James Tucker, Head of CISOs in Residence at Zscaler: “Ethical hacking is an absolute must in this industry”

With a cybersecurity career spanning 17 years, James Tucker is worth listening to. As is his CV: he’s held key positions at Sourcefire, Palo Alto Networks and Baffin Bay Networks, and now serves as Head of CISOs in Residence at Zscaler. All that experience comes to bear in this rapid-fire interview, where he covers the latest security challenges, the role of ethical hackers and why we shouldn’t blame end users for security mistakes.

“If you blame the user, you learn nothing,” he explains. “Itโ€™s only by owning the gap that you get closer to fixing it.” And in this era dominated by Mythos and other emerging AI threats (which James also covers), he points out that the winners are the ones who are focusing on the “boring” things such as process.

“Itโ€™s also vital to address legacy systems because theyโ€™ll become major risks in an AI-driven world,” he explains. “Beyond that, you need to test in the same manner that you operate and adopt full-scale red teaming to find weaknesses early.”

Before we move into the full interview, it’s worth doubling down on James Tucker’s experience and why we think it’s worth five minutes of your time to listen to him. Prior to joining Zscaler in 2019, he was Director of System Engineering at Baffin Bay Networks and a senior Security Engineer elsewhere – in short, he’s been at the coalface and has earned his stripes.

James now oversees both EMEA and APJ regions for Zscaler, advising customers on how to achieve meaningful security outcomes. And sharing his wisdom on the latest challenges, as he explains below:

What are the biggest cybersecurity challenges those in leadership roles are facing?

The number one challenge cybersecurity leaders face today is finding people with the right skills to keep pace with AI-driven change. Every organisation wants to move quickly on AI, but many are struggling with legacy infrastructure, talent shortages, and a lack of readiness for what these technologies mean in practice. Weโ€™re already seeing successful AI pilots fail to scale because the existing foundations canโ€™t support them securely. 

At the same time, AI is accelerating the threat landscape, increasing the speed of vulnerabilities, patching and exploitation. Letโ€™s take Mythos for instance. Over the next six to 12 months Mythos and Mythos-adjacent capabilities will surface vulnerabilities faster than anyone can patch them, and most large organisations arenโ€™t going to keep up., and most large organisations arenโ€™t going to be able to patch fast enough.

The challenge for leaders is balancing innovation with security, while modernising infrastructure fast enough to support the future safely and effectively.

What is your take on ethical hackers and their role in cybersecurity?

Ethical hacking is an absolute must in this industry. I think everybody should have someone on their team who thinks outside the box, who is willing to argue and challenge the status quo. However, sometimes the interpretation of the ethics can be a bit loose. So, while I love the concept and I think itโ€™s needed, I do think there needs to be a bit more ethics in ethical hacking. 

In the AI era, itโ€™s important that ethical hackers are equipped with the tools to do their job properly. Every vulnerability is going to be found, and youโ€™d rather it was an ethical hacker that finds it.

What are some prevention strategies you believe every business should adopt?

Too often, we see businesses ignoring known risks because those systems or processes are tied to revenue and operational convenience. This is often where the problem starts. To tackle this, first you must reduce your attack surface and properly implement zero trust, not just in the cloud but on-prem as well. 

Itโ€™s also vital to address legacy systems because theyโ€™ll become major risks in an AI-driven world. Beyond that, you need to test in the same manner that you operate and adopt full-scale red teaming to find weaknesses early. Doing this properly should speed the business up, rather than slow it down.

What is it about generative AI that makes it so prone to exploitation by threat actors? Conversely, how can it be used for good (in cybersecurity)?

Generative AI is so prone to exploitation because it is fundamentally designed to consume vast amounts of data and respond in ways that please the user, making it susceptible to manipulation. An attacker can exploit this through techniques like prompt manipulation, effectively tricking systems into bypassing safeguards. 

At the same time, AI can be a major force for good in cybersecurity. It can ingest and analyse huge volumes of security data far beyond human capability, helping to identify risks, prioritise threats, and surface actionable insights. Ultimately, AI enables faster, more intelligent detection and response, piecing together fragmented signals into a clearer picture of risk.

Which cybersecurity best practices are being adopted with the most success by companies?

The practices winning right now are the boring, unglamorous, disciplined ones that are applied consistently rather than selectively, such as least privilege, strong policy enforcement, and a culture that stops treating users as the problem. The organisations getting this right have moved accountability into the security function itself. This means that when something slips through, the question becomes โ€œwhich control failed?โ€ not โ€œwhich employee clicked the link?โ€ If you blame the user, you learn nothing. Itโ€™s only by owning the gap that you get closer to fixing it. 

The other measure of maturity is alignment. The best teams I have seen build security into how the business operates rather than bolting it on at the end. Doing this means that it becomes part of how the company runs, instead of a checkpoint everyone shares workarounds for.

Whatโ€™s something that has drastically changed about cybersecurity since you first got started in the field?

When I started in cybersecurity, attacks were the domain of highly skilled, often state-sponsored actors. Today, the biggest shift is how dramatically that barrier has fallen. Now, with access to AI tools, almost anyone can launch targeted attacks at scale. This has created a real asymmetry, as attackers can move faster, automate more, and operate with far less expertise. As defenders, weโ€™re facing a completely different challenge, where speed, scale, and accessibility are all working in the attackerโ€™s favour.

Also from our Interviews section

Rowan Campbell TechFinitive
Rowan Campbell

Rowan is a writer for TechFinitive focusing on technology companies doing interesting things all around the globe. He is currently studying philosophy at university.