It is essential to regain control over the visibility of one’s risk exposure.

The InCyber Forum took place in Lille from March 31st to April 2nd, 2026, and Global Security Mag discussed with Bernard Montel, Field CTO EMEA at Tenable.

Bernard Montel
Tenable

Global Security Mag: can you introduce yourself and tell us how your professional background led you to your current role?

Bernard Montel: I am Field CTO EMEA at Tenable, where I support organizations in understanding and managing their exposure to cyber risk, particularly in increasingly complex cloud and hybrid environments.

With over 25 years of experience in cybersecurity, I have developed expertise across key areas such as vulnerability management, cryptography, identity and access management, and security operations. My career has led me to hold both technical and strategic roles, allowing me to build a comprehensive view of security challenges, from traditional infrastructure to modern cloud architectures.

Before joining Tenable, I was Technical Director EMEA at RSA, where I worked on threat detection and response challenges, supporting large and mid-sized organizations in implementing cybersecurity best practices.

Today, my role is to help companies better understand their cyber resilience and secure increasingly interconnected ecosystems, particularly with the rise of artificial intelligence. I also actively contribute to raising awareness of these topics through speaking engagements and publications on current threats, risk management, and cyber exposure.

Global Security Mag: what will be your focus at the InCyber Forum (FIC) 2026?

Bernard Montel: we highlight the new challenges related to the rise of artificial intelligence and the rapid transformation of digital infrastructures.

We discuss in particular the growing importance of non-human identities, such as AI agents or service accounts, which are redefining attack surfaces and making access management more complex. Today, these identities even represent a higher level of risk than human users 52% versus 37% which marks a real paradigm shift.

We also address risks related to cloud environments, software supply chains, and the infrastructures supporting Europe’s ambitions in AI, in a context where digital dependencies are becoming increasingly difficult to map.

In this context, we present our latest innovation, Tenable Hexa AI, an agentic AI engine integrated into Tenable One, which enables the automation of security workflows and transforms exposure insights into concrete actions.
Faced with a rapidly expanding attack surface and growing environmental complexity, the challenge is now to move from a reactive posture to a proactive and automated approach. The goal is to enable organizations to continuously reduce their exposure at the speed of AI, while giving security teams more time to focus on strategic priorities.

Global Security Mag: what are the strengths of the solutions you will present on this occasion?

Bernard Montel: Tenable’s solutions stand out for their ability to provide a unified and contextualized view of risk exposure, covering vulnerabilities, identities, misconfigurations, and now AI systems.

In increasingly complex environments, it becomes essential to understand digital dependencies between assets, users, services, and automated workflows. This understanding makes it possible to move beyond an isolated approach to security.
Our technologies do not just identify vulnerabilities: they reveal potential attack paths, including the most hidden ones, by correlating different types of risks across cloud and hybrid environments.

With the integration of Tenable Hexa AI, we are taking a new step forward. The goal is no longer just to analyze exposure, but to transform it into concrete, orchestrated actions. Through an agentic approach, we automate security workflows, prioritize critical risks, and accelerate remediation at the enterprise scale.
This enables teams to move from a reactive approach to a proactive and continuous risk reduction strategy, while improving operational efficiency in the face of an ever-expanding attack surface.

Global Security Mag: this year, the InCyber Forum will focus on “Mastering our digital dependencies.” What is your analysis of this topic?

Bernard Montel: the issue of digital dependencies is now central. Organizations rely on increasingly broad ecosystems that include cloud services, open-source components, and more and more artificial intelligence systems. Before we’ve really managed to get a handle on this, we’ve added AI to the mix. AI systems do not operate in isolation, they are built on layers of third-party code, open-source packages, external integrations, and access to providers. That creates another set of dependencies that can quietly widen risk.

The challenge is that these dependencies are often poorly mapped and lack visibility, creating security blind spots.

Despite the adoption of advanced technologies, many attacks still exploit basic weaknesses such as known vulnerabilities or misconfigurations. And this is where AI is creating addition risk - not in new or novel attacks but by the introduction of speed, automating some of the more manual elements of an attack and allowing threat actors to move at the speed of AI.

Global Security Mag: how do your solutions address this issue?

Bernard Montel: when we talk about dependencies we need to link those digital assets together. Having first the full map and visibility of the entire attack surface to connect the dots between what is at risk and whether there is an attack path that a threat attacker could use to compromise systems to extract data or take systems offline.

Our solutions are specifically designed to make these dependencies visible and understandable. We enable organizations to map their environments, identify critical vulnerabilities, and understand how they can be exploited within complex attack chains.
This includes analyzing cloud environments, human and non-human identities, as well as software dependencies, a key point when considering that 86% of organizations today use third-party components containing critical vulnerabilities.

The objective is to help security teams prioritize risks effectively and reduce real attack surfaces, moving from an isolated vulnerability approach to a global and contextualized view of exposure.

Global Security Mag: how should technologies (AI / Quantum, etc.) evolve to help master digital dependencies?

Bernard Montel: Technologies such as AI must evolve toward greater transparency and applicability, in order to better understand the interactions between the different components of a system.

AI can also play a key role in analyzing complex environments, helping to detect correlations or attack paths that would be difficult to identify manually. However, these technologies must not overshadow the essentials: mastering the fundamentals. Without proper security hygiene, even the most advanced tools will not be sufficient to reduce risk.

Regarding quantum, the challenges are more medium-term, particularly around cryptography, but they also fit within this same logic of anticipating future technological dependencies. Organisations need to be able to review their crypto level, including how it expands their attack surface, to identify those areas that need to be migrated to the new generation of PQC algorithm. Like all domains, this should be considered as a potential vulnerability and managed proactively.

Global Security Mag: what message would you like to convey to CISOs, DPOs, CIOs, and cybersecurity leaders?

Bernard Montel: I believe it is essential to regain control over the visibility of one’s risk exposure. In environments where infrastructures, identities, and dependencies are multiplying, it is no longer enough to secure isolated assets: a global and coherent approach is required.
At the same time, it is crucial not to neglect the fundamentals. A large proportion of attacks still exploit known and avoidable vulnerabilities, highlighting the importance of strong security hygiene.

With the rise of artificial intelligence, organizations must also integrate these new uses into their strategies, particularly by taking into account non-human identities and the new attack surfaces they introduce.

More broadly, there needs to be a shift in mindset: cybersecurity should no longer be seen as a constraint, but as a true performance driver. This requires moving from a fragmented approach to a unified and preventive vision, focusing on the risks that truly matter to protect data, operations, and customer trust.
Finally, I encourage cybersecurity leaders to strengthen dialogue with business and executive teams. Exposure management is a concrete opportunity to position cybersecurity as a strategic issue, serving resilience, growth, and innovation.

Articles similaires

Interviews

8 June 2026

Cybersecurity for Good!

Proofpoint Innovation Center was launched last May in France (Neuilly-Sur-Seine), and Loïc (…)

Interviews

19 April 2026

It is essential to regain control over the visibility of one’s risk exposure.

The InCyber Forum took place in Lille from March 31st to April 2nd, 2026, and Global Security (…)

Interviews

11 April 2026

Backup is essential, but without recovery capability, it loses all its value.

InCyber Forum 2026 took place in Lille from March 31st to April 2nd, and Cyril VanAgt, VP (…)