- Job title
- Chief Technology Officer
- Sector
- Cosmetics
- Organization type
- medium-sized business
- Joined
- Jan 2022
- Message
- 13
We're planning a comprehensive pentest and Red Team simulation for our company's e-commerce infrastructure and internal ERP systems. We received quotes from two different cybersecurity consulting firms, with budgets ranging between 90,000 TL and 160.000 TL. During one of the technical calls, I was taken aback when the consulting firm openly mentioned using ChatGPT and similar generative AI tools to craft social engineering scenarios and generate variations of certain custom exploits.
I know AI is used in cybersecurity for both offensive and defensive purposes but how common and ethical is this in a professional Red Team engagement? More importantly, could sensitive configurations, source code snippets or internal employee data from our systems be fed into these public AI models?
Is using external AI in these tests considered standard industry practice or is it just a shortcut that brings data leak and low-effort reporting risks? What kind of restriction clause should we put in the contract regarding this?