
AI security
Securing and deploying AI in defence
Overview
AI security on both fronts: AI-driven security orchestration and automated response that lets a small team fight at machine speed, and structured programmes that secure an organisation's own AI systems against manipulation, poisoning and misuse.
AI on both sides of the fight: orchestration and automated response that lets a small team defend at machine speed, and programmes that secure your own AI against manipulation.
Capabilities
- AI SOAR: security orchestration and automated response
- Force-multiplies small security teams to machine speed
- AI security programmes: securing models against poisoning and misuse
- Governance frameworks for AI deployed in sensitive environments
- Adversarial testing of your own models: evasion, extraction and data-poisoning red-teaming before an AI capability is trusted with a mission
- Deployed as a force multiplier that lets a small sovereign team defend at machine speed without ceding control to a foreign platform
Specifications
| Type | AI security |
| Offer | AI SOAR + AI security programme |
| Effect | Machine-speed response / hardened AI |
| Origin | Independent / non-aligned |
In depth
AI is both the tool and the target
The catalogue describes two connected services under AI security. AI SOAR, or security orchestration and automated response, helps a small security team operate at machine speed. A separate AI security programme protects the organisation's own models and deployments against manipulation, poisoning and misuse. Treating these as the same problem would miss the operational distinction. One applies automation to detection and response. The other asks whether an AI system can be trusted with a sensitive task, how its data and behaviour can be interfered with, and what governance applies when it is deployed. The product record puts both fronts together because an organisation can use AI to defend while still needing to defend the AI it owns.

Automation with a defined human role
AI-driven orchestration and automated response are intended to force-multiply a small team rather than replace its control of the defence. The recorded effect is machine-speed response, supported by the wider defensive capability's AI-assisted operations and defence-in-depth. The catalogue records those operations blocking more than 100,000 threats daily, while the AI security entry identifies the SOAR offer as the mechanism for a smaller team to act at that tempo. Automation can handle the response work assigned to it; the product record does not turn that into an unsupervised engagement authority. Human decision-making remains relevant wherever the organisation's policy, mission or consequences require it.
Testing the model before trusting the mission
The AI security programme includes governance frameworks for sensitive deployments and adversarial testing of an organisation's own models. The listed tests cover evasion, extraction and data poisoning. Securing against poisoning addresses the data or training path being manipulated. Evasion asks whether an input can make the model miss or misread what it is meant to detect. Extraction concerns attempts to obtain information from the model. These are concrete test categories, not a general promise that a model is safe. The independent, non-aligned origin keeps the programme accountable to the buyer, and the stated approach avoids ceding control of AI defence to a foreign platform.
Keep the two assurance questions separate
A security team considering AI SOAR needs to ask what the automation is permitted to do when it detects a threat. A team introducing an AI system into a sensitive environment needs to ask what happens when the model is manipulated, its data is poisoned or its behaviour is extracted. The catalogue records governance frameworks for the second question and automated response for the first. It also identifies adversarial testing before an AI capability is trusted with a mission, covering evasion, extraction and data-poisoning red-teaming. This makes the programme applicable to an organisation's own models rather than only to a vendor's security console. The wider defensive record supplies the operating context: AI-assisted operations are shipped with defence-in-depth and human oversight, and are recorded as blocking more than 100,000 threats daily. That operational result belongs to the defensive capability, while AI security supplies the separation of responsibilities and tests needed before a buyer places a new model in a sensitive workflow. An independent, non-aligned team keeps both decisions with the buyer.
A programme for systems already in use
The offer is not limited to a future model that has not yet reached an operator. It includes security orchestration and automated response for current defence operations, and a structured programme for an organisation's own AI systems. The latter can be examined before a capability is trusted with a mission, using adversarial tests for evasion, extraction and data poisoning, while governance frameworks address deployment in sensitive environments. The catalogue also identifies manipulation and misuse as risks. This gives the buyer a defined sequence: use automation to help a small team respond, test the models it owns, and retain control of the platform rather than ceding the intelligent layer of defence to a foreign provider.

Why Unstrat: the difference
Unstrat is the authorised global representative and distributor for this capability. It is already in service with a track record behind it, so you are buying something that has done the job elsewhere, not funding a first attempt. You are not the test bed.
Independent, non-aligned origin, with no political exposure to any major-power ecosystem.
One accountable team from first briefing through delivery and in-region sustainment.
AI-driven response proven in operations blocking 100,000+ threats daily.
How it reaches you
Related capability
View all →Procurement & sustainment
Classification and the end-user-certificate chain are confirmed before this capability is represented to your market.
Sourced from an independent manufacturer: no major-power disclosure rules or political conditions.
A single team responsible from first briefing through delivery: not a chain of foreign primes to integrate yourself.
Lifecycle support and operator training delivered in-region, building capability that outlasts the initial deployment.
Questions buyers ask
What is AI security?
Two different jobs share the name. One is using AI to run security operations faster than a small team could manually; the other is protecting your own models from manipulation, poisoning and misuse. We do both: AI-driven orchestration and automated response, and structured programmes that harden the models before they are trusted with anything that matters.
Best SOAR platform alternatives
Cortex XSOAR is the reference automation platform and publishes what that means: more than 1,000 integrations, playbook-driven automation, case management and full multitenancy for service providers. Our AI SOAR runs inside an operation blocking over 100,000 threats a day, and comes from a non-aligned supplier with no obligation to report to a foreign government. We do not publish an integration count, so check the list against your actual tool estate before deciding.
Can AI replace security analysts?
No, and the vendors do not really claim it either when you read closely. Palo Alto's own customer figures for XSOAR describe 30% of incidents automated and one full-time analyst's time saved, which is a force multiplier rather than a replacement. We ship AI-assisted operations with defence in depth and human oversight for the same reason: an automated action on a bad inference is still your outage.
See: AI security
How do you secure an LLM deployed in a government environment?
Start with a threat model for the model itself, then test it adversarially for evasion, extraction and data poisoning before it is trusted with a mission. Add a rule for which actions the system may take without a human, and a decision about what data the security tooling may see. We deliver that as a structured programme rather than as a product licence.
See: AI security programmesGovernance compared with HiddenLayer and XSOAR
Adversarial testing for machine learning models
We red-team models for evasion, extraction and data poisoning, using the same team that attacks live production networks. HiddenLayer covers a broader published attack list, including prompt injection, PII leakage, inference attacks and model tampering, mapped to MITRE ATLAS and OWASP LLM with more than 64 techniques. If framework mapping is a procurement requirement, that difference is worth noting: we do not publish ours.
See: Attack classes and framework mappingOffensive cybersecurity
AI-driven detection and response for a small security team
Automation earns its place when the team is too small to work the alert queue by hand, which describes most national teams. Our AI SOAR is designed to force-multiply a small team to machine speed, and it is tuned against real alert volume from an operation blocking more than 100,000 threats daily rather than a demonstration data set. Human oversight stays in the loop by design.
What access does an AI security vendor need to our model and training data?
Ask early, because the answer varies a lot. HiddenLayer makes non-invasiveness a headline claim, observing vectorised model inputs only, without access to training data, features or the model itself, which is a genuine deployment advantage where you cannot expose training data to a vendor. We have not published our access requirements, so put the question in writing before scoping.
Model poisoning and data poisoning: what should we test for?
Test the three families that change outcomes: evasion, where inputs are crafted to be misclassified; extraction, where the model or its data is stolen through queries; and poisoning, where training data is corrupted upstream. Our adversarial testing covers those before an AI capability is trusted with a mission. HiddenLayer's published list extends further into prompt injection and model tampering, which is a useful checklist whichever supplier you pick.
We want to automate our SOC but cannot host it on a foreign cloud. What are the options?
Separate the automation decision from the hosting decision, then be precise about what you lose. XSOAR is cloud-native SaaS with an on-premises option and publishes multitenancy for service providers, which we do not. Our AI SOAR is delivered by a non-aligned supplier with no reporting line to a foreign government, and deployment options are agreed per engagement rather than published, so ask for them in writing.
What governance do we need before deploying AI in a defence or intelligence environment?
At minimum: a documented threat model for the model, adversarial testing against evasion, extraction and poisoning, a decision on what data the tooling may see, and a rule for which actions may be taken without a human. We deliver that as a structured programme. Neither the HiddenLayer nor the XSOAR datasheet describes a governance framework, because they are products rather than programmes, so expect to build that layer regardless of what you buy.
See: Governance for sensitive environmentsAI security programmes
How do we measure whether SOAR automation is actually reducing analyst load?
Baseline the alert count, the median time to close and the proportion of incidents touched by a human, then measure the same three after six months. XSOAR publishes customer-reported figures on exactly those axes, with weekly alerts falling from 10,000 to 500 and response time from three days to 25 minutes. We do not publish automation metrics of our own, and we would rather show the effect on your queue than borrow someone else's numbers.
Our AI is being used for fraud scoring. Who checks that the model itself is not the attack surface?
Somebody outside the team that built it, testing it the way an attacker would rather than the way a validator would. Our AI-assurance work sits next to financial-crime and payment-network defence, so the model, the data feeding it and the network it runs on are examined together. That combination is unusual, and it is why the AML engine and the AI security programme are sold by the same team.
Can one supplier both automate our defence and secure our models, or should we split it?
We do both deliberately, because the orchestration platform is itself a model-driven system that needs the same scrutiny. The counter-argument is independence of assessment, and it is a reasonable one for a ministry with a strict separation policy. HiddenLayer covers only model protection and XSOAR only orchestration, so splitting the work means running two procurements and owning the join yourself.
See: Scope of each offer
How do we stop an automated response from causing the outage we were trying to prevent?
Restrict the action set, stage the automation, and keep a human decision point on anything that isolates a production system. Our operations run AI assistance with defence in depth and human oversight for exactly this reason, on estates where an unnecessary isolation is itself an incident. Write the allowed action list into the runbook before the platform goes live, not after the first false positive.
Which adversarial AI frameworks should our testing map to?
MITRE ATLAS and the OWASP LLM list are the two most commonly demanded in tenders, and HiddenLayer maps to both across more than 64 adversarial techniques. We do not publish our framework mapping, which is a documented gap on our comparison page rather than an oversight to argue about. If a named mapping is a hard requirement, raise it at scoping and get the answer in writing.
AI security: questions
What is AI security?
AI security is Unstrat's Cyber (Cyber & Critical Infrastructure) capability: AI security on both fronts: AI-driven security orchestration and automated response that lets a small team fight at machine speed, and structured programmes that secure an organisation's own AI systems against manipulation, poisoning and misuse.
How does AI security work?
AI security delivers its effect through AI SOAR: security orchestration and automated response, Force-multiplies small security teams to machine speed and AI security programmes: securing models against poisoning and misuse, capabilities matched to the requirement and confirmed under briefing rather than published.
Who provides AI security?
AI security is delivered by The Cybersecurity Group, whose focus is cyber & critical-infrastructure security. Unstrat represents The Cybersecurity Group to government and enterprise buyers worldwide as an independent, non-aligned prime vendor.
Why choose AI security over a major-power alternative?
AI security is sourced from an independent, non-aligned provider, so it carries no major-power disclosure rules, upgrade-locks or political ramifications. Concretely: AI-driven response proven in operations blocking 100,000+ threats daily. The capability is accountable to you, not to a foreign vendor's government and its release schedule.
How is AI security procured, and where can it be delivered?
AI on both sides of the fight: orchestration and automated response that lets a small team defend at machine speed, and programmes that secure your own AI against manipulation. Every engagement begins with a briefing, and export eligibility is confirmed per market under briefing rather than published. Where controlled capabilities are involved, the classification and end-user-certificate chain is confirmed first. AI security is then sustained in-region by one accountable team from briefing through long-term operation.





