"You Never Crack the Code"
ConnexPay's Chief Security and AI Enablement Officer, Brendon McCaulley on AI, exposure management, and what the next five years ask of security leaders
"I never think I've cracked the code of how to protect the business."
Coming from most security leaders, that would sound like hedging. Coming from Brendon McCaulley (Chief Security and AI Enablement Officer at ConnexPay, and one of the most aggressively forward-leaning AI adopters we've met in the CISO community), it's something closer to an operating principle. He has rebuilt how his team works, given AI responsible access to his company's data, and reoriented his security program around a single question he wants to be able to ask out loud: what should I worry about?
That second half of his title (AI Enablement) isn't decorative. It's the job. ConnexPay is a payments technology company serving travel, advertising, insurance, and embedded finance, and McCaulley's mandate runs from securing it to making it faster.
He's also been a Hive Pro customer for close to a year, running continuous threat and exposure management across software, network, and cloud environments. We caught up with him in the Hive Pro suite at the Cosmopolitan during Black Hat 2026, where he sat down with Hive Pro CMO Dan Schoenbaum for a conversation about what changed, what he's building next, and what he'd tell the CISOs who aren't sleeping well.
"All these different solutions didn't talk to each other"
Before Hive Pro, ConnexPay's exposure program looked like a lot of programs do: capable tools that refused to be a system.
"A bit of a mismatch of solutions: Windows Defender and Nessus. The issue we were having was all these different solutions didn't talk to each other and didn't give us a holistic picture of our exposure across our environment."
The breaking point wasn't a breach. It was growth:
"Something had to change, especially as we're scaling our company and building out new environments and new products. The traditional systems we were using just weren't keeping up."
Asked whether he has that single view today, McCaulley is candid: getting there. But he's clear about what "there" looks like.
"What I really want is to have a conversation with our vulnerability footprint: to be able to ask those critical questions, rapidly drill down into what we really need to focus on. What should I be reporting to our executive team and our board?"
Schoenbaum asked what he'd ask an AI first thing in the morning, if he could ask only one thing. His answer was a single question.
"What should I worry about? And actually be able to rely on the promise of AI to know what I mean by that question, and help me and my team focus on the things that matter."
Answering that well means understanding criticality, exploitability, and business context at once: more or less the thesis of continuous threat exposure management.
Risk-on, eyes open
On the perennial debate (is AI a bigger gift to defenders or attackers), McCaulley declines to pick a lane.
"Anybody who gives you a definitive answer one way or the other isn't really thinking about it enough. On a good week I'm really excited about the problems we can solve with AI. And then, yeah, late at night when I wake up in a cold sweat, I worry about the bad actors using AI, or even internal users doing something irresponsible that they didn't intend."
Pressed on the balance, though, he lands firmly:
"There is more risk, for sure. But I feel like the promise and the benefits are more than the increased risk."
He frames unmanaged AI as an existential business threat, not just a security one: upstart competitors eroding moats, irresponsible internal use, adversaries who move faster. The answer, in his view, is the same technology, pointed the other way.
What AI actually changed for his team
This is where the story stops being about strategy and starts being about people.
"It's given us a shot in the arm in terms of insight into our environment: capabilities we frankly didn't have the budget, the time, or the personnel to implement, especially in a company our size. My security administrators and architects have gotten a lot more of an engineering mindset with AI development tools. We're able to extend products like Hive Pro that have rich APIs."
And then the part he clearly enjoys telling:
"They actually thanked me for being such an AI champion, because it's fundamentally transformed the way they work. I've got guys on my team who have been in IT for 35 years and they're like, I can't believe I'm building security applications. Their job looks fundamentally different than it did six months ago."
His advice to peers still holding AI at arm's length is about access, paired with discipline:
"You can give AI responsible access to a lot of your company's information, and build in layered guardrails and deterministic behavior so it won't go rogue on you. If you give AI access to more and more of your data, it will help you more and more. That context makes it a trusted advisor."
"You know you're a CISO when…"
"You know you're a CISO when you have to think about more than does an individual security control make us more secure. Typically, an individual control doesn't make you more secure. The layering and building of a security program makes you more secure: a program that scales with the complexity of the business."
That dovetails with the worst advice he says he's ever received: security by obscurity, and the single-control test.
"You can pick apart any security control and say, debatably this doesn't make us more secure. And so now you have a hundred things you're not doing. My job is to manage the risk of the organization and reduce the likelihood of a breach."
Three things he'd point to in Hive Pro
Asked for three ways Hive Pro has helped ConnexPay, McCaulley didn't hesitate.
"One of the features that really sold me on Hive Pro is the breach and attack simulation, where I can actually run payloads that look like real attacks and test my security controls and the efficacy of those controls. That's a killer feature."
"The chaining and applicability of vulnerabilities to our environment: helping us quantify our systems by criticality, the number of vulnerabilities they have, and getting a matrix of what should I really care about."
"Last but not least, especially in the age of AI, is the rich API that Hive Pro has. We've been able to extend Hive Pro and integrate it into a lot of our bespoke security systems."
A three-year bet from a CISO who doesn't make them
Perhaps the clearest signal of where McCaulley has landed isn't a quote at all, it's a signature. He is, by his own practice, a CISO who doesn't sign multi-year licenses. Security tooling moves too fast, and locking in ahead of the market is exactly the kind of "cracked the code" thinking he warns against.
He recently signed a three-year license with Hive Pro anyway, on the strength of what the platform demonstrated during ConnexPay's proof of concept.
What he wants next
His ambition for the platform is bi-directional. Today Hive Pro feeds his AI systems; he wants his AI feeding Hive Pro: conversational prioritization, and eventually guardrailed remediation automation that verifies both that the vulnerability is closed and that nothing in production broke.
The five-year question
Near the end, McCaulley offered the question he thinks every security leader should be asked: where do you see your role going in the next five years?
"I see a lot of people that say, I've cracked the code of how I should protect the business. That's a really dangerous thing to say. The only cracking of the code is continuous improvement and continuous diligence."
And that, he argues, is the optimistic reading, not a treadmill, but a mandate.
"The great opportunity is the enablement of the business to grow and mature and get safer, all empowered by AI. If you think of security as an enabler (a feature you're providing your customers, that you're safeguarding their data), the pie doesn't have to be fixed."
To the CISOs who aren't sleeping well
We closed by asking what he'd say to peers drowning in vulnerabilities.
"It's incredibly easy to set up, even in complicated environments. It's wide-reaching: we can talk to a ton of different facets of your footprint, from software composition analysis and code security to network security and cloud security posture management. All of that gives you a single pane of glass to see your vulnerability and threat exposure across those footprints."
"And it's got a really extensive API. So I look at Hive Pro with AI-based access to its API as a hell of a combination. I would highly recommend CISOs look into this."
See Hive Pro in action and find out what continuous threat and exposure management looks like for your environment.
See Hive Pro in ActionBrendon McCaulley is Chief Security and AI Enablement Officer at ConnexPay. This interview was conducted by Dan Schoenbaum, CMO of Hive Pro, and has been edited for length and clarity.

.jpg)



