AI-driven security can only interpret what an organization makes visible to it—but collecting more data is not enough. In a SecurityWeek opinion article published August 27, 2026, Danelle Au argues that security analysis needs high-fidelity telemetry connected to operational context, while keeping sensitive data under meaningful control. That is a useful architectural thesis, not a proven rule that every organization should collect everything.
Why does AI-driven security need more than alerts?
Security tools commonly filter, normalize, and summarize activity before it reaches a security information and event management system (SIEM). Au says this can leave “roughly 10–20%” of the environment’s generated telemetry available for analysis. The article does not provide a study or method for that estimate, so it should be understood as Au’s claim—not as an independently established industry-wide measurement.
As an Amazon Associate I earn from qualifying purchases.
The distinction matters because alerts are interpretations of events, not the events themselves. A filtered alert may identify a file upload or an unusual login, but analysts may need the underlying sequence, timing, and surrounding activity to judge whether it is benign or part of a larger incident. AI does not remove that dependency: a model’s conclusions are bounded by the quality, coverage, and context of its inputs.
Free tools Windows power users keep installed
One-click scans. No signup required.
A related point appeared in a May 22, 2024 prepared statement to a U.S. House hearing. Michael Sikorski, CTO and vice president of engineering at Unit 42, said, “AI models are only as good as the inputs they are trained on.” The hearing is an official record of testimony, not an independent evaluation of commercial cyber-defense systems; its statements support the importance of input quality, not a particular product’s effectiveness.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
How can connected data change an investigation?
Au’s example is hypothetical: an employee preparing to leave downloads a competitive-analysis document, uploads it to personal cloud storage, and emails it externally. A data-loss-prevention (DLP) system or cloud access security broker (CASB) might generate separate alerts for parts of that activity. Considered independently, each may reveal only one action.
Linking the events could give an investigator a more useful picture: whether the same person accessed the document, how the file moved, whether its destination was unusual, and how the actions fit the user’s behavior over time. Document lineage and event timing can help distinguish a concerning chain from routine activity. This does not mean an AI system can infer intent with certainty; it means connected evidence can make a judgment more informed and easier to investigate.
What information might provide operational context?
Au’s proposed picture reaches beyond conventional security logs. Depending on the organization and the question being investigated, relevant sources may include network, operational-technology (OT), Internet-of-Things (IoT), SaaS, and cloud activity; human and non-human identities; and business content such as source code, customer records, or financial models.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsRank #2
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
These categories serve different purposes. Telemetry records activity; identity data helps associate actions with accounts or services; operational context explains what systems and processes do; and business content may show what information is at stake. Joining them can improve interpretation, but it is not a universal collection mandate. A source is useful only when it is relevant, sufficiently reliable, governed appropriately, and practical to maintain.
Why does more visibility make control more important?
Expanding analysis into sensitive business information raises architecture questions alongside detection questions: where data is stored and analyzed, who can access the inputs and outputs, which models process them, and what happens if a government or other authority compels access. Au’s argument is that privacy and data sovereignty must accompany completeness rather than be treated as later add-ons.
References to laws such as the GDPR, the U.S. CLOUD Act, DORA, or HIPAA do not establish how any one law applies to a particular organization or design. Legal duties depend on facts such as jurisdiction, data type, provider relationships, and processing arrangements. Organizations should assess those obligations with qualified counsel rather than infer a legal answer from a general architecture discussion.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
What should organizations evaluate before broadening data access?
A practical design starts with investigation needs and then tests whether each proposed source can be used safely and effectively. The relevant trade-offs include coverage, fidelity, cross-system linkage, retention, access controls, and integration effort.
Recommended Free Tools
- Define the investigation question. Identify which incidents or decisions the system must support before expanding collection.
- Check fidelity and provenance. Determine what is filtered or normalized, what original records remain available, and how analysts can trace an output to its inputs.
- Test cross-system linkage. Confirm that identity, endpoint, network, cloud, SaaS, and business records can be connected with reliable timestamps and identifiers where needed.
- Set retention and queryability requirements. Decide how long relevant records must remain available and whether investigators can retrieve the underlying events, not only summaries.
- Specify control boundaries. Establish where data and models run, who may access raw data and derived outputs, and how access is audited.
- Account for privacy, legal obligations, and operational cost. Limit collection to justified purposes and assess the integration and governance burden of each source.
The hearing transcript offers a separate, carefully bounded illustration of the gap between raw activity and actionable review. Sikorski reported that his company’s AI-powered security operations center ingested 59 billion events daily, reduced them to 26,000 raw alerts, and then to 75 requiring further analysis. He also reported customer outcomes including a reduction in response time from 2–3 days to under 2 hours, a fivefold increase in incident closeout rates, and a fourfold increase in daily security data ingested and analyzed. These are company-reported figures in witness testimony, not independently evaluated benchmarks, and they do not validate Au’s 10–20% estimate.
The hearing also included a Gecko Robotics witness’s example from physical critical-infrastructure inspections: a partner’s manual process reportedly yielded 3,000 data points, while robots collected more than 8 million on the same asset. That example concerns physical inspection data, not enterprise cyber telemetry; it illustrates a different context in which richer data collection was discussed.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
What does “complete data” mean in practice?
Completeness is best treated as fit-for-purpose coverage, not an attempt to ingest every available record. A useful security data foundation preserves enough fidelity to investigate, links events to relevant identity and operational context, and applies controls appropriate to the sensitivity of each source. Data without reliable provenance or governance can create noise and exposure instead of better decisions.
Au’s broader point is that model sophistication alone cannot compensate for missing or disconnected evidence. The practical challenge is to make relevant information available to analysis while preserving the ability to understand where it came from, who can use it, and under what conditions.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




