Close Menu
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
More items
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
X (Twitter) LinkedIn
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
Login
LinkedIn Bluesky
Resilience Forward
Subscribe Now
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
Resilience Forward
You are at:Home»Managing resilience»Technology»How much does AI cost in your AI security process? (Page 15)
Technology

How much does AI cost in your AI security process?

AI has huge potential around security. That potential goes both ways, with attackers using AI to improve their ability to exploit vulnerabilities and defenders responding faster to threats. But effectiveness can be expensive. Eric Avery looks at how to understand and control your defensive AI costs…
May 12, 20265 Mins Read
AI tokens concept

According to research by the AI Security Institute around attack scenarios and AI agents, the best AI models can now complete more than half of a simulated realistic security attack process of 32 steps. More importantly, the cost for that full attempt process is now around £65 or $80.

On the defence side, AI is already making a difference too. In Sumo Logic research, 90% of respondents said that AI is extremely or very valuable in reducing alert fatigue and improving detection accuracy for their teams. Currently, nearly half (49%) of respondents use AI and machine learning for threat detection, while other deployments include automated response (20%), anomaly detection (17%), and using AI for incident triage (9%), showing that while AI for security has developed rapidly, there is still a long way to go toward full AI SOC environments.

 One of the biggest challenges to these fully automated AI security programmes is the cost. In the Sumo Logic research, 63% of respondents said that high operational cost is their biggest pain point. So how can security teams fashion their response to work effectively with AI resources without breaking their budgets?

 Understanding the cost of defensive AI

Agentic AI systems rely on tokens – the unit of measurement for work processed by large language models. A token equates to a word, part of a word, or a number, which then links up with other tokens to provide the meaning and context of a given item. For security, this could cover information from a set of logs that are then parsed, passed through the LLM, and the context used to understand whether there is a threat or not. The more data you process, the more tokens you use. The more you interact with that set of data, the more tokens you consume as well.

 There are two distinct areas of cost optimisation around AI. The first use case for agentic AI around security involves agents that rely on an optimised data layer you control. Here, the foundation is everything. When your data is structured, segmented, and scoped properly, your AI agents only process what is relevant. The tighter your scope, the more efficiently tokens are used and the less time models spend analysing noise. In other words, preparing the data that your agents can potentially use and how they might use it prevents them from burning through tokens unnecessarily.

Rather than bringing together multiple sets of data that have to be turned into tokens, using one central, curated data architecture that supports focused prompting creates an inherently more efficient environment. By ensuring you operate on a well-architected data foundation and are incorporating optimised data interaction practices, you are able to spend less time proactively tracking token consumption and setting usage thresholds so that innovation doesn’t outpace accountability.

For external interactions with data you do not control, such as everyday conversations with public generative tools like Gemini or Claude, cost optimisation takes a different form. Here, the emphasis shifts primarily to human prompting habits and architectural efficiency. Concise prompting paired with fresh contextual data or cached knowledge can drastically reduce unnecessary token usage. Model choice also matters – smaller, task-aligned models are often sufficient for contextual synthesis, while larger ones are best reserved for high-value generative insight.

 Techniques such as retrieval-augmented generation (RAG) add another layer of efficiency. By referencing trusted internal data repositories rather than overly broad, open-ended querying, RAG reduces repetition and limits spend while maintaining accuracy. The key thing to take away is that AI providers are not going to be responsible on your behalf or guarantee control under the covers. You have to go the extra mile and use your deterministic capability to insulate tooling from unexpected cost and architectural abuse.

 Efficient AI security comes back to data management

 Across both categories – controlled agents and open models – the unifying theme is disciplined data management. The better we define, secure, interact with, and monitor our data layers, the more efficiently AI can operate.

This is where strong data foundations, effective pipelines, and transparent monitoring turn cost from a reactive surprise into a proactive lever. For CISOs, that translates directly to stronger, leaner security programmes that have a higher trust foundation from inception and a company that spends intelligently on compute and tokens, not haphazardly.

 The challenge around AI security is that many companies don’t have that data layer built for security in place. Where they do, the team involved may not be security specialists that understand the workflow and approach that security teams have to follow. To get over this, start with conversations around how data can be managed more effectively, and how these practices can be scaled up over time. Those building data lakes or lakehouses have experience of bringing different data sets together, but they may not be familiar with the real-time world of security. Collaborating around this approach can help you improve your performance, while also avoiding the cost for duplicating data or spending too much on tokens to power your AI security processes.

In conclusion

According to McKinsey, 50% of organizations expect to embed AI across their security stack over the next three years. The goal is to make teams more effective in their roles by speeding up processes and deploying automation. In practice, teams deploying AI have to be more technically precise, financially responsible, and data-driven from the ground up if they want to achieve their goals.

The author

Eric Avery is Global Head of Data and Infrastructure at Sumo Logic, a cloud security and log analytics company. Eric runs Sumo Logic’s own data infrastructure that processes that handles more than four exabytes of data every day. Prior to Sumo Logic, Eric led cloud operations and services at companies including AWS, Delphix, and Infor.

Africa Asia Asia Pacific Australasia Europe Middle East North America UK
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp
Previous ArticleCloud Security Alliance releases AI Security Maturity Model
Next Article UK King’s Speech includes the Cyber Security and Resilience Bill

Related Posts

An exploding digital padlock illustrates the requirement for post-quantum cryptography.

Research breakthrough brings reliable quantum computers and Q-day closer to reality

September 10, 2026
A danger sign on a digital background.

New blob URL phishing technique evades detection by using legitimate Microsoft services

September 10, 2026
AI risks

Unmanaged AI workflows expose EMEA organizations to rising compliance and data risks

September 9, 2026
City skyline at sunset with bright light trails and a translucent blue smart-city grid overlay and GPS pins indicating locations.

AI world models: future possibilities for organizational resilience?

September 7, 2026
DRJ and BCI logos

DRJ and BCI publish guidance for governing, managing, and using AI in resilience

September 7, 2026
Decision making with over whelming information.

AI can find the vulnerability. Accountability still sits with your crisis leadership

September 7, 2026
Advertisement
Resilience First
This week's most read articles
Under pressure: An egg cracking under pressure applied by squeezing clamps form the sides.

Managing scenario testing for operational resilience

May 16, 2024
COSO logo

New COSO ERM guidance aims to help organizations with practical implementation

May 12, 2026
Close-up of a green-brown iris peering through a jagged tear in dark paper or wall material.

The blind spots in business continuity

September 2, 2026
Latest resources
The word Glossary surrounded by letter tiles to illustrate The International Resilience Glossary.

DRI International publishes updated International Glossary for Resilience

February 27, 2026
Load More

Subscribe to Updates

Get our Resilience Updates newsletter.

Most Popular Feature Articles
Three dark coloured light bulbs on a black background illustrate the concept of The Dark Triad in Crisis Management.

The Dark Triad in crisis management

Five stage crisis management framework

A five stage framework for a crisis management process

Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

Latest Reports
A futuristic red warning alert icon with glowing exclamation mark.

Cloud Security Alliance publishes Hugging Face Incident Initial Post-Mortem

A person hold a building door open for a person behind who is tailgating to get unauthorised access.

Security Culture: A Strategic Capability That Builds Resilience in a Volatile World

An identity icon with a map marker on it, indicating the concept of identity as a target for attackers. The icon is on a generic IT background predominantly in black and orange.

Identity-based approaches dominate initial access for ransomware attacks

A promo box for an article about resilience governance.
© 2026 Resilience Forward
  • About Resilience Forward
  • Newsletter
  • Newsfeed
  • Advertise
  • Call for Papers
  • Contact
  • Privacy Policy and Cookie Use
  • AI Use Policy

Type above and press Enter to search. Press Esc to cancel.

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?