Back to blog

We Built Walls to Stop Hackers. So Why Are They Still Getting In?

How machine learning is changing the way we detect cyber-attacks.

6 min read
A glowing digital wall cracked by red attack lines in front of a network of servers, with the text “We built walls, but still hackers get in. How?”

We Have Been Building Walls for Years

Firewalls, antivirus software, intrusion detection systems, passwords and access controls have been protecting our digital systems for years. We built these layers of security to keep attackers out, and they are still an essential part of cybersecurity today.

But there is a problem.

“What happens when the attack doesn't look like something we've seen before?”

A new malware variant might not match a known signature. A stolen account might initially behave like a legitimate user, and a zero-day attack may have no existing rule telling a security system that something is wrong.

This is where machine learning starts becoming useful.

From "Do We Know This Attack?" to "Does This Look Wrong?"

Traditional security often relies on predefined rules and signatures to identify known threats. If an incoming activity matches something already classified as malicious, the system can block it or raise an alert.

Flowchart: incoming activity is checked against known threats; a match leads to Block, no match leads to Allow.
Figure 1. Traditional, rule-based security decision flow.

Machine learning adds another question:

“Does this behaviour look unusual?”

For example, imagine an employee who normally logs in from one location and accesses five applications during a working day. Suddenly, the same account logs in from an unusual location, accesses many systems and downloads thousands of files.

There may be no known attack signature associated with this activity.

But the behaviour is different.

Diagram comparing normal behaviour (login, apps, files) with a sudden change (login, many applications, huge download) that is flagged as an anomaly and triggers an alert.
Figure 2. Normal behaviour compared with a sudden change that triggers an alert.

This is one of the main ideas behind ML-based security: instead of looking only for known attacks, systems can also learn patterns of normal activity and identify behaviour that significantly deviates from those patterns.

So Where Is Machine Learning Being Used?

Research shows that machine learning is being explored across many areas of cybersecurity, from detecting attacks to analysing user behaviour and identifying potentially vulnerable systems.

Some important applications include:

  • Intrusion Detection — identifying unusual network or system activity that could indicate an attack.
  • Malware Detection — analysing files and behaviour to identify potentially malicious software.
  • Phishing Detection — finding patterns associated with malicious emails, messages and websites.
  • User Behaviour Analysis — detecting unusual login, access or usage patterns.
  • Vulnerability Detection — helping identify potentially weak areas in software and systems.
  • Threat Intelligence — processing large amounts of security information to identify useful patterns and indicators.

A 2026 comprehensive review analysed more than 81,000 cybersecurity and machine learning publications, showing how rapidly this research area has grown.

But Here's the Catch

If machine learning can detect things humans might miss, does that mean we can finally automate cybersecurity?

Not quite.

Diagram of three problems in ML security: bad data leading to poor results, false alarms leading to alert fatigue, and adversarial attacks leading to model manipulation.
Figure 3. Three recurring problems in ML-based security systems.

Bad Data

Machine learning learns from data, so the quality of that data directly affects the quality of its decisions. If the training data is incomplete, noisy, biased or unbalanced, the model can learn the wrong patterns.

False Alarms

A security model that constantly says "ATTACK!" is not very useful if most of those alerts are actually harmless. Security teams still need to investigate the results and determine which alerts represent real threats.

The AI Can Be Attacked Too

This is perhaps the most interesting part.

Attackers can attempt to manipulate the inputs or data used by an ML system so that the model makes an incorrect decision. This area, known as adversarial machine learning, has become an important part of cybersecurity research.

So now we have another problem:

“We're not only protecting the system. “

“We also have to protect the system that is protecting the system.”

So, Are Firewalls Becoming Useless?

No. That's not what the research suggests.

The real change is that security is becoming more layered, with traditional security controls working alongside intelligent detection and human decision-making.

Diagram of layered security: traditional security (firewall, MFA, patching), ML detection (anomaly, malware, behaviour) and human expertise (analysis, decisions, response) combining into a stronger defence.
Figure 4. A layered defence combining traditional security, ML detection and human expertise.

A firewall can control network traffic. An ML model can identify unusual behaviour that may not match a predefined rule. A security analyst can then investigate the alert and determine whether it represents an actual threat.

Each layer solves a different part of the problem.

And this idea becomes even more important as software systems themselves become more intelligent.

What Happens When the System Being Protected Can Also Take Action?

Consider a modern AI application.

An AI agent may have access to company information, APIs, databases, tools and business workflows. At that point, security is no longer only about blocking an attacker at the network boundary.

You also need to ask:

“Who can access the agent?”

“What can the agent access?”

“What actions can it perform?”

“Can someone review a sensitive action before it happens?”

“Can we see what happened after the action was taken?”

This is where platforms such as A Realtime Tech (opens in a new tab) approach the problem from another direction.

Its platform brings AI agents, workflows, business systems and real-time events together while providing controls such as scoped access, governance, human approvals and execution traceability. In other words, the goal is not only to make an AI system capable, but to make its actions more controlled and observable.

Flowchart: a real-time event reaches an agent, whose AI decision passes a policy and access check leading to allow, warn or human review, followed by the action and an audit trace.
Figure 5. A simplified view of how intelligent actions can be controlled before and after execution.

This is an important evolution in security thinking: detection is only one part of the problem.

When intelligent systems can actually perform actions, access control, governance, human oversight and observability become equally important.

The Bigger Picture

The important shift isn't simply:

“Traditional Security → AI Security”

It is closer to:

“Known Threats → Known Threats + Unusual Behaviour”

And as AI systems become capable of taking actions, the question expands again:

“Can we detect something unusual?”

becomes:

“Can we control what an intelligent system is allowed to do?”

Machine learning gives security teams another way to look at what is happening inside their systems. Modern AI platforms add another layer by controlling how intelligent systems access information, use tools and execute actions.

Instead of only asking:

“Have we seen this attack before?”

we can also ask:

“Does this look like something that shouldn't be happening?”

and eventually:

“If something goes wrong, can we see it, control it and understand what happened?”

That doesn't eliminate attackers, and it doesn't make firewalls or other traditional controls unnecessary.

But it gives defenders more than another set of eyes.

It gives them more ways to detect, control and understand what is happening.

Conclusion

We built walls because we needed to keep attackers out, and those walls are still an important part of cybersecurity. But modern systems are becoming too complex to rely only on predefined rules describing attacks we already know.

Machine learning helps by looking for patterns, anomalies and behaviours that may not have been explicitly defined beforehand. At the same time, intelligent systems introduce new challenges around data quality, false alarms, adversarial attacks, access and control.

The future of cybersecurity isn't about replacing the walls.

It's about making the entire defence system smarter — and making sure we can still control what happens behind those walls.

Sources and further reading

About the Author

Adithya Sapalya

AI Engineer

An AI Engineer who combines AIML engineering, GenAI, and cybersecurity to build practical agentic systems and intelligent automation that turn complex ideas into real-world solutions.

View on LinkedIn (Adithya Sapalya, opens in a new tab)

Further Reading