By Michael Hiskey
The June 2026 New York City CxO Security Forum brought together senior cybersecurity, technology, risk, and business leaders for candid, practitioner-led discussions on how AI is reshaping enterprise security and governance.
A recurring theme was that the greatest challenges surrounding AI are no longer technical—they are organizational. Speakers explored how AI agents should be governed as digital workers, why identity and access management must evolve for AI-native environments, and how automation should eliminate repetitive work while improving explainability and trust.
Participants also examined new approaches to measuring cyber risk. From third-party risk scoring and insider threat detection to OT security and identity governance, discussions highlighted the limitations of manual processes and static controls, pointing instead toward AI-driven models that enable faster, more informed risk decisions.
The forum concluded with lessons from the SolarWinds incident, reinforcing that major cyber events quickly become executive leadership challenges. Today’s CISO must balance technology expertise with governance, communication, and business judgment.
Across every session, the message was consistent: organizations that modernize governance, embrace AI responsibly, and make risk measurable will be best positioned to navigate the next generation of cybersecurity challenges.
Find more details and all of the presentation materials in the CxO Security Forum Online Community Portal at engagez.net/cxo.
The web page for this Forum is CxOSecurityForum.com/NYC
Discussion Pod #1
Agentic AI Meets Zero Trust: What Actually Breaks—and How to Fix It
Josh Woodruff – Author, Agentic AI + Zero Trust
“AI agents are the employees you forgot to interview.”
Start-Up Showcase #1
OT Security’s Missing Control Layer?
Josh Ross – Founder & CEO, IronLoop
“There’s an opportunity to take DevOps principles and apply them to the OT space.”
Discussion Pod #2
The Missing Metric in Third-Party Risk Management?
Jeremy Huval – Chief Innovation Officer, HITRUST
“We don’t need another assessment—we need better measurement.”
Discussion Pod #3
Beyond the Headlines: Executive Accountability, Regulatory Pressure, and the Reality of CISO Risk
Tim Brown – Former Chief Information Security Officer, SolarWinds
“Security leaders today are responsible for communicating cyber risk to the business—not just running security technology.”
Discussion Pod #4
AI-Native Identity: Why IAM Is Being Rewritten
Barak Perelman – Founder & CEO, Opti
“Identity governance is no longer one program. It’s a matrix of jobs.”
Start-Up Showcase #2
The Insider Threat Problem We Still Haven’t Solved
Casper Neo – Founder & CEO, Palace Cybersecurity (nee Google)
“Access abuse hides in an ocean of legitimate activity.”
We extend our sincere thanks to Banc of California, our Strategic Partner for the event; Brown Rudnick, our gracious host in New York City; and Opti.ai and HITRUST for their support of the CxO Security Forum community and their commitment to advancing meaningful dialogue among cybersecurity and technology leaders.
Discussion Pod #1
Author, Agentic AI + Zero Trust
The forum opened with a thought-provoking discussion that challenged one of the most common assumptions about enterprise AI: that the biggest obstacles are technical. Instead, Josh argued that successful AI adoption is primarily a leadership and governance challenge. Organizations that struggle with AI often attempt to automate broken processes, while those seeing meaningful business value first rethink how work should be performed and then apply AI to accelerate it.
A central theme was that AI agents should no longer be viewed as software tools but as digital workers operating inside the enterprise. Unlike employees, however, these “workers” are often deployed without interviews, onboarding, training, or supervision—despite receiving broad access to enterprise systems. This changes the security problem from preventing unauthorized access to managing authorized misuse.
The discussion explored how Zero Trust principles must evolve to address non-human identities and autonomous decision-making. Rather than slowing innovation, participants agreed that governance enables organizations to move AI projects from perpetual pilots into production with greater confidence and lower risk. The conversation also emphasized that security leaders have an opportunity to reposition themselves from the department that says “no” to the function that enables responsible AI adoption.
I welcome your input on this article… please do that via the summary LinkedIn post on this same topic!
Start-Up Showcase #1
Founder & CEO, IronLoop
Josh Ross challenged attendees to rethink a longstanding assumption in operational technology (OT) security: that visibility alone is enough. While most OT security investments focus on asset discovery, monitoring, and vulnerability detection, he proposed that organizations are missing a configuration control layer capable of validating intended system states and understanding the impact of changes before they occur.
The discussion highlighted the differing priorities of IT and OT teams. While IT emphasizes protecting data, OT prioritizes safety and operational continuity, making organizations reluctant to patch systems that could introduce downtime. Ross argued that applying DevOps-style configuration management principles to industrial environments could enable organizations to modernize OT more safely and confidently.
Discussion Pod #2
Chief Innovation Officer, HITRUST
Jeremy Huval shared an early look at a new approach for measuring third-party cyber risk that moves beyond today’s fragmented assessment process. Rather than introducing another framework or questionnaire, the concept normalizes existing assurance artifacts—including questionnaires, SOC 2 reports, ISO certifications, HITRUST certifications, audit reports, and inherent risk factors—into a standardized Information Risk Score designed to quantify residual cyber risk and support executive decision-making.
The discussion centered on a common frustration shared by both vendors and enterprise TPRM teams: today’s process measures activity rather than risk. Executives need to know how much third-party risk they are actually accepting, whether it exceeds their organization’s risk appetite, and when it should be mitigated, accepted, or financially transferred. Participants also explored an emerging cyber insurance model that could transfer vendor-specific residual risk through contract-specific insurance policies.
Discussion Pod #3
Former Chief Information Security Officer, SolarWinds
Current Partner at Team8 VC
When the SolarWinds SUNBURST attack became one of the most consequential cyber incidents in history, Tim Brown found himself leading the technical response while simultaneously navigating an unprecedented personal legal battle. As the first CISO ever charged individually by the SEC—a case ultimately dismissed—Brown offers a candid, deeply personal account of what happens when technical, business, legal, regulatory, and human crises collide.
Rather than focusing on the attack itself, Brown examines what follows: building cross-functional crisis teams, communicating under extraordinary uncertainty, managing boards, customers, regulators, media, and law enforcement simultaneously, and maintaining leadership while facing the possibility of losing both career and reputation. He also reflects on how the incident reshaped Secure by Design initiatives, software supply chain security, executive accountability, and the evolving role of today’s CISO.
This session is less about SolarWinds and more about what every security executive should understand before facing their own defining moment.
Discussion Pod #4
Founder & CEO, Opti
Barak Perelman challenged attendees to rethink identity governance for the AI era, arguing that today’s Identity and Access Management (IAM) platforms were designed for a workforce of human users—not AI agents, non-human identities, and increasingly dynamic enterprise environments. Drawing on interviews with nearly 100 CISOs and CIOs, he observed that most identity teams remain overwhelmed by manual processes, professional services engagements, and repetitive operational work, leaving little time to reduce actual risk.
Rather than layering generative AI onto legacy IAM platforms, Perelman advocated for purpose-built, AI-native identity models capable of understanding entitlements, context, business roles, and access behavior. He argued that the goal of AI should not be to replace security professionals, but to eliminate the repetitive work that prevents them from focusing on governance, risk, and business enablement.
The discussion also highlighted the growing urgency created by AI agents and non-human identities, which are rapidly expanding the identity attack surface while exposing the limitations of today’s governance models.
Start-Up Showcase #2
Casper Neo presented a novel approach to one of cybersecurity’s most persistent challenges: identifying when users with legitimate access begin behaving in ways they should not. Drawing on technology he developed and deployed at Google, Neo demonstrated how deep recommendation models—the same techniques that power platforms like YouTube and TikTok—can learn what “normal” access looks like across an enterprise and identify anomalous behavior without relying on static rules or manually maintained detection logic.
Rather than asking whether a user has permission to access a resource, the model predicts whether they should be accessing it based on historical patterns, organizational context, and continuously evolving behavior. The approach enables security teams to prioritize insider threat investigations, identify excessive entitlements, and surface suspicious activity from millions of legitimate access events with remarkably low alert volumes. Research presented at Black Hat and accepted for USENIX Security demonstrated strong results when evaluated against simulated insider attacks at Google.
I welcome your input on this article… please do that via the summary LinkedIn post on this same topic!