Managing Complexity in Cybersecurity

Bhartrihari Pandiya, Prasad Kulkarni · 2025

The rise of complex cyber-attacks is automation based on artificial intelligence (AI), and problems arise when the control of these events is not in the hands of humans. While digital immune systems (DIS) utilize AI and machine learning to spot and combat cyber risks in real-time, the systems are not immune to human-based threats like insider attacks, social engineering, and credential-based intrusions. These tactics leverage behavioral and psychological vulnerabilities rather than the technical ones, making them challenging for AI-based security solutions to catch. This study analyzes why automated cybersecurity mechanisms may have their limitations, and how human oversight may complement DIS, with potentially a behavioral forensic view of human oversight. This research discusses AI-run security models shortcomings using two well-known cyber incidents, the first being the Twitter Bitcoin Scam (2020) and the second being the Solar Winds cyberattack (2020). In both instances, attackers evaded automated security controls by exploiting human weaknesses via social engineering in Twitter's case and a complex supply chain attack in SolarWinds. The first detects anomalies while the second relies on known attack signatures, therefore failing to recognize these attacks. Analysts later detected behavioral discrepancies that uncovered these breaches. Behavioral forensics is the intersection of psychology, criminology, and data analysis and holds the key to detecting deceptive behaviors and insider threats that AI-driven systems miss. This research analyzes the limitations of DIS and explores a cyber-physical infrastructure that essentially combines DIS with both behavioral forensics and human oversight to build a strong and adaptive cybersecurity framework. The findings discuss how a Human-in-the-Loop (HITL) security model, explainable AI (XAI) and zero-trust frameworks can increase cyber resilience by balancing automation with human expertise. The importance of introducing human oversight for cyber operations against technical threats and behavioral threats enabling a security-aware culture in an organization.

Read the paper · More papers on PaperTik