Why Vanta Wants Boards to Measure Cyber Risk in Business Terms
The Business of CybersecurityJuly 18, 2026
38
00:30:3027.92 MB

Why Vanta Wants Boards to Measure Cyber Risk in Business Terms

In this episode of The Business of Cybersecurity, I speak with Khush Kashyap, Senior Director of Governance, Risk, and Compliance at Vanta. Khush began her career as a software engineer before moving into cybersecurity, giving her a builder’s view of governance and operational resilience.

Our conversation begins with the UK Cyber Security and Resilience Bill and the demands it could place on managed service providers, data centers and designated suppliers. Proposed reporting windows could require an initial notification within 24 hours and a fuller incident report within 72 hours. Khush explains why organizations should map their supplier dependencies, define reporting responsibilities and rehearse those deadlines before a real incident tests them.

We then examine what Vanta calls security theater. Khush argues that teams have spent years gathering screenshots, maintaining documents and completing questionnaires because passing an audit became the accepted measure of success. The danger is that an organization can appear compliant while controls remain poorly designed, incorrectly scoped or ineffective in daily operations.

AI can compound that problem. It can generate policies, automate attestations and produce reassuring dashboards, but those outputs mean little when nobody validates the systems or checks whether the underlying controls are working.

Khush also explains why shadow AI creates a larger governance problem than shadow IT. Employees can introduce copilots, models, APIs and autonomous agents that access company data or take actions without the security team knowing they exist. Her advice begins with a live inventory covering cloud assets, SaaS applications, suppliers, machine identities, AI tools and agents.

We also discuss how CISOs can improve their conversations with boards. Instead of presenting compliance status as the main result, Khush recommends explaining business exposure, supplier dependencies, potential outage costs, reporting readiness and the speed at which failed controls can be detected.

Can organizations turn compliance into a continuous operating discipline that protects the business every day, rather than a scramble before the next audit? Please share your thoughts with me.

Useful Links

[00:00:00] Your agents aren't producing accurate answers because they don't have a complete semantic understanding of your data. And Denodo is solving this and solving it through semantic consistency. Through semantic consistency, your agents can start making accurate predictions in real time. So see what else Denodo can do by visiting denodo.com to learn more. But now let me introduce you to today's guest.

[00:00:33] What if your cybersecurity program looks great on a dashboard, passes every audit, but still leaves the business dangerously exposed? Well, my guest calls this security theater. And AI could make that problem even worse by helping companies produce policies, evidence and reassuring green dashboards without proving the controls underneath are actually working.

[00:01:00] So today we're going to discuss the 140 unmanaged tools that companies can discover in just 90 days. Why AI agents are creating a new generation of hidden risk. And how security leaders can stop chasing compliance certificates and start showing boardrooms whether the business is genuinely becoming safer. We've got a lot to talk about today. So before we go any further, let me officially introduce you to my guest.

[00:01:29] So thank you for joining me on the podcast today. Can you tell everyone listening a little about who you are and what you do? Thank you so much for having me here, Neil. I lead the Governance Risk and Compliance Function at Vanta. I'm a senior director here. I work alongside our CISOs organization. I have to say my path here has been a little unusual because I started my career not in cybersecurity, but as a software engineer.

[00:01:54] But then I found my way into security from the builder's side rather than the auditor's side, which shaped how I think about this work. So I also host Vanta's video podcast where we do the tabletop with CISOs. And we actually run live incident scenarios with them. So I spend a lot of time watching very smart security leaders discover in real time where their incident response plans and their mental model and framework around incidents break.

[00:02:23] It's very humbling for everyone, including me, too. I love that. What a great origin story. And I love that winding path and the unconventional route to get you where you are today. And looking back at your career, I mean, you've worked with security teams across so many major enterprises for more than a decade now. And as organizations prepare for the UK cybersecurity and resilience bill over here, I'm curious, what kind of conversations are you having most with CISOs?

[00:02:51] And where do you think many organizations are still underprepared? What are you hearing here? Yeah, I think the conversations have definitely shifted a lot in the last few months because initially we were thinking the bill is going to be out. It was still a hypothetical scenario of what the bill is going to be and when it's going to be out.

[00:03:11] But knowing that it's being expected to move before the end of the year, the CISOs talking about it, the security leaders wondering about it, their conversations have moved from what might this look like to am I ready for this? And there are two themes, I would say, which are dominating my conversations with them.

[00:03:33] First is the scope, because the bill pulls managed service providers, data centers, designated critical suppliers into the regulatory perimeter, which reflects how modern organizations actually operate. Because they are mostly operating on a web of cloud service providers, MSP, external partners. So it's all included in it.

[00:03:54] Last year proved why we need this, you know, all the breaches and after breach impacts we were seeing with M&S, Harrods, Elnar. The supplier was the gateway through which the incidents were happening. So the technical vulnerability sat outside the enterprise perimeter, but the operational financial regulatory consequences landed squarely inside the organization.

[00:04:18] The second theme that's dominating in my conversations with the CISOs is speed, because the reporting regime is 24 hours for initial notifications and 72 hours for full report. And this is not a lot of time. This is where I'm seeing a lot of unpreparedness, underpreparedness and CISOs really worrying about it.

[00:04:41] Because during the first year of an incident, our teams should be trying to contain the problem, not debating who owns the reporting obligation, hunting down for regular contact details, arguing with the supplier about whose incident it actually is. We need to be like plugging the gap and plugging the hole at that time. That's where I'm seeing a lot of underpreparedness.

[00:05:05] But one thing that I have been sharing with a lot of the security leaders that I'm talking across the board with different industry segments is a very practically rooted advice, which is, you know, start here.

[00:05:18] Run a discovery project to identify your critical suppliers, map your business dependencies, get notification SLAs and evidence rights into most of your critical supplier contacts and rehearse this 24 by 72 process before you actually need to go through it. They will top it, as I would say. Those are the most important themes which are coming up in my conversations. So many great points there. And a lot of what you said will resonate with people listening.

[00:05:47] And when I was doing a little research on you, I was also reading how you often talk about security theatre, where organisations will spend enormous amounts of time in meetings and proving compliance without actually genuinely reducing any risk, which is something that I suspect many people listening have seen and experienced firsthand too. But how did we get to this point? What does meaningful cyber resilience look like beyond just ticking a box and passing an audit?

[00:06:17] I think how did we get here is definitely to do with the incentives. Yeah. For decades now, the definition of success of a good security programme has been to pass the audit. So the teams have been optimising for evidence collection. Weeks lost before an audit gathering screenshots nobody's ever going to look again at. Incident response plans that exist purely in documents, sometimes never even tested.

[00:06:47] Vulnerability SLAs and different procedural guidance document existing just for the sake of audits and never operationalised in the companies. Even vendor questionnaires were completed at onboarding, filed away, never taken a look at if it's going to increase the risk posture of the company, if we are going to identify more critical service providers, what do we do about them?

[00:07:10] So it was like hundreds of controls maintained from an evidence perspective because regulatory frameworks asked for them and they had no connection to risk that actually matters to the business. So that's where I think that security theatre emerged. It was incentivised to exist because of the sole focus on audits. Now with AI, there is also AI-generated theatre.

[00:07:37] Organisations are using AI to create policies, standards, docs, not spending any time in actually operationalising them, not understanding what parts of your controls are designed well. But they're using AI to automate monitoring and attestation. And if nobody is validating the AI itself, you get a dashboard which says everything is green and healthy, while the underlying controls are quietly failing, not scoped well, not designed well, not operating effectively.

[00:08:06] But that confidence in AI is happening without assurance. So I would say those are some of the areas of what we have seen. Meaningful resilience in this space will change what success looks like. If success is reducing the risk, you will ask different questions. You will see if your controls are designed well, they're scoped well, are you revisiting them? Are they operating effectively?

[00:08:35] Could you detect a drift? Could we spot a problem today rather than three months from now? Do we only spot problems when audit comes? And practically, that means to rely on visibility before anything else. Create a current inventory of your cloud environment, your vendors, your machine identities, AI tools, agents. Then make controls continuous instead of point-in-time evidence collection. Flowing through the integrations of your systems.

[00:09:04] And when control fails, you want to know the day off. While the risk is still small and you can fix it. Not at the time of audits, I would say. And I wanted to share a big stat with people listening today about visibility. So I'm glad you've raised that. And that was one of Vanta's findings in a report that found that organizations typically discover

[00:09:28] around 140 unmanaged tools accessing their environment within just 90 days of connecting to your platform. So, I mean, what does this tell us about the reality of AI and SaaS adoption inside modern organizations? And why has visibility become such an important security capability? It feels a big blindside here. Totally.

[00:09:52] I think it's telling us that every organization has far more technology than it realizes. And, you know, that gap between what you think you have and what you actually have is where a lot of the supplier chain and security risk lives. That 140 number isn't a story. I don't think it's a story about negligence. It's a story about how easy adoption has become.

[00:10:19] Any employee with a credit card or a free tier sign up can connect to a new tool to your environment in minutes. AI has only poured fuel on this. Every new SaaS platform now ships with AI features, agents and integrations that expand the surface. Security teams are expected to govern often without filing a ticket and having visibility into it or even knowing it's like it's somebody we have contracted with.

[00:10:46] It's a procurement, part of a procurement system or not. One thing where we had this really good conversation at RSA this year was around how ShadowEye is already exponentially bigger than ShadowIT ever was. And I do stand by that. With ShadowIT, at least the unit of adoption was an application. With AI, it's an agent co-pilot model API integration. Things that act on your data and increasingly take actions on your behalf today.

[00:11:16] So I think the fundamental principle is pretty simple here. We cannot govern assets we don't know that exist. Which is why inventory has quietly become the foundational security capability of this era. It was not the way before. It is the starting point for AI governance, for third-party risk, for the bills, supply chain requirements, for all of it. Visibility is not like a nice to have anymore.

[00:11:42] It's the control that all of your other security controls actually depend upon. And we should also mention that AI adoption is accelerating faster than any governance in many organizations around the world. So on that side of things, where are you seeing the biggest control gaps emerging? And are there any practical steps that security leaders listening could be taking to bring governance back into step with innovation?

[00:12:12] Yeah, I think the biggest gap is between adoption velocity and visibility. Yeah. Teams across businesses are introducing co-pilots, AI-powered SaaS, features, agents, model APIs, often without security ever seeing them. Access has become frictionless now. So that's the reason why ShadowEye AI is growing so much more exponentially faster today.

[00:12:41] And I think the second gap is around agency. As AI moves from generating content to making decisions and taking actions, the governance question is changed completely here. What can this agent access? What actions can it perform? Where is human approval required? Is it required? How are its decisions logged and reviewed? These questions need a lot of answering and in-depth governance before deployment.

[00:13:11] We can't do that after the fact because these ungoverned agents with system access are effectively an unvetted supplier inside your environment. It's a supply chain risk, which is just hiding out there. And then practically, I think about AI enablement in a few stages. It's like from people avoiding AI entirely to using it as a fancy search engine to building repeated automated workflows to building their own AI-coded apps.

[00:13:41] Each stage up creates more value and more governance surface. I think the mistake is trying to freeze people at stage one. The right move is to let people climb while pulling guardrails around the climb and telling them how to do the things that they really want to do that will drive a lot of business efficiency for them securely and safely. And then I go back to my point around, you know, anchor it back to your three steps.

[00:14:09] Build your AI inventory to cover your models, agents, co-pilots, third-party AI features. Set clear policy on what AI can access and do with human approval gated on high-impact actions. Embed governance into the deployment path itself. And then security teams that show up as enablers, not as blockers. And help with AI adoption.

[00:14:33] They will, because in the end of the day, your employees are going to think of you either as blockers and rout around you, or they're going to think of you as supportive allies and work with you to do the things that they were going to do anyway, safely and securely.

[00:14:52] And we will have many people listening from organisations that are so busy trying to prepare for evolving regulations like the EU AI Act and along with the changes in the UK legislation as well. And on behalf of those people listening, how can security and compliance teams avoid treating every new regulation as almost a separate project? And instead, start building a security programme that can adapt as requirements evolve.

[00:15:20] That seems a much more sensible approach, but equally it can be quite a tricky balance. But any advice there? Yeah. I think if you run your compliance programme as a series of projects, you will always be behind. Yeah. You know, the regulations are now arriving faster than projects can close. The Cybersecurity and Resilience Bill, the EU AI Act, NIS2, evolving frameworks like ISO 42001. There are some more frameworks coming up on agentic security as well.

[00:15:51] If we treat them, each of them as a standalone effort, we will be drowning our teams in so much duplicated work. And then the thing that we have noticed so far with a lot of these frameworks is that these regulations overlap enormously in substance. They all fundamentally ask very similar questions. Do you know what systems you have? Do you know what your suppliers can access? Are your controls actually working? Can you prove it quickly?

[00:16:20] A single well-instrumented programme should be able to answer most of them, if not all of them. And then I feel like there are two misconceptions which I always push back upon. The first is that regulations slow innovation. I think the opposite is true when governance is done well. Clear guardrails, being an enabler, being an ally.

[00:16:46] It gives teams confidence to adapt AI and new technology faster because everyone understands the boundaries, the oversight, the safety and security mechanisms around it. And I think the second big misconception is that regulation is mainly paperwork. The strongest frameworks push organisations to understand their security programme and systems thinking.

[00:17:11] Systems maintaining visibility, documenting accountability, keep evidencing their control work. These practices improve security regardless of what the regulators are asking of us. This is why I continue to talk about continuous trust because evidence should come directly from your environment. Controls should be scoped well. They should be designed well.

[00:17:34] They should be designed in a way that can comply with various types of different regulations and not go one by one. And then these controls should map to your risk in your organisation, your regulatory burden, your framework clause numbers. Drift should be detective. If all of this is architected really well, then you're just building it once and each new regulation becomes a mapping exercise rather than a fire drill.

[00:17:59] You'll be just identifying a couple of areas where you may have to do a little bit more or extra because of one new regulation, which is going to make your audits, the experience of your engineers and your IT professionals in your organisation much easier because the evidence already reflects your day-to-day reality. And you're not trying to play catch up on each audit and on each regulatory requirement.

[00:18:26] Another big stat from your research was that 59% of enterprises believe AI-related threats are advancing faster than their internal expertise, which is obviously quite worrying. So again, for these people listening, how should security leaders approach workforce development so their teams can more confidently manage AI-enabled risks rather than constantly reacting to them and firefighting all the time?

[00:18:52] Yeah, I think the first priority isn't training at all, which is where we usually get to. It should be visibility. You can't build expertise against systems that you don't know exist. So start with a clear inventory of everything that you need to care about. It could be your models, agents, co-pilots, third-party AI tools, which are being used across your business.

[00:19:21] From there, build governance into day-to-day operations rather than treating it as a specialist knowledge. Teams should understand what an AI system is allowed to do, what data it can access, where human approval is required, and how actions are logged and reviewed. Those operational muscles matter as much as deep technical expertise and engineering expertise does. And also, they're quite learnable by every practitioner you already have.

[00:19:48] And then another thing that I would also suggest is broaden your definition of workforce. About a decade ago, we had already broadened our definition of workforce to include contractors. It was full-time employees and contractors. Today, AI has changed the risk across entire organizations. So product, engineering, legal, procurement, and compliance, they all need fluency, not just security.

[00:20:14] And when you broaden your definition of workforce to also include AI agents, you'll manage their identities well. You'll manage their permissions well. You'll know where human in the loop needs to be there. You'll govern them better as well. So the organizations that will treat AI governance and security as a cross-fessional capability, understanding how big your definition of workforce is, will do really well.

[00:20:37] And the security team will not be facing the burden of being so small and nimble and agile while taking care of these really, really big things that are coming at them. And when we look at security, I think it is traditionally being viewed as a technical function. But increasingly, of course, it requires board-level engagement and for good reason.

[00:21:01] So what information should CISOs be presenting to executive leadership teams so cyber risk becomes more of a business decision rather than just another compliance update or box-ticking exercise? What needs to happen here? I think one thing that we shouldn't be reporting on to board is compliance status. And one thing that we should start reporting on to the board is business exposure.

[00:21:29] And that will really help them change the conversation because every organization today depends upon technology to operate. So a serious incident interrupts operations, damages customer trust, creates regulatory exposure, hits the balance sheets directly, and you see the hit much sooner than later.

[00:21:52] And then I think there is a language that boards already speak and understand, which is their balance sheets and what it means to them. So I recommend CISOs frame it as security as business risk alongside finance, legal, and operations. Don't try to think about it like a technical addendum where you start going into different controls by controls and those kinds of things.

[00:22:18] Start with helping them understand what critical services depend on which systems and suppliers on a very uber macro level. Do we have a good understanding of all these different things? What would an outage actually cost per day? Which suppliers could take us down? How quickly would we know? Can we meet the 24-hour, 72-hour reporting obligations today? Yes or no? If any of these answers are no or we are ill-informed, we need to do more work.

[00:22:46] We need a little bit more resources to get the work done. Those are the conversations and the discussions we should be having at the board level. And then the other thing that I'll say is the format of assurance matters a lot. So move boards away from point-in-time attestations that we passed an audit in March. Start talking to them around your security dashboards, which all CISOs care about.

[00:23:13] Your real-time evidence-led reporting, automated control validation, continuous monitoring of your supplier posture, drift detection in your controls, remediations of your vulnerabilities. Extract uber-level themes as risks tied to business exposure. And then start building genuine confidence about your security program and your risk exposure being actively managed in the company with your board.

[00:23:41] And that will also take us away from security theater. Love it. Such a powerful point. And I always try and give people listening a series of valuable takeaways. So before I let you go, if you could leave security leaders with one practical roadmap for the next 6 to 12 months, what kind of actions would you prioritize to strengthen governance, reduce operational risk, and prepare for a future where AI inevitably becomes embedded across every part of the business?

[00:24:09] What advice would you leave everyone with there? I think the defining challenge of the next year is going to be how to keep governance aligned with the speed of AI adoption and the velocity of AI technology changes that we are seeing in our landscape today. And it's both sides of the fight. Our research found the fastest growing threats to UK businesses were all AI-related.

[00:24:36] AI phishing, AI malware, AI-driven identity fraud. But organizations are also manufacturing risk internally through shadow AI, exploding number of machine identities, autonomous agents making operational decisions. So we have to tackle the risk from both ends, which is AI security risks, and then AI adoption causing more risk.

[00:24:59] And then the roadmap that I would give to my fellow security leaders for the next 6 to 12 months will include five things. First is get more visibility. Build and maintain a live inventory of your cloud assets, SaaS, vendors, machine identities, AI tools, agents, because everything else depends upon it. Second, I would say is map your critical suppliers.

[00:25:23] Identify every third party with network access or sensitive data and then tier them by risk and disruption potential. And strengthen contracts with incident notification SLAs, evidence rights, and continuous monitoring. With the bill expected to receive royal assents this year, we should be doing this now. It should be part of your timeline. Don't scramble later after your regulators come after you. And I would tie it back to the third point, which is rehearse the clock.

[00:25:52] It's like something which is very frightening for me are the timelines for incident notifications and reporting period. So start testing your ability to meet the 24-hour and 72-hour reporting with your suppliers in the exercise. I personally have done incident response with suppliers sitting on the call, on a Zoom, for example, and being part of that exercise, especially when they're critical service providers. Don't just do it with your own team because that's only part of the picture. That's not your complete picture.

[00:26:22] Escalation paths, reporting ownership, all of these should be trusted in a drill. It should never be tested live during a breach. Fourth is make your controls continuous. Evidence direct from systems, drift detected same day, audits as a byproduct of daily operations rather than an annual event. And then fifth and the last one is put guardrails around AI. Don't be a blocker, be an enabler, but with guardrails.

[00:26:52] Keep human approval in place for high-impact actions, changing access, deleting data, moving money. These are all really high-impact actions. While you keep letting AI accelerate the lower-risk work, that keeps accountability where it belongs without slowing the business down. I think the organizations that succeed will be the ones that make governance as part of their everyday operations. And then trust becomes something continuously maintained and demonstrated,

[00:27:20] which will give customers, regulators, their board far greater confidence than any audit certificate ever could. Wow, that is such good advice. Pure gold in there for me. And I suspect we would have set off more than a few lightbulb moments in our conversation today. Like we said a few moments ago, that Banter Research finds organizations that discover 140 unmanaged tools

[00:27:47] accessing their environment within 90 days of connecting to Banter. So anyone listening who we woke up today, they want to find out more information about anything we've talked about. Where would you like me to point everyone listening? Everything we have talked about today, the state of trust research, our guidance on the cybersecurity and resilience bill, AI governance resources, everything is at banter.com. You can also find me on LinkedIn as Khushbukashab.

[00:28:14] And if you enjoy watching CISOs get put through paces in real life incident scenarios, you can check out Banter's YouTube as well. Awesome. Well, we've covered so much in a short amount of time today from that widening control gap between AI adoption and governance, incoming regulatory pressures, and the need to rethink compliance. So I will add links to everything that you mentioned there.

[00:28:41] And there'll be a blog post associated to this episode at Tech Talks Network. I'll also embed one of your videos and links to the YouTube channel there. But more than anything, thanks for joining me today, Khush. I'm bringing all this to life. Really appreciate it. Thank you so much, Neil. It was a pleasure and one of the best meetings I've had this month. I think today's conversation challenged the idea that passing an audit automatically means that your company is secure.

[00:29:06] As my guest explained today, visibility must come first. And you cannot govern AI agents and suppliers that you don't even know exist. And also talking about why CISOs should stop reporting compliance statuses to boards and start talking about business exposure. I also loved her advice to security teams at the end there. Don't become the department employees work around.

[00:29:35] Yeah, put guardrails around AI adoption, but help people use it safely and make governance part of everyday operations. Is this what you're seeing and hearing in your organization? Is your company genuinely reducing cyber risk? Or has proving compliance become more important than just improving security? Let me know. TechTalksNetwork.com. We have 4,000 interviews over there.

[00:30:03] You can also catch me on the road or learn more on how you can work with me. But that's it today. I'll see you next time on the Business of Cybersecurity podcast. Bye for now.