All articles

Security Tool Sprawl Is Turning Blue Team Defenders Into Modern 'Script Kiddies'

The Security Digest - News Team
Published
July 23, 2026

Benjamin Glover, Manager of Information Security at Cumulus Media, argues that defenders who stack tools they can't explain are losing the judgment real resilience requires, and draws a hard line on how far AI should reach into the SOC.

Credit: The Security Digest

Make The Security Digest one of your go-to sources on Google

Add The Security Digest on Google

In the early 1990s, a script kiddie was someone who did not know how to hack but knew how to run scripts. I am seeing security professionals become modern-day script kiddies, except instead of scripts, they are pushing buttons in tools they do not understand.

Benjamin Glover

Manager of Information Security

Benjamin Glover

Manager of Information Security
Cumulus Media

Every new threat ships with a matching platform, and every platform adds another portal to check. Under the stack, the ability to explain how any of it works erodes. One blue team leader argues defenders are trading away the judgment that real resilience runs on.

Benjamin Glover is Manager of Information Security at Cumulus Media, one of the largest audio media companies in the United States. A CISSP who worked up from security analyst to running the program, he sees the platform obsession from the defender's seat, where it looks like liability dressed as maturity.

"In the early 90s, a script kiddie was a person who didn't know how to hack but knew how to run scripts. I'm seeing a lot of security professionals turning into modern-day script kiddies, but instead of scripts, it's tools. They don't understand the back end of what the tool is doing, and that's really hurting our profession," Glover says.

Where the risk meets reality

His answer starts before the purchase order. "The first thing I look for in any tool is whether it's going to create another management plane," he says. "Is this another portal my team has to check every day? If so, that rules it out automatically." Whatever clears the tool sprawl filter still has to fit the attack it claims to stop. "You have to understand the workflow of the risk before you can create an interceptor to it. Risk is a missile aimed at your organization. You have to know where in the arc to put your interceptor to knock it out of the air."

Automated scoring fails the same test. "I've seen a ton of these AI vulnerability management platforms. It's a 9.8, okay, cool. But I've got to have 50 different things happen in my environment, and the attacker has to control 49 of them already. If they have those 49, the 50th doesn't really matter." Severity without context is noise, which is why risk-based prioritization keeps displacing raw scores.

Hit it off at the gate

The same discipline applies before AI enters the environment: policy first, change management behind it, and a real route for employees to request new tools. "If you think AI is going to enter your realm, create a comprehensive policy for usage of those applications. Hit it off at the gate instead of letting users take the lead on what's allowed in," Glover says. Skip that release valve and the outcome is guaranteed. "They're going to bypass your systems no matter what kind of controls you have in place."

He points past AI too, from zero trust checks on every request to post-quantum cryptography ahead of harvest now, decrypt later campaigns.

Never give the robot the knife

On agentic security, Glover splits the SOC workflow cleanly. Enrichment is automation wherever it originates. "It doesn't matter if the LLM is pulling from Shodan or my analyst is pulling from Shodan. Shodan has that same information. URLScan has it. Joe Sandbox has it."

Remediation is a different matter. "I am not giving a robot a knife. Type three different questions into an LLM and you're going to get three different answers every time. You can't have three different answers in a security incident. There needs to be one answer." The gap widens with everything an agent can't see. "Maybe I got a call 30 minutes ago and this user is actually in Panama, and the AI thinks it's a malicious attacker. I don't want it disabling their account. Or engineering is testing a new script. I don't want that computer isolated off the network."

The pattern holds across AI in the SOC, from the last mile between recommendation and action to the hardening case for keeping irreversible remediation under human control. Standards bodies are drafting trust frameworks for autonomous agents.

Apprenticing the next generation

His biggest worry sits a decade out. Vendors building the AI-native SOC concede analysts aren't going anywhere, yet the restructuring reshaping security teams keeps trading this quarter's savings for the profession's bench. "If you don't have any Tier One people, you're never going to get Tier Two or Tier Three people. What's going to happen in 10 or 15 years when you're not apprenticing the next generation?"

Glover keeps a reminder against overestimating the technology, a tongue-in-cheek paper that builds a neural network inside Age of Empires II to puncture the habit of seeing humanity in machines. "AI is able to translate. That's all it's able to do. It will look at things humans have done, but it will not do things humans have not thought of doing," he says. "As long as that light of human creativity shines, AI is never going to take over."