bg
Cybersecurity
07:51, 29 September 2026
views
3

Staffcop to Launch AI Tools for Cyber Incident Investigations

They are expected to help identify vulnerabilities by pointing to potential weak spots in an organization’s defenses.

Artificial intelligence is playing an increasingly important role in information security. Algorithms can analyze large volumes of data and speed up responses to attacks. Another promising use is incident investigation.

Focus on Context

Recently, Staffcop, a company within the Kontur ecosystem, announced the upcoming release of AI tools for information security professionals. The tools are intended to help analyze data and test hypotheses during cyber incident investigations. Crucially, the system is designed to understand context. Users will be able to phrase queries in plain language, while the algorithms will search not only for exact matches but also for events that are similar in meaning.

This approach addresses one of the most difficult problems in incident investigations. Investigators do not always know the exact indicators they need to search for – facts, information or digital traces. When those indicators are known, they can be encoded in policies by setting keywords and other conditions. It becomes much harder when an investigator has only a hypothesis and the relevant signal is buried in a large volume of events and is difficult to describe in advance as a formal set of rules.

Tailored to Specific Tasks

LLM policies will handle the data analysis. They will be able to identify topics, sentiment, behavioral patterns, communication intent and entities in messages. The developers plan to build in several possible ways to use the algorithms. If needed, customers will also be able to adapt the models to their specific tasks.

“Users will be able to work with the results through a chatbot. For example, they could request messages from the past week on a particular topic or find messages showing signs of aggression. The system will turn the question into a query against Staffcop data and generate the results. From there, users will be able to open the original event and examine it in context,” the developers say.

At the same time, the AI will not independently determine whether a violation has occurred. Its role is specifically to assist people and narrow the search. The final decision will always remain with the information security professional.

Support for Third-Party AI Models

The AI component will be deployable within a customer's infrastructure, including an isolated environment if the necessary computing resources are available. The architecture can connect compatible language models, including models already deployed within a company's infrastructure.

Deploying these AI tools is particularly significant for Russia's information security market. The sector faces a substantial shortage of qualified professionals, and tools like these can help address that challenge. This is especially relevant for large organizations that need to analyze huge volumes of information, where an overloaded human analyst could miss something important.

Expanding Use of AI Algorithms

The use of large language models in cybersecurity has been expanding since 2024. Initially, AI was configured to analyze events and generate threat descriptions. Such systems were not limited to companies specializing in data protection. For example, VK began developing AI models to counter DDoS attacks and bot activity. The AI was intended to distinguish malicious traffic from genuine spikes in activity on the platform.

A new trend emerged in 2025. According to UCSB and Solar Group, up to half of Russian companies were concerned about data leaks resulting from the use of AI tools. Businesses identified the main source of risk not as weak technical defenses but as a lack of internal policies and inadequate staff training. Against this backdrop, demand also grew for tools that could automatically identify and prevent potential threats.

The launch of Staffcop's technology addresses the market's growing demand for cybersecurity automation. Now, what organizations need are intelligent assistants that can quickly process large volumes of information and point to vulnerable areas. This reflects a broader approach to AI: rather than replacing people, it should serve as a tool that supports human decision-making.

During an investigation, it is not always possible to create a complete set of rules in advance that will lead to the event you are looking for. Sometimes a security professional starts with nothing more than a hypothesis that needs to be tested against a large volume of data. We want to shorten that path: let users give Staffcop a task in ordinary language, find the events related to it, and then investigate those events in context. The AI does not investigate the incident instead of the professional. It helps them understand where to look more quickly
quote
like
heart
fun
wow
sad
angry
Latest news
Important
Recommended
previous
next