September 22, 2026
Where Is AI in Your Environment? How WWT and Tanium Are Translating Cyber Risk for the Boardroom
Kate Kuehn, AVP, Global Cyber Advocacy, WWT, sits down with Tanium's Chris Mahoney, AVP, Americas, and Tim Morris, Chief Security Advisor, to unpack what boards of directors actually care about when it comes to AI and cybersecurity risk. They discuss the long-standing "language gap" between security practitioners, C-suite executives, and board members, and how that gap is widening as AI reshapes both the attack surface and the regulatory landscape. 2026 marks a shift from "are you secure" to "are you providing reasonable security". Learn how the WWT-Tanium partnership helps translate technical security data into the business risk and continuous compliance metrics boards can actually act on.
Cybersecurity leaders and board members often speak different languages when it comes to risk — and AI is only widening that gap.
In this conversation, Kate Kuehn, AVP, Global Cyber Advocacy, WWT, Chris Mahoney, AVP, Americas, Tanium, and Tim Morris, Chief Security Advisor, Tanium, break down what's changing, what boards need to know, and how the two organizations are helping close the divide.
Key themes explored in the discussion:
- The practitioner-to-board "language barrier" — CVEs and MTTR vs. exposure management and KPIs vs. risk posture, liability, and cost of capital, and why none of these translate cleanly up the chain
- "Where is AI in my environment?" as the starting question for any board-level risk conversation, followed by discovering usage, drift, and authorization
- The regulatory pivot from deterministic compliance ("are you secure") to proving "reasonable security" in a probabilistic, AI-driven world — continuous monitoring, model drift, data lineage, red-teaming, zero trust evidence
- Continuous compliance vs. point-in-time snapshots — the case for real-time visibility ("video, not a photograph") over periodic scans
- The asset inventory → asset intelligence → autonomous intelligence maturity journey, and why organizations can't skip steps toward self-diagnosing, self-healing systems
- Which metrics actually resonate with the board (data risk, performance risk, compliance risk) vs. vanity metrics that don't survive translation ("truth is not an average")
- "Automation follows instructions, autonomy pursues outcomes" — where operating models need to head as AI accelerates the pace of both innovation and attack
- 2026 as the "year of accountability/execution," including emerging concepts like algorithmic fiduciary duty and materiality of AI failures
- The WWT-Tanium partnership as a bridge between practitioner-level endpoint data and board-level risk reporting
- Closing advice for CISOs: start with AI visibility, prioritize speed of remediation over tool sprawl, and build reporting cycles fast enough to keep pace with AI-driven threats