Your developers can now build an application in an afternoon. An AI agent can modify infrastructure in seconds. Yet opening the network path that new workload needs can still take a ticket, three meetings, four approvals, and “somebody named Bob who happens to be on vacation.” That gap forces an uncomfortable choice: security either becomes a department of no that slows the business, or people find a way around it to get their work done. Neither outcome is acceptable.
Jeff Spear, Chief Information Security Officer at Tufin, sat down with G. Mark Hardy, host of the CISO Tradecraft podcast, to explore how security leaders can keep the business moving without losing control of network access, policy, and compliance. Spear carries a dual mandate: protect Tufin’s business while enabling its customers. Across a career that has spanned on-premises infrastructure, cloud transformation, and now agentic AI, one constant has remained — the network connects everything.
Governance is not management
The distinction Spear draws is one many organizations blur. Network management asks whether the lights are green: is the network working, is data flowing, and can the business operate? Governance asks harder questions: Should this connection exist in the first place? Who requested it? What business purpose does it serve? Is that purpose still valid? And who accepted the risk it created?
A network can pass every management test and still fail governance. A firewall may be configured exactly as intended, with every rule functioning precisely as designed, while still enforcing a policy that no longer makes sense. Businesses change continuously. Applications are added, locations open and close, and mergers and divestitures reshape what should be allowed to communicate. Governance is the discipline of keeping network intent aligned with business reality over time.
The stakes are not abstract. Spear described an anonymized case in which an inability to integrate an acquired network nearly sank a deal, with seven figures ultimately swinging the outcome. His lesson for security leaders: get involved early. “It’s better to be under the tent than under the bus.”
You cannot govern what you cannot see
Governance depends on visibility, and an inventory list is not enough. The question sounds simple—who can talk to whom, and why?—but in a large enterprise, the answer is rarely straightforward. The cloud team understands its connections. The firewall team understands its rules. Meanwhile, the person who requested a critical rule three years ago may no longer work at the company. Responsibility becomes diffuse, and ownership disappears.
The better mental model is relational, not list-based. A map of how traffic actually flows can answer questions that an inventory cannot: Can a user in accounting reach this application? Through which devices? Where does the traffic cross a trust boundary? That same map becomes a translation layer between security and the business. Instead of leading with technical abstractions, a CISO can ask why 50 people have access to an application when the business owner says only 40 should.
That is the broader lesson: visibility answers what exists. Governance determines what should exist. The value comes from connecting the two so security teams can explain risk in business terms and act on it.
“You can’t think in lists any longer.”
— Jeff Spear, CISO, Tufin
Access debt is the bill nobody is paying
Access debt: every network connection without a documented owner, business justification, or expiration date. It is a loan against your future security posture that compounds through complexity and exposure.
One of the conversation’s sharpest ideas was giving a familiar security problem a name: Access Debt. Security teams already understand technical debt because shortcuts made today create costs tomorrow. Access Debt follows the same pattern. Every unmanaged connection quietly increases complexity, expands exposure, and becomes another future problem someone has to solve.
Not all Access Debt is accidental. Organizations sometimes accept temporary risk deliberately to keep the business moving, documenting and tracking it like any other form of technical debt. The dangerous kind is the debt nobody records, the connection nobody remembers approving, and nobody is actively paying down.
The antidote is to treat time as a first-class control.
Mature governance moves beyond a simple allow or deny decision and asks two additional questions:
- Under what conditions?
- For how long?
Just in time, network access should not stop at identity. It belongs at the network layer as well, where temporary business requirements have a habit of becoming permanent rules.
Time matters because risk changes faster than ever. Threat actors have long exploited forgotten connectivity, probing one port at a time until an overlooked opening becomes the easiest path in. AI is compressing that timeline by accelerating vulnerability discovery and exploitation. A connection that looked low risk last quarter can become an attractive target long before anyone remembers to review it.
Access Debt is what happens when yesterday’s security intent quietly outlives today’s business intent. Continuous assurance is how you keep the two aligned.
In practice, continuous assurance starts by asking three simple questions of every network connection:
- Who owns it?
- Does it still serve a legitimate business purpose?
- When should it expire?
“Every permanent access grant is a bet that the future is going to look exactly like it does today.”
— Jeff Spear, CISO, Tufin
Automation without governance just breaks things faster
Once an organization can see its environment and define what access should exist, automation becomes powerful. Infrastructure as code makes network change repeatable, testable, and fast—but speed is neutral. Automating a broken process does not make it secure; it simply makes the wrong decision happen more consistently and at greater scale.
The order of operations matters. Policy has to be expressed in terms a machine can evaluate before enforcement can be safely automated. If the policy lives only in people’s heads and scattered documentation, there is nothing reliable for automation to enforce.
The healthier framing is guardrails, not gates. Good security should make the secure path easier than the insecure one. Spear points to controls that can block an end-of-life library while automatically offering a compliant alternative. The goal is not to make the CISO the final person standing in the pipeline saying no. It is to embed policy into the path so the business can move faster without abandoning control.
Agents need a job, not just access
That distinction becomes even more important with AI. A chatbot connected to a firewall console is not automatically a security agent. As Spear puts it, “A chatbot has access; an agent has a job.” A genuine security agent needs a defined and bounded scope, authoritative context from a live source of truth, explicit boundaries over what it can read, recommend, and change, and a workflow that verifies its actions.
The operating model should look less like unrestricted autonomy and more like a junior engineer working inside clear guardrails: complete the assigned task, document the action, and have a senior engineer verify the result when appropriate. AI changes how decisions are executed; it does not remove accountability for making the right decisions in the first place. Intelligence without governance does not reduce risk—it accelerates it.
“A chatbot has access; an agent has a job.”
— Jeff Spear, CISO, Tufin
The first-Monday mandate
For the CISO inheriting thousands of rules across multiple vendors and inconsistent ownership, Spear’s advice starts with restraint, not a purge. Resist the temptation to start deleting rules until the dashboard turns green. Instead, aim for precision: build relationships before breaking fences, establish a north star, then bucket and prioritize the work. Each bucket should connect to a business story that makes the underlying risk understandable.
That approach brings the article’s central idea into focus. “Everything is programmable except judgment.” Automation and AI agents do not eliminate the need for governance; they make weak governance harder to hide. The real work is writing down the decisions organizations have historically carried in people’s heads: what should talk to what, under what conditions, for how long, and who owns the call. Do that, and automation can safely accelerate the business. Skip it, and you have simply built a faster way to be wrong.
“Everything is programmable except judgment.”
— Jeff Spear, CISO, Tufin
Watch the CISO Tradecraft Podcast
Network governance is not another layer of security bureaucracy. It is how organizations make sure automation and AI accelerate the business without accelerating risk. The organizations that can clearly define what should connect, why it should connect, for how long, and who owns the decision are the ones best positioned to move quickly without losing control.
Hear Jeff Spear explore these ideas in more depth on the CISO Tradecraft podcast and get your network exposure assessment today.
Ready to Learn More
Get a Demo