A Single Partner for Everything You Need With more than 450 technology partners in its ecosystem, Optiv provides clients with best-in-class security technology and solutions that equip organizations to detect and manage cyber threats effectively and efficiently in today's growing attack surface. Optiv's Partner of the Year Awards recognize forward-thinking innovation, performance and growth, and unparalleled technology solutions.
We Are Optiv Security Greatness is every team working toward a common goal. Winning in spite of cyber threats and overcoming challenges in spite of them. It’s building for a future that only you can create or simply coming home in time for dinner. However you define greatness, Optiv is in your corner. We manage cyber risk so you can secure your full potential.
Vibe Coding, AI Agents and the End of Passwords A conversation with Optiv CISO Rob Gregory Breadcrumb Home Insights Blog Vibe Coding, AI Agents and the Death of the Password September 08, 2026 A self-described cyber nerd, Rob Gregory’s route to becoming CISO at Optiv did not follow a conventional corporate trajectory. Joining the U.S. Army out of high school, he picked cyber for a very practical reason: "The recruiter had a list filtered by bonus, and there was one at the top that had $40,000 next to it. 18-year-old Rob wanted that one."That choice led to nine years in military intelligence – including a key post at the National Security Agency’s security operations center – a stint in support of the FBI, and then a transition as an executive into private sector security roles. Today, Gregory steers Optiv’s internal cybersecurity operations while advising executive peers across the industry. Optiv counts more than two dozen former CISOs on staff, which gives the company a distinct strategic advantage in a sector where translating technical expertise into clear business strategy can be challenging. This shared experience is applied to help CISOs bridge the gap between day-to-day cybersecurity defense and board-level decision-making. In this conversation, Gregory details CISO needs, the realities of evolving AI adoption, and why eliminating passwords remains one of cybersecurity's most critical objectives. Taming Tool Sprawl and Artificial Intelligence Q: What challenges are top of mind for security leaders right now? A, Platformization and consolidation. That continues to be No. 1. As an industry, we spent the last five to 10 years chasing best-of-breed solutions. C-suite leaders are now looking at stacks containing 30 or 40 different tools, each with its own dashboard and required level of expertise to support. It isn't scalable. Conversations are heavily focused now on where organizations can consolidate to single-pane platforms. The second area is AI governance. A year ago, it was: 'What are we going to do with AI?' We have rapidly moved past that. The struggle now is governing agentic capabilities. An AI agent approved for one task today might perform completely differently a week from now after an employee issues a new prompt. Multiply that across functions – it’s not slowing down. We are also seeing a heavy ramp-up in "vibe-based coding," using AI platforms to allow laypersons to develop full software stacks by inputting simple prompts. They’re good at making a functional tool, but they are terrible at making them secure. CISOs are facing a tornado of challenges trying to let the business move at speed without allowing unsecure apps to run freely across corporate networks. Q: How is Optiv approaching AI internally to evaluate these tools before advising clients on them? We revamped our AI governance program about a year ago in close partnership with our CIO. We established an AI Center of Excellence to serve as an onboarding pipeline for new ideas and tools. That framework allowed us to experiment in controlled sandboxes, learn from early mistakes, and test agentic capabilities safely. Q: Optiv employs over two dozen former CISOs across its organization. Why is having that specific operational background such a differentiator when advising clients? There is no substitute for sitting down with someone who has actually been in the seat. It provides immediate credibility. It’s one thing to read an article on how to be a CISO; it is completely different to sit down with someone who has had to fight for a half-million-dollar investment from a CFO in a year where budgets are being cut by 10 percent. We have a field team of CISOs meeting with clients on a daily basis, and this experience allows us to engage in real-world conversations on both the technical nuances and the business-facing challenges of cybersecurity leadership. Winning the War on Passwords Q: Passwordless authentication is a hot button topic for you. Why is this transition taking so long for enterprises to execute? Passwords are a self-induced challenge. For years, the standard advice was to rotate complex passwords every 60 days, which led directly to password reuse and predictable patterns. When combined with credential leaks from high-profile data breaches, it created a massive surface area for attack. Passwordless authentication replaces passwords entirely using multifactor elements, like a cryptographic key pair bound to a specific physical device combined with biometrics. A passwordless system fundamentally cannot be phished because there are no harvesting credentials to steal. The implementation barrier is scope. Large enterprises run hundreds or thousands of underlying applications, and converting every platform requires significant change management. We focus a lot on social engineering, phishing, user awareness training and more, which are all the right things. However, eliminating the password removes the single largest point of failure in the security stack. It should be a Top 3 priority for every organization. Leading with "How" and Managing the Next Frontier Q: What is one thing CISOs should start doing today, and one thing they should stop doing immediately? CISOs need to start leveraging AI to streamline their own personal workdays. Many security leaders are focused on enabling and governing the business’s use of AI, but they aren't upskilling themselves to become more efficient in their own roles. Stop doing? Stop saying "no." CISOs need to start saying "how." When security leaders act as roadblocks to business initiatives, they risk finding themselves excluded from executive-level conversations and strategic decision-making. Q, Looking ahead, where will CISOs be focusing their attention? On maintaining an inventory and developing ways to monitor all the AI agents their organizations are creating. Governance is key because agents floating around exponentially increases risk. Much like we review job performance with humans, there is a need to evaluate, connect with and assess ever evolving AI agents over time. We know what the questions are, and we are working on the answers and the best solutions before things get out of hand. By: Optiv Share: Optiv vibe coding AI agents passwordless authentication Identity Security Cybersecurity Trends Cyber Risk Artificial Intelligence Authentication digital identity CISO insights Cyber Threats security leadership Enterprise Security optivimpact About Optiv Security: Secure greatness.® Optiv is the world’s largest pure-play cybersecurity company. With unmatched technology partnerships and deep technical expertise, Optiv securely enables the AI era for more than 6,000 clients. From financial services and health care, to government, energy and retail, organizations trust Optiv to advise, deploy and operate cybersecurity programs that reduce risk and deliver real results. Learn why Optiv is the most trusted brand in cyber at optiv.com.
About Optiv Security: Secure greatness.® Optiv is the world’s largest pure-play cybersecurity company. With unmatched technology partnerships and deep technical expertise, Optiv securely enables the AI era for more than 6,000 clients. From financial services and health care, to government, energy and retail, organizations trust Optiv to advise, deploy and operate cybersecurity programs that reduce risk and deliver real results. Learn why Optiv is the most trusted brand in cyber at optiv.com.