Why judgment is emerging as cybersecurity’s defining skill

AI is getting better at much of what security teams have long spent time on: analyzing information, identifying patterns, and providing technically sound recommendations quickly. As those capabilities become more routine, they are changing what security practitioners spend their time on. Reaching a

AI is getting better at much of what security teams have long spent time on: analyzing information, identifying patterns, and providing technically sound recommendations quickly. As those capabilities become more routine, they are changing what security practitioners spend their time on.

Reaching a technically sound recommendation is also getting easier, which puts more weight on the judgment about what to do with it. A recommendation can make complete sense from a security perspective and still carry consequences for the systems, people and business around it that change what the right decision is.

Experienced practitioners bring context an AI system usually lacks: how systems are actually used, which parts of the business depend on them, what happened during previous incidents, and what an action is likely to set off. That context often changes what a team decides to do next.

This matters for security leaders as they hand AI a larger role in operations. They are the ones deciding where it can act with more freedom and where human judgment stays in the loop. Some of the hardest calls start with analysis that is technically sound, because the information available to the AI may not include enough context about that particular environment.

Security teams face this daily. For example, a critical vulnerability with a public exploit may need to be patched immediately. But if it affects a line controller or a medical device running under vendor certification, an unscheduled reboot could stop production or create a regulatory issue. The environment determines how and when the team should respond.

The same applies to suspicious infrastructure. An IP address tied to malicious activity may also belong to shared cloud infrastructure or a content delivery network that business services depend on, and blocking it would take those services down with it.

Context changes the decision

Experienced practitioners know things about their environments that never made it into an asset inventory, a runbook, or any dataset AI can reach. They know the unimportant server still supports a critical business process. They remember that isolating one network segment during a previous incident took down another service. They can also tell that activity which looks hostile is really an authorized red team, a security test, or scheduled vendor work.

In one case, for instance, a service account showed authentication activity far above its baseline, baseline was connecting from an unfamiliar host at 3 a.m. The recommendation was to disable it pending investigation. An experienced analyst checked the account’s activity and noticed the same spike, host and timing four times a year, during the quarterly close. The activity was statistically unusual and completely normal for that particular business process. Disabling the account would have stopped financial settlement mid-run and cost the team days of manual reconciliation.

This is one of the decisions CISOs now face as they expand AI’s role. How much autonomy to grant a system should not rest mainly on model confidence or threat severity, since neither tells you what happens once the recommended action is taken. Reversibility and blast radius are the better test, and they need to be assessed separately. Isolating a domain controller is reversible by reconnecting it and doing it at the wrong moment can cause an organization-wide outage.

Low-impact, reversible actions are better candidates for greater autonomy, with safeguards in place. More scrutiny makes sense when actions are difficult to reverse. They have a broad potential impact, cross legal or trust boundaries, affect systems beyond the evidence available, or reduce the organization’s ability to investigate what happened.

AI models and their capabilities will keep changing. Security leaders still need to understand the potential impact of the actions they allow them to take.

Look at what people actually do

AI can leave an analyst with dozens of recommendations to review in the time they once spent investigating a handful of cases. Each analyst now has more decisions to make. Organizations need to measure what happens to those decisions.

The KPI you choose determines the behavior you get. Make automation rate the focus, people have an incentive to approve

Source: CyberScoop