What does it actually look like when a single security leader runs a full program with a team of AI workers behind them? In this transcript, Frederick Lamartin, Fractional CISO and Security Advisor, walks through how he uses Axari in live client engagements: layering his own context and judgment onto out-of-the-box AI employees, accelerating a NIST Cybersecurity Framework maturity assessment, and operating the resulting roadmap through a Chief of Staff. It is a candid view of where the human stays in control and where the platform creates leverage.
The following is a transcript:
I’m a fractional CISO, so I work across multiple clients, industries, and environments. Most of them face the same challenge: they do not have the budget for a full-time CISO, and in many cases they also do not have the budget for dedicated full-time security staff.
The way I’ve been using Axari is with my own context, judgment, and accountability layered into the platform. I use it to increase visibility and create operational leverage that I would not normally have as a single team member.
What’s powerful is that it scales me in a way that traditional hiring often cannot. Even when you finally get approval for another headcount, you are usually onboarding a junior analyst who may take six months to a year before they fully understand the environment and the business context.
With Axari, you are starting with agents that already have core skills and benchmarked knowledge. Then you add your own organizational context and judgment on top of that, which gives you much more control over the output.
This is essentially the entry point into Axari. At the top left you have the Chief of Staff, which lets you operate across the platform without needing to manually interact with every individual employee or workflow. Underneath that, you have different AI employees with different core skill sets. Out of the box you get roles like Threat Analyst, GRC Reporting, Incident Response, Program Strategist, Vulnerability Analyst, and Executive Assistant.
I also created my own Security Awareness Specialist. I wanted someone with more content creation capability and stronger creative writing skills combined with the mindset of a security analyst. That flexibility has been really useful.
One of the ways I’m using the platform right now is with a client where I’m conducting a NIST Cybersecurity Framework assessment as part of onboarding. It’s essentially a maturity assessment across the six major categories and their related subcategories. The end result is a roadmap, and that roadmap becomes the foundation of the engagement and the long-term security program work I drive with the client.
Realistically, if I were doing all of that alone, there are limits to how much I could operationalize and sustain. With these AI employees, I can drive that roadmap much more effectively, as long as I’m still controlling the context and applying my own judgment to the outputs.
For example, I had already developed my own methodology and assessment approach, but I used Cole, the Program Strategist, to help generate the maturity assessment output structure. I could then feed my findings into that framework and use it to accelerate roadmap creation. Of course, none of that goes directly to the client without my review. The leadership team is still getting my judgment and accountability on top of the generated work.
And yes, technically you could do portions of this with standalone Claude agents as well. The difference with Axari is what happens after the roadmap is created. Once I lock in that roadmap, I can create channels where all of the different AI employees responsible for various parts of the program collaborate together around those initiatives. Because the platform integrates with both security tools and productivity tools, you effectively end up with a functioning AI security team.
From there, I operate primarily through the Chief of Staff. I can create responsibilities for employees, assign work across channels, and manage the roadmap operationally.
Another important point is flexibility. You start with a strong set of core employees out of the box, but if you want additional skill sets or specialized roles, you can create them yourself. You define the name, the role, the system prompt, the environmental context, and then attach the tools and skills that the employee needs to operate effectively.
Do you want platform access? Request it here: https://www.axari.ai/request-invite/
Frederick Lamartin is a virtual security advisor and Fractional CISO who helps EU and US companies build security programs that support business growth. After 10 years in the PwC network across the US, Germany, and his last role as security leader for PwC Sweden, he founded Fractional Fred Security where he brings security leadership and practical risk management to scaling organizations. Based in the Greater Vigo area, he combines deep cybersecurity experience with a business-first approach to making security a business enabler. Frederick is a graduate of the U.S. Naval Academy and George Washington University.