
The Era of 'Security Needs Human Judgment' Is Over
Contents
Security work is still, to a surprising degree, done by hand.
When an alert fires at two in the morning, deciding whether it's a real breach or just noise comes down to a person reading the logs line by line. When a new vulnerability is published, a person has to work out whether it actually affects this particular setup, and whether applying the patch will break something else. Earning an ISO 27001 (ISMS) certification, and keeping it, means a person writing the policies, preparing the statement of applicability, and filling in the risk-assessment tables, year after year.
For more than twenty years, I watched this mountain of manual work pile up, from the front lines and from the business side both.
Like most people in this industry, I believed this for a long time: "Only a human can do this. Judgment needs context, and in the end a person has to be accountable. You can't hand it to a system." This past year, that belief changed.
What changed is not the judgment, but everything before it
What changed is not the part where a human decides. It's the work people kept carrying in front of that decision, justified by the words "security needs human judgment."
Whether to file a breach notification, whether an incident is material, whose name signs off an internal audit: in Japan and in the US alike, it comes down to a person putting their name on it, and that does not move to a machine. In ISMS terms, you can borrow a hand to write the policies and the statement of applicability, but you cannot borrow the independence of the internal audit or the approval of the board.
Everything upstream of that, though, no longer has to be done by people.
I want to let go of "only a human can do this"
As a specialist, this is a little frightening to say out loud. What I'm describing is wanting a future where the skill I spent more than twenty years building is no longer needed. And that is the future I've come to want.
Much of the work people are killing themselves over today, first-line incident triage, checking whether a vulnerability actually applies to your setup, drafting ISMS documents, is work humans shouldn't have to do. Many specialists draw a line and insist their own domain is the one AI can't touch. I want to do the opposite and erase that line myself.
That is what's best for the people on the ground. The endless alert handling, the never-ending document upkeep: if a human doesn't have to carry it, all the better.
Over the past year, this stopped being a fantasy. Anthropic's Mythos has surfaced thousands of zero-days across every major operating system and browser, among them a remote code execution flaw in FreeBSD that had sat there unnoticed for seventeen years (CVE-2026-4747) and a twenty-seven-year-old bug in OpenBSD. Things that survived decades of human review are now coming out, which says less about the count than about how deep the reach now goes.
The more the big vendors consolidate, the fewer options a company without a security team has
I've also looked at security as a business, which is why I can see the other reality too.
The industry has been consolidating for several years now. Google acquired Wiz, Palo Alto Networks acquired CyberArk, and the large vendors are bundling network, cloud, identity and endpoint into a single platform. On the buying side, the large enterprises with the budget for it are pushing the same way, cutting down from dozens of tools so that one vendor carries the accountability.
For a company that can staff a security team, that works well. For a company that cannot, what's left is a choice between buying a heavy product carrying dozens of features and doing nothing at all. Neither the price nor the operational headcount is within reach.
AI keeps eating away at the livelihood of existing security solutions. What you sold yesterday with people and specialized tooling starts getting replaced by a general-purpose AI today. In a world repainted every few months, spending years stacking up a large product doesn't pay off, at least not for me.
So: build small
The path I chose was not to build a big product as a company. I chose the opposite: a small SaaS leaning on AI.
An AI-native build pushes the development cost down about as far as it can go. I'm not selling complexity, so you don't need a specialist to use it. And if the job is handing security's manual work to AI, the person who spent twenty years closest to that work is probably the fastest one to do it. That's me.
The volume of work has not gone down. What a dedicated team at a large enterprise used to absorb is now asked of companies that have no such team: taking inventory of which domains and servers are exposed to the outside, working out whether a published vulnerability actually bites on this particular setup, and producing evidence of continuous monitoring for the security questionnaires that keep arriving from customers. All of it sits in front of the decision, and none of it ever ends.
About this site
On this site, I'll put out the results, as they are, of trying to see how much of security's manual work AI can take over.
What I'm building now is a micro-SaaS called PentaTrail: a CTEM service that uses AI to continuously keep track of your company's externally visible attack surface.
Sources
- The Hacker News: Anthropic's Claude Mythos Finds Thousands of Zero-Day Flaws Across Major Systems (2026-04)
- SentinelOne: CVE-2026-4747 — FreeBSD RPCSEC_GSS RCE
- TechCrunch: Anthropic scales Claude Mythos to critical infrastructure in 15+ countries (2026-06-02)
- FE International: Cybersecurity M&A 2026 — Trends, Deals & Valuations
Visualize your attack surface with PentaTrail CTEM/ASM
From discovery to vulnerability validation and remediation — all powered by the CTEM framework.
Get Started


