Nova
Log inGet started
AI training · Tech and data

AI training for information security managers

AI reads the vulnerability advisories, the frameworks, and the security questionnaires for you, and writes a first draft of a policy. The risk analysis, the decision, and the signature stay yours.

Get startedTry the interactive demo

Free, no account needed. You try the real product yourself.

In brief

AI for information security managers, in brief

AI helps information security managers with tasks such as “Track the week’s vulnerabilities,” “Find a requirement in the frameworks,” and “Write or update a security policy.” Start with a single task, in Perplexity: allow 10 minutes the first time, and always review the result before you use it.

  • 10concrete use cases
  • 6recommended tools, 5 of them free to start
  • 10 to 30 minper use case, the first time

The tasks where AI helps most

  • Vulnerability and threat monitoring
  • Security policies, acceptable use policies, and procedures
  • Risk assessments
  • Customer and vendor security questionnaires
  • Employee security awareness
  • Incident management and incident reports
Use cases

10 concrete AI use cases for information security managers

For each task: how it goes today, then with the tool. And the time it takes the first time.

Perplexity · “Pro Search”

Track the week’s vulnerabilities

TodayDozens of advisories a week, three of which concern you. Finding them takes an hour; missing them costs far more.

With PerplexityA short list of the vulnerabilities that concern you, ranked by urgency, with the link to each official advisory.

  • 10 min
  • every week

Gemini Notebook · A “Security frameworks” notebook

Find a requirement in the frameworks

TodayA simple question, “what is required for backups?”, and you have to reopen the standard, the directive, and the in-house policy.

With Gemini NotebookA table of the requirements that apply to a topic, with the original article and the gap with your policy.

  • 15 min
  • every week

Claude · “Projects”

Write or update a security policy

TodayWriting rules that comply with the framework, work in the field, and can be read by an employee takes weeks of back-and-forth.

With ClaudeA numbered draft policy, tied to your framework, with the list of choices to settle before approval.

  • 30 min
  • every month

Also

Gemini Notebook · A “Security evidence” notebook

Answer a customer’s security questionnaire

Answers backed by your own documents, and the list of questions where you are missing evidence.

  • 30 min
  • every month

LM Studio · A local model, “Chat” tab

Analyze a reported email on your own machine

A first analysis of the email, the indicators found in the headers, and a reply ready for the employee.

  • 15 min
  • every week

Gamma · “Generate”

Prepare a security awareness session

A short awareness deck, with practical cases, to adapt with your own examples.

  • 20 min
  • every month

Claude · With your notes attached

Write a security incident report

A structured incident report, readable by leadership, with the list of corrective actions.

  • 20 min
  • as needed

Claude · Excel file, in the conversation

Build a risk assessment template

A risk assessment template in an Excel file, to correct and rate in a workshop with the business teams.

  • 30 min
  • as needed

Microsoft Copilot · Copilot in Excel

Calculate the security committee metrics

A “Dashboard” tab with three metrics, their formulas visible, and a chart for the committee.

  • 15 min
  • every month

Perplexity · “Research”

Review a request for a new AI tool

A sourced brief on the requested tool, with the points to clarify before you give your opinion.

  • 10 min
  • every month

All 10 use cases on this page are in Nova, each with its steps and its prompt.

Try the interactive demo
One use case, start to finish

Perplexity for information security managers: track the week’s vulnerabilities, step by step

  • 10 min
  • every week

What to check

A precise list of your versions is useful to an attacker: stay at the level of the product and the major version. The vendor’s advisory is the reference, not its summary.

Track the week’s vulnerabilitiesPerplexity · “Pro Search”
  1. Open perplexity.ai and switch to incognito mode with the icon at the top right. For this kind of question, “Pro Search” reads dozens of sources: 3 per day on the free plan.
  2. Paste the prompt below into the search box, with your products, and no server name or company name.
  3. Click the small numbers to open the vendor’s advisory and the official alerts.
  4. Log what concerns you in your tracker, with the link and the date of the advisory.

The prompt to copy

I am an information security manager. My environment includes: [products and major versions: operating system, firewall, email, VPN, business software]. List the vulnerabilities published or updated in the last [seven days] that affect these products. For each one: the CVE ID, the affected versions, the severity, whether it is already being exploited, the patch or the workaround, and the link to the vendor’s advisory or to the CERT-FR alert. Rank by urgency. Leave out what doesn’t concern my versions, and say so. Flag what you couldn’t confirm at the source.

My path

What you’ll be able to do, one step after another

In Nova, “My path” starts from your level: one next step at a time.

  1. Talk to AI like a colleague

    The first moves, with free tools.

  2. Write faster, without mistakes

    In your jobWrite or update a security policy

  3. Get answers from your documents

    In your jobFind a requirement in the frameworks

  4. Find an answer you can trust

    In your jobTrack the week’s vulnerabilities

  5. Never retype anything again

    In your jobAnswer a customer’s security questionnaire

For a team: everyone moves forward in their own job. You see the team’s progress, never one person’s activity.

The tools

AI tools for information security managers, and what they cost

Claude

Free to start

Write a policy, a risk assessment template, or an incident report from your notes and your frameworks, kept in a “Project.”

Recommended planFree to start. For company data: Team, $25 per user per month ($20 if billed yearly), with no training on your content by default.

Perplexity

Free to start

The week’s monitoring and the vetting of a new tool: answers that point to the advisory or the vendor’s page, which you open in one click.

Recommended planFree: 3 “Pro” searches per day and 1 “Research” report per month. Then: Pro, $20 per month (€22 on the French App Store).

Gemini Notebook

Free to start

You upload the standard, the official guides, and your security policy. It answers by citing the article, from those documents alone.

Recommended planFree: 50 sources per notebook and 50 questions per day. Included in Google Workspace if your company uses it.

LM Studio

Free to start

An AI model installed on your computer: you can read a reported email or a log excerpt without it leaving your machine.

Recommended planFree, $0: free with local models, no account needed. Internal use at work is allowed.

Gamma

Free to start

A clean awareness deck in a few minutes, to adapt with your own examples.

Recommended planFree, $0, to try it: 400 credits that do not refill. Then: Plus, €8 per user per month, billed yearly (€96).

Microsoft Copilot

If the company is on Microsoft 365: the month’s metrics are calculated in Excel, without taking the exports out of the company workspace.

Recommended planMicrosoft 365 Copilot Business, €15.60 excl. tax per user per month, annual commitment.

Prices taken from the vendors’ official pages, dated on each tool page. These subscriptions are not included in Nova. Brands are named to identify the tools. No affiliation.

Ground rules

The rules to follow with AI in this job

Always do this

  • No unpatched vulnerability, no audit result, no architecture diagram, and no secret in a consumer assistant. Use the company workspace, or an AI model installed on your computer.
  • An advisory, a requirement in a standard, or an article of law is checked at the source: the vendor’s site, the official text, the national authority’s alert.
  • Logs, reported emails, and incident reports contain personal data: GDPR applies, and the data protection officer is involved.
  • AI prepares, you decide. Accepting a risk, granting an exception, and classifying an incident are signed off with leadership.

Never hand this to AI

  • Letting it classify an incident on its own or decide on a notification to the authorities.
  • Letting it block an account, an address, or a traffic flow without human approval.
  • Pasting in a password, a key, or the full report of a penetration test.
Questions

Frequently asked questions about AI for information security managers

Which AI tools should information security managers use?

Nova recommends 6 to start with: Claude, Perplexity, Gemini Notebook, LM Studio, Gamma, and Microsoft Copilot. 5 of them can be used for free to get started.

How does Claude help information security managers?

Write a policy, a risk assessment template, or an incident report from your notes and your frameworks, kept in a “Project.” The plan to choose: Free to start. For company data: Team, $25 per user per month ($20 if billed yearly), with no training on your content by default.

Where should information security managers start with AI?

With “Track the week’s vulnerabilities,” in Perplexity (“Pro Search”). Allow 10 minutes the first time. A short list of the vulnerabilities that concern you, ranked by urgency, with the link to each official advisory.

Is this an accredited course that leads to a certificate?

No. Nova is software, not an accredited training provider: it issues no diploma or certification. It costs €19 per month for one person, and €129 per month for a team of up to ten people.

Go further

AI training: related jobs