Brought to you by Bootstrap Cyber Media LLC
I’m calling it now. The next cybersecurity services boom will be built around the expertise required to transform security operations in the AI era.
I believe Security Operations Transformation will become one of the most valuable service categories in cybersecurity over the next several years. The opportunity is open to major consulting firms, but it is not reserved for them. Managed service providers (MSPs), managed security service providers (MSSPs), boutique consultancies, and highly experienced security professionals building small expertise-led businesses all have room to claim a piece of this market.
The need is a direct result of businesses becoming AI-enabled while threat actors use the same technologies to improve their own operations.
No, this is not Skynet. The more immediate problem is less cinematic and probably more expensive. Businesses are integrating AI into already complicated environments without fully understanding how it changes access, authority, data movement, software behavior, decision-making, or risk.
At the same time, security teams are being sold AI-enabled defenses that promise faster investigation, better detection, automated response, and relief from the endless conveyor belt of alerts. Those capabilities are appealing. But, they may also create new opportunities to automate bad decisions.
Companies need experts who understand how AI fits into the broader technology ecosystem, how to harness its benefits safely, and how to use it to improve security. They need help moving forward, not another 75-page report explaining that AI is risky.
That is the job of Security Operations Transformation.
AI is the Catalyst, Not the Category
It is tempting to call this “AI transformation” or “AI security transformation,” but tacking “AI” onto the term seems shortsighted, as it’s becoming ubiquitous. AI is rapidly becoming part of ordinary business operations. It is being embedded into productivity platforms, development tools, business applications, cloud services, security products, customer experiences, and internal workflows. Asking whether a company “uses AI” will soon be about as useful as asking whether it “uses the internet.” Of course it does. The important questions are where, how, why, and with what controls.
The same is becoming true inside security operations. Google describes an agentic security operations center (SOC) in which AI agents can perform alert triage, gather evidence, run analyses, correlate signals across tools, and deliver an explained verdict for human review. Google distinguishes this model from traditional security orchestration, automation, and response (SOAR), which follows rigid, pre-scripted playbooks rather than dynamically determining how to investigate a threat [1].
Artificial intelligence has entered the security ecosystem, but it is not replacing it. It’s part of a greater whole.
The National Institute of Standards and Technology (NIST) has organized the cybersecurity and AI intersection into three connected areas:
Securing AI systems.
Conducting AI-enabled cyber defense.
Thwarting AI-enabled cyberattacks.
In other words, organizations need to protect the AI they adopt, use AI appropriately within cybersecurity, and prepare for adversaries whose capabilities are changing because of the same technology [2].
Security Operations Transformation as a practice, then, cannot be an isolated AI initiative. It will require changes across security architecture, workflows, staffing, technology, strategy, and decision authority.
AI is the catalytic technology, just as the Internet and cloud computing were catalytic technologies. Security Operations Transformation is the broader service required to help organizations adapt.
Tech Industry Déjà Vu?
Back in my day, [mid 1990s] the commercial rise of the internet aka the “Dot Com Boom” created demand for developers, network engineers, architects, hosting providers, security professionals, consultants, and service businesses to help organizations change how they operate.
More recently, cloud computing became the darling of the industry and created demand for cloud architects, migration specialists, integration partners, cloud-security consultants, and eventually financial operations specialists to deal with the invoices everyone swore would be lower.
The analogy is not perfect, but the underlying market pattern is similar.
When a new technology becomes broadly available companies rush to adopt it. Then they discover that access to the technology is not the same as possessing the architecture, controls, operating model, skills, and judgment required to benefit from it safely.
Accenture’s current demand supports that pattern. Its clients are investing in cloud, data, security, and operating-model transformation to establish the foundations required to scale AI. They are asking managed service providers for more consulting and expertise, not merely more capacity [5].
Accenture also states that large-scale AI programs require deep industry and functional knowledge in addition to AI and technology expertise [5].
The cloud-services boom rewarded people who could help organizations navigate the transition. I believe the AI era will do the same for cybersecurity.
The Budgets Are Already Moving
PwC’s 2026 Global Digital Trust Insights survey found that enabling key cybersecurity capabilities with AI was the leading priority for cyber-budget allocation, the use of managed cybersecurity services, and efforts to address cyber talent gaps. Security leaders identified threat hunting, agentic solutions, event detection, behavioral analytics, identity and access management, and vulnerability scanning and assessment as priorities for the coming year [3].
PwC also found that knowledge and skills gaps were the top two barriers to implementing AI for cyber defense. Organizations are responding through AI tools, security automation, tool consolidation, workforce development, and specialized managed services. AI and cloud were ranked as the leading use cases for specialized managed security services [3].
EY’s 2026 research found that among senior security leaders already using AI in cybersecurity, 85% said their current cybersecurity budgets were insufficient to meet AI-enabled threats. Within two years, 67% expect to spend at least $5 million on AI cybersecurity, while 34% expect to spend at least $10 million [4].
The point I want to drive home is that the money is not flowing only to products. Accenture told investors in June 2026 that clients are investing in the foundations needed to scale AI, including cloud, data, security, and operating-model transformation. The company also said the nature of managed-services programs is evolving, with clients asking for more consulting and AI expertise within those engagements [5].
That, my friends, is the market signal.
Clients seeking security services are now facing changes that cannot be solved through another isolated implementation or outsourced task. They need someone who can help redesign how security works.
What Security Operations Transformation Means
I define Security Operations Transformation as:
The expert-led redesign of the people, processes, technologies, architecture, governance, and decision models used to protect an organization.
This is broader than SOC modernization. The SOC may be one part of the engagement, but a modern security operation crosses identity and access management, security engineering, cloud and SaaS security, data protection, exposure management, incident response, governance, risk, compliance, application security, third-party risk, and business resilience, among others.
It is important to distinguish transformation from implementation. A tool implementation might configure an AI-enabled investigation feature in a security platform. A transformation engagement determines:
Whether the feature belongs in the workflow.
Which data it should access.
What conclusions it may reach.
Which actions it may perform.
Where human approval is required.
How its performance will be evaluated.
What happens when it is wrong.
How analyst roles should change.
How the tool fits with the rest of the technology stack.
Whether the process it automates should exist in its current form at all.
Simply automating a broken process does not transform it. It produces broken results faster, like putting a turbocharger on a 1987 Yugo. Transformation begins with the desired operational outcome and works backward to determine what must change across the system.
Two Sides Of The Transformation
There are two sides to this transformation coin. A provider may specialize in one, or address both through a holistic practice.
Enhancing Security Operations with AI
Security teams need help determining where AI, automation, and new operating models should change their own work.
Security products are already moving from AI-generated summaries and chatbot assistance toward agents capable of performing complex security tasks. Google’s model includes agents that gather evidence, investigate alerts, analyze scripts, correlate information across tools, and return an explained verdict. The company maintains that humans should retain control over final decisions and oversight [1].
EY found that 85% of surveyed security leaders require humans to remain in the loop for critical security decisions. The same study found that 90% of organizations struggle to recruit and retain cybersecurity professionals with expertise in AI-driven security solutions, while only 20% reported having AI cybersecurity governance fully optimized and embedded into organizational culture [4]. This creates demand for outside expertise.
A Security Operations Transformation engagement focused on this side of the market could include:
Mapping current security workflows and dependencies.
Identifying suitable uses for AI and automation.
Defining human decision points.
Redesigning triage, investigation, and response procedures.
Integrating data across security platforms.
Reworking escalation paths and provider handoffs.
Establishing validation and quality-control processes.
Redesigning roles and responsibilities.
Developing skills-transition plans.
Creating metrics that measure operational improvement rather than tool usage.
The goal is not to add AI to every process because someone watched a keynote and got ideas. The goal is to improve security outcomes.
Ensuring Secure Use of AI Technology for Business
The second focus is protecting the businesses adopting AI systems, enabling safe (at least, safer) adoption throughout the organization.
Businesses are deploying AI faster than many security programs can discover or govern it. The desire to leverage the technology for productivity and bottom-line gains is a powerful driver of AI-adoption without consideration of how to do so without compromising security.
An AI agent may have an identity, access cloud resources, retrieve sensitive data, interact with SaaS applications, invoke APIs, execute code, rely on third-party components, and produce output that becomes part of another automated process. Securing it requires more than choosing an approved model or publishing an acceptable-use policy.
Service providers may need to help clients:
Discover approved and unapproved AI use.
Inventory models, applications, copilots, and agents.
Map data flows and system dependencies.
Manage human and machine identities.
Control agent permissions and delegated authority.
Secure retrieval-augmented generation systems.
Evaluate third-party models and components.
Threat-model AI applications.
Test models and agents for abuse.
Monitor behavior and output.
Prepare for AI-related incidents.
Integrate AI governance with existing security operations.
Some providers will cover both sides of the transformation. Others should partner with complementary specialists.
Understanding Adversarial Use of AI
Meanwhile, back at the ranch… adversaries are using the same technology to improve their own results. It’s important for any transformation to be real-world ready by understanding how threat actors use AI to improve their own bottom line.
In May 2026, Google Threat Intelligence Group reported a maturing transition from experimental AI-enabled activity toward the industrial-scale application of generative models within adversarial workflows. Its researchers documented AI-assisted vulnerability discovery and exploit generation, defense evasion, malware development, reconnaissance, information operations, autonomous malware activity, and attacks against AI software dependencies [6].
Google also identified a threat actor using a zero-day exploit that its researchers believe was developed with AI assistance. According to the report, the threat actor planned to use the exploit in a mass-exploitation event, although Google’s counter-discovery may have prevented its use [6].
Attackers are not replacing their entire playbook with an evil robot wearing a hoodie. They are using AI as a tool in their arsenal. Defenders need to do the same, while maintaining the controls and accountability that attackers are not terribly concerned about (rude of them, really).
Demand for Expertise Grows as Tooling Becomes More Prolific
This is what I believe the cybersecurity services market needs to understand now. As AI-enabled security tooling becomes more accessible, the tool itself becomes less differentiating. The scarce resource shifts toward people who can determine how the technology should be applied within a particular environment.
A provider that knows how to configure a product can compete on certifications, availability, and price.
A provider that can help a client redesign its security operation can compete on judgment, experience, and outcomes.
The most valuable experts will understand the connections between systems. They will also know where the plan is likely to fall apart when it reaches the people doing the work. That contextual judgment is difficult to automate because it comes from experience. It is knowing that a control may be technically correct, but operationally ignored. It is recognizing that an integration will become an expensive maintenance problem. It is spotting the point where automated containment could interrupt a critical business process and ruin everyone’s Tuesday.
This is systems thinking applied to cybersecurity and it’s in high demand.
The Opportunity
Large consulting firms are already pursuing enterprise transformation work. They have global delivery teams, executive relationships, technology partnerships, and enough PowerPoint capacity to blot out the sun. That does not mean they own the market.
Most businesses are not Fortune 500 enterprises. They still need help adapting to AI-enabled operations and AI-enabled threats. Many cannot afford a large consulting engagement. Others need specialized experience that a broad transformation firm may not possess.
This creates room for:
MSPs that understand a client’s infrastructure and business environment.
MSSPs with deep knowledge of security workflows and recurring operational problems.
Boutique consultancies specializing in identity, cloud, data, application security, operational technology, or governance.
Vertical specialists serving healthcare, financial services, manufacturing, government contractors, or other regulated environments.
Experienced practitioners who have transitioned into independent consultancy.
Small teams that combine technical, operational, and change-management expertise.
Specialization is an advantage here. A ten-person consultancy does not need to become Accenture. It needs to know which transformation problem it is more qualified to solve than Accenture.
Let’s just hope the firms seizing the opportunity here offer more than promises to transform everything after sending two employees to a three-day AI workshop. This is not that.
The Many Flavors of “Security Operations Transformation Service”
To be clear, I do not recommend that service providers rush to tack the term onto their marketing materials in some sort of gold rush. Adding “Security Operations Transformation” to your website sounds impressive, but that is not enough. A real service needs a defined client, a recognizable problem, a repeatable method, specific deliverables, and measurable outcomes.
The service should carry the client from a present state toward a designed future state. Ideally, the provider remains involved through implementation, coaching, validation, or ongoing advisory support.
Taking an ordinary maturity assessment, adding a section about ChatGPT, and calling it transformation will not hold up for long.
Clients are serious about AI spending and return on investment. They will eventually separate firms with transformation expertise from firms that found a new adjective for the same old service.
The Bottom Line
AI technology has exposed how badly cybersecurity expertise is needed. As the tools continue to improve, the difficult work will be deciding where they belong, securing what they change, redesigning the operation around them, and helping the organization move safely from where it is to where it needs to be. That is Security Operations Transformation.
For MSPs, MSSPs, boutique consultancies, and experienced practitioners ready to build an expertise-led business, it may be the most important cybersecurity services opportunity of the next decade.
Resources
[1] Google Cloud, “Agentic AI for security operations,” Google Cloud Security. [Online]. Available: https://cloud.google.com/security/resources/agentic-soc. [Accessed: Aug. 3, 2026].
[2] National Institute of Standards and Technology, “Draft NIST guidelines rethink cybersecurity for the AI era,” Dec. 16, 2025. [Online]. Available: https://www.nist.gov/news-events/news/2025/12/draft-nist-guidelines-rethink-cybersecurity-ai-era. [Accessed: Aug. 3, 2026].
[3] PwC, “New world, new rules: Cybersecurity in an era of uncertainty,” 2026 Global Digital Trust Insights, Oct. 1, 2025. [Online]. Available: https://www.pwc.com/us/en/services/consulting/cybersecurity-data-tech-risk/library/global-digital-trust-insights.html. [Accessed: Aug. 3, 2026].
[4] Ernst & Young LLP, “The AI landscape in cybersecurity,” Mar. 16, 2026. [Online]. Available: https://www.ey.com/en_us/consulting/the-ai-landscape-in-cybersecurity. [Accessed: Aug. 3, 2026].
[5] Accenture plc, “Third Quarter Fiscal 2026 conference call transcript,” Jun. 18, 2026. [Online]. Available: https://investor.accenture.com/~/media/Files/A/accenture-v4/investors/earnings-reports/2026/accenture-third-quarter-fiscal-2026-conference-call-transcript.pdf. [Accessed: Aug. 3, 2026].
[6] Google Threat Intelligence Group, “GTIG AI Threat Tracker: Adversaries leverage AI for vulnerability exploitation, augmented operations, and initial access,” Google Cloud Blog, May 11, 2026. [Online]. Available: https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access. [Accessed: Aug. 3, 2026].



