About
Anand is the Co-Founder of CompFly AI, where he leads product strategy and go-to-market execution. He brings 15 years of deep expertise spanning compliance, audit, M&A, and cybersecurity, having spent his career in the highly regulated, global financial services sector with leadership roles at Ernst & Young, Franklin Templeton Investments, and Dolby Laboratories. Anand has been featured in The AI Journal, and TechBullion, and has published research on AI governance on SSRN and FinExtra. He is a member of The Conference Board's Chief Audit Executives Council and the OpenAI Forum. He holds a CISA certification, a Master's in Engineering from Lehigh University, and an MBA in Finance from The Wharton School at the University of Pennsylvania.
Anand Salodkar
Published content

expert panel
NIST emphasizes that effective AI risk management depends on organizations being able to govern, map, measure and manage how AI systems are used. However, following that guidance is becoming increasingly complicated.Artificial intelligence is moving into everyday business operations faster than many organizations’ security and governance processes can keep up. Employees and business teams can now build workflows around large language models, add AI copilots to existing tools, and connect agents to company systems without the kind of formal deployment process that traditionally gives security teams visibility into new technology. As AI moves from standalone experimentation into copilots, connected workflows and increasingly autonomous agents, security teams may have less visibility into where it’s being used, what data it can reach and what actions it’s authorized to take. The result is a widening gap between the AI environment an organization believes it is governing and the one actually taking shape across the business.It’s essential for security leaders to gain visibility into the web of AI systems being built across their organizations—and the ever-expanding attack surface that comes with it. Below, members of the Senior Executive Cybersecurity Think Tank—with expertise spanning enterprise cybersecurity strategy, breach prevention, risk management and cybersecurity leadership—explain how security leaders can get ahead of business-led AI deployments and recognize when unmanaged AI risk is already beginning to compound.

expert panel
An attacker who gains access through a stolen credential may quickly move across devices, cloud resources and network systems in search of valuable data or greater control. Each step can generate clues, but when those signals land in separate tools and queues, security teams may struggle to recognize the full attack before the damage spreads.This challenge is becoming harder to tackle as traditional boundaries between users, devices, applications and infrastructure continue to dissolve. NIST’s zero-trust guidance reflects that shift, moving security away from static, network-based perimeters and toward continuous decisions based on users, assets and resources. This same erosion of boundaries is what makes it harder to catch attackers who don’t need to break anything to move around. CISA’s guidance on identifying and mitigating “living off the land” techniques warns that attackers can abuse legitimate, trusted tools and processes to blend in with normal system activity, making isolated alerts harder to interpret without broader context.Yet many organizations still measure security effectiveness largely by how well they detect suspicious activity. Detection remains essential, but alerts alone don’t determine which risks matter most, coordinate action across environments, or help the business continue operating when defenses fail. That requires an approach that connects visibility with timely decisions, enforceable controls and plans for maintaining and restoring critical operations.Moving beyond a detection-centric model means reconsidering how security data, decisions and defenses work together across the enterprise. Below, members of the Senior Executive Cybersecurity Think Tank—with expertise in enterprise cybersecurity strategies, data breach prevention, risk management, threat detection and cybersecurity leadership—explain what a more unified, real-time approach to visibility, control and resilience should look like.

expert panel
Cybersecurity leaders have never had the luxury of moving slowly, but the second half of 2026 may test even the most mature security teams. AI is accelerating both sides of the fight: Attackers can find vulnerabilities, craft more convincing scams and move faster, while businesses (and employees) are racing to embed AI into products, workflows and everyday operations. That combination raises the stakes for every leader responsible for protecting data, systems, customers and trust.The challenge isn’t just technical. As cyber risk spreads across engineering, finance, operations, legal, HR, procurement and executive teams, the old model of security as a separate checkpoint no longer fits how businesses actually run. The organizations that handle this next phase successfully will need to rethink cybersecurity as a shared operating discipline, not a last-minute review, compliance exercise, or problem for one department or leader to solve alone.Members of the Senior Executive Cybersecurity Think Tank have deep expertise in enterprise cybersecurity strategies, risk management, threat detection and cybersecurity leadership. Below, a group of them discusses what they see as the biggest cybersecurity challenges for leaders in the second half of 2026 and how organizations move from reactive defense to enterprisewide resilience.

expert panel
Agentic AI systems are designed to operate autonomously to achieve a goal, interpreting objectives, selecting tools, executing multistep tasks across systems, and adapting their approach based on intermediate results. Unlike traditional software that follows fixed instructions, agentic AI can make decisions, delegate to other agents and take actions with real-world consequences, often with minimal or no human intervention at each step.Enterprises are adopting agentic AI at a rapid pace, drawn by its ability to compress complex workflows ranging from IT operations and software development to customer service and financial processing. These automated pipelines run faster and at a greater scale than human teams alone. But that same autonomy introduces a security challenge that conventional frameworks weren’t built to handle.Traditional access controls were designed around a simpler premise: Verify the user or system, then permit or deny the action. In agentic environments, that model breaks down. An agent may be fully credentialed and operating within approved systems yet still drift into behavior that no one explicitly authorized. That’s why intent-based security is quickly becoming a core consideration for enterprise AI adoption. For security leaders, the challenge is building controls that are strong enough to prevent harm without slowing the very automation they’re trying to enable. Members of the Senior Executive Cybersecurity Think Tank have deep expertise in enterprise cybersecurity strategies, risk management, regulatory compliance, and modern security architecture. Below, three of them discuss why intent matters in agentic environments and which runtime signals and safeguards leaders should prioritize as autonomous systems become more deeply embedded in business operations.

expert panel
The foundational philosophy of zero trust can sound deceptively simple: Verify everyone, trust no one and keep attackers from moving freely. In practice, though, it’s not that neat. Businesses change, employees need access to new tools, cloud environments expand and attackers keep finding fresh ways to test old assumptions. New users, new systems, new attack vectors: The environment that zero trust is meant to protect keeps changing, which means it’s time to move beyond philosophies and frameworks and implement realistic, forward-thinking architectures.The essential question is whether an organization can clearly see what’s happening across its systems, contain damage when something goes wrong, and keep operations running without forcing people to work around security controls to get their jobs done. The answer lies in shifting focus from implementation milestones to measurable outcomes: protecting the most critical assets, supporting the way people actually work, and measuring progress through outcomes rather than activity. The goal of zero trust isn’t to prove that every possible risk has been eliminated. It’s to show that an organization is becoming harder to compromise, faster to respond and easier to operate securely. Members of the Senior Executive Cybersecurity Think Tank have years of experience and deep expertise in enterprise cybersecurity strategies, threat detection, risk management and zero-trust architecture. Below, five of them discuss how to define “good enough” zero trust progress in practical terms and the real-world signals that tell leaders they’re reducing risk, not just adding friction.

expert panel
A code audit might catch a misconfiguration before it ships. A penetration test might expose how a real attacker could chain vulnerabilities together. A bug bounty might surface something neither effort ever would have found. Each of these exercises brings value, but each one only shows part of the picture at a moment in time. But software risk constantly grows and changes as systems, dependencies, attackers and business priorities evolve. Security gaps often live where handoffs break down: between development and release, between internal teams and external researchers, and between finding a problem and implementing a fix. And as AI supercharges the speed at which vulnerabilities can be found, patching cadence matters more than ever. When teams design a security program in which code audits, pentesting and bug bounties reinforce one another across the entire software lifecycle, they’re better positioned to find issues early, prioritize what matters and build safer products without bottlenecks and delays. Moving from point-in-time testing to continuous improvement requires both structural changes and cultural ones, including how findings are tracked and how engineering and security teams collaborate day to day. Below, members of the Senior Executive Cybersecurity Think Tank share what they’ve learned about integrating code audits, pentesting and bug bounties into a security program that keeps improving with every test, fix and release.
Company details
CompFly AI
Company bio
The Control Plane for Autonomous Agents CompFly provides the operational layer to discover AI agents, enforce tool boundaries at runtime, and turn autonomous decisions into durable evidence for security and compliance.
