Playbooks
The everyday security jobs AI can help with.
A play is a job your team already does — clearing the alert queue, answering a questionnaire, writing up an incident. Each one names the single number it should improve, so you can prove the help is real before you scale it.
5 of 17 plays shown · controls required before each play runs
L2 Assisted: AI helps; the human still decides. The baseline controls each play needs before it runs.
What a play is
Not a feature to switch on. A job to do better.
Most AI pitches sell you a tool. A play does the opposite: it starts from a job you already do and asks a simpler question — can we do this one faster or better, and can we prove it? That keeps the focus on the work, not the technology.
How you run one
Four steps, in plain terms.
Click through the steps — this is the whole method, start to finish.
Step 1 of 4
Start with one everyday job.
A play is just a job your team already does over and over. Clearing the alert queue. Answering a security questionnaire. Writing up an incident. Pick one that happens often — that repeating job is the play.
Two kinds of play
Using AI to do security work, and securing the AI you build.
AI-secure the enterprise
Using AI to do security work better: monitoring, incident response, application security, governance, identity, and threat intelligence.
13 plays below
Secure the AI
Controls around the AI systems you build or run — assurance, guardrails, model security.
4 plays below
Most of today’s plays are the first kind — using AI to lighten security work. That’s deliberate: it’s where the fastest, safest wins are.
The catalog
The jobs, grouped by team.
Open any one to see why it’s a good place to start, the ways to help it, and the safeguards it needs.
Identity Security
1 playAccess-review assistRun periodic access reviews: surface stale and excessive access, chase attestations to completion.Cuts review completion time ↓
Why it’s a good place to start: Mandated on a cycle in every regulated org, chronically late, and the completion date is already reported — a built-in before/after.
Ways to help this job — a fitted skill is just one option
The safeguards grow as you let AI do more
Show the exact control IDs (for your security & GRC team)
L2 · AI drafts, a human approves
L3 · AI acts, a human supervises
L4 · AI acts, humans audit after
These are real CSA AI Controls Matrix objectives. Governance lens: Identity & Access Management.
Network & Infrastructure Security
1 playAI infrastructure & facility assuranceInventory and assure the physical and cloud floor AI workloads depend on; verify provider facility and storage controls.Raises critical ai assets with verified ownership ↑
Why it’s a good place to start: AI uptime and residency fail when the floor under the model is unverified; asset ownership and facility checks are already audit asks.
Ways to help this job — a fitted skill is just one option
The safeguards grow as you let AI do more
Show the exact control IDs (for your security & GRC team)
L2 · AI drafts, a human approves
L3 · AI acts, a human supervises
L4 · AI acts, humans audit after
These are real CSA AI Controls Matrix objectives. Governance lens: Datacenter Security · Infrastructure Security.
Endpoint & Workload Security
1 playEndpoint & AI-tool postureKeep every endpoint that runs AI tools at the policy floor: inventory, harden, encrypt, detect, and wipe when lost.Raises managed endpoints meeting the ai-tool posture baseline ↑
Why it’s a good place to start: Copilots and agents land on laptops first; posture drift is already measured by MDM/EDR, so before/after is free.
Ways to help this job — a fitted skill is just one option
The safeguards grow as you let AI do more
Show the exact control IDs (for your security & GRC team)
L2 · AI drafts, a human approves
L3 · AI acts, a human supervises
L4 · AI acts, humans audit after
These are real CSA AI Controls Matrix objectives. Governance lens: Universal Endpoint Management.
Application & DevSecAIOps Security
3 playsSecure code-review assistSecurity review of code changes: flag dangerous patterns, check fixes, reduce review queue time.Cuts security-review turnaround ↓
Why it’s a good place to start: AppSec review is the classic bottleneck between dev velocity and security; AI pre-screening is mature and the turnaround number already exists.
Ways to help this job — a fitted skill is just one option
The safeguards grow as you let AI do more
Show the exact control IDs (for your security & GRC team)
L2 · AI drafts, a human approves
L3 · AI acts, a human supervises
L4 · AI acts, humans audit after
These are real CSA AI Controls Matrix objectives. Governance lens: Application & Interface Security.
LLM guardrails / prompt-injection defenseFit a guard to an LLM app’s real attack classes; verify against known and held-out attacks.Raises attack catch rate ↑Proven once
Why it’s a good place to start: The one play with an evidenced fit already (a fitted guard, modeled — StoryBond is the worked example): the org’s own attack classes beat any off-the-shelf filter.
Ways to help this job — a fitted skill is just one option
One of these has been fitted and measured on a real app — see the worked example →
The safeguards grow as you let AI do more
Show the exact control IDs (for your security & GRC team)
L2 · AI drafts, a human approves
L3 · AI acts, a human supervises
L4 · AI acts, humans audit after
These are real CSA AI Controls Matrix objectives. Governance lens: Model Security · Application & Interface Security · Threat & Vulnerability Management.
AI SDLC tollgate reviewsReview every AI-assisted PR and model release against eight CI gates from Plan to Monitor; gate strength scales with the AI Cyber Maturity Model (AI-CMM) autonomy tier (our model) the stage runs at.Raises % of ai-assisted prs passing all gates pre-merge ↑
Why it’s a good place to start: Catches the unique failure modes of GAI-in-the-SDLC (slopsquatting, license/IP contamination, vacuous AI-written tests, model-supply-chain swaps) before they reach production. Validated against OWASP LLM Top 10 (2025) and NIST SP 800-218A.
Ways to help this job — a fitted skill is just one option
The safeguards grow as you let AI do more
Show the exact control IDs (for your security & GRC team)
L2 · AI drafts, a human approves
L3 · AI acts, a human supervises
L4 · AI acts, humans audit after
These are real CSA AI Controls Matrix objectives. Governance lens: Application & Interface Security · Model Security · Governance, Risk and Compliance · Data Security and Privacy Lifecycle Management · Logging and Monitoring.
Data Security
2 playsPolicy / DPIA drafting & mappingDraft privacy and AI-impact assessments and policies; map them to the obligations they serve.Cuts drafting time per assessment ↓
Why it’s a good place to start: Exercises the privacy capability directly (DPIA, consent, DSR); drafting hours are large, tracked, and the output doubles as compliance evidence.
Ways to help this job — a fitted skill is just one option
The safeguards grow as you let AI do more
Show the exact control IDs (for your security & GRC team)
L2 · AI drafts, a human approves
L3 · AI acts, a human supervises
L4 · AI acts, humans audit after
These are real CSA AI Controls Matrix objectives. Governance lens: Data Security and Privacy Lifecycle Management · Governance, Risk and Compliance.
AI data encryption & key operationsChoose, operate, and audit encryption and keys for AI training, inference, and stored outputs — including customer-managed keys on provider services.Raises ai data stores under managed encryption with evidenced key control ↑
Why it’s a good place to start: Key and crypto failures are rare but catastrophic; rotation and CMK evidence is already demanded by auditors and customers.
Ways to help this job — a fitted skill is just one option
The safeguards grow as you let AI do more
Show the exact control IDs (for your security & GRC team)
L2 · AI drafts, a human approves
L3 · AI acts, a human supervises
L4 · AI acts, humans audit after
These are real CSA AI Controls Matrix objectives. Governance lens: Cryptography, Encryption & Key Management · Data Security and Privacy Lifecycle Management.
Cloud & Container Security
1 playCloud & container change guardBaseline AI system configuration, catch drift, gate change, and roll back cleanly when a bad deploy lands.Raises ai config drift findings closed within sla ↑
Why it’s a good place to start: IaC and container drift are already ticketed; AI components just need to be in the same change and baseline loop.
Ways to help this job — a fitted skill is just one option
The safeguards grow as you let AI do more
Show the exact control IDs (for your security & GRC team)
L2 · AI drafts, a human approves
L3 · AI acts, a human supervises
L4 · AI acts, humans audit after
These are real CSA AI Controls Matrix objectives. Governance lens: Change Control and Configuration Management.
Security Operations
6 playsAlert triage & enrichmentDisposition the alert queue: enrich each alert with context, close false positives, escalate what matters.Cuts time per alert ↓
Why it’s a good place to start: The single largest hours sink in every SOC — daily, high-volume, language- and pattern-heavy, with a clean per-alert baseline.
Ways to help this job — a fitted skill is just one option
The safeguards grow as you let AI do more
Show the exact control IDs (for your security & GRC team)
L2 · AI drafts, a human approves
L3 · AI acts, a human supervises
L4 · AI acts, humans audit after
These are real CSA AI Controls Matrix objectives. Governance lens: Logging and Monitoring · Security Incident Management, E-Discovery, & Cloud Forensics.
Phishing-report handlingAnalyse user-reported emails: verdict, user reply, and containment for the true positives.Cuts time per reported email ↓
Why it’s a good place to start: High volume, highly repetitive, exists in every org; verdict quality is directly checkable, so before/after is cheap to measure.
Ways to help this job — a fitted skill is just one option
The safeguards grow as you let AI do more
Show the exact control IDs (for your security & GRC team)
L2 · AI drafts, a human approves
L3 · AI acts, a human supervises
L4 · AI acts, humans audit after
These are real CSA AI Controls Matrix objectives. Governance lens: Security Incident Management, E-Discovery, & Cloud Forensics · Threat & Vulnerability Management.
Incident summarization & commsTurn a closed incident into the post-incident report and the stakeholder communications.Cuts time per incident report ↓
Why it’s a good place to start: Pure language work on material that already exists in the case record — the lowest-risk, fastest-payback AI fit in incident response.
Ways to help this job — a fitted skill is just one option
The safeguards grow as you let AI do more
Show the exact control IDs (for your security & GRC team)
L2 · AI drafts, a human approves
L3 · AI acts, a human supervises
L4 · AI acts, humans audit after
These are real CSA AI Controls Matrix objectives. Governance lens: Security Incident Management, E-Discovery, & Cloud Forensics · Governance, Risk and Compliance.
Detection-rule engineeringWrite, test and tune SIEM detections for new threats and noisy rules.Cuts time to new detection ↓
Why it’s a good place to start: Scarce-skill bottleneck work where AI drafting demonstrably compresses the idea-to-deployed cycle; output is testable, so quality is verifiable.
Ways to help this job — a fitted skill is just one option
The safeguards grow as you let AI do more
Show the exact control IDs (for your security & GRC team)
L2 · AI drafts, a human approves
L3 · AI acts, a human supervises
L4 · AI acts, humans audit after
These are real CSA AI Controls Matrix objectives. Governance lens: Logging and Monitoring · Threat & Vulnerability Management.
Threat-intel digestionRead the feeds and advisories; extract what applies to this org; brief the team and update watchlists.Cuts time to actionable intel ↓
Why it’s a good place to start: Reading-heavy, daily, chronically under-served; summarization with org-context filtering is a proven LLM strength.
Ways to help this job — a fitted skill is just one option
The safeguards grow as you let AI do more
Show the exact control IDs (for your security & GRC team)
L2 · AI drafts, a human approves
L3 · AI acts, a human supervises
L4 · AI acts, humans audit after
These are real CSA AI Controls Matrix objectives. Governance lens: Threat & Vulnerability Management.
Vulnerability triage & prioritizationRank the scanner backlog by real exploitability and business context; route fixes to owners.Cuts critical-vuln backlog age ↓
Why it’s a good place to start: Backlogs are universal and unbounded; context-aware ranking is where AI beats static CVSS sorting, and backlog age is already tracked.
Ways to help this job — a fitted skill is just one option
The safeguards grow as you let AI do more
Show the exact control IDs (for your security & GRC team)
L2 · AI drafts, a human approves
L3 · AI acts, a human supervises
L4 · AI acts, humans audit after
These are real CSA AI Controls Matrix objectives. Governance lens: Threat & Vulnerability Management.
Security Governance, Risk & Assurance
2 playsSecurity-questionnaire & vendor-risk responseAnswer inbound security questionnaires and assess vendors against the org’s control baseline.Cuts questionnaire turnaround ↓
Why it’s a good place to start: Document-heavy, template-shaped, perpetually backlogged; answers are checkable against the control record, so quality is auditable.
Ways to help this job — a fitted skill is just one option
The safeguards grow as you let AI do more
Show the exact control IDs (for your security & GRC team)
L2 · AI drafts, a human approves
L3 · AI acts, a human supervises
L4 · AI acts, humans audit after
These are real CSA AI Controls Matrix objectives. Governance lens: Governance, Risk and Compliance · Supply Chain Management, Transparency, and Accountability.
Audit-evidence preparationCollect, organise and narrate the evidence pack for internal and external audits.Cuts evidence-collection time per audit ↓
Why it’s a good place to start: Audits recur on a calendar; the work is retrieval-and-assembly, the format is fixed, and hours are already billed — measurement comes free.
Ways to help this job — a fitted skill is just one option
The safeguards grow as you let AI do more
Show the exact control IDs (for your security & GRC team)
L2 · AI drafts, a human approves
L3 · AI acts, a human supervises
L4 · AI acts, humans audit after
These are real CSA AI Controls Matrix objectives. Governance lens: Audit & Assurance · Governance, Risk and Compliance.