At Black Hat 2026 day two, Krista Case of theCUBE Research, principal analyst and practice lead for cyber resilience and security, and Jon Oltsik of theCUBE Research, principal analyst in residence, host a kickoff discussion on the evolving chief information security officer role, hereafter CISO, the impact of artificial intelligence, hereafter AI, and enterprise cyber resilience.
Oltsik examines how CISOs must transition from siloed controls to integrated agentic solutions that enable continuous risk monitoring and control. They highlight the need for analytics-driven risk signals vendor-CISO alignment and security automation to operationalize AI while preserving measurable resilience.
Case emphasizes that CISOs require broader purviews and closer collaboration with legal engineering and business leaders to define AI governance resilience metrics and operational guardrails that support responsible AI adoption without impeding business objectives. They advocate integrating identity data and resilience disciplines to create unified security programs that are strategic cross-functional and outcomes oriented.
Topics include AI governance identity security data protection vendor risk management threat modeling incident response and strategies for building cyber resilience across the enterprise. The discussion provides practical guidance for CISOs security leaders vendors and risk managers seeking to align security programs with business priorities while adopting AI responsibly.
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
Black Hat USA 2026. If you don’t think you received an email check your
spam folder.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open the link to automatically sign into the site.
Register for Black Hat USA 2026
Please fill out the information below. You will receive an email with a verification link confirming your registration. Click the link to automatically sign into the site.
You’re almost there!
We just sent you a verification email. Please click the verification button in the email. Once your email address is verified, you will have full access to all event content for Black Hat USA 2026.
I want my badge and interests to be visible to all attendees.
Checking this box will display your presense on the attendees list, view your profile and allow other attendees to contact you via 1-1 chat. Read the Privacy Policy. At any time, you can choose to disable this preference.
Select your Interests!
add
Upload your photo
Uploading..
OR
Connect via Twitter
Connect via Linkedin
EDIT PASSWORD
Share
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
Black Hat USA 2026. If you don’t think you received an email check your
spam folder.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open the link to automatically sign into the site.
Sign in to gain access to Black Hat USA 2026
Please sign in with LinkedIn to continue to Black Hat USA 2026. Signing in with LinkedIn ensures a professional environment.
Are you sure you want to remove access rights for this user?
Details
Manage Access
email address
Community Invitation
Keynote Analysis
At Black Hat 2026 day two, Krista Case of theCUBE Research, principal analyst and practice lead for cyber resilience and security, and Jon Oltsik of theCUBE Research, principal analyst in residence, host a kickoff discussion on the evolving chief information security officer role, hereafter CISO, the impact of artificial intelligence, hereafter AI, and enterprise cyber resilience.
Oltsik examines how CISOs must transition from siloed controls to integrated agentic solutions that enable continuous risk monitoring and control. They highlight the need for analytics-driven risk signals vendor-CISO alignment and security automation to operationalize AI while preserving measurable resilience.
Case emphasizes that CISOs require broader purviews and closer collaboration with legal engineering and business leaders to define AI governance resilience metrics and operational guardrails that support responsible AI adoption without impeding business objectives. They advocate integrating identity data and resilience disciplines to create unified security programs that are strategic cross-functional and outcomes oriented.
Topics include AI governance identity security data protection vendor risk management threat modeling incident response and strategies for building cyber resilience across the enterprise. The discussion provides practical guidance for CISOs security leaders vendors and risk managers seeking to align security programs with business priorities while adopting AI responsibly.
Principal Analyst and Practice Lead for Cyber Resilience and SecuritytheCUBE Research
Jon Oltsik
Principal Analyst in ResidencetheCUBE Research
search
(INTRO)
Krista Case
>> Hey, welcome back to theCUBE. This is our kickoff for our day two coverage, live here at Black Hat 2026. We're here at the Mandalay Bay in Las Vegas all day. I'm Krista Case. I'm joined here with Jon Oltsik, my co-host and my analyst in residence here at theCUBE Research. Jon, how you feeling this morning? How you doing?
Jon Oltsik
>> I'm doing great, ready for another day.
Krista Case
>> I know. I know, I know. The energy's still up this morning. And Jon, I know we've talked a lot over the last couple days here at the show, naturally about kind of the impact of AI on the cybersecurity industry. And what I thought we could do this morning is kind of laser in on the impact to the role of the CISO. Because we've got a couple of great CISO guests coming on theCUBE today. We've had a number of conversations with them over the last couple days, and really here at Black Hat. It's a very practitioner-driven show, as you know. So we've got a lot of practitioners trying to navigate this FUD around the impact of adversarial AI and kind of trying to navigate the new tools that vendors are promoting here at the show that use AI to sort of try to fight fire with fire. So I wanted to even go a little bit beyond the technology this morning, Jon, and talk to the role of the CISO and how they're really managing cyber risk but they're also helping the business to make decisions around what are some of the right practices and technologies for governance, resilience, and these operational guardrails. We've had a lot of conversations around AI moving into production and what sort of guardrails do we need in place? I tend to think about it as this requires a CISO to have a broader purview, not only across traditional security stack, but also looking at identities and data and resilience and governance and all of these areas becoming interconnected. And I've also been thinking about this AI governance through the lens of the different roles that the CISO has to collaborate with within the enterprise. So things like legal, compliance, engineering, IT, they almost have to be sort of the connective tissue helping to facilitate these conversations. So they're really becoming a business enabler. And I guess I wanted to get your take on this, Jon. where do you see security leaders being asked to help the business to adopt AI responsibly. Are you seeing this shift and are you getting any feedback from CISOs on how they're navigating this?
Jon Oltsik
>> Yes and yes. So the CISO role has been in transition for a long time and it's been easily 10 years that we've been saying, oh, security needs to get closer to the business. There's never been a time where that was more of a requirement. And the business needs to get closer to security. And so if we're going to have these AI-based initiatives, we better get security involved at the beginning. And that hasn't always been the case. So all of the constituents that you mentioned need to be participants. Because as a CISO, if I'm going to look and create the appropriate threat model. I need to understand all of the ramifications of an initiative. And so that's where we're at. Now, are we there? No. But I'd say just as we're looking at the show as AI is transformational to technology, AI has to be transformational to the organization as well.
Krista Case
>> Absolutely, Jon. And so are you, as you walk the show floor and have some conversations, are you starting to see that, maybe some of these conversations are starting to happen and There's a recognition on the business side that some of these conversations really need to be driven top down, which I think is kind of what you're alluding to.
Jon Oltsik
>> Not really. And I made this observation at RSA, and I think it's still true. About 20 % of CISOs get it. They understand the implications. They understand what their organization's trying to do with AI. They may not know exactly what individual users are doing with AI, but they understand they need to get a handle on it. And they're looking at security architecturally, so what's the strategic direction that security has to go. But I think that's only about 20 % of the market. So the other 80 % are in a state of ignorance, sometimes ignorance is bliss, or at least assumed bliss.
Krista Case
>> We can't stress about what we don't know about.
Jon Oltsik
>> That's right.So even though we're talking about AI a lot, it's a tactical show. It's AI for this, AI for identity, AI for the SOC, AI for exposure management. But the strategic discussions of how that translates into a CISO program are pretty minimal. And the truth is, and I've said this for years too, but of all the vendors here, I'd say one in 10 knows what the CISO does. And of those companies, maybe another one in 10 can actually talk to the CISO at their level. And even within those companies, they have a few people who can have that conversation. So there's a real disconnect.
Krista Case
>> Yeah, I agree. And so if you were a CISO and you're trying to figure out, you're being inundated with all these requests to meet with vendors, what would you look for in terms of a vendor that actually understands these challenges that the CISO is navigating and that they understand how to talk to them in their terms?
Jon Oltsik
>> Well, I wouldn't open the door to any vendor right now, meaning I would recruit the vendors based on my requirements, based on my assessment of what I need and what the business is doing. So it's a difficult time for some of the vendor salespeople, but the first thing they should do is understand that customer's business, understand their industry, understand where AI plays, and where AI plays with new types of technology, new types of business processes, new types of relationships. That's a lot to think about, but you have to get into that mindset before you go into the customer. And again, on the CISO side, they should be cherry picking who they talk to based on their requirements and their strategic plans.
Krista Case
>> Yeah, I agree. And I think going to those requirements and those strategic plans, Jon, I had a conversation with the CISO earlier in the week, and this individual is saying that AI is changing how the business thinks about risk. we've sort of been alluding to this, but it's opening their minds to the fact that they have to accept some level of risk. Previously, Obviously the answer is no, we want no risk. And now they're saying, okay, we want to be able to implement AI as a part of our daily processes and we understand that we're opening ourselves up to a certain level of risk as a result of that. So I guess the question to you is how do you think the CISO should go about balancing the need to reduce risk appropriately but also not get in the way of the business and sort of actually help the business to adopt AI faster, going to the conversation around operationalizing AI and establishing those guardrails.
Jon Oltsik
>> Yeah, even though there's AI and we're moving faster and we have new opportunities, the formula for the CISO hasn't changed. So this is what I was saying before, is the CISO has to be involved in the business plan, understand what the initiative is, understand who that initiative touches, what data it touches, what identity it touches, to build the right threat model. And then it's their responsibility, the CISO's responsibility, to go to the executives and the board and say, here are the risks I see. Here's how much it will cost us to mitigate or minimize those risks, because you can't eliminate the risk. Do you want to accept the risk? Do you want to mitigate the risk? Or do you want to transfer the risk? So those are your choices. you can't get in the way. And no one should try to get in the way. You'll get run over, you'll lose your job if you try to get in the way. So that's really the way it is.
Krista Case
>> Yeah, absolutely Jon. And I think in order to have the visibility and the control to be able to do this, what I'm seeing is that these disciplines like identity, data, threat intelligence, resilience, they need to almost, they need to be more integrated together and they need to operate in sync. So I guess, are you seeing that as well? And maybe how might you recommend a CISO think about that evolution in their technology stack?
Jon Oltsik
>> Well first of all, hallelujah. That's absolutely what they should do. We've managed security historically on a domain by domain or a silo basis that doesn't scale. We knew it didn't scale, but we had no choice, but now we do have a choice. So what you should do, this is where the strategy comes into play is, I have to understand that risk, but how do I monitor that risk and control that risk over time, and that's where these agentic solutions will help enormously. Now, in my view, they're immature. they're still somewhat stratified. So you have to again understand your immediate pain points, but you need a bridge to the future, you need a bridge to that strategic integration that you talk about, because we do have to understand risk across the enterprise. Risk will change, it's very dynamic, we'll have new partners, third parties, fourth parties. How do you understand that that's where I think some of these agentic solutions will help?
Krista Case
>> I agree, Jon. And I think, so you're kind of talking to maybe the external view of kind of some of these partners to work with. We've talked about kind of the role of security in the business working together. As we operationalize AI, I'm curious your thoughts on some of the other strategic partners to the CISO. Is it the CIO? Is it engineering? my thought is it probably depends on the unique business.
Jon Oltsik
>> Yes.
Krista Case
>> But are there any roles that come to mind to you as maybe being a more strategic partner to the CISO during this adoption of AI?
Jon Oltsik
>> Yeah, at a really large company, it's going to be the chief risk officer. But most companies don't have that role. So I think the biggest intersection will be with the line of business managers who are driven to drive profit, lower cost. They'll use AI much more, they'll accelerate their pace, they'll look at it strategically. So you have to be in that business. You have to really understand, well what are you doing, what are you trying to do, and then you can assess the risk. So it really goes back for a while, it was fashionable to think of a BISO, a business information security officer. I haven't heard that term in a few years, but that mindset really comes into play here.
Krista Case
>> Yeah, I definitely agree. And I think as this role evolves for the CISO, again, in some of these conversations I've been having over the last couple of days, it's come up that sort of the definitions of success and those metrics are going to evolve. Previously, it was things like, OK, we prevented this number of attacks. But as we, especially as we start to not only operationalize AI, but also really start to integrate resilience as a part of this continuum of cybersecurity, they're being measured based on things like uptime, the ability to restore the minimum viable operations for the business. what are some of the metrics that you think will be really critical in this conversation moving forward?
Jon Oltsik
>> I think you're right, I think it's the resilience factor that I know is near and dear to your heart. Early in my career I worked at companies that were very concerned with business continuity and disaster recovery. Now that was typically at the data level, but with resilience you're looking at the operational level across people, process, and technology. So they'll be measured there. They'll also be measured with managing and monitoring risk appropriately. They'll be measured by their ability to deal with emergent risks like vulnerabilities and exposures that come up and their ability to work with IT, for instance, to mitigate those risks or put in compensating controls. But I think ultimately it's the business. And that's the whole notion of the CISO to me, in my day, the CISO probably started their career as a Windows administrator or a Check Point firewall administrator or something like that. Those days are gone. So this is a business role and you'll need strong technology people supporting that person, but it's a business role.
Krista Case
>> Yeah, I completely agree. So Jon, hopefully you and I will be back here at Black Hat next year. How do you think...
Jon Oltsik
>> From your mouth to God's ears.
Krista Case
>> Right? So how do you think the day-to-day for the CISO will have evolved? again, assuming we sit down again here in 12 months, we've talked a lot of kind of high-level strategic, but I'm curious, again, kind of day-to-day.
Jon Oltsik
>> I don't think it's going to change radically in the next year, but I do think that the pace of change is incrementally increasing. So CISOs tend to be risk averse. They tend to be cynics. And I understand, we're paid to break things in security and believe things can be broken. But at the same time, I think they'll have to be much more open-minded. They'll have to really pay attention to changes with skill sets needed and staffing and just the day-to-day business activity. So I think the metrics will be there. They may, and I'm seeing this too, their programs may become much more automated and much more integrated in the way they manage them. So no more spreadsheets, much more of an agentic process too. So it could change quite a bit in terms of the way we do things, but I'd say the day-to-day important points that they have to manage are about the same, will be about the same.
Krista Case
>> Yeah, and that's a great point. And you bring up the automation, and obviously here at the show, every vendor is pushing their ability to use AI to automate different pieces of the security stack. What do you think are some of the key points that might be automated maybe even in the near term, over the next 12 months or so?
Jon Oltsik
>> Well, I think that we'll get better with discovery and monitoring of assets and automating the changes. So moving from periodic scans, periodic reviews to continuous. Things like penetration testing and red teaming. There's the opportunity to move those to a much faster pace and integrate them into some of the controls that we have. So we understand our threats, we make some changes to our controls, but are those changes really effective? Well, we can do some continuous testing. So I think those kinds of automation will be there. Now, what I'm a little less bullish on is the automation that happens between security and IT. I think that will happen over time, but we're fighting 60 years of culture. And those are separate organizations and they have their own agendas and their own objectives and things. They have to come together. But again, we're fighting culture and those are the lessons we have to learn is that changes are happening so fast that we have to be a little bit more adaptable ourselves.
Krista Case
>> More open -minded, more adaptable, and more willing for these kinds of typical silos to break down.
Jon Oltsik
>> Yes. Now, can I ask a question?
Krista Case
>> Certainly.
Jon Oltsik
>> I think next year we're going to see some nightmares, between now and next year, around AI. And so AI complacency. Yes. Let AI do all the work. Some of these solutions up here may not be developed as good as they could be, and maybe the AI goes amok, runs amok. What do you think?
Krista Case
>> I agree. we just, what, a couple weeks ago saw the Hugging Face incident, which, I think showed, obviously, the potential for that.
Jon Oltsik
>> Who named that? Hugging Face? Who named that?
Krista Case
>> It's a good question, right? But I think, we're already starting to see that.
Jon Oltsik
>> Yes.
Krista Case
>> And I think also, from the vendor side of things, if I was a practitioner, I would try to be, skeptical toward any of these new solutions, especially if they're coming out of stealth very quickly, how are they being developed? Are they being developed using some of these vibe coding techniques? So I would definitely be mindful of that. And it's something, and I know Jon, you actually had a conversation around the potential for, especially for large enterprises with established security teams to potentially create some of their own AI driven automation and tooling. So that maybe is something on the horizon. But I think both the adversarial and kind of the vendor side of things, it's going to be really interesting to see how that develops.
Jon Oltsik
>> And we'll be here to see.
Krista Case
>> That we will.That we will. Anything else top of mind for you, Jon, as we head into day two here?
Jon Oltsik
>> Anything else top of mind? No, I think your point about CISOs and the fact that you have them on today is a good sobriety test for the hoopla that's going on upstairs. We need a pragmatic approach to this, even though it is revolutionary, we understand how to make changes, albeit we'll have to do that at a faster pace. So that's, I think that's a good way to conclude the show for theCUBE and for you and I.
Krista Case
>> Great. Well, Jon, thanks so much for sitting down with me to kick off day two here. Thanks for kind of co-hosting with me. And yeah, I really look forward to continuing the conversations with you.
Jon Oltsik
>> We will do so. And thank you.
Krista Case
>> Absolutely. and thanks so much for joining. Stick around we're going to be live all day here from Black Hat 2026 with much more on the role of the CISO and more
>> Hey, welcome back to theCUBE. This is our kickoff for our day two coverage, live here at Black Hat 2026. We're here at the Mandalay Bay in Las Vegas all day. I'm Krista Case. I'm joined here with Jon Oltsik, my co-host and my analyst in residence here at theCUBE Research. Jon, how you feeling this morning? How you doing?
Jon Oltsik
>> I'm doing great, ready for another day.
Krista Case
>> I know. I know, I know. The energy's still up this morning. And Jon, I know we've talked a lot over the last couple days here at the show, naturally about kind of the impact of AI on the cybersecurity industry. And what I thought we could do this morning is kind of laser in on the impact to the role of the CISO. Because we've got a couple of great CISO guests coming on theCUBE today. We've had a number of conversations with them over the last couple days, and really here at Black Hat. It's a very practitioner-driven show, as you know. So we've got a lot of practitioners trying to navigate this FUD around the impact of adversarial AI and kind of trying to navigate the new tools that vendors are promoting here at the show that use AI to sort of try to fight fire with fire. So I wanted to even go a little bit beyond the technology this morning, Jon, and talk to the role of the CISO and how they're really managing cyber risk but they're also helping the business to make decisions around what are some of the right practices and technologies for governance, resilience, and these operational guardrails. We've had a lot of conversations around AI moving into production and what sort of guardrails do we need in place? I tend to think about it as this requires a CISO to have a broader purview, not only across traditional security stack, but also looking at identities and data and resilience and governance and all of these areas becoming interconnected. And I've also been thinking about this AI governance through the lens of the different roles that the CISO has to collaborate with within the enterprise. So things like legal, compliance, engineering, IT, they almost have to be sort of the connective tissue helping to facilitate these conversations. So they're really becoming a business enabler. And I guess I wanted to get your take on this, Jon. where do you see security leaders being asked to help the business to adopt AI responsibly. Are you seeing this shift and are you getting any feedback from CISOs on how they're navigating this?
Jon Oltsik
>> Yes and yes. So the CISO role has been in transition for a long time and it's been easily 10 years that we've been saying, oh, security needs to get closer to the business. There's never been a time where that was more of a requirement. And the business needs to get closer to security. And so if we're going to have these AI-based initiatives, we better get security involved at the beginning. And that hasn't always been the case. So all of the constituents that you mentioned need to be participants. Because as a CISO, if I'm going to look and create the appropriate threat model. I need to understand all of the ramifications of an initiative. And so that's where we're at. Now, are we there? No. But I'd say just as we're looking at the show as AI is transformational to technology, AI has to be transformational to the organization as well.
Krista Case
>> Absolutely, Jon. And so are you, as you walk the show floor and have some conversations, are you starting to see that, maybe some of these conversations are starting to happen and There's a recognition on the business side that some of these conversations really need to be driven top down, which I think is kind of what you're alluding to.
Jon Oltsik
>> Not really. And I made this observation at RSA, and I think it's still true. About 20 % of CISOs get it. They understand the implications. They understand what their organization's trying to do with AI. They may not know exactly what individual users are doing with AI, but they understand they need to get a handle on it. And they're looking at security architecturally, so what's the strategic direction that security has to go. But I think that's only about 20 % of the market. So the other 80 % are in a state of ignorance, sometimes ignorance is bliss, or at least assumed bliss.
Krista Case
>> We can't stress about what we don't know about.
Jon Oltsik
>> That's right.So even though we're talking about AI a lot, it's a tactical show. It's AI for this, AI for identity, AI for the SOC, AI for exposure management. But the strategic discussions of how that translates into a CISO program are pretty minimal. And the truth is, and I've said this for years too, but of all the vendors here, I'd say one in 10 knows what the CISO does. And of those companies, maybe another one in 10 can actually talk to the CISO at their level. And even within those companies, they have a few people who can have that conversation. So there's a real disconnect.
Krista Case
>> Yeah, I agree. And so if you were a CISO and you're trying to figure out, you're being inundated with all these requests to meet with vendors, what would you look for in terms of a vendor that actually understands these challenges that the CISO is navigating and that they understand how to talk to them in their terms?
Jon Oltsik
>> Well, I wouldn't open the door to any vendor right now, meaning I would recruit the vendors based on my requirements, based on my assessment of what I need and what the business is doing. So it's a difficult time for some of the vendor salespeople, but the first thing they should do is understand that customer's business, understand their industry, understand where AI plays, and where AI plays with new types of technology, new types of business processes, new types of relationships. That's a lot to think about, but you have to get into that mindset before you go into the customer. And again, on the CISO side, they should be cherry picking who they talk to based on their requirements and their strategic plans.
Krista Case
>> Yeah, I agree. And I think going to those requirements and those strategic plans, Jon, I had a conversation with the CISO earlier in the week, and this individual is saying that AI is changing how the business thinks about risk. we've sort of been alluding to this, but it's opening their minds to the fact that they have to accept some level of risk. Previously, Obviously the answer is no, we want no risk. And now they're saying, okay, we want to be able to implement AI as a part of our daily processes and we understand that we're opening ourselves up to a certain level of risk as a result of that. So I guess the question to you is how do you think the CISO should go about balancing the need to reduce risk appropriately but also not get in the way of the business and sort of actually help the business to adopt AI faster, going to the conversation around operationalizing AI and establishing those guardrails.
Jon Oltsik
>> Yeah, even though there's AI and we're moving faster and we have new opportunities, the formula for the CISO hasn't changed. So this is what I was saying before, is the CISO has to be involved in the business plan, understand what the initiative is, understand who that initiative touches, what data it touches, what identity it touches, to build the right threat model. And then it's their responsibility, the CISO's responsibility, to go to the executives and the board and say, here are the risks I see. Here's how much it will cost us to mitigate or minimize those risks, because you can't eliminate the risk. Do you want to accept the risk? Do you want to mitigate the risk? Or do you want to transfer the risk? So those are your choices. you can't get in the way. And no one should try to get in the way. You'll get run over, you'll lose your job if you try to get in the way. So that's really the way it is.
Krista Case
>> Yeah, absolutely Jon. And I think in order to have the visibility and the control to be able to do this, what I'm seeing is that these disciplines like identity, data, threat intelligence, resilience, they need to almost, they need to be more integrated together and they need to operate in sync. So I guess, are you seeing that as well? And maybe how might you recommend a CISO think about that evolution in their technology stack?
Jon Oltsik
>> Well first of all, hallelujah. That's absolutely what they should do. We've managed security historically on a domain by domain or a silo basis that doesn't scale. We knew it didn't scale, but we had no choice, but now we do have a choice. So what you should do, this is where the strategy comes into play is, I have to understand that risk, but how do I monitor that risk and control that risk over time, and that's where these agentic solutions will help enormously. Now, in my view, they're immature. they're still somewhat stratified. So you have to again understand your immediate pain points, but you need a bridge to the future, you need a bridge to that strategic integration that you talk about, because we do have to understand risk across the enterprise. Risk will change, it's very dynamic, we'll have new partners, third parties, fourth parties. How do you understand that that's where I think some of these agentic solutions will help?
Krista Case
>> I agree, Jon. And I think, so you're kind of talking to maybe the external view of kind of some of these partners to work with. We've talked about kind of the role of security in the business working together. As we operationalize AI, I'm curious your thoughts on some of the other strategic partners to the CISO. Is it the CIO? Is it engineering? my thought is it probably depends on the unique business.
Jon Oltsik
>> Yes.
Krista Case
>> But are there any roles that come to mind to you as maybe being a more strategic partner to the CISO during this adoption of AI?
Jon Oltsik
>> Yeah, at a really large company, it's going to be the chief risk officer. But most companies don't have that role. So I think the biggest intersection will be with the line of business managers who are driven to drive profit, lower cost. They'll use AI much more, they'll accelerate their pace, they'll look at it strategically. So you have to be in that business. You have to really understand, well what are you doing, what are you trying to do, and then you can assess the risk. So it really goes back for a while, it was fashionable to think of a BISO, a business information security officer. I haven't heard that term in a few years, but that mindset really comes into play here.
Krista Case
>> Yeah, I definitely agree. And I think as this role evolves for the CISO, again, in some of these conversations I've been having over the last couple of days, it's come up that sort of the definitions of success and those metrics are going to evolve. Previously, it was things like, OK, we prevented this number of attacks. But as we, especially as we start to not only operationalize AI, but also really start to integrate resilience as a part of this continuum of cybersecurity, they're being measured based on things like uptime, the ability to restore the minimum viable operations for the business. what are some of the metrics that you think will be really critical in this conversation moving forward?
Jon Oltsik
>> I think you're right, I think it's the resilience factor that I know is near and dear to your heart. Early in my career I worked at companies that were very concerned with business continuity and disaster recovery. Now that was typically at the data level, but with resilience you're looking at the operational level across people, process, and technology. So they'll be measured there. They'll also be measured with managing and monitoring risk appropriately. They'll be measured by their ability to deal with emergent risks like vulnerabilities and exposures that come up and their ability to work with IT, for instance, to mitigate those risks or put in compensating controls. But I think ultimately it's the business. And that's the whole notion of the CISO to me, in my day, the CISO probably started their career as a Windows administrator or a Check Point firewall administrator or something like that. Those days are gone. So this is a business role and you'll need strong technology people supporting that person, but it's a business role.
Krista Case
>> Yeah, I completely agree. So Jon, hopefully you and I will be back here at Black Hat next year. How do you think...
Jon Oltsik
>> From your mouth to God's ears.
Krista Case
>> Right? So how do you think the day-to-day for the CISO will have evolved? again, assuming we sit down again here in 12 months, we've talked a lot of kind of high-level strategic, but I'm curious, again, kind of day-to-day.
Jon Oltsik
>> I don't think it's going to change radically in the next year, but I do think that the pace of change is incrementally increasing. So CISOs tend to be risk averse. They tend to be cynics. And I understand, we're paid to break things in security and believe things can be broken. But at the same time, I think they'll have to be much more open-minded. They'll have to really pay attention to changes with skill sets needed and staffing and just the day-to-day business activity. So I think the metrics will be there. They may, and I'm seeing this too, their programs may become much more automated and much more integrated in the way they manage them. So no more spreadsheets, much more of an agentic process too. So it could change quite a bit in terms of the way we do things, but I'd say the day-to-day important points that they have to manage are about the same, will be about the same.
Krista Case
>> Yeah, and that's a great point. And you bring up the automation, and obviously here at the show, every vendor is pushing their ability to use AI to automate different pieces of the security stack. What do you think are some of the key points that might be automated maybe even in the near term, over the next 12 months or so?
Jon Oltsik
>> Well, I think that we'll get better with discovery and monitoring of assets and automating the changes. So moving from periodic scans, periodic reviews to continuous. Things like penetration testing and red teaming. There's the opportunity to move those to a much faster pace and integrate them into some of the controls that we have. So we understand our threats, we make some changes to our controls, but are those changes really effective? Well, we can do some continuous testing. So I think those kinds of automation will be there. Now, what I'm a little less bullish on is the automation that happens between security and IT. I think that will happen over time, but we're fighting 60 years of culture. And those are separate organizations and they have their own agendas and their own objectives and things. They have to come together. But again, we're fighting culture and those are the lessons we have to learn is that changes are happening so fast that we have to be a little bit more adaptable ourselves.
Krista Case
>> More open -minded, more adaptable, and more willing for these kinds of typical silos to break down.
Jon Oltsik
>> Yes. Now, can I ask a question?
Krista Case
>> Certainly.
Jon Oltsik
>> I think next year we're going to see some nightmares, between now and next year, around AI. And so AI complacency. Yes. Let AI do all the work. Some of these solutions up here may not be developed as good as they could be, and maybe the AI goes amok, runs amok. What do you think?
Krista Case
>> I agree. we just, what, a couple weeks ago saw the Hugging Face incident, which, I think showed, obviously, the potential for that.
Jon Oltsik
>> Who named that? Hugging Face? Who named that?
Krista Case
>> It's a good question, right? But I think, we're already starting to see that.
Jon Oltsik
>> Yes.
Krista Case
>> And I think also, from the vendor side of things, if I was a practitioner, I would try to be, skeptical toward any of these new solutions, especially if they're coming out of stealth very quickly, how are they being developed? Are they being developed using some of these vibe coding techniques? So I would definitely be mindful of that. And it's something, and I know Jon, you actually had a conversation around the potential for, especially for large enterprises with established security teams to potentially create some of their own AI driven automation and tooling. So that maybe is something on the horizon. But I think both the adversarial and kind of the vendor side of things, it's going to be really interesting to see how that develops.
Jon Oltsik
>> And we'll be here to see.
Krista Case
>> That we will.That we will. Anything else top of mind for you, Jon, as we head into day two here?
Jon Oltsik
>> Anything else top of mind? No, I think your point about CISOs and the fact that you have them on today is a good sobriety test for the hoopla that's going on upstairs. We need a pragmatic approach to this, even though it is revolutionary, we understand how to make changes, albeit we'll have to do that at a faster pace. So that's, I think that's a good way to conclude the show for theCUBE and for you and I.
Krista Case
>> Great. Well, Jon, thanks so much for sitting down with me to kick off day two here. Thanks for kind of co-hosting with me. And yeah, I really look forward to continuing the conversations with you.
Jon Oltsik
>> We will do so. And thank you.
Krista Case
>> Absolutely. and thanks so much for joining. Stick around we're going to be live all day here from Black Hat 2026 with much more on the role of the CISO and more