At ISC2’s Spotlight event on Artificial Intelligence (AI), Matt Stamper, CEO and CISO advisor for Executive Advisors Group and co-author of the CISO Desk Reference Guide explored the impact of AI on traditional approaches to incident response and whether organizations are approaching both effectively.
The question to answer was clear, said Stamper. “Our world is fundamentally changing,” he observed. “We're seeing new things happening very, very quickly. So, we begin with just a simple premise, are our incident response programs AI ready?”
Stamper pointed to four fundamental areas that we all find challenging. Identity governance came first, with Stamper observing that we have multiple levels of identity to deal with – not just employees and contractors but potentially also customers. On the subject of data governance, he observed that it has always been hard and remains so, stating that: “It's still fundamentally difficult. We have disparate data stores. We have challenges around … create, write, update and delete permissions on data tracking, data lineage, tracking data movement, understanding how data moves into and out of the organization, the proverbial data flow.” In short, he reminded us, “Those are fundamentally difficult issues.” Moving on to vulnerability management, the story was no better: “Our vulnerability management programs are inordinately challenging to do and to do at scale,” he said, “especially now that we're discovering vulnerabilities with a level of rapidity that most organizations fundamentally are not prepared for.” Lastly came third-party risk management, which Stamper bluntly described as “an inordinately complicated environment,” with complexities such as looking at vendors’ vendors’ vendors and complex shared dependencies across environments.
All of the above came as no surprise to the audience. The host also pointed out an additional problem we all face: AI amplifies and accelerates risks, and so our response programs need to be “AI-ready”.
AI Impact on Incident Response Norms
So, how is AI changing incident response? First, the knowledge our adversaries have about us is far more profound and more adversaries than ever before know all about us. The barrier to entry to using that knowledge, thanks to all the tools available to non-expert bad actors, “collapsing in short order”.
Speed was the next factor cited: attacks are no longer slow enough for us to sit and think about how we might respond to an attack, because it is happening so quickly. Context awareness was the next problem – because of the “digital detritus” we leave everywhere, AI-assisted attackers can use this to learn about us.
The list of problem areas went on: polymorphic attacks (where malware changes itself so it cannot be recognized); dependencies between systems and suppliers; geopolitical risks. It then landed at agentic AI, with Stamper noting that “agents, just like service accounts, machine accounts and human accounts, have entitlements and access.” The list wrapped up with daisy-chained attacks (where a set of apparently modest vulnerabilities can be exploited in combination to result in an intrusion – just as tools such as Mythos can exploit) and then good old social engineering – spoofing and deepfakes – which are easier than ever thanks to all the information about us out on the internet and exploitable by AI.
Moving the focus on to incident response, Stamper looked first at the basic facts of “traditional” incident response. Incident responders generally have vast amounts of data to deal with: “The number of log sources, telemetry, etc. that comes into our security operations center (SOC) effectively can be overwhelming,” he said, going on to ask: “and do we actually have the right telemetry, the right data to make the right informed decision and action?” Additionally, we will often have no idea what the attacker is trying or intending to do, which hampers our ability to react appropriately.
The third concern was down, perhaps surprisingly to some, to the incident responders’ knowledge of their own organization: “There are many times where security leaders and their teams may not understand the business to the level that is appropriate to make an appropriate response when security issues surface,” observed Stamper. We went on to point out another potential flaw in our companies, namely that we may not even have “the right staff with the right training and competencies, with the right access to the right tools to be able to address incidents in an appropriate way.” The final point addressed AI head-on – specifically noting that if we are being attacked by an AI agent our response timescales are compressed enormously.
Stamper then referred back to his previous point about organizational context – that is, how well the responders know their organizations. The audience were left in no doubt that this is a complex issue to overcome. We need to know about our industry, customers and markets; we need to understand our company, its funding, its senior management and its plans for growth and change; we need sight of business processes, applications, data coming in and out; knowledge of vendors, suppliers and contractors is essential; and most importantly the connections between all of the above must be understood. Once more, Stamper then brought back in the main undertone of the talk: “That context has also just gotten orders of magnitude more complex,” he pointed out, “because business units and other areas within the organization are adopting AI.” That is, our own AI can be a potential threat to our own security if we are not managing or controlling it properly.
The presenter then turned to things we can do in an effort to be ready for an incident, whether AI-driven or not. Table-top exercises were cited as a great place to begin, noting that they “flatten the learning curve” and hence at least some basic, uncomplicated exercises should be done regularly. Use playbooks to test our response techniques, he said, to “declare war on ambiguity”, encourage questioning, and do the exercises internally rather than unnecessarily spending money on external exercise-setters.
Developing a New Playbook
Taking the playbook concept an inevitable step further – after all, many of us already have playbooks for our incident response mechanisms – Stamper noted that we need to develop AI-centric playbooks. We should ensure that our main organizational risks are included in the scenarios. It is also essential to test our detection triggers – that is, make sure they actually stand a chance of working. “Would we see this? Would we respond to that if it were to occur? Do we know what those indicators of compromise might be?” he said, reminding us also to ensure that all the teams involved know what they are supposed to be doing so they don’t all assume someone else is dealing with an issue – and that includes teams outside IT such as legal and compliance, who might not be used to ultra-rapid reaction times. “Machine-speed” response also needs consideration, as we may have to react and potentially contain an attack in seconds or minutes, though on the flip-side provision of “human in the loop” organic lifeforms that can take non-automated decisions are essential.
Prior to wrapping up, Stamper introduced the audience to a colorful term unfamiliar to most, about which he had been interviewed by a friend at research firm Gartner: FMC, or Fuzzy Managerial Cr*p – the things that are often forgotten or glossed over by the incident response team. Examples given included: dealing with regulatory requirements such as deadlines for reporting; when to communicate and to whom; understanding the risk tolerance we have to work to; when to work with the corporate lawyers; when and how to involve law enforcement agencies; contractual obligations with third parties that require us to inform them what has been going on.
Stamper ended by posing a few questions. First: how will your incident response program adapt to today’s environment? “Incident response is not easy under the best of circumstances,” he reminded us, continuing by reminding the audience that “It is becoming horrifically more challenging with AI.” Second, which AI-specific risks are most key for your organization? “We don't want to be blindsided by risk that should have been reasonably anticipated,” he added.
The underlying messages of how to make incident response ready for AI were threefold: first, we can add a good level of readiness for AI-assisted attacks with some fairly basic thinking and adaptation of our existing response techniques and playbooks. Next, while we are modifying our response mechanisms, it is important not to forget our existing playbooks and “traditional” response techniques. Finally, be sure to include all the teams you need in your responses and in plentiful internal exercises that will tease out any improvements you can make to your response procedures ready for when the worst happens.
ISC2 Spotlight on National Security & Critical InfrastructureCritical infrastructure powers economies, supports essential services and safeguards national security. Join leading experts on December 2-3, 2026 for practical insights, strategic perspectives and actionable guidance on securing critical infrastructure in an increasingly complex threat landscape. This free virtual event is available exclusively to ISC2 Members, Associates and Candidates. Cybersecurity professionals in every stage of their career are encouraged to participate. Discover how organizations are strengthening defenses across sectors, including energy, transportation, healthcare, manufacturing, water systems and telecommunications — and what it takes to harden mission-critical operations in a rapidly evolving cybersecurity landscape. |

