Cybersecurity Leadership Roundtable — Moderating Conversations with Industry CISOs
In June, I had the opportunity to moderate a Security Leaders’ Dinner Roundtable in San Diego focused on a question that is becoming increasingly important for enterprise security leaders:
What happens when physical and cyber risk can no longer be managed separately?
The discussion brought together leaders across cybersecurity, IT, physical security, facilities, risk, compliance, and operations. My role as moderator was not to provide all the answers. It was to ask the questions that could move the conversation beyond individual tools and toward the broader leadership challenges organizations face.
The session was private, so I will not share individual comments or attribute viewpoints to participants. But the questions we explored are relevant to almost every modern enterprise.
When Physical Security Becomes Cybersecurity
A physical access badge, visitor-management system, employee identity, cloud account, and corporate device may be managed by different teams.
The risk, however, is connected.
Imagine an employee leaves the company and their digital account is disabled immediately, while their physical access remains active. Or the reverse.
Each department may have completed its own process correctly, yet the organization still has a security gap.
That is why security leadership increasingly requires visibility across organizational boundaries, not just within the cybersecurity team.
Are You Ready, or Just Ready for the Audit?
Another important question was the difference between compliance and operational readiness.
Most organizations can prepare documentation for an audit. The harder question is whether the same information is available when an incident happens without warning.
If an auditor, executive, or investigator asked today who accessed a location, which systems they could reach, and what happened afterward, how quickly could your organization provide a reliable answer?
Security readiness should not have to be assembled after the fact.
Fragmented Systems Create Leadership Problems
Security teams rarely suffer from a lack of tools.
They often suffer from a lack of connection between them.
Physical access records may live in one platform. Identity data lives somewhere else. Visitor records, endpoint activity, compliance documentation, and incident information may all have separate owners.
When an incident happens, teams can spend valuable time piecing together the story.
That is not simply a technology problem.
It is a leadership and coordination problem.
Someone has to establish ownership, define how teams work together, and make sure critical information is available when it matters.
Compliance on Paper Is Not Resilience
One of the questions I found particularly important was whether an organization can be technically compliant while still knowing that its processes would struggle under the pressure of a real incident.
The answer should influence how leaders think about security programs.
Compliance provides a baseline.
Resilience requires something more: clear ownership, usable evidence, coordinated teams, tested processes, and the ability to respond without spending days reconstructing what happened.


The Value of Moderating the Conversation
Moderating a group of experienced security leaders reinforced something I have seen throughout my career.
The most difficult cybersecurity problems rarely belong to only one department.
They exist between systems, teams, responsibilities, and assumptions.
A good leadership conversation creates room to examine those gaps before an incident exposes them.
As physical infrastructure becomes more connected to digital systems—and as technologies such as AI continue to reshape how organizations operate—the boundaries will become even less distinct.
Cybersecurity leadership means seeing those connections clearly and making sure the organization is prepared to act on them.
That is the conversation security leaders need to keep having.
