What I learned from talking to 300 CISOs with Chris Cochran | Security Mondays S1 Ep.3

What I learned from talking to 300 CISOs with Chris Cochran | Security Mondays S1 Ep.3

🎙 Eva Benn 👥 101K 📅 May 4, 2026 ⏱ 32 min 👁 18K 📄 interview 🧭 2026-08-16
Available in: English (current) Français

Keywords

shadow AIAI governancedata poisoningagentic AIthird-party risk

Summary

In this episode of Security Mondays, host Eva Benn interviews Chris Cochran, Field CISO and VP of AI Security at SANS Institute. Chris shares key takeaways from his conversations with 300 CISOs globally about AI security. The discussion covers the prevalence of shadow AI, which is the default condition in most enterprises due to top-down pressure to adopt AI without proper governance. Chris emphasizes the need for AI governance councils to align business functions and manage risks. He warns of a ‘calm before the storm’ where malicious autonomous agents will exploit vulnerabilities, and stresses the importance of foundational security practices like asset management and telemetry. The episode also addresses emerging threats such as data poisoning, citing Anthropic’s research that 250 samples can poison a model regardless of size. Chris advises leaders to invest in AI governance, training, and revisiting third-party risk assessments for vendors that have added AI capabilities. He previews the SANS AI Security Maturity Model ebook, which provides a five-stage path to mature AI security programs.

168 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable, practical insights for cybersecurity leaders. Chris Cochran’s extensive experience lends credibility, and the discussion is grounded in real-world observations from his interactions with 300 CISOs. The argumentation is solid, with clear reasoning about the causes of shadow AI and the need for governance. However, some claims, such as the 250 samples to poison a model, are presented without detailed evidence, and the conversation sometimes lacks depth on technical specifics.

Scientific Rigor, Source Quality, Title Accuracy

The video demonstrates scientific rigor by referencing credible sources like OWASP’s AI Exchange and Agentic Top 10, and Anthropic’s research on data poisoning. The sources cited in the description are relevant and authoritative. The title accurately reflects the content, focusing on insights from conversations with CISOs. The discussion is well-structured and aligns with the title.

143 words

Title / Content Match

The title accurately reflects the content, as the episode focuses on insights from Chris Cochran's conversations with 300 CISOs.

Quality & Reliability

8/10

The video features an experienced cybersecurity leader (Chris Cochran) with a strong background (NSA, Mandiant, Netflix, SANS). The discussion is grounded in practical experience and references credible sources like OWASP and Anthropic research. However, some claims (e.g., 250 samples to poison a model) are presented without detailed verification, and the conversation is largely anecdotal.

Chapters

Cited Sources

Concurring Sources

External References

Contribution & Novelties

The video offers a unique perspective by synthesizing insights from 300 CISO conversations, providing a current snapshot of AI security challenges and priorities. It emphasizes the prevalence of shadow AI and the need for governance, which is a practical takeaway. The discussion of data poisoning and the ‘calm before the storm’ adds forward-looking analysis.

Pour aller plus loin :

111 words

Radar Profile

The radar profile shows high scores in information quantity, quality, and reliability, with a slightly lower technical level. This indicates a well-informed discussion that is accessible to a broad audience, but may not delve into deep technical details.

Reliability 8/10