Innovation

Automating Cyber Defense Without Losing Human Judgment

Written by Fed Gov Today | Sep 18, 2026, 3:36:07 PM

Presented by Tines & Carahsoft

Cyberattacks increasingly unfold at machine speed, forcing public-sector organizations to reconsider processes that depend on analysts completing every step manually. Navid Wlotzka, Principal Solutions Engineer for Public Sector at Tines, says automation can help agencies respond faster—but it should not remove people from decisions where human judgment remains essential.

Speaking at the Billington Cybersecurity Summit 2026, Wlotzka emphasizes that the emergence of AI has not made the fundamentals of cybersecurity less important.

Organizations still need to understand their assets, manage vulnerabilities, test incident-response capabilities and confirm that their security tools are working properly. These cyber-hygiene practices become more important when adversaries use AI to find and exploit weaknesses quickly.

“Cyber hygiene still reigns true today,” Wlotzka says.

The difference is that agencies can now use automation to perform those practices more consistently and at greater speed.

Meeting Machine-Speed Threats

AI can help an attacker analyze systems and exploit vulnerabilities, including weaknesses defenders have not yet identified. A response model that relies entirely on people completing repetitive steps may not move quickly enough.

Automation can collect information from security tools, enrich an alert with additional context and perform the first stages of an investigation before an analyst becomes involved.

The human still makes the consequential decision, but the analyst begins with a clearer understanding of what happened. That reduces the time spent gathering routine information and accelerates the path to action.

Wlotzka says people should remain involved at important pivot points in an investigation or response. Agencies need to identify those points deliberately rather than applying the same level of human review to every task.

Using AI Only Where It Adds Value

Not every automated workflow needs artificial intelligence. Wlotzka distinguishes between AI-enabled tasks and deterministic automation, which follows established rules and produces predictable results.

A deterministic workflow may gather data from several systems, check it against defined criteria and present the findings to an analyst. Those steps can be completed through conventional automation without consuming AI resources.

An organization can then add AI at a specific point where it contributes something the deterministic process cannot. The model might summarize the findings, improve the investigator’s notes or identify a relationship within the data.

This selective approach gives an analyst additional insight without routing every task through an AI system. It also helps control the cost of model usage, which can grow quickly when organizations process large quantities of information.

The broader question is how AI supports the organization’s mission and strategic goals. Agencies should avoid adding a model to a workflow simply because the technology is available.

Beginning With the Work People Do Not Want to Do

Wlotzka recommends that agencies take a crawl-walk-run approach to automation. The first phase should focus on repetitive, low-level work that consumes time but does not require complex judgment.

Security operations centers often generate large numbers of alerts. Analysts must collect information, eliminate obvious false positives and document the results. Much of that work follows consistent steps.

Automating 70% to 80% of those routine tasks can substantially reduce the burden on the workforce. Analysts then spend more time investigating sophisticated threats, examining unusual behavior and making decisions that affect the mission.

This approach also gives the organization an opportunity to build confidence in its automation before expanding it into more complicated processes.

Leaders can observe whether workflows perform as expected, measure the time they save and determine where human intervention is still needed.

Knowing When Not to Automate

There is a point at which automation can go too far. A process should not become fully autonomous when it depends on context, accountability or judgment that a machine cannot reliably provide.

An automated system might gather evidence and recommend isolating a device. A person may still need to consider whether that device supports a critical operational function before taking it offline.

The right balance will differ by agency and mission. The important step is separating predictable work from consequential decisions and designing the workflow around that distinction.

Automation should make human expertise more effective, not eliminate it. By reducing noise and repetitive work, agencies can give cyber professionals more time to concentrate on the activities that require experience, creativity and a deeper understanding of mission risk.

Key Takeaways

  • Cyber hygiene remains the foundation of defense even as agencies confront AI-enabled, machine-speed attacks.
  • Deterministic automation should handle predictable work, with AI added selectively where it provides meaningful analytical value.
  • Agencies can begin by automating repetitive tasks while preserving human judgment at critical decision points.