Trending Topics

Peter Gaffney, Chief Information and Security Officer at Sovos: “The role of CISOs has changed significantly over the past decade”
Few cybersecurity leaders can say they have experienced the industry’s evolution across as many sectors as Peter Gaffney. Over the past 20 years, his career has spanned retail, tech and media alike, before arriving at his current position as Chief Information and Security Officer at Sovos. That journey has given Peter a uniquely broad perspective on how cybersecurity has evolved from technical discipline to a business enabler.
One instant takeaway from our interview? That one of the greatest challenges facing cybersecurity leaders today is the acceptance that prevention alone is no longer enough. The sheer “speed and scale of change” means that organisations must instead prepare to contain incidents quickly – and ensure the business can continue operating even when breaches inevitably occur.
While much of this threat comes from the introduction of AI, Peter is quick to point out that its impact cuts both ways.
For threat actors, AI has become powerful as a “force multiplier,” enabling automated phishing campaigns and deepfake technologies to evolve more sophisticated and targeted attacks. Yet the same technologies are proving just as valuable for those defending, allowing security teams to identify suspicious patterns in a fraction of the time it would take to perform manually.
As Peter explains, AI ends up “dramatically shortening the window in which attackers operate,” all the while “making detection and resolution easier for security teams”.
Ultimately, for Peter, resilience is shaped primarily through flexibility rather than rigid defences. The organisations destined for success are those that can continually evolve their security, designing programmes and tools that can serve to scale alongside the business. In doing so, leaders can ensure they protect growth without placing a new barrier in the way.
With Peter’s advice in mind, we wanted to take a look back at Peter’s own journey, to see how his experience has informed his view of modern cybersecurity.
Could you please introduce yourself to our audience and share how you ended up working in cybersecurity?
I’m currently the Chief Information and Security Officer at Sovos, where I lead the company’s global technology and security strategy to drive innovation, resilience and operational excellence. I have more than 20 years of experience across technology, engineering and cybersecurity.
Before joining Sovos, I was the Senior Vice President of Systems and Chief Information Security Officer at Magnit, a global workforce management solutions provider. My role and expertise has taken me through leadership roles across industries including retail, tech and media, including my time at Oracle and Ann Taylor.
So for me, the move into cybersecurity wasn’t a sharp pivot, it was an evolution. And today, I really view it as a business enabler helping organisations build trust, operate securely and create a competitive advantage.
What are the biggest cybersecurity challenges those in leadership roles are facing?
I’d say the biggest challenge right now is just the speed and scale of change, especially driven by AI. What used to take attackers weeks now happens in hours, and the volume and sophistication of attacks has increased dramatically.
Because of that, the mindset has shifted. It’s no longer realistic to think purely in terms of prevention. Leaders have to assume incidents will happen and focus on containment how quickly you can limit impact, reduce the “blast radius,” and keep the business running.
Another major challenge is complexity. Most organisations are dealing with fragmented systems, legacy technology and technical debt, which creates gaps in security coverage and makes consistent governance difficult. At the same time, there’s increasing pressure from customers, regulators and procurement teams. Security has become part of the buying process, and gaps in frameworks or certifications can directly impact revenue and growth.
Finally, the threat landscape itself is evolving: AI, supply chain risks, insider threats… all of these are becoming more prominent and harder to manage in isolation. So when you put it all together, the real challenge for leaders is balancing risk, speed and business enablement -building security programs that are strong enough to protect the organisation, but flexible enough to keep up with how fast the world is changing.
What are some prevention strategies you believe every business should adopt?
The most effective prevention strategy lies in robust processes and the teams that execute them. Organisations often fall into the trap of deploying numerous products that can solve all their security problems, however an abundance of tools can create more operational friction.
True security stems from clear guidance, practical compliance paths and well-defined governance. By pairing these fundamentals with comprehensive employee training, orgs can eliminate the risky workarounds that often lead to exposure across teams.
Overall, accountability frameworks are essential and can’t be the sole responsibility of the CSO or CISO. More and more, we’re seeing security become an enterprise-wide necessity from training to operations, making each department accountable for the risk of their own team. When security teams go back to the fundamentals, they ensure that both their tools and their people are positioned to succeed.
What is it about generative AI that makes it so prone to exploitation by threat actors? Conversely, how can it be used for good in cybersecurity?
What makes AI threatening to organisations is its ability to be a force multiplier, meaning it can enhance the capabilities of human work. Whether it’s used for positive or negative outcomes is up to the user’s discretion.
In many cases, attackers are becoming faster and more efficient by using AI-driven tools, deepfake technology and automated phishing campaigns. The mix of these technologies lowers the barrier of entry to a company’s sensitive information and increases the frequency and scale of attacks an enterprise must combat. With increased international tensions, these tools have also become readily available to outside threats hoping to disrupt global infrastructure or supply chains.
On the other side of the same coin, AI can have the same effect for positive outcomes – dramatically shortening the window in which attackers operate and making detection and resolution easier for security teams. By leveraging AI, companies can identify suspicious patterns across massive datasets that would take a human hours, days or more to sift through.
This has made the role of CIOs more about strategizing how to deploy and implement AI technology effectively, ensuring faster and more efficient protection.
Which cybersecurity best practices are being adopted with the most success by companies?
What we’re seeing work best right now are practices that focus less on trying to prevent everything and more on reducing complexity, limiting impact and scaling securely.
First, identity and access control has become foundational. Organisations that centralise identity and move toward zero-trust things like conditional access and least-privilege models are seeing real success because it shrinks the attack surface and limits how far an issue can spread.
Second is data protection and governance. Tools like CASB and DLP are proving very effective because they protect data closer to the source and give better visibility into how it’s being used, especially important as companies adopt cloud and AI.
Another big one is risk-based vulnerability management. The most mature organisations aren’t just fixing everything: they’re prioritising based on real risk and exploitability, which makes remediation efforts far more impactful. You’re also seeing strong adoption of standardized frameworks and certifications – things like ISO and SOC 2, which help formalise security programs, improve governance, and build trust with customers and regulators.
Finally, there’s a big shift toward containment and “blast radius” thinking. Instead of assuming you can stop every attack, the best programs are designed so that when something does happen, it’s contained, observable and recoverable without impacting the entire business.
So overall, the companies that are succeeding are the ones simplifying their environments, focusing on identity and data, and building security programs that scale with the business rather than slow it down.
What’s something that has drastically changed about cybersecurity since you first got started in the field?
The role of CISOs has changed significantly over the past decade. Security leaders are no longer measured solely on technical controls or infrastructure. They are expected to be business partners who help the organisation move faster, earn customer trust and reduce friction in revenue cycles. This evolution is driven by a market where buyers have become increasingly sophisticated and thoughtful about their partnerships.
Today’s customers expect transparency and visibility into governance, software development practices and risk management frameworks before they commit to a contract. As a result, CISOs now play a vital role in the sales cycle, influencing the sales process by proving an organisation’s reliability.
The most effective leaders recognise that their job is to design safety frameworks that allow teams to adopt innovations with speed and ease. By aligning security posture with business objectives, they ensure that risk is managed effectively without sacrificing the velocity required to compete in an increasingly digital world.
More interviews
- Nick Turner, CEO of Dreamdata: “Resist the temptation to talk in probabilities”
- Dr Deepak Kumar, Founder and CEO, Adaptiva: “Even with partial automation, organizations are leaving too much on the table.”
- Neha Duggal, Chief Product Officer at P0 Security: “Security teams need control at the point where an identity tries to take action”

