Michael Fanning, CISO at Splunk, joins The Tech Trek for a grounded conversation on how the security leader role is changing in the AI era. This episode gets into the real tension facing modern CISOs, balancing risk without slowing the business down, hiring for technical depth over narrow credentials, and defining success in a field where perfection is not a realistic metric.
This is a practical conversation for security leaders, engineering leaders, founders, and operators trying to make sense of AI adoption inside the enterprise. Mike breaks down why security has to move from fear based messaging to business enablement, why many teams may be overlooking strong security talent hiding in adjacent technical roles, and where AI can either reduce burnout or make it worse.
In this episode
Why the CISO role is becoming more engineering driven and more tightly tied to business outcomes
Where AI creates real leverage for security teams, and where it introduces new operational risk
Why the security talent gap may be as much a hiring mindset problem as a supply problem
What actually causes burnout in security teams, beyond the usual talking points
How to think about success in security when zero incidents is not a serious metric
Highlights
1:44, The CISO role is shifting from pure protection to business enablement
7:11, AI creates leverage for defenders, but it is also accelerating the attacker playbook
9:31, The biggest AI security risks, from developer copilots to agent driven decision making
14:15, Why security teams need room to experiment with AI or risk falling behind
16:58, Only 1 percent of CISOs surveyed prioritized technology to close the skills gap
22:16, AI can reduce burnout, but only if it cuts noise instead of creating more of it
Security is about assessing risk and finding a way to say yes in a way that is responsible.
A practical idea worth taking back to your team
Look beyond candidates with formal security titles. Mike makes the case that strong engineers, SREs, and cloud practitioners often already understand the systems, access models, and infrastructure realities that matter most. Security can be taught on top of that foundation.
Link to report: https://www.splunk.com/en_us/form/ciso-report.html
Follow The Tech Trek for more conversations with leaders shaping how technology actually gets built, secured, and scaled.