Some of the worst breaches don't start with a critical alert. They start with a low or informational one that nobody had time to open, and that's happening right now. Attackers are adopting near frontier-grade, open-weight AI trained on tool telemetry, letting them sit deliberately below the threshold where a human ever looks. That's only going to get more common.
Perry Schumacher, Chief Strategy Officer at Ridge IT Cyber and architect of its KAIROS platform, argues you can't out-hire this problem, and you can't fix it by handing an AI the keys either.
Instead, Perry lays out a different design for the AI-assisted SOC: investigate every alert, but let the AI touch nothing. That means two models that must independently reach the same verdict, code (not another model) that verifies every cited log actually exists, and automation that only acts inside limits the customer sets.
He'll also make the case for collective defense across the whole stack, not one vendor's wall: the shape of an attack crosses between organizations, but the telemetry never does.
This segment is sponsored by Ridge IT Cyber. Visit https://securityweekly.com/ridgeisw to learn more about them!
- 0:00 - Introduction to Ridge IT and Kairos 0:54 Building an AI-Powered SOC
- 01:48 - AI-Assisted Software Development
- 03:30 - Alert Fatigue and Missed Threats
- 04:26 - Why AI Makes Attacks Stealthier
- 06:07 - Preventing AI Hallucinations
- 07:01 - Using Code to Validate AI Decisions
- 09:20 - Integrating With Existing Security Tools
- 09:59 - Kairos as a Security Data Overlay
- 11:00 - Why SOC Teams Need More Investigations
- 12:57 - What Happens After an AI Verdict?
- 13:33 - Human Oversight and AI Guardrails
- 14:57 - Automating Security Response Safely
- 15:44 - Closing Remarks and Ridge IT
Perry Schumacher serves as the Chief Strategy Officer at Ridge IT Cyber, where he leverages over 20 years of international experience in IT and cybersecurity. A seasoned manager and executive, Perry has implemented business process improvement projects across multiple continents and industries, including Utility, Aerospace, Defense, Facility Management, and Rail. At Ridge IT Cyber, Perry directs strategic initiatives to enhance cyber resilience, leading the company’s vision for innovative security solutions and managed IT services.
InfoSec World is introducing a fresh experience for 2026, with new voices, a new venue, and new topics reflecting the challenges security teams are facing now. Join practitioners and leading professionals from across industries in Orlando, October 12–14. Listeners save 30% on their pass with code ISW26-SWSAVINGS at securityweekly.com/infosecworld2026.