
Gwen Takagawa
Senior Consultant, Coalfire (CIPP/US, CIPP/E, CIPM, PMP)
Cyber Risk Advisory



When we work through cybersecurity maturity assessments with CISOs, the biggest challenges we help them confront are often not technical. They know their environments. They have a long wish list. What they benefit from is business-specific prioritization and identification of ‘quick wins’ that validates the best use of (inevitably scarce) resources.
This hasn’t changed. Yet lately, we’ve found ourselves helping CISOs use enterprise AI tools to redefine ‘quick wins’: Projects that would have been too resource-intensive, that now become conceivable with AI-enabled tools.
However, even with officially sanctioned tools, adopting AI tools introduces a whole new set of risks. In the process of supporting tool adoption for specific use cases, we are evolving new ways to identify the “right” balance between efficiency, innovation, and risk mitigation.
When fine-tuning SIEM alerts, there is a constant tension between “receiving too many alerts to triage” and “missing something critical.” A similar tension between signal and noise applies when evaluating AI tools for risk and compliance workflows. Tuning to the appropriate level of “false negatives” and “false positives” requires an understanding of both the risk and the context in which the tool is being used.
Consider the risks of AI as analogous to the real problems the SOC team wants to surface through the SIEM. For AI, a non-exhaustive selection of these risks includes:
Take the example of hallucinations. In some scenarios, a ‘false negative’ for hallucination (where baseless claims go undetected) would be disastrous. Consider the well-publicized news articles about lawyers embedding cases that do not exist into their court filings. Or, similar to examples we’ve seen in practice, consider an AI tool reviewing logs. Every month, a database scan runs and returns the same satisfactory result. Even when the log for the result does not materialize one month, the tool fills in the expected pattern and reports that the database scan completed, rather than alerting on a potential concern.
On the flip side, ‘false positives’ for hallucination are where accurate outputs are mistakenly flagged as unreliable. This results in excessive and unnecessary human oversight, validating information that was correct to begin with. Much like a SOC analyst overwhelmed with alerts, over-tuning AI tools with constant oversight can erode the very efficiency gains that made AI appealing in the first place.
Navigating this tradeoff requires the same pragmatic, context-driven approach we use when prioritizing remediation activities at the conclusion of cybersecurity assessments. For each AI use case in security and compliance, assess:
One CISO identified a backlog project that was an ongoing pain point: External auditors had expanded the scope of their audit over time, to include hundreds of hours expended on systems that the CISO’s team considered low risk. Yet the team did not have a defined rationale or approach to justify excluding the system from scope. They also did not have resources available to fully audit the systems internally.
Could their newly-adopted enterprise AI system help?
Coalfire worked with the team to mindfully approach the project and balance the CISO’s desire to innovate with a conservative stance on risk.
We started by identifying the risk of ‘false negatives’, or in other words, what could go wrong because of using an AI tool for the assessment? The most significant risk of false negatives for this use case involves hallucinations. If the tool misrepresented evidence, there would be increased risk either from inviting additional scrutiny by external auditors noticing discrepancies, or by reducing needed scrutiny of critical systems.
Then we considered the risk of ‘false positives.’ What considerations constrained the amount of oversight to build into the tool?
Coalfire’s recommended approach to balancing the risks included:
This example shows how AI can help teams tackle labor-intensive priorities that were previously out of reach. A project once seen as too resource-consuming became a quick win with the right AI support.
Artificial intelligence offers new ways to augment these teams and help move work forward. But as with any new technology, AI comes with new challenges to overcome. By thinking through the known risks and how they may interact with the specific task at hand, CISOs can identify the right tools and the right risk mitigations.
CISOs need their teams to work through pilot projects to explore both the capability of the tools and to understand how AI-related risks materialize in practice. Just as a SIEM requires tuning over time, based on the actual alert frequency and risk tolerance, teams need to begin adopting AI tools to gain data points that will inform decisions on appropriate levels of oversight.
Over time, this approach enables teams to adopt AI in a way that’s defensible, efficient, and tailored to their unique risk landscape. And in the process, redefine “quick wins” to include a wider variety of backlog projects.
At Coalfire, we design AI workflows that balance speed with accountability. Just as our maturity assessments help CISOs prioritize what matters most, we advise our clients on systems that make sense for your business model and align with your risk tolerance. Whether you are piloting a small process or exploring a more systemic AI integration, these principles remain the same.
If you are exploring how to integrate AI into your risk or compliance functions, we can help you build the right foundation. Let’s talk.