Skip to content
CISO Spotlights

Career profile

Rich Baich

Senior Vice President and Chief Information Security Officer, AT&T

Status
Current role, per sources checked 15 July 2026
Appointed
Not stated in the sources
Published

Compiled 27 September 2026 from public records. Each statement below is drawn from the sources listed at the end.

Rich Baich is chief information security officer for AT&T, a title he carries into the company's own Secure Connections cybersecurity conference this year as one of its featured speakers.

Career path

Before AT&T, sources describe three earlier stops in the CISO chair: the Central Intelligence Agency, AIG and Wells Fargo.

Earlier still, his record includes work as a Naval information warfare officer, senior director for professional services at Network Associates (now McAfee), and, after the September 11 attacks, special assistant to the deputy director for the FBI's National Infrastructure Protection Center.

Baich served in the military for 20 years, including as commander in the information operations directorate at NORAD/Northern Command Headquarters and as commanding officer at the Navy Information Operations Center, among other military and presidential appointments.

In 2005 he authored Winning as a CISO, a leadership sourcebook for security executives; his education includes the United States Naval Academy, the Naval War College, Joint Forces Staff College, and an MBA from the University of Maryland Global Campus.

Published views on prevention versus detection

In a July 2026 opinion piece co-written with Hugh Thompson, Baich argued that the security industry has over-invested in detection at the expense of blocking attacks before they happen, noting that most new cybersecurity startups entering RSA Conference's innovation competition ship detection tools rather than prevention tools.

The piece concluded that reducing the number of entry points available to attackers matters more than expanding detection headcount, and that the profession should be judged on how well it lowers the likelihood of compromise rather than how efficiently it observes compromise after the fact.

Two years earlier, at Fordham University's International Conference on Cyber Security, Baich had made a related point about artificial intelligence, saying it lets a security team build a tool that answers policy questions instantly rather than replacing the judgment of the people applying patches.

He added at the same event that he remained "a fan of the human operator applying a patch," even as AI took on more of the analysis behind that decision.

Sources

  1. 1.
    AT&Tsecureconnections.att.com · undated page · checked 27 September 2026 · tier A
  2. 2.
    CSO Onlinecsoonline.com · undated page · checked 27 September 2026 · tier B
  3. 3.
    CSO Onlinecsoonline.com · published 15 July 2026 · checked 27 September 2026 · tier B
  4. 4.
    Dark Readingdarkreading.com · published 18 January 2024 · checked 27 September 2026 · tier B

Tier A: the organization itself, a regulator or a government page. Tier B: established trade or business press.