Last month at our inaugural Innovate Federal Executive Evening, Tristan Fries, Director of Cybersecurity Services at Novacoast, sat down with the Director of the Cyber Protection Division at the US Department of Transportation’s CISO Office, Dr. Justin Hubert, and former Secret Service CISO Roy Luongo for a panel discussion on cybersecurity. The conversation quickly transitioned beyond theory to the practical challenges that leaders face every day. Both speakers brought a wealth of experience: Hubert draws on two decades across federal, academic and military sectors, while Luongo spent years overseeing the Secret Service’s enterprise‑wide information assurance programs. In their unscripted conversation on AI, Zero Trust, and the unsolved identity problem, four things stood out.
Defenders Don’t Have the Advantage — But They Have a Head Start
A recent industry conference claim that cyber economics now favor defenders over attackers didn’t survive contact with the panel. The counter: attackers only need one success in a thousand attempts, while defenders need to be right every time. What has changed, temporarily, is access. Defenders using AI tools now have a window to get ahead of adversaries who haven’t caught up yet. That window won’t stay open. The practical question isn’t whether AI helps defense, it’s whether teams can act on the flood of findings AI surfaces, given most enterprises are already sitting on thousands of unaddressed vulnerabilities. More detection without triage capacity isn’t progress.
Non-Human Identity Is the Gap That Will Bite First
Both panelists returned to this repeatedly: as AI agents get deployed at scale, they’re being handed credentials with none of the discipline applied to human identity — no least privilege, no rotation, no attribution when something goes wrong. Luongo’s broader point was that Zero Trust efforts fall apart without data classification: you can’t make informed decisions about what a user, device, or agent should touch if you don’t know the value of the data itself. Hubert’s warning was similarly direct: networks can’t be protected while automated credentials go unmanaged at scale. In practice, that starts with a real data inventory and classification effort, followed by tools that can retroactively tag legacy assets — unglamorous work both leaders identified as a major hurdle. The warning underneath it all was specific: unmanaged swarms of agent identities are coming, and most organizations aren’t tracking them as a category yet.
Zero Trust Is a Framework to Tailor, Not a Checklist to Complete
Overengineering it by implementing the “full steak” of NIST SP 800-207 or the DoD/NSA Zero Trust Reference Architecture makes systems unusable. Underimplementing leaves gaps attackers will find. The panel’s advice: tailor the model to your specific mission and threat profile, pilot in a low-risk segment, iterate, then scale. Rather than pitching Zero Trust as a security cost, position it as a modernization enabler —cloud migration, API enablement — since that framing resonates with executive leadership far better than a pure security pitch.
AI Governance Should Extend Existing Controls, Not Wait for New Ones
Rather than treating AI as a category requiring novel governance, the panel’s position was to apply the frameworks security teams already run, such as data classification, access review, privacy-by-design, and close AI-specific gaps as they appear. Leaders don’t need a new AI-specific rulebook so much as a risk register and a legal review step layered onto controls that already exist. Waiting for polished federal guidance means falling behind; moving without fundamentals means exposure at scale. Sanctioned, monitored use beat prohibition in their experience: blocking AI doesn’t stop usage, it just removes visibility into how it’s happening. One specific risk worth flagging: reverse prompt extraction, where attackers infer proprietary data by studying what an organization prompts for — a real exposure for any organization where IP is core to the business and AI guardrails haven’t caught up.
The Takeaway: It’s Not New Risk, Just New Speed
The common thread: none of this is new risk. It’s old fundamentals — identity, data classification, risk-based triage — under new pressure and moving faster than the frameworks meant to govern them.
Security must evolve at the same speed as technology. By treating governance as an accelerator, grounding Zero‑Trust in data and identity, and turning the talent shortage into a structured learning pipeline, cybersecurity leaders can transform today’s “wild west” of AI and legacy systems into a controlled, resilient environment. The first step is simple: pick one item from the checklist, assign a champion and start moving. That momentum will pay off as AI, Zero‑Trust and the skills landscape continue to shift.