In an environment where cyberthreats evolve faster than many organisations can handle, one aspect of security has never changed: the principle of least privilege. However, for many CISOs, it feels almost impossible to manage privileges without disrupting the business.

David Bellini, CEO of CyberFOX, offers a fresh perspective on this challenge. As a co-founder of ConnectWise, he spent years learning about the realities of IT teams before focusing on cybersecurity. Now, with CyberFOX supporting nearly 4,000 customers, Bellini aims to show that strong security can be simple and non-disruptive. We spoke with him about the real challenges facing CISOs today, from adopting AI to meeting cyber insurance requirements.
Many organisations want to implement privileged access management (PAM) without making the workload impossible. What is a practical way for CISOs to handle this?
We’ve been telling people since the mid-90s that they shouldn’t give users privileged access. However, we have legacy software that requires privileged access. So, we’re trying to fix programming problems and legacy issues from 30 years ago, and the CISO is getting stuck in the middle.
The main point is that this is not a technology problem; it is a change management problem. I’ve watched too many organisations try to solve this by taking away admin rights on Friday and dealing with the chaos on Monday. That’s not sustainable, and it’s not fair to end users.
A practical approach is to initiate with exceptions or policies and have your privilege management solution operate silently for a few weeks to identify which applications actually need administrative access, as well as when. You may be surprised at the results. Often, a “critical” application only needs it to be run as an admin to install updates but doesn’t need to be run as an admin all the time. Once you determine what is needed, you can create smart rules to escalate access only when necessary, and then rollback later upon completion.
The great thing about this process is that users often don’t see the difference. A user clicks to update Bluebeam, AutoCAD, or QuickBooks, everything works and they move along with their day without disruption or delay. Meanwhile, you have mitigated another attack vector. That is security that sticks, when it improves productivity rather than detracting from it.
As AI is adopted more broadly, how should privilege management strategies change?
AI is interesting because it is making cybersecurity easier and more complex at the same time. On the one hand, AI is helping with policy creation and anomaly detection in the privilege management space. On the other hand, AI systems themselves need to have robust privilege controls, especially applicable to sensitive data and automated decision-making.
The bigger challenge I’m seeing is that AI adoption is happening so fast that traditional security reviews can’t keep up. Teams are adopting AI tools or integrations before considering the access they provide to others. Teams can easily integrate its AI writing tool into its content management system, providing a third-party AI with comprehensive access to its content and, therefore, its data, without much consideration.
From a privilege management perspective, it is no longer enough to say, “this user can access this data, at this time, with this AI tool, and for this purpose.” Without this granular control, you’re essentially giving shadow AI a free pass to spread throughout your organisation unchecked. To get to that level of detail and stop unauthorized AI tools from slipping through the cracks, you need to automate – you won’t get there managing it all by hand.
Moreover, we need to think about a future where every single human worker will have an AI assistant. The assistant will need some level of access to the system they are using to function effectively. The question becomes: how do you provide the minimum required access to an AI that is designed and built to help as broadly as possible?
Cyber insurance is increasingly requiring least privilege compliance. How can CISOs prove this?
This is a key issue. I had a conversation with a customer recently. He said that the cyber insurance questionnaire that the insurance company sent to him went from one page to 27 pages, with privileged access being front and centre. The insurance company knows that the greatest risk in the case of a breach is the privileged credentials.
The problem is that “least privilege” means different things to different people. Insurers want to ensure that there aren’t permanent admin accounts, but they also want to see that your business can operate efficiently.
You need to be able to demonstrate to the insurer who has access to what, when they use it, and how you monitor and control access. Manual processes won’t work, as they are not auditable at scale.
In fact, we had a customer whose cyber insurance premium didn’t increase from year to year because, in addition to documenting processes, he implemented the principle of least privilege and had no standing administrator accounts. The insurance company considered this to be a significant reduction of risk. That’s thousands of dollars of premium reduction that could offset the cost of the security solution.
But my advice to CISOs is that you shouldn’t be doing privilege management just for compliance; do it because it is the appropriate security practice, and consider the insurance benefit as a bonus. Insurance requirements change, but security fundamentals don’t.
What do you envision for privileged access management in the next five years?
PAM will become more intelligent and context-driven; the majority of PAM is still relatively binary today: you have access or you don’t. In the future, we will begin to see a shift towards more dynamic, risk-based access models that consider who is requesting access, what they are trying to accomplish, from where they are accessing it and the current threat landscape.
We will see improved integration between PAM and other security solutions. Today, I think that the context of privilege management feels disjointed; in the future, we will see it as deeply integrated with your endpoint detection, identity management, your SIEM – everything working together to make access decisions in real-time.
Another trend I think we will see is the democratisation of PAM. For quite some time, privilege management has been reserved for very large organisations, mainly due to the complexity and high cost of legacy vendors. That said, privilege access management needs to happen at every single organization, regardless of size. In the near future, every organisation, will put into practice least privilege like they do today with anti-virus and firewalls.
Lastly, the wild card is all things artificial intelligence. I believe AI will be an outcome changer in access management because it can be a decision support tool for better access decisions, as well as a new “type” of user requiring access to systems – I think we are just beginning to scratch the surface of what that means.
What’s your advice for CISOs evaluating PAM solutions?
Start by thinking about your actual use cases instead of just the vendor’s list of features. Gather your team, and go through the real use cases when a user needs elevated access. Especially don’t think about IT administrators only. Remember the accounting staff who needs to update QuickBooks or the engineer who needs to run AutoCAD or other legacy software that requires privilege access.
Next, be honest about your operational maturity within your organization. If you do not have a security team, stay away from solutions that want those efforts to be included in full time. Many organizations buy enterprise PAM solutions only to see it sit unused in their environment because it was too complicated to implement correctly or maintain once implemented.
Test everything yourself. What I mean by testing is to actually get the opportunity to test, rather than just watching a demo. Have a trial format, and let your users do their job. Then figure out what broke, what confused them, and what worked fine. At the end of the day, the best PAM offering is going to be the one that your team will use daily and does not require full-time headcount to maintain.
Think about the vendor culture as well. Are they responsive to your questions? Do they understand your industry and operational environment? Security offerings are going to become part of your infrastructure for years, so it is essential to be able to work with people whom you trust and who understand your business.
And finally, think about the total cost of ownership vs just the license fees. A non-expensive offering that requires considerable customisation and support will cost you more than a user-friendly offering that will cost you more initially. Also consider implementation time, training, continuing support and the opportunity cost of your team and time.
The goal isn’t to buy the most advanced PAM solution on the market. The goal is to implement least privilege in a way that actually improves your security posture without making your users’ lives miserable. Sometimes the simplest solution is the best solution.


