John Sapp
VP Information Security & CISO · Texas Mutual Insurance
Position Evolution
3 tracked across this operator's appearancesSame operator, on the record, on the same topic, at different points in time. Each delta below is anchored to verbatim transcript spans verified against source — no paraphrases. This is the alumni-graph moat: SemiAnalysis cannot reproduce this query because they don't have the speaker-stable corpus.
Quantifying security risk in financial terms
Hardenedconfidence 82%Sapp's financial quantification argument began as a vendor ROI justification in April 2026 and expanded by August 2026 into a board-level communication strategy covering all incident types. The broadening scope—from one vendor's value to enterprise-wide loss modeling—signals a more mature and institutionalized approach to security economics.
"if we looked at all the flaws that our developers remediated over the last, just take the last quarter and we put a dollar value to that, the cost per developer hour spent on that, now we come up with a number and I balance that against the spend that I put on something like a Chainguard, now the return on that investment is very visible."
Source on theCUBE ↗"I quantify risk in financial terms because if I can give them at least a range of what the probable losses will be, whether it's a technology incident or a cyber security incident, then they have an understanding of what our resiliency planning needs to be from an operational standpoint."
Source on theCUBE ↗AI risk governance and CISO role
Hardenedconfidence 78%In 2026-04, Sapp framed the CISO role as business-aligned AI enablement. By 2026-08, he had crystallized this into a concrete structural prescription—reordering GRC to CRG—showing growing conviction that governance frameworks themselves must be restructured. The shift matters because it moves from a cultural posture to an actionable governance model.
"we are in the AI era so it is all things AI is now our focus, this new digital era. And so when I think about it from the CISO perspective, we do have to be more connected to things that are in terms of how the business is creating value."
Source on theCUBE ↗"I like to say it's time for us to turn GRC around. We've talked about governance, risk, and compliance for years, right? Now it's time to turn it around to CRG, cyber risk governance, and that encompasses both technology and cyber security risk."
Source on theCUBE ↗Resilience versus redundancy distinction
Shiftedconfidence 75%Earlier, Sapp's framing centered on proactive security-by-design to prevent incidents. By the later appearance, he explicitly reframed the goal around response and recovery, distinguishing resilience from redundancy. This represents a meaningful shift in emphasis from prevention to operational continuity as the primary security objective.
"we want to make sure those things are secure by design and by default."
Source on theCUBE ↗"resiliency is not redundancy and I think sometimes people confuse the two. Resiliency is about your ability to respond and recover because it's not if, but when something is going to occur."
Source on theCUBE ↗All theCUBE appearances (3)
CrowdStrike Fal.Con 2024 | John B. Sapp | Texas Mutual Insurance
GUEST
RSAC Conference 2025 | John Sapp, Texas Mutual Insurance & Company
GUEST
Chainguard Assemble 2026 | John Sapp, Texas Mutual Insurance Company
GUEST · Texas Mutual Insurance · VP Information Security & CISO