Skip to content
04Personas/ Security

CISO

Owns the runtime floor: what gets screened, logged, and stopped.

You are accountable for
  • A screening minimum no team can drop below
  • AI assets inside security posture management, not beside it
  • Prompt injection, data leakage, and now agentic attackers
What keeps you up at night
  • A zero-click exfiltration through an AI assistant (the EchoLeak shape)
  • Shadow AI and shadow agents holding live credentials outside any review
  • An incident with no reconstructable trace of what the AI did
Decisions you own
  • Set the org-wide runtime screening floor and own its change control
  • Extend posture management, detection, and IR runbooks to AI and agents
  • Decide the logging posture: what is captured, redacted, retained
Questions you should be asking
  • What screening covers apps that never talked to the platform team?
  • Can we replay any AI interaction end to end for forensics?
  • Which agents could an attacker reach through content they control?