Security leaders are being asked to govern a risk surface expanding in two directions at once.

AI governance has risen rapidly up the CISO agenda while threat pace is accelerating around it.

Inside the enterprise, agents are gaining more access, authority and ability to act; outside it, attackers can identify and combine weaknesses faster.

Opening ADAPT’s 13th Security Edge in Sydney, Joey Meynink, Head of Strategy at ADAPT, framed the challenge around machine-speed risk from the outside and greater autonomy on the inside.

More than 140 cyber, risk, compliance and architecture leaders explored how security can strengthen control, accelerate response and prepare the wider organisation for more autonomous operations.

CISOs now face decisions about where controls sit, which actions require human intervention, how fast vulnerabilities can be closed and who remains accountable when AI influences business outcomes.

Architect trusted autonomy around actions and consequences

Half of AI tools in pilot or deployment are outside a formal governance framework, increasing the likelihood that security teams discover access, identity and data risks after systems are already moving towards production.

Gabby Fredkin, Head of Analytics & Insights at ADAPT, showed how the governance conversation is moving into model visibility, shadow AI, agent access and real-time monitoring.

Organisations with stronger governance maturity build those requirements into architecture earlier, allowing security and risk controls to move with deployment.

The gap remains substantial.

Only 7% of CISOs have defined controls and ownership in place for governing AI agents and non-human identities, with large enterprises performing just as poorly.

Identity, data classification, observability and decision boundaries need to remain visible as agents move across systems and interact with other agents.

Scott Brown, CISO at Rio Tinto, drew on the company’s long experience with autonomous mining operations, where teams considered fault states and safety consequences from the outset.

He also argued for governance frameworks that can accommodate multiple models as providers, capabilities and economics change.

This gives security a durable control point around what an autonomous system can do, what happens when it fails and how control is recovered.

Colin Renouf, CISO at Healius, focused on explicit boundaries and recoverability, including grounding models to approved information sources and designing agent environments so another system or person can take over when required.

Matt Boon, Senior Research Director at ADAPT, brought the operating model gap into focus, calling for organisations to inventory AI already in use, build governance into architecture and pressure-test agent chains before production.

He also pointed to fragmented operating models as a growing security barrier as AI increases the need for tighter coordination across security, technology and business teams.

As autonomy scales, governance needs to follow the full chain from identity and data access through to action, consequence and recovery.

Back to top

Accelerate vulnerability operations as threat pace rises

Threat pace has jumped from the #8 barrier facing CISOs to #3 in a single research wave, while cyber resilience now ranks as their #2 concern after AI.

Faster vulnerability discovery increases the value of triage and remediation capacity.

Security teams need to identify which weaknesses create material attack paths and direct limited engineering effort towards them quickly.

Greg Rattray, former Global CISO at JPMorgan Chase, described the emerging discipline as “vulnerability operations”.

AI can identify chains of weaknesses much faster, pushing remediation expectations from weeks or months towards days and, for critical exposure, hours.

Greg identified prioritisation as the highest-leverage step. More automated discovery can overwhelm security operations unless organisations can determine which findings create the greatest business risk and concentrate remediation there.

Colin described integrating an LLM with security monitoring to learn normal behaviour and accelerate incident response, extending automation already familiar across firewalls and endpoint security.

Keith Howard, CISO at Suncorp Group, described an intelligence-led model built around a consolidated findings pipeline, separating urgent issues from systemic weaknesses that feed into the wider security program.

Priorities are refreshed continuously as threat intelligence changes.

Machine-speed defence requires a shorter path from intelligence to prioritisation to remediation.

Security, engineering and technology operations need shared visibility into the risks that warrant immediate change and enough delivery capacity to close those paths.

Back to top

Build resilience for the day the playbook runs out

Greg urged leaders to identify the digital services most critical to operations, test severe but plausible disruptions and practise restoring them.

Recovery cuts across the CIO, business and operational teams, making resilience a shared enterprise capability.

His work with Ukrainian organisations showed the value of deep operational knowledge under sustained attack.

Teams that understood their networks, data and services could move workloads and replace functionality quickly as conditions changed.

Alex Loizou, Cybersecurity Leader and Managing Director at Intrinsic Security, brought that challenge into the reality of a major public breach through his experience leading security at Medibank during its 2022 incident.

The organisation moved from detecting unusual activity to public disclosure within days, requiring leadership shifts, a trusted “twin CISO” and multiple incident-response partners to maintain decision capacity and confidence in the findings.

Alex separated recovery into immediate remediation and longer-term structural work, with assurance built into both because a major incident creates a trust deficit across boards, regulators, customers and employees.

Maryam Bechtel, CISO at TAL Australia, stressed that relationships across technology, finance, legal, audit, communications and crisis management need to exist before they are tested under pressure.

David Gee, Author, CISO and ADAPT Advisor, reinforced the value of educating senior stakeholders on cyber and AI risk before an incident forces those conversations into a crisis setting.

Resilience needs leadership redundancy, tested recovery paths, trusted executive relationships and communication practices that can operate while facts are still emerging.

Back to top

Share AI accountability across the executive team

AI governance is now the CISO’s #1 security priority and #1 constraint, yet only 2% of CIOs think the CISO should own it.

Security owns critical controls, but AI governance spans the workflows and outcomes managed across the business.

ADAPT research showed that executive teams increasingly look to security for risk mitigation, even as enterprise-wide governance remains immature.

Maryam and Keith stressed shared decisions across the CIO, CFO and business on risk, compliance, enablement and investment, while David highlighted the judgement and problem-solving leaders need as frameworks continue to evolve.

The CISO can set control requirements and expose risk, but accountability for autonomous business decisions must stay with the executives who own those outcomes.

Back to top

Recommended actions for security leaders

Trusted autonomy requires security architecture and enterprise accountability to evolve together.

  • Inventory agents, models and non-human identities. Map what they can access, change and trigger before autonomy spreads further through business workflows.
  • Build controls around actions and consequences. Define boundaries, observability, escalation and recovery based on what an agent can do and the impact if it fails.
  • Move to risk-led vulnerability operations. Use AI to improve discovery and triage, then connect findings directly to engineering capacity that can close the highest-risk attack paths.
  • Exercise recovery beyond the security team. Test major disruption with technology, business, communications and executive leaders, including decision rights when normal playbooks fail.
  • Distribute AI accountability. Keep security responsible for control design and assurance while business, technology, data and executive owners remain accountable for the workflows and outcomes agents influence.

 

Back to top

Can security move at machine speed without owning every decision?

Machine-speed risk will continue shortening the distance between vulnerability, exploitation and response as more enterprise decisions move into autonomous systems.

CISOs need enough visibility and authority to shape that environment, while technology and business leaders need to own the decisions, recovery capability and risk appetite surrounding it.

Security Edge showed that boundary already shifting, with effective defence reaching further across technology and business operations as autonomy grows.

Back to top

Contributors
Justina Uy Content Marketing Manager
Justina Uy is a data-driven content marketer that thrives on democratising elite know-how to empower Australia’s underdogs. Skilled at translating complex ideas... More

Justina Uy is a data-driven content marketer that thrives on democratising elite know-how to empower Australia’s underdogs.

Skilled at translating complex ideas into a compelling story across formats and channels, she shifts seamlessly between writing long-form articles, creating viral social media posts, and producing thumb-stopping videos.

Since 2015, Justina executes her vision through a sophisticated understanding of the rapidly evolving digital and business landscape to serve entertaining and educational insights to the executive community.

Less
security compliance leadership