In conversation with Canada’s CISO of the Year finalists
Microsoft shipped fixes for 974 vulnerabilities on Sept. 8, its largest security release on record, and researchers have connected the rising volume to Microsoft’s own use of AI-assisted vulnerability discovery.
Anthropic published research in June showing a model can turn a newly disclosed vulnerability into a working exploit in hours. And somewhere inside the building, an agent is asking for access to a data repository.
That last problem brings security leaders back to familiar controls around identity, access, and accountability.
Scroll down for the full conversation
I sat down with this year’s two finalists for CISO of the Year at the CanadianCIO Awards, run by the CIO Association of Canada. Read the full profiles below:
They were joined by Marshall Kuypers, director of product management at Armadin, which sponsors the award. Armadin builds AI agents that attack a client’s live network to find weaknesses a real attacker could use, a practice known as penetration testing.
That Microsoft release came up in our conversation the day after it went out. The question at TransLink is whether the testing cycle can safely be shortened.
“How can we patch faster? Can we reduce the testing cycle? Can we apply a patch earlier than what it should be?” asks He.
Antonishen has the same volume problem and a grid to protect, which rules out speed as the only answer.
“You can’t just shotgun patch everything,” says Antonishen. “We’re still quite nervous that we would break things that would have a significant impact on our business.”
An agent can be given an identity and access to data, without a person sitting behind every action. At TransLink, the security team discussed agent identity and access the morning we spoke.
As He describes an agent is “half human, half machine,” and she’s building an intake process around it: a business case, a named approver, and limits on which data the agent can reach.
“You need to be mindful of your cost management as well. It consumes tokens,” says He.
Antonishen is still working through who owns an agent once it’s deployed.
“Do you rely on the creator of an AI agent or a program model to own it? Does that get handed off to an operational team? How do you track and manage AI drift?” asks Antonishen. “These are all important questions that you need to build into your program up front before things go sideways.”
Antonishen pushes back on the idea that any of this is about distrusting the technology.
“We don’t need to govern AI because we don’t trust the technology,” he says. “We have to govern AI because we’re accountable for what the AI actually does.”
Kuypers pointed to the incident in which OpenAI’s agents carried out an autonomous hack during a safety test, where the agents worked out how to pass messages to each other by renaming files.
“OpenAI didn’t ask the agent to hack,” says Kuypers.
His own company runs attacks against live client networks with five layers of safeguards, a proxy that enforces scope, and a mode where a human approves every single command.
“If you forget about something on the side, the AI is probably going to find a way to go exploit it,” he says.
None of the controls the three of them describe are new.
Least privilege, identity governance, logging, a human approving anything consequential. They were on the list before any of this, and the cost of having skipped them is now arriving faster.
“We’re really going to have to just treat AI the same way going forward,” says Antonishen.
Watch the conversation:
This article is part of a series profiling the finalists for the 2026 CanadianCIO of the Year Awards, CISO of the Year category, presented by the CIO Association of Canada. The winner will be announced Oct. 1 in Toronto. Digital Journal is the national media partner for the CIO Association of Canada.
In conversation with Canada’s CISO of the Year finalists
#conversation #Canadas #CISO #Year #finalists