Cybersecurity and safety in the age of AI
Brian McKay
Senior Investigator/ Trainer | ICAM Australia
It is good to group these terms together, because coming from the cyber side... we do tend to think of this as security. But I do like talking about this as safety and security.
- Brian McKay
About this session
Cybersecurity has always been framed as an IT problem: keeping malicious actors out. But once AI systems start making decisions and taking actions inside high-risk environments, a breach stops being purely a data problem. It becomes a safety one.
In this session of the Safety Voices webinar series, host Sam Williams sits down with Brian McKay to explore that overlap: why he treats cybersecurity and safety as one conversation rather than two, who actually ends up owning the risk when a system fails, and what health and safety professionals need to understand about AI adoption, without needing to become IT experts themselves.
The CIA triad, applied to AI
Brian's starting point is that AI doesn't need a new security model. It needs the same one, applied harder in a few specific places.
Confidentiality: Preserving restrictions on information, privacy, corporate secrets, classified or sensitive data. Unchanged in principle, but AI systems introduce new leakage points: sensitive data fed into a training set can resurface in an output months later, without anyone intending it to.
Integrity: Making sure data hasn't been destroyed or modified, intentionally or not, and that it can be trusted. This is where AI adds real weight: training data itself becomes an asset that needs protecting, since a poisoned or biased dataset produces confidently wrong outputs at scale.
Availability: Systems need to be there when needed, for users and for the automated processes now built on top of them, from cloud services to power grids.
The risks aren't new categories. They're the same three questions, asked with more urgency, because AI systems are now targets in their own right, attractive precisely because of the data they hold and the decisions they're trusted to make.
Why safety has to be in the room
Brian draws directly on his background in critical infrastructure, where cybersecurity teams and the engineers and electricians actually running plants and distribution networks had to learn to work as one group, not two adversarial ones.
The pattern he's seen repeatedly: the business owner makes the case for a new system, security's instinct is to say no, and safety gets treated as an afterthought to both. But once large-scale, high-risk systems are involved, there's an inherent threat to safety sitting underneath every cybersecurity decision.
His view is straightforward. A health and safety professional doesn't need to master IT or security. What they do need is a seat at the table during risk assessment, enough understanding of the potential outcomes and their impact on safety to ask the right questions when a new AI system is proposed, not after it's already been deployed.
Key takeaways from the session:
1. Cybersecurity and safety are one risk conversation, not two
Once AI systems start taking actions rather than just producing outputs, a security failure and a safety failure can be the same event. Treating them as separate conversations misses that overlap.
2. Ownership of AI risk sits across teams, not inside one
Security tends to own the "no," the business owner owns the case for adoption, and health and safety needs to be present for both, understanding the safety impact well enough to weigh in before deployment, not after.
3. Social engineering got a serious upgrade, not a new category
Phishing, deepfakes and impersonation aren't new attack types, but AI has made them dramatically more convincing. A cloned CEO voicemail or a generative-AI LinkedIn profile built to pass hiring checks lands very differently than a typo-ridden email from a stranger, and that believability is itself a safety-relevant risk.
Speaker
Brian McKay
Senior Investigator/ Trainer, ICAM Australia
Brian McKay is a seasoned expert in cyber security, engineering, and safety, with 30 years of experience spanning critical infrastructure protection, innovation integration, and project management. His career includes leadership roles at Amentum, Booz Allen Hamilton, Xcel Energy, and the U.S. Navy, where he served as a nuclear-trained submarine officer. Brian has developed cyber security frameworks, led AI-driven defence initiatives, and worked with agencies like USINDOPACOM and the Nuclear Regulatory Commission. He holds degrees in Electrical Engineering and an MBA, along with CISSP and PMP certifications, and frequently speaks at industry conferences on cybersecurity and critical systems.
ecoPortal past webinars
Learn the latest and greatest health and safety strategies from global industry leaders.
Our Partners
We partner with a range of innovative health and safety organisations to bring you expert insights into the most pressing topics concerning health and safety today