The Human-AI Handshake: A Framework to Build Trust and Unlock Innovation in Modern Security Ops
Michael Raggi (Principal Threat Response Analyst · CrowdStrike)
BSides NYC 2025 (0x05) · Day 1 · Tech - Other
Overview
In an era where Artificial Intelligence (AI) is frequently heralded as a transformative "Big Bang" for various industries, including cybersecurity, Michael Raggi's talk at BSides NYC offered a refreshing counter-narrative. Instead of focusing solely on the boundless potential, Raggi delved into the inherent chaos and challenges that unfettered AI deployment can introduce within an enterprise. His presentation, "The Human-AI Handshake," posited a human-centric framework designed to deliberately direct this "Big Bang," fostering an orderly universe where AI tools integrate seamlessly and effectively into security operations. The core premise is that for AI to truly unlock innovation, it must first earn the trust of the human operators it aims to assist.

Key moments
- 0:30 Chaotic universe metaphor for uncontrolled AI deployment
- 2:00 Vision for orderly, centralized AI deployment
- 2:50 Framework overview: building trust and innovation
- 5:20 Defining the X-axis: Trust generated in AI
- 6:00 First step: Technology and process audit
- 6:40 Critical considerations for feeding data to AI
The Human-AI Handshake: A Framework to Build Trust and Unlock Innovation in Modern Security Ops
Speakers: Michael Raggi, Principal Threat Response Analyst, CrowdStrike
Conference: BSides NYC
YouTube: https://www.youtube.com/watch?v=F6zPsGNkQnE
Overview
In an era where Artificial Intelligence (AI) is frequently heralded as a transformative "Big Bang" for various industries, including cybersecurity, Michael Raggi's talk at BSides NYC offered a refreshing counter-narrative. Instead of focusing solely on the boundless potential, Raggi delved into the inherent chaos and challenges that unfettered AI deployment can introduce within an enterprise. His presentation, "The Human-AI Handshake," posited a human-centric framework designed to deliberately direct this "Big Bang," fostering an orderly universe where AI tools integrate seamlessly and effectively into security operations. The core premise is that for AI to truly unlock innovation, it must first earn the trust of the human operators it aims to assist.
Raggi, a Principal Threat Response Analyst at CrowdStrike, presented a structured approach for integrating AI into Security Operations Centers (SOCs), threat intelligence, and incident response functions. He argued that the typical metrics of "time saved" and "cost reduced" are insufficient for measuring AI's true impact and can inadvertently lead to a binary focus on labor elimination. Instead, he proposed trust generated as the fundamental metric for successful AI adoption. This framework emphasizes intentional design, robust governance, strategic deployment of different AI types, and continuous feedback loops, all aimed at building confidence in AI systems among the human teams who will ultimately use them.
This talk is crucial for security leaders and practitioners grappling with the rapid influx of AI tools. It provides a pragmatic roadmap for moving beyond speculative hype to implement AI in a way that enhances human capabilities, streamlines workflows, and avoids the pitfalls of disjointed, untrusted, or poorly governed deployments. By prioritizing the human element and systematically addressing concerns around data quality, transparency, and job security, Raggi's framework offers a pathway to sustainable and impactful AI integration in modern security operations.
Background
▶ Watch: Chaotic universe metaphor for uncontrolled AI deployment (0:30)
The current landscape of enterprise technology is increasingly dominated by discussions of Artificial Intelligence. From large language models (LLMs) to specialized machine learning algorithms, AI is being rapidly developed and deployed across various sectors. In cybersecurity, the promise of AI is particularly alluring: automating mundane tasks, identifying sophisticated threats, accelerating incident response, and augmenting human analysts. However, this rapid proliferation often mirrors a "Big Bang" scenario, as described by Raggi, where new AI-wrapped tools are scattered across enterprise stacks without adequate planning or integration.
This chaotic deployment frequently leads to significant challenges. APIs fail to communicate effectively, creating data silos and integration headaches. A lack of understanding about new AI capabilities and limitations results in "dark matter and black holes" – wasted time and resources due to inefficient or misused tools. Furthermore, the deployment of AI is often brought down to Earth by "new gravities" such as legal frameworks, compliance requirements, ethical considerations, and technical limitations, many of which were not fully understood prior to deployment. The problem is exacerbated by a tendency to measure AI success solely through metrics like "time saved" or "cost reduced," which, while important outcomes, fail to capture the nuances of human interaction and the qualitative benefits AI can bring. This narrow focus can also inadvertently create fear among employees about job displacement, leading to resistance and skepticism rather than eager adoption.
Prior work in technology adoption theory, such as Everett Rogers' Diffusion of Innovations model, highlights that technology adoption follows a curve, starting with innovators and early adopters, moving through an early majority and late majority, and finally reaching laggards. Raggi explicitly references this technology adoption curve in his framework, underscoring the importance of tailoring deployment strategies to different segments of the user base. The challenge for security operations is to navigate this curve intentionally, building a foundation of trust that encourages widespread adoption, rather than simply pushing tools onto a skeptical workforce. The existing problem, therefore, is not just about what AI can do, but how it is introduced, governed, and integrated into inherently human-centric organizations.
Key Findings
▶ Watch: Framework overview: building trust and innovation (2:50)
Michael Raggi's presentation introduced a comprehensive human-centric framework for AI adoption in security operations, fundamentally shifting the metric of success from purely economic outcomes to trust generated. His key findings and contributions can be summarized as follows:
- Trust as the Primary Metric for AI Adoption: Raggi argued forcefully against the conventional wisdom of measuring AI success solely by "time saved" or "cost reduced." He posited that these metrics create a false binary of labor elimination and overlook the qualitative benefits of AI. Instead, he proposed trust generated—trust in the applications, models, and development teams—as the essential x-axis for charting AI adoption alongside the y-axis of quantitative adoption (e.g., percentage of users or teams). This redefinition acknowledges that enterprises are human constructs first and foremost, and successful technology integration hinges on human acceptance.
- The Technology Adoption Curve as a Strategic Guide: Raggi mapped his AI deployment framework onto the well-established technology adoption curve, identifying distinct phases for engaging different user segments. This includes starting with innovators for initial technology and process audits, engaging early adopters with agentic AI for menial tasks, and then expanding to the early and late majority with specialized generative AI, ultimately leveraging AI to automate AI adoption for laggards. This structured approach ensures a deliberate and phased rollout.
- The Importance of a Unified AI Interface and Knowledge Funnel: A critical finding is the need for a centralized AI interface and a single knowledge funnel (e.g., maintained in Git or Bitbucket repositories). This approach cultivates trust in a unified manner, preventing the need to build trust for myriad individual tools, each inheriting biases from previous applications. Transparency into the underlying knowledge files empowers analysts and overcomes the "black box" human bias of "I don't know what it's doing, therefore I won't use it."
- **Guardrails and Governance: Telling AI What Not to Do: Perhaps one of the most vital findings for security practitioners is the emphasis on defining AI governance and explicitly "telling AI what not to do." This involves establishing clear guidelines for who builds AI, what its allowed uses are, and critically, what data it should not return (e.g., PII), what actions it should not take (e.g., validating false/true positives without human oversight), or what novel code it should not generate by combining disparate code sets. Strong guardrails are essential to prevent hallucinations**, reduce liability, and ensure operational integrity.
- Strategic Deployment of Agentic vs. Generative AI: Raggi differentiated between agentic AI (passive, autonomous multi-step automation for menial tasks) and generative AI (active, co-pilot, prompt-based augmentation for meaningful tasks). He advocated for starting with agentic AI to automate "mundane, not meaningful" tasks, thereby winning champions and building trust networks by making daily workflows easier. This initial success then paves the way for deeper adoption of generative AI among trusted, specialized teams, which acts as a "10x" multiplier for analyst capabilities.
- Specialization and Orchestration for Scale: As AI adoption grows and specialized agents proliferate (e.g., 15, 20, 50, 110 agents), a front-end orchestrator agent becomes essential. This orchestrator intelligently redirects user queries to the most appropriate, specialized generative AI agent, ensuring efficiency and deeper knowledge utilization. This prevents a messy, unmanageable proliferation of tools and ensures that the right information is delivered by the most knowledgeable agent.
- Continuous Feedback and Transparency: The framework emphasizes the necessity of robust feedback mechanisms, active listening, and transparency. This includes openly addressing anxieties about job displacement, technical issues, and legal/compliance concerns. Collaboration in AI development, with a clear understanding of intentions (e.g., automating processes vs. eliminating jobs), is paramount to cultivating the trust needed to overcome human obstacles and avoid significant delays (e.g., 9 to 18 months) in tool adoption.
These findings collectively present a holistic and human-centric blueprint for successfully integrating AI into security operations, prioritizing long-term trust and collaborative innovation over short-term, siloed deployments.
Technical Deep Dive
▶ Watch: Defining the X-axis: Trust generated in AI (5:20)
Raggi's framework is an architectural blueprint for AI deployment in security operations, emphasizing structured processes and specific technical components to foster trust and efficacy. The core of this framework is a phased approach, mapped onto the technology adoption curve, with distinct technical prerequisites and implementations at each stage.
1. Technology and Process Audit (Innovators Phase):
Before any AI deployment, a thorough audit is crucial. This involves:
- API Mapping: Identifying all available APIs within the enterprise environment, understanding their access restrictions, data limitations, and potential integration challenges when combined with AI. This ensures a clear understanding of what data can be fed to AI and how AI can interact with existing systems.
- Process Suitability Assessment: Evaluating existing security operations processes (e.g., incident response, threat hunting, vulnerability management) to determine which are best suited for AI augmentation and which are not. Processes with stringent compliance requirements or those demanding high levels of human validation (e.g., certain true/false positive validations) might not be ideal for initial AI rollout, as they could lead to wasted cycles if AI outputs cannot meet validation levels. This helps identify "natural stewards" or strong partners for AI development.
2. Building a Knowledge Funnel (Early Adopters Phase):
A cornerstone of trust and effective AI is a centralized, transparent knowledge base.
- Single Source of Truth: Instead of allowing disparate data sources, the framework mandates a single source and repository for AI data sets. This means curating high-quality data from wikis, Confluence pages, and other internal documentation. The data must be scrubbed, segmented, and sanitized for specific use cases, preventing a "mile wide, an inch deep" knowledge base that conflates information.
- Unified AI Interface: A unified application for interfacing with AI is critical. This is not necessarily a single tool but rather a consistent access point (e.g., a web portal, a specialized chat interface) that multiple teams (SOC, threat intelligence, incident responders) use to send requests and receive responses. This approach builds trust in one interface rather than requiring trust cultivation for every individual AI-wrapped security tool. Transparency is key here, often achieved by maintaining the underlying knowledge files in version control systems like Git or Bitbucket repos, allowing analysts to inspect the data AI is trained on.
3. AI Governance: Defining Guardrails (Early Adopters/Early Majority Phase):
Establishing "laws of gravity" for AI is paramount to prevent uncontrolled or risky behavior.
- Identity and Expectations: Each AI agent must have a clearly defined identity, understanding what inputs it expects from users and what type of prompts it should return.
- "What Not to Do": This is the most critical technical and policy component. Governance must explicitly define:
- Data Restrictions: What Personally Identifiable Information (PII) or sensitive data the AI is forbidden from accessing or returning.
- Action Limitations: What actions the AI is not allowed to perform autonomously (e.g., validating false positives or true positives without human confirmation).
- Code Generation Rules: Restrictions on generating novel code by combining disparate, potentially incompatible or proprietary code sets from different repositories.
- Testing and Adherence: Robust testing mechanisms for these guardrails are essential to prevent hallucinations or outputs that are not productionizable, which can lead to significant legal, liability, and operational headaches. All teams developing AI must adhere to these core functions.
4. Strategic AI Deployment: Agentic vs. Generative (Early Majority Phase):
Raggi distinguishes two primary forms of AI for strategic deployment:
- Agentic AI: This is passive, autonomous, multi-step automation primarily for menial tasks. Examples include automating repetitive data enrichment, log parsing, or initial triage steps. The goal is to make life "seem so much more doable" for users, winning support by taking away the "mundane, not the meaningful." This builds initial trust by demonstrating tangible, low-risk benefits.
- Generative AI: This is an active co-pilot, prompt-based system designed to "10x the ability of an analyst," unlocking creativity and impact. This is where analysts interact directly with AI for complex problem-solving, threat intelligence synthesis, or advanced incident response assistance. Deployment begins with trusted, specialized teams who can design and deploy agents tailored to their unique workflows, leveraging the pre-built trust in the unified interface.
5. Specialization and Orchestration (Late Majority Phase):
As adoption scales and numerous specialized generative AI agents are developed, an orchestration layer becomes necessary.
- Specialized Agents: These agents are trained on deeper, more focused knowledge repositories for specific functions (e.g., a specific malware analysis agent, a cloud security compliance agent). They perform better than generalized agents trained on all enterprise data.
- Orchestrator Agent: A front-end orchestrator agentic agent is built on top of the knowledge funnel. Its role is to intelligently redirect incoming user queries to the most relevant specialized generative AI bot or agent. This ensures that queries receive the most accurate and context-specific responses, maintaining an organized library of agents and preventing information overload.
6. Metrics, Feedback, and Life Cycle Management (Laggards Phase):
The final stages focus on sustaining growth and trust.
- Metrics Tracking: Beyond simple adoption rates, metrics should capture the quality of AI outputs, user satisfaction, and adherence to governance.
- Feedback Mechanisms: Formal and informal channels for human feedback are crucial. This includes listening to anxieties, technical issues, and legal/compliance concerns. Collaboration in AI development, where users feel heard and their input is valued, is key to cultivating trust.
- Stasis and Maintenance: Continuous maintenance of underlying systems, knowledge repositories, and processes is essential. The framework is not a one-time deployment but an ongoing life cycle of refinement and adaptation based on feedback and evolving needs.
By meticulously structuring AI deployment with these technical and process-oriented components, Raggi's framework aims to transform the chaotic "Big Bang" into an orderly, trust-driven evolution of security operations.
Demo / Proof of Concept
▶ Watch: First step: Technology and process audit (6:00)
Michael Raggi's talk, "The Human-AI Handshake," focused on presenting a conceptual framework and a strategic roadmap for AI adoption in security operations. The presentation did not include a live demonstration or a specific proof of concept of the framework in action. Instead, Raggi used allegories and a detailed explanation of his proposed stages and components to illustrate how an enterprise could systematically build trust and integrate AI. The emphasis was on the architectural and governance principles rather than a specific tool or implementation.
Defensive Implications
▶ Watch: Critical considerations for feeding data to AI (6:40)
Raggi's framework offers profound defensive implications for security operations, shifting the focus from simply deploying AI to strategically integrating it to enhance human capabilities and bolster an organization's security posture.
- Reduced Analyst Burnout and Improved Efficiency: By prioritizing agentic AI to automate "menial, not meaningful" tasks, organizations can significantly reduce the repetitive burden on their security analysts. This directly addresses analyst burnout, a pervasive issue in SOCs, freeing up human talent to focus on complex problem-solving, proactive threat hunting, and strategic initiatives. This also translates to improved efficiency in initial triage, data enrichment, and routine compliance checks, allowing faster response times to critical incidents.
- Enhanced Threat Detection and Response: The framework's emphasis on specialized generative AI agents and a unified knowledge funnel means that analysts can leverage highly contextualized AI assistance. Instead of generic AI, specialized agents (e.g., for malware analysis, cloud security, or specific threat actor intelligence) can provide more accurate and relevant insights, accelerating threat detection, improving the fidelity of alerts, and enabling more informed incident response decisions. The orchestrator agent ensures that analysts are directed to the most knowledgeable AI for their specific query, maximizing the utility of AI tools.
- Stronger Governance and Reduced Risk: The crucial section on "Telling AI what not to do" directly addresses critical defensive risks. By establishing clear AI governance and guardrails for data access (e.g., preventing PII exposure), action limitations (e.g., not auto-validating critical alerts), and code generation, organizations can mitigate the risks of AI hallucinations, unintended actions, or compliance violations. This proactive risk management is essential for maintaining data integrity, adhering to regulatory requirements, and preventing AI from inadvertently creating new attack surfaces or vulnerabilities. Robust governance also ensures that AI outputs are reliable enough to be trusted in critical security decisions.
- Cultivating Trust to Overcome Human Roadblocks: The framework's central tenet of trust generated is a direct defensive advantage. A workforce that trusts the AI tools—understanding their capabilities, limitations, and the transparency of their underlying data—is far more likely to adopt and effectively utilize them. This overcomes the "human bias" and resistance often encountered with new technology, preventing delays in adoption (e.g., 9-18 months) that could leave an organization vulnerable. When analysts trust AI, they are more likely to integrate its insights into their defensive strategies, leading to a more robust and adaptive security posture.
- Improved Situational Awareness and Proactive Security: A well-implemented knowledge funnel and specialized AI agents can synthesize vast amounts of threat intelligence, internal security data, and contextual information. This provides security teams with enhanced situational awareness, helping them identify emerging threats, understand attacker tactics, techniques, and procedures (TTPs), and proactively implement preventative measures. By augmenting human intelligence, AI can help organizations move from a reactive to a more predictive and proactive defensive stance.
- Empowering Analysts as Builders: By enabling "trusted outposts of expertise" to design and deploy specialized AI agents using a unified system, the framework empowers security analysts to tailor AI to their specific defensive needs. This fosters innovation from within, creating AI tools that are highly relevant and effective for the unique challenges faced by the organization, rather than relying solely on generic vendor solutions. This collaborative approach ensures that the AI is built with a deep understanding of operational realities and defensive requirements.
In essence, Raggi's framework transforms AI from a potential source of chaos and risk into a strategic asset that strengthens an organization's defensive capabilities by empowering its human operators, streamlining operations, and embedding responsible governance into its core.
Key Takeaways
- Trust is the Core Metric: The fundamental measure of successful AI adoption in security operations should be trust generated among users, not merely time or cost saved. Enterprises are human constructs, and AI success hinges on human acceptance.
- Strategic Phased Deployment: AI integration should follow a deliberate, phased approach mapped to the technology adoption curve, starting with agentic AI for menial tasks to build initial trust among innovators and early adopters, then expanding to generative AI for specialized teams.
- Unified Knowledge and Interface: Establish a single source of truth for AI knowledge (e.g., Git or Bitbucket repos) and a unified AI interface to cultivate trust centrally and provide transparency into underlying data, overcoming "black box" skepticism.
- Robust AI Governance and Guardrails: Crucially, define "what AI should not do," including restrictions on data access (PII), autonomous actions, and novel code generation. Strong guardrails prevent hallucinations, reduce liability, and ensure operational integrity.
- Automate the Mundane, Not the Meaningful: Prioritize agentic AI for automating repetitive, non-core tasks to free up human analysts and build trust by making workflows easier, rather than automating meaningful tasks that provide identity and impact.
- Specialization and Orchestration for Scale: As AI adoption grows, develop specialized AI agents for specific functions and implement a front-end orchestrator to intelligently route queries to the most relevant agent, maintaining efficiency and depth of knowledge.
About the Speaker(s)
Michael Raggi is a Principal Threat Response Analyst at CrowdStrike. In his presentation at BSides NYC, he emphasized his personal connection to the topic, stating, "today I'm just Michael, not affiliated with CrowdStrike, just a guy from New York." His background in threat response provides him with practical, real-world experience in security operations, allowing him to speak authoritatively on the challenges and opportunities of integrating new technologies like AI into existing workflows. His insights are grounded in the daily realities faced by security teams, making his human-centric approach to AI adoption particularly relevant and actionable for the cybersecurity community. He also mentioned having "mistakenly gone to business school for like a year and a half," which likely contributed to his understanding of organizational dynamics and technology adoption curves.
Reviews
Dr. Zero (Offensive Security Researcher) — WEAK
A polished framework talk that repackages Rogers' Diffusion of Innovations and basic MLOps governance advice with a security-ops skin. The 'trust as the primary metric' reframe sounds novel in the abstract but collapses under scrutiny — it's a rhetorical move, not a measurable operationalization. Nothing here would surprise anyone who has shipped an internal AI tooling program in the last two years.
Heather Calloway (CISO) — SOLID
Raggi offers a sensible, practitioner-oriented framework for AI adoption in security operations — phased deployment, governance guardrails, trust as a metric. The thinking is sound, but the talk stays comfortably inside the SOC and never reaches the institutional or board-level questions that determine whether any of this actually gets resourced and executed.