When security deals in absolutes, the business finds a way around it.
When security deals in absolutes, the business finds a way around it.
Bose CISO Arun Abraham joins Ash Hunt to discuss why flat “no”s create shadow IT, how security leaders can enable AI without opening the gates, and why fundamentals like data, identity, vulnerability management, and risk prioritization still matter most.
0:00 Are We Too Secure?
1:25 The CISO outsider advantage
5:19 Puritanism in security
6:24 How to earn trust when you tell executives the truth
8:11 Why quantitative risk beats maturity curves
9:39 The three fundamentals: detect, respond, VM
13:44 What AI enablement requires from security
14:14 The cloud playbook applies: enable or get shadow AI
15:10 The CISO who got replaced for saying no
15:49 Why Bose's security team has a backlog
19:59 The five-minute aha moment
21:34 If you don't know where your data is, you can't enable AI
25:09 The internal AI agent that replaced policy
27:22 The secure SDLC didn't look like this five years ago
29:44 AI won't invent new attacks - it'll use your deficiencies
31:04 Perfect is the enemy of good