AI is changing the economics of cyberattacks faster than most commercial security teams can add people. The important shift is not that every attacker suddenly has a new playbook. It is that automation can help adversaries research, test, adapt, and repeat familiar techniques at machine speed.
Red Canary’s latest research offers a useful answer: defenders need machine-speed analysis, but they still need human accountability. That combination matters especially for commercial organizations, where a small team may be responsible for identities, endpoints, cloud services, SaaS applications, and the business decisions that connect them.
Red Canary’s 2026 Threat Detection Report analyzes more than 110,000 confirmed threats across over 4.5 million identities, endpoints, and cloud assets. Its most consequential finding for commercial teams is the continued rise of identity-based activity.
According to Red Canary, identity threats increased 850 percent year over year and accounted for 53 percent of its confirmed threat volume in 2025. That reflects a business environment in which a valid account can unlock email, cloud consoles, SaaS applications, source repositories, and sensitive data without an attacker needing to “break into the network” in the traditional sense.
The operational problem is bigger than any single alert. Analysts must compare login history, device context, network origin, MFA changes, cloud activity, and threat intelligence, often across tools that were never designed to work as one investigation.
Red Canary’s analysis is refreshingly measured: AI is accelerating and automating attacks more than it is inventing wholly new attack methods. That is still a serious change. Faster research, more convincing social engineering, automated reconnaissance, and repeatable credential abuse can produce more plausible activity than a human-only team can investigate one event at a time.
“Let the agent handle everything” is an appealing slogan and a poor operating model for high-consequence decisions. Red Canary’s own work emphasizes expert-supervised agents, predefined procedures, measurable quality, and a human making the final call.
In one documented identity-investigation workflow, Red Canary reports that agentic automation reduced a process that previously took roughly 25 to 40 minutes to just over three minutes. In supported cloud and identity workflows, it also reports a 60 percent reduction in mean time to notify without a decline in alert quality. Those are Red Canary-reported results, but the operating lesson is broadly useful: automate the repetitive evidence gathering, not accountability.
The average commercial environment does not fail because every security tool is ineffective. It struggles because the number of relationships an analyst must evaluate grows faster than the team. The meter below is an illustrative operating model, not an industry benchmark. It shows why adding one more console rarely solves the underlying problem.
One endpoint alert or one suspicious login can usually be reviewed by a person. At this level, the team can keep up.
The analyst must connect users, devices, cloud services, applications, and business context. Manual review becomes slower and less consistent.
Automated activity changes quickly and creates more investigative paths than people can follow one by one. Machine-speed analysis becomes essential, with people setting limits and validating high-impact actions.
Zscaler completed its acquisition of Red Canary in August 2025 with a stated goal of combining exposure management, threat intelligence, automation, and agentic AI-driven threat management. That direction matters because commercial teams need a connected operating loop, not separate programs for prevention, exposure, detection, and response.
The Zscaler Zero Trust Exchange reduces unnecessary exposure by enforcing policy between users, workloads, devices, and applications rather than extending implicit network trust.
Zscaler Security Operations brings proactive and reactive risk work together. Asset Exposure Management and Unified Vulnerability Management combine asset context, policies, and remediation workflows; Risk360 provides real-time risk metrics across major stages of an attack. The goal is to direct attention to business-relevant exposure instead of treating every finding as equally urgent.
Red Canary contributes the managed detection, investigation, threat intelligence, and expert-supervised automation needed to turn signals into decisions. Zscaler Deception can also create high-confidence signals and initiate automated response actions when adversaries interact with lures and decoys.
The integration roadmap belongs to Zscaler and Red Canary. The strategic value, however, is already clear: richer security context becomes more useful when it can drive a faster, repeatable, human-verified investigation.
Start by identifying which identity, endpoint, cloud, SaaS, and exposure sources are required for a complete investigation. Automation built on partial context only reaches the wrong conclusion faster.
Document the questions a strong analyst asks, the sources used to answer them, and the conditions that change severity. This creates the guardrails an agent can execute consistently.
Prioritize collection, enrichment, correlation, summarization, and recommendation. Keep destructive or business-disrupting actions behind explicit approval until reliability is demonstrated.
Track investigation time, time to notify, accuracy, completeness, containment time, and analyst workload. “Number of agent runs” is not a security outcome.
Use analyst feedback, incident reviews, false positives, and missed context to improve procedures and data quality. Superhuman performance comes from compounding small, verified improvements across the operating system.
Commercial security teams do not need to imitate the headcount of a global enterprise SOC. They need an operating model that makes every analyst faster, gives every decision better context, and keeps humans accountable for the actions that matter.
SecureDynamics can help commercial organizations strengthen their Zscaler foundation through authorized design and deployment, education, health and adoption reviews, and co-managed ZIA, ZPA, and ZDX operations. Where a requirement involves Red Canary MDR, we can help frame the use case and connect it to the appropriate Zscaler and Red Canary team without making unsupported operational commitments.
Talk with SecureDynamics about your security-operations roadmap →