1. Modern CISOs are expected to preserve customer trust alongside supporting business speed and expansion. What are the most imperative prerequisites when investing in controls- ones that foster business growth rather than slowing it down?
In the current economic environment, innovation has been accelerated by new and emerging technologies and this drives all aspects of an organization, including security, to adapt to the demands of faster pace of working.
Being a blocker to innovation, technology adoption, or operational adaptation, is a way to guarantee obsolescence so security has to first view itself as a business support tool rather than as purely some sort of security compliance enforcement tool. Security can be a business enabler by providing security support tools to even front-line Sales or Marketing teams (e.g., a Security Trust Center on a web site can be a quick way to win positive attention from potential or current customers).
Security controls must also be selected and applied in line with current technology and industry trends; for example, adopting a standard such as ISO 42001 or the OWASP Top 10 guidance for the various AI aspects is a current and relevant security control selection.
Once controls are selected, however, it is just as important to implement them in ways that are not intrusive or cumbersome and that is the finesse side of security implementation today; you can achieve by basing control implementation decisions on a solid risk-based approach, adopting federated control ownership with centralized guardrails, automating security wherever possible, embedding controls in the workflows, and adopting useful security KPI’s.
2. In a globally distributed environment, it’s challenging to reiterate tick-the-box compliance frameworks to keep pace with market demands. While translating regulatory complexities into uniform internal controls, which aspect have you found to be the most cumbersome in your opinion– and does it continue to remain ungovernable?
Compliance frameworks have grown in number in the last decade and, although there can be overlap between the various frameworks and standards, it is usually the subtle differences between them can catch you off guard when implementing them.
For example, the definition of personal data or PII can vary between standards and frameworks or the specific requirements of, for example, the UK CyberEssentials framework can differ from the NIST SP 800-53 framework or from PCI-DSS.
I try to maintain either a manually created mapping document for the various frameworks and standards that are of typical concern or I utilize a GRC tool which has this capability already built in.
With every new technology, there has been a release of either new or updated security standards or frameworks so change is inevitable and you have to be prepared for this. I have found that maintaining a harmonized ISMS has meant that I need to find the new unique requirements that have emerged and then map them to my ISMS content to ensure I have them covered.
Doing this manually is, and will remain, a difficult task but using a GRC tool can help with this effort enormously and, happily, there are even some open-source options out there for GRC tools now.
3. Industry pulse reports, including Gartner, spotlight enabling and protecting AI as a top CISO priority. Given your expertise, how would you rank the subsequent struggles while building an Artificial Intelligence Management System (AIMS)? Where does accountability land?
The AI explosion onto the marketplace is very similar to the Cloud technology boom – it was everywhere, all at once, and many third-party vendors for organizations were using it even before their customers were and this expanded the security threat landscape.
AI has so many avenues into your organization from end users utilizing free LLM’s or even corporate LLM’s, to third party suppliers using it, to automation of work tasks with AI Agents, or using AI code development tools. Because there are so many areas where AI is used today, adapting an existing ISMS to include AIMS components (and you should have a unified MS for AI and security) can be a daunting task.
In my experience, getting security team members themselves to embrace AI and its unstoppable presence in the organization can be a considerable struggle but without this, the reality of how AI needs to be secured will be missed.
Secondly, I would say that getting transparency from organization staff with regards to where they either are using or they want to use AI is very important but is also difficult (I recommend an AI Steering Committee or similar to manage AI for now).
Lastly, without understanding the full risk profile of AI in your organization you cannot protect against its threats (and your customers want you to!) so ensuring that all third-party vendors are re-assessed for AI risks is an ongoing effort to ensure the AIMS is properly applied.
4. Integrating AI security into the SDLC can prove demanding- given AI introduces new attack surfaces that traditional AppSec processes don’t cover entirely. Is there any single most critical rule leaders must follow to ensure a control design that engineers and product teams can realistically back?
When it comes to integrating AI security into the SDLC, gaining the support of engineers, developers, and product teams for new AI specific controls requires federation of security into the SDLC workflow.
Attempting to implement a new set of AI security controls into the SDLC through processes operated by the Security team will lead to frustration for everyone. Instead, follow the same processes for all security controls in the SDLC: design the controls based on industry standard guidance, add the controls at the critical steps in the SDLC where those controls belong, utilize gating in the SDLC to ensure controls are indeed being applied, and test for security.
To better federate the controls, try adding an AI Agent for security in the SDLC. For example, you could add a security AI agent that performs a threat risk assessment and data privacy impact assessment at the design stage of the SDLC and allow the product team direct access to it. This would allow the team to know at the start of the SDLC lifecycle exactly what risks their project may face and how to mitigate them.
This same AI agent could also be generating its output into your organization’s ticket system where the Security team could then verify the TRA and DPIA.
For the security testing, ensure your security team is trained on AI testing and that you have obtained an AI testing tool for them to use and then Security can take care of the security testing.
5. Tech consolidation concentrates power among major cloud platforms and identity providers, elevating the need for endpoint management and integrity across log review processes. Do you have a practicing philosophy for maintaining a repeatable yet scalable management system that helps you deal with ethical and regulatory ambiguities?
There has been a growing trend in the consumption of technology services in the last two years to seek out safe homes for the organization’s data.
“Federated data” has become a more frequent quest in the current climate of privacy legislations and global politics. In addition, the latest AI legislations and security standards contain a noticeable amount of overlap with privacy requirements so the location of your data and, more importantly, the location of your customers’ data, has become a critical consideration.
Happily, there are options for cloud services and common technology products that can help with locating the data where you need it to be and also help you with taking more control of the technology you rely upon.
My approach is to first review all current technology in use and ensure that a) it provides the service that is required, b) there is a clear RACI documented that defines what the vendor is responsible for versus my organization, c) a Data Privacy Impact Assessment has been completed that captures where all data and log data is being sent to and stored.
Once I get all of this information gathered, I then look at any vendor or product that might either be redundant or that might need to be looked at for replacement. Uncooperative vendors who cannot or will not provide me with the information I require for my assessment become the first ones that I look at for replacement or removal.
6. AI can be easily weaponized to accelerate threat vectors. In cases where SaaS sprawl extends beyond centralized control, what critical foundational blocks can security leaders lay down to identify and mend time-sensitive visibility gaps?
Recent events have certainly shown that AI is a very effective tool for attacks and the only way to effectively combat the speed and capabilities of AI-enabled attacks is to match that AI power with AI power. Security tools should be AI-enabled so that they can detect, process and react to attacks faster. The human in the loop will still always be required but AI is now required.
Of course, even the best security tooling can be ineffective if you do not know what you do not know so a full review is required of your systems, infrastructure, vendors, and a mapping of your data storage locations and data movements.
I would then look for every opportunity to pull log data from everywhere you can into a central logging solution which could then feed critical security tools such as a SIEM. This could then permit you to focus your AI enablement effort on your SIEM as a critical first step to modernize your security tool kit.
The threat analysis portion of your SIEM would provide you with the suggested fixes and, with more advanced versions of SIEM technology, it could even apply fixes.
7. As the global economic climate tightens, enterprise tech buyers expect consistent security assurance- be it compliance certifications or transparent risk metrics. When it comes to earning the trust of an entire B2B committee, how do you communicate customer-facing transparency without creating an unsustainable workload for your team?
The most savvy security professionals have realized by now that the days of security staying in the shadows of the organizations have ended; today, security has to help the front-line teams to sell products or services.
The most effective way to turn security into a sales-enablement tool that I have seen is to build a security story for these teams that is easily understood and communicated.
In addition to creating white papers that describe critical security features of your product, making a Trust Center available for clients and your sales team to access is also a good idea and provides a bit of self-service security information.
Finally, modern GRC tools often include a security questionnaire tool for responding to client security questionnaires and the better GRC tools add an AI to help ensure the security data you provide is accurate and complete.
All of these options can help reduce your workload with regards to providing security transparency to your customers.

Anthony English, VP of Information Security/CISO at WorkJam
Anthony English is an enterprise technology executive with more than 30 years of experience leading digital transformation, enterprise IT, privacy, cybersecurity, AI governance, and technology strategy across higher education, SaaS, healthcare, financial services, government, lottery and gaming, and critical infrastructure organizations. He currently serves as Vice President, Security and Chief Information Security Officer at WorkJam, where he leads enterprise security, internal IT, AI governance, and technology risk while advising executive leadership and the Board on strategic technology initiatives.
Throughout his career, Anthony has held executive leadership positions with global organizations including IGT, Atlantic Lottery, Interuniversity Services Inc., Mariner Innovations, Butterfield Bank, and WorkJam. He has extensive experience aligning technology strategy with business objectives, modernizing enterprise services, implementing governance frameworks, and leading multidisciplinary teams through complex organizational change.
Anthony is a recognized international speaker, published author, and trusted advisor on enterprise technology, cybersecurity, privacy, governance, and artificial intelligence. He serves on several industry committees and advisory boards and holds numerous executive certifications, including CISSP, CISM, CISA, CGEIT, CRISC, C|CISO, and Certified AI Professional, amongst others. He also holds a Government of Canada Secret Level II Security Clearance.




