ISC2 Insights talked with members Christopher Pope, CISSP, CCSP and Daniel Marques, CISSP, about how the rapid adoption of artificial intelligence (AI) is transforming how cybersecurity teams carry out their work, the beneficial role that AI is already playing in day-to-day cybersecurity roles, how it is also changing roles and responsibilities, as well as creating new functional requirements that cybersecurity professionals need to tackle.
Pope and Marques explored how AI is reshaping the cybersecurity landscape. While the conversation acknowledged the growing capabilities of AI, it also emphasized that effective cybersecurity will continue to depend heavily on human judgement, governance and critical thinking.
The Value of Trust and Accountability Over Automation
Trust was a central theme throughout the discussion. Marques argued that organizations naturally take time to trust AI systems, particularly when decisions are influenced by tools developed by third parties. Building confidence in AI requires extensive testing, experimentation and validation. At the same time, cybersecurity professionals must be careful not to place too much trust in AI outputs. The quality of any AI system depends largely on the quality of the data it receives. Poor, inaccurate or compromised data can lead to unreliable results, reinforcing the longstanding "garbage in, garbage out" principle.
Alongside trust, the pair also discussed transparency and accountability. Marques stressed that AI systems should not be allowed to make critical decisions independently because machines cannot be held accountable for their actions. Instead, humans must remain responsible for decision-making and oversight. To support accountability, organizations need mechanisms to understand how AI systems reach their conclusions, maintain records of model behavior and ensure outputs can be audited when necessary.
Pope built on that point, emphasizing the importance of robust AI governance practices, including machine learning operations (MLOps). Treating AI models as managed assets, much like software code, enables organizations to track versions, test for bias, monitor performance and roll back changes when required. Both speakers agree that prompts, training data and model configurations should be governed with the same rigor as traditional software development.
Human oversight remains a critical requirement as AI adoption grows. The speakers argued that every AI implementation should have a designated owner responsible for ensuring it aligns with organizational principles and risk tolerance. Security and governance teams must determine when human review is required, particularly for decisions with significant operational, financial or strategic consequences. AI may perform much of the heavy lifting, but humans must continue to evaluate outputs, assess quality and exercise judgement.
In their concluding advice, Pope encouraged continuous education so that practitioners can look beyond marketing hype and better evaluate AI technologies. Marques stressed the growing importance of critical thinking, problem-solving and effective communication. Their shared message was clear: while AI will become a powerful tool within cybersecurity, human expertise, informed judgement and strong governance will remain essential.
For You, By You: Join Us and Build ISC2's AI Security CertificationAs cybersecurity professionals evolve and adapt their skillset and job functions because of AI, ISC2 has announced the development of a new AI security certification to recognize and benchmark AI skills and competence within the cybersecurity workforce. The AI security certification development process presents an opportunity for cybersecurity professionals to input into the process and help define parameters for the certification. This is your moment to play a defining role at the foundation of this new certification:
For more information about the ISC2 AI security certification program and how to contribute to the various development activities taking place, go to https://www.isc2.org/new-ai-certification. |

