Threat reality versus hype — what AI actually changes for analysts.
What you will cover
AI-enabled social engineering: deepfake voice and video, spear phishing at machine scale, synthetic pretexting
LLM-assisted adversary workflow: reconnaissance, phishing infrastructure, malware iteration and evasion
Agentic attack chains and machine-speed recon — what compresses, what doesn’t
Separating demonstrated capability from marketing: evidence-based threat perception
Practice prompt
Collect three recent “AI threat” claims from news or vendor blogs. For each, write one sentence of demonstrated evidence and one sentence of speculation. Recalibrate your prior with base rates, not narrative hype.
Human factors lens: threat perception under novelty — how availability bias and narrative hype distort analyst priors, and how to recalibrate with base rates.
Module 02
AI in the Analyst’s Toolkit — Power & Failure Modes
Copilots, triage, and the hallucination problem in live workflow.
Prompt-driven investigation: structured querying of logs, pcaps and intel through natural language
Failure modes that matter: hallucination, confabulation, sycophancy, silent omission, prompt injection via retrieved content
Local vs. cloud models: data handling, evidential integrity and client-confidentiality boundaries
Practice prompt
Ask any copilot to enrich an unfamiliar IOC. Demand sources. Note where it invents a CVE, vendor, or attribution. Write a three-line “trust-but-verify” checklist you will use under deadline pressure.
Human factors lens: the automation conundrum — the better the tool, the worse the operator’s catch rate when it fails.
Module 03
Calibrated Trust: Automation Bias & Vigilance
The core human factors module — matching confidence to demonstrated reliability.
What you will cover
Automation bias and complacency: evidence from aviation, medicine and process control — and its arrival in the SOC
Algorithmic authority: why AI output feels more credible than a colleague’s, and when that’s rational
Alert fatigue 2.0: AI-generated detections, triage queues and vigilance decrement
The out-of-the-loop performance problem: losing situational awareness in systems you nominally supervise
Structured verification protocols: second-channel confirmation, provenance checks, dissent-by-design in team review
Practice prompt
Design a one-page verification protocol for “AI recommends close”. Include: when to escalate anyway, what second channel to use, and how to record the dissent.
Human factors lens: calibrated trust as a trainable skill — matching confidence to demonstrated reliability, per tool, per task, per context.
Module 04
Skill Maintenance in an AI-First SOC
Keeping tradecraft alive when the model drafts the first pass.
What you will cover
Cognitive offloading and skill degradation: what deskilling research says about analysts who never draft the first pass
Verification-before-output: reading AI drafts like a hostile reviewer, not a grateful recipient
Deliberate practice: manual-first drills and “AI-shadow” exercises (do it yourself, then diff against the model)
Where AI must not be used: evidential chains, legal thresholds, novel intrusion sets, client-attributable judgement calls
Practice prompt
Schedule one AI-shadow drill this week: investigate a small log or ticket manually first, then compare to an AI draft. List two things you caught that it missed, and one thing it caught that you missed.
Human factors lens: the “use it or lose it” curve — designing a personal practice regime that fits inside a working week.
Module 05
Governance, Accountability & Capstone Thinking
Auditable AI-assisted work — what lands on an analyst’s desk in practice.
What you will cover
Governance frame: ISO/IEC 42001, NIST AI RMF, EU AI Act awareness — practical implications for analysts
Accountability when the AI is wrong: logging, provenance and auditability of AI-assisted decisions
Writing reports that disclose and defend AI assistance
Write a short client-ready summary of a fictional incident in which AI assisted triage. Explicitly record: what the AI produced, what you verified, what you changed, and who owns the conclusion. Then list two injected-error patterns you would hunt for under time pressure.
Human factors lens: debrief what the team delegated, what it verified, what it missed, and what changes on Monday.
Assessment
Knowledge check
Four scenario questions from the SAN-101 item bank. This is a learning check — not a formal certification exam.
Q1. An AI copilot summarises an inbound alert and concludes “no further action required.” Your queue is long. The calibrated response is to:
Silent omission is the highest-consequence, lowest-visibility failure mode of AI triage. Closure recommendations earn the same structured verification as escalations. (Module 3)
Q2. Which failure mode is most likely when an LLM is asked to enrich an unfamiliar indicator of compromise?
Confabulation is the default failure on low-knowledge queries. Provenance checks are mandatory on enrichment output. (Module 2)
Q3. After six months of AI-first drafting, your manual log-analysis speed has measurably dropped. The human factors term and correct countermeasure are:
Deskilling is the predictable cost of never drafting the first pass. Counter with structured practice regimes. (Module 4)
Q4. An AI-assisted incident conclusion is auditable when:
Accountability attaches to people and records, not policies or vendors. (Module 5)
–
Free online edition for individual learning. Not CPD-accredited. Not (ISC)² accredited. Not a substitute for instructor-led delivery.