When Will You Trust an AI Agent Enough to Stop Watching It?


Ask a security team to hand real work to an autonomous agent and the objections come fast: it’ll hallucinate, it’ll lie, nobody wants to touch it.

In “Hacking our Comfort with Autonomous Agents: An hour of critical thinking about getting agents to do the things we want them to do without worrying about it,” we sat with the harder question beneath that reflex. We want to use it. But we’re scared. So what does it take to trust something that runs without you watching it? And once you’ve figured that out, you’ll need to figure out what those junior analysts are going to do now.

Joining

David Spark

for this conversation were

Tim Leehealey

, vp, corporate strategy and operations,
Strike48
, and

Benjamin Stephan

, former CISO, Sandisk.

HUGE thanks to our sponsor, Strike48

Article content


Watch the full video here


Join us next time on Friday, September 11, 2026, for “Hacking Vendor Selection”

Super Cyber Friday will be back Friday, September 11 for our discussion “Hacking Vendor Selection: An hour of critical thinking about what happens in your environment that influences what you buy.” It all starts at 1 PM ET/10 AM PT.

>>> REGISTER HERE for just the Friday, September 11th, 2026 show <<<

Or register once for every upcoming Super Cyber Friday event. No need to sign up week to week.


Couldn’t join us live on Friday? We saved the best parts for you.

Super Cyber Friday Express is the podcast version: the heart of the conversation, and takeaways you can actually use. It’s only 20 minutes and ready on Fridays after our live show. The shortened version of the show gets you the key points on demand, but the full experience only happens LIVE in the room.

Subscribe to Super Cyber Friday Express

Please subscribe via Apple Podcasts, Spotify, Pocket Casts, or just type “Super Cyber Friday Express” into your favorite podcast app.


Did you know that we have an events calendar?

Visit our events page to subscribe (look at the dropdown in the upper right) so you can stay up to date on Super Cyber Friday and other CISO Series content.

Best quotes from our guests

“Let’s not build a random agent. Let’s build a workflow of deterministic steps that does one through ten, and in between steps four and five, where there’s that little intuition, let’s build a very programmatic micro agent.” — Tim Leehealey, Strike48

“Trust but verify. But flip it around a little bit. When we look at agentic, let’s look at it as verify to build trust.” — BJ Stephan, former CISO

“If you don’t give an agent an off-ramp, it will lie to you… If you don’t make that explicit, it will just start to make stuff up.” — Tim Leehealey, Strike48

“There’s going to be changes in resourcing, but the reality is AI up-levels your people and makes them smarter, faster, more efficient.” — BJ Stephan, former CISO

“What are you gonna say if June of next year you didn’t implement an agentic SOC and you got attacked by an agentic adversary? ‘I thought Jimmy would be able to keep up with it, and he didn’t. He let me down.’ It’s just not a viable argument anymore.” — Tim Leehealey, Strike48

“You don’t want rubber stamping. You want a second opinion. You want something different, and it’ll give you better fidelity and better trust.” — BJ Stephan, former CISO

Quotes from the chatroom

“For autonomous SOC, I strongly recommend a crawl, walk, run strategy to slowly increase your comfort with the platform.” –

Andrew Aken, PhD, CISSP

,
QKS Group

“‘What are we really trying to do?’ and ‘What is the problem we are solving?’ are essential questions.” –

David Larsen

,
Väsentlig Consulting LLC

“Three legs to a stool which becomes toxic for agentic world: 1. access to private data, 2. exposure to untrusted inputs 3. an outbound channel. Our goal should be break one leg of the workflow.” –

Vijay Jajoo

,
KPMG US

“We should embrace autonomy but understand that the agent may go rogue or run wild, so monitor the workflow as best you can as the agent (intern) matures.” –

Andre Payne

,
Payne Consulting and Management Group

“I think fundamentally a lot of people across the tech sector have forgotten the fundamentals since AI has come to play. We’ve always had controls across pipelines, we’ve always had controls on people (whole debate in itself), and yet when you add AI in people get confused in how to build solid with controls in place.” –

Cassius Edison

,
Closed Door Security UAE

“AI MUST complete the task. Therefore it can only utilize the off-ramps it has available. The trick is to manage the off-ramps in a way that they provide the value needed, while not allowing the model to be lazy. Because it absolutely will be lazy.” –

Howard Holton

,
Phronia Counsel LLC



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *