The Human in the Loop Is Not Optional
Attackers have AI. Defenders need AI. But that doesn’t mean the SOC can run itself. Lisa Liu, Corporate Marketing and Communications Manager at Stellar Cyber, joins Alan Shimel on Techstrong TV to make the case that the human in the loop is not optional — and that treating analysts as a brake pedal misses the point entirely. Lisa walks Alan through Stellar Cyber’s decade-long AI-first approach as a security operations platform purpose-built for MSSPs and lean enterprise teams, and uses an autonomous-driving analogy to explain why fully autonomous SOCs are still a bad idea: when AI makes a mistake, you need a human who knows how to drive to steer to safety. She and Alan dig into how AI and analysts work symbiotically, why no governing logic in cybersecurity lasts more than a couple of months right now, and why adaptability — not playbooks — is the new strategic advantage.
Transcript
Hi, everyone. Welcome back here to Techstrong TV. My next guest is Lisa Liu, and Lisa is with Stellar Cyber, and we're going to welcome her here to Techstrong.
Hey, Lisa. Welcome. It's good to see you.
Thank you for having me. Really excited to be here today. It's a pleasure.
Our pleasure. So, Lisa, let's start with you. You are an AI thought leader, okay?
And you work at Stellar. Let's hear a little bit of your journey and how you came to be here at Stellar and involved in the AI world. Absolutely.
So, as you mentioned, I am the thought leader here at Stellar Cyber, so I manage a lot of our communications and our public relations and things like that. And it's more important than ever to be telling our AI story, especially because everyone in the industry is saying AI, everyone in every industry is saying AI. But AI has been such a core part of our mission since we were founded over 10 years ago, so crafting the narrative around our own journey forward into the industry is extremely important today.
Yep. And let's hear a little bit about Lisa's story, though, before Stellar. How long have you been at Stellar?
What'd you do before that? I've been at Stellar now for a little over two years. I've been in marketing and communications for a couple years before that, and before that, I was in graduate school.
Got it. Yeah. Very cool.
So, it's interesting. There are some industries that have been more affected by AI than other places. I always tell people, look, two of the industries that have really been at sort of the tip of the spear, number one, coding.
96% of developers are now using AI tools to help them code. Mm-hmm. Number two, marketing.
Marketing is an area where AI naturally lends itself to really helping. Not necessarily eliminating jobs, the same way I don't think it's eliminating coding jobs, but enhancing what individuals can do. So, AI thought leader, right?
You couldn't be an AI thought leader without probably leveraging AI to help you with that. So, for a moment, let's talk personal with you. How are you using AI as an AI thought leader, as someone heading marketing and stuff like this?
How's it helping you? How is it making you 3x or a better you, if you will? That's a really insightful question.
I think actually the way I leverage AI has been very similar to the way it's leveraged in the cybersecurity industry, which is to say that everyone has access to it, so the way that you develop nuance and the way you deploy those tools becomes the main differentiator. When everyone has this kind of widely available tool, just this magnitude is not enough to differentiate yourself. It's not enough to put yourself ahead.
And it rather becomes a question of how you use it as a step up, so how you use it to ingest a ton of data. And I think cybersecurity is an industry that is so voluminous in terms of the messaging that you're seeing, that using AI to parse a lot of that messaging has been really helpful for me personally. But how I later take those conclusions to craft the narrative on top of that, that's the work that I have to do, and that's what I believe is the differentiator between me as a human versus the content that AI gives me.
So, it's kind of like a symbiotic process where it would take me hours to read everything that's out there and to be able to parse through just every bit of messaging that's being put out because they're being put out in large part by AI tools. But how I use that and how I process that to craft my own conclusions, that's up to me. Excellent.
If you don't mind, I want to spend a few moments on Stellar Cyber. Absolutely. Look, there are people in our audience who don't know about Stellar.
I think you mentioned off the bat that it's been around for, was it 10 years or something you said? Over 10 years, yep. Yep.
Tell people a little bit about the Stellar story. I would love to. So, we are a security operations platform, and we're the only one purpose-built for MSSPs and leaner enterprise teams.
So our logic has been from the very beginning, before everyone was saying AI, to use AI to be able to process an immense amount of data in order to help leaner teams be able to respond to attacks accordingly without overburdening their analysts. So anyone who works in cybersecurity knows that there are a few core problems that have persisted for years, and this doesn't change no matter what technologies are developed. And part of that is being exacerbated in large part by the fact that attackers now have AI tools as well.
So the alert volumes that we're seeing are only increasing, which means that things like alert fatigue and analyst burnout are only becoming more and more important and necessary to address. So our logic of consolidating security tools to streamline your ability to respond to alerts efficiently and accurately has only been validated by further market developments. Yeah.
People who want to reach out or maybe dig in a little deeper into Stellar and exactly how it does that, where should they go, Lisa? Well, I run our company LinkedIn page, so I would absolutely encourage them to visit us on LinkedIn to see some of our thought leadership, to listen to some of our podcasts. We've got some great content about shows that we're attending, how you can see demos in your area.
" Cool. All right. If you don't mind, I want to pivot a little bit and talk about our topic of discussion today, which is human-in-the-loop agentic AI in security operations.
And, whether we're talking about a SOC, a security operations center, or the broader, just the business of doing security, of doing cyber. I think there's a growing realization that, hey, you need AI to fight AI, right? Absolutely.
The bad guys are using AI. We need that sort of scale. We need AI scale to defend.
Mm-hmm. But I think the other realization is we're not at the point, and I don't know if we will be anytime really soon, where we could just put this on autopilot, and we can go have cake all day or something. You need the human in the loop.
So what's a poor security team to do, right? How do we rectify or how do we have it both? That's a really great question.
I think that's what everyone in the industry is trying to find, that exact balance between the human and the autonomous. And as you said, we can't escape the fact that everyone is using AI tools, hackers above all, and human response time simply isn't enough to combat that anymore. And you're just dealing with so many alerts that if you were to address every single one of them manually, that's an impossible task, and you're setting yourself up for failure.
On the other hand, like you said, full autonomous SOC is an idea that we've had for a couple of years now, and we've been able to address potentially the shortcomings. And I think the conclusion is that that is not a viable solution. We'll always need human analysts to be able to supervise and to be able to train the AI models that are working with and for them.
And an example I really like to draw on personally is autonomous driving. So we've had the technology to have driverless cars for a while now, but there's a reason that all of those cars still come with a driver's seat. Because when blackouts happen, when short circuits happen, you do still need a situation where you have a human driver who knows how to drive and is able to step in and steer them to safety.
If you're caught in a disaster where AI makes a mistake, that mistake has the potential to compound into something completely disastrous. So if you don't have oversight, if you don't have guardrails, that could be the end of your business. That could be a huge calamity.
So human mistakes happen, of course, but when you have the efficiency of AI tools, a mistake could be absolutely limitless in its repercussions. So I think the idea of AI tools being, like I said earlier, symbiotic with the human element is the future of AI and cybersecurity, where the human is able to learn from the way AI tools make decisions, so that you have junior analysts performing at the level of senior analysts. And the human decision-making also, in turn, informing AI so that it works better, it works faster, it works smarter.
This is the key difference. This is how we stay ahead. And like you said, everyone has AI now, and what we need to realize is your greatest asset is still your human analyst.
You need to invest in your team. That's the differentiator, right? Absolutely, it's necessary to be powered and have that machine-level response and to be able to respond quickly to things, but the human will always be in the loop.
And I want to emphasize, though, Lisa, a lot of people think of human in the loop as a brake pedal. It's not necessarily a brake pedal. Yes, the human in the loop can press the brake, slow down, stop, do over, whatever.
But when we say human in the loop, it's not necessarily synonymous with a brake pedal. It could really be an accelerator. It could make the AI even go faster because there's a human there saying, "Yeah, good, go.
Move. " I think too many people think of it as sort of a... Security itself.
You used to talk to a lot of IT people, and security was like an anchor chain tied to IT, slowing it down. We shouldn't have that same mental image of the human in the loop of agentic AI security operations. We're not here to slow it down.
We're just here to make sure that nothing really, really bad happens while we're going as fast as we can. Of course. And if you think about the way you use any other tool, for example, a hammer or any other construction tool, when you use that tool, you're not actively thinking about how to limit yourself with that tool.
Instead, the more you use it, the more you learn to use it, the faster you start to use it, and the more natural it starts to feel, the more integrated into your workflow it becomes. And that's the same kind of logic with AI. You're not acting as an impediment to the way the tool runs.
Instead, the tool makes you smarter, makes you better at recognizing patterns, and respond to things faster. So it's a great way to train the human element as well. I love it.
Lisa, we're almost out of our 15 minutes here. I don't know, did we mention the website for Stellar Cyber? ai.
ai. Mm-hmm. Very cool.
Lisa, there's been a lot this week in the news, or actually last week, because it's only Tuesday when we recorded this, but around the government forced Anthropic to pull their model from Mythos and Fable and so forth. At some point, rubber meets the road in the real world. So when Stellar is talking to your clients, helping clients, right, with their security operations, what impact is Mythos and stuff having on real-world security, real-world clients as far as you can see there?
Actually, I would love to direct listeners to a great article written by our senior VP of product on how Mythos is changing the game in cybersecurity as well. But it basically confirms the fact that there's no governing logic that can last in cybersecurity for more than a couple of months. And as AI tools develop, that timeframe becomes shorter and shorter, right?
So as soon as you develop tools, other people, bad actors, are developing them as well. And as soon as you think you've adapted to a playbook, that playbook changes. So the ability to be flexible and to have a solution that you can pivot with and that you can redeploy according to the way a landscape changes, that becomes all the more important.
So sticking to traditional methods of security and having the same tools that you've had forever and assuming that that attack surface will never change is simply just not a viable way to go forward. So that kind of flexibility is what we really encourage our customers to consider when they're thinking about rearranging their tool portfolio, when they're considering the advantages of a platform approach, when they're wondering if they need the added advantages of auto triage, things like that. So, the adaptability is the really essential quality that we keep seeing reinforced by market changes.
Love it. Hey, Lisa, thanks for coming here on Techstrong TV today. We appreciate it.
Keep doing what you're doing at Stellar Cyber because you're on the front lines there, and the world, as you said, doing the same old, same old isn't going to work anymore. Thank you so much for having me. All righty.
Hey, Lisa Liu, AI thought leader, corporate marketing manager at Stellar Cyber on Techstrong TV. We're going to take a break. We'll be back.