Ancestors

Toot

Written by Tindra on 2024-12-11 at 20:11

Y'all, we need to talk about when GenAI use is worse than just doing a job "terribly".

Lots of my job involves reading insurance questionnaires. And they're long and tedious and talk about things like they're absolutes but we all know there's way more nuance than there's room for in a couple of box checks.

But! There's comments fields! And for me and my team, those comments fields are gold. They give us a sense of how the organization really thinks about security. We can usually tell if the questions were answered by the legal team, or the IT leadership, or the security leadership, because each of those roles uses different language and jargon. And this tells us about the organization! We love reading y'all's comments.

And then there's something I saw recently where the comments were... off. It almost felt like someone was copy/pasting from a cyber security basics textbook. In response to every "do you implement this control" question, there was a response of "Yes! We implement that control! It is a really important control because ".

I mentioned this to my teammates and their immediate response? GenAI. That's not how any professional adjacent to this field writes. You don't need to explain to your insurance carrier what those controls are. We know. That's why we're asking about them in the questionnaire!

And, I get it. These questionnaires are long and confusing. You don't know what the "right" answer looks like. We get it. But GenAI isn't going to help. It's not going to give an accurate answer of what's in your organization's environment. It's not going to give us a sense of your competency. It absolutely isn't going to impress us, because now we think that you have no idea how cyber security works.

If you're using GenAI to get over writer's block, that's great! But you still need to edit that content into shape. If you're worried about language barrier issues and think GenAI will help you get your point across better because its English is better? Just write in your native language, we have translation tools. If you're worried that your answer isn't "good enough"? Look, the questionnaire is the start of a conversation. If you're the sort of company that does calls with underwriters, we can talk through whatever issues you think you have. But we need to have an honest exchange.

Just, please, PLEASE, don't blindly use GenAI to fill out your questionnaires.

(originally posted on LinkedIn https://www.linkedin.com/posts/adraeger_yall-we-need-to-talk-about-when-genai-use-activity-7272393626205261825-SAVq?utm_source=share&utm_medium=member_desktop )

=> More informations about this toot | More toots from TindrasGrove@infosec.exchange

Descendants

Proxy Information
Original URL
gemini://mastogem.picasoft.net/thread/113636010819032894
Status Code
Success (20)
Meta
text/gemini
Capsule Response Time
210.56309 milliseconds
Gemini-to-HTML Time
0.539677 milliseconds

This content has been proxied by September (ba2dc).