Cybersecurity at the NFL: Why the First Person Through the Door Shouldn’t Make the Decision
4 min. read&w=3840&q=75)
Kam Karaji spent 14 and a half years as a UK police commander, working counter-terrorism and firearms and collecting medals for bravery along the way, before cybersecurity found him.
Today he's an award-winning CISO and the director of cybersecurity and risk management at the NFL, running cyber strategy, enterprise risk, and event security for Super Bowls, international games at the Bernabéu and Stade de France, broadcast platforms, and 32 clubs.
We got into what stadium security looks like when you treat the venue as one connected machine, how the NFL handles AI governance without becoming the department that blocks everything, and the firearms lesson that explains most bad decisions in incident response.
Key takeaways
Why do smart security teams make bad calls under pressure?
Police call it red mist. Chase an assailant and you go tunnel vision: locked on your target, blind to everything around you. Firearms training teaches that the first officer through the door is the least appropriate person to make the decision. A cyber incident produces the same effect. The team sprinting at the threat has red mist too, and the question of what brings that threat back to life goes unasked.
Try this: name an incident commander before you need one, and keep that person away from the keyboard when things go wrong.
How vulnerable are stadiums to cyber attacks?
A stadium is one unified computer. Turnstiles, fire escapes, lighting, building management, fields that rotate up from underground. All of it connected. Tell the building it's on fire and every door fails open, ten minutes before kickoff, with 60,000 people inside. Breaking in got trivial. The question attackers ask now is what causes the most damage.
Try this: list every connected system behind your product, venue, or platform and ask of each: what's the worst instruction it would obey?
What drives insider risk in an organization?
Motive. Insider threats always have one (a missed promotion, a pay rise that never came), so the NFL scores human risk by access and behavior, and treats honest feedback as a security control. Defense-in-depth diagrams end at the data. Kam draws people in the middle with it: your people belong in the crown jewels.
Try this: cross-check your highest-access people against who last got honest career feedback. The overlap is your real risk register.
What is shadow AI and how do you govern it?
Shadow AI is employees using AI tools the company never approved, often with company data in the prompts. It will happen, because people are inquisitive. The NFL's AI governance model: commercial data stays out, one approved tool chosen through due diligence, an acceptable use policy with a real consequence model, and a review of every new model release before anyone presses the green button.
Try this: run an amnesty. Ask the team which AI tools they already use, pick the best fit, approve it properly, and write down what can never go in a prompt.
How do you manage third-party and supply chain risk?
Start with the hard truth: your third party is held up by a fourth, fifth, and sixth, and the platform you pay for is driven by vendors you've never assessed. The NFL tiers its suppliers and writes disclosure into the contract: if you're business-critical, you tell us who props you up. Accountability shifts down the chain, and so do the financial repercussions.
Try this: add one clause at your next renewal: any business-critical vendor names the vendors that keep their service running.
Why does tunnel vision make risk assessments fail?
Police trainers handed Kam a Where's Wally book. You spend an hour finding Wally and miss the 100 other things happening around him. He uses the same image for risk today: situational awareness beats tunnel focus, every time.
Try this: in your next risk review, spend the last ten minutes on everything around the risk you came to discuss.
Is quantum computing a cybersecurity risk?
Yes, and Kam thinks it's heading for the same panic cycle AI got five years ago. Quantum computing packs city-scale processing power into a single chip, solving in minutes what today's machines need years for, and it will eventually break the encryption most businesses rely on.
Try this: put quantum on your enterprise risk register this quarter and let the assessment travel down to the business units, before anyone buys the chip.
How do you build a security culture people actually follow?
The thing Kam is proudest of delivering in his career is a logo. A workforce was scared to come into the office during a physical security crisis, and the board wanted metal detectors everywhere, which makes scared people more scared. Kam built a steering group out of the scared people instead and shipped a badge: see something, say something, be safe. The founder of that company still talks about it.
Try this: next time people are worried about a change, recruit the worried people to design the fix.
Listen & watch
DELIVERED is a production of Infinum and Your Majesty.