CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

“Sorry, I can’t help with that”: How your guardrails might become the attacker’s best friend

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5272

As cited

Copy frozen at (site build).

threat intel

“Sorry, I can’t help with that”: How your guardrails might become the attacker’s best friend

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

“Sorry, I can’t help with that”: How your guardrails might become the attacker’s best friend

A Cisco Talos newsletter explores how poorly designed artificial intelligence (AI) guardrails in security operations can inadvertently assist attackers by slowing or halting threat investigations. The author advocates for operational sovereignty, where organizations control and customize their own guardrails rather than relying on inflexible third-party provider restrictions. Talos also evaluated 66 large language model (LLM) combinations for security operations and found that selecting the right model requires balancing efficacy, speed, cost, and consistency against actual workflows, not generic leaderboard rankings.

Why it matters: Security teams deploying agentic security operations center (SOC) tools must test LLM and reasoning models against their own workflows before production use and establish internal control over guardrails to prevent AI-driven delays that give attackers time to complete their objectives.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

“Sorry, I can’t help with that”: How your guardrails might become the attacker’s best friend

A Cisco Talos newsletter explores how poorly designed artificial intelligence (AI) guardrails in security operations can inadvertently assist attackers by slowing or halting threat investigations. The author advocates for operational sovereignty, where organizations control and customize their own guardrails rather than relying on inflexible third-party provider restrictions. Talos also evaluated 66 large language model (LLM) combinations for security operations and found that selecting the right model requires balancing efficacy, speed, cost, and consistency against actual workflows, not generic leaderboard rankings.

Why it matters: Security teams deploying agentic security operations center (SOC) tools must test LLM and reasoning models against their own workflows before production use and establish internal control over guardrails to prevent AI-driven delays that give attackers time to complete their objectives.

VendorsMicrosoftGoogleCisco
Actorsplay
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary