Ransomware, shadow AI, autonomous agents, and quantum computing are landing on the CISO’s desk at once, and few security leaders feel ready. Volker Rath, Field CISO at Cloudflare, believes the answer lies in changing how organizations think, not only in buying more tools.
In this conversation with ET Edge CISO Forum, Rath argues that AI has not changed what a ransomware attack is, but it has made the early stages faster, cheaper and far more likely to succeed. He says policy documents alone cannot serve as guardrails for AI agents or shadow AI, because they leave the conflict of interest in place. Governance, he says, must sit with a separate party.
He also makes a case for mean time to patch as the one metric that matters. He warns that quantum readiness is already behind schedule and explains why Zero Trust must now cover machine identities and AI agents. Compliance, in his view, is only a baseline.
His advice to leadership teams is direct: bring the CFO, CIO, CTO, and CISO into one room, challenge the status quo, and plan backward from the future.

CISO Forum: Ransomware groups are now using AI to accelerate reconnaissance, phishing, and negotiation. From your seat at Cloudflare, how has ransomware sophistication changed in the last 12 to 18 months, and is Shadow AI within enterprises making this worse by expanding the attack surface without anyone realising it?
Volker Rath: The attack vectors threat actors use to target their victims have changed in the last 12 to 18 months, and ransomware is no exception.
Has the fundamental concept of a ransomware attack changed? Probably not! What AI has changed is threat actors’ ability to do two things.
One is the ability to scale and orchestrate attacks. They can now combine different vectors and mechanisms in a fully automated way.
For an attacker, the first goal is always to compromise an identity. This is how you drop a workload and get credentials. This is typically the first step: compromising an identity.
Compromising an identity also means making somebody click something, and then ransomware takes its way. You could do this in many ways: email, WhatsApp, LinkedIn, SMS, voice, video meetings, everything.
We needed whole call centres in the past and outsourced this to operators at scale. Now, with AI, these early phases of the attack chain can be fully automated. Therefore, the likelihood of success is increasing significantly.
If the likelihood of breaking in increases significantly and you can orchestrate attacks using AI, you accelerate the attack and increase its impact. Ransomware is no exception.
What we’ve seen is that we typically talk about ransomware and then we talk about double extortion. First, you pay to decrypt the data, and then you pay again because they say, “Hey, by the way, we also stole your data, so pay me again.”
And now there even is a concept of triple extortion, to say, “Well, you pay twice, but we will launch a DDoS attack. We will take your business away. You need to pay again.”
Which ultimately tells us: paying money is never, never, never a good idea. You cannot trust these people, and there is no trustworthy deal with a cybercriminal today, especially if it is completely AI-orchestrated and triple extortion is part of the AI agent’s DNA against you.
Another point is shadow AI. It is linked to this topic, but only slightly.
I would say it doesn’t really increase the risk of a ransomware attack because it’s a very different thing. Keep them separate if they are separate.
The controls to protect yourself and make yourself more resilient to ransomware attacks are often different. They overlap, of course, but they differ from the controls you would implement to address shadow AI.
Ransomware is an attack. Shadow AI isn’t. Shadow AI is a risk that hasn’t materialised, whereas ransomware has. But shadow AI also increases the risk of data loss and of people engaging with shady sources on the internet, which is often an early step in an attack such as ransomware.
CISO Forum: Employees experimenting with unsanctioned AI tools has become one of the fastest-growing blind spots for CISOs. What does a realistic Shadow AI governance framework look like in practice? How do you give security teams visibility without simply banning tools and pushing usage further underground?
Volker Rath: People addressing this question may say that security, compliance, risk management, businesses, and developers all need to act.
AI is like the invention of the mobile phone. Once the genie was out of the bottle, it was unthinkable to go back. It does not make sense to ban it entirely, because that would shield us from reality. It is not just a gimmick with a temporary effect. It is changing the world and changing businesses. Security and compliance people need to become business enablers.
The way to do this is first to be aware of your risk appetite. If you are a small startup developing a video game that doesn’t deal with sensitive data, with a focus on speed of innovation and a fast go-to-market time, constantly changing features are a top priority. You may be perfectly fine, from a compliance and security perspective, to use every AI out there. You may not be fine from a cost perspective.
Because when we talk about risks, we need to talk about governance domains. You were hinting at a governance framework. Governance is not a single thing; it encompasses multiple domains. Security and compliance are just one domain.
There is reliability and resiliency. There is operational resiliency. There is performance. There are operational efficiencies. There is cost efficiency and cost management.
While I can be perfectly fine on the compliance side, I can be totally not fine on the cost side. If I want to achieve business outcomes, I need to operate within my tolerance levels across all of these domains. A governance framework should cover all of these domains.
When it comes to controls, we are talking about what kind of controls we are putting in place. That is why you put a governance framework in place: to identify the need for controls. And when we talk about controls, we are always talking about people, process, and technology.
Security and compliance always go wrong when people think they are primarily technology problems. Everything in IT is people, process, and technology.
We need policies in the first place. The easiest way to prevent risk is for people not to engage in risky behaviour. Training, education, and policies are effective mechanisms for mitigating many risks.
And then, of course, you need to implement controls for visibility and control, which is the next level of governance. Governance is always about visibility and control across all of these domains. And there’s no control without visibility, so you need to start with visibility. Shadow AI visibility must be implemented separately, ideally using a central control point.
What I mean by that is: let us assume you use AI on your mobile phone, on a computer your employer issues, and in one cloud, two, three, or four different clouds as well.
Where do you implement controls? On your phone, on the endpoint, in each cloud, and whatever? It just becomes really, really, really difficult — kind of mission impossible. I think it’s important, especially for AI governance, to consider a Secure Service Edge and implement SASE solutions and centralised control points to provide visibility and control across all your use cases, including shadow AI.
CISO Forum: Most enterprises rushed to adopt generative AI over the last two years; now the harder conversation is agentic AI, where systems act autonomously. What governance guardrails should be in place before an organisation lets an AI agent execute business-critical workflows, not after?
Volker Rath: Guardrails are an interesting concept. Nobody doubts their importance. Yet one colleague, who sometimes runs demonstrations of prompt injection or shows how to circumvent guardrails, coined a phrase: “Guardrails are adorable.”
That is the opposite of effective. Why? AI has many parallels with humans, and one is that we are not good at managing conflicts of interest.
I’ll give an example. You are a top-notch broker at a bank, and you are given a very aggressive profit target. At the same time, you are told, “Hey, by the way, we have our policies. You need to be compliant with these policies.”
Well, if there is a conflict — and there will be one 100% of the time — which way are you going? We know that humans are particularly bad at making the right choices. Guardrails don’t work if you implement them as a policy in a PDF document.
It’s a good thing because it may reduce the risk by 80%, though not by 100%.
If you tell your little child, “Don’t touch the hot plate,” that’s a guardrail. But the child has a conflict of interest. It’s so curious about what’s up there on the stove, what Mama is cooking, and bang — the finger is in there.
The only way it works is to implement guardrails as a governance layer that is not operating with a conflict of interest. Make it a separate party.
I am running this thought experiment with a couple of executives right now. Large organisations are really thinking about this, and they realise that what we have today — the governance frameworks we have — provide a good start. Still, they’re not really ready yet to manage shadow AI separately and AI agents at scale.
My test question is always: think about 10,000 agents running in your organisation. Many of them are running on behalf of someone. Some of these people have already left the organisation, so they’re running on behalf of somebody that doesn’t exist. And some of them are shadow AI.
And the organisation asks you to reduce costs by 20%. Based on which business decisions would you select the agents you want to retire?
Is it security? Is it compliance? Is it performance? Is it total cost of ownership? Is it return on investment? Is it quality? Is it duplication of use cases? Is it business criticality? Dependency on other agents? Are you taking away the hub of a wheel with many spokes? These kinds of things; and most likely, it’s all of them.
Because this is what we do when we make people redundant: we make decisions based on quality. We have a feeling for compliance. We have a feeling for work ethics, for value and price, because we have lots of mechanisms in place to deal with humans.
And with agentic AI, we don’t have that today. And we’re not even thinking about how to stay on top of shadow AI separately at scale.
And this is an area where there is a lot of movement today. I don’t think we have an answer yet that we could call a de facto standard.
We’re all building. It’s all very new. It’s happening very, very quickly.
CISO Forum: The CISO’s role is evolving, enabling secure innovation rather than just blocking risk. Concretely, what does that shift look like day-to-day? Is it about earlier involvement in product and business decisions, a different relationship with the board, or something else entirely?
Volker Rath: Yeah, it’s not an easy time to be a CISO. Over the last two or three years, I’ve heard “CISO burnout” more often than ever. The reason is simple: everything is moving faster. Think about how much cloud computing changed the world. We had to reinvent it, and we also realised there are many afterthoughts we are aware of today. Early cloud adoption, and then we didn’t talk about AI—separate shadow AI. We called it shadow cloud back then, which is still a thing.
Everything has happened very fast, and we need to stay on top of things. Emerging technologies are changing the technology landscape, the threat landscape and, therefore, risk profiles at unprecedented speed. The internet took 12 or 14 years to reach one billion people worldwide. AI took two and a half.
Some of these AI-powered new businesses are moving at a speed, and they’re making money at a speed we couldn’t even think about. So, what’s actually happening is more than a problem for CISOs. We’re dealing with full-on industry disruption.
This is why I run a workshop, and I still do. I run it multiple times with large organisations that are stuck, who think, “I don’t know what’s next.” Well, there are so many options. It’s not that we don’t know what to do technically; everything feels overwhelming. Our strategies are no longer applicable. Some strategies worked yesterday. They don’t work today anymore.
I think, as a CISO, the core principles haven’t changed. The things that worked well in the past also still work, like Zero Trust, threat modelling, ground-zero protection, defence in depth, and all these kinds of things.
But because everything is happening so fast, we need to ensure that security remains a business enabler. CISOs should evolve into a role some people call, and I like it, the Chief Trust Officer. It’s not just securing AI. If you really want to create business value from AI, you need to build trust.
Trust between machines, trust between humans and machines, trust between third parties and whatever. That’s becoming increasingly challenging.
It’s time to challenge the status quo and develop new strategies that work backwards from what is most likely to come, rather than making iterative improvements to what we have today.
The bad guys, the threats, and technology don’t care what yesterday was. They don’t improve a little thing from yesterday. They completely rethink everything and create a new reality.
If our defence and compliance thinking is still stuck in the mode of, “Let’s make the thing we have today a little bit better than yesterday,” then this approach is fundamentally flawed.
CISO Forum: Why do you think cyber resilience has moved from an IT concern to a business imperative discussed at board level? What’s the one resilience metric or capability you think most Indian enterprises still underinvest in?
Volker Rath: It is a boardroom issue. It wasn’t in some organisations, but it is now. I’ve talked to many CISOs who said, “I’m not taken seriously in the boardroom. I’m just this security guy.” I’m not seeing a CISO whose role is viewed by the board as important as that of a CTO, COO, or CFO. That has changed a little, and it’s changing more and more. Mythos accelerated that change in thinking.
At one of the largest banks, I’m now seeing the CEO dictate patch times. We have never seen it like that. Why is a CEO dictating patch time?
They say, “Look, I want you to find all the vulnerabilities first. Don’t let the bad guys. Whatever tools the bad guys are using, use them and find them first. And I give you, for every external-facing vulnerability, 48 hours. I don’t care how hard this is. No excuse. Make it happen.” You have AI, so make use of it. That mandate from a CEO is quite remarkable, which tells us something.
This is a CEO of a large bank who is talking to the big hyperscalers, the big security companies, and the big frontier-model CEOs in the world. After talking to all of them, they realised their risk profile had changed fundamentally.
This time, it’s not like, “Cyber is a nuisance.” This time, we’re dealing with significant risks. Think about it: a bank is a big computer anyway these days.
Something has definitely changed. In some organisations, this change is still happening. It hasn’t happened yet. It depends on the type of business.
If there’s one metric you asked me for, it’s the mean time to patch. And this is a metric, and I will tell you why. What Mythos told us — or what AI Mythos, as a placeholder for AI-powered attacks, told us — is that our protective controls on the network, identity, and application sides — firewalls, identity management, identity protection, application management, WAFs, and these kinds of controls — are less effective.
They are less effective. Period. There is no way back. Faster than ever before, it drills holes in firewalls, drills holes in WAFs, luring us into all sorts of attacks on all sorts of communication channels, and we are more likely to fall victim to these amazingly, unfortunately, amazingly crafted attacks. That is where shadow AI matters most.
Given that protective controls are less effective, Zero Trust tells us that, per the NIST paper, we need to fall back on and operate under an assumed state of compromise. Respond faster. And the most powerful cyber weapon has always been the zero-day, because the zero-day is the universal key to the kingdom. Therefore, I agree with this CEO: we need to respond not just when someone finds a vulnerability.
We need to proactively use AI harnesses, like the ones we posted on the Cloudflare blog. We need to utilise AI-driven tools to perform vulnerability management and patch faster before the bad guys find it. Because ultimately, what they’re doing is not magic. We can do the same magic. It’s just a question of whether we do it or not. If they can find vulnerabilities, we can find vulnerabilities. And that’s the mindset that needs to change. We need to separate shadow AI from the AI we use defensively.
CISO Forum: Quantum computing capable of breaking current encryption is still likely years away, yet you advocate preparing now. What should a CISO’s post-quantum roadmap actually contain today: inventorying cryptographic assets, testing quantum-safe algorithms, something else, and what happens to organisations that wait?
Volker Rath: The question suggests that when you say “years away,” which I hope is right, we still have time. I disagree for a couple of reasons.
We are talking about the development of what we call cryptographically relevant quantum computers. It’s a mouthful: cryptographically relevant quantum computers.
That means we will have computers based on quantum principles that can run algorithms like Shor’s algorithm, which can crack current encryption standards.
What’s vulnerable is encryption in transit, right? So, like TLS and HTTPS. That is a problem. Encryption at rest is less of a concern.
But if encryption in transit, which is all the traffic on the internet, is vulnerable, we are in trouble. So, what is the risk?
Yes, you could say it’s not available today, so why should I be concerned? Well, there are two reasons. One is “harvest now, decrypt later,” which may matter for some use cases. If you have highly sensitive information, such as health data, it will remain valuable for a long time. Health information is the most valuable and longest-lived on the black market.
Therefore, “harvest now, decrypt later” is potentially highly profitable for the bad guys. The other thing that we are dealing with is that cryptographically relevant quantum computers may be available by 2030, according to NIST. Not long ago, we thought it was 2035. So, we cut five years out of that roadmap.
Cloudflare, Google, Microsoft, IBM — they are now engineering against 2029. They are bringing it even further forward. It’s 2026 now. So, why this urgency?
There is a risk you can imagine: such a quantum computer would be an unbelievable cyber weapon. Once it is ready, it may not be published for some time, and nation-states may use it while keeping it under wraps. So, we won’t know exactly when this attack capability is available. That’s what we need to prepare for. And 2029, I think, is what we should aim for.
Therefore, when you think about upgrading infrastructure at scale, especially network infrastructure at scale, it is incredibly hard. There are so many devices that make up local area networks and wide area networks.
So, I would say, no, it’s not years away. I think most organisations are already behind and should start with their post-quantum readiness roadmap.
The easiest way for your origin server to become quantum-ready is, for example, to put it behind Cloudflare. Cloudflare is quantum-ready today. But this requires a deeper conversation about what that actually means.
Apart from encryption at rest, we also need — and we plan to upgrade by 2028 — to upgrade certificates.
Certificates are used for authentication. They also need to be quantum-ready. It’s quite a complex problem space. And I highly, highly, highly recommend everyone who reads this to start their post-quantum readiness journey now.
CISO Forum: Enterprises running workloads across AWS, Azure, GCP, and private cloud often end up with fragmented security postures and inconsistent policy enforcement. What’s the most common multi-cloud security mistake you see, and how should organisations think about consistent control across environments without slowing their cloud strategy?
Volker Rath: The problem space is people, process, and technology. Start with people: large organisations now run on multiple cloud platforms, and they often underestimate the expertise required across them. These clouds have different APIs, logs, platforms, and cloud-native controls. There is no feature parity. It’s a mess. And yes, some experts can cover three clouds; most cannot.
If you’re an incident responder, you need to know Google Cloud, Amazon, Cloudflare, and Azure. It’s really, really hard to deal with all of that. That’s the people aspect.
From a security perspective—from a CISO perspective—the other aspect is controls implementation: which controls should you choose? This is not easy. Clouds have cloud-native controls like AWS GuardDuty, for example, or others, which are really, really good. I can highly recommend using them.
But with other controls, the question is: should I use a cloud-native control in each cloud, or a centralised control that covers all clouds? Should I keep shadow AI separate from these controls?
Many organisations consider this solely from a cost perspective, which is a big mistake. Managing the same controls three times across three clouds, with three different solutions and no feature parity, creates a very inconsistent and immature cybersecurity approach across your clouds.
You may have this in one cloud, but not in another. I’ll give you a highly simplified example. There are malware detection capabilities in all three clouds. Azure has malware capabilities that already delete a virus on an endpoint. AWS’s malware capabilities are detection only. That’s not a problem per se, because I can engineer against that and cover it with other things.
But ultimately, I cannot monitor them together. I cannot use the same incident response process for all of them. Some need engineering to make these controls fully effective in detect, protect, respond, and recover. Others are nearly there.
That, at scale, is an absolute mess. And a mess is not only expensive. A mess introduces complexity, friction, and inefficiencies. That is the last thing you want in your cyber defences, as attack vectors become faster and more agile.
Organisations are increasingly leaning toward centralised controls, consolidating security solutions, and adopting security platforms such as Cloudflare. This lets them see the benefits that, yes, they may not always have the best control in the world — the best-of-breed approach — but they gain full integration, feature parity, and much easier automation of response processes.
I have less training, fewer technologies to oversee, and fewer log sources and log formats. The list is endless. My advice is to have a good decision framework for when you want a third-party platform security controls perspective, when to use cloud-native controls, and to keep shadow AI separate.
CISO Forum: Zero Trust has been an industry buzzword for years, but you argue it’s more critical than ever now that those AI agents—not just humans—are accessing systems and data. How should the Zero Trust model evolve to account for machine identities and autonomous agents making access decisions?
Volker Rath: This is one of the most important questions we’re dealing with in AI right now. Zero Trust has served us well, as articulated in the original NIST paper from 2010. The core Zero Trust principles have proven sound. We need machine-to-machine interaction because, without trust, there’s no business and no interaction.
If we don’t solve this trust issue, we will fail in many ways. As you write, it’s not just a buzzword. Zero Trust is probably the most bastardised term in the industry, so we need to be very careful when we talk about it. Zero Trust means “never trust, always verify.” Easy said, not always easy to do. So, where have we seen this go wrong big time recently? You remember maybe the Salesforce-SalesLoft hack. For most organisations, logging in to Salesforce applies Zero Trust principles. You can use identity federation and various Zero Trust access mechanisms to log in to Salesforce.
The same thing applies if you log in to SalesLoft. After you log in to SalesLoft, you create a permanent bond or integration between SalesLoft and Salesforce, with static, long-lived access keys stored in SalesLoft’s databases. SalesLoft, by the way, was highly certified, with all the certifications under the sun. But this is not a problem specific to SalesLoft.
I always call it the cancer in SaaS. The cancer in SaaS is that SaaS-to-SaaS integrations are based on long-lived credentials stored somewhere — exactly the opposite of what Zero Trust tells us. So, “never trust, always verify” is sometimes hard to create because it’s not always under our control.
But we need to do a couple of things, and we are heavily innovating in this space. And so are many vendors. And I hope we will soon reach — can agree to — industry standards, but that would be another conversation. The first thing: we need to give agents a verifiable, strong identity. If an agent can be just an IP address with an AI behind it, I don’t know where this is coming from. I don’t know if I can trust it. We also need to separate approved AI from shadow AI, so shadow AI cannot claim that identity.
I don’t know if the agent says, “I’m an agent for Microsoft,” that it is an agent for Microsoft. You’re just coming from a random IP address. Similar problems we have with identity and phishing and this kind of thing. We need a verifiable identity. They need least-privilege access along with everything. And shadow AI must not be able to claim that identity or act outside approved use.
Think about MCP service at the beginning. The early versions of MCP service said, “I use my agent, my AI tool, to connect to an MCP server.” And then the MCP server accesses a system of records as the MCP server. It doesn’t even — it lost my complete identity context. How can you implement the principles of least privilege? It was impossible. So, we need to make sure that everything I do, even with the help of AI, can only happen as if I were not using AI. If I don’t have access to this, no matter which AI I use, I will never have it. It’s just a helper organization. And then we need to authenticate and authorize every action. That also means shadow AI cannot act outside my identity context or blend into approved use.
There’s no way that we — and this is again because an AI is a man in the middle or acting on behalf. The same thing we did with applications. We wrote an application that has access to a database. And here we are: we give the application a username and password in a .conf file that is lying around forever on a file system. The mother of all evil in terms of security. So, we need to make sure that authentication and authorisation happen for every single microtransaction, and not just for — not even for — a long-lived session. Are we there yet? No. That is how we keep shadow AI separate and keep it from slipping through.
But we’re heavily innovating, and we need to come to industry standards because if we don’t solve this problem, we will have — we have to solve this problem. Think about agentic commerce. Somebody is on your behalf buying — an agent is buying on your behalf — a pair of shoes. Let’s say this is coming soon.
So you may use your phone, or I may use it. I’m seeing a pair of shoes, and I tell the — or maybe I watch a YouTube video, and I may tell the YouTube video, “Hey, what are these shoes?” And the AI in YouTube says, “These are shoes from Adidas’ latest model,” blah, blah, blah. And I say, “Buy them.”
I want them in size, whatever, 45, green color. And then my personal AI agent actually goes on the hunt on the internet to get the best price and the delivery rates, and it will be delivered. This future is technically already here. This is not an unthinkable, two-step thing. This future is already here, but we still lack the trust. While we can technically do this today, we have not yet sorted out how to do it with full confidence. Now, that’s what we’re working on. And, of course, we need always, always, always the human in the loop. If we reach certain thresholds of uncertainty, if there’s the slightest doubt, humans must stay in the loop.
That’s actually even baked into laws now in Europe. We cannot forget that agents, machines in the world we live in today, do not carry responsibility, certainly not accountability. And also, my advice is: never outsource thinking to a machine. It is a tool. It is a tool. It is not yet a kind of living organism next to us that we inherently trust. Like, I can trust my wife. I can give all my money to my wife and say, “Hey, handle my affairs.” And if she says, “Hey, I don’t know, how do I do this with this, or should I do this?” she will come back naturally because we have this trust in between us. This is — I don’t see a near future where we reach that with AI.
CISO Forum: You work closely with organisations running sensitive, regulated workloads in the cloud. What’s different about securing a regulated financial services or healthcare workload in 2026 compared to five years ago, and where do you see compliance frameworks struggling to keep pace with how fast the threat and technology landscape is moving?
Volker Rath: There are two parts to the question: what differs between highly regulated and less regulated industries.
What matters is how we respond, and the frameworks are always behind.
Technically, it depends on your risk appetite. Operating in a highly regulated industry changes that appetite.
The impacts are more severe when security and compliance requirements come from laws, regulations, industry standards, and customer trust, with consequences for the organisation, including potential loss of money and trust.
But is it fundamentally different? No. It is just a different level. It does not change how you secure things, how you run compliance, or how you manage risk. It only changes how important it is to you. And compliance frameworks, by the way, always struggle to keep up. I argue that this is the default.
Because compliance frameworks were never intended to keep up with day-to-day operations, they typically provide a security baseline. They say, “That’s the minimum.”
If you look at the NIST or ISO frameworks, for example, there is a common misconception that if I do everything to be NIST- or ISO-compliant, then I am secure. This is wrong, period.
I can even be ISO- and NIST-compliant and use outdated security controls that would meet an auditor’s requirements but are no longer resilient because of what happened over the last two years with AI. But I would certainly meet auditors. So, what is it?
Security and compliance frameworks — we need to have them. They guide us toward compliance, which is a security baseline. And compliance is important because it creates trust. It tells us whether somebody is taking things seriously, including security.
But we need to understand — and I heard it once from the CISO of Amazon, and I like that — he said, “Compliance is for people who don’t know better.”
If you want to be secure, you don’t look to a compliance framework. You look to one only if you have no clue where to start, right? But if you’re a security professional, you technically don’t need compliance. You know what good looks like.
And what good looks like is more clearly defined today in industry best-practice standards, such as the Well-Architected Framework. All the big clouds have Well-Architected Frameworks. They aim for a much higher standard and are updated much quicker, right? So, for those who really achieve security resilience, compliance with industry best practices is much more important than compliance with NIST or ISO, right? Not that this is bad, but the question is how high you aim.
And there’s a sad reality in the regulated industry. In a previous role, part of my job was to train high-risk and audit teams from highly regulated industries on assurance and risk readiness. I ran training courses, mainly for banks, for their audit teams on auditing the cloud. I ran them with risk teams on how to risk-assess clouds.
And there is one conversation that I will never forget. A Group Chief Risk Officer of a large, globally leading bank told me that he sees the risk that the risk function itself becomes a fundamental risk for the bank, simply because risk people and audit people are not tech experts. They are not cloud experts. They are not AI experts. They do not get cloud training. They do not get AI training.
Even worse, they do not even have an engineering function. When we talk about security, we immediately understand that it requires engineering to build security controls that scale and work at machine speed. And when we talk about AI governance, we say we need things that protect it at machine speed. But you hardly see the words “machine speed” used when you talk about assurance and risk functions. And they are struggling big time.
If we cannot provide good risk assessments, and if we cannot implement effective — and I am not saying compliant, I am talking about effective — assurance capabilities in highly regulated industries, whose definition is that they have highly, highly sensitive data, which is your data and my data, your health data and my health data, then we are in trouble.
So, that said, we need to modernize not just technology and security. We also need to modernise risk management, assurance capabilities, and our approach to shadow AI. We need to merge them. And we need to have mechanisms that help them also operate at scale.
And my advice here, again, is to start with people, process, and technology. People need to be trained. Risk and assurance teams need engineering capabilities. Security teams need engineering capabilities.
And I know that, especially with highly regulated industries, we need to work on reducing our attack surface. And some of this is really, really hard because of digital legacy, right? Especially banks, insurance companies, telcos and business-critical and critical-infrastructure companies — they are dealing with a lot of digital legacy.
And my last advice here to answer this question is: Frederick the Great said, “The one who defends everything, defends nothing.” I think it is really, really important now to go to your asset register, identify all the things that handle sensitive information, fast-track application modernization, and implement a crown-jewel protection approach.
We cannot have a compliance or risk view for the entire organisation. This doesn’t make sense. You know, you don’t protect your lawnmower in your garage the same way you protect your mom’s old wedding ring, which you may put in the safe, right? But in IT, we quite often do that.
CISO Forum: If you had to bet on the one cybersecurity trend that will force the biggest strategic rethink for CISOs over the next year AI-driven attacks, agentic AI governance, quantum readiness, or something else entirely what would it be, and why?
Volker Rath: My answer is simple: all three. I can’t pick one, and I don’t want to, because these are top of mind for every executive I talk to.
If it is AI-driven attacks, as I said, they reduce our cyber resilience by making our protective controls less effective. That must be top of mind.
Agentic AI governance. This is the Wild West at the moment. Everyone does everything with AI. And now we’re not only using AI anymore; we’re building agents that work on our behalf.
If we forget everything we’ve learned in the last 30 or 40 years of computing and Zero Trust, and if we forget the afterthoughts we’ve had when we adopted cloud computing, then everything becomes an afterthought. Zero Trust is an afterthought, operating at scale is an afterthought, automating key functions like security and compliance is an afterthought.
All of these afterthoughts are even 20 or 100 times more important with agentic AI because of the technology’s speed. So it must be top of mind.
Quantum readiness matters because the threat is that people get the master key to everything. So it has to be top of mind.
I believe, and that’s my suggestion for a lot of organisations, that one thing has become very obvious to me from running executive workshops with large organisations. There’s a common problem: many executives operate in silos. The CISO does what the CISO does, the CIO does what the CIO does, and the CFO does what the CFO does. Shadow AI is often managed separately, and often the same way.
They never actually got into a room, for example, to discuss how best to approach cloud adoption. As I said, governance has all of these different domains. The CFO owns one domain, the CIO owns another, the CTO owns a third, and the CISO owns a fourth.
When I said, “We need to all come together to discuss cloud adoption,” the answer was always, “We never had these people in a room for half a day.” So I’m sorry, we can’t do that. And then my answer was, “Well, you don’t have a problem then.”
Most of them came back. And they came back saying, “We realised we are so badly in trouble because we never talked.” So the same thing is happening here with shadow AI.
If there is a reason for a strategic offsite that includes all the key people of an organisation, then it’s now. There’s never been a more urgent need for a strategic offsite, because technology is changing, and disruptive technologies are disrupting most businesses.
This is existential. They’re disrupting the threat landscape. We are operating in a very different risk landscape. And for a lot of organisations, they’re even wondering, “Is our whole business model future-safe? Or am I being completely disrupted? Is my entire SaaS application a five-minute white-coding exercise tomorrow, and nobody would ever come to my website and give me their money?”
So it is time for an offsite. It is time to challenge the status quo of doing everything—financial management and IT, security and compliance management, risk management, operational excellence, operational scale. Challenge the status quo.
Put your strategies from five years ago in the bin, and don’t develop new strategies based on iterative improvements of where you are today. That’s why it needs to be an offsite.
Put yourself in the mindset and work backwards from what’s most likely to be the situation in the future and how your organisation should operate in the future. And you will start learning that you will ask very different questions.
