
James Henry at Crossword Cybersecurity gives his perspective on AI’s trust problem and where it should sit in today’s cyber-security mix
There is no getting away from the fact that artificial intelligence (AI) is allowing some astonishing advances in a number of areas. Whether it is freely communicating with Alexa, enabling advances in medical fields such as cancer detection and drug development, or helping engineers design more efficient components, we can all point to positives.
It is right that there are debates about how AI fits more broadly in the enterprise IT stack and whether (or not) artificial general intelligence is a threat. For CISOs, AI in their own departments also requires them to face some challenges.
The rise of generative AI, with several large language models (LLMs) and interfaces such as ChatGPT, Llama and Bard, has been very beneficial for business. But generative AI can also be exploited, with tools such as WormGPT and FraudGPT being used to create potential new threats.
These tools and others are being used to great effect, with an impact that security teams are working hard to manage.
For over a decade, CISOs have been told that AI is part of the solutions they should be deploying. AI was a marketing hot word used to describe solutions that exhibited some level of autonomy but fell far short of what we regard as AI today. This led to stories that AI had failed to deliver: the benefits were oversold and there was an expectation from users that AI would be their silver bullet.
These experiences, together with the fact that much of today’s AI is black box technology that cannot easily be explained, have created a trust problem for CISOs. Can and should we use an AI solution for any part of our cyber-security?
CISOs and their teams want to know how the technology they are using works. This knowledge creates confidence, and means that CISOs can make risk-informed decisions about where to deploy AI, and how much autonomy it should be given. These are decisions that every CISO needs to make, based on the threats they face and the resources and capabilities they have available in their organisation.
In addition, every CISO will have a personal risk appetite that affects how far they want to go down the AI road.
The transparency and explainability of AI are two of the considerations that will play a key role in helping CISOs to feel comfortable about embracing AI: if a CISO makes a business decision, and has final sign off on the action that will take place, they need to be able to explain their reasoning.
Transparency and explainability help vendors prove the value of their technology. As AI solutions are learning and adapting all the time, the ability to explain how conclusions are reached is essential, both for compliance and also to make sure that AIs are not exhibiting bias.
One of the main opportunities for business is the potential for generative AI to enhance, or in some cases, replace resources within security teams.
Security teams are often overloaded with resource-intensive, repetitive tasks and projects. These time-sapping activities include such things as continuous monitoring, threat intelligence, vulnerability management, and incident response. There is a strong argument that AI could indeed support these security teams, and take on some of the routine heavy lifting, freeing hard-pressed teams to focus on higher value tasks.
We are already starting to see early signs of this with ‘co-pilot’ LLM AI solutions which can act as a trusted security operations advisor when security professionals are completing security operations tasks. These early advancements could enable junior staff with lower skills and experience to learn from their co-pilot, thereby addressing the cyber-skills gap and reducing the burden on more experienced security staff.
Generative AI has huge potential to be used defensively to automate intensive security team tasks, permitting security teams to be much more efficient, focussed on delivering improvements rather than just struggling to ‘keep the lights on’. These tools could even be used to automate specific tasks when a trigger is activated, acting as an autonomous, intelligent and adaptive security playbook.
The opportunity for AI to act as a partner within the security team may well outweigh the threats. Some people take a cynical or pessimistic view of the potential for generative AI in the cyber-security field. However, it is important to take a balanced view, considering both the risks from generative AI and the opportunities it could afford us in the future.
We are still at the very early stages of seeing true AI-enabled cyber-security. For generative AI to prove of value to CISOs and security operations teams we first need to address some of its inherent challenges, such as how to best manage training data quality, how to reduce bias and improve fairness, and how to address the risk of excessive agency and hallucinations.
In the healthcare industry, AI is outperforming consultants in areas such as reviewing medical scans to identify cancer risks. But these are discrete problems. They are very different from those faced by cyber-security today.
CISO will be forced to match attackers’ use of AI, which is already impressive. This is the same cyber-security arms race that there has always been. But it would be a mistake to view AI as replacing the expertise that exists in information security teams.
AI can relieve teams of some of the heavy lifting and alert them to anomalies. However, humans in the loop should validate AI’s findings and decide on the action to be taken. This will build the trust in AI that CISOs need to see.
The AI opportunity for CISOs is exciting, but the industry must work to build their confidence in this technology.
James Henry is Consulting Innovation Director at Crossword Cybersecurity
Main image courtesy of iStockPhoto.com
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543