How Abacus Insights achieved faster, more consistent investigations, freeing its security team to focus on the strategic work that actually matters.
Bill Brown could have retired by now. A lot of his peers have. “I’m so glad I didn’t,” he says, “because I would have hated to miss this.”
As both CISO and CIO of Abacus Insights, a healthcare data company whose business depends on keeping sensitive information clean, governed, and secure, Brown has spent the past year rebuilding how his security organization works. The catalyst is the one every security leader is considering: AI. But Brown isn’t interested in the technology for its own sake. It’s in what the technology frees his people to do.
He says the same thing to everyone at Abacus: if you’re creating or using any digital content, you need a copilot riding along with you. He follows this himself, and not only at work. He has spent the last year training his new golden retriever puppy with the help of an AI assistant, which gives him advice on training methods, discipline, and even vet instructions. That instinct, AI as a constant companion to real work, sets the tone for a much larger change inside the security function.
If you’re creating or using any digital content, you need a copilot riding along with you.
Brown thinks about his team’s time in three categories: run, grow, and transform. Run is the keep the lights on work. Grow and transform are the strategic, higher-value work that actually moves the business.
The problem was that too much of his small, talented security team was stuck on run. Abacus operates lean, with a compact security group that also handles SOC escalations. The endless triage of alerts was consuming people who were capable of far more. That’s not just an efficiency problem. It’s a growth problem. Skilled analysts don’t want to spend their careers sorting noise.
Brown’s conclusion was straightforward.
We’re not going to hire any more SOC analysts. We’re going to put the people we have to use in other areas.
What convinced him wasn’t a feature list. It was a point of view. “What drew me to 7AI was the vision that AI agents would handle the ‘run’ work, the endless alert triage, so my team could focus on ‘grow and transform’ work,” Brown says. The platform could do the heavy lifting around the clock: correlating data, curating alerts, and taking on the work that had been pulling his team away from strategic priorities.
Beyond functioning as an AI SOC, 7AI brought a broader vision for how AI reshapes security operations, and a team with deep expertise across both cybersecurity and AI. It felt like a partner, not another vendor selling a point solution.
The implementation reinforced the choice. Rather than a single launch, 7AI introduced capabilities in measured steps. “That really helped our team gain trust as we go,” Brown says, “as opposed to a big bang where we’d all stand around asking whether the thing actually works.” For a security function in critical infrastructure, where the cost of being wrong is high, earning trust incrementally mattered more than moving fast.
Since implementing 7AI, we’ve changed how our security team operates, with people spending their time on strategic work instead of sorting through the noise.
The first wins were in triage. 7AI told the team which alerts deserved human eyes, so the analysts supporting escalations could stop sifting everything by hand. Then the work moved up the value chain, from telling the team what to look at to taking action itself. “The more agentic the platform gets,” Brown says, “the more it starts to actually take actions. That’s where it really starts to show value.”
As the run work lifted, people moved. One team member who once lived in the alert queue now spends his time strengthening the company’s endpoint security standards, work no one had been able to get to before. Another is building out the tooling requirements for the GovRAMP effort. On the security engineering side, a team lead is acting as a cloud architect, supporting a transformation project he’d never have had time for while managing the daily alert load.
Brown was deliberate about how he framed this change to his team. From day one, the message was that this wasn’t about cutting jobs or cutting costs. “We’re looking to have our teams do more. More of the transform and grow work, less of the run,” he says. Before anyone asked what was at risk, he wanted them to ask a different question.
Don’t think about doing the same with less. Think about what you can now do that you couldn’t before.
The team isn’t handing everything to the machine. “It’s not running on its own yet,” Brown notes. The analyst still verifies, trusting but checking, as the agents take on more. The direction is set, and the work that remains is the work that’s worth a person’s time and expertise. As Brown puts it, Human Work never goes away. The tools do the run work so his people can do more for their customers.
The bigger change at Abacus isn’t a faster SOC. It’s a different way of operating, and a different job for the people who lead it.
Governance is now at the center. With AI tools multiplying, Brown spends more than half his day orchestrating and governing AI activity, and managing the steady stream of “shadow AI” requests from across the company. Every request gets checked against what the business is actually trying to do, and against whether someone else has already asked for the same thing.
Some lines he won’t cross yet. Abacus isn’t letting agents run loose on employee desktops. The guardrails aren’t mature enough. And he’s increasingly focused on the data underneath. Years of company data sit in Slack, Confluence, and Jira with little taxonomy or organization, and AI is only as trustworthy as the data it works from. All of this is pulling Brown’s role back toward the CIO title. He describes the security leader’s function as a mullet: enforcer in the front, enabler in the back.
Come to me with a use case, not a tool.
Ask Brown where the SOC goes from here, and he’ll tell you a big transformation is coming. Security teams will become more proactive, getting ahead of threats rather than only reacting to them.
He already sees a preview outside security. In finance, agents now chain together the company’s core systems to handle the monthly close and produce board reports. The same kind of action taking is coming to the SOC, and it’s the change he’s most eager for.
His advice to a CISO a year behind him is practical: start with your biggest problem, and follow your team’s time. Wherever they’re spending the most hours running is where AI belongs first. And the role he thinks every company will soon invent? “Someone whose entire job is to walk the business and ask why AI isn’t being used yet, almost like a Chief AI Officer.” He’s also changed how he reads his own instincts. Early in his career, when something made him uncomfortable, he treated it as a warning to back away. With AI, he’s flipped it.
I’ve learned to look for the uncomfortable feelings. When something around AI makes me uneasy, that’s usually where the real opportunity is.
It’s the same lesson, scaled up, that’s reshaping his security organization. The discomfort of letting go of the old way is usually a sign that something better is on the other side. For Brown, that’s reason enough to not have retired.
Bill Brown joined 7AI’s Nate Burke and Yonatan Striem-Amit to talk through balancing innovation and risk, the lessons past IT revolutions hold for today’s CISOs, and how AI is reshaping security for sensitive healthcare data.