The Defenders Are Catching Up
Three developments in four days suggest the defensive side of cybersecurity is finally beginning to scale.
The Defenders Are Catching Up
AI for scale. Humans for judgment
Three developments in four days suggest the defensive side of cybersecurity is finally beginning to scale.
Every article I have published lately has carried the same underlying message. The threat is accelerating. Attackers are moving faster. The gap between discovery and remediation is growing. Those things are all still true. But last week, the evidence started pointing in a different direction as well.
Three developments published between June 2 and June 5 show something that has been missing from most of the recent cybersecurity conversation. The defenders are not standing still. The tools, the governance frameworks, and the organizational commitment to use #AI for protection, not just to fear it, are starting to catch up. This article is about those three developments and what they mean for everyone responsible for security in their organization.
On June 2, Cisco ‘s Chief Security and Trust Officer, Anthony Grieco , published a blog post that deserves more attention than it has received. In eight weeks, Cisco scanned 1.8 billion lines of code across its entire product portfolio in over 25 programming languages. The same work would have taken their world-class security research team eight years to complete manually.
That number is worth reading twice. Eight years of security research, compressed into eight weeks. Not through shortcuts or reduced quality, but through AI-assisted scanning that operates at a scale no human team can match.
A common concern about AI-driven vulnerability discovery is that it floods security teams with noise, generating so many findings that engineers cannot tell which ones actually matter. Cisco found the opposite. By pairing frontier AI models with a human-guided review process, they achieved a false-positive rate of under 3% across 1.8 billion lines of code. That means the findings their engineering teams received were actionable, not overwhelming.
Cisco also developed #CodeGuard, an open-source project designed to inject security best practices directly into AI-assisted software development workflows. The goal is to make secure coding a natural part of how software gets built in the first place, rather than something that gets checked much later during a security review.
Starting in July 2026, Cisco will publish vulnerability disclosures twice a month rather than on its current monthly schedule, a direct response to the volume and speed of AI-assisted discovery. The company is also launching a product called Live Protect, which provides customers with a temporary protective layer against newly discovered vulnerabilities while they deploy a permanent fix. The goal is to help bridge the gap between when a vulnerability is discovered and when it is fully patched.
This matters beyond Cisco. It is proof that large organizations can use the same AI capabilities driving the threat to run their defenses at a scale and speed that was simply not achievable before.
On the same day Cisco published its findings, President Trump signed an executive order titled “Promoting Advanced Artificial Intelligence Innovation and Security.” The order directs federal agencies to establish a framework for the secure deployment of frontier AI models, including a voluntary process by which AI developers would provide the government with early access to models for up to 30 days before releasing them to other partners.
This is the US government formally acknowledging that powerful AI models need to be evaluated for cybersecurity implications before they reach the public. It is not a heavy-handed regulatory regime. The framework is voluntary, not mandatory, and it does not require licensing or pre-clearance. But it signals something important. The question of how frontier AI models affect national security is now a formal policy priority, not just a concern debated in research papers.
The order also directs the Treasury Secretary to establish an AI cybersecurity clearinghouse, in collaboration with the AI industry and critical infrastructure operators, to coordinate vulnerability scanning, validation, and remediation. CISA is directed to issue binding operational directives to expand AI-enabled defensive tools for federal civilian systems and to make those tools accessible to state and local governments, rural hospitals, community banks, and local utilities.
That last detail is worth highlighting. The explicit mention of rural hospitals, community banks, and local utilities reflects recognition that organizations with the least cybersecurity capacity are often the most exposed. Extending AI-powered defensive tools beyond the federal enterprise to those institutions is the right instinct.
Cybersecurity and Infrastructure Security Agency (CISA) followed the executive order on June 4, announcing it is developing a new platform to help agencies leverage the defensive capabilities AI can provide, with at least one binding operational directive expected imminently to direct agencies in securing large language models.
These developments do not come out of nowhere. A World Economic Forum (WEF) report published in May found that 94% of cyber leaders now identify AI as a defining force in cybersecurity, and 77% of organizations are already using AI in their security operations. The report, developed in collaboration with #KPMG and drawing on 20 real-world case studies, found measurable gains in cost reduction, response speed, and resilience among organizations deploying AI strategically.
The report makes a point that I think gets lost in most coverage of AI and cybersecurity. AI’s value in this space is not about replacing human expertise. It is about enabling human experts to operate at a scale previously impossible. A security engineer does not become less important when they have AI working alongside them. They become capable of covering ground that no team could cover before.
That is exactly what the Cisco story illustrates. Their security research team did not disappear. They guided the AI, validated the findings, and made decisions about what to fix and how. The AI changed what that team could accomplish in eight weeks. It did not change who was responsible for the outcome.
These are big organizations with significant resources. It is reasonable to ask what any of this means for a mid-sized company, a school district, a regional hospital, or a government agency in an emerging market.
The honest answer is that the tools becoming available through initiatives like Project Glasswing, Cisco’s open-source #CodeGuard project, and the AI cybersecurity clearinghouse the executive order mandates are designed to extend defensive capability beyond the largest and most well-resourced organizations. That extension will not happen overnight, and many organizations still lack the resources to take full advantage of these capabilities today.
For any organization thinking about where to start, the Cisco approach offers a useful framework. They did not try to deploy AI everywhere at once. They used it to scan code they already had, in a process guided by human experts who could assess the quality of the results. The technology compressed the timeline. The humans ensured the findings were worth acting on.
That balance, AI for scale, humans for judgment, is available to organizations of all sizes. The tools are increasingly accessible. The question is whether there is organizational commitment to use them.
In my professional view, the most important shift happening right now is not the emergence of a single tool or a single policy. It is the beginning of a genuine institutional response to a challenge that has been building for years. Cisco’s numbers are real. The executive order is signed. The WEF data shows that some organizations are already seeing results. The defenders are not winning yet. But for the first time in a while, there is credible evidence that they are moving in the right direction, and at a speed that starts to match what the threat demands.
Cybersecurity #AISecurity #CyberDefense #SecurityLeadership #CyberResilience #ArtificialIntelligence #VulnerabilityManagement #AmieOnSecurity
Cisco Blogs, 8 Years of Security Research in 8 Weeks: https://blogs.cisco.com/news/8-years-of-security-research-in-8-weeks-transforming-cybersecurity-with-ai
Axios, Cisco Revamps Vulnerability Disclosures for the AI Era: https://www.axios.com/2026/06/02/cisco-revamps-vulnerability-disclosures-for-the-ai-era
BizTech Magazine, AI Could Help Security Teams Move Faster: https://biztechmagazine.com/article/2026/06/ai-could-help-security-teams-move-faster-say-cisco-and-openai-leaders
The Register, Cisco Praises AI Bug Hunt: https://www.theregister.com/ai-and-ml/2026/06/02/cisco-praises-ai-bug-hunt-wont-reveal-flaw-tally/5250291
A.O. Shearman, Trump Administration Issues Executive Order on AI and Cybersecurity: https://www.aoshearman.com/en/insights/trump-administration-issues-executive-order-on-ai-and-cybersecurity
Mayer Brown, President Trump Signs Executive Order on Advanced AI Innovation and Security: https://www.mayerbrown.com/en/insights/publications/2026/06/president-trump-signs-executive-order-on-advanced-ai-innovation-and-security
Federal News Network, AI Executive Order Sets Stage for New Cybersecurity Directives: https://federalnewsnetwork.com/cybersecurity/2026/06/ai-executive-order-sets-stage-for-new-cybersecurity-directives/
Federal News Network, CISA Close to Issuing New Cyber AI Directive: https://federalnewsnetwork.com/cybersecurity/2026/06/cisa-close-to-issuing-new-cyber-ai-directive/
World Economic Forum, New Report Shows How AI Gives Cybersecurity Competitive Advantage: https://www.weforum.org/press/2026/05/new-report-shows-how-ai-gives-cybersecurity-competitive-advantage/
Freshfields, Trump Executive Order on AI: https://www.freshfields.com/en/our-thinking/blogs/a-fresh-take/trump-executive-order-on-ai-voluntary-framework-cybersecurity-focus-and-key-ta-102n18b
Originally published at https://www.linkedin.com.
메타데이터
- post_id
- 32c2ed9137b3
- slug
- the-defenders-are-catching-up-32c2ed9137b3
- url
- https://medium.com/@amieonsecurity/the-defenders-are-catching-up-32c2ed9137b3
- canonical_url
- https://medium.com/@amieonsecurity/the-defenders-are-catching-up-32c2ed9137b3
- author_url
- https://medium.com/@amieonsecurity
- status
- ok
- fetched_at
- 2026-07-08 02:40:31