Machine-Speed Security for Commercial Teams: What Red Canary Gets Right
AI is changing the economics of cyberattacks faster than most commercial security teams can add people. The important shift is not that every attacker suddenly has a new playbook. It is that automation can help adversaries research, test, adapt, and repeat familiar techniques at machine speed.
Red Canary’s latest research offers a useful answer: defenders need machine-speed analysis, but they still need human accountability. That combination matters especially for commercial organizations, where a small team may be responsible for identities, endpoints, cloud services, SaaS applications, and the business decisions that connect them.
The threat changed shape and picked up speed
Red Canary’s 2026 Threat Detection Report analyzes more than 110,000 confirmed threats across over 4.5 million identities, endpoints, and cloud assets. Its most consequential finding for commercial teams is the continued rise of identity-based activity.
Identity is now a primary attack surface
According to Red Canary, identity threats increased 850 percent year over year and accounted for 53 percent of its confirmed threat volume in 2025. That reflects a business environment in which a valid account can unlock email, cloud consoles, SaaS applications, source repositories, and sensitive data without an attacker needing to “break into the network” in the traditional sense.
The operational problem is bigger than any single alert. Analysts must compare login history, device context, network origin, MFA changes, cloud activity, and threat intelligence, often across tools that were never designed to work as one investigation.
AI compresses the attacker’s work cycle
Red Canary’s analysis is refreshingly measured: AI is accelerating and automating attacks more than it is inventing wholly new attack methods. That is still a serious change. Faster research, more convincing social engineering, automated reconnaissance, and repeatable credential abuse can produce more plausible activity than a human-only team can investigate one event at a time.
The answer is not autonomous security
“Let the agent handle everything” is an appealing slogan and a poor operating model for high-consequence decisions. Red Canary’s own work emphasizes expert-supervised agents, predefined procedures, measurable quality, and a human making the final call.
In one documented identity-investigation workflow, Red Canary reports that agentic automation reduced a process that previously took roughly 25 to 40 minutes to just over three minutes. In supported cloud and identity workflows, it also reports a 60 percent reduction in mean time to notify without a decline in alert quality. Those are Red Canary-reported results, but the operating lesson is broadly useful: automate the repetitive evidence gathering, not accountability.

What machine speed should do
- Collect context: retrieve user, device, cloud, network, and historical activity without forcing an analyst to pivot between consoles.
- Enrich and correlate: compare the event with baselines, threat intelligence, known infrastructure, and related activity.
- Apply repeatable procedures: execute the same investigation steps consistently, even during alert spikes or overnight hours.
- Explain the evidence: present the relevant facts and reasoning so a person can validate the conclusion.
What humans must still own
- Approval for consequential containment and business-disrupting actions
- Judgment when identity, operational, legal, or customer context is incomplete
- Escalation, communication, and ownership across technical and business teams
- Continuous review of the procedures and guardrails agents are allowed to use

The commercial security complexity meter
The average commercial environment does not fail because every security tool is ineffective. It struggles because the number of relationships an analyst must evaluate grows faster than the team. The meter below is an illustrative operating model, not an industry benchmark. It shows why adding one more console rarely solves the underlying problem.

Simple: One signal
One endpoint alert or one suspicious login can usually be reviewed by a person. At this level, the team can keep up.
Strained: Connections multiply
The analyst must connect users, devices, cloud services, applications, and business context. Manual review becomes slower and less consistent.
Overwhelmed: The pace becomes machine-driven
Automated activity changes quickly and creates more investigative paths than people can follow one by one. Machine-speed analysis becomes essential, with people setting limits and validating high-impact actions.
Where Zscaler and Red Canary fit
Zscaler completed its acquisition of Red Canary in August 2025 with a stated goal of combining exposure management, threat intelligence, automation, and agentic AI-driven threat management. That direction matters because commercial teams need a connected operating loop, not separate programs for prevention, exposure, detection, and response.
Prevent and control
The Zscaler Zero Trust Exchange reduces unnecessary exposure by enforcing policy between users, workloads, devices, and applications rather than extending implicit network trust.
See and prioritize
Zscaler Security Operations brings proactive and reactive risk work together. Asset Exposure Management and Unified Vulnerability Management combine asset context, policies, and remediation workflows; Risk360 provides real-time risk metrics across major stages of an attack. The goal is to direct attention to business-relevant exposure instead of treating every finding as equally urgent.
Detect and respond
Red Canary contributes the managed detection, investigation, threat intelligence, and expert-supervised automation needed to turn signals into decisions. Zscaler Deception can also create high-confidence signals and initiate automated response actions when adversaries interact with lures and decoys.
The integration roadmap belongs to Zscaler and Red Canary. The strategic value, however, is already clear: richer security context becomes more useful when it can drive a faster, repeatable, human-verified investigation.
A practical operating model for commercial teams
1. Consolidate the evidence before automating decisions
Start by identifying which identity, endpoint, cloud, SaaS, and exposure sources are required for a complete investigation. Automation built on partial context only reaches the wrong conclusion faster.
2. Define the investigation procedure
Document the questions a strong analyst asks, the sources used to answer them, and the conditions that change severity. This creates the guardrails an agent can execute consistently.
3. Automate low-regret work first
Prioritize collection, enrichment, correlation, summarization, and recommendation. Keep destructive or business-disrupting actions behind explicit approval until reliability is demonstrated.
4. Measure outcomes, not AI activity
Track investigation time, time to notify, accuracy, completeness, containment time, and analyst workload. “Number of agent runs” is not a security outcome.
5. Improve the system after every decision
Use analyst feedback, incident reviews, false positives, and missed context to improve procedures and data quality. Superhuman performance comes from compounding small, verified improvements across the operating system.
What commercial leaders should ask next
- Can we correlate identity, endpoint, cloud, SaaS, and exposure data in one investigation?
- Which investigation steps are repetitive enough to automate safely?
- Which actions always require a human decision?
- Can we prove that automation improves time and quality at the same time?
- Who owns 24x7 visibility, escalation, and follow-through when our internal team is unavailable?
Move toward superhuman analysis responsibly
Commercial security teams do not need to imitate the headcount of a global enterprise SOC. They need an operating model that makes every analyst faster, gives every decision better context, and keeps humans accountable for the actions that matter.
SecureDynamics can help commercial organizations strengthen their Zscaler foundation through authorized design and deployment, education, health and adoption reviews, and co-managed ZIA, ZPA, and ZDX operations. Where a requirement involves Red Canary MDR, we can help frame the use case and connect it to the appropriate Zscaler and Red Canary team without making unsupported operational commitments.
Talk with SecureDynamics about your security-operations roadmap →
Primary sources
- Red Canary: 2026 Threat Detection Report overview
- Red Canary: Identity attacks
- Red Canary: Incorporating AI agents into SOC workflows
- Red Canary: A masterclass in AI security operations
- Zscaler: Completion of the Red Canary acquisition
- Zscaler: What is Zscaler Security Operations?
- Zscaler: What is Risk360?