Site icon The Security Student Podcast

Show Notes: AI as a Force Multiplier: Inside the New GSOC Operator’s Toolkit | Episode #46

Overview

#046 – Today I’m joined by Michael Farley. He is a 17-year veteran of the security industry who has worked in GSOC leadership at some of the most demanding technology environments. He specializes in standing up and optimizing global security operations centers, engineering SOPs, runbooks, and instructional systems that turn operational chaos into what he calls “Source of Truth” command hubs. A big part of his craft sits at the intersection of GSOC operations and learning and development, designing onboarding programs, training curricula, and analyst enablement frameworks rooted in adult learning principles. Lately, he’s been applying that same architectural mindset to AI, building retrieval-augmented generation (RAG) systems and custom intelligence agents to multiply what small teams can do.

If there’s one thing I took away from this conversation, it’s that you have to embrace the spirit of a pioneer to actually learn these AI tools. You have to be willing to explore, test the limits, break things, and iterate your way to something that works.

In this episode, we get into how he’s using NotebookLM and Gemini agents to power SOPs, intel reports, and analyst training, plus where this is all heading, from in-house LLMs to the future security role we both see coming: the physical security AI integrator.


Highlights from This Episode

  1. Your RAG system is only as good as the documents inside it; write SOPs to be as pristine and granular as possible, and consider adding a separate line under each human procedure written specifically for the AI to read and implement, so the machine does not get tangled in language meant for operators.
  2. Give AI instructions the way you would give them to a 10 year old; do not say “take the clothes out of the washer” and assume the dryer is implied. State where it starts, where it stops, what the output should look like, and at which steps it should pause and ask you for input.
  3. Start your agents with the least instructional language possible and build the fence around them over time; too many hard guardrails up front can cause an agent to overlook something critical that you or your client actually wanted in the report.
  4. Curate the source list your agent may pull from and the sources it may not; naming trusted outlets up front is one of the highest value instructions available, especially in a GSOC where local sources matter.
  5. Trust what you verify; AI will not tell you when it is unsure, and it will state a wrong conclusion with complete confidence, as it did when it decided a bridge under construction for three years was probably open and safe for a traveler to cross.
  6. Use several narrow agents rather than one comprehensive agent; hallucinations increase when a single agent is asked to cover too much ground, which is part of why the Pentagon deploys more than 100,000 agents across separate tasks.
  7. Lean on AI as a writing aid, report drafter, and researcher, and stay cautious with heavy quantitative work; percentages, dates, and hard numbers still need a human verifying each one.
  8. Feed it your past reports and preferred structure; once a model understands your audience, your formatting, and the way you formulate your thoughts, it will get you 70 to 80 percent of the way there, and quick turnaround reports that took 16 hours can land in four.
  9. Fix the data pipeline before you deploy the AI; most GSOCs have a five window problem where cameras, alarms, and intel feeds sit walled off from each other, and the military invested in data scaffolding first for exactly this reason.
  10. Be a pioneer and push all the buttons; the instructional language you develop transfers across Claude, Gemini, and ChatGPT even when the tool itself does not, so the skill you are building is portable no matter which platform your organization adopts.

Memorable Quotes:

RESOURCES MENTIONED


Related Episodes


Share this
Exit mobile version