Unsexy AI in Cybersecurity (Notes on Attention, Responsibility, and Systems That Refuse to
Unsexy AI in Cybersecurity
(Notes on Attention, Responsibility, and Systems That Refuse to Lie)
FYA: Raymond Ambury 😎
Most AI in security is marketed as salvation.
What we actually need are systems that interrupt our worst cognitive habits.
Security doesn’t fail for lack of intelligence.
It fails because human attention degrades under noise, and we keep building machines that produce more of it.
This is not a tooling problem.
It’s applied psychology with a pager.
1. Asset Inventory as an Observation Problem
An asset is neither confirmed nor denied until something goes wrong.
AI that continuously observes the environment collapses uncertainty:
-the asset is real
-or it’s removed from the story we tell ourselves
Clarity is cheaper than forensics.
2. Alert Fatigue and Behavioral Conditioning
After enough false positives, people stop trusting cause and effect.
AI shouldn’t “detect threats.”
It should shape attention; rewarding engagement only when it matters.
Most alerts don’t deserve action.
This isn’t neglect. It’s conditioning.
3. Responsibility in Distributed Systems
Every incident includes:
-approvals without understanding
-controls without owners
-dashboards mistaken for decisions
AI’s role isn’t foresight.
It’s accountability mapping:
-who could act
-who was overloaded
-where responsibility dissolved into process
Failures emerge from systems, not villains.
4. Identity and Purpose in Access Control
Many identities persist long after their reason for existing is forgotten.
AI that highlights:
-accounts without clear function
-permissions justified by habit
-access that exists because removal felt risky
Access sprawl isn’t malicious.
It’s existential drift.
5. Phishing Triage as Risk Allocation
No system can examine everything with equal care.
AI must allocate attention:
-deciding what deserves human review
-seeing patterns humans cannot
-accepting that tradeoffs are inevitable
Precision isn’t the goal.
Damage reduction is.
6. Control Validation as Empirical Practice
Controls are assumed effective because they are documented.
AI that periodically asks:
“Can this be demonstrated right now?”
If a control is never exercised, it’s theoretical.
Security is empirical by necessity.
7. Automation and the Removal of Heroics
Burnout isn’t accidental; it’s structural.
AI that reduces:
-emergency rituals
-improvisational response
-reliance on individual endurance
The goal isn’t brilliance.
It’s continuity.
Closing Thought
AI won’t meaningfully improve security by outthinking adversaries.
It will do so by reducing ambiguity, noise, and self-deception.
The highest-leverage systems:
-collapse uncertainty
-preserve attention
-enforce uncomfortable clarity
Unsexy.
Quiet.
Effective.
Which is why they rarely get applause.
scottg/out 🚀
Threat intelligence every morning — new victims, new groups, what matters, in plain English. Free, with receipts.
Subscribe to the Daily →
Scott Gardner ·