# Zoom CISO on AI's Real Role in Security: Enabler, Not Replacement


Sandra McLeod breaks down how AI transforms security operations while addressing the persistent myth that automation will replace human defenders.


## Background and Context


Zoom has become one of the most widely deployed communication platforms globally, serving billions of users across enterprises, education, government, and consumer segments. With that ubiquity comes responsibility—and complexity. The video communications giant operates at a scale that demands sophisticated, forward-thinking security strategies, especially as threats evolve and organizations demand real-time collaboration at global scale.


Sandra McLeod, Chief Information Security Officer at Zoom, recently discussed how her organization approaches securing a platform that touches nearly every industry and geopolitical region. Her perspective cuts through both the hype and the fear surrounding artificial intelligence in cybersecurity, offering a grounded view of how AI actually changes security operations.


The timing of this conversation matters. As organizations worldwide grapple with AI integration—from threat detection to incident response—leaders are asking hard questions: Will AI replace my security team? Can I automate my way out of the skills shortage? McLeod's answers suggest a more nuanced reality.


## The Evolving Threat Landscape at Global Scale


Zoom's threat surface is immense. The platform handles:


  • Video, audio, and instant messaging across every time zone
  • Integration with hundreds of third-party applications and enterprise workflows
  • Compliance requirements spanning GDPR, HIPAA, FedRAMP, SOC 2, and dozens of regional regulations
  • Nation-state scrutiny and geopolitical tensions that make infrastructure targets of interest

  • This complexity means Zoom's security operations center (SOC) cannot rely on traditional, manual approaches to threat detection and response. The volume of events alone—millions of security signals daily—would overwhelm human analysts working without intelligent systems.


    Yet, as McLeod emphasizes, the answer is not to remove human judgment. Rather, it's to amplify it.


    ## AI as a Workflow Accelerant, Not a Replacement


    McLeod's core argument centers on a critical distinction: AI should augment security teams, not replace them. In practice, this means:


    Automating the Mundane

  • Sorting, categorizing, and prioritizing security alerts to reduce analyst noise
  • Performing rapid initial triage of potential incidents
  • Identifying patterns in vast datasets that human analysts would struggle to surface manually
  • Automating routine response actions (disabling compromised accounts, isolating suspicious sessions, blocking known malicious IPs)

  • Freeing Human Experts for Strategic Work

  • Investigation of complex, ambiguous incidents that require context and judgment
  • Threat hunting and proactive vulnerability research
  • Security policy refinement and risk modeling
  • Executive communication and business alignment

  • Enabling Faster Response

  • AI-driven systems can detect and initiate containment in seconds, whereas manual processes take hours or days
  • This speed difference is critical in adversarial scenarios where attackers move quickly

  • ## The AI Security Workflow Shift


    Modern AI-enhanced security operations look different from traditional SOC models:


    | Traditional SOC Workflow | AI-Enhanced Workflow |

    |---|---|

    | Analyst receives alert, reads context, makes decision | AI surfaces alert with pre-filled context, analyst validates and acts |

    | Manual log analysis to understand incident scope | AI correlates logs, suggests incident timeline and scope |

    | Hour-long incident response cycle | 15-minute detection-to-containment cycle |

    | Reactive investigation only | Proactive threat hunting with AI pattern detection |


    McLeod's practical point: the most effective teams don't eliminate human involvement—they eliminate time wasted on mechanical tasks.


    ## Addressing the Cybersecurity Skills Gap


    The industry faces a persistent problem: there are far more open security roles than qualified candidates. McLeod's position suggests that AI can make security careers more attractive and sustainable:


  • Reduced burnout: When junior analysts spend less time on alert triage and more on investigation and learning, they develop skills faster and stay in roles longer
  • Faster onboarding: New team members can leverage AI-assisted analysis to understand incident patterns without years of manual experience
  • Higher leverage per headcount: Teams accomplish more with the same staff, reducing pressure to hire at unsustainable rates

  • This is particularly important for mid-market and smaller organizations that cannot compete with giants for security talent. AI tools democratize access to some of the analytical capabilities that only large enterprises could previously afford.


    ## Technical Considerations and Guardrails


    McLeod also addresses the practical concerns organizations should have about AI in security:


  • Explainability: AI-driven recommendations must be interpretable—security teams need to understand *why* a system flagged something, not just accept its verdict
  • False positive management: Algorithms that produce too many false alerts cause analyst fatigue and undermine trust; the goal is precision, not recall alone
  • Feedback loops: AI systems improve with data; Zoom's teams provide continuous feedback to refine detection models
  • Adversarial awareness: Attackers also use AI; security organizations must anticipate evasion attempts against their own ML-based defenses

  • ## Implications for Organizations


    For enterprises deploying communication platforms like Zoom, McLeod's perspective has three key takeaways:


    1. Security posture depends on enabling your team, not replacing them. Organizations should invest in both AI-enhanced tools AND in recruiting, retaining, and developing security talent. The two are complementary, not competitive.


    2. AI implementation requires governance. Deploying AI without clear policies about how it's used, what it decides, and how humans oversee it creates new risks. Organizations should define decision boundaries—which actions AI can take independently versus which require human review.


    3. The speed advantage is real. AI-enhanced detection and response can compress incident cycles from days to minutes. For organizations handling sensitive data, this difference is material to breach impact and regulatory liability.


    ## Advice for Aspiring Security Leaders


    McLeod's guidance to the next generation of cybersecurity professionals is clear: understand AI, but don't expect it to be a shortcut.


  • Build fundamentals first: Before specializing in AI security, develop deep knowledge in traditional security domains—networking, system administration, threat intelligence, incident response
  • Learn the business context: The best security leaders understand what their organization does and why security matters to its mission
  • Embrace continuous learning: AI and security both move fast; comfortable careers depend on staying current
  • Think about people: Security is ultimately about protecting people and assets; technology is the means, not the end

  • ## HackWire Analysis


    McLeod's framing of AI as "enabler, not replacement" is a necessary counterweight to two competing narratives in security discourse. On one side, vendors promise AI will solve everything; on the other, some professionals fear technology will eliminate security careers. Both miss the point.


    The real story is that AI redistributes security work, not eliminates it. It automates the repetitive signal processing that consumed junior analysts' time and allows senior analysts to focus on harder problems. For the industry, this matters because the bottleneck in cybersecurity isn't computational power—it's human judgment, creativity, and accountability.


    Where McLeod's perspective becomes particularly important is in guarding against what we might call "trust drift": the gradual erosion of human oversight as organizations grow confident in AI systems. Zoom's approach, with humans explicitly validating AI recommendations and maintaining decision authority, is the model. The dangerous pattern is when organizations use AI's speed as justification to remove humans from critical decisions entirely. That path leads to cascading failures when adversaries craft attacks specifically designed to evade automated defenses.


    For CISOs and security leaders across industries, McLeod's advice is actionable: invest in tools that amplify your team's capabilities, not replace their judgment. Hire for critical thinking and domain expertise, not just AI credentials. And maintain the human feedback loops that keep systems sharp and accountable. The organizations that do this well will outpace competitors who pursue full automation and discover, too late, that machines are insufficient without human wisdom.


    — HackWire Editorial


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)