Clear escalation, testing and oversight help organisations manage consequences of machine-driven detection, triage and response
As more cybersecurity activities become automated, the central challenge is not simply whether to automate, but how to define the boundaries within which autonomous systems can act.
Greater automation can help security teams handle fast-moving threats. Investigation, triage and containment actions that once required analyst intervention may increasingly occur in seconds.

Cezary Piekarski, Group CISO, Standard Chartered
However, organisations should identify where autonomous systems operate, how their decisions are made, and who remains accountable when an action affects operations, customers or regulatory obligations.
Low-risk and reversible actions may be suitable for automation, while actions with significant business consequences should have clear escalation and approval requirements. The human role may shift from operating every control to setting guardrails, managing exceptions and ensuring that technology aligns with the organisation’s risk appetite.
Keep human judgement in key decisions
Automation can process large volumes of information quickly, but security decisions often depend on business context. Security leaders need to determine when a technical finding requires action, when an automated response could create greater disruption, and when an incident needs wider business involvement.
Communication also remains important. Cybersecurity teams need to translate technical findings into clear explanations of operational risk, likely consequences and available mitigation options. This helps decision-makers act promptly when an incident affects customers, services or other stakeholders.
High-impact incidents can involve competing priorities across security, operations, legal obligations, customer communications and reputational considerations. Organisations should define who has authority to make those trade-offs before an incident occurs.
Test decisions, not only technology
Continuous resilience testing should examine more than whether technical controls detect or contain an attack. Exercises can test how teams make decisions, coordinate across functions, communicate during disruption and respond when automated actions produce unexpected results.
Organisations should also maintain clear records of automated decisions, actions and overrides. This can support post-incident reviews, identify gaps in governance and help teams refine the thresholds under which systems act independently.
Give CISOs clear priorities
The role of the CISO has evolved significantly. Today, effective cybersecurity leadership is as much about people as it is about technology. Increasingly, CISOs must engage with boards and executive leadership teams. Translating cyber and AI-driven risks into clear business implications is now a core skill.
Therefore, CISOs should consider whether their organisation has:
- Defined the actions that can be automated and those that require human approval
- Set escalation paths and accountable decision-makers for high-impact incidents
- Tested how automated controls behave when they generate false positives, miss a threat or disrupt an important service
- Prepared business leaders to understand the operational implications of cyber and AI-related risks
- Built a culture in which employees can report mistakes, raise concerns and escalate issues early
AI may increasingly support detection, investigation and response at a speed beyond human capability. However, accountability for the consequences of those actions remains with the organization. The priority for cybersecurity leaders is to ensure that automation operates within clear risk, governance and human-control boundaries.
