Guardrails May Be Helping Attackers, Warns Cybersecurity Expert
A writer for the Cisco Talos Blog discusses how poorly-designed AI guardrails may be helping attackers. These guardrails are supposed to prevent certain actions, but they can also slow or halt investigations, giving attackers time to complete their mission.
The writer notes that operational sovereignty relies on having control of one's own limits and policies. This means that security teams should have the flexibility to customize guardrails according to their own threat model and temporarily remove specific safeguards under authorized circumstances.
Cisco Talos recently evaluated 66 large language models (LLMs) and reasoning combinations for security operations, but found that selecting the right model is a complex balancing act between efficacy, speed, cost, and consistency. The writer advises organizations to test models against their specific workflows before deploying them, build representative cases, track variables, and establish acceptable thresholds.