The wave of enterprises embracing AI is creating new security challenges: security teams often only learn about agentic AI projects after they are already running.

This is what Anup Kumar, CEO of Optiv Consulting, calls a "generational" opportunity. Investment firm Vobis Ventures acquired the consulting business from value-added reseller Optiv Security on June 2, gaining a team of about 500 consultants and approximately 200 Fortune 500 clients.

"This is a dream hunting ground for us and for anyone in this space," said Kumar, who also serves as Vobis's operating executive partner. "We have been looking for assets like this for a long time. For us, it is incredibly exciting as a foundational capability."

Optiv Consulting is being established at a time when AI consulting firms can gain support from major large language model developers. Both Anthropic and OpenAI view consulting firms and system integrators as key partners for reaching enterprise customers. Anthropic's Claude partner network, launched in March, presents an attractive collaboration opportunity.

"One of our priorities is to establish a partnership with Anthropic, especially given their focus on enterprise customer implementation. I believe our customer bases are very similar, so we will seek to collaborate with them to create greater value for clients," Kumar said.

Kumar expects enterprise adoption of Claude to "take off" in the coming years, which will require appropriate security architecture as a foundation.

"I think the timing is just right," he said.

Separation of consulting and resale businesses

At a time when major value-added resellers are touting their own consulting capabilities, KKR-backed Optiv Security's decision to divest its consulting business is itself a topic worthy of separate discussion.

The two companies resulting from the split will become exclusive partners to ensure clients receive comprehensive services, but Optiv Consulting has effectively exited the resale space. This is also part of the company's attempt to approach AI governance differently from its peers.

Kumar noted that cybersecurity vendors and partners currently focus on providing technology to identify and protect non-human identities. This is a good foundation, but it is far from sufficient.

"The real question is what happens after you authorize an agent—this is actually the further downstream part," Kumar said. "How do you prevent agents from misbehaving, how do you prevent them from going out of control? This is what we are trying to solve at a holistic level."

Gartner coined the term "cyber regret" to describe organizations investing heavily in strategy and funding for generative AI and agentic AI projects at the expense of cybersecurity. Kumar, however, views both as belonging to the same domain—the combination of AI adoption and AI governance. CISOs are often brought in late in agentic AI projects, without the opportunity to proactively participate in the design of AI governance.

"CISOs are not involved early enough, they lack full visibility and control, and I think that is the challenge," he said.

Vendors and consulting firms typically pitch their AI projects to CTOs, CIOs, and business leaders, while Optiv's target stakeholders are usually CISOs. By bundling AI implementation with AI governance in its pitch, Optiv Consulting aims to expand its audience.

"In the future, we believe this will be a joint decision between business leaders and CISOs, because such initiatives are typically driven at the business leader level," Kumar said.