K logix Blog Content that helps security professionals align information security with business objectives.
- The Foundation for Successful AI Adoptionby khaug@klogixcorp.com (Katie Haug) on August 11, 2026 at 3:33 pm
- Before You Build an AI Solution, Ask These Five Questionsby Meghan Mulkeen on August 5, 2026 at 5:45 pm
- Company Update: Celebrating Growth, Customer Trust, and 25 Years of K logixby kwest@klogixcorp.com (Kevin West) on August 4, 2026 at 3:56 pm
2026 has been another year of growth and momentum for K logix. As we approach our 25th anniversary, we’re proud of the progress we’ve made, the relationships we’ve built, and the continued trust our customers place in us to help strengthen their security programs
- 5 Real AI Failures That Every Organization Can Learn Fromby Meghan Mulkeen on July 29, 2026 at 6:40 pm
- Why Open Source Is Becoming the New Software Supply Chain Battlegroundby wfarlie@klogixsecurity.com (Will Farlie) on July 21, 2026 at 5:03 pm
Do you know anyone who still plugs parking lot USBs into computers? Maybe you do. Do you know anyone who pulls code directly from a public GitHub repo? Without a doubt. However, if we think about the underlying concepts (bringing unverified, public data into an organization’s ecosystem), aren’t these actions fundamentally the same? What is a public GitHub or npm if not a digital parking lot for code?
- How to Secure AI: A Breakdown of the TRiSM Frameworkby Meghan Mulkeen on June 24, 2026 at 7:49 pm
You cannot secure what you cannot see.
- Profile: Alastair Paterson, CEO and Co-Founder, Harmonic Securityby khaug@klogixcorp.com (Katie Haug) on June 22, 2026 at 6:24 pm
For Alastair (Al) Paterson, building security companies has never been about reaching the destination. It is about the challenge of creating something that helps organizations solve real problems during periods of major change.As a serial entrepreneur and cybersecurity leader, Al previously founded Digital Shadows, a threat intelligence company that grew to more than 500 enterprise customers before being acquired in 2022. After the acquisition, he found himself in an unfamiliar position.“I’d gone from managing 160 people to zero,” he recalls. “I thought the acquisition and destination was where I wanted to get. But I realized that I’d enjoyed building it, and that was where the real fun was. It’s the journey as much as anything else.”That realization coincided with another major event. Just months after the acquisition, ChatGPT was released and organizations around the world began racing to understand what AI would mean for their businesses. For Al, the opportunity was immediately obvious.“I became very passionate about the AI era very quickly,” he explains. “My immediate reaction, given all my security heritage, was no enterprise is just going to roll this stuff out. They’re going to need to get it live for competitive reasons, but there’s going to be a whole host of security, legal, and compliance challenges around this.”That observation became the foundation for Harmonic Security. Founded in 2023, Harmonic helps organizations accelerate AI adoption safely by providing visibility, governance, and security controls across the rapidly expanding AI ecosystem. As enterprises embrace AI tools, agents, copilots, and automated workflows, Harmonic enables organizations to understand how AI is being used, where data is flowing, and how to apply the appropriate safeguards without slowing innovation.For Al, the mission has remained consistent from day one. “I kept asking myself how we can help accelerate safe, fast AI adoption in the enterprise,” he recalls. “That became the founding goal with Harmonic.”Building for a Moving TargetUnlike many cybersecurity categories that emerge around a specific problem, Al believes AI represents something fundamentally different. “This is not one of those times,” Al observes. “The whole world is being hit with this AI tsunami, and security teams are having to become AI experts overnight.”That reality has shaped how Harmonic operates. When the company launched, the primary concern for many organizations centered on browser-based use of tools like ChatGPT and the risk of sensitive information being exposed through employee interactions. Since then, the landscape has evolved dramatically. AI capabilities have become embedded into enterprise applications and increasingly autonomous agentic systems.As a result, Harmonic has had to evolve alongside the market. What began as a platform focused on AI-related data protection has expanded to address broader governance challenges, including agent management, prompt injection attacks, visibility into AI usage, and oversight of increasingly complex AI workflows.“It isn’t a static thing,” Al notes. “We’re seeing it move from browser usage to applications, to engineering workflows, to agents, and now cloud-hosted agents and team-based AI environments.”For many organizations, keeping pace with those changes has become one of the biggest challenges of AI adoption.Why Traditional Security Approaches Fall ShortAl believes one of the biggest misconceptions organizations have is assuming AI can be managed using the same security approaches that worked in previous technology eras.The challenge is not simply protecting data. It is understanding how employees interact with AI systems, how agents operate autonomously, and how sensitive information moves through increasingly dynamic environments. “Those are not things that you can cover with the old world of rules and DLP from the previous era,” he explains.That belief has become one of Harmonic’s primary differentiators. While many legacy vendors have added AI messaging to their existing platforms, Al believes the underlying technology was not built for how AI is actually being used today.People no longer interact with technology through rigid workflows. They treat AI systems as advisors and collaborators, and as autonomous agents capable of performing actions on their behalf. Al comments, “You can’t govern that with the prior generation’s tools.”To address those challenges, Harmonic developed proprietary language models designed specifically to identify sensitive information, detect prompt injection attacks, and monitor potentially risky AI behavior. These capabilities allow organizations to move beyond traditional compliance-driven controls and gain visibility into how AI is being used across the enterprise.“We’re in a very different era now,” Al notes. “People are feeding AI data in different forms, spinning up agents, and using these tools in ways we’ve never seen before.”Turning Security Teams into AI EnablersAs Harmonic has worked with organizations across financial services, healthcare, technology, and many other industries, one trend has become increasingly clear to Al. The most successful security leaders are not the ones trying to slow AI adoption. They are the ones helping the business embrace it responsibly.“There’s a tension between the business and the security organization,” he explains. “The CEO may conclude that AI adoption is existential to the company and that they’ve got to move quickly.”In that environment, security teams face a choice. They can position themselves as obstacles, or they can become strategic partners helping the business move forward safely. Al sees a significant opportunity for security leaders who choose the latter.“The huge career opportunity is for security teams to be AI native and pro AI enablement, and saying yes and leaning in,” he emphasizes.Increasingly, organizations are creating AI steering committees to guide adoption efforts. In many cases, CISOs are taking leadership roles within those groups, helping shape governance, risk management, and business strategy. For Al, that shift represents a broader evolution in the security profession.“If you become known for being an enabler in AI and being very AI savvy, understanding what the tools do and using them yourselves while putting the right controls around it, that is one hell of a career opportunity,” he points out.He believes the future belongs to security leaders who spend time understanding how employees actually work and helping teams use AI more effectively. “If you say no, then the business is just going to stop asking you,” he cautions.Leading at the Speed of AIThe pace of change in AI has also reshaped how Al thinks about leadership and company building. Unlike traditional software companies that can plan product roadmaps years in advance, Harmonic operates in an environment where major developments can emerge within weeks.“The idea that you’re going to build a twelve-month enterprise roadmap that you stick to is ridiculous for a company like us,” Al explains. Instead, the company focuses on maintaining a clear mission while remaining agile enough to adapt as the market evolves.Every week, the team evaluates what has changed in the AI landscape, what it means for customers, and how those developments should influence product direction. “We’re very clear about what is changing in real time,” he notes. “What does that mean for product? What does it mean for marketing? And what does it mean for our customers?”That approach extends to the company culture as well. One of Harmonic’s core values is what Al describes as flourishing in the unknown. Team members are encouraged to embrace uncertainty in order to adapt quickly, and to view ambiguity as an opportunity rather than an obstacle.Al shared, “It’s all about people that actually embrace the uncertainty and can function very quickly.” For Al, that mindset is essential in an industry where change is constant.The Next Chapter of AI AdoptionAs organizations move beyond early experimentation, Al believes the conversation around AI is becoming more sophisticated. Initially, many discussions focused almost exclusively on risk. Today, leaders are asking different questions.How is AI being used? Which teams are driving adoption? Where is the organization generating value? And what measurable business outcomes are being achieved?To help answer those questions, Harmonic recently introduced capabilities designed to provide visibility into AI usage patterns across organizations. The goal is not simply to understand risk, but to help leaders understand adoption, enablement, and return on investment.“This is becoming more than a risk conversation,” Al points out. “It’s becoming an enablement and ROI conversation as well.” That evolution reflects what he sees across the broader market.Organizations are no longer asking whether AI will become part of their business. They are trying to determine how to adopt it effectively, securely, and at scale. For Al, helping customers navigate that challenge remains the mission.As the AI landscape continues to evolve, Harmonic’s role is not to slow adoption, it is to help organizations move faster with confidence, providing the visibility and controls needed to embrace the opportunities of the AI era while managing the risks that come with it.
- Profile: Evan Wheeler, Senior Director Technology Risk Management, Capital Oneby khaug@klogixcorp.com (Katie Haug) on June 22, 2026 at 6:19 pm
Evan Wheeler approaches cybersecurity through a risk lens, one that prioritizes business alignment and long-term decision making. At Capital One, he operates within the second line of defense, partnering closely with cybersecurity and technology teams while advising the business on how to manage and prioritize risk across a complex and evolving landscape.His perspective reflects a broader evolution in the industry. Security is no longer just about controls and technology, it is about navigating ambiguity and making informed decisions in an environment where the pace of change continues to accelerate.From Cybersecurity to Risk LeadershipEvan’s path into risk began with a gap. Early in his career, organizations were being asked to assess security risk, but there was no clear model for how to do it. “At the start of my career people started asking for security risk assessments, and there was no such thing,” he explains. Rather than relying on traditional approaches like vulnerability scans or penetration testing, he began building frameworks from scratch. “We started making it up on our own, looking at what risk assessments look like in other fields and trying to adapt it,” he says. That experience shaped his mindset that risk requires a different way of thinking. “It is a lot less absolute and a lot more about dealing with uncertainty and gray space,” Evan explains. For leaders who embrace that ambiguity, it creates a closer connection to the business and how decisions are actually made.Expanding Risk Beyond the EnterpriseEvan sees one of the biggest shifts in cybersecurity not within the organization itself, but in the expanding ecosystem around it. Risk is no longer contained within enterprise boundaries. It now extends across third and fourth parties, global operations, and interconnected systems that are increasingly difficult to track in real time.What has changed most is not just the complexity, but the expectation of visibility. Boards and executives are no longer satisfied with understanding internal risk alone. They expect clear, immediate answers about exposure across regions and supply chains.This shift has elevated the role of security and risk leaders. It is no longer enough to secure your own environment. Leaders must understand and account for dependencies they do not fully control, while still being able to explain that risk in a clear and actionable way.For Evan, this is where the challenge lies. The ecosystem has grown faster than traditional approaches to managing it, forcing organizations to rethink how they measure, monitor, and communicate risk at scale.There Is No Single CISO PlaybookOne of the consistent themes Evan highlights is the diversity of leadership styles across the industry. “I do not find that there is any boilerplate CISO,” he says. Each leader brings a different perspective, shaped by their background and the needs of their organization. Some focus on product security, others on operations or strategy. The same is true for boards and executive teams. “They all have very different makeups and interests and priorities,” he explains. For Evan, this reinforces the importance of adaptability. Effective leaders surround themselves with diverse perspectives and tailor their approach to the environment they operate in.Investing in High-Leverage ControlsIn an environment of increasing complexity, Evan sees a clear shift toward prioritizing investments that deliver broad impact.“We are all looking for where we can get the most leverage,” he says. Rather than deploying point solutions, organizations are focusing on controls that reduce risk across multiple scenarios. Technologies like passwordless authentication and data tokenization stand out because they eliminate entire categories of threats rather than addressing a single issue.“It does not just solve one threat vector, it solves across a whole gamut of things,” Evan explains. This approach reflects a more strategic use of resources, where the goal is not to solve every problem individually, but to reduce risk at scale.AI Will Accelerate EverythingFor Evan, the impact of AI is undeniable, even if the full implications are still unclear. “I feel like I cannot quite imagine what two or five years ahead looks like,” he says. What is clear is the speed. The time between discovering a vulnerability and seeing it exploited is shrinking rapidly. “It used to be weeks, now we are talking maybe hours or a day,” he explains. At the same time, defenders are gaining new capabilities. AI can improve detection, response, and remediation, allowing organizations to move faster and operate more efficiently.“I think both defenders and adversaries will mature at the same level,” Evan says. For him, the dynamic is not about one side gaining an advantage, but about an acceleration on both sides. The result is a faster, more demanding environment where organizations must be ready to respond in real time.AI as a Business ImperativeOne of the most notable shifts Evan highlights is how AI is being viewed within organizations. “The question from organizations always is, how can we get it faster?” he says. Unlike previous technology waves, AI is not just an optimization, it is a business priority. “AI is really a business imperative,” he explains. This changes the role of security. Instead of evaluating whether to adopt a technology, leaders must focus on how to enable it safely. That requires clear guardrails and close collaboration with the business. It also requires trust that organizations can move quickly without compromising security.Balancing Automation and Talent DevelopmentAs AI introduces new efficiencies, Evan is also thinking about its long-term impact on the workforce. “There is always going to be a need for experts,” he says, but he also raises a critical question about the pipeline of future talent. If entry-level roles are reduced, organizations may struggle to develop the next generation of leaders. Over time, that could create gaps that are difficult to fill. At the same time, AI creates opportunities to elevate existing roles. Tasks that were once manual can now be automated, allowing teams to focus on more strategic work.“Right now, the only limits of AI is our imagination,” Evan says. That balance between efficiency and development will be one of the defining challenges for security leaders in the years ahead.The Fundamentals Still MatterDespite the rapid pace of change, Evan emphasizes that many core challenges remain the same. “The basics are really hard,” he says. Issues like configuration management, process consistency, and root cause analysis continue to require significant effort and discipline. These are not simple problems, even if they are often described that way.At the same time, he sees an opportunity to improve. Many of these processes are still manual and can be automated with the right approach. AI may finally make that possible at scale.Looking AheadWhen asked what will matter most in the near future, Evan is careful not to overstate certainty. “I do not know that I can picture a big shift,” he says. What he does expect is continued acceleration. Organizations that embrace AI, apply it thoughtfully, and build the right guardrails will be better positioned to adapt. He also sees the potential for AI to reshape how security tools work together, acting as a layer that connects and orchestrates across systems.In many ways, the future remains undefined. But for Evan, one thing is clear. Success will depend less on predicting what comes next and more on building the ability to respond to it.
- Profile: Jay Mody, CISO & Head of IT Infrastructure, Chimera Investment Corporationby khaug@klogixcorp.com (Katie Haug) on June 22, 2026 at 6:11 pm
Jay Mody has spent nearly three decades evolving alongside technology itself. Over the course of a 28 year career spanning infrastructure, engineering, cybersecurity, and financial services, he has witnessed wave after wave of transformation. Through it all, one principle has remained consistent: security must enable the business, not slow it down. “I’ve always looked for gaps in business processes and controls, and tried to be proactive rather than reactive,” he says. That mindset has shaped his leadership at Chimera Investment Corporation, where he serves in a dual role as both CISO and Head of IT Infrastructure. Since joining the company, Jay has helped guide Chimera through rapid growth, major acquisitions, evolving regulations, and the transition to a cloud-first environment, all while building a mature cybersecurity program designed to support the business as it scales. Jay sees his role as helping the organization grow securely while preparing for whatever comes next.“I’m always trying to be a business enabler,” he says, “My goal is to let the business drive the car fast while making sure we have the right guardrails and brakes in place when needed.”Security as a Business EnablerOne of the defining shifts in Jay’s career came when he stopped viewing cybersecurity as purely a technical discipline and began aligning it directly with business priorities. “What are the challenges the business is facing? What is the CEO’s vision?” he says. That perspective became especially important after Chimera brought in a new CEO focused on growth and acquisitions. Jay recalls a conversation where the company’s leadership made clear that expansion would move quickly and security needed to keep pace.Rather than positioning cybersecurity as a blocker, Jay focused on demonstrating readiness. He highlighted the company’s investments in compliance, governance, and resilience while building new programs to support brand protection and digital trust.One example involved protecting executive identities and the company’s public presence online. “I implemented a program to protect our digital brand,” he explains. “Making sure there is no impersonation and no lookalike domains out there.” That business-first mindset now shapes how he approaches nearly every security initiative. Whether discussing infrastructure modernization, acquisitions, or AI adoption, the conversation always starts with business impact.Building AI and Data Governance As AI adoption accelerates across financial services, Jay is focused on ensuring governance evolves just as quickly. Two of his largest priorities today are AI governance and data governance, both of which he recently presented to senior management and the board.“AI is something our CEO sees as essential,” Jay explains. “But he wants to make sure we have proper governance and guardrails.” Jay approaches AI through three distinct lenses: AI as an asset, AI as a threat, and AI as a tool. That framework has helped structure how they evaluate risk and manage adoption across the organization.At the center of the strategy is governance. Chimera established an AI task force that brings together stakeholders across enterprise risk, legal, business intelligence, and technology to define policies, training requirements, and operational controls. “We need proper training. We need policy clearly defined,” he says. “Then the operations team can create the controls and processes based on those policies.” The challenge, however, is the pace of change. Jay notes that vendors are increasingly embedding AI capabilities directly into enterprise platforms, often without customers actively requesting them. “They are already introducing AI features into their applications without asking anyone,” he comments. For security leaders, that creates a difficult balance. Organizations cannot afford to fall behind, but they also cannot introduce AI without understanding the risks. “We don’t want to be left behind,” Jay shares. “But we also need to adapt our controls to this changing environment.” To support that effort, they are using the NIST AI Risk Management Framework as the foundation for the governance strategy, while also implementing additional monitoring around AI agents and cloud environments.Preparing for AI-Driven ThreatsWhile AI presents opportunities, Jay is equally focused on how it changes the threat landscape. One of the biggest concerns is how quickly attackers can weaponize vulnerabilities using advanced AI models. “Our response time is narrowing,” he reflects. “We used to get days to patch systems. Now as these models evolve, bad actors will eventually have access to these capabilities as well.” His response centers on two priorities: response time and resiliency. Jay’s team focuses heavily on protecting internet-facing systems through continuous threat exposure management while maintaining strong internal segmentation and zero-trust controls. But he also recognizes that prevention alone is not enough.“If a bad actor breaches our network and brings systems down, I’m going to rely on our established backup and disaster recovery process,” he explains. That preparation is something Chimera has invested in for years. Jay emphasizes that resiliency is not built during a crisis. It must already exist before one occurs.“My team is prepared to respond to any breach or ransomware threat,” he stresses. He also sees AI playing a growing role in recovery itself. They are implementing AI-driven recovery capabilities designed to identify the safest restore points following an incident, reducing recovery time during a potential attack.Scaling Security Through Growth and AcquisitionThe company’s recent acquisitions introduced another major challenge: integrating organizations with very different levels of security maturity. Rather than immediately imposing controls, Jay focused first on awareness and alignment. “These are the gaps we identified in your environment,” he recalls telling leadership teams. “Here’s the roadmap to bring you into Chimera’s secure operating environment.” That roadmap included deploying visibility tools, integrating vulnerability management, and aligning systems with the controls already established within Chimera’s environment.Jay approached both situations the same way: transparency, collaboration, and education. “Technology evolves. Risk evolves,” he explains. “It’s a changing landscape.” Leading Through Collaboration and AccountabilityJay describes his leadership style as collaborative and execution focused. “I want my team to collaborate and work across the business,” he says. “The business needs to understand why we are doing this and where the end state will be.” He also emphasizes accountability. For Jay, projects are not complete when technology is deployed. They are complete only after monitoring, backup, disaster recovery, compliance integration, and documentation are fully operational. “I don’t want someone telling me the project is done,” he says. “I want to know the monitoring is in place, the backup is configured, and the documentation is complete.” At the same time, he is intentionally preparing his team for larger leadership opportunities by gradually giving them ownership over critical systems and initiatives. He comments, “Many team members want to grow and work on different technologies, so I’m giving them more responsibility as they develop.” That investment in people mirrors the support Jay says he has received throughout his own career.Since joining the organization, he has grown from Director of Infrastructure to CISO and Head of IT Infrastructure, gaining direct access to executive leadership and the board along the way.“They’ve given me that growth ladder,” he says. “I have a seat at the table, and I can share risk very transparently.” For Jay, that transparency is essential to effective leadership, especially as AI, cloud adoption, and cyber risk continue to evolve simultaneously.The pace of change may continue to accelerate, but his focus remains consistent: build resilient systems, support the business, and prepare the organization for what comes next.
- Profile: Rob Sherman, CISO, Lantheusby khaug@klogixcorp.com (Katie Haug) on June 22, 2026 at 6:07 pm













