No security team? Here is how to split security work between AI tools, a fractional CISO and your own people, what AI should never decide, and a 90-day setup plan.

A hybrid human-AI security team is a working arrangement where AI tools handle high-volume detection, triage and drafting, a named human owns every decision that carries business risk, and an experienced security leader, often a fractional or virtual CISO, sets the rules for which actions AI may take on its own and which need sign-off.
Every few weeks we get the same call. A founder of a 70-person SaaS company has just bought an AI-powered security tool, or turned on the security copilot bundled with their cloud platform. The dashboard looks impressive. Then a large customer sends a security questionnaire asking, "Who is accountable for incident response, and how are automated actions approved?" Nobody in the room can answer.
After more than 25 years in security and audit, I recognize the failure: technology gets bought before ownership gets assigned. This guide is the division of labor I set up with companies of 30 to 200 people that have no dedicated security staff.
Because they cannot hire their way out. The 2025 ISC2 Cybersecurity Workforce Study, based on 16,029 respondents, found that 59% of respondents report critical or significant skills needs, up from 44% the year before. A third say they lack the budget to staff their teams adequately. AI was the most pressing skills need, cited by 41%.
The same study shows AI is already in the room: 28% of respondents have integrated AI tools into security operations, and another 19% are actively testing them. So the question for a founder is no longer whether AI will touch your security program. It is who supervises it.
There is real upside. IBM's Cost of a Data Breach Report 2026 found that organizations using security AI and automation saved an average of $1.93 million per breach. The same report found that 92% of organizations with an AI-related breach lacked proper AI access controls, and only 40% reported using access controls on their AI models and data at all. The tools help. Ungoverned tools create a new attack surface.
Small companies do not need a security operations center. They need three layers that each do what they are good at.
AI tools do the volume work. Log correlation, alert de-duplication, phishing triage, drafting policies, summarizing vendor SOC 2 reports, mapping evidence to controls. None of it should end in an irreversible action without a person.
A fractional or virtual CISO owns the program. That means risk decisions, the rules of engagement for automation, incident command, board and customer reporting, and the audit relationship. At IRM, our Virtual CISO service Crawling tier starts at $2,000 a month for 15 to 20 hours, which is the right size for most companies under 100 people. Our ROI model uses $250,000 a year as the baseline for a full-time CISO, so the gap is significant. Full tiers are on our pricing page.
Internal staff run the day-to-day. Usually a DevOps lead or CTO for technical controls, an ops lead for access reviews, and the founder as final risk owner.
The table below is the one I share in kickoff sessions. Some AI security vendors will disagree with the right-hand column. I am comfortable with that.
Security decision | AI tool | Virtual CISO | Internal staff | Can AI decide alone? |
|---|---|---|---|---|
Rank and de-duplicate alerts | Responsible | Consulted (tuning) | Informed | Yes, with weekly sampling |
Declare a security incident | Consulted | Accountable | Responsible (first responder) | No |
Isolate a production host or revoke an admin session | Consulted (recommends) | Accountable | Responsible (executes) | No, unless pre-approved in a written runbook |
Block a known-malicious email or domain | Responsible | Accountable (sets rule) | Informed | Yes |
Accept a vulnerability as residual risk | Consulted | Responsible | Accountable (founder or CTO) | No |
Approve a new AI vendor or plugin | Consulted (summarizes) | Responsible | Accountable | No |
Draft a security policy | Responsible (first draft) | Accountable | Consulted | No, a draft is not a policy |
Answer a customer security questionnaire | Responsible (draft) | Accountable | Consulted | No |
Notify customers or regulators of a breach | Not involved | Responsible | Accountable (CEO, counsel) | Never |
The rule behind the last column is simple. If a decision is reversible in minutes and the cost of being wrong is low, AI can act. If it touches production availability, legal exposure, or a customer relationship, a human with authority signs.
The NIST AI Risk Management Framework organizes AI risk work into four functions: Govern, Map, Measure and Manage. For a small SaaS company, I translate that into five oversight checkpoints you can actually run.
Before deployment. The vCISO writes down what each AI tool may read, what it may change, and what it may never touch. If you cannot write it in a paragraph, the tool is not ready.
At the action boundary. Any automated containment step needs either a named approver or a pre-approved runbook entry. Log both.
Weekly sampling. Someone on staff reviews ten closed alerts the AI marked benign. This is the cheapest way to catch a model that has quietly drifted.
Monthly review. The vCISO reviews false positive and false negative trends, any automated actions taken, and new AI tools that showed up in expense reports.
Quarterly evidence. Export the logs of approvals and overrides. Your SOC 2 or ISO 27001 auditor will ask how automated controls are monitored, and this is your answer.
Checkpoint five matters more than founders expect. Across our assessments, the companies that struggle in audit are rarely the ones without AI. They are the ones who cannot show a human ever looked at what the AI did. If you are heading toward an audit, our SOC 2 readiness program builds these records in from the start.
Order of operations matters. Buying the AI tool first is the most common mistake I see.
Name the accountable risk owner (usually the CEO or CTO) and engage the vCISO.
Run a baseline assessment of identity, endpoints, cloud configuration, backups and logging. Our free Cybersecurity Baseline Assessment covers the essentials.
Inventory every AI tool already in use, sanctioned or not. Most companies find several they did not know about. See what shadow AI is and how to find it.
Map your current people to responsibilities. The NIST NICE Framework defines more than 40 work roles across five categories; you will not fill them, but it is a useful checklist for spotting gaps nobody owns.
Fill in the RACI table above for your own environment and get the founder to sign it.
Write the automation rules of engagement: which actions are allowed, which need approval, which are banned.
Publish an acceptable AI use policy for staff, and set up your incident response plan with named roles and phone numbers.
Deploy AI detection and triage tools in advisory mode only. They recommend; people act.
Review 30 days of AI recommendations. Where accuracy is consistently high on low-risk actions, allow those to run automatically.
Run one tabletop exercise where the AI tool raises a false alarm and one where it misses something. Practice both.
Start the weekly sampling and monthly review cadence.
Prepare a one-page board summary: what AI does, who approves what, and what changed.
By day 90 you have a documented program where AI speeds things up and a named person owns every consequential call.
I am an advocate for AI in security operations. I also spend a lot of time cleaning up after it. Here is where it goes wrong.
When nobody owns the output. An AI triage tool with no assigned reviewer gives you faster alerts that nobody reads. You have increased noise and the illusion of coverage.
When the copilot has more access than the people using it. Tools connected to your cloud console, ticketing system and email with broad API permissions are now a high-value target. The OWASP Top 10 for LLM Applications 2025 lists Prompt Injection (LLM01) and Excessive Agency (LLM06) as core risks for exactly this reason. A crafted message in a ticket can steer an over-privileged agent. Our guide on how to secure AI agents covers scoping permissions.
When drafts become policy. AI writes plausible security policies in minutes. Plausible is not accurate. I have reviewed AI-drafted incident response plans that named roles the company did not have. An auditor will notice.
When automated response hits production. A tool that isolates a host on a false positive can cause the outage you were trying to prevent. Keep containment in advisory mode until you have tested the boundary.
When confidence replaces skepticism. AI summaries sound certain. Junior staff tend to accept them. The weekly sampling checkpoint exists to keep that skepticism alive.
This model is not the right first move for every company.
If you have no security owner at all, adding AI tooling first is backwards. Start with one accountable person, a baseline of controls and an incident process. AI amplifies a team. It does not replace the absence of one.
If your environment is small and stable, with one cloud account, a few dozen users and a managed detection provider already monitoring, your provider is running the AI side for you. Focus on the human side: knowing who decides when they call you at 2 a.m.
And if customers are not yet asking about AI governance, a signed RACI, an AI use policy and the five checkpoints above are enough for most companies under 100 people. When they ask for more, a formal AI governance program is the next step.
No. AI can draft, correlate and summarize, but it cannot be accountable to a board, sign a risk acceptance, or speak to a regulator after a breach. A virtual CISO provides that accountability at a fraction of a full-time salary, and AI makes their limited hours go further.
Declaring an incident, accepting residual risk, approving a new vendor, and notifying customers or regulators. Anything that affects production availability should require either a human approver or a pre-approved, tested runbook entry.
For most companies between 30 and 100 people, 15 to 20 hours a month is enough once AI handles triage and first drafts. Companies preparing for SOC 2 or ISO 27001, or with several enterprise customers, usually need 20 to 40. Our vCISO cost guide breaks this down.
Auditors evaluate whether a control operates and is monitored, not which tool produced the record. What they will ask is how you know the automated control works. Approval logs, override records and your weekly sampling notes answer that question.
If you want a second opinion on how to split the work in your company, book a consultation and we will walk through your RACI together.
Our diverse industry experience and expertise in AI, Cybersecurity & Information Risk Management, Data Governance, Privacy and Data Protection Regulatory Compliance is endorsed by leading educational and industry certifications for the quality, value and cost-effective products and services we deliver to our clients.