Left Arrow Icon

All articles

Customer Experience Now Depends on a Business-First CISO

Cresta News Desk
Published
August 10, 2026

Brian Fricke, CISO at AutoNation, argues that protecting CX starts with pricing security gaps in revenue terms, running security as an internal service that shapes customer-facing products from day one, and automating its own work first.

Credit: The Security Digest

Make CX Current News one of your go-to sources on Google

Google icon
Add CX Current News on Google
Quote Icon
These three processes generate this much revenue per day, and should you have an outage, within 24 hours you'll likely lose this amount. If I can't have that kind of conversation, no one sees the value.

Brian Fricke

Chief Information Security Officer

Brian Fricke

Chief Information Security Officer
|
AutoNation

Every customer interaction rides on a stack of digital processes: the online checkout, the service scheduler, the financing approval. When one goes down, the experience goes with it. When one is breached, trust follows. Cyber risk has turned more pervasive and more strategic, boards treat it as a leadership test, and security's oldest budget argument is now a customer experience problem.

Brian Fricke is Chief Information Security Officer at AutoNation, the largest automotive retailer in the United States, and a four-time CSO and CISO whose seats span City National Bank of Florida, BBVA USA, Bank OZK, and Military Sealift Command. A former active-duty Marine with an executive MBA in cybersecurity analytics, he has spent a career inside businesses where customer trust is the product.

"The only reason security teams have ever existed is to enable the business. We're here to secure it, contain incidents, and control access, but we only exist to support the business objectives and business value," Fricke says. At a retailer built on customer experience, that means protecting every interaction the business depends on.

Price the outage in customer terms

His method runs through business continuity data: map each line of business to the processes customers actually touch, quantify what they generate, and price every gap. "These are your critical processes. These three processes generate this much revenue per day, and should you have an outage, within 24 hours you'll likely lose this amount." The same frame carries harder news. "You can weave in that you're missing multifactor here, and yes, these processes have workarounds, but the likelihood of a breach is high because we don't have logs coming from that system."

The dollar figure opens the door. The full ledger runs past it. "You're understanding, from a risk perspective, what are my strategic, operational, reputational, compliance, and financial risks around technology," he says. In customer terms, that's the checkout that dies on a launch weekend, the service appointment lost to an outage, the breach disclosure that sends a loyal customer elsewhere. Revenue returns when the systems come back. Trust takes longer.

Skip the translation and security reads as a cost center. "If I just say I need a whole log management collection project, they ask why we're spending all this money. If I can't have that kind of conversation, no one sees the value." It's the shared language finance leaders now demand, and it takes range. "You have to talk technical to the technical teams, understand how technology can be abused, translate that into risk, and articulate why it's a priority to invest in."

In the room on day one

The operating model changes with the pitch. Most security teams live in reactionary firefighting, triaging requests and proving a blocker wasn't theirs, even as service operations turn proactive. A team stuck reacting either slows the launch or lets friction ship, and customers feel both. Rather than the department that blocks projects at the end, Fricke wants security running as an internal service organization that helps teams build customer-facing products correctly from day one. "We work with the project team early on and define the security requirements before they build the thing, so once they deploy, we're not saying here's a bunch of vulnerabilities and missing controls."

The leap is cultural as much as procedural, and specificity beats coverage. "Uplifting your whole security org from reactionary to proactively engaged can be a big leap. But becoming a truly security service oriented organization, that's the change that has to happen."

Automate your own house first

"What AI has really done is highlighted the accessibility of automation. The business says we want to use AI. Really, what you want is process automation." Security should be its own first customer. SOC decisioning, vendor due diligence, and access workflows can run through agentic tooling inside a layered defense for the agent era, with people on the last mile. "Humans should be doing more of that final review of the results."

The urgency is pace, because what the business wants to automate is the customer experience itself, from service scheduling to support conversations. "Security teams need to use those tools to automate their own stuff, so we can advise the business on automating their stuff. If we're just using manual stuff while the business runs faster than we do, that's not a good combination for success."

The scoreboard is acceleration

Enterprises scale AI faster than their oversight, and analysts warn security costs will shave the profit gains. His discipline is the baseline, the small-pilot habit applied to security's own work. "Pick one or two impactful processes. Baseline them so you know how long they take and how accurate they are. After you build the agentic thing, measure again in 30, 60, 90 days and make incremental changes," he says, the same coaching loop CX teams run.

Too much spend still chases headlines instead of evidence. "We're throwing a ton of money at AI, assuming everybody knows how to do it. People ask what headcount I can cut. That's not always the case. You might be gaining market share, compressing your five-year roadmap into three. It should be that you're accelerating the business in some measurable way."

In customer terms, that measure might be how confidently the business can stand up new experiences without importing new risk, or how far it can grow before incidents grow with it. The demonstration starts at home. "CISOs have to be the ones to show how it's done. Here's how it's working for us, and we're doing it. So let's scale that out to the business."