The security leader has never had the system of record that every other executive takes for granted, and Mike Armistead thinks AI can finally close that gap.
In this episode I sit down with Mike Armistead, co-founder and CEO of Pulse Security, to discuss why the CISO has spent decades running a security program without a system built to run it, including the silos that created the problem, what a system of truth actually looks like, and where AI does the heavy lifting versus where the human stays in the seat.
Mike has been through this movie before as the co-founder of Fortify and of Respond Software, so his view on the AI wave is measured rather than breathless. We also get into the reporting gap between what CISOs say and what boards actually need, and the research findings that put real numbers on it.
We chatted about:
Mike’s path through two exits and why the AI wave pulled him back to build a third company
Why security grew up as a set of technical silos, each speaking a slightly different language, with no system to run the program as a whole
What a system of truth for the CISO means, and how an agentic layer reads across both structured and unstructured data like policies and assessments
Where agents take over the toilsome work of regulatory monitoring, vendor and vulnerability intelligence, and status reporting
Governing the guardrails rather than the keystrokes, and why closing the loop still involves people and their judgment
What corporate directors actually want to hear from a CISO in a 15 to 20 minute quarterly slot
The research findings, including that 55% of boards have never defined the cyber risk they are willing to accept and only 12.5% of CISOs are very confident the board leaves with a true picture of the risk
Bringing Joanna Burkey’s dual perspective as a former CISO and current corporate director into the product
Prefer to listen?
Be sure to subscribe and leave a review as it truly helps the show!
A few takeaways from the conversation:
The CISO is the last executive without a system of record
Mike frames the gap in terms every leader will recognize. The CFO manages financial risk from an ERP with a general ledger at its core, and the CRO runs the pipeline from a CRM. The CISO manages cyber risk from a scattering of spreadsheets, assessment documents, and point-in-time audits. His argument is that security grew up at the practitioner level, one technical silo at a time, and never developed the layer that answers questions about the program itself rather than about a single threat or vulnerability. I have lived this in programs I have supported, where the leader has to walk over to the deputy, the cloud team, the endpoint team, and the SOC to assemble a picture that should already exist in one place.
Agents for the toil, humans for the judgment
Mike is careful about where autonomy fits, and I appreciated that he did not oversell it. Agents are good at scouring the landscape and pulling the right signals for a specific company’s stack, which turns a board member’s “are we affected by that thing I read about” into a grounded answer instead of a scramble. But he is clear that “closing the loop involves people.” His quarterly access review example lands well. An agent can pull from cloud, identity, GitHub, and HR, but the calls on how broad the review goes and whether to grant exceptions stay with the security professional. What the system adds is memory of those decisions, so the exception you granted last time does not get relitigated from scratch.
The board reporting gap is about ground truth, not delivery
The numbers from the research are the part that should make people sit up. Mike cited that 55% of boards have never defined the level of cyber risk they are willing to accept, and that only 12.5% of CISOs are very confident the board walks away with a true picture of the risk. He does not think this is mainly a storytelling problem. As he put it, “we often, I think, the trees are presented instead of the forest.” The CISO gets 15 to 20 minutes a quarter and tends to fall back on the SOC metrics that feel comfortable, while the director wants to know what changed in the landscape and what the program’s posture is against it. Closing that gap means better ground truth underneath the narrative, not just a better narrative.
Institutionalizing the tribal knowledge
The thread that ties it together is one every practitioner knows. Programs run on tribal knowledge, the contract clauses a leader has ruled on before, the exceptions, the context that lives in a few people’s heads. Mike brought in Joanna Burkey, former CISO at HP and Siemens and now a corporate director, as an advisor precisely because she has seen both sides, and her point is that this knowledge “needs to be institutionalized in a way.” Capturing it saves time and money and headache, and it is the difference between a program that resets every time someone leaves and one that compounds what it learns.
Thanks to Mike for a sharp conversation on a problem the industry has mostly ignored while it chased AI for AppSec and the SOC. You can follow his work at Pulse Security AI and connect with him on LinkedIn.









