
Community blog
Community Spotlight: The CISO Is the Defensive Captain Now
Sherri Douville, CEO of Medigram and Chair of the Trustworthy Technology & Innovation Consortium (TTIC), just published a piece making a sharp argument: the CISO isn't a coach calling plays from the sideline anymore, they're a captain who has to operate on the field. Her line for it: "Configuration has stopped predicting behavior." Documenting what a system is supposed to do, the SOC 2 and HIPAA technical-safeguards way, answers a different question than whether it actually behaves correctly under everything production throws at it.
She uses Praxen and Observra as the concrete answer to that gap. Praxen's RAISE checks, domain limitation, knowledge-base balance, zero trust, supply-chain governance, adversarial testing, and continuous monitoring, verify an agent's behavior against what it's authorized to do, and Observra's runtime telemetry keeps that verification running after deployment instead of stopping at ship time. The proof point in her own stack: Medigram's clinical AI deployment, Darwin, posted the highest Praxen behavioral score recorded to date.
Check it out: The CISO Is the Defensive Captain Now, Not the Defensive Coach