From the CISO’s Diary #1 — Why F1 Cars Have the World’s Best Brakes: Cybersecurity as a Business Enabler in the AI Era

From the CISO's Diary #1 — Why F1 Cars Have the World's Best Brakes: Cybersecurity as a Business Enabler in the AI Era

Someone once asked me, during a lecture I was giving to a group of executives: “If Formula 1 cars are built for speed, why do they invest so much money in brakes?”

The room went quiet. Someone half-joked, “so they can stop before the wall.” I let it sit for a second, then said: no. They invest in the best brakes in the world so they can go faster. Because a car that can’t stop with precision can never be trusted to enter a corner at 300 km/h in the first place. The brake is not the opposite of speed. The brake is what makes speed possible.

That sentence has followed me for years, through boardrooms in Tel Aviv, Zurich and Warsaw, through CISSP classrooms, through late-night incident calls. Because it captures, in one image, the thing I spend most of my career trying to explain to people who are not security professionals: cybersecurity is not the department of “no.” Done right, it’s the engineering discipline that lets the business floor the accelerator.

The Boardroom Where I First Really Understood This

Years ago, early in my time doing risk advisory for a financial services client, I sat in a steering committee where the CFO opened with a simple question: “What’s our cyber budget actually buying us?” Not a hostile question — a real one. Nobody in the room, including the CISO at the time, had an answer that wasn’t technical jargon. SIEM coverage. EDR deployment percentage. Patch cadence.

I remember the silence. It was the same silence as the F1 question. Everyone in that room had a P&L to defend, and “we reduced our attack surface by 12%” doesn’t move a P&L. What moves a P&L is: “we can now launch this new digital product three months faster because the security architecture is already Zero Trust by design, instead of bolted on after a breach forces our hand.”

That’s the translation job. I’ve spent twenty years, from MAMRAM to the IDF’s cyber units, through building ISO 27001 from scratch at Nation-E, through CISO-as-a-Service work across European research consortiums, to running BDO’s Security Academy today — doing the same translation, over and over, in different rooms: turning bits and CVEs into euros, reputation, and time-to-market.

Brakes in the Age of AI Agents

Now add AI to the car. Every board I sit in front of today is racing to deploy AI agents — copilots that read email, agents that touch CRM data, LLMs wired into customer service pipelines. The acceleration is real and it’s justified. McKinsey estimates generative AI could add trillions in annual value across industries. Nobody wants to be the company still driving a manual transmission in 2025.

But here’s where the brakes matter more than ever, because the failure modes are new and mostly invisible to the business side.

Take indirect prompt injection. I’ve run tabletop exercises where a “harmless” customer support AI agent, connected to a mailbox, reads an email containing hidden instructions — white text on white background, or buried in a PDF footer — and the agent quietly follows them: forwarding internal data, changing a refund amount, exfiltrating a customer list. The AI wasn’t hacked in the traditional sense. Nobody breached a firewall. Someone just talked to it, and it listened, because nobody built brakes into what it’s allowed to do with what it reads.

Take data poisoning. If your model is fine-tuned on a data lake nobody has mapped — the kind of shadow data I’ve been surfacing for over a decade in enterprise risk assessments — you may be training your next customer-facing model on a poisoned or stale dataset without knowing it. I’ve seen data lineage so tangled that a bank literally couldn’t tell me, with confidence, which of 40+ data sources fed their fraud-detection model. That’s not an AI problem. That’s a DSPM problem — Data Security Posture Management — wearing an AI costume.

From the CISO's Diary #1 — Why F1 Cars Have the World's Best Brakes: Cybersecurity as a Business Enabler in the AI Era

The Real Cost of Missing Brakes

Let me put numbers on this, because boards move on numbers, not metaphors. IBM’s Cost of a Data Breach Report has consistently put the average breach north of $4.4 million globally, with breaches involving shadow data costing roughly 16% more, and those that take over 200 days to identify and contain costing significantly more than faster-detected ones. Now overlay that with the EU AI Act penalty structure — up to €35 million or 7% of global annual turnover for the most serious violations. Suddenly “we didn’t have an AI governance framework” isn’t an engineering excuse. It’s a line item a CFO has to explain to shareholders.

I did a Business Impact Analysis (BIA) with a client last year where we mapped, for the first time, exactly which AI-touched processes would halt the business if compromised. The answer surprised the executive team: it wasn’t the flashy customer-facing chatbot. It was a quiet internal agent doing invoice reconciliation, plugged into finance systems with almost no oversight, that could have frozen cash flow for two weeks if manipulated. Nobody had drawn that brake line before we asked the uncomfortable question.

Building the Brakes, Not the Roadblocks

The teams I respect most don’t ask “should we adopt AI.” They ask “what’s our stopping distance.” That’s a different engineering conversation:

  • Map before you accelerate. You cannot secure — or govern — data and AI pipelines you haven’t inventoried. DSPM isn’t a product decision; it’s a discipline of knowing where your sensitive data actually lives before an agent gets access to it.
  • Treat every AI agent like a new employee with root access. Least privilege, output validation, and human-in-the-loop for anything touching money or customer data — not because AI is untrustworthy, but because trust without verification is how F1 teams lose championships and companies lose customers.
  • Run the BIA before the incident writes it for you. Ask which AI-touched process, if poisoned or hijacked for six hours, actually stops revenue. Most executives are surprised by the answer.
  • Governance is a speed feature, not a tax. Under the EU AI Act and equivalent frameworks emerging globally, documented risk classification and monitoring isn’t paperwork — it’s the thing that lets you ship the next AI feature without a six-month legal freeze the moment a regulator asks questions.
From the CISO's Diary #1 — Why F1 Cars Have the World's Best Brakes: Cybersecurity as a Business Enabler in the AI Era

Back to the Track

I think back often to that boardroom, and to every classroom since where I’ve drawn the same F1 car on the whiteboard. The point was never the brakes themselves. The point was the corner. A car with weak brakes doesn’t get a warning label — it just never enters the corner at full speed, and it loses the race one lap at a time, quietly, while everyone blames the engine.

Cybersecurity in the AI era is exactly this. The organizations winning right now aren’t the ones deploying AI slowest, or the ones deploying it recklessly. They’re the ones who built the brakes first — the DSPM, the least-privilege agent design, the BIA, the governance mapped to real business processes — so that when the straightaway opens up, they can actually floor it, instead of white-knuckling the wheel and hoping the corner doesn’t come too fast.

If this resonated, or if you’ve got your own version of the “why brakes” boardroom moment, I’d genuinely like to hear it — come say hello on LinkedIn: https://www.linkedin.com/in/omri-sagron-cissp-24508331/


I write From the CISO’s Diary from 20 years across BDO, ThriveDX, the IDF and my own ventures. Let’s connect: Omri Sagron on LinkedIn.

From the CISO's Diary #1 — Why F1 Cars Have the World's Best Brakes: Cybersecurity as a Business Enabler in the AI Era

לפרטים נוספים מוזמנים לפנות אלינו