The incident example points to a second management issue: operational accountability across security and infrastructure teams. When one team sees suspicious activity and another cannot prove where controls are working, the gap is not just technical visibility; it is an operating-model problem. CIOs and CISOs should test whether the NOC, SOC, legal, communications, and executive stakeholders can move from detection to containment with a common fact base, defined escalation paths, and evidence strong enough for regulators, insurers, and customers.
AI adds a portfolio and talent dimension. Leaders should resist framing AI as either a security cure-all or a full replacement for human judgment. The better near-term question is which vulnerability-management and response tasks can be automated safely, and which still require human accountability because they affect risk acceptance, customer trust, or regulatory exposure.
Practical next questions:
- Who has explicit authority to halt a release, and under what criteria?
- Can operations teams demonstrate control effectiveness, not just assert it?
- Which security workflows should be automated first, and what oversight metrics will govern them?
In this installment of IT Leaders Fast-5 — InformationWeek’s column for IT professionals to gain peer insights — Lovelie Moore, business information security officer (BISO) at Toyota Financial Services, explains how to push back when technology updates are moving too fast and why having an incident management plan is critical when threat actors find a way in.
She also talks about how AI is changing vulnerability management and cybersecurity operations, putting the CISO role in flux — potentially to the point of obsolescence.
Moore has a doctorate in cybersecurity, a field she has been in for 17 years. In addition to her role at Toyota Financial Services, Moore is an adjunct professor at Tarrant County College, and is an honorary chair of the Security Awareness and Resilience Council for the GlobalCISO Leadership Foundation. Earlier this year, she published My Vulnerabilities are Patched: A Cybersecurity Framework for Human Resilience.
This interview has been edited for clarity and space.
Lovelie Moore, business information security officer, Toyota Financial Services
The Decision That Mattered
What decision — technical or organizational — made the biggest difference recently, and why?
There was an update on an application that utilized AI, and there were vulnerabilities on the update that would push bad code into production. I pushed back on it, and it got all the way up to the CISO. That was the best decision I made this week.
How did you determine it was bad code?
The scan — using our tools that we have in place — will let us know if there are vulnerabilities that have been published.
Are companies addressing vulnerability management in a different way and having to triage potential risks differently due to AI?
Yes and no. Using AI to [address] vulnerabilities is a risk because we know that AI models sometimes can escape. We know that AI doesn’t have the capacity to manage vulnerabilities, but AI can let us know that they’re there and tell us where to [make a] fix.
The Hard-Won Lesson
What didn’t go as planned recently — and what did it force you to rethink?
In a former position, I noticed that there was bad activity happening on the network. A lot of data was going out to the APNIC [Asia Pacific Network Information Centre] IPs. The network team kept saying it was stopping it but couldn’t show where on the network it was actually blocked. We were tracking it on the security operations side, but the NOC [network operations center] wasn’t.
It took about three years of recon activity before they were able to get in. That didn’t go as planned — not getting ahead of it and stopping that information from leaking to the threat actors.
How did I correct it? I took care of the incident management until we were able to get fully back online.
What did the incident management process look like?
Making sure I report the correct information up to the CISO, lead the team and find patient zero or endpoint zero. Making sure I had the right information to support them, so they could talk to the press and to legal. Helping them with the insurance claim and writing the after-action report. There’s a whole incident response life cycle from detection to eradication and next steps.
The Perspective Shift
What have you read, watched or listened to recently that changed how you think about leadership or technology — even slightly?
I recommend Cyber Defense Magazine. I had the honor of having an article published in that magazine as well.
One thing that has me thinking and shifting on technology is definitely the rise of AI. I’m working on a white paper right now because I see the trajectory of positions that AI is taking over — for scalability, profitability, etc. — and it’s moving up the ladder very quickly.
My research is about AI and the evolution or the extinction of the CISO. Will the CISO evolve to a different position, or is it going to go extinct with the use of AI? I’m looking at it in a forward-thinking way regarding the implementation of this technology everywhere. I think it’s going to impact the quality of life for a lot of people. Like Skynet — I won’t be around when it gets there, but I’ll have lineage, and I definitely see something like that happening.
Regarding the potential evolution or extinction of the CISO — is the concern that AI would replace the cybersecurity team?
Absolutely. We will still need human oversight, but there are going to be a lot of functions that are going to be removed and replaced by AI. Humans will do the oversight only until AI eventually learns how to do it.
Enjoyed this article? Sign up for our newsletter to receive regular insights and stay connected.

