By Kerissa Varma, Chief Security Advisor at Microsoft Africa
The defining cybersecurity challenge of the AI era is not intelligence, but autonomy. As African organisations embrace agentic AI, assumptions that have shaped security strategies for decades are beginning to break down. Security teams have traditionally defended against attacks powered by human decision-making and speed. But AI agents can reason, adapt and act independently. In a world where cyberthreats operate at machine speed, organisations must rethink not only what they protect, but how they protect it.
For African businesses, autonomous AI is no longer a distant prospect. Agents are proliferating in sectors such as financial services and logistics, and 82% of African respondents to an MIT Sloan Management Review and BCG survey said they viewed agents more as colleagues than tools. Private-sector adoption in countries such as Kenya, Nigeria and South Africa is advancing faster than AI policies and governance frameworks can evolve, leaving organisations to navigate an increasingly complex risk landscape. In a recent Dark Reading survey, almost half of respondents identified agentic AI as the single most dangerous attack vector facing modern infrastructure.
The challenge is not only that organisations are deploying autonomous systems faster than governance can evolve. It is that they are doing so as cyberthreats themselves become increasingly autonomous. The very physics of cybersecurity is changing. Attackers can now use AI to lower the cost of offence, generating exploits faster, scaling campaigns further and operating with unprecedented efficiency. Meanwhile, the volume, velocity and complexity of what must be secured continue to grow. Approaches built for human actors cannot keep pace with AI agents and machine-speed attacks.
For African organisations, the question is no longer how quickly they can adopt AI, but whether their security can evolve at the same pace.
Security needs a new operating model
The answer is not simply to add more AI to existing workflows. It is to redesign security around a cyber stack built for autonomy. Signals and sensors create awareness across the digital estate; security context turns those signals into usable understanding; models supply intelligence and reasoning; and a harness coordinates models and agents across security workflows. Agents then apply that intelligence, while actuators translate decisions into protection. Together, these layers form a continuous learning system that can understand risk, adapt to change and improve security outcomes over time.
Context turns data into decisions
Of all the layers in this new security model, context may be the most important. Raw signals from identities, devices, applications, data flows and user activity can reveal unusual behaviour, suspicious activity or emerging threats, but they rarely explain why those events matter or how they connect to broader organisational risk.
For autonomous security systems to make sound decisions, they need a shared, continuously updated understanding of the environment they are helping to defend. By connecting identities, devices, applications, data and activities into a coherent picture of risk, security context enables AI agents to distinguish normal behaviour from genuine threats, prioritise action and reason more accurately. Rather than continuously gathering and correlating information from disparate sources, agents can operate with a near real-time understanding of the organisation, improving the quality of decisions while reducing the time, compute and cost required to operate at scale.
Intelligence must be matched to the task
Context provides the foundation for sound decision-making, but effective security also depends on applying the right intelligence to the right problem. Investigating a suspicious sign-in, analysing malware or assessing a complex attack path each demands different forms of reasoning, expertise and speed.
Rather than relying on a single model, organisations need a flexible, multi-model architecture that can apply the most appropriate capability to each task while balancing quality, reliability, responsiveness and cost. This is particularly important in security, where protection must operate continuously and at scale. By taking this approach, businesses can strengthen outcomes today while retaining the flexibility to benefit from future advances in AI, without having to rebuild their security architecture every time the technology evolves.
Actuators turn insight into protection
Applying the right intelligence to the right problem is only valuable if it leads to action. Security teams do not need more alerts. They need better outcomes. This is where actuators become a critical part of the cyber stack, giving organisations the ability to translate intelligence into action.
By connecting detection, decision-making and response, actuators help organisations move from simply reporting risk to continuously reducing it. This allows routine measures to happen faster and more consistently, while defenders remain in control and focus their expertise where it adds the most value.
Trust must be built in from the start
Every layer of the cyber stack ultimately depends on trust. As organisations introduce greater autonomy into security operations, safety, governance and accountability cannot be treated as afterthoughts. They must be designed into the architecture from the outset. This means establishing clear guardrails around how AI systems operate, ensuring decisions can be explained and audited, and maintaining strong oversight of data, access and compliance requirements.
The age of agentic AI presents African organisations with a choice. They can apply yesterday’s security models to tomorrow’s technology, or they can build security, trust and resilience into autonomous systems from the start. Those that act now can turn security from a constraint into the foundation for faster innovation, greater scale and stronger competitiveness.
Kerissa Varma is Microsoft’s Chief Security Advisor for Africa and Founder and President of Women in Cybersecurity (WiCyS) Southern Africa. She has more than 20 years of experience helping organisations strengthen cyber resilience and security leadership.