Sanjiv Cherian argues that automation in the security operations centre is an amplifier, and that amplifiers are indiscriminate: they make a good team faster and a weak team wrong at scale.
The prevailing question about artificial intelligence in cybersecurity is whether it will replace human analysts. Sanjiv Cherian thinks that question is doing a lot of damage, mostly by distracting from a more uncomfortable one.
“Automation is an amplifier, and amplifiers do not have opinions. If your detection logic is sound, automation makes you dramatically faster. If your detection logic is noise, automation industrialises the noise. Every organisation deploying this technology is about to find out which of those two it was, and some of them are not going to enjoy the answer.”
Cherian is Co-Founder and Chief Commercial Officer of Microminder Cyber Security, working with enterprises and critical infrastructure operators across the United Arab Emirates, Saudi Arabia and the United Kingdom. He has built his commentary in this area around a specific idea: that value comes from the deliberate pairing of human judgement with machine capability, rather than from either in isolation. He describes the discipline of designing that pairing as the central skill of the next decade of enterprise security.
He is specific about where automation genuinely earns its place. Alert triage and enrichment, where the volume defeats human teams and the decisions are largely deterministic. Correlation across large, disparate telemetry sets. Log summarisation and case narrative generation, which compress the analyst’s slowest task. Detection engineering support, where a model can propose coverage against known adversary techniques far faster than an engineer working from scratch. Regression testing of existing detections against catalogued techniques such as those in MITRE ATT&CK.
He is equally specific about where it does not.
“Ambiguity is where it falls over, and ambiguity is most of the job. A privileged account behaving unusually at two in the morning is either an incident or a systems administrator doing a migration nobody logged. The difference is organisational context, and that context is not in your telemetry. It is in someone’s head.”
The second failure mode he raises is accountability, which he considers the most neglected question in the entire discussion.
“If an automated action isolates a production system and stops a manufacturing line, who owns that decision? In most organisations there is no answer, because the automation was deployed by the security team and the consequence lands on operations. That is not a technology gap. That is a governance gap, and it will surface in the worst possible circumstances.”
Cherian also draws a distinction he says is routinely collapsed: using AI to do security, and securing the AI that the business has already deployed. The second, he argues, is arriving faster than most security functions have planned for. Models are being connected to internal data stores, given tool access and permitted to take actions, frequently outside any established change control process. The associated risks, prompt injection, data leakage through model interfaces, over-permissioned integrations, and an expanding supply chain of third-party model providers, do not map cleanly onto existing control frameworks.
“Most security teams I speak to have an AI strategy for the SOC and no inventory of the AI already running in their business. That asymmetry is going to be expensive. The first question is not what model should we deploy. It is what has already been deployed, by whom, with access to what.”
On the adversarial side he is measured rather than alarmist. The observable near-term effect, he argues, is not novel attack capability but a collapse in the cost and effort of established techniques. Social engineering at scale, in fluent local languages, tailored to individual targets, has become inexpensive. Reconnaissance that once took days now takes minutes.
“The attack has not changed. The economics of the attack have changed. That matters more, because it means techniques that were previously reserved for high-value targets are now viable against everyone.”
His practical recommendation to executives is deliberately narrow. Do not begin with a platform decision. Begin by identifying the three tasks consuming the most analyst time that involve the least judgement, automate those, measure the recovered hours, and reinvest them in the work that requires context. Then, separately and urgently, inventory the AI already operating inside the business.
“The organisations that will get this right are not the ones buying the most capable technology. They are the ones that are honest about which decisions require a human, and disciplined enough to protect the time of the people making them.”
Sanjiv Cherian writes publicly on operational technology security and the enterprise use of artificial intelligence, publishing to an audience of more than 21,000 followers on LinkedIn and at sanjivcherian.com, where he sets out his work on the deliberate pairing of human judgement with machine capability. Sanjiv Cherian spoke on “Digital Transformation vs Cyber Threats in UAE Energy and Utilities” at the OT Security First MENA Event in Abu Dhabi in February, 2026 and has been twice quoted on the CISO Series Podcast for his thought leadership on Cyber security. The through-line is consistent across everything he publishes: technology sets the ceiling on what a security function can do, and people determine how much of that ceiling is ever reached.
AUTHOR BIO BLOCK: Sanjiv Cherian is a British cybersecurity executive based in Dubai, United Arab Emirates. He is Co-Founder and Chief Commercial Officer of Microminder Cyber Security, which delivers operational technology and industrial control systems security, managed security operations, penetration testing and cyber assurance services across the United Arab Emirates, Saudi Arabia and the United Kingdom. Born in Mumbai, he moved to the United Kingdom at twenty-one and spent two decades in London before relocating to Dubai in November 2024. He holds a Master of Business Administration from Liverpool John Moores University. He writes and speaks on operational technology security, critical national infrastructure protection, and the role of artificial intelligence in enterprise security. More at sanjivcherian.com






