People are still fall trapped to, you know, phishing emails, people, credentials. Right. Like identity. All of those fundamental problems are still here. They didn't go away because AI came around. Right. AI has sort of amplified them. But we can't forget about the kind of fundamentals as well. I see a lot of organizations in this kind of conversation of how do we govern this? How do we think about? And it's like, OK, let's think. Do you patch your machines? Right. Are you updating your machines?
[00:08:14] Are you removing machines that are end of life? Like are we at least doing the basic stuff? Do you understand what models are being used across your organizations? Does anyone have, you know, open claw if you don't allow that across your organization? Like, let's understand those things. It doesn't need to be, you know, and I think as we're kind of all navigating this, we will have better governance, better tools across the entire organizations. But I don't think we'll ever be able to let go of these kind of fundamentals that still need to be in place.
[00:08:43] And at Tanium, you've always emphasized real-time visibility across endpoints. Nothing new there. But as AI agents, machine identities, and autonomous systems become part of enterprise environments, I'm curious, how do you see endpoint security needing to evolve to continue keeping up with this pace? Oh, man. We, so security, the way it's worked traditionally is.
[00:09:11] A human's, right, to some extent we use obviously some automation here, say go look for, we define what is bad, right? We define and say these are bad things that can happen on a machine. And we send that down to the machine and say watch if these bad things happen if they do send us an alert. I'm not sure we're going to really have time for those loops anymore.
[00:09:31] So how do you have something on the device itself tell you something is wrong without having you send down signatures or having to send down, you know, something to say alert me if this happens? They need to just be able to tell us, hey, something is going on. And I think we have now tools, you know, there's models out there that can help us sort of evolve security in this direction. And I think that's going to be really important.
[00:09:56] I don't think the pace any longer is going to be can I scan my endpoints and then react to what comes back on those scan results? By that point, just think about how many more vulnerabilities, how many more exploits have been created just from that point when you were just waiting for the scan results to come back. So I do think we're all going to really have to the pace of this is going to change completely. And I think we're all going to have to sort of adapt to that.
[00:10:19] And another challenge I hear repeatedly is that security teams are becoming overwhelmed by alerts. And as alert fatigue sets in, they struggle to identify the actual incidents that genuinely matter. So how can AI maybe help reduce some of that noise without creating a dangerous level of maybe overconfidence in some of those automated decisions? Yeah.
[00:10:43] You know, one of the first one of the first sort of AI integrations we did was to solve this problem a couple of years ago. So and a couple of things we wanted to make sure we kept intact because the overconfidence, the hallucination or it not having all of the context is a very real problem. You know, there's a lot of context as humans we keep in our brain that we haven't written down anywhere. Right. These and we or we haven't provided to these machines.
[00:11:11] So a couple of things that we've done is actually have when AI actually triages these alerts and actually processes these alerts, actually have it tell you how confident are you about this alert? And also sort of its chain of thought, like how did you triage this? What did you take into consideration? And then also we kind of have, you know, things like judges in place.
[00:11:33] We have kind of verification processes in place to say, OK, what else do you think is worth considering before you say this is sort of the final thing to consider? And so these are little things that we can take in. We can kind of apply. The other thing is this is kind of goes back to humans being these being humans. We have to rely on humans to be the judges at the end of the day.
[00:11:57] So you may be able to reduce down to here's 50 alerts that really need a human to actually look at look at mainly as well. And it's collapsed down from 50,000 alerts potentially. Again, when researching it, I know you've spoken a lot about operational resilience alongside cybersecurity. So why do you think resilience has become just as important as prevention?
[00:12:20] And again, for people listening, any practical steps that their organization should be taking to ensure that they can continue operating even when those attacks succeed? Yeah, I think the prevention thing is becoming more and more critical. We have left security, right? A lot of like security tools, they're the last line of defense. A lot of things have gone wrong for your security tool to go off, right? That means something wasn't patched.
[00:12:49] Something obviously came through your doors. Like something went wrong and then that's not why your security systems are going off and saying you have an alert. Here's something that you need to pay attention to. I think the proactiveness of this has become really important. And a couple of things I keep challenging organizations to do and think really hard about is just really fundamental things like patching. Why is that not automated in your organization?
[00:13:13] Like we should all have a really good answer if we're not able to automate something as fundamental as patching in 2026. And also reducing your attack surface, right? We think a lot about we need to keep, especially now, I hear a lot of conversations about patch faster. We need to remediate these vulnerabilities faster. There's more of them. Okay, but you also need to reduce your attack surface because there's no way every single person is going to be able to apply every single patch. And not every patch is available for all of these vulnerabilities.
[00:13:42] So how do you also shrink yourself down to make yourself less of a target as an organization as well? So like that's the other challenge I tell people is like, why are we not removing applications that aren't being used or closing ports that aren't being used? Make yourself a smaller target as an organization. And then think about the fundamental things like patching, why those things are also not automated across your organization.
[00:14:05] And beyond the technology itself that we're talking about today, I've also loved how you've shared some very thoughtful perspectives online and around AI's broader role in society, even arguing that the goal shouldn't be to replace human agency, but actually to think about expanding it. So how should that philosophy influence the way an organization or someone listening there might be able to deploy AI in their security teams and across the wider business?
[00:14:34] Anything you can share that would bring that philosophy to learn? Yeah, it's really interesting. I think what I would challenge people to think about when they're applying sort of AI to these problems is really ask yourself, why? Why are we doing that? I think there's a little bit right now of a jerk reaction where we're just doing it because it's the thing to do. Is this a problem that can be handled by automation? There's still problems that just plain old automation is just sufficient enough for.
[00:15:03] So I really critically think of why we're doing it when we're doing it and the way we're applying it. And the other thing is, I do think I do challenge people if you're kind of organizational chart, if your business processes, if the tools they're using all still look the same at the end. I'm not sure that was really the effective approach. I'm not sure you really have made the dent that you wanted to make. And you've made really the dent that you wanted to make to become kind of a more of an autonomous organization.
[00:15:33] And I'm going to have a bit of fun with you now and pull up my virtual crystal ball. And if we were to look ahead and try and imagine we're having this conversation three years from now, which I know is very difficult considering the level of technological change we've witnessed in the last three years alone. But what do you think the best security organizations will be doing differently in three years time? And also any advice you'd leave listeners today to help them build an AI enabled security strategy
[00:16:01] that is both resilient and fundamentally human centered. Anything you'd share there? Yeah, I mean, to answer your first part of your question, crystal ball three years. So now, I don't know. You know, I think I really can struggle to say through the manuscript now on what that's going to look like with the pace that we're going at. I think an organization that is truly kind of has shaped themselves and future-proofed themselves
[00:16:27] as an organization that has moved to a much more proactive position, right? They are really addressing things. They're trying to address things before they ever even become an alert, before they ever even become an incident. And it's kind of ingrained. It's not just the responsibility of the CC or CIO. It's the responsibility of every single person across that organization. And they have the understanding, they have the tool, and they have the agency to help participate in that as well.
[00:16:54] And I've loved chatting with you today around how AI and autonomous systems are reshaping cyber defense and IT leadership. And also for people listening, that growing pressure on the CIOs and the CTOs to balance innovation, governance, and operational resilience. For everybody listening that want to dig a little bit deeper, find out more information about you, the work, and everything that you're doing, and keep up to speed with some of the announcements coming out of the company. Where should people listening go?
[00:17:22] Tinium.com, or you can find me on LinkedIn. Perfect. Well, I will add links to everything there. And for anyone listening interested in that challenge of managing strategic technology decisions in these rapidly changing threat environments, I urge you to check those links out. And also feedback to me. Let me know your experiences. What's working? What isn't? But more than anything, thank you for starting this conversation today. Let's hope we can keep it going. And thank you for your time.
[00:17:52] Thank you so much. I think my guest left a very clear and practical message today. AI cannot compensate for weak cyber hygiene. Organizations, they need to know what runs across their environments, patch machines, remove unused applications, close unnecessary ports, and understand where shadow AI is actually operating.
[00:18:17] And AI can help compress thousands of alerts into a manageable set. But confidence scores, transparent reasoning, verification, and human reviews all remain crucial. And autonomy is a spectrum. And every business must decide which decisions machine can make and which require a human judgment. So if your organization introduced autonomous security tomorrow, would you be able to explain
[00:18:46] where it should act alone, where it should ask permission, and who remains accountable? Because that's where we need to get to. Let me know your experiences. This is techtalksnetwork.com. I'd love to keep the conversation going here. And I'll be back again real soon with another guest of the Business of Cybersecurity podcast. Hopefully, I'll get to speak with you again now. Bye for now.

