//Security operations

AI in a security operation, done so it holds.

For security directors and the people who run corporate security teams. Matt Aubin built the AI his own firms run on, and the problems are the same on your side of the fence: alert volume, vendor claims nobody can check, staff already using chatbots on material they should not, and an insurer that has started asking questions in writing.

By Matt Aubin, Founder, Southern Recon Agency and E3 Legacy Intel. CDFE, FBCI. Investigating since 2009. Updated .

//The five problems

Said the way security directors actually say them.

These are the five that come up first in nearly every conversation with a security leader. If one of them is the reason you are reading this, that is the conversation to start.

My team is drowning in alerts and every vendor says AI fixes it.”

Some of it AI genuinely carries: the first pass over an alert queue, the pattern nobody has time to look for, the summary of what happened for the people who were not on the bridge. Some of it AI quietly makes worse, because a confident wrong summary of an incident is more dangerous than no summary. The work is knowing which is which in your environment, on your data, with your staffing, and writing that down so the answer does not change with whoever is on shift.

I cannot tell which vendor claim is real.”

Almost every product in this market now says AI on the box. Very few can answer what the model actually does, what data leaves your building to do it, what happens when it is wrong, and what record it leaves behind. Those four questions separate a tool from a demo. He has built the thing these vendors are selling, so he knows which answers are hard and which are evasions.

My staff are already pasting sensitive material into chatbots.”

They are, and telling them to stop has never worked anywhere. What works is a written rule they can actually follow, a sanctioned place to do the work that is easier than the unsanctioned one, and a way to see whether the rule is holding. That is a policy, a tool decision and a training session, and they have to be done together or none of them holds.

My insurer and my legal team have started asking about AI.”

Then the answer wants to exist in writing before the next question arrives. What they tend to ask for is specific: where AI is used, who checked its output, what record exists of that check, and what was disclosed. An organization that cannot answer from a document answers from memory under pressure. The signed AI evidence audit is that document, dated and signed by a named and credentialed person, renewed every year as the tools move. What any particular insurer does with it is theirs to decide.

I have to decide whether to build or buy, and I get one shot.”

Most security teams should buy most of it and build one thing that is genuinely theirs. Which one is the whole question, and it depends on what is unique about your environment rather than on what is exciting about the technology. That decision is the first thing a seat is usually spent on, and it is the cheapest hour in the engagement.

Which of the five is yours?

Say it in a couple of lines. You get a straight answer on whether it is a seat, a build, the signed audit or a training day, and the scope comes back in writing.

//What you can buy

The same four things, pointed at a security operation.

A monthly advisory seat

A standing advisor on your calls, in front of your executives and in your inbox: the build or buy call, the vendor review, the rule your staff follow, and what to say when the insurer or the general counsel asks. Priced on value and results, never on hours. What the seat is.

A custom private build

A private AI system built and maintained for one security organization that nobody else runs, pointed at the part of your work that is genuinely yours. It stands on its own and does not need a seat beside it. How a build works.

A signed AI evidence audit

One signed document stating how AI is used, recorded, checked and disclosed in your security work, measured against the Evidence-Grade AI Standard, renewed every year. Written to be handed to an insurer or to counsel. What the audit covers.

Training and keynotes

A session for the operations floor on what AI carries and how to prove what it produced, and an executive briefing for the people deciding what to build or buy. The two training tracks.

//Proof

Checkable, and none of it is a case study about you.

He built it

He built the AI his own investigation firms run on, wrote its requirements, chose its architecture, and has maintained it through every model change since.

He wrote the standard

He authored the Evidence-Grade AI Standard, eight pillars and a checklist for AI assisted findings that have to hold up when someone argues with them.

Rooms he has taught

He has taught for ASIS International and for investigative associations statewide, regionally and internationally, and trained a delegation of Brazilian prosecutors at World Orlando, the State Department sponsored conference.

Seventeen years

Investigating since 2009. Founded his first firm in 2010 and built it into Southern Recon Agency in 2014.

//Questions security leaders ask

Answered straight.

What does AI actually do in a security operation today?

The honest answer is that it carries volume, not judgment. It triages an alert queue, it reads far more log and open source material than a person can, it drafts the incident write up, and it finds the pattern nobody had time to look for. It does not decide what is an incident, it does not decide what to tell your executives, and it does not carry accountability. Every one of those stays with a human, and a security program that blurs that line finds out the expensive way.

How do I stop my staff putting sensitive material into chatbots?

By giving them somewhere sanctioned to do the same work and making it easier than the workaround, then writing one rule short enough to remember, then checking whether it is holding. A ban with no sanctioned alternative is a rule everyone breaks quietly, which is worse than no rule, because you lose the visibility as well. Matt Aubin writes that rule with security leaders and trains the staff on it.

What should I ask an AI security vendor?

Four questions. What does the model actually do, in a sentence a person outside the company can check. What data leaves my environment to make that happen, and where does it go. What happens when it is wrong, and how would I know. What record does it leave that I could hand my insurer or my counsel. A vendor who cannot answer all four in plain English is selling a demo.

Does the signed AI evidence audit apply to a security team, or only to investigators?

It applies to both. The audit states how AI is used, recorded, checked and disclosed in the work, measured against the Evidence-Grade AI Standard, and a corporate security team producing incident findings is in exactly the position an investigation firm is. It is one signed document, renewed every year, and it is written to be handed to an insurer or to counsel.

Who is Matt Aubin, and why security operations?

Matt Aubin is an AI investigation expert and cybercrime specialist, Founder, Southern Recon Agency and E3 Legacy Intel. Investigating since 2009. He built the AI his own firms run on, and the same work sits underneath security operations and investigations: the same evidence problems, the same vendor claims, the same insurer questions. Security is not a smaller version of investigation on this site. It is an equal door.

The standard all of this is measured against is Evidence-Grade AI, the figures an insurer will quote come from the FBI's 2025 Internet Crime Report on the AI fraud numbers page, and if a wire has already left, AI cybercrime consulting is the page for the first seventy two hours.

Tell me what AI is touching in your security operation.

The alert queue, a vendor decision, the rule your staff follow, or the letter from your insurer. Say the shape of it and you get a straight answer.