Tanium CTO Harman Kaur: Fix cyber hygiene before AI

Tanium CTO Harman Kaur: Fix cyber hygiene before AI

The Air Force cyber officer–turned–Tanium CTO on why patching, inventory and phishing drills are still important

Nicole Deslandes

September 4, 2026    9 Minutes Read


Before she became chief technology officer at Tanium, Kaur was assigned to a medical unit in the military with an inspection looming. Every computer had to be patched and inventoried, which meant people walking the wards with clipboards and stopping nurses to check that their machines were configured correctly.

“These people are just trying to do their rounds,” she recalls. It was an early lesson in the gap between the people who run security and the people who have to live with it — and in the fact that neither can do their job if the other can’t.

Fast-forward to 2026, and Kaur runs technology strategy and the AI roadmap at Tanium, the California-based endpoint management vendor whose platform the company says spans more than 36 million endpoints. She also still serves in a cyber intelligence unit in the U.S. Air Force.

Now, the dual vantage point as practitioner and vendor shapes how Kaur thinks about the current AI moment in cybersecurity.

Companies have spent the past few years demanding that every function “do something with AI.” But enterprise generative AI pilots are struggling to produce measurable return in many organizations. Meanwhile, IBM’s 2025 Cost of a Data Breach report found that one in five organizations had suffered a breach tied to “shadow AI” — tools employees adopted or built without IT’s knowledge.

Kaur’s argument is simply that the fundamentals — patching, asset inventory, identity, phishing drills — haven’t changed since the clipboard days, and she worries organizations will abandon them in a rush to “protect ourselves from AI.”

Over coffee, she talked with TechInformed about why patching cycles are stuck in the past, what a 10-person company gets right that a global enterprise struggles with and the “care and feeding” problem with AI apps built outside IT’s control.

You didn’t start out in technology. How did you get from the military to a cyber degree?

I had a bit of an interesting start to my career. It started in the military, and didn’t start in anything tech-related at all.

I thought I would join the military and it would be short-lived, and I’d go on to law school. I was studying a lot, and then I met a mentor, and six months before my graduation he said, “I think you should learn how computers work.” I don’t know why, but I walked back into my counselor’s office and said, “I think I want to switch majors.” She said, “You’re supposed to graduate.” I said, “I don’t know, something’s telling me I should just do this.”

I did that, and extended my time in school by another year and a half. Then, in the military, I was actually doing HR and operations work. I switched to computers and just kind of fell in love with technology, more in the sense of building things, which really fascinated me. Then I coincidentally moved into a cyber intel unit doing HR work. The unit was going through a transition of its mission, and my job was to bring in the right people for that transition. That is how I got introduced to Tanium, and how I got close to the cyber and intelligence mission in the military.

Even when I first applied to Tanium, I thought maybe it would take me some time to pivot — maybe I needed to think a bit more about whether this was really what I wanted. I actually applied for an HR role. I went to my interview, and it wasn’t an HR person doing the interview — it was one of their leaders on the federal team at the time. He started asking me technical questions, and I started engaging with him, humoring him. He said, “What are we doing?” And I said, “I just want to have fun.” I think he caught on that I didn’t just want to do HR. The right path for me was more on the cyber side, and that’s where I started my career.

How does your time in the military shape your thoughts today on cybersecurity?

I’ve been part of so many different types of units: aircraft maintenance units, medical units within hospitals, operations units that own all the pilots and planes. I’ve gotten perspective on how each of them needs and values cyber from their own lens.

I remember being in a medical unit with doctors and nurses, and all they care about is the safety and wellness of their patients. They couldn’t care less if a patch is applied; they don’t know the difference. They just want to make sure they can take care of a patient. That taught me early on to ask: how do I get a doctor to understand this in terms of “this will help you take care of a patient better”? Is what I’m doing? [Am I] going to help this person take care of a patient? Is it going to help planes take off, because that’s what a pilot cares about? Is it going to help turn wrenches on a machine, because that’s what a maintainer cares about?

I remember we had an inspection coming up. All systems had to be updated and inventoried, and people were walking around with clipboards, believe it or not, checking machines were set up a certain way. I remember asking the nurses so many questions, and thinking, “These people are just trying to do their rounds.” Then I thought more about it and realized: “I understand this person is also just trying to do their job, but they don’t understand how important this [inspection] feels to the people doing it right now. So how do we connect those worlds? Because obviously they can’t take care of patients if they can’t log into their machines, and their machines don’t work either.” I think it’s really helped me broker those conversations and find that balance.

How has AI changed cyber for you?

I’m still actually part of the military organization, so I get to see two sides: the practitioner side, and the side where I get to help build tools and engage with a lot of different organizations globally.

A lot has changed, and everyone talks about that. What I keep pointing out — and I think we’re forgetting — is that the fundamentals haven’t changed. Even back then, walking around with clipboards, what mattered was the hygiene of those machines — they had to be patched, we had to know all the machines in the hospital and everything plugged into it so we could protect it. Those fundamentals haven’t changed.

AI is adding a layer of complexity, but I worry we’ll abandon the things that will always stay core and true, just because we’ve got to “protect ourselves from AI.” It’s like leaving your door open and trying to figure out how to close the windows really fast.

So do you think people are getting too distracted by AI, or relying on it too much?

I’m not sure it’s distraction or over-reliance. I think we need a realistic, balanced conversation, because the data shows a lot of organizations are just throwing AI at things when the ROI isn’t quite there yet. We went through a cycle of boards demanding everyone implement AI, and now we need to scale that back and ask more thoughtful questions.

People also talk about the cost of AI — but how many things are we solving with AI that could just be solved with simple automation? It sounds cooler to say “I used AI to do this.”

I think we have to ground things in reality a bit more.

Is there a certain size of organization most at risk?

Risk isn’t just for large, shiny organizations. Every organization, whether you have 10 employees or 100,000, carries risk relative to its size. Smaller organizations aren’t unique in being exposed to this risk, and they’re very much exposed to it.

What tends to work in favor of smaller organizations is that they generally know who has access to what; that span of control is usually a lot tighter.

This helps, especially now, when one of the biggest problems everyone’s battling is span of control and who has access to what data, and what are they doing with it. If you’re a small organization, you might actually know the answers to those questions, but if you’re a really large global organization, you may have no idea and you have to rely on these tools.

How do you implement cyber hygiene yourself?

First and foremost, patching should be hands-free. It sometimes kills me that we’re still patching the way we were 10, 15 years ago. And patching doesn’t need to happen on a 30-day cycle, that’s just what was decided decades ago. Patching cycles can be compressed significantly.

The other thing is, a lot of organizations still don’t know what’s on their network. I think, how is AI going to help if you don’t even know what’s on your network? For us, it’s having constant awareness the moment something plugs into our network. Everything is inventoried, and we refresh that constantly, not on a weekly or monthly cycle.

Phishing is still a huge concern. We still run different phishing campaigns targeting internal employees, so there’s constant awareness. Yes, we’re all talking about AI and these cool things, but people are still texting and emailing saying “click this link, there’s a PTO request pending.” Just a phishing attempt. So we’re still doing those fundamental drills constantly.

Identity is another really common factor. We’re constantly evaluating tools to simplify identity and get a really holistic view of what everyone has access to, and whether they’re entitled to it.

What are your thoughts on how to keep on top of self-made AI applications when people bring them into the workplace?

That has a couple of layers. There’s the security risk, but the other interesting thing is: who maintains them? If I create an application my team starts relying on, and it’s not governed by IT, and I decide to leave — who knows the care and feeding of it, and every workflow that depends on it?

Internally, what we’ve done is set up a center-of-excellence AI team, part of our CIO’s team. Their job isn’t to tell people they can’t develop these applications — it’s to help maintain them so there’s longevity, so I’m not a single point of failure if I’ve built something my team relies on.

It also helps people see that a lot of people are developing similar things. There’s a lot of duplication across organizations. We all think we’re the only ones with a clever idea, and it turns out five other people had it too. So it helps avoid the same application or integration being built five different times.

Finally, how do you take your coffee?

An iced latte.

10 Leaders Defining the Future of Tech

Discover who’s setting the agenda for 2025.

VIEW LEADERS

10 Leaders Defining the Future of Tech

Discover who’s setting the agenda for 2025.

VIEW LEADERS