Skip to main content
AI Transformation at a Payment Security Firm: 18 Months InPCI DSS Compliance
5 min readFor Fintech Risk and Compliance Teams

AI Transformation at a Payment Security Firm: 18 Months In

The Challenge

SISA, a forensics-driven cybersecurity company in the payment security sector, faced a critical question 18 months ago: how do you integrate AI across your operations while defending against AI-powered threats?

The company's founder saw AI as both an operational accelerator and a shift in the threat landscape. Traditional cybersecurity methods weren't enough. SISA needed to build AI capabilities for defense and develop expertise in securing AI implementations for clients who were increasingly concerned about model security, data poisoning, and prompt injection attacks.

This wasn't a pilot project. It required an enterprise-wide transformation affecting all ten of the company's solution lines and the creation of a new service offering around AI security.

The Environment and Constraints

SISA operates in a regulated environment where clients expect forensics-backed analysis and evidence-based recommendations. The company couldn't adopt AI through superficial implementations or treat it as "a box-ticking exercise."

Three constraints shaped their approach:

Speed of market evolution. Client inquiries about securing AI implementations were accelerating faster than available expertise. SISA needed to build competence internally while delivering client solutions.

Change management complexity. The founder noted that many underestimate the scale of change management required in AI transformation. This wasn't just a technology deployment; it required shifting how security analysts, auditors, and consultants approached their work.

The dual nature of AI. As a forensics-driven organization, SISA's incident response work revealed that attackers were using AI as effectively as defenders. Their 2024 Digital Threat Report for the BFSI sector documented rising polymorphic malware and increasingly sophisticated malicious scripts enabled by AI code generation.

The Approach Taken

SISA structured their AI integration around three parallel tracks:

AI for Cybersecurity embedded artificial intelligence across all ten solution lines. This meant identifying where AI could drive growth and efficiency in existing services, from fraud detection to compliance automation.

Cybersecurity for AI launched as a dedicated solution line 18 months ago. This addressed client demand for securing AI implementations. To support this practice, SISA developed an ANAB-accredited certification program called Cybersecurity Professional for AI (CSPAI), which trained practitioners on AI-specific threats across three dimensions:

  • Analytical AI risks (data poisoning, model inversion, adversarial examples)
  • Creative AI risks (prompt injection, model supply chain tampering)
  • Autonomous AI risks (unbounded autonomy, multi-agent collusion)

The certification program became both a revenue stream and a mechanism for building internal expertise.

AI for Continuous Improvement focused on infusing AI into internal operations: faster insights, smarter decisions, automated evidence review, and report generation for tasks that auditors typically find tedious.

At RSA Conference earlier this year, SISA demonstrated an Agentic SOC that automated L1 and L2 security operations tasks, allowing analysts to focus on higher-value work.

Leadership education was critical. The founder emphasized that many leaders overestimate their understanding of AI and, as a result, fail to identify the right use cases for their organizations. SISA required top leadership to understand what AI truly could and couldn't do before approving transformation initiatives.

Results and Metrics

The CSPAI certification program received what the company described as "tremendous response and adoption globally." This validated both market demand for AI security expertise and SISA's positioning as a thought leader in the space.

The Agentic SOC solution saw "strong adoption" after its RSA launch, demonstrating that clients were ready to automate routine security operations tasks when presented with a forensics-backed approach.

More broadly, the company achieved AI integration across all solution lines within the 18-month transformation window, meeting the aggressive timeline the founder recommended for organizations of SISA's complexity.

Lessons Learned

The founder's retrospective advice reveals lessons learned:

Underestimating change management. The transformation proved more difficult than anticipated. "The first learning I would share with anyone beginning their AI journey is to accept that change will be difficult," he noted. Organizations should budget more time and resources for the human side of AI adoption.

Leadership education upfront. Rather than building AI capabilities first and educating leadership later, SISA would prioritize executive AI literacy earlier in the process. Misaligned expectations at the leadership level cascaded into misidentified use cases and wasted effort.

Continuous measurement. The company learned to "measure progress continuously, and ensure that AI transformation stays on the CEO's agenda." Without executive-level accountability, AI initiatives drift into pilot purgatory.

Takeaways for Your Team

Treat AI security as a distinct practice area. You can't bolt AI security onto existing application security or network security functions. The threat models are different. Data poisoning, model inversion, and prompt injection require specialized knowledge. If clients are asking you about securing their AI implementations, you need dedicated expertise.

Build competence across the organization. SISA's approach of "everyone should understand how AI impacts their role and decisions" addresses a common failure mode: AI expertise concentrated in a single team while the rest of the organization remains uninformed. Your fraud analysts, compliance officers, and incident responders all need baseline AI literacy.

Plan for 6-18 months, not quarters. The timeline depends on your organization's size and complexity, but genuine AI transformation takes longer than most executives expect. SISA's 18-month window for enterprise-wide integration reflects the reality of change management, not just technology deployment.

Prioritize use cases that move revenue or reduce costs. SISA focused on "changes that directly improve either the top line or the bottom line." AI initiatives that don't map to measurable business outcomes become science projects.

Recognize that attackers have AI too. Your forensics data will tell you this story. Polymorphic malware is easier to generate. Malicious scripts are more sophisticated. If you're only thinking about AI as a defensive tool, you're missing half the picture.

The payment security sector is entering what SISA's founder called "Agentic Commerce," where AI agents will conduct transactions with minimal human oversight. Your AI transformation isn't optional preparation for a distant future. It's foundational work for threats already in your environment.

You Might Also Like