
Imprivata CEO Fran Rosch says AI tools let attackers automate phishing and find vulnerabilities faster. The old perimeter model is dead, and identity is the new control plane.
Fran Rosch has watched the math change. As CEO of Imprivata, a digital identity company serving hospitals, energy firms and other life-or-mission-critical industries, he sees AI compressing the time and skill an attacker needs to cause real damage.
In a Forbes article published this week, Rosch described a world where AI systems now automate reconnaissance, generate phishing campaigns that actually fool people and find vulnerabilities faster than human teams can patch them. Capabilities that once required a highly skilled adversary are now accessible to anyone with a subscription. The consequence is that cybersecurity has moved from the IT department to the CEO's desk.
"Modern AI systems dramatically reduce the time and expertise required to discover vulnerabilities, generate convincing phishing campaigns, automate reconnaissance and accelerate other stages of an attack," Rosch wrote.
The old model of perimeter defense – lock down the network, secure the applications, assume everything inside is safe – no longer works. Employees log in from coffee shops. Critical applications live across three cloud providers. Third-party vendors need direct system access. And AI agents now work alongside human employees, querying databases and executing workflows without a badge.
"The perimeter has dissolved," Rosch wrote. "Identity has become the new control plane."
Under that framework, every employee, contractor, partner, application and AI agent is an identity that must be governed. The challenge, Rosch said, is managing those identities at scale. A hospital might have thousands of human users and, soon, hundreds of AI agents pulling patient records. Without clear governance, those agents operate with broad permissions and limited oversight.
"Innovation without visibility inevitably creates risk," he wrote.
Rosch rejected the framing that CEOs must choose between speed and security. The two are not in tension, he argued. One depends on the other. Organizations that build governance into AI adoption from the start will move faster over time, not slower. They will not have to stop and retrofit controls after an incident forces the issue.
The payoff, he said, is trust. Customers, regulators and partners now expect companies to show that sensitive data is protected and that critical operations can continue even during an active attack. Resilience, Rosch wrote, is no longer measured by whether an incident happens.
"It is measured by how confidently an organization can continue to operate despite them," he said.
Rosch closed with a reframing of the question every CEO hears. The better question is not how fast the company can adopt the next technology. It is whether the foundation exists to let that innovation scale with confidence.
"Governance, resilience and trust won't determine how fast organizations can move," he wrote. "They will determine how far they can go."
Prepared with AlphaScala editorial tooling from the source reporting linked above. Indexable analysis may include a cited Alpha Score value. Publishing checks screen each story before release. Educational coverage, not personalized advice.