Home
Blog
AI moves faster. But humans are setting the course.

Summarize with AI

Share
Copied !

AI moves faster. But humans are setting the course.

In this interview, Cyril Simonnet, Sekoia’s Chief Revenue Officer, explains how context, data, runbooks, and human judgment will shape AI-powered cybersecurity.
Interlocking pink lines as part of Sekoia's branding.

Key takeaways

Cyril Simonnet shares a practical view of AI in cybersecurity, from preparing the right data to keeping people accountable for decisions.

  • AI needs complete, connected context to support reliable detection and investigation.
  • Automation should remove repetitive SOC work while analysts retain judgment and control.
  • Runbooks make AI actions visible, repeatable, and adaptable to each organization.
  • Teams should test AI claims with controlled attacks, clear outputs, and evidence from real customers.
  • Experience remains essential for training systems and helping new analysts build strong foundations.

AI is changing how cyber operations are carried out and how security teams respond. The technology can process more activity at greater speed, but its value depends on the context behind it and the people directing it.

In this conversation, Cyril Simonnet, Sekoia’s Chief Revenue Officer, explains why context comes before automation and how runbooks keep AI accountable. He also reflects on why experience will matter even more as AI takes on repetitive work, the curiosity that brought him into cybersecurity at 14, and the humility the industry has taught him since.

Watch the full video interview below as part of Sekoia's brand-new "Intelligence Asymmetry" podcast, or keep reading to learn more.

A career that started with Minitel

Megan: What first drew you to cybersecurity?

Cyril: Cybersecurity has been my passion since I was 14. The first keyboard I had in my hands was a Minitel, a product built by France Télécom.

Some of the services were expensive, so I found a way to access them at a much lower cost. I discovered that I wasn’t the only person doing this and joined a group of people who were interested in hacking and understanding how systems worked.

When I finished high school, I decided to study cybersecurity because it was what I wanted to do. I went to engineering school in Paris with the same group of friends, and that became my career.

I’ve never done anything else. Even cooking, I can’t cook. I just do cyber.

Megan: You started by exploring the offensive side before moving into defense!

Context comes first

Megan: AI is attracting a lot of attention in cybersecurity. What should people ask before investing in an AI-powered SOC or an agentic security solution?

Cyril: AI works based on context. If you don’t have the right context, AI won’t work well.

Everyone understands this when they use ChatGPT. If you write a prompt with two or three words and give it very little context, you probably won’t get the answer you want.

Security teams face the same problem. Many organizations have the information they need, but it’s split across different sources. Those sources aren’t always connected, so analysts have to search in several places to build the context they need for detection and investigation.

Some people present the absence of a central data platform as an advantage because it means you don’t have to buy a SIEM. I see it differently. Centralizing and enriching the data is a requirement. Once you have the context, you can run AI on top of it and get much better results.

That changes two things. Detection and investigation can move much faster. At Sekoia, we’re currently seeing around 85% accuracy in this area, and it keeps improving.

The second change concerns the SOC team. Attacks are driven by machine speed and machine volume. You can’t ask 10,000 people to investigate 10,000 parallel attacks. You need a machine to handle the volume.

You still need a human in the loop. Someone has to understand the output, apply the right context, and decide what to do next.

Alert verdict in Sekoia, showing a confirmed attack with 95 percent confidence.
Alert verdict in Sekoia

AI should remove repetition, not judgment

Megan: Do people in a SOC have the skills to challenge an AI agent’s verdict?

Cyril: Definitely. They’re already doing it. The challenge is the volume and speed of attacks. Analysts know how to do the work, but they don’t have enough time to handle every task manually. Analysts need the information required to make a decision quickly. They also need to be able to question the model and help it improve.

The issue today is that they don’t have enough time. They’re overwhelmed by recurring tasks that don’t require much analysis, but still have to be completed. AI can help people return to the work where they bring the most value. It can take repetitive tasks off their hands and give them more time to investigate, decide, and respond.

Adoption begins with data

Megan: Some organizations are moving quickly on AI while others are waiting. What happens when companies wait too long?

Cyril: If you have the data, adoption can move quickly. The agents already come with detection and investigation capabilities, and you can build on top of them.

The key is putting the data in one place. From the moment an alert arrives to the moment it’s identified, the process can take roughly 100 seconds. But if the context is incomplete, AI can produce hallucinations, incorrect information, or results that aren’t useful. Teams then spend more time managing false positives and checking the output than fixing the problem.

Centralizing data can be a complex project, depending on the infrastructure. You can begin with the sources that are easiest to collect, then enrich the context with additional sources over time.

The situation is different in environments that have to remain disconnected from the internet. Military organizations, government ministries, and other highly critical environments may need an air-gapped setup. The infrastructure used for detection and response must also operate locally and offline. That can take longer because organizations need to buy and install the required equipment. The exposure may be lower in a disconnected environment, so there can be more time to prepare. For organizations connected to the internet, the need is more immediate.

We’ve moved from broad claims about AI to documented attacks that are already using these capabilities. This is happening now, so organizations don’t have unlimited time to think about it.

Cybersecurity behaves like a fire

Megan: The time required to prepare the right context seems more important than the time required to adopt AI itself.

Cyril: That’s right. We also work with partners who help customers build that context. Around 70% of our customers come through a partner that delivers the service.

Whatever industry you’re in, your operations depend on the internet. When that connection fails, recovery can take a long time and the impact shows up in the business.

More mature organizations understand that a compromise is like a fire. It isn’t always a fire in one place. It can be fire everywhere at once. Extinguishing it is difficult, and the recovery can take three weeks to two months. The people doing that work become the IT fire service. They don’t want to go through the same experience again.

These organizations aren’t looking for technical detail alone. They want a service that can detect and respond within minutes, sometimes seconds. The fastest you extinguish a fire, the less impact it has. The same principle applies to cyber operations.

A strong service partner manages the context, the AI, and the data sources. They know how to do the work and commit to the result. Your problem becomes their problem. This is a services issue as much as a technology issue. It’s people working with people.

How to evaluate AI claims

Megan: Many cybersecurity companies are making big claims about AI. What separates a durable AI security business from a solution that is only attracting attention?

Cyril: Start by asking how many customers the company has. We improve through data. If we have more data, we can improve the system.

Then ask about the roadmap. AI can support more detection, investigation, response, reporting, compliance, and automation over time. You need to understand where the product is going.

AI also creates a lot of hype. Some companies treat it as a way to increase their valuation, so you need to separate genuine capability from a marketing story. You shouldn’t assume that AI can replace people and put all your trust in the system. That creates a false sense of security and can become a threat in itself. Look at the customer base and how the system is being used. Token usage can give you an indication of activity, and you should also ask which use cases the agents already support.

Then test the system. Set up a lab environment, run controlled attacks, and see whether the AI can detect them. Also look at how the system communicates its results. Can your team understand the output? Is the interface usable? Does the information help analysts respond?

Without a human in the loop, it’s machine to machine. People are what make the difference.

Runbooks make AI accountable

Megan: How do runbooks support that human role?

Cyril: A runbook defines what happens when an alert arrives. A SOC analyst follows a series of actions. They verify information, check the context, and contact the right person or team.

Sekoia provides runbooks for different types of alerts. Analysts can adapt them to their own environment, regulations, and operating model. They may need to add more detail or change the response based on the organization’s context.

That is the human in the loop. Once the runbook is defined, AI can execute it. This is how teams save time while keeping control over the response.

Runbooks also make AI more transparent. People often describe AI as a black box because they can’t see what the agents are doing behind the scenes. A runbook gives the team a clear view of the actions the system will take, and it can be changed when needed. The runbook becomes part of the organization’s knowledge. It is shaped by people and reflects their decisions. AI executes it, but people define it.

A screenshot of a runbook in the sekoia dashboard, complete with full detection rationale, and a list of potential false positives.
Runbook in Sekoia

AI will become cheaper, and attacks will scale

Megan: As agentic operations become more capable, are there services customers will stop paying for?

Cyril: Prices will go down because AI costs will go down. As long as organizations are connected to the internet, they will need security services, and those services will have to become accessible to more people.

AI will become more widely available. That can help defenders, but it also means the technology can be used for harmful purposes. At some point, organizations with the same level of capability as the threat actors targeting them will be better positioned to defend themselves.

That could become a tipping point. People who currently resist AI may decide that it is here and they need to make the best use of it.

We already see that AI agents can run many operations in parallel. The cost and the difficulty of controlling those operations are still issues, but the capability is growing. Some of the use cases will be harmful, and those incidents will happen more often.

Now that we're in "Super intelligence" territory, we can’t respond effectively if we don’t have equivalent defensive capabilities. When choosing an AI solution, the question is not only which use cases it supports. You also need to ask what the system knows and what context it can use.

Because if you don’t own the context, the use case won’t work as expected.

Cybersecurity is entering a new game

Megan: How do you see the industry changing from here?

Cyril: I don’t think we know the limits of AI yet. Cybersecurity is one of the industries that will be heavily disrupted because it is built on data. AI works with data, and cybersecurity works with data.

Everything we know about the cybersecurity market today could look very different in two years. AI is changing how companies operate and making it easier to scale both attacks and defense. It’s a completely new game, and we have to stay agile.

Humility is a security skill

Megan: If we look back in two years, what might the industry realize it misunderstood today?

Cyril: Even if I’m French, it would be arrogant to claim that I know what will happen! Cybersecurity has taught me that I don’t know everything.

When you get compromised, it’s usually because there was something you didn’t know. That can happen to anyone. You should never laugh at another organization because it has been attacked. It could happen to you tomorrow.

The right response is to understand what happened and learn from it. The aviation industry works in a similar way. If an Airbus crashes, Boeing will study it because it wants to prevent the same thing from happening to its own aircraft. The industry learns through shared evidence, including the information recorded by aircraft black boxes.

The mindset matters. I’ve worked in cybersecurity since before the internet was widely available, and I’ve seen many changes. The lesson is that anything can happen, so you have to stay ready. There is no certainty. That is a human mindset we need to keep if we want to stay in the game.

"The lesson is that anything can happen, so you have to stay ready." Quote from the interview, with "Intelligence Asymmetry" podcast logo.
A quote from Cyril.

Experience must teach the machine

Megan: How will AI affect people entering the industry?

Cyril: Experience helps people get more from AI. Experienced professionals know how to assess the output and recognize what is useful. Their experience can also help the AI improve.

That creates an opportunity for people who have spent many years in the same field. They can bring their knowledge into the system and help educate it.

But there is also a risk. People leaving school today may find it harder to get internships or entry-level experience if AI is doing the work that used to form the beginning of their careers. A calculator is a useful comparison. If you use one every time, you may struggle to calculate without it. The reason people can still calculate in their heads is that they learned the basics before they started relying on the device. We need to think about how people will build those foundations in cybersecurity.

AI could also become a mentor for SOC analysts. It can adapt to the person asking the questions and explain the same subject in different ways. A junior analyst could use it to understand the reasoning behind an investigation and learn from the process.

Runbooks can support that learning too, but someone with experience still needs to build them. They need to know what the response should achieve before they can define the process.

That's why we need training programs that help people develop enough knowledge to remain in control of the loop.

AI changes the economics of the SOC

Megan: How should companies decide whether the cost of AI is worth the investment?

Cyril: Today, many organizations calculate the cost of security through the number of people required to handle the work. AI can reduce the number of people needed to process the same volume because it handles recurring tasks and sends analysts more refined data.

But the story doesn’t end with reducing headcount. The history of automatic teller machines shows what can happen when technology takes over a repetitive task.

People thought ATMs would mean fewer bank employees because customers would use machines instead of going into a branch. In practice, banks created more services. Employees spent less time handing out cash and more time helping with loans and other products. The bank increased the value of its people because the machines handled the routine work.

AI can have the same effect in cybersecurity. AI consumption may grow exponentially while hiring grows more slowly. The people who understand that shift early can move into work that creates new services and new value.

Imagine a SOC managing 20,000 devices with a team of seven to nine people around the clock. If AI reduces the team needed for routine monitoring, the remaining people can build services, support customers, or create new revenue.

One of our partners manages around one million endpoints with an internal platform maintained by 26 people. The partner recognized that moving the platform to Sekoia could free those 26 people to build the next services the company wants to sell.

That's the opportunity. AI can lower the cost of creating new capabilities, but people still need to decide what to build and why.

The human creates the difference

Cybersecurity has always involved decisions and trade-offs. Organizations have limited resources and have to choose where to invest.

AI can make it possible to build more protection at a lower cost. It can create room for new services and new ideas that teams couldn’t afford to explore before.

People still need to think differently and decide what matters in their own market. AI can support that work, but it can’t replace the human perspective behind it.

There is a lot of fear around AI. The people using it every day are often moving faster because it helps them handle tasks that used to be difficult or time-consuming. When the technology solves a real problem, people see the value quickly.

The next tipping point will come soon. The industry is still discovering what these systems can do, and the geopolitical situation will accelerate some of those changes.

Conclusion

AI will reshape cybersecurity. It will change the speed of attacks, the work of the SOC, and the way companies build security services. The organizations that benefit most will prepare their data and give their teams the right context. They’ll also keep people responsible for the decisions that matter. Through it all, teams must stay curious and stay humble. And above all, be ready to learn from what whatever happens next.

This transcript is part of Sekoia’s Intelligence Asymmetry podcast, where cyber leaders, Sekoia’s experts, and partners share the thinking behind modern defense. Visit our YouTube channel to watch the full episode and explore the complete series.

Cyber Threat Intelligence

Actionable cyber threat intelligence for security teams that need to understand threats faster, focus on what matters, and operationalize intelligence across hunting, detection, and investigation.

Abstract circular icon with a central human figure surrounded by six connecting nodes.