For more than 17 years, Deinkumo Liberty, CC, has worked in safety-critical operations across offshore and onshore drilling facilities. During that time, he has completed countless Permit-to-Work reviews, isolation verifications, maintenance activities and operational risk assessments. But the most important lesson learned had very little to do with permits or procedures; it was learning how disciplined organizations make decisions when the consequences of getting them wrong are unacceptable.

AI Month: The Real AI Risks are the Assumptions We Stop Challenging - Deinkumo Liberty, CCDisclaimer: The views and opinions expressed in this article belong solely to the author and do not necessarily reflect those of ISC2.

In high-consequence environments, documentation is never accepted as evidence, only as the beginning of independent assurance. While people outside process industries sometimes assume that once a Permit-to-Work has been authorized, isolation certificates completed and paperwork signed, work can begin. In reality, the opposite is actually true. At that point, the operational discipline that keeps people, assets and the environment safe is only just beginning.

For maintenance involving process isolation or breaking containment, documentation is only one layer of assurance. Drawings are reviewed, equipment identification is confirmed, isolations are independently checked, the line is physically walked, pressure conditions are verified and the work party confirms that the plant in front of them matches the plant described on paper.

Managing Risk

These activities are designed to reduce uncertainty and manage operational risk to a level that is as low as reasonably practicable (ALARP). They do not exist because people are expected to be perfect, but because assumptions are not.

On one maintenance activity, the Permit-to-Work had been authorized. Isolation certificates had been completed and every administrative prerequisite suggested the job was ready to proceed. Before work could begin, the operational checks required by the work process continued. As the team walked the line, compared the approved documentation with the physical plant and confirmed equipment identification against the process drawings, we discovered that the wrong process system had been isolated.

So, while the paperwork accurately reflected what everyone believed, it didn’t reflect reality. Had work started based solely on the documentation, we may have broken containment on a live high-pressure system, creating serious risks to personnel, the facility and the environment. Work stopped immediately, the permit was suspended while the isolation strategy was reviewed and the correct system was identified and isolated. The findings were documented so the wider workforce could learn from the event.

I never regarded that experience as evidence that the Permit-to-Work system had failed. I saw the opposite. The system had succeeded because it was deliberately designed to challenge assumptions before they could lead to consequences.

That lesson followed me into cybersecurity.

From Physical to Cybersecurity

When I transitioned from safety-critical operations into cybersecurity risk and governance, I was struck by how familiar many of today’s discussions around artificial intelligence (AI) felt. AI is becoming part of everyday cybersecurity decision-making. It helps analysts prioritize vulnerabilities, identify anomalies, recommend responses and assess cyber risk faster than ever before.

Most conversations understandably focus on hallucinations, bias, privacy and model accuracy; those are important issues. But, from the perspective of someone who spent almost two decades making decisions in which mistakes could have immediate physical consequences, I believe another risk warrants equal attention.

The greatest risk is not simply that AI produces the wrong answer. It is that people gradually stop challenging the answers it produces.

Confidence Must Be Earned Through Evidence

Safety-critical industries learned long ago that confidence must be earned through evidence. Recommendations supported by documentation, technology, or sophisticated analytics don’t become trustworthy simply because they appear authoritative. Trustworthy decisions are built on verified assumptions, not persuasive recommendations.

During my postgraduate research into explainable AI for cybersecurity risk scoring in industrial environments, I found myself returning to the same lesson I’d learned years earlier offshore. Explainability is often described as a technical capability that helps users understand how a model reached its conclusion. Technically that’s true; but, operationally, it’s more important role is as an assurance mechanism.

In operations, walking the line before breaking containment was never about proving the paperwork wrong. It was about proving reality right. Explainability serves a similar purpose. It enables decision-makers to test the reasoning behind a recommendation before acting on it.

Without that capability, people are asked to trust; with it, they can challenge. Explainability doesn’t guarantee that a recommendation is correct, but it preserves something far more important: the human ability to question, verify and remain accountable.

Safety-critical industries recognized this principle long before AI existed:

  • Permit-to-Work systems require independent assurance before work begins
  • Management of Change processes test assumptions before changes are implemented
  • Safety barriers are periodically checked rather than assumed to be available simply because an indicator says they are healthy

These disciplines are not administrative overhead. They exist to improve the quality of decisions before consequences occur. I believe organizations adopting AI should apply the same mindset.

So, before accepting an AI-supported recommendation, five governance – rather than technology – questions are worth asking:

  • On what assumptions does this recommendation rely?
  • What evidence supports those assumptions?
  • Has anyone independently challenged those assumptions?
  • What would happen if those assumptions proved to be wrong?
  • Who remains accountable for the final decision?

Looking back, the most valuable lesson I took from over 17 years in safety-critical operations was learning how disciplined organizations make decisions when the consequences of getting them wrong are unacceptable. For such high-consequence organizations, trust isn’t something to declare; it’s something they verify.

AI may change how recommendations are generated, but it doesn’t change who carries responsibility when those recommendations shape actions. And AI will undoubtedly become better at generating recommendations; whether it will improve our decisions will depend on whether we remain disciplined enough to challenge them.

Deinkumo Liberty, CC, has over 17 years of experience in safety-critical energy operations, OT cybersecurity and cybersecurity risk assurance. He has held engineering, operational leadership and assurance roles, with responsibility for asset integrity, operational risk, contractor assurance and incident investigation. His cybersecurity work spans industrial control systems, AI risk in industrial environments, cyber resilience and translating safety-critical assurance principles into cybersecurity practice.

For You, By You: Join Us and Build ISC2's AI Security Certification

As cybersecurity professionals evolve and adapt their skillset and job functions because of AI, ISC2 has announced the development of a new AI security certification to recognize and benchmark AI skills and competence within the cybersecurity workforce.

The AI security certification development process presents an opportunity for cybersecurity professionals to input into the process and help define parameters for the certification.

This is your moment to play a defining role at the foundation of this new certification:

  • Contribute to identifying the knowledge, skills and abilities necessary to securely design, implement and manage AI systems
  • Creating questions for a pilot exam
  • Participate in publicly available pilot exams to help ensure it accurately validates a candidate capabilities

For more information about the ISC2 AI security certification program and how to contribute to the various development activities taking place, go to https://www.isc2.org/new-ai-certification.

Related Insights