Blog

banner-asset-med

Profile: Salaam Harris, CISO, CRICO/Risk Management, The Risk Management Foundation of the Harvard Medical Institutions

Salaam Harris Header

 

Salaam Harris’s interest in technology started long before it became his career. As a child, he was fascinated by understanding how things worked, taking apart electronics, experimenting with circuit boards, and tinkering with his first computer.

His professional path began in the U.S. Air Force, although not initially in technology. Salaam started as a fighter jet mechanic before an opportunity emerged to retrain in cyber operations supporting a reconnaissance intelligence unit. The transition allowed him to combine his longstanding interest in technology with the discipline and mission focused environment of the military. 

From there, Salaam continued developing his technical expertise through training and education while taking on roles with Raytheon and Northrop Grumman. At Northrop Grumman, his work included helping to secure training environments and simulators for the Navy. He later moved to South Shore Health, where he helped mature the cybersecurity program and build out its security operations capabilities. 

Those experiences eventually led Salaam to Dragonfly Therapeutics, where he was the first dedicated cybersecurity professional and had the opportunity to build a program from the ground up. It was an experience that prepared him well for the CISO role he holds today. 

Building With the Mission in Mind

When the opportunity arose for Salaam to step into a CISO position, the ability to shape a cybersecurity program around the needs of the organization appealed to him. 

“I like a challenge,” Salaam shares. “I like to make sure that I have the opportunity to develop a program and influence that program from the ground up, from strategy and governance to operations, resilience, and specifically the culture.” 

It is an approach heavily influenced by his military background. As Salaam advanced through the Air Force, he was given significant responsibility early in his career. Managing large budgets and working around multimillion dollar aircrafts taught him to consider how individual decisions could affect a much larger mission.

That perspective translates directly to cybersecurity. For Salaam, a security strategy cannot exist independently from the organization it protects. Priorities and investments need to connect back to what the business is ultimately trying to accomplish. 
The same is true for culture. Technology and processes can only go so far if employees do not understand why security matters. Salaam focuses on making cybersecurity relevant to people by connecting their individual actions to consequences they can understand.

Once employees understand that connection, Salaam sees them as an extension of the security team. He even has a name for them, calling them “cyber warriors.” 

Turning Cyber Risk Into Business Decisions

Today, Salaam’s responsibilities span the overall cybersecurity strategy and risk posture of the organization. But he views communicating that risk to executives and board members as an equally important part of the CISO role.

The goal is not to just report vulnerabilities or threats. It is to provide leadership with enough context to make informed decisions about the organization.

“A big part of my role is translating that information and that risk posture to our executive leadership team and our board members,” Salaam explains. “More importantly, it is making sure that they have the appropriate information to make those decisions.” 

That requires participation across the organization. Salaam believes the effectiveness of a cybersecurity program ultimately comes back to whether people understand what the security team is doing, why it matters, and how they can contribute.
 
Preparing for AI Rather Than Waiting

As cybersecurity priorities evolve, Salaam sees AI governance and security as one of the most pressing issues facing CISOs. Identity is particularly important as AI agents introduce an entirely new category of nonhuman identities into enterprise environments.

“We have to be thinking about them as another employee,” he explains. Security leaders need to consider what level of access an AI agent has and what actions it can take on behalf of the organization. 

Salaam does not believe the answer is to wait until the AI landscape becomes clearer. Organizations that take that approach risk falling behind. “If you’re not using AI in this day and age, you’re going to be left behind,” he says. “You’ve got to have guardrails, controls, policies, and governance in place, but you also have to make sure that you’re agile and can adjust and shift because this space is moving extremely quickly.” 

For Salaam, security should enable that adoption rather than stand in its way. The objective is to help the business use AI while creating enough structure to manage the risks that come with it.

Rethinking Identity

AI is also amplifying an identity challenge that was already becoming more complicated. Traditional environments were relatively contained, with identities and infrastructure largely residing on premises. Today, SaaS applications, cloud environments, and now AI agents have expanded where identities exist and what they are capable of doing.

“Identities are everywhere,” Salaam explains. “You have to make sure that you know where all these identities are.”

That begins with visibility and a comprehensive inventory, but it also requires understanding what those identities are actually doing. Salaam believes organizations need insight into whether an identity is actively performing tasks, what it can access, and whether accounts remain in the environment that should no longer be there. 

As AI agents become more autonomous, that visibility will become even more important. Organizations are no longer governing access exclusively for employees. They are increasingly responsible for understanding the permissions and activities of machines acting on their behalf.

Why People Still Matter

Even as AI becomes more capable, Salaam pushes back on the assumption that it will immediately reduce the need for cybersecurity professionals.

Security organizations already face limited resources while technology costs continue to increase. At the same time, security stacks are becoming larger and more complex, creating additional technologies that need to be implemented and operationalized.

AI adds another layer because organizations need people who can analyze what AI produces and oversee what agents are doing. When asked where he would invest if resources were unlimited, Salaam did not hesitate.

“It would 100% go towards people,” he shares. “You can go buy more technology, but who’s going to manage that technology? There is a balance to it, but you’re always going to need more people than technology.” 

In fact, Salaam believes the near term effect of AI could be the opposite of what some organizations expect. Rather than immediately reducing cybersecurity staffing needs, the speed of AI adoption and the complexity of governing it may require more resources as organizations learn how to manage the technology effectively. 

Putting People First

Salaam describes his leadership style as a blend of servant and transformational leadership, an approach shaped considerably by his military career and the leadership training he received throughout his years in the Air Force.

At its center is a straightforward principle that people come first. Transparency is also very important to him. Salaam wants team members to feel comfortable telling him when something is not working or even when they disagree with him.

“That psychological safety is extremely important within cybersecurity,” he explains. “I need people to be comfortable and willing to let me know if something isn’t working. We can always make adjustments, but if you don’t tell me, I won’t know.” 

That philosophy extends beyond his own team. Salaam regularly mentors people outside his organization. For him, giving that time back is a reflection of the support he received throughout his own career. “I wouldn’t be where I am right now without the people that helped me get to where I am,” he shares. “So I make sure that I always try to give that back to the community.” 

Across his career, the environments have changed considerably, from military intelligence and defense to healthcare and corporate cybersecurity. But the principles Salaam brings to each challenge have remained consistent. He is always focused on understanding the mission, building a culture where people understand their role in protecting it, and never losing sight of the people behind the technology.

 

    Subscribe

    Stay up to date with cyber security trends and more