
The cybersecurity industry is flooded with breach headlines, each one reinforcing the narrative that attackers are winning. For chief information security officers, the pressure to demonstrate control while enabling business innovation has never been higher. Engineering teams across enterprise IT are writing their own software with AI coding assistants, spinning up agents that act on their behalf, and assigning those agents the same access privileges their human creators hold. This shift has pulled the role of the CISO into territory that did not exist two years ago.
The AI Agent Revolution and Its Security Implications
Speaking at the Span Cyber Security Arena conference, Hrvoje Englman, CISO at Span, described how this transformation is changing what defenders worry about most. Span’s workforce includes a sizable population of developers alongside a larger group of engineers. The engineers are the new variable. With AI-assisted coding, they are building applications and personal agents to automate parts of their own jobs. Each new agent inherits the identity of its creator, and those identities are typically over-provisioned. Least privilege remains an aspiration that is hard to enforce in production environments.
"I cannot be the blocker," Englman said. "You cannot block progress. People will find ways around it." His priority is enabling secure use of AI inside the company rather than prohibiting it. This pragmatic approach reflects a broader industry shift from blanket bans to risk-based enablement. As AI tools become more accessible, the traditional security model of gatekeeping and approval workflows is becoming untenable. CISOs must find ways to embed security into the development process without slowing down innovation.
The Bus-Factor Problem Multiplies
The risk extends beyond access control. When a single engineer automates a business process using five interacting agents and then leaves for another job, the organization inherits an undocumented system that nobody understands. Englman called this an inversion of the traditional bus-factor problem. Previously, a key person leaving created a knowledge gap. Now the agents they built keep running, and the company has no record of what they do or why. This phenomenon is exacerbated by the velocity of AI development: agents can be created in minutes, tested informally, and deployed without any formal change management process. The resulting shadow IT landscape is far more complex than anything security teams have dealt with before.
The implications for audit, compliance, and incident response are profound. Without visibility into which agents exist, what data they access, and how they interact, organizations cannot effectively assess their risk posture. Englman emphasized that traditional asset management and configuration management databases (CMDBs) are inadequate for tracking ephemeral AI agents. Security teams need new approaches to discover and monitor these digital workers, potentially leveraging AI itself to map agent behaviors.
Defender’s Leverage Is Real, with Limits
AI has produced concrete gains in defensive work. Englman pointed to log analysis as one area where the value is immediate. Feeding hundreds of megabytes of log files into an AI tool and asking it to surface anomalies or pivot on an IP address compresses work that previously took analysts hours. Policy drafting is another use case. Generating a first draft from internal context can cut a three-day task to a single day, and the time savings compound across a workforce. These productivity gains are allowing smaller security teams to handle workloads that would have required significant headcount growth just a few years ago.
However, Englman drew a sharper line on the vendor pitch for autonomous AI-driven security operations centers. The idea of defensive AI battling offensive AI in real-time, with no humans in the loop, does not match what is achievable now. Log ingestion remains the hardest part of running a SOC, and detection engineering still depends on people who can explain why an alert fired. "You get an alert, but your analyst doesn’t understand the alert," Englman said, describing the failure mode he sees in teams that lean too heavily on automated tooling. "And you have two million alerts, and then what?" Autonomous isolation of systems remains out of reach because the AI does not understand the business process. Decisions about when to shut down a critical service get escalated to senior leadership during real incidents, and that judgment stays with humans.
Englman also pushed back on the industry framing of breaches. Most of the largest incidents trace back to phishing and credential theft. Vendors selling AI-powered SOCs as a defense against nation-state actors are addressing a smaller part of the problem than their marketing suggests. The fundamental security challenges—identity management, patching, and basic hygiene—remain the same, regardless of how advanced the AI hype becomes.
The Threat Model for a Services Provider
Span sells IT services to enterprise clients, which doubles its exposure. The company is a target in its own right and a target for attackers seeking access to its customers. A typical end-user organization can absorb a breach and recover. For Span, the response itself becomes the product on display. Englman said the company has to be able to demonstrate that controls were in place, that the failure was contained, and that the incident was handled with the same discipline it offers customers. Reputation is what gets sold, and negligence would end the business. This high-stakes environment forces Span to maintain a level of security maturity that many organizations only aspire to. It also means that every security decision is scrutinized for its potential impact on customer trust.
The services provider model also demands transparency. Clients need to see that the security team is not just compliant but genuinely proactive. Englman’s approach includes regular third-party audits, continuous monitoring, and a culture of incident simulation. He believes that the best way to build confidence is to show, not just tell, how the security program operates.
Skills Shortage, Restated
The widely discussed cybersecurity talent gap, in Englman’s view, is misframed. Entry-level applicants are abundant. Senior practitioners with five or more years of operational depth are scarce, and that gap cannot be closed quickly through training programs. The Span Cyber Security Center has trained more than 3,000 people, and Englman said the pipeline matters precisely because the industry’s push toward automated tooling threatens to eliminate the junior roles where future experts get built. His measure for a SOC analyst centers on whether they can explain what the alert means and how the conditions that triggered it came about. Without that understanding, an analyst rolling a fifty-fifty guess on relevance is no better than a model doing the same.
Englman advocates for structured apprenticeship programs that pair junior analysts with experienced mentors. He warns that over-reliance on AI tools can create a generation of security professionals who can operate dashboards but lack deep technical understanding. The goal should be to use AI to augment human decision-making, not replace the foundational knowledge that comes from hands-on experience.
The Wisdom He Has Discarded
Asked which piece of conventional security wisdom he has stopped believing, Englman named the framing of humans as the weakest link in the chain. He called it lazy and a form of blame culture. The responsibility, he said, sits with the CISO to build systems where a user clicking a malicious link does not bring the environment down. Brittle defenses that depend on perfect human behavior are a design failure. This perspective aligns with modern security thinking that emphasizes resilience, defense in depth, and user-centered security design. Instead of punishing users for mistakes, organizations should invest in controls that reduce the blast radius of inevitable errors.
Englman’s philosophy extends to how Span handles phishing simulations. Rather than focusing on failure rates, the team looks at how quickly users report suspicious emails. The measure of success is not zero clicks but rapid reporting and coordinated response. This shift from blame to enablement has improved both security outcomes and employee morale.
Source:Help Net Security News
