Critical Infrastructure Security, Government security

Industry CISOs urge resilience, AI governance and regulatory reform

ICIT CISO panel

Industry chief information security officers (CISOs) called for greater cyber resilience, stronger public-private collaboration and more consistent regulations during a panel discussion at a June 10, 2026, Institute for Critical Infrastructure Technology (ICIT) event in Washington.

The panel, moderated by CyberRisk Alliance's Parham Eftekhari, brought together security leaders from manufacturing, financial services and food production to discuss the biggest risks facing enterprise organizations and what policymakers can do to help.

Several panelists said artificial intelligence is reshaping the threat landscape. Frank DePala, global CISO at Enpro, said organizations are rapidly deploying AI while security governance and vendor capabilities remain immature. Combined with nation-state activity targeting critical infrastructure and supply chains, he said AI is accelerating the speed and scale of attacks.

Supply chain resilience emerged as another common concern. Mike Rogers, CISO at Hormel Foods, pointed to the risks posed by disruptions affecting suppliers and logistics providers, while other panelists said organizations increasingly depend on thousands of third-party vendors whose cybersecurity maturity varies widely.

Rather than focusing solely on prevention, Frank McGovern, CISO at StoneX, said organizations must prioritize resilience and ensure critical services remain operational during an attack. He also highlighted identity management and employee burnout as growing operational challenges.

The CISOs also criticized today's regulatory environment, saying overlapping global cybersecurity requirements consume resources without necessarily improving security. McGovern called for greater consistency in regulations and a single federal reporting channel for cyber incidents, arguing that multiple agencies often request the same information during a crisis.

On workforce development, panelists urged greater investment in cybersecurity education beginning at the K-12 level, along with expanded internship and apprenticeship programs to help graduates gain practical experience. They also said remote work can expand access to cybersecurity talent in rural communities.

Asked what policymakers should prioritize, the panel called for better sharing of government threat intelligence with the private sector, regulatory harmonization, stable long-term cybersecurity programs, and continued investment in workforce development and operational resilience.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds