By Fadeen Davis, Sr Principal Analyst, Gartner
Generative AI is transforming how cybersecurity teams work. From summarizing complex information to accelerating research and drafting content, these tools can help cybersecurity leaders move faster and operate more efficiently. As organisations embed AI into everyday processes, many CISOs are beginning to explore its role in creating cybersecurity strategies and policies.
However, strategy creation should not suffer in a bid to be faster. Cybersecurity strategies and policies are more than documents. They reflect an organisation’s business priorities, risk appetite, regulatory obligations, and operational realities. While GenAI can accelerate the drafting process; it cannot replace an organisation’s cybersecurity leadership because it doesn’t understand the business context and risks.
organisations that rely on AI-generated outputs without adequate human oversight risk producing generic guidance that fails to address evolving business priorities, regulatory requirements, and cultural nuances. It may lead to compliance gaps, operational friction, weakened board confidence, and increased exposure to reputational or financial risk.
To realize the benefits of GenAI while maintaining accountability, CISOs should focus on four key actions.
Retain Executive Control and Business Context
The first step is to ensure that GenAI supports the development of cybersecurity strategy and policy rather than driving it. Asking GenAI to create a strategy or policy on its own can undermine quality and governance controls, increasing the risk of producing unreliable or generic content that does not reflect the organisation’s priorities and requirements.
Instead, CISOs should design these documents intentionally, breaking them into logical sections, defining structured inputs, and using GenAI to assist with specific activities such as research, summarization, analysis, or drafting individual components. Organisations should provide GenAI with information specific to their culture, risk appetite and operational realities, rather than relying on generic templates.
When developing strategy, organisations should start with business, technology and environmental drivers that influence the cybersecurity programs priorities. For policy development, the focus should be on maintaining structure and consistency with existing standards and governance requirements. CISOs should also clearly define the intended audience, tone and speaker so the model has the context it needs, rather than forcing it to make assumptions or generate unnecessary detail.
Engineer Prompts with Precision
AI outputs are only as good as the instructions used to generate them. Generic prompts often produce generic recommendations and increase the likelihood of inaccuracies or hallucinations.
Every prompt should be grounded in business reality. This means clearly defining the business drivers influencing cybersecurity priorities, whether related to growth initiatives, regulatory developments, operational resilience, or technology transformation. organisations should also specify their current risk appetite, the intended audience, and the desired outcome, whether strategic guidance, policy support, control assessment, or gap analysis.
Using precise instructions and action-oriented language, such as analyze, summarize, or identify gaps, helps improve relevance and quality. Inputs from audits, executive discussions, and regulatory reviews can further strengthen outputs by ensuring they reflect organisational realities rather than generic assumptions.
Inject Regulatory and Audit Requirements
One of the most important limitations of AI is its lack of awareness regarding an organisation’s specific compliance obligations. AI cannot determine which regulations apply to a business, anticipate upcoming enforcement deadlines, or understand the nuances of industry-specific requirements without explicit guidance.
Cybersecurity programs should be periodically evaluated against recognized frameworks and standards such as ISO 27001, NIST Cybersecurity Framework, and NIST 800-53, while also accounting for contractual obligations and regional regulatory requirements. Cybersecurity leaders should manually incorporate required controls, governance expectations, and operational procedures into AI-generated drafts. By embedding these requirements early and consistently, CISOs can transform AI outputs into actionable strategies and policies that are better positioned to withstand scrutiny from auditors, regulators, executive leadership, and boards.
Make Rigorous Human Review Non-Negotiable
No matter how advanced AI becomes, cybersecurity strategy and policy require expert judgment before they can be approved and operationalized. Every AI-generated draft should be treated as a starting point rather than a finished product.
A rigorous review process helps identify inaccuracies, challenge assumptions, and determine whether recommendations align with business goals, technology priorities, and risk management objectives. It also ensures that policies address material risks, provide practical guidance, and support employee adoption.
Human reviewers should verify compliance with current laws and frameworks, assess whether recommended controls are necessary and appropriate, and confirm that cybersecurity investments are focused on the risks that matter most to the organisation.