Field Guide

The Cyber Survival Guide:
Insights from 31
Security Leaders

Recommendations from top security leaders on what is working inside their programs today

Preview pages from The Cyber Survival Guide: Insights from 31 Security Leaders

About the Guide

Security programs are changing faster than playbooks.

Security leaders are being asked to adopt AI and report risk in business terms, usually with the same headcount they had last year. The decisions they make now will set how AI operates inside their programs for years: where it gets autonomy and where a person stays accountable.

from the field

Insights from top security leaders

Joseph Davis, Chief Security Advisor, Microsoft: “When you’re going up against nation states’ offensive measures, they have literally unlimited budget against private and public companies. You’re never going to win that war. The war you need to win is the bounce back.”Petra Klein, Group Chief Security Officer, Swedbank: “You have to have a mindset today that if you’re reachable, you’re breachable. You stop almost 90% of all cyberattacks with just pure cyber hygiene.”Mohit Bansal, Senior Manager of Security Engineering, Webflow: “AI is genuinely good for the front half of the funnel: triaging, enriching, correlating, and drafting the initial timeline. The critical decisions in the second half require practitioners with deep operational experience.”

inside the guide

Eight areas where leaders are rethinking strategy.

Each section pairs a direct recommendation with the reasoning behind it.

01

AI Governance and Adoption

02

Human-in-the-Loop SOC

03

Risk-First Security and Compliance

04

Security Culture and the Human Element

05

OT and Critical Infrastructure

06

Leadership, Reporting, and Liability

07

Identity, Trust, and the New Attack Surface

08

Preparedness and Collective Defense

Free Download

Get the full guide

Get recommendations from 31 security leaders that you can apply to your own program, including:

  • Where leaders draw the line between AI autonomy and human accountability in the SOC
  • How to fold compliance into one risk register and report exposure in dollars
  • Why psychological safety shortens dwell time, and how to build it
  • What changes when the thing you protect is a physical process instead of data
  • How to pre-authorize containment so the first hour of an incident is execution, not negotiation

‍