
AI is rewriting the rules of risk management
With cyber risks and compliance demands increasing, automation is quickly becoming the smartest way for businesses to stay secure, agile and ahead of the curve
Organisations today face unprecedented challenges when it comes to managing risk. More applications, increased cloud migration and the proliferation of software-as-a-service solutions have dramatically expanded the threat landscape. Meanwhile, security teams are struggling with strict regulations, shrinking budgets and talent shortages.
At the same time, chief information and security officers are keen to demonstrate the business value that the security function provides, rather than just being viewed as a cost centre. They want to convey cybersecurity's role in mitigating risk, achieving compliance standards and helping to win new business.
It is against this backdrop that artificial intelligence (AI) presents a double-edged sword, often representing both a significant threat and a powerful solution.
Cybercriminals are using AI to create more convincing phishing attempts and generate more complex attack codes. But AI-powered tools are also providing unprecedented capabilities in risk management and compliance.
'We're seeing more vulnerabilities and attack vectors than ever before,' explains Jeremy Epling, chief product officer at Vanta. 'AI is being used by attackers to create new threats, whether through sophisticated phishing attempts or AI-generated attacks.
'But AI also gives us a capability we never had before: dealing with unstructured data. So much of compliance and security revolves around documents and screenshots, and now we have an entirely new way to understand and provide value.'
Vanta's most recent The State of Trust Report reveals a striking insight: 77 per cent of IT decision-makers believe automation can relieve the manual burden of compliance, saving them time and money. Yet only 60 per cent of business leaders agree. This gap likely stems from a fundamental misunderstanding of the manual burden faced by security teams, says Epling.
'It boils down to who feels the pain every day. Business leaders are looking at the numbers and the ROI and driving the business, but they're not living in these tools every day and building a deep appreciation for how many hours get sucked into these reviews,' he explains. 'Governance, risk and compliance has been underserved for a long time in terms of providing a high level of innovation and helping to drive efficiencies.'
Businesses are spending more time than ever before on compliance. In the UK, companies already dedicate 12 working weeks per year to keeping operations compliant. Security teams in particular often dedicate far more time to compliance than to other value-adding activities, such as cyber strategy and threat mitigation.
Here, intelligent automation offers multiple operational benefits. 'AI can help generate secure code, automate remediation processes and provide a single pane of glass for your entire security programme,' Epling says.
For example, AI can automatically respond to complex security questionnaires and analyse vendor documents, identifying risks and providing actionable insights. It can also ensure consistency around security policies, as AI can detect irregularities across multiple policy documents. Automated systems can also immediately identify documentation issues, which can help prevent last-minute audit complications.
'Instead of spending hours manually reviewing documents and copy-pasting responses, AI can take a first pass on these tasks,' says Epling.
Perhaps most importantly, intelligent automation enables security teams to be seen as strategic business enablers rather than cost centres. 'When you achieve compliance standards, you can unlock new markets and win additional business,' Epling says.
He continues: 'Automation helps us clearly show time savings and improvements in efficiency. For example, when teams use Vanta's automated workflows, we can quantify how much faster they're completing tasks compared to before. That makes it easy for security leaders to go back to their management and explain the tool's value.'
But it's not just security teams that benefit from automation tools, he explains; these systems can also help engineering and IT teams to work more efficiently. 'Since they're not in the security trenches every day, giving them focused, actionable remediation guidance, along with context about why it matters, helps them prioritise effectively,' Epling says.
And with Vanta's tools, such as automated questionnaires, customers are constantly providing feedback to help the firm improve its programmes.
'It's a way to turn security from a cost centre into a growth enabler,' says Epling. 'When you can show how your trust posture helps close deals faster or opens new opportunities, it becomes a clear business-value driver. And it bridges the gap between security teams and leadership, so they're finally speaking the same language.'
For organisations considering intelligent automation, Epling offers some practical guidance.
The first step is to start small – focus on specific areas such as supplier risk or questionnaire management. Then trial AI tools with existing documents and policies, and make sure the AI solutions provide clear citations and explanations.
Epling also advises organisations to consider comprehensive platforms that offer a holistic view of governance, risk and compliance.
'For startups and small businesses, there are tools designed to help you get your first certification,' says Epling. 'You don't need prior knowledge – the right platform will guide you step by step.'
As cyber threats become more sophisticated and the compliance burdens increase, intelligent automation isn't just a 'nice-to-have' – it's becoming a necessity.
Such automation marks a transformative approach to risk management. By embracing AI-powered tools, organisations can not only mitigate risks more effectively but also turn compliance into a strategic business advantage.
'The goal is to spend less time on paperwork and more time on deep, impactful security work that truly protects your organisation,' says Epling.
As cyber threats continue to evolve, the message is clear: intelligent automation isn't just a technological upgrade, it's a critical component of your security strategy.
To learn more, please visit vanta.com

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles


The Independent
24 minutes ago
- The Independent
Elon Musk calls out his own AI tool after embarrassing post
Elon Musk corrected his AI bot Grok on X after it spread misinformation from a fake post. The fake post showed a doctored screenshot of Musk claiming he took Stephen Miller 's wife, Katie Miller. Grok falsely claimed the post was real and had been deleted, prompting Musk to clarify that he never made the post. Katie Miller previously worked with Musk on DOGE and in the White House as a 'special government employee'. Musk's relationship with the Trump administration deteriorated after he criticised President Trump, leading to a fallout. Katie Miller is now in a difficult position due to the strained relationship between Musk and Trump, while continuing to work for Musk.


The Sun
30 minutes ago
- The Sun
Britain's Bond-style ‘Q' boffins unveil underwater drone to take on Putin's cable-cutters…by blowing them to smithereens
BRITAIN'S top defence brainboxes have unveiled a Bond-style underwater drone designed to stop Putin's cable-cutting saboteurs in their tracks. The super sub can hunt out and destroy sabotage threats lurking on the seabed - by blowing them to smithereens. 5 5 5 Developed by the MoD's Defence Science and Technology Laboratory (Dstl), it is armed and ready to protect the UK's vital undersea cables and pipelines. Using a remotely operated vehicle (ROV), Dstl's boffins have added cutting-edge sensors, cameras, and explosive systems to high-tech underwater robot. That way, operators are able to spot unexploded bombs, place charges remotely, and safely neutralise the threat — without risking Royal Navy divers. John, a Dstl explosives engineer, said: 'This technology would be a valuable toolset for keeping our Armed Forces safe whilst providing the public with value for money. 'This unique capability with its sensors, tools and cameras will give operators a real time ability to deal with these underwater hazards in a safe, effective and efficient way.' The underwater drone goes deeper than any diver can, staying down for far longer and working tirelessly. It can be launched from a ship or even a shoreline, sending back sonar and video feeds to operators who remain at a safe distance while disarming explosives or fending off hostile actions. Crucially, it's reusable. Once a threat is neutralised, the drone sub lives to dive another day - cutting costs while keeping seas safe. The project is also a win for British industry, supporting specialist jobs through partnerships with firms like Alford Technologies, Atlantas Marine, Sonardyne and ECS Special Projects. Trials have already taken place in Portsmouth's Horsea Island, Portland Harbour, South Wales and as far afield as Norway. Putin humiliated as Russian war facility EXPLODES in Ukrainian drone strike The Royal Navy is now developing tactics and techniques to make full use of the new tech. The Ministry of Defence hailed the innovation on social media, calling it a leap forward in protecting sailors and vital undersea cables. The new underwater drone arrives amid warnings about Russian undersea activity in UK waters. In April, it was revealed that Kremlin spy sensors had been found close to British territory — believed to be tracking the Royal Navy's nuclear submarines. The sensors, reportedly deployed using Russian oligarchs' luxury yachts, were discovered washed ashore and picked up by Navy minehunter ships. Officials fear the covert operation could be part of a wider 'greyzone' campaign to gather intelligence and target undersea infrastructure. Royal Navy and RAF assets were scrambled last November when the suspected Russian spy ship Yantar was seen 'lurking around pipelines and internet cables' in the Irish Sea. Around the same time, RAF fighter jets intercepted a Russian warplane over the North Sea, and unmanned Russian underwater vehicles were also detected near communication cables. 5 5 One senior source told The Sunday Times: 'It's a bit like the space race. This is a world clouded in secrecy and subterfuge… but there's enough smoke to suggest something is on fire somewhere.' In March, HMS Cattistock and a Wildcat helicopter were sent to monitor the Admiral Vladimirskiy, a so-called research ship revealed in 2023 to be a spy vessel suspected of probing Britain's power supply and internet links. HMS Somerset and other Royal Navy units were also deployed multiple times to escort Russian vessels including a beach landing ship returning from the Mediterranean. At least 11 internet cables in the Baltic Sea have been damaged in the past 15 months — some suspected to have been dragged by Russian ships — while surface vessels like the Admiral Vladimirskiy have continued probing waters near the UK. In response, military chiefs are drawing up Operation Atlantic Bastion — a sweeping new patrol mission using air, land and sea forces to defend UK and Nato interests in the North Atlantic. What is the Defence Science and Technology Laboratory? THE Defence Science and Technology Laboratory — better known as Dstl — is the UK government's secretive hub of military innovation. Based at Porton Down in Wiltshire, it's packed with some of Britain's brightest scientific minds, often likened to James Bond's Q Branch. Part of the Ministry of Defence, Dstl works behind the scenes to give UK Armed Forces a cutting-edge advantage. From cyber warfare and AI to battlefield tech and bio-defence, it develops, tests and fine-tunes everything that keeps British troops one step ahead. Dstl collaborates with industry, universities and international partners, but much of its work remains classified. Its projects aren't just for warfighting — they're designed to save lives, protect national infrastructure, and deliver tech that punches well above its weight on the world stage.


The Independent
40 minutes ago
- The Independent
Democrats have a dirty secret - they actually like some of the tax cuts in Trump's ‘big beautiful bill'
Some of the sweeping tax cuts proposed in President Donald Trump 's massive spending package have found support among Democrats — even as they are expected to oppose the legislation over proposed cuts to Medicaid and other government services when it comes up for debate in the Senate later this month, according to a new report. The gargantuan budget package, which House Republicans and the White House have dubbed the One Big Beautiful Bill Act, passed the House by a single vote last month and is now drawing heat from fiscal hawks in both chambers as well as Tesla CEO Elon Musk, who was fresh off his months-long stint as a special government employee when he began threatening to back challengers to any legislator who votes for the bill. Still, there are facets of the proposal that have appeal for some Democrats, the New York Times reports. Virginia Rep. Don Beyer, a Democrat who is also a wealthy car dealership owner, told the Times his party is 'in general very much in favor of reducing taxes on working people and the working poor' when asked about Trump's plan to end taxes on service workers' tips. 'Those people are living on tips,' he added. Trump's tip tax cut plan has also attracted attention from Sen. Jacky Rosen of Nevada, a state where service workers make up a large and powerful voting bloc that has traditionally supported Democrats but shifted to Trump in large numbers during the 2024 presidential election, handing him the Silver State's electoral votes. Rosen, a Democrat, took to the Senate floor last month to advance a bill approving Trump's 'no tax on tips' plan. It passed unanimously even though the measure was largely symbolic because the U.S. constitution requires tax laws to originate in the House 'I am not afraid to embrace a good idea, wherever it comes from,'. she said at the time in remarks on the Senate floor. Yet despite the support for some of the individual tax provisions in the plan, it's highly unlikely that it will be able to muster enough if any Democrats to ease the way to Trump's desk, even under a Senate procedure known as budget reconciliation, which fast-tracks some types of spending legislation without subjecting it to the upper chamber's de facto 60-vote threshold for passage. Democrats are expected to unanimously vote against the legislation in the upper chamber, where it has also attracted opposition from some Republicans who've complained that the cuts to spending in the package don't go far enough to offset the reduced revenue caused by provisions meant to enact Trump campaign promises to end taxes on tips for service workers, as well as taxes on overtime pay for hourly workers and on social security benefits for seniors. Nonpartisan experts such as those at the Congressional Budget Office have warned that the reduced tax receipts would blow a massive hole in the federal budget and jeopardize America's long-term fiscal outlook, but that hasn't stopped some prominent Democrats from getting behind the individuals tax cuts. Trump and his allies hope the prominent tax cut proposals will blunt Democrats' efforts to paint the One Big Beautiful Bill Act as a giveaway to wealthy GOP donors that will gut government services while only providing limited relief for working-class voters. To that end, the president and others in his camp have routinely taken to social media to argue that anyone who votes against the bill is effectively voting for tax increases because the legislation makes permanent a number of temporary tax cuts enacted in the 2017 Tax Cuts and Jobs Act, which Trump signed into law during his first term. Democrats, meanwhile, remain opposed to the bill's massive cuts to Medicare and other measures that make it harder for people to claim tax credits meant to boost lower-income Americans' bottom lines. Rep. Brad Schneider, an Illnois Democrat, told the Times that the whole bill had to be considered rather than any individual provision or provisiosn. 'Any one thing — a tax credit or a tax cut — might make sense, but you've got to take a look at the whole picture,' he said.