As the number of potential security vulnerabilities continues to outpace available cybersecurity resources, Deutsche Telekom has evaluated how artificial intelligence can be integrated into existing security processes to expand the scope of security assessments. The project focused on scaling established testing methods rather than replacing conventional security practices.
Cybersecurity teams are facing increasing pressure as IT environments become more complex, software development cycles accelerate, and organizations manage a growing number of internet-facing systems. At the same time, the volume of potential vulnerabilities continues to rise faster than available personnel resources. As a result, many organizations are forced to prioritize security assessments, limiting comprehensive testing to selected systems or specific projects. Against this backdrop, Deutsche Telekom has evaluated how modern AI models can extend existing security processes without replacing established methodologies.
The project centered on integrating GPT-5.5 Cyber into partially automated security workflows. Rather than delegating security decisions to artificial intelligence, the objective was to determine whether proven assessment methods could be applied across significantly larger environments without increasing staffing requirements or project duration at the same rate. According to the company, AI is intended to complement existing expertise by improving the scalability of established security practices.
One area of focus involved the analysis of internet-exposed systems. In this use case, the AI model supported the organization’s Red Team in evaluating externally accessible endpoints within the corporate infrastructure. Besides validating suspected vulnerabilities, the analysis identified additional attack paths and potential risk scenarios that might have remained undetected during more narrowly focused assessments. The principal benefit was not a single analysis but the ability to perform the same methodology across a much larger number of systems.
A second application concentrated on source code analysis within GitLab repositories. Thousands of lines of code from products and services were automatically examined for potential vulnerabilities, security-relevant patterns, and potentially malicious content. Whereas comparable reviews had previously been performed primarily for individual projects or specific incidents, the AI-assisted approach enabled a much broader examination of existing software assets. This provided security teams with a more comprehensive inventory of relevant code while allowing risks to be identified during normal operations rather than only during formal audits or after specific concerns had been raised.
The project also highlighted a practical consequence of expanding security assessments: broader analysis inevitably produces a larger number of findings. According to Deutsche Telekom, the challenge therefore shifts from identifying additional issues to managing them efficiently. Organizations seeking to scale security analysis must also strengthen downstream processes, including vulnerability management, patch management, documentation, and risk assessment, so that additional findings can be evaluated, prioritized, and addressed within operational security workflows.
“Today, large organizations face the challenge of securely operating vast amounts of infrastructure, applications, and code. AI can help conduct security audits more broadly and frequently than has been possible until now. The key is to translate the insights gained into robust processes,” says Jasper von Hoersten, Solutions Engineering Manager, Enterprise at OpenAI Germany.
“Our goal was not to replace existing security procedures with AI. The key question was whether we could apply established testing processes more broadly without having to increase resource requirements to the same extent. The results are very promising. They provide insight into how follow-up processes would also need to be optimized to reap the maximum benefit from this efficiency,” says Thomas Tschersich, CSO of Deutsche Telekom.
“Advances in AI enable companies to expand security analyses to significantly larger environments. However, the decisive factor remains integration into existing security processes. Assessing risks and deriving concrete measures still require the expertise of experienced security teams,” says Tschersich.
Looking ahead, increasingly capable AI agents may support subsequent stages of remediation by proposing code modifications, preparing software patches, and validating compliance with security and quality requirements. Nevertheless, Deutsche Telekom emphasizes that experienced security professionals remain responsible for evaluating risks and making operational decisions. In this context, artificial intelligence is viewed as a means of extending human expertise rather than replacing it. As cyber threats continue to evolve and organizations face ongoing shortages of cybersecurity professionals, scalable security processes may become an increasingly important element of enterprise security strategies.

Dr. Jakob Jung is Editor-in-Chief of Security Storage and Channel Germany. He has been working in IT journalism for more than 20 years. His career includes Computer Reseller News, Heise Resale, Informationweek, Techtarget (storage and data center) and ChannelBiz. He also freelances for numerous IT publications, including Computerwoche, Channelpartner, IT-Business, Storage-Insider and ZDnet. His main topics are channel, storage, security, data center, ERP and CRM.
Contact via Mail: jakob.jung@security-storage-und-channel-germany.de
