TL;DR: Four CISOs argue that generative AI is already changing security strategy, with immediate action needed to protect security infrastructure and separate real risk from hype, according to Abnormal AI’s Vision 2024 webinar. The governance question is no longer whether AI matters, but which identity, access, and control assumptions need to be rewritten now.
Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “CISO Chat(GPT): How Top Brands are Using AI in Cybersecurity”.
Key questions
Q: How should security teams govern generative AI once it becomes part of daily operations?
A: Treat generative AI as an access-bearing workflow, not a standalone tool.
Q: Why does generative AI change identity and access assumptions for CISOs?
A: Because AI can influence how security actions are selected and carried out, the old assumption that control decisions map cleanly to a human operator becomes weaker.
Practitioner guidance
- Review AI-touching security workflows Identify where generative AI is used in alerting, prioritisation, policy recommendation, and response, then document who retains approval authority at each step.
- Separate human and AI decision rights Define which security decisions remain human-approved and which may be delegated to automated or AI-assisted systems, especially in privileged operations.
- Reassess privileged access to security tooling Inventory administrator paths into SIEM, SOAR, email security, and identity platforms, then classify any AI-adjacent access as a high-risk control path.
Bottom line: Generative AI is changing cybersecurity strategy by forcing leaders to revisit how decisions, approvals, and accountability are structured across security operations.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Generative AI is now a governance problem, not only a threat-detection problem. The webinar's real signal is that CISOs are treating AI as a strategic force that changes how security organisations allocate trust, not just how they classify alerts. That means the control conversation moves upstream into identity, approval, and accountability design. Practitioners should read this as a governance reset, not a tooling trend.
A question worth separating out:
Q: What should CISOs ask before adopting AI security tools?
A: CISOs should ask what problem the tool solves, how the model was trained, who trained it, whether the organisation’s data will feed public models, and what controls exist for misuse or poisoning. Those questions separate real operational value from FOMO. Adoption should follow a specific security need, not broad enthusiasm for AI.
👉 Read our full editorial: Cisos say generative ai is reshaping cybersecurity strategy