Accrued Accuracy: Building Trust in the Age of Agentic Cyberdefense

Related

Share

The margin for error in security keeps shrinking. Attackers now use AI to find weak spots faster, exploit them at scale and keep probing until something gives. Defenders, meanwhile, are buried in data. Every alert is a decision, and every decision is a chance to get it wrong.

That’s why accuracy is the single most important factor in defense. Teams rely on the people and systems that get it right under pressure. When those systems slip, companies face real business and reputational risks. 

Everywhere else, we’re handing work to AI

Outside of security, most of us have gotten comfortable letting AI move fast for us. We send AI-drafted emails after a quick skim. We check a health question, read a short answer and get on with our day.

Companies are doing the same thing at a much bigger scale. Agentforce has handled 4.3 million inquiries on the Salesforce support page and resolved 70% of them. 90% of ServiceNow internal IT support requests are now handled autonomously. For many business functions, that’s a fair trade when a misrouted ticket is cheap to fix.

Security works differently, because the cost of a mistake is huge. Acting on a benign alert means downtime that can cost millions, and the opposite is worse: missing a true positive means game over. Attackers design their moves to look normal, and they adapt the moment a team responds. Leaders need to trust their security system to get it right. An AI that still hallucinates is a liability, and a risk no company can take. As the price of every error keeps climbing, it makes sense that people trust AI less with anything related to security.

62% of cybersecurity professionals reported high levels of concern about over-reliance on AI recommendations, and 61% about undetected errors that could scale rapidly across systems.

In security, trust means knowing an agent can act inside a company’s environment without disrupting the business or opening new gaps.

Meeting that standard demands accuracy at every step. Handing a generic AI agent the call on revoking someone’s access, blocking traffic, quarantining a laptop or pulling a server offline creates serious risk. When a support bot gets it wrong, the result is an awkward email. When a security agent gets it wrong, it can bring the business to a halt. Employees can’t work, customers can’t get served, and the hit to business continuity can last long after the incident.

To avoid that outcome, many security teams still keep a human in the loop. However, while it may limit the damage if an AI agent goes rogue, waiting has a cost too. Attackers can go from a foothold to real damage in minutes, and if every response waits for a human sign-off, it may arrive too late. What teams need is an accurate response that arrives in time and scales across the organization.

The speed part is getting easier. AI can already reach a verdict on an alert in seconds. Reaching the right verdict, and acting on it without breaking something the business relies on, is much harder. That accuracy gap is the most urgent problem in security right now, and the biggest opportunity.

Closing the accuracy gap is the reason we invested in CPR, a framework built by Inbal Argov, our VP of Product Strategy. CPR turns accuracy into three checks, and an agent has to pass them before it acts without a human:

Confidence. It looks at how sure the agent is about its conclusion, measured against that agent’s actual track record on similar cases.

Precision. It looks at how surgical the action is. A precise response revokes a single session and leaves the account alone. It blocks one URL and keeps the domain open. It isolates one host while the rest of the network keeps running.

Reversibility. It asks whether the action can be undone. If a step can be rolled back in a few minutes, it’s far less risky than one that’s permanent.

Together, the three checks weigh the risk of acting against the risk of waiting. Doing nothing is a decision too, and a slow response to a real attack carries its own cost. An agent acts on its own only when acting is the safer choice, so teams are no longer stuck choosing between speed and safety.

Accuracy depends on context

All three checks run on context. Accuracy comes from seeing each alert within the full picture of the organization around it. Once an agent understands what it’s touching, it can pick the right action. That’s where most AI falls short today. In our own testing on real customer cases, generic AI got to the right answer about 60% of the time. With Mate’s context, agents judged those same cases far more accurately, and the number climbed to about 97%.

At Mate, that context comes from our Security Context Graph, a living model of an organization’s security. It shows who owns each asset, what depends on it, which systems are critical, which identities have elevated access and which policies apply. With that picture, an agent can see the blast radius of an action before it does anything.

Building the Security Context Graph was a priority from day one. When we started Mate, we knew enterprises would need security tools that move faster and also make the right call. We believed that a solid foundation would bring value to the entire SecOps quickly and with high quality.

We built Mate as a foundation for security defense the way Claude was built for coders: for the full scenario from day one. Nobody built a Claude for databases or a Claude for web apps. Those silos would produce bad code. We built Mate to be a single defense loop from day one.That foundation matters because security leaders are being handed an impossible job. Be accurate all the time. Move fast. Don’t put the business at risk. Adopt new technology before attackers do.

Those security and business requirements pull against one another. Going faster leads to more mistakes. Playing it safe means falling behind. Most companies end up picking one and living with the downside of the other. That’s not a trade we can afford to make in a world with AI-powered attacks. With the right checks and the right context, the question becomes when an AI agent has earned the right to act on its own, and how far it should go.

Attackers aren’t going to slow down, and AI is going to take on more of the work of defending the business. The leaders who handle this well will hand over control gradually. They’ll give agents more room as those agents prove they can be trusted with it. Every accurate call builds on the last, and that accrued accuracy is what earns an agent the right to act.

Asaf
CEO & Founder at  | Website | + posts

Asaf Wiener is the CEO and Co-Founder of Mate Security, which develops AI agents for security operations. Previously, he led vulnerability management at Wiz and helped develop Microsoft Defender Vulnerability Management into a standalone product. His background spans cybersecurity product development, cloud security, and vulnerability management, with a focus on applying AI to security investigations and response.