Cybersecurity keeps making headlines — not because attackers are getting clever, but because attacks are constant, bigger, and bolder. And yet, in boardrooms and IT shops everywhere, leaders are telling themselves the same comforting lie: “We’re safe. We’ve got the tools.”
A few years ago, that tool was EDR. Today, it’s AI. Both promised to solve the talent shortage, cut costs, and stop attackers in their tracks. But both share the same fatal flaw: they don’t replace people — they remove them. And when you take people out of the equation, you also take away vigilance. What you’re left with is the illusion of security.
We Didn’t Learn from EDR
When EDRs first hit the market, hiring slowed. Companies assumed the agents would take over the job teams of security experts. Eventually, hiring picked back up because persistence kept slipping through, and attackers still owned the machines. This is one of the reasons there is a shortage in the field now.
But the reality is that not everyone actually learned that lesson. Professionals still believe that EDRs handle everything automatically. This mindset that the tool equals total protection never completely went away.
Now, AI is being sold the same way. And once again, companies are making the mistake of believing the tool can replace the team.
Attackers Are Using AI Too
AI is powerful. It can speed up investigations, triage alerts, and cut through 100s of lines of logs. But defenders aren’t the only ones using it. Attackers are too, and their AI has no rules.
While defenders lean on constrained copilots that only see what they’re trained to see, attackers run unfiltered models that do whatever they’re told to do:
– Make persistence look like routine Windows Tasks
– Obfuscate a credential stealer so it blends in
– Generate a dropper that hides inside a legitimate process
– Even rewrite their malware until it looks invisible to EDRs and “Clean” to AI-driven defenses
Read that again. AI doesn’t just help attackers build malware; it actually helps them build malware that knows how to hide from the tools we trust to stop it. And that’s the defender’s blind spot: AI isn’t a detective — it’s a predictor. It only knows how to flag what looks like the patterns it’s been trained on. Anything new, anything novel, slides past until a human catches it and retrains the system. Attackers know this, which is why they shape their activity to look routine. Our AI plays in the box. Theirs doesn’t. The attackers have an advantage from the start.
Persistence Equals Control
Persistence is the attacker’s endgame — and it’s where tools consistently fall short. Once persistence is in place, the attacker doesn’t just have access for a moment; they own the system indefinitely.
And it rarely looks like something obvious. Instead, it hides in plain sight:
- a scheduled task that quietly calls back to a command-and-control server on every reboot,
- a registry “Run” key that ensures malware revives no matter how many times you think you’ve cleaned it,
- or a Windows Management Instrumentation (WMI) subscription — a built-in automation framework — repurposed so it triggers malicious code while looking like ordinary system monitoring.
Here’s the catch: attackers want you to think you’ve already won. They’ll deliberately drop a few noisy files, knowing your EDR or AI tool will flag and quarantine them. The dashboard goes green, the help desk breathes a sigh of relief, and the cleanup feels complete.
But that “victory” is manufactured. The real payload — the persistence — remains untouched. And once it’s in place, the attacker can do almost anything:
- mine cryptocurrency in the background,
- capture keystrokes until a banking login shows up,
- exfiltrate sensitive data a trickle at a time,
- or simply hold access for later, waiting to pivot deeper into the network.
This is the real problem: the tools are playing checkers while the attackers are playing chess. The tools look for pieces that stand out, capture them, and call the game over. But attackers are thinking three moves ahead, embedding persistence in ways that look like legitimate IT activity, knowing the tools will overlook it. They’re not just bypassing defenses — they’re out strategizing them.
The MSP and IT Blind Spot
Too many MSPs are selling EDR or AI as if it’s full defense. They roll out the platform and tell clients they’re fully protected. But most don’t have a dedicated security professional on staff. The focus remains on uptime, patching, and help desk tickets. Security is a checkbox, not discipline.
Internal IT departments fall into the same trap. They outsource to SOCs that handle thousands of clients. When an alarm goes off, those SOCs will respond. But they won’t be inside your system every day, hunting persistence, checking hashes, or hardening defenses. They simply can’t.
The only way to close that gap is with in-house security. A dedicated professional who knows your environment, follows up after the alert, and refuses to take “all clear” at face value.
The Job Market Problem
This is why the cybersecurity job market looks the way it does now. Companies are pausing or cutting security hires because they think AI and EDRs are enough. It feels like efficiency. It looks good for their bottom line.
We’ve seen this before. When EDRs first arrived, hiring slowed too — until persistence kept slipping through and companies realized the tools weren’t enough. Then demand spiked higher than ever.
But it’s temporary. The compromises already in place will eventually surface. And when they do, businesses will realize dashboards don’t defend them, and copilots don’t replace vigilance. They’ll scramble to hire, and demand will spike even higher than before. Only by the time this happens, attackers will have had years of a head start. It will be an uphill battle.
The Growth Curve
Some leaders are still telling themselves that AI will eventually “Catch up.” As the models get better, they’ll close the gaps. But no one seems to realize that attackers are using the exact same technology. As our AI gets better, so does theirs. The curve is mirrored.
That means the difference will never be the AI itself. The difference will always be the human behind it.
Cybersecurity isn’t about dashboards or copilots. It’s about people who know how to use tools without being fooled by them. Right now, too many organizations are betting everything on programs and cutting back on people. The attackers want this as well.
Because when it’s AI vs AI, it’s still human vs human. And if you don’t have a defender behind your AI, the attacker already has the advantage. What makes the human defender irreplaceable is context and creativity. People can spot the social engineering angle in a phishing email, see the intent behind an unusual login, or recognize when “normal” system activity is anything but. Tools can’t do that — especially AI, which at its core is still only predicting patterns, not truly understanding them. That’s the real difference — and it’s why cutting people out of the equation isn’t just short-sighted, it’s dangerous.

Leave a Reply