Over the past year, AI has become a recurring theme in many of the security architecture reviews, solution assessments and assurance activities that Rimple Kapil, CISSP, CCSP, has been involved in. Like many cybersecurity professionals, she initially viewed AI as another emerging technology that would eventually be incorporated into existing security frameworks, governance processes and assessment methodologies. Kapil quickly discovered that it’s not that simple.
Disclaimer: The views and opinions expressed in this article belong solely to the author and do not necessarily reflect those of ISC2.
I wasn’t surprised when the introduction of AI raised entirely new security questions. Many of the underlying principles were familiar, but AI expanded existing conversations around trust, accountability, data handling and decision-making, often making them far more complex than in traditional technology assessments.
One of the first signs that AI required a different assessment approach came during an architecture workshop. The discussion began in a familiar way: APIs, authentication mechanisms, integrations and network connectivity. However, once a large language model became part of the proposed solution, the conversation shifted. Instead of discussing only traditional application components, we found ourselves exploring questions that wouldn’t normally appear in a standard architecture review.
Where would prompts be processed? What organizational data would be shared with the model? Which trust boundary did the AI service sit within? What would happen if the AI service became unavailable or returned an unexpected response?
It changed the way I approached architecture reviews. AI was not simply another application component. It introduced new data flows, new dependencies and new trust relationships that needed to be understood and assessed.
A second lesson emerged as discussions around agentic AI became more common. During one engagement, the most important architectural discussion wasn’t about the AI model itself but about authority and accountability. The team needed to determine which actions an AI agent could perform independently, which required human approval and who remained accountable for decisions influenced by AI-generated recommendations.
Governance had always been part of architecture discussions, but AI brought those conversations to the forefront. Discussions about accountability, human oversight and decision authority became just as important as discussions about integrations, security controls and system design. As a result, I began treating AI agents as a new category of actor within enterprise architectures. Just as we establish controls for users, service accounts and privileged access, I found that AI-enabled systems required similar consideration around authority, accountability and oversight.
What AI Taught Me About Security Operations
Another recurring theme emerged during discussions with security operations teams. Many teams were excited about AI-driven threat detection, alert triage and automated investigations. The potential benefits were obvious: AI held the possibility of reducing analyst workload, identifying patterns across large volumes of telemetry and accelerating investigations. However, several engagements revealed a different challenge.
Before AI could improve security operations, teams often needed to address long-standing issues related to data quality. Inconsistent logging, duplicate events, incomplete telemetry and excessive alert noise were common obstacles. On one occasion, the team was evaluating advanced AI-driven detection capabilities. As we worked through the details, it became clear that the immediate challenge was not the AI solution itself. The larger issue was the quality and consistency of the data being supplied to it. This reinforced another important lesson for me: AI doesn’t replace operational maturity but, in many cases, it amplifies it.
Where strong logging, alerting and governance practices already existed, AI had the potential to improve efficiency and visibility. Where foundational controls were weak, AI often highlighted existing problems rather than solving them.
I also became increasingly cautious about treating AI-generated outputs as decisions rather than recommendations. While AI can accelerate analysis and provide useful context, accountability for security decisions still rests with people. Throughout my engagements, I found the most effective approaches combined AI’s ability to process information at scale with human judgement and oversight.
The Governance Conversations That Changed My Perspective
Perhaps the most interesting aspect of how AI has changed assessments is how often governance has become the central topic. Technical discussions were usually straightforward; governance discussions are not and I frequently encounter questions that organizations are still trying to answer. Who is accountable when an AI-generated recommendation influences a business decision? How should AI-related risks be assessed? What level of oversight is required before AI-generated outputs are acted upon?
One observation stands out: many teams assumed that using a well-known AI provider or deploying a model within their own environment automatically reduced risk. Yet the location of a model did not eliminate concerns around accuracy, bias, accountability or inappropriate outputs.
Such conversations gradually altered my own perspective. Rather than treating AI governance as a separate discipline, I began viewing it as an extension of existing governance principles.
The organizations that appeared most prepared for AI weren’t necessarily those with the most advanced technology. But, often, they were those that established clear accountability, approval processes and oversight mechanisms before AI became deeply embedded within business operations. The lesson I took away was simple: AI changes the questions, but it doesn’t remove the need for governance.
How I’ve Expanded My Assurance Approach
As AI became more common in engagements, I found myself adapting assurance activities.
Traditional security assessments remain essential; reviews of authentication, access control, encryption, network security and secure development practices continue to provide value. However, I realized that they no longer provided the complete picture for AI-enabled solutions and, increasingly, I was asking additional questions. How were prompts being handled? What safeguards existed to prevent misuse? How was training or inference data protected? Could model outputs be trusted? What controls existed to limit unintended actions?
I also noticed that traditional testing approaches required adjustment. Penetration testing teams were starting to explore risks such as prompt injection, model manipulation and attacks targeting autonomous AI agents. Secure code reviews were expanding to examine how applications interacted with AI services and how AI-generated responses were validated.
It seemed clear to me was that AI didn’t require an entirely new assurance discipline, but it did require existing assurance practices to evolve. The core objective remained unchanged: understanding risk and validating controls. The difference was that AI introduced new areas that needed to be considered alongside traditional security concerns.
Three Responsibilities I Now Associate With AI
After participating in numerous AI-related assessments, I’ve come to view cybersecurity’s role through three interconnected responsibilities.
- AI for Security: Using AI to improve cybersecurity defense, investigations and security operations
- Secure Use of AI: Enabling a business to adopt AI safely while protecting privacy, intellectual property and sensitive information
- Security for AI: Protecting AI systems themselves from threats targeting models, prompts, agents and supporting infrastructure
Initially, I found many discussions focused almost entirely on the first area because the benefits were easy to see. But over time I’ve become convinced that sustainable value depends on addressing all three. Focusing on only one of these responsibilities leaves important risks and opportunities unaddressed.
Looking Ahead
Reflecting on the past year, I believe that AI has changed the context in which we apply our skills, not the fundamental purpose of cybersecurity. Throughout our careers, we have adapted: to the internet, to mobile computing, to virtualization and to cloud platforms. Each technology introduced new risks, new opportunities and new ways of working. AI is simply the latest chapter in that evolution.
What gives me confidence is that the qualities defining effective cybersecurity professionals remain unchanged. Curiosity, critical thinking, accountability and sound judgement are just as important today as they were before AI entered the conversation.
My biggest lesson is that successful AI adoption is an organizational challenge, not primarily a technology challenge. And the most effective responses I’ve seen combine technology, governance, assurance and human oversight.
AI will continue to evolve. My approach to cybersecurity will continue to evolve with it. The principles that underpin our profession, however, remain remarkably consistent.
Rimple Kapil, CISSP, CCSP, has 21 years of experience in telecoms, cloud platforms, network infrastructure and cybersecurity architecture. She has held technical and architecture roles, with responsibility for designing, reviewing and assuring secure solutions across cloud and on-prem environments. Her cybersecurity work spans network security, cloud security, risk management and secure-by-design practices.
For You, By You: Join Over 6,000 Volunteers and Build ISC2's AI Security CertificationAs cybersecurity professionals evolve and adapt their skillset and job functions because of AI, ISC2 has announced the development of a new AI security certification to recognize and benchmark AI skills and competence within the cybersecurity workforce. The AI security certification development process presents an opportunity for cybersecurity professionals to input into the process and help define parameters for the certification. This is your moment to play a defining role at the foundation of this new certification:
For more information about the ISC2 AI security certification program and how to contribute to the various development activities taking place, go to https://www.isc2.org/new-ai-certification. |


