Timothy Liu is the CTO and cofounder of Hillstone Networks.
Extended detection and response (XDR) is a cybersecurity solution that has exploded in adoption over the past several years. While the category is undeniably hot and projected to produce nearly $9 billion in global revenue by 2028 (up from $1.7 billion today), opinions differ on XDR when it comes to landing on a standard definition of its core capabilities and place in the value chain of cybersecurity efforts.
In 2020, Gartner defined XDR as “a unified security incident detection and response platform that automatically collects and correlates data from multiple proprietary security components.” That was only three years ago, but a lot has changed since then.
The Rise Of XDR
There is a running joke in the cybersecurity industry about the ever-expanding “alphabet soup” of product category initialisms that are in the market. The reality is that it’s more like an “alphabet sea.”
XDR, in particular, is the categorical expansion of the mature solutions in network detection and response (NDR) and endpoint detection and response (EDR). With responsibility for devices (endpoints) and connectivity (networks) often siloed inside organizations, there became a need to unify these technologies and to normalize their data to make it intelligible and actionable for the security teams who are tasked with keeping an organization safe.
Thus, XDR, yet another cybersecurity initialism, was born. In short, XDR is the poster child for an industry that has a remarkable knack for developing new solutions to the problems its old solutions helped create.
What AI Means For XDR
If normalizing data and making sense of it sounds like an incessantly daunting and monotonous task, that’s because it is, especially at enterprise scale and internet speed. But there’s a new kid in town who actually loves this stuff. This kid never gets tired, and they seem to know the answer to any question you ask them, even the really hard ones.
That “kid” is artificial intelligence (AI).
By now, we have all experienced how AI has taken the world by storm, and this is especially true in the technology industry. For every consumer-facing AI application, be it for novelty or productivity, there are dozens of others designed specifically to expedite the deeply technical work that goes on behind the scenes in developing modern technology solutions.
The AI arms race is in full swing, and we now have AI “co-pilots” delivering everything from software code and quality assurance to full-scale media campaigns that are scheduled, analyzed and optimized in near real time.
Predictably, adversaries are now using AI as well to harm companies by identifying and exploiting new and novel vulnerabilities. They are finding these utilizing the same public large language models (LLMs) that everyone else uses for more mundane purposes.
This changes the game completely. Before AI, threat actors often relied on a tedious combination of hands-on hunting and programmatic vulnerability detection. They can now prompt a single interface to identify the weaknesses in infinite combinations of code, inputs and conditions.
When an adversary’s computational and analytical power is based on the collective knowledge and data that makes up what is essentially the entire history of the information economy, it is difficult to rationalize a cybersecurity countermeasure like XDR that is limited by design to communicate only with other security products.
What’s Next For XDR
This is where we are. The darling category of the cybersecurity industry, designed to turn disparate point solutions into a Swiss Army knife of defense, is itself at risk of becoming a point solution thanks to AI.
So, where does XDR go from here? It’s hard to know for sure, but one thing is certain: For traditional XDR to retain its spot on the podium, it’s going to need access to a lot more data—fast.
Collaboration between the large AI and cybersecurity vendors might facilitate this, and it could potentially tilt the scales in the defenders’ favor if the parties could agree to some form of early warning exchange on AI discoveries of new and novel threats. That would really be something. That said, this option might not be feasible when players in the AI space also have their interests in the cybersecurity space. In other words, I wouldn’t hold my breath for much altruism there.
What we do know is that point solutions are dead and that our industry’s attempts to extend their functionality have now been outmaneuvered by AI. The truth is, we are in a bold new world having to fight back against AI, and no one knows what that will look like or be called just yet. But time will tell. Since we love our initialisms, I’ll just say that AIDR has a nice ring to it.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

