Defensive AI · The real differentiator at OCIRIA
We use AI to defend, not to ship reports faster: to see what a human team misses and to act continuously, not just alert. With the person deciding and signing.
Defensive AI
AI is changing attack as much as defence. We use it on two levels: to see what a human team would miss —in the audit— and to act, not just alert, continuously —in the platform—. No magic promises: the model proposes, the person decides and signs.
It's the thread that runs through our three steps: it sees in the diagnosis (Step 1), recommends in the decision (Step 2) and acts in the platform (Step 3). The human line never disappears.
What we mean by defensive AI
For us, defensive AI is using artificial intelligence models to do three concrete security tasks better: detect weak signals a human team would overlook, correlate events across disparate sources in a reasonable time, and prioritise the response by what matters to your business, not by an automatic CVSS score.
It's not a product you buy in a box. It's a layer that plugs into the analysis process and is always supervised by a human owner. The model suggests; the person decides and signs.
Offensive AI vs defensive AI
The asymmetry is real. Attackers are already automating reconnaissance, phishing email drafting, malware variant generation and credential discovery with AI. The barrier to entry for attack drops every quarter.
Defence has a different advantage: context. The attacker knows in general what they're after; you know exactly which assets are critical, which usage is normal and which deviation matters. Well-used defensive AI amplifies that context —it doesn't replace it—.
What an attacker can automate with AI:
- Mass collection of public information about their targets.
- Generation of personalised social engineering messages.
- Testing payload variants to evade detection.
- Discovery of misconfigured infrastructure at scale.
What a defender can automate with AI:
- Correlation of events across identity, network and endpoint logs.
- Detection of anomalous access or exfiltration patterns.
- Generation of investigation hypotheses for the analyst.
- Executive incident summaries in plain language.
The underlying difference: the attacker wants volume; the defender wants precision.
How we apply it in each service
In vCISO. We turn the operational noise —alerts, tickets, logs— into a monthly dashboard your leadership committee reads in fifteen minutes. The AI prepares the draft; the owner validates and signs it.
In ISO/IEC 42001. We govern our own AI usage with the same standard we help you implement. We practise what we preach: every model we use has its system card, its risk assessment and its documented human oversight.
In OSINT Audit. AI speeds up collection and correlation: when a search returns ten thousand results, a well-aimed model leaves the two hundred that matter. The analysis and the conclusion are always signed by a human.
AI that acts, not just alerts · the platform
The usual tools warn you, but they don't put the fire out. When you turn on the platform, defensive AI goes from assisting the analysis to acting on the risks it already knows from your audit:
- Detects vulnerabilities and attacks in real time, tuned to your report and up to date with every new threat.
- Fixes autonomously: it contains and remediates instead of sending you a ticket to solve yourself.
- Verifies instantly that the fix works and that your operation is still intact.
Governed autonomy: kill-switch, human approval for anything sensitive and everything reversible. The machine does the repetitive work at machine speed; the person keeps the judgement and the final word. It's consistent with what we say right below: AI is a tool, never an unsupervised vendor.
What we do NOT do with AI
- We don't make security decisions with AI without human oversight.
- We don't write executive reports with AI without an engineer reviewing them line by line.
- We don't hand you AI-generated reports signed as if a human wrote them.
- We don't put your confidential data into public services without a data processing agreement.
AI is a tool, not a vendor.
A note on transparency
If one of our reports has sections produced with AI assistance, we flag it. If a free tool of ours uses AI to analyse what you send it, we tell you before you click "Analyse". It's the consistent thing to do under ISO/IEC 42001 and the EU AI Act.
Want to see a concrete case?
Ask us for a thirty-minute session. We'll show you a real —anonymised— dashboard and explain what the AI does, what the human does, and exactly where the line is.
When you want to see it in action: See plans and pricing · Talk to us