Skills
About
Ken Grohe has enjoyed being a business entrepreneur for over 35 years. Grohe's experience includes a 25-year career at EMC, as VP & GM of the flash, software, and partner business units. He was with Barracuda Networks as SVP & GM, CRO of Virident and its acquirer, Western Digital, and President of SignNow. Additionally, he was the CRO of Samsung's Stellus and President, CRO at AI leader WekaIO, CRO/SVP of Taos/subsequent Partner, Platform and Security Engineering at IBM, and fractional CMO of SPHERE. An International Bestselling Author, and Rockland, Mass Hall Of Fame inductee ('22), Grohe has served as a board advisor/investor to several technology companies, including: Zoom, SecurityScorecard, Evisort/WorkDay, Boston Red Sox, SantaCruz Warriors, Multiple Sclerosis Society, Pasatiempo, SalesCommunity, Boston College, Stanford GSB, Breezeway, CoPilot, Cohesity, ServIQ/ServiceExpress, Taos, Mettalic.io/Commvault, Cytactic, SPHERE, www.SantaCruzWhatever.com, & www.LeverageGTM.com
Ken Grohe
Published content

expert panel
Cyber exercises give an organization a chance to uncover weaknesses before a real attack puts its response to the test. Yet what teams rehearse often differs from what they face. A 2025 survey of 480 senior U.S. cybersecurity leaders found that 57% of significant cyber incidents involved attacks the security team hadn’t prepared for. Since no organization can rehearse every scenario, the value of an exercise lies less in the script than in whether it builds the judgment and coordination a response will need when events don’t go according to plan. A scenario that simply walks the security team through familiar technical steps reveals little about how the business would function when a critical vendor goes dark, core systems are unavailable, or executives must make high-stakes calls about operations, disclosure and customer communication with incomplete information. CISA has advised that incident response plans include senior business leadership and board members and that senior management participate in tabletop exercises, reflecting the view that cyber readiness must extend well beyond the security team.Members of the Senior Executive Cybersecurity Think Tank bring deep expertise in enterprise cybersecurity strategy, risk management, incident response and cybersecurity leadership. Below, they explore what separates a useful cyber exercise from a compliance-driven tabletop and how leaders can design exercises that test executive judgment, operational dependencies and cross-organizational coordination.

expert panel
AI can create value quickly, but every new model, agent and AI-enabled workflow can also add another layer of complexity for security teams to understand and protect. When adoption—sanctioned or not—moves faster than visibility and governance, organizations can begin accumulating AI risk debt: unresolved exposures, unclear ownership and controls that may no longer match how the technology is actually being used. Recent research underscores that gap: Less than half of the security leaders surveyed said their companies knew all the AI agents operating on their networks, and less than half said they controlled those agents’ access to corporate data.The challenge is that this debt doesn’t necessarily show up as a single, obvious vulnerability. It can build quietly as AI systems become more capable, new uses emerge and dependencies multiply, leaving security programs trying to manage risk across a moving target. As AI agents evolve from tools that assist employees into systems capable of acting across enterprise environments, companies are confronting governance and security questions for which established practices are still developing.For security leaders, the question is where that growing gap between AI adoption and effective oversight poses the greatest danger—and how to close it before the debt becomes harder and more expensive to unwind. Members of the Senior Executive Cybersecurity Think Tank bring deep expertise in enterprise cybersecurity strategy, data breach prevention, risk management, regulatory compliance and modern security architecture. Below, they explore where AI risk debt is accumulating most dangerously and what security leaders can do now to bring it under control.

expert panel
As companies move more critical systems and data into cloud and SaaS environments, investigating a cyber incident can become a complicated exercise in reconstructing events across systems an organization doesn’t fully control. If important evidence is unavailable or incomplete, determining what happened—and demonstrating what did or didn’t happen—can become much harder. NIST’s work on cloud forensics highlights the distinct challenges investigators face when collecting and analyzing evidence in cloud computing environments.Access to that evidence isn’t always a given. In 2024, CISA, OMB and ONCD worked with Microsoft to expand cloud audit logging for federal customers regardless of license tier and increase default retention from 90 to 180 days, part of a broader push to make critical security logs available without added licensing barriers. That highlights a larger business risk: An organization may discover the limits of its forensic visibility only after an incident, when legal teams, regulators and insurers are looking for clear answers.Cybersecurity leaders therefore need to look beyond whether their cloud environments can detect suspicious activity and determine whether those environments can support a credible investigation after a breach or other security incident. Members of the Senior Executive Cybersecurity Think Tank bring deep experience in enterprise security, incident response, risk management, regulatory compliance and cloud security. Below, they examine how leaders can strengthen forensic readiness before an incident occurs and where evidence gaps can create the greatest problems once an investigation is underway.

expert panel
Cybersecurity teams have always had to distinguish legitimate activity from malicious activity, but external AI agents make that judgment call harder. Unlike a conventional user session or scripted bot, an agent can pursue a goal across multiple steps, adapt as conditions change and operate at a speed and scale that can far exceed human activity.The challenge grows when organizations are interacting with agents they didn’t build, deploy or directly control. Those agents may be acting on behalf of customers, vendors or business partners—or probing systems for an attacker—and their behavior can evolve in real time. In a recent real-world example, AI agents run internally by OpenAI found an unintended path to the internet while trying to complete an evaluation, then breached Hugging Face systems in an effort to obtain information that could help them finish the task. The incident illustrates how quickly an autonomous system can move beyond the boundaries its operators expected.For cybersecurity leaders, that raises a broader question: How do you defend systems when the actor at the other end may be autonomous, adaptive and outside your control? Members of the Senior Executive Cybersecurity Think Tank bring deep expertise in enterprise cybersecurity, risk management, threat detection and modern security architecture. Below, they explore how defensive strategy should evolve as external AI agents become more capable and which protections matter most when agent-driven activity originates beyond the organization.

expert panel
Software supply chain security is often treated as a gatekeeping problem: Keep malicious code from entering the environment. But modern applications are built from dense webs of open-source and third-party dependencies, and a single compromised package can surface across numerous applications and systems downstream, far beyond the first project that installs it.Recent attacks have shown how quickly that risk can multiply. In September 2025, the self-replicating Shai-Hulud worm infiltrated the npm ecosystem through compromised maintainer accounts, spreading automatically across the registry by hijacking developer credentials. By the time it was contained, the worm had compromised more than 500 packages, prompting GitHub to remove them from the registry to stop further propagation.For security leaders, the challenge isn’t only determining whether a package is safe at the point of entry—it’s understanding how far a compromise could travel once that software is already embedded across an organization. Supply chain risk is compounded when organizations lack visibility into how the technology they rely on is developed, integrated and deployed.Members of the Senior Executive Cybersecurity Think Tank bring deep expertise in enterprise cybersecurity strategies, data breach prevention, risk management, threat detection and modern security architecture. Here, three of them examine how leaders should assess the downstream risk posed by poisoned software dependencies and what meaningful prevention and containment look like when a single compromised component has the potential to affect many systems.

expert panel
An attacker who gains access through a stolen credential may quickly move across devices, cloud resources and network systems in search of valuable data or greater control. Each step can generate clues, but when those signals land in separate tools and queues, security teams may struggle to recognize the full attack before the damage spreads.This challenge is becoming harder to tackle as traditional boundaries between users, devices, applications and infrastructure continue to dissolve. NIST’s zero-trust guidance reflects that shift, moving security away from static, network-based perimeters and toward continuous decisions based on users, assets and resources. This same erosion of boundaries is what makes it harder to catch attackers who don’t need to break anything to move around. CISA’s guidance on identifying and mitigating “living off the land” techniques warns that attackers can abuse legitimate, trusted tools and processes to blend in with normal system activity, making isolated alerts harder to interpret without broader context.Yet many organizations still measure security effectiveness largely by how well they detect suspicious activity. Detection remains essential, but alerts alone don’t determine which risks matter most, coordinate action across environments, or help the business continue operating when defenses fail. That requires an approach that connects visibility with timely decisions, enforceable controls and plans for maintaining and restoring critical operations.Moving beyond a detection-centric model means reconsidering how security data, decisions and defenses work together across the enterprise. Below, members of the Senior Executive Cybersecurity Think Tank—with expertise in enterprise cybersecurity strategies, data breach prevention, risk management, threat detection and cybersecurity leadership—explain what a more unified, real-time approach to visibility, control and resilience should look like.
Company details
LeverageGTM, Inc.
Company bio
Leverage the transformative power of generative AI alongside our proven growth strategy to propel your business forward. With our Silicon Valley expertise, we’ll guide you in harnessing the latest AI technologies, identifying essential resources, and forging strategic connections. This integrated approach will accelerate your momentum and enhance your company’s value as you expand into new markets.