• CIOsurge
  • Posts
  • The AI governance gap just got exploited

The AI governance gap just got exploited

Plus: Why a CISO who talks endpoints loses the board.

The AI governance gap just got exploited

Powered by Single Fin

Welcome to this week’s edition of CIOsurge!

This week:

  • Tim Youngblood on why the CISO who walks into the boardroom talking endpoints has already lost

  • A new SANS study: 4 in 10 security teams have no formal AI policy, and 6 in 10 have no visibility into where AI runs

  • The state of AI security in 2026, where a single agent compromise can open the whole enterprise

Let’s make this week a game-changer.

Stay sharp. Stay ahead.

How a Legendary CISO Evaluates Early-Stage Vendors: People, Problem, Progress

Every CIO and CISO is being asked to place bets on early-stage tools right now, often on a two-week timeline. So when I sat down with Tim Youngblood, the first CISO at Dell and a longtime leader at T-Mobile, McDonald's, and Kimberly-Clark, I wanted his framework for separating the startups worth piloting from the ones that just demo well. Tim has evaluated 40 to 50 startups a year for over a decade and is now an angel investor, so this is hard-won.

He starts with the founders. "You have to look at whether those founders have really the it factor to drive what they're trying to do," he told me. He weights prior experience heavily, even failed attempts, because he wants to know they have been through the process and learned. A trail of success and the right pedigree makes him lean in.

Then he moves to the problem, which he thinks most people underweight. "That's the one thing we don't pay enough attention to, how these companies are defining the problems that they solve." His line for it is perfect. "You can have the greatest mousetrap in the world, but if no one wants to catch mice, it just doesn't matter." A phenomenal solution to a problem the business does not care about is worth nothing.

Third is progress, and specifically scale. Tim ran an identity ecosystem with 2.2 million people and 14 different tools at McDonald's, so he knows most startups have never stress-tested whether their solution can scale. "That is always difficult for startups because they don't have the environment to even know if their solutions can scale." He also looks hard at existing customers. Being a vendor's biggest customer made him nervous, because it meant being the guinea pig. A peer of similar size already on board made a company far more attractive.

Tim also shared a practice worth stealing. At Kimberly-Clark he built what became the PI Group, for Portfolio Innovation Enablement, and ran it Shark Tank style. He would invite five or six startups to pitch to his full leadership team, engineers and general counsel and procurement included, with one rule: do not bring your marketing people, bring the people who can actually explain how it works. Forty companies a year in, ten pilots out, two or three into the portfolio.

The takeaway for operators: score every early-stage vendor on people, problem, and progress. The founder's track record, how sharply they define the problem, and real evidence they can scale will tell you more than any polished demo.

The AI Governance Gap Is Now a Measurable Hole

A report released by the SANS Institute found that enterprise security teams are adopting AI faster than ever, but the governance meant to support that expansion has not kept pace. Four out of ten security practitioners said their organization has no formal policy for AI adoption at all. More than six out of ten said they have no visibility into where AI models are being used or what kind of information is being exposed to them. The finding lands as security teams race to deploy AI for defense, often without the basic policy scaffolding, ownership, or monitoring that any other enterprise system would require before going live.

This is the gap that turns into an incident. You cannot govern what you cannot see, and six in ten teams are flying blind on their own AI footprint. The uncomfortable part is that security teams are among the fastest adopters, so this is not a shadow-IT problem coming from marketing or finance. It is happening inside the function that is supposed to own the controls. Start with the least glamorous work there is: write the policy, inventory where AI is actually running, and assign an owner to each deployment. It is not exciting, and it is the only thing standing between you and the headline.

— Zack Tembi

The State of AI Security in 2026: One Compromise Opens Everything

CIO.com's assessment of the AI security landscape describes a new and complicated attack surface created by the spread of AI infrastructure like MCP servers and command-line interfaces. Unlike traditional software, these AI agents operate as autonomous entities that can execute code and access sensitive data, often sitting inside development environments and cloud resources. That means a single compromise can hand an adversary the ability to conduct reconnaissance, harvest credentials, and exfiltrate data across the enterprise. The report notes the primary threat over the past year has been model hijacking through prompt injection, where attackers plant malicious instructions in public places like GitHub issues or documentation and trick an AI agent into executing unauthorized commands, exploiting the trust between a model and the data it reads.

The controls that matter here are not new or exotic, which is the good news and the indictment at the same time. Least privilege, defense in depth, and auditing every agent's permissions before it goes live are the same fundamentals we have preached for twenty years. The difference is that an autonomous agent with too much access does not just leak, it acts, and it acts across systems at machine speed. Before you deploy another MCP server, ask exactly what it can touch and what happens if it is turned against you. If you cannot answer that, it is not ready.

💡 CIO Spotlights

Young Shon named Chief Information Officer at Headlands Research

  • Appointed CIO of Headlands Research, a global clinical trial site network, overseeing the company's worldwide IT organization

  • Will guide technology strategy, infrastructure, cybersecurity, enterprise applications, and innovation across the network's international sites

  • Joins from Flourish Research, where as VP of Technology Delivery he built the enterprise technology roadmap and led its early AI initiatives

  • Career spans technology consulting at Accenture and enterprise IT leadership at AstraZeneca and Teva Pharmaceuticals, with transformation roles at TFS CRO, Entitech Solutions, and Perspective Therapeutics

    Read the full story

Mark Mathewson named Chief Information and Data Officer at Ally Financial

  • Appointed CIDO of Ally Financial, a NYSE-listed top-25 US financial holding company, effective July 20, leading technology and data across all functions and lines of business

  • Brings more than 25 years of financial services technology leadership

  • Most recently divisional CIO for Capital One's retail and commercial banking units, overseeing teams across the US, Mexico, and India during a 12-year rise from VP to EVP

  • Earlier spent 12 years at Fannie Mae across application development, IT governance, and portfolio management, plus consulting at Deloitte

  • Mandate centers on driving the next phase of AI-driven technology transformation for the nation's largest all-digital bank

    Read the full story

🗞️ Submit a Section

Want to be featured in the next edition of CIOsurge?

Did you like today's newsletter?
Powered by Typeform

Reply

or to participate.