Thirty years ago, a Cisco customer service representative named Greg Akers picked up the phone to help a customer whose router was behaving strangely. Nobody knew it then, but he was fielding what would become one of the first cybersecurity service calls in the history of the commercial internet. At the time, Cisco had been building internet infrastructure for a decade. We didn’t have a security team. We didn’t have a security process. Cybersecurity did not really exist … yet. We couldn’t have predicted the scale or sophistication of the attacks that are now routine. We were focused on building something the world had never seen, and the people trying to break it hadn’t caught up yet.
That gap between what we build and what we can defend is not new, and it is not evidence of recklessness. It’s evidence of novelty. There is no playbook. If innovators only built within the limits of what they could already secure, they wouldn’t be innovating at all; they’d be maintaining. Safety has always trailed inventions, from the light bulb to the automobile to the internet itself. The question was never whether the gap would appear. It was how fast we’d close it, and what we’d learn along the way.
It’s Software, Not a New Species
Lately, I hear a lot of fear about artificial intelligence or super intelligence, fear that we’ve unleashed something categorically new and uncontrollable. I understand the anxiety, but I’d look to history to offer people a more pragmatic view to consider. AI is not a new species; it is software. Powerful, fast-moving, occasionally unpredictable software, but software nonetheless, and we have done this before. We learned to secure the mainframe, the client-server era, broadband, and the cloud — not completely, and not all at once — but well enough to unlock enormous economic growth and real benefits for billions of people. We will learn to secure this well enough, too. Not because it will be easy, but because we have thirty years of hard-won muscle memory as an industry for exactly this kind of problem.
That said, I want to be careful not to sound cavalier, because there are no victory laps in security. It is a fixed answer to a question that keeps changing. A system that is secure today can be vulnerable tomorrow, not because anyone made a mistake, but because the people on the other side are also innovating. And with AI, that adversary isn’t always a person outside. Sometimes, it’s the system itself, behaving in ways we didn’t intend or fully anticipate. That is a meaningfully different problem, and it deserves its own rigor, not just the old playbook.
Lessons from the Aviation Industry
The uncomfortable truth about security is that it is fundamentally humbling. That is true for every industry, every company size, and every security team. Commercial aviation is a prime example of where innovation and security must align. While commercial aviation is remarkably safe, the industry treats safety as a commitment that never really ends. We didn’t always have the systems we rely on today; we reached those current standards by realizing, at a significant investment of time and resources, that safety could not rely on individual expertise alone. It had to be engineered as a system. Modern air travel’s reliability stems not from human infallibility, but from that deliberate, systemic design.
If a plane fails a preflight check, it doesn’t fly, no matter how well it flew yesterday. And if an airline introduces an entirely new aircraft, they don’t immediately put passengers on it — they fly it in unpopulated airspace, wired with sensors and watched closely, so they can learn what they don’t know yet, before anyone’s safety depends on the answer. The extraordinary technology in the cockpit is never trusted alone. Air traffic control watches every aircraft from the ground, independent of what the pilot sees on their own instruments, and it says something when a plane drifts out of its lane. Investigators comb through every accident, near miss, and mechanical failure, and those findings become rules that apply industry-wide, not just to one airline. No single airline grades its own homework.
That’s the model I’d like to see built around AI. The best technology companies can create, paired with independent monitoring (not just of model builders, but AI in operations), transparent investigation of failures, and rules that apply across the industry rather than varying company to company. That’s not a brake on innovation. It’s the reason people are willing to get on a plane at all — and trust a system they don’t fully control.
The Culture We Need Now
Every serious security practitioner I know carries a version of that humility — the quiet knowledge that your best work is invisible by design, and the one day it isn’t, everyone will see it. The right response to someone else’s breach is not to throw rocks. It’s to recognize that the same match is being played against you, right now, and to help where you can. This is the fight our industry shows up for every single day, and it is a fight we do not always win.
That means being honest about where we fall short. Like many technology companies, we regularly disclose when our own products have active vulnerabilities being exploited in the wild. I firmly believe that transparency is how the industry gets better. But we also must be disciplined and balance our duty to share critical lessons with the reality that, in the wrong hands, too much detail too soon acts as a roadmap for an adversary. It’s about enough precision to drive security, without handing a weapon to those trying to break in. I’d also caution against a culture where the loudest voices are the ones trying to prove a company or a model is foolish. That dynamic doesn’t make anyone safer. It just makes people quieter about their problems, which is the opposite of what we need. Transparency requires trust that disclosure won’t be weaponized.
So, what do we do with that humility? We can’t predict exactly where AI will create risk next — anyone who tells you they can is selling something. What we can do is apply the same layered-system thinking that transformed aviation into one of the safest human ways to travel.
Regulators and governments have an important role here, the same role air traffic control plays — not flying the plane, but watching the whole sky, and speaking up the moment something drifts out of line.
What’s Next?
We must put ourselves in the best possible position, using what we know today, and adjust as we learn tomorrow. AI moves at a pace we’ve never seen before, and that demands intention, strategy and thoughtfulness working together in equal measure. It also requires an honest look at how other industries have tackled this exact puzzle before.
I don’t say any of this from outside the fray. Cisco has spent thirty years being the company in the room when things go sideways on the internet, and we’ll spend the next thirty helping figure out how to secure whatever AI becomes. I’m an optimist about where this goes. I also know, from three decades of experience, that optimism and vigilance were never in conflict. They’re the same job.
Stay up on Thought Leadership from Cisco
Get the latest blogs from Cisco Executives in your email.
Subscribe to the Executive Platform
Executive Perspectives
Navigate the latest technology trends and get solutions with the help of Cisco executives.
Go to Executive Perspectives
