This conversation cuts straight to the point.Jeffrey Spear, Tufin's CISO, brings a no-nonsense perspective shaped by years in app sec and regulated industries. He’s not interested in theory - he’s focused on what actually works when managing risk across hybrid, multi-cloud networks.We talked about why network security posture is now a board-level issue, how to close the DevOps-security gap, what real visibility looks like, and why AI should assist - not replace - security decisions. He also shared sharp takes on supply chain risk, partner accountability, and building a culture where security is default, not bolted on.Jeffrey is direct, practical, and clear. If you care about making policy enforceable in complex environments, this is one you'd like to read.
MSSP Alert: Let’s start with the big picture. There’s been a lot of talk lately about network security posture management becoming a board-level priority, especially in these messy hybrid, multi-cloud environments. From your vantage point, why is this area getting so much traction now? And how do you plan to shape Tufin’s response to that demand?
Jeffrey Spear: Absolutely. Network security posture management is gaining traction at the board level because the question at the top hasn’t changed. Boards are still looking at their CISO and asking, ‘Are we secure?’
What has changed is the environment we operate in. With the rise of hybrid and multi-cloud infrastructure, the complexity has increased dramatically. At the same time, regulations like the SEC disclosure rules, DORA, and others are pushing cybersecurity into the core of enterprise risk management. Boards are beginning to understand that this isn’t just an IT issue. They’re starting to appreciate the nuances and challenges that come with maintaining a secure, compliant environment across diverse and distributed infrastructure.At Tufin, we help organizations answer that question, "Are we secure" with clarity. We provide the visibility, control, and automation needed to understand and enforce policy across hybrid networks. Our focus is on enabling segmentation strategies that reduce risk, support zero trust, and help meet evolving regulatory obligations. We see our role not just in operations, but in helping CISOs communicate with confidence about where their exposure lies and how it’s being managed.MSSP Alert:You’ve spent a lot of time in application security, especially in cloud-native setups. How do you see that experience translating into your new role? And where do you think the biggest gaps still are when it comes to aligning network security policies with what’s actually happening in DevOps or product pipelines?
Jeffrey Spear: Coming from an application security background, especially in cloud-native environments, has given me a strong appreciation for the pace and complexity of modern development pipelines. Security in that space has had to evolve rapidly to keep up - embedding into CI/CD workflows, aligning with infrastructure as code, and integrating early in the development process.That mindset directly informs my role at Tufin. One of the biggest gaps I continue to see is the disconnect between what is happening in DevOps and what is being enforced at the network layer. Developers are pushing changes quickly, deploying across hybrid, multi-cloud, and even GovCloud environments, often with minimal visibility from the network or security teams. At the same time, those teams are expected to enforce segmentation, manage exposure, and ensure compliance with frameworks like DORA, NIST, or FedRAMP - all without slowing delivery.Tufin is well positioned to bridge that gap. We help organizations translate intent into enforceable policy, tying it directly to real-world network configurations. That includes supporting complex environments with policy simulation, change automation, and audit-ready controls across traditional data centers, cloud-native stacks, and regulated cloud footprints. My focus is to continue bringing a DevSecOps mindset into network security so policy becomes a design input, not a post-deployment scramble.MSSP Alert:“Tufin’s platform gives security teams what they’ve been missing - visibility and control that can adapt to evolving needs and evolving networks.” Visibility sounds great in theory, but every CISO knows it’s hard to measure. When you say “visibility and control,” what does that actually look like in practice? Are there specific KPIs or signals you’ll be watching to track progress?
Jeffrey Spear: You’re right. Visibility sounds great in theory, but it only matters if it drives outcomes. For me, visibility means being able to answer a few critical questions with confidence: What systems can communicate? Who approved those paths? Are they still needed? Are we compliant? And what changed recently that might increase risk? Control means we can act on that information - whether that’s approving a change, enforcing segmentation, or rolling back risky access.At Tufin, we bring those two elements together by mapping policy intent to actual network behavior across hybrid, multi-cloud, and on-premise environments. That gives security teams a central, policy-aware view of connectivity, and the tools to automate, validate, and enforce access decisions in a way that aligns with compliance frameworks and internal risk standards.As for KPIs, I look at things like how quickly policy changes can be simulated and validated before they go live, how much risky or overly permissive access we help reduce, and how many policy violations are automatically detected and resolved. These are real, operational metrics that show whether visibility is working.From a zero trust perspective, we help teams measure how well they are progressing by mapping current access patterns to least privilege principles. Are users and workloads only accessing what they truly need? Is access constrained by environment, application, or business unit? Can we verify and enforce these boundaries continuously? If the answer to those questions improves over time, then you are moving forward on your zero trust journey, and we see it as our role to help accelerate that progress with clarity and control.MSSP Alert:Visibility is one thing - but how do you take that next step toward actual segmentation and policy enforcement, especially in a zero-trust model? What’s the risk of over-automating that process?
Jeffrey Spear: Visibility is just the beginning. To enforce segmentation in a zero trust model, organizations need the ability to translate intent into consistent policy across hybrid and cloud environments. At Tufin, we help bridge the gap between the CISO, who owns the responsibility, and the network operations team, who takes the action. Our platform gives both sides what they need. CISOs gain confidence that policies are being followed, and network teams get the tools to validate and enforce access without manual overhead.We also address drift. In complex environments, change is constant. Access patterns shift, and policies fall out of sync. Tufin makes it possible to detect that drift and bring the environment back into compliance quickly and reliably. Automation is important, but only when guided by context. Our goal is to enable safe, accountable automation that aligns operations with security outcomes.MSSP Alert:I want to ask you about AI. Tufin launched some pretty ambitious tools this year - TufinAI and TufinMate. From your perspective, what’s the right balance between leaning into AI to boost efficiency, and putting the right guardrails in place so you’re not making security decisions on autopilot?
Jeffrey Spear: AI has huge potential to boost efficiency, especially when it comes to parsing complex environments and reducing manual work. At Tufin, tools like TufinAI and TufinMate are designed to help teams understand policy intent faster, simulate changes, and surface insights that would otherwise take hours to uncover.But AI is not a substitute for accountability. Security decisions - especially those that affect access, segmentation, or compliance - still need human validation. The goal is not to replace the operator, but to elevate them. AI should help teams move faster and with more confidence, but with clear checks in place.We’re focused on making sure these tools support real workflows while respecting that risk decisions ultimately lie with people. That means building in transparency, auditability, and the ability to override or challenge recommendations. Efficiency matters - but so does trust. Trust comes from knowing that AI is working with you, not ahead of you.MSSP Alert:I’d love to get your forward-looking take. When you think about the next 12 to 24 months, what keeps you up at night? Are there any trends that you think are being underestimated?
Jeffrey Spear: What keeps me up at night is the growing risk around supply chain attacks. Whether it’s a compromised open source package, a vulnerable third-party integration, or a trusted vendor being exploited as an entry point, the attack surface is no longer just internal - it extends to everyone you do business with.What concerns me most is that these risks often go undetected until they’re already weaponized. Many organizations still treat third-party risk as a contract review process or an annual questionnaire. But attackers are targeting the blind spots between those controls - things like build pipelines, update channels, and the transitive dependencies buried deep in software stacks.At Tufin, we’re thinking hard about how to surface and contain that kind of risk. That includes validating not just direct connectivity, but inherited trust relationships across the network. We’re also focused on giving customers the ability to react quickly when something breaks down, whether that’s isolating a compromised zone, revoking access, or tracing exposure back to the source.I think the industry is starting to wake up to the scale of this problem, but the pace of response still lags behind the creativity of attackers. Over the next 12 to 24 months, making supply chain visibility and resilience a first-class security concern needs to become the norm, not the exception.MSSP Alert:Tufin’s partner strategy now spans MSSPs, solution integrators, and technology alliances, supported by enhanced deal registration, new portal tools, and certifications. As CISO, how will you engage and enable this diverse partner ecosystem to not only deploy Tufin securely at scale, but also uphold consistent security standards and trust across every channel?
Jeffrey Spear: Being in security for close to 20 years, I’ve learned the difference between a true partner and a transactional relationship. The best partners bring more than just delivery capacity. They bring perspective, accountability, and a shared commitment to doing things the right way.As CISO, I see our partner ecosystem as an extension of our own security program. Whether it’s an MSSP managing operations, a solution integrator deploying our platform, or a technology partner building integrations—they all contribute to the experience and trust our customers place in Tufin. My role is to make sure that trust is earned and maintained at every step.That means aligning on secure deployment practices, identity and access controls, incident response expectations, and compliance requirements. We’re embedding that guidance into partner enablement, certifications, and portal tools so partners are not just selling Tufin - they’re deploying and supporting it securely and consistently.The infrastructure is there with enhanced deal registration, training paths, and technical resources. My focus is on building lasting partnerships that reflect the same security standards we hold internally, and that customers can count on across every channel.”MSSP Alert:How do you ensure quality, security, and consistency across partners - especially when the tools are easy to adopt but hard to master?
Jeffrey Spear: Tools that are easy to adopt can create a false sense of confidence. Just because something is up and running doesn’t mean it’s being used correctly or securely. That’s where the real challenge lies - not just in adoption, but in mastery. To ensure quality, security, and consistency across our partners, we focus on three things: enablement, validation, and accountability. First, we make sure partners have access to clear, practical guidance on how to deploy and manage Tufin securely. That includes secure-by-default configurations, architecture best practices, and hands-on training.Second, we validate that knowledge through certifications and ongoing technical engagement. A certified partner should not only know how to install our platform, but also how to align it with segmentation goals, zero trust strategies, and compliance frameworks like DORA, ISO 27001, and SOC 2. These frameworks demand traceability, access controls, and ongoing risk management, all of which rely on partners executing to a high standard.Finally, we stay engaged. Whether through joint delivery, customer feedback loops, or incident postmortems, we keep a close eye on how the tools are being used in the field. If there’s a gap between capability and execution, we work together to close it.Security is not just about features. It’s about discipline and consistency. Our goal is to build a partner ecosystem that reflects that, no matter who is doing the work.
An In-Depth Guide to Network Security
Get essential knowledge and practical strategies to fortify your network security.
Suparna is the Senior Managing Editor for CyberRisk Alliance’s Channel Brands, including MSSP Alert and ChannelE2E. She manages content development, sharpens editorial workflows, and ensures storytelling is tightly aligned with audience needs. With a background in technology, media, and education, she combines strategic insight with creative execution.
LevelBlue’s Kory Daniels explains where CISOs are making progress, where resilience programs still fall short, and why AI threats and vendor risk require stronger governance.