Nearly a third of respondents to an ISC2 study said their teams have already integrated artificial intelligence (AI) security tools into their operations. This momentum is undeniable. As Vu Van Than, CISSP, SSCP, CC argues, it raises a critical question. What if the real risk is not that cybersecurity teams are adopting AI too fast, but that we are adopting it before we’ve learned how to question it?

AI Month: AI Adoption is Not Cybersecurity Maturity – My Lessons from the Field - Vu Van Than, CISSP, SSCP, CCDisclaimer: The views and opinions expressed in this article belong solely to the author and do not necessarily reflect those of ISC2.

As a head of cybersecurity in my organization, I don’t see AI as something to resist. I see it as something to understand, test and govern. In my own team, I’ve seen AI help analysts and pentesters move faster. I’ve also seen cases where speed began to look like assurance, before the evidence was strong enough. Here are five lessons I’ve learned.

AI Is Useful for Speed, But Not Always for Depth

In penetration testing, my team has used AI to support reconnaissance, generate test ideas, summarize scan results and automate repetitive tasks. In practice, this is valuable for speed and coverage. But, when a test involves complex business logic, authorization flows, fraud scenarios or organization-specific processes, AI has often reached its limit. It may suggest many attack paths, but it does not always understand which one matters to the business.

Moving the Hardest Judgment Closer to Impact

A good pentester does more than find a payload. They understand intent, context, impact and abuse cases. It turns out that AI can assist that process, but it cannot replace the human ability to connect a technical weakness to a real organizational consequence. In practice, the most important part of the work is often deciding which risk matters, which finding should be escalated and what harm is actually plausible.

AI Use Is Not a Security Metric, Security Outcomes Are

AI has a cost and that cost should be measured. It is not only a license or token cost. In practice, I find it includes infrastructure, technical expertise, tuning, security review, data protection controls and validation effort. Secure AI deployment guidance is aimed at organizations bringing AI capabilities into managed environments – especially those deploying and operating systems developed by another entity.

In my experience, if AI-assisted work produces output that still requires senior people to correct, interpret and defend, we need to ask ourselves whether it improved the security decision or only increased the amount of output.

SOC and AI Depends on the Evidence Pipeline Behind It

Using AI on top of security information and event management (SIEM) and security telemetry is attractive. It has helped my analysts query logs, correlate alerts, summarize findings and suggest investigation paths. But, when key events have not been collected, normalized or monitored, then the AI layer has produced fluent summaries of an incomplete reality. Faster investigation is not always better investigation if the underlying assumptions are wrong.

AI Expands the Attack Surface When It Moves from Recommendation to Action

A chatbot that only suggests an answer is one thing. An AI agent that can call tools, query systems, access files, create tickets or trigger workflows is a different beast. At that point, AI becomes a question of identity, access and operational authority. This is why I do not grant AI agents broad or unrestricted access; agentic AI introduces privilege risks, structural risks and wider attack surfaces that require governance, monitoring and human oversight.

This brings me to accountability. When AI becomes part of security decision-making, "the model recommended it" is not an acceptable explanation. The model can recommend, prioritize and summarize, but my people must still own the decision and its consequences.

This is not a universal answer; they are my “field observations” from leading a security team through AI experimentation. As is widely accepted, I’ve found that AI can accelerate cybersecurity work, but it doesn’t automatically create cybersecurity maturity. It amplifies both our capability and our blind spots.

So, my concern is not AI in the workflow. It is our tendency to treat adoption as evidence that resilience, governance and judgment are already in place.

Vu Van Than, CISSP, SSCP, CC, has 10+ years of experience in enterprise SaaS, SOC consulting, retail technology, telecommunications, cloud security and DevSecOps. He has held management, technical and teaching roles, with responsibility for security strategy, governance, architecture, SOC, incident response and risk management. His cybersecurity work spans threat modeling, proactive defense, strategic deception, cyber foresight and security education.

For You, By You: Join Us and Build ISC2's AI Security Certification

As cybersecurity professionals evolve and adapt their skillset and job functions because of AI, ISC2 has announced the development of a new AI security certification to recognize and benchmark AI skills and competence within the cybersecurity workforce.

The AI security certification development process presents an opportunity for cybersecurity professionals to input into the process and help define parameters for the certification.

This is your moment to play a defining role at the foundation of this new certification:

  • Contribute to identifying the knowledge, skills and abilities necessary to securely design, implement and manage AI systems
  • Creating questions for a pilot exam
  • Participate in publicly available pilot exams to help ensure it accurately validates a candidate capabilities

For more information about the ISC2 AI security certification program and how to contribute to the various development activities taking place, go to https://www.isc2.org/new-ai-certification.

Related Insights