preloader
Resources

Speak Ya Clout: Straight-Shooting CISOs Trade Real Talk On AI Security With Cisco

RANT Roundtable July 2026

In Partnership With

Language is important. Understanding depends on having a shared frame of reference, and in a field like cybersecurity – littered with acronyms, buzzwords, marketing hype and nerdy tech-speak – communicating critically important ideas requires practitioners, leaders and rank-and-file members of every organisation to be able to speak clearly to one another if problems are ever going to be solved. And at RANT events, we’re always keen to encourage plain speaking: the more down-to-earth the words used, the less chance there is of anyone missing the point.

But still, sometimes the community can surprise us. Such was the case with one – notably droll – contributor to a discussion convened in Manchester by Cisco, who were keen to hear about the challenges organisations are dealing with around adoption of so-called artificial intelligence. It was very early in the evening, and RANT’s guest host – Nnamdi Ozonma, information security officer for the UK and Nordic regions at Bilfinger – had asked what seemed a fairly innocuous, get-the-ball-rolling question. Among those businesses represented around the table that had chosen to adopt AI tools, did their security leaders feel that the organisation had also adopted suitable controls?

   “We’re currently in a phase we call ‘f—ing around and finding out’,” our admirably relaxed CISO reported. There was, of course, a chorus of barking laughter – but, just as evident, a widespread sense of rueful identification with the sentiment, even if the rest of the attendees may have phrased the response somewhat differently.

“It’s moving so fast, and it’s so new, that the only way to know how to secure it is to use it and work it out,” the f-bomb detonator continued. They represented a company with a series of semi-autonomous internal divisions, each able to set its own individual risk-acceptance/risk-avoidance levels, but with one shared security team and a single board overseeing everything. This puts our friend in a somewhat invidious position.

“The mandate across everything is ‘We should use AI and we have to adopt it’,” they said of the edicts issued across the organisation by the board. “It’s measured, and we’re trying to put guardrails in place. We’re letting staff use AI to help with their jobs, but not to export files. To find out how we can benefit, we have to use it.”

This early insight proved to be a key theme of an involving and wide-ranging hour of robust dialogue. How do you securely deploy a technology you can’t understand the security implications of until after you deploy it? But – spoiler alert! – it will come as little surprise to anyone who’s been watching the AI security picture evolve that even as high-level and highly experienced a group as the baker’s dozen CISOs, BISOs and other senior security leaders were unable to unpick this particular Gordian knot.

Who’s Gonna Take The Weight?

“There’s so much enthusiasm from the higher echelons to use it and benefit from it, so experimentation is what we’re all having to do,” another security leader agreed. “But has anyone actually done what you would do if you were carrying out a scientific experiment, which would be to set a hypothesis and then test it?”

Not yet, was the widespread answer. And this revealed another, underlying, potentially more subtly disturbing, conundrum: the benefits of AI deployment are assumed to be so significant that those deployments are not only arriving without tested hypotheses to confirm security, but without even any metrics by which to assess the expected benefits. Board-level FOMO means staff are being encouraged to use AI tools to develop agents to carry out tasks in the hope that benefits will accrue – but without being given a framework against which success can be measured.

   “I think  the issue at the moment is people have a solution but not a problem,” another CISO argued. “There’s the drive, the push, but the use case isn’t there. What are we building these agents for? What are the guardrails? What are the outcomes?”

It isn’t just the benefits that aren’t quantified yet, either – the risks, crucially, are often yet to be adequately assessed, or limits placed on their acceptability.

   “How are we quantifying what’s going wrong? Ozonma asked. “Is it security incidents? Operational value is tangible,” he added, but the implication of the opposite was clear: if security’s success is measured by absence of incidents, then it’s not provable or demonstrable. And when the tools are changing and evolving at such rapid pace, even a successful attempt at conducting such measurements risks being out of date before it’s ready to report internally.

Another option, one CISO argued, is to take a step back from trying to implement technical controls, and to look instead to shore up the organisation on  a more deeply embedded, cerebral level.

   “I wouldn’t go for technical controls,” they said. “I’d want to enhance our culture around use of AI. If you can build a secure culture in how your staff engage with AI, then when things move and change, the culture should give you some measure of protection. It’s harder to build a culture than to write a policy, but that’s where I’d want to spend the money. If you build a culture, you’ll get much more benefit and far fewer problems.”

Soliloquy Of Chaos

Technical controls and pragmatic, use-case-specific restrictions can, of course, be put in place by individual businesses, divisions or departments. These may help to limit risk, although they may also restrict benefits. The trouble, attendees seemed to mostly agree, is there’s no way of knowing in advance where the most prudent place to draw those lines might be. A lack of advice from governments, regulators and other central sources of knowledge and expertise was cited as an issue here – only for one CISO to push back on the assertion.

   “I’m going to disagree that there’s no standard advice,” they argued. “There is: there’s governance. It’s not perfect, and people are often fumbling in the dark. Two years ago it was true that there were no guardrails, but we’ve come a long way since then.

“We’ve got standards we’ve been working with for decades that will work with this,” they continued. “We just have to find out where the gaps are. If we focus on those deltas we’ll get value from our human decision-making.”

“There’s some frameworks, and there are some flaws,” another security leader (partly) agreed. The problem, they suggested, was making sure those frameworks were understood throughout the business, and could be applied uniformly and consistently. The reason this rarely happens is no real surprise: it’s because this technology has users – who, being human, tend to resist being shoved into a limited number of restrictive categories.

“We think we’ve got three types of users,” this leader continued. “There are ones who go, ‘We’ve got to use AI now!’ And then you ask them, ‘What do you want to use it for? And they say, ‘Don’t know!’ Then there’s those who want to use it to speed up their basic daily tasks. But it’s the third type that are the big headache. We used to have colleagues making bonkers decisions but having to go through gatekeepers – and now they’ve got tools they can use to go out and do those bonkers things invisibly.”

Regulations, frameworks and best-practice guidance do exist, Cisco’s solutions engineering manager, Bradley Rossi, noted: but they don’t apply in all instances, and even in the scenarios where they do notionally have an impact, there are gaps.

   “There are things like the European Union AI Act,” he acknowledged, “but there are complete sectors where it doesn’t apply – like healthcare. It’s scary. People want to use AI because it’ll cut waiting lists and get faster first opinions on the results of CT scans – so there’s a push from the public to use it, but no set framework to specify what you’re allowed to do.”

“It’s true,” another veteran security leader lamented. “People have had the opportunity to learn, but in my experience, a lot of them haven’t.”

“A lot of people who are in positions where they could show leadership haven’t learned,” another CISO said. “They’re saying, ‘We must use AI’ and have charged ahead because of what it might deliver, without clearly defining anything, and whilst often shutting down discussion of possible risks.

“Virtually everyone I know who works in a private company who has engaged with AI has a story of someone in their organisation who has done something really bad with it,” they added. “Often it gets caught; sometimes it doesn’t, but things get smoothed over. But everyone I know in a private company knows someone in that position – and that tells me this problem is widespread.”

Moment Of Truth

Cisco doesn’t have a whizz-bang AI-security solution it’s trying to sell. Rossi and his colleague, technical solutions specialist Regan Newman, were keen to highlight the operating concept they call UZTNA – universal zero-trust network access. The last four letters of that acronym – what Rossi calls “the low-hanging fruit” – is stuff that most businesses already do, or try to do. Universalising it, though, “really does change the game,” he argued.

   “With non-human identities involved, and with nation-state interest in some of your intellectual property, you need to be really sure what permissions you’re giving these agents,” Rossi said.

“The whole idea isn’t new,” Newman added. “ZTNA isn’t one thing you can achieve – you don’t suddenly say, ‘Hey, I’m ZTNA-compliant.’ You need to work out what zero-trust means in your environment, and what your priorities are.”

Several businesses represented in the room were somewhere on their ZTNA journey, but the zero-trust element appeared to be tripping some of them up.

   “I think it’s an impossible target,” one leader said. “We can’t get over the line on being perfectly zero-trust. We have very tight controls and we’ve done pretty well in red-team exercises, but it’s not perfect.”

“It’s a myth that you can every achieve 100% perfect zero trust,” another leader agreed. A short discussion followed about what achieving perfect zero trust actually means.

“I think it means that we have a fair level of trust that in most situations, zero trust is going to be effective,” one leader said, carefully. “We have mostly effective controls – by which I mean, our controls are fully effective in most situations. We rely on technological, governance and cultural controls. But there’ll always be things that slip between those.”

“It’s best endeavours, isn’t it?” another CISO suggested.

“Exactly,” Ozonma agreed. “It’s based on the risk tolerance within your organisation. Tomorrow it’s going to change. As security professionals, our job is to consistently make sure we’re providing that level of assurance. Fundamentally, everything we do is based on risk management. Is it acceptable, tolerable, or a flat-out ‘No’?”

Which seemed to bring us back to where we came in, and the need to experiment. Also, Newman suggested, the need to share the results of those experiments.

   “Don’t let this knowledge be kept exclusive,” he said. “Leverage each others’ experience: there’s lots of lessons to learn. That f—ing around and finding out? There’s plenty that can be learned from that experience.”