CISOs have a stack of tools but no system built to run the security program itself. Mike Armistead wants to fix that.
In this episode I sit down with Mike Armistead, co-founder and CEO of Pulse Security AI and a longtime security founder behind Fortify and Respond Software. We dig into why the security leader has never had a system of truth the way the CFO has an ERP and the CRO has a CRM, and how an agentic layer on top of the existing tools can finally close that gap. Mike is measured about where AI gets to decide and where the human stays in the seat, and he shares what surprised him most from research with more than 80 senior practitioners and corporate directors.
In this episode: - Why two exits later Mike came back to build a third company around the AI wave - The silos that left CISOs with an acronym soup of tools and no way to run the program - What a system of truth for the CISO actually means and how it layers on top of existing structured and unstructured data - Where agents do the heavy lifting on regulatory monitoring, vendor intelligence, and status reporting - Governing the guardrails, not the keystrokes, and why closing the loop still involves people - What corporate directors actually want to hear in the 15 to 20 minutes a CISO gets each quarter - The findings that stood out, including that 55% of boards have never defined the cyber risk they are willing to accept, and only 12.5% of CISOs are very confident the board leaves with a true picture of the risk - Institutionalizing the tribal knowledge every security program runs on
Chapters: 0:00 Intro 0:18 Mike's background and two prior exits 1:08 Why the AI wave pulled him back 2:21 Why the CISO has no system to run the program 4:09 Starting at the program level, not the SOC or AppSec 5:28 What a system of truth for the CISO means 8:19 Speaking the language of the business 9:09 Where AI does the heavy lifting on a typical Tuesday 11:57 Govern the guardrails, not the keystrokes 15:44 Bringing deputies into the conversation 16:46 What the research with senior practitioners found 20:37 Boards, risk tolerance, and the reporting gap 24:57 AI as a double-edged sword for security leaders 25:35 Joanna Burkey and institutionalizing tribal knowledge 27:31 A year from now for the security leader
Podden och tillhörande omslagsbild på den här sidan tillhör
Chris Hughes. Innehållet i podden är skapat av Chris Hughes och inte av,
eller tillsammans med, Poddtoppen.