Council Post: Artificial Intelligence Won’t Reinvent Cyber Risk—But It May Reinvent Cybersecurity
RJ Friedman is a 10x CISO, 3x MSSP founder, board member, and CEO of NecessityWorks.gettyAs someone who uses 15 billion tokens per month (the equivalent of roughly 125,000 novels) and helped review the Cloud ...
RJ Friedman is a 10x CISO, 3x MSSP founder, board member, and CEO of NecessityWorks.

getty
As someone who uses 15 billion tokens per month (the equivalent of roughly 125,000 novels) and helped review the Cloud Security Alliance's Mythos CISO papers, you may be surprised to hear me say the majority of risks posed by AI are not unique when looking at it through the lens of a chief information security officer (CISO).
There are definitely some new risks and threat vectors—there’s no shortage of people shouting about them from the rooftops. But for the most part, for those of us in risk management, the risks our organizations face today look just like they've looked for the past 30 years.
The real reason LLMs have become such a successful scare tactic for security vendors is that most organizations didn’t have the basics down prior to the technological advancements in machine learning. Now, those same weaknesses are in danger of being exposed exponentially faster.
Old Problems, New Substrates
Take, for example, phishing. We have all heard LLMs have made phishing more of a problem. But even in 2022, the year ChatGPT was released, phishing was already the most common originating threat vector. Deepfakes, while spooky, are simply taking advantage of the same weaknesses in your processes and change management as the poorly written phishing emails employees still fall for.
How about vulnerability management? There is a lot of hype about LLMs allegedly too dangerous to release, and how they could cause disaster in the wrong hands. Yet, the vulnerability ecosystem has long been operating beyond sustainable human-scale. As recently as April 2026, NIST publicly acknowledged the NVD backlog had grown so large it could no longer comprehensively enrich every disclosed vulnerability, moving all backlogged CVEs published before March 1, 2026, into a “not scheduled” category pending available resources.
Artificial intelligence absolutely compounds and exacerbates these problems, but these problems are not new. The risk still explodes when proper people and processes aren't in place to properly triage and patch real vulnerabilities that can affect your organization.
The Real Opportunity For Defenders
By now, you may be wondering: Is this guy just saying we were screwed before, and we're still screwed now, just with more velocity?
Not necessarily. I am an artificial knowledge optimist, and I think we are at a pivotal moment, one in which the future may depend on. In many ways, LLMs have offered attackers accelerated capabilities, but in even more ways, we as defenders can wield it even better.
For years, defenders have attempted to secure machine-scale infrastructure using fundamentally human-scale processes, including human analysts triaging alerts, human engineers reviewing vulnerabilities, human compliance teams mapping controls and human operators correlating telemetry across environments of impossible scale and complexity. And for decades, CISOs have been saying we have a shortage of literally millions of security professionals.
Artificial intelligence may represent the first truly believable opportunity to operationalize cybersecurity at the scale modern infrastructure actually demands.
The first step we took, years ago, in the security organizations I manage was to actually require everyone in infosec to securely use LLMs. After reminding our teams LLMs are still often wrong and they are 100% responsible for any of their inputs and outputs, we got to work; and while we started with the basics, we have been able to do some miraculous things.
For example, at NecessityWorks, we have built systems to intake data from hundreds of integrations and give defenders the ability to query deterministic graph data with agents in real time. This helps us execute everything from policy creation to gap analyses, LLM-led IAM assessments to DLP analysis, machine assisted alert validation (MAAV) to incident response—and all in a fraction of the time it took us to do any of these things in the past.
Getting Back To Basics At Machine Scale
I am frequently asked where to start, and for most readers, the answer is the same as I would have given you in 2021: back to basics.
The encouraging reality is organizations do not need entirely new philosophies to adapt to this era. In many ways, the path forward still looks remarkably similar to what strong security programs have always required: disciplined governance, operational visibility, prioritized remediation and intelligent automation.
The real breakthrough of LLMs may be that they greatly compress the time required for defenders to understand complex systems, identify new risk and operationalize action across environments of previously impossible scale.
1. Structure Governance
If you haven’t used an LLM to help you analyze your policies and standards, this is your sign. Take this further by safely building out a corpus of institutional knowledge and using that as a knowledge base (though I do stress the importance of deterministic approaches).
Start by asking simple questions:
• Based on this KB, which of my policies are stale?
• Which of my policies are probably not being followed?
• Which of my policies are not in line with a SOC 2?
If this is your first time doing this, prepare to be impressed.
2. Visibility
Unfortunately, I think most security teams are still using spreadsheets for their CMDBs, but spreadsheet or not, LLMs can help you with the scripting and integrations needed to build out better visibility across your infrastructure.
Once that's built, and you have a centralized data source of your whole environment, you can take this further by asking the important questions:
• Which users have too much access?
• Which devices are improperly classified based on usage and user access?
The sky is the limit here, and assuming governance is in place, this step is the most important for long-term scalability. You can't protect what you can't see.
This pattern continues through all control categories, and we have experienced some tremendous benefits from using it across them all.
A Rare Moment Of Advantage For Defenders
For years, we have been trying to solve machine-scale problems by introducing new point solutions, dashboards and security engineers. For years, we have been told we are losing, and "the attackers only have to be right once," while we have to be right every time.
That asymmetry was never sustainable, which is why this fascinating point in time gives defenders much more of an advantage. LLMs may not fundamentally reinvent cyber risk, but they may actually reinvent our ability to manage it.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?