Balancing AI Benefits and Risks as Your Next CISO Could be Artificial Intelligence - Evan McHenry - BSW #466
Get every episode summarized
Each time Security Weekly Podcast Network (Audio) publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
About this episode
“This week, we welcome Evan McKenry, Chief Information Security Officer at Robinhood Markets, to discuss how to practically implement and secure AI in the enterprise.”From the transcript
As businesses race to embrace AI, security leaders are struggling to modernize cyber hygiene and prevent over-privileged agents from causing unintended harm. How do you balance the benefits of AI with the Risks of AI?
Evan McHenry, Chief Information Security Officer at Robinhood Markets, joins Business Security Weekly to discuss how to practically implement and secure AI in the enterprise. Evan will share his lessons learned over the last 18 months, including how to communicate with the Board, why you should own Enterprise Architecture and embrace IT, and why you don't have time to argue with your CFO. If you're struggling to balance the benefits of AI with the Risks of AI, this interview is for you.
In the leadership and communications segment, Security spending is growing — except for the typical CISO, What Leaders Need to Know About AI and Psychological Safety, The Cyber Gap, and more!
Visit https://www.securityweekly.com/bsw for all the latest episodes!
Show Notes: https://securityweekly.com/bsw-466
Get every episode summarized
Each time Security Weekly Podcast Network (Audio) publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Transcript ready
772 searchable segments. Every word is indexed and playable.
Full transcript
Security Weekly Podcast Network (Audio) — Balancing AI Benefits and Risks as Your Next CISO Could be Artificial Intelligence - Evan McHenry - BSW #466. Machine-transcribed; use the interactive transcript above to jump the player to any line.
This week, we welcome Evan McKenry, Chief Information Security Officer at Robinhood Markets, to discuss how to practically implement and secure AI in the enterprise. In the leadership and communication segment, security spending is growing, except for the typical CISO. What leaders need to know about AI and psychological safety, the cyber gap, and more, is the security weekly starts. Now. It's the show where we explore the business of security to improve the security of business. Your trusted source for emerging risks, leadership, and communication. Get ready for business security weekly. Welcome to Business Security Weekly. This is episode number 466 recorded September 21st, 26. I am your host, Mount Alderman. Joining me again is my single co-host this week is Mr. Jason Elbacurky, a little different now. Come on the football games this week. This was a good week.
Happy Monday. You know, the branch took a W against the box. My Patriots took one against the Steelers. I said to the summer sorry, not sorry, but it is what it is, right? This is the NFL, the future with the Pats winning every week. Let's go. Come on. Well, that, that, the, the, the Kansas City game was a really good game to us. That's a tight game last night. It was. It was a tight game. 3330. Let me tell you the Colts. They, I thought they're going to pull it out there for a hot minute. I thought so too, which, you know, look, I thought Kansas City played really, really well. This two weeks in a row. And the Colts to keep up with them means the Colts are probably a pretty good team this year. Yeah, no doubt. We get the Jags next week. Yeah, we got the Jags. They were back in one boy. Liam Cohen. So, yeah, he's a Rhode Island boy coach of the Jags. I can't wait to see what happens then, but I got faith in my Pats, no doubt. That's a high profile injuries this week. You see the Jane Daniels injury? All by the way, Caleb Williams.
Not good. No. Oh, dangerous being a quarterback in the NFL. That is. It is. It is. All right, one quick announcement. And then we're going to get into the interview. Identity risk is growing fast. Too much access. Too many accounts and not enough control. MFA fatigue attacks, credential abuse are slipping past defenses and impacting the business. And fixing it without adding friction is the challenge at the identity virtual cybersecurity summit on September 30th. Learn how to balance security, usability and risk reduction. Security Weekly listeners can register for free by visiting securityweekly.com forward slash identity using that same promo code CSS 26-sw. Evan McKennery is a vice president and the chief information security officer at Robinhood markets where he leads security and corporate engineering, ensuring secure and scalable operations. Formerly deputy C. So he drove key security initiatives and aligned Robinhood's IT infrastructure
with rapid growth. With over 20 years in security and IT, Evan has approved the track record and regulated industries. Evan, welcome to business security weekly. Hello. Thank you for having me. Thanks for coming. As people know on this show, CISO, any CISO anywhere wants to come on and share wisdom with the audience is always welcome. I think your PR team or somebody reached out and I'm like, yeah, like when can we get them on? Yeah, happy to do it. We're doing a ramp up to share more information also about this topic, one of blog posts we're doing. And we'll be very soon sharing out probably close to 10 different areas that we have adopted AI and security so that we can share some of our learnings with the rest of the industry. Yeah, that's what we're going to talk about today. You guys have been on a project. I think for about 18 months on bringing AI into the enterprise and I thought, what a better topic than to like share the lessons learned as a CISO of bringing AI technologies in with
the all the concerns we all know, right? Like we've seen some of these interesting attacks, the hugging phase kind of jailbreak, etc. Like as a trading kind of network, right? The regulations you guys are under probably creates a little concern at times about what this AI can and can't do. So Evan, once you give us a little background on the project and kind of where things started and then let's dig into some of the lessons you've learned. Yeah, absolutely. And I think one thing that's fairly unique would have highlighted about Robinhood and particularly securing Robinhood is we are one of the fastest moving fintechs out there. We have incredible design principles, our user experiences, a core part of our application. And obviously the regulatory and security perspectives are our bare minimum here. We cannot skip on anything. Many companies get like one or two of those combinations, but Robinhood has, you know, all four at once.
So navigating that has been quite a fun time. And I will also share it's possible. Like we've been able to do it. We have over 97% of all employees, engineering or non-engineering at Robinhood use our R.A.I. tools on the daily. All of our A.I. network traffic is inspected and goes through centralized services. We have custom and point scanners that are running. And we have a pretty lean crew. We have operating principles of lean and discipline. So we can do it with a small and mighty team, but it requires extreme decision making and alignment with the entire company on the path forward. So I'll share a little bit more about that shortly. But our journey started generally, I would say mid 2025 is whenever particularly security and infrastructure started picking this up. Our key focus was getting a product out there. Cortex launched in, I think it was mid 2025. And that was a customer facing product. But we began to see that it was possible to build and manage our own infrastructure instead
of waiting on vendors to do it. And that's been a key part of our story, which is build it, don't wait. I would say it has taken us probably about six to nine months to get all of our IT and security and infrastructure teams ramped up into a place where they can understand AI natively. And that was a huge get pain of learning and learning education, providing tools and securing them along the way and risk accepting some various decisions just to get things out there. So that's one area that I think we have to, we can talk a little bit more about is the fact that if you don't adopt AI, you're accepting an entirely different kind of risk. And that's a competitive risk and in the security space. If you're not adopting AI now, you haven't been adopting AI for the past six months, you're already behind the taffers. So you have to start by succeeding some AI infrastructure decisions so that you can prepare for the future. Security teams are overwhelmed.
In 2025, more than 48,000 vulnerabilities were disclosed, yet only a small fraction pose real risk. Most organizations remain stuck in a reactive cycle, responding to everything without the clarity to know what actually matters. Original, a global provider of independent software support is built on one principle, giving organizations control over their own IT roadmap, risk, and critical systems. Optus by original is a predictive intelligence service that brings that same approach to security, helping teams predict risk validate what matters and act with confidence. Visit securityweekly.com forward slash original for a conversation with a security expert today. So Evan, I'm interested in like rewinding to the beginning of the strategic conversation. How involved was your board in these strategies? And what types of conversations were you having upfront with the board? Like you mentioned, you know, if we don't start adopting AI, this is the risk. If we do go down this path here, some risk that we're going to have to talk about deal with strategically and work our way through.
So, you know, I'm very curious from a board level and to be honest with you, the rest of the executive team as well, how involved are they in these conversations? And what types of stakeholders were they in that entire journey? Yeah, so I think Robin, it's fortunate you can look at our board of directors online. We have a lot of well-known people in the technology industry from Silicon Valley. So we, I think one of the key learnings I have here is during a technical innovation and shift in an industry, it's important to have people on the board that understand the company's nature and can communicate in ways that are just, it's not just about risk acceptance and, you know, ERM perspective, but instead it's also about competitive risk acceptance. They were very involved. I think they were pushing and they continue to push on the frontier. They, we talk about everything AI, every quarter, I'm talking to them about something AI security. So on the product fund, it was, it was a huge opportunity and I think, you know, Vlad
is great in terms of being a visionary. He knew from the outright moment that there was a competitive advantage to being AI native company and adopting AI. But also I will say along the way, him and I've had private conversations in which he's asked me directly, do you want to pull the breaks on this? Where to comfort level, where's your risk tolerance level? And I think that's a key part of this journey, as a particularly CISO, is no, you have independence with your board, you have independence with your leadership team. I am peers with infrastructure and peers with product engineering, but I report to Vlad. I have my own spot on the board, which I have in the safety committee. And I'm part of various entity boards around the company. So I have the voice and I don't think companies can move quickly enough right now to adapt to the industry change without their CISO having that voice. Yeah, right? So obviously Robinhood made a decision to move forward.
You didn't want to be in a competitive risk situation. What are some of the first kind of AI risks you identified early on that you knew you needed to tackle in order to create an environment that didn't put you into a regulatory kind of issue, right? Because I think that's the first one people were trying to figure out. Okay, I've made the decision I'm going. Where should I focus first? Like what are those big risk areas that I need to address early on, head on, or we're not going to get there? Yeah, I think one of the things is shadow sprawl. Especially whenever you have a large amount of pressure coming from industry, your executives, it's in the news. We're in mental parks. We have a ton of times we got the lunch and you're surrounded by volunteer employees, opening eye employees, and you're right in the thick of it. So I think one is understanding that there is a spectrum of risk on the shadow IT front
that you have to manage. And if you're an IT leader, you have IT leadership background where you were a former IT specialist, you've probably been dealing with this in different ways, which is you catch that something's running on an endpoint, but it's not part of the paved road. You do the quick risk assessment. Do they have access to sensitive data? Do they have access to communicate outside of our perimeter, etc? You have to make a moment in which you're thinking the risk here is minimal. I am not going to take a extreme decision on this and shut this thing down because this person is adopting and using it, but I'm going to monitor it's usage. So you add a lot of alerts to around it. You can create AI tools that scan product roadmaps to give you an alert if something news coming up on a product that you're keeping an eye on. I highly suggest doing that right now because things are moving so quickly. But that's one of the key areas where it was just the shadow usage, particularly with the MCP services. Right as they came out, obviously immediately some threat actors were putting malicious
extoll directly into an MCP or just having bad practices. So we identified a couple of those choke points, MCP services, endpoint usage, access to private information, being able to do PI Redaction. And we built our first party tooling around all of those choke points. So then we would have a foundation in which as our risk posture would ebb and flow and things would change, we had tooling that we could adapt to that moment. And this is where the build advantage is in there for the defenders right now. And IT governance in which you can build these tools a lot more easily now than previously. But you can build them and you need to have that control to match where you are this week and next week and not have a third party that you're going to and begging to get some roadmaps time with. It's interesting because one of the challenges I've seen is the ability to monitor these different environments. And so you saw the same thing, but instead of waiting for the industry and the vendor
community to catch up, you kind of built your own infrastructure I think, right? We sure did. Yeah. The MCP gateway I think was a big win for us. Originally when we began pushing a lot of adoption goals across the company, it was download the MCP run at my grand point and we're scanning and monitoring the endpoint using EDR and DLP tools to look for bad practices. But then as we got the gateway stood up, we switched our entire security infrastructure team and corporate security team to building our own MCP services and putting them through this gateway that had logging into Lema tree in it. And then as you would take one MCP from the wild and customize it to Robinhood and add it to our gateway service, we would then block the endpoint install for anything that looked like that MCP. So we gave an incremental approach that we could get this gateway adopted, keep the company
moving at velocity because it's very important to Robinhood. We are a fast moving company and continue to push adoption throughout the company. That was a pretty good service. And now we just basically boot your laptop up, you get an update on the MCP gateway service, it's auto configured across cloud or other internal infrastructure that we have people using AI tooling on and we only have to manage one thing. So Evan, how important was data governance and identity boundaries and things of that nature within your environment? Because I know a lot of organizations were trying to jump in and really leverage AI as that competitive advantage quickly realize that their data governance needs some work. We talk about foundations, we talk about making sure your foundations are in control. A lot of the legacy IT debt is catching up to us, right? Of the places that we collected, you know, and they're realizing that they have to go back and look at their data pipelines or identity boundaries, their DLP, just to make sure they're not leaking sensitive data.
How important was that in your strategy? I would say data governance was number one. And back in early 2025, we built a, we call it LLN gateway. There is an open source tool called LLN gateway, no relation, but ours is a data governance reduction tool and logging tool. We also made an architectural decision very early on that we were only going to be leveraging AWS bedrock hosted instances so that we can have a gateway service for the APIs. That was then enforced on our safety by design review process. So anytime anyone would try to do anything with AI and add new architecture, bring in a new vendor, we disallowed direct inference at the labs and forced them through the API gateway. That policy has been shifted as the data retention stories been a little bit more clear and we've been able to move more observability and data governance directly into the tools themselves. That was absolutely number one non-negotiable.
We cannot have any AI tool leaking sensitive data for our customers or MNPI for the company. And that was the first governance decision that we made and built out. That's amazing. That's great to hear. It's something that I have angelized every organization who comes to my company for advice and consulting, right? It's all right. First step, let's take a look at data governance. Let's take a look at your data landscape, right? Make sure everything solid there. Yeah, if you don't have control of your data, kind of what are you doing? That's the big, big thing. I think the IAM story is interesting. We actually made a somewhat, I don't know, I think at the moment it was radical. I was talking to a lot of NHI vendors, non-human identity vendors about this topic. We chose to build services and accounts tied directly to the human. So we could have full understanding of human attribution. And we were, I think I went on a 14 week campaign at our weekly all hands that we do with a flat and the rest of the leadership team for the company in which I reminded everybody,
you are accountable for all of your agents actions. And if your agent spin up sub agents, it's a lineage of accountability. They were accountable for the whole thing. So we were really clear with them on that. And we have since moved into service accounts and having non-human identity in there. But that was another architectural decision in which we could build a, we have a culture of safety always and every employee is ownership of that part of the culture. We had that really baked in that you're accountable for your actions. And we were monitoring you. And we also publicized any major events that happened without shaming the individuals for naming them. But we spoke about it like, hey, we had this thing happen. The agent went and rolled a dashboard out to a third party website. This human approved it. This is the type of stuff you have to watch out for. And that was before classifiers directly built into the harnesses were a thing. That's an amazing approach. I mean, it's basically chain of custody back to a human. Right? I love it.
It's worked out pretty well. We're now at this point in time. We have background agents running and we're working through the non-human identity versus service account identity story. Our big believers in the non-human identity is the right way to go. But I believe the near future for this is AI agents will have intent. They are designed to perform certain actions. They have intent at markdown files associated with them. Other LLMs that judges are assessing access request policies based on the intent and the type of access and the requests and providing it just in time to perform that action. And we're pushing and encouraging everyone to adopt a similar model. I mean, we've talked about intent and agency when it comes to these agents and tying it back to a human chain of custody is a really interesting way to manage that. Because we talked about how do you put guardrails around intent and agency because that's what these tools are going to have. Amazing.
So I want to dig into this just a little bit. I don't want to go super deep here, Evan. But I think this is an area that everybody struggles with right now is you've got the human responsible for the agent. It spawns a process. You keep that. Your LLMs that are providing guardrails, are they using service accounts? Then, and then Mary and the service account, like monitoring service and guardrail service to an agent that still link back to a human. And so it's kind of a combination of the two, right? Where does the nonhuman identity fit into your model then? Nonhuman identity fits in for background agents. So these are more, these are less owned by an employee. And the way I'm thinking about it is these are owned by the department. So I own the ultimately I'm accountable for the responsibility of actions of all of my employees. My Silicon employees are probably the same.
So I believe we are going to see a future and we're actively working on this right now in which the head of the department has a team of synthetic employees who have the intent policies and you have judges looking at the intent and access requests. Those judges are probably service accounts is they have a very, very strict amount of access that they need and that's probably persistent. But ultimately that accountability is just the department owner, just like any other employment action. Got it. Yeah, I'm taking notes as we're doing this because like I said, a lot of people struggle with this and to understand how you're actually doing is kind of helpful in what's the architecture I need to put in place to support this rollout because I'll give you an example, right? When you build a platform and you open up a set of MCP services, how do you track the registering of those agents? Now you're a little more close loop so you may not run into this situation.
But a lot of vendors in the space will have to allow agents to access those services. Do you use human accounts? Not a service accounts. You use nonhuman identity accounts. I think we're all struggling with this, which is why I'm so intrigued with this component. Yeah, I think having a well-defined description of what each account type is and how that operates and then governance around those accounts. We own the IAM policies and teams. Every time access requests or service accounts are made or an agent identity is spun up, it's my organization that's ultimately classifying all that work and our GRC function is auditing that and then ultimately audit and external audit can come in and follow that train of execution decisions back into the originating description of the account as it was generated and what was classified for. That's awesome. That's so great. Obviously, Jason, we got your data and identity questions out.
Okay. Now these things are running. We've got the foundational elements. The next challenge I see is how to monitor what these agents are doing in real time. Again, this is probably stuff you built because I haven't seen a lot of good tooling out there yet in order to do this. Is it just the judges and these different services that are running that are providing that monitor and or did you even go deeper? It's deeper than that. There are judges that are running, but we also have our EDR side of the fence and points side of the fence. There's much more deterministic work that's going on. I think the key part I would encourage everyone as much as they can, work with your IT leaders and your finance department. This is much easier whenever you don't have shadow IT, which I think Robinhood is generally pretty strong at. In Robinhood, I'm also leading corporate engineering at a work closely with the finance department.
Every piece of software that comes into the company goes through my safety by design review process, vendor review process governance from finance. If it looks weird, I am a sign off on that. They can escalate it to me. I'm required to approve it. I can tell them, don't cut that check. We don't want that. Working with the leadership team, I work and tell them why we're not going to allow the next product management tool to go into the company. Part of that is maintaining the ability to manage all of the securely requires that we have a minimum set of tools and we're not sprawling all over the place. If any new software comes in and there's an executive decision that we have to adopt it, it comes in with head down request. We talked previously in other areas about total cost of ownership. That software doesn't get installed without my apartment being able to support it. I love that you clicked into the relationship with finance because on this show, I've
evangelized Matt, you know this. One of the best relationships a CSO can have with the CFO for so many reasons. Can you just talk to me about your relationship with your CFO? How important that strategic relationship is, not only from an investment perspective, but from influence, from quantifying risk within the organization, conversations with the board. There's just so many benefits to having a very strong relationship with the CFO. I'm just interested in how yours operates. I think for both of our CFOs, Jason Warnick and Shivarma, great relationships with them, agree with you. It's a P-Zero one. You must have a good relationship where you're trusted. I think the key area for me building those relationships was thinking like a business donor and knowing every dollar I take from this company is draining product and revenue and money back to our customers and savings. It's really important, I believe, for CSOs to have a bit of a business background as
well. I'm a bit more in the engineering side. I'm interested in the GRC side, but ultimately, I've done a lot of work in the side of businesses. I think one, the CFO, believing that you are operating with the best intent for the company and you independently managing your budget like you own a part of the business and trying to find savings and then seeing that, go and cut software when you know you don't need it. You use roles whenever they become redundant. You down-level roles whenever you don't think you need a more senior person on the organization that is just the ethical thing to do in a publicly traded company as an executive. But I think it's a little bit rare in our space where in the CISO world, a lot of CISOs collect tools because the tools reduce risks in different ways. But I definitely have to make that trade off exercise and I'm seeing that I'm doing that. It makes the times where I go to say, I need a million or two for this exact reason, non-board
discussions and instead little walks around the office. And I think that helps me move quickly. And again, the independent seat on the board is important as well. We're in the Safety Committee, the CFO and I are both there together and we can talk about topics at the board. But fortunately, at Robinhood, not been in one board meeting yet where finance has been discussed as a constraint on security. I love it. The CISO has a fiduciary area. What a concept. Right? Right? I think it's expected from most executive roles. Why not? Why not that role? Exactly. Exactly. And this is what Jason and I talk about a lot. We're going to cover an article in the second segment that doesn't make that assumption, by way, or parts of that assumption, which is you have to understand the business impact of the things you're trying to do. And if you don't, then are you really making the right decisions and you just kind of laid out why you need to have kind of that understanding of the business and the revenue and the impact
and everything that goes along with it as a fiduciary? Yeah, absolutely. And I think it also makes communicating to your organization and regulatory bodies why certain decisions are made. Much easier. I know whenever we're launching brand new products, I'm consulting with the GMs about the risks of those products. I'm telling them what we need in order to secure those products. And I'm also telling them what we don't need. So I think that's a part of the equation. And you have to do a little bit of intentional speaking and you say, here's what I could ask for, but I only need this. Yeah. Any mistakes that you would try to help others avoid along the path? You know, I think right now, the biggest mistake that we encountered as we were rolling forward was initially trying to do everything at once instead of sitting down and selecting what are the tools that we really need to just get started.
So what I mean by that is very early on, particularly, I think it was February to March, right around Opus 4.6 coming out where sweet tasks were being completed pretty high quality. We wanted to transform the entire company at once. So we were looking at all everything from, what can we replace, Giro with, it's AI native, what are all the productivity tools, the IDs, what are all the things we can just swap to the younger companies that are more AI native. And the reality what we saw was a lot of the traditional tools, I met from Giro, Slack is another one. I think Slack ironically now is a traditional tool, but 10 years ago it was not, but it is a core part of most businesses at the moment. When you just roll back to first principles, you can architect them in your own way to make them AI native. Like Gira, even before I think it's Robo that came out, you could build projects that
actually integrated really easily with APIs and service accounts that AI agents could use with MCPs. You might have to develop those MCPs on your own, but you can do that. And we wasted a lot of time evaluating software because we didn't quite realize that we can rebuild through applications engineering and building around the third party software. We can rebuild a lot of what actually makes their competitors AI native. And we'll stop with that. And once we made that realization, we saved a lot of time. And we're able to shift it over towards more of the gateway services and focusing on, okay, we're starting with cloud, we're not going to go with all these other areas, all these other tools, we're going to just start here and secure this and build our, really our policy and strategy around securing desktop and CLI AI tools. And then copy and paste that to all the other vendors as we get more comfortable with it. It's interesting because we just went through an evaluation to replace Gira.
We ended up going linear because of the MCP capabilities because now my development team can orchestrate the release builds and everything else through the agents, which is why we did it. It's interesting. You're like, I guess in theory, we could have built it on Gira if we wanted to, if we wanted to extend it, but we shifted. So I think your point is, you don't necessarily have to shift. Don't waste the time on some of those tools shifts because you're wasting some time and slowing yourself down. My last question, I'll let Jason ask anymore. You said you stuck with cloud. How important is it for the infrastructure to support other models longer term? I see it a lot is these models are going to continue to shift and morph and change. And one model is going to get better than the other. How have you accounted for the ability to kind of refactor the models in order to gain the best capabilities out of whoever kind of continues to advance the best?
Yeah, that's a great question. So I'll clarify, technically we started with AWS bedrock hosted models and then we allowed our engineers who were more fluent with CLI to use those models through CLI. And then as we were looking at the adoption through the enterprise, we then selected a single desktop app. Now, you know, Google works face customers were Gemini enterprise customers. We have codex usage, but I think, answer your question directly. It's extremely important for you to have diversification. You absolutely cannot just be on one platform. I believe there is a vendor lock in problem when that happens and there is certainly a horse race, you know, every couple of weeks there's, you know, another major release. And some of them are such a significant improvement that you do want to be able to adopt them.
I think also when you're a mid size enterprise and you're hiring AI native engineers and employees, they become very used to certain harnesses and are more productive on those harnesses and with those models, even if there is a slight gain in function in a new release, they we see people still regularly using, you know, the prior version of Opus just because they're comfortable with how to prompt engineer. It's almost like how to say it's like when like Python started coming out, you know, you started to see a lot of software engineers slowly moving over to Python, but it was hard. So you would, you would see them sticking with older, older languages. But I see something similar where that function gain is getting less and less important than a person's familiarity with working with the model. So so Evan, my last question is more of a big think on the horizon question because we talk about it a lot on the show and you know, as as security leaders absorb more pressure,
more responsibility, we're starting to see a thinning of the herd. Folks who are leaving the profession, stopping being a CISO, going from being an internal CISO to maybe a fractional or VISO, right? What do you see the future of the security leader role? Is it transitioning to more of a chief trust officer, chief risk officer? Where do you see the future in the next few years knowing how deep on the bleeding edge you are right now? What do you see the future of the role? I believe the future of the role is you will see a lot of chief technology and security officers, chief information officers, dual hiding with chief security officer roles. I think that's becoming a farmer prevalent even today. But I believe every security officer is going to have to be a some combination of a security engineer, an IT engineer, an applications engineer, and a software engineer, infrastructure engineer.
And I don't think you have to be able to do hands on keyboard for all of those, but you need to be fluent and able to think in those roles. And I think that's part of the reason we see the that the need of the herd right now where it is just an incredible amount of learning that is required on the daily. The the risk acceptance I think is immense and responsibility is immense, but individuals that learn how to work with their risk officers, work with their legal team, work with their CFOs, and carry those paths. I believe can have much more impact and actually lead a more secure organization that way. Amazing. Thank you. Evan, thank you so much for joining us on Business Security Weekly. Thanks for having me.
All right, before we get into this week's articles, one quick announcement, InfoSec World brings cybersecurity professionals together across industries from healthcare and financial services to government in the Fortune 500. Join the community in Orlando, Florida, October 12th to 14th for practical education, new perspectives, and cybersecurity research unveiled live. Listener, save 30% on their paths with code ISW26-sw savings by visiting securityweekly.com forward slash InfoSec World 2026. All right, Jason, we're going to get into some of the fun articles. A couple of these tie back to the previous segment, which was awesome. Awesome. Because AI is all over the news still. I don't think it's going to wait. Yeah, who would have thought? All right, so first article, security spending is growing, except for the typical CISO.
Yeah, so it was interesting to see that security budgets grew by 5%, but the median budget growth was flat. Which, I mean, what does that tell us? That tells us that the AI hype is probably in full swing at this point, and there's some level of investment on the security side when it comes to AI. But it's looking like we're having a little bit of, I don't know, what we call that, mixed-mixed budget or mixed-mixed innovation budgets maybe, because the investment is probably coming out of IT budgets or elsewhere. And maybe our security teams are reaping some of the benefit of it. But here's my fear. My fear is that we're treating cybersecurity now as back to the old days of operational overhead. There was a hot minute where I had some hope that we would be strategic investment, but that seems to be dwindling. Yeah. Evan said this a little bit in the last segment.
Right, he talked about how the CISO has to be aligned to the CFO and that relationship. He owns commercial engineering, so a lot of stuff comes through him for involvement. If you're in that position as a CISO, this probably doesn't impact you. I mean, he said it, right, in the previous segment. If software comes in, he's attaching headcount to be able to manage and take care of that software. Right. So he's accounting for at the entry gate. So if CISOs are in that position, then they have control over these budgets as new stuff comes in. But if you're not, then guess what? You're not in that position. This is the key though, right? I mean, it's all about the makeup of the business. And Evan is lucky enough that he's aligned to a revenue generating product. Right? Where he's helping evolve the product and security is essential for the existence of that product. Not every CISO is that tied into product revenue, right? But the question becomes,
how do you start on lining to the business value of your organization, whether it's revenue generation, whether it's services, whatever your organization produces as that product, start embedding yourself in there, learn the business, figure out how you're making the revenue of your organization reliable, safe, trustworthy, right? Start having those type of conversations with the leaders around your organization. So you can figure out where security fits into growing the business. Because that's where Evan has that spot. Yeah. He can make those influential decisions because he's tightly tied to revenue generating activities. Yeah. At the end of this article, it gives you quick tips. As for CISO's trend, keep pace. The reports advice is to give AI its own budget line. I would actually say it probably has multiple budget lines. Sure. Line back to the business and back to the revenue. So you can track the costs and the
improvements and everything else you've done. You don't want it necessarily all bundled together, because if you're not aligned to revenue generation, then that's going to get diluted too. You almost have to break this out by AI business enablement components. I absolutely agree wholeheartedly. That's what that dilution comment I had up front with. It's all getting diluted in the IT budget. That's the key. You need to be able to pull out where security is bringing value to the table. You also need to be able to pull out from a budget, like Evan said, opportunities of consolidation and operational efficiencies. If you don't own that budget and you don't own that spend, how are you going to be seen as that fiduciary, where you're making good decisions in consolidation? So I wholeheartedly agree. They should be separated out by your business units. Yeah, for sure. The second article is basically the entire previous interview segment. CISO's race to control AI agents without destroying their value. Evan just walked us through Robinhood's 18 month kind of lessons learned on this because he's right.
In a lot of what he really brought out in the last segment that ties to this article is the pain point. How do you adjust for that? He's lucky enough to have an engineering team that can build some stuff. Other organizations may not be able to do that. That's right. That's right. When I saw this article, I'm like, this is the interview segment. Yeah, it totally is a great alignment to the interview, but it's the struggle bus that CISOs are going through right now. The balance of the operational benefits that it's going to bring to your organization along with God. Pay attention to the news, right? The unprecedented cyber risk that we're seeing. I mean, think about some of the things that are happening out there in the world today when it comes to these agents that go rogue and still untested legal waters of where that liability falls. Right. Remember, it's a scary place to be. Exactly, but remember what he said. The human is responsible for the agent. That's right. He's got services that the agent can use.
And then he's got judges that are testing intent and agency, right? That's a multi-tiered AI architecture. It is. And it's an amazing architecture. It's one that I know you took notes on and believe me, I did as well. And I think it's just an amazing view to make sure that there's still that human accountability in the mix. There's human accountability. Then there's judges monitoring and voting on access to some of the stuff to prevent hopefully some of these breakout attacks that we've seen in the news, right? He's trying to build an architecture. We've been talking about the last few shows. Handful of shows is how do you put guardrails around intent and agency? Because the traditional guardrails and controls that we have in the security world don't work in these situations. Yeah. Yeah. Yeah. You want more on this article? See previous interview segment. That's right. That's right. All right. So I pulled this article last week, but I reserved it for this week because I knew the conversation we were having with Evan. Your next CISO could be
artificial intelligence. Please know. That's all I can say. I mean, you know, yes, we talked about the role of the CISO evolving and we talked about the role of the CISO maybe being combined between a CIO CISO, a CTO CISO, whatever the case may be, but it's evolving, I think in a good way, more responsibility, more aligned to the business. That's great. But when you're going to stick an AI agent into your organization and act as that cybersecurity professional, governance risk and compliance professional, title legal, title finance, a board report out, right? How do you do that with an agent? It's it's I'm sorry. I think we're grasping here. Can AI be a good source of research for a professional? Sure. Do I think it replaces a professional? Absolutely. No. It just goes back to my fiduciary conversation.
Agents, the AI doesn't know, not per se, right? So there's there's zero. Whether you should or shouldn't act because he doesn't have that context, there's zero contextual judgment. There's zero relationships with the other leaders in the organization. There's zero relationships with the board. How do you make an AI agent in your CISO? It's it's it's I don't know an exercise and pure disaster for any organization who does this. Yeah. I agree. I agree. But yeah, I pulled it and I saved it just for this week. Yeah. And hey, by the way, I want to talk about the best target in the world for adversarial threats. Go attack that virtual CISO. That's an AI agent. Let's go. Yeah, exactly. Exactly. All right. This next article, what leaders need to know about AI and psychological safety. It talks about the patterns to look out for. So this was an interesting article for me
when you think about culture, company culture, AI, how people are using these things. And so it goes through some examples, but the it really boils down to looking at these four patterns to look for. And each pattern kind of tells you a little bit about the culture and the accountability in the culture, which was really interesting to do through these. Yeah. I love the fact that this article is part of this week's conversation because I think it's a conversation that's being neglected. You know, AI conversations are all about productivity and economies of scale and innovation and moving the business forward. What we're not talking about is the impacts of the employees, right? We're not talking about oh my lord. You know, is this as this AI agent that
I'm putting all of my information into right now, tracking what I do every day so they can eventually replace me. That's a cultural stress right there. Or oh my, I have this great agent that I use or great LLM that I use every day and makes me more productive. It allows me to bring more value to the business. My boss is happier than they've ever been with me. Are they going to think of this as shadow AI and take it away? That's the other side of the conversation, right? Because it is actually a productivity tool. It is actually helping people, you know, be more productive. So there's all of these different angles when it comes to the psyche of the employee, right? That we're not thinking about and we're not having conversations about and we need to talk about this more. Yeah. Because there's a lot of blind spots when it comes to the human. Yeah, there are. It also gets into the different how AI actually either an equalizer or it's in a neighbor or it's even a mere.
Of course multiplier. Yeah. What's multiplier, right? Yeah. Yeah. Yeah. I mean, or you're sitting back and we've talked about it on the show before. You're calling the AI agent by a name and a personality as if it has a persona and it's a person. How do you address the psychological effects of that where you're forcing your employees to have conversations with an agent and treat it like it's human? Yeah. I don't know. This warrants a whole lot of conversation. It really, really does. Yeah. And this is just some of that early research that they're starting to move down this path, which is why again, this was a really interesting article for leaders to start to understand this and understand these patterns and what those patterns mean for the organization. Because as leaders, we have to identify some of this. The examples they give of somebody, you know, identifying something but it's anonymous and nobody takes responsibility for doing it because they don't feel safe. Like that in itself is a clue, folks. You got a culture problem. I would, I'd like to put something out
there and say maybe we find one article every week that has to do with the psychology of AI because I really want to start paying attention to how this evolves. I don't know if you saw the the announcement that Microsoft put out. But Microsoft came out with an announcement that basically said at a highest level, it's rejecting the pursuit of conscious AGI because they don't believe in giving persona to an agent. They don't believe in giving that type of, I don't know, I treating it like a person, humanizing it. I guess I could say humanizing a technology built agent. And there's conversation around the around the industry right now of what happens when conscious AGI becomes a thing. Do they have rights? Right. Do they have rights? Like this is a conversation, literal conversation that's happening out there in the industry. Do you give rights
to a Silicon persona, Silicon based persona? We need to be talking about this. Yeah. Yeah. Well, you saw a bunch of the news drop was it last weekend around some of the safety concerns of agents and you know, there's a lot of buzz about that too. Essentially, at that level, it's all of us. Are we going down the SkyNet path? That's right. Exactly it. I know. So what happens when we finally get to the point where we've innovated so far that there truly is conscious AGI? Right. What then? Yeah, then what? Yeah. Yeah. The leadership test, you don't know you're taking interesting, interesting article from a perspective of you don't know the next test that you're taking. Right? Like you're right. You know, as I sit back and I look at my career, right? And Evan, this kind of walk
in through some of his earlier on the interview, you get into different roles, not knowing kind of what questions people ask or where you go next. And is that experience across these different domains and different areas? Because when you're going through kind of your next promotion, your next job or whatever, you never know the question that's going to be asked. So how do you from a career perspective, how do you round out your skill sets? How do you get to a point where you've got those all those things covered? Well, I guess it depends. What do you want to do? What do you want to be? Where do you want to go? What does articles trying to get to is do you know what that test looks like? Sure. You know, it's funny because I say it a lot. I'm constantly in a position of trying to figure out what I want to be when I grow up. Yeah. And I've done a decent job throughout my career, right? I mean, at the end of the day, I've progressed through leadership positions. But I still always want to know what I want to be
when I grow up. I think it's that growth mindset that I have. And folks with a growth mindset, I think need to take a step back and at the end of the day sit back and say, everything's a test. Everything is proving myself to go on to my next best thing, right? It's why I've always taken the position of, I'm going to train folks who work for me how to take my job. Because I want to be on to that next best thing. Great. So it's always a test for folks who have that growth mindset, that driver mentality, who always want to excel, who always want to learn, who always want to move on to the next best thing. It's always a test. Every day is a test. Yeah. Every day is a test. Speaking about tests, this last article, it's a long one. But I think it's super critical for anybody in critical infrastructure to me. Oh my god. So this article is called the cyber gap. It's from the council on foreign relations. It's how to counter China's threat to
America's critical networks. And in this article, it lays out the four pillars required for us to protect our critical infrastructure. Anybody that's in this space, I highly recommend you read this because it does, I thought it did a really good job of laying out what's happened and where we are and what we're going to have to do to fix it or we're host. I mean, first and foremost, I've been preaching from the mountain tops around critical infrastructure for years now about the importance of shoring up our critical infrastructure across all 16 domains. Critical infrastructure isn't just the things you think about like, you know, water and power and oil and gas. It goes beyond that. It's our airlines. It's our communication systems. It's honestly, it's event centers like Gillette Stadium is considered critical infrastructure because massive amounts of people show up there all the time. And those are security, those can
have security risks from a physical security perspective. I would say not only if you're in critical infrastructure, folks who are interested in protecting this country will volunteer your time at your local water utility, your local electric utility, go help, go have conversations at city council meetings about the importance. If you have a utility, if you have critical infrastructure, that's part of your municipality or part of your state. It's time for all of us to put some skin in the game here because they're not going to be able to do it by themselves. It's going to require public private citizen partnerships here of folks who know what they're doing and it can help shore this up. It is that important. Yeah, it is. And I haven't seen kind of an article like this, the depth of it. I know. Right. I mean, if you were to read this thing, it's almost an hour read. Yeah. Right. It's very in depth that lays out the four pillars.
And why we need to do it. It's, yeah, anybody who's struggling with this stuff is, you know, the the the the the the the the the the the the the the the the the the the the the military. So I I kind of know what you know geopolitical threat can do and what their intents are. Modern day warfare has nothing to do with boots on the ground anymore. You want to you want to soften the earth for a population, take away their electricity, take away their water, take away their food, take away all their essentials, mass chaos, that then an attack happens. Yep. That's the way modern day warfare is going to soften the area. Yeah. And the tools to take down those are through these connected systems. That's right. That's right. Yeah. Little scary, but this was a great article. That's why I had to include it. And I wanted to save it for last today. Yeah, absolutely. If anything, it's a call to action on the folks listening here. Go volunteer time will help. Exactly. Jason, always a pleasure. Thank you for joining me today.
Thank you everyone for watching and listening. We'll see you next week on Business Security Week. We'll see you next week on Business Security Week. Zero trust is clearly the future as threats get faster, quieter and harder to detect, but implementing it shouldn't disrupt the business. Threat locker enforces default deny at execution in a way that remains enterprise ready, scalable and operationally clean. Unknown software is stopped cold. Trusted apps stay contained and drift is locked down across the environment. It's zero trust that works in real enterprises and prepares you for the threats ahead. CYC's are adopting it at securityweekly.com forward slash threat locker. Thank you for watching. If you enjoyed this content and would like to find more, see what the rest of the security weekly network has to offer. Visit securityweekly.com forward slash subscribe to find all of our shows and the latest episodes. Hope to see you on a future episode.
More episodes
More from Security Weekly Podcast Network (Audio)
State of the AI SOC, regulating AI, and can AI agents feel pain? - Aqsa Taylor -...
Security Weekly Podcast Network (Audio)
RAM, Muse, CloudSyncD, Springsteen, Software, Persistence, and Michael Jenkins -...
Security Weekly Podcast Network (Audio)
Hacking Without Boundaries - Michael Jenkins - PSW #946
Security Weekly Podcast Network (Audio)
Defending at AI Speed as Quantum Threats and AI Policies Won't Save You - Nolan...
Security Weekly Podcast Network (Audio)