Left Arrow Icon
All articles

CISOs Are Becoming Risk Champions As Recovery Replaces Prevention As The Metric

The Security Digest - News Team
Published
August 11, 2026

Joseph Davis, Chief Security Advisor for Microsoft's U.S. Health & Life Sciences business, makes the case that the next generation of CISOs will be measured on recovery, auditable decisions, and resilience.

Credit: The Security Digest

Make The Security Digest one of your go-to sources on Google

Google Icon
Add The Security Digest on Google
Quote Icon
When you're going up against nation states' offensive measures, they have literally unlimited budget against private and public companies. You're never going to win that war. The war you need to win is the bounce back.

Joseph Davis

Chief Security Advisor

Joseph Davis

Chief Security Advisor
Microsoft, U.S. Health & Life Sciences

Enterprise security leaders are still judged on the attacks they stop, and the rules governing what their companies tell investors are about what happens after one lands. A public company that decides a cybersecurity incident is material has four business days to file what happened and what it expects the damage to be. Its annual report has to name who oversees cybersecurity risk and how management handles it. Both answers require a written record of what the company did during an incident and who authorized it. Security programs organized around prevention produce no such record, and a compliance certificate doesn't replace it.

Joseph Davis, Chief Security Advisor for Microsoft's U.S. Health & Life Sciences business, was a Microsoft customer before he was a Microsoft employee, and he advises executive teams from that footing. He has consulted across medtech, pharmaceutical, payer, and provider organizations, contributed to FDA guidance on connected medical devices, and speaks at DEF CON's Biohacking Village. Every recommendation he brings to a leadership team carries a cost model weighing the price of paying down a given risk against the price of leaving it in place.

"The cybersecurity industry has been obsessed with what we call 'left of bang', right before the incident, stopping the attacks. When you're going up against nation states' offensive measures, they have literally unlimited budget against private and public companies. You're never going to win that war. The war you need to win is the bounce back," says Davis. The budget asymmetry he describes reframes what a security program can promise. A prevention program measures itself against attempts it turned away, and a recovery program measures itself against the hours between an incident and a functioning business.

Agents run the exercises

Adversary simulation used to require staffing two teams and scheduling them against each other. Banking security teams have started preparing the governance layer before they turn any of it on. "We're seeing agentic autonomous agents being incorporated in XDR and SIEM environments, so that you don't have to have humans playing the role of red team, and you don't have to have humans playing the role of blue team in detection, to see how well your controls have been implemented," says Davis. "Then you have green team agent operators that will help with decision support around how to improve things going forward, and they might even be able to make some of those remediations."

Detection coverage across most enterprise deployments already leaves substantial gaps, which raises the cost of an unsupervised test that goes wrong. "That is not to say there's no human in the loop," says Davis. "There has to be a human in the loop before these exercises move forward, or during the exercise, because the last thing you want to do is take down your production systems just to simulate an attack on your enterprise."

The same capability runs in the other direction. An attacker working from local hardware leaves no vendor logs, no API records, and no usage telemetry for anyone to subpoena. "It's widely being used as an offensive tool as well," Davis notes. "Individuals can use local models on edge systems that have incredible shared memory resources, NPUs, CPUs and GPUs that all get to share half a terabyte of memory. You can make a local model, or some open source models without guardrails, do whatever you want them to do."

Beyond the CISO's desk

Security leaders now have to underwrite decisions about manufacturing lines, claims processing, and clinical operations, and the knowledge those decisions require stays with the people running them. Davis treats the concentration of accountability in one office as an organizational design error, and organizations that have corrected it describe the outcome as shared responsibility across the business. "The CISO can't be accountable for everything, nor should they be accountable for everything," he says. "Typically the CISO comes from a technical background, or a military background, or maybe some kind of audit background, but they don't necessarily know how sausage gets made. That's up to the business, and they have to partner with the business in order to make key investments."

Distributing accountability requires the operating side to see what an incident costs them specifically. Warnings pitched at threat actors and attack techniques leave plant managers and claims directors with nothing to act on. Davis describes one organization where the message came from the chief executive at an all-hands, built around a badge reader and a plant floor. "The CEO got up on stage and said, tomorrow you might come to the office and you won't be able to get into the building, and the reason is because a cyber criminal attacked our card access system," he recalls. "None of the manufacturing is going to happen, because they can't get into the plant."

Putting a number on the outcome turns awareness into a budget line item. A quantified loss figure gives an executive team something to weigh against the cost of the control. Davis uses business vocabulary deliberately when he describes the discipline. "I'm not really talking about security, because I think security is inherent to business risk," he explains. "Business risk essentially needs to be quantified in order for a strategy to be created. Where do I invest? Where do I pay down my risk? How much insurance do I need?"

Funding the bounce back

Once a company puts a number on its risk, the money can go two ways. Some of it makes an incident less likely, and some of it shortens how long the business stays down once one lands. The second kind of spending is the one enterprises are now pulling together, funding remediation, modernization, and rehearsal as one continuity program under a single owner and a single budget. "If good risk rigor and management is performed prior to any event, the thing that needs to follow up is not only investment in reducing the risk, but investment in resiliency," notes Davis. "Investment in resiliency means you're probably better at getting your business up and running after a disaster than you are in defending against attacks."

Operating executives ask how long before they ask what happened. A recovery that requires an engineer to touch every affected machine takes longer the more machines a company owns, and the responders doing that work are the same people already stretched thin. "The problem that chief operating and administrative officers are concerned with is, I don't give a hill of beans what happened," says Davis. "I want to know how much this thing is costing me, how long we're going to be down, how quickly we can recover."

Recovery work also has to be documented while it happens. The people doing it sit across operations, legal, communications, finance, and IT, and the order in which they made their decisions is what a regulator reads afterward. Teams that have been through a real incident describe choices made in the first hour that the company is still answering for years later. "If you don't audit how you respond, when the SEC comes in knocking and says you had an incident, did you pay the ransom, who's responsible, who's going to sign this document that says we've been materially affected and it's going to show up in our 10-K?" Davis adds. "All of that needs to be recorded."

Risk champions take the job

Executive teams make decisions in hours and dollars. A security leader who reports how long the business would be down after an incident, and what those hours cost, is speaking in the same terms as the finance and operations chiefs at the table. A count of blocked attacks says nothing about the systems that can't be patched and would go down anyway. "That's what's going to make or break CISOs," says Davis. "CISOs are going to be risk champions and not necessarily cybersecurity champions. You're a champion of the practice that makes your company more resilient."

Davis carries the standard past the security program and into how he assesses a company, treating a recovery answer as a read on operational rigor everywhere else. "How well can they engineer the product, or their claims to patient care, or their claims to have the best retailer of the year?" he concludes. "If they don't have that operational rigor in areas of risk reduction and recovery and resilience, then I'm starting to lose faith in their product."