Today’s security leaders are navigating many of the same challenges: evolving AI adoption, tighter budgets, maturing security strategies, and increasing expectations from executive leadership. During Innovate Cybersecurity’s Seattle Chapter Executive Evening, security leaders from manufacturing, aviation, financial services, and SaaS came together to share how they’re approaching these challenges.
The panel featured the following CISOs & Executive Leaders:
- Joshua Carlson, CISO, PACCAR
- Brian Talbert, CISO, Alaska Airlines
- Varsha Agarwal, Head of Information Security, Prosper Marketplace
- Jonathan Barrios, CISO, Vindicia
Rather than providing a recap of the discussion, we’ve distilled the conversation into five executive insights—highlighting the key themes that emerged alongside practical takeaways inspired by the perspectives shared during the panel.
Executive Snapshot
Across the discussion, five themes consistently surfaced:
- Security investments must demonstrate measurable business value.
- AI adoption is accelerating faster than governance practices.
- Identity—including non-human identities—remains foundational to modern security.
- Zero Trust is most successful when implemented incrementally.
Boards respond best when cybersecurity is framed as a business conversation
Every Security Investment Needs a Business Case
One of the strongest themes throughout the evening was the growing pressure to justify cybersecurity investments through measurable business outcomes.
As budgets tighten and executive scrutiny increases, security leaders are finding that every investment must demonstrate value beyond technical improvements. Whether purchasing new technology or evaluating existing platforms, organizations are increasingly prioritizing solutions that reduce risk while supporting broader business objectives.
Panelists Emphasized
- Security investments should be tied to clear business outcomes, not just technical capabilities.
- Existing tools should be evaluated regularly to identify opportunities for consolidation and cost savings.
- Security leaders should be prepared to communicate the return on investment behind major initiatives.
Practical Takeaway
Before your next budget discussion, evaluate each major security investment by asking:
- What business risk does this address?
- How does it reduce organizational risk or improve resilience?
- Can its value be clearly explained to executive leadership?
AI Is Creating Opportunity—And New Identity Challenges
Panelists explored artificial intelligence’s promise and the governance challenges that accompany rapid adoption.
While AI is helping organizations improve operational efficiency, it is also expanding the attack surface. AI agents, automation platforms, service accounts, and other non-human identities are becoming increasingly common—and many organizations are still determining how to govern them effectively.
The discussion reinforced the importance of extending existing security fundamentals to emerging AI environments.
Panelists Emphasized
- AI governance should build upon existing security controls rather than operate separately.
- Non-human identities require the same visibility, ownership, and governance as human users.
- Organizations should understand where AI is being used before developing governance strategies.
Practical Takeaway
Organizations should consider:
- Inventorying service accounts, bots, and AI agents.
- Reviewing privileged access assigned to non-human identities.
- Applying existing identity governance and least-privilege principles to AI-enabled systems.
Organizations should consider:
Applying existing identity governance and least-privilege principles to AI-enabled systems.
Inventorying service accounts, bots, and AI agents.
Reviewing privileged access assigned to non-human identities.
Zero Trust Continues to Be a Journey, not a Destination
The panel highlighted how organizations continue to evolve their Zero Trust strategies through deliberate, incremental progress.
Security leaders described the value of focusing first on high-priority assets, validating security controls in targeted environments, and using measurable success to support future expansion.
Zero Trust was consistently framed as a business enabler—supporting cloud adoption, digital transformation, and secure collaboration—not simply another security initiative.
Panelists Emphasized
- Focus first on protecting the organization’s most critical systems and data.
- Start with manageable implementations before expanding across the enterprise.
- Measure outcomes and use those results to build support for future initiatives.
Practical Takeaway
Identify one critical business system that could benefit from stronger identity verification, segmentation, or continuous authentication, and use that initiative to establish a roadmap for broader Zero Trust adoption.
Boards Want Business Context, Not Security Metrics
As cybersecurity becomes increasingly visible at the executive level, panelists argued the importance of communicating security in business terms rather than technical language.
Whether presenting to boards or executive leadership, successful CISOs are increasingly connecting cybersecurity initiatives to operational continuity, financial impact, customer trust, and regulatory obligations. Effective communication often begins with explaining why a particular risk matters to the business.
Panelists Emphasized
- Frame cybersecurity conversations around business impact rather than technical metrics.
- Keep executive messaging concise and outcome focused.
- Use relatable examples to help non-technical stakeholders understand organizational risk.
Practical Takeaway
When preparing for your next executive presentation, structure the conversation around four questions:
- What business function is at risk?
- What could happen if that risk isn’t addressed?
- What is being done to reduce the risk?
- How does the investment support the business?
Technology Consolidation Continues to Be a Strategic Priority
The panelists also discussed how many organizations are maximizing the value of existing security investments before introducing new technologies.
With continued budget pressure across many industries, security leaders are evaluating overlapping tools, simplifying security operations, and improving efficiency wherever possible. Technology consolidation can reduce operational complexity while helping organizations maintain strong security outcomes.
There was also recognition that experienced security professionals remain one of an organization’s most valuable assets, making thoughtful technology optimization an important consideration before workforce reductions.
Panelists Emphasized
- Review existing security platforms before investing in additional tools.
- Look for opportunities to eliminate overlapping capabilities.
- Technology optimization can often improve efficiency while preserving security effectiveness.
Practical Takeaway
Consider performing a periodic review of your security stack to identify duplicate capabilities, opportunities for consolidation, and areas where operational complexity can be reduced.
Final Thoughts
As organizations continue adapting to an increasingly dynamic threat landscape, discussions like these provide insight into how today’s cybersecurity executives from multiple industries are turning strategy into action.
Security leaders are being asked to accomplish more with constrained resources, enable rapid innovation without sacrificing governance, and communicate cyber risk in language that resonates across the business. While technologies continue to evolve, the conversation reinforced that successful security programs remain grounded in strong fundamentals: disciplined investment decisions, identity-first security, practical implementation strategies, and close alignment with business objectives.