John Sapp of Texas Mutual Insurance, vice president of information security and chief information security officer, discusses securing artificial intelligence deployments and operationalizing zero trust at Texas Mutual during the theCUBE conversation at the New York Stock Exchange. Sapp draws on decades of CISO experience to examine AI security capabilities, governance, inventory of agentic systems, risk quantification and how information security teams enable business innovation. They emphasize maintaining an inventory of AI use, establishing governance and automated verification controls, framing cyber risk in financial terms for boards, deploying guardrails for responsible adoption, using AI to reduce alert fatigue and monitoring AI cost tokenomics.
A theCUBE Research study finds many organizations struggle to recover data after attacks, highlighting resilience gaps within insurance and other regulated industries. This discussion addresses cyber resilience, zero trust implementation, AI governance, data recovery and risk management to help security leaders balance protection and innovation.
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
theCUBE + NYSE Wired: Zero Trust Cyber Series. If you don’t think you received an email check your
spam folder.
Sign in to theCUBE + NYSE Wired: Zero Trust Cyber Series.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open this link to automatically sign into the site.
Register For theCUBE + NYSE Wired: Zero Trust Cyber Series
Please fill out the information below. You will recieve an email with a verification link confirming your registration. Click the link to automatically sign into the site.
You’re almost there!
We just sent you a verification email. Please click the verification button in the email. Once your email address is verified, you will have full access to all event content for theCUBE + NYSE Wired: Zero Trust Cyber Series.
I want my badge and interests to be visible to all attendees.
Checking this box will display your presense on the attendees list, view your profile and allow other attendees to contact you via 1-1 chat. Read the Privacy Policy. At any time, you can choose to disable this preference.
Select your Interests!
add
Upload your photo
Uploading..
OR
Connect via Twitter
Connect via Linkedin
EDIT PASSWORD
Share
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
theCUBE + NYSE Wired: Zero Trust Cyber Series. If you don’t think you received an email check your
spam folder.
Sign in to theCUBE + NYSE Wired: Zero Trust Cyber Series.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open this link to automatically sign into the site.
Sign in to gain access to theCUBE + NYSE Wired: Zero Trust Cyber Series
Please sign in with LinkedIn to continue to theCUBE + NYSE Wired: Zero Trust Cyber Series. Signing in with LinkedIn ensures a professional environment.
Are you sure you want to remove access rights for this user?
Details
Manage Access
email address
Community Invitation
John Sapp, Texas Mutual Insurance
Inna Tokarev Sela is the CEO and founder of Illumex. The platform enables companies to extract value from structured data, creating a virtual semantic graph for users to interact with in natural language. Illumex focuses on contextualizing data in real-time and offers built-in governance features. By partnering with major data platform providers, Illumex has increased data usage for customers. The company has raised $13 million and has a diverse workforce. Inna's leadership style is described as empathetic. Illumex envisions a future where data interactions are seamless and efficient. Overall, the company aims to lead the industry towards a more streamlined application-free future.
play_circle_outlineSecuring Claims Trust at Texas Mutual: AI Safety, Zero Trust, Cyber Resilience, and Algorithm Governance
replyShare Clip
play_circle_outlineCascading AI Failures: Building Automated Controls, Risk Detection, Independent Verification, and Oversight to Prevent Operational, Legal, Regulatory, and Financial Harm
replyShare Clip
play_circle_outlineAgentic AI concerns: inventory autonomous agents, governance, discover shadow AI, comply with regulations.
replyShare Clip
play_circle_outlineSecOps augmentation: AI reduces alert fatigue, automates triage, escalates contextual decisions to humans.
replyShare Clip
play_circle_outlineCISO evolution: role shifted from technical to business-aligned risk manager and AI-era enabler.
replyShare Clip
play_circle_outlineTokenomics and cost risk: monitor AI compute/token costs to prevent surprising budget overruns.
VP Information Security & CISOTexas Mutual Insurance
search
Dave Vellante
>> Hi everybody. Welcome back to the New York Stock Exchange. My name is Dave Vellante and you're watching theCUBE and the NYSE Wired's ongoing series on Zero Trust and Cyber Resilience. And also we're going to be running the segment on our AI Trust and Cyber Resiliency Summit coming up in end of February and it features leaders from Walmart, Capital One, Experience. And our next guest, John Sapp, who's the Vice President of Information Security and Chief Information Security Officer at Texas Mutual. Great to see you, John. Thanks for coming in to the studio here.
John Sapp
>> Pleasure. Always a joy to sit down and have a chat with you.
Dave Vellante
>> Yeah, ditto. And so this is an interesting time in our industry. So first of all, let's talk about Texas Mutual. You're the largest workman's comp insurer in Texas.
John Sapp
>> Right.
Dave Vellante
>> And so tell us a little bit more about the business. I think you're probably, what, a thousand employees? You service a lot of agents, 9,000 agents or so.
John Sapp
>> Yeah. 1.2 billion or so in written premium. But one of the things, as we talk about trust, that's one of the things that's most important to Texas Mutual is the trust of the policy holder and their employees. Because at the point an employee gets injured on the job, workman's comp becomes their paycheck. So they have to trust and believe that we're going to deliver and pay that claim on time, every time. But one of the aspects that we're adding into our program at Texas Mutual with AI is cyber safety. And thinking about things from that perspective, and now with AI becoming so just used so broadly and so widely and so rapidly evolving in the business, you have to be able to ensure that it's going to operate safely and that it's not going to hallucinate or create any unknown or unexpected results that are going to harm someone.
Dave Vellante
>> So let's talk about trust. So prior to the pandemic, we would talk about things like zero trust and it was a buzzword. And then after the pandemic, it became, I guess, a mandate, but hard to operationalize. And then the AI herd around the world comes in in November of 2022 and it changes things even more. So how do you think about trust from a technology and a data and an AI perspective? What does trust mean to you in this current-
John Sapp
>> Yeah. Zero trust is now, that's table stakes. It is expected. And trust between data, AI, the application layer and those different components, it's about having the appropriate governance, which is about oversight and visibility into the algorithm. Is the algorithm operating as expected? Is it delivering information that can be trusted? How do you verify and validate that information before it gets used to make a decision? And that's at the core of trust is, was the decision made upon, made using information that could be trusted, that was validated, that was verified, and that has appropriate context? Because that's one thing that the AI application itself can't do is it can't understand context.
Dave Vellante
>> So an AI is still, parts of AI anyway are kind of a black box. So if you have an AI that makes a decision to say, deny a claim and it's not correct, that's a risk that you have to mitigate, right?
John Sapp
>> Absolutely. And it's probably the most important risk because when you think about cyber and technology risk, they create a cascading effect of risk across the organization because if technology fails, which in this case AI is the technology, it creates cascading risk, which is you have operational risk. So your business operations can be disrupted, a bad decision. Then you get legal and regulatory and compliance risk, financial risk. So you see how it cascades and can create a broader expansion of the risk. So making sure that context matters in this and being able to trust and verify that data. And that's where, when I think about it, when I talk about AI security capabilities, that's the key. And what I mean by AI security capabilities is this. The ability to be able to have oversight, which is the governance part, risk management, which is, how do I identify when, where, and how the model may have gone wrong? How do I verify that independently, but also in an automated way? And that's why you have to be able to automate those controls.
Dave Vellante
>> Okay. So I want to draw an analogy with, well, the history of cyber. I mean, it used to be we'd try to protect the parameter, right? And then the parameter just vaporizes, so there's no parameter. And so you have to use new techniques and you're always constantly trying to keep up with the attackers, but then you have to be able to recover. You indicated that. A new study from theCUBE research I was reading on SiliconANGLE from Paul Gillan found that, and I would love your reaction, found that although most organizations say their performance is strong against relative to the NIST Cybersecurity Framework, only 12% said they can cover all their data after an attack, and 34% experienced data loss exceeding 30% of their data in the past year. So that's challenging because you can't necessarily afford to apply stringent cybersecurity to all your data. There's maybe some data that you don't care as much about. You don't have unlimited budgets. So how do you deal as a CISO, how do you deal with that challenge?
John Sapp
>> Well, you have to think about it in those layers. It is because there's an old saying about you don't want to put a million dollar fence around a $10 asset.
Dave Vellante
>> Exactly, right.
John Sapp
>> Yeah. So you have to think about it and what's the value of the assets. And everything's an asset in my mind, whether it's a business process, whether it is an application, whether it's data, whether it is the actual people that work for the organization, everything's an asset in my mind. So it is think about the value of those different assets and what part and what role do they play in the business functions or in the business operations. So is it a revenue-generating business function? Okay, we want to think about that. But you also can't discount things that might be expense or liabilities to the business such as paying claims because making claims payments is maybe almost more important or equally, certainly as important as generating the revenue on the written premiums. So I think about it and layered it in that way so that I take that type of an approach to it.
Dave Vellante
>> What's interesting about this conversation right now is we're not talking tech. I'm sure we can talk tech.
John Sapp
>> Right.
Dave Vellante
>> But you're talking to me like you would talk to a board of directors. You're talking about assets, you're talking about revenue, protecting that. I want to go there and talk about from a CISO's perspective, how should your peers be speaking to the board? What are the dos and don'ts there?
John Sapp
>> Yeah. Oh, I love this part of the conversation. And it is really, you have to talk to them in language that they understand because every board member understands financial terms. That is one of the foundational things. It's a basic requirement to be a board member is you have to know and understand finance. And so when you think about it and you put things, when you quantify the risk and the impact that it could have or potentially could have on the business, that's what they care about. Because to me, the metrics that matter are, does it increase revenue? Does it reduce costs and does it overall, could it give us a competitive advantage? And those are the things that in the boardroom, if you're having that conversation, you've got their ear.
Dave Vellante
>> So in thinking about quantifying it, and I'm curious how you communicate that. I mean, I think in terms of what's the probability of an attack or a breach, assume it's pretty high, but then what's the impact of that and what's the expected loss? And that expected loss presumably is a function of the value of the asset. Is that how you communicated? But how do you quantify that?
John Sapp
>> Yeah. So actually it's a pretty simple equation. So you take the value of the asset, which will give you the impact component, and then you take a look at... So probability comes from the history of attacks and what's currently going on. So I take in a couple threat intelligence and also what are the vulnerabilities or the weakness we have in our environment. I take all of that and I basically put it in my calculator, if you will. And then what I come out with is a simple equation of the value of the asset, the impact and potential disruption to the business equals X. And so when I put that into a financial term, so now it's understood is that, okay, so the investment from a security standpoint to protect against that is, let's call it $1 million, but the risk and the impact financially is $10 million. Well, that just made my case to justify the acquisition of whatever security control or technology I say I need to protect the business and those assets.
Dave Vellante
>> So I'm curious, John, when you deliver that kind of message to the board, because you've got assumptions in there about the probability and the impact, a lot of times boards of directors would be poking at those assumptions and say, "Well, maybe that's too high." Is it the opposite with cyber? In other words, are you sure you've got a high enough probability and a high enough impact because it could be worse than John you're saying?
John Sapp
>> Right.
Dave Vellante
>> And do you get that kind of dynamic?
John Sapp
>> You do get some of that, but the way we explain it, because their first question is, "How do you know we can trust these numbers?" We're talking about trust, right? That's part of the question is, "Where did you get these numbers from and how did you get that number?" And I always tell them this, is I start with either an audited financial statement or something that our finance and accounting department has come up with. So now you basically push it back to their side of the table is that, "No, these aren't my numbers. I started with your numbers." And then they can see how you got there. So it's a simple two or three step process that literally you can walk them through and be able to identify for them that, Look, we started with, we generate a billion dollars a year in revenue. And of course we're not going to lose 100% of that if we have a technology outage. Let's say an AI system goes wrong and there's an outage in that business process. So let's say it's disrupted for eight hours. We of course aren't going to lose a billion dollars in revenue, right? But the odds are, the probability of any loss is actually very low because it's a short term outage. But let's say the same way you would do with any business impact analysis, it is the longer you have an outage, the greater the impact. And so we're using the same formula as a BIA. So we're not doing anything new, we're just applying it in a different way.
Dave Vellante
>> Yeah. So I mean, I like the simple approach. You take a billion dollars, you got how many working days, you're out for a day, you do the math. That's it. So, all right, I want to pull up some other data I got from Deloitte. They had this state of AI in the Enterprise survey. It was pretty substantial, 3,000 business and technology leaders like yourself. They found that while 74% said they expect to use Agentic AI within the next two years, only 21% said they have a mature governance practice in place for autonomous agents. So how are you thinking about Agentic, agents infecting other agents? This changes the probability and the impact, doesn't it?
John Sapp
>> Yeah. I mean, and you think about it right now, there's Multibook, which is an actual social channel for agents. No humans are allowed.
Dave Vellante
>> I saw that the other day. I was like, "What?"
John Sapp
>> Yeah.
Dave Vellante
>> They're chatting about how to fake out humans.
John Sapp
>> Yes.
Dave Vellante
>> Agents are talking to-
John Sapp
>> So you've got that aspect of it. And so the way I think about it is this, is it really is about the governance is critical because in order to have effective governance, it's about visibility and to be able to have that oversight and being able to know and understand what's the inventory of what's being used because at the end of the day, and in Texas, we have a Responsible AI Governance Act now, which talks about if someone can allege that, "Hey, you know what? I think this company used AI to make a decision that harmed me, so maybe denied me benefits." So that goes to the attorney general and now they begin an investigation. So you have to have good governance and good governance has to have a couple of components. You have to have an inventory of what AI is being used in your organization. And it's not about the ones that you know about, you need to understand which ones do you not know about. So be able to discover what's being used in the environment that may not necessarily be formally approved, but then also think and take what are any of those being used in business processes where decisions are being made and that's where you want to focus because that's where your highest risk is going to be. And it's about, we've been talking about governance, risk and compliance for years, right, decades in technology, but now it's really important in that aspect of you have to have good governance and effective risk management. And compliance to me is just a natural byproduct of doing those first two.
Dave Vellante
>> You mentioned some regulations in Texas that are presumably unique to Texas, although other states may have versions of them, California, Massachusetts, New York. And so David Sacks, who's the AI czar, talks about this a lot with saying, "We can't have state by state regulations," but we actually do. Now you're on the practitioner side, but when you talk to the technology companies that are selling to you, this has got to be a challenge for them. Does it come up in conversation or is it just say, "Hey, you're in Texas and this is what you got to do or you're out."
John Sapp
>> Well, it does come up. And I often, I'm an advisor to a number of different cyber technology startups, right? And so this is part of the conversation I have with them as an advisor, but also as a potential purchaser of their technologies. And so we talk about it in terms of how do you help me achieve the governance that I need? And right now, it's not about governance framework. Governance really is more about the execution.
Dave Vellante
>> I want to come back to this notion of agentic. We throw that term around a lot. We're starting to understand what it actually means. We're starting to see it in production, in enterprises, and even in our own use of AI. How does it change or does it change the discussion around cyber resiliency in terms of hardening the top and actually recovering? What impacts do you see agents working on behalf of humans having on the way you think about cyber resilience?
John Sapp
>> Yeah. In the security world, I think about cyber resilience a lot. And at the end of the day, resilience is about your ability to withstand, recover from and/or adapt to an adverse condition. So when I think about it in that way, vulnerabilities and attacks, exploits happening in an environment, I have to be able to withstand it. So AI can help me withstand that by quickly identifying or detecting things. And so that level one, level two effort that says, "Okay, I need to triage an event that just happened." So example, your home, you've got a security system, a motion sensor goes off, how quickly can you detect and respond to what that action may have been? So same way in a technology environment. So when I think about it that way, it's how quickly can I detect? And I'm using AI for that and now response based on, is it just an event of interest, something that just, "Oh, it was a motion detector, it was just the cat."
Or was it, "Okay, that was actually a burglar and so now I need to go into response mode and be able to neutralize the threat that's in the environment." So now AI can do that much faster than a security analyst, right? So it's how quickly can I get to level three, level four where my internal security analyst is now going to apply context because as I said earlier, AI can't provide context. You still need a human to do that.
Dave Vellante
>> So a scorge of SecOps is false positives and getting overwhelmed with alerts. So are you saying that AI actually helps remediate some of that?
John Sapp
>> Absolutely. So what AI can do is actually get that down to a manageable number and I use it and we talk about resiliency. So I have two managed security services in my environment. So on one hand, I've got a vendor product solution that does it for me. Because they're a product vendor, of course they're going to be focused around what their product discovers, but then I've got just a pure play service provider who also does managed detection and response, but they're both using AI to reduce the alert fatigue. So what they don't want to do is they don't want to just fire off an alert per second, right? Because now you're chasing things, you could be chasing ghosts. It is using AI to get us to, is that something that we actually need to pay attention to? And then elevate it to an internal person. And that's why you need both outsourced resources because they're a commodity and they can apply resources at a much faster rate. Their playbooks are consistent, they're effective, they're efficient, but being able to escalate to an internal team where they can provide context, that becomes the key to, "Do I have a security incident that needs just some simple remediation, maybe a tweak of a configuration? Or did I actually have a breach that now I need to do investigation?"
Dave Vellante
>> Thank you for that. I want to shift gears a little bit and talk about security as an enabler versus a blocker. So SecOps oftentimes is seen as the department of no, picking up from where IT left off, I can't do that. So how do you make it such that the security standards and practices that you implement can actually help the lines of business get products out faster?
John Sapp
>> Yeah. And so that is a key. And that is, for me, that is part of what I define my program as. One, we are a modern information security program. And the reason I use the word modern is because you have to continue to adapt with the business, because if the business decides tomorrow they want to go into some line of business that they've never gone into, you have to enable them to do that. And I'm going to just digress a little bit in that. When you think about the evolution of the CISO role, in '95 when Steve Katz was first, arguably the first CISO, right, 30 years ago, we had to be very technically focused. And I think of these in generations in 10 year increments. So that was gen one technical. Gen two was about becoming aligned with the business, right? So that's where we first started having to start to try to enable the business. Then we had the shift 10 years later to becoming risk managers and now we're in the age of AI. So you still have to be all those things together in order to enable the business to deliver on their initiatives because that's what's important first because foundational security capabilities, that's just what we're expected to deliver. You don't get a pat on the back for that. What you do get is you do get acknowledged when you are enabling the business, whether it is to be innovative or to have some competitive advantage. So that's key and identify security capabilities in a way that you already have in place what they're going to need before they know they need it.
Dave Vellante
>> I want to ask you about competitive advantage and innovation. I mean, it's not your primary role, but you're an enabler of that. And I want to ask in the context of your AI strategy. So early on in AI, we heard don't waste any money on AI until you get your data act together. Obviously you got to secure it. That's table stakes.
John Sapp
>> Right. Sure.
Dave Vellante
>> What I've found in our research and talking to some of the leaders in financial services and manufacturing is that once they got their data infrastructure in order, whether it's their database, their vector search, whatever else, that getting on AI, the AI curve as fast as possible is actually the more productive path, again, assuming they are secure, as opposed to waiting. In other words, let AI help cleanse and shape the data. In fact, one practitioner said to me, "Most of our data is still crap, but it's the AI that helps us find the real data that we need so we're not stressing about trying to boil the ocean. We've learned that getting that first project up and running maybe took 15 or 18 months, but the second one was faster, the third one's faster, and now we're at 19 or 20 and we're on a flywheel." Does that description resonate with you? Are there risks from a CISO perspective of that type of strategy? What would you advise?
John Sapp
>> Yeah, I think it absolutely resonates. And my theme for this year is enable the responsible use and secure adoption of AI. It is, no, we're not directly responsible for innovation, but we can help drive it. And we do so by being able to understand and not get in the way of what they're doing. Discover what they're doing, not put them through a heavy-handed governance type approach, but be able to discover it and be able to present them with information that, "Hey, notice you guys are starting to use AI in this way. Here are some of the things to think about and here's what we've enabled on the back end to be able to help you." We've put guardrails in place so that now you can go down that highway as fast as you want to. It's like thinking about, I just went out and bought a fast car and now I put it on a highway that has no guardrails. I want to put them on the Audubon because I want to put them where they can go as fast as they want without worrying about running into some compliance issues because we've put the appropriate guardrails in place. And that's where I think we really position them to not run afoul of regulations and to be compliant, but enable them to achieve those goals and objectives in a responsible and secure way.
Dave Vellante
>> How did you get into being a CISO? You've got a long career, you advise a lot of companies, and so they're tapping your brain to help guide them and protect our country, our firms, our reputation, et cetera. How'd you get into it?
John Sapp
>> It was probably about 20 some odd years ago and I was a developer and I was at a crossroads in my career and I really had to figure out what was next because developers knew more languages than I knew back then. I was older, they were younger, they knew more languages. Actually, their salaries were less than what I was making at the time. So it was, how do I transition and what's the next frontier for my career? And at that time, I was working for a Fortune 10 pharmaceutical company and they built an IT risk management function. And the person that I was working for at the time, she was tagged to go build that and she said, "I have no clue what that is. Do you want to come help me?" So I said, "Sure." And I enrolled in a bootcamp down in Monterey, California, spent a week doing that, took the CISSP, passed that, and there I was. And so it really just became, it was a lot like everything else that I've done in my career. I didn't go to college, went to a vocational high school where I learned to write code, right? It was learn things that are important to you if... I knew I wanted a career in technology from what happened in high school. So it was just, how do I continue to evolve and raise the stakes for myself and that's how it's been. I've had some excellent mentors along the way, so that's how it happened.
Dave Vellante
>> Last question. What would you say is the one thing that your peers, when they're sleeping with one eye open, that they should be most concerned about, most focused on to protect their organizations?
John Sapp
>> Yeah. I would say this, establishing a set of AI security capabilities that include AI risk management, that include the ability to deploy guardrails and really build out that part of your program because none of us had it. Because AI, yes, it's just another application, but it's a very different kind of an application. So think about it in that way, but also keep an eye on the tokenomics. You've heard that term used with crypto, but now it's really relevant when you think about AI because the cost of running AI can increase very rapidly. And if no one's paying attention to that, those innovations that the organization may achieve could be offset in a terrible way by the cost. And as we said a little bit earlier, one of the goals is to reduce costs, but while achieving the innovations and manage that. So think about those things and how you can contribute. So just think about protecting the business, but be a contributor to enabling the business to support revenue generation. And my last thought on that is we don't generate revenue, but we do protect the generation of revenue.
Dave Vellante
>> Indeed. You thought your cloud costs were a surprise, but when you see the token costs.
John Sapp
>> Yes.
Dave Vellante
>> John Sapp, thank you so much for coming into our studio.
John Sapp
>> My pleasure.
Dave Vellante
>> It's always a great time. And thank you for watching this ongoing Wired Cube series on Zero Trust and Cyber Resilience. Stay tuned for more great content from our AI Trust and Cyber Resiliency Summit. I'm Dave Vellante, right back right after this short break.
>> Hi everybody. Welcome back to the New York Stock Exchange. My name is Dave Vellante and you're watching theCUBE and the NYSE Wired's ongoing series on Zero Trust and Cyber Resilience. And also we're going to be running the segment on our AI Trust and Cyber Resiliency Summit coming up in end of February and it features leaders from Walmart, Capital One, Experience. And our next guest, John Sapp, who's the Vice President of Information Security and Chief Information Security Officer at Texas Mutual. Great to see you, John. Thanks for coming in to the studio here.
John Sapp
>> Pleasure. Always a joy to sit down and have a chat with you.
Dave Vellante
>> Yeah, ditto. And so this is an interesting time in our industry. So first of all, let's talk about Texas Mutual. You're the largest workman's comp insurer in Texas.
John Sapp
>> Right.
Dave Vellante
>> And so tell us a little bit more about the business. I think you're probably, what, a thousand employees? You service a lot of agents, 9,000 agents or so.
John Sapp
>> Yeah. 1.2 billion or so in written premium. But one of the things, as we talk about trust, that's one of the things that's most important to Texas Mutual is the trust of the policy holder and their employees. Because at the point an employee gets injured on the job, workman's comp becomes their paycheck. So they have to trust and believe that we're going to deliver and pay that claim on time, every time. But one of the aspects that we're adding into our program at Texas Mutual with AI is cyber safety. And thinking about things from that perspective, and now with AI becoming so just used so broadly and so widely and so rapidly evolving in the business, you have to be able to ensure that it's going to operate safely and that it's not going to hallucinate or create any unknown or unexpected results that are going to harm someone.
Dave Vellante
>> So let's talk about trust. So prior to the pandemic, we would talk about things like zero trust and it was a buzzword. And then after the pandemic, it became, I guess, a mandate, but hard to operationalize. And then the AI herd around the world comes in in November of 2022 and it changes things even more. So how do you think about trust from a technology and a data and an AI perspective? What does trust mean to you in this current-
John Sapp
>> Yeah. Zero trust is now, that's table stakes. It is expected. And trust between data, AI, the application layer and those different components, it's about having the appropriate governance, which is about oversight and visibility into the algorithm. Is the algorithm operating as expected? Is it delivering information that can be trusted? How do you verify and validate that information before it gets used to make a decision? And that's at the core of trust is, was the decision made upon, made using information that could be trusted, that was validated, that was verified, and that has appropriate context? Because that's one thing that the AI application itself can't do is it can't understand context.
Dave Vellante
>> So an AI is still, parts of AI anyway are kind of a black box. So if you have an AI that makes a decision to say, deny a claim and it's not correct, that's a risk that you have to mitigate, right?
John Sapp
>> Absolutely. And it's probably the most important risk because when you think about cyber and technology risk, they create a cascading effect of risk across the organization because if technology fails, which in this case AI is the technology, it creates cascading risk, which is you have operational risk. So your business operations can be disrupted, a bad decision. Then you get legal and regulatory and compliance risk, financial risk. So you see how it cascades and can create a broader expansion of the risk. So making sure that context matters in this and being able to trust and verify that data. And that's where, when I think about it, when I talk about AI security capabilities, that's the key. And what I mean by AI security capabilities is this. The ability to be able to have oversight, which is the governance part, risk management, which is, how do I identify when, where, and how the model may have gone wrong? How do I verify that independently, but also in an automated way? And that's why you have to be able to automate those controls.
Dave Vellante
>> Okay. So I want to draw an analogy with, well, the history of cyber. I mean, it used to be we'd try to protect the parameter, right? And then the parameter just vaporizes, so there's no parameter. And so you have to use new techniques and you're always constantly trying to keep up with the attackers, but then you have to be able to recover. You indicated that. A new study from theCUBE research I was reading on SiliconANGLE from Paul Gillan found that, and I would love your reaction, found that although most organizations say their performance is strong against relative to the NIST Cybersecurity Framework, only 12% said they can cover all their data after an attack, and 34% experienced data loss exceeding 30% of their data in the past year. So that's challenging because you can't necessarily afford to apply stringent cybersecurity to all your data. There's maybe some data that you don't care as much about. You don't have unlimited budgets. So how do you deal as a CISO, how do you deal with that challenge?
John Sapp
>> Well, you have to think about it in those layers. It is because there's an old saying about you don't want to put a million dollar fence around a $10 asset.
Dave Vellante
>> Exactly, right.
John Sapp
>> Yeah. So you have to think about it and what's the value of the assets. And everything's an asset in my mind, whether it's a business process, whether it is an application, whether it's data, whether it is the actual people that work for the organization, everything's an asset in my mind. So it is think about the value of those different assets and what part and what role do they play in the business functions or in the business operations. So is it a revenue-generating business function? Okay, we want to think about that. But you also can't discount things that might be expense or liabilities to the business such as paying claims because making claims payments is maybe almost more important or equally, certainly as important as generating the revenue on the written premiums. So I think about it and layered it in that way so that I take that type of an approach to it.
Dave Vellante
>> What's interesting about this conversation right now is we're not talking tech. I'm sure we can talk tech.
John Sapp
>> Right.
Dave Vellante
>> But you're talking to me like you would talk to a board of directors. You're talking about assets, you're talking about revenue, protecting that. I want to go there and talk about from a CISO's perspective, how should your peers be speaking to the board? What are the dos and don'ts there?
John Sapp
>> Yeah. Oh, I love this part of the conversation. And it is really, you have to talk to them in language that they understand because every board member understands financial terms. That is one of the foundational things. It's a basic requirement to be a board member is you have to know and understand finance. And so when you think about it and you put things, when you quantify the risk and the impact that it could have or potentially could have on the business, that's what they care about. Because to me, the metrics that matter are, does it increase revenue? Does it reduce costs and does it overall, could it give us a competitive advantage? And those are the things that in the boardroom, if you're having that conversation, you've got their ear.
Dave Vellante
>> So in thinking about quantifying it, and I'm curious how you communicate that. I mean, I think in terms of what's the probability of an attack or a breach, assume it's pretty high, but then what's the impact of that and what's the expected loss? And that expected loss presumably is a function of the value of the asset. Is that how you communicated? But how do you quantify that?
John Sapp
>> Yeah. So actually it's a pretty simple equation. So you take the value of the asset, which will give you the impact component, and then you take a look at... So probability comes from the history of attacks and what's currently going on. So I take in a couple threat intelligence and also what are the vulnerabilities or the weakness we have in our environment. I take all of that and I basically put it in my calculator, if you will. And then what I come out with is a simple equation of the value of the asset, the impact and potential disruption to the business equals X. And so when I put that into a financial term, so now it's understood is that, okay, so the investment from a security standpoint to protect against that is, let's call it $1 million, but the risk and the impact financially is $10 million. Well, that just made my case to justify the acquisition of whatever security control or technology I say I need to protect the business and those assets.
Dave Vellante
>> So I'm curious, John, when you deliver that kind of message to the board, because you've got assumptions in there about the probability and the impact, a lot of times boards of directors would be poking at those assumptions and say, "Well, maybe that's too high." Is it the opposite with cyber? In other words, are you sure you've got a high enough probability and a high enough impact because it could be worse than John you're saying?
John Sapp
>> Right.
Dave Vellante
>> And do you get that kind of dynamic?
John Sapp
>> You do get some of that, but the way we explain it, because their first question is, "How do you know we can trust these numbers?" We're talking about trust, right? That's part of the question is, "Where did you get these numbers from and how did you get that number?" And I always tell them this, is I start with either an audited financial statement or something that our finance and accounting department has come up with. So now you basically push it back to their side of the table is that, "No, these aren't my numbers. I started with your numbers." And then they can see how you got there. So it's a simple two or three step process that literally you can walk them through and be able to identify for them that, Look, we started with, we generate a billion dollars a year in revenue. And of course we're not going to lose 100% of that if we have a technology outage. Let's say an AI system goes wrong and there's an outage in that business process. So let's say it's disrupted for eight hours. We of course aren't going to lose a billion dollars in revenue, right? But the odds are, the probability of any loss is actually very low because it's a short term outage. But let's say the same way you would do with any business impact analysis, it is the longer you have an outage, the greater the impact. And so we're using the same formula as a BIA. So we're not doing anything new, we're just applying it in a different way.
Dave Vellante
>> Yeah. So I mean, I like the simple approach. You take a billion dollars, you got how many working days, you're out for a day, you do the math. That's it. So, all right, I want to pull up some other data I got from Deloitte. They had this state of AI in the Enterprise survey. It was pretty substantial, 3,000 business and technology leaders like yourself. They found that while 74% said they expect to use Agentic AI within the next two years, only 21% said they have a mature governance practice in place for autonomous agents. So how are you thinking about Agentic, agents infecting other agents? This changes the probability and the impact, doesn't it?
John Sapp
>> Yeah. I mean, and you think about it right now, there's Multibook, which is an actual social channel for agents. No humans are allowed.
Dave Vellante
>> I saw that the other day. I was like, "What?"
John Sapp
>> Yeah.
Dave Vellante
>> They're chatting about how to fake out humans.
John Sapp
>> Yes.
Dave Vellante
>> Agents are talking to-
John Sapp
>> So you've got that aspect of it. And so the way I think about it is this, is it really is about the governance is critical because in order to have effective governance, it's about visibility and to be able to have that oversight and being able to know and understand what's the inventory of what's being used because at the end of the day, and in Texas, we have a Responsible AI Governance Act now, which talks about if someone can allege that, "Hey, you know what? I think this company used AI to make a decision that harmed me, so maybe denied me benefits." So that goes to the attorney general and now they begin an investigation. So you have to have good governance and good governance has to have a couple of components. You have to have an inventory of what AI is being used in your organization. And it's not about the ones that you know about, you need to understand which ones do you not know about. So be able to discover what's being used in the environment that may not necessarily be formally approved, but then also think and take what are any of those being used in business processes where decisions are being made and that's where you want to focus because that's where your highest risk is going to be. And it's about, we've been talking about governance, risk and compliance for years, right, decades in technology, but now it's really important in that aspect of you have to have good governance and effective risk management. And compliance to me is just a natural byproduct of doing those first two.
Dave Vellante
>> You mentioned some regulations in Texas that are presumably unique to Texas, although other states may have versions of them, California, Massachusetts, New York. And so David Sacks, who's the AI czar, talks about this a lot with saying, "We can't have state by state regulations," but we actually do. Now you're on the practitioner side, but when you talk to the technology companies that are selling to you, this has got to be a challenge for them. Does it come up in conversation or is it just say, "Hey, you're in Texas and this is what you got to do or you're out."
John Sapp
>> Well, it does come up. And I often, I'm an advisor to a number of different cyber technology startups, right? And so this is part of the conversation I have with them as an advisor, but also as a potential purchaser of their technologies. And so we talk about it in terms of how do you help me achieve the governance that I need? And right now, it's not about governance framework. Governance really is more about the execution.
Dave Vellante
>> I want to come back to this notion of agentic. We throw that term around a lot. We're starting to understand what it actually means. We're starting to see it in production, in enterprises, and even in our own use of AI. How does it change or does it change the discussion around cyber resiliency in terms of hardening the top and actually recovering? What impacts do you see agents working on behalf of humans having on the way you think about cyber resilience?
John Sapp
>> Yeah. In the security world, I think about cyber resilience a lot. And at the end of the day, resilience is about your ability to withstand, recover from and/or adapt to an adverse condition. So when I think about it in that way, vulnerabilities and attacks, exploits happening in an environment, I have to be able to withstand it. So AI can help me withstand that by quickly identifying or detecting things. And so that level one, level two effort that says, "Okay, I need to triage an event that just happened." So example, your home, you've got a security system, a motion sensor goes off, how quickly can you detect and respond to what that action may have been? So same way in a technology environment. So when I think about it that way, it's how quickly can I detect? And I'm using AI for that and now response based on, is it just an event of interest, something that just, "Oh, it was a motion detector, it was just the cat."
Or was it, "Okay, that was actually a burglar and so now I need to go into response mode and be able to neutralize the threat that's in the environment." So now AI can do that much faster than a security analyst, right? So it's how quickly can I get to level three, level four where my internal security analyst is now going to apply context because as I said earlier, AI can't provide context. You still need a human to do that.
Dave Vellante
>> So a scorge of SecOps is false positives and getting overwhelmed with alerts. So are you saying that AI actually helps remediate some of that?
John Sapp
>> Absolutely. So what AI can do is actually get that down to a manageable number and I use it and we talk about resiliency. So I have two managed security services in my environment. So on one hand, I've got a vendor product solution that does it for me. Because they're a product vendor, of course they're going to be focused around what their product discovers, but then I've got just a pure play service provider who also does managed detection and response, but they're both using AI to reduce the alert fatigue. So what they don't want to do is they don't want to just fire off an alert per second, right? Because now you're chasing things, you could be chasing ghosts. It is using AI to get us to, is that something that we actually need to pay attention to? And then elevate it to an internal person. And that's why you need both outsourced resources because they're a commodity and they can apply resources at a much faster rate. Their playbooks are consistent, they're effective, they're efficient, but being able to escalate to an internal team where they can provide context, that becomes the key to, "Do I have a security incident that needs just some simple remediation, maybe a tweak of a configuration? Or did I actually have a breach that now I need to do investigation?"
Dave Vellante
>> Thank you for that. I want to shift gears a little bit and talk about security as an enabler versus a blocker. So SecOps oftentimes is seen as the department of no, picking up from where IT left off, I can't do that. So how do you make it such that the security standards and practices that you implement can actually help the lines of business get products out faster?
John Sapp
>> Yeah. And so that is a key. And that is, for me, that is part of what I define my program as. One, we are a modern information security program. And the reason I use the word modern is because you have to continue to adapt with the business, because if the business decides tomorrow they want to go into some line of business that they've never gone into, you have to enable them to do that. And I'm going to just digress a little bit in that. When you think about the evolution of the CISO role, in '95 when Steve Katz was first, arguably the first CISO, right, 30 years ago, we had to be very technically focused. And I think of these in generations in 10 year increments. So that was gen one technical. Gen two was about becoming aligned with the business, right? So that's where we first started having to start to try to enable the business. Then we had the shift 10 years later to becoming risk managers and now we're in the age of AI. So you still have to be all those things together in order to enable the business to deliver on their initiatives because that's what's important first because foundational security capabilities, that's just what we're expected to deliver. You don't get a pat on the back for that. What you do get is you do get acknowledged when you are enabling the business, whether it is to be innovative or to have some competitive advantage. So that's key and identify security capabilities in a way that you already have in place what they're going to need before they know they need it.
Dave Vellante
>> I want to ask you about competitive advantage and innovation. I mean, it's not your primary role, but you're an enabler of that. And I want to ask in the context of your AI strategy. So early on in AI, we heard don't waste any money on AI until you get your data act together. Obviously you got to secure it. That's table stakes.
John Sapp
>> Right. Sure.
Dave Vellante
>> What I've found in our research and talking to some of the leaders in financial services and manufacturing is that once they got their data infrastructure in order, whether it's their database, their vector search, whatever else, that getting on AI, the AI curve as fast as possible is actually the more productive path, again, assuming they are secure, as opposed to waiting. In other words, let AI help cleanse and shape the data. In fact, one practitioner said to me, "Most of our data is still crap, but it's the AI that helps us find the real data that we need so we're not stressing about trying to boil the ocean. We've learned that getting that first project up and running maybe took 15 or 18 months, but the second one was faster, the third one's faster, and now we're at 19 or 20 and we're on a flywheel." Does that description resonate with you? Are there risks from a CISO perspective of that type of strategy? What would you advise?
John Sapp
>> Yeah, I think it absolutely resonates. And my theme for this year is enable the responsible use and secure adoption of AI. It is, no, we're not directly responsible for innovation, but we can help drive it. And we do so by being able to understand and not get in the way of what they're doing. Discover what they're doing, not put them through a heavy-handed governance type approach, but be able to discover it and be able to present them with information that, "Hey, notice you guys are starting to use AI in this way. Here are some of the things to think about and here's what we've enabled on the back end to be able to help you." We've put guardrails in place so that now you can go down that highway as fast as you want to. It's like thinking about, I just went out and bought a fast car and now I put it on a highway that has no guardrails. I want to put them on the Audubon because I want to put them where they can go as fast as they want without worrying about running into some compliance issues because we've put the appropriate guardrails in place. And that's where I think we really position them to not run afoul of regulations and to be compliant, but enable them to achieve those goals and objectives in a responsible and secure way.
Dave Vellante
>> How did you get into being a CISO? You've got a long career, you advise a lot of companies, and so they're tapping your brain to help guide them and protect our country, our firms, our reputation, et cetera. How'd you get into it?
John Sapp
>> It was probably about 20 some odd years ago and I was a developer and I was at a crossroads in my career and I really had to figure out what was next because developers knew more languages than I knew back then. I was older, they were younger, they knew more languages. Actually, their salaries were less than what I was making at the time. So it was, how do I transition and what's the next frontier for my career? And at that time, I was working for a Fortune 10 pharmaceutical company and they built an IT risk management function. And the person that I was working for at the time, she was tagged to go build that and she said, "I have no clue what that is. Do you want to come help me?" So I said, "Sure." And I enrolled in a bootcamp down in Monterey, California, spent a week doing that, took the CISSP, passed that, and there I was. And so it really just became, it was a lot like everything else that I've done in my career. I didn't go to college, went to a vocational high school where I learned to write code, right? It was learn things that are important to you if... I knew I wanted a career in technology from what happened in high school. So it was just, how do I continue to evolve and raise the stakes for myself and that's how it's been. I've had some excellent mentors along the way, so that's how it happened.
Dave Vellante
>> Last question. What would you say is the one thing that your peers, when they're sleeping with one eye open, that they should be most concerned about, most focused on to protect their organizations?
John Sapp
>> Yeah. I would say this, establishing a set of AI security capabilities that include AI risk management, that include the ability to deploy guardrails and really build out that part of your program because none of us had it. Because AI, yes, it's just another application, but it's a very different kind of an application. So think about it in that way, but also keep an eye on the tokenomics. You've heard that term used with crypto, but now it's really relevant when you think about AI because the cost of running AI can increase very rapidly. And if no one's paying attention to that, those innovations that the organization may achieve could be offset in a terrible way by the cost. And as we said a little bit earlier, one of the goals is to reduce costs, but while achieving the innovations and manage that. So think about those things and how you can contribute. So just think about protecting the business, but be a contributor to enabling the business to support revenue generation. And my last thought on that is we don't generate revenue, but we do protect the generation of revenue.
Dave Vellante
>> Indeed. You thought your cloud costs were a surprise, but when you see the token costs.
John Sapp
>> Yes.
Dave Vellante
>> John Sapp, thank you so much for coming into our studio.
John Sapp
>> My pleasure.
Dave Vellante
>> It's always a great time. And thank you for watching this ongoing Wired Cube series on Zero Trust and Cyber Resilience. Stay tuned for more great content from our AI Trust and Cyber Resiliency Summit. I'm Dave Vellante, right back right after this short break.