Home / Newsroom / Rooted in Security: Session 4 on AI, Emerging Threats and the Evolving CISO

Rooted in Security: Session 4 on AI, Emerging Threats and the Evolving CISO

auhorBy Stephanie Zavala
August 25, 2026
1 min read
article image
vector

Share

AI was never going to be a small part of the conversation at Session 4 of Rooted in Security.

As the discussion moved through emerging threats, IAM and the changing role of the CISO, it kept coming back to the same challenge: AI is already being used throughout organisations, so how do security teams make sure it is being used safely without standing in the way?

There were plenty of different views in the room, along with practical examples of what people are seeing within their own organisations. Four sessions in, it was also great to see familiar faces returning and new people joining the community.

We caught up with Stephanie Zavala after the event to hear what stood out from the discussion, what attendees can take back to their own teams, and where Rooted in Security goes next.

For anyone who couldn’t attend, what did you want to get people talking about at Session 4?

The purpose of the topics covered is to discuss about how they view the use of AI in their organizations. The landscape is changing at a pace that we haven’t seen in a long time and this newer technology is changing the way that security professionals look at policies, controls, integrations, new tools and insider threats. Now how you safeguard your environment is generally up to the leader, budget, and team; however, it’s clear that securing AI tools and integrations is top of mind for everyone!

You covered emerging threats, Hugging Face and the open-source AI ecosystem, IAM + AI, and the evolving role of the CISO. Which topic sparked the most discussion in the room, and why?

Every subject was heavily covered – but a lot of the conversation kept on going back to how AI is shifting the landscape and changing how security professionals look at IAM, the CISO role and just general day to day activities.

When it came to AI and emerging threats, what were people actually seeing or dealing with in their own organizations?

The consistent problem they are seeing is heavy use of AI without the proper guardrails and controls. It’s inevitable that developers and others within organizations are going to use AI tools in their day to day and they are using them at higher levels than any other technology we’ve seen. So, it’s not about being the ‘department of NO’ but rather “Department of YES and HOW” and taking the right steps to implement these tools and integrating them with proper security policies.

Did anything shared during the discussion challenge your own thinking or give you a different perspective?

Someone mentioned that a breach isn’t always a bad thing, that you cannot let a disaster go to waste in this industry because you need to learn from it and share it. Conferences and community events like these create a space where everyone feels comfortable to share learned perspectives from their experiences.

The role of the CISO was another big part of the conversation. How are people seeing that role change as AI becomes more embedded across organizations?

We discussed that although the CISO is a C-level they sometimes do not have a seat at the table like a CTO, CIO or CEO would have. This is something that needs to change as there is so much more pressure on the CISO to secure an organization from outside and insider (AI usage) threats. We also discussed how there could potentially be a shift on reporting structure and how that could possibly change how executives look at the CISO. Reporting directly into a CEO rather than CTO or CIO – and having other executives report into them.

 

Were there any practical ideas or pieces of advice shared that you think attendees could take back to their own teams?

I know the Leads and Managers left with a lot of great ideas and perspectives. The most practical is looking at AI as a friend and not an enemy and shifting the idea of being a Department of NO to the Department of Yes and How.

Four sessions in, how have you seen the Rooted in Security community develop since the first event?

We’ve seen the community grow in a really organic way. We have attendees who have been with us for several sessions throughout the year, while also welcoming new faces at every event. That mix has been one of the most rewarding parts to see. The feedback has also been remarkably consistent: there’s a real need for more spaces like this in NYC where people can connect, share experiences, and have honest conversations about security. I’m really proud to help create and host one of those spaces.

What’s next for Rooted in Security, and what can the community look forward to?

Our final session of the year will take place at the tail end of Cybersecurity Awareness Month, making it a great way to close out 2026 on a high note. We’re excited to bring the community together one more time this year and then come back in 2027 with even more sessions, speakers, and most importantly, great conversations!

Interested in joining the next Rooted in Security session?
team

Looking for your next role in technology?

We’ve been helping clients achieve the results they need for over 20 years. In that time, we’ve refined ou. We’ve been helping clients achieve the results they need for over 20 years. In that time, we’ve.