Archived post from legacy Decis reporting
(I’ll keep this short as I don’t want to suddenly spam your inbox after weeks of silence.)
I’ve been collaborating with Doug Gray from HumanRisks on an AI white paper these last few months, and I’m pleased to announce that it’s now published.

We took a much deeper dive into the topic than in any of our previous work, conducting a thorough review of how AI can assist security risk managers. We based this on the most recent academic studies of how knowledge workers make best use of these tools and aligned these AI benefits with identified gaps and challenges in Security Risk Management.
(And by deep-dive, I mean deep: we get right down to the task level, showing how specific processes in the enterprise security risk management (ESRM) cycle can be enhanced by AI.)
But even if you don’t need to get to that level of detail, it’s giving you the background and a framework to think about how you can implement AI in your own organization.
We hope that this is something that security risk managers can pick up and put to use right away. But to be honest, there’s a lot for risk managers in general as the top-level framework is quite flexible.
The executive summary is below plus a link to the shared download page.
This was quite an endeavor and I’m hugely grateful to Doug for not only being a great thought partner and co-author but for tackling the meatiest parts of the paper and steering it to publication. Thank you.
I hope you enjoy the paper and find something of value here.
All my best

AI Applications In Enterprise Security Risk Management
Doug Gray, Andrew Sheves, September 20204
Executive Summary
Following the release of highly accessible AI Large Language Models in late 2022, we have witnessed the widespread and rapid global adoption of AI tools for both personal and workplace applications.
As sufficient time has now passed to allow the impact of these advancements to be looked at and practical benefits to be identified in more detail, this paper seeks to examine where these identified benefits are likely to play a significant role in a sector crucial to organizations globally: Security Risk Management.
The analysis begins with an examination of the benefits of AI in the broader workplace via a review of several well-regarded studies. Next, we compare these benefits to widespread challenges identified by leaders in the security risk management industry, allowing us to contextualize applications of AI tools specifically for security risk management teams. In particular, we focus on teams seeking to improve the efficiency and efficacy of core management processes and procedures with innovative solutions.
Included is a detailed breakdown of AI applications across the Enterprise Security Risk Management process as defined by ASIS International, to clearly identify areas where Security Risk Leaders can consider implementations across their workflows, overcome strategic challenges and drive a more effective security posture across their organizations. Based on this assessment, we conclude that the efficiency and time- saving benefits of AI-augmented processes, in addition to the additional strategic insights AI can support, are well placed to be levered by Security Risk Leaders in order to elevate the strategic value of security activities.
General Benefits of AI
AI Tools can support significant efficiency improvements across routine tasks
Deployment of AI tools in the workplace aids non-expert employees more
AI models do however continue to perform poorly when pushed beyond their limits
Applicable Security Management Challenges
Security leaders are facing an increasingly complex operating environment
Security risk teams deploy a wide range of tools with complex outputs as part of their day-to-day workflows
Many security teams continue to be seen as tactical functions within their organizations
Applied AI Benefits for Security Leaders
AI tools are well-placed to augment, enhance, and improve security teams’ workflows at scale
AI pattern recognition, filtering and data synthesis capabilities will support a significant uplift in proactive insights across complex threat environments
Efficiency improvements from AI Tools can support leaders in elevating the profile of security within their organizations from tactical to strategic
While comprehensive, we stress that the findings included in this paper are intended to be a practical resource for security risk teams and are therefore non-technical, based on both the citations below and observations we have made in our own work.
AI has significant potential to benefit the security risk management sector. It is the opinion of the authors that the industry should move towards adopting these tools with a combination of speed, caution and empathy. Noting that there remains to be security, confidentiality and staff welfare issues that require ongoing consideration.
