SecureITWorld (1)
Sign Up

We'll call you!

One of our agents will call you. Please enter your number below

JOIN US



Subscribe to our newsletter and receive notifications for FREE !





    By completing and submitting this form, you understand and agree to SecureITWorld processing your acquired contact information as described in our Privacy policy. You can also update your email preference or unsubscribe at any time.

    SecureITWorld (1)
    Sign Up

    JOIN US



    Subscribe to our newsletter and receive notifications for FREE !





      By completing and submitting this form, you understand and agree to SecureITWorld processing your acquired contact information as described in our Privacy policy. You can also update your email preference or unsubscribe at any time.

      Strengthening Enterprise AI Security with AI Action Governance: A Conversation with J.Paul Haynes, CEO at Cinchy

      J.Paul Haynes CEO at Cinchy

      Get ready to gain top-notch insights into the world of cybersecurity, tech, and beyond. This is what our interview series ExtraMile by SecureITWorld aims to meet. We host top leaders and innovators from all corners of the industry.

      So, for our latest session, we're absolutely thrilled to have J.Paul Haynes, CEO of Cinchy, a company helping organizations accelerate innovation through trusted access to data, systems, and AI. With more than 35 years of experience in technology leadership and cybersecurity, J.Paul brings expertise in building and scaling high-growth technology businesses.

      In this conversation, J.Paul discusses how Cinchy is approaching the growing intersection of AI, cybersecurity, and data governance. He also explains AI Action Governance, AI transparency, ecosystem collaboration, and the layers enterprises need to consider when building and scaling AI environments.

      Gain strategic takeaways from J.Paul on how to scale AI with confidence, not just speed. Dive in now...

      1. AI is changing the way organizations manage and govern data. As CEO of Cinchy, how are you adopting AI to make data access more secure, intelligent, and efficient for enterprises?

      J.Paul. Cinchy’s roots go back nearly a decade in enterprise data management. The challenge has always been giving applications secure access to systems of record. AI has made that problem exponentially more important because data is the fuel for these systems — and that data isn’t just sitting in databases. It’s spread across SharePoint, shared drives, email, and other enterprise systems. Most organizations simply aren’t comfortable giving an LLM unrestricted access to all of it, nor should they be.

      That’s the problem we’re tackling with our platform. Connect provides curated, governed access to the right enterprise data while preserving provenance and existing permissions. Our Govern solution adds runtime controls over what AI can access and do, including enforcing user entitlements, screening for sensitive information such as PII or MNPI, and requiring human approval for higher-risk decisions. Every action can be logged for traceability and accountability. Ultimately, if you want to trust an AI system to make decisions on behalf of your business, you first have to trust the data it is using and control how it can act on it. That’s where we see data management and AI governance converging.

      2. With Cinchy joining the AI Partnerships (AIP) Network, what's your perspective on ecosystem-driven collaboration helping enterprises overcome the complexity of deploying trusted data across applications and business processes?

      J.Paul. The complexity of enterprise AI deployment is daunting, and for the foreseeable future, there won’t be a one-stop solution. The problem is simply too broad for any one company to specialize in every aspect of AI security, governance, data access, and traceability. We fully expect to work alongside multiple technology and services providers in our customer environments. That’s what makes the AIP Network valuable: it brings together a trusted ecosystem of AI specialists, making it easier for us to collaborate and help enterprises assemble the capabilities they need to deploy AI securely and responsibly.

      3. Cinchy's PeriMind introduces the concept of AI Action Governance. How does this strategy differ from traditional AI governance, and why is runtime oversight becoming important?

      J.Paul. AI Action Governance is how we distinguish what PeriMind does from traditional AI governance. Traditional approaches largely focus on establishing policies, monitoring how AI systems behave and reporting on compliance so corrective action can be taken after the fact. PeriMind acts as a control plane, enforcing those policies at runtime, before an AI action is allowed to proceed.

      That distinction matters because once an AI system has taken an action, the horse is already out of the barn. Runtime governance keeps AI between the guardrails by enforcing data access and user privileges, preventing inappropriate exposure of sensitive information such as PII or MNPI, and requiring human approval for high-impact decisions. We still provide the reporting and traceability organizations expect from governance, but we add something increasingly important as AI becomes more autonomous: the ability to intervene before an inappropriate action happens.

      4. With the EU Act largely impacting enterprise expectations globally, how should organizations outside Europe, specifically in North America, adopt the growing emphasis on AI transparency, accountability, and governance?

      J.Paul. This is a question we hear often from customers. The absence of a North American equivalent to the EU AI Act doesn’t mean organizations here can afford to wait. Frameworks such as ISO/IEC 42001 and the NIST AI Risk Management Framework are already shaping expectations around transparency, accountability, and governance, while the EU AI Act has implications for any organization doing business in Europe.

      I expect we’ll also see these expectations increasingly driven by customers and supply chains. We saw a similar evolution with SOC 2, where demonstrating strong controls became a practical requirement for doing business even when certification wasn’t explicitly mandated by law. AI governance is likely to follow a similar path. Over time, demonstrating that your AI systems are responsibly governed may become a condition of winning (and keeping) enterprise customers. For North American organizations, the smart approach is to start building those capabilities now rather than waiting for regulation to force the issue.

      5. Most organizations usually think of the AI stack mainly in terms of models such as Claude, ChatGPT, or Gemini. What are the most crucial layers behind the model that enterprises need to consider when building a scalable and secure AI environment?

      J.Paul. Many organizations are in the AI assistant/co-work phase and are dabbling with their first few agentic trials. Even at this early adopter position, there are many elements that need to be considered. For example: you need tools to monitor what data sources you are pointing the AI tools at; you need tools to ensure LLM access is consistent with what user making the request is entitled to access; you need to track and programmatically flag, review and approve if you have PII or MNPI data leaving the organization; you need to log every single AI usage by user and impacted data; you probably also need to rate limit token usage and have some measure of token cost governance now called “tokenomics”; you need to maintain an inventory of all AI usage both company provisioned and sanctioned and shadow AI; you need to have a full inventory of what AI tools and what accesses they are granted maintained; and you AI business continuity plan needs to be developed, maintained and tested as the Mythos government stoppage has shown us. There is also the entire notion of cybersecurity resilience for your AI estate which is a distinct and new threat surface from the rest of the organization. Essentially you need to think of this as a production environment that needs to be viewed through a 24x7 production uptime lens where you build to RTOs and RPOs that are acceptable to the business.

      6. You've spent 15 ½ years at eSentire, spearheading the managed detection and response (MDR) model. What strategic experience from building and scaling cybersecurity businesses continues to shape your approach to leadership and innovation at Cinchy?

      J.Paul. eSentire and spearheading the MDR category was all about solving a very hard problem which turned out to be both disruptive to the installed MSSP market leaders, and in heresy to many enterprises. Just 10 years ago we would hear “you can’t block my traffic without permission” as a common refrain to our radical approach to the problem. In reality, we actually had to block traffic on the customer’s behalf because the turnaround time of 8+ hours to get approval was too risky. Today, 8 minutes is too risky, and the entire sector has to do this at a speed and efficacy which was unimaginable just 10 years ago. Building and scaling that business was about getting really good at solving a common problem and bringing a solution to that segment of the market who shared the problem. This then became the solution to the same problem in every industry. At eSentire, we started with mid-sized financial services firms including investment banks, broker dealers, large private equity, and asset managers. This group are often the tip of the spear in terms of adopting new technologies. Once we dominated that segment we then moved on to adjacent markets and eventually, most all markets. It’s a market entry approach that was made popular by SAP in the 80’s and turned into a playbook by technology marketing expert Geoffrey Moore. At Cinchy we have adapted the playbook to the nuances of AI (especially for speed and agility), but generally the principles still apply in this new frontier.

      7. Moving forward, how do you see the consolidation of AI, cybersecurity, and data governance in building the future of enterprise technology? In which areas do you see the major opportunity for organizations?

      J.Paul. We’re already seeing the lines blur between AI for cybersecurity and cybersecurity for AI. Platforms from companies like Microsoft and CrowdStrike increasingly use AI to detect and contain external threats, which is critical as both attack velocity and the attack surface grow.

      But there’s another dimension emerging: governing the behaviour of AI itself. Generative AI systems can drift, behave unpredictably and occasionally make very confident, very wrong decisions. As organizations move AI from experimentation into production, there is a significant opportunity to put runtime guardrails around these systems so business leaders can trust them to operate safely and reliably. That’s where Cinchy sees a major opportunity.

      The third piece is data. Everyone understands that data is the fuel for AI, but much of today’s enterprise data simply isn’t AI-ready. Waiting for years-long data cleanup projects isn’t realistic. The opportunity is to give AI governed access to the right data, establish provenance and permissions, and determine which information can be trusted without first having to fix everything. Bring those three capabilities together (AI, cybersecurity, and governed data), and you have the foundation for moving AI from promising experiments into trusted enterprise infrastructure.


      Discover More In-depth Interviews:

      Advancing Endpoint Data Protection with AI-Powered Data Classification: In Conversation with Hannaleena Pojanluoma, CEO at Jetico

      Identifying Security Gaps through Continuous Security Validation Ft. Daniel DeCloss, Founder at PlexTrac


      Cinchy Reviews & Recognitions


      Cinchy Reviews & Recognitions


      Explore our most viewed blogs

      • About Our Guest
      • About Company
      About Our Guest

      J.Paul Haynes

      J.Paul Haynes is CEO of Cinchy, a company helping enterprises secure, govern, and control AI interactions across data, systems, and applications. He also serves as an Advisor to eSentire, where as CEO and President he  helped scale the company into a global leader in Managed Detection and Response (MDR).

      A professional engineer and entrepreneur with more than 35 years of experience, J.Paul has built and led high-growth technology companies, working closely with growth capital and private equity partners to accelerate innovation and scale. He is a recognized authority on cybersecurity, AI, and technology leadership, regularly advising organizations across North America, Europe, and Asia.

      About Company

      Cinchy

      Cinchy helps organizations accelerate innovation through trusted access to data, systems and AI. Its AI Action Governance platform, PeriMind, enables enterprises to securely connect, govern and monitor AI systems as they interact with enterprise data and applications—providing the visibility, control and accountability organizations need to deploy AI with confidence. Trusted by leading financial institutions, government organizations and global enterprises, Cinchy is helping define the next phase of enterprise AI governance.






        By completing and submitting this form, you understand and agree to SecureITWorld processing your acquired contact information as described in our Privacy policy. You can also update your email preference or unsubscribe at any time.

        ExtraMile Video Series


        SecureITWorld (1)

        Contact Us

        For General Inquiries and Information:

        For Advertising and Partnerships: 


        Copyright © 2026 SecureITWorld . All rights reserved.

        Scroll to Top