Monday, 28 September 2026 PDT | 05:35 AM
The 1 News Alt Logo Text Smart News for Global Indians

What Mature Security Programs Need Before Deploying AI

AI News September 28, 2026 04:30 PM
What Mature Security Programs Need Before Deploying AI

Enterprise CISOs are under pressure to buy AI-powered security tools, but with vendors increasingly marketing their products as AI, it is hard to tell which tools will reduce risk and which will add cost. And when AI is deployed atop weak access controls, poorly classified data, or limited network visibility, it can exacerbate those gaps.

The World Economic Forum found that roughly a third of organizations have no process to assess the security of AI tools before deploying them, even as 87% of leaders see AI-related vulnerabilities as the fastest-growing cyber risk.

The National Institute of Standards and Technology (NIST) notes that third-party generative AI tools can introduce privacy and information-security risks based on the data and systems they can access. A Cloud Security Alliance (CSA) study found that 53% of organizations have had AI agents exceed their intended permissions, and 47% experienced a security incident involving an AI agent in the past year.

ISACA reports that 56% of digital trust professionals do not know how quickly they could halt an AI system during a security incident.

These findings suggest many security leaders are adopting AI faster than they can evaluate what they are buying or control what it can access.

Emerj’s Yolandi de Weerdt hosted Mark Alvarado, CISO at Academy Sports + Outdoors, on the AI in Business podcast to map out how security leaders can separate real AI value from vendor claims, and how AI can compound existing weaknesses in identity management, data governance, network security, and employee technology practices.​

This article examines three insights for leaders deciding where AI belongs in a security program:

Listen to the full episode below:

Episode: What Mature Security Programs Need Before Deploying AI – with Mark Alvarado of Academy Sports + Outdoors

​Guest: Mark Alvarado, CISO at Academy Sports + Outdoors

Expertise: Cybersecurity Strategy, IT Compliance, Enterprise Risk Management, Identity and Access Management.

Brief Recognition: Mark Alvarado is Executive Director of IT Security & Compliance at Academy Sports + Outdoors, where he has built and led the company’s security program and strengthened its ability to detect and protect business data. He brings more than 20 years of experience across cybersecurity, risk, and compliance, with previous security roles at Ovintiv and Norton Rose Fulbright. At Academy Sports + Outdoors, he established an incident response framework that reduced recovery time by 90% and helped mature the organization’s cyber program. Alvarado holds a Master of Legal Studies in Cyber Law from Texas A&M University School of Law and an M.S. in Cybersecurity and Information Assurance from Western Governors University.

A vendor may claim that its product uses AI to identify threats faster, but that claim alone does not establish whether the product is suitable for a particular security environment. Mark Alvarado argues that vendors cannot know a company’s systems or operating practices as well as the buyer does. The responsibility sits with the buyer to understand its own needs and ask the right questions.

Alvarado traces this discipline to his background in business analysis. When a department requested a solution, he documented the current workflow, the desired state, and the technical requirements before researching options and getting stakeholders’ buy-in.

He applies the same sequence to security investments: begin with a written problem statement, identify possible solutions and their true cost of ownership, and use that work as the basis for a project charter. Whether or not AI is involved, Alvarado says this work either sells him on a solution or talks him out of it before he asks anyone for budget.

Alvarado also recommends establishing a shared definition of “AI” during purchasing discussions because buyers and vendors may use the term to describe different functions. Before a conversation turns technical, financial, or legal, both sides should confirm what they mean by it.

Employee behavior creates an additional readiness test. Alvarado recommends an AI governance program that gives employees clear guidance on when they should and should not use AI, and which questions to ask before they do:

Without employees’ buy-in, he warns, people will find a way around the controls.:

“You can have the most robust locks on your house. But if someone in your house just flat out leaves it open, or bypasses or jimmies the lock, it doesn’t matter how expensive that lock is. Someone’s gonna get in.”

— Mark Alvarado, CISO at Academy Sports + Outdoors

​Identity, data, and network visibility as deployment foundations

In Alvarado’s view, if a security program wasn’t already “buttoned up,” AI “has only made your program exponentially worse.” His starting point is understanding how the company is laid out, where its critical data sits, and where the edge really is, then working backward from there.

From that, he identifies three foundations to prioritize before deploying AI. These programs do not need to be flawless first. Getting them “buttoned up really tight,” he says, is a journey with its own costs. Each foundation answers a question a team should be able to answer before an AI system goes live:

Alvarado does not want to minimize the other domains of cybersecurity. But as more companies move to the cloud and attacks rise in volume and sophistication, he sees these three areas as the ones AI will rely on, and the foundation for organizations to “fight AI with AI.” With those areas buttoned up, he says, teams using AI-based tools stand a fighting chance.

​Response thresholds tied to material business risk

With identity, data, and network activity visible, Alvarado sees value in using AI to analyze large volumes of activity for departures from established patterns. He compares the network to a road, a device to a car, an identity to its driver, and credentials to the keys. An unexpected change in route, destination, device, or data accessed may indicate that someone other than the authorized user is operating the account.​

Because most people are creatures of habit, the system can benchmark an identity’s normal activity and surface deviations for review. A deviation is not, by itself, evidence of malicious activity, since business needs change.​

Alvarado distinguishes asking a user to confirm unusual activity from taking away the “keys” by disabling an identity or terminating a network connection. When a pattern is so different, or an action so egregious, that the organization can’t afford to get it wrong, he acts first and investigates second. He frames that decision around what a CISO is actually responsible for:​

“Fundamentally, at a CISO level, your job is not to stop every little thing that happens. You can, that’s great. There’s a cost associated with it. Your job is to keep the event from being material. The material threshold is different for every company, and each company should determine what that material threshold is. That’s how you make sure that you’re making good use of funds, because your program’s gonna cost.”​

​The materiality threshold, he adds, is different for every company, and each organization should determine its own.​

Alvarado acknowledges the cost of acting before an investigation is complete, since a false positive can interrupt legitimate work. If that happens, the car goes back on the road, and in his experience no one gets upset about erring on the cautious side. AI-based tools cost a little more, he says, but the cost is justified once the three foundations are in place.​

Together, these points connect Alvarado’s central argument: start with a defined business problem, then build the controls that turn an AI-generated signal into a defensible security decision.