Podcast Highlights Recovery Leadership Amid Cyber Breach

In a recent episode of the InformationWeek Podcast, senior technology leaders discussed how chief information officers and chief technology officers respond when a cybersecurity breach occurs, especially as threats evolve with artificial intelligence and emerging quantum capabilities.
Panelists share practical guidance on breach detection and response
Zach Lewis, CIO of the University of Health Sciences and Pharmacy in St. Louis, joined the discussion at Black Hat 2026 alongside Brian Alvey, CTO of WordPress VIP. The conversation focused on early signs that indicate a problem, the distinction between a near‑miss and a full breach, and how response tactics differ based on the intrusion type.
Lewis noted that “early indicators often look like unusual network traffic or unexpected login attempts,” emphasizing the need for continuous monitoring. Alvey added that “a near‑miss might involve a suspicious file that never executes, while an actual breach typically shows data exfiltration or persistent access.” Both agreed that the speed of detection directly influences the effectiveness of containment measures.
When it comes to communication, the panelists debated whether to disclose every incident publicly. “Transparency is valuable, but you have to weigh the risk of exposing details that could help attackers,” Lewis said. Alvey echoed that sentiment, suggesting a tiered approach: internal briefings for staff, limited external statements for regulators, and broader disclosures only when required.
Automation and AI also play a growing role. The discussion highlighted Anthropic’s Mythos as an example of a tool that can sift through logs faster than human analysts. “AI can surface anomalies that would otherwise be buried in noise,” Alvey explained, noting that automation speeds up root‑cause analysis and helps prioritize remediation steps.
Who leads recovery and how organizations reshape their defenses
After a breach, responsibility for rebuilding and hardening systems often shifts to a designated recovery team. Lewis described how his university assembles a cross‑functional group that includes security engineers, legal counsel, and communications staff to draft a post‑incident plan.
Related: CTOs discuss controlling AI spending
The podcast featured a “Questionable Ideas” tabletop exercise, where participants acted as interim executives at a fictional firm plagued by mischievous goblins and gremlins. The scenario, though whimsical, highlighted the importance of clear decision‑making structures during a crisis.
From a broader perspective, the rise of AI‑driven attacks forces organizations to rethink traditional security models. As AI tools become more accessible, both attackers and defenders can automate complex tactics, making the threat environment more fluid.
Recovery plans now incorporate regular drills that simulate both near‑misses and full breaches. Lewis said his team runs quarterly exercises to test response times and communication protocols. Alvey added that “continuous improvement is essential; we revise policies after every incident, whether it’s a minor anomaly or a major compromise.”
When the dust settles, the final step often involves updating policies, patching vulnerabilities, and training staff on new procedures. The panelists stressed that these actions should be documented in a post‑action report, which serves as both a record and a roadmap for future defenses.
Listeners were invited to share their own experiences with breach response by emailing the podcast team. The episode aims to provide a practical framework for technology executives handling the ever‑changing security environment.
