The security team who says “no” three times no longer receives questions. Faced with the fourth problem, the company circumvented them entirely, making decisions without security intervention, deploying tools without review, and creating exposure that the security team won’t discover until something breaks.
Mike Coogan, Chief Technology Officer and Chief Information Security Officer (CISO), with more than two decades of experience leading cybersecurity and IT transformation across industries, including Brink’s Home Security, has a name for the security culture that produces this result. “The ‘no’ department is intellectually lazy,” Coogan says. “It fails to look at risk holistically and it harms the relationships that actually make security work.” »
Listening is the Most Underrated Safety Skill
When a corporate actor says they want to punch holes in the network, they are not asking for a security breach. They express a desire to transfer a third party’s data with minimal friction. These are totally different problems with totally different solutions, and a security team that responds to the first without understanding the second has failed in the most important part of its job.
Coogan observes that security professionals are rewarded internally for saying “no,” which exactly reinforces the behavior that erodes their organizational influence. Each “no” without an alternative teaches company this security is an obstacle rather than a partner. There is secure means to deploy AI, manage authentication, manage e-commerce, and manage development,” says Coogan. “Failure comes from shutting down insecure ideas without exploring the underlying purpose.” Moving from reactive to consultative does not require different technical skills. It it takes discipline to ask yourself what the company is actually trying to accomplish before responding to how they described it.
You can outsource the work. You can’t outsource responsibility
The gap between how executives and security teams view AI is costing organizations more than just productivity. This costs them their competitive position. Organizations that refuse to interact with AI Because of its risks, we see competitors who have adopted it move faster, execute more efficiently, and conquer ground that becomes progressively more difficult to recover.
Coogan’s position on AI largely reflects his position on security; THE the cost of inaction is a risk it deserves the same rigorous evaluation as the risk of an action. I could charge a a thousand reasons why AI is a bad idea,” he says. “But the reality is that it is being adopted industry-wide, and those who adopt it will move forward more quickly. What is the opportunity cost of not taking advantage of it, and how does it weigh against the cost of cybersecurity?” Security professionals who fail to frame this question in business terms are the ones who tune out important discussions between leaders.
The principle of accountability applies regardless of what is outsourced. You can delegate the work to the AI. However, judgment and responsibility for its results cannot be delegated. When an AI tool produces a wrong response and the user blames the tool, the responsibility has not changed. It is up to the person who chose to rely on the result without verifying it.
The risk that no one talks about
Third-party risk is one of the most underestimated threats facing business leaders today, and it is materializing in a way that is almost impossible to fully map. Organizations source non-essential functions from third-party vendors for legitimate reasons. financial and operational reasons.
These providers then optimize their own operations by outsourcing them to third parties, without the knowledge of the original organization and without meaningful oversight. The original organization already has difficulty assessing safety posture of its direct partners. His partners’ partners are effectively invisible. “You can’t outsource responsibility,” Coogan says. Safety teams that help leaders understand the chain of responsibility they are the ones who earn a place at the strategic table, rather than being handed a list of ready-made decisions.
Follow Mike Coogan on LinkedIn for more information on cybersecurity leadership, business-aligned security strategy, and building security organizations.






