Sean D. Mack

Sean D. Mack

Creator
0 followers

CIO/CISO and author (Enterprise Security: A Data‑Centric Approach) who discusses real‑world cybersecurity leadership conversations and enterprise risk focus areas.

Security Vendors Must Own AI, Not Serve It
SocialMay 5, 2026

Security Vendors Must Own AI, Not Serve It

GenAI is going to augment nearly every layer of the security stack. The interesting question for vendors is not whether the stack disappears. It is whether you become a feature of someone else's AI, or whether AI becomes a feature of...

By Sean D. Mack
Decentralized Teams Scale Better Than Centralized Command
SocialMay 4, 2026

Decentralized Teams Scale Better Than Centralized Command

Happy May the 4th! The most underrated leadership lesson in Star Wars is structural, not spiritual. The Empire ran centralized command and control. The Rebellion ran small, autonomous teams making local decisions. Half the enterprises I work with are still figuring...

By Sean D. Mack
AI‑First GRC Turns Risk Assessments Into Immediate Action
SocialMay 2, 2026

AI‑First GRC Turns Risk Assessments Into Immediate Action

Working on launching a new GRC platform, Cygnal. AI first, risk first. The interesting part is not the technology, it’s how quickly we can turn assessment into action. Super excited about what we are building and the value this is already...

By Sean D. Mack
Prioritize Real-Time Business Threats Over Mere Documentation
SocialMay 1, 2026

Prioritize Real-Time Business Threats Over Mere Documentation

I keep coming back to this: The goal is not to document risk. The goal is to understand what could actually hurt the business today.

By Sean D. Mack
AI Threats Accelerate: Speed, Automation, Availability Redefine Risk
SocialMay 1, 2026

AI Threats Accelerate: Speed, Automation, Availability Redefine Risk

There’s a lot of noise around AI threats like Mythos. From what I’ve seen, the techniques are not new. What is new: speed automation availability Anyone can now operate at a much higher level than before. That changes the game. If you're not one of the...

By Sean D. Mack
Assess Your Cyber Risk in the AI Era
SocialMay 1, 2026

Assess Your Cyber Risk in the AI Era

Do you actually know your cyber risk? Join us for an upcoming webinar on cyber risk in the age of AI. The core question is simple but but hard to answer for many. Register now: https://buff.ly/1TfqYzt

By Sean D. Mack
CIO‑CISO Misalignment Leaves Enterprise Risk Owner Undefined
SocialApr 30, 2026

CIO‑CISO Misalignment Leaves Enterprise Risk Owner Undefined

The CIO CISO alignment issue is still one of the biggest gaps I hear about in my daily conversations with technology leaders. Who actually owns enterprise risk? And how are you managing alignment across your organization? Check out the latest...

By Sean D. Mack
Choosing CTEM vs ASM: Which Delivers More Value?
SocialApr 29, 2026

Choosing CTEM vs ASM: Which Delivers More Value?

Are you using CTEM or ASM for your organization? Interested to know how you've integrated these tools into your security operations? What’s delivering the most value?

By Sean D. Mack
AI Builds Apps Fast, but Google Mispronounces My Street
SocialApr 29, 2026

AI Builds Apps Fast, but Google Mispronounces My Street

It continues to baffle me that AI can now rapidly develops applications from scratch and yet Google Assistant still can’t pronounce the name of my neighborhood "Peck Slip".

By Sean D. Mack
Musk's AI Safety Claims Clash with His Aggressive Ventures
SocialApr 29, 2026

Musk's AI Safety Claims Clash with His Aggressive Ventures

It might just be me, but Elon Musk positioning himself as a champion of AI safety, in court, no less, is a tough sell. This is someone actively building one of the most aggressive AI companies in the market.

By Sean D. Mack
Link Cyber Risk Directly to Financial Outcomes, Not Just Controls
SocialApr 28, 2026

Link Cyber Risk Directly to Financial Outcomes, Not Just Controls

How are you actually measuring cyber risk today? Frameworks are helpful, but they don’t always translate cleanly to business impact. Are you tying risk to financial outcomes or still working mostly in controls and maturity?

By Sean D. Mack
Join a No‑Pitch Virtual Roundtable on Transport Security
SocialApr 28, 2026

Join a No‑Pitch Virtual Roundtable on Transport Security

I'll be hosting a virtual roundtable tomorrow on securing transport systems. No pitches, just real discussion with cybersecurity leaders. Great way to network and learn. If you're interested, register now at: https://buff.ly/L7CxprA

By Sean D. Mack
NYC Cybersecurity Leaders: Join AI‑MDR Dinner Roundtable
SocialApr 27, 2026

NYC Cybersecurity Leaders: Join AI‑MDR Dinner Roundtable

Cybersecurity leaders in the NYC area: I'll be hosting a roundtable dinner this Thursday on MDR in an AI world. Small group, free food and drink, no vendor pitches. If you're interested in joining you can register now: https://buff.ly/ph28llE

By Sean D. Mack
Quitting Threads, Yet Still Posting About It
SocialApr 26, 2026

Quitting Threads, Yet Still Posting About It

Me: I'm quitting Threads and saving hours every week. My wife: Wait are you posting that to Threads right now? Me: ... ...

By Sean D. Mack
AI Reliability Engineer: The Future Code Orchestrator
SocialApr 25, 2026

AI Reliability Engineer: The Future Code Orchestrator

There is a new role is that is needed in the world of AI: The AI Reliability Engineer. The developer of the future will be an orchestrator of agents, a master at understanding code management, a new breed that can...

By Sean D. Mack
AI Adoption Outpaces Ops Discipline, Creating Risk Gap
SocialApr 25, 2026

AI Adoption Outpaces Ops Discipline, Creating Risk Gap

I have been thinking a lot about how quickly teams are adopting AI tools. The gap between experimentation and operational discipline is growing. That gap is where most of the risk is right now.

By Sean D. Mack
Mid-Size Firms See Cybersecurity as Essential, Not Optional
SocialApr 24, 2026

Mid-Size Firms See Cybersecurity as Essential, Not Optional

From ISMG: cybersecurity is becoming a must have for mid sized firms, not a nice to have. https://buff.ly/HzPfKHs The interesting shift is not the decision to invest. It is how organizations are deciding what actually moves the needle.

By Sean D. Mack
Prioritizing Cyber Risks Beats Mere Awareness
SocialApr 23, 2026

Prioritizing Cyber Risks Beats Mere Awareness

One of the hardest parts of cybersecurity right now is not awareness. It is prioritization. Everyone knows there is risk. Few teams are aligned on what matters most. How do you know if you're tackling the most important risks for your organization?

By Sean D. Mack
Seeking Best Practices for Managing Multiple AI Coding Agents
SocialApr 21, 2026

Seeking Best Practices for Managing Multiple AI Coding Agents

Are you managing multiple AI coding agents? If so, how are you doing it? Are you using an orchestration tool? Another agent to manage the agents? I'm starting to work with Claude Agent Teams and as well as just running multiple...

By Sean D. Mack
AI Forces Firms to Rethink Build‑vs‑buy Decisions
SocialApr 21, 2026

AI Forces Firms to Rethink Build‑vs‑buy Decisions

One of the more interesting comments from a recent roundtable: A large financial institution is re-evaluating build vs buy across their entire stack because of AI assisted development. Including major SaaS platforms. Are you rethinking this right now? Does AI truly change...

By Sean D. Mack
AI Tools Free Time to Focus on Product
SocialApr 20, 2026

AI Tools Free Time to Focus on Product

Spent more time with AI assisted development this weekend. I spend less time thinking about code and more time thinking about the product.

By Sean D. Mack
AI Security Shifts to Governance, Data Control, Real Risk
SocialApr 20, 2026

AI Security Shifts to Governance, Data Control, Real Risk

Great roundtable in NY last week with Zscaler on securing the next wave of AI in financial services. The conversation has changed. Less hype, more focus on governance, data control, and real risk.

By Sean D. Mack
AI Security Fundamentals Unchanged, Just Faster and Messier
SocialApr 20, 2026

AI Security Fundamentals Unchanged, Just Faster and Messier

I keep hearing “AI security is different.” Not sure I buy that. Most of what teams are dealing with looks very familiar, just faster and messier. Shadow AI, identity, third parties. We’ve seen all of this before. The tooling changed. The fundamentals didn’t.

By Sean D. Mack
AI Advances Outpace Organizational Operating Models
SocialApr 19, 2026

AI Advances Outpace Organizational Operating Models

Feels like we are still very early in figuring out how AI fits into real organizations. The technology is moving fast, but the operating models are still catching up.

By Sean D. Mack
Leadership Requires Choosing Between Competing Tradeoffs
SocialApr 18, 2026

Leadership Requires Choosing Between Competing Tradeoffs

A lot of leadership comes down to tradeoffs that do not have clean answers. Speed vs risk, centralization vs autonomy, innovation vs control. You rarely get to optimize for all of them at once.

By Sean D. Mack
Tools Are Easy; Business‑focused Risk Understanding Is Hard
SocialApr 17, 2026

Tools Are Easy; Business‑focused Risk Understanding Is Hard

The more time I spend in security, the more I believe tools are the easy part. Understanding risk in a way the business cares about and then acting on it is where most teams struggle.

By Sean D. Mack
Seeking Real‑World CTEM Platform Success Stories
SocialApr 17, 2026

Seeking Real‑World CTEM Platform Success Stories

What is your favorite CTEM platform right now and why? Less interested in feature lists and more interested in what is actually working in production.

By Sean D. Mack
Evaluating Real Value vs Noise in CTEM Platforms
SocialApr 17, 2026

Evaluating Real Value vs Noise in CTEM Platforms

Are people actually getting value out of your CTEM platforms? I see a lot of interesting capabilities, but I am still trying to separate what is useful from what is just noise.

By Sean D. Mack
Even AI Can't Automate My Expense Reports—Need an Agent
SocialApr 16, 2026

Even AI Can't Automate My Expense Reports—Need an Agent

We have AI writing code, generating content, analyzing data, and yet I am still doing expense reports manually. Feels like one of the most obvious use cases for an AI agent and yet... If someone has and AI agent that could...

By Sean D. Mack
Agentic AI Security Needs Layered, Integrated Defenses
SocialApr 16, 2026

Agentic AI Security Needs Layered, Integrated Defenses

We keep asking how to solve agentic security as if there is a single answer, but most of the conversations I am having suggest it is a combination of least privilege, access controls, monitoring, and good architecture. The question might not...

By Sean D. Mack
SMBs Know Basics; Prioritize What Truly Matters
SocialApr 16, 2026

SMBs Know Basics; Prioritize What Truly Matters

For SMBs, cybersecurity is rarely a knowledge problem. Most teams know the basics. The challenge is figuring out what actually matters for their business and doing that well.

By Sean D. Mack
New CXO Advisor Services Cut Cyber Risk Fast
SocialApr 15, 2026

New CXO Advisor Services Cut Cyber Risk Fast

We are expanding CXO Advisor with new services across pen testing, incident response, and transformation. The goal is to fundamentally help companies reduce their cybersecurity risk. If you are trying to improve your security posture in a practical way, happy to...

By Sean D. Mack
NYC Cyber Leaders: Join Roundtable on Secure AI
SocialApr 14, 2026

NYC Cyber Leaders: Join Roundtable on Secure AI

If you are a cybersecurity leader in NYC, I'll be hosting a roundtable this Thursday on secure AI adoption. Small group, strong peer set, and candid discussion about what is actually working and what is not. Free food, drinks, and great...

By Sean D. Mack
AI Success Depends on Operating Model, Not Just Technology
SocialApr 14, 2026

AI Success Depends on Operating Model, Not Just Technology

One thing I keep coming back to is that AI is less of a technology decision and more of an operating model decision. The companies that get this right are thinking about ownership, workflows, and accountability, not just which models...

By Sean D. Mack
Embedding AI Organization-Wide Mirrors Early DevOps Evolution
SocialApr 14, 2026

Embedding AI Organization-Wide Mirrors Early DevOps Evolution

Do you have an AI org or are you embedding AI across existing teams? This feels very similar to early DevOps where everyone was spinning up dedicated teams and roles, but over time it became something that had to be...

By Sean D. Mack
AI Coding Boosts Enterprise Productivity—But How Much?
SocialApr 13, 2026

AI Coding Boosts Enterprise Productivity—But How Much?

What is the actual impact of AI assisted coding in large enterprises? I am personally pretty blown away by what I can build with it but at scale I rarely hear specifics on the impact. Are large teams actually 10% faster...

By Sean D. Mack
Agentic AI Identity Needs Integrated Control System, Not One Solution
SocialApr 13, 2026

Agentic AI Identity Needs Integrated Control System, Not One Solution

Great roundtable in Boston last week with Okta on identity for agentic AI. The biggest takeaway for me is that no one really knows how to solve this challenge yet. People are looking for a single solution when the reality...

By Sean D. Mack
Seeking Real-World Feedback on SAFE GRC Platform
SocialApr 10, 2026

Seeking Real-World Feedback on SAFE GRC Platform

Do you use the SAFE GRC platform? Had a chance to see it at RSAC and was impressed but don't hear from many folks using it. Would love to hear real-world feedback from current users.

By Sean D. Mack
Exploring Agentic AI's Impact on Large Development Teams
SocialApr 10, 2026

Exploring Agentic AI's Impact on Large Development Teams

Are you using agentic AI in your development teams? Working with it individually has been powerful. Very curious how this translates to large codebases and teams.

By Sean D. Mack
Shadow IT Evolves: From User Shortcuts to Autonomous Systems
SocialApr 9, 2026

Shadow IT Evolves: From User Shortcuts to Autonomous Systems

Shadow IT used to mean people using tools without approval. Now it can act on its own.

By Sean D. Mack
Seeking User Priorities for New AI‑Native GRC Platform
SocialApr 8, 2026

Seeking User Priorities for New AI‑Native GRC Platform

What is the most important thing you want in a GRC platform? We are building something new, AI-native from the ground up. Would value input from people actually using these systems day to day.

By Sean D. Mack
AI Coding Frees Developers to Focus on Product Vision
SocialApr 8, 2026

AI Coding Frees Developers to Focus on Product Vision

I've been spending a lot of time on AI assisted development and I continue to be blown away. What I like most is not the speed (although that's impressive) but the ability to focus on the bigger issues: how the...

By Sean D. Mack
AI‑Assisted Development: Incremental Boost or Enterprise Transformation?
SocialApr 8, 2026

AI‑Assisted Development: Incremental Boost or Enterprise Transformation?

What is the real impact of AI-assisted development in large enterprises? On personal projects, it feels like a step change. At scale, I am not sure yet. Is it incremental or transformational?

By Sean D. Mack
AI Security Mirrors Existing Controls, Not a New Paradigm
SocialApr 7, 2026

AI Security Mirrors Existing Controls, Not a New Paradigm

Is AI security actually different? The categories look familiar: Shadow AI, Shadow IT Agent identity, IAM AI vendors, TPRM So what is fundamentally different about security for AI related threats?

By Sean D. Mack
AI Agents Behave Like Users, Not Service Accounts
SocialApr 7, 2026

AI Agents Behave Like Users, Not Service Accounts

AI agents are not service accounts. They are closer to users accounts, but more complex. They act on behalf of others. They change behavior. They can create more agents. How are you handling Agentic identity?

By Sean D. Mack
Autonomous Agents Pose a New Large‑scale Threat
SocialApr 6, 2026

Autonomous Agents Pose a New Large‑scale Threat

An agent with a goal and agency can do real damage. We used to worry about compromised accounts. Now we need to worry about autonomous decision-making at scale. That is a very different risk model.

By Sean D. Mack
Teams Still Operate Security Without a Dedicated CISO
SocialApr 6, 2026

Teams Still Operate Security Without a Dedicated CISO

What surprised me in recent discussions is not the threats. It is how many teams are still trying to manage this without dedicated leadership. How are you structuring security if you do not have a CISO?

By Sean D. Mack
Seeking Real‑World OpenClaw Use Cases and Experiences
SocialApr 3, 2026

Seeking Real‑World OpenClaw Use Cases and Experiences

Anyone using OpenClaw? Very interested to hear how folks are using it? What's your favorite use cases?

By Sean D. Mack
AI Finally Closes Search Loop, but Trust Remains Uncertain
SocialApr 3, 2026

AI Finally Closes Search Loop, but Trust Remains Uncertain

The evolution of search has always been "Find". Google never got there but, now, AI has. AI is the first time it feels like the loop is actually closed. But it raises a new question: How much do you trust the answer?

By Sean D. Mack