What you'll learn
Why the CISOs surviving the agentic transformation share one trait: they've swapped "no" for "maybe," operate as business executives, and make risk visible instead of blocking revenue.
How Gary ran security due diligence across SoftBank's 560-plus portfolio companies in 16 countries — using NIST CSF as the crosswalk for every international regulator from Singapore's MAS to Japan's J-SOX.
Where AI governance goes after visibility: auditors demanding point-in-time attestation plus three-to-six-month lookbacks to prove your controls haven't drifted.
Description
Gary Hayslip has run security programs from more angles than almost anyone in the industry. He retired from the U.S. Navy as a chief petty officer, built the cybersecurity program for the City of San Diego, ran security (and a chunk of IT) at Webroot through an acquisition, served as Global CISO for SoftBank across its investment funds and portfolio, and now works as Field CISO at Zenity after a field CISO run at Halcyon. He's also co-author of the CISO Desk Reference Guide, the book a generation of security leaders used to figure out the job. This conversation is about what the CISO role is turning into — and what the people doing it well have in common.
The specifics carry this one. At San Diego, Gary charged 70% of his security budget back to 30-plus departments, which forced cyber to operate like a business. At SoftBank, he assessed hundreds of companies for an investment committee writing checks in the hundreds of millions, working days that ran 5 AM to 9 PM across time zones. Today he's interviewing candidates by asking them to open their GitHub and show what they've actually built with AI — and writing book chapters in a week that used to take two months. If you're a security leader watching the CIO and CISO roles converge, considering a field CISO seat, or trying to figure out what "AI governance" will mean when the auditors show up, this episode is for you.
What we cover
"it isn't your job to say no. Instead, it's your job to make the risk visible" — the characteristics of security leaders who are actually succeeding through the agentic transformation.
"Look, guys, they're not gonna open the checkbook unless we know what we're dealing with here." — what it's like to audit your friends: running due diligence across SoftBank's portfolio without burning relationships.
"it's almost like being a CISO role on sabbatical" — what the field CISO job actually involves, from the guy who wrote the definitive article on it.
"even with AI, cyber is still cyber" — where AI is landing inside security programs first, why the SIEM space is about to shift, and why inventory still matters.
"they're gonna look for drift" — Gary's take on Conor's thesis that AI governance is moving from visibility to enforced guardrails and attestation.
"You can say you use Claude, actually show me what you were doing with Claude." — how hiring, skill sets, and team-building have changed, and why dev and security teams are converging.
"we always wanted to leave it better than we found it" — the fish-tacos-and-beer origin of the CISO Desk Reference Guide and 20 years of writing for the community.
"Why do we have a 2003 server?" — career lessons from Navy to San Diego to Webroot to the boardroom, including the risk trade-off a younger Gary would have gotten wrong.
Thank you to our Sponsors:
RISC Point is security & compliance consulting tailored to your business. Talk to RISC Point.
Hampton North is the premier US based cybersecurity search firm. Start building your security team with Hampton North.
Sysdig is the leader in AI-powered real-time cloud defense; stop watching and start defending.
The conversation
"It isn't no, it's maybe" — the CISOs winning the agentic shift
Conor opens by asking what separates the security leaders rising to this moment from the ones getting run over by it. Gary's answer has nothing to do with technology. The successful ones partner with other business units, operate as business executives, and accept that companies need to pivot, launch new services, and find new revenue — with security attached, not in the way.
"it isn't your job to say no. Instead, it's your job to make the risk visible and as a team, you figure out, you know, how you're going to manage it"
— Gary Hayslip
The posture he describes is specific: visible, flexible, and allergic to binary answers. "It isn't no, it's maybe. Maybe we can do that if we look at it this way. Here's a couple of issues. Have you thought about this?" That framing matters more now than it did five years ago because, as Gary puts it, AI is driving security into every unit of the business whether you like it or not. The rigid yes/no CISO doesn't have a seat at those tables.
Conor probes whether curiosity is the underlying trait, and Gary confirms it — the same instinct that has him constantly reassessing his stack isn't about closing today's risks. It's about looking six and twelve months out at where the CEO and board are taking the company and asking whether the program will be ready when they get there.
Due diligence across 570 companies and 16 countries
The SoftBank chapter of the conversation is worth the listen on its own. Gary sat on the investment side, assessing companies before hundreds of millions to billions of dollars moved — and he's clear that the reports weren't just red-flag lists. He prioritized findings, made recommendations, and then met with the CIOs and CTOs of companies SoftBank invested in to help them actually fix things. The goal wasn't gatekeeping; it was making the companies better investments and cutting down on 2 AM incident calls.
The regulatory sprawl was the hard part. Multiple international regulators, operations in 16 countries, data sovereignty laws that changed with every deal — Norway, France, Japan, the US. His move was to anchor everything on NIST CSF, because every framework he dug into was ultimately based on NIST, which made it possible to crosswalk whether he was talking to MAS in Singapore or dealing with J-SOX in Japan. Audit, compliance, and legal weren't occasional contacts; they were in the same Slack channels daily.
Stu raises the awkward part: sometimes the CISO whose house you're inspecting is a friend. Gary's approach was blunt honesty.
"Look, guys, they're not gonna open the checkbook unless we know what we're dealing with here."
— Gary Hayslip
He says he never really got pushback — partly persona, partly the fact that he stayed on as a resource after the deal closed, sometimes acting as interim CISO for acquired companies until a team was in place. The findings could be stark ("when you're talking to a company that's a biotech and they don't even have 2FA installed"), and the hours were brutal: "It wasn't uncommon for me to start the day at 5 AM and end at 9 PM" across UK and Tokyo time zones. But the model — assess, prioritize, then help — is a template for anyone doing portfolio or M&A security work.
The field CISO job, from the guy who wrote the manual
Gary wrote an in-depth LinkedIn article breaking down the field CISO role — the one Andy Ellis pointed to on a recent episode as the definitive take. His core claim: strip everything else away and the job is relationships. Yes, you work with sales and marketing, and Gary actually enjoys the go-to-market exposure — he tells CISO peers it teaches you how the business makes money, who the customers and competitors are, "and it is why you didn't get all of your bonus this year."
But the substance is customer advocacy. At Halcyon he ran a "mind of the CISO" briefing to teach sales teams how to talk to technical executives. He held monthly one-on-ones with customer CISOs that often weren't about the product at all — board deck reviews, career strategy for their next role. His rule: it's their hour. And he closes the loop the other direction too, carrying customer feedback into monthly meetings with the product and engineering teams so the roadmap reflects what practitioners actually need.
"to me, I look at it as it's almost like being a CISO role on sabbatical"
— Gary Hayslip
You're still a CISO, still in the community, still helping people — "but you're not chasing Jira tickets" or figuring out who broke the config on the Palos. Less operational, more strategic. For senior CISOs weighing the move, that's the most honest one-line summary of the trade you'll hear.
"Even with AI, cyber is still cyber" — but the SOC and SIEM won't survive intact
Asked where AI is actually delivering inside security programs versus where it needs more time, Gary starts with a corrective:
"even with AI, cyber is still cyber. You still got to manage the risk."
— Gary Hayslip
Access control, identity, frameworks, controls — they may be buried under newer technology, but they're all still there. What's changing fast is the SOC, and he's explicit that "I'm expecting the whole SIEM space is gonna shift as well," because near-real-time data and machine-speed decisions break tooling built for a slower decade. The fundamentals translate directly to agents: you need inventory (he expects some form of AI SBOM), monitoring to catch unsanctioned tools and surprise licensing bills, and management — because "agents have a tendency to do what they wanna do," and a compromised agent needs the same visibility an EDR gives you on an endpoint.
The threat side is already moving. Social engineering aimed at non-human identities — at agents themselves — was a joke Gary was trading at Black Hat MEA in Riyadh in December. "It's already real, you know, six months later."
Conor then floats his thesis: "AI governance" has meant visibility for the last two years — knowing your models, MCP servers, and skills — and is now shifting toward enforced guardrails. Gary agrees and takes it further. He expects attestation: a platform that produces a report saying at this date and time, we are built this way, with these frameworks and these tools, by policy, with nothing out of norm. And when a Big Four auditor shows up for a regulator, current state won't be enough.
"they're gonna go ahead and look for drift or look for change, and you wanna be able to show that you are consistent"
— Gary Hayslip
If your platforms can't show the last three and six months, you can't demonstrate governance. That's the bar to build toward now.
"Show me" — hiring changed, and so did the team
Gary's hiring at SoftBank previews where every security team is headed. His interview question was direct: are you using AI tools? Fine — which one, and what did you build?
"You can say you use Claude, actually show me what you were doing with Claude."
— Gary Hayslip
He wanted GitHub accounts and working artifacts, not claims. Stu notes the whiplash — interviews went from "using Claude is cheating" to "do an AI demo or don't bother" in about a year. The team-level shift is just as stark: Gary went from one or two people who knew Python to everyone on the team scripting, because the work is building and automating. At SoftBank they were building custom GPTs and debugging weird behavior down in the JSON when the models did something unexpected.
The second-order effect is convergence. The same tools security teams use to understand AI are in the dev teams' hands, and Gary says developers are finally getting "a better understanding of why we're freaking out." He's had dev-team people jump into security and never seen one fail. Zoom out and he sees the org chart converging too: CIO and CISO responsibilities merging, and a likely future where an AI officer manages AI strategy for the business with the CISO on a dotted line handling security, sandboxing, and monitoring on the back end.
Leave it better than you found it
The through-line of Gary's career is a phrase from his military days: "we always wanted to leave it better than we found it." It's where the mentoring comes from — "you take care of your people, you take care of your teams" — and it's why the CISO Desk Reference Guide exists. The origin story: a startup event, fish tacos and beer, Matt Stamper talking Gary into writing a book he didn't want to write. Matt mind-mapped the content, they ended up with 19 chapters — enough for two volumes — and made a structural choice that defined the book: three authors with very different careers (Bill Bonney the strategic enterprise CISO from Intuit, Matt the CIO/CISO mid-level operator, Gary the hands-on practitioner) each giving their point of view in every chapter, with consolidated takeaways at the end. They stood up their own publishing house and shipped it through Kindle Direct Publishing. It's now translated into multiple languages and used in colleges.
The writing process itself tells the AI story in miniature. In 2015, a chapter took a month and a half to two months of research. Now, writing a new book on incident response and leadership with Alan Alford and Nate, Gary uses Claude — trained on nearly 20 years of his own published writing — and can have a chapter done in a week, still restructuring and rewriting the paragraphs that don't land. He republishes old LinkedIn articles for the same reason he wrote them: the 200–300 comments teach him things he missed. "Hey, I work in a shipyard... don't forget about OT."
The payoff moment: dinner with Brendan, the CTO at MGM, who told Gary he used the first book in 2015 to figure out how to take his first civilian CISO role while leaving Army Cyber Command.
"Dude, that's why I wrote it... I wanted to go ahead and help people."
— Gary Hayslip
It traces all the way back to Black Hat 2005 at Caesars, where an active-duty Gary watched the graybeards and hackers at the bar and thought, "Someday I wanna be that." His path there is a checklist worth stealing: give back, mentor, be authentic, know how to boot Linux and break things — then write about what you learned and where you screwed up.
Show notes
Guests — Gary Hayslip, Field CISO at Zenity; former Global CISO at SoftBank; former CISO for the City of San Diego; former CISO (with CIO duties) at Webroot; former field CISO at Halcyon; U.S. Navy veteran, retired chief petty officer; co-author of the CISO Desk Reference Guide.
Books mentioned — CISO Desk Reference Guide, Volume I and Volume II (Gary Hayslip, Matt Stamper, Bill Bonney); an in-progress book on incident response and leadership Gary is co-writing with Alan Alford and Nate.
Frameworks / models / tools named — NIST CSF; J-SOX (Japan); MAS (Singapore); Claude; custom GPTs; Python; JSON; GitHub; Jira; Kindle Direct Publishing; Palo Alto firewalls; EDR; SIEM; AI SBOM; MCP servers; 2FA; Linux.
Other people / shows / resources referenced — Matt Stamper; Bill Bonney; Rick McElroy; Andy Ellis (prior Zero Signal guest); Alan Alford; Brendan, CTO at MGM; Masayoshi Son ("Masa"); Phil; SoftBank; Zenity; Halcyon; Webroot; City of San Diego; U.S. Navy; ezCater; DHS; WWT; CDW; Intuit; Gartner; Black Hat; DEF CON; Black Hat MEA (Riyadh); RSA Conference; Gary's field CISO article on LinkedIn.
Hosted by Conor Sherman and Stuart Mitchell.