Left Arrow Icon
All articles

The Security Org Chart Is About To Reorganize Around Outcomes, Not Handoffs

The Security Digest - News Team
Published
August 23, 2026

Rinki Sethi, Chief Security & Strategy Officer at Upwind Security, on why agentic AI is pushing security teams to organize around outcomes rather than the functional handoffs between SecOps, GRC, and identity.

Credit: The Security Digest

Make The Security Digest one of your go-to sources on Google

Google Icon
Add The Security Digest on Google
Quote Icon
You could 10x your staff by having a team of agents that you're managing, even as an IC.

Rinki Sethi

Chief Security & Strategy Officer

Rinki Sethi

Chief Security & Strategy Officer
Upwind Security

For most of its history, the security organization has run on handoffs. Security operations catches something, documents it, and passes it to governance, risk, and compliance, which logs the risk and routes the control question to whoever owns identity or infrastructure. Each team has its lane, its tooling, and its queue. Agents do not work that way. The lines between functions are blurring because agents can execute workflows across them without the handoffs humans historically required. If the work no longer stops at the seams between teams, it's fair to ask why the team is still built around them.

Rinki Sethi is Chief Security & Strategy Officer at Upwind Security and a four-time CISO whose past seats include Twitter, Rubrik, and BILL, with earlier stops at Palo Alto Networks and IBM. She is also a founding partner at Lockstep and has served on the boards of StrongDM, ForgeRock, and Vaultree. When she posted her own sketch of a future security org chart on LinkedIn, it drew a real debate, and she is the first to say the specifics are open.

"I don't know for sure what the future org chart is going to look like, but it's going to be different," she says. "Maybe this is one view of what it could look like." The specifics may be open. The direction, she argues, is not.

The work stops respecting the seams

Sethi walks through a simple version of what she means. A detection fires. If the fix is something an agent can safely handle on its own, it handles it. If there is no control in place to mitigate it, the agent writes the finding straight into a risk register, and a high-severity entry there triggers an alert and pulls a human in to follow up.

Trace that path on a traditional org chart and it crosses three teams. In her example, the workflow crosses all three without stopping for a human handoff. "The agents just went and did all the work," she says. "So it starts becoming more outcome-based, rather than security operations doing this task and then handing it over to GRC and then to these other teams." When the connective work between detection, risk, and response collapses into something an agent does in one motion, the case for keeping those as separate stops on an assembly line gets weaker. "This is an opportunity for us to think differently around the outcomes that we're after, and organize around that," she says.

The specialized functions don't vanish. Identity and access management is still deep, hard work. The point is narrower and, in a way, larger: the organizing principle moves from who owns which task to which outcome the whole system is accountable for. Instead of organizing primarily around SOC, IAM, GRC and AppSec, teams may increasingly organize around outcomes: reducing exposure, protecting identities, securing production, maintaining resilience and managing enterprise risk.

Ten times the reach, same headcount

The economics are what make this more than an org-design thought experiment. Security has never scaled the way the threat has. The talent gap is old news, and hiring was never going to close the distance between the work coming in and the people available to do it. Agents change the math on that in a way Sethi finds energizing.

"You could 10x your staff by having a team of agents that you're managing, even as an IC," she says. The multiplier applies to capacity. An individual contributor can run a fleet of agents that does what used to take a room of people. That reframes what a security job is. The interesting work stops being manual triage and becomes the design of the agent infrastructure behind it, a build problem more than a queue-clearing one.

She has watched a version of this play out before agents entered the picture. Tier-one and tier-two analysis was already heading toward automation, and the career path was already bending away from it. "At Palo Alto Networks, we already saw a career path where we said, we're not going to call them analysts anymore. Everybody's an engineer, and you start getting into threat hunting and the more unique things you want to focus on," she says. As machines absorb more of the repetitive work, people can move up the stack toward threat hunting, engineering, and the incidents that demand judgment.

Autonomy still needs accountability

A person remains accountable throughout, even if a person isn't approving every individual action. Where the approval sits depends on consequence. Actions that are low-risk and reversible can run autonomously, while irreversible, ambiguous, or regulated decisions route to a human first. Deterministic guarantees still matter, regulation and compliance have not caught up to what the technology can do, and the depth of understanding that lets a defender build the right agent in the first place does not become optional. "You still have to have the understanding of how attacks happen, how the bad guys are thinking, to build the right kind of agent infrastructure," she says.

Her non-negotiable is transparency into what an agent did and why. Any tool making consequential decisions has to provide enough evidence, context, and an auditable decision trail for a person to understand and validate what it did. "I can't imagine a world where folks are not going and looking at the reasoning and validating that," she says, at least in the near term. The role shifts over time toward governing which agents may talk to which, and with what permissions, but the instinct to check the machine's work stays put for a while.

The CISO becomes a chief trust officer

Push the outcome-based idea up the org, and it reshapes the top job too. Sethi sees the CISO role widening into something closer to a chief trust officer, with security increasingly intertwined with privacy and data governance. The accountability becomes how the enterprise establishes and maintains trust across its people, its machines, its data, its AI systems, and the third parties it depends on. As agents become actors in the enterprise with identities, permissions, data access, and delegated authority, the trust boundary expands well beyond traditional cybersecurity.

Underneath that role, Sethi expects a new shared-services layer to form. In a lot of engineering organizations, tooling lives in a central platform team rather than being re-bought by every group. She thinks security is heading toward its own version of that, an AI security platform where the tools are managed centrally rather than each function running its own stack.

What that layer needs from the people running it is a slightly different profile than the classic specialist. It calls for someone who can invent the next generation of capability and also explain it, translate it, and carry it across the business.

Never waste a good incident

The reason any of this feels urgent right now is that the threat side is moving at the same speed as the tooling. The autonomous agent that breached Hugging Face in July, chaining real vulnerabilities and running thousands of actions across a single weekend with no human directing the individual steps, is the kind of public, undeniable event that reorders a lot of calendars. Sethi's phone fills with texts from CISOs whose boards and CEOs are suddenly asking what they should be worried about, and where the focus should go, whether that is sharper detections or firmer guardrails around what agents are allowed to do.

She treats those moments as leverage. "Never waste a good incident," she says, borrowing the old crisis-management line and pointing it at investment. A high-profile breach is the rare moment when the attack surface stops being abstract to the people holding the budget. She has watched the cycle before, from Home Depot to Heartbleed, where a single loud event unlocked years of cyber spending, and she reads the agentic moment as one worth using to fund a rethink of how teams are built.

Her 90-day advice starts with the risk-appetite conversation most companies keep putting off, before buying anything new. Everyone wants agents, and the efficiency gains hold up, so the question is how much risk the business is actually willing to take to get there. "What's your company's appetite for risk? Let's be very open about it," she says. A company sprinting toward AI with a low tolerance for risk has to invest heavily in visibility and controls to match. One moving more cautiously is in a different spot. Either way, the appetite gets named out loud and the executive team and board get aligned on it.

An inventory follows, covering more than which agents are running. What each one can access, what actions it can take, who authorized it, which other agents it can talk to, and whether anyone can reconstruct what it did afterward all belong on the same list, and what comes back rarely matches what leadership assumed. Agents doing reversible, low-stakes work can operate with greater autonomy. As access becomes more privileged, actions more consequential, or behavior harder to observe and reverse, human oversight increases.

From the org chart down to the ninety-day plan, her answer is the same. "We all own this together," she says. The security leader is not meant to carry the agentic transition alone, and the teams built to handle it, whatever the boxes end up being called, will be organized around the outcomes everyone is accountable for rather than the handoffs that used to define them.