August 4, 2026

"You Never Crack the Code": Brendon McCaulley, ConnexPay

Dan Schoenbaum
Chief Marketing Officer
"You Never Crack the Code": Brendon McCaulley, ConnexPay
"You Never Crack the Code": Brendon McCaulley, ConnexPay | HivePro
HivePro Perspective // Customer Conversations

"You Never Crack the Code"

ConnexPay's Chief Security and AI Enablement Officer, Brendon McCaulley on AI, exposure management, and what the next five years ask of security leaders

Customer Spotlight AI Enablement Continuous Exposure Management
Company
ConnexPay
Industry
Travel, Advertising, Insurance & Embedded Finance
HivePro Customer
~1 Year
Recent Commitment
3-Year License
"I never think I've cracked the code of how to protect the business."

Coming from most security leaders, that would sound like hedging. Coming from Brendon McCaulley (Chief Security and AI Enablement Officer at ConnexPay, and one of the most aggressively forward-leaning AI adopters we've met in the CISO community), it's something closer to an operating principle. He has rebuilt how his team works, given AI responsible access to his company's data, and reoriented his security program around a single question he wants to be able to ask out loud: what should I worry about?

That second half of his title (AI Enablement) isn't decorative. It's the job. ConnexPay is a payments technology company serving travel, advertising, insurance, and embedded finance, and McCaulley's mandate runs from securing it to making it faster.

He's also been a Hive Pro customer for close to a year, running continuous threat and exposure management across software, network, and cloud environments. We caught up with him in the Hive Pro suite at the Cosmopolitan during Black Hat 2026, where he sat down with Hive Pro CMO Dan Schoenbaum for a conversation about what changed, what he's building next, and what he'd tell the CISOs who aren't sleeping well.


"All these different solutions didn't talk to each other"

Before Hive Pro, ConnexPay's exposure program looked like a lot of programs do: capable tools that refused to be a system.

"A bit of a mismatch of solutions: Windows Defender and Nessus. The issue we were having was all these different solutions didn't talk to each other and didn't give us a holistic picture of our exposure across our environment."

The breaking point wasn't a breach. It was growth:

"Something had to change, especially as we're scaling our company and building out new environments and new products. The traditional systems we were using just weren't keeping up."

Asked whether he has that single view today, McCaulley is candid: getting there. But he's clear about what "there" looks like.

"What I really want is to have a conversation with our vulnerability footprint: to be able to ask those critical questions, rapidly drill down into what we really need to focus on. What should I be reporting to our executive team and our board?"

Schoenbaum asked what he'd ask an AI first thing in the morning, if he could ask only one thing. His answer was a single question.

"What should I worry about? And actually be able to rely on the promise of AI to know what I mean by that question, and help me and my team focus on the things that matter."

Answering that well means understanding criticality, exploitability, and business context at once: more or less the thesis of continuous threat exposure management.


Risk-on, eyes open

On the perennial debate (is AI a bigger gift to defenders or attackers), McCaulley declines to pick a lane.

"Anybody who gives you a definitive answer one way or the other isn't really thinking about it enough. On a good week I'm really excited about the problems we can solve with AI. And then, yeah, late at night when I wake up in a cold sweat, I worry about the bad actors using AI, or even internal users doing something irresponsible that they didn't intend."

Pressed on the balance, though, he lands firmly:

"There is more risk, for sure. But I feel like the promise and the benefits are more than the increased risk."

He frames unmanaged AI as an existential business threat, not just a security one: upstart competitors eroding moats, irresponsible internal use, adversaries who move faster. The answer, in his view, is the same technology, pointed the other way.


What AI actually changed for his team

This is where the story stops being about strategy and starts being about people.

"It's given us a shot in the arm in terms of insight into our environment: capabilities we frankly didn't have the budget, the time, or the personnel to implement, especially in a company our size. My security administrators and architects have gotten a lot more of an engineering mindset with AI development tools. We're able to extend products like Hive Pro that have rich APIs."

And then the part he clearly enjoys telling:

"They actually thanked me for being such an AI champion, because it's fundamentally transformed the way they work. I've got guys on my team who have been in IT for 35 years and they're like, I can't believe I'm building security applications. Their job looks fundamentally different than it did six months ago."

His advice to peers still holding AI at arm's length is about access, paired with discipline:

"You can give AI responsible access to a lot of your company's information, and build in layered guardrails and deterministic behavior so it won't go rogue on you. If you give AI access to more and more of your data, it will help you more and more. That context makes it a trusted advisor."

"You know you're a CISO when…"

"You know you're a CISO when you have to think about more than does an individual security control make us more secure. Typically, an individual control doesn't make you more secure. The layering and building of a security program makes you more secure: a program that scales with the complexity of the business."

That dovetails with the worst advice he says he's ever received: security by obscurity, and the single-control test.

"You can pick apart any security control and say, debatably this doesn't make us more secure. And so now you have a hundred things you're not doing. My job is to manage the risk of the organization and reduce the likelihood of a breach."

Three things he'd point to in Hive Pro

Asked for three ways Hive Pro has helped ConnexPay, McCaulley didn't hesitate.

1. Breach and attack simulation
"One of the features that really sold me on Hive Pro is the breach and attack simulation, where I can actually run payloads that look like real attacks and test my security controls and the efficacy of those controls. That's a killer feature."
2. Attack chaining and real-world applicability
"The chaining and applicability of vulnerabilities to our environment: helping us quantify our systems by criticality, the number of vulnerabilities they have, and getting a matrix of what should I really care about."
3. The API
"Last but not least, especially in the age of AI, is the rich API that Hive Pro has. We've been able to extend Hive Pro and integrate it into a lot of our bespoke security systems."

A three-year bet from a CISO who doesn't make them

Perhaps the clearest signal of where McCaulley has landed isn't a quote at all, it's a signature. He is, by his own practice, a CISO who doesn't sign multi-year licenses. Security tooling moves too fast, and locking in ahead of the market is exactly the kind of "cracked the code" thinking he warns against.

He recently signed a three-year license with Hive Pro anyway, on the strength of what the platform demonstrated during ConnexPay's proof of concept.


What he wants next

His ambition for the platform is bi-directional. Today Hive Pro feeds his AI systems; he wants his AI feeding Hive Pro: conversational prioritization, and eventually guardrailed remediation automation that verifies both that the vulnerability is closed and that nothing in production broke.


The five-year question

Near the end, McCaulley offered the question he thinks every security leader should be asked: where do you see your role going in the next five years?

"I see a lot of people that say, I've cracked the code of how I should protect the business. That's a really dangerous thing to say. The only cracking of the code is continuous improvement and continuous diligence."

And that, he argues, is the optimistic reading, not a treadmill, but a mandate.

"The great opportunity is the enablement of the business to grow and mature and get safer, all empowered by AI. If you think of security as an enabler (a feature you're providing your customers, that you're safeguarding their data), the pie doesn't have to be fixed."

To the CISOs who aren't sleeping well

We closed by asking what he'd say to peers drowning in vulnerabilities.

"It's incredibly easy to set up, even in complicated environments. It's wide-reaching: we can talk to a ton of different facets of your footprint, from software composition analysis and code security to network security and cloud security posture management. All of that gives you a single pane of glass to see your vulnerability and threat exposure across those footprints."
"And it's got a really extensive API. So I look at Hive Pro with AI-based access to its API as a hell of a combination. I would highly recommend CISOs look into this."
Want the same single view of your exposure?

See Hive Pro in action and find out what continuous threat and exposure management looks like for your environment.

See Hive Pro in Action

Brendon McCaulley is Chief Security and AI Enablement Officer at ConnexPay. This interview was conducted by Dan Schoenbaum, CMO of Hive Pro, and has been edited for length and clarity.

Recent Resources

Dive into our library of resources for expert insights, guides, and in-depth analysis on maximizing Uni5 Xposure’s capabilities
Azure security posture management and CTEM dashboard

Azure Security Posture Management: Complete CTEM Guide

Request a Hive Pro demo to strengthen Azure security posture management with CTEM, threat intelligence, validation, and unified cloud exposure insights.
Read More
Security team analyzing dark web threat intelligence

Dark Web Threat Intelligence for Exposure Management

Request a demo to see how dark web threat intelligence helps prioritize urgent exposures, track active exploits, and guide faster remediation.
Read More
Security team reviewing connected attack paths across multiple cloud environments

Multi-Cloud Exposure Management: Practical Guide

Schedule a Hive Pro demo. See how multi-cloud exposure management helps prioritize active threats and validate the attack paths that matter most.
Read More
Continuous AWS security vulnerability management network visualization

AWS Security Vulnerability Management: Best Practices Guide

Schedule a free consultation. Master AWS security vulnerability management. Use our comprehensive guide to native scanning, CTEM, and exposure reduction.
Read More
Multi-cloud exposure paths across connected cloud environments

Multi-Cloud Exposure Management: A Practical Guide

Request a demo to see how multi-cloud exposure management unifies risk, validates attack paths, and helps teams fix the exposures that matter most.
Read More
Visualization of exposure management across multiple clouds

Multi-Cloud Exposure Management: A Practical Guide

Request a demo to see how multi-cloud exposure management reveals attack paths, prioritizes exploitable risk, and validates defenses.
Read More

What’s new on Hive Pro?

Get through updates and upcoming events, and more directly in your inbox

Reduce real exposure. Not just vulnerability volume.