Why being human still matters in the world of cyber security
When the adversary is a wily and creative human, only man and machine working together can defeat them


Disciplines such as artificial intelligence and machine learning are playing increasingly important role in cyber security, but not at the expense of human intellect.
This is one of the key messages from the first day of McAfee MPOWER, the company's annual security conference in Las Vegas.
Indeed, one of the company's two new product launches, Investigator, has this complementary approach of human and machine at its very heart.
Speaking during a press panel on "human machine teaming", McAfee CTO Steve Grobman explained why in cyber security the human element remains so vital, whereas advanced analytics and AI is replacing humans in other disciplines.
"I think cyber security is a fundamentally different field to many other areas where artificial intelligence, machine learning is being used, Grobman said. "The example I like to give is weather forecasting [because] as we get better at forecasting weather, the laws of physics don't get upset and decide to change the way water evaporates. As we get better over time at forecasting where hurricanes are going to land, we make continuous progress.
"What makes cyber security such a different field than almost everything else in natural science that's using these same technologies is there's an adversary applying game theory on the other side of the table that's going to change the game. What machines are not good at is recognising human intellect you really need humans to understand human intellect."
Celeste Fralick, chief data scientist at McAfee, said the important thing is to use both AI and human resources rationally and where they can be of greatest value.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"We're dealing with humans and we have to act like humans back," she explained. "But at scale, you don't have an opportunity to do that logically with that amount of data [coming in] so you're going to have to do something different."
Machines, she said, should be used for tasks like summarising data, identifying patterns and making predictions, while humans should do more creative thinking at a human level, such as what the adversary may be doing. Based on that and the information provided by the data science capabilities, humans should then be the ones to decide what level of intervention is required and plan out next steps.
"Cyber security far outweighs [other disciplines in] the variety of data and the amount of data that's coming in because [cyber-attacks are] human driven [and] machine driven," Fralick explained. That pairing, she said, has to be reflected in how cyber security vendors respond to the threat.
Main image credit: Bigstock

Jane McCallion is Managing Editor of ITPro and ChannelPro, specializing in data centers, enterprise IT infrastructure, and cybersecurity. Before becoming Managing Editor, she held the role of Deputy Editor and, prior to that, Features Editor, managing a pool of freelance and internal writers, while continuing to specialize in enterprise IT infrastructure, and business strategy.
Prior to joining ITPro, Jane was a freelance business journalist writing as both Jane McCallion and Jane Bordenave for titles such as European CEO, World Finance, and Business Excellence Magazine.
-
What is polymorphic malware?
Explainer Polymorphic malware constantly changes its code to avoid detection, making it a top cybersecurity threat that demands advanced, behavior-based defenses
-
Outgoing Kaseya CEO teases "this is just the beginning" for the company
Opinion We spoke to Fred Voccola who remains a key figurehead at the firm as it enters its next chapter...
-
McAfee and Visa offer 50% off antivirus subscriptions for small businesses
News UK Visa Classic Business card holders can access the deal starting today
-
McAfee Total Protection review: Expensive at full price
Reviews Protects your PC and includes a decent firewall, but costly and less effective than some rivals
-
McAfee Total Protection review: Quick, effective and affordable
Reviews A solid security choice, with perfect malware protection, a fully functional VPN and more
-
McAfee’s zero trust solution strengthens private applications’ security
News MVISION Private Access grants secure access to private resources from any device or location
-
PowerShell threats increased over 200% last year
News A new McAfee report finds PowerShell attacks driven largely by Donoff malware.
-
McAfee to sell enterprise business to STG for £2.8 billion
News The enterprise business will be rebranded, with McAfee focusing on personal security
-
Has the US government finally nabbed John McAfee?
News Official Twitter account claims notorious tech tycoon has been “detained by authorities”
-
John McAfee ordered to pay $25 million over neighbour's murder
News Controversial figure insists that he will not pay