20 July 2026
The technology cyber attackers use to get past your defences is the same technology you need to stop them. Artificial intelligence is no longer a future concern for security teams. It is already shaping how attacks are launched and how they are stopped.
Businesses that do not adopt AI-driven security are falling behind on both capability and speed. AI has lowered the barrier to entry, putting sophisticated attack techniques within reach of people without deep technical skill, while also giving defenders faster detection and sharper analysis than manual methods allow.
At Manux Solutions, we work with New Zealand businesses asking the same question. They understand the risk, but they do not have the time or the specialist skills to work out where AI genuinely strengthens their security, and where it introduces new exposure.
Generative AI and machine learning are now core parts of how security teams operate. AI helps identify threats faster, analyse malicious code, and monitor behaviour across an environment at a scale no analyst could manage alone.
The shift is not subtle. The World Economic Forum found that 47% of organisations now cite generative AI as their primary security concern, and 86% of business leaders experienced at least one AI-related incident in the past year. The FBI has documented a 37% increase in AI-assisted business email compromise attacks. (Source: WatchGuard, Artificial Intelligence (AI))
Traditional tools are struggling to keep pace. Around 76% of malware now consists of zero-day threats that traditional antivirus does not recognise. That gap between catching most threats and missing a quarter of them is why security teams are moving toward AI-powered detection.
(Source: WatchGuard, Artificial Intelligence (AI))
AI has also removed the grammatical errors and awkward phrasing people once relied on to spot a scam. Deepfake audio and video can now impersonate an executive convincingly enough to authorise a fraudulent transfer.
For small and medium businesses, this is significant. Attackers no longer need deep technical skill or large resources to run a convincing, well-targeted attack.
AI supports defenders across several parts of the security operation, bringing together the speed of automation with the judgement of trained analysts.
In practice, this includes:
The result is that threats are identified and investigated faster, often before a business is aware anything has occurred.
The same capability that helps defenders also helps attackers.
Malicious bots now account for a significant share of internet traffic, adapting their behaviour in real time as they encounter security controls.
AI can also automate the process of analysing a patch and generating working exploit code, compressing the window between a vulnerability being disclosed and it being actively exploited from weeks to hours.
Security operations centres receive thousands of alerts a day, and most are false positives or low-priority events. Automation is what makes that volume manageable.
None of this removes the need for people. It changes what they do, shifting analysts from triaging every alert to designing the rules, tuning the models, and building the playbooks automation runs on. (Source: WatchGuard, Artificial Intelligence (AI))
Automation helps handle volume, but humans still make the judgement calls that machines cannot. Security professionals review the cases automation cannot resolve, investigate attacks that do not match known patterns, and decide what level of risk is acceptable.
The work itself is changing. Analysts used to spend most of their time triaging alerts. Now they design the detection rules that generate those alerts and tune the models that filter the noise.
This shift means security professionals need to understand both the business threats they are defending against and the technical capabilities of their tools. They are becoming architects of the security system, not operators who manually respond to every incident.
AI systems trained primarily on attacks against one industry might miss techniques common in another. Security teams need to validate their AI tools against the actual environment and threats they face, not just trust vendor claims about accuracy.
Automated response actions carry risk too. A false positive that locks out a legitimate user during a genuine business emergency creates its own kind of damage. Human oversight matters, because someone still needs to review automation's decisions and stay accountable for action taken in the business' name.
At Manux Solutions, we help New Zealand businesses understand where AI genuinely strengthens their security position, and where it introduces exposure that needs to be managed.
We work with organisations to assess how AI is already shaping the threats they face, and put the right mix of automation and human oversight to work in their favour, without losing the judgement that keeps automated decisions accountable.
Our focus is on practical outcomes: reducing risk, improving resilience, and giving businesses confidence in how AI is being used across their environment, both by their defences and by the people trying to get past them.
If you are reviewing how AI fits into your business' security posture, Manux Solutions can help.
We can work with you to understand where your environment stands today, identify where AI-driven risk or opportunity sits, and explain how the right mix of automation and human oversight could strengthen your defences.
Get in touch with the Manux Solutions team to start the conversation.