The AI Security Team Member Who Hallucinates (but Still Gets Invited to Meetings)
LLM-based tools are now embedded across cybersecurity operations — triaging alerts, summarizing threat intelligence, drafting incident reports — and are fast, cheap, and useful. They also hallucinate: per the SANS 2024 Security Operations Survey, 76% of teams use AI-assisted tools daily, and 41% have hit AI-generated hallucinations in threat reports weekly. Practical, operations-focused guidance for managing that risk is largely missing, tending toward technical failure-mode analysis or policy ignoring under-resourced teams for whom imperfect AI beats no analysis. The takeaway: keep deploying AI, but only with skepticism, verification, and frameworks for logging, validating, and trust-tiering its output.
Speakers
Additional details
Session Type
In-Person, Breakout
Session Tag
AI Services, Security Operations
Role
Incident Responder, Security Managers, SOC Analyst, Threat Hunter