IT Tech Pulse Exclusive Interview with Paul Forte, Chief Executive Officer of JupiterOne

Stay updated with us

Paul Forte, CEO of Jupiter One
🕧 18 min

Paul Forte, CEO of JupiterOne, explores why understanding connected systems, identities, and permissions is becoming critical to modern cybersecurity.


You came into cybersecurity from outside the industry after 25 years in leadership roles elsewhere. What did that outside-in vantage point teach you that a traditional security career path might have missed?

It taught me that the industry talks itself into thinking every new threat is unprecedented, when most of the time it’s a familiar pattern showing up in a new costume. I watched this exact anxiety play out with the internet, with Y2K, with big data. Each time, the reaction was the same: panic first, then a slow realization that the fix wasn’t some heroic new invention; it was getting serious about understanding what you actually had and how it was connected.

Coming in from outside, I didn’t inherit the industry’s instinct to treat security as a checklist problem. I came in asking business questions: what happens if this breaks, what does it touch, who’s exposed if it goes wrong. That’s a relationships question, not an asset question. A traditional security career teaches you to secure the thing in front of you. It doesn’t always teach you to ask what that thing is connected to, and why that connection is where the real risk lives.

From military service to CRO roles at SingleStore, Actifio, and IBM, to now leading JupiterOne, what capability has carried through every chapter and shaped how you now guide the company’s strategy?

The thing that’s carried through every one of those chapters is context. In the military, you don’t win by knowing where the enemy is standing right now; you win by understanding how they move, what they can reach, and what happens next. It’s the same discipline in enterprise tech and data. At SingleStore, at Actifio, at IBM, the hardest problems were never really about a single system in isolation. They were about how systems, data, and people interacted, and where the pressure points were when things got stressed.

That’s exactly the thesis JupiterOne was built on, six years before I got here, and it’s why I felt so at home walking in the door. Security has spent decades treating assets like a list. My whole career has been about understanding relationships, not lists. That’s the lens I bring to strategy here: don’t ask me what we have, ask me how it all connects, because that’s where the answer actually lives.

You’ve argued a regulated institution can pass every audit and still be completely exposed. Can you unpack why compliance and true security aren’t the same thing, and where that gap tends to hide?

Compliance frameworks- SOC 2, PCI DSS, DORA, NIS2, FFIEC- they all serve a real purpose. They create baseline discipline and force organizations to document controls and prove they’re operating. But they were built to verify that a control exists, not to understand how your environment actually behaves.

Here’s the gap: those frameworks look at assets individually. Is this system patched? Is that access reviewed? Does this control exist? They don’t ask how access to one system combines with an identity over here to create a pathway to something critical over there. Risk isn’t sitting inside any single asset. It’s emergent; it shows up in the relationships between things.

So you can have every lock on every door checked and signed off, and still have no idea that three of those doors connect to a hallway nobody mapped. That’s the gap. You can be one hundred percent compliant and one hundred percent exposed, at the same time, because compliance never asked the second question.

You talk about moving from ‘10,000 vulnerabilities’ to the 50 that matter because of what they connect to. How does JupiterOne help security teams reason about blast radius in an AI-accelerated threat landscape?

For a board, the number that matters isn’t how many vulnerabilities you have; it’s how many of them can actually get to something you care about. Ten thousand vulnerabilities sounds terrifying until you realize most of them are dead ends; nothing important is downstream of them. The fifty that matter are the ones with a path, through an identity, a permission, a connected system, to your most critical asset. That’s blast radius: not “is this one thing broken,” but “if this one thing breaks, how far does the damage travel.”

Think of it like a hospital thinking about infection control. You don’t treat every hallway in the building as equally dangerous. You care about which hallways connect to the ICU. AI has made this more urgent because it doesn’t stop at the first open door; it keeps going, testing what’s connected, what it can reach next, faster than any human attacker ever could. So the board-level question isn’t “how many vulnerabilities do we have,” it’s “do we know which fifty could actually reach the crown jewels, and have we closed those paths?” That’s a much smaller, much more answerable problem, and it’s the one JupiterOne is built to answer.

JupiterOne’s graph-native model maps relationships between identities,permissions, and assets rather than securing them in isolation. Why is that relationship-first view becoming essential as attack surfaces grow more interconnected?

Because attackers, and now AI models, don’t think in rows and columns. They think in paths. If you hand a security team a spreadsheet of assets, it tells you what you have. It doesn’t tell you how column A relates to column F, and that relationship is exactly what an attacker is looking for.

As environments get more interconnected- cloud, SaaS, AI agents with their own access and permissions- the number of possible relationships explodes. A relationship-first view isn’t a nice-to-have anymore; it’s the only way to keep pace, because the risk was never really in any single asset. It’s in how everything talks to everything else. If your tools can’t see that, you’re defending a list while the real exposure lives in the connections you can’t see.

With frameworks like DORA and FFIEC guidance pushing institutions from ‘prove you have controls’ toward ‘prove you understand your exposure,’ how is JupiterOne helping customers get ahead of that shift?

That shift is the whole ballgame, and honestly it’s overdue. “Prove you have controls” is a static, point-in-time exercise. “Prove you understand your exposure” is a continuous, dynamic one; it’s asking an institution to actually know how its environment behaves, not just that a policy exists on paper.

That’s the exact gap JupiterOne was built to close. Instead of assembling evidence on an audit schedule, we give teams a continuously updated, relationship-aware map of their environment, so when a regulator or a board asks “do you understand your exposure,” the answer isn’t “we believe so, give us three weeks to prove it.” It’s an answer they can query and see in real time. Regulators are catching up to something that’s always been true: a documented control and an implemented, understood one are not the same thing.

Looking to 2027, you’ve drawn parallels to the internet, cloud, and Y2K as historical patterns. What do those moments predict about how AI-driven exposure will reshape risk management for regulated industries?

Every one of those moments followed the same arc: new technology creates fear, fear drives urgent action, and that action builds the systems that eventually make the threat manageable. The internet didn’t destroy industries the way people feared; it reshaped them. Y2K didn’t cause the disaster people braced for, because the preparation actually worked. Cloud went from “who would ever trust their data to someone else’s servers” to the default operating model in about a decade.

AI-driven exposure is going to follow that same arc, just compressed. By 2027, I think regulated industries stop treating this as an emergency and start treating it as the new operating environment, the same way we did with cloud. The institutions that get there first will be the ones that used this moment to actually understand their environment instead of waiting for a federal program or a vendor to hand them certainty. Readiness, not access, is what separates the winners in every one of these cycles, and I expect the same to be true here.

For CISOs and Chief Risk Officers still thinking in terms of assets to protect, what’s the one mindset shift toward ‘systems of relationships’ you’d urge them to make starting today?

 Stop asking “is this asset protected” and start asking “in the context of everything it’s connected to, what does this asset enable?” For years we’ve framed risk around servers, databases, endpoints, applications, and asked if each one was locked down. That made sense when threats were slower and more contained. AI doesn’t see a checklist of assets; it sees a network of identities, permissions, data, and services, and it looks for paths, not single points of failure.

So the shift is this: you’re not defending a set of doors anymore; you’re defending the pathways between them. Understanding those pathways, how access propagates, how a low-risk system connects indirectly to something critical, is your security posture now. Start today by asking your team one question: can we clearly map how an attacker, or an AI acting like one, would move from any exposed entry point to our most critical assets? If the answer isn’t a confident yes, that’s where to start.

Thank you, Paul, for taking the time to share your insights with us.

Write to us [wasim.a@demandmediaagency.com] to learn more about our exclusive editorial packages and programmes.

About Paul Forte About JupiterOne

Paul Forte is CEO of JupiterOne, the AI-powered security platform helping organizations understand their environments as connected systems rather than lists of assets. He came to cybersecurity from outside the industry, with over 30 years of sales and leadership experience scaling companies, including as Chief Revenue Officer at SingleStore and President of Global Field Operations at Actifio (acquired by Google Cloud). He joined JupiterOne as CRO before stepping into the CEO role. A US Army veteran, Paul brings what he calls “foxhole leadership” to the job, a blend of military discipline and modern go-to-market process. He holds an MBA from the University of Michigan Ross School of Business. Outside of work, he’s an avid tennis player and a devoted dad.

JupiterOne is a cyber asset intelligence company built on a single idea: you cannot secure what you do not understand, and understanding means seeing the relationships between assets, not just the inventory. The platform maps how identities, systems, data, and access connect so organizations can see how risk actually moves through their environment, and which exposures matter most.

  • Wasim Attar manages ITTech Pulse, a digital e-magazine under Demand Media, delivering timely technology insights and trends. As a PR professional, he drives brand visibility through guest contributions, exclusive interviews, and strategic campaigns, positioning ITTech Pulse as a voice in technology.