ITSPmagazine is free online publication that focuses on information technology, cybersecurity, data privacy, the InfoSec community and the influence that all this has on our everyday lives – as businesses, individuals and the society in which we live. Delivered through articles, podcasts, webcasts,…
ITSPmagazine | Technology. Cybersecurity. Society.
The ITSPmagazine | Technology. Cybersecurity. Society podcast is a highly informative and entertaining show that covers a wide range of topics in the cybersecurity field. The hosts do an excellent job of engaging with their guests and creating conversations that are both educational and enjoyable to listen to. Whether you're a beginner or an expert in cybersecurity, there is something for everyone in this podcast.
One of the best aspects of this podcast is the diversity of subjects covered. The hosts interview experts from various backgrounds and discuss real problems in the cybersecurity field. This allows listeners to gain insight into different perspectives and stay up-to-date with current issues. Topics such as AI and technology, privacy, ethical hacking, and cyber safety are explored in depth, providing valuable information for anyone interested in these areas.
Another great aspect of this podcast is its ability to engage with its audience. The hosts make an effort to be accessible and chat with everyone, creating a welcoming environment for listeners to interact and ask questions. This not only makes the podcast more enjoyable but also fosters a sense of community among cybersecurity enthusiasts.
However, one potential downside of this podcast is that it can sometimes delve into technical jargon that may be difficult for beginners to understand. While it is aimed at both beginners and experts, those new to the field may find themselves getting lost during certain discussions. It would be helpful if the hosts could provide more context or explanations for complex concepts to make it more accessible for beginners.
In conclusion, The ITSPmagazine | Technology. Cybersecurity. Society podcast is a highly valuable resource for anyone interested in cybersecurity, technology, and society's impact on these areas. The informative yet entertaining format keeps listeners engaged while providing them with valuable insights from experts in the field. Despite some technical jargon that may be challenging for beginners, this podcast offers a wealth of knowledge that will leave listeners wanting to learn more about these important topics.

What actually changed for the AI SOC this year? Bill Peterson, Senior Director of Product Marketing at Sumo Logic, says it reached the point of getting into production, where a year or so ago the same conversation was about what was coming. Marco Ciappelli puts the count of companies carrying AI SOC in the name at 43, and Bill Peterson says that number strikes him as low. The market is maturing, and Sumo Logic announced its own set of AI SOC products and solutions during the week. The second thing is what a security audience does with it. Hands-on practitioners want to touch it, see it, feel it, and Sumo Logic ran live demos of its products on site. When a technical audience puts hands on a keyboard and tries something, Bill Peterson expects them to take it back to work with them. Production first, then enablement of the practitioners. The third is the pace behind all of it. Most security vendors are SaaS companies running CI/CD and shipping continuously, so three and six month roadmaps and delivery are the norm now and the 12 to 18 month roadmap is gone. Some customers are what Sumo Logic internally calls AI shy, accepting they have to get there while taking a slow and reasoned approach, and Bill Peterson treats that as normal for any technology. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Bill Peterson, Senior Director of Product Marketing at Sumo Logic On LinkedIn: https://www.linkedin.com/in/williampetersonjr/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Learn more about Sumo Logic: https://www.sumologic.com/ Sumo Logic Dojo AI: https://www.sumologic.com/solutions/dojo-ai Sumo Logic Dojo AI agent announcements at Black Hat USA 2026, including general availability of the SOC Analyst Agent: https://www.prnewswire.com/news-releases/sumo-logics-new-dojo-ai-agents-investigate-and-resolve-security--cloud-operations-issues-at-machine-speed-302839720.html Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS Bill Peterson, Sumo Logic, Marco Ciappelli, brand briefing, brand story, brand marketing, marketing podcast, Black Hat USA 2026, AI SOC, agentic AI, security operations, Dojo AI, SOC analyst agent, product marketing, CI/CD release cycles, AI adoption, human in the loop, security operations center, market maturity Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Lisa Liu, Corporate Marketing and Communications Manager at Stellar Cyber, connects with ITSPmagazine on the floor at Black Hat USA 2026 in Las Vegas. What are buyers asking for now that the RSAC Conference noise has settled? Data. Liu says people have had time to run their own research, look at what vendors offer, and come back using specific keywords and asking for something behind the marketing. Does a more skeptical audience make the conversation harder? Liu describes the opposite. She says people are pushing back on claims they hear, which presses vendors to prove at a higher standard that a technology does what it says it does. Feedback arrives more specific, and the exchange moves from explaining to planning as people ask how a capability could work in their environment. The reply she calls validating is the customer who reports the product did what it was said it would do, giving analysts their time back and helping teams work more efficiently. What makes Black Hat different for a company that works the major events? Ask people what they are looking for and they will tell you. Liu says pain points here are felt daily and described plainly, and that candor is feedback the company works to internalize and make productive. Looking ahead, she says new product releases are coming, with new features and expansions of what customers have responded to, and that Stellar Cyber will share them on its website and on LinkedIn. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Lisa Liu, Corporate Marketing and Communications Manager at Stellar Cyber LinkedIn: https://www.linkedin.com/in/lisaaliu/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Stellar Cyber: https://stellarcyber.ai/ Stellar Cyber on LinkedIn: https://www.linkedin.com/company/stellarcyber Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS lisa liu, stellar cyber, marco ciappelli, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, security operations, agentic ai, ai in cybersecurity, vendor claims, proof and data, soc analysts, rsac conference, event coverage, las vegas Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Michael Parisi, Chief Growth Officer at Steel Patriot Partners, connects with ITSPmagazine on location at Black Hat USA 2026 for a recap of the week. He describes Steel Patriot Partners in the order it sets its priorities. Business owners first, engineers second, compliance and security people third. A consulting and advisory company, he says, but really an engineering firm. What changed at this event? Parisi says the AI slop visible at RSAC Conference died down here, and that people are cutting through the noise and going back to a core group of tools and solutions with the capabilities to address the business challenges AI is creating. Non-human identities sit at the top of that list, the number one concern he heard relative to AI. Organizations recognize the risk and are working out how to solve for it. His observation is that many information security teams do not realize their traditional cybersecurity tools already carry the capabilities to do it. Who are security leaders asking before they decide? People they already know. Parisi describes CISOs going back to the individuals they have had long-term relationships with and sourcing guidance from them before decisions get made. Automation has expanded what can be done, but nobody got more hours in the day to evaluate everything arriving in front of them. The next move he points to is asking the question, either of the engineers at the provider or of a trusted advisor, and getting the configuration aligned to the business outcome it was bought to serve. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Michael Parisi, Chief Growth Officer, Steel Patriot Partners LinkedIn: https://www.linkedin.com/in/michael-parisi-4009b2261/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Steel Patriot Partners: https://www.steelpatriotpartners.com Find Your Path, three questions to start: https://www.steelpatriotpartners.com/find-your-path Steel Patriot Partners Insights: https://resources.steelpatriotpartners.com Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS michael parisi, steel patriot partners, marco ciappelli, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, non-human identities, machine identity, ai risk, security tool configuration, trusted advisor, ciso decision making, cybersecurity engineering, compliance advisory, security tool sprawl, vendor noise Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Qualys returns to Black Hat USA 2026 with an AI Risk Operations Center built around three principles customers have been asking for over the last three years. May Mitchell, Chief Marketing Officer at Qualys, walks through them in order. Detect vulnerabilities at AI speed. Prioritize what surfaces, because not every finding calls for action in the same hour and the sequence follows the workflows a team already runs. Eliminate it through autonomous remediation, then confirm the fix worked. Mitchell also notes that Qualys has been a Black Hat sponsor for over 23 years. What are security teams asking for at AI speed? They want detection to keep pace with disclosure. Mitchell points to InstaScan, the innovation Qualys launched during Black Hat week, which provides continuous scanning and detection. The meetings on the floor have been with customers from across the regions, not only the US. How has the AI conversation shifted since RSAC Conference? It has narrowed to implementation. Mitchell says the messaging moved from AI to agents to autonomous, and that this year the questions are targeted. How do I implement it. How do I get it into the workflows. How do I have governance. The economics of AI sits alongside those questions, with more asked about ROI, since budgets are not rising across the board. That pushes organizations to evaluate their technology stack, consolidate, and look for a single platform that gives complete visibility and gives security leaders something they can take to a board or a CFO. Customization depends on the size of the organization, and larger heterogeneous environments are where Qualys partners come in with risk assessment services, planning, integration, and ongoing management. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST May Mitchell, Chief Marketing Officer at Qualys On LinkedIn: https://www.linkedin.com/in/maymitchell/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Qualys: https://www.qualys.com/ InstaScan announcement: https://www.qualys.com/company/newsroom/news-releases/usa/qualys-launches-instascan-to-detect-vulnerabilities-within-minutes-of-disclosure Agent Insta and scanless detection: https://blog.qualys.com/product-tech/2026/08/03/instascan-agent-insta-scanless-detection ROCon Americas 2026 in Austin: https://www.qualys.com/rocon/2026/americas Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS May Mitchell, Qualys, Marco Ciappelli, brand briefing, brand story, brand marketing, marketing podcast, Black Hat USA 2026, risk operations center, InstaScan, AI speed detection, autonomous remediation, vulnerability management, prioritization, security governance, economics of AI, platform consolidation, cyber risk management, CISO, ROCon Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Daniel Bardenstein, CEO and Co-Founder of Manifest Cyber, uses RSAC Conference as a fixed point and compares it to what he is hearing in Las Vegas. The marketing has held its shape. At RSAC Conference, companies with little claim to the label were describing themselves as agentic. Here, he cites a survey referenced in a talk that morning counting 47 AI SOC companies among the vendors on site. What has moved is scrutiny. Practitioners and security leaders are pressing on what differentiates one AI product from another and whether a product is a thin layer built around a frontier model. Bardenstein also reports conversations about open weight models and reduced dependency on frontier lab providers following the OpenAI Hugging Face incident and the White House action on Fable and Mythos. Contracting is shifting as well, with procurement teams adding due diligence and paperwork whenever AI shows up inside a product. Marco Ciappelli raises the question sitting under the label. Agentic AI brought questions about how many agents are running and who owns their identity, and AI SOC suggests an operations center assembled largely from automation. Bardenstein points to narrower use cases teams already trust, including finding vulnerabilities in source code and suggesting patches, then offers his own test for buyers. Does it reduce vulnerabilities, does it reduce false positives, does it deliver faster outcomes and fewer breaches. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Daniel Bardenstein, CEO and Co-Founder at Manifest Cyber On LinkedIn: https://www.linkedin.com/in/bardenstein/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Manifest Cyber: https://www.manifestcyber.com/ Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS daniel bardenstein, manifest cyber, marco ciappelli, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, ai soc, agentic ai, ai in cybersecurity, vendor differentiation, open weight models, frontier models, security procurement, ai due diligence, software supply chain security Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Sean Murphy, Field CISO for North America at F5, spent the week behind the scenes at Black Hat USA 2026, in the corridors and at dinner with the CISOs and cybersecurity minded people who fill the halls. Marco Ciappelli caught him at the close of it and asked what the industry learned this year. The answer arrived as three words. Vulnerabilities, and the flattening of the curve between vulnerability, exposure, and exploit. Visibility, because a team cannot defend what it does not know it has. Velocity, which carries the other two. Sean Murphy calls the acceleration a physics problem rather than a technology problem, given the forces and friction now moving through security work. Moore's law is out the window in his framing, and advancement arrives week by week. For a CISO writing a roadmap and defending an investment case for the next six to 18 months, the plan keeps pivoting underneath them. AI shifted just as fast. What was recently understood as hyperscaler sized, built for the largest organizations, is now generative and agentic AI running at the enterprise level, in production rather than in a pilot. That leaves a population question. Agents are identities, non-human identities with permissions and responsibilities, and Sean Murphy points out they are proliferating alongside the human identities already under governance. He also offers a reframe on agents that slip past misconfigured guardrails and go crawling for LLMs and repositories. That is an agent doing exactly what it was told to do, relentlessly, until it succeeds. The work ahead is guardrails and governance over all of that visibility. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Sean Murphy, Field CISO for North America at F5 On LinkedIn: https://www.linkedin.com/in/seanmurphy092009/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Learn more about F5: https://www.f5.com Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS Sean Murphy, F5, Marco Ciappelli, brand briefing, brand story, brand marketing, marketing podcast, Black Hat USA 2026, field CISO, agentic AI, non-human identity, AI governance, guardrails, vulnerability management, security visibility, security roadmap, identity and access management, enterprise AI adoption Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Brian Dye, Chief Executive Officer at Corelight, spends Black Hat USA 2026 asking every organization he talks to the same question. What are you doing with AI in the SOC? A year ago, he says, teams thought it was a good idea but were wary of it, and people knew LLMs could produce things without being sure what to do with them. Now he is talking with organizations building their own agents for incident response and for threat hunting, and running their own quality control on the output rather than taking it on faith. What decides how far an agentic SOC workflow can go? The data does. Brian Dye describes a three-legged stool where the model and the agents are only two of the legs. The third is the data going into the workflow, and without the right data the agents hit a headroom of logic. He credits three changes for the shift. Agentic development decomposes an investigation into smaller chunks that can be trusted individually. Time in the saddle has made teams better at separating claims from reality. And organizations now ask the workflow itself what it could not answer and what data it wishes it had. Why does a week like this one matter to product development? Corelight works on translating the network into the right fuel for AI, which means understanding the architecture each customer is building toward, whether that is an in-house SOC, a third party SOC, or a workflow running through their own SOAR or SIEM. Brian Dye also describes the Black Hat NOC as a room where the work looks different. Most security teams look for a needle in a haystack. The NOC team is finding the sharp needle in a stack of dull needles, separating illicit activity from the legitimate malware analysis training running on the same network, while using the room as a multi-vendor playground for new integrations and workflows. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Brian Dye, Chief Executive Officer at Corelight On LinkedIn: https://www.linkedin.com/in/brdye/ RESOURCES Black Hat USA 2026 event coverage from ITSPmagazine: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Learn more about Corelight: https://corelight.com Corelight blog: https://corelight.com/blog Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS brian dye, corelight, marco ciappelli, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, agentic ai, ai in the soc, security operations center, network detection and response, threat hunting, incident response, black hat noc, soar, siem, network evidence, agentic workflows Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Rahul Sood has run the application security business at Harness for almost a year. He describes application security as one of the core pillars of the company, part of a vision of building a DevSecOps platform. A year ago Harness publicly announced that security accounted for a quarter of its revenue. Sood says the figure is now considerably higher. The company did not start there. Founder Jyoti Bansal thought about Harness for a decade before founding it, Sood says, after seeing the problem inside one of the largest banks. Harness launched as a DevOps platform, then merged with an API security company Bansal had also funded. The result is a platform that treats security as part of the developer workflow rather than a bolt-on, and covers it from code all the way to runtime. What changes when security lives inside the developer workflow? Developers stop leaving their own tools to chase findings. Harness aggregates results across scanners, deduplicates them, and puts remediation, assignment, and exemption requests in one place. Security teams get the other half of the picture through a policy engine that shows which policies fire on every build, which ones break a build, and where a developer asked for an exception, with a full audit trail behind it. Where is the bottleneck now that AI writes the code? It moved downstream. Sood says nearly every development team is generating more code with AI, while the volume actually reaching users has not risen at the same rate. By his estimate coding is 20 to 30 percent of the software development life cycle, and the remaining 70 to 80 percent happens after the code is written. That includes agents. Harness has extended the platform to support the Agent DLC, with native capabilities for AI evaluation and prompt testing alongside security coverage for agents from code to runtime. Sood points to two differences. The span from code to runtime covers agents while they are built and while they run, and skill scanning and prompt scanning were added to the same scanner already looking for code vulnerabilities rather than shipped as another tool to buy. The operational payoff shows up in release cadence. Sood describes a tier one US bank that maintained 150 separate policies and convened a team to confirm each one had been met before it could launch its banking app. Automating that review removed the meeting, and the bank now runs multiple launches within weeks. With 80 to 90 percent of software now assembled from third-party packages, libraries, and open source components, the same policy engine can block any build that pulls in a package which is end of life or malicious. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Rahul Sood, General Manager, Application Security at Harness On LinkedIn: https://www.linkedin.com/in/rssoods/ RESOURCES Black Hat USA 2026 event coverage from ITSPmagazine: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Harness: https://www.harness.io/ Harness customer case studies: https://www.harness.io/customers Securing the Agent DLC, by Rahul Sood: https://www.harness.io/blog/securing-the-agent-dlc Harness AI Security: https://www.harness.io/products/ai-security Harness Application Security Testing: https://www.harness.io/products/application-security-testing Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS rahul sood, harness, sean martin, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, application security, devsecops, agent dlc, ai security, api security, policy engine, software supply chain, open source risk, prompt scanning, skill scanning, code to runtime, developer experience, release velocity Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Why does compliance paperwork fall behind the systems it describes? Because the systems change faster than the documents. Travis Howerton points to cloud native technologies that spin up and down on demand, which makes describing infrastructure in paperwork something that goes out of date instantly. Add new regulation for third party risk, supply chain, zero trust, and privacy, and an approach that was already expensive and frustrating stops being fit for purpose. RegScale answers that with compliance as code. The company went to NIST and helped write the standard that became OSCAL, the Open Security Controls Assessment Language, then built the capability for machines to attest to their own state using it. Paperwork starts writing itself, and CISOs get risk and compliance outcomes as a byproduct of operational excellence rather than as a separate project. Is automating the evidence trail a shortcut? Travis Howerton argues the opposite. It prevents corner cutting, because the alternative is what he calls compliance theater. An old general he worked for described that as a mother-in-law visit, where you clean the house to a ridiculous standard, everybody goes through the dance, and the moment the visit ends the kids destroy the house again. Where should a security team start automating? Start with what hurts. He tells people to think like a surgeon, who opens by asking the patient what is wrong, then work backwards from the pain. There is no easy button, and the honest starting point is the truth about how fast teams will need to react. That pain usually maps to one of three business drivers. Cut cost, or shift the share of budget going to checklist compliance toward tools that buy down risk. Get real-time assurance. Or earn the reps and certs needed to sell into a market, whether that is FedRAMP for government work or PCI for card data. Compressing those timelines by 70 to 80 percent lets a company get to market faster and grow revenue. The results Travis Howerton cites are specific. One large government agency is touting over $100 million in labor savings, and a Department of War customer with a 52-week end-to-end cycle has compressed it by 36 weeks using RegScale technology alongside other integrated tools. Having tripled, doubled, and doubled again over the last three years, RegScale stays focused on the largest and most complex organizations, with international markets and the energy sector on the horizon. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Travis Howerton, Co-Founder and CEO at RegScale LinkedIn: https://www.linkedin.com/in/travishowerton/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas RegScale: https://regscale.com OSCAL, the Open Security Controls Assessment Language: https://pages.nist.gov/OSCAL/ Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS travis howerton, regscale, sean martin, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, compliance as code, continuous controls monitoring, oscal, grc engineering, fedramp, fisma, authority to operate, ai agents, risk management, cybersecurity compliance Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Post-quantum cryptography was in conversation after conversation at Black Hat USA 2026, yet Larry Lunetta of HPE walked part of the show floor and counted a single reference to quantum. Where the topic shows up, and where it does not, says something about who is expected to solve it. Why does a problem described in 1994 matter now? Larry Lunetta points to Peter Shor, who asked what would happen to RSA if a different kind of computing technology existed. What changed since then is the trajectory. Five years ago cryptographically relevant quantum computing looked like a 10 to 15 year phenomenon. Larry Lunetta now puts it as soon as three years out, with the original algorithm improved, qubit hardware advancing, and classical supercomputing pulling the timeline in alongside it. The exposure starts before any of that arrives. Larry Lunetta describes harvest now, decrypt later, where an attacker collects RSA-encrypted data today and waits for the machine that can open it. Data that carries no consequence when it leaks this year can be read later, which puts long-lived information like identity records and medical data at the front of the queue rather than in a later phase. HPE puts a three part journey in front of customers. Cryptographically aware asks which data is most sensitive, where it lives, and whether it is protected sufficiently. Cryptographically planning reaches into the refresh cycle, so that new network, server, and storage purchases already implement PQC-relevant algorithms. Cryptographically nimble accounts for the fact that no cryptographically relevant quantum computer exists to test against yet, which makes the ability to change algorithms and firmware quickly part of the design. Who owns the conversation inside the business? Larry Lunetta puts the CISO at the center of gravity, with CIOs becoming aware and boards engaged where GDPR governs customer and private information. His advice for security leaders is to broaden the conversation toward infrastructure and operations, and to make encryption and PQC readiness a question asked during procurement rather than after it. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Larry Lunetta, Vice President, Portfolio Technical Marketing at HPE On LinkedIn: https://www.linkedin.com/in/larryathpe/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas HPE: https://www.hpe.com Post-Quantum Cryptography overview: https://www.hpe.com/us/en/what-is/post-quantum-cryptography.html HPE technology leadership in quantum: https://www.hpe.com/us/en/about/technology-leadership-quantum.html Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS larry lunetta, hpe, sean martin, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, post-quantum cryptography, pqc, quantum computing, harvest now decrypt later, rsa encryption, cryptographic agility, ciso, crypto agility, nist post-quantum standards, it infrastructure security, encryption, data protection Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Most people know HPE for servers, compute, and storage. David Hughes leads a pillar that gets less attention. He runs the SSE and security business inside HPE Networking, which he says accounts for about a third of the company now that HPE has merged with Juniper, and which organizes into four pillars: campus and branch, data center switching, routing infrastructure, and security. Recorded on location at Black Hat USA 2026, the conversation opens on a balancing act Hughes hears constantly. Customers want to push hard on AI adoption while staying protected and avoiding undue risk. The same tension runs between teams. Networking answers for performance and user experience. Security answers for protecting those users and the company's data. HPE's answer is to embed security thinking into the network itself, making it a sensor and an enforcement point for the security team. What happens when users are no longer only people? The identity question moves to devices, workloads, and agents. Hughes frames it as human and non-human identity, and his position is to take the ZTNA architecture that works for people and adapt it, starting with IoT devices, then workloads, then agents. Put an agent in a sandbox and it sees only the subset of resources it is supposed to reach. How do networking and security teams work from the same picture? Through shared visibility and agentic technology across the management layer. HPE is putting agentic technology into how it manages storage, compute, networks, and security products, then meshing those agents together so a wifi complaint that turns out to be a firewall policy change gets to root cause faster, with automatic remediation as the goal. Hughes also covers post-quantum cryptography, where HPE is moving across all product lines to introduce quantum resistant and quantum safe capabilities in hardware and software, with some launched this year and more coming through the following quarters. The deadline arrives earlier than most calendars suggest, because data harvested today can be decrypted later. Rounding it out: HPE Threat Labs, announced earlier in the year with Mounir Hahad's team from Juniper at its core, and AI focused capabilities on the next generation firewalls covering observability, role based governance over which services employees can use, and session level inspection of prompts and responses. Hughes closes with a direct invitation to CISOs who know HPE for compute and networking and have yet to meet the security team. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST David Hughes, SVP and GM of SASE and Security for Networking at HPE On LinkedIn: https://www.linkedin.com/in/david-hughes-42751636/ RESOURCES Black Hat USA 2026 event coverage from ITSPmagazine: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas HPE: https://www.hpe.com/ HPE Threat Labs: https://www.hpe.com/us/en/hpe-labs/threat-labs.html Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS david hughes, hpe, sean martin, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, zero trust, ztna, non-human identity, agentic ai, ai security, post-quantum cryptography, network security, sase, sse, hpe threat labs, self-driving network, firewall governance, juniper, iot security, cross domain troubleshooting Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Recorded on location at Black Hat USA 2026, Eric Avigdor of Menlo Security describes an adoption pattern he hears in customer conversation after customer conversation. AI makes teams measurably more productive. The guardrails that keep company data inside the business arrive later, if they arrive at all. Eric Avigdor leads product for AI security and data security at Menlo Security, and he splits the problem into two categories that get very different levels of attention. One is how people use AI in the browser, including what data gets pasted into an assistant and how much of that usage anyone knows about. The other is autonomous agents built to run business processes, where the question is how to keep them productive without letting their goals get hijacked. The category Eric Avigdor says compliance teams skip past is the agent that holds sensitive data and internet access at the same time. Read a poisoned web page, take the hidden instruction, and the goal changes. What is the difference between an agent running analysis on an internal database and an agent doing financial analysis at a bank with customer records and web access? One of them can be told to send the data somewhere else. So who owns AI governance? In most companies, nobody does, at least not with authority. Responsibility lands with the endpoint team, the network team, or the browser team, and each one works its own angle. An endpoint team tracks agent traffic on the endpoint and then loses the trail when the agent moves data cloud to cloud. A cloud team has the reverse blind spot. Menlo Agent Runtime Security, or MARS, is built around what an agent actually does rather than what it intends to do. Agent traffic is proxied through the Menlo Security cloud browser, where data masking, indirect prompt injection prevention, and web-based and file-based threat prevention are applied before an incident becomes cleanup work. Browser and web traffic today, MCP traffic next. For regulated organizations, that architecture produces something auditors can use. Logging, dashboarding, and a visual record of what an agent attempted in the real world. Europe has the AI Act. The US has not landed comparable rules yet, and Eric Avigdor says that gap concerns him enough that he is talking with people working to close it. GUEST Eric Avigdor, Vice President of Product, Menlo Security | On LinkedIn: https://www.linkedin.com/in/eric-avigdor-0b561118/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Menlo Security: https://www.menlosecurity.com/ Menlo AI Agent Security: https://www.menlosecurity.com/product/ai-agent-security Menlo AI Adaptive DLP: https://www.menlosecurity.com/product/ai-adaptive-dlp Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS eric avigdor, menlo security, sean martin, brand story, brand marketing, marketing podcast, brand spotlight, black hat usa 2026, mars, menlo agent runtime security, ai agent security, prompt injection, indirect prompt injection, data exfiltration, ai governance, browser security, agentic ai, autonomous agents, shadow ai, data loss prevention, eu ai act, ai compliance, coding agents, mcp security Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Proactive and actionable get used a lot in security, and Michael DeBolt, President and Chief Intelligence Officer at Intel 471, is direct about it. Inside Intel 471, proactive means moving past indicators of compromise, which he describes as temporary, and focusing on adversary behavior instead. Indicators still get blocked. Intent, capability, and motivation are what tell a defender whether they are actually a target. So what is pre-attack intelligence? It is information gathered from inside adversary communities before an attack is launched, built on embedded access to the places where financially motivated actors communicate. DeBolt sets aside the deep and dark web framing, arguing the phrase suggests a space nobody can reach. Mapping it reveals a structured ecosystem of financially motivated cybercrime, with enabling services operating alongside the actors themselves. Why track actors rather than ransomware groups? Because operators move and behaviors stay. Many current groups are staffed by people who ran earlier groups that have since disbanded, and techniques travel with them. A threat hunt built around the behavior holds up whether that person is operating under one banner, another, or on their own. Intel 471 maps techniques to the MITRE framework, which lets a consuming team run threat profiling and decide which actors present more risk than others. The same logic applies to exposure work. An organization scanning its attack surface and finding internet facing vulnerabilities can ask which threat actors are discussing those vulnerabilities, and whether that moves an item to the top of the list. The CISO conversations DeBolt describes land on numbers most security leaders already report on. Mean time to respond, mean time to detect, and alert volume that can absorb half or more of an analyst's day. He uses the phrase decision grade intelligence for intel that informs security operations rather than sitting beside it, with integrations pushing it straight into analyst workflows. Two customer situations show the daily version. Intel 471 helped an organization locate an insider after its own monitoring flagged something unusual. Separately, initial access brokers advertise compromised credentials that feed ransomware operations downstream, and since actors lie and embellish, validating those claims is part of the work. DeBolt closes on a note that sits right next to everyone's AI investment. Credentials, identity, internet facing vulnerabilities, and open remote access tools are still how attackers get in. GUEST Michael DeBolt, President and Chief Intelligence Officer, Intel 471 LinkedIn: https://www.linkedin.com/in/mdebolt/ RESOURCES Black Hat USA 2026 Event Coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Learn more about Intel 471: https://www.intel471.com/ Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS Michael DeBolt, Intel 471, Sean Martin, brand story, brand marketing, marketing podcast, brand spotlight, cyber threat intelligence, pre-attack intelligence, adversary behavior, ransomware, initial access brokers, insider threat, MITRE framework, threat hunting, decision grade intelligence, compromised credentials, attack surface, cybercrime underground, Black Hat USA 2026 Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Recorded on site at Black Hat USA 2026 in Las Vegas, Seth Summersett joins Sean Martin to talk through the volume problem that shapes a modern security operations team. Seth Summersett spent about a decade at the NSA and roughly a decade at Mandiant, finishing there as head of innovation and custom engineering, then a couple of years at Meta supporting business unit level CISOs. He co-founded Embed Security with Jeffrey Johns, who ran the data science team alongside him at Mandiant. The catalyst came from watching a managed service run on human scale day after day. Two analysts and a hundred forwarded phishing emails means someone is choosing which ones to open and carrying the ones they cannot reach. Embed Security sits downstream of existing detection investments, taking signals from SIEM, EDR, identity, and email rather than asking a team to rip and replace what it already runs. What do security analysts actually want from AI in the SOC? According to Seth Summersett, it is not a verdict. Analysts want the work off their plate in a way they can verify, which is why Embed Security built what it calls chain of evidence, showing every question asked and the path to each conclusion. Teams also test it in reverse, running previously dispositioned alerts back through the platform to compare results against their own analysts. The numbers come from a competitive bake off at one of the company's largest clients. Embed Security dispositioned roughly 75% of that client's alerts to the point where the team stopped treating them as primary work, against a daily volume above 10,000 alerts. Why not build this in house? Seth Summersett says the demo is the easy part. What follows is evaluation loops that measure a change across hundreds of thousands of alerts rather than one, governance, and a way to capture organizational knowledge automatically. In regulated sectors, auditors may ask a team to prove how a conclusion was reached and that it holds consistently. There is a people side to this as well. Embed Security has supported a wellness program at BSides across its last two events, backing a calming kit and curriculum for analysts working under incident pressure. Seth Summersett closes with consistency for leaders, since a leader looking at 10% of alerts does not have a full risk profile, and career longevity for analysts who would rather build a long run in security operations than burn out in two or three years. GUEST Seth Summersett, Co-Founder and CEO, Embed Security LinkedIn: https://www.linkedin.com/in/summersett/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Embed Security: https://www.embedsecurity.com Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS seth summersett, embed security, sean martin, brand story, brand marketing, marketing podcast, brand spotlight, black hat usa 2026, security operations, soc analyst burnout, alert triage, agentic ai security, chain of evidence, siem alert fatigue, edr alerts, ai soc platform, security analyst workflow, build versus buy security ai, security operations governance, threat investigation Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

James Pope is on site in Las Vegas more than a week before the doors open. As SOC lead for the Black Hat NOC and Senior Director of Security Product Research and Technical Marketing Engineering at Corelight, his show starts with switches and access points rather than alerts. The team brings in the ISP, the firewall, the switches, and the access points, deploys them across the conference, and then moves into SOC mode. If there is no network, there is nothing to secure. The tooling arrives through partnership rather than sponsorship. James Pope says a company cannot buy or sponsor its way into the NOC, and that the team picks what it wants and fills gaps as it finds them. Cisco covers Umbrella and file malware analytics, Palo Alto Networks provides the firewall and XSIAM as the log aggregator, Arista handles switching and access points, Jamf runs MDM across the registration devices, and Lumen supplies the internet. Corelight is the network visibility layer. That layer carries different weight here than it would inside a company. Asking attendees to install a certificate or an endpoint agent so the NOC can inspect their traffic is a request nearly everyone declines. In most corporate environments the endpoint is one of the richest sources of signal. At Black Hat, visibility into attendee activity comes from network data. A Black Hat positive is malicious activity that is legitimate in context. Attendees pay to learn attack techniques against real targets, and researchers demonstrate new exploits on stage. Those events generate true detections no corporate SOC would ignore. The NOC lets them run rather than killing a paid training exercise or a live demo. So how does the team tell a training exercise from a real attack? It baselines each classroom and spends its time on the outliers. When seventy students in a room run the same attacks against the same destinations, the activity is probably sanctioned. The curriculum is ingested as a JSON file and the system moves through a series of gates, asking whether this is a class, whether multiple sources are reaching the same destination, and whether the attack would be expected in that curriculum. Anything that does not fit comes back for a human. The team informs far more often than it blocks. On the day of the recording, James Pope went to the trade show floor to tell someone that command and control traffic was running from their machine, and handed over logs for their IT and security team. He is not their manager, and what happens next is their call. Illegal activity is treated differently, and a handful of times per show the team asks a room to stop. At Black Hat Asia, traffic from a Corelight sensor showed a double RAT infection on one machine, a single APT running one implant for exfiltration and another for command and control. Working from traffic, James Pope established that the person was a reporter, the region they covered, and the company they worked for. Open source intelligence narrowed it to a single name, registration confirmed the person was on site, and the NOC invited them in. The reporter arrived expecting a product demo. The laptop was reset with everyone present, sessions were revoked, passwords were changed, and the reporter left in a secured state. This year the team opened the Outpost, running real Black Hat network logs from Corelight behind application guardrails, LLM guardrails, and a kill switch, where visitors query the data with text to SQL. Agentic triage stitches alerts into detections and detections into a timeline, and James Pope treats the ability to drill down to raw logs as a requirement rather than a preference. Success is measured largely by what does not happen: no compromise of registration, the switches, or the access points, and people who arrive infected leaving better than they got here. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST James Pope, Senior Director of Security Product Research and Technical Marketing Engineering at Corelight, and SOC lead for the Black Hat NOC RESOURCES Black Hat USA 2026 event coverage from ITSPmagazine: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Learn more about Corelight: https://corelight.com Corelight blog, including the Black Hat NOC series: https://corelight.com/blog Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS james pope, corelight, sean martin, marco ciappelli, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, network detection and response, network evidence, security operations center, threat hunting, agentic triage, ai in the soc, conference network security, black hat noc, command and control, incident response Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Recorded on location at Black Hat USA 2026 in Las Vegas at the end of day two, Karthik Kannan, Founder and CEO at Anvilogic, walks through a seven year build that reached its original shape this year. The plan from the start was a full security operations platform covering data, the detection engineering process, triage and investigation, and case management. In the shorthand of the category, SIEM and SOAR combined. It arrived in phases. Detection engineering came first, implemented on top of Splunk for most customers, then the data platform expanded into data lakes including Snowflake, Databricks, and Microsoft Azure. Triage and investigation followed over the last two years. In the last year Anvilogic rolled out agents that carry out the work of specific personas, and this year the company launched Blueprints, an orchestrator agent that brings the discrete agents together to run a whole workflow with humans in the loop. What separates a security graph from a frontier model? It knows the environment. Karthik Kannan describes the enterprise security graph as Anvilogic's own model running inside the network, learning the micro environment, with frontier LLMs called on to fill gaps in the macro environment. His argument is that platforms operating as LLM wrappers miss the last mile, because AI on its own reaches 60, 70, or 80 percent of the way if you are lucky. How does a team keep control when agents run the workflow? Through gates, permissions, and a record of what happened. Workflows can be described in plain English, with human gates inserted as often as the team wants. Access controls sit at the persona, organization, and object levels, and activity is audited and logged, which matters to the GRC teams Anvilogic works with. Screens dedicated to what the company calls a maturity score show which feeds are coming in, what kinds of detections exist, and what coverage looks like against the MITRE ATT&CK framework, in a form available to executives and CISOs. Karthik Kannan also points to version 8.0, introduced the week before the event, which includes an Anvilogic MCP Server for connecting to third party tools. Customers are already building their own Blueprint workflows during proofs of concept, including a large life sciences customer Anvilogic expects to feature in a public case study. Karthik Kannan is careful about the claim being made here. This is not a proclamation of an autonomous SOC. It is automation that makes life in a SOC easier and more efficient, adopted at a crawl, walk, run pace, with every step visible along the way. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Karthik Kannan, Founder and CEO at Anvilogic On LinkedIn: https://www.linkedin.com/in/karthikkannan001/ RESOURCES Black Hat USA 2026 event coverage from ITSPmagazine: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Learn more about Anvilogic: https://www.anvilogic.com Anvilogic 8.0, from onboarding to investigation: https://www.anvilogic.com/learn/anvilogic-8-0-automate-the-soc Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS karthik kannan, anvilogic, sean martin, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, agentic secops, ai soc platform, enterprise security graph, detection engineering, triage and investigation, blueprints orchestrator agent, mcp server, mitre att&ck coverage, human in the loop automation, siem and soar, security operations, grc audit logs Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Sean Murphy spent most of the past decade running F5 technology as a customer inside highly regulated environments. He is now about four weeks into the role of Field CISO for North America, and he describes the first month as drinking from a fire hose. Depending on how the math is done, he places F5 among the seven largest cybersecurity companies once BIG-IP is counted as security tooling, with the reasoning running through the CIA triad. Availability is the leg that tends to fall out of the security conversation, and without it there is no resiliency. What changes for a CISO when AI moves from experimentation into production? Sean Murphy points less at speed on its own and more at what he calls the physics behind it. Anyone can build an agent, and people do, which brings shadow AI along for the ride. Forces multiply across speed and scale until the consequences turn existential for some organizations, and governance and visibility land at the feet of the CISO. He argues they should not stop there. Sean Murphy wants a gating step that carries a business justification and a named accountable owner for each agent. His concern is less about who owns what an agent is designed to do and more about who answers for what it does outside that intent. Intention, in his framing, is the new frontier and the new perimeter. What should executive teams understand before approving more agents? Exposure has stopped tracking company size. Adversaries are weaponizing agentic AI, and Sean Murphy describes the curve from vulnerability to exposure to exploit as closed for practical purposes, which removes the hiding places smaller organizations used to count on. Investment in AI innovation needs matching investment in governance and guardrails, or the result surfaces as a data breach or an SEC filing tied to shadow IT and shadow AI. On the technology side, he points to the F5 Application Delivery and Security Platform watching at the customer edge and the regional edge, where AI logic and risk scoring can delay attempts before they reach customer production environments. That delay gives a security team room to detect, respond, recover, and patch on a compressed timeline instead of an almost instantaneous one. It is also why he favors a platform over a set of niche products, with AI risk scoring, runtime analysis, and behavioral alerting in one place a team is trained on. Sean Murphy closes with a story from the customer seat, where F5 protections acquired through Silverline and Shape helped him push off automated botnet attacks and keep the business running, before anyone framed that work as AI. Boards are pressing executive teams on why more is not underway, and his answer is assurance built on capability, with enough friction in place to stay out of the headlines. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Sean Murphy, Field CISO for North America at F5 On LinkedIn: https://www.linkedin.com/in/seanmurphy092009/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Learn more about F5: https://www.f5.com F5 AI Security Platform and the SurePath AI acquisition: https://www.f5.com/company/news/press-releases/f5-ai-security-platform-control-enterprise-risk Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS Sean Murphy, F5, Sean Martin, brand briefing, brand story, brand marketing, marketing podcast, Black Hat USA 2026, field CISO, agentic AI, shadow AI, AI governance, agent accountability, application delivery and security platform, AI risk scoring, web application firewall, board reporting, security leadership Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Sumedh Thakar joined Qualys as an early software engineer on the scanner, back when a 90-day scan cycle came with another 90 days to fix whatever it found. Twenty-three years later he leads the company, and the number he uses now is 90 seconds. At Black Hat USA 2026 he walks through what that compression asks of security teams. So what has actually changed? The questions have not. Where are my assets, what is my assessment of them, what do I prioritize, and what do I fix. Thakar points at the clock instead, citing a CISA directive that gives government agencies three days and zero-day conversations built around a 24-hour window. Layering dashboards on top of that produces what he calls dashboard tourism when nothing gets fixed at the end of it. Qualys organizes its response around three pillars. AI speed detection compresses the gap between a vendor disclosure and a confirmed finding. Hyper prioritization runs an actual exploit to see whether firewall and EDR controls already block it, cutting a theoretical 1% down to roughly 20% of that 1%. Autonomous remediation applies the fix without routing it through a human first. How far along is autonomous patching already? Qualys has deployed over half a billion patches, 150 million of them in the past 12 months, and 40 million of those went out with no human intervention. Thakar describes a global company with 450,000 employees running the agent for autonomous patching, where the board metric is a maximum four-hour exposure window from the time a patch is released rather than a count of vulnerabilities. He expects the monthly patch cadence to give way as disclosures accelerate. Qualys recently released InstaScan, which Thakar calls scanless scanning, delivering a finding within an hour of a vendor disclosure. A patch reliability score built using AI lets an agent judge whether a patch is dependable and reboot-free before applying it on a laptop. His closing advice to CISOs is to show up as a business partner. The board and the CEO need visibility into potential loss, current spend, and whether risk sits inside an acceptable appetite. For a $500 million business that means pricing what a breach would cost, funding the reduction of an $80 million exposure, and transferring what remains to cyber insurance. His shorthand for the operating model is the ROC alongside the SOC. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Sumedh Thakar, President and CEO at Qualys On LinkedIn: https://www.linkedin.com/in/sumedhthakar/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Qualys: https://www.qualys.com/ InstaScan announcement: https://www.qualys.com/company/newsroom/news-releases/usa/qualys-launches-instascan-to-detect-vulnerabilities-within-minutes-of-disclosure Agent Insta and scanless detection: https://blog.qualys.com/product-tech/2026/08/03/instascan-agent-insta-scanless-detection The Risk Operations Center with Enterprise TruRisk Management: https://blog.qualys.com/product-tech/2024/10/09/qualys-launches-enterprise-trurisk-management-the-industrys-first-cloud-based-risk-operations-center Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS Sumedh Thakar, Qualys, Sean Martin, brand briefing, brand story, brand marketing, marketing podcast, Black Hat USA 2026, autonomous remediation, patch management, vulnerability management, hyper prioritization, AI speed detection, scanless scanning, InstaScan, risk operations center, cyber risk management, zero day remediation, CISO, exposure management Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Lisa Liu, Corporate Marketing and Communications Manager at Stellar Cyber, says the AI noise has been running since RSAC Conference, and that what separates vendors now is whether they can back their claims with data their customers gave them. She came to Black Hat USA 2026 with figures on Agentic Auto Triage. The numbers she cites: up to 19 minutes saved per hour per analyst, up to 1.5 full-time analysts per year, and 99.7 percent agreement with the human analyst. Liu treats the accuracy figure as the one carrying the weight. Reacting at machine speed matters only if the verdicts hold, and she describes security as a low trust industry where the burden of proof sits with the vendor. Stellar Cyber is a security operations platform purpose built for MSPs and lean enterprise teams, offering full cycle, full visibility, unified security operations. Liu says the company builds its business logic around the customer pain point, maximizing the efficiency of the resources a team already has. With alerts climbing as attackers pick up the same AI tools as everyone else, she argues that hiring through the volume is out of reach for most teams. So where does reclaimed time go? Liu says that call belongs to the customer. Reported answers include customer relations, other facets of the job, and expanded roles that analysts never had time for. There is a learning effect too. Analysts can see every step of the decision making behind an AI conclusion and draw lessons from it. For managed service providers, Liu says partner analysts deliver more customized services and take in feedback more productively once their schedules loosen up. Where partners serve very different market segments, platform flexibility carries the load, along with full visibility and automation at machine speed. She also hears a shift on the floor: running many separate vendors creates expensive overlap and leaves gaps, and a single platform approach is becoming industry standard. What comes next? Liu places the industry in a proof stage. More validation is necessary, claims about the Agentic SOC keep arriving, and backing those up with more numbers is a large part of moving forward. AI has been part of the Stellar Cyber logic since the company was founded over 10 years ago, and she says that has not changed. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Lisa Liu, Corporate Marketing and Communications Manager at Stellar Cyber LinkedIn: https://www.linkedin.com/in/lisaaliu/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Stellar Cyber: https://stellarcyber.ai/ Stellar Cyber and M-Theory at Black Hat USA 2026: https://www.businesswire.com/news/home/20260728715036/en/Stellar-Cyber-and-M-Theory-to-Demo-Proof-Based-AI-SOC-at-Black-Hat-USA-2026 Stellar Cyber on LinkedIn: https://www.linkedin.com/company/stellarcyber Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS lisa liu, stellar cyber, sean martin, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, agentic auto triage, agentic soc, alert fatigue, security operations platform, mssp, managed security service provider, soc analyst productivity, ai in security operations, autonomous soc, siem replacement, analyst burnout, human in the loop ai Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

On the show floor at Black Hat USA 2026, Marco Ciappelli connected with Dr. Chris Pierson, Founder and CEO at BlackCloak, about a change in where the company draws the line around who gets protected. BlackCloak launched Impersonation Protection several months ago for the C-suite and their families. Clients came back asking for more reach. Why does deepfake risk extend past the executive? Because the people surrounding an executive hold the access attackers want. Pierson lists the trusts and estates attorney, the private wealth manager, the lawyer, the spiritual advisor, the dog walker. Each one is a plausible caller with a legitimate reason to reach out about money, schedules, property, or family. The economics moved too. Pierson contrasts an era when a convincing fake needed something close to a studio operation with what the same result costs now: a laptop, a small sample of audio or video, roughly three minutes of processing, live video and audio. He points to the February 2024 case where a finance employee acted on an impersonated CFO and twenty five million dollars went out the door. The expanded capability lets a member extend coverage across their circle at no cost to the invited contact. Pierson says the platform can now scale to hundreds, thousands, or tens of thousands of individuals at a single company, along with family members and key contacts. The point, as he frames it, is to stop the deepfake where it starts, which is at the human. What changed for executive protection over the past year? Physical and digital stopped being separate programs. Pierson traces that shift to the murder of Brian Thompson, the UnitedHealthcare CEO, and to the questions corporate security teams started asking afterward. Digital breadcrumbs sit on data broker sites and across the deep and dark web, and erasure is unrealistic, which moves the work toward protection rather than removal. That thinking shows up in the product. Members receive travel advisories tied to where they are going, and a CISO can pair a world threat dashboard with cybersecurity guidance for a specific trip. Behind it sits eight years of member data and one of the larger deception networks aimed at individuals, which shows BlackCloak where targeting concentrates, from executive airports to the Olympics to the World Cup. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Dr. Chris Pierson, Founder and CEO at BlackCloak On LinkedIn: https://www.linkedin.com/in/drchristopherpierson/ RESOURCES Black Hat USA 2026 event coverage from ITSPmagazine: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Learn more about BlackCloak: https://blackcloak.io The BlackCloak Digital Executive Protection Platform: https://blackcloak.io/product/ BlackCloak extends deepfake protection to the executive's entire trusted circle: https://blackcloak.io/news-media/blackcloak-extends-deepfake-protection-to-the-executives-entire-trusted-circle/ Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS chris pierson, blackcloak, marco ciappelli, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, digital executive protection, impersonation protection, circle of trust, deepfake, executive protection, ciso, data brokers, threat intelligence, travel advisory, social engineering, wire fraud, personal cybersecurity Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Show Notes There is a version of the music career that gets written about, and there is the version that gets played. Frankie Raye lives in the second one. She performs six or seven nights a week across the greater Tampa Bay area, mixes covers with originals depending on what the room wants, and treats the gig itself as the practice session. She points at old video of herself and measures the distance she has traveled, not against a chart position, but against her own playing. That volume changes how craft works. Frankie Raye does not describe herself as a guitar player. She describes herself as a singer whose guitar carries her voice, and she is direct about the shortcuts that make a set possible: capo up, transpose on the phone, skip the bridge if the chords are ugly, come back to the chorus. The room is singing along to the chorus anyway. What sounds like a confession is closer to a working method, and the results are visible over 12 years of professional performing. Her songwriting has flipped in the past few years. Frankie Raye used to build the music first and squeeze lyrics into it. Now the hook arrives first, often from a conversation or a road sign, and lives in her phone until a riff comes along that fits. A song she is recording this year began as a complaint about venues that want maximum energy on a minimum budget. Another began as a poem written from the passenger seat on a drive south. She performs that one, "Wasting Time," live during the episode. On artificial intelligence she is unambiguous. Frankie Raye does not use it for music, and her objection is not about quality but about origin and consequence: the material was written by people, and the person who could have been hired to write a song for a friend was not hired. That position leads somewhere unexpected. If machine-generated tracks are charting, she reasons, then chasing that sound is chasing something that no longer rewards a human for reaching it. So she stopped. She writes what she wants and releases what she wants, and she has decided against the label path she once wanted, choosing instead a following small enough to know by name. The measure she offers at the end of the conversation is not streams or signings. It is 50 people who bought tickets because they wanted to be in the room. That is a quieter ambition than the industry usually rewards, and it may be the only one currently under an artist's own control. Host Sean Martin, Co-Founder at ITSPmagazine, Studio C60, and Host of Redefining CyberSecurity Podcast & Music Evolves Podcast | Website: https://www.seanmartin.com/ Guest Frankie Raye, Singer-Songwriter | Website: https://frankieraye.com/ Resources Frankie Raye Official Website: https://frankieraye.com/ Frankie Raye Live Show Schedule: https://frankieraye.com/live-show-schedule Frankie Raye Electronic Press Kit: https://frankieraye.com/electronic-press-kit Frankie Raye on Instagram: https://www.instagram.com/frankierayemusic/ Myrtle Beach Songwriters Festival, November 13-14, 2026: https://myrtlebeachsongwritersfestival.com/ Music Evolves: Sonic Frontiers Newsletter: https://www.linkedin.com/newsletters/7290890771828719616/ Keywords frankie raye, sean martin, independent artist, singer songwriter, songwriting process, working musician, live music economy, ai in music, cover songs, gigging, tampa bay music scene, independent music career, hook writing, music, creativity, art, artist, musician, music evolves, music podcast, music and technology podcast More From Sean Martin on ITSPmagazine More from Music Evolves: https://www.seanmartin.com/music-evolves-podcast Music Evolves on YouTube: https://www.youtube.com/playlist?list=PLnYu0psdcllTRJ5du7hFDXjiugu-uNPtW On Location with Sean and Marco: https://www.itspmagazine.com/on-location ITSPmagazine YouTube Channel: https://www.youtube.com/@itspmagazine Be sure to share and subscribe! Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Automation and AI have flooded the sales and marketing side of the market, and Michael Parisi, Chief Growth Officer at Steel Patriot Partners, says the security leaders on the receiving end were already past capacity. The pitch tends to lead with the product rather than the problem. So many CISOs have stopped taking direct sales calls and started asking a different question: what VAR do you work with, and who can I buy you through? That routing puts weight back on partners who know where a program has been and how to move it forward. Parisi describes a partner meeting during the week with RegScale and Wiz, with Steel Patriot Partners in the services role, and the recognition that the company is moving toward systems integration with engineering at the center. Software providers can supply the product. Aligning and configuring it against a specific set of business expectations is a different job. What happens when that job has no owner? Tools get bought and the return never shows up. Parisi sees organizations spending on best of breed and failing to recognize ROI because the tools are not being used or configured against the business objective. The correction is engineering work rather than another purchase. One client was told by its board to cut a significant portion of the IT and information security budget. Steel Patriot Partners looked for overlap, found three tools accomplishing the same business outcome, met the number, and exceeded it on cost savings. Parisi attributes the underlying problem to years of deferred maintenance on the stack, from teams with the appetite to buy tools and without the time to configure them. He expects the consolidation the cloud market saw a decade ago to reach cybersecurity tooling and GRC, and puts a number on it: 48 main GRC providers today, roughly five within five years. Good enough, configured appropriately, beats best of breed sitting idle. For CISOs building the next budget cycle, Parisi recommends bringing the sourcing closer in. Go to your anchor partners, ask what they are running next year and what worked this year, and skip the attempt to talk to everybody. Steel Patriot Partners co-founder Jason Ford has a line that fits alongside it. Have an open mind. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUEST Michael Parisi, Chief Growth Officer, Steel Patriot Partners LinkedIn: https://www.linkedin.com/in/michael-parisi-4009b2261/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Steel Patriot Partners: https://www.steelpatriotpartners.com Steel Patriot Partners at Black Hat USA 2026: https://www.steelpatriotpartners.com/events/black-hat-usa-2026 Steel Patriot Partners Insights: https://resources.steelpatriotpartners.com Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS michael parisi, steel patriot partners, sean martin, brand story, brand marketing, marketing podcast, brand spotlight, black hat usa 2026, ciso budget, channel partners, var, systems integrator, grc consolidation, security tool sprawl, licensing costs, roi, configuration, compliance, cybersecurity engineering, regscale, wiz Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Crogl arrived at Black Hat USA 2026 with two announcements behind it. The week before the show, the company made a free download of its AI SOC agent generally available. On the morning of this conversation, it went public with a major global partner tied to the U.S. Department of Defense. Monzy Merza, Co-Founder and CEO of Crogl, ties both back to a position the company took three years ago, which is that customers should control their own data and a security product should be secure. What does sovereignty mean in security operations? Less about geography, more about control and choice. Merza points to the electric utility that wants current AI technology inside an OT environment and historically had one path, which ran through the internet. Crogl is built to run closed off from the internet with its capability intact, which is what critical infrastructure operators, large banks, and defense organizations need to satisfy their own regulators. There is a second reason, and it lands on intellectual property. A large financial institution holds knowledge about its customers that nobody else holds. If an outside party takes that data and builds derivative work from it, the institution has given away something it never intended to sell. Can a sovereign deployment still be flexible? Merza makes the case that it can when the architecture is right. Customers bring whatever model they want, including models they build. Crogl creates a semantic layer across data stores without transforming, normalizing, or moving the data, so a field labeled one way in one data lake connects to its counterpart in the next. Federated querying and federated search were base principles from the start, and the company holds a patent on the approach. One customer runs a hundred terabytes a day across six data lakes. The operational math is where it gets interesting for the business. An analyst who might close ten alerts in a shift can work fifty or sixty when the rest arrive with a verdict and documentation already attached. Risk drops because alerts actually get investigated, audit cycles move faster because the evidence is there when the auditor asks, and cost follows the data rather than the pipeline. The reaction from practitioners is the part Merza keeps returning to. Rather than worrying about being replaced, the people he talks with are glad to skip the seventeen thousandth phishing email and spend that time on a blast radius question they could not get to before. One person went from a fresh install to a submitted investigation report in under ten minutes and posted about it publicly. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUEST Monzy Merza, Co-Founder and CEO of Crogl | On LinkedIn: https://www.linkedin.com/in/monzymerza/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Learn more about Crogl: https://www.crogl.com Download Crogl: https://www.crogl.com/download Crogl newsroom: https://www.crogl.com/newsroom Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS monzy merza, crogl, sean martin, brand story, brand marketing, marketing podcast, brand spotlight, black hat usa 2026, sovereign ai, ai soc, autonomous investigation, threat hunting, air gapped deployment, ot security, federated search, knowledge graph, alert triage, soc analyst workload, audit evidence, data sovereignty Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

At Black Hat USA 2026 in Las Vegas, Daniel Bardenstein, CEO and co-founder of Manifest Cyber, starts with a gap his team measured in a survey of security leaders and practitioners. Leadership described one version of what is happening with AI inside the enterprise. The people doing the hands-on work described another. Adoption keeps moving, and security teams are working to catch up. So what is the real risk in AI security? Bardenstein puts less weight on non-determinism than most and more on ordinary poor software security, because AI is software. He walks through the OpenAI and Hugging Face incident, where models got out of sandboxes because the sandboxing was weak and the guardrails were missing. When Hugging Face went to use its own AI to defend and run forensics, the guardrails read the request as cyber activity and declined. That fallback to an open weight model points to why he expects open weight adoption to accelerate. With frontier models, the provider sets the system prompt and treats it as intellectual property, so development teams inherit whatever was decided upstream. Open weight leaves more room to control the system prompt, the training data, and how the model gets deployed. What does it mean to say AI has its own supply chain? Unless an organization controls how training data is sourced, housed, labeled, tagged, and modified, it is relying on something someone else built. Public datasets carry whatever is inside them, including personal and health data, licensing exposure, and material no one examined until models were trained and deployed. Models hosted on public hubs sit in the same category. Two asks come up in most CISO conversations with Manifest Cyber. Visibility is one, and few organizations have an AI inventory covering which models run where, inside which applications, and which agents teams have stood up on their own. Third party risk is the other, since AI is getting built into vendor products whether a buyer asks for it or not. That turns model provenance into a trust question about the vendor. Bardenstein started Manifest Cyber four years ago after responding to Log4Shell from the Pentagon, where the question was where one affected piece of code was running across everything the organization had built and bought. Years later, he finds few security leaders who could answer that question quickly about a poisoned model or dataset. His advice for CISOs is to know what is inside what the organization builds and buys, with particular attention to the parts it does not build. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUEST Daniel Bardenstein, CEO and Co-Founder, Manifest Cyber On LinkedIn: https://www.linkedin.com/in/bardenstein/ RESOURCES View all of our Black Hat USA 2026 coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Learn more about Manifest Cyber: https://www.manifestcyber.com Beyond the Black Box: How AI is Forcing a Rethink of Software Supply Chain (research report): https://www.manifestcyber.com/beyond-the-black-box-ai-report Manifest Cyber on LinkedIn: https://www.linkedin.com/company/manifestcyber/ Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS daniel bardenstein, manifest cyber, sean martin, brand story, brand marketing, marketing podcast, brand spotlight, ai supply chain security, software supply chain security, ai inventory, shadow ai, third party cyber risk, open weight models, frontier models, model provenance, hugging face, log4shell, ciso, agentic ai, black hat usa 2026 Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Most vendors at Black Hat USA 2026 have something to say about agentic AI. Jeremy Powell, CISO at Sumo Logic, spends this conversation on the harder proof, which is what happens when a company runs its own product in production at scale. Sumo Logic has been doing that for roughly ten to eleven months. Powell calls it customer zero, and it shapes how he answers almost every question here. The Sumo Logic SecOps team ingests seven exabytes a day globally, which Powell puts at roughly half a billion 8K movies. Against that volume, the team reports 100 percent first level triage handled through automation and about 25 hours saved per analyst per week. Everything learned in production feeds back into the product organization in real time. Security tooling is notoriously hard to use, especially in the enterprise, and Powell is candid that the realization drove a concerted engineering and product effort to fix it. One result showed up at Black Hat this week in the evolved version of Mobot, the conversational interface inside the product. Users can now prompt their way into an investigation, see the audit trail behind it, and get to an answer without configuring their way there first. So how do you trust a decision an agent made? Powell points to an audit trail and a log trail behind every decision the SOC Analyst Agent produces, traceable back through every conceivable log to the root decision. He describes it as human on the loop rather than in the loop. People keep the decisions. Execution and delivery get automated. That changes the shape of the job. Powell describes the SOC becoming something closer to an agile QA organization, where analysts assess the fidelity of what the agent did instead of grinding through first level alerts. On the question of whether automation costs analysts their jobs, he uses a phrase he borrowed from someone else: pay attention to the tension. His answer is that the work gets better and more interesting and the analysts get more capable. The same logic carries up to the board. Powell argues a security leader's job at the executive level is to measure risk transparently and report it accurately, and that boards will build a trend line out of three data points. Telemetry becomes the raw material for informed risk decisions communicated in an executive-friendly way, with the full reasoning available on request. As he puts it, the auditor cares, and the board cares if you fail the audit. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUEST Jeremy Powell, CISO, Sumo Logic LinkedIn: https://www.linkedin.com/in/executivembajeremypowell/ RESOURCES Sumo Logic: https://www.sumologic.com/ Sumo Logic at Black Hat USA: https://www.sumologic.com/events/black-hat Dojo AI agentic security and cloud operations: https://www.sumologic.com/blog/dojo-ai-agentic-security-cloud-operations Building an AI-first SOC, the customer zero story: https://www.sumologic.com/blog/building-ai-first-soc-customer-zero See Mobot in action: https://youtu.be/ZZLXaft7tYM View all of our Black Hat USA 2026 coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS Jeremy Powell, Sumo Logic, Sean Martin, brand story, brand marketing, marketing podcast, brand spotlight, Black Hat USA 2026, agentic AI, SOC analyst agent, security operations center, human on the loop, first level triage, security automation, telemetry, exabyte scale, customer zero, Mobot, conversational interface, CISO, board reporting, risk communication, SIEM, AI governance Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Security leaders count open vulnerabilities in the hundreds of thousands, and in some organizations the number runs past a million. Ondrej Vlcek, Co-Founder and CEO of AISLE, describes teams with no practical route through that backlog while attackers use automation to shrink the time between a disclosure and a working exploit. The question worth asking is what a program looks like when remediation moves at the same speed as exploitation. What makes AI-driven remediation different from static code analysis? Reasoning replaces pattern matching. Linters and commercial scanners flag code that resembles a known error shape, while a reasoning model infers what the developer intended, compares that intent against the actual implementation, and evaluates how the gap could be abused. Ondrej Vlcek points to business logic flaws, timing errors, and race conditions as the classes that pattern matching leaves untouched. The judgment behind AISLE comes from a long run in the industry. Ondrej Vlcek wrote device drivers for Windows 95 in 1995 at a seven-person antivirus company called Avast, stayed more than twenty-five years, moved through CTO and COO into the CEO seat, and took the company public before its sale to NortonLifeLock in 2022. He co-founded AISLE in 2024 with Jaya Baloo, a three-time public company CISO, and Stanislav Fort, an AI researcher who worked at DeepMind and Anthropic. Why does the software supply chain deserve the larger share of attention? Because most of the code in a running application was written somewhere else. Ondrej Vlcek puts the typical enterprise application at roughly ten percent first-party code and ninety percent open source and dependency code, which is also level ground for an attacker reading the same source and pointing the same models at it. Reachability analysis becomes the deciding factor, separating the vulnerable functions your code actually calls from the thousands of transitive dependencies it never touches. For first-party code, AISLE closes the loop differently: read the documentation, the architectural material, and the threat model, then generate a patch aligned with the project's own conventions and test it automatically. The standard Ondrej Vlcek sets is a fix that reads as though a human maintainer wrote it. The customer spread runs from embedded firmware at Bose to smart contracts at the Ethereum Foundation, where heavily audited and sometimes formally verified code still benefits from another set of checks because the systems touch money flows directly. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUEST Ondrej Vlcek, Co-Founder and CEO of AISLE On LinkedIn: https://www.linkedin.com/in/ondrejvlcek/ RESOURCES Learn more about AISLE: https://aisle.com Meet AISLE at Black Hat and DEF CON in Las Vegas: https://aisle.com/black-hat The AISLE platform: https://aisle.com/platform AISLE CVE discoveries: https://aisle.com/cve-discoveries Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS ondrej vlcek, aisle, sean martin, brand story, brand marketing, marketing podcast, brand spotlight, vulnerability management, vulnerability remediation, agentic ai, cyber reasoning system, software supply chain security, reachability analysis, open source security, application security, first-party code, third-party dependencies, static code analysis, zero-day vulnerabilities, ai in cybersecurity, code patching, embedded firmware security, smart contract security Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Sean Martin catches John Sotiropoulos and Rock Lambros at the end of the OWASP GenAI Security Summit, held alongside Infosecurity Europe 2026 at ExCeL London. Both are deep in the standards work: John Sotiropoulos co-leads the OWASP Agentic Security Initiative and sits on the board of the OWASP GenAI Security Project, and Rock Lambros serves as Director of AI Standards and Governance at Zenity and co-leads the OWASP Top 10 for LLM 2026 update. The headline from the day is the launch of the Agentic Security Council, bringing Oxford University, Queen's University Belfast, CSIT, and other research institutions into the same room as practitioners and industry. John Sotiropoulos frames the reasoning bluntly: content on its own does not create change. Papers and Top 10 lists matter, but they only matter if the people building and defending systems can act on them. The number that reframes everything is twenty-two seconds. That is the average time from an initial access event to the next attacker action, down from eight hours. John Sotiropoulos puts the question directly to anyone still running a human-speed playbook: how do you respond to that? A panel on incident response with participants from AWS and Microsoft, a keynote from Microsoft's National Security Officer, and a walkthrough of the State of Agentic Security and Governance report all point at the same shift toward runtime security. Rock Lambros brings a different kind of grounding. For the first time in the four-year history of the OWASP Top 10 for LLM, the update draws on a corpus of reported incidents rather than opinion and community vote alone. It is one data point among several, but it is data, and that changes what the list can claim. A panel with the heads of AI security at Deloitte supplies the operational counterweight. As one of them puts it, security has to stop being the Ministry of No, because people will route around it and ship anyway. The report's adoption tiers and maturity levels exist for exactly that reason: security that lives only inside a PDF is not security. The invitation from both John Sotiropoulos and Rock Lambros is the same. Join the work. Research, red teamers, defenders, builders, and SecOps all looking at one view of what is actually happening is the only version of this that scales to machine speed. ⬥HOST⬥ Sean Martin, CISSP | Co-Founder, ITSPmagazine & Studio C60 | Host, Redefining CyberSecurity Podcast & Music Evolves Podcast | https://www.seanmartin.com/ ⬥GUESTS⬥ John Sotiropoulos, Deep Cyber | Co-Lead, OWASP Agentic Security Initiative; Board Director, OWASP GenAI Security Project | On LinkedIn: https://www.linkedin.com/in/jsotiropoulos/ Rock Lambros, Director of AI Standards and Governance, Zenity; Founder, RockCyber | Co-Lead, OWASP Top 10 for LLM 2026 | On LinkedIn: https://www.linkedin.com/in/rocklambros/ ⬥RESOURCES⬥ Infosecurity Europe 2026 is taking place June 2-4, 2026 | ExCeL London. Follow our coverage: https://www.itspmagazine.com/infosecurity-europe-2026-infosec-london-cybersecurity-event-coverage OWASP GenAI Security Project | https://genai.owasp.org Contribute to the OWASP GenAI Security Project | https://genai.owasp.org/contribute The Future of Cybersecurity Newsletter | https://www.linkedin.com/newsletters/7108625890296614912/ Redefining CyberSecurity Podcast | https://www.seanmartin.com/redefining-cybersecurity-podcast On Location | https://www.itspmagazine.com/on-location

FedRAMP has changed before. What makes the Consolidated Rules for 2026 different is that the dates are on the calendar and the fence sitters have run out of runway. Jason Ford, Co-Founder and CEO of Steel Patriot Partners, has been inside the program since Rev 3 in 2013. Michael Parisi, Chief Growth Officer, comes at it from the business side. Together they map what changes and, more usefully, what it means for the decision in front of a provider right now. So what actually changes? The program consolidates into two paths, 20X and Rev 5. FedRAMP Ready moves to legacy status. Class A, B, and C pipelines open across a thirty to sixty day window, mandatory adoption arrives January 1, and new Rev 5 certifications close on June 11, 2027. Authorized becomes certified. Jason Ford also points out where the rules live: fedramp.gov, hosted in GitHub, which means they move with a commit. Reading them once is not tracking them. Why did FedRAMP need to change at all? Michael Parisi frames it as a supply problem. Agencies and primes have been working from a limited and aging set of technologies while better tools sat outside a process that was slow, rudimentary, and expensive. The action was warranted. His follow-up question gets less airtime: if the process moved faster, did responsibility move with it, and does the stakeholder now holding that due diligence know it yet? The engineering shift is real and it is the part most teams see coming. Jason Ford describes RMF thinking giving way to continuous DevSecOps, proving compliance in real time rather than at a point in time. Vulnerability remediation is where the compression bites. CISA's updated guidance drops severity score as the driver in favor of stepped prioritization, and windows that used to run 30, 60, and 90 days now land closer to three to twenty-one. What does this cost a business past the budget line? Time and capacity. 20X is faster than a Rev 5 process that once ran eighteen months, but faster is not instant. Retraining a couple hundred users inside a thousand-person organization is not a small endeavor, and if the transition eats half of the organization's capacity for a year, that is half as much capacity aimed at the business paying for it. Jason Ford is not arguing against the move. He is arguing that disruption belongs inside the decision. Then there is the internal work almost nobody has started. Mapping an existing Rev 5 ATO scope into a new certification level is not clear-cut, and past the mapping, marketing and sales both need re-education. Michael Parisi describes building a translation layer for customers: here is what we provided before, here is what it is now, and this change came from the program rather than from any reduction in assurance. Roughly half the time, Steel Patriot Partners tells organizations not to pursue certification at all. Michael Parisi treats that as one of the more valuable things the firm does. The opposite failure shows up just as often, with companies preparing to spend heavily on 20X because it sounds quicker and cheaper, when the agency or prime they are chasing expects a certification level. A lower bar only helps if the buyer accepts it. Where should a business start? With the business conversation. Michael Parisi notes the answer does not have to be yes or no today; it can be a maybe with defined trigger points. Jason Ford closes on posture: come with an open mind, and do not hand a multi-year commitment to a language model whose guardrails and training are not built for that call. Or, shorter: don't wait, and don't go it alone. Steel Patriot Partners built a three-question starting point for that first conversation at https://www.steelpatriotpartners.com/find-your-path. This is a Brand Story. A Brand Story is a ~35-40 minute in-depth conversation designed to tell the complete story of the guest, their company, and their vision. Learn more: https://www.studioc60.com/creation#full GUESTS Jason Ford, Co-Founder and Chief Executive Officer, Steel Patriot Partners On LinkedIn: https://www.linkedin.com/in/jason-ford-5ab206/ Michael Parisi, Chief Growth Officer, Steel Patriot Partners On LinkedIn: https://www.linkedin.com/in/michael-parisi-4009b2261/ RESOURCES Learn more about Steel Patriot Partners: https://www.steelpatriotpartners.com/ FedRAMP's Consolidated Rules for 2026: What It Means for Cloud Providers: https://resources.steelpatriotpartners.com/fedramps-consolidated-rules-for-2026 Find Your Path, a three-question starting point for ISO, CMMC, and FedRAMP decisions: https://www.steelpatriotpartners.com/find-your-path Complimentary ROI Workshop: https://www.steelpatriotpartners.com/roi-workshop Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS jason ford, michael parisi, steel patriot partners, sean martin, brand story, brand marketing, marketing podcast, fedramp, fedramp consolidated rules for 2026, fedramp 20x, rev 5, fedramp certification classes, cloud service provider compliance, federal compliance, cisa vulnerability remediation, continuous monitoring, devsecops, ato, 3pao, govramp, cmmc, grc, federal marketplace, compliance roi Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

For companies in the defense industrial base, a compliance deadline is not paperwork. It is the difference between winning contracts and watching them stall. In this Brand Feature, Jason LaPointe, Chief Technology Officer at Exostar, and Michael Parisi, Chief Growth Officer at Steel Patriot Partners, walk through what it takes to get FedRAMP ready without cutting corners. Exostar was born out of a consortium that included Boeing and Lockheed Martin, and its FedRAMP-moderate posture lets smaller suppliers keep working on Department of War contracts. How does that work? Instead of moving every server and mailbox into a secure boundary, a supplier inherits roughly 80% of the controls from Exostar, which shrinks the scope of its own CMMC audit considerably. The clock was real. At the time, a November transition date loomed, after which many suppliers could no longer self-attest. That specific timeline has since been paused, but the pressure to prove readiness has not gone away. Exostar needed to show it was FedRAMP-moderate and ready for an audit, and working with Steel Patriot Partners, the team pulled a January target in by nearly three months, not by skipping steps, but by moving with confidence. Why build a new platform instead of retrofitting the old one? Jason LaPointe describes a platform first initiative: build the new compliant home, then migrate customers into it. Trying to modernize inside a live production environment would have been disruptive, so the team built alongside rather than on top, which freed them to re-architect and retool without breaking customers. Michael Parisi frames the engagement as embedding, not staff augmentation. Steel Patriot Partners plugged directly into the product team through daily standups and leadership calls, delivered infrastructure as code and deployment pipelines, and kept the work with US citizens, a requirement once controlled unclassified information is in play. What makes an audit go smoothly? Preparation that extends to how questions get answered. Jason LaPointe compares the audit to a deposition, where an unsolicited comment hands an assessor somewhere new to go. Michael Parisi, who spent years in the assessor's seat and ran the practice for a large C3PAO, explains why knowing the auditors and presenting information cleanly protects the outcome. The business math is unforgiving. Miss the audit window and millions in direct contracts can be exposed, while auditors book out six to eight months. Exostar cleared it with a clean, no POA&M result, and the business is now seeing tailwinds through initiatives like Golden Dome. The lesson Jason LaPointe offers other technology and security leaders is about temperament. Every part of the organization gets touched, from R&D to HR to finance, and the willingness to change quickly becomes the governor on success. Having a clear voice at the table for what good looks like, as Steel Patriot Partners provided, is what accelerates the decisions. This is a Brand Feature. A Brand Feature is a ~30 minute in-depth conversation designed to go deep on a company's story, solutions, and customer success. Learn more: https://www.studioc60.com/creation#feature GUESTS Jason LaPointe, Chief Technology Officer, Exostar Website: https://www.exostar.com/ LinkedIn: https://www.linkedin.com/in/jasonlapointe Michael Parisi, Chief Growth Officer, Steel Patriot Partners Website: https://www.steelpatriotpartners.com/ LinkedIn: https://www.linkedin.com/in/michael-parisi-4009b2261/ RESOURCES Learn more about Exostar: https://www.exostar.com/ Aerospace and Defense solutions from Exostar: https://www.exostar.com/industries/aerospace-defense/ Learn more about Steel Patriot Partners: https://www.steelpatriotpartners.com/ Find Your Path with Steel Patriot Partners: https://steelpatriotpartners.com/find-your-path/ Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS Jason LaPointe, Michael Parisi, Exostar, Steel Patriot Partners, Sean Martin, brand story, brand marketing, marketing podcast, brand feature, FedRAMP, FedRAMP-moderate, CMMC, CMMC 2.0, defense industrial base, DIB, controlled unclassified information, CUI, compliance inheritance, C3PAO, FedRAMP audit, platform modernization, GCC High, Department of War, defense supply chain, cybersecurity compliance Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

PODCAST EPISODE | An Analog Brain In A Digital Age With Marco Ciappelli Fifteen years ago, Rose Ross brought a client an idea for an awards program built specifically for enterprise tech startups. The client passed. She built it herself — and the Tech Trailblazers have been running ever since, independent, judged by practitioners, and open for entries until 3 September.

PODCAST EPISODE | An Analog Brain In A Digital Age With Marco Ciappelli Every organization has a policy on AI. Most of them are unwritten, unspoken, and enforced by silence. Priyanka Dave — behavioral scientist, dual PhD, and the person responsible for teaching an entire university system how to work with these tools — explains what actually happens inside a company that refuses to say the word out loud.

⬥EPISODE NOTES⬥ Tidal is about to stop paying royalties on any track it judges to be fully machine-made. Frame that as a music story and you miss the shift underneath it. By Deezer's own detection, roughly 75,000 AI-generated tracks now arrive every day, about 44% of everything uploaded, yet that same AI music is only 1 to 3 percent of what people actually play, and around 85% of those streams are flagged as fraudulent. The flood is not an audience. It is an attack on a shared payout. This edition follows one pattern across six industries: when the cost of generating something collapses toward zero, platforms stop paying for output and start paying for proof of human origin. Tidal cuts AI royalties. The Authors Guild sells a "Human Authored" badge for ten dollars a title. YouTube demonetizes "inauthentic" content. curl killed its bug bounty after a flood of AI slop, then reopened when the slop got good. And where no gatekeeper owns the payout, hiring, the open web, the scientific record, the flood just degrades the mechanism until no one trusts it. In this edition of Lens Four:

⬥EPISODE NOTES⬥ Almost every booth at Infosecurity Europe 2026 had settled on the same four words. Outcomes. Resilience. Sovereignty. Human in the loop. The messaging had grown up, more tempered than RSAC, more honest in its European register. The tell was quieter — almost none of it could connect those words to a definition of success a buyer could actually verify. Strip away the polish and the show floor was a working argument about what the cybersecurity market is for, at the exact moment the clock that governs it collapsed to seconds. The go-to-market caught up to the language. The capability did not. This is the prove-it problem, and it is worth pulling apart clearly. In this edition of Lens Four:

ON LOCATION | Sean Martin & Marco Ciappelli — Infosecurity Europe 2026 Two conferences, two moods: at RSA the drumbeat was resilience; at InfoSec, it's sovereignty. Sean and I close the week with Forrester analyst Madelein van der Hout — beaming in from the Netherlands — on why Europe makes a framework out of everything, what AI deployment is doing to the boardroom, and the security jobs that don't exist yet.

For most of the internet's life, proving identity has meant proving something you know or something you hold: a password, a code, a text message. Kevin Surace, CEO of TokenCore, argues that era is closing fast. As one of the people who helped invent the AI assistant at General Magic, he has a clear view of why the same technology now makes faces and voices simple to fake. Why isn't MFA enough? Because it protects a weak foundation. A decade-old paper mapped fifteen ways to defeat SMS codes, auth apps, and push approvals. Few attackers bothered with them until platforms like Salesforce and Microsoft made those methods mandatory. Now the attack has moved to where the door is. Surace walks through one of the common methods: an AI-written phishing email from a service you already trust, a PDF, and a pixel-perfect login page generated in moments. The credentials you enter relay to an attacker who is logging into the real site in real time. The push prompt asks if it is you, you approve, and the intruder is inside within minutes. The numbers back it up. Palo Alto Networks Unit 42 found that roughly ninety percent of successful intrusions over the past year involved hacked identity, almost all of them MFA or auth apps. The people compromised had privileged access, which means they had MFA in place. So what actually works? Surace makes the case for biometric-assured identity, a category Gartner projects growing into a twelve billion dollar market. TokenCore ties access to a fingerprint stored only on your device, the exact domain your account lives on, and physical proximity over a short-range wireless link. Look-alike domains never register, remote relays never get close enough, and the company never holds your biometric. The hardware comes as a ring, a portable, or a node about the size of an AirTag, and it is FIDO2 compatible, so it works with existing single sign-on. Most customers go passwordless once it is running. The reaction Surace hears most often from security leaders is that they can finally sleep at night. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUEST Kevin Surace, Chief Executive Officer, TokenCore LinkedIn: https://www.linkedin.com/in/ksurace/ RESOURCES Learn more about TokenCore: https://www.tokencore.com Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS Kevin Surace, TokenCore, Sean Martin, brand story, brand marketing, marketing podcast, brand spotlight, biometric assured identity, identity security, multi-factor authentication, MFA bypass, phishing resistant authentication, FIDO2, credential theft, passwordless, deepfake, AI security, account takeover, Unit 42, Gartner Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

In this Brand Highlight, Kevin Surace, CEO of TokenCore, catches up on a market that has accelerated faster than even his team expected. Biometric-assured identity has gone from the fringes to the core, and the clearest example is the video call: on Zoom or Teams, there is often no reliable way to know whether the person on screen is real, human, or an AI avatar. Surace points to cases where employees wired money because a synthetic version of their boss appeared to ask for it. That risk is pushing the work outward. Beyond using TokenCore internally, the larger banks are asking how to extend biometric assurance to the customers who move wires, because a phone call no longer confirms who is actually on the line. The goal is to know that it is the right person, on the right domain, within a few feet of the device, and not someone operating from another country. For security leaders, Surace offers direct advice: start moving off MFA and authenticator apps now, since those methods are being compromised constantly. He acknowledges the change is hard, often for cultural reasons more than technical ones, and suggests starting with admins and the people who touch real data before expanding over roughly a year. The upside, he notes, is that employees tend to welcome it, going passwordless or even ID-less and logging into tools like Salesforce in under two seconds. This is a Brand Highlight. A Brand Highlight is a ~5 minute conversation that captures a focused idea, update, or perspective from the guest. Learn more: https://www.studioc60.com/creation#highlight GUEST Kevin Surace, Chief Executive Officer, TokenCore LinkedIn: https://www.linkedin.com/in/ksurace/ RESOURCES Learn more about TokenCore: https://www.tokencore.com Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS Kevin Surace, TokenCore, Sean Martin, brand story, brand marketing, marketing podcast, brand highlight, biometric assured identity, identity security, deepfake, AI avatar, video call security, MFA, passwordless, FIDO2, CISO, account takeover, wire fraud, Zoom security, identity assurance Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

A rugby World Cup winner walks into a room full of people who defend networks for a living. Maggie Alphonsi joins me to talk about breaking barriers, leading with your strengths, and what changed the day athletes stopped waiting for the back page and started telling their own stories.

PODCAST EPISODE | An Analog Brain In A Digital Age With Marco Ciappelli — On Location at Infosecurity Europe 2026 The most dangerous attacks at Infosecurity Europe 2026 weren't the high-tech ones. Lee Clark of the Retail & Hospitality ISAC sits down with me to explain why the soft target is still a human being — a help desk, a new hire, a phone ringing at dinner — and what stays in our hands as the shopper quietly becomes an algorithm.

A ransomware crew can run through your whole company between dinner and dessert. Sean Martin sat down with Cynthia Kaiser — twenty years at the FBI, now leading the Halcyon Ransomware Research Center — on the speed of the threat, the human cost the industry keeps abstracting away, and why a slice of ransomware deserves a harder name than “crime.”

⬥EPISODE NOTES⬥ What does it take to lead a 200-person security organization without coming up through the technical ranks? Tera Ladner, Deputy Global Chief Information Security Officer at Aflac, answers that question by describing a path that runs through information management, e-discovery, and a law degree before it ever reaches the security org chart. The result is a leader who looks at a program through the lens of controls, evidence, and defensibility, and who treats security as a people problem before a technology one. Host Sean Martin and Tera Ladner dig into what that orientation changes in practice. Rather than opening a stakeholder conversation with controls or threats, Tera Ladner starts by listening: what are the business goals, and how does security enable them? Working inside an insurance company helps, because risk is already the shared language of every leader in the building. The job, as she frames it, is translation, turning a technical event into a business and resiliency impact that the people who own the decisions can actually act on. The conversation turns to hiring and team building, where Tera Ladner names curiosity as the first trait she screens for, the instinct to ask the second, third, and fourth question until the real problem surfaces. From there she argues for a broader "tool belt": storytelling, relationship building, influence without authority, and the ability to navigate ambiguity, a skill she sees tested daily as boards and technology leaders press for answers on frontier AI. Technical skills alone, she suggests, were enough years ago and are not enough now. Culture sits at the center of how she leads. "Your team lives in the house that you build," she tells her people leaders, and she describes the team norms, transparency, integrity, and care, that hold a security organization together in the hard moments. That same relationship-first instinct extends outward, to a seat at the executive table that has to be earned by giving stakeholders a seat at yours, and downward into the talent pipeline through Aflac's Cyber Inspire and Empower Girls programs, which grew from 200 girls in their first local year to 815 in the second. For security and risk leaders, the throughline is hard to miss: the future of the field depends less on finding more technologists and more on building leaders who can listen, translate, and bring people who never saw themselves in cyber to the table. ⬥GUEST⬥ Tera Ladner, Deputy Global Chief Information Security Officer at Aflac On LinkedIn: https://www.linkedin.com/in/teraladner/ ⬥HOST⬥ Sean Martin, Co-Founder at ITSPmagazine, Studio C60, and Host of Redefining CyberSecurity Podcast & Music Evolves Podcast | Website: https://www.seanmartin.com/ ⬥RESOURCES⬥ Aflac: https://www.aflac.com/ Cyber Inspire and Empower Girls (Aflac community programs introducing students and seniors to cybersecurity): https://www.linkedin.com/company/cyberinspire The Future of Cybersecurity Newsletter: https://www.linkedin.com/newsletters/7108625890296614912/ More Redefining CyberSecurity Podcast episodes: https://www.seanmartin.com/redefining-cybersecurity-podcast Redefining CyberSecurity Podcast on YouTube: https://www.youtube.com/playlist?list=PLnYu0psdcllS9aVGdiakVss9u7xgYDKYq ⬥ADDITIONAL INFORMATION⬥

There is a con called the Spanish Prisoner. A letter arrives from a stranger: a wealthy man sits in a foreign jail, and for a small advance to free him, he will reward you many times over. The trick is at least four hundred years old. It is also, give or take a few details, the email sitting in your spam folder this morning. I keep that in mind whenever someone tells me cybercrime is a technology problem. The tools change. The mark does not. We are still robbed through the same prehistoric wiring: a flash of fear, a moment of greed, a decision made in panic before the slow part of the brain wakes up. That is the thread I pulled on with Sarah Armstrong-Smith at InfoSecurity Europe. Sarah spent nearly thirty years in cyber and crisis leadership, was Chief Security Advisor at Microsoft, and now runs Secure Horizons. She has written two books on the human side of all this and sits on the UK Government Cyber Advisory Board. After all of it, she says the thing most people in her position will not say out loud: whatever we are doing is not working. More tools, more money, more people, more AI, and the problem keeps getting worse. Attack, wake-up call, attack, wake-up call. How many wake-up calls, she asks, does anyone need? I asked what keeps her up at night. She described an industrial accident on the scale of 9/11, triggered through a network: the first time a cyber incident kills people in numbers. We have been lucky so far. She doubts luck is a plan. The industry loves a big number, and the number is exactly where the human disappears. X million records stolen, Y terabytes gone. The day before, my friend Geoff White sat in this same chair and described a ransomware attack that shut down a hospital, which meant a woman missed the cancer appointment she had counted on. That is an Armageddon, and it has a name and a face. Sarah, as it happens, knows Geoff's work well enough to carry a line from him on the back of her book. The human element keeps finding the same small circle of people willing to talk about it. So how do we move this from a line item to a fact of society? Her answer is collective resilience. There is no prize for being the last one standing, because we are all wired into the same supply chain, the same dependencies, the same brittle web. And the smallest businesses, the ones without a war chest to ride out the storm, are the ones we discuss the least. Then a statistic. Close to half of all crime in the UK is now fraud or cyber. Around one percent of policing is pointed at it. Read those two numbers again. We fund what we can see, and we want officers on the street because a visible patrol both deters the thief and reassures the neighbourhood. The crime that actually empties our accounts happens somewhere we have agreed not to look. Follow the money, Sarah says, and you rarely stop at one criminal's pocket. It pays for the next thing: drugs, weapons, and more often than people imagine, the trafficking of human beings. Will AI save us? She did not flinch. Whatever you build to detect, the other side uses to evade. The asymmetry holds. Technology is part of the answer and never the whole of it, because the problem was never only technical. So what do we carry forward, and what do we leave behind? We carry the person behind the number: the one who misses the appointment, the small shop that never reopens. We leave behind the fantasy that a clever enough machine will spare us the harder work, which is teaching a whole society to recognize the Spanish Prisoner when it arrives, wearing this year's technology. Sarah's books are linked below, with a second edition on the way. Geoff's conversation is part of this same coverage. And if you want more of these, the newsletter lives at marcociappelli.com. Let's keep thinking. — Marco Co-Founder ITSPmagazine & Studio C60 | Creative Director | Branding & Marketing Advisor | Personal Branding Coach | Journalist | Writer | Podcast: An Analog Brain In A Digital Age ⚠️ Beware: Pigs May Fly |

Show Notes What happens to creativity when every song, sound, and style is a thumb-tap away? Sam Young has spent more than two decades behind the decks in London, and his answer is blunt: originality is at an all-time low. As a DJ, producer, remixer, and founder of the record label WyldCard, he sits at the exact point where taste, technology, and commerce collide, and he sees a culture increasingly content to recycle what already works. Sean Martin and Sam Young dig into how algorithms quietly shape what listeners believe they like, and how that pressure reaches the dance floor. Sam Young draws a clear line between a club night, where a crowd shows up hungry for records it has never heard, and a private event, where the real skill is reading a host's taste from the handful of songs they send and still making the room move. The throughline is judgment, the human ear that no recommendation engine has learned to replace. The conversation turns to sampling, AI, and the difference between craft and shortcut. Sam Young runs A&R for WyldCard himself, listening to demos every week, and he can hear within seconds when a producer is chasing a trend instead of setting one. His distinction is sharp: taking something obscure and making it feel new is an art, while feeding a recognizable hook into a tool and printing one more cover version is not. He is candid about AI as a cheat code, and just as candid about a near future where producers simply talk to their software and ask for ten options. This is not a lament, though. Sam Young points to the rare artists who still cut through precisely because they refuse to sound like everyone else, and to a younger generation quietly rediscovering originality. The optimistic version of the story is the one Sean Martin keeps circling back to: technology at its best clears away the busywork so the mind stays in control of what gets made. The question this episode leaves open is whether the tools that make music easier to produce will widen the gap between the familiar and the genuinely new, or finally close it. Host Sean Martin, Co-Founder at ITSPmagazine, Studio C60, and Host of Redefining CyberSecurity Podcast & Music Evolves Podcast | Website: https://www.seanmartin.com/ Guest Sam Young, DJ, Producer, and Remixer | Founder of WyldCard Records (production aliases Vanilla Ace and Sammy Deuce) | Website: https://djsamyoung.com/ Resources DJ Sam Young | https://djsamyoung.com/ WyldCard Records on SoundCloud | https://soundcloud.com/vanillaace Music Evolves: Sonic Frontiers Newsletter | https://www.linkedin.com/newsletters/7290890771828719616/ Keywords sam young, vanilla ace, sammy deuce, wyldcard, sean martin, dj culture, music and ai, sampling, algorithms and music taste, originality in music, house music, record label a&r, nu-disco, music production, creativity, art, artist, musician, music evolves, music podcast, music and technology podcast More From Sean Martin on ITSPmagazine More from Music Evolves: https://www.seanmartin.com/music-evolves-podcast Music Evolves on YouTube: https://www.youtube.com/playlist?list=PLnYu0psdcllTRJ5du7hFDXjiugu-uNPtW On Location with Sean and Marco: https://www.itspmagazine.com/on-location ITSPmagazine YouTube Channel: https://www.youtube.com/@itspmagazine Be sure to share and subscribe! Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

PODCAST EPISODE | Redefining CyberSecurity With Sean Martin — On Location at InfoSecurity Europe 2026 On Location With Sean Martin And Marco Ciappelli Adversaries are stealing encrypted data today that they cannot read yet, and storing it until a quantum computer can. Sean Martin sat down with Forescout's Rik Ferguson to talk about “harvest now, decrypt later,” why Q-Day is closer than the comfortable timelines suggest, and what the decisions you make this year have to do with secrets you thought were safe forever.

PODCAST EPISODE | An Analog Brain In A Digital Age — On Location at InfoSecurity Europe 2026 On Location With Sean Martin And Marco Ciappelli Bronwyn Boyle can talk about software vulnerabilities for hours. Talking about her own — the burnout she didn't recognize until someone named it — turned out to be harder, and more important. We sat down at InfoSecurity Europe to talk about the human cost of guarding the machine, and whether our analog brains were ever built for this.

PODCAST EPISODE | Redefining CyberSecurity With Sean Martin — On Location at InfoSecurity Europe 2026 On Location With Sean Martin And Marco Ciappelli The UK's threats change by the day. Its laws change over years. Sean Martin sat down with James Morris — former Member of Parliament, now Director of the CSBR — to ask how a government writes cyber policy fast enough to matter, and why “resilience” has quietly stopped being a technical word.

At Infosecurity Europe 2026, Jeanclaude Toma, Chief Executive Officer of Apricorn, joins Sean Martin to reframe where secure storage fits in the security conversation. After roughly four decades building hardware-encrypted drives, Apricorn wants the market to treat storage as a security decision rather than a hardware afterthought. How does a storage device become a security control? Toma points to the device itself: no one reaches the data without the code. Access requires a PIN entered on the drive, and the encrypted vault stays closed to everyone else. The protection travels with the drive and does not depend on the host system. Apricorn builds to FIPS certification requirements, hardens against environmental stress down to the connector, and tests repeatedly so compliance arrives built in. Why does this matter at the macro scale? Toma joined Apricorn three months ago to expand the portfolio and connect storage to the broader security marketplace, from military, government, and aerospace settings to the enterprise. He also hints at new form factors still under wraps. Listen in to hear why Apricorn treats the business and operations behind the product as seriously as the product itself. This is a Brand Highlight. A Brand Highlight is a ~5 minute introductory conversation designed to put a spotlight on the guest and their company. Learn more: https://www.studioc60.com/creation#highlight GUEST Jeanclaude Toma, Chief Executive Officer, Apricorn LinkedIn: https://www.linkedin.com/in/jeanclaude-toma/ RESOURCES Learn more about Apricorn: https://apricorn.com Infosecurity Europe 2026 coverage from ITSPmagazine: https://www.itspmagazine.com/infosecurity-europe-2026-infosec-london-cybersecurity-event-coverage Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS Jeanclaude Toma, Apricorn, Sean Martin, brand story, brand marketing, marketing podcast, brand highlight, hardware-encrypted storage, FIPS certified storage, secure data storage, encrypted USB drives, data protection, Infosecurity Europe 2026, secure peripherals, PIN authenticated storage Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

At Infosecurity Europe 2026 in London, VimalRaj Sampathkumar, Head of Technical Operations for the UK and Ireland at ManageEngine, opens with a sharp observation: the market does not lack tools, it lacks tools that work together. After 16 years with the company, he has watched IT and security teams collect software faster than they can connect it. ManageEngine, a division of Zoho Corporation, builds roughly 60 products across endpoint management, IT operations, service management, and identity and access management. The point is not the count. VimalRaj Sampathkumar explains how tight integration lets those products share data, run automations, and power workflows, so a process like joiner-mover-leaver can be shaped to how each organization actually works instead of forced into a template. That same logic carries into cybersecurity. Customers rarely ask for one feature; they ask how to strengthen their posture and reach resilience. ManageEngine answers with solutions that scale from a single tool to a full suite, backed by flexible licensing and an AI roadmap. It is a look at why consolidation, not collection, is becoming the smarter security strategy. This is a Brand Highlight. A Brand Highlight is a ~5 minute introductory conversation designed to put a spotlight on the guest and their company. Learn more: https://www.studioc60.com/creation#highlight GUEST VimalRaj Sampathkumar, Head of Technical Operations, UK & Ireland, ManageEngine LinkedIn: https://www.linkedin.com/in/zenandzipfiles/ RESOURCES Learn more about ManageEngine: https://www.manageengine.com Infosecurity Europe 2026 coverage: https://www.itspmagazine.com/infosecurity-europe-2026-infosec-london-cybersecurity-event-coverage Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS VimalRaj Sampathkumar, ManageEngine, Zoho Corporation, Sean Martin, brand story, brand marketing, marketing podcast, brand highlight, IT management, IT security, endpoint management, identity and access management, IT operations, integration, consolidation, cyber resilience, Infosecurity Europe 2026 Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

At Infosecurity Europe 2026 in London, Bill Peterson, Senior Director of Product Marketing at Sumo Logic, joins us to unpack a tension every regulated security team knows well. When an incident hits, the business has to keep running. At the same time, regulators expect sensitive data to stay in region. For a long time, those two demands have pulled in opposite directions. Sumo Logic has spent 15 years as a SaaS platform on AWS, processing roughly four exabytes of data a day for around 2,000 customers. The core promise is speed, driving mean time to resolve as low as possible. Peterson frames it in business terms, because the person signing the check wants to know the return, not the bits and bytes. The news from the show is Sumo Logic availability on the AWS European Sovereign Cloud. EU organizations can keep their data in region, handled by EU staff, while still running the full platform for incident response. That turns a painful either/or into a checklist a regulated buyer can complete. Genesys is the first customer live in the sovereign cloud, with payment processor OpenPay preparing to follow. How does this play out for highly regulated industries? Sumo Logic is focused on finance, healthcare, telco, and government, the verticals feeling the most pressure. The path Peterson describes is simple: let Sumo Logic handle incident management, let AWS move and grow the data in region, and check the sovereignty box without giving up operational readiness. Underneath sits a full-featured SIEM and Dojo AI, the agentic approach Sumo Logic launched earlier this year. The goal is not to replace analysts but to keep a human in the loop while handing proven, repetitive work to an agent. Fix one server, confirm the solution, then let an agent patch the other 599 under oversight. A SOC Analyst Agent reaches general availability at Black Hat later this year, alongside an MCP server. On observability, the differentiator is reading both structured and unstructured data without normalizing it first. A zip code is structured; a cryptic web hook error is not. Sumo Logic reads both, which feeds directly into faster time to identify and faster time to resolve. For any leader weighing sovereignty against uptime, Bill Peterson makes a clear case that they can finally live in the same plan. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUEST Bill Peterson, Senior Director of Product Marketing, Sumo Logic LinkedIn: https://www.linkedin.com/in/williampetersonjr/ RESOURCES Learn more about Sumo Logic: https://www.sumologic.com/ Sumo Logic on the AWS European Sovereign Cloud (announced at Infosecurity Europe 2026): https://www.sumologic.com/newsroom Infosecurity Europe 2026 event coverage: https://www.itspmagazine.com/infosecurity-europe-2026-infosec-london-cybersecurity-event-coverage Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS Bill Peterson, Sumo Logic, Sean Martin, brand story, brand marketing, marketing podcast, brand spotlight, AWS European Sovereign Cloud, data sovereignty, incident response, mean time to resolve, SIEM, security operations, Dojo AI, agentic AI, SOC analyst agent, observability, log analytics, Infosecurity Europe 2026 Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

At Infosecurity Europe 2026, Matt Middleton-Leal, Regional Vice President for Qualys across Northern Europe, joins Sean Martin inside the Risk Operations Center built into the Qualys booth. The premise is blunt: cybersecurity has spent years getting good at measuring risk and almost no time getting good at fixing it. The Risk Operations Center, or ROC, is the Qualys answer to that imbalance. So what is a ROC? It is not a product. Middleton-Leal describes it as an operating model that pulls scattered risk signals together, ranks them by business context and financial impact, and drives them toward remediation. If a SOC looks in the rearview mirror at what already happened, the ROC looks through the windshield at the risk ahead. Why now? Because risk moves at machine speed. In an AI-driven world of frontier models and autonomous agents, Middleton-Leal argues that remediation tied to service desk tickets is already too slow. He shares what happens when a client prepares to deploy tens of thousands of new agents before anyone knows what those agents touch or where their data goes. The example that lands hardest is a number: 62 million risk findings across one client's combined tooling. Middleton-Leal walks through how threat intelligence, business context, and safe exploitability testing collapse that figure to under one percent of fixes that genuinely reduce loss. It is a concrete look at how to prioritize remediation instead of drowning in dashboards. There is a quieter shift underneath it all: financial risk quantification, long reserved for the largest banks, reaching companies that never had the analysts to build it. Working with Richard Seiersen, Chief Risk Technology Officer at Qualys, the company is building ways to answer questions like what a ransomware event would likely cost a business in your sector and region. Middleton-Leal closes with the one place every organization should start, whether they use Qualys or not. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUESTMatt Middleton-Leal, Regional Vice President, Northern Europe, Qualys LinkedIn: https://www.linkedin.com/in/matt-middleton-leal-a56557/ RESOURCES Qualys: https://www.qualys.com ITSPmagazine Infosecurity Europe 2026 coverage: https://www.itspmagazine.com/infosecurity-europe-2026-infosec-london-cybersecurity-event-coverage Richard Seiersen, Chief Risk Technology Officer at Qualys, co-author of "How to Measure Anything in Cybersecurity Risk" Connect with Matt Middleton-Leal on LinkedIn: https://www.linkedin.com/in/matt-middleton-leal-a56557/ Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS Matt Middleton-Leal, Qualys, Sean Martin, brand story, brand marketing, marketing podcast, brand spotlight, Risk Operations Center, ROC, risk remediation, cyber risk quantification, exposure management, vulnerability management, Richard Seiersen, AI security risk, Infosecurity Europe 2026, machine speed remediation, security operations Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Something has changed at the board level. Recorded in the media room at Infosecurity Europe 2026 in London, Ian Schenkel, VP Sales, EMEA & APAC of Intel 471, describes directors who no longer take security on faith. After a year of headline breaches from Jaguar Land Rover to Marks and Spencer and the Co-op, leadership wants proof rather than promises. What does the board actually want to know? A straight answer to one question: are we okay? Ian Schenkel starts with geopolitics. Nation-state activity, supply chain exposure, and shifting global markets all shape whether a business can keep running. Threat intelligence becomes the early warning system leaders use to decide where to move and which actors have a history of targeting their industry. The next question gets personal. Does this affect us? Have we already been hit? This is where Intel 471 leans on retroactive threat detection. When new indicators of compromise surface, an analyst can build detection queries in seconds against a SIEM, SOAR tool, SentinelOne, Microsoft, or Palo Alto, then report back to the board with a clear answer. How does intelligence reach the board without getting lost in the weeds? It travels as a story the board can act on. Intel 471 pulls its three core areas, cyber threat intelligence, attack surface management, and threat hunting, into a single report that scales from an executive summary to a detailed account of what was found and neutralized. The stories make it real. During merger rumors, an attacker registered a look-alike domain and emailed employees from it. In another case, Intel 471 warned an organization it did not yet work with about a politically motivated actor that was openly discussing it. The value is the early signal, long before perimeter and endpoint defenses ever engage. Sometimes the right move is not technical at all. It might be briefing executives on targeted ransomware or reminding employees to stay alert against the email that has not arrived yet. The throughline, as Ian Schenkel frames it, is prevention over reaction, and a board finally asking the right questions. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUEST Ian Schenkel, VP Sales, EMEA & APAC, Intel 471 LinkedIn: https://www.linkedin.com/in/ianschenkel/ RESOURCES Learn more about Intel 471: https://www.intel471.com Connect with Ian Schenkel on LinkedIn: https://www.linkedin.com/in/ianschenkel/ Infosecurity Europe 2026 event coverage: https://www.itspmagazine.com/infosecurity-europe-2026-infosec-london-cybersecurity-event-coverage Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS Ian Schenkel, Intel 471, Sean Martin, brand story, brand marketing, marketing podcast, brand spotlight, cyber threat intelligence, threat hunting, attack surface management, board reporting, geopolitical intelligence, early warning system, indicators of compromise, retroactive threat detection, business resilience, Infosecurity Europe 2026 Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

At Infosecurity Europe 2026 in London, Matt Ellison, Director of Sales Engineering EMEA & APAC at Corelight, joins Sean Martin to unpack the visibility gap widening across security operations. The SOC is either drowning in data or missing the data that matters most. Corelight, custodian of the open-source Zeek project, builds a platform that turns raw network traffic into evidence teams can actually use. Why do today's most evasive attacks slip past endpoint detection? Because they are designed to. Ellison points to typhoon-style campaigns staged from network and hardware devices specifically to avoid EDR. When a platform sees all of the network traffic moving backwards and forwards, those moves stop being invisible. Seeing more is only half the battle. Ellison describes teams trapped by a fear of missing something, switching on every "just in case" detection until alert volume becomes its own crisis. The real question shifts from "what fired" to "what does this actually mean for my environment." How do you investigate a detection you cannot see inside? A black box hands down a verdict with no evidence behind it. Corelight takes an open approach, exposing the data behind every conclusion so analysts can follow a flow to its root cause and apply the one thing no vendor ships: their own knowledge of the network. The proof tends to show up fast. Ellison recalls a proof of value where, within thirty minutes, the team surfaced sensitive information moving unencrypted across the network. Other finds are smaller but telling, like a finance team's certificate using a weak cipher. Corelight even names its catch-all logs plainly, the "weird" log and the "unknown" log. Visibility feeds compliance too. Frameworks like NIS2, DORA, and GDPR demand evidence, not a tool humming in the corner that no one reviews. Ellison previews a coming release that adds asset classification, identifying every device on the network and explaining the why behind it. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUESTMatt Ellison, Director of Sales Engineering EMEA & APAC, Corelight LinkedIn: https://www.linkedin.com/in/matthewrellison/ RESOURCES Learn more about Corelight, including customer stories: https://corelight.com Zeek, the open-source NDR project Corelight maintains: https://zeek.org Infosecurity Europe 2026 coverage from ITSPmagazine: https://www.itspmagazine.com/infosecurity-europe-2026-infosec-london-cybersecurity-event-coverage Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS Matt Ellison, Corelight, Sean Martin, brand story, brand marketing, marketing podcast, brand spotlight, network detection and response, NDR, Zeek, open source security, network visibility, threat hunting, SOC alert fatigue, EDR evasion, encrypted traffic analysis, NIS2, DORA, GDPR, Infosecurity Europe 2026 Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.