- CISO Series Newsletter
- Posts
- Join us tomorrow for "Hacking AI in the Loop"
Join us tomorrow for "Hacking AI in the Loop"
Join us TOMORROW, Friday [08-14-26], for "Hacking AI in the Loop"
Join us Friday, August 14th, 2026, for “Hacking AI in the Loop: An hour of critical thinking about who's actually driving when the process meets the model.”
It all begins at 1 PM ET/10 AM PT tomorrow, with guests Bil Harmer, CISO, Supabase, and Brett Conlon, CISO, American Century Investments. We'll have fun conversation and games, plus at the end of the hour we'll do our meetup in breakout rooms.
Or register once for every upcoming Super Cyber Friday event. No need to sign up week to week.
Defense in Depth
What Makes a Good AI Security Deployment?
AI security vendors are in abundance, selling their solutions. But the irony is that not even the vendors themselves can point to a mature AI security implementation. Where is the AI reference architecture everyone else is supposed to copy?
Check out this post by Chris Matthews of UpGuard for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark, the producer of CISO Series, and Edward Contreras, senior evp and CISO, Frost Bank. Joining us is Peter Liebert, CISO, Salesloft & Clari.
Listen to the full episode here.
Non-determinism changes everything
The controls that work across the rest of the security stack assume the system behaves predictably. "Cloud, AppSec, identity, endpoint, those are deterministic systems," said Krunal Sabnis of neurelay.ai. "You can write a control, test it, and it behaves the same way tomorrow. AI pipelines don't. The same model, same prompt, same guardrail can produce different outputs every run." That's precisely why vendor self-assessment matters, he said. It would be "the first honest acknowledgment that securing AI isn't a product you buy, it's an operational discipline you build." Harshil Shah of Deloitte sees a measurement gap. "The issue isn't intent, it's demonstrable control effectiveness," he said. Consistent ways to measure controls in production still don't exist. Red teaming and governance alignment are investments being made, he acknowledged, but "until those controls are tested continuously and outcomes are measurable (detection rates, containment speed, false positives), the market will struggle to separate capability from positioning."
The foundation problem
The conversation within most organizations hasn't kept pace with the technology. "The biggest gap is literacy within the business to even have a meaningful discussion about gaps," said Dave D. of Kmart Australia. Conversations lean toward "what's the next flashy thing we can deploy" rather than "how can we build a solid foundation to ensure long-term sustainability," he said. "Sadly, the Agile 'fail fast' mentality does not apply when it comes to AI." Steve Biswanger of Biswanger Consulting pointed to a framing problem feeding the confusion. "Is the problem calling it 'AI' as though it is a single thing, expecting a single solution?" Traditional security solutions still apply to AI environments, he said, but they're insufficient to cover the full scope. "We are still at the stage where a bunch of startups are innovating niche solutions," he added. "Eventually best practice approaches will emerge, and the traditional security vendors will acquire and assimilate."
Nobody owns the whole problem
AI security can't be treated as a single team's responsibility because AI doesn't operate within a single team's domain. "AI security can't be done well in isolation because AI doesn't operate in isolation," said Steve Strout of Digital Risk Alliance. "It sits at the intersection of data governance, privacy, model integrity, third-party risk, and operational resilience." Everyone is discovering their new responsibilities in real time. "The security team can't secure what the data team hasn't classified, what the privacy team hasn't mapped, and what ML engineers built without requirements because nobody defined any." Andrea Thu Le of Allianz Global Investors identified where that typically breaks down. "We need to figure out who owns AI security before anything operational gets built," she said. The organizations that close this gap fastest, she said, "aren't necessarily the ones with the biggest budgets — they're the ones that resolved the ownership question early and moved to operational testing while others are still drafting RACI matrices."
The authorization gap
The reason no one can point to a reference implementation for AI security may be that the industry started by solving the wrong problem. "The industry conflated two different problems: AI safety and AI security," said Mark Rogge of EnforceAuth. The distinction matters, he said. "Safety asks, 'Will the model behave nicely?' Security asks, 'Who authorized this model to access that data, make that decision, or take that action?'" Every mature security category was built on authorization as its foundational layer. "AI skipped that step," he said. "We went straight to guardrails and prompt filtering and called it security."
Please listen to the full episode on your favorite podcast app, or over on our blog, where you can read the full transcript. If you’re not already subscribed to the Defense in Depth podcast, please go ahead and subscribe now.
Huge thanks to our sponsor, CoreView
Subscribe to Defense in Depth podcast
Please subscribe via Apple Podcasts, Spotify, YouTube Music, Amazon Music, Pocket Casts, RSS, or just type "Defense in Depth" into your favorite podcast app.
Cybersecurity Headlines - Department of Know
Our LIVE stream of The Department of Know happens every Friday at 4 PM ET / 1 PM PT with CISO Series reporter and guest host, Sarah Lane, and a panel of security pros. Each week, we bring you the cybersecurity stories that actually matter, and the conversations you’ve been having at work all week long.
Friday’s episode will feature Peter Gregory, author of over 50 books on cybersecurity and Michael Bickford, former CISO, New York State Gaming Commission, Unisys Security Consulting. Join us on YouTube and catch up on what shaped the week in security.
Thanks to our Cybersecurity Headlines sponsor, ThreatLocker
Help us get the word out! Share next week’s Super Cyber Friday registration link on LinkedIn, tag me (David Spark) and CISO Series, and you'll be entered for a chance to win an item from our prize store. We'll randomly pick one winner from everyone who shares.
Participate! Add our live shows to your calendar
Learn more about all of the fun ways you can participate, and add our events to your calendar.
Google Calendar, iCalendar, Outlook, or export an .ics file
Cyber chatter from around the web...
Jump in on these conversations
"Microsoft denies Windows 11 is spying on desktop PCs, reveals what the service actually does" (More here)
"Which Certifications are ACTUALLY worth it?" (More here)
"Cyber insurance renewal demands are getting absurd. Are you actually hitting every requirement or dropping coverage?" (More here)
Coming up on Super Cyber Friday:
[08-14-2026] - “Hacking AI in the Loop"
[08-21-2026] - “Hacking Productivity with AI"
Register for and add all of these events to your calendar on our Events Page.
Cybersecurity Headlines - Daily News Shorts
Subscribe to the CISO Series YouTube channel, for daily shorts videos from CISO Series reporter, Rich Stroffolino. You can find all of the stories he’s covered, plus new content every weekday, at the Cybersecurity Headlines Shorts YouTube playlist.
Thank you for supporting CISO Series and all our programming
We don’t just say we appreciate your feedback; we incorporate it into our programming. Learn more about all of the fun ways you can participate.
We love all kinds of support: listening, watching, contributions, What's Worse?! scenarios, telling your friends, sharing on social media, and most of all we love our sponsors!
Everything is available at cisoseries.com.
Interested in sponsorship, contact me, David Spark.





