Nejla Seyhan Susam, Cyber Defense Technologies Manager at Garanti BBVA, discussed fault tolerance and the human role in cyber defense. Susam stated the following:
“When we consider general technology usage today, artificial intelligence is a concept deeply intertwined with efficiency; however, the situation changes somewhat when it comes to security. I would like to introduce this topic with an example. Looking back at 2020, the average ‘breakout time’—that is, the time it takes for an attacker to make their first lateral movement after gaining system access—was nine hours; by 2025, this duration had dropped to just 29 minutes. Furthermore, the shortest recorded time was 27 seconds, and the interval between initial access and the start of the first data leak shrank to four minutes. This demonstrates that attackers are leveraging AI to accelerate their operations, turning the defense side into something akin to an arms race. We must match the increasing speed of attackers with greater speed on the defense side. Consequently, the most critical criterion for using AI in a Security Operations Center (SOC) is the ability to increase speed. From our perspective, accelerating processes—whether in alarm analysis, prioritization, false-positive filtering, detection, or response—is the most vital aspect of SOC operations. However, making the right decision alongside that speed is also crucial; if you make a wrong decision while moving quickly, your response time can actually end up being longer than before. Therefore, it is essential to generate the right decision rapidly by utilizing the correct resources and correlating the right data through proper triage. This is precisely where the human role comes into play.” No matter how much we automate or leverage AI, making a wrong decision without the involvement of human intuition, thought, and analysis can lead to far worse consequences. Suppose a threat alert is triggered in a system and you take action against it—such as disabling a critical service user or isolating a host—resulting in significant financial loss. Therefore, while increasing speed, it is crucial to prioritize making the right decision and to incorporate the human factor into the process. It is vital to use AI for repetitive tasks where risks are lower and error tolerance is higher, while keeping humans involved in the process—maintaining a “human-in-the-loop” approach—in scenarios where risks are higher, error tolerance is lower, and potential financial losses are significant.
About the Wise
Similar Videos from this Wise
Which Cybersecurity Tasks Should Be Outsourced, and Which Should Be Handled In-House?
Nejla Seyhan Susam, Head of Cyber Defense Technologies at Garanti BBVA, spoke about which cybersecurity tasks should be [&hel...
Are Autonomous and Proactive Systems Possible in Cyber Defense?
Nejla Seyhan Susam, Cyber Defense Technologies Manager at Garanti BBVA, discussed the feasibility of human-independent, pro...











