Security

The Top Priority for CISOs in the AI Era | Steve Winterfeld, Akamai | TFiR

0

Security teams in financial services are being outpaced by the organizations they protect. As institutions accelerate into agentic AI and API-driven architectures, the tools, skills, and guardrails required to secure these environments are fundamentally different from those built for traditional web infrastructure. Most security teams have not made that shift yet.

In this interview on TFiR, Steve Winterfeld, Advisory CISO at Akamai, walks through the top priority for CISOs right now and why embedding security into business transformation, at the same speed, is the only viable posture.

Guest: Steve Winterfeld, Advisory CISO at Akamai
Show: TFiR

Here is what every CISO and security leader in financial services needs to know.

Technical Deep Dive

Q: What should be the top security priority for CISOs in financial services right now?

Steve Winterfeld, Advisory CISO at Akamai, says the single most important move for a CISO is to align security strategy directly to where the business is heading in its transformation journey. Financial institutions are at different stages, some are heavily API-driven, some are all-in on AI, and some are still in early transformation, and the security focus must match that specific trajectory. Embedding security into the transformation process at the same speed, rather than reacting after deployment, is what prevents compounding risk.

“As people move fast in transformation, we don’t have mature security guardrails. My security staff may not be experts in how to protect against agentic AI.” — Steve Winterfeld, Advisory CISO, Akamai

Q: Why do different transformation paths require different security tools?

Winterfeld explains that agentic AI, large language model APIs, and traditional web pages each carry distinct attack surfaces and require purpose-built tooling. A tool set appropriate for securing a traditional web application does not map to the behavioral and data-flow risks introduced by agentic AI systems. Organizations that apply a one-size-fits-all security stack across all three environments leave critical gaps in coverage.

“Agentic AI needs a different set of tools. APIs need a different set of tools. Traditional web pages need a different set of tools.” — Steve Winterfeld, Advisory CISO, Akamai

Q: How should security leaders address the skills gap around agentic AI protection?

Winterfeld identifies two parallel actions required: investing in targeted training so security staff develop expertise in agentic AI threat models, and deploying the right tools built specifically for those environments. Neither alone is sufficient. Without trained staff, purpose-built tools are misconfigured or underutilized; without the right tools, even skilled teams cannot keep pace with AI-driven attack surfaces.

“I need to do a lot of training to make sure I have the right skills and I need to make the right tools.” — Steve Winterfeld, Advisory CISO, Akamai

Q: How does the security posture differ across banks at different stages of digital transformation?

Winterfeld notes that the financial services sector is not monolithic in its transformation maturity. Some institutions are primarily API-driven, some smaller banks are not yet in heavy transformation, and others are fully committed to AI adoption. The practical implication is that there is no single security priority that applies universally across the sector. Each institution must assess its own transformation trajectory and weight security investment accordingly.

“I have some partners that are really into transforming but it’s still mostly APIs. I have others, the smaller banks, that really aren’t doing a lot of transformation. Then I have some banks that are all in on AI.” — Steve Winterfeld, Advisory CISO, Akamai

Resources & Documentation

  • Akamai, security platform and advisory resources for financial services, API protection, and AI security

***

👇 Click to Read Full Raw Transcript

Swapnil Bhartiya: If you were advising a CISO or security teams based on this report, what should be their top priority right now?

Steve Winterfeld: So I think it is ultimately making sure you’re closely tied in to your business transformation. You know, I’ve got some partners we work with that are really into transforming, but it’s still mostly APIs. I have others, the smaller banks that really aren’t doing a lot of transformation. Then I have some banks that are all in on AI. As you look at where your business is going, that’s where I would focus. Because if they’re headed into APIs or you’re in APIs and continuing to expand, then absolutely that’s where you need to focus. Because as people move fast in transformation, you know, we don’t have mature security guardrails. Our my security staff may not be experts in how to protect against agentic AI. So I need to do a lot of training to make sure I have the right skills and I need to make the right tools. You know, agentic AI needs a different set of tools in large language. APIs need a different set of tools in large language. You know, traditional web pages need a different set of tools and APIs. So, so my advice is closely link up with where transformation is and embed yourself in that translation so that security is moving at the same speed.

Swapnil Bhartiya: Steve, once again, thank you for joining us and for sharing these insights on the latest cyber attack trends shaping the financial services sector. And of course, as usual, I will encourage viewers to go check out this report and also pay attention to what Steve is suggesting here. Thanks for watching and I’ll see you in the next video. Thank you.

Steve Winterfeld: Thanks. Stay vigilant.

How to Unify Database Provisioning Across Multi-Cloud Without Rebuilding Your Platform | Julian Fischer, anynines | TFiR

Previous article