Are We Too Secure?
When security deals in absolutes, the business finds a way around it. Bose CISO Arun Abraham joins Ash Hunt to discuss why flat “no”s create shadow IT, how security leaders can enable AI without opening the gates, and why fundamentals like data, identity, vulnerability management, and risk prioritization still matter most. Connect Arun Abraham on LinkedIn: https://www.linkedin.com/in/arun-abraham-134b175/ Bose Corporation: https://www.bose.com/ The Watchtower: https://www.cyera.com/watchtower Chapters 0:00 Are We Too Secure? 1:25 The CISO outsider advantage 5:19 Puritanism in security 6:24 How to earn trust when you tell executives the truth 8:11 Why quantitative risk beats maturity curves 9:39 The three fundamentals: detect, respond, VM 13:44 What AI enablement requires from security 14:14 The cloud playbook applies: enable or get shadow AI 15:10 The CISO who got replaced for saying no 15:49 Why Bose's security team has a backlog 19:59 The five-minute aha moment 21:34 If you don't know where your data is, you can't enable AI 25:09 The internal AI agent that replaced policy 27:22 The secure SDLC didn't look like this five years ago 29:44 AI won't invent new attacks - it'll use your deficiencies 31:04 Perfect is the enemy of good