TechChannels Expert Insights

Q&A:  Cyera Data and AI Security Officer Rick Holland Talks Tokenomics, How to Move from AI Experimentation to Trustworthy, Measurable Adoption

Written by Teri Robinson | Sep 24, 2026, 7:58:15 PM

For security leaders, the challenge of AI has become managing the speed at which AI is entering the enterprise while confronting data, identity, and governance problems that organizations have struggled with for years.

Rick Holland, CISO and Data and AI Security Officer, at Cyera, sat down with Tech Channels at Black Hat to discuss how AI is expanding before many companies have fully addressed shadow IT, agents are gaining access to data whose source of truth may be unclear, and security teams are being asked to govern technologies that continue to evolve at an extraordinary pace. According to Holland, “the pace of change, the velocity is overwhelming.”

Agentic AI raises the stakes further because these systems use information to make decisions and take actions. Poor data governance, excessive or unused identities, and inconsistent controls therefore become more consequential when organizations “unleash the agent hoard” on top of them. At the same time, businesses face pressure to demonstrate that their AI investments are producing tangible results rather than simply adding technology and cost.

Holland shares what it takes to move from AI experimentation toward trustworthy, measurable adoption. He says organizations should start with focused use cases, and contends trustworthy AI requires collaboration across security, data, IT, and business teams. Governance, he says, “ultimately needs to move beyond policies and committees to technical controls. Central to that evolution is a deceptively simple question: Should this agent take this action at this time with this data?”

Q. What is putting the most pressure on security leaders right now?

A. We’re seeing overwhelmed security leaders. The threat landscape has always been a challenge and the barrier to entry has been getting lower and lower, even without AI. Now, the shadow AI problem is such an unknown. Before the lunch keynote at the AI Summit I did a handraising exercise. There’s a lack of maturity that people have on agentic; the number of people that said they felt like they had Shadow AI under control—nobody's hands went up. We still can't even handle the same Shadow IT stuff that we've had for years.”

Q. Why is keeping up with AI becoming so difficult for security teams?

A. Trying to keep up with the threats AND trying to keep up with your business that is trying to do AI, whatever doing AI is. Unfortunately, a lot of people don't know they haven't defined what AI means for them. They're not getting value out of it. The pace of change, the velocity is overwhelming.

Q. Are organizations paying the piper for not getting governance under control before AI hit?

A. I would say we've been paying the piper for 20 years. But suddenly there’s AI and now it's even worse. AI has exacerbated the problems.

Q. Why do existing data and identity governance problems become more consequential with agentic AI?

A. Some people are paying for all these identities, especially on the Microsoft side, that have never been used. That’s just an example—those organizations can fund Sierra just off unused identities in their environment that they don't need. Or sometimes it's on the data side. An organization has 10 different versions of something. They have all these backup files that they don't need anymore. Now we unleash the agent horde on this house of cards and everyone's got poor data governance, everyone's got poor identity governance, and on the data side now agents are trying to figure out what the source of truth is.

Q. Why does the quality of enterprise data matter so much when agents are making decisions?

A. Agents are making decisions based on data that they have access to. And so it's even more like a house of cards.

Q. How should organizations approach AI initiatives without getting caught up in overly ambitious projects?

A. One of the things that we'll talk to customers about is to aim small, look for a minimum viable product. Get it out and iterate. It’s the same thing with AI initiatives. Pick a small effort.

Q. Why should AI projects be evaluated on measurable business outcomes?

A. You just got all this money to do AI, but what value are you delivering? The CFO is going to ask what value has been delivered. So, again, pick a small project.

Q. What does a successful, measurable agentic AI use case look like?

A. One of my customers does a lot of M&A, and they built out an entire agentic pipeline. So, in looking at targets, the agentic pipeline, they accelerated due diligence, document collection and document review. Then they had the post-close integration. They've been using this for six months and they shaved off 30% of their time from start to close the transaction. That is extremely meaningful when you're trying to get revenue from it.

Q. Who needs to be involved in AI governance and strategy?

A. First, not trying to do these grandiose things. Get some wins, get confidence in your organization. Because more than ever, it goes back to your persona question. The CDO can't do it by themselves. The chief AI officer can't do it by themselves. The CISO can't do it by themselves.

Q. Why is “trustworthy AI” a more useful concept than simply “secure AI?”

A. Surprisingly, to me, I will still come across CISOs that just like we talk about we talk about trustworthy AI, and I really like that distinction versus secure AI. Securing AI is a component of trustworthy AI, but you also have to have clean data. And it really starts with that cross-functional team.

Q. What did your own experience with data science teach you about the importance of clean data?

A. I remember the first time I hired a data scientist at Digital Shadows 10 years ago. I believed since I had one on my own team now, we were going to unlock all this data. Then it turned out our data was garbage. So I could only do a third of the things that I wanted to do because the data wasn't clean. It wasn't ready.

And that was just a human, a post grad person that was working with the data, not this agent horde that's out there now.

Q. What should organizations be trying to maximize with their AI investments?

A. They’ve got to token value max and pick the projects that impact customer retention, customer satisfaction, and revenue increase. We also try to have customers not think about just OpEx savings, because the value of AI is not in cost savings. The value in AI is accelerating the business, in doing new things you couldn't do before.

Sure, CFOs, many of them, will want to know about the bottom line. They need to think about top line, and how to increase the top line, and have some optimization.

Q. How should organizations think about the growing cost of AI?

A. We have unlimited tokens here, which is cool. But I was just talking to one of the guys on the team, and they're definitely looking at our tokenomics. But again, it goes back to the value. How are you going to deliver value?

Q. Are organizations becoming more mature about AI governance?

A. The other big trend is the lack of maturity in general. But I do have some customers that are seemingly more mature on their governance side. Customers will have the right approach, an AI steering committee. They have AI governance, but they still don't have a way to validate it.

Q. Why is governing AI consistently across an enterprise so difficult?

A. How do you govern across scale? How do you do it for the knowledge worker and governance on the vibe-coders, the citizen engineers. How do you have governance on developers? How do you have governance on every single vendor that's got third party relationships?

Q. What does effective AI governance need beyond policies and checkboxes?

A. We're struggling with the discovery, then the guardrails for governance, and then the protect parts. Managing the drift is a problem with agents. They love to drift. That's what they do. People are really struggling for it. Can they have technical controls that when the model—and it doesn't have to be a frontier model—starts going off the rails.

Q. What should organizations be monitoring once agents are deployed?

A. I would suggest you go in and start looking now at telemetry. Did your agents do something unexpected as well? You need to be able to answer: Should this agent take this action at this time with this data. For some decisions agents make that data won’t be in it, but nobody can confidently answer that question at all.

Q. How can organizations determine whether an agent has drifted from its intended purpose?

A. What was the intent of the creator? Have we drifted from that intent? When we drift, can we get it back in its guardrails? So that's what we're working toward now.

Q. Why is diversity particularly valuable in threat intelligence?

A. When I was at Digital Shadows and I ran the Intel team there, I had about 40 people on my team. All my leaders were women, and 55% of my team were women. I have found in the threat intelligence community, it's a community where you need a lot of diversity because you don't want to have a groupthink for intel analysts.

The rise of agentic AI is exposing a fundamental reality: organizations cannot build trustworthy AI on top of weak foundations. Poor data quality, unclear sources of truth, unmanaged identities, shadow AI, and inconsistent governance existed long before today's agents. AI is amplifying those problems by giving autonomous systems the ability to make decisions based on the data and access organizations provide them. Holland contends that enterprises have been “paying the piper for 20 years” and AI has made the consequences more pronounced.

Addressing that challenge requires more than securing individual AI systems. It means thinking in terms of trustworthy AI, where security is one component alongside clean data, appropriate access, governance, and cross-functional accountability. No single executive can own that challenge alone. CISOs, chief data officers, technology leaders, AI leaders, and business stakeholders all have a role in determining where AI should be used, what information it can access, and how its behavior should be governed.

It also requires a clearer definition of value. Rather than launching sweeping AI initiatives simply to “do AI,” Holland advocates starting small, demonstrating results, and expanding from there. And the opportunity goes beyond reducing operating expenses: he argues that AI's greater potential lies in accelerating the business, improving customer satisfaction and retention, increasing revenue, and enabling organizations to do things they could not do before.

As agents become more autonomous, however, governance must become operational as well. Organizations need enough context and telemetry to understand what an agent is doing, what data and identities it can access, whether its behavior matches its creator's intent, and when that behavior begins to drift. The next stage of enterprise AI maturity will therefore be measured not simply by how many agents an organization deploys, but by whether it can confidently understand, govern, and derive meaningful value from what those agents actually do.