#1749527: Why Solve Your Problems When We Can Just Scare You?

Description: For years the security tool market has sold fear over fixes, handing CISOs growing lists of findings with no real way to act on them. So what happens now that buyers are starting to ask for remediation instead of another warning?

This week's episode is hosted by me, David Spark, producer of CISO Series and Mike Johnson, CISO, Rivian. Joining us is Nada N.oaman, SVP and CISO, The Estée Lauder Companies Inc.. Thanks to our podcast sponsor, Native.

Skipping the apprenticeship
AI now produces work that looks senior without any of the judgment that actually comes from experience. Conor Grennan, former chief AI architect at NYU Stern School of Business, argues companies are automating the output of expertise while quietly dismantling the apprenticeship model that builds it in the first place. Junior roles are disappearing fast, and with them the reps people need to develop real judgment, especially in security. Training staff to use AI tools without training them to challenge AI output is just building a faster path to confident mistakes. The apprenticeship model isn't easy to rebuild once it's been optimized away.

Privileged users nobody manages like one
AI agents hold credentials, call APIs, query databases, and write to systems, which makes them privileged users in every way that matters. Jacob Combs, CISO at Tandem Diabetes Care, points out most organizations are managing that access about as rigorously as they managed privileged access back in 2012. Human accounts back then still had an owner to name and access to revoke the moment someone left. Non-human identities don't come with that same trail. When an agent does something it shouldn't, accountability doesn't stop at a person, it lands wherever the org quietly decided to point, and that's usually the CISO by default rather than by design. Assigning real ownership means naming who's accountable for identities that outlast the people who deployed them.

Findings without the authority to fix them
Security teams have spent years buying visibility tools that deliver exactly what was promised: a growing list of everything that's wrong. Ross Haleliuk of Venture in Security argues that fear-based selling stopped moving the needle a long time ago, and that those tools never came with the authority to actually fix what they found. CISOs are now on record as having known about the gaps before the breach happened. As the market shifts from selling findings to selling remediation, the real risk is buying a new category that just repackages the old problem. If the authority to fix things still sits with other teams, the tool you buy barely matters.

Security was always behavioral
A recent thread on the cybersecurity subreddit asked whether security is becoming more behavioral than technical. The top answer was blunt: it always has been. Which makes it odd that most security budgets still read like a catalog of technical controls. A program stacked with awareness training and thin detection fails just as badly as one built the opposite way, one commenter pointed out. The blast radius of a human mistake is a technical problem. The mistake itself isn't. CISOs own both sides of that equation, whether the budget reflects it or not.

Listen to the full episode on our blog or your favorite podcast app, where you can read the entire transcript. If you haven't subscribed to the CISO Series Podcast via your favorite podcast app, please do so now. Listen to the full episode here.
More info: https://www.linkedin.com/pulse/why-solve-your-problems-when-we-can-just-scare-you-cisoseries-c0e7c/

Date added Aug. 12, 2026, 10:34 p.m.
Source Linkedin
Subjects
  • AI/ML - Artificial Intelligence / Machine Learning / GenAI / Artificial General Intelligence - AGI - Various
  • PodCasts / Webcast / Webinar / eSummit / Virtual Event etc.
  • Security Management/Strategic Security/ROI/ROSI - CISO and Higher Level