The world demands connectivity. Business organizations need to handle growing pressure to protect what matters most. This has elevated the role of firms that help businesses strengthen their digital foundations and navigate emerging risks. Their value lies in enabling continuity, confidence, and prolonged growth. Also, the individuals who tackle this pressure have become influential. Their role involves shaping the cyber strategy, guiding decisions backed by seamless security, and nurturing trust across the organization. Eric Hlutke, CISO at Compass MSP, is the epitome of cyber excellence. His skill in anticipating challenges before they escalate reflects his command of and devotion to his work.
Beyond Monitoring
Early in the discussion, Eric Hlutke clears the myth about the mid-market security landscape: the real issue is architectural, not technological. Many providers assemble collections of tools and layer support services around them to create monitoring capabilities. This results in often fragmented operations and slower response times when speed matters most.
He believes mid-sized organizations face enterprise-level threats without the resources to build enterprise-grade defenses. Existing solutions often swing between basic monitoring and overly complex frameworks designed for much larger enterprises.
He shares, “We build programs designed for specific use cases and industry verticals. That distinction matters, and it matters most when something goes wrong.”
Compass MSP was built to bridge that divide. Through its Core cybersecurity offering and integrated vCISO practice, the company delivers structured, outcome-driven programs tailored to real business needs. Whether supporting CMMC compliance or helping organizations assess AI-related risks, Compass MSP focuses on building practical, industry-specific security programs.
Tangibility in Results
Eric Hlutke believes theterm ‘enterprise-grade security’ has become overused because it is rarely defined in practical terms. While many providers make the claim, few explain how it translates into day-to-day operations, accountability, or measurable outcomes.
At Compass MSP, he says, the focus is on building structured security programs rather than offering a collection of features. Its Core and Apex Security offerings are designed around continuous detection, investigation, response, and improvement. Clients have defined coverage, measurable SLAs, and a security posture that is tracked over time, versus assessed once and filed away in the digital ether.
The company’s vCISO model adds a strategic dimension. Each client is paired with a dedicated security leader who helps shape priorities, communicate risks, and drive long-term progress. Compass MSP has also extended this approach to emerging areas such as AI risk management, giving mid-market organizations access to capabilities often reserved for larger enterprises.
He shares, “CMMC is the clearest proof point. Achieving Cybersecurity Maturity Model Certification is not a marketing exercise; it is a rigorous, third-party validated assessment of 110 security practices across 14 security domains.”
The strongest validation comes from client outcomes. He points to successful CMMC engagements, including perfect audit scores after CMMC readiness engagements, as evidence that effective security is built on disciplined execution, not marketing claims.
Resilience at Scale
Eric Hlutke believes that while the implementation may scale down for smaller organizations, the standards should not. Having worked in high-scale environments where speed and resilience are non-negotiable, he views them as operational requirements.
He notes that the volume of cyber threats does not discriminate by company size. A mid-market business can be just as attractive a target as a large enterprise, particularly if it sits within a broader supply chain or handles sensitive information. Yet many smaller organizations are expected to operate with fewer resources and less support.
Eric shares, “That reality shaped how we built our delivery model. Detection latency targets, response time SLAs, automated containment capabilities, these are the outcomes that are defined and measured across our client base, not just for enterprise accounts.”
The company emphasizes measurable outcomes such as response-time commitments, rapid threat detection, and automated workflows that reduce reliance on manual intervention. According to him, the goal is simple: bring the discipline, consistency, and operational rigor of enterprise security to organizations that have been conventionally asked to settle for less.
Placing Leadership Right
Looking back on more than two decades in the industry, Eric believes the biggest barrier to building effective cybersecurity programs is leadership alignment. But not for the reasons many assume.
He notes that the conversation often centers on whether security leaders can communicate risk effectively to boards and executive teams. In his experience, this is rarely the real issue. The more fundamental challenge is whether an organization has genuinely decided to treat security as a business priority rather than a compliance obligation.
When security is viewed primarily through a compliance lens, investments tend to be reactive and limited.
He states, “The CISO’s role becomes defending the status quo rather than building capability to address risk. Technology decisions get driven by checkbox requirements rather than a risk posture acceptance.”
The most successful organizations are those where leadership recognizes security as a core business function. Once that shift occurs, priorities become clearer. Investments become more purposeful. Security leaders gain the support and authority needed to build lasting capabilities rather than short-term fixes.
That belief continues to shape Compass MSP ’s approach. He envisions strategic advisory as a critical component of helping organizations align leadership, manage risk more effectively, and build stronger security programs gradually.
Outcome is the Focus
Eric emphasizes tool acquisition outpacing capability development. As he has worked across global enterprises and platform-scale environments, his experience has exposed him to this reality. He says further that Security teams at scale face constant pressure from vendors, from auditors, and from incident post-mortems to add greater and more complex controls. Each addition is individually defensible and has justifiable merit to add to the environment. The SIEM needed better log sources for higher fidelity alerts. The EDR needed a new behavioral analytics module to detect sophisticated bad actors. The identity platform needed privileged access management bolted on.
The resultant being an environment where the number of security tools exceeds the team’s ability to operate any of them with the needed competency.
He adds, “I have walked into many environments across financial services, consumer technology, and global manufacturing, where the security stack had 40 or 50 tools deployed, significant annual spend, and detection capability that was objectively worse than what a well-tuned stack of 12 or fewer tools would have delivered. The architectural complexity of the many tools was not protecting with efficiency; rather, it was complicating the operational model.”
Organizations that were successful in scaling effective programs had one thing in common: they defined what outcomes they were trying to produce before they selected technology, and they held themselves accountable to those measurable outcomes rather than to coverage checklists in a standard.
Disciplined organizations consolidate tools deliberately and stay vigilant about signal quality. They build their operating models first and let technology serve those models, rather than the reverse. Holding that line is hard, because much of the pressure to expand the stack is commercial: vendor partnership agreements and revenue models reward adding more products, not running fewer ones well. That incentive is exactly why many providers wrap a service desk around a sprawling collection of cybersecurity tools. Resisting it takes resilience, and that discipline is what keeps a program consistent over time.
Unified Approach
For Eric, the industry’s integration challenge has less to do with technology and more to do with how security services are delivered. While many providers promote unified platforms, the reality is often far more fragmented behind the scenes.
He points out that detection, investigation, and response are frequently handled by different teams, supported by different tools, and governed by separate processes. As a result, critical information can get lost in the transition. The issue is a lack of consistency. And in cybersecurity, even small delays can have significant consequences.
He adds, “The integration challenge is not technical at its core. The technical problems are largely solved, as there are mature SIEM’s, SOAR, and EDR platforms that can exchange telemetry and automate handoffs. The challenge is organizational and economic.”
According to Eric, true integration happens when ownership extends across the entire security lifecycle. Rather than treating each function as a standalone service, organizations need a model where teams operate with shared context, aligned objectives, and collective accountability for outcomes.
That mindset has influenced how Compass MSP approaches security operations. The company has built a coordinated framework that brings together monitoring, investigation, and response under a single operational structure. Each stage has clearly defined responsibilities, but the focus remains on maintaining momentum and reducing friction throughout the process.
Looking ahead, Eric believes automation and AI will further strengthen that model. As routine tasks become increasingly automated, security professionals can devote more attention to complex incidents that demand critical thinking and experience. In his view, the future of cybersecurity is about creating smarter, more connected operations that can respond with speed, consistency, and confidence.
Loop Closure
A closed-loop security system is defined by accountability. Every security event follows a clear path from detection to resolution, with insights from that process feeding back into stronger defenses over time. The goal is not simply to identify threats, but to ensure that every incident leads to measurable improvement.
He believes many security programs fall short because the process often ends with an alert, an investigation, or a ticket. Resolution may be documented, but the lessons learned are rarely integrated into future detection strategies. As a result, organizations remain vulnerable to variations of the same threat.
Compass MSP was built around a different philosophy. Every alert is tied to a predefined response path, and success is measured by verified outcomes rather than administrative closure. The team continuously evaluates whether existing controls would detect similar threats in the future and adjusts accordingly.
He also highlights the advantage of aligning IT and Security operations under a unified framework. When operational and security teams work from the same playbook, organizations can respond faster, reduce disruption, and restore normal operations more efficiently.
He adds, “The measurable outcomes that validate this are straightforward: mean time to detect, mean time to contain, recurrence rate of the same threat class across the client portfolio, and client risk score trajectory over time.”
Metrics such as detection speed, containment times, recurring threat patterns, and long-term risk reduction provide a clearer picture of security performance. In his view, the true test of a security program is whether it becomes stronger after each one.
Accountability Question
For Eric, the fragmentation seen across modern security operations is rooted far more in structure than in technology. Tool sprawl, he mentions, is simply a byproduct of deeper industry dynamics. He believes the security ecosystem has been built around incentives that rarely encourage integration. Vendors are rewarded for expanding their footprint. Service providers are often measured by coverage and retention. Compliance frameworks assess specific controls within defined boundaries. Individually, these approaches make sense. Collectively, they can create an environment where complexity grows faster than security effectiveness.
The larger issue, according to him, is responsibility. Many providers are responsible for delivering a product or service, but not necessarily for improving a client’s overall security posture. As a result, organizations often accumulate tools, reports, and processes without a clear way to measure whether risk is actually being reduced.
He adds, “It is the only structural change that actually addresses the fragmentation problem, because it creates real incentives to consolidate, integrate, and measure rather than to accumulate and obscure.”
In his view, meaningful progress begins when accountability shifts from activities to outcomes. That means defining success in terms of measurable security improvements rather than coverage metrics alone. It is a more demanding standard, but one that naturally drives greater integration, clearer ownership, and better decision-making.
Credibility Gap
The distinction has little to do with technical competence. The security leaders who earn business trust are often just as technically capable as those who remain operationally focused. The difference lies in their understanding of the business itself. He believes many security professionals spend years developing expertise in areas such as incident response, detection engineering, identity architecture, and vulnerability management. Those disciplines are essential. However, technical mastery alone does not automatically translate into organizational influence.
According to Eric, the leaders who bridge that gap develop a deep fluency in how their organizations create value, define risk, and make decisions. They understand not only how threats operate, but also how security outcomes affect revenue, regulatory exposure, insurance costs, shareholder interests, and long-term business objectives.
That perspective changes the conversation. Rather than discussing the strength of a security control, they explain how that control reduces the likelihood of a material business event. Rather than reporting coverage metrics, they connect security investments to measurable reductions in risk and operational impact.
He adds, “Not simplified language, but rather precise language tied to their world so they can understand. There is a difference between telling a board that the organization has “strong endpoint coverage” and telling them that lateral movement from an initial compromise would be detected and contained within a defined window, reducing the probability of a material data breach by a specific percentage, with a direct implication for cyber insurance terms and litigation exposure.”
They are able to translate security into the language of business without oversimplifying the underlying complexity. Those who develop that level of fluency gain credibility beyond the security function. They can operate comfortably in both the SOC and the boardroom. More importantly, they earn the authority to build programs that drive meaningful outcomes.
Ideal Architectural Program
The leadership shift from securing a single enterprise to delivering outcomes across multiple client environments comes down to one word: architecture.
Within a single organization, security leaders are expected to go deep. They build a detailed understanding of the business, the risks involved, and its operating environment. The objective is to create a program tailored to a specific set of needs.
In a managed services environment, however, the focus changes. Rather than solving challenges for one organization, leaders must design programs that can deliver consistent results across dozens or even hundreds of clients. The priority shifts from customization to repeatability.
There are some disciplines that work well inside an enterprise but can become obstacles at scale. Highly customized processes, relationship-driven workflows, and unique tool configurations often create inconsistency and make quality control more difficult. The goal is to establish programs that are robust by design.
Accountability evolves as well. In an enterprise, a security leader owns a single program. In a services model, accountability extends across an entire client portfolio. That requires standardized reporting, measurable outcomes, and a systematic approach to assessing risk and performance.
He believes the leaders who navigate this transition most successfully are those who develop a genuine interest in program architecture. They move beyond solving individual security problems and focus on building systems that deliver reliable, measurable outcomes at scale.
Integrating Digital Harmony
The most tangible and business-critical application of AI at Compass MSP is a core component of daily security operations. The company has embedded AI-driven orchestration and automation into its Security Operations Center (SOC), enabling faster, more consistent incident response at scale.
He explains that Compass MSP has significantly reduced manual, analyst-led processes by implementing automated response workflows that activate the moment a threat is detected. In the case of a phishing incident, for example, the system can automatically gather email metadata, validate indicators of compromise against threat intelligence sources, quarantine malicious messages, notify affected users, and generate investigation tickets. All this happens without waiting for human intervention.
When suspicious endpoint activity suggests lateral movement, predefined containment measures are triggered immediately, ensuring rapid response regardless of staffing availability. The outcome is a more resilient security operation driven by speed, consistency, and operational efficiency.
Beyond internal security operations, Compass MSP has also developed AI Security Assessments as a client-facing offering. According to Eric, organizations are embracing AI technologies at a pace that often outstrips the development of appropriate governance frameworks, risk controls, and data protection policies.
This assessment helps businesses scrutinize their AI adoption strategies, identify potential data exposure risks, uncover governance gaps, and prioritize remediation efforts based on measurable business impact.
At a broader level, he sticks to the point that truly impactful AI initiatives share three defining characteristics:
- They improve a clearly unequivocal business process
- Deliver tangible outcomes
- Have responsible ownership
In his view, AI deployment that cannot demonstrate those fundamentals remains experimental, regardless of how it is positioned in marketing narratives.
Crafting Systems
Drawing on his experience at organizations such as Meta, AB InBev, and Teradata, Eric believes the distinctive difference between scalable and reactive security organizations lies in where security capability resides.
Organizations that scale successfully build security into their operational framework rather than relying on the expertise of a few key individuals. Detection processes are documented and repeatable, incident response follows established playbooks, and risk decisions are guided by clear governance frameworks. This approach ensures that security remains consistent, resilient, and transferable as the organization grows.
In contrast, reactive organizations often depend heavily on a small group of high-performing professionals. Their ability to detect and respond to threats is frequently tied to individual knowledge and experience. It makes the program less adaptable and more vulnerable to disruption. While these teams may handle familiar threats effectively, they often struggle to respond consistently to new and evolving risks.
He underlines a simple test of security maturity: if the organization’s senior security leaders were to leave, would the program continue to function effectively? In organizations that have scaled successfully, the answer is yes. It is because capabilities are embedded within processes and systems rather than individual memory.
Ultimately, he believes that sustainable security programs are built on strong foundations. While these investments rarely receive the same attention as major incident responses or new technology deployments, they are what enable organizations to scale security effectively over the long term.
Seamless Business Fluency
While Eric from the Compass MSP views business integration as the defining characteristic of the next generation of cybersecurity leadership, he believes the reality is more nuanced than choosing between technical specialization, operational orchestration, or business acumen. In his assessment, future security leaders will need credibility across all three disciplines. What will ultimately distinguish the most effective among them is their ability to lead at the pace demanded by AI.
He shares, “Technical specialization remains foundational, but the nature of what security leaders need to understand technically has shifted. The attack surface is widening faster than most organizations are equipped to track. AI is not just changing how defenders operate, it is changing how attackers operate, too, on what scale, and with what level of sophistication.”
As AI-powered capabilities become increasingly accessible, attackers can execute sophisticated and highly targeted campaigns with greater scale and efficiency. He points out that AI-driven tools are already present within cybercriminal ecosystems. It lowers barriers to entry and accelerates the speed at which new threats emerge. As these technologies mature, he expects the gap between attacker capabilities and traditional defense models to widen further.
The industry’s challenge is responding to the present ground reality. The advent of increasingly capable AI systems has fundamentally altered the threat landscape, creating risks that move faster than many organizations’ existing security frameworks can accommodate. Leaders who continue to treat AI-enabled threats as a long-term concern risk falling behind an adversary evolving in real time.
He also argues that operational orchestration has become a defining requirement for modern security programs. Effective organizations are no longer dependent on disconnected teams, fragmented tools, or lengthy decision-making cycles. Instead, they are building integrated environments where technology, processes, and people work together seamlessly, enabling responses that operate at machine speed rather than organizational speed.
Ultimately, however, Eric from the Compass MSP stresses that business integration is shifting in cybersecurity’s leadership role from technical management to strategic influence. The most successful security leaders will be those who can combine technical depth with operational discipline while translating emerging risks into business decisions that executives and boards can act upon.
In Eric’s view, the cybersecurity leader of the AI era will not be remembered for explaining incidents after they occur. The leaders who will define the next generation are those who anticipate change, build resilient architectures in advance, and secure organizational commitment before a crisis forces the conversation.

