Lesson 1 of 4
Where AI helps a security team
Summarising, enriching and drafting, versus deciding — and which is which.
14 min 3-question quiz 3 guides to read next
The useful frame is not "can AI do security" but "which parts of this work are language problems, and which are judgement calls with consequences".
Where it earns its place
Summarising and translating. Turning a long alert chain, a packet capture summary, a PowerShell blob or a vendor advisory into something an analyst can read in thirty seconds. Low risk: a wrong summary is noticed by the person reading the underlying data.
Enrichment. Pulling the context an analyst would have gathered by hand — asset owner, recent changes, related tickets, what this host normally does — and putting it beside the alert.
Drafting. Detection rules, queries, timelines, incident notes, customer notifications. The analyst still reviews, but starts from something.
Searching unstructured material. Documentation, past incidents, policies, threat intel. Retrieval over a corpus a team already has is the most reliably valuable application in this list.
Where it does not
Final decisions with consequences. Blocking an account, isolating a host, closing an alert as benign. A model that closes alerts will eventually close the real one, and nobody will know until later.
Anything requiring a guarantee. "Did we see this indicator anywhere in the estate" is a query, not a question for a model.
Novel attacker behaviour. Models are good at things resembling what they have seen. Genuinely new behaviour is exactly the case where they are confidently wrong.
The pattern that works
AI proposes, a human disposes, and the proposal comes with its evidence. The analyst sees the summary and the alert, the draft rule and the data it was built from. The time saved is real, and the failure mode is a wasted minute rather than a missed intrusion.
One more thing to decide early: what you send to a provider. Alerts contain hostnames, usernames, file paths and sometimes the contents of documents. That is a data-flow question for the security team itself to answer, preferably before the pilot.
Check your understanding
3 questions · pass with 2 correct
Enrol for free to save your progress, unlock every lesson and earn a certificate.
Sign in to enrolFurther reading
Guides that go deeper on this lesson.
-
AI-Powered Cyber Attacks
How attackers use AI to scale phishing, find vulnerabilities and automate attacks, and what it means for defenders.
1 min read
-
Security Awareness for AI Users
What every employee should know about using AI tools safely: data handling, verification and spotting AI-enabled scams.
1 min read
-
Data Leakage to AI Providers
Managing the risk of sensitive data reaching third-party AI services through employees and applications.
1 min read