Secure AI adoption is becoming an important priority for Scottish organisations. Artificial intelligence can save time, improve access to information, and help people work more effectively. It is also helping cyber criminals create more convincing scams and carry out familiar attacks at greater speed.
Liz Smith, Business Development Director, and Sam Flockhart, Client Technology Manager at Lugo, attended the Sword and the Shield: AI and Cyber Security event in Edinburgh.
Lugo partners with Cyber and Fraud Centre Scotland to help organisations strengthen their cyber resilience and respond confidently to changing security risks.
What this article covers
This article shares the event’s practical lessons for Scottish business leaders, including:
- Why AI and cyber security must be considered together
- How AI is making familiar scams more convincing
- Why strong cyber security foundations still matter
- How to control access to sensitive business information
- What to ask suppliers introducing AI features
- Where AI can create genuine business value
- The practical actions leaders can take now
The main message was encouraging. Organisations do not need to avoid AI, but they do need to lead its introduction carefully.
🤝 Bringing AI and cyber security together
The event, hosted by Cyber and Fraud Centre Scotland at Brodies’ Edinburgh office, brought together specialists in cyber security, artificial intelligence, technology, and law.
The discussion was refreshingly practical and largely free of the usual AI fanfare. AI is neither a magic wand nor a reason to hide under the desk.
Used well, AI can help an organisation grow, develop its people, and improve its services. Used without appropriate care, it can expose sensitive information, increase existing weaknesses, and create risks that nobody quite owns.
Jude McCorry of Cyber and Fraud Centre Scotland opened the event by making the case for considering AI and cyber security together, rather than treating them as separate subjects.
This matters because an AI tool rarely sits neatly within one department. It may:
- Access business or client information
- Support a client-facing process
- Help prepare advice or communications
- Influence business decisions
- Connect with other systems
- Take actions on someone’s behalf
Its safe use can therefore involve leadership, technology, data protection, legal, compliance, and operational teams.

A practical test for business leaders
Caólán Keenan of Cyber and Fraud Centre Scotland helped bring the risks to life through a practical exercise.
Attendees considered what they would do if an existing software provider introduced AI into a system holding sensitive information. They then had to respond to a claim that the new AI feature had disclosed organisational data.
The exercise raised questions that every organisation should be asking:
- What information can the AI access?
- Where is that information processed?
- Is the information used to train the AI?
- Can the feature be disabled?
- Who approved its use?
- How would a reported security weakness be verified?
- Who would lead the response?
The lesson was clear: AI governance cannot begin after something goes wrong.
🛡️ The cyber security basics still matter
Thaïs Ramdani of Cyber and Fraud Centre Scotland brought the discussion firmly back to cyber security fundamentals.
AI has not removed familiar threats. Organisations must still protect themselves against:
- Phishing
- Stolen passwords
- Invoice and payment fraud
- Ransomware
- Weak or reused passwords
- Systems that have not been kept up to date
- Excessive access to confidential information
In many cases, AI has simply made these attacks quicker, cheaper, and more convincing.
Phishing is becoming harder to spot
The traditional signs of phishing are now less dependable. Poor spelling, strange grammar, and awkward wording are no longer reliable giveaways.
AI can create a polished message, copy a familiar writing style, refer to genuine business activity, and encourage the recipient to continue the conversation through another channel.
A suspicious message may not contain a link or attachment. It could simply ask someone to move the conversation to WhatsApp, Teams, text message, or a phone call.
Voice and video are not proof of identity
Synthetic audio and video create a further risk. A caller who sounds like a senior colleague, or an online meeting that appears to include familiar people, should not automatically be accepted as proof of identity.
This is especially important when someone is asked to:
- Release confidential information
- Change supplier bank details
- Approve a payment
- Reset an account
- Provide login information
- Bypass an established process
The answer is not to expect every person to spot every deception. Even the sharpest pair of Scottish eyes can be caught on a busy Friday afternoon.
Use several layers of protection
Organisations need several layers of protection so that one mistake does not automatically become a serious incident.
These should include:
- Multi-factor authentication
- Secure password management
- Properly configured e-mail security
- Carefully controlled access to information
- Independent checks for financial changes
- Security awareness training
- A quick and simple way to report concerns
A supportive reporting culture is also part of good cyber security. If someone clicks a suspicious link or shares information incorrectly, the priority should be to report it quickly and limit the impact.
Hiding a mistake through fear of blame gives an attacker more time, which is the last thing anyone needs.
The event’s message was direct: AI cannot replace basic cyber security.
⚡ AI attacks require faster defences
John Brodie of Kallidin AI described AI as both the sword and the shield.
Cyber criminals can use AI to improve phishing, create false identities, identify weaknesses, and carry out attacks more quickly.
At the same time, defenders can use AI to recognise unusual activity, identify vulnerabilities, analyse patterns, and respond at a speed no person could match.

One of the event presentations highlighted three growing external threats:
- Machine-speed attacks: familiar attacks carried out much faster
- Synthetic identity: AI-generated voice, video, and identity impersonation
- Supply chain AI risk: exposure created by suppliers and software providers
The challenge for leaders is straightforward. Criminals are already investing in AI, so organisations need to consider whether their defences are keeping pace.
Automation can create new bottlenecks
Faster detection can create another problem. If an automated system generates more alerts than a team can assess, the bottleneck has simply moved.
Good implementation must consider the full process:
- What happens when an alert is raised?
- Who reviews it?
- Which actions can happen automatically?
- Which actions need human approval?
- How is an incorrect action stopped or reversed?
Organisations should aim for controlled assistance rather than blind autonomy.
If an AI system can change records, communicate externally, or interact with sensitive information, it needs clear boundaries, limited permissions, appropriate monitoring, and human approval for higher-risk actions.
⚖️ Governance and accountability
Martin Sloan of Brodies discussed developing legal questions around AI-generated content, intellectual property, liability, and reliance on automated output.
A significant point from the panel was that AI governance should be based on how the technology will be used. One broad rule cannot cover every situation.
Using AI to prepare a first draft is very different from allowing it to:
- Provide regulated advice
- Make decisions about people
- Change financial information
- Approve transactions
- Communicate directly with clients
- Alter live business systems
Each use needs its own assessment of the information involved, the possible consequences, and the checks required before anyone relies on the result.
AI governance is a shared responsibility
Governance should not sit with one person or department.
Business leaders should define the purpose and acceptable level of risk. Technology specialists should understand access, security, and integration. Legal and compliance teams should consider the organisation’s obligations. Operational leaders should make sure the process works in practice.
Someone must still be accountable. “The AI did it” is unlikely to satisfy a client, regulator, insurer, or board.
🔗 Do not overlook your supply chain
Alastair Hoey of Network ROI focused on the questions organisations should ask when purchasing AI services or when existing software providers add AI features.
A firm may have strong internal policies but still be exposed through a provider that handles its information differently.
An organisation that selected a system several years ago cannot assume the service, risks, or supplier arrangements remain unchanged.
Questions to ask your suppliers
When a provider introduces an AI feature, ask:
- What information can the feature access?
- Where is the information processed?
- Is the information anonymised?
- Is customer information used for AI training?
- Which other organisations are involved?
- How is access controlled?
- Can the feature be disabled?
- How will the provider notify you about future changes?
For Lugo’s regulated clients, this type of supplier review is particularly important. Confidentiality and compliance responsibilities do not disappear because information is being handled by someone else’s system.
The panel’s advice was not to reject innovation automatically. The better approach is to create a secure route to “yes”, supported by appropriate checks and safeguards.
📈 Where AI can create real value
The event was not only about risk. John Brodie also highlighted examples of AI being used successfully in medicine, fraud detection, software development, and scientific research.

The wider business lesson was about choosing the right problem.
AI can be particularly helpful when people are overwhelmed by information or spend significant time repeating predictable tasks.
In professional services, suitable opportunities may include:
- Summarising long documents
- Preparing an initial draft
- Finding information across approved business records
- Supporting meeting preparation
- Comparing information from several sources
- Highlighting patterns for human review
- Reducing repetitive administration
The most valuable question is not, “Where can we use AI?”
A better question is, “Where does work currently wait, and could AI help without creating a greater risk elsewhere?”
Start small and measure the result
Choose one or two clear uses rather than starting numerous disconnected experiments.
Before beginning, decide:
- What problem are we solving?
- What should improve?
- How will we measure the result?
- What information will the AI access?
- Who will check the output?
- Who is accountable?
A collection of uncontrolled experiments may look innovative, but it seldom produces sustainable value.
Treat AI as a junior member of the team
A useful principle from the event was to treat AI like a junior member of the team.
A capable new colleague may produce valuable work quickly, but an experienced person would still review important advice, calculations, recommendations, and client communications.
This is where people and technology work best together. AI can complete some of the groundwork, while experienced professionals provide context, judgement, challenge, and accountability.
✅ Seven practical steps for Scottish organisations
1. Understand how AI is already being used
Identify which AI tools people are using, why they are using them, and whether approved options meet their needs.
Simply banning unapproved tools may drive their use further underground. Speak with your people and understand the problem they are trying to solve.
2. Create clear and practical guidance
Produce concise guidance explaining:
- Which AI tools are approved
- What information must never be entered
- When human review is required
- Who can approve a new use
- How concerns should be reported
AI governance should involve business leadership, technology, data protection, risk, and compliance. It is a business issue, not something to leave quietly in the IT cupboard.
3. Review access to business information
An AI assistant connected to poorly organised files could surface confidential material that the person using it should never have been able to see.
Remove outdated access, classify sensitive information, and tidy up data before connecting AI to it.
This is especially important for regulated organisations holding confidential client, financial, legal, or people-related information.
4. Strengthen financial controls
Changes to payment instructions, supplier bank details, or significant transactions should be verified independently using trusted contact information.
A familiar voice, face, or writing style is no longer sufficient evidence.
Consider requiring approval from two people for significant transactions or changes to payment details. Verification should use a trusted contact method that is separate from the original request.
5. Review your providers
Review providers regularly, particularly where services hold client, financial, or people-related information.
AI features can be added to systems you already use, so supplier risk is not limited to new purchases.
6. Make reporting straightforward
People should have a simple way to report suspicious messages, unexpected requests, accidental disclosures, and possible security incidents.
If reporting is difficult or time-consuming, concerns may not be raised quickly enough.
Clear reporting arrangements, regular awareness training, and a supportive culture unite people and technology around shared responsibility for security.
7. Prepare for an incident
Maintain and test an incident response plan.
The plan should clearly explain:
- Who leads the response
- Who makes important decisions
- How systems will be contained
- Who contacts clients and suppliers
- When insurers, regulators, or law enforcement may need to be involved
- How services and information will be restored
The plan should also explain how to handle a claim from someone saying they have found a vulnerability or obtained organisational data.
The claim should be taken seriously, but it must be verified before information is disclosed, payments are discussed, or changes are made.
That is what secure leadership looks like: preparing before an incident rather than having a committee meeting while the digital roof is already on fire.
Moving forward with confidence
AI presents genuine opportunities and genuine risks, but neither needs to be exaggerated.
The organisations most likely to benefit will not necessarily be those that adopt every new tool first.
They will be those that:
- Choose useful and appropriate applications
- Set clear boundaries
- Protect confidential information
- Measure the business value
- Review AI-generated work
- Keep people involved in important decisions
- Remain accountable for the outcome
Lugo has supported regulated Scottish organisations with secure IT strategies since 2003. We understand the need to balance innovation with confidentiality, compliance, client trust, and commercial reality.
By bringing people and technology together, Lugo helps organisations build secure foundations, adapt confidently, and grow without introducing avoidable risk.
Our aim is simple: to provide clear advice, practical support, and an outstanding service delivered with integrity.
📞 Discuss secure AI adoption with Lugo
Are you confident that your organisation’s AI use is secure, controlled, and delivering genuine value?
Lugo can help you review your cyber security foundations, understand how AI is already being used, assess access to sensitive information, and develop a practical approach to secure AI adoption.
Book an appointment with Lugo to discuss your organisation’s cyber security and secure AI adoption.







