From Cloud to AI: Building Security Programs That Scale
Published 04/24/2026
At RSAC Conference 2026, Sean Martin caught up with Rich Mogull at the Cloud Security Alliance (CSA) booth for a candid on-site conversation about where enterprise security programs stand today -- and what it actually takes to keep pace with AI. Mogull, who joined CSA as Chief Analyst in October 2025, brings a practitioner's instinct to a research-first organization. The result is a new membership model designed not just to produce guidance, but to help organizations act on it.
What Does the Cloud Security Alliance Actually Cover?
CSA is best known for cloud security, but Mogull is quick to point out that the organization operates across three distinct pillars: cloud, zero trust, and AI. The connection is not arbitrary. Zero trust principles emerged in large part as a response to cloud adoption, and AI workloads are predominantly cloud-native. Each pillar represents a transformational technology that security teams have had to absorb without a clear roadmap -- and that is precisely where CSA has tried to fill the gap.
"Our sweet spot is these transformational, disruptive technologies," Mogull explains. He traces his own journey back to 2009, when cloud was still a fringe concept, and notes that existing security practices rarely translate cleanly into new paradigms. The frameworks that work well for on-premises environments do not map neatly onto cloud-native architectures, and the same challenge is now repeating itself with AI. CSA's role, as Mogull sees it, is to get ahead of that curve through rigorous, practitioner-informed research.
What Is the AI Security Maturity Model and Why Does It Matter?
The AI Security Maturity Model gives enterprise security teams a structured lens for assessing and improving their AI security posture. Unlike generic capability frameworks, it is built around measurable outcomes, key performance indicators, and categories specific to AI environments -- including model security, AI infrastructure, agentic applications, MCP servers, and AI developer enablement. The model is currently in its final review phase after receiving more than 600 comments from 60 international reviewers.
Mogull designed the model as a practical companion to CSA's existing Cloud Security Maturity Model, which he also authored. The approach is consistent: define the journey, build in measurable KPIs, and make the outputs as automatable as possible so organizations can connect tools like cloud security posture management platforms directly to their maturity tracking. "My focus is always how do I make something a usable tool, not just an interesting piece of research," he says. The AI model extends that philosophy into a domain where practitioners often feel they are flying blind.
How Is CSA Helping Organizations Move From Research to Implementation?
Producing research is one thing. Helping organizations apply it is another. Mogull joined CSA in part because he recognized that gap firsthand -- spending years as an independent consultant helping clients implement the very frameworks CSA had produced. That model does not scale. So one of his primary mandates is to build scalable support structures directly into the membership program.
CSA's new Enterprise Membership tiers -- announced in March 2026 -- center on what Mogull calls the Operational Maturity Roadmap. Members begin with an onboarding assessment, then work with CSA analysts on a monthly basis to receive specific, structured guidance tied to their maturity level across cloud, AI, and zero trust. The program culminates in an annual progress report tracking measurable improvement against defined goals. "I want to deliver better outcomes," Mogull says. "Not just research on a shelf, but evidence that an organization has actually moved." The three-year arc runs from foundational through operationalization to external communications -- including support for completing STAR registry entries and the Consensus Assessment Initiative Questionnaire.
Watch the full Brand Spotlight conversation with Rich Mogull and explore the Cloud Security Alliance's research, maturity models, and membership programs. Connect with Rich Mogull on LinkedIn.
Unlock Cloud Security Insights
Subscribe to our newsletter for the latest expert trends and updates
Related Articles:
We are Fixing the Wrong Problem in Non-Human Identity Security
Published: 04/23/2026
How to Choose the Right AI Standard: A 7-Point Guide
Published: 04/22/2026
Software Supply Chain Security Needs an Upgrade
Published: 04/21/2026









