41 minOct 8, 2026

Measuring Risk and Business Impact: A CISO's Approach to Decreasing MTTR

Kris Burkhardt, CISO at Accenture, and Rob Cross at Synack on how enterprise security leaders measure cyber risk, reduce MTTR, and connect security outcomes to business impact through continuous security validation.

Kris Burkhardt Global CISO, Accenture
Rob Cross Global Head of Strategic Programs, Synack

Overview

Kris Burkhardt, CISO at Accenture, and Rob Cross at Synack on how enterprise security leaders measure cyber risk, reduce MTTR, and connect security outcomes to business impact through continuous security validation.

What you'll learn

MTTR is a business metric

CISOs need to show how faster discovery, validation, and remediation reduce exposure and improve business resilience.

Validated risk drives prioritization

Security teams need to move beyond vulnerability volume and focus on exploitable findings that create real business risk.

AI requires continuous validation

As AI accelerates innovation and attacker behavior, enterprises need faster testing, better context, and continuous validation.

Chapters

Jump straight to the part you need.

Full transcript

Read transcript

Good day. My name is Rob Cross. I'm the global head of strategic programs for SYNNEC. And with me as a guest is the global chief information security officer for Accenture, Chris Burkhart. Chris, welcome. Hey. Thanks, Rob. Great to be here and looking forward to the conversation. Absolutely. Great to see you again. So just for the listeners, would love for you to introduce yourself and give us a broad overview of your journey just in the tech industry and how you came to the rise of being the global CISO for one of the

largest, if not the largest, management consulting company on the planet, Accenture. Sure. Happy to do that. Well, let's see. Let let's let's start simply with where I am. So I'm I'm Accenture's global CISO. I've been in this role now for five years, and I spent the ten years before that helping to build the organization. My career journey is it's kind of simple and complicated at the same time. Right out of school, I joined joined Accenture,

actually Anderson Consulting way back when. Wow, yeah. And in Anderson Consulting and Accenture, I've done a number of different roles. My first ten years, I did a lot of client facing roles, mostly not mostly, entirely technology driven. So a lot of technology architecture, things that we would probably just use frameworks for today. We actually have developed, you know, developed ourselves back then.

So I did some of that. I spent a number of years abroad both in Tokyo and in Manila. I spent another five years with our our internal IT group. We called it CIO at the time, but, you know, helping move us from Lotus Notes to Microsoft deck. I don't think you remember what was yourself there. We won't say it, but I love those notes. Bob, I started when I was ten, so that's what saying.

So so, you know, that that that was kind of the technical portion. The second half of my career, we realized that we needed more formal rigorous approach to information security. We had, I'll call it, pockets of well intentioned people and goodness, but we wanted to bring that together. So I helped to do that and then helped build the organization out. And, you know, now I you know, today, I run it. So that's my that's my career journey in brief.

I I was a technologist first. Many other CSOs, I say, generally start from either either technology, compliance, or some sort of law enforcement background. Right? And so, you know, I'm I'm a I'm a technology one. If you're not familiar with it, we're a global solutions and services company. We help companies reinvent by building their digital core, help them unleash AI, and our strategy really is to

be the reinvention partner of choice for our clients and also be a great place to work. So interesting in just my travels and working with yourself and some of your peers some and a lot of your peers, how so many people come from an educational background of, like, poly sci and history. Because back in the day, there was no, like, information security degrees, but it's interesting to see the educational background for sure, but you rooted in technology. Yeah. For for me, French LID and econ. So it's incredible.

Brothers and sisters out there, like, you know, critical thinking skills still count. That's great. That's awesome. So you gave a brief overview of yourself. Thank you. And then a little bit snippet on on Accenture, which was part of my next question. But, you know, what are the key priorities of the business currently, and how is your specifically from a security perspective, enabling those goals? Yeah. So, you know, right now, I I'd say, look,

everybody is talking about AI. And I think if I could just ask the world to step back, you know, maybe a couple of years, I think there's been a lot of effort really trying to implement a lot of the the the zero trust principles. And to me, what that really means is you've got to have good identity, you know, strong identity because we're we're not just on prem anymore. You're in the cloud, so the your identity really becomes

your first line of defense. You've got to have strong endpoint protection, good good software to ensure that the various devices you use aren't compromised. And then, of course, you know, you have to have a, you know, a strong transport layer between those things, which really happens a lot by default today. We're really kind of blessed in the sense that most implementations of HTTP are, you know, modern, they're secure.

You know, we all have TLS now, right? Like, so there's there's a lot of strength there. And then along with that along with that is, you know, you gotta have your data organized. You gotta have a good what what we often call a digital core. So those, maybe that technical debt that many companies used to have or still have where their data is in disparate systems, it's pretty hard to get together and and organize. Like it's important to get through that and resolve that so you can really unleash the power,

which brings us to where we are today. Today, right, I can't believe we've gone five minutes and haven't yet mentioned AI, but you know, here we go, right? And that is the big deal right now, and a good solid security, I'll say secure, you know, bedrock really does enable the business because then the business can be confident that the security is going to be there for them, and that, you know, they know identity is strong, they know, you know,

perhaps their cloud posture is strong, and they can really focus on solving business problems, and today they're solving business problems with AI. So if you don't have, you don't really have that strong security foundation, you can't launch, right? And like you need that, you need that, you need your data organized, You know, you need a few other things, right, to make to make that work or I'll I'll say from a technological architecture. But, like, those foundational points are critical because AI

is just gonna struggle, and you're not gonna get the benefit of it if you don't have those things in order. So, I mean, I read your earnings report at the end of the year, and a massive part of your growth was in AI consulting and just getting that into the client environment. You come from those roots. I think there's a lot of people out there deploying AI quickly, and to do something fast and secure is really, really hard. You are the global CISO, so I've always thought of you as really being the the corporate side.

But are you also saying in what you just went through that you also consult with the client facing side? So when your consultants are out there in your client environment strategizing and deploying AI on in their instance that you've helped your organizations help design the security around that deployment that you you have your tranche of your your tentacles in that too in the delivery side. Are you still connected there? Yeah. Look. I'll I'll I'll say it this way. Organizations that that that we, you know,

that are our clients, they tend to be pretty massive, right? Yeah. And consequently, a lot of the stuff that we do is based on patterns, still bespoke at the end of the day, right? It just has to be to match you know the different types of businesses our clients are in. So a lot of I do, as you say, am accountable for all of our own corporate security, but I'm also accountable for ensuring that our

engagements are run-in a secure manner, and I spend about half of my time speaking with clients about our experiences with AI or security tools, or you know, other things, really just as a peer. It's not a it's important that we are practicing what we preach, so to speak. So, you know, often I'm customer zero for, you know, for our security practice and for implementing new patterns or new technologies.

AI is no different. You know, we're out there really trying to push the push the edge on our own use of GenAI and our own use of AgenTic AI. And it's, you know, it's it's actually a lot of fun to speak with clients about what we're doing and hear what they're doing. Right? We're we're not the only innovators out there. And really, the the kind of the the progress you can make by sharing some notes like that is is amazing, and it's a lot of fun, frankly.

Yeah. You it's fun learning from your customers as I've learned from working with your organization over the years for sure. When we talk about obviously, our company is in the pen testing as a service space. We bring a platform approach, and you've been our client for quite a number of years. Pen testing can be over commoditized, a repetitive exercise for just compliance where a little is learned and improved over time. It's kinda you come in, you do a light test. It's great. And then it lives in a spreadsheet and, you know, MTTR, I mean, time to remain teams start to grow.

How have you used SYNNEC and its capabilities and its platform approach to not just find vulnerabilities, but meaningfully use the data from it to improve your security posture either overall in your corporate environment or if have we in at all impacted the client delivery side? If you could just talk to to those, that would be great. Let me start with a classic pen test. I think there was was a time, and maybe some people are still living in this time, that a penetration test was

a compliance kind of requirement. And you had to do one once a year, and you had to check the box. And I think it was part of maybe an ISO certification or SOC one, SOC two certification. Regardless, your customers wanted to know that you did it. And I think, well, that served a purpose a long time ago. It really doesn't harness the power of what pen testing can really do.

You know, for us, right? So we have a, we have an entire tech surface management team, right, that looks at how we're vulnerable from, you know, from from the outside looking in, whether that's through, you know, vulnerabilities or configurations or I'll say, know, poorly configured software. There's all sorts of vectors that pen testers can use. And so for us, you know, pen testing and I'll talk about SYNNAC here a little bit, right?

It's a it's a learning experience for us, right? Every finding we get is a chance to understand, like, did that come about? How do we prevent it? How do we test for it ourselves, Right? So that, know, we can use your time and our time more effectively because that is that is the short commodity here. And it is, you know, it's it's really it's really a circle, right?

You know, flywheel where we learn from mistakes that we made and then we go back, we under you know, we understand where they were introduced in the process, and we look to prevent them, and we also look for testing to find them again. And by testing, what I really mean is think more in terms of scanning, right? So testing that we can automate and run, you know, every day against our addressable IP space, right?

So that's how we look at it. I think about our experience, Rob, together, right? When we first started looking at it, you had a perspective education and that perspective was correct, but I think you know in your mind we were thinking about it more as an education for individuals, and we really need to think about it more as an education for the organization, like how do we make the organization as an organism kind of smarter and the way that we did that was to do

that analysis and prevent the stuff and then, you know, scan for over time. And we actually, and I'll stop blathering on here in just a moment, one of the biggest things that you guys were able to find for us is, you know, there are in the complexity of the, like, many, many web apps we have, you know, buried deep within them are the occasional the occasional unauthenticated object, like, that should be behind authentication. You were able to find those and that really opened our eyes to

a different issue. We actually built an entire scanning tool to go find all those, you know, on our attack surface. So, know, now I think when you guys look for those, it's pretty rare that you that you find one and it's especially rare when you find one that we didn't already know about. So it's, you know, it's like that's just one one use case that you know, you helped us learn and helped us prevent future problems. I think used correctly pen testing is a super powerful

tool used incorrectly. It's just a waste of your money. I think a lot of folks look in the beginning of what you're talking about. Pen testing is really just a compliance destination, and the journey ends there. And for the audience, Chris and I have been having this conversation for five, six years that really the journey of transformation starts at testing because and what Accenture, I think, done really beautifully, if I can say that, is you've looked at the what we find and you've gone back and

understood the why. And the why is really interesting, which I skipped over a little bit, and most people don't know this, but you have a very transient workforce that is different than any one of my clients. And when Chris and I started having this discussion, he kinda said, listen. I can't control left of me. There we have a very transient workforce. So going from what we find to ideating on how to what's the why and the root cause and how do we build mitigating measures your own technology to engineer that out. So when we test, we find nothing as a trust but verify versus a real technical

backstop of a catch all, I think was really just amazing. That is the way testing should be used, is learning and root cause and mitigating your engineering process that's causing failures before it gets to testing. Testing should be driving to zero, and you guys have done that in one particular category for sure. So Yeah. I I I completely agree, and I'll I'll I'll argue a little bit. I I wouldn't I wouldn't argue I wouldn't say that we have a particularly transient workforce. Just we have a big workforce. Yeah. Okay. Sure. So Thank you.

So when you so when you think about us, right, just to put it in numbers, right, we we employ about eight hundred thousand people globally. Yeah. If we turn over just ten percent, it's eighty thousand people. Yeah. So it's, you know, it it makes it makes for it makes it makes a situation where you can't you can't train your way out of a problem. Like, it's like people behavior and people training just one part of the solution, but you really have to have other controls in place to to to get those guardrails up.

Sorry. Not to be argumentative. Just No. No. No. You're no. I appreciate you qualifying that because to me, it's like a ten percent is like, oh, that's not they're probably in HR standards. That's probably small, but scale of your company Yeah. When it hit my ears, I was like, eighty thousand people. Like, oh my numbers. Yeah. That's like exactly. It's like a fortune whatever company, and and it goes in and goes out. But to your scale, it's like, yeah, it's only ten percent. Totally. I thank you for qualifying that. Five of the hometowns that I grew up in. That's true.

Okay. Accenture, you guys have publicly committed to train over half a million people on GenAI, which is, I think, is really on GenAI fundamentals, which is a massive commitment. How is your team currently using AI? And, also, if I can ask, have you seen an increase in volumes as AI becomes more prominent in your adoption internally? Like, I'm hearing, like, hey, Claude code, and I let me call that tool out particular, but vibe coding, like, you can code faster, but it doesn't necessarily mean it's more secure.

And I'm just curious on both end ends of that, what your perspective is. Well, a a couple of thoughts. So, you know, we've been at this journey for a little while now. I think I think we had as a company, I think our bookings for q one this year were our our AI bookings were, you know, over north of two billion. So, you know, that's out of I I'm not gonna get the number exactly right, but it's out of, you know, roughly billion in bookings. So, you know, over ten percent, right, which I think is good.

And we we've already deployed over over three thousand agents. Right? So we're so we've been doing this for a little while. I think not that anybody's doing doing it for a long while, but, you know, we're we've got our we've got our our feet underneath us on this. So, you know, a couple of thoughts that that I'll say, you know, how are we using it? So my organization, we like many many information security groups out there,

you know, we're really reliant on the vendors to kind of get get useful AI out there into their products, and that's starting to happen. And we're we're and that that's like really the scaling that we need. But but for a lot of other activities like like that, we're, you know, we're not scanning our entire IPs our IP space and all those things for other more pointed activities, and I'll say, like, three,

level four type activities. We're do we're using a a couple of things. Like many other people, we're using AI for enrichment of incidents. So so as we see them, we're using AI to look for use cases that traditional SOAR, you know, SOAR automation components, rule based SOAR won't necessarily pick up, but AI might. So we're starting to look at that. We've we've used AI to help automate our

web application testing. Right? That is that's a space that has traditionally taken some expertise to do to understand how to, you know, go down all the branches of a web app and really look for all the things that you need to look for. We have a a an agentic approach now. It's actually kind of a master organizer agent that uses six other agents to go through and do testing against against an application. You know, I won't I won't say it's quite comprehensive yet,

but it's very good if you're just an individual developer and you want to like knock out most the problems and make it easier for your final QA, right? So we're doing a number of things like that, we're also using a lot of Gen AI, we need to make sure that in the contracts that we have with clients that both parties have thought about security properly and we have the right clauses in there to ensure that, you know, is covered either by us or our client and governed properly.

And so, Gen AI is very good at picking out those clauses no matter the specific language that was used. You know, we're seeing a number of places. How are we securing it? So that's a harder question. Over the last couple years, you know, we have rolled out this whole responsible AI program. It looks at a number it looks at AI from a number of different angles. You know, ethics, for example, looks for bias,

and security is also one of those angles. So we ensure that we ensure that the applications that use those and the data that feeds into them and sort of the you know, the prompts and the outbound messaging, you know, back like in the GenAI, like when we were mostly talking about GenAI, actually all that is safe and secure. AgenTic, I'd say we're a little less mature in the sense that the technology is moving so fast with the and

with you know, some of the now some of the coding tools that really help you just rip out agents like nobody's business. And so we're we have a few tools that we're working on. We have a registry that we've rolled out. And so I'd say we're I'd say we're as mature as anyone in that space right now, but the whole market needs to mature in that space like there's work to be done there. So we've been in the meantime, we focused on the things we can control, right,

which is access. So back to my earlier point, identity authorization access is super critical. That's even more true in agentic land, and we spent a lot of time ensuring that the people are thinking about the data stores and the APIs and whatnot that their agents can access. Because agents, you know, unlike you and I, you and I are gonna realize, Rob, when we stumbled across some data that we probably shouldn't have access to. Right. An agent is just not gonna think about that.

So it's, you know, it's really critical that as people use agents for tasks that they themselves used to do or would expect a colleague to do, that they think about, you know, the security aspect there. My final point on this is I'll say that we've talked to a lot of the big security companies and a lot of the, you know, smaller startups in the last six months about different ways to secure GenTech and MCP, and I'd say there's a lot of answers out there that are

coming and hopeful that we'll get a little bit more clarity here in the next month or two about how things are gonna shape up a little bit. We're starting to see common forms, common language, and all that, You know, just like we did in the security world ten or fifteen years ago, people started to talk, you know, speak a common language. So It's it's promising. Yeah. I'll maybe circle back on that towards the end if we have time. I was recently at a capital summit or CISO

summit sponsored by Intel, and, I was definitely in a room of folks at your level, which was amazing. I was the not the smartest one in the room for sure. But I don't think I'm the smartest one in this room. No. I think you are. But one of the hot topics that if we have time, I'd love to get your thought on is how do you sit you know, never before in history has it been scary that, one of the CISOs says that RBAC is pretty much dead. That AI, one person with AI can exfiltrate IP at

a rate in fifteen minutes that could out of a company. And how do you control that when someone in accounting that needs AI to be more efficient but has full access that AI has full access to things I wouldn't have access to or or he or she didn't have access to. So we can circle back on that. I'll only get your thoughts. And and well, the general thought was what key that is. The thought was the security industry hasn't caught up to it yet. There was full confidence that we as an industry will. We always do. But that we're a little bit behind the power curve that

it's just accelerating so fast. Every two weeks, it's like it's a next gen new generation, a new gen it's like it's at crazy speeds. You're not wrong. Yeah. Yeah. So let me shift focus. You know, one of SYNNEX superpowers and still is today is we offer a continuous manual offensive security engagement where we just never stop testing, and it's one part of our portfolio that Accenture has leveraged. Just curious what were some of the core things of value that you thought that that brought to the table and why your team

decided to employ continuous methodology on testing some of the assets for you. Yeah. I so let me say a couple things about that because we we didn't really talk about you asked, but I think I didn't respond about AI powered attacks. And, you know, some of the things we see out there. One one that I wanna call out, and I won't necessarily assume it's AI powered, but it's one that we've seen in the last year. And that is really the, you know, the the the zero day attack.

In the last twelve to twenty four months, you know, zero day attacks have taken on a very different aspect than they did beforehand, in the sense that threat actors now have, infrastructure, let's call it zero day engines, that they can load their zero day into and just hit as many potential targets as possible in the least amount of time. And, you know, they just load them up with web shells that they can come back to later.

And, you know, you can think of a potentially more even more of a doomsday scenario where they, you know, they load them up and just, you know, wanna burn down the world. Right? Like, you could see that happen. So I think I think it's important to recognize that it's important to recognize that our our defenses, you know, have to change and they have to they have to account for that style of attack. And there's, you know, there's lots of ways to address that, but one way, a straightforward way is what you guys

are talking or what you're talking about, which is, you know, this continuous pen testing. Continuous pen testing, I think, really helps with a number of challenges. Zero days being one of them because, you know, you're constantly looking for weaknesses and often zero days will link several weaknesses together. So if you can break that chain by just addressing one, that's that's great. The other side of that coin is teams are always releasing code.

Yes. They're releasing, and with that code, they may be unknowingly releasing vulnerabilities. You know, we've all seen the we've all seen the page where they will release code, they'll fix a vulnerability, and then with their next major release, they'll they'll release that old vulnerability again because Yes. Picked it in the original, right, that happens. Yes. You know, I think that's even the even the best

even the best coders and software companies out there are guilty of that, like we've seen that many times, it's a challenge. And having somebody doing continuous pen testing is going to find those, right? It's going to find those right away, so you know, if you can focus a number of testers who are constantly looking and, you know, honestly trying some of the same tests over and over again, like that's kind of the point, but also trying new ones on your most critical assets,

I think you can dramatically reduce your risk of compromise in in multiple scenarios. So gone are the days where you can do your monthly scan and, like, that's probably gonna be good enough. You know? Yeah. You need to do, I think, far more than that. You know, for us, I know, like, there we we do we do constant scans. We have other scans that we do hourly. Right? We have other scans we do daily. I don't think we have anything we do monthly anymore. Right? So it's, like, it's just not not happening.

I think having a group like yours attacking us to help us constantly really helps prevent the the bad guys who are attacking us constantly, Protects against the bad guys who are attacking us constantly from from finding something that, you know, you didn't already find. Right? So it's it's a it's a smart thing to do. Yeah. I mean, we we've and we've had this conversation. There's two ways to look at it. It's the attacker exposure time. Right? You the vulnerabilities out there and the time to find and then

the time to identify and the time to fix is you gotta take that off the market. Yep. This waterfalls into my next question to you is when we talk about different KPIs, and measuring risk and translating that into business impact, I know is a key concern of a of a CISO and, your peers. How has your approach to measuring and communicating continuous security improvements, a very Kaizen type of approach of always, you know, iterative incremental evolvement to ensure the

executive team understands? So this way this way and this way, what are you measuring as KPIs to help you deliver that message of risk and business impact and and, we're counting what counts, and how have you communicated that? Yeah. I mean, look, we we do we do measure we do measure time to remediation. Right? That's one of the the metrics that we that we look at. But the way that we really look at it is

we wanna we wanna make sure that people remediate we wanna make sure that people remediate stuff within a given time limit. Like, the there are that's remote stuff. The reason it's important is it's a target that people can understand and hit. Right? So it it's hard to convince a development organization, hey. We wanna collectively lower our average mean time to remediation from, I don't know, twenty six days to, you know,

fourteen, so try harder. It's much easier to tell them you got seven days. Like, it's gotta be fixed in seven days. If it's not seven days, right, we you've got a problem. Right? And then, you know, I can I can measure how many how many they don't fix in seven days, which, you know, it gets it gets you to the same same thing as long as you're willing to work with them to continually lower that threshold until it gets to a period you like? We also we also, like many other companies, we also have an emergency remediation

regime where, like, we just want to fix something as fast as possible, right? That's some of those zero days fall into that as they do for many other companies. Is that is that a separate is that like a tiger team that's separate that goes in, or are you saying that's a that's a no process thing? So the way that we do it is we maintain very good communication and very clear communication expectations with our, you know, our many groups of developers, and we just reach out directly to them and track to closure

when they fix these things, right? Okay. That's what we do. So we'll we will, you know, we've instrumented our entire attack surface and so we'll look for all the places. We have a particular zero day. We do that very quickly, and then we reach out to the teams that own that, you know, the particular places and tell them they gotta fix it quickly. And then, you know, work with them to get it fixed. We'll support them, but, you know, they know it's a big deal, and they're on it. Right? That's part of the that's part of the agreement that we have with them.

The other but getting kinda getting back to your metrics question, the other one though that I that I actually care probably more about is how many times do we repeat vulnerabilities? Right? Like, that's the one that I really care about. So when you guys, in your pen test, when you find something novel, you know, there's a new vulnerability out there and we you know, it's maybe an even different style of vulnerability that we haven't seen before. That's, you know, maybe it's not even a MITRE

or it is, you know, a a kind of a unique implication of a MITRE vulnerability. Right? I wanna measure how well we prevent that vulnerability from showing up again. Like, for me, that's a good deal. Like, I wanna make sure that we're not repeating it because it's one thing to, know, in blissful ignorance, introduce a vulnerability that nobody really knew about. It's entirely different thing to repeat that over and over again.

And that's what I really, really wanna prevent. And so that's you know, we measure that. We look at repeats, and we look at, you know, teams that are, you know, have the you know, make the mistake that I spoke about before where they reintroduce vulnerabilities with major releases, those types of things. Right? So that's that's a metric that I care a lot about. So I think both are important, but I think if you just focus on meantime to remediation only You're set yourself up for a a

lot of bad deja vu. I I can need to take a tangent there because you just I need to ask a question. So it's such a large organization. You come across that use case. Can you cite any examples, like, that that you're able to talk to on like, when you find that, how do you incent the behavior to change so it doesn't get repeated? Is do you have, like, gamification? Is it more of an awareness thing? Do you produce, like, internal and you push it to the groups? Like, how do you, like, how do you prevent it from be recurring? Yeah. We share the fee. Right? Like Oh, okay.

We have we have the concept of a reopened vulnerability. Right? So so, you know, we can tell people like, hey. You've had, you know, a lot of reopened ones. Like, you need to think about how you're releasing your code or your configurations. Right? So we, you know, we we look at that, and it's it's a it's a, you know, it's a let's call it friendly conversation. It's not a I don't I don't scorecard people on it in in the same

explicit way that I do some of the other things only because I haven't needed to. Right? Because it's it's sort of one of those things where I pointed out to somebody, and they're happy to fix it because they also don't wanna have to repeatedly fix the vulnerability in production. So you find a problem of in team one, and it's an acute problem, you go and make them aware of it. Yep. If you start to see the same problem across n number of teams, then your communication becomes much more broader. Yeah. Find it on a yeah.

Yeah. We can do that. I I would say, though, the the repetition point, it's pretty rare that it's broad based. Like Okay. It's broad usually something else going on that's causing that vulnerability to repeat. It's usually it's it is, you know, nine times out of ten, it's a it's a team that's not being as careful with, you know, code check ins, and and I I'll screw up the tech the technical terminology. But That's okay. Roll or, you know, putting the putting the fix into all the code branches properly.

Right? It's just that it's that kind of, you know, there there there might be one person on the team that wasn't doing it right, and we turn it out. They fix it, and we're fine. So let's just slightly change gears to you go and meet with the board. Is is the board of communication. Yeah. How do you communicate risk? And is when you get up and do your presentations, you just get sucked down the rabbit hole of AI AI AI and

securing and what are the guardrails you're putting in place? And, like, what is the and how do how do you succinctly communicate risk to where yeah. Just I'm I'm just curious. Like, I could go on now, but you understand what I'm asking is, like, what's what's your methodology on that? I get this question a lot. We saw this twenty years ago with financial expertise on boards. There's still a dearth of cybersecurity expertise on boards. Right? So a lot of my, you know, a lot of my colleagues ask, how do I communicate with the board? So, look, boards wanna know.

Boards are, you know, you have to remember, boards are a governance structure. They wanna know that you have a control system in place and that that control system is effective, like that's what they want to know. And so the way that I talk to our board about risk is I talk to them about it very much in business terms, right? So we have at Accenture, we have different types of risk areas that are, you know, unique to us and they're gonna be different than,

I don't know, an automotive company's risk areas or, you know, capital markets company's risk areas. Right? So so we put in terms they can understand in terms of, like like, in business risk. And I don't dive into you know, I don't I don't give them like, hey. We had, you know, two million vulnerabilities that we fixed. Right? Or, you know, like, they they don't they don't wanna know that. What they wanna know is, we meeting our SLAs? Are we doing what we need to do to keep our client engagement secure?

Our firm's, you know, technology secure? Are are we securing our acquisitions properly? Right? That's what they really, you know, that's what they really wanna know and understand. So I tend to roll up my, you know, my metrics into that into that control framework. And I also talked about the control framework, right, much like we spoke about earlier with the pen testing, we are a learning organization. I share stories with the board about,

usually they go something along the lines of, company X had a problem, the root cause of that problem at company X was, you know, a, b and c, right? I don't know, perhaps they didn't have strong service desk controls and they gave out a password they shouldn't have. What we do at Accenture to prevent that problem is this, right? Here's how we do service desk controls and here's how we think about it, and here are the controls that we have in place. And so with

some anecdotes like that, I can make the rest of the control system really come alive for them, and they can understand the, you know, the control set that we have and how we think about it. And then and then, you know, when we get into questions, it's much more along the lines of, you know, what do we think about this risk area, or how do we control for that risk? You know, I'm on the board of this other company. We had we had a problem over there. Like, would we ever have that problem here? Right? So it becomes a much more of a conversation like that.

And, yeah, AI is part of it, but I think the board talks to, many of my other executive colleagues about AI quite a bit. And maybe by the time it to me, they're a little they're a little warm. AI, I don't know. You know, it's a big topic for everybody. So, in all seriousness, of course, we address it. Like, we talk about it, but it's not a it is from a security perspective. The fun part of AI, I think, is enablement. The not so fun part is defending against it. And the answer to that is really you just have to be

better and faster and move at AI speed. And then getting you know, I I referenced it earlier, getting some of those extra controls in place that you you're gonna wanna have to, you know, defend yourself against AI powered attacks. Yeah. Yeah. I really appreciate the fact that you're spending time with SYNACT and with us and commenting on how you lead a global organization. It's just been wonderful being a partner with you and seeing how you all have just evolved,

and I've learned from your organization for sure. I know you're a busy person, so thank you so much for the partnership, the continued trust, and certainly for your time this afternoon. And we I look forward to seeing you when I come to Chicago next time. So thank you so much for your time, Yeah. Hey. Thanks, Rob. I'll I'll I'll say the same thing. You you guys have been a wonderful partner for us over the years. You know, we've learned a lot from you as well, and, you know, you you have caused change for good within our organization, right, and continue to do so. So, you know, we love that. And, great conversation today, and, yeah,

I would look forward to our our our next breakfast downstairs. Awesome. Thank you so much.

Speakers

Kris Burkhardt

Accenture

Global CISO

Rob Cross

Synack

Global Head of Strategic Programs

Risk measurement, MTTR and AI security FAQ

Why does MTTR matter to CISOs?
MTTR helps security leaders measure how quickly teams move from discovery to validation and remediation. Reducing MTTR helps lower exposure windows and demonstrate measurable security impact.
How does continuous security validation help reduce MTTR?
Continuous security validation helps teams identify, validate, and prioritize exploitable risk faster, so remediation efforts can focus on the findings that matter most.
Why is business impact important in cybersecurity?
Business impact helps CISOs connect security findings to risk reduction, operational priorities, and executive decision making.
How does AI change enterprise security testing?
AI increases the speed and scale of both innovation and adversarial activity. Security teams need faster validation, stronger prioritization, and continuous testing to keep pace.
Why combine AI with human security expertise?
AI expands speed and coverage, while human experts provide context, creativity, business logic validation, and deeper exploitability analysis.
How does Accenture approach measuring cyber risk?
Accenture focuses on connecting cybersecurity outcomes to measurable business impact, operational resilience, and faster remediation rather than relying only on vulnerability volume or compliance metrics.
Why is reducing MTTR becoming more important?
As attack surfaces expand and AI accelerates attacker behavior, organizations need to shorten the time between identifying exploitable risk and remediation to reduce exposure windows.

Next step

See what validated risk looks like on your attack surface.

Run a Sara AI pentest against a defined scope, see which findings the Synack Red Team confirms as exploitable, and measure the time from discovery to validated finding.