May 28 2026
Security

How Can AI Agents Support Lean Security Teams?

Small businesses should explore how artificial intelligence and automation can improve their security strategies.

Growing cyber threats and limited head count create ongoing challenges for security teams at small businesses. 

Although 94% of small business leaders are “somewhat” or “very” knowledgeable about cyber threats, half feel overwhelmed by the number of cybersecurity tools on the market, and only 11% use tools powered by artificial intelligence, according to a 2025 CrowdStrike report. However, small businesses should consider where AI can best augment their security strategy

“For organizations with lean security teams, there is an exciting opportunity for AI to support some of the heavy lifting. We are already seeing huge gains for defenders, where AI can help triage alerts and potentially intercept malicious behavior, where only major incidents require human intervention and support,” says Ramya Chitrakar, vice president of engineering at Google Cloud Security

She says that smaller security teams can embrace AI-powered automation to eliminate alert fatigue, automate triage and improve around-the-clock visibility.

Click the banner below to learn more about finding an effective cyber resilience strategy for your business. 

 

Fighting Alert Fatigue To Help Security Teams Focus 

“Alert fatigue has long been a struggle in cybersecurity,” Chitrakar says. “This challenge, along with the manual nature of most security operations tasks, is notorious for burning out security teams. It also forces security operations centers into a reactive loop, preventing them from achieving a more proactive, optimized posture.” 

Agentic AI can help automate some of those tasks to free analysts’ attention for more high-level matters. As an example, Chitrakar notes, Google Security Operations has an Alert Triage and Investigation agent that has processed over 5 million alerts in the past year, reducing a typical 30-minute manual analysis to 60 seconds with Gemini

A 2025 Sophos report found that 76% of cybersecurity professionals reported experiencing burnout over the past year. When security platforms have agentic AI capabilities, security teams can start to engage with building agents using plain language instead of specialized queries. 

“Additional use cases include malware analysis and vulnerability discovery. Malware analysis is especially critical because few possess the advanced reverse-engineering skill sets required to perform it,” Chitrakar says, adding that Gemini-powered VirusTotal Code Insight, for instance, can analyze binary behavior to identify emerging threats. 

READ MORE: Get the strategic pros and cons of cloud computing for SMBs.

It’s critical that security teams govern their nonhuman agents with the same rigor that they do their highly privileged human analysts, she says. AI agents shouldn’t have unchecked access across a security information and event management platform; a security orchestration, automation and response tool; or downstream enforcement points. 

“Strict safety guardrails and API scoping must dictate what an agent can observe versus what it can execute. For example, an autonomous agent might have the authority to query threat intelligence and quarantine a standard workstation at 2 a.m., but taking a higher-risk action — such as modifying a core enterprise firewall rule — might still require human authorization based on predefined risk policies,” Chitrakar says. 

Additionally, security operations center visibility requires “extreme explainability and centralized logging,” so that when the morning shift arrives, staffers have a transparent, centralized audit trail about an incident that was resolved, she adds. That way, they know why an agent made a certain decision. 

“By embedding these strict playbook boundaries and identity governance directly into the security operations platform, teams can confidently scale their autonomous, around-the-clock defense while retaining absolute control and oversight over their environment,” Chitrakar says.

LEARN MORE: Discover how AI is forcing businesses to rethink their infrastructure strategies.

gradyreese/Getty Images
Close

New Research from CDW on Workplace Friction

Learn how IT leaders are working to build a frictionless enterprise.