Skip to main content
Episode 06/33 min

Five Over the Speed Limit: Who Actually Owns AI and Cyber Risk?

Chad Lorenc

Global CSO & Board Director · Security Practice Manager, AWS

Chad Lorenc

About This Episode

Jason Lee sits down with Chad Lorenc, Global CSO, board director, and Security Practice Manager at AWS, on the turf war between the CTO, the CIO, and the CISO over AI governance and cyber risk, and who is actually accountable. Chad has held the CTO seat at a startup he founded, built a bank's security program from scratch as an early CISO under Gramm-Leach-Bliley, served as chief architect and deputy CISO at a Fortune 500, and now advises Fortune 500 security leaders on cloud and AI security strategy.

They get into who actually wins when the C-suite disagrees and why it is rarely the person who is right, what a well positioned CISO looks like when the reporting line runs through the CIO, how shadow IT cracked the CIO's hold on the business and cloud migration split the CIO and the CTO into a slow secure camp and a fast less secure one, whether the chief AI officer is a real role or another hat on top of a hat, why data hygiene is the first pain point in AI and why the chief data officer never actually owned the data, the case for elevating the CISO to a true CSO who owns AI, why nobody buys least privilege and how to sell the business outcome instead, the Visa negotiation that bought years of credibility, the four CISO profiles, the first question boards should be asking before they write an AI policy, and the one thing Chad wishes boards understood: you are already using AI.

The most dangerous drivers on the road are actually the ones that go five to ten under the speed limit. I want to be in a car with a CISO that's going about five over.

Chad Lorenc, Security Practice Manager, AWS

In This Episode

  • 01The winner is rarely the person who is right. When the CTO, the CIO, and the CISO disagree, the one who wins is the one tied closest to business outcomes and speaking a language the executive staff and the board understand. Trust, not the org chart, resolves the conflict.
  • 02Drive five over the speed limit. The most dangerous drivers are the ones going ten under, and a CISO is not there to avoid risk but to take the best calculated risk. Say no rarely enough that when you do, the business knows it really means no.
  • 03Cloud did not create the CIO versus CTO split, shadow IT did. IT matured into a cost center wrapped in red tape, the business routed around it, and the office of the CTO was set up to move fast. That chasm between slow and secure and fast and less secure never closed.
  • 04The chief AI officer owns everything and nothing. Like the chief data officer before it, the role collapses into governance, because AI is now embedded in every app and the real work is data hygiene and access. That work looks a lot like the CISO's job, which is the case for elevating security to a true CSO who owns AI.
  • 05Nobody buys least privilege, and transparency comes before policy. Sell the business outcome the control enables, tied to the market share the board is already counting on. And before a board asks whether it has an AI policy, it should ask whether it can see where AI is already being used, because it already is.
Chad Lorenc

About the Guest

Chad Lorenc

Global CSO & Board Director · Security Practice Manager, AWS

Chad Lorenc is a Global CSO and board director, and a Security Practice Manager at AWS, where he works with senior leaders on operational security strategy for AI and the cloud. Across 25 years he has founded a startup and served as its CTO, built a regulated bank's security program from scratch as an early CISO, served as chief architect and deputy CISO for a Fortune 500 with security implementations spanning three dozen countries, and advised more than twenty Fortune 500 CISOs on cloud security strategy. He is the primary author of the Crawl, Walk, Run cloud security maturity framework and has trained thousands of executives and board members on incident response, AI governance, and SEC disclosure.

Follow the Show

The Blind Spot

Cybersecurity conversations on what happens after the risk is visible. Subscribe so you do not miss an episode.