Skip to content

Lesson 1 of 4

Free preview

Where AI helps a security team

Summarising, enriching and drafting, versus deciding — and which is which.

14 min 3-question quiz 3 guides to read next

On this page
  1. Where it earns its place
  2. Where it does not
  3. The pattern that works

The useful frame is not "can AI do security" but "which parts of this work are language problems, and which are judgement calls with consequences".

Where it earns its place

Summarising and translating. Turning a long alert chain, a packet capture summary, a PowerShell blob or a vendor advisory into something an analyst can read in thirty seconds. Low risk: a wrong summary is noticed by the person reading the underlying data.

Enrichment. Pulling the context an analyst would have gathered by hand — asset owner, recent changes, related tickets, what this host normally does — and putting it beside the alert.

Drafting. Detection rules, queries, timelines, incident notes, customer notifications. The analyst still reviews, but starts from something.

Searching unstructured material. Documentation, past incidents, policies, threat intel. Retrieval over a corpus a team already has is the most reliably valuable application in this list.

Where it does not

Final decisions with consequences. Blocking an account, isolating a host, closing an alert as benign. A model that closes alerts will eventually close the real one, and nobody will know until later.

Anything requiring a guarantee. "Did we see this indicator anywhere in the estate" is a query, not a question for a model.

Novel attacker behaviour. Models are good at things resembling what they have seen. Genuinely new behaviour is exactly the case where they are confidently wrong.

The pattern that works

AI proposes, a human disposes, and the proposal comes with its evidence. The analyst sees the summary and the alert, the draft rule and the data it was built from. The time saved is real, and the failure mode is a wasted minute rather than a missed intrusion.

One more thing to decide early: what you send to a provider. Alerts contain hostnames, usernames, file paths and sometimes the contents of documents. That is a data-flow question for the security team itself to answer, preferably before the pilot.

Check your understanding

3 questions · pass with 2 correct

1. Which task is a good fit for an LLM in a security team?
2. Why is 'did we see this indicator anywhere' a poor question for a model?
3. What should a security team settle before piloting an assistant?

You'll see your score; enrol to have it count towards your certificate.

Enrol for free to save your progress, unlock every lesson and earn a certificate.

Sign in to enrol

Further reading

Guides that go deeper on this lesson.

  • AI-Powered Cyber Attacks

    How attackers use AI to scale phishing, find vulnerabilities and automate attacks, and what it means for defenders.

    1 min read

  • Security Awareness for AI Users

    What every employee should know about using AI tools safely: data handling, verification and spotting AI-enabled scams.

    1 min read

  • Data Leakage to AI Providers

    Managing the risk of sensitive data reaching third-party AI services through employees and applications.

    1 min read