Agents After Dark
Sara Abak on securing the enterprise while AI outruns the rules
Sara Abak asks a simple question: would a carmaker ship a vehicle without a seatbelt?
In this episode
- Regulate frontier AI like any product that can cause harm at scale
- Anchor security in the business, because you cannot protect what you cannot see
- Board trust beats laying down the law and the department of no
- Fund AI work inside existing projects with legal, HR, and IT
Key takeaways
- 0:00 In the cold open, Sara compares releasing frontier models like Fable and Mythos without safety testing to a carmaker shipping a car without a seatbelt, and says every cyber leader she talks to is worried about them.
- 1:59 She anchors every new engagement in what the business actually does: objectives per business unit, threat surface, endpoints, suppliers, customers, data, and geolocation, before applying any framework.
- 4:16 Her core principle is you can't protect what you don't know and can't protect what you can't see, so mapping the organization always comes before designing controls.
- 8:02 She pushes back on the traditional CISO stance of laying down the law, arguing the job is to build trust with the board and audit and risk committee so people actually accept the advice.
- 11:13 Her clinical psychology background helps her recognize when an initiative is a dead course, so she can cut her losses rather than keep spending time and energy she won't get back.
- 16:16 She's not arguing to block all innovation, she wants a pragmatic approach where anything unsafe and chaos-causing gets paused and blocked from release until it's proven safe.
- 21:19 AI capabilities inside vendor platforms, like ERP systems or Diligent board papers, stay switched off until they pass a review and risk assessment rather than being enabled by default.
- 31:44 Standalone responsible AI programs rarely get funded, so she anchors AI work inside an existing digital or data project with people and culture, legal, and IT at the table instead.
Highlights
Toyota or Nissan or Volvo, whoever it is, would not release a car without a seatbelt or safety features, and I see it in the same way that Mythos and Fable should not be released because it's dangerous.
You can't protect what you don't know. You can't protect what you can't see.
It's not what you talk about in the meetings, it's what you talk about in the hallway, what you talk about before you get there, and who you talked to before you get there that's going to make a big difference.
Full transcript 35:48 · click to expand
Cold open: the seatbelt argument
Sara: Every single leader I’ve spoken to, or person in cyber I’ve spoken to, is worried and concerned about Mythos and Fable. Toyota or Nissan or Volvo, whoever it is, would not release a car without a seatbelt or safety features. So I see it in the same way that Mythos and Fable should not be released. There needs to be more regulation around software and solutions.
Welcome to Agents After Dark
Matt: Hello everybody, you are listening to Agents After Dark, powered by Prefactor. I am Matthew Doughty, CEO and co-founder of Prefactor.ai. As enterprises deploy more AI agents, one question becomes increasingly difficult to answer: how do you actually know what your agents are doing? Prefactor gives organizations a place to see how their agents are behaving, where they’re performing as intended, where risk is emerging, and what action needs to be taken.
I’m delighted to be joined today by Sara Abak, who has been acknowledged as a top 100 cybersecurity leader by The Cyber Express. She regularly appears on stage in Australia at a number of conferences as an extremely experienced CISO operating across energy and utilities. Thank you so much for being with me today, Sara. When we’ve spoken before, you have a unique approach to coming into organizations that have had complicated relationships with security, and being able to bring people along the journey. How do you go into an organization and change the culture around security and cybersecurity when entering for the first time?
Sara: Thanks for having me, Matt. I’ve gone through this process a couple of times, and it’s different for each organization, but the pattern and the strategy you use is very similar.
Anchoring security in the business
Sara: It’s really anchored in understanding what’s important for that business or businesses, and that’s probably one differentiator I recommend even for technology leaders: to be able to understand what the organization is actually about, what the objectives or purpose of each business unit are, what they’re trying to achieve. Doing a bit of a threat surface assessment to see how many people there are, how many endpoints, what technologies they have, who their key suppliers and key customers are, how much data they’re holding and what kind, and having a look at their geolocations. Those data points are probably the most important things I anchor myself in to build a view of what may be important, what the threats may be, and what the channels of attack are for that organization.
From there I build using good practice cybersecurity capabilities or frameworks to see which are applicable, while also getting a view of the current security posture, usually through an external supplier if that assessment hasn’t already been done. Without that mapping, you’re just applying a generic theoretical approach, and that doesn’t work because you can’t connect with the leaders of each business unit. You can’t help them, you can’t enable them. You can’t protect what you don’t know. You can’t protect what you can’t see. So the best thing to do is really understand all of those things and then develop, design, uplift, or augment the services you need to provide, whether that’s internal, hybrid, or outsourced, depending on size, risk, budget, and where the organization sits in terms of growth.
The most important thing is demonstrating that you’re going to make it easier for people to do business with you. It’s not about the cyber part, it’s about why you’re there and how you can help the organization, the people, and the business units. It takes time to create that culture change, and you demonstrate the positive impact through how you approach it and how your team communicates with people at various levels.
Escaping the department of no
Matt: When we last spoke, you talked about the role of the CISO as a platform and enabling function for the business. I think when most people picture a CISO, there’s a reputation that it’s the department that says no. Where do you think that gap comes from, and how have you shifted that mentality with the people you’ve worked with?
Sara: The short answer is through unsuccessful attempts over the last ten-plus years, trying to create and lead change and seeing the impact it has on people and culture. The way I adapted my style, I use the analogy that my role is to create a platform for people to take off and do what they need to do safely. So I anchor the services I’m providing to actually help them, while being firm and professional about how I have difficult conversations, being open about the risks and exposure, and backing that with data and facts.
I think what’s influenced this in the past is how CISOs traditionally behave at an audit and risk committee or board or ELT level. There’s an expectation that we’re governing things independently and need to lay down the law. I remember saying to one really experienced CISO who was clashing at the board level, “Don’t you want to build trust when you go to the board and the audit and risk committee? For them to accept what you’re saying, you need to build that trust.” The reason they’re pushing back is probably because your style isn’t adapting to what they’re expecting. So it’s about simplifying and making it organization specific when you go to the board, showing why it matters so it resonates with them, rather than applying a one size fits all approach.
Clinical psychology and reading the room
Matt: At the beginning of your career you trained in clinical psychology.
Sara: I didn’t train in it, I got a university degree in it.
Matt: A university degree in it. What’s interesting about the approach you’ve described is it’s almost a management philosophy of building trust to bring people along. How much do you lean on that psychology background day to day, especially in a world with this much change and risk?
Sara: It’s really important, given how much behavior, values, and attitude matter when you go into an organization. It’s about spending the time upfront to understand people’s personalities and what’s driving them, why they have a certain pattern of behavior. You can’t get lost in it, because it could become a never-ending cycle, but it gives you a view into how to get the best out of the situation. When you go in empathizing, not being defensive, and not fearful, you get more out of the partnership even when you disagree with stakeholders.
You may also figure out that this is a dead course, that you’re not going to get much out of it, so you cut your losses and approach it differently rather than wasting your time and energy and somebody else’s. Earlier in my career I’d prepare a great business case and expect it to land well, and it usually wouldn’t. What I’ve learned over the last ten to fifteen years is that sometimes you’re not going to get the answer you want the first time, so you go in knowing where you can create change, what phases you have to work through, and that you might have to seek approval or support over time rather than all at once.
It comes back to the human factor, because you’re working through people, not bots. With a bot, if you tell it something, it just goes and does it if the program allows it. With humans, you can’t just say do this and expect it to happen. It’s got to be adaptable, and it’s not what you talk about in the meetings, it’s what you talk about in the hallway, what you talk about before you get there, and who you talked to before you get there that’s going to make a big difference.
Fable, Mythos, and the case for regulation
Matt: You gave me a nice bridge to the next question, because you can’t control bots the way you can influence people. About two weeks ago Fable was pulled from Anthropic’s library, and I suspect it’ll get re-released soon. The news last week was that the NSA said it had broken all of their controls. When things move at that pace, how do you adapt as a cyber leader, and how do you help others go on that journey when people’s awareness of the damage an agent can do today is minimal relative to the impact it can have?
Sara: It’s two parts. First, how I keep up to date: I’m part of a large cyber community, and I regularly attend key events just to connect and talk to other leaders, share knowledge, and hear how they’re dealing with things. A problem shared is a problem solved. On top of that, I have a few views around Fable and Mythos. The first is that, unfortunately, we don’t have any regulation or laws, and that’s why this chaos is occurring in my opinion. That’s why every leader or person in cyber I’ve spoken to is worried and concerned about Mythos and Fable.
Toyota or Nissan or Volvo would not release a car without a seatbelt or safety features and providing assurance, and I see it the same way, that Mythos and Fable should not be released because it’s dangerous. It may be criminal, it may not be, but there needs to be more regulation around software and solutions if they can be so damaging and chaotic to the whole world. I’m not saying block all innovation. I’m saying we need to approach it pragmatically: if something is unsafe and is going to cause chaos, it needs to be paused and blocked for release until it’s safe.
Matt: How do you define safe, though? You don’t want to prevent innovation, but someone might say that massively increasing regulation and preventing release of things like Fable ultimately threatens innovation. How do you pair those two things?
Sara: I’d apply the same principles and attitude we apply to any other product, like a car, or the way we license guns: you wouldn’t allow people to get a license if certain criteria weren’t met. It’s a risk-based lens. If something is going to create more risk and expose so many people globally, that’s dangerous. That’s still evolving, so perhaps it shouldn’t be released until there’s enough regulation or assurance that it won’t get into the wrong hands and be misused by adversaries.
Foundations, zero trust, and holding vendors accountable
Sara: The other things we adapt in response to emerging threats are, first, going back to your foundations: making sure your foundational security controls are layered, so it’s harder for an adversary to compromise or damage your critical systems, whatever’s important to the organization, whether that’s OT, email, or CRM. Our role is to make sure we’re not an easy target. That’s the zero trust type of approach, not just the technology, but layering controls at each point where something’s important so it’s harder to compromise and easier to detect.
The other thing is keeping our security and technology partners accountable, asking them to help and explain what they’re doing to protect us, because we’ve all purchased and licensed so much security software and managed services. It’s a shared responsibility, a team sport, so we need those conversations with our partners and suppliers to push them to solve some of these problems and provide assurance.
Matt: I’m interested in the vendor accountability piece, because your vendors are building and using agentic solutions too. I was at RSAC recently and the whole floor in San Francisco was new AI security tools. How do you ensure your stack is up to date, and that you hold those security companies accountable, since something like Fable can damage your organization but just as easily damage your vendors and suppliers?
Sara: That’s really relevant, it’s been coming up a lot the last couple of months. The key is, unfortunately, we want to leverage the AI capabilities vendors have, but we wouldn’t switch them on or enable them until we go through a review and assessment process to determine what it’s actually doing and what the impact may be. We’ve got ERP systems from providers that obviously have AI, and you shouldn’t enable anything until you do an audit or get assurance around the impact. Once you’re comfortable, it’s okay, whether that’s targeted smaller areas or bigger rollouts. It’s the same with Diligent board papers: a lot of organizations haven’t enabled the AI features yet, and you don’t enable it until you go through that due diligence and risk assessment.
Another part is engaging with vendors in your regular governance meetings, asking what AI capability they’re introducing, and getting your security team involved to make sure you’re going through the appropriate risk assessment before making a decision. One of our managed services is actually introducing more AI to help with detection of AI threats and risks, which is good to see, that our partners are also on to a new version that helps us defend against AI type threats.
Shadow AI and locking down what people upload
Matt: That makes a lot of sense as a framework. I think about people using ChatGPT or Claude and uploading information with severe data privacy or customer data implications into the cloud without a second thought, because it helps them build a presentation or be more effective. That’s happening every day in our organizations. How do you guard against that, given these big frontier models aren’t actively putting guardrails in place to stop it? How do you prevent an HR person uploading salary data, or a customer success manager uploading financial data, that then gets used as training material?
Sara: I hear what you’re saying, and a lot of organizations haven’t got complete control or transparency around this, but it’s not any different to ten or five years ago. It’s really about locking down policies and business rules through your environment, deciding what cloud services or applications you want to allow and what actions are permissible, the same way you’d manage a mobile device or a browser. In some organizations ChatGPT isn’t approved at all. In others it is, which is why a lot of organizations have introduced Copilot as their starting safe option, because they have an enterprise agreement with Microsoft and it runs inside their environment rather than data getting out into the public domain.
You lock down the channels where data can leave the environment, whether that’s pasting into Teams, copying a document out, in a browser or an application. But it can’t just be technology. It’s got to be complemented by awareness, policies, an acceptable use policy for AI, code of conduct, and training, whether that’s intranet messages, awareness modules, stand-ups, or using an incident that’s happened as a warning. I never waste a good incident. But you always need to anchor yourself in data and facts. Whenever you have a risk like exfiltration or data loss, you need to periodically monitor, gather, and run reports on user behavior, what SaaS or cloud solutions people are using, not to identify individuals, but to see whether the behavior is risky. We put controls in place to error-proof things as much as possible: if someone navigates toward a risky service, we might block it with a coaching message, or give them a cautious prompt asking if they still want to proceed.
Board reporting and behavior data
Sara: What I used to do, and still do, is every quarter for board reporting and audit and risk reporting, run compliance and KPI audits around what’s happening, so you can decide whether behavior and target performance is as expected and whether you need to make adjustments.
Matt: That’s interesting, I feel like I can clip myself with this one. The idea of performance managing somebody on their use of AI is new, because we’ve heard companies talk about wanting engineers to use AI as much as possible. But what you’re describing is how you performance manage somebody on the negative impact of using AI. That’s an interesting concept.
Funding responsible AI without a standalone budget
Matt: As a final question, imagine we’re at the 26th of June, 2027, looking back. What’s the biggest thing that went wrong for enterprise AI adoption, and what should we have done differently with hindsight?
Sara: I think we didn’t do our assessment, a formal assessment, and then design a supported, funded program to understand the risks and what initiatives we should be funding and driving forward, whether internal or external effort, with a forum or committee to help make decisions and move things along.
What I find when I speak to other leaders is they ask how to fund a responsible AI or ethical AI project, and I’ve shied away from that, because in my experience it doesn’t work as a standalone ask, even though some organizations do manage to fund it. My advice is to be a bit of an opportunist and anchor the AI development, analysis, and adoption journey into an existing project, like a digital or data project, so you don’t need extra funding. You do need various stakeholders at the table, people and culture, legal, IT, to make decisions and analyze data periodically. Doing this as an isolated technology project doesn’t work well, because it’s not a technology problem, it’s an enterprise and community problem, and you need relevant leaders involved, from AI literacy across the workforce to purchasing, onboarding, and partnering decisions.
Matt: That’s a hiding to nothing question, because it’s moving so fast that what good looks like today probably isn’t what good looks like next month.
Sara: There is one thing for sure: you have to be able to make decisions. Think about what’s important to you, what happens if something’s not working, and work backwards from there. Some leaders are waiting for somebody to come and save them with the answer, and that’s probably not going to happen. We have to be the driver as much as possible, to enable adoption safely.
Matt: Good advice for everybody who probably did not audit their AI before investing in it. Thank you so much for your time today, Sara, this has been a really interesting conversation. I’m looking forward to getting more CISOs on, because it brings a level-headed approach to AI in a world where everyone’s talking about it as if it’s going to change everything, when a lot of what you’ve talked about today is leveraging existing patterns and ways of working to manage it safely.
Sara: Thank you, Matt, pleasure.