AI Governance Is Key—But Don’t Let It Slow Down Cyber Defense: Optiv CISO
‘We’re kind of in a space where traditional defense is going to be behind if we continue the way we’ve been doing things,’ Optiv CISO Rob Gregory tells CRN.
While businesses must make governance an essential part of their AI strategies, it’s also crucial to not allow policies and approval processes to prevent defenders from moving as quickly as today’s increasingly machine-speed attackers, according to Optiv security chief Rob Gregory.
In an interview with CRN, Gregory said that threat actors have gained a massive advantage due to the fact that they can adopt the newest AI models and tools immediately—without concern for governance. Businesses, by contrast, have to account for such limitations.
The major takeaway for businesses is to not sidestep those safeguards—but not let them slow cyber defense to a crawl, either, said Gregory, CISO at Leawood, Kansas-based Optiv, No. 29 on CRN’s 2026 Solution Provider 500. The reality, he noted, is that attackers will be able to exploit that in a bigger way than in the past.
Many threat actors today are “all-in on AI”—and don’t have to deal with limitations on usage that businesses have, Gregory said.
Attackers “don’t have the concerns that organizations and corporations have around, ‘How do we manage AI? Let’s develop an AI use policy, let’s develop AI inventories,’” he said.
Without a doubt, these are “amazing governance procedures that organizations should be doing,” Gregory said.
But attackers don’t face any of these constraints, he said.
“They’re going to grab the latest and greatest tool—the latest and greatest model, the next Mythos—and immediately start trying to leverage it,” Gregory said, referring to Anthropic’s Claude Mythos frontier model.
The issue is not governance itself, but rather, it’s the danger of allowing governance to become a bottleneck, he said.
Ultimately, “we’re kind of in a space where traditional defense is going to be behind if we continue the way we’ve been doing things,” Gregory said.
As customers and partners evolve their defenses, Optiv’s role is to help businesses build an approach to security that can adapt at the same rapid pace as the attacks—without abandoning the requirement for controls, he said.
“I think fundamentally, the job for Optiv isn’t to give a silver bullet against AI-driven threats. That just doesn’t exist,” Gregory said. “More so, where I see our role and mission is to help them build defenses that can adapt as fast as the threats do.”
For many organizations, that will mean shifting their mindset around governance in order to allow cyber defense to move as quickly as is safely possible, according to Gregory.
“We’ve got to move as fast as the threats—which is intimidating. I don’t want to sugarcoat it,” he said. “Because a lot of organizations have not been moving anywhere near as fast as the threat have. And luckily, they’re all, largely, starting to make that pivot and starting to work toward that new flow.”