Walk, don’t run, but never stand still on AI transformation

0

By Tim Morris, Chief Security Advisor, Americas, Tanium

Recently, the Australian Government disclosed that an AI agent had accessed a Medicare statistics portal without authorisation. No personal information is believed to have been exposed, but the incident forced a question many leadershad been deferring onto the agenda: how do you adopt AI at the pace the business needs without losing control of it?

The natural instinct is to slow down. I understand that, but standing still carries its own risk. According to the ABS, around 35 per cent of large businesses, 22 per cent of medium businesses and 11 per cent of small and micro businesses were using AI in 2024–25. Yet when it comes to AI integrated across the business, many organisations are still puttingit in the too-hard basket because the change and investment look too big.

What often gets missed is that the current state is already hard. Technical debt gets plenty of attention. Process debt gets far less, and it may be the bigger problem. As environments have sprawled, routine tasks have grown more complicated, and many are stillmanual. Before deciding AI is too big a lift, leaders should look at the hard things they are already doing that it could remove.

Doing nothing is not the easy route

Every organisation gets comfortable with the familiar. Processes that have been in place for years feel simple because the team knows them, not because they are. People resist change, but in my experience most of these tasks aresimpler on the other side.

Take patching. Patching isn’t hard. The process is. Dashboards are a big part of that process, and for years they have given teams false confidence. Not because anyone is hiding anything, but because they report on data that is out of date by the time anyonereads it. The dashboard shows green while exposure is still sitting on the endpoint. Maybe the Configuration Management Database (CMDB) is incomplete. Maybe patching decisions are based on a scan that was stale before anyone acted on it. Or the tool reportsa patch as deployed but cannot confirm it worked until the next scan, which may not run for another week.

These dashboards are easy to operate, and they help IT operations and security teams feel like the job is done. In reality, working from outdated information makes everyone’s job harder over time, and in today’s threat landscape it does little to improve resilience.

Real-time visibility changes that. When you can see the actual state of every device, not what a scan reported last week, the gap between what the dashboard says and what is true closes. Automation, and increasingly AI, can then act on that data within definedguardrails. That gives organisations an accurate picture of their risk and a faster path to fixing it, and it makes the shift from reacting to threats to getting ahead of them far more achievable.

I saw this firsthand in a previous role, leading cyber engineering and research responsible for defending more than 500,000 endpoints. The hardest part wasn’t the technology. It was getting everyone, including leadership, to accept that we couldn’t have world-classincident response without real-time visibility. Once we had it, the returns were immediate in incident response, malware outbreaks, threat hunting and zero-day vulnerability management, and soon extended to patch reporting. From then on, real-time data didn’tjust help us handle each crisis efficiently. It showed us which processes were built on stale data, so we could fix them.

The emotional hype cycle

I think of AI adoption as moving through an emotional hype cycle. Excitement turned quickly to fear, and many organisations moved into prohibition while they worked through the uncertainty. The leaders who will come out ahead arethe ones who move through caution to implementation rather than waiting for certainty that never arrives.

As the excitement fades, it is worth remembering that AI is not the goal. It’s a tool for reaching a business objective, so start with the objective and work backwards. Transformation takes time, but no leader wants to be stuck at caution while competitorsreach transformation.

Machine-speed defence

Leaders are wading through a steady stream of vendors claiming to be the silver bullet for AI or resilience. There isn’t one. The better test is to ask about the data. What is the source? How fresh is it? Is it correct? And whatis the consequence of acting on it if it isn’t? AI and automation are only as good as the data underneath them. Those four questions are what separate a confident, evidence-based conversation with your board from a green dashboard.

The gap between machine-speed discovery and human-paced response is where risk lives. Attackers, and now AI agents, operate at machine speed. Defence has to as well, but the Medicare incident is a reminder that autonomy without control is its own risk. Thegoal is autonomy the organisation can see, verify and override.

In practice, that means a team can see the current state of every endpoint at any hour, act on the evidence with a plan, and report risk to the board without waiting for the next scan.

I spent years defending more than 500,000 endpoints. The hardest lesson was not about the technology. It was that you cannot defend what you cannot see, and you cannot see it if you are working from last week’s data. The Medicare incident is a reminder thatautonomy without visibility is not progress. Adopted deliberately, with real-time data underneath and people in control, AI does not just improve resilience. It makes the job actually doable at the scale modern environments demand.

Share.