[Digital Today reporter Chi-kyu Hwang] "As AI spreads, the center of gravity in the security market is rapidly shifting from products to operations. As products become more standardized, gaps between companies are shrinking. In this situation, the key is how well organizations apply security to their own environments. The trend in which operations determine security will strengthen."
Young-mok Kwon (권영목), CEO of Pago Networks, which specializes in managed detection and response (MDR), summed up the changes in the security landscape driven by AI in a recent interview with a reporter. Until last year there were differences in product capabilities among companies, but recently the gaps have narrowed in both network security and endpoint security. AI is accelerating that trend, he said.
Kwon said the situation changed rapidly this year after Anthropic released Mithos. He said Mithos is expected to speed up attacks, and the industry fell into panic amid concerns it would be hard to keep up. In that environment, he said, the importance of operations is being highlighted even more. He added that, whether in Korea or not, in the global security industry cooperation with Anthropic, OpenAI and others is no longer a distinguishing feature, to the extent that many companies are working with leading AI firms. He again stressed that, in that environment, a condition companies prioritize in security is how well they can apply AI and operate in a way optimized for their own environments.
According to Kwon, the growing emphasis on operations in the security market is based on the view that in a fight between attackers and defenders using AI, defenders can have an advantage depending on how they execute.
"AI enhances defenders' capabilities as well as attackers'," Kwon said. "People inside a company know that specific corporate environment better than attackers do. If they keep their heads, there is no need to panic, and the side that blocks may even have the advantage." He said it is necessary to accept the AI trend but not leave everything to AI, and to optimize by separating the roles of people and AI.
As AI takes on more work, the amount of work for people is also increasing, making the redistribution of roles between AI and humans an important variable in corporate security strategy, he said. Kwon said the company is already applying to some customers a human-in-the-loop methodology that assigns AI security solutions roles similar to humans while leaving room for human intervention.
Since its founding in 2017, Pago Networks has focused on MDR services. MDR is a business that provides outsourced security operations for companies that lack the capacity to manage security themselves. Unlike security monitoring that deploys people directly at customer sites, MDR focuses on detecting and responding to the status of security infrastructure remotely.
For companies that already have infrastructure, Pago Networks provides operations on an outsourced basis, and for those without infrastructure it supports infrastructure selection when needed. It also recommends security solutions that work well with its MDR service. Recently, it has been combining MDR and AI and strengthening its identity as a security operations center (SOC) as a service company beyond MDR.
Kwon said it is expanding from MDR into a SOC as a service business model. He said the core of SOC as a service is to keep the security monitoring area, such as checking system availability, and on top of that use AI to provide services that companies find hard to staff and run themselves, including blue teams, red teams, CERT (Computer Emergency Response Team), penetration testing and more.
As part of its SOC as a service strategy, Pago Networks also introduced three brands targeting the AI-era security environment.
It reorganized detection and response, threat hunting, detection engineering and offensive security capabilities around AI and offers them under three brands: PAGO DeepACT DEFENSE, PAGO DeepACT ATTACK and PAGO DeepACT Detection-Engineering.
· From detection and response to threat hunting...Pago Networks unveils AI-based security operations strategy
Kwon said the rapid expansion in speed and scope of security operations due to advances in AI is demanding fundamental changes to existing SOC operating methods. He said the direction the company is pursuing is not for AI to replace people, but for AI to handle repetitive analysis and detection tasks so that security experts can judge real risks and focus on more important decisions.
Kwon also highlighted providing an operating environment that feels like running one company’s products, even if security products are selected from multiple companies.
"If endpoint and network security products come from different vendors, it is not easy to create synergy from an operations standpoint," Kwon said. "Pago Networks has a framework that connects multiple products as if they were one." He said this is the direction MDR providers should pursue, and customers are already demanding it.
Overseas, MDR is already a mature business, but in South Korea companies' awareness of MDR had not been favorable from the perspective of providers. Companies only began to recognize what MDR was 1 to 2 years ago, he said. But the mood changed sharply this year amid the shock from Mithos. Kwon said it was not easy to build the market and promote MDR in South Korea for 7 years, but now there is no need to explain it.
Offensive security, an approach from the attacker’s perspective rather than the defender’s, is another trend Kwon has recently been focusing on and sees as having significant potential.
He said the rise of keywords such as continuous offensive security testing (COST) and continuous threat exposure management (CTEM) should be seen in that context. Kwon said growing concern that hackers armed with AI models like Mithos could find unpatched vulnerabilities and attack immediately is accelerating moves in the security solutions market to use AI to conduct ongoing simulated hacking or penetration testing before attackers get in. He said that on the operations side, whereas previously the focus was mainly on defender-centered solutions, it is now shifting toward viewing offensive security alongside them.