Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityLogical SecuritySecurity & Business Resilience

Liars in the wires: Getting the most from GenAI without getting duped

By Aaron Shelmire
Colleagues celebrating

Image via Unsplash

September 19, 2024

Before, artificial intelligence (AI) and machine learning (ML) required programming languages. Now, simple text interfaces enable everyone to interact with powerful models that are seemingly limitless. A University of California, San Diego study found that GPT4 has passed the TuringTest, with 54% of participants mistaking GPT4s responses as coming from a human. Many of the latest AI enabled tools can make you feel like you’ve mastered new subjects far and wide, unlocking vast riches and capabilities at first glance. Until you submit those results to true experts in those fields, and end up sanctioned like the legal counsel in New York for generating fake case matter. AI was going to change the world, until it didn’t. 

There are a few industries that have remained skeptical of large AI claims, with cybersecurity amongst them. AI has proven to be a hard sell in the computer security space. Perhaps due to the trauma of the early 2010s ML and UEBA that was going to automate detection of all the threats with zero false positives. 

So why is AI and ML challenged with cybersecurity? 

There are notable challenges with AI/ML in cybersecurity: Cybersecurity deals with finding extraordinarily rare events, for which there is a very high penalty in failure, and the findings need to be explainable.

Even though it seems like every day there is news of another intrusion or ransomware attack, these events are rare in comparison the the quadrillions of normal events generated each day. This poses a challenge for AI and ML, which gravitate towards the most common nearby explanation, when cybersecurity events are themselves one of the many less likely explanations. 

There is a high penalty for errors in cybersecurity, while the areas where AI and ML have been most successful have a low penalty for false positives. In cybersecurity, the most common situations result in a mistaken explanation adding more false positive alerts to the team’s load, eroding trust in the system they are relying on for help. At it’s worst, a mistaken result by AI leads to an alert that would normally be raised being overlooked, and an intrusion that could have been stopped being overlooked.

Finally, cybersecurity requires explainable findings, but our GenAI copilots can’t testify. GenAI is a habitual liar, sometimes convincingly so, many times providing false references and explanations. In cybersecurity, analysts often need accurate references to better understand the stimuli they are evaluating. In other cases, accurate references and explainable results are necessary for court cases, insurance settlements, and liability claims. This is an area that will likely improve over time as GenAI systems become embedded as research assistants, though for today, we can’t trust these liars in the wires.

The rest of the world is talking about the benefits of GenAI, what can it do for cybersecurity? 

Most cybersecurity jobs are exercises in context switching from one urgent fire to the next. Those context switches are productivity killers. GenAI has proven most useful for drafting code, with vendors such as AWS claiming code assistants can help developers complete tasks 28% faster than without. I wouldn’t be surprised if that development speed gain is faster in cybersecurity, where the context switches are more common. In our field, the code assistant can help pull analysts into the task of writing data ingestion parsers, detection rules, or automated response and enrichment scripts. 

Every cybersecurity group I’ve worked with has struggled with post incident write ups, often because the team members are paralyzed by writer’s block. Generating the start of technical documents is a great way to break through the block wall facing these writers, and with the added bonus that giving security analyst’s a sort-of but not quite correct report is a surefire way to nerd-snipe their undivided attention! This is an area where GenAI shines.

GenAI may be appropriately named, similar to sales lead-gen, where GenAI gives a starting point to work from, requiring skilled practitioners to take that start molding it to a finished and accurate product. My words, not AI’s. 

KEYWORDS: artificial intelligence (AI) machine learning organizational resilience organizational risks

Share This Story

Aaron shelmire headshot

Aaron Shelmire is the Chief Threat Research Officer & Co-Founder of Abstract Security. Image courtesy of Shelmire

Blog Topics

Security Blog

On the Track of OSAC

Blog Roll

Security Industry Association

Security Magazine's Daily News

SIA FREE Email News

SDM Blog

Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Northland Controls sponsored content
    Sponsored byNorthland Controls

    The Execution Gap: Why Great Security Design Doesn't Always Deliver Great Security

Popular Stories

People watching fireworks

Security Guard Assaulted at Firework Show

Cargo ship sailing

You Can’t Secure a Ship Like a Laptop

Medical professional

Nearly 85% of Nurses Experienced Workplace Violence in the Last Year

Glasses in front of coding on screen

The Good Hackers Security Leaders Can’t Afford to Ignore

Coding

6 Data Breaches to Know About (June 2026)

Kaseware sponsored webinar
Schneider Electric sponsored webinar

Events

August 19, 2026

From Investigative Question to Defensible Answer: AI in Digital Forensics and Incident Response

LIVE: August 19, 2026 at 2 PM EDT We'll examine where AI can deliver meaningful value, where incomplete context or black-box reasoning can introduce risk, and what governance, validation, and evidence-traceability controls organizations should establish.

August 25, 2026

Critical Infrastructure Security Is National Security: Protecting Essential Operations in an Era of Escalating Risk

LIVE: August 25, 2026 at 2 PM EDT Learn why critical infrastructure security has become a national security imperative, and the strategies organizations can adopt to improve visibility, collaboration, and response across their security operations.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


Alertmedia sponsored webinar
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing