1. WEF‘s Cybersecurity Outlook for 2026 spotlights a disparity of concerns- CEOs focus on cyber-enabled frauds, while CISOs concern themselves with the supply chain. The pain points from the boardroom to the frontline fall on a spectrum. How do you spotlight these nuances through your framing- without alienating any of the segments?
If you zoom out for a moment, business leaders and security leaders aren’t actually disagreeing about what matters – they’re just measuring risk in different units.
Most CEOs think in terms of revenue, brand, and shareholder value. Meanwhile, most CISOs focus on the upstream factors – attack surface exposures, supply chain risks, and time-to-detect – that can disrupt those priorities. They’re each looking at the same problems from different vantage points.
I recently spoke with a security leader whose organization produces a monthly cross-functional security report covering governance, compliance, nation-state activity, cybercrime trends, physical security, and vulnerability management. This report serves as a forcing function to align various business leaders every month. In doing so, they create a shared understanding of risk despite very different levels of security expertise and corporate goals.
My security team often says we “add brakes to cars so they can go faster.” The purpose of security isn’t to slow the business down – it’s to give the entire organization the confidence to move faster by understanding the tradeoffs. That shared understanding is how you avoid alienating stakeholders.
Ultimately, effective cybersecurity communication is about helping different teams understand why security is relevant to them. When everyone understands how security supports the organization’s broader objectives, the boardroom and the SOC stop having separate conversations and can solve the same problem together.
As a practical tip, for anyone else working through the same pain points, I’d recommend Stanford’s Cybersecurity and Executive Strategy course (XACS302). It’s a great foundational resource for learning how to translate security risk to business.
2. The ‘lone wolf’ model of the cybersecurity industry has hit a dead end. And Censys winning Wiz’s Most Popular New Integration (2025) is a stunning example of the pivot towards an ecosystem model. Do you find it challenging to differentiate value-driven alliances from a simple logo-swap, especially with vendor trust hitting an all-time low?
The “lone wolf” model in cybersecurity doesn’t work anymore because attackers don’t operate that way. Over the last several years, we’ve seen threat actors lower their costs by sharing infrastructure, reorganize in response to law enforcement activity, and dramatically increase the speed and scale of attacks through AI. If adversaries are collaborating, defenders can’t afford to act in silos. That’s why partnerships have become the connective tissue of modern security operations.
I also agree with the premise of your question – not every partnership creates value. That’s a missed opportunity because both companies have invested engineering, product, and go-to-market resources without solving a meaningful customer problem. In my experience, the root cause is almost always misalignment. Two partners can genuinely believe they’re building something valuable together, but if the integration isn’t rooted in “What real customer workflow are we improving?” adoption will always lag.
That’s why at Censys we manage ecosystem partnerships through a structured six-stage lifecycle: Identify, Engage, Develop, Pre-Release, Production, and Promotion. We start by validating customer demand, understanding unique value differentiation, and aligning on the business problem we’re solving together. Only then do we invest in development and ultimately go-to-market execution.
The partnerships that fail often skip those early stages. My litmus test is simple: Does this integration reduce analyst effort, accelerate investigations, or improve detection? If the answer is no, it’s probably just going to result in a simple API key exchange or a logo on a webpage.
That’s why industry recognition like Wiz’s Most Popular New Integration is meaningful to me. It’s not validation that two companies integrated – it shows that customers found value in that workflow. On July 20th, our Censys logo was on a Times Square billboard for the first time, alongside Wiz and their partners, as a result of that customer adoption. And that feels pretty great.
3. 94% of leaders expect AI to be the biggest force shaping security this year. But with organizations spinning up shadow AI without oversight, the attack surface also expands. Leaning into your expertise, what sort of risk does the unseen cost of such rapid AI expansions present for sustaining meaningful partnerships?
Every new AI agent, MCP server, or exposed API becomes part of the modern attack surface. As business units begin deploying AI outside of established security processes, the fundamental questions security teams rely on – “What do we need to protect?” and “What is the risk if it’s popped?” – are much harder to answer.
Governance, visibility, and compliance controls simply aren’t keeping pace with AI adoption. In the last year, we observed active exploitation of remote code execution (RCE) vulnerabilities in AI tooling like Langflow AI. This year, we’re seeing AI infrastructure adopted at extraordinary speed. For example, OpenClaw grew from fewer than 1,000 to more than 21,000 publicly exposed instances in roughly a week. This type of infrastructure appears faster than most organizations can inventory it.
With every pain point that’s developing with AI, we’re also seeing the security industry respond with new solutions, which reshapes the partnerships that support them. Existing integrations – for example with your SIEM, SOAR, CMDB – are expanding to track AI infrastructure, so organizations can monitor these new assets effectively. At the same time, entirely new categories like AI SOC and AI-pentesting companies are driving new partnership models, while established companies like Anthropic and Google are building brand new AI partner programs.
But I think the less obvious challenge – and one wasn’t getting enough air time until recently – is the economics of AI solutions. Successful partnerships can no longer be evaluated solely on technical interoperability. Every workflow carries token costs, compute costs, and operational tradeoffs. If partners don’t account for those economics, they will find themselves redesigning the integration midway into the relationship because it simply isn’t sustainable at scale for customers.
I believe the next generation of partnerships will be judged on two dimensions: security efficacy and AI economics. They’ll need to deliver measurable security outcomes while remaining operationally and financially sustainable for customers.
4. Mid-market leaders face the brunt of cyber-inequity- outpaced by Fortune 500 because they lack the resources to manage complex exposure. As the Director of Strategic Alliances and Channels, have you found it simpler to level the playing field or adapt to the disparity?
In my experience, midmarket organizations are missing the time, staffing, and budget compared to their enterprise counterparts. I’ve worked with healthcare, water, and energy organizations that fit squarely into this category. The constraints they experienced are consistent: lean security teams, growing regulatory pressure, and an expanding external attack surface. They don’t need more dashboards – they need timely, accurate, comprehensive insights that map into the processes they already use.
For partners that means we need to make enterprise-grade security outcomes accessible without requiring enterprise-sized security teams. That’s where partnerships become incredibly powerful. By integrating the tools these organizations already use, we extend the capabilities of a small security team.
At Censys, we’ve seen the impact of that approach through initiatives and research that helped organizations rapidly identify and respond to emerging threats, especially for healthcare and water organizations across the United States. Those efforts had a measurable impact because multiple organizations leaned into help and provided complementary insights. Ultimately, that’s how partnerships help level the playing field.
5. You’ve built GTM functions across Dublin as well as London. With cyber inequity becoming a leading industry pain point across different regions, are there any trade-offs worth considering before stepping into regulated borders?
I’ve helped build go-to-market launches across North America, EMEA, and APJ a few times now, and one theme has remained consistent: successful expansion is rarely about translating your business – it’s about adapting it.
Regulations are critical to get right. They determine how data is handled, where it’s stored, and what obligations vendors need to consider. But they are also fairly clear ways to determine those requirements. You can consult foreign counsel and compliance expertise, navigate data residency requirements, and build compliant products.
What’s much more nebulous is understanding what customers actually need in different regions. While security challenges themselves don’t respect borders, every market does have different expectations around partner ecosystems, communication styles, and priorities.
That’s where localization becomes much more than translation. Translation changes the language. Localization changes how you communicate value. It affects everything from prospecting emails and executive presentations to partner enablement and customer success.
As a result, your strategy should be global, but the execution has to be local. The companies that succeed internationally are the ones that recognize customers don’t just buy differently because of a border – they buy differently because they’re working in different business contexts.
6. Stakeholders consider cybersecurity as a cost center- with financial loss prevention as their No. 1 priority. Having worked as the Director of International Sales at Censys, you have unique insight into the buyer journey. What are some of the mistakes leaders make in trying to strategically position a technically-nuanced solution in front of prospects already dealing with tool sprawl?
In cybersecurity, there’s always something on fire. Your company can solve important problems and still not be a priority because security teams are constantly balancing competing needs across the business.
The biggest mistake I think vendors make is leading with pitching instead of the customer’s priorities. Too often, conversations are driven toward a predetermined use case rather than understanding what the organization is actually trying to accomplish. The question every seller should ask themselves after a meeting is “Do I understand this team’s priorities, and where does my solution align to any of them?”
Ultimately, buyers invest because a product helps them achieve a priority that matters to them. If you can’t clearly tie your solution to that outcome, even a great product will see high technical win rates without procurement.
7. Managing alliances demands a relationship-heavy investment for the long term, whereas managing channels frequently needs a high-velocity, scalable GTM motion. How do you plan on aligning the incentive and partner enablement frameworks for these two distinct motions- without diluting Censys’ USP?
Historically, channel programs were built around a few core tenets: recruit partners, provide incentives, and enable them to take products to market. Strategic alliances, by contrast, were often centered on technology integrations, marketplaces, OEM relationships, and executive partnerships designed to expand product capabilities or create new routes to market.
Today’s enterprise buying environment requires a more connected approach to partner strategy. Customers are not purchasing individual tools – they’re assembling ecosystems of technology, services, and knowledge to solve complex business problems.
As a result, the partner system is interconnected: a technology alliance created interoperability, an industry partnership provided credibility, value-added reseller identified the customer needs, a services partner drove a successful deployment, and a cloud marketplace unlocked additional budget. The best partner programs don’t manage these as separate motions – they consider the journey holistically.
For us, for example, we recognize that each partner type plays a different role within this ecosystem. We look at revenue influenced, brand awareness, and the activities and metrics that drive investment and enablement. The common thread is that enablement should help every partner clearly understand the value they bring and how they contribute to customer outcomes.
Each partner type has a different role to play, so incentives and enablement should reflect that, but the underlying value proposition remains consistent. When those motions are aligned, it’s a multiplier effect that strengthens our differentiation.

Celestine Jahren, Director of Strategic Alliances and Channels at Censys
Celestine Jahren is Director of Strategic Alliances and Channels at Censys, the leading Internet Intelligence Platform. She works with global enterprises, critical infrastructure organizations, and ISACs to help organizations better understand and reduce cyber risk. Her expertise spans attack surface management, Internet-exposed infrastructure, and cyber threat intelligence trends.
Celestine has delivered more than 50 presentations across North America, Europe, and Asia at leading cybersecurity conferences and industry forums, including Black Hat, RSA Conference, Infosecurity Europe, Dark Reading, FS-ISAC, H-ISAC, E-ISAC, MS-ISAC, Auto-ISAC, and many more. Her insights have been featured in industry publications including CIS Cyber Quarterly, ChannelE2E Perspectives, and Medium, where she writes about cybersecurity strategy, threat intelligence, and the evolving role of partnerships.




