The common language putting AI to work in cybersecurity
The cybersecurity industry has spent years adding tools to defend increasingly complex digital environments. The result, however, has often been a technology stack that generates as much operational friction as protection.
The average organisation operates 83 security tools supplied by 29 vendors, according to a 2025 study from the IBM Institute for Business Value. Each product has its own way of describing users, devices and processes. A laptop might be identified as a host by one platform, an instance by another and a device by a third. For security analysts, this inconsistency creates a significant translation burden: before they can determine whether an event is malicious, they must establish whether different records refer to the same asset or activity.
The Open Cybersecurity Schema Framework, or OCSF, is designed to remove that burden by giving security products a common language. As artificial intelligence changes the speed and nature of cyber operations, this standardisation is becoming more than an efficiency measure; it’s emerging as a prerequisite for effective automation.
From fragmented data to operational intelligence
OCSF is an open, vendor-neutral framework that standardises how security events and objects are described. Vendors map their data to a shared model, allowing events such as logins and process launches to be represented consistently, regardless of their source. This tackles the problem of ‘schema drift’, in which small differences in terminology and formatting accumulate across a security environment. Those differences slow investigations and force detection engineers to maintain multiple versions of essentially the same rule.
Across hundreds of detection rules, the cost mounts quickly. Skilled staff spend their time maintaining integrations rather than finding threats.
OCSF allows a rule to be written once and applied across endpoint, cloud, identity and network data. Analysts can begin with the behaviour under investigation, rather than first deciphering how each product has labelled it.
The timing is important as the age of AI is bringing an end to the security operating model that has prevailed for much of the past decade. Attackers can increasingly operate at machine speed, making machine-speed defence essential. However, automated defence can only be as reliable as the information on which it acts. An AI agent supplied with fragmented, inconsistent telemetry inherits every weakness in that data: it may make incorrect decisions faster than the human analyst it was intended to support. By contrast, an agent receiving normalised, de-duplicated and intelligence-enriched information begins with context rather than a cold look-up.
This is the practical meaning of operational intelligence: information that has already been made useful before it reaches a human analyst, an autonomous agent or an agent operating under human supervision.
Fixing the problem at the point of entry
A key distinction is whether security information is normalised when it enters an organisation’s environment or translated later, when somebody runs a query.
Many businesses currently send raw data into a security information and event management (SIEM) platform or data lake and normalise it afterwards. While this can work, it means searches and detection rules must repeatedly carry the logic needed to reconcile different formats. OCSF-native ingestion converts each source into the shared schema as soon as the data arrives. The translation happens once, after which every investigation and detection rule can refer to the same fields.
Removing duplicates before information reaches storage keeps the dataset closer to what actually occurred. Queries have less material to scan, while analysts and AI systems can focus on distinct activity rather than repeated alerts.
Standardising the container, not the cargo
Adopting OCSF does not require an organisation to replace its existing security products. Endpoint, cloud, identity and network platforms continue to operate as before: the framework governs the shape of the data they produce, not the tools themselves.
The principle resembles the standard shipping container. Rather than dictating what companies transported, containerisation created a common format that could move efficiently between trucks, trains and ships. OCSF aims to provide the equivalent container for cybersecurity data, allowing an event to move from detection to threat hunting, analytics and AI without being repeatedly unpacked and translated.
The framework has also developed beyond its single-vendor origins. It began with 18 founding companies and, by the time it joined the Linux Foundation in November 2024, involved more than 200 organisations and 900 contributors. Participants include technology vendors, enterprises and government agencies with AWS, Cisco, IBM and Splunk among the contributors.
|
Neutral, community-based governance is important because a common security schema will deliver lasting value only if organisations trust that it will not become another source of vendor lock-in. As businesses add cloud platforms, security products and telemetry sources, OCSF can turn each new connection from a bespoke integration project into a more straightforward mapping exercise. The larger prize is a security foundation capable of supporting both people and machines. |
![]() |
Shorter certificate lifespans are a warning shot for quantum readiness
Certificate lifespans and quantum readiness are not really two separate initiatives, even though...
Autonomous AI agents increasing data risks: report
AI systems surfacing sensitive data to unauthorised users are now the second most common form of...
Why the Five Eyes AI warning should change the Board's cyber agenda
If you don't test your identity recovery in a real-life crisis scenario, you are...

