Most Innovative Tech Leaders from USA 2026

Redefining Enterprise Security As They Evolve

Peter Bassey

Cyber Security Audit Leader

Bank of New York

Peter Bassey
Most Innovative Tech Leaders from USA 2026

Redefining Enterprise Security As They Evolve

Peter Bassey

Cyber Security Audit Leader

Bank of New York

Peter Bassey-Most Innovative Tech Leaders from USA 2026

Cybersecurity has entered an era where discovering vulnerabilities is no longer the hardest part. The harder question is knowing which exposures could actually harm the business when organisations cannot fix everything at once. Peter Bassey’s career has increasingly centred on that distinction. His experience across technology audit, cybersecurity risk management and governance, vulnerability management, penetration testing, threat hunting and continuous auditing has shaped a view of risk that moves beyond isolated controls toward attack paths, business impact and resilience. As a Cyber Security Audit Leader at BNY, Peter is helping advance that thinking through continuous cyber audit and risk assurance, while Faster Than Fixable extends the conversation to the wider cybersecurity community. TradeFlock speaks with Peter about rethinking cyber risk, prioritising what matters and building resilience for a threat landscape that is transforming at a rapid and exponential pace triggered by Artificial Intelligence.

Your career changed when you saw cybersecurity beyond isolated controls. What stayed with you?

One of the most defining periods of my career came more than 15 years ago, while a financial services company was preparing for significant growth and the possibility of becoming a public company. I was building the Technology Internal Audit function while also taking on responsibilities across cybersecurity, security operations and enterprise risk management. The work showed me something I had not fully appreciated before. Some of the biggest risk reductions did not come from traditional audit findings. They came when business and technology stakeholders worked together to understand a problem, develop a solution and change behaviour. That experience changed how I viewed both cybersecurity and internal audit. The real value was not simply identifying what was wrong. It was helping the organisation understand its exposure and make better decisions. I also began to see the importance of becoming a trusted adviser, someone who could connect business, technology, cybersecurity and risk rather than viewing each through a separate lens.

What is the central idea behind Faster Than Fixable?

The central idea came from recognising that organisations can no longer respond to cyber risk by trying to fix everything faster. AI is accelerating vulnerability discovery and exploitation, while cloud, APIs, third parties and increasingly interconnected environments continue expanding the attack surface. The volume and velocity of exposure can simply outpace the capacity to remediate it.

Faster Than Fixable argues for a different way of thinking. Vulnerability management needs to connect with threat intelligence, penetration testing, threat hunting, identity security, network security, SOC operations and business risk so organisations can understand which exposures actually matter. The objective is not to produce the largest list of vulnerabilities. It is to identify the attack paths that could lead to meaningful business harm and disrupt them. That shift also reflects a lesson I learned early in my career. Silos hide risk. Integration reveals it.

What makes your approach different from traditional vulnerability scoring?

I increasingly find myself asking a different question. Instead of asking, “How severe is this vulnerability?” I ask, “What can an attacker actually do with it?” Severity still matters, but it cannot tell us the whole story.

A medium-rated vulnerability could enable privilege escalation or provide a pathway into a critical business service, making it far more consequential than an isolated critical vulnerability protected by strong compensating controls. Attackers do not necessarily think in our categories. They look for combinations of weaknesses that create a viable route to an objective.

That is why I advocate an attack-path and exposure-based approach. We need to understand whether something is exploitable in our environment, whether threat actors are actively targeting it, what identities or assets it connects to, which business service could ultimately be affected and how quickly the exposure could become material. Prioritisation itself becomes a cybersecurity control when organisations cannot fix everything at the same speed it emerges.

Where do you see the biggest opportunity for cybersecurity innovation?

The biggest opportunity is connecting technologies and teams that have historically operated independently. Vulnerability management, threat intelligence, identity security, network security, SOC operations, penetration testing, cloud security, and business risk all generate valuable information, yet organisations often struggle to bring those perspectives together into a meaningful view of exposure.

I believe the next generation of cybersecurity will be defined by context, connectivity, continuous assurance and intelligent prioritisation. AI makes that opportunity even more important because it is changing the speed at which both attackers and defenders can operate. Organisations need to improve visibility and decision-making while continuously reassessing assumptions that may have been valid yesterday. Innovation, therefore, is not simply about introducing another security technology. It is about changing the way we think about the problem so we can produce better outcomes. More importantly, I think that educational institutions need to revamp their cyber curriculum to practically align with how cyber threats operate in the real world and how organisations are structured to address those threats. I hope that my book, Faster than Fixable, would be a good starting point for these conversations and can form the framework of an effective cyber curriculum and a guide for organisations to reduce silos and leverage cyber as a significant business enabler.

What advice would you give the next generation of cybersecurity leaders?

Understand the business, build connected teams and remain relentlessly curious. Technical expertise is essential, but credibility comes from explaining why a cyber exposure matters to a critical business service, customer trust, financial performance, or strategic objective. Business leaders need to know what decision has to be made, not simply what technical issue has been discovered. Strong cybersecurity leaders also create an environment where different perspectives can come together. The question should not be, “Who owns this finding?” It should be, “How do we collectively reduce this exposure?”  It is important that leaders start looking at metrics that really matter and tell the right story on actual cyber risk and exposure rather than just performance indicators.

"Stop asking how severe the vulnerability is. Start asking what an attacker can actually do with it."

The threat landscape will continue changing through AI, cloud, APIs, identity, supply chains and eventually technologies such as quantum computing. Experience alone will not be enough. Leaders will need intellectual humility, curiosity and the willingness to redesign approaches that worked yesterday but may not work tomorrow. Ultimately, cybersecurity leadership is about trust. People need to trust your judgment, your transparency and your ability to help the organisation adapt when conditions change.

My book, ‘Faster than Fixable ’, answers all these questions and more and is available on  www.amazon.com.