Dallas 360 News Digital News & Media Platform

collapse
Home / Daily News Analysis / The CISO selling confidence in a market full of breach headlines

The CISO selling confidence in a market full of breach headlines

Jul 19, 2026  Twila Rosenbaum 24 views

Engineering teams across enterprise IT are writing their own software with AI coding assistants, spinning up agents that act on their behalf, and assigning those agents the same access privileges their human creators hold. The shift has pulled the role of the chief information security officer into territory that did not exist two years ago. Speaking at the Span Cyber Security Arena conference, Hrvoje Englman, CISO at Span, said it is changing what defenders worry about most.

Span’s workforce includes a sizable population of developers alongside a larger group of engineers. The engineers are the new variable. With AI-assisted coding, they are building applications and personal agents to automate parts of their own jobs. Each new agent inherits the identity of its creator, and those identities are typically over-provisioned. Least privilege remains an aspiration that is hard to enforce in production environments. “I cannot be the blocker,” Englman said. “You cannot block progress. People will find ways around it.” His priority is enabling secure use of AI inside the company rather than prohibiting it.

The bus-factor problem multiplies

The risk extends beyond access control. When a single engineer automates a business process using five interacting agents and then leaves for another job, the organization inherits an undocumented system that nobody understands. Englman called this an inversion of the traditional bus-factor problem. Previously, a key person leaving created a knowledge gap. Now the agents they built keep running, and the company has no record of what they do or why. This is a critical issue for CISOs who must manage shadow IT and ensure that even automated systems can be audited and decommissioned properly. The bus-factor problem is not new—it has been a staple of risk management for decades. But in the age of agentic AI, the bus factor becomes a fleet of autonomous buses driving through the corporate network with no drivers at the wheel. The lack of documentation means that when an agent malfunctions or is exploited, the security team has no baseline to compare against, making incident response far more complex.

Defender’s leverage is real, with limits

AI has produced concrete gains in defensive work. Englman pointed to log analysis as one area where the value is immediate. Feeding hundreds of megabytes of log files into an AI tool and asking it to surface anomalies or pivot on an IP address compresses work that previously took analysts hours. Policy drafting is another use case. Generating a first draft from internal context can cut a three-day task to a single day, and the time savings compound across a workforce. These gains are real, but they come with caveats. The tools are only as good as the data they are trained on and the models they use. Englman drew a sharper line on the vendor pitch for autonomous AI-driven security operations centers (SOCs). The idea of defensive AI battling offensive AI in real-time, with no humans in the loop, does not match what is achievable now. Log ingestion remains the hardest part of running a SOC, and detection engineering still depends on people who can explain why an alert fired. “You get an alert, but your analyst doesn’t understand the alert,” Englman said, describing the failure mode he sees in teams that lean too heavily on automated tooling. “And you have two million alerts, and then what?” Autonomous isolation of systems remains out of reach because the AI does not understand the business process. Decisions about when to shut down a critical service get escalated to senior leadership during real incidents, and that judgment stays with humans. He also pushed back on the industry framing of breaches. Most of the largest incidents trace back to phishing and credential theft. Vendors selling AI-powered SOCs as a defense against nation-state actors are addressing a smaller part of the problem than their marketing suggests. The real battleground is still the inbox and the password. If CISOs can reduce the risk from phishing and credential theft, they will have a bigger impact than deploying the most advanced AI-driven response platform.

The threat model for a services provider

Span sells IT services to enterprise clients, which doubles its exposure. The company is a target in its own right and a target for attackers seeking access to its customers. A typical end-user organization can absorb a breach and recover. For Span, the response itself becomes the product on display. Englman said the company has to be able to demonstrate that controls were in place, that the failure was contained, and that the incident was handled with the same discipline it offers customers. Reputation is what gets sold, and negligence would end the business. That means the security team cannot afford to be seen as incompetent or unprepared. Every incident is a test of the brand promise. In addition to the direct threat, a services provider like Span must also manage third-party risk. Its customers trust Span to protect their data, and that trust can be shattered in an instant by a breach that could have been prevented. The CISOs role in a services organization is not just technical; it is also deeply commercial. They must be able to communicate with clients, regulators, and the board in a language that resonates. That is why Englman emphasizes confidence. Confidence is not arrogance; it is the ability to demonstrate that the organization has done its homework and built a resilient security posture. In a market full of breach headlines, customers are looking for partners who can give them that confidence. And that confidence must be built on a foundation of sound practices, not just marketing hype.

Skills shortage, restated

The widely discussed cybersecurity talent gap, in Englman’s view, is misframed. Entry-level applicants are abundant. Senior practitioners with five or more years of operational depth are scarce, and that gap cannot be closed quickly through training programs. The Span Cyber Security Center has trained more than 3,000 people, and Englman said the pipeline matters precisely because the industry’s push toward automated tooling threatens to eliminate the junior roles where future experts get built. If organizations rely too heavily on automation, they will starve the pipeline of the practical experience needed to develop senior talent. Entry-level analysts learn by triaging low-level alerts, writing reports, and shadowing senior staff. If those tasks are automated away, new hires never develop the intuition and judgment required for complex incidents. The result is a workforce of button-pushers who cannot think outside the script. His measure for a SOC analyst centers on whether they can explain what the alert means and how the conditions that triggered it came about. Without that understanding, an analyst rolling a fifty-fifty guess on relevance is no better than a model doing the same. The human element remains irreplaceable, at least for now. The industry needs to invest in building senior talent, not just hiring it. That means creating mentorship programs, offering challenging assignments, and resisting the temptation to automate everything for short-term efficiency gains.

The wisdom he has discarded

Asked which piece of conventional security wisdom he has stopped believing, Englman named the framing of humans as the weakest link in the chain. He called it lazy and a form of blame culture. The responsibility, he said, sits with the CISO to build systems where a user clicking a malicious link does not bring the environment down. Brittle defenses that depend on perfect human behavior are a design failure. This perspective is gaining traction among forward-thinking security leaders. Instead of blaming users, they invest in layered defenses, such as email security gateways, multi-factor authentication, and micro-segmentation. They also focus on user education, not as a replacement for technical controls, but as a complement. The goal is to reduce the blast radius of any single mistake, not to eliminate mistakes entirely. Perversely, the blame culture often leads to users hiding mistakes out of fear, which prevents the security team from learning about and responding to incidents in a timely manner. Englmans view is that the CISO should create an environment where security is a shared responsibility, but the ultimate accountability for system design falls on the leadership.


Source:Help Net Security News


Share:

Leave a comment

Your email address will not be published. Required fields are marked *

Your experience on this site will be improved by allowing cookies Cookie Policy