CDBA Research Seminar: Dave Chatterjee

Seminar Title: The CPD Framework: Governing Cybersecurity and Agentic AI Risk

Abstract: Cybersecurity and artificial intelligence governance are typically treated as separate disciplines — different owners, different frameworks, different audit cycles. This talk argues that the separation is itself a governance liability: both domains tend to fail for the same underlying reason, a gap between leadership commitment and operational discipline, rather than a shortage of tools, talent, or regulation.

The Commitment–Preparedness–Discipline (CPD) framework reframes both cybersecurity and AI governance as a single organizational capability, evaluating readiness across three interdependent dimensions: leadership culture and accountability (Commitment), technical controls and operational resilience (Preparedness), and execution rigor and continuous improvement (Discipline).

The argument is developed through two parallel cases. The first follows AgentDesk, an illustrative composite modeling a production agentic AI customer-service deployment handling 18,000 autonomous interactions daily, through six recurring AI governance failure modes — reward hacking, prompt injection, tool-access data exposure, policy hallucination, third-party integration risk, and automated-decision opacity — grounded in documented incidents, including a disclosed Microsoft Copilot data-exfiltration vulnerability (EchoLeak, CVE-2025-32711). The second revisits a composite healthcare data analytics engagement assessed under the CPD Governance Framework, which scored 68.3 / 100 overall, driven by a striking pillar-level divergence: 90% Commitment, 70% Preparedness, and just 30% Discipline.

Despite spanning different risk surfaces and regulatory regimes — HIPAA, NIST CSF, and ISO 27001 on one side; the EU AI Act, NIST AI RMF, and CFPB/FTC guidance on the other — both cases surface an identical Commitment–Discipline gap: strong intent, thin execution. The talk closes by proposing that governance maturity is a portable, domain-general institutional capability rather than a technology-specific outcome, with implications for how boards, regulators, and IT governance scholarship evaluate organizational readiness as cybersecurity and AI risk continue to converge.

Bio: A globally recognized authority on cybersecurity strategy, AI governance, and operational resilience, Dr. Chatterjee is Adjunct Associate Professor at Duke University’s Pratt School of Engineering and a former tenured faculty member at the University of Georgia. He is the creator of the CPD framework — an empirically grounded model that helps organizations translate cybersecurity and AI strategy into resilient execution under real-world operational pressure. He advises global enterprises and public-sector organizations on cybersecurity governance, AI risk management, and digital resilience, and his experience includes service on CISO SWAT teams and strategic advisory boards addressing complex cyber and AI-driven challenges.

Dr. Chatterjee is the author of Cybersecurity Readiness: A Holistic and High-Performance Approach and the Amazon-bestselling techno-thriller The DeepFake Conspiracy. He hosts the Cybersecurity Readiness Podcast and is featured on the RSA Conference Expert Portal.

Dr. Chatterjee was Editor-in-Chief of the Journal of Organizational Computing and Electronic Commerce, a Taylor & Francis international peer-reviewed research publication.

Photographs will be taken during this seminar and may be shared on social media. If you do not wish to appear, please notify tbs.research@tcd.ie.

Tickets

Additional Information