惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

美团技术团队
Blog — PlanetScale
Blog — PlanetScale
阮一峰的网络日志
阮一峰的网络日志
M
MIT News - Artificial intelligence
月光博客
月光博客
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
U
Unit 42
博客园_首页
WordPress大学
WordPress大学
H
Hackread – Cybersecurity News, Data Breaches, AI and More
J
Java Code Geeks
F
Fortinet All Blogs
腾讯CDC
罗磊的独立博客
IT之家
IT之家
I
InfoQ
V
V2EX
博客园 - 叶小钗
A
About on SuperTechFans
Y
Y Combinator Blog
C
Check Point Blog
量子位
Martin Fowler
Martin Fowler
Vercel News
Vercel News

informationweek

2026 tech company layoffs InformationWeek Podcast: CTOs on using AI in regulated spaces How top CIOs are measuring the real ROI of IT automation What AI must learn from Roosevelt, conservation and 1929 Experian's chief innovation officer gleans AI gains with startup collab ETS CIO on competing with AI startups 'running with scissors' Before the next VMware: How CIOs prepare for vendor shocks The strategic alignment powering cyber-resilient organizations The AI infrastructure bottleneck is becoming a CIO problem InformationWeek Podcast: CTOs on reining in rogue AI agents Workplace equity in the age of AI Why and how to implement an AI asset rationalization strategy Why companies are shifting toward private AI models AI agents in automation: When to build, when to buy Navan CTO AI on trial: The Workday case that CIOs can The AI infrastructure boom is coming for enterprise budgets How CIOs can manage LLM costs: A practical guide What CIOs miss when buying vertical SaaS software InformationWeek Podcast: How CTOs balance AI and their teams Whirlpool, Duke Energy, Cleveland Clinic CIOs on scaling AI Where CIOs get stuck rebuilding the enterprise: What 'Rewired' reveals As AI makes projects harder to track, will CIOs need new controls? Why disaster recovery plans fail in geopolitical crises A silent erosion of enterprise AI by data poisoning Priceline CTO prioritizes engineers able to 'hold a room and a roadmap' InformationWeek Podcast: When CTOs need to restart IT projects Wayfair CTO maps agentic path across digital and brick-and-mortar commerce The AI contract gaps the Google-Pentagon deal just made visible Non-human identity sprawl is agentic AI's real risk
Poor UX undermines security policies, says Texas A&M Univ...
Kelsey Ziser · 2026-06-12 · via informationweek

Vince Kellen, CIO, Texas A&M University System

Courtesy Texas A&M University System

As users face a growing number of authentication prompts, security checks and compliance requirements, organizations need to pay more attention to the friction — and security risks — those safeguards can create.

That's the view of Texas A&M University System CIO Vince Kellen, who argues that implementing high-security protocols at the expense of usability and user experience no longer serves as an effective cybersecurity strategy. 

The challenge, he explained, is protecting users without creating so much friction that they look for ways around security controls. 

"Unless the [user] experience is wonderful, you can't have high security," Kellen said, in an interview with InformationWeek during the recent Cisco Live event in Las Vegas. 

Without achieving both high security and high visibility into the network, together with a seamless user experience, "the user will invent ways around you," he added.

Related:How AI is changing the breadth of cybersecurity roles

Why users bypass security controls 

Kellen pointed to multifactor authentication as one area where users are becoming frustrated with the hoops they have to jump through to access their accounts.

"You go to sites, and it's not just two-factor authentication — in some cases, it's four or five," he said. Layering multiple security technologies without considering the user experience can complicate cybersecurity programs and diminish their effectiveness. 

That concern also affects how Kellen views zero-trust architectures, which he described as a critical part of his security strategy for Texas A&M University System. The network he oversees includes 12 universities and eight state agencies — each with its own CIO. 

The key components of zero trust security are access and action — who has access to applications, and what is happening on the network (the action), he explained. For example, by using real-time packet inspection for threat detection and software-defined networking, an organization could flag an instance in which a user is attempting to share private data. This approach also speeds up response time to potential security threats.

"The network will say, 'OK, Vince, it looks like you're transmitting HIPAA data. We're going to immediately start to deploy real-time policy around your flows and your computer to redirect and change this,'" Kellen said.

The goal is to move more of the enforcement into the technology itself, he said — rather than depend on users to recognize every risk or make the correct security decision. 

AI agents aren't a special security case

Kellen applies a similar view to securing agentic AI. He said he doesn't "fret about agents" but views them in the same way as securing human users. 

Related:Cisco's Jeetu Patel on overcoming the 'AI trust deficit'

"I try not to get terribly freaked out just because the thing is called an agent," Kellen said. 

For Kellen, securing agentic AI builds on many of the same principles CIOs already apply to users and devices. Agents still need identity, visibility, behavioral monitoring, and policy enforcement. 

He added that he does worry about "semantic drift" — models that gradually diverge from their intended behavior — and what he called "semantic malfeasance," agents that act contrary to their intended purpose.  

Behavioral monitoring offers one way to identify agent or model drift, Kellen said, noting that organizations have historically applied such monitoring to users and devices. 

When it comes to encouraging behavioral changes in humans, Kellen said that cybersecurity trainings are useful for nudging users to comply with security policies, but training cannot carry the full burden of cybersecurity. 

"The technical controls have to win," Kellen said. 

Users might chastise themselves for falling for a phishing attempt, but humans are naturally trusting by nature, he pointed out. As a result, strong cybersecurity policy and technologies are needed to compensate for human error.

Related:Anthropic's Mythos forces a rethink of vulnerability management

Technical controls also perform better when they're "as invisible to the user as possible," so measures like biometrics can increase usability. 

But, Kellen added, "we're still many years away from a real seamless [security] experience."

About the Author

Kelsey Ziser

Senior Editor, InformationWeek

Kelsey Ziser is a senior editor at InformationWeek, where she covers C-suite dynamics, data strategies and the evolving cybersecurity threat landscape. 

Kelsey also oversees the publication's IT Leaders Fast-5 column, which brings peer insights to IT professionals, and the tech layoffs tracker. She has been with InformationWeek since September 2025. 

Before joining InformationWeek, she spent nine years at sister publication Light Reading, reporting on a broad range of topics including smartphones and devices, AI, satellite connectivity and enterprise networking. Kelsey has a Bronze Regional Azbee Award in the Technical Article category. Outside of work, she enjoys reading four (or 12) books at once, watching movies about space travel, crafting and tending to an ever-growing collection of houseplants. Kelsey has a bachelor's degree in journalism and mass communication from UNC-Chapel Hill and is based in Raleigh, N.C. She can be reached at [email protected] or on LinkedIn