ai · security · skills

Playbooks

The everyday security jobs AI can help with.

A play is a job your team already does — clearing the alert queue, answering a questionnaire, writing up an incident. Each one names the single number it should improve, so you can prove the help is real before you scale it.

Autonomy raises the bar50 controls required
Alert triage & enrichmentTime per alert
3
Phishing-report handlingTime per reported email
3
Incident summarization & commsTime per incident report
3
Detection-rule engineeringTime to new detection
3
Threat-intel digestionTime to actionable intel
3

5 of 17 plays shown · controls required before each play runs

L2 Assisted: AI helps; the human still decides. The baseline controls each play needs before it runs.

What a play is

Not a feature to switch on. A job to do better.

Most AI pitches sell you a tool. A play does the opposite: it starts from a job you already do and asks a simpler question — can we do this one faster or better, and can we prove it? That keeps the focus on the work, not the technology.

How you run one

Four steps, in plain terms.

Click through the steps — this is the whole method, start to finish.

Step 1 of 4

Start with one everyday job.

A play is just a job your team already does over and over. Clearing the alert queue. Answering a security questionnaire. Writing up an incident. Pick one that happens often — that repeating job is the play.

Clear the alert queueAnswer a questionnaireWrite the incident report

Two kinds of play

Using AI to do security work, and securing the AI you build.

AI-secure the enterprise

Using AI to do security work better: monitoring, incident response, application security, governance, identity, and threat intelligence.

13 plays below

Secure the AI

Controls around the AI systems you build or run — assurance, guardrails, model security.

4 plays below

Most of today’s plays are the first kind — using AI to lighten security work. That’s deliberate: it’s where the fastest, safest wins are.

The catalog

The jobs, grouped by team.

Open any one to see why it’s a good place to start, the ways to help it, and the safeguards it needs.

Identity Security

1 play
Access-review assistRun periodic access reviews: surface stale and excessive access, chase attestations to completion.Cuts review completion time

Why it’s a good place to start: Mandated on a cycle in every regulated org, chronically late, and the completion date is already reported — a built-in before/after.

Ways to help this job — a fitted skill is just one option

Vendor AI featureFitted skillDeterministic automation

The safeguards grow as you let AI do more

L2AI drafts, a human approves3 to start
L3AI acts, a human supervises+3 more
L4AI acts, humans audit after+3 more
Show the exact control IDs (for your security & GRC team)

L2 · AI drafts, a human approves

IAM-08IAM-01HRS-15

L3 · AI acts, a human supervises

IAM-05GRC-15LOG-13

L4 · AI acts, humans audit after

IAM-07IAM-18LOG-12

These are real CSA AI Controls Matrix objectives. Governance lens: Identity & Access Management.

Network & Infrastructure Security

1 play
AI infrastructure & facility assuranceInventory and assure the physical and cloud floor AI workloads depend on; verify provider facility and storage controls.Raises critical ai assets with verified ownership

Why it’s a good place to start: AI uptime and residency fail when the floor under the model is unverified; asset ownership and facility checks are already audit asks.

Ways to help this job — a fitted skill is just one option

Fitted skillProcessVendor AI feature

The safeguards grow as you let AI do more

L2AI drafts, a human approves3 to start
L3AI acts, a human supervises+3 more
L4AI acts, humans audit after+2 more
Show the exact control IDs (for your security & GRC team)

L2 · AI drafts, a human approves

DCS-01DCS-06I&S-01

L3 · AI acts, a human supervises

DCS-07DCS-08I&S-02

L4 · AI acts, humans audit after

DCS-17LOG-12

These are real CSA AI Controls Matrix objectives. Governance lens: Datacenter Security · Infrastructure Security.

Endpoint & Workload Security

1 play
Endpoint & AI-tool postureKeep every endpoint that runs AI tools at the policy floor: inventory, harden, encrypt, detect, and wipe when lost.Raises managed endpoints meeting the ai-tool posture baseline

Why it’s a good place to start: Copilots and agents land on laptops first; posture drift is already measured by MDM/EDR, so before/after is free.

Ways to help this job — a fitted skill is just one option

Fitted skillProcessDeterministic automation

The safeguards grow as you let AI do more

L2AI drafts, a human approves3 to start
L3AI acts, a human supervises+3 more
L4AI acts, humans audit after+2 more
Show the exact control IDs (for your security & GRC team)

L2 · AI drafts, a human approves

UEM-01UEM-04UEM-05

L3 · AI acts, a human supervises

UEM-08UEM-09UEM-11

L4 · AI acts, humans audit after

UEM-13LOG-12

These are real CSA AI Controls Matrix objectives. Governance lens: Universal Endpoint Management.

Application & DevSecAIOps Security

3 plays
Secure code-review assistSecurity review of code changes: flag dangerous patterns, check fixes, reduce review queue time.Cuts security-review turnaround

Why it’s a good place to start: AppSec review is the classic bottleneck between dev velocity and security; AI pre-screening is mature and the turnaround number already exists.

Ways to help this job — a fitted skill is just one option

Vendor AI featureFitted skillPeople

The safeguards grow as you let AI do more

L2AI drafts, a human approves3 to start
L3AI acts, a human supervises+3 more
L4AI acts, humans audit after+2 more
Show the exact control IDs (for your security & GRC team)

L2 · AI drafts, a human approves

AIS-04AIS-12HRS-15

L3 · AI acts, a human supervises

AIS-05GRC-15TVM-13

L4 · AI acts, humans audit after

AIS-06IAM-18

These are real CSA AI Controls Matrix objectives. Governance lens: Application & Interface Security.

LLM guardrails / prompt-injection defenseFit a guard to an LLM app’s real attack classes; verify against known and held-out attacks.Raises attack catch rate Proven once

Why it’s a good place to start: The one play with an evidenced fit already (a fitted guard, modeled — StoryBond is the worked example): the org’s own attack classes beat any off-the-shelf filter.

Ways to help this job — a fitted skill is just one option

Fitted skillProcess

One of these has been fitted and measured on a real app — see the worked example →

The safeguards grow as you let AI do more

L2AI drafts, a human approves2 to start
L3AI acts, a human supervises+3 more
L4AI acts, humans audit after+2 more
Show the exact control IDs (for your security & GRC team)

L2 · AI drafts, a human approves

MDS-06TVM-13

L3 · AI acts, a human supervises

MDS-07LOG-15LOG-16

L4 · AI acts, humans audit after

MDS-10AIS-13

These are real CSA AI Controls Matrix objectives. Governance lens: Model Security · Application & Interface Security · Threat & Vulnerability Management.

AI SDLC tollgate reviewsReview every AI-assisted PR and model release against eight CI gates from Plan to Monitor; gate strength scales with the AI Cyber Maturity Model (AI-CMM) autonomy tier (our model) the stage runs at.Raises % of ai-assisted prs passing all gates pre-merge

Why it’s a good place to start: Catches the unique failure modes of GAI-in-the-SDLC (slopsquatting, license/IP contamination, vacuous AI-written tests, model-supply-chain swaps) before they reach production. Validated against OWASP LLM Top 10 (2025) and NIST SP 800-218A.

Ways to help this job — a fitted skill is just one option

ProcessDeterministic automationPolicyPeopleVendor AI featureFitted skill

The safeguards grow as you let AI do more

L2AI drafts, a human approves3 to start
L3AI acts, a human supervises+5 more
L4AI acts, humans audit after+3 more
Show the exact control IDs (for your security & GRC team)

L2 · AI drafts, a human approves

AIS-04AIS-12DSP-17

L3 · AI acts, a human supervises

AIS-05MDS-06MDS-07GRC-15LOG-16

L4 · AI acts, humans audit after

AIS-13MDS-10LOG-12

These are real CSA AI Controls Matrix objectives. Governance lens: Application & Interface Security · Model Security · Governance, Risk and Compliance · Data Security and Privacy Lifecycle Management · Logging and Monitoring.

Data Security

2 plays
Policy / DPIA drafting & mappingDraft privacy and AI-impact assessments and policies; map them to the obligations they serve.Cuts drafting time per assessment

Why it’s a good place to start: Exercises the privacy capability directly (DPIA, consent, DSR); drafting hours are large, tracked, and the output doubles as compliance evidence.

Ways to help this job — a fitted skill is just one option

Fitted skillPolicyPeople

The safeguards grow as you let AI do more

L2AI drafts, a human approves3 to start
L3AI acts, a human supervises+3 more
L4AI acts, humans audit after+2 more
Show the exact control IDs (for your security & GRC team)

L2 · AI drafts, a human approves

DSP-09DSP-01DSP-17

L3 · AI acts, a human supervises

GRC-15DSP-08LOG-16

L4 · AI acts, humans audit after

LOG-12IAM-18

These are real CSA AI Controls Matrix objectives. Governance lens: Data Security and Privacy Lifecycle Management · Governance, Risk and Compliance.

AI data encryption & key operationsChoose, operate, and audit encryption and keys for AI training, inference, and stored outputs — including customer-managed keys on provider services.Raises ai data stores under managed encryption with evidenced key control

Why it’s a good place to start: Key and crypto failures are rare but catastrophic; rotation and CMK evidence is already demanded by auditors and customers.

Ways to help this job — a fitted skill is just one option

Fitted skillProcessPolicy

The safeguards grow as you let AI do more

L2AI drafts, a human approves3 to start
L3AI acts, a human supervises+3 more
L4AI acts, humans audit after+2 more
Show the exact control IDs (for your security & GRC team)

L2 · AI drafts, a human approves

CEK-01CEK-03DSP-01

L3 · AI acts, a human supervises

CEK-08CEK-12CEK-09

L4 · AI acts, humans audit after

CEK-13LOG-11

These are real CSA AI Controls Matrix objectives. Governance lens: Cryptography, Encryption & Key Management · Data Security and Privacy Lifecycle Management.

Cloud & Container Security

1 play
Cloud & container change guardBaseline AI system configuration, catch drift, gate change, and roll back cleanly when a bad deploy lands.Raises ai config drift findings closed within sla

Why it’s a good place to start: IaC and container drift are already ticketed; AI components just need to be in the same change and baseline loop.

Ways to help this job — a fitted skill is just one option

Fitted skillDeterministic automationProcess

The safeguards grow as you let AI do more

L2AI drafts, a human approves3 to start
L3AI acts, a human supervises+3 more
L4AI acts, humans audit after+2 more
Show the exact control IDs (for your security & GRC team)

L2 · AI drafts, a human approves

CCC-01CCC-02CCC-06

L3 · AI acts, a human supervises

CCC-04CCC-07CCC-08

L4 · AI acts, humans audit after

CCC-09LOG-12

These are real CSA AI Controls Matrix objectives. Governance lens: Change Control and Configuration Management.

Security Operations

6 plays
Alert triage & enrichmentDisposition the alert queue: enrich each alert with context, close false positives, escalate what matters.Cuts time per alert

Why it’s a good place to start: The single largest hours sink in every SOC — daily, high-volume, language- and pattern-heavy, with a clean per-alert baseline.

Ways to help this job — a fitted skill is just one option

Vendor AI featureFitted skillDeterministic automationProcess

The safeguards grow as you let AI do more

L2AI drafts, a human approves3 to start
L3AI acts, a human supervises+4 more
L4AI acts, humans audit after+3 more
Show the exact control IDs (for your security & GRC team)

L2 · AI drafts, a human approves

LOG-01HRS-15DSP-17

L3 · AI acts, a human supervises

LOG-15LOG-16GRC-15TVM-13

L4 · AI acts, humans audit after

LOG-12IAM-18MDS-10

These are real CSA AI Controls Matrix objectives. Governance lens: Logging and Monitoring · Security Incident Management, E-Discovery, & Cloud Forensics.

Phishing-report handlingAnalyse user-reported emails: verdict, user reply, and containment for the true positives.Cuts time per reported email

Why it’s a good place to start: High volume, highly repetitive, exists in every org; verdict quality is directly checkable, so before/after is cheap to measure.

Ways to help this job — a fitted skill is just one option

Vendor AI featureFitted skillDeterministic automation

The safeguards grow as you let AI do more

L2AI drafts, a human approves3 to start
L3AI acts, a human supervises+3 more
L4AI acts, humans audit after+3 more
Show the exact control IDs (for your security & GRC team)

L2 · AI drafts, a human approves

SEF-06HRS-15DSP-17

L3 · AI acts, a human supervises

LOG-15LOG-16GRC-15

L4 · AI acts, humans audit after

SEF-07IAM-18LOG-12

These are real CSA AI Controls Matrix objectives. Governance lens: Security Incident Management, E-Discovery, & Cloud Forensics · Threat & Vulnerability Management.

Incident summarization & commsTurn a closed incident into the post-incident report and the stakeholder communications.Cuts time per incident report

Why it’s a good place to start: Pure language work on material that already exists in the case record — the lowest-risk, fastest-payback AI fit in incident response.

Ways to help this job — a fitted skill is just one option

Fitted skillProcessPeople

The safeguards grow as you let AI do more

L2AI drafts, a human approves3 to start
L3AI acts, a human supervises+2 more
L4AI acts, humans audit after+2 more
Show the exact control IDs (for your security & GRC team)

L2 · AI drafts, a human approves

SEF-01SEF-03DSP-17

L3 · AI acts, a human supervises

GRC-15LOG-16

L4 · AI acts, humans audit after

SEF-05LOG-12

These are real CSA AI Controls Matrix objectives. Governance lens: Security Incident Management, E-Discovery, & Cloud Forensics · Governance, Risk and Compliance.

Detection-rule engineeringWrite, test and tune SIEM detections for new threats and noisy rules.Cuts time to new detection

Why it’s a good place to start: Scarce-skill bottleneck work where AI drafting demonstrably compresses the idea-to-deployed cycle; output is testable, so quality is verifiable.

Ways to help this job — a fitted skill is just one option

Fitted skillVendor AI featureProcess

The safeguards grow as you let AI do more

L2AI drafts, a human approves3 to start
L3AI acts, a human supervises+3 more
L4AI acts, humans audit after+2 more
Show the exact control IDs (for your security & GRC team)

L2 · AI drafts, a human approves

LOG-03TVM-05HRS-15

L3 · AI acts, a human supervises

LOG-07GRC-15TVM-13

L4 · AI acts, humans audit after

LOG-14IAM-18

These are real CSA AI Controls Matrix objectives. Governance lens: Logging and Monitoring · Threat & Vulnerability Management.

Threat-intel digestionRead the feeds and advisories; extract what applies to this org; brief the team and update watchlists.Cuts time to actionable intel

Why it’s a good place to start: Reading-heavy, daily, chronically under-served; summarization with org-context filtering is a proven LLM strength.

Ways to help this job — a fitted skill is just one option

Fitted skillProcess

The safeguards grow as you let AI do more

L2AI drafts, a human approves3 to start
L3AI acts, a human supervises+2 more
L4AI acts, humans audit after+2 more
Show the exact control IDs (for your security & GRC team)

L2 · AI drafts, a human approves

TVM-04HRS-15DSP-17

L3 · AI acts, a human supervises

LOG-16GRC-15

L4 · AI acts, humans audit after

TVM-10LOG-12

These are real CSA AI Controls Matrix objectives. Governance lens: Threat & Vulnerability Management.

Vulnerability triage & prioritizationRank the scanner backlog by real exploitability and business context; route fixes to owners.Cuts critical-vuln backlog age

Why it’s a good place to start: Backlogs are universal and unbounded; context-aware ranking is where AI beats static CVSS sorting, and backlog age is already tracked.

Ways to help this job — a fitted skill is just one option

Vendor AI featureFitted skillDeterministic automation

The safeguards grow as you let AI do more

L2AI drafts, a human approves3 to start
L3AI acts, a human supervises+2 more
L4AI acts, humans audit after+2 more
Show the exact control IDs (for your security & GRC team)

L2 · AI drafts, a human approves

TVM-09TVM-03HRS-15

L3 · AI acts, a human supervises

TVM-08GRC-15

L4 · AI acts, humans audit after

TVM-11IAM-18

These are real CSA AI Controls Matrix objectives. Governance lens: Threat & Vulnerability Management.

Security Governance, Risk & Assurance

2 plays
Security-questionnaire & vendor-risk responseAnswer inbound security questionnaires and assess vendors against the org’s control baseline.Cuts questionnaire turnaround

Why it’s a good place to start: Document-heavy, template-shaped, perpetually backlogged; answers are checkable against the control record, so quality is auditable.

Ways to help this job — a fitted skill is just one option

Fitted skillProcess

The safeguards grow as you let AI do more

L2AI drafts, a human approves3 to start
L3AI acts, a human supervises+3 more
L4AI acts, humans audit after+2 more
Show the exact control IDs (for your security & GRC team)

L2 · AI drafts, a human approves

GRC-09HRS-15DSP-17

L3 · AI acts, a human supervises

GRC-15STA-13LOG-16

L4 · AI acts, humans audit after

LOG-12IAM-18

These are real CSA AI Controls Matrix objectives. Governance lens: Governance, Risk and Compliance · Supply Chain Management, Transparency, and Accountability.

Audit-evidence preparationCollect, organise and narrate the evidence pack for internal and external audits.Cuts evidence-collection time per audit

Why it’s a good place to start: Audits recur on a calendar; the work is retrieval-and-assembly, the format is fixed, and hours are already billed — measurement comes free.

Ways to help this job — a fitted skill is just one option

Fitted skillProcess

The safeguards grow as you let AI do more

L2AI drafts, a human approves3 to start
L3AI acts, a human supervises+3 more
L4AI acts, humans audit after+2 more
Show the exact control IDs (for your security & GRC team)

L2 · AI drafts, a human approves

A&A-05A&A-01DSP-17

L3 · AI acts, a human supervises

A&A-06GRC-15LOG-16

L4 · AI acts, humans audit after

A&A-03LOG-12

These are real CSA AI Controls Matrix objectives. Governance lens: Audit & Assurance · Governance, Risk and Compliance.

The catalog carries no performance numbers on purpose — the “before” and “after” are yours, measured on your own work at assessment time. One fit has been measured so far (Modeled, on a staging copy); everything else is a starting template until you fit and measure it.