- Conor Tuohy
Back to the Millennium Live podcast. It's great to have you here and welcome to Q4. I know all of you are busy at work and through the executives that we've had on this podcast, we're going to continue to end the year as strong as we began it with some awesome episodes for you. A cybersecurity one today, you know, as AI adoption and cybersecurity is accelerating, is governance keeping up that pace? And that's our topic for today and this upcoming Millennium Live. episode, features a great guest. We have Chris Cochran. He's the field CISO and vice president of AI security at SANS Institute. And he's here to explore the widening gap between just how quickly organizations are adopting AI and how prepared they are to secure, govern it, challenge it. He's a Marine Corps veteran, former leader at organizations like Netflix, U.S. House of representatives, the NSA. He spent his career you know translating that complexity into clarity and you know whether guiding organizations through emerging ai threat landscapes or shaping the next generation of ai security practitioners this is going to be a great conversation so chris first of all thank you for your service and thank you for joining the millennium alliance podcast yeah what an intro i'll try to live up to it appreciate uh you having me on and looking forward to the conversation amazing and i think this conversation is ultimately asking the that critical question you know as ai moves deeper into business operations are organizations building that governance and security maturity that's needed to continue safely and responsibly so i think a good way to start chris and i want to bring up the 2026 sans ai survey insights that shows that ai adoption security jumped from 50 to 78 percent in a single year the largest move the survey has ever recorded so Did the governance side of the house move anywhere closer to that so fast?
- Chris Cochran
It does not compare to that whatsoever, unfortunately. The hard part is, you know, we started to look at AI as this, you know, solve all for any problem that you could come up with. There was a lot of top-down pressure for folks to start to leverage AI and push it into production. Because there is a competitive advantage when you have artificial intelligence on your side. But the problem is we sort of put the cart before the horse. We started to leverage AI before we could govern it, before we could secure it. But I wouldn't say that's necessarily the fault of anyone in particular. The situation with artificial intelligence is a lot of these technologies are brand new, right? We're sort of figuring things out as we go along. So I would say that folks are starting to warm up. to the idea and the maturity of governance being sort of like the bedrock for any AI program and an organization.
- Conor Tuohy
Yeah, I mean, a great, great point there, Chris. And not only that, but the survey found that 95% of leaders believe attackers are already using AI, which is obviously no surprise there. But only 16% have shifted priority towards defending against AI enabled. threats. And that's while 78% of organizations already saw enabled attacks through AI. So how do you explain this gap between this belief and an action upon it?
- Chris Cochran
Yeah, I would say there's probably a couple of things at play here. One is that there is a belief and there's a bit of truth to the thought that, hey, my conventional solutions, my conventional controls will mitigate a lot of the stuff that's happening. whether it's AI driven or not. And there's a lot of truth to that because it's leveraging a lot of the same stuff that we deal with anyways. The changes that I see that we're dealing with right now are mostly from the standpoint of scalability, right? Now attackers are able to scale much better. The barrier of entry is much lower, but it's largely a lot of the same attacks. But what I would have to say is that I think that That is probably changing. I think folks are starting to understand that the world is changing, the threats are changing, and we're going to have to take steps in order to mitigate this impending storm that we might be dealing with. And I think a lot of it deals with, honestly, the fundamentals and going back to the basics. And so when you think about, hey, how do folks start to prepare? I think it looks less like AI. I think it looks more like good general practices. But I do believe that there is going to be a little bit of a fight fire with fire as things develop and grow.
- Conor Tuohy
Couldn't agree more with you. And, you know, you're quoted in that survey giving a very specific 90-day sequence, and that's name an owner, inventory tools, write a one-page policy, brief the team, and then reassess. That moves most organizations from stage one to stage two. Now, why does that simple sequence work when so many governance efforts continue to stall?
- Chris Cochran
I would say it really comes down to one concept and that's ownership. And I mean, if you think about any initiative, any program that you're building inside of cybersecurity or any organization, it really comes down to having an informed captain to help make decisions. They're the ones with the context. They're the ones that are driving this initiative forward. Whenever you say hey everyone owns x no one owns it so then there's a lack of intentionality. And so whenever you have someone, hey, you are the informed captain, you set forth what this whole thing looks like for the organization. And then you put it on paper and you say, hey, this is where we're starting, right? This is the starting point. I think that's the sticking point for a lot of people. They just don't know how to start. And if you can make that first baby step, it's almost like, hey, I want to get in shape. The hardest part is probably that first workout, right? It's that first run. It's that first time to the gym. But once you start that momentum, it's easier to carry that momentum into maturity.
- Conor Tuohy
Absolutely. Yeah, I mean, with any work, right, as soon as you get into it, then it's much easier to continue.
- Chris Cochran
Exactly.
- Conor Tuohy
But continuing on here, I mean, with some of this data here, 63% of practitioners now report significant shortcomings in AI threat detection. That's up from 45% last year. Two thirds say AI has misled their team at least once. So is that a sign, Chris, that the technology is getting potentially a little bit worse or is it or it's finally being just actually tested at a real scale?
- Chris Cochran
Yeah, I would say there's a huge adoption for AI and people are starting to realize that AI is not perfect. Right. There are shortcomings. There are things that AI does really well. And then there are things that it doesn't do well at all. And so it's really about understanding, number one, what the technology is. I think the more people learn about how the technology actually comes about, like how did it come to be, right? I think some people have this misconception that someone coded all of these responses into a solution. And that's what you have your chatbot or your agent is doing. But when you realize that it's something that's grown. when you realize that you really can't see deeply into the mind of a model, when you learn that there are things like deception and misalignment, you start to realize, hey, maybe we have to be, number one, careful about what roles we give AI in our organization and in our processes. But then also, what are the mechanisms and the mechanics around being able to control and monitor to make sure that we aren't pushed in the wrong direction? And then finally, because we know. AI has hallucinations. So now we know that, hey, if I'm going to get an answer from AI, I want it to show its work. I want to show where the sources of its information is coming from, so that whenever I get an answer and I need to use this answer to make a decision, take an action, or even brief a team, I'm able to go back to the source itself to make sure that, hey, this is actually what's occurring and not something that AI seemed to dream up that day.
- Conor Tuohy
Absolutely. And, you know, you introduced the principle of least agency as the agentic version of least privilege in the AI security maturity model. And if I'm on a leadership team, you know, how should we decide whether their business problem actually needs an autonomous agent versus perhaps maybe just a simpler tool?
- Chris Cochran
Yeah, I love that question. I love it because when I'm thinking about how do I solve something, right? In the very beginning, we sort of touched on how we started to use AI as everything, right? Like a silver bullet. It was a solution that started looking for a problem. But when you realize like, hey, you know, if I'm trying to solve a solution, I want to solve it with the least amount of movable parts. Because that's when you start to run into trouble. So if I can look at something like standard classic automation and use that. right? It's deterministic, right? I'm not dealing with a probabilistic technology like AI, and I can put it on rails and it just works every time. I'd rather go there. Now, there are always going to be those use cases where AI is probably the best solution. But if I can use something that's just as simple as possible, I'm going to go that route rather than making it a little complicated.
- Conor Tuohy
Totally, absolutely. I mean, great points, Chris. And, you know, thinking to hear about, you know, deepfakes, AI-assisted exploitation, AI-generated phishing, and they're all clustered within a few points of each other in these observed attacks. What does it mean for the defenders, you know, that adversaries aren't learning on one favorite AI technique, but, you know, spreading it across the whole kill chain?
- Chris Cochran
Yeah, I would say it's similar to how we operate, right? We didn't just say, hey, we're going to just apply AI to this aspect of cybersecurity. We didn't say we're just going to apply it to this aspect of business. Very similar to us, they're starting to look at, hey, what are the different ways we can use AI for our operations? And so, I mean, they're going to get to a point where they're trying to completely automate entire chains, right? We've seen extortion operations that were automated. And so the more they see the utility, the more they see the scalability of AI, they're going to start to leverage it, whether it's for using deepfakes for, you know, wire transfer fraud or whether it's to use it for phishing emails and phishing campaigns. They're just going to start to look at all of these aspects. And then not only that. You're starting to see the commercialization of even the AI side of things from a cyber criminal standpoint. They're already, you know, they have those phishing platforms where someone can pay to rent that platform for a certain amount of time and start to do some of those operations. And so not only do you have the folks that are just doing it for nation state or espionage reasons, you have cyber criminals, you have folks that just want to see the world burn. I mean, and everything in between. And so you're going to see very different flavors of attacks and consistency across the board. And I think it's only going to become more consistent over time.
- Conor Tuohy
So, I mean, the survey shows that top defenses against AI-enabled attacks are behavioral detection and user awareness training, not AI-specific tools.
- Chris Cochran
Right.
- Conor Tuohy
Do you think... Do you think that suggests that organizations perhaps are overinvesting in AI versus AI, fighting AI with AI or underinvesting in fundamentals?
- Chris Cochran
Yeah, I would say it's probably a combination of both, I think. And then again, I mean, if you go to any conference, you'll see a monumental amount of marketing around. we have the AI thing to help save your team time, save your team money and heartache. And some of those claims are legitimate. But I think when we start to look at ourselves, if we really have a good hard look at what are the things that we probably need to improve on, I can probably venture to guess that most folks listen to this. If you're a security leader, there's probably room to improve things like asset management or identity, whether you're talking about workforce identity, non-human identity, agentic identity, things like the incident response process. I mean, all of these little things are problems that we've been dealing with since forever. And if you don't have it to a point where you feel like, hey, we're at an 85 or 90% level of maturity in those things, there's a lot of value there that you can squeeze out of that. If you jump... to leveraging AI to help, you know, solve some of those gaps. That's great. That's a great use of AI. But if you're going and building your AI processes on top of processes that are broken or outdated or incomplete, it's only going to create more of a headache. So I would say look at the fundamentals first before you start really leveraging AI to the best of its ability.
- Conor Tuohy
Yeah. You know, building off this. that point, Chris. Here's a question that I think could potentially be overlooked, and I'm not sure why. But let's say an AI agent takes an action that causes real harm, such as a regulatory violation, bad decision at scale. Who should actually be accountable? And can most companies you speak to even answer that question today?
- Chris Cochran
Most organizations Probably cannot answer that question, first and foremost. But I really think it's sort of like this weird blended answer, because obviously you have your frontier AI labs and they give solutions to organizations to do their work. It's really ultimately up to the organization that's using the technology to ensure that they are not using a technology that's going to hurt their organization or hurt their customers. But also there is a level of responsibility for the AI labs to understand, hey, if we put this out into the world, we have to do our due diligence to make sure that it's safe and that nothing's going to, or at least we've gone through, put it through the paces. Or we're going to know, hey, this is the intended outcome that we're looking for. Here's some failure modes that we need to think about. And we need to be communicative to our customers to ensure that they understand what are some of the risks and problems they're in. So I think it's a shared responsibility. And I think it's going to become even more of a shared responsibility over time. Obviously, these technology companies, these vendors, they're going to have really... solid terms of use and indemnification clauses. But if you get to the point of negligence, I mean, there isn't really much that those clauses are going to help an organization. But I do think it's a shared responsibility at the end of the day.
- Conor Tuohy
Absolutely. And, you know, the survey also found some real anxiety in the open-ended responses. People are worried about roles disappearing. and being asked to prove AI competence with no clear path to build it. How do you think about supporting a workforce that's being asked to adopt AI faster than it's being trained to or just being trained to challenge it?
- Chris Cochran
I think there's a lot of fear around what the world's going to look like six months, nine months, a year, two years, 10 years from now. And I think the most powerful thing that we can do right now is learn as individuals and then train our folks inside our organization to understand exactly what's going on, both at the micro level of like understanding what the technology is, what it does, the shortcomings, the things that it does well. But then also on the macro scale of like, how is it going to change the way we operate? And I think the more people are informed on exactly how can we leverage this? technology in a positive way? How do we leverage it in a way that's going to enable me to do more with less or to be more effective and more powerful and more scalable? Then I think people will be more excited about the technology. But when they're hearing that there are organizations out there that are looking to get rid of folks, right, they're trying to get rid of entry-level entry-level roles because, hey, we can just use AI to... replace them. I think that's really short-sighted. I think that you really have to understand, hey, if right now you are operating at a scale that you feel like you could do so much more, why not use the technology to do that more? Why would you literally attempt to do exactly what you're doing today with less people? I think that you really need to start to get creative about how are we going to leverage this technology to Thank you. be the best organization that we possibly can be. And I think people also need to look at the technology in that way. You need to look at the technology as something that's a tool, right? Think of it as an Ironman suit that is going to just give you superpowers to do stuff that, you know, was impossible a few years ago. So I wouldn't fear it. I would try to understand it. And the more you understand it, the less you fear it anyways.
- Conor Tuohy
That's a great analogy, Chris. And, you know, I want to put a nice bow on this conversation by kind of just giving, you know, everything that's in this amazing 2026 survey, which, you know, adoption up 28 points, failures are up, governance is essentially flat year over year. Where do you think the average organization actually sits on your five-stage maturity model right now? And honestly, I mean, for a leader who hears all this and realizes they're on stage one still. What's that one move that you tell them to make even this week before anything else that could really help them out and get them ahead of the game?
- Chris Cochran
Yeah, I would say most organizations that I work with are usually in that one to two stage. I have a handful of organizations that I work with that are at that three level. And then there are few and far between that are pushing into that four. I would say the main thing that they can do is... get everyone on the same page. have an AI governance council, or even just have that single person that is the informed captain for artificial intelligence in the organization. Because when you think about AI, AI governance, having a council, it isn't just a cybersecurity thing. It isn't just an IT thing. It's actually an entire organizational process because every aspect of business can be influenced or leverage artificial intelligence. And so when you have Folks that represent these different aspects of the business come together. You can have a common lexicon. You can have communication of, hey, this is what we're trying to do. Then IT can help you figure out exactly how do you implement it? How do we make this a reality? And then security can inform you on the risks and make sure that, hey, let's do this in the safest, most risk, you know, mitigating way possible.
- Conor Tuohy
Chris, thank you so much. I've learned a lot in our... executive audience has certainly learned a lot. You know, thanks to our partners over at SANS Institute for just having this great survey that it was the base of our conversation today. And Christy, you know, examining this rise of AI-enabled attacks and workforce readiness, accountability for autonomous systems, you know, all these things that could lead leaders to create action. and move from ai government's uncertainty towards meaningful action uh chris you have a great career and you're certainly helping build uh the future when it comes to ai systems and making them both powerful and safe so i thank you for your time please come back on the podcast anytime you'd like you're you're a great conversationalist and would love to learn even more absolutely connor i appreciate the invite and uh yeah uh hopeful hopefully this was helpful to somebody out there
- Chris Cochran
And, yeah, we're happy. Be happy to come on anytime.
- Conor Tuohy
Thanks for listening to another episode of Millennium Live, your home for executive education.