[Panel] Beyond Compliance: Who Owns, Measures, and Engineers Resilience in the AI Enterprise?

Tuesday, August 11, 2026
4:05 PM - 5:00 PM
CISO Forum Track (Salon III)

About This Session

Patching, compliance, and AI adoption metrics may demonstrate activity, but they do not necessarily prove that an organization is secure, resilient, or receiving meaningful value from its technology investments. This panel will examine how CISOs can move toward continuous security engineering, control validation, secure-by-design practices, recovery testing, and measurable operational resilience as technologies, threats, and dependencies continue to change.

Panelists will also discuss how responsibility for AI risk should be divided across the CISO, CIO, Chief AI Officer, legal, compliance, data governance, and business leadership. The conversation will focus on who can approve or stop AI-enabled deployments, how residual risk should be accepted, and which metrics best demonstrate control effectiveness, AI asset visibility, human oversight, fallback readiness, provider concentration, and return on investment.

Speakers

Brian "SchleiF" Schleifer

Brian "SchleiF" Schleifer

Director of Content, Events - SecurityWeek

Brian "SchleiF" Schleifer is Director of Content for SecurityWeek Events. He is a retired United States Air Force veteran, cybersecurity professional, podcast host and content leader. He previously served in senior cybersecurity engineering and leadership roles at Modern Technology Solutions, Inc. His experience includes cyber-physical and weapon systems security, security control assessment, cyber testing, risk management, and AI governance. He is pursuing a Doctor of Technology at Purdue University, where his research focuses on adaptive cybersecurity policy for AI-enabled systems. He is also the creator of the Adaptive Artificial Intelligence Risk and Assurance Framework, or AAIRAF. With more than 10,000 hours of public speaking, instruction, and panel moderation experience, Brian is known for making complex cybersecurity, technology, and risk topics practical and accessible.
Tahjar Roamartinez

Tahjar Roamartinez

CISO - Attalon

Ms Roamartinez is a seasoned IT and cybersecurity professional with over 15 years of experience in cybersecurity, AI security engineering, IT strategy, and business development, specializing in risk management, compliance, and enterprise security solutions. With a strong background in regulatory frameworks such as NIST 800-53, ISO 27001, GDPR, and HIPAA, Tahjar has successfully led global security teams, spearheaded AI-driven security initiatives, and managed multimillion-dollar IT operations.

As an AI Engineer with a background in risk management and compliance, she leverages deep expertise in governance, risk, and compliance (GRC) and cybersecurity principles to design, deploy, and maintain secure and compliant AI infrastructures and systems.

As Business Developer and Program Manager of Cyber Warfighters Group, Inc., she drove revenue growth by 40% and led large-scale cybersecurity initiatives for Fortune 1000 companies. Tahjar’s expertise spans cybersecurity, digital transformation, identity and access management (IAM), and IT governance, ensuring organizations remain resilient against evolving threats.

Previously, she held leadership roles in both the private and public sectors, including serving as Chief Information Security Officer (CISO) equivalent in the U.S. Army, where she managed a $2B cybersecurity operation. Tahjar’s strategic leadership extends to IT healthcare consulting, retail, life science, manufacturing, business continuity planning, security, and risk assessments.

In her military career, she managed cybersecurity for global U.S. Department of Defense facilities, including security protocols for networks, servers, computers, and logical designs. She has spearheaded innovative global digital transformation, security, and procurement initiatives for Fortune 500 highly-regulated global enterprises, specializing in AI utilization and IoT security, emphasizing proactive compliance, governance, and procurement oversight. She has successfully managed teams of up to 200 employees and contractors, fostering collaboration among diverse cross-functional teams. Tahjar has led e-commerce platform rollouts in the United States, Germany, China, France, India, Brazil, Cambodia, Japan, Argentina, Turkey, and Switzerland, focusing on strategic market expansion and B2B collaboration.

Tahjar holds IT and cybersecurity certifications as a Certified Ethical Hacker, IT Service Manager, Network, and cybersecurity practitioner. She has an MBA and a BS in Computer Information Systems from Texas A&M University.
Anna Loshkareva

Anna Loshkareva

Risk Officer, Digital - Navy Federal Credit Union

Cyber Security and Risk Executive with over 25 years of experience building and running Cyber Security programs of different sizes and scales. Proven record of bridging business and security missions together. Focus on empowering innovation, fostering collaboration, and promoting risk-based approach to security.

My mission is to protect and enable the business by transforming the culture from “No” to “KNOW”.

Expertise includes governance, compliance, risk management, security engineering and operations, Cloud, threat intelligence, threat management, incident response.
Andrea Elliott

Andrea Elliott

Founder and CEO - EMG Advisory

AI is rewriting what industries can do, and the leaders who govern it with seriousness and imagination will reshape theirs rather than scramble to catch up. I help those leaders imagine beyond what AI makes possible today, then usher them through the transformation for the betterment of the people their industries serve.

It starts with something deceptively simple: helping organizations make sound AI decisions they can stand behind, quickly and confidently. Done right, that discipline is not a brake on ambition. It is what lets a company reimagine what is possible with AI.

My work sits at the intersection of law, governance, risk, compliance, ethics, strategy, and systems design. After 15+ years in risk and compliance roles, most recently as Chief Compliance Officer where I built the company's AI governance framework from the ground up, I founded EMG Advisory on a conviction: AI does not need more hype. It needs structure, accountability, and leaders who treat risk as a strategic discipline.

That is the part most people miss: When done well, risk management does not slow AI down. It decides where you can afford to move fast and where you cannot, and it is inseparable from strategy; your AI strategy does not survive without it.

The other half of how I work is AI-native wiring. I think in systems, synthesize fast, and collaborate with AI at the conceptual layer as a cognitive partner, translating complexity into strategic clarity. It is also how EMG itself is built: I practice the responsible, operationalized AI I help my clients deploy.

I work with organizations that want to use AI strategically, responsibly, and with foresight. I help leaders:

- Turn AI risk and compliance into strategic advantage
- Make defensible AI decisions at the speed of business
- Translate regulatory ambiguity into operational clarity
- Anticipate second and third order effects before they surface
- Design governance that works in practice, not just on paper

The regulatory landscape shifts faster than most AI roadmaps and the patchwork of overlapping laws and standards leaves organizations unsure what they must comply with. Pair that with AI that stalls in committee and governance impeccable on paper that no one operates by and the gap becomes clear. Closing it is where I do my best work.

But closing the gap is the floor, not the ceiling. The organizations that govern AI with seriousness and imagination will not just keep up; they will transform what their industries can do for the people who depend on them. That is the future I am building toward.

Je m’appelle Andrea