A security leader who spent years buying F5 technology now works inside the company, and four weeks in he is making the case that availability belongs in the security portfolio and that every agent heading into production needs a name attached to it. Recorded on location at Black Hat USA 2026, this conversation moves from board pressure and shadow AI to what a compressed detection window actually buys a security team.
Sean Murphy spent most of the past decade running F5 technology as a customer inside highly regulated environments. He is now about four weeks into the role of Field CISO for North America, and he describes the first month as drinking from a fire hose. Depending on how the math is done, he places F5 among the seven largest cybersecurity companies once BIG-IP is counted as security tooling, with the reasoning running through the CIA triad. Availability is the leg that tends to fall out of the security conversation, and without it there is no resiliency.
What changes for a CISO when AI moves from experimentation into production? Sean Murphy points less at speed on its own and more at what he calls the physics behind it. Anyone can build an agent, and people do, which brings shadow AI along for the ride. Forces multiply across speed and scale until the consequences turn existential for some organizations, and governance and visibility land at the feet of the CISO.
He argues they should not stop there. Sean Murphy wants a gating step that carries a business justification and a named accountable owner for each agent. His concern is less about who owns what an agent is designed to do and more about who answers for what it does outside that intent. Intention, in his framing, is the new frontier and the new perimeter.
What should executive teams understand before approving more agents? Exposure has stopped tracking company size. Adversaries are weaponizing agentic AI, and Sean Murphy describes the curve from vulnerability to exposure to exploit as closed for practical purposes, which removes the hiding places smaller organizations used to count on. Investment in AI innovation needs matching investment in governance and guardrails, or the result surfaces as a data breach or an SEC filing tied to shadow IT and shadow AI.
On the technology side, he points to the F5 Application Delivery and Security Platform watching at the customer edge and the regional edge, where AI logic and risk scoring can delay attempts before they reach customer production environments. That delay gives a security team room to detect, respond, recover, and patch on a compressed timeline instead of an almost instantaneous one. It is also why he favors a platform over a set of niche products, with AI risk scoring, runtime analysis, and behavioral alerting in one place a team is trained on.
Sean Murphy closes with a story from the customer seat, where F5 protections acquired through Silverline and Shape helped him push off automated botnet attacks and keep the business running, before anyone framed that work as AI. Boards are pressing executive teams on why more is not underway, and his answer is assurance built on capability, with enough friction in place to stay out of the headlines.
This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing
GUEST
Sean Murphy, Field CISO for North America at F5
On LinkedIn: https://www.linkedin.com/in/seanmurphy092009/
RESOURCES
Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas
Learn more about F5: https://www.f5.com
F5 AI Security Platform and the SurePath AI acquisition: https://www.f5.com/company/news/press-releases/f5-ai-security-platform-control-enterprise-risk
Are you interested in telling your story?
▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full
▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight
▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight
▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings
KEYWORDS
Sean Murphy, F5, Sean Martin, brand briefing, brand story, brand marketing, marketing podcast, Black Hat USA 2026, field CISO, agentic AI, shadow AI, AI governance, agent accountability, application delivery and security platform, AI risk scoring, web application firewall, board reporting, security leadership
Agents in Production Need a Named Accountable Owner | A Brand Briefing at Black Hat USA 2026 with Sean Murphy, Field CISO for North America at F5 | Hosted by Sean Martin
[00:00:00] Sean Martin: I think we have the obligatory, you have a great name opening, right?
[00:00:15] Sean Murphy: Yes.
[00:00:15] Sean Martin: I think so. Sean Murphy. Sean Murphy with F5.
[00:00:18] Sean Murphy: Yes. Right. F5.
[00:00:19] Sean Martin: You are a CISO. Been a CISO for many, many years.
[00:00:22] Sean Murphy: Yes.
[00:00:23] Sean Martin: And we met a long time ago. Didn't realize it until we reconnected now. So good to see you.
[00:00:27] Sean Murphy: Yep.
[00:00:28] Sean Martin: So good to see you.
[00:00:28] Sean Murphy: You too.
[00:00:28] Sean Martin: You're a Field CISO for F5 now, so you're bringing all the knowledge and experience of being in the seat and helping F5 customers through the challenges that they face. Given your experiences and the value that F5 brings to the solutions, how's that going? It's a new role for you.
[00:00:46] Sean Murphy: It's going great. It's, you know, drinking from the fire hose, right. As you mentioned, for at least the last seven to 10 years, I've been a customer on the customer end of F5 and thought I knew a lot about what they were delivering with BIG-IP and with the wide area, or the, I'm sorry, the web application firewalling.
[00:01:00] And as I joined the organization just about four, four weeks ago, have really come to learn more about F5 as a cybersecurity company. I think depending on how you do the math, it's about the seventh largest cybersecurity company. If you throw in BIG-IP as a security tooling, and as a CISO I know that it's about confidentiality, integrity, and availability, right? So I do think that BIG-IP and load balancing is certainly part of the security portfolio.
[00:01:37] Sean Martin: People forget availability.
[00:01:38] Sean Murphy: Yes. And without availability, there's no resiliency and there's all the other things that we worry about in the security space.
[00:01:46] Sean Martin: Yeah.
[00:01:47] Sean Murphy: So F5, as I've come in, 30 year company that has a lot of solution sets around those parameters. Moving into the AI space with [00:02:00] the WAF that's powered by an AI backend and the acquisition of SurePath AI just recently to bring more AI capabilities into our risk scoring. And so even as a customer who thought they knew a lot about what F5 does and can bring to the table, in the last four weeks I've come to learn there's a very deep, deep inventory of capabilities and solutions that, like I said, I'm drinking from the fire hose to learn.
[00:02:27] Sean Martin: Well, there's a lot of stack to learn, right? There's the networking, the applications, certainly the data stack, with AI and APIs serving all this stuff. As a CISO, and from your peers as well, if you want to bring in some of that experience and understanding, organizations are pushing, or have pushed, the envelope in terms of AI adoption, right? What does that do to a CISO?
[00:02:57] Sean Murphy: Beyond giving you the night sweats? [00:03:00] I would say, first of all, we grow up in the CISO community knowing that we have to be aligned with the business. We have to be aligned with the strategic imperatives of the organization, no matter what industry you're in. I was in very highly regulated industries, but nonetheless, the business is the business, and unless you're in a pure cybersecurity company, you have to be able to build that balance and build that trust.
But the way AI has moved from experimentation and been democratized through the, you know, anybody can build an agent, and they do, which brings up the topic of shadow AI, which is, it's there, it's happening. Moving that from experimentation to in production is something that has really accelerated the cybersecurity, the CISO role, because it's really not just about accelerating the cyber, it's about the physics behind it. The forces are multiplying, [00:04:00] the speed, the scale, all of those things that are really, in some cases, existential in an organization are now laying at the feet of the CISO to get ahead of in terms of governance and visibility. And I will ultimately make the point that it's not to be laid at just the feet of the CISO. There's accountability that has to happen in this space. But I think the model really is multiple individuals that have to be accountable for what the agents are gonna do.
[00:04:33] Sean Martin: Right.
[00:04:33] Sean Murphy: And what decisions they make.
[00:04:36] Sean Martin: So let's start at the top, because the executive leadership team, business owners, one and the same in some organizations. What should they know from you as a CISO as they're interacting with your team and deploying AI or letting their teams deploy AI? And what not?
[00:04:57] Sean Murphy: Well, I think it starts with something that I think we [00:05:00] all learned earlier in our career, that it can happen to you. We used to say it's not if, it's when. In this case with AI, it absolutely can happen to you with the way the adversary is able to weaponize agentic AI. So that you can no longer hide in a, you know, I'm a small organization, or I'm a medium sized organization, and how could I possibly be a target? This has not happened to us before. The vulnerability to exposure to exploit curve is really gone for all intent and purposes. So there's no hiding places. If you're plugged into the agentic space, the adversary will find you at scale and at speed.
And so first of all, executives have to know that this can happen to you. And the second thing they have to know is that while there is proper investment in the innovation of agentic AI in the first place, there's also got to be the governance and the investment in the [00:06:00] security capabilities that help us put the guardrails on and do it safely and securely so that we're not rushing headlong into a data breach or some kind of SEC filing, which has happened, right, based on shadow IT or shadow AI.
[00:06:15] Sean Martin: Yeah, well, all the same. All the same. The way I look at it is it's basically skunk works on steroids, right?
[00:06:26] Sean Murphy: That's a good one.
[00:06:26] Sean Martin: Yeah. Everybody has the ability to spin up their own little thing, and even if it's business sanctioned, it's still a bunch of things. And I feel that the time of designing and architecting a system
[00:06:41] Sean Murphy: Mm-hmm.
[00:06:42] Sean Martin: that has testing and validation and maybe even some audit if it's being regulated, before it gets deployed. So the stuff's just being deployed now. So how do CISOs kind of get ahead of that? Are there tools? I'm sure F5 has [00:07:00] capabilities to help with some of this stuff.
[00:07:02] Sean Murphy: So one of the things that I particularly like about the model that the ADSP platform for F5 has is around being able to kind of see at the customer edge and at the regional edge that the AI, the agentic AI capabilities, or the attempts to attack, they're seeing them before they're getting into the environment of our customers. And they're with AI logic and with risk scoring able to, and here's the key, able to at least delay the issues before they hit the home base of our production environments, of our customers.
So it gives us a little bit of time as a CISO, right, to detect, respond, recover in some cases, or to do the patching, do the configuration management, in a very much compressed timeline, but not the almost [00:08:00] instantaneous timeline that it is. And I'll take a step back to say, it does, it still starts with governance. It starts with some level of gating with a business justification, a named accountable owner of the agents, whatever they are. Because again, I don't worry so much about somebody who owns what the agents do. I want somebody that is gonna be accountable for when the agents do something we didn't intend them to do. Right. Because intention, that's really the new frontier. The new parameter, right. Or the perimeter. New perimeter.
[00:08:32] Sean Martin: New perimeter,
[00:08:33] Sean Murphy: yeah.
[00:08:34] Sean Martin: The frontier. I love that word, frontier. Yeah. Because it is a new frontier. And so how are some of your peers, and maybe conversations you had leading into the new role, and maybe some examples from being in the new role where you're talking to CISOs, challenged here as well, where they're able to actually embrace the technology and set up their teams to actually do [00:09:00] some cool things.
[00:09:00] Sean Murphy: Mm-hmm.
[00:09:01] Sean Martin: What, what are you hearing there?
[00:09:02] Sean Murphy: Well, actually, I'll take it in a little bit of a different direction. Because one of the really nearest term stories that I heard yesterday, I was just talking to one of my colleagues and he was talking about how, you know, 2027, I have a roadmap of investment that I want to do. And guess what? I'm now pivoting hard on building out the AI capabilities on my team, which it takes time. Humans have to take time to build up their skills. So our security teams are all learning on the fly. This wasn't programmed necessarily in 2026 going into 2027. So now that's a hard pivot that has to get people up to speed.
So that's one area where I'm hearing, yes, there's a rush to invest, there's a rush to get ahead of this, but it's actually more of a pivot than anybody really [00:10:00] thoughtfully going into this. Right. I mean, we are in reactive mode to be proactive.
[00:10:04] Sean Martin: Right. And so the CISOs that you're talking to now, they're trying to figure out how to organize their team, have conversations with the business leader. What's the executive level conversation sound like? Is it different now than it was last year?
[00:10:28] Sean Murphy: In terms of the cybersecurity justifications, right? And
[00:10:32] Sean Martin: I'm thinking more specifically kind of like the best practices, because you're talking about a pivot. If you're gonna pivot, you're taking something away and doing something different. So what about best practices and fundamentals? Are some of those things in jeopardy? Are you able to leverage some of those things?
[00:10:54] Sean Murphy: Well, again, it starts with the strategic imperatives. So at the executive level, they're telling [00:11:00] me what they want to have happen. Go to market faster. They wanna be innovative. They want to put a better customer experience out there.
I'm coming to the table with, okay, so here's what we need to do to make all of that happen in the timeline that you want it to happen. So there's tooling that we have to invest in. I think this gets to really more of your last question about skill setting the team and showing the executive management that we are investing in tool sets that embed AI functionality like the ADSP with F5 and the AI powered web application firewalling, et cetera.
And so having those capabilities in place helped me to assure executive leadership, and I'll throw in the board for good measure, because they're actually putting the pressure on most organizations, because they're coming to the executive [00:12:00] team and saying, why aren't we doing more in this area? And so then the executive team is responding to that. And as a security professional, as a CISO, you have to be able to get in those conversations, and then give the assurance and the confidence that you are building in the capabilities to help enable them to be able to do those things at some frictionless speed. Right? Because again, I go back to the physics part of this, there is a coefficient and friction that's changing as well within this. You can't be the place to go say no, but you also have to put just enough in there so that we're not racing to the headlines for bad things.
[00:12:42] Sean Martin: So I would imagine the amount of noise that you hear as a CISO in terms of these are all the problems you have, even if you haven't experienced it yet, here are all the solutions available to help you with all of those problems. And oh, by the way, you have to change your environment for some of them. You can [00:13:00] plug some of it into your existing environment. It's a lot of noise. So as a CISO, I know you rely on your peers.
[00:13:07] Sean Murphy: Mm-hmm.
[00:13:07] Sean Martin: A lot of CISO communities come together and talk about these things. How important are those conversations through you and the community to help build trust with the people you're talking to now, so that that conversation is solid throughout the community?
[00:13:27] Sean Murphy: Yeah, that's a good question. So if you're referring to me personally in this role, I think it starts with a little bit of the been there, done that. Right. I've got the battle scars. I know what a CISO is going through at the board level, at the executive team level, within their own building programs and teams. I maybe haven't done their job, but I've done a job very much like their job. So I try to bring some authenticity and credibility to the conversation.
Beyond that, I think where I see the conversations going is we're all looking [00:14:00] for the maximum efficient technologies and solution sets that we can put in. I call it the best solutions that work the best together, which leads you to more of a platform of solutions discussion. It's again why I've been very happy with what I know now that F5 is investing in and doing, because it's coming together as a platform that CISOs can put in place and not have to chase after all the niche products that do this one thing or that one thing.
Even if they do it a little bit better, it's still better inside of a platform that you have your team's fully trained up on, you're fully leveraging. And if they can do the AI risk scoring and they can do the runtime analysis and they can do the checking for behavioral probabilistic type of alerts, if they can do all that in a platform, then why not go that direction. So F5 brings a very compelling argument to the table [00:15:00] and as a security company for a platform approach.
[00:15:03] Sean Martin: I love it. And I'm gonna give you a moment, Sean, to maybe say a final word, and then maybe I'll peek into the last four weeks. Is there a moment where a customer or a prospect looked to you and said, I had no idea that was possible. Thank you for bringing that experience or that knowledge to me.
[00:15:25] Sean Murphy: I wish I could say yes, but I'll turn that around to say, within F5, and as I'm meeting with peers and colleagues and people that I'm gonna be working with to go to the customers, I get the feedback that we have to demonstrate to our customers how much we are a cybersecurity company. We're not your, and this is not my phrase, but we're not your granddaddy's F5, right? We are bringing to the table real cybersecurity solutions. And the customers that we have that are using them, like Sean Murphy in my previous [00:16:00] role, I can give you stories of how I was saved literally by F5 and some of the protections that we got through the Silverline and the Shape acquisitions that F5 had, in botnet protections prior to anybody talking about AI. Right? I mean, we're talking about automated onslaughts of attacks that F5 helped me push off and keep our business up and running.
And so, big fan coming into the organization from a customer perspective. But now just kind of wanting to get out there and help get that word out and get people to have a shared experience with me of how I've seen the world and how I've experienced F5. Because I think it can help compel them to drive towards that platform mentality, the big solution set that F5 brings to the table.
[00:16:52] Sean Martin: So cool. They're lucky to have you. Lucky to have you. And I think the CISO community is in a much [00:17:00] better place now that you're here to now can help spread the word of what you know through all the channels you have access to now. So
[00:17:07] Sean Murphy: yeah,
[00:17:07] Sean Martin: I'm super proud.
[00:17:09] Sean Murphy: Thanks, Sean. And you guys,
[00:17:09] Sean Martin: congratulations.
[00:17:09] Sean Murphy: We share a great name.
[00:17:11] Sean Martin: So that's, we do share a great name. That's the best part of it.
[00:17:11] Sean Murphy: Exactly, exactly.
[00:17:11] Sean Martin: So, connect with Sean Murphy. That is connect with me too, if you like.
[00:17:11] Sean Murphy: That's right.
[00:17:11] Sean Martin: But he's gonna be more interesting to talk to. And yeah, connect with the F5 team. A lot of innovations in AI and up and down the stack to help you protect your applications and your environment. So thanks for watching. Stay tuned for more.