How one conversation on day three changed my title

Listen to highlights
A week before I joined Firstsource, I was in a room with roughly 120 CISOs from around the world. Five days, no agenda but one: where is our profession going?
On the last day I said something I had never said out loud before. The CISO role, the way we have defined it for 20 years, will not survive the next 18 months. A few people nodded, slowly, the way people nod when they agree but have not yet decided what to do about it. Then everyone flew home to their old titles.
I flew to my new one. Three days in, in a conversation about where the industry was heading, I said the same thing again. Except this time, it was not a stage. It was the job I had just signed. And I did not just say the old title was ending. I said what I thought should replace it.
Nobody told me to settle in first and earn the right to opinions. My boss, despite having no background in cybersecurity, immediately grasped the idea and bought in proposing the title change on the spot.
I will come back to why a listed company moved that fast. But I want to be honest about what I was really asking for because it was not a new business card. A title is a promise. Chief Information Security Officer promises you will protect the information. I was asking to promise something more challenging.
When a quality miss becomes a lawsuit
Let me make this concrete, because it does not land as a theory. Take a claims floor. Five thousand associates adjudicating, running at a three percent error rate. That is a number a quality team lives with and works down, quarter after quarter. Nobody in that building calls it a security problem. It is not one.
Now take the people out of the seat and put a model in it, running at machine speed. Let that model drift from its baseline. Not a little. Say it drifts completely. You do not get a slightly worse version of three percent. You get outcomes that are wrong almost entirely, at a volume no human reviewer could have caught in time. Then run the worse version.
Someone tampers with that model on purpose, and its decisions start skewing against one group of people, by demography, by race, by whatever line they choose to draw. That is not a quality miss. It is not even a security incident the way we have trained ourselves to picture one. It is a class action, and the person who owns security never touched a stolen file.
This is not hypothetical. In 2025, a federal judge let a class action against a major US health insurer go forward over an automated system that rejected claims without a doctor genuinely reviewing the files. The reporting behind the suit found a single physician could clear tens of thousands of denials a month, about a second per claim. The court's reasoning cut to the point. Letting an algorithm decide while a medical director simply pushes the button does not satisfy the duty to have a human evaluate the need for care.
No data was stolen. No perimeter was breached. The exposure came entirely from decisions made at machine speed, and that is a category most security functions were never built to own.
The word that had to leave
Look at what changed in the title: Chief Information Security Officer became Chief Trust and Resilience Officer. The word that left was information. That was the point.
For 20 years, that I did the work. Protect the information and infrastructure, and the job was done. It was never the wrong mandate. It is just no longer the whole one because the businesses we protect are not selling only products and services anymore. They are selling decisions and outcomes, made by agents, at a speed no human reviews in real time.
Trust took the place of information because someone now has to answer for whether those decisions can be trusted, not only whether the data behind them stayed where it was put. Resilience took the place of security because when one of these decisions goes wrong, it does not go wrong once. It goes wrong at machine speed, across thousands of instances, before anyone in the room can react.
Recovery is the job now. That is the promise underneath the new title. Both words are commitments to the business, not just to the data.
Victim or author?
Here is the distinction that changes everything about how the job feels. If your data gets stolen, there is a playbook. You have run the tabletop. You know how you notify people, how you work with regulators, how you rebuild trust after. And everyone at the table understands the business as the victim in that story.
If your model makes ten thousand biased decisions before anyone notices, there is no equivalent playbook. You are not the victim anymore. You are the author. Most security functions, mine included until recently, were never built to sit in that seat.
Three years ago, we were losing sleep over coordinated inauthentic behavior over misinformation moving through AI across every channel. That was real, and it was about information. What keeps me up now is a quality product, built with care and shipped to market, which causes harm because the decision inside it drifted. The stakes moved from information to outcomes. Trust is what sits on the line.
This isn't a rule change; it's a different game entirely
This was never only about one title at one company. I like acronyms, so here is mine. Four things have moved at once: Scope, Speed, Scale, Sophistication. What a bad actor can reach has widened completely.
What used to take days now takes minutes, sometimes less. One exploit chains itself into thousands. And the sophistication that used to belong only to nation states now sits with anyone holding an internet connection. That is not a pivot, that is a shift.
Someone told me once that you cannot patch your way out of this, and I think about it constantly, because they assume the threat holds still long enough to be patched. It does not. The old playbook is out the window. What replaces patching is containment, and what makes containment work is architecture.
Defense in depth does not go away in the agentic era. It becomes the wrapper you put around the agent itself. You set guardrails on what an agent can do, but guardrails alone are not enough because the frontier models underneath them change every week.
So the honest answer to whether your guardrails hold is a different answer every week. The wrapper has to sit on top of that. And governance moves from a compliance chore to the center of the table, because governance is now how you defend not just your systems and your applications, but your business.
Depth is the advantage now
Every risk decision now has to be quantified by its outcome, not by a generic score. Not the old risk register. Outcome by outcome, what happens to the business, to the person, if this one goes wrong. That is how a leader should decide, and increasingly, it is how the agents themselves will decide which controls to enforce.
But the thing that holds all of it up is not a tool or a framework; it is domain knowledge. The people who understand exactly what a decision means inside their business, in claims, in collections, in healthcare, in banking, are the ones who catch drift before a regulator does. I tell associates who worry AI is coming for their jobs the same thing every time. What you carry, nobody else has. Understand your domain and you are the king. Full stop.
Then I tell them the practical next step: go attach yourself to the engineering team, borrow a couple of engineers, and start automating the workflows you know cold. You bring the domain, they bring the build, and six months later you are AI-native and you do not need to borrow anyone. Being in-house, with real domain depth, is worth more than any tool bought to replace it.
Three questions I ask walking in
When I walk into an organization today, I am really asking three questions.
- Do you have visibility into your AI pipeline, your models, the shadow AI nobody officially signed off on because you cannot protect what you cannot see, and most places still cannot see most of it?
- Do you have real governance around onboarding agents and supply chain partners, with the right people in the room, the data owner, the business owner, the CTO, and the CISO because a governance structure that lives with the security function alone is not a governance structure?
- Do the teams doing the daily work have the skill, not just the leadership?
If the answer to any of these is no, the gap is not a tooling gap. It is an accountability gap, and no outside vendor can close it for you
What the title cost me
I will not pretend the trade was comfortable. Twenty years spent building a title people recognized on sight, handed in for one nobody had heard of. But recognition was never the actual job. Staying ahead of what the business needs protected next was always the job, and it had already moved without waiting for the title to catch up.
By day five, it was approved. What struck me was not the speed, though for a listed company to move that fast on something this unconventional says something on its own. What struck me was that nobody in the room needed the argument explained twice. Say the business now sells decisions and outcomes, not products and services, and the rest follows on its own.
Most CISOs are trained to protect the business. I would rather enable it with a title that promises what the business actually needs now. The title did not change that week. It finally caught up with the work.
So here is what I would say to the CISO still sitting under the old title. The mandate has already shifted, whether the organizational chart admits it or not. If the job has changed, the way you see the job has to change with it, and that change has to start somewhere visible. It starts with a title that names the mandate you carry, not the one you inherited.
But it cannot end there. It has to run through the budget you fight for, the people you hire, the tools you buy, and the questions you walk into a room asking. A new title with the old outlook is just a rebrand.
The title is the first signal, not the whole shift. The rest of it, budgets, resources, tooling, the lens you bring to every decision, has to follow, or the title was never earned in the first place.
