Building the Three Lines of Defense for 2026 and Beyond
Lt. Gen. Rajesh Pant, Lokesh Garg, Sanjay Bahl (CISO), Richard LaTulip
Nullcon Goa 2026 · Day 1
Overview
This Nullcon panel discussion, "Building the Three Lines of Defense for 2026 and Beyond," delves into the critical evolution of the traditional three lines of defense model in an era defined by rapid technological shifts, particularly the widespread adoption of Artificial Intelligence (AI) and cloud-native architectures. Featuring insights from Lt. Gen. Rajesh Pant, Lokesh Garg, Sanjay Bahl (CISO), and Richard LaTulip, the talk addresses the growing challenges faced by Chief Information Security Officers (CISOs) and the broader cybersecurity landscape. It critically examines how established risk management frameworks must adapt to maintain relevance and effectiveness in the face of continuous innovation, emphasizing the need for agility, integration, and a proactive stance against emerging threats.

Key moments
- 0:00 Overview of Three Lines of Defense and CISO challenges.
- 2:00 Emphasizing continuous assessment and audit in security.
- 4:00 CISO's evolving role: business enabler, not 'Department of No.'
- 5:30 Why the Three Lines of Defense model is being re-evaluated.
- 6:30 CISO must convert vulnerabilities into financial impact for board.
- 7:30 The indispensable and expanding role of the CISO today.
Building the Three Lines of Defense for 2026 and Beyond
Speakers: Lt. Gen. Rajesh Pant; Lokesh Garg; Sanjay Bahl (CISO); Richard LaTulip
Conference: Nullcon
YouTube: https://www.youtube.com/watch?v=abGTPy9r1e0
Overview
This Nullcon panel discussion, "Building the Three Lines of Defense for 2026 and Beyond," delves into the critical evolution of the traditional three lines of defense model in an era defined by rapid technological shifts, particularly the widespread adoption of Artificial Intelligence (AI) and cloud-native architectures. Featuring insights from Lt. Gen. Rajesh Pant, Lokesh Garg, Sanjay Bahl (CISO), and Richard LaTulip, the talk addresses the growing challenges faced by Chief Information Security Officers (CISOs) and the broader cybersecurity landscape. It critically examines how established risk management frameworks must adapt to maintain relevance and effectiveness in the face of continuous innovation, emphasizing the need for agility, integration, and a proactive stance against emerging threats.
The central theme revolves around preventing cybersecurity from becoming a bottleneck—the dreaded "department of no"—while ensuring robust protection. The speakers explore how the roles of the first line (owning risk), second line (overseeing and challenging), and third line (auditing) are being reshaped by microservices, the shift from CAPEX to OPEX, and the inherent complexities of AI-driven systems. The discussion underscores the imperative for CISOs to transcend traditional technical roles, becoming strategic business enablers who can articulate cyber risk in financial terms and drive resilience. This article will dissect the panel's arguments, providing a deep dive into their recommendations for fortifying organizational defenses for the challenges of 2026 and beyond.
Background
▶ Watch: Overview of Three Lines of Defense and CISO challenges. (0:00)
The "three lines of defense" model has long been a cornerstone of effective governance and risk management within organizations. Traditionally, the first line of defense comprises operational management, which owns and manages risks as part of its daily activities. The second line of defense consists of functions like risk management, compliance, and information security, which oversee and challenge the first line's risk-taking activities, developing policies and providing guidance. Finally, the third line of defense is internal audit, providing independent assurance to the board and senior management on the effectiveness of governance, risk management, and internal controls across both the first and second lines.
However, as the panel highlighted, this model faces significant pressure in the current digital landscape. The rapid pace of technological change, particularly the advent of AI and the proliferation of cloud-native architectures utilizing microservices, challenges the traditional, often siloed, implementation of these lines. The shift from capital expenditure (CAPEX) to operational expenditure (OPEX) in cloud environments fundamentally alters how resources are consumed and secured. Furthermore, the perception of the CISO as the "department of no" — an impediment to business innovation rather than an enabler — has historically undermined the strategic importance of cybersecurity. The panel's discussion is rooted in addressing these foundational shifts, questioning the model's continued validity without adaptation, and proposing concrete strategies to evolve it into a more dynamic and integrated framework capable of tackling modern cyber threats.
Key Findings
▶ Watch: CISO's evolving role: business enabler, not 'Department of No.' (4:00)
The panel presented several critical findings and recommendations for adapting the three lines of defense model to modern challenges:
- Enduring Logic, Evolving Application: Despite criticisms labeling it the "three lines of delay," the fundamental logic of the model—first line owns risk, second oversees, third audits—remains sound. The challenge lies in its application within fast-moving digital environments.
- Continuous Audit is Imperative: Annual audits are rendered obsolete by daily infrastructure changes and continuously evolving AI models. The panel strongly advocated for continuous audit processes, moving towards concepts like Continuous Automated Red Teaming (CARD) to keep pace with dynamic environments.
- CISO as a Business Enabler: The CISO's role must transform from a technical gatekeeper to a strategic business enabler and ambassador. This involves partnering with business verticals, understanding critical assets, and translating technical vulnerabilities into tangible financial impacts for the board. An example cited was the JLR (Jaguar Land Rover) incident, where a security lapse reportedly led to a loss of $3.3 billion, underscoring the need to quantify risk in dollars.
- Shift to Resilience Metrics: Instead of focusing solely on metrics like "mean time to detect" or "number of vulnerabilities," the emphasis should shift to resilience, specifically Mean Time To Recover (MTTR) and the overall impact on business operations.
- Board-Level Cyber Awareness: Increased involvement from the board of directors is crucial. Organizations need cyber-aware individuals on their boards who understand security risks, preventing cybersecurity from being overlooked in favor of solely focusing on the bottom line. The panel noted a trend of CISOs ascending to CEO positions, further highlighting this growing recognition.
- Shared Responsibility and Integrated Approach: In cloud-native and microservices environments, cybersecurity risk cannot solely rest with the CISO. Shared responsibility across product heads, revenue leaders, and engineering teams is vital. An integrated approach, clearly defining roles and responsibilities using frameworks like the RACI matrix (Responsible, Accountable, Consulted, Informed), is essential to prevent exploitable gaps between organizational silos.
- Auditing AI Decisions: A significant emerging challenge is how to audit AI-based decisions. This involves understanding the basis of decisions, identifying biases, and detecting potential poisoning within AI models. The concept of Explainable AI (XAI) is highly sought after by auditors.
- Investment in Threat Intelligence and Skilled Professionals: Continuous evaluation of the threat surface, supported by robust cyber threat intelligence, is non-negotiable. The panel stressed the importance of local threat intelligence, as threat flavors vary geographically. Furthermore, investment in R&D and developing a pool of skilled professionals capable of understanding the entire organizational ecosystem is critical.
- Human-in-the-Loop for AI: While AI offers immense speed and support, a final human interface remains necessary for critical decisions, especially concerning trust, transparency, and ethical practices, acknowledging the "Skynet is real" sentiment.
Technical Deep Dive
▶ Watch: Why the Three Lines of Defense model is being re-evaluated. (5:30)
The technical discussions during the panel primarily centered on the implications of modern IT architectures and AI on cybersecurity practices. The shift to cloud-native architectures and the adoption of microservices fundamentally alters the attack surface and how security controls are applied. Instead of monolithic applications, organizations now deal with distributed, ephemeral components, requiring a more dynamic and continuous approach to security. This change moves the focus from a CAPEX-heavy, on-premise security model to an OPEX-driven, service-based security approach in the cloud.
A significant portion of the technical deep dive revolved around the challenges and solutions for continuous auditing and continuous monitoring. The panel argued that traditional annual audits are wholly inadequate for environments where infrastructure changes daily and code iterates constantly. Instead, they advocated for leveraging technology to enable continuous evaluation of the threat surface. This includes:
- Continuous Automated Red Teaming (CARD): An advanced form of continuous security assessment where automated tools constantly probe systems for vulnerabilities, mimicking real-world attacker behavior. This moves beyond periodic penetration testing to integrate security testing throughout the development and deployment lifecycle.
- Explainable AI (XAI): As AI models become integral to business operations, auditing their decisions presents a novel challenge. Auditors require XAI to understand the rationale behind AI-driven outputs, identify inherent biases, and detect any potential data poisoning that could compromise the integrity of the AI's decisions. The panel pondered the creation of an "AI handler" or a "consent officer" within AI platforms to ensure results are authentic and ethical, suggesting a need for a new role or system layer dedicated to AI governance.
- Cyber Threat Intelligence (CTI): Richard LaTulip specifically highlighted CTI as a vital component for maintaining a "leg up" in security. By combining continuous monitoring of internal changes with external threat intelligence, organizations can pragmatically and strategically prioritize the highest risks based on their criticality. A crucial nuance added was the importance of local threat intelligence, as the "flavor" of threats can vary significantly across geographies, necessitating tailored intelligence gathering and analysis.
- Attack Surface Management (ASM): The discussion touched upon the complexities of managing the attack surface in dynamic environments. Engineers constantly iterate on code, leading to continuous changes. Internal processes, such as employee onboarding and off-boarding, or even internal departmental transfers, can introduce scope creep where access privileges are retained unnecessarily, or responsibilities are not properly handed over. This can lead to forgotten assets, unmanaged vulnerabilities, and gaps in patch management, which can be exploited. Continuous monitoring, combined with CTI, helps identify and address these gaps proactively, rather than relying on retrospective annual reviews.
- Human-in-the-Loop for AI: Despite the advancements in AI, the panel strongly advocated for a "human in the loop" for critical AI-based decisions. This isn't just about technical oversight but about ensuring ethical considerations, transparency, and trust. While AI can accelerate identification and processing, the ultimate decision-maker should remain human, especially in scenarios where AI's "black box" nature prevents full transparency. This sentiment echoes concerns about the potential for AI autonomy, referencing popular culture like "Skynet."
The technical discourse emphasized that while technology introduces new challenges, it also provides the tools—such as advanced monitoring solutions and AI-driven security analytics—to address them. The key is to integrate these tools into a continuous, adaptive security framework that aligns with the speed of digital business.
Demo / Proof of Concept
▶ Watch: CISO must convert vulnerabilities into financial impact for board. (6:30)
This panel discussion focused on strategic and operational shifts in cybersecurity frameworks rather than demonstrating specific tools or vulnerabilities. Consequently, there was no live demo or proof of concept presented during the talk. The speakers concentrated on conceptual models, best practices, and future-oriented recommendations for evolving the three lines of defense.
Defensive Implications
▶ Watch: The indispensable and expanding role of the CISO today. (7:30)
The insights from this panel discussion offer several critical defensive implications for organizations aiming to fortify their cybersecurity posture for the future:
- Embrace Continuous Security: Defenders must shift away from periodic, snapshot-based security assessments (e.g., annual audits) towards continuous audit and continuous monitoring. This requires investing in automated tools that provide real-time visibility into the organization's changing attack surface, including infrastructure, code, and AI models. Implementing Continuous Automated Red Teaming (CARD) can proactively identify vulnerabilities at digital speed.
- Quantify Risk in Business Terms: CISOs and their teams should develop the capability to translate technical vulnerabilities and cyber risks into quantifiable financial impacts. This enables more effective communication with the board and senior management, driving necessary investments and fostering a deeper understanding of cybersecurity's strategic importance.
- Prioritize Resilience over Prevention Alone: While prevention remains crucial, the focus should expand to cyber resilience, emphasizing the ability to quickly recover from incidents. Metrics should shift towards Mean Time To Recover (MTTR) and the overall business impact of disruptions, rather than solely counting vulnerabilities or attacks.
- Foster Shared Responsibility: Cybersecurity can no longer be the sole domain of the CISO. Organizations must implement frameworks like the RACI matrix to clearly define and distribute cybersecurity responsibilities across all business units, including product development, engineering, and operations. This ensures that risk ownership is embedded throughout the organization, eliminating exploitable silos.
- Invest in Cyber Threat Intelligence (CTI): Establish or enhance CTI capabilities, with a particular emphasis on collecting and analyzing local threat intelligence. This tailored intelligence helps prioritize and address the most relevant and critical threats specific to the organization's geographical and operational context.
- Address AI Security and Governance: As AI adoption grows, defenders must develop strategies for auditing AI-based decisions. This includes demanding Explainable AI (XAI) capabilities from vendors, implementing mechanisms to detect and mitigate AI biases and poisoning, and ensuring ethical AI practices. The concept of an "AI handler" or "consent officer" could be a future defensive role or system component.
- Maintain a Human-in-the-Loop for Critical AI Decisions: Despite AI's capabilities, a human interface should remain for critical decision-making, particularly where trust, transparency, and ethical considerations are paramount. This acts as a crucial safeguard against unforeseen AI failures or malicious manipulation.
- Strengthen Attack Surface Management (ASM): Implement robust ASM processes that account for continuous changes in the environment. This includes rigorous access reviews, proper off-boarding procedures for employees, and diligent patch and vulnerability management to prevent "scope creep" and forgotten assets from becoming exploitable gaps.
- Advocate for Board-Level Cyber Expertise: Proactively work to educate board members on cyber risks or advocate for the inclusion of cyber-aware individuals on the board. This ensures that cybersecurity is a consistent consideration in strategic decision-making, not just an afterthought.
- Invest in Talent and R&D: Recognizing the increasing complexity, organizations must invest in continuous training for existing cybersecurity professionals and actively recruit and develop skilled professionals who understand the entire enterprise ecosystem. R&D investments are also crucial to stay ahead of evolving threats and leverage new defensive technologies.
Key Takeaways
- The traditional three lines of defense model remains logically sound but requires significant adaptation for the AI and cloud-native era, moving from static to dynamic risk management.
- CISOs must evolve into strategic business enablers, translating cyber risks into financial impacts and driving organizational resilience rather than being perceived as a "department of no."
- Continuous audit and continuous monitoring are essential to keep pace with daily infrastructure changes and rapidly evolving AI models, making annual reviews obsolete.
- Auditing AI decisions presents a new frontier, requiring Explainable AI (XAI), robust bias detection, and a human-in-the-loop for critical choices to ensure trust and ethical practices.
- Shared responsibility for cybersecurity across all business units, supported by clear frameworks like the RACI matrix, is critical to prevent exploitable gaps and foster a collective security culture.
- Investment in local cyber threat intelligence, skilled cybersecurity professionals, and R&D is paramount for proactive defense and effective attack surface management in a constantly changing threat landscape.
About the Speaker(s)
The panel featured a diverse group of experts contributing to the discussion on the future of cybersecurity and risk management:
- Lt. Gen. Rajesh Pant: Referred to as "General Pant" and "Ponce" during the talk, he provided a high-level strategic perspective, often drawing parallels from military organization and emphasizing the logical foundation of the three lines of defense. His contributions focused on continuous audit, the CISO's evolving role, and the challenges of auditing AI.
- Lokesh Garg: As a listed speaker, Lokesh Garg contributed to the overall panel discussion, though specific direct quotes were not explicitly attributed in the provided transcript. His presence indicates expertise in the domain being discussed.
- Sanjay Bahl (CISO): Listed as a CISO in the metadata, Sanjay Bahl's insights would typically come from the perspective of an active cybersecurity leader grappling with these challenges daily. While specific direct quotes were not explicitly attributed to him in the provided transcript, his role as CISO highlights the practical application of the discussed concepts.
- Richard LaTulip: Richard offered a perspective rooted in his experience, notably mentioning his time with the US Secret Service. His contributions focused on the CISO as a business enabler, the importance of continuous monitoring, and the critical role of cyber threat intelligence, including the nuances of local intelligence and the human element in AI oversight.
Reviews
Dr. Zero (Offensive Security Researcher) — WEAK
A panel of credentialed speakers talking in circles about governance frameworks that have been debated at every enterprise security conference for the last decade. No data, no specifics, no novel signal — just four people restating that CISOs should speak business language and audits should be continuous.
Heather Calloway (CISO) — SOLID
A competent panel covering genuinely important governance terrain — CISO role evolution, continuous audit, AI governance, shared risk ownership — but it stays at the level of framing rather than instruction. The right people are in the room; the conversation never gets specific enough to change how any of them operate.