Cybersecurity News in Asia

RECENT STORIES:

SEGA moves faster with flow-based network monitoring
Cellid and Megane Top Partner to Commercialize and Expand the AR Glass...
ICAC and UNODC’s pioneering international anti-graft training br...
Singapore police flag 3.64m dormant “shell pages” for takedown in Mid-...
Zero-click flaw enables remote code execution in four mainstream AI co...
Five ways to limit AI-assistant data leaks
LOGIN REGISTER
CybersecAsia
  • Features
    • Featured

      Shadow AI Is the New Insider Threat

      Shadow AI Is the New Insider Threat

      Monday, September 21, 2026, 9:11 AM Asia/Singapore | Features, Newsletter, Sponsored, Tips
    • Featured

      Addressing the AI-driven vulnerability debt

      Addressing the AI-driven vulnerability debt

      Thursday, September 17, 2026, 10:03 AM Asia/Singapore | Features, Sponsored
    • Featured

      Cybercriminals zero In on APAC’s digital boom, SMBs in the crosshairs

      Cybercriminals zero In on APAC’s digital boom, SMBs in the crosshairs

      Monday, September 14, 2026, 2:30 PM Asia/Singapore | Features, Sponsored
  • Opinions
  • Tips
  • Whitepapers
  • AWARDS 2026
  • Directory
  • E-Learning

Select Page

Tips

AI in EDR/XDR: Enhancing cybersecurity with a balance of machine and human expertise

By CybersecAsia editors | Monday, April 28, 2025, 9:47 AM Asia/Singapore

AI in EDR/XDR: Enhancing cybersecurity with a balance of machine and human expertise

Explore how AI can strengthen threat detection and response; address ethical considerations, and, under constant human scrutiny, proactively keep organizations safe.

Incredibly sophisticated cyber threats have made organizations turn to AI-driven solutions to strengthen their cybersecurity posture. At the same time, Endpoint Detection and Response (EDR) and Extended Detection and Response (XDR) technologies nowadays are increasingly leveraging AI and ML technology in their platforms.

According to Kaspersky, the implementation of ML has provided a platform for EDR and XDR solutions to create a normal activity baseline within organizations. Any subtle deviations from baseline can be flagged for suspicious activity. Said the firm’s AI Technology Research Center Group Manager, Vladislav Tushkanov: “AI is no longer a future concept in cybersecurity: it’s already reshaping the way we detect, respond to, and prevent threats… As cyber threats grow in scale and sophistication, AI is becoming the foundation for resilient, proactive cyber defense.”

Unlike rule-based detection systems, which rely on predefined patterns, ML-driven behavioral analysis can detect previously unknown threats, such as zero-day attacks and more advanced malware, according to the firm.

However, it is important to note that human expertise is still critical in interpreting and responding to complex or ambiguous alerts.

AI in threat hunting

The manual method of threat hunting generally involves searching logs and alerts for various items thought to be suspect. Only then can security analysts deem a possible information security risk.

This time-consuming method has been, and now some say it is becoming, less central. AI can assist with threat hunting by correlating data from many sources and uncovering indicators of compromise that would not be seen easily.

Nonetheless, effective threat hunting typically combines AI-driven insights with the experience and intuition of human analysts.

  • Minimizing the false positive rate
    When security tools generate an overwhelming number of alerts and high false positive rates, security teams may experience alert fatigue and inadvertently overlook real threats. AI is enhancing alert precision by continuously improving detection models while prioritizing threats based on risk levels.
    Therefore, while AI-driven EDR and XDR is relegated to the routine tasks of distinguishing benign anomalies from actual threats, human teams can focus on high-impact incidents and save other investigations from far more distraction, according to the firm.
    It is important to recognize, however, that AI models themselves can be subject to bias or errors, and regular review and tuning are necessary.
  • Automated incident response and remediation
    With AI, EDR and XDR platforms have a real-time capacity to respond to threats. Upon the detection of a potential attack by such a system, it could automatically trigger some predefined response actions: e.g., isolating a compromised device, blocking malicious IP addresses, or quarantining suspicious files among others. This will cut the time of incident response and lower security teams’ workloads from operational response, allowing them to focus on strategic decision-making instead.

    However, automated responses should be carefully managed to avoid unintended consequences, and human oversight remains important.
  • Predictive threat intelligence
    AI enhances the ability to comprehend threats by continuously assimilating global threat data, learning from past incidents, and predicting emerging attack patterns. EDR and XDR platforms, using ML models that have been trained on massive security datasets, can then predict incoming threats and harden defenses ahead of time. This predictive approach helps organizations stay ahead of attackers and adapt their security strategies to evolving threats.

    Still, the effectiveness of predictive models depends on the quality and diversity of the data they are trained on.

Risks, limitations and ethical considerations

While AI brings significant benefits to EDR and XDR, there are important considerations. AI and ML models can sometimes produce biased or inaccurate results if not properly trained and validated, and may raise privacy concerns due to extensive data monitoring.

Industry best practices recommend maintaining human oversight (“human-in-the-loop”) to interpret AI-driven findings and ensure ethical use. Additionally, as attackers increasingly use AI, defenders must remain vigilant against AI-generated threats and misinformation.

The future of AI in EDR and XDR

Upcoming generational improvements in AI and ML will only further strengthen the ability of EDR and XDR in accurately detecting, analyzing, and responding to threats. Some of the key trends to keep an eye on are:

  • Explainable AI: As AI systems have grown more and more complex, security teams will demand more transparency on why a decision has been made by an AI tool. XAI will clarify for analysts why certain threats are flagged and increase their trust in AI security products.
  • AI vs AI security: While cybercriminals utilize AI to evade detection, security vendors will develop countermeasures to combat AI-driven threats, leading to an ongoing AI arms race.
  • Self-learning security systems: AI models will continually develop, learning from new attack patterns and automatically adapting to new threats while minimizing the requirements for manual updates from the human side.

When EDR and XDR solutions are powered properly by AI, and deployed in a balanced approach, organizations will be able to address ethical, privacy, and operational challenges alongside technological innovation.

Share:

PreviousExploits remained the most frequently used initial infection vector in 2024: report
NextCybersecurity firm reports Telco, Entertainment, Government clients most targeted by DDoS in Q1

Related Posts

Question everything: 20 challenges to the critical mind in the mis/dis-information age

Question everything: 20 challenges to the critical mind in the mis/dis-information age

Thursday, August 1, 2024

One day to V-Day: did you fall for any of these scams yet?

One day to V-Day: did you fall for any of these scams yet?

Monday, February 13, 2023

Protect Christmas cheer from cybercrime

Protect Christmas cheer from cybercrime

Monday, December 5, 2022

ChatGPT, what have you done for defenders lately?

ChatGPT, what have you done for defenders lately?

Monday, March 20, 2023

Leave a reply Cancel reply

You must be logged in to post a comment.

Voters-draw/RCA-Sponsors

Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
previous arrow
next arrow

CybersecAsia Voting Placement

Gamification listing or Participate Now

LEARN MORE

Vote Now -Placement(Google Ads)

Top-Sidebar-banner

Whitepapers

  • Critical Security Threatsand the Need for ZTNA: How evolving cyberattacks demand a Zero Trust approach

    Critical Security Threatsand the Need for ZTNA: How evolving cyberattacks demand a Zero Trust approach

    Cyber threats have become more frequent and sophisticated, targeting organizations of all sizes across all …Download Whitepaper
  • Zero Trust Made Simple: Why it matters and how to get started

    Zero Trust Made Simple: Why it matters and how to get started

    Data breaches and cyberattacks are no longer limited to large, high-profile organizations.Download Whitepaper
  • Cloud Secure Edge: Remote access, better security

    Cloud Secure Edge: Remote access, better security

    ​SonicWall Cloud Secure Edge™ is a modern, cloud-native Security Service Edge (SSE) solution that addresses …Download Whitepaper
  • Closing the Gap in Email Security:How To Stop The 7 Most SinisterAI-Powered Phishing Threats

    Closing the Gap in Email Security:How To Stop The 7 Most SinisterAI-Powered Phishing Threats

    Insider threats continue to be a major cybersecurity risk in 2024. Explore more insights on …Download Whitepaper

Middle-sidebar-banner

Case Studies

  • How a Vietnamese D2C retailer built its own secure digital infrastructure

    How a Vietnamese D2C retailer built its own secure digital infrastructure

    Would your organization build your own digital infrastructure – including AI governance and cybersecurity – …Read more
  • Cyber protection for medical clinics in Singapore

    Cyber protection for medical clinics in Singapore

    As Singapore’s healthcare sector becomes increasingly digital and interconnected, clinics are facing heightened cyber risks, …Read more
  • India’s WazirX strengthens governance and digital asset security

    India’s WazirX strengthens governance and digital asset security

    Revamping its custody infrastructure using multi‑party computation tools has improved operational resilience and institutional‑grade safeguardsRead more
  • Bangladesh LGED modernizes communication while addressing data security concerns

    Bangladesh LGED modernizes communication while addressing data security concerns

    To meet emerging data localization/privacy regulations, the government engineering agency deploys a secure, unified digital …Read more

Bottom sidebar

Other News

  • Cellid and Megane Top Partner to Commercialize and Expand the AR Glasses Business

    Friday, September 25, 2026
    Combining Cellid’s Technological Expertise with Megane …Read More »
  • ICAC and UNODC’s pioneering international anti-graft training brings together law enforcers worldwide to combat illicit enrichment

    Friday, September 25, 2026
    HONG KONG, Sept. 25, 2026 …Read More »
  • Cohesity Introduces Agent Resilience to Protect and Recover AI Agent Infrastructure

    Tuesday, September 22, 2026
    Cohesity Agent Resilience launches with …Read More »
  • LRQA Named ‘Best in Critical Infrastructure Protection’ at CybersecAsia Readers’ Choice Awards 2026

    Monday, September 21, 2026
    Prestigious regional recognition highlights LRQA’s …Read More »
  • Cyble and Cyber Security Council of UAE Sign MOU to Strengthen National Threat Intelligence Capabilities

    Thursday, September 17, 2026
    ABU DHABI, UAE, Sept. 17, …Read More »
  • Our Brands
  • DigiconAsia
  • MartechAsia
  • Home
  • About Us
  • Contact Us
  • Sitemap
  • Privacy & Cookies
  • Terms of Use
  • Advertising & Reprint Policy
  • Media Kit
  • Subscribe
  • Manage Subscriptions
  • Newsletter

Copyright © 2026 CybersecAsia All Rights Reserved.