Metricstream Logo
×
Blogs

AI-Powered Cyber Risk Management: Separating Hype from Operational Reality

AI-Powered Cyber Risk Management
6 min read

Introduction

We recently hosted a webinar on a question many cyber risk teams are working through right now: how to bring AI into cyber risk management without losing control of the decisions it informs.

Our keynote speaker was Shradha Reid, Cybersecurity Risk Director at DTCC, where she leads the cybersecurity risk treatment program. Pat McParland, VP of Product Marketing at MetricStream, moderated. Shradha works in one of the most tightly regulated environments in financial services, so her view on where AI fits was grounded in practice. Here are six takeaways from the session.

For the full discussion, watch the webinar here: Link

At a Glance: Six Takeaways on AI-Powered Cyber Risk Management

QuestionKey Takeaway
Is AI creating new cyber risks?AI is amplifying familiar cyber risks while introducing governance challenges. It's changing the speed, scale, and reach of familiar ones like phishing and identity attacks.
Where does AI help cyber risk teams today?Vulnerability prioritization, risk assessments, and emerging threat analysis, by correlating data that teams already hold.
How much of an assessment can AI handle?Shradha's rough estimate was 60 to 70% of the mechanics. The judgment calls still belong to people.
Is full autonomy the goal?No, but selective, bounded autonomy with oversight proportional to the consequences. Autonomy isn't a sign of maturity, and accountability for AI-driven decisions stays with humans.
What does AI need before it's useful?Connected risk context, with assets, threats, controls, evidence, issues, and owners linked in one taxonomy.
What shouldn't change as AI scales?Accountability, traceability, explainability, ongoing validation, and human control over high-stakes decisions.

1. AI Changes the Speed of Cyber Risk, Not Its Nature

Shradha started by pushing back on the idea that AI is an entirely new problem. Phishing, social engineering, identity attacks, and vulnerabilities have been around for years. What's different is how quickly attackers can run reconnaissance, how convincing impersonation has become, and how cheaply social engineering now scales. That puts far more pressure on identity and access controls.

Defenders get the same acceleration, but most GRC processes still run on a periodic cycle. You assess, collect evidence, report, and repeat next quarter. The threat environment doesn't follow that calendar. Shradha was careful here: faster governance doesn't mean automating risk decisions. It means getting the right information to decision makers sooner, before a vulnerability is exploited or before an exposure becomes an incident.

2. In Cyber Risk Management, Severity Isn't the Same as Risk

Shradha applies one test to any AI use case. Does it solve a problem you already have, or does it exist because the technology does? Vulnerability prioritization passes that test.

She described two vulnerabilities, both rated critical. One sits on a low-value asset with compensating controls and no meaningful threat activity. The other sits on a business-critical asset, is known to be exploited, lacks compensating controls, and affects an important service. Both carry the same CVSS rating, but they don't carry the same risk. AI helps by pulling together vulnerability, threat, asset, control, and business context much faster than an analyst can.

It doesn't decide what risk the organization will accept. The same logic applies to emerging threats. Shradha's view is that most cyber teams already have more information than they can process. The useful part is helping you decide whether a threat matters to you. Which technology is affected? Are you exposed? Which business services are at stake, and which controls already mitigate them?

3. AI Can Take on the Assessment Grind, but the Judgment is Yours

Anyone who has run a risk assessment knows how much time goes into mechanics. There's evidence gathering, document review, control mapping, comparing responses against prior assessments, and writing the narrative. Shradha estimated that AI could cover roughly 60-70% of that work. In her own use, it has summarized evidence, flagged inconsistencies in documentation, suggested mappings to policies and control standards, and drafted first narratives.

Did it produce false positives? Yes. But those flags still led her to better questions for control owners. Her bigger warning was about ownership. An AI-generated assessment isn't your work until you've challenged it. Does the evidence support the conclusion? Is the residual risk reasonable? What's missing from the data, and what assumptions sit underneath it?

4. Autonomy isn't a Measure of Maturity

"One of the biggest mistakes we can make with AI is treating autonomy as the definition of maturity," Shradha said. She walked through a continuum. AI can assist by searching policies, summarizing documents, and drafting narratives. It can analyze by correlating data and detecting anomalies. It can recommend risk ratings, control gaps, and remediation priorities. At the far end, it can act by triggering workflows, creating issues, and changing statuses. Each step raises the stakes on data quality and validation. The question she asks at every stage is what happens if the

AI is wrong. Picture a material cyber exposure rated as low risk and passed into a regulatory report with no human review. "You can't go and say, AI did it," she said. The accountability stays with the organization. Her answer is human-in-the-loop review for high-stakes decisions and human-on-the-loop oversight for lower-stakes tasks, where people monitor exceptions and escalations.

5. AI Only Knows the Risk Context You Give It

AI will present its output confidently, whether or not it has the full picture. A vulnerability record on its own tells you something technical. Context tells you whether it sits on a critical asset and whether anyone is actively exploiting it.

Shradha described the chain that creates that context. Threats connect to assets. Assets carry vulnerabilities. Controls mitigate them, and evidence supports the controls. Deficiencies become issues, and issues become remediation plans with named owners. The hard work, she said, lives in data architecture, taxonomy, integration points, ownership, and the ability to trace one item to the next. Without that foundation, AI has nothing authoritative to reason from.

6. Five Things That Should Stay True as AI Scales

Shradha closed by emphasizing that the governance principles shouldn't weaken just because AI is involved.

  • Accountability: A named person owns each risk and each AI use case. Shared ownership usually means nobody is accountable. 
  • Traceability: In a regulated environment, you will need to show how you reached an answer. That includes the data used, the model version, what changed, and who approved it. 
  • Explainability and challenge: What matters is whether your team can understand the main drivers of a conclusion, disagree with it, record that disagreement, and override it. 
  • Validation and monitoring: Data, threats, models, and processes change. What worked six months ago needs checking again. 
  • Controlled autonomy: AI recommends, and people decide on high-stakes calls.

Boards want to understand the organization's risk, she noted, and an AI-generated slide deck doesn't give them that. She sees governance as what makes AI adoption defensible, rather than what slows it down.

What This Means for Cyber Risk and GRC Leaders

Wherever your team is in its AI adoption journey, Shradha's message is the same. The destination isn't autonomous GRC. It's a team that spends less time hunting for information and more time interpreting and challenging it. Getting there depends less on the AI model and more on connected, authoritative risk data.

See how MetricStream's AI-powered Cyber GRC connects assets, threats, vulnerabilities, controls, evidence, and issues with business context in a single platform. Its AI-assisted workflows help teams surface and prioritize exposure, while people remain responsible for reviewing recommendations and making consequential risk decisions.

Watch the full webinar:

 
tharika

Tharika Tellicherry Manager, Product Marketing, MetricStream

Tharika is a Product Marketing Manager at MetricStream, where she leads go-to-market strategy, messaging, and sales enablement for Cyber GRC products. With over eight years of experience driving growth for AI, analytics, and SaaS solutions, she specializes in translating complex technologies into clear, customer-centric narratives that accelerate adoption. A storyteller at heart, she’s passionate about connecting product innovation with meaningful market impact.