12 Questions That Expose Whether Your Security Program Is Actually Working
A roundup of hard questions CISOs should already be asking — about blast radius, nonhuman identities, and whether 'vibe coding' has eaten your attack surface.

Security programs don't fail dramatically. They calcify quietly, built for last year's threat model, staffed by teams that stopped asking uncomfortable questions. A dozen security leaders recently shared the questions they believe cut through the noise.
Some are classics reframed. Roland Palmer, CISO at JumpCloud, asks his team what specific incident the security program actually prevented — not generically, but concretely, with business impact attached. It's ROI framing, and it forces precision. Vague answers mean vague value.
The identity questions are where things get interesting. Palmer calls IAM for both human and nonhuman identities an "every-hour question" now. AI agents, shadow deployments, and automated pipelines churn out new identities faster than most governance processes can track. Richard Watson, global cybersecurity leader at EY, adds a sharper edge: most traditional identity governance tooling wasn't built for nonhuman principals at all. That's not a configuration gap. That's a category gap.
Mean time to detect still matters. Dale Hoak, CISO at RegScale, frames it bluntly — assume breach, then ask how fast you'd actually know. Purple team exercises and tabletop drills exist precisely to stress-test that assumption before an attacker does it for you. MTTD correlates directly to blast radius. Small number good. Large number bad.
Third-party risk remains the question organizations keep deferring. Hoak notes that most companies have better visibility into their own environments than into the vendors and software dependencies sitting upstream. Recent supply-chain incidents have demonstrated exactly what that asymmetry costs.
Then there's the vibe-coding problem, which sounds whimsical and isn't. Nico Waisman, CISO at XBOW, is asking whether security programs have guardrails fast enough to keep pace with AI-assisted development that has handed code-generation capability to every employee, not just engineers. The attack surface implication isn't theoretical.
Doug Kersten at Appfire draws the shadow-AI parallel plainly: employees are adopting AI tools before procurement or legal even knows they exist. Same visibility problem as shadow IT. Faster timeline. Broader data exposure.
Sean Murphy at BECU, the fifth-largest U.S. credit union, poses the question that probably belongs first on the list: "What are the security things that will shut down the business?" Not IT resilience. Business resilience. The gap between those two framings is where programs fall short.
Watson's speed question deserves a read-twice. Today's governance processes were built for a slower threat environment. AI accelerates attacker tooling and defender tooling simultaneously. The organizations that fail are the ones that upgraded their offense wishlist but didn't touch their detection cadence or response playbooks.
None of these are novel primitives. Detection latency, identity sprawl, third-party dependencies, shadow technology — these are known categories. What changes is the rate at which AI compounds each of them. That's the actual story here.



