The United States needs a federal consumer data privacy law, but not one like the recently proposed SECURE Data Act.

On April 22, Republicans on the House Energy and Commerce Committee introduced the SECURE Data Act (H.R. 8413), making it the first attempt at comprehensive privacy legislation in years; unfortunately, the bill is a disaster, as it would erase too much state-level progress.

The main problem with the SECURE Data Act is the issue of federal preemption. The bill would preempt all state legislation, effectively eviscerating strong state legislation like California’s CCPA (2018) and CPRA (2020).

The preemption problem

Nobody, myself included, wants businesses to have to deal with a patchwork of data privacy laws. We absolutely need a federal data privacy law on the books. That said, any federal law should build on top of state-level laws; it shouldn’t dilute existing laws, rendering them unenforceable, and erasing years of state-level legislative work.

As of May 2026, the U.S. has comprehensive privacy legislation in 21 states: Alabama, California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oklahoma, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia.

Of course, there is a great deal of nuance here, as some states have stronger laws than others. Nevertheless, any proposed federal law should be treated as a floor to build on top of these state-level laws, rather than a ceiling.

I agree with the Electronic Frontier Foundation’s Mario Trujillo, who writes, “Federal privacy laws should allow states to build ever stronger rights on top of the federal floor. Many federal privacy laws allow this, including the Health Insurance Portability and Accountability Act (HIPAA).”

Which businesses are affected

The proposed bill would apply to all businesses subject to the FTC Act, as well as all businesses in the U.S. that process the personal data of 200,000 U.S. consumers or more.

Additionally, there’s another standard that would affect other businesses; any business that processes the data of more than 100,000 U.S. consumers and derives more than 25% of revenue from selling that data would also be subject to the SECURE Data Act.

As it stands, the proposed bill exempts businesses with less than $25m in adjusted gross annual revenue.

Key provisions of the bill

The SECURE Data Act mandates that U.S. consumers be given a clear mechanism to opt out of targeted advertising practices as well as the sale of their personal data.

Were the bill to pass, many businesses that process and control consumer data would be forced to obtain opt-in consent before they processed any sensitive consumer data, including geolocation, financial information, and health data. Also, the bill would require businesses to get parental consent before processing the personal data of kids aged 13-16.

Data broker registry

This is my favorite part of the proposed bill. The SECURE Data Act would create a federally mandated data broker registry. Maintained by the FTC, this registry would require many data brokers to register every year and disclose all of their data collection and sales activities.

All data brokers that make over 50% of their profits by selling our personal data would be forced to register in the FTC’s public database. This is a wonderful development.

Enforcement

Here is where things get problematic for privacy advocates. The SECURE Data Act mandates that all enforcement be handled by the FTC and state attorneys general.

Particularly problematic for most privacy advocates, the proposed bill doesn’t include a private right of action, meaning that consumers cannot file civil suits against law-breaking companies. Only the FTC and state attorneys general can enforce the SECURE Data Act.

Moreover, the proposed bill includes a “45-day notice-and-cure provision,” which basically means that if a company is caught breaking the law, they have 45 days to “cure” any violation with no penalty.

Personally, for me, the lack of a private right of action isn’t a deal-breaker. And I think future iterations of this bill can reach a compromise on this issue.

No private right of action

Although privacy rights activists are up in arms about the lack of a private right of action, Electronic Privacy Information Center (EPIC) Deputy Director and Policy Director Caitriona Fitzgerald suggests that a compromised version of a private right of action could be reached down the line.

As Fitzgerald writes, “Previous bipartisan privacy proposals, such as the American Data Privacy and Protection Act and the American Privacy Rights Act, proposed a compromise version of a private right of action that allowed for injunctive relief so that consumers could force companies to stop violating the law, but did not allow for statutory damages.”

I think such a “compromise version” of a private right of action could get future iterations of this bill across the finish line.

The issue of “notice and choice” and burying fine print in the privacy policy

Another important issue to highlight is “notice and choice”; this is a common model in data privacy that allows companies to collect our data as long as they tell us what they’re doing with it (and they give us an option to opt-out.)

The problem with “notice and choice” is that sometimes exactly how the data is being used is buried in the companies’ privacy policies. And who reads these?

Also, many times, the consumers’ choice to allow data collection is bundled with the service itself, creating a take-it-or-leave-it situation.

Alternatively, companies sometimes combine user consent for necessary data collection (e.g., a navigation app needing our location data in order to provide us with directions) with totally unrelated uses (e.g., selling our location data to third-party advertisers or data brokers).

A far better policy is to mandate that companies adhere to data minimization requirements. For example, some state-level laws prevent companies from collecting consumer data beyond what is necessary to fulfill the requested service. This way, even if the consumer technically gives his or her consent, it is still illegal for companies to surreptitiously over-collect and profit from that user’s data in other ways.

The SECURE Data Act perpetuates the notice-and-choice model, as opposed to requiring that companies adhere to data minimization. This is a shame.

Maryland’s data privacy law has an excellent data minimization standard, as did two other previous bipartisan federal bills: American Data Privacy and Protection Act (ADPPA) and American Privacy Rights Act (APRA). It’s too bad the SECURE Data Act didn’t have such a standard.

Support for the SECURE Data Act

I’d be remiss if I didn’t point out that many folks are happy with the proposed bill. As an example, Adam Thierer, a senior fellow at the R Street Institute, was excited to see the bill not include a private right of action. Thierer writes, “Importantly, the SECURE Data Act wisely does not include a PRA, which would only exacerbate America’s growing over-litigation problem.”

And of course, many lobbyists and lawmakers are rejoicing at the chance to dilute the CPRA and other state laws. For example, advocacy group Americans for Tax Reform and twenty-three other center-right groups are particularly excited by the prospect of the SECURE Data Act passing.

The self-proclaimed center-right groups collectively write, “If all 50 states move forward with their own privacy laws, it could cost the American economy over $1 trillion in the next decade, with $200 billion of that burden falling on small businesses.” These 24 groups want to see “strong preemption, with no private right of action and no open-ended rule-making authority for federal agencies or additional state regulations.”

My take

I agree with the EFF’s contention that “the bill is weaker than congressional proposals in prior years, as well as most of the 21 state consumer privacy laws already on the books.”

The fact that the SECURE Data Act preempts existing state-level laws ultimately makes this a bad bill.

Aside from the federal preemption problem, which is a deal-breaker in and of itself in my mind, there are several other issues with the SECURE Data Act. As it stands, the bill perpetuates the “notice and choice” status quo, allowing organizations to obfuscate how they process consumer data, as they bury the specifics deep in their corporate privacy policies. Given that few consumers bother to read or understand corporate privacy policies, data minimization provisions would be much better than this “notice and choice” approach.

Unlike other privacy advocates, I am less concerned about the bill’s failure to include a private right of action. That’s not a deal-breaker for me. However, I am inclined to agree with EPIC’s Fitzgerald, who writes, “The combination of minimal consumer protections, weak enforcement, and insanely expansive preemption of state laws makes the SECURE Act a disaster for Americans’ privacy.”

That said, there are some great things inside the proposed SECURE Data Act. I particularly like the call for a federal data broker registry. It’s refreshing to see politicians on both sides of the aisle ready to crack down on the data brokerage industry, a particularly pernicious part of the data surveillance apparatus.

You install a fancy alarm system in your house thinking that you can conquer every threat that comes in your way. One day, an alarm goes off… but no one knows what to do.

The system works exactly as intended. This is not the failure of the system, this is the failure of the preparedness.

In enterprises, AI is playing the same role. AI is now embedded across security operations. It monitors network behavior, detects anomalies in real time, prioritizes alerts, and, in some cases, initiates automated responses.

Simultaneously, AI is shaping both sides of the equation. The same capabilities that strengthen defense are also being used to create faster, more adaptive attacks, narrowing the margin for response.

When something goes wrong, preparedness is not defined by how quickly a threat is identified, but by how effectively it is handled.

The AI paradox: Stronger defense, smarter attacks  

AI is not in an early stage in today’s enterprises and their cybersecurity systems. It is mainstream now. Already, 73% of organizations have integrated AI into their cybersecurity systems.

This sounds reassuring, except that at the same time, 65% of IT leaders say their current cybersecurity defenses cannot handle AI-powered attacks.

This highlights a deeper contradiction. Enterprises are continuing to integrate AI into their system to position them as future-ready, but how are they actually using it?

If 65% of IT leaders say their current cybersecurity defenses cannot handle AI-driven attacks, are organizations truly preparing for what lies ahead, or simply adopting AI without assessing its real impact?

What enterprises mistake for AI-ready cybersecurity preparedness? 

AI has quickly become the default layer in the modern cybersecurity systems. Nevertheless, AI-readiness is the system is not defined by how well the systems are understood and managed.

For many organizations, preparedness begins and ends with deployment.

AI systems are trained on the data, influenced by patterns, and largely dependent on the configurations that can be easily manipulated.

Let us assume a scenario:

An AI system flags an anomaly in network behavior. The alert is prioritized based on pattern recognition, and the system assigns it a risk score. On the surface, everything is functioning as expected.

But what happens next depends on the context.

  • If the model has been trained on incomplete or biassed data, the alert may not reflect the actual severity of the threat.

  • If configurations are misaligned, the system may either over-prioritize noise or underplay critical signals.

  • If teams rely entirely on the system’s output without validation, response decisions may be delayed or misdirected.

The system identifies the signal. But the interpretation, validation, and response still depend on human understanding and operational clarity.

This is not a hypothetical situation.

In 2026, the Mythos AI system demonstrated what the future of cybersecurity could look like. The model was capable of identifying hundreds of critical vulnerabilities across complex systems in a fraction of the time traditional methods would take.

On the surface, this represents the ideal state of preparedness. Faster detection, broader visibility, and more intelligent systems.

Despite these restrictions, Bloomberg reported that a small group of unauthorized users accessed the model through a third-party vendor environment on the same day Anthropic announced its limited release.

A tool built to strengthen defense had simultaneously become a point of vulnerability. This is where assumptions about preparedness begin to break. The verdict was not that the AI failed, but that the organizational layer around it was not ready.

Toward a definition of cybersecurity preparedness that can withstand the age of AI 

Cybersecurity preparedness in the age of AI is not only about the presence of the intelligence system.

As attack timelines compress, with breakout times now measured in minutes rather than days, the advantage does not lie in detecting more signals, but in reducing the time between detection and decisive action.

CrowdStrike’s 2026 Global Threat Report highlights this clearly. The average breakout time, the span between an attacker’s initial access and lateral movement through a network, dropped to just 29 minutes in 2025, a decline of 65% from the previous year.

Simultaneously, more than 50% of known vulnerabilities no longer require authentication, lowering the barrier for exploitation.

This creates an environment where threats do not need to be sophisticated to be effective. They only need to move faster than the organization’s ability to respond.

Real preparedness for a cybersecurity attack in the age of AI is not measured by the sophistication of tools. It is measured by what happens in the 29 minutes after the alarm goes off.

But are response processes tested, not just documented? Is the gap between detection and action measured in seconds or in escalation chains?

Those are the questions that separate organizations that are genuinely resilient from those that are merely well-equipped.

Alarms will go off again… is your organization prepared? 

When people talk about the biggest gap in the enterprise security systems, they immediately point to misconfigured AI model or an unpatched system. But, it is no longer the technical deficiencies.

The most dangerous vulnerability in 2026 is not sitting in your tech stack. It is sitting in your org chart.

Attackers have already automated their side of the equation, AI is merely compressing the time between their intent and their execution. Now, the remaining variable is how swiftly the IT team can think, react and determine what actions to take.

Let us be honest, right now that variable is losing. This is the skill gap that no AI tool can close.

The WEF Global Cybersecurity Outlook 2026 found that 66% of organizations report significant cybersecurity talent shortages. And 56% of the survey respondents cited that the cybersecurity skills shortage is their top challenge to improving resilience.

The consequences are measurable: 88% of organizations experienced at least one significant security event in the past year that respondents tied directly to a skills shortage.

These are not pipeline problems waiting to be solved by better hiring. They are operational failures happening right now, inside organizations that have already invested heavily in the right tools.

No platform fixes this. No AI layer closes a skills gap.

Genuinely resilient organizations treat their security posture as a hypothesis to be tested, here is how:

  • Stop running drills that your team could pass in their sleep. Make it uncomfortable. Make it real.

  • An alert that nobody acts on is just a notification. Start measuring the gap between “we saw it” and “we stopped it.”

  • Detection without response is just expensive logging. Keep closing the loop until the process becomes second nature.

  • Your AI is only as smart as the data you fed it. Audit it like you would audit anything else that holds the keys to your kingdom.

  • What about those third-party vendors with access to your systems? They are your problem too. Treat them like it.

The 29-minute breakout window is not a technology problem. It is an organizational readiness problem.

Closing that window requires not just faster tools but faster humans, clearer response chains, and the institutional muscle memory that only comes from repeated, realistic testing.

The alarm will go off again. The only question worth asking is whether your organization has rehearsed what happens next, before the clock starts.

In this episode of the ManageEngine Insights podcast, host Lauren Spiller speaks with James Healy, author of BS at Work and founder of The Behaviour Boutique, about a growing contradiction in modern organizations: Despite smarter systems and rapid advances in AI, adoption continues to fall short.

At the heart of the problem, James argues, is a flawed assumption. Organizations design systems with the expectation that employees will behave logically, follow processes, and adapt seamlessly.

But human behavior doesn’t work that way. People are influenced by emotion, social context, and identity, creating a disconnect between how systems are built and how they are actually used.

A defining theme in the discussion is identity. Work is not just about completing tasks but about how people see themselves within their roles. This is where many transformation efforts quietly fail: not at the system level but at the people level.

The conversation then turns to AI and its role in the future of work. While AI continues to excel at structured tasks, James highlights a less visible layer of work that often goes unnoticed.

If you’re looking to understand why AI and workplace systems don’t always deliver on their promise, this conversation offers a grounded perspective on the human side of work. Dive in now.

Agenda

  • Why AI and modern workplace systems are built on flawed assumptions about human behavior
  • The gap between system logic and real employee behavior
  • Identity at work: Why change feels personal, not just operational
  • Common behavioral blind spots in IT rollouts
  • The importance of soft skills
  • AI in the workplace: Why we anthropomorphize technology
  • Guardrails for the human/AI interface

Let me paint you a picture.

It’s 2:47am. Somewhere in a dimly lit room that smells faintly of cold coffee and existential dread, a security operations center (SOC) analyst is staring at alert number 847 of the night. The alert says: “Suspicious login from unusual location.” 

The analyst, bleary-eyed and running on willpower and an energy drink, clicks into it.

Username: j.smith@corp.com

Location: Chicago

But wait! John Smith was in London this morning. Or was it yesterday morning? The analyst squints. Checks another tool. Opens a ticket. Escalates. By the time anyone looks at it, John Smith has already had his credentials used to exfiltrate six months of financial records.

This is much more likely than the worst-case scenario that you imagined.

The modern SOC is, in many ways, a monument to human suffering dressed up in dashboard form. Thousands of alerts. Dozens of tools. Four analysts. And somewhere out there, an attacker who only needs to be right once.

The math has been broken for years   

Let’s talk numbers.

The average large enterprise SOC processes over 3,000 alerts per day from more than 30 different security tools. A 2025 industry survey found analysts collectively handle around 960 alerts daily, and that’s the average.

Then there’s the speed problem. In 2025, the average breakout time (the time between an attacker’s initial access and full lateral movement through a network) compressed to just 4 minutes in the fastest observed incidents. The average SOC analyst—working through a queue of hundreds of alerts—simply cannot triage, investigate, and respond in 4 minutes. Not unless they’ve discovered some way to violate the laws of physics that the rest of us haven’t been told about.

And underneath all of this sits a workforce crisis so severe it would be funny if it weren’t catastrophic. The global cybersecurity skills shortage is approaching 4.8 million unfilled positions worldwide. Hiring your way out of this problem isn’t just expensive, it’s impossible.

So yeah, the math has been broken for years. Agentic AI is the first technology that changes it.

So what is an agentic SOC, actually? 

An agentic AI system isn’t simply a chatbot you ask questions. It’s an AI that pursues goals autonomously, executing multi-step tasks, reasoning through incomplete information, and acting across tools without waiting to be told.

In security operations, that means an agent receives an alert, and without prompting correlates it against threat intelligence, checks endpoint telemetry, reviews identity logs, assesses severity, executes initial containment, and produces an investigation report. All in seconds. Around the clock. Without getting demoralized.

The global AI-driven cybersecurity market was valued at approximately USD 25.35 billion in 2024 and is expected to expand to USD 93.75 billion by 2030, registering a CAGR of 24.4% between 2025 and 2030.

It’s clear that the market—unlike the analysts it’s meant to assist—is not fatigued.

The proof isn’t theoretical. It’s already sitting in production logs 

Muhammad Ali Paracha, Transurban’s head of cyber defense, didn’t set out to build an AI system. He set out to fix something that had quietly broken. Alert volumes had grown so large that analysts were triaging just 8% of tickets. The other 92%? Invisible. And at month-end, when senior analysts reviewed closed cases in Excel, they kept finding errors in tickets that couldn’t be reopened. The damage was already done.

Hiring more analysts wasn’t the answer. It was too expensive, too hard to find, and too slow to scale.

So his team built two AI agents: one to check that incoming tickets were categorized correctly, another to verify resolution notes before cases closed. Neither agent made final calls. They flagged issues and handed findings back to the human analyst. Simple quality control. But the effect was significant: analysts were finally making decisions based on accurate, complete information instead of memory and guesswork. The next phase is automating the entire triage and response process. What started as a paperwork fix is becoming a full operational model.

That pattern of agents doing the heavy lifting so humans can do the thinking is showing up everywhere.

This is the shift that matters. From analyst-as-triage-machine to analyst-as-strategic-thinker. It’s better for security. It’s better for analysts. It’s better for organizations. It’s almost suspicious how obviously correct it is.

The objections (And why most of them are wrong) 

Objection 1: “AI will replace all our analysts and destroy jobs” 

It won’t, and this framing misunderstands what agentic AI is good at. Agentic AI excels at speed, scale, and pattern recognition across enormous datasets. It is genuinely bad at judgment calls with organizational, legal, or reputational implications. Every production agentic SOC deployment in 2025 operates on a human-in-the-loop model for consequential decisions. The agent handles coverage and speed. The analyst handles accountability and judgment. Organizations that try to cut humans out entirely will not save money, they’ll expose themselves to risks the technology was never designed to absorb.

The more honest concern is: what happens to analysts’ skills? Gartner has warned that by 2030, 75% of SOC teams could experience erosion in foundational security analysis skills due to overdependence on automation. This is real. The answer isn’t to avoid agentic AI. It’s to design for skill retention deliberately. Use agents to handle the tedious; keep humans engaged in the interesting.

Objection 2: “We don’t trust AI making autonomous decisions about our infrastructure” 

This is a sensible objection dressed up as a philosophical one. The answer is governance, not avoidance. Define clearly what agents can do autonomously (enrich, triage, investigate, recommend), what requires human authorization (isolate a server, block a user, execute a remediation), and what requires senior review (anything with legal or business consequences). The boundaries aren’t hard to draw. They just require someone to actually draw them.

Objection 3: “The threat landscape is too dynamic for AI to keep up” 

Respectfully: the threat landscape is too dynamic for humans to keep up. AI-driven phishing attacks increased by 1,265% in 2025Ransomware incidents grew by 45%. Attackers are already using AI at scale. The question is not whether to deploy AI in the SOC. The question is whether you’d like your AI or theirs to win.

What does the agentic SOC actually look like in 2026

We’re past the hype cycle. This is real, it’s deployed, and it’s delivering results. But adoption is still early. The Gartner Hype Cycle for Security Operations places AI SOC agents at the Innovation Trigger stage, with market penetration at just 1-5%. That means most organizations are either ignoring this entirely or doing preliminary evaluations. Neither of those positions will be comfortable in a few months.

Organizations that start building agentic SOC capabilities today will have a real security advantage over their competitors. Not a small one either. A big one. The speed gap grows. The cost savings grow. Junior analysts become more effective. It all adds up.

Attackers have already made their call. They are using AI to move faster and hit harder.

So here is the question every CISO needs to answer: are you going to keep sending your analysts into battle with a queue of 3,000 alerts and a cup of stale coffee? Or are you going to give them a machine that never sleeps?

The choice seems obvious.

Before DaVonda St. Clair ever reviewed a firewall policy or assessed an infrastructure vulnerability, she was managing pallets of military equipment for the U.S. Air Force. As an Air Force logistics manager, her job was to make sure the right supplies were in the right place. “Just in case we went to war,” she explained over Zoom.

She didn’t know it then, but she was already doing the work of a cybersecurity architect — which is now her job at IBM. More specifically, St. Clair advises Air Force Civil Engineer leadership on cyber risk management and infrastructure protection. She also holds a Lean Six Sigma Master Black Belt, a credential she’d earned in practice before knowing it existed.

St. Clair’s path from Air Force logistics manager to cybersecurity architect isn’t a detour; it’s a direct route. For security leaders struggling to build their A-team, her story is just one example of where to look. This article explores why some less obvious backgrounds are a natural fit for cybersecurity and how CISOs can home in on a largely untapped talent pool.

What the resume doesn’t show

As recently as 2024, the conversation about the cyber talent gap focused on headcount, with reports citing millions of unfilled roles. But skills shortages have since become the top concern, casting doubt on the traditional hiring profile.

What organizations typically look for in a candidate — computer science degree, technical certifications, teeth cut in IT — is no longer sufficient. Today, 95% of cybersecurity teams report at least one skills gap, with governance, risk, and compliance among the more notable shortfalls.

St. Clair holds a degree in computer information systems, which isn’t unusual for a cybersecurity architect. But her resume told a different story — one that, while seemingly unrelated on paper to cybersecurity, turned out to be exactly the right preparation for it:

  • Checking shelf life on war reserve materials is, functionally, software auditing: verifying what you have, what’s expired, and what needs to be renewed.
  • Assessing which squadron needs what equipment translates directly to understanding which teams need what tools and access levels.
  • Sourcing materials from other bases without stripping them of critical resources is a form of third-party risk management — solving your own problem without creating another elsewhere.

When St. Clair took on her first IT role after leaving the Air Force, then, the overlap was obvious. “It was the same thing,” she says. “I just had to change my job title.” She already knew how to control levels of access and manage assets — she just needed to learn the language and translate it to a new context.

What hiring practices often miss

Technical fluency is the minimum requirement for most cybersecurity roles. But the ability to think across an entire system — to ask what happens on the other side when something fails — is harder to screen for, and rarer than most hiring managers realize.

“When you have engineers who are solely technical, they’re thinking of this switch, that router,” says St. Clair. “It needs to go here, it needs to go there. And most of the time, they’re not thinking — what is the communication path behind that switch or router? And how would that affect the end user?”

St. Clair was already applying this process-oriented way of thinking in the military long before she earned her Lean Six Sigma Master Black Belt. This certification — built around process improvement, waste elimination, and variation reduction — formalized what she’d spent years practicing in the Air Force without knowing it had a name.

“There are people who will put blinders on so they can really focus and get things done, and that’s fantastic,” St. Clair acknowledges. “But if you’re not looking at the entire picture, you may have to do something over again.”

The problem is, this mindset isn’t easily represented on a resume — at least not in the keywords the ATS (applicant tracking system) will scan for. Someone who can anticipate a process breakdown before it becomes a vulnerability is the kind of candidate organizations want but rarely find. Had St. Clair applied for a role requiring five years of security-specific experience and a CISSP, her resume wouldn’t have made it past the first filter.

What uncovering talent actually looks like

St. Clair landed her first cybersecurity role thanks to a director who noticed she did something her peers didn’t: she made it her business to understand everyone else’s job.

It didn’t happen overnight. After leaving the Air Force, she spent several years in adjacent roles, steadily moving closer to cybersecurity while doing what she’d always done: ask questions, solve problems, and learn every part of the operation around her.

“I was working in inventory management, but I wanted to get into tech,” she explains. “I was ordering the equipment and software. But I would go around to every team and say things like, ‘You’re ordering a lot of these parts. Why is that?’ Then, ‘What are you doing with this cabinet? If I order bulk pieces, could we store them here?'”

“I’m not good at sitting behind a desk all day,” she laughs. “There’s always something we could do better.”

Once, when a vendor sent the wrong shipment and told St. Clair to keep it, she tracked down another site that could use it instead. Another time, she helped an engineer think through how to sunset aging software without disrupting thousands of customers.

The director noticed the way she approached problems — even those that weren’t hers to solve — and encouraged her to apply for a job in information assurance, a field adjacent to cybersecurity that draws on many of the same skills she’d been using all along.

It wasn’t a meticulously worded job posting or an ATS that uncovered St. Clair’s talent. It was someone watching her work. That distinction matters.

Takeaways for tech leaders

Stories like St. Clair’s are, admittedly, atypical. They require leadership who are willing to look past job titles to recognize real, demonstrated capabilities. The takeaway here is that the signals worth looking for won’t always be found on a resume.

CISOs and security leaders might instead pay attention to how candidates talk about their previous work — whether they describe processes, ask about downstream effects, and think about the people on the other side of a decision. Someone who spent years in logistics, compliance, law enforcement, or any field demanding operational thinking under pressure may be exactly what your team is missing.   

What if AI isn’t just assisting you but quietly influencing you?

AI no longer just writes emails or answers questions. It watches how you respond, what you trust, what calms you, and what persuades you. And then it learns.

From emotionally fluent chatbots to eerily persuasive recommendations, AI is beginning to use the same social engineering tricks that were once the forte of human hackers, only now it’s faster, subtler, and at massive scale.

So what happens when manipulation itself becomes automated?

To unpack this shift, we’re joined by Jamie Woodruff, one of the United Kingdom’s leading ethical hackers and a specialist in exposing how trust gets exploited. Known for breaking into systems by hacking people rather than code, Jamie brings a rare, human-first lens to cybersecurity.

In this conversation, he draws chilling parallels between classic social engineering and the emerging reality of AI-driven influence, showing how machines are now learning the same tricks humans once perfected.

Listen to the episode to understand why the easiest system to hack today isn’t software, it’s trust.

Agenda:

  • How AI crossed the line from a helpful assistant to subtle influence engine

  • Why humans trust machines faster than they trust people

  • How AI models predict emotion, hesitation, and compliance at scale

  • The rise of AI-generated manipulation inside everyday workflows

  • Why traditional security measures can’t stop psychological exploits

  • The importance of AI governance evolving beyond data to include influence and behavior

  • How you can spot manipulation and reclaim agency

Unsure about AI? Take our two-minute quiz for a clear readiness score Arrow X
x