CISO Dan Wilkins on a Mission-Driven Approach to Automation and Bot Governance

Dan Wilkins, CISO, Arizona Department of Economic Security

The explosion of automation and APIs has created a surge in non-human identities that now far outnumber humans in many systems. Dan Wilkins, CISO of the Arizona Department of Economic Security, said that effective governance begins with understanding your agency’s mission. Without this foundation, security teams risk chasing the wrong targets.

Wilkins described how rapid automation has shifted many tasks from people to bots and APIs, leading to overlooked legacy accounts and hidden identities.

He built a three-pronged approach tailored to public-sector realities. First, Wilkins prioritizes purpose-built audits focused on detecting specific characteristics of non-human identities. Second, he applies a validated “trust arena” for vendor onboarding, holding third parties to strict standards before granting access. Finally, he invests in people who understand how to use limited tools effectively to uncover blind spots.

“If you don’t have visibility on what’s going on, it’s almost impossible to identify where those threats are,” Wilkins said.

In this video interview with Information Security Media Group at Gartner Security & Risk Management Summit, Wilkins also discussed:

  • How purpose-built audits target the traits of automated and legacy accounts;
  • Why vendor access is granted only after meeting strict security benchmarks;
  • Why security investments focus on staff who can maximize available tools.

Wilkins is a cybersecurity veteran with more than 25 years of experience across the military, private and public sectors. Throughout his career, he has led multiple high-performing teams and developed strategies to prevent burnout, boost effectiveness and apply emerging technologies to advance organizational goals.


Source: bankinfosecurity.com