SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact Us
Ask someone to describe a CISO's toolkit and the conversation almost always starts with security technology. SIEMs, EDR platforms, vulnerability scanners, and threat intelligence services dominate the discussion. They're all important, but they're not what fills the day of the average security leader.
The longer you spend in the role, the more you realise that being a CISO is less about operating security tools and more about operating a business function. Governance, risk management, compliance, reporting, audits, executive communication, and organisational alignment occupy far more time than investigating alerts or evaluating the latest security product.
The tools that make those responsibilities possible are often overlooked because they aren't particularly glamorous. Yet they're the systems that enable security programmes to scale, support business growth, and demonstrate value to executive leadership.
When organisations ask how to build stronger governance, the first recommendation is rarely a software platform. The real work begins with getting everyone on the same page. That sounds deceptively simple, but it's often the hardest part of governance.
Technology teams, legal, procurement, compliance, privacy, and business leaders all have different priorities, terminology, and measures of success. If those groups aren't aligned, no governance platform will solve the problem.
That's why organisations should build active governance councils rather than passive steering committees. These shouldn't be meetings that exist simply because the calendar says they should. They should be working sessions where business stakeholders bring forward initiatives, technology teams explain how they can enable them and security identifies practical ways to manage the associated risks.
When governance works this way, security stops being viewed as the department that says "no." Instead, it becomes the function that helps the organisation get to "yes" responsibly. That shift in mindset changes every conversation that follows.
Once governance processes are in place, technology can make them significantly more effective. Many organisations have invested in governance, risk, and compliance platforms such as ServiceNow GRC, RSA Archer, OneTrust, or MetricStream to centralise policies, risk registers, control evidence, and audit activities. These platforms improve visibility, reduce duplication, and provide the traceability that regulators and auditors increasingly expect.
However, it's important not to mistake software for maturity. Some organisations have sophisticated GRC implementations but struggle to maintain current information because ownership and processes were never clearly defined. Other organisations run surprisingly effective governance programmes using little more than SharePoint, Confluence, and carefully managed spreadsheets.
A governance platform does not create maturity on its own. Maturity comes from establishing repeatable processes, clear ownership, and ways of working that people consistently follow. Technology simply makes those processes more efficient and scalable.
Security professionals often laugh about Excel being one of the most widely deployed governance tools in the world. The joke persists because it's true. Many governance programmes still rely on spreadsheets to track asset inventories, AI use cases, supplier assessments, audit findings, policy exceptions, and remediation activities.
While enterprise platforms offer greater automation and scalability, a spreadsheet that is actively maintained will always be more valuable than an expensive system filled with outdated information.
The challenge comes as organisations grow. Cloud services, third-party suppliers, AI applications, and business systems multiply rapidly, making manual tracking increasingly difficult. As organisations grow, the sheer volume of assets, risks, and governance activities eventually make spreadsheets difficult to manage. That is when many organisations transition to dedicated governance platforms that provide greater visibility, automation, and consistency.
One of the biggest changes over the past decade has been how CISOs communicate risk. Executive teams don't make decisions based on CVSS scores or vulnerability counts. They make decisions based on business impact.
That's why many organisations have adopted structured approaches such as FAIR to quantify cyber risk in financial terms. Even organisations that don't implement formal quantification frameworks can benefit from maintaining well-structured risk registers that identify key risks, assign ownership, and document mitigation strategies.
Interestingly, the register itself is not the most valuable output. The value comes from the conversations required to build it. The process forces organisations to think systematically about what could go wrong, what matters most to the business, and how much risk they are prepared to accept. Much like writing a business plan, the exercise itself often delivers more value than the document that eventually gets filed away.
If there's one lesson that consistently emerges from governance reviews, it's that accountability matters more than inventory. Most organisations can produce a list of technology assets. Far fewer can identify who owns every cloud workload, SaaS application, business system, or AI capability.
When ownership is unclear, projects become orphaned. Nobody reviews access permissions, monitors ongoing health, or takes responsibility for responding when new vulnerabilities emerge. Over time, those forgotten systems become operational blind spots.
Accountability becomes even more important as organisations deploy AI. Every AI application or autonomous agent should have an identified business owner who remains accountable for how it operates, the data it accesses, and the outcomes it produces. Technology may automate tasks, but accountability should never be automated.
Executive reporting is another area where governance tools can make an enormous difference. Whether an organisation uses Power BI, Tableau, or ServiceNow dashboards is less important than the questions those dashboards answer.
Boards rarely want operational metrics in isolation. They want to understand whether risk is improving, where investment is needed, and whether security is helping the organisation achieve its strategic objectives.
The most effective dashboards focus on trends rather than snapshots. They combine risk, compliance, audit findings, asset ownership, and programme maturity into a narrative that executives can understand without a technical background.
Honest reporting is equally important. Organisations are still maturing their approaches to areas such as AI governance and digital resilience. Being transparent about current capabilities, existing gaps, and the investment required to improve builds significantly more credibility than presenting perfect-looking metrics that hide uncertainty.
Documentation is often viewed as something organisations produce for auditors, but that's the wrong perspective. Documentation exists to preserve organisational knowledge.
If critical governance processes exist only in someone's head, they disappear the moment that person changes roles or leaves the company. Mature organisations document not only policies, but also standards, workflows, decision criteria, and governance processes so that operations remain consistent through organisational change.
Good documentation has also become one of the strongest foundations for responsible AI adoption. Organisations can automate only the processes they genuinely understand. If a workflow cannot be documented consistently, it's unlikely to be automated successfully.
Commercial governance platforms remain essential for many large enterprises, but they aren't the only options available. I've seen organisations simplify governance using collaborative documentation platforms, workflow automation tools, and open-source technologies that integrate surprisingly well with existing processes.
Platforms such as Wiki.js for documentation, n8n for workflow automation, Neo4j for relationship mapping, and OpenProject for collaborative planning can complement commercial tools without requiring significant investment.
Technology plays an important role, but effective governance ultimately depends on maintaining accurate information and establishing processes that people understand and trust.
Security technology will always remain a critical part of the cybersecurity profession. But most CISOs are not spending their time inside security products. They spend them in governance council meetings, risk reviews, board meetings, audit preparation, asset ownership discussions, executive dashboards, documentation, reporting, cross-functional collaboration, and the operational systems that keep all these activities connected.
Those may not be the tools that generate headlines, but they are the ones that determine whether a security programme becomes a strategic business capability or simply another technology function.
The strongest security programmes aren't built on the largest security stacks. They're built on governance that enables the business to move faster because everyone understands the processes, priorities, and responsibilities. That's the real toolkit of the modern CISO.
Explore the modern CISO’s governance toolkit infographic for a practical seven-step framework to align stakeholders, centralise information, track ownership, quantify risk, visualise progress, document processes, and automate governance activities.


Chris Cochran is a Marine Corps veteran, cybersecurity leader, and strategist with deep expertise in threat intelligence, security operations, emerging technology, and executive leadership.
Read more about Chris Cochran