thirdbrain.

What's possible with AI in IT operations and security

Evidence current to mid-2026.

In IT operations and security, AI is ready today for the repetitive, documentation-heavy work: ticket triage, vulnerability scan summaries, patch gap reports and security policy drafting, always with IT staff on the decisions. Alert triage and identity access reviews are promising pilots. Access revocation, incident judgement calls and any auto-remediation of live systems stay firmly with people.

Each task below sits in one of three bands: a strong fit today, worth a careful pilot, or keep with people for now.

A clear breakdown of where AI does and does not fit across the core tasks of an IT operations and security function. A practical starting point, not the last word. Evidence current to mid-2026.


Where AI is mature: strong fit today

Proven and available today. AI does the bulk of the work and the IT team reviews it.

FunctionThe job todayWith AI
Service desk ticket triage and routingStaff submit requests by email, Teams or phone; IT person reads, classifies and routes each one, with back-and-forth to clarify what the user actually needsAI classifies incoming tickets, suggests a priority and routes to the right queue; IT person handles escalations, edge cases and anything requiring judgement
Vulnerability scan report summarisationRun the scanner, read through hundreds of Common Vulnerabilities and Exposures (CVE) entries, work out which ones apply to the actual environment and write up the action itemsAI reads the scanner output and produces a prioritised summary of findings mapped to the real estate; the IT person confirms which apply and owns every remediation decision
Patch compliance gap reportingManually check patching status across devices and systems, build a list of what is patched and what is not, chase down the gapsAI monitors patching status and generates gap reports by device, OS and severity level; the IT person reviews and drives remediation
Security content and policy draftingWrite phishing simulation emails, security bulletins, acceptable use policies and awareness training content from scratchAI drafts from a brief; IT manager reviews against Essential Eight controls and the Information Security Manual (ISM) baseline, adapts to the business context and owns sign-off
Incident documentation and post-incident reportsPiece together what happened from memory, system logs and chat threads after an incident, then write up the timeline and findingsAI drafts the incident timeline from log summaries, alert data and notes; the IT person checks accuracy, fills in the context and owns the official record

Where AI is emerging: consider piloting with a human gate

Promising but not yet proven at this scale. AI assists and IT staff stay in the loop, so trial it on a contained scope first.

FunctionThe job todayWith AI
Security operations centre (SOC) alert triageAnalyst works through the alert queue in sequence; each alert needs context lookup, judgement and a disposition; alert volume means real threats get buried in noiseAI scores and prioritises alerts, suppresses known false positives and surfaces the most likely true positives; analyst investigates escalations and owns every containment call
Phishing email triageStaff report suspicious emails; analyst reviews each one manually, looks up URLs and senders and decides whether it is maliciousAI pre-scores and classifies each submission and flags high-confidence indicators; analyst confirms the verdict and handles edge cases. AI does not block autonomously
Vulnerability prioritisationTeam prioritises remediation by Common Vulnerability Scoring System (CVSS) severity score alone, making it hard to separate actually-exploitable findings from high-severity-but-never-attacked onesAI combines CVSS severity, Exploit Prediction Scoring System (EPSS) exploit-probability and Known Exploited Vulnerabilities data into a ranked shortlist; the IT person owns the remediation schedule
Identity and access reviewIT manager manually reviews access rights in batches from spreadsheets or the directory, working out who has what and whether it still makes senseAI surfaces anomalous permission patterns, overprivileged accounts and unused access that has accumulated over time; IT manager owns and executes all access changes
AI for IT operations (AIOps) event correlation and noise reductionOn-call engineer manages a flood of monitoring alerts during an incident, manually linking related events and trying to find the root cause in the noiseAI correlates and deduplicates events across monitoring sources, surfaces root-cause candidates and suppresses noise; engineer investigates and decides
Incident response playbook draftingSecurity lead writes incident response (IR) playbooks from scratch, working from Australian Cyber Security Centre (ACSC) or US National Institute of Standards and Technology (NIST) guidance and adapting to the specific environmentAI drafts the playbook from a brief and applicable frameworks; security lead validates the steps, adapts to the environment and owns the final document
Endpoint hardening scripts and cloud provisioningIT generalist writes scripts to apply hardening controls or configures cloud infrastructure manually in the consoleAI drafts scripts and configuration from a brief; the IT person reviews every line, tests in a non-production environment and owns deployment. Never apply untested AI-generated config to live systems

Where AI is not ready or suitable today: keep with people

These stay with people, either because the tooling is not reliable enough or because controls and compliance rule it out.

  • Access revocation decisions. AI may surface candidates for review. The IT team must own and execute every removal: access left live after a departure or role change is one of the most common precursors to data theft.
  • Incident response judgement calls. Containment scope, escalation path, breach notification timing and crisis communications under pressure. The IT manager or incident lead leads the response; AI supports with log summaries and draft comms at most.
  • Security-risk sign-off and ransom-payment decisions. The business owner or head of IT accepts a residual security risk, and decides whether to pay a ransom under extortion. AI can summarise the options and consequences but must not decide. A ransom payment also triggers a mandatory report under the Cyber Security Act 2024.
  • Auto-remediation of production systems. AI agents can reverse manual emergency patches not yet committed to the repository. The IT team approves every change to live systems. The human approval gate is the control.

Worth weighing: for any of these, the upfront work (connecting tooling, defining rules and response criteria, cleaning the asset inventory) is a one-off setup; the ongoing job on the strong-fit items is mostly reviewing AI output and handling escalations, not the original grind. That time goes back into the hardening, the judgement calls and the threats that actually matter.

One practical note on the threat side: AI is also the attacker’s tool. AI-written phishing emails and deepfake voice and video have made business email compromise (BEC) and executive-impersonation fraud cheaper and more convincing. That is not a reason to avoid AI tools; it is a reason the human gate on payments, access changes and unusual requests matters more, not less.

This guide sits on top of the things that stay the same whatever your function. See the ground rules

Questions

The questions leaders ask.

Will AI replace our IT staff or security analysts?

No. Tickets, scan summaries and reports still need IT staff to own the decisions, handle escalations and deal with anything requiring judgement. For a small IT team or a generalist IT person, AI takes the repetitive processing and gives back time for work only the IT team can do. The compliance-critical decisions, access revocation, incident containment and breach notification, stay with people.

Is it safe to use AI tools for security work?

With the right controls, yes. The main risk is not the AI output being wrong (though it can be); it is the data going in. Logs, scan reports and infrastructure details are sensitive configuration information. Use enterprise AI tools with Zero Data Retention and training off, not consumer tools. And never let AI block, remediate or revoke access without IT staff confirming the action first.

Where should we start if we have a small IT team?

Ticket triage is the most contained first step: it uses AI already built into common IT service management tools, the IT person still handles escalations, and the time saving is measurable. Vulnerability scan summarisation is the next natural step for any team already running a scanner. Start narrow, measure the time you get back, and let that justify the next move.

What about the Essential Eight and our compliance obligations?

AI does not change the Essential Eight obligations; it helps you meet them more efficiently. Patch gap reporting and security policy drafting are both areas where AI saves time while the IT manager owns the decisions. Check that any AI tool touching your systems does not undermine your multi-factor authentication (MFA), least-privilege or application control posture. Also: the Australian Cyber Security Centre (ACSC) Essential Eight is transitioning to a new Essentials series; verify the current framework position before using AI to report against specific controls.

Can AI help during an active incident?

Yes, carefully. AI is useful for producing a first-draft incident timeline from logs and notes, and for drafting the post-incident review. What it must not do is make containment calls, decide who gets notified, or take automated action on live systems. Those decisions involve legal obligations, including Notifiable Data Breaches timelines, and risk calls that the IT manager or incident lead must own.

How current is this, and how fast does it change?

Faster than most functions in this series. The Australian Signals Directorate (ASD) Essential Eight to Essentials series transition is ongoing, guidance on AI agents was published in May 2026, and detection tools are evolving quickly. The evidence here is current to mid-2026. If something has shifted since you read this, the fastest way to get the current picture for your situation is a quick chat.

Book a discovery call

A first conversation

See how this applies in your world.

Book a confidential chat. Tell us where you see the opportunity, in it operations and security or anywhere else, and we will agree a sensible next step. No deck, no pitch.