Guest Introduction:
Sean Murphy is the Senior Vice President and Chief Information Security Officer at BECU, the 4th largest credit union in the United States and the largest community-based credit union in the country, with approximately $30 billion in assets. With more than 7 years at BECU, Sean leads a security organization of 60 professionals spanning risk management, identity and access management, security operations, platform engineering, and disaster recovery. His career spans the U.S. Air Force and military medicine, civilian healthcare, and now financial services, giving him a cross-sector lens on cybersecurity accountability that is rare at the executive level.
Here's a Glimpse of What You'll Learn
- Why Sean reframes the "they only have to be right once" threat model and how layered defense changes the math entirely
- How AI-powered email security tools are doing what traditional gateways never could, and why bolting an LLM onto a legacy product is not the same thing
- Why Sean believes the good guys ultimately win the AI security battle and the one condition that has to be met first
- The direct call to action Sean is making to security manufacturers about their responsibility in the AI era
- His three-principle framework for building and defending a security product portfolio to a board
- Why the CISO peer network remains one of the most underrated and most reliable tools for evaluating new security technology
- What Sean's cross-sector background in healthcare and the military taught him about who actually bears the cost when cybersecurity fails
In This Episode
Sean arrives at this conversation with something most CISOs do not have: a career that has moved through military medicine, civilian healthcare, and now critical financial infrastructure. That arc shapes how he thinks about cybersecurity accountability, not just as a technical discipline but as a protection of real people who cannot absorb the consequences of getting it wrong. At BECU, the $30 billion in assets under management belongs to the members. Sean makes that point directly and returns to it throughout the conversation. When cybersecurity fails at an institution like this, it is not an organizational metric that suffers. It is someone's savings, someone's mortgage, someone's financial life. That is the weight he carries into every board presentation and every product decision.
The conversation sharpens quickly when Sean pushes back on one of the most repeated framings in security: that defenders have to be perfect every day while attackers only have to be right once. He does not dismiss the underlying tension, but he reframes it in a way that changes the strategic posture entirely. If your architecture gives an adversary a single opportunity to get through, then yes, that framing holds. But the answer is not to accept it as fixed. The answer is layered defense built across protection, detection, response, and recovery, where attackers have to win at multiple levels before they reach anything critical. Sean is specific about what this looks like in practice, drawing on AI-powered email security as a concrete example of the model working. Tools that use machine learning to evaluate URL age, flag anomalous behavior, and move suspicious content before a user ever sees it represent what security has always needed to be able to do. The distinction he draws matters: that is fundamentally different from slapping an LLM onto a traditional email gateway and calling it AI-powered, which introduces prompt injection risk without solving the underlying problem.
Where this episode breaks real ground is in Sean's argument about manufacturer accountability. It is a point he admits he was not planning to make when the conversation started, but once it surfaced he developed it with clarity and conviction. Organizations that are not in the business of cybersecurity cannot be expected to carry the full defensive burden when the products being shipped into their environments arrive with vulnerabilities baked in. Sean draws the parallel to law enforcement: communities are not expected to police themselves simply because a police force exists, and yet organizations are routinely penalized when vendor-originated vulnerabilities result in a breach. His ask is not to absolve defenders of responsibility. It is to hold manufacturers to a higher standard, specifically that they use AI proactively to find and fix vulnerabilities before publishing them, rather than waiting for researchers or attackers to surface them first. He closes with three principles for how he builds and defends his own product portfolio: platform consolidation over niche products, objective industry benchmarking through tools like the Gartner Magic Quadrant, and the CISO peer network, where honest conversations about what actually worked and what nearly caused a breach drive some of the most reliable buying decisions in the industry.