Hook

Video Poster Image

Key Takeaways:

  • Process Before Platform
    Map your customer journey first. Then choose the tools that support it. Automation without clarity just amplifies the chaos.
  • Build a Single Source of Truth
    Stop juggling multiple systems. Pick one core platform for data and integrate everything else into it.
  • Automate the Repetitive, Personalise the Rest
    Automate the predictable. Keep the personal moments human. That’s how you stay connected while scaling.
  • AI Should Be Your Teammate, Not Your CEO
    Use AI to assist, not decide. It should lighten your cognitive load — not replace your judgment.

If your business feels like it’s held together with spreadsheets and wishful thinking, this episode will show you how to scale without losing the soul of your brand.

Sub-Header 1

Sub-Header 2

Sub-Header 3

Sub-Header 4

Sub-Header 5

Sub-Header 6

Sub-Header 7

Sub-Header 8

Sub-Header 9

Sub-Header 10

Give AI a job in your cybersecurity consultancy

Aug 25, 2026
Cybersecurity consultancy founder reviewing an AI generated market intelligence brief on a Monday morning

Key takeaways

  • Treat AI like a new hire. Give it a job description, a start date, a probation review and a set of permissions.
  • A skill is the job description. An agent is the hire carrying it out. Write the job description first, then automate.
  • Tie every AI job to a day of the week. Research on implementation intentions shows vague intentions die.
  • Nothing reaches a client until you'd put your name on it.

"AI relevance gets decided inside your own business."

There's a gap between what cybersecurity founders say about AI in public and what they're doing with it in private.

In public, the conversation is about agents operating inside client environments, who approves what, shadow AI, governance, etc. In private, on calls with me, it sounds different. One client asked me straight out whether his business would still exist in 12 months because of AI.

Yes, it will. But relevance gets decided inside your own business. The founders putting AI to work in their consultancies this year will pull ahead of the ones circling it, and that distance widens slightly every week while you're busy delivering.

AI is changing so rapidly. There'll be another model release next week. Probably tomorrow. Keeping up with all of it is a full-time job you don't have time for, and awareness is plenty.

So here's the one idea this whole post hangs on. Treat AI exactly the way you'd treat a new hire. When you advertise for a new employee, it starts with a job description, a start date, a probation review and a defined set of permissions once they begin. Miss any of those four and the experience for both parties may not be great. Same with AI. 

 

The two reasons AI is not effective in your business

I see the same two blockers on nearly every client call, whatever the industry:

The first is time. You're so busy delivering that putting AI to work in your own business keeps getting put on the back burner. It's the same reason your SOPs aren't written. A client is waiting on something this afternoon, someone on the team needs a decision, your accountant is chasing paperwork, and essentially, you're so busy firefighting, you don't have time to get going with AI.

The second is that you're wired for risk. Letting AI run parts of your business with no one checking the output doesn't sit right with you. That instinct is correct, and it belongs at step four. It shouldn't stop you at step one.

 

AI jargon explained in hiring terms

Half the reason AI stays on the shelf and doesn't get used is the vocabulary. So here's the whole glossary mapped to something you already understand: hiring. Save the graphic below and keep it.

(IMAGE: ai-jargon-buster.png. created by Claude)

 

Model (or LLM): The candidate pool. ChatGPT, Claude, Manus, Grok and Gemini are each a different candidate with different strengths. You're choosing who to hire.

Prompt: A one-off verbal instruction or chat. "Can you pull together last month's numbers?" Fine for small asks. Useless for repeatable work, because you're re-explaining the instructions every single time.

Skill: The job description written down. A document telling the AI exactly how you want a specific task done, step by step, the same way you'd write an SOP for a new starter. Claude calls these skills. In other tools, the same document works as custom instructions, or you can upload them as a project file.

Agent: The hire actually doing the work. Multi-step tasks carried out on its own, following the job description you wrote. With these, you can build in checkpoints for approval before they run entirely autonomously.

Automation: The recurring calendar entry. The agent runs on a schedule without you kicking it off. Only automate a job description you've already tested.

Hallucination: The confident new hire who'd rather invent an answer than say "I don't know". This is why the probation review exists.

Human in the loop: The manager sign-off. A person checks the output before it goes anywhere that matters. Can also be built in at specific checkpoints before the agent progresses to the next step.

Shadow AI: Staff using AI tools you haven't approved, with no job description and no sign-off. You already flag this on client engagements. It applies at home too.

That's the whole vocabulary. Now the four steps.

 

Write the AI's job description before you automate

Skill first, agent second, automation last- that's the order. Reversing it is how you end up with a fast machine producing work you'd never put your name on.

You'd never let a new starter loose on client work with no SOP. AI is no different. The job description is where all your expertise goes, and it's the part only you can write. And if you're staring at a blank page thinking you couldn't even tell me what your process is, there's a shortcut. You can use Claude's record a skill feature to help you out.

Do what you'd do with a new hire: let it shadow you. Record yourself doing the task once, on a screen recording or a voice note, and talk through what you're doing and why as you go. Then hand Claude the transcript and ask it to turn what you said into a skill. It drafts the SOP, you correct it, and it writes the job description from work you were doing anyway. The expertise still comes from you. You just never had to stop to take the time to sit down and write it.

 

Tie the AI job to a day of the week

The second step is to tie the AI task to a day of the week. Psychologist Peter Gollwitzer has spent decades showing that people follow through when an intention is tied to a specific situation, and fail when it stays vague. His 2006 meta-analysis with Paschal Sheeran covered 94 studies and found a medium to large effect, d = .65. In behavioural science, that's a serious result.

"I should use AI more" is easy to say. That's exactly what makes it easy to forget. Anything with a should in it lands like a weight on your chest and then gets deprioritised.

Compare it with this. Every Monday morning, Claude emails me my market intelligence brief. The job now has a day and an output. No new hire ever started without a start date. Don't let this one.

I watched this play out with a cybersecurity client. I'd built him a set of skills, brand guidelines and a few other AI tools tied to his actual work. He understood them, could see where they'd help, and weeks later hadn't touched one. He hadn't committed to when he'd start. And he was procrastinating setting up the AI because his job had no start date, and he assumed setup would be harder than it was. So at a live session we uploaded them there and then, into ChatGPT, and gave one job a Monday slot. Market intelligence research, emailed to him first thing, covering the trends and moves relevant to his industry and his buyers.

The output got good enough that he's now considering turning it into a paid newsletter. Once the job ran every Monday, he could see options that were invisible while the skills sat in a dashboard.

 

Check AI output like you would a new team member on probation 

Every new hire gets their work checked before you trust them. Applying the same loop here is smart.

  1. Give it a real piece of work, the kind you'd hand to an assistant.
  2. Look at what comes back.
  3. Decide whether you'd use it again.
  4. Adjust the next run based on what you learned.

The review has one question at its centre. Would I be happy putting my name on this?

Some outputs will be excellent. Others will take you 45 minutes to fix after you spent an hour building the automation that was supposed to save you 20. There's nothing quite like using AI to create a brand-new admin problem for yourself. I've managed it more than once. That's probation doing its job.

 

Decide what AI can do without you

You'd never give a new starter domain admin on day one. Decide what the AI can do alone, and where a human looks before anything leaves your sandbox.

I got a taste of the alternative a few weeks ago. Someone had been calling me repeatedly, chasing a sale. This time I picked up, and a few seconds in something felt off, so I asked whether I was speaking to an AI. It said yes. I asked it to stop calling. It said sure and hung up so abruptly it was rude. The bot probably followed its job description to the letter. I still came off that call thinking less of the company behind it. Maybe I'm the grumpy outlier and their numbers look great. Someone at that company decided they were happy for AI to behave this way. And I wonder whether anyone actually listens back and reviews the calls.

As a cybersecurity consultant, you spend your working life finding gaps in other people's systems and asking who owns the risk. If an AI output goes straight into client delivery with no one checking it, you've built a gap you'd flag on any audit. You've been drawing these lines for clients for years. Draw them for your own AI or human hires.

At the end of the day, automating something doesn't remove the need to manage it.

 

Give AI its first job this week

Every business runs in the same seven departments. Brand, marketing, sales, finance, operations, client delivery and people. I've built three Claude skills for each, 21 job descriptions ready to hand over, several of which can be scheduled to run on their own. You can get them free here. Install the first, and it walks you through the rest as you need them.

One best practice here, and I'd say this about anyone's skills, mine included. Read each one before you upload it. It's a job description. You should know what it says before you hand tell it to start.

Begin with a task that never touches a client. Monday morning market intelligence is a good first hire, because the worst case is a mediocre read with your coffee.

The gap between talking about AI and putting AI to work closes one job at a time.

Go give AI a job. Then make it earn its keep.

 

Frequently asked questions

What is the difference between an AI skill and an AI agent?

A skill is the job description. It's a document telling the AI how you want a specific task done, step by step, like an SOP for a new hire. An agent is the AI carrying out multi-step work on its own by following that document. Write the skill first, then let an agent run it, then automate.

How do I write an AI skill if I don't know my own process?

Record yourself doing the task once and talk through each step as you go. Screen recorders and meeting tools give you a transcript automatically. Paste that transcript into Claude and ask it to turn the process into a skill. It drafts the step-by-step document, and you correct anything it got wrong before you hand it the job.

What should a cybersecurity consultancy's first AI job be?

Something recurring that never touches a client. Brand guidelines set up, call reviews, 1:1 prep, anything that doesn't reach a customer to begin with. And ideally something you can set up on a recurring schedule to build the habit.

What is an implementation intention?

A plan that links a specific situation to a specific action, in the form "when X happens, I will do Y". Peter Gollwitzer's research found this format produces far better follow-through than a vague goal like "I should use AI more". His 2006 meta-analysis with Paschal Sheeran reported an effect size of d = .65 across 94 studies.

Where should a human check AI output?

Anywhere the output could reach a client, a prospect or your name in public. The gate is one question. Would I be happy putting my name on this? Internal research carries low risk. Anything entering client delivery needs a human review step written into the process.

Is it safe to automate work in a cybersecurity consultancy?

It's safe once you've decided in advance what the AI may do alone and where a person looks first. The risk lives in the undefined boundary. Apply the same access control thinking you'd apply on a client engagement, and never give a new hire admin rights on day one.

 

Related reading

 

Resources mentioned

Stay connected with episodes, news and behind-the-scenes updates!

We hate SPAM. And we will never sell your information, for any reason.

Frequently Asked Questions

Resources Mentioned

Recent Episodes

Give AI a job in your cybersecurity consultancy

How to hand over client work in your cybersecurity consultancy with...

Delegation for cybersecurity founders: what to hand over, and what...