Podcasts about ciso

  • 1,443PODCASTS
  • 12,373EPISODES
  • 36mAVG DURATION
  • 2DAILY NEW EPISODES
  • Aug 4, 2026LATEST

POPULARITY

20192020202120222023202420252026

Categories




Best podcasts about ciso

Show all podcasts related to ciso

Latest podcast episodes about ciso

CISO-Security Vendor Relationship Podcast
See, Our Compliance Framework Includes a Checkbox for Resilience

CISO-Security Vendor Relationship Podcast

Play Episode Listen Later Aug 4, 2026 43:43


All links and images can be found on CISO Series This week's episode is hosted by me, David Spark, producer of CISO Series and Mike Johnson, CISO, Rivian. Joining us is our sponsored guest, Khush Kashyap, senior director of GRC at Vanta. In this episode: Running up the token meter Some risks resist a price tag Resilience isn't a vacation policy Compliance is the wrong finish line A huge thanks to our sponsor, Vanta Still stuck on the quarterly audit treadmill? Meet Calm-pliance. Vanta combines compliance, risk, and proof on one Agentic Trust Platform—and continuously monitors your controls, keeping you audit-ready all year round. Find your Calm-pliance here.

HR Mixtape
Trust at Speed: Hiring Fraud, Deepfakes, and the Identity Risks CHROs Can't Ignore

HR Mixtape

Play Episode Listen Later Aug 4, 2026 19:55


Most CHROs have a fraud problem they didn't sign up for. Deepfakes in video interviews. Synthetic IDs at the application stage. AI-generated credentials that pass every automated screen. Only 31% of CHROs say they're confident in their ability to prevent hiring fraud, and the technology making it easier gets more sophisticated every quarter. Nik Daruwala, Vice President of Sales at Checkr, has spent 21 years in B2B technology sales, including thousands of direct conversations with HR leaders trying to protect their hiring funnels without losing speed. Checkr powers background verification for Uber, Lyft, DoorDash, and Instacart, and was the first API in the background check industry. In this episode, he covers: Why hiring fraud appears at every stage of the funnel, from the initial application through post-hire monitoring, and what a continuous identity verification strategy actually looks like in practice How CHROs should be thinking about partnering with their CISO to address a risk that's moved from the cyber stack into the talent pipeline https://thehrmixtape.com/episodes/trust-at-speed-hiring-fraud-deepfakes-and-the-identity-risks-chros-cant-ignore-with-nik-daruwala Why the speed-versus-safety trade-off in hiring is a false choice, and what good looks like when both coexist in the same program Timestamps [00:00:39] Context: this conversation was recorded live at the Checkr booth at SHRM 2026 [00:01:01] How enterprise hiring changed over 24 years: global sourcing, the normalization of remote hiring, and why the explosion of application volume made quality screening harder [00:02:50] The CHRO anxiety most people aren't talking about: making sure candidates throughout the funnel are actually who they claim to be [00:04:13] Only 31% of CHROs have confidence in their ability to prevent hiring fraud, and why the AI tools now available to candidates are changing that threat surface fast [00:04:39] The three identity threats CHROs weren't trained for: deepfakes in interviews, synthetic IDs at the application stage, and AI-generated credentials that pass automated screens [00:06:44] Why most organizations are reactive on hiring fraud, and the parallel to the early days of cybersecurity: you don't prioritize it until you have your first incident [00:08:42] Where fraud actually shows up across the hiring funnel: application, interview, background check, and continuously post-hire [00:09:41] The speed-versus-compliance trade-off is a false choice, and why the best hiring programs don't ask their teams to make it [00:13:27] Nik on what it actually means for trust to be a competitive advantage, and why that should be the north star for every hiring program [00:16:00] The two-to-three year horizon: AI automating talent sourcing and administrative tasks, continuous monitoring as table stakes, and why the hiring decision stays human Brought to You by Paylocity Paylocity is the fastest growing unified platform for HR, Finance, and IT. Paylocity brings your people, processes, and data together in one place so HR leaders can spend less time managing systems and more time doing the work that actually moves their organizations forward. Learn more at paylocity.com Keywords: hiring fraud, background checks, identity verification, deepfakes, synthetic IDs, AI-generated credentials, CHRO priorities, talent pipeline security, hiring at scale, continuous monitoring, background screening, hiring compliance, HR technology, Checkr, credential fraud, HR risk management, fraud prevention, remote hiring risk, AI in hiring, talent operations

Paul's Security Weekly
AppSec, Shopify-Style; State of Mobile Security; the News - Kern Smith, Andrew Dunbar - ESW #470

Paul's Security Weekly

Play Episode Listen Later Aug 3, 2026 97:00


Interview with Andrew Dunbar, CISO at Shopify After 13 years at Shopify, Andrew has some valuable insights to share on application security. In this episode, we discuss how AI has changed application security processes where bug bounty now fits in a post-Mythos, post-AI harness world. Andrew's Resources: https://shopify.engineering/building-an-agentic-harness-that-outlasts-the-model Interview with Kern Smith Kern Smith, VP of Global Solutions at Zimperium, joins us to talk about the state of mobile security. This was a great conversation, talking about the history of mobile devices in the enterprise and how challenging securing mobile apps is in the age of vibe-coding. Segment Resources https://zimperium.com/resources/new-zimperium-research-reveals-that-ai-based-attacks-are-targeting-and-succeeding-on-mobile Global Mobile Threat Report 2026 Enterprise Security News Finally, in the enterprise security news, Pre-black hat funding goes nuts we have 4 new cybersecurity unicorns! Cyera acquires Oasis for one BILLION dollars Lots of new product announcements with hacker summer camp next week Hugging Face got hacked by a competitor's agent and are cool with it? Finding out that wiping a burner phone is illegal the week before DEF CON is not ideal Are open, local models the future of AI? AI isn't coming for your job lots of vendor reports bad cybersecurity takes are apparently mainstream memes now??? All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-470

Paul's Security Weekly TV
AppSec, Shopify-Style; State of Mobile Security; the News - Andrew Dunbar, Kern Smith - ESW #470

Paul's Security Weekly TV

Play Episode Listen Later Aug 3, 2026 97:00


Interview with Andrew Dunbar, CISO at Shopify After 13 years at Shopify, Andrew has some valuable insights to share on application security. In this episode, we discuss how AI has changed application security processes where bug bounty now fits in a post-Mythos, post-AI harness world. Andrew's Resources: https://shopify.engineering/building-an-agentic-harness-that-outlasts-the-model Interview with Kern Smith Kern Smith, VP of Global Solutions at Zimperium, joins us to talk about the state of mobile security. This was a great conversation, talking about the history of mobile devices in the enterprise and how challenging securing mobile apps is in the age of vibe-coding. Segment Resources https://zimperium.com/resources/new-zimperium-research-reveals-that-ai-based-attacks-are-targeting-and-succeeding-on-mobile Global Mobile Threat Report 2026 Enterprise Security News Finally, in the enterprise security news, Pre-black hat funding goes nuts we have 4 new cybersecurity unicorns! Cyera acquires Oasis for one BILLION dollars Lots of new product announcements with hacker summer camp next week Hugging Face got hacked by a competitor's agent and are cool with it? Finding out that wiping a burner phone is illegal the week before DEF CON is not ideal Are open, local models the future of AI? AI isn't coming for your job lots of vendor reports bad cybersecurity takes are apparently mainstream memes now??? All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-470

Cyber Security Today
Healthcare Cybersecurity in 2026: Healthcare CISO Matt Burke on AI, MFA, SOCs & Incident Readiness

Cyber Security Today

Play Episode Listen Later Aug 1, 2026 22:51


On Cybersecurity Today on the Weekend, host David speaks with Matt Burke, CISO of Bespoke Concierge MD, a telemedicine provider with doctors licensed in all 50 states, about defending patient data amid rising healthcare threats in 2026.   Burke explains why healthcare is heavily targeted, recounts a formative 3 a.m. incident rebuilding a critical connection during surgery, and outlines his top concerns: increasingly sophisticated bad actors, "hacking as a service," and user mistakes.   He emphasizes education, strong security tooling backed by a proactive/reactive SOC, and rigorous practice of incident and disaster recovery plans, balancing prevention with rapid response.   The discussion also covers AI's benefits and risks, leadership support for security, the importance of MFA for both work and personal accounts, and Burke's wish for broader adoption of effective SIEM tools.   00:00 Weekend Show Intro 00:39 Meet Matt Burke 01:23 Concierge Care Model 02:45 Why Healthcare Security 03:13 Origin Story 3AM Call 05:20 Top Threats 2026 06:29 Defense Tools That Work 07:50 AI Helps And Hurts 09:37 Winning Doctor Buy In 10:57 Castle Versus Response 13:42 Threat Surge And Resilience 18:17 Culture And MFA Everywhere 19:59 Career Advice And Magic Wand 22:33 Closing Thanks

This Week in Startups
Why AI has no taste and how to fix it (w/ Thais Castello Branco) | E2319

This Week in Startups

Play Episode Listen Later Jul 31, 2026 75:09


This Week In Startups is made possible by: YSecurity https://YSecurity.io/TWIST MongoDB https://MongoDB.com/ai Odoo https://Odoo.com/twist Today's show: AI models can solve PhD-level math equations and code an app in minutes… So why does everything they design look like identical slop? Thais Castello Branco, founder of Taste Labs, raised $18.5M in seed funding to teach frontier models about aesthetics and outputting quality content. She talks to Jason and Lon about why even frontier models regress to the mean on subjective tasks, how paid "TasteMakers" can improve output quality, and whether AI accelerates or destroys the half-life of "what's cool." PLUS Leopold Aschenbrenner's AI hedge fund liquidated its public stock portfolio, but it may be too soon to count this 25-year-old completely out. Google Earth adds AI generation and turns into a misinformation factory. LinkedIn and Substack join the AI slop crackdown. And why does every venture capitalist seem to have an opinion about the Ceuta border crisis? Guest Thais Castello Branco on X: https://x.com/thaiscbranco_ Taste Labs: https://tastelabs.com/ Amplify Partners: "Kill the Slop": https://www.amplifypartners.com/blog-posts/kill-the-slop-announcing-our-investment-in-taste Relevant Links Leopold Aschenbrenner's essay "Situational Awareness": https://situational-awareness.ai/ CNBC on SA fund collapse: https://www.cnbc.com/2026/07/31/leopold-aschenbrenner-situational-awareness-fund-fire-sale.html Henk van Ess thread on Google Earth + Nano Banana: https://x.com/henkvaness/status/2082912544394498228 Substack CEO Chris Best: "Against Claudefishing": https://post.substack.com/p/against-claudefishing NPR on the Ceuta crisis: https://www.npr.org/2026/07/31/g-s1-136507/morocco-spain-migration Ethan Goodhart's self-driving golf cart post: https://x.com/EthanGoodhart/status/2082136189998682598?s=20 "Wind" app on TestFlight: https://testflight.apple.com/join/zZqmhhwf TechCrunch: "Gritt exits stealth": https://techcrunch.com/2026/07/21/gritt-exits-stealth-with-34-million-for-robots-to-build-solar-plants-then-everything-else/ CA Gov: Project Nexus solar-covered canal announcement: https://www.gov.ca.gov/2026/04/29/governor-newsom-announces-the-completion-of-first-of-its-kind-solar-covered-canal-in-the-central-valley-piloting-a-new-way-to-save-water-and-reduce-costs/ Molly Wood's "Everybody in the Pool" podcast: https://www.everybodyinthepool.com/ Timestamps:   0:00 Coming up on today's show… 1:23 Thais Castello Branco on teaching models to have good taste 10:45 YSecurity - The on-demand security team for startups. Need enterprise-grade security without hiring a $400k CISO? YSecurity gives you 40+ expert engineers, matched to exactly what you need, by the hour, with your first six hours completely free. Go to https://YSecurity.io/TWIST 15:19 The "TasteMaker" community of paid human curators 20:37 MongoDB - AI-assisted and agentic coding is helping you build faster than ever. Start building at https://MongoDB.com/ai 24:40 Jason's personal "cool hunter" prompt 30:16 Odoo - The all-in-one business platform. Get started for free at https://Odoo.com/twist 37:36 Situation Awareness lacked situational awareness 46:59 Claude models hacked three external organizations 50:54 Google Earth adds Nano Banana for some reason 54:24 The AI Slop crackdown spreads 57:54 Too many opinions about the Ceuta migrant crisis 1:04:05 Self-driving golf carts and also cars 1:09:53 Robot arms are installing solar panels   Subscribe to the TWiST500 newsletter: https://ticker.thisweekinstartups.com Check out the TWIST500: https://www.twist500.com Subscribe to This Week in Startups on Apple: https://rb.gy/v19fcp   Follow Lon: X: https://x.com/lons   Follow Alex: X: https://x.com/alex LinkedIn: ⁠https://www.linkedin.com/in/alexwilhelm   Follow Jason: X: https://twitter.com/Jason LinkedIn: https://www.linkedin.com/in/jasoncalacanis   Check out all our partner offers: https://partners.launch.co/   Great TWIST interviews: Will Guidara, Eoghan McCabe, Steve Huffman, Brian Chesky, Bob Moesta, Aaron Levie, Sophia Amoruso, Reid Hoffman, Frank Slootman, Billy McFarland   Check out Jason's suite of newsletters: https://substack.com/@calacanis   Follow TWiST: Twitter: https://twitter.com/TWiStartups YouTube: https://www.youtube.com/thisweekin Instagram: https://www.instagram.com/thisweekinstartups TikTok: https://www.tiktok.com/@thisweekinstartups Substack: https://twistartups.substack.com

ITSPmagazine | Technology. Cybersecurity. Society
Vulnerability Backlogs Can Finally Reach Zero | A Brand Spotlight Conversation with Ondrej Vlcek, Co-Founder and CEO of AISLE | Hosted by Sean Martin

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Jul 31, 2026 17:45


Security leaders count open vulnerabilities in the hundreds of thousands, and in some organizations the number runs past a million. Ondrej Vlcek, Co-Founder and CEO of AISLE, describes teams with no practical route through that backlog while attackers use automation to shrink the time between a disclosure and a working exploit. The question worth asking is what a program looks like when remediation moves at the same speed as exploitation. What makes AI-driven remediation different from static code analysis? Reasoning replaces pattern matching. Linters and commercial scanners flag code that resembles a known error shape, while a reasoning model infers what the developer intended, compares that intent against the actual implementation, and evaluates how the gap could be abused. Ondrej Vlcek points to business logic flaws, timing errors, and race conditions as the classes that pattern matching leaves untouched. The judgment behind AISLE comes from a long run in the industry. Ondrej Vlcek wrote device drivers for Windows 95 in 1995 at a seven-person antivirus company called Avast, stayed more than twenty-five years, moved through CTO and COO into the CEO seat, and took the company public before its sale to NortonLifeLock in 2022. He co-founded AISLE in 2024 with Jaya Baloo, a three-time public company CISO, and Stanislav Fort, an AI researcher who worked at DeepMind and Anthropic. Why does the software supply chain deserve the larger share of attention? Because most of the code in a running application was written somewhere else. Ondrej Vlcek puts the typical enterprise application at roughly ten percent first-party code and ninety percent open source and dependency code, which is also level ground for an attacker reading the same source and pointing the same models at it. Reachability analysis becomes the deciding factor, separating the vulnerable functions your code actually calls from the thousands of transitive dependencies it never touches. For first-party code, AISLE closes the loop differently: read the documentation, the architectural material, and the threat model, then generate a patch aligned with the project's own conventions and test it automatically. The standard Ondrej Vlcek sets is a fix that reads as though a human maintainer wrote it. The customer spread runs from embedded firmware at Bose to smart contracts at the Ethereum Foundation, where heavily audited and sometimes formally verified code still benefits from another set of checks because the systems touch money flows directly. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUEST Ondrej Vlcek, Co-Founder and CEO of AISLE On LinkedIn: https://www.linkedin.com/in/ondrejvlcek/ RESOURCES Learn more about AISLE: https://aisle.com Meet AISLE at Black Hat and DEF CON in Las Vegas: https://aisle.com/black-hat The AISLE platform: https://aisle.com/platform AISLE CVE discoveries: https://aisle.com/cve-discoveries Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS ondrej vlcek, aisle, sean martin, brand story, brand marketing, marketing podcast, brand spotlight, vulnerability management, vulnerability remediation, agentic ai, cyber reasoning system, software supply chain security, reachability analysis, open source security, application security, first-party code, third-party dependencies, static code analysis, zero-day vulnerabilities, ai in cybersecurity, code patching, embedded firmware security, smart contract security Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Cybercrime Magazine Podcast
Culture Shapes Security. Identity Risk & Passwords. Susan Koski, Fmr. CISO, PNC & Flavius Plesu.

Cybercrime Magazine Podcast

Play Episode Listen Later Jul 31, 2026 18:33


Susan Koski is the former CISO at PNC. In this episode, she joins host Charlie Osborne and Flavius Plesu, CEO at OutThink, to discuss the future of passwords, how best to manage identity risk, and more. Culture Shapes Security is a Cybercrime Magazine podcast series brought to you by OutThink. To learn more about our sponsor, visit https://outthink.io.

Cyber Security Headlines
The Department of Know: Minnesota water hack, LLM finds encryption flaw, human error hit Hugging Face

Cyber Security Headlines

Play Episode Listen Later Jul 31, 2026 30:24


This week's Department of Know is hosted by Rich Stroffolino, with guests Janet Heins, CISO, ChenMed, and Derek Fisher, Director of the Cyber Defense and Information Assurance Program, Temple University. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. Huge thanks to our sponsor, Pindrop A finance worker joined a video call with their CFO and wired $25 million to attackers. This isn't fiction—it happened. Deepfake video. AI voice. Completely convincing. It could be happening in your meetings right now. Pindrop Pulse for Meetings can detect deepfake impersonation before the damage is done. Go to pindrop.com and start verifying.

Defense in Depth
Why is Preventative Security So Difficult?

Defense in Depth

Play Episode Listen Later Jul 30, 2026 30:16


All links and images can be found on CISO Series Prevention in cybersecurity is a lot like flossing: everyone knows they should do it, but few do it enough. What's stopping us? Check out this post by Ross Haleliuk of Venture in Security for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark, the producer of CISO Series, and Edward Contreras, senior evp and CISO, Frost Bank. Joining us is Deneen DeFiore, vice president & chief information security officer, United Airlines. In this episode: The sponsorship gap One strike and you're out Policy without position Prevention isn't static A huge thanks to our sponsor, CoreView Attackers don't break into Microsoft 365. They log in and reconfigure it. When tenant configurations drift or get tampered with, recovery can take weeks and missed settings can reopen the door. The Cyber Resilience Framework for Microsoft 365 covers the five pillars, harden, govern, detect, respond, recover, and shows exactly where today's tools leave gaps. Download the free practical guide

Business, Brains & the Bottom Line
Ep. 159: Ready to Recover Series: Part 5: When everything goes wrong, the fundamentals still win

Business, Brains & the Bottom Line

Play Episode Listen Later Jul 30, 2026 19:11


After exploring identity sprawl, cloud complexity, ransomware recovery, disaster recovery strategy, and cyber resilience, Paul sits down with Joe Ross, Joe Galvan, Terry Murray, John Parker, and Stephen Sepulveda, who returns for the conclusion of this special five-part series.Together, they revisit the foundational practices that consistently determine whether an organization recovers or becomes the next cautionary tale.From immutable backups and recovery testing to application ownership and modern cyber recovery platforms, the panel cuts through the noise to focus on what actually works under the highest pressure. The episode concludes with each guest sharing the single most important priority every IT leader should take back to their organization.Whether you're a CIO, CISO, IT Director, Infrastructure Architect, or Disaster Recovery professional, this final conversation brings together the key lessons from the series into a single practical roadmap for building true cyber resilience.Topics DiscussedWhy backup testing is the only way to know you'll recoverThe technologies that are changing modern cyber recoveryWhy application owners must be part of every recovery strategyImmutable backups and the role they play in ransomware defenseLessons learned from the experts across all five episodesThe top priorities every IT leader should focus on to strengthen resiliencePractical steps organizations can take today to prepare for tomorrow's outage

Leaders In Tech
The Cybersecurity Mistake That Costs Companies Millions

Leaders In Tech

Play Episode Listen Later Jul 30, 2026 43:56


Welcome to another episode of Leaders in Tech hosted by David Mansilla! In this episode, we welcome Thom Langford, air CTO at Rapid7 and former CISO at Publicis Groupe and Velonetic. Thom takes us through his fascinating career path—from early days setting up 640K memory PCs and Vax VMS systems to building enterprise cybersecurity programs from scratch. Beyond tech stacks and vulnerability management, Thom opens up about his personal battle with burnout and addiction, offering powerful lessons on mental health, leadership, and setting workplace boundaries. Key Takeaways & What You'll Learn:The Security Paradox: Why absolute security stops business innovation, and how CISOs must manage compromise and complexity. Unconventional Career Paths: How a corporate identity theft crisis launched Thom's CISO career. Mental Health in Cybersecurity: Overcoming burnout, dealing with "secrets and failure," and why normalizing mental health discourse saves careers. Empathetic Leadership: The rule of "Public Support, Private Correction," providing air cover for your team, and leading with trust. Work-Life Balance: Practical strategies for tech professionals, including learning to decline unnecessary meetings and setting hard boundaries.

The CyberWire
More than meets the AI.

The CyberWire

Play Episode Listen Later Jul 29, 2026 29:24


The Senate confirms Jay Clayton to lead ODNI. A new CISA framework highlights critical infrastructure isolation capabilities. OpenAI's rogue agent breached more than just Hugging Face. The average cost of a data breach continues to rise. Indirect prompt injection proves irresistible to cyber criminals. Broadcom patches multiple VMware products. ShinyHunters claims responsibility for Ernst & Young's recent breach. Our guest is Sean Zadig, CISO at Yahoo, discussing the impact of AI on the defense side. These aren't the droids you're looking for. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Sean Zadig, CISO at Yahoo, discussing the impact of AI on the defense side without all the hype in either direction, what is a CISO actually doing about it. Selected Reading Senate Confirms Jay Clayton to Lead U.S. Intelligence Community (The New York Times) China and Iran Are Already Inside US Grids: CISA Demands Tested Isolation Plans (Tech Times) OpenAI's rogue agent compromised a customer at a second tech firm, executive says (Reuters) Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident (Hugging Face) The Average Cost of a Data Breach Rises to $5 Million (Infosecurity Magazine) USSPACECOM Issues Space Warfighting Environment 2040 for Joint Force Space Operations (ExecutiveGov) THE SPACE WARFIGHTING ENVIRONMENT 2040 Framing the Future for the Joint Warfighter (U.S. Space Command)  Notes from Underground: Adversarial Prompt Injection (Proofpoint) Critical VM Escape Vulnerability Patched in VMware ESXi (SecurityWeek) ShinyHunters Claims Ernst & Young Hack (SecurityWeek) America bans imported robots due to supply chain and security risks (The Register) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

The 30 Minute Hour™

Artificial Intelligence is transforming business at an unprecedented pace.Cyber threats are evolving by the hour.Yet many leaders are still treating technology as an IT problem instead of a leadership priority.In this episode, we sit down with Ben Wilcox, CTO and CISO of ProArch, to discuss what executive leaders need to know about AI, cybersecurity, and building organizations that are resilient, scalable, and prepared for what's next.

Risk Management Show
How AI Is Exposing Identity's Biggest Weakness with Yossi Barishev

Risk Management Show

Play Episode Listen Later Jul 29, 2026 28:25


In the age of AI-driven attacks, your identity infrastructure is likely your weakest link. Yossi Barishev, CEO of Way Security and former incident responder for nation-state threats, joins the Risk Management Show to explain why identity has become the only perimeter left. Discover why traditional security tools are failing and how to prepare your organization for the era of autonomous AI agents. In this episode, we dive deep into the reality of modern cybersecurity, where 99.9% of attacks still exploit basic hygiene failures rather than exotic zero-day vulnerabilities. Yosi shares his experience from the front lines of military intelligence and elite incident response firms, highlighting the massive coverage gaps in current Identity and Access Management (IAM) implementations. We discuss the transition from legacy systems to SaaS and why the lack of uniformity in IT infrastructure is creating a crisis for global enterprises. You will learn about the essential pillars of identity security: maintaining a clean inventory, enforcing the principle of least privilege, and ensuring your security solutions actually cover your entire environment. Whether you are a CIO, CISO, or risk leader, this conversation provides a roadmap for moving away from manual, expensive processes toward automated, resilient identity foundations that can withstand the speed of AI

@BEERISAC: CPS/ICS Security Podcast Playlist
Supply Chain Risk: What Manufacturers Need to Know

@BEERISAC: CPS/ICS Security Podcast Playlist

Play Episode Listen Later Jul 29, 2026 22:18


Podcast: Industrial Cybersecurity InsiderEpisode: Supply Chain Risk: What Manufacturers Need to KnowPub date: 2026-07-28Get Podcast Transcript →powered by Listen411 - fast audio-to-text and summarizationTwo global dairy producers made headlines this week after breaches that started with third party vendors.Dino and Craig break down how it happened and why it keeps happening. They walk through the reality of remote access on the plant floor, from cellular modems to TeamViewer installs nobody remembers approving, and explain why a single sensor in a plant might show you 25 percent of your assets at best. The conversation gets to the root of the problem: people, not technology. OT teams still lock IT out of critical systems, CISOs carry responsibility without authority, and incident response plans rarely account for the integrators working across multiple plants at any given moment. If you lead security for a manufacturing organization, this episode arms you with the tough questions to bring back to leadership before your company is the one filing with the SEC.Chapters:(00:00:00) - The CISO gets hung out to dry, not the third-party vendor(00:01:02) - Two global dairy producers breached through third-party vendors(00:02:12) - The messy reality of remote access on the plant floor(00:03:47) - Why IT has no visibility into what's connected in manufacturing(00:05:29) - North-south versus east-west traffic monitoring(00:06:41) - The culture problem of OT locking IT out(00:08:14) - Responsibility versus authority for CISOs(00:10:47) - The budget excuse and the real cost of downtime(00:14:32) - Incident response plans that leave system integrators out(00:18:56) - SEC filings, brand damage, and the tough questions to askLinks And Resources:Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedInThanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you'd like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review!The podcast and artwork embedded on this page are from Industrial Cybersecurity Insider, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.

CISO-Security Vendor Relationship Podcast
Why Don't You Tell Me Which Metrics Sound Most Impressive?

CISO-Security Vendor Relationship Podcast

Play Episode Listen Later Jul 28, 2026 48:02


All links and images can be found on CISO Series This week's episode is hosted by me, David Spark, producer of CISO Series and Andy Ellis, principal of Duha. Joining is Pavi Ramamurthy, Global CISO and CIO, Blackhawk Network. In this episode: Numbers that make the board feel good and nothing else The audit is not the same thing as the truth Receipts aren't a strategy Stop blaming the human, fix the system they're standing in A huge thanks to our sponsor, ThreatLocker ThreatLocker delivers Zero Trust Network Access and Zero Trust Cloud Access that verifies both user and device before granting access to specific applications. No broad access, nothing exposed, and no reliance on credentials alone. It's a smarter way to control access and reduce risk. Learn more at ThreatLocker.com/CISO.  

sound numbers metrics cio impressive receipts ciso duha andy ellis global ciso threatlocker david spark zero trust network access blackhawk network ciso series
Serious Privacy
A multifacted week in privacy

Serious Privacy

Play Episode Listen Later Jul 28, 2026 33:51 Transcription Available


Send us Fan MailWelcome to the Serious Privacy podcast, where Paul Breitbarth, Ralph O'Brien, and Dr. K Royal, discuss a week in privacy. We have some jucy news from Europe, New Jersey, and the United Kingdom. Tune in! If you have comments or questions, find us on LinkedIn and Instagram @seriousprivacy, and on BlueSky under @seriousprivacy.eu, @europaulb.seriousprivacy.eu, @heartofprivacy.bsky.app and @igrobrien.seriousprivacy.eu, and email podcast@seriousprivacy.eu. Rate and Review us! From Season 6, our episodes are edited by Fey O'Brien. Our intro and exit music is Channel Intro 24 by Sascha Ende, licensed under CC BY 4.0. with the voiceover by Tim Foley.

Cyber Risk Management Podcast
EP 215: Is Your AI Strategy a Risk Decision in Disguise?

Cyber Risk Management Podcast

Play Episode Listen Later Jul 28, 2026 51:59


There's a popular new playbook for running an "AI-native" company. Record everything, put all your data in one place, and let an AI agent reach all of it. The productivity story is real. New hires ramp up in days, and the whole company can ask questions it never could before. But the same moves that create the speed also switch off safeguards that some businesses are not allowed to switch off. So, which controls are we turning off to get this speed, and are we allowed to? Your hosts are Kip Boyle, CISO with Cyber Risk Opportunities, and Jake Bernstein, Partner with K&L Gates.   Y Combinator's AI native playbook video -- https://youtu.be/B246K_G7mHU AIR-MAP website -- https://air-map.io/

The Cyber Security Transformation Podcast
Series 7 - "The First 100 Days of the CISO: A Critical Period for Organisational Alignment" - Episode 1

The Cyber Security Transformation Podcast

Play Episode Listen Later Jul 28, 2026 8:42


JC Gaillard starts Series 7 of the Cybersecurity Transformation Podcast by looking back at the "First 100 Days of the New CISO" and why it is a critical period of organisational alignment; his book on the matter published in 2025 is available here on Amazon

Cloud Security Podcast by Google
EP288 CISO Tested, Board Approved: Cloud Resilience with General Mills CISO Noah Korba

Cloud Security Podcast by Google

Play Episode Listen Later Jul 27, 2026 25:32


How do you make sure your favorite cereal is always on the shelves when a cyber disaster strikes? In this episode, hosts Tim Peacock and Alicja Cade sit down with Noah Korba, VP of Digital Core, Cybersecurity, and Enterprise Architecture at General Mills, to look under the hood of "Mills Collaborative Recovery"—their intensive, annual two-week drill that actually recovers 90% of their Google Cloud estate to test real-world cyber resilience. ⌨️ "Clicking and Clacking" vs. Talking: Why General Mills ditched traditional tabletop discussions to actually run hands-on, keyboard-driven recoveries of their entire cloud infrastructure.

Cyber Security Headlines
The Department of Know: OpenAI hacks Hugging Face, Chinese LLM ban, Kratos takedown

Cyber Security Headlines

Play Episode Listen Later Jul 24, 2026 34:41


This week's Department of Know is hosted by Rich Stroffolino, with guests Nick Espinosa, host, Deep Dive Radio Show, and Dennis Pickett, vp, CISO, Westat. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. Huge thanks to our sponsor, QuilrAI AI agents don't ask permission. They act -- moving data, triggering workflows, changing systems. QuilrAI is the permission layer they never had. Its Decision Engine evaluates the content, context, and intent of every action - before it completes. Alerts tell you later. QuilrAI decides now. Visit quilr.ai. Stay safe - Quilr it.

Defense in Depth
Identity and Access Management (IAM) in an Agentic AI World

Defense in Depth

Play Episode Listen Later Jul 23, 2026 30:20


All links and images can be found on CISO Series Check out this post by Tomás Maldonado, CISO, NFL, for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark, the producer of CISO Series, and Yaron Levi, CISO, Dolby. Joining is Will Gregorian, vp of information technology & security, Galileo Medical. In this episode: From who to what The manipulation problem Cryptographic accountability The audit gap A huge thanks to our sponsor, ActiveState ActiveState gives security and engineering teams a single governed source for open source software. With 79 million components built from source, continuously remediated, and delivered directly into the tools teams already use, ActiveState eliminates the CVE backlog and the developer toil that comes with it. Companies see a 60 to 99% reduction in CVEs and reclaim up to 30% of developer time. Learn more at ActiveState.com.

Serious Privacy
A Big 300! Regulating Canada and the World (with Philippe Dufresne)

Serious Privacy

Play Episode Listen Later Jul 22, 2026 40:31 Transcription Available


Send us Fan MailWelcome to the Serious Privacy podcast, where Paul Breitbarth, Ralph O'Brien, and Dr. K Royal, celebrate 300 episodes. And for this milestone, we invited Philippe Dufresne - Privacy Commissioner of Canada and Chair of the Executive Committee of the Global Privacy Assembly. It is a fascinating discussion and one not to miss! If you have comments or questions, find us on LinkedIn and Instagram @seriousprivacy, and on BlueSky under @seriousprivacy.eu, @europaulb.seriousprivacy.eu, @heartofprivacy.bsky.app and @igrobrien.seriousprivacy.eu, and email podcast@seriousprivacy.eu. Rate and Review us! From Season 6, our episodes are edited by Fey O'Brien. Our intro and exit music is Channel Intro 24 by Sascha Ende, licensed under CC BY 4.0. with the voiceover by Tim Foley.

Cybersecurity Where You Are
Episode 197: AI-ready OT Data Begins with Understanding

Cybersecurity Where You Are

Play Episode Listen Later Jul 22, 2026 33:10


In episode 197 of Cybersecurity Where You Are, Sean Atkinson sits down with Ben Wilcox, Chief Technology Officer and Chief Information Security Officer at ProArch; and Ed Skoudis, President of SANS Technology Institute. Together, they discuss artificial intelligence (AI), operational technology (OT) data, and how understanding creates the foundation for AI-ready OT data.Here are some highlights from our episode:00:54. Introductions to Ben and Ed02:16. How we understand and integrate AI into OT environments04:30. How OT diverges from information technology (IT) in data responsibilities05:23. Opportunities for AI to assist OT06:33. The importance of meeting OT systems where they are08:10. A passive and incremental approach that respects the operations machines are doing12:29. Efficiency gains, public safety improvements, and other benefits of AI-ready OT data17:47. What lifecycle management, asset hierarchies, and governance look like for OT data22:14. The promise of AI to help to make OT environments understandable23:19. A team sport: How IT and OT can work together to understand assets and data28:38. The need for translation in IT-OT communication29:01. Recommendations for how to make OT data AI readyResourcesCIS Critical Security Controls®CIS Controls version 8.1 ICS WorkbookArtificial Intelligence and Large Language Models Companion GuideCIS Controls v8.1 Enterprise Asset Management Policy TemplateCIS Controls v8.1 Software Asset Management Policy TemplateCIS Controls v8.1 Data Management Policy TemplateCIS Controls v8.1 Account & Credential Management Policy TemplateEstablishing Essential Cyber HygieneProArchCybersecurity for Critical InfrastructureEpisode 77: Data's Value to Decision-Making in CybersecurityEpisode 183: The Role of CISO in Supporting Risk TranslationIf you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.

Let's Talk About (Secur)IT
The Threat They're Not Watching: Signal Intelligence with Hanna Linderstål

Let's Talk About (Secur)IT

Play Episode Listen Later Jul 22, 2026 53:03


"Every organization I've tested — I've always found a way in."That's not a hacker bragging.That's Hanna Linderstål — a cybersecurity strategist, who teaches digital espionage at the Swedish Defence University, and is one of Europe's most respected voices on autonomous defense.She started coding at 11. No internet. Just a modem, a phone line, and curiosity that never stopped.In our latest SecurIT episode, she said something that should keep every CISO up at night:"Most organizations are defensive in posture and delusional in practice."We talked about:The signal intelligence blind spot almost no company is watchingWhy more data ≠ better security (it's just noise without context)The OODA loop what the military knows about crisis response that your board doesn'tHow a spy was caught downloading files at midnight on a Saturday — and why your systems wouldn't have caught him eitherWhy the next pandemic might not be biological it might be three weeks without internetThe most uncomfortable quote of the episode?"I have never found an organization where we didn't find a potential risk we could exploit. Not one." If you're in security, leadership, or you just rely on the internet to run your business — this one's for you.

Packet Pushers - Full Podcast Feed
HS138: When “One Cloud To Rule Them All” Is NOT the Answer: Repatriation for AI and more

Packet Pushers - Full Podcast Feed

Play Episode Listen Later Jul 21, 2026 30:56


Some enterprises are finding reasons to pull back from a cloud-first IT strategy and run workloads in on-premises data centers. John and Johna dig into why companies are making the change, including cost and AI security. They also discuss and the strategic implications for IT, and what organizations stand to gain—and lose—from repatriation.  Episode Links:... Read more »

Packet Pushers - Fat Pipe
HS138: When “One Cloud To Rule Them All” Is NOT the Answer: Repatriation for AI and more

Packet Pushers - Fat Pipe

Play Episode Listen Later Jul 21, 2026 30:56


Some enterprises are finding reasons to pull back from a cloud-first IT strategy and run workloads in on-premises data centers. John and Johna dig into why companies are making the change, including cost and AI security. They also discuss and the strategic implications for IT, and what organizations stand to gain—and lose—from repatriation.  Episode Links:... Read more »

Heavy Strategy
HS138: When “One Cloud To Rule Them All” Is NOT the Answer: Repatriation for AI and more

Heavy Strategy

Play Episode Listen Later Jul 21, 2026 30:56


Some enterprises are finding reasons to pull back from a cloud-first IT strategy and run workloads in on-premises data centers. John and Johna dig into why companies are making the change, including cost and AI security. They also discuss and the strategic implications for IT, and what organizations stand to gain—and lose—from repatriation.  Episode Links:... Read more »

Cybercrime Magazine Podcast
Public Sector Cyber Brief. Govt. Defense. Michael Centrella, SecurityScorecard & Stephen Ward.

Cybercrime Magazine Podcast

Play Episode Listen Later Jul 21, 2026 12:16


Michael Centrella is the Head of Public Policy at SecurityScorecard. In this episode, he joins host Charlie Osborne and Stephen Ward, co-founder at Brightmind Partners, former CISO, and former Special Agent with the US Secret Service, to discuss government cyber defense and what organizations can do to stay protected. SecurityScorecard's mission is to make the world a safer place by transforming the way organizations understand, mitigate, and communicate cybersecurity risk to their boards, employees, and vendors. Learn more about our sponsor at https://securityscorecard.com

This Week in Startups
An AI that watches your every click may be the future of work | E2314

This Week in Startups

Play Episode Listen Later Jul 20, 2026 42:01


This Week In Startups is made possible by: Vanta https://www.vanta.com/twist Superhuman https://superhuman.com YSecurity https://YSecurity.io/TWIST Today's show: *Cybersecurity has long focused on cleaning up a system AFTER a breach but Ent founder Brandon Dixon says that's backwards. He just raised a $100M seed round to put an AI agent on everyone's company laptops that catches the risky clicks, leaked files, or rogue agents BEFORE they wreck havoc. PLUS Clawra creator David Im return swith his new project, Sume's Avatar, a multi-model orchestration layer that generates 60-second UGC videos from a single prompt… and gets it right on the first try, rather than falling back on trial and error. Guests: Brandon Dixon on LinkedIn: https://www.linkedin.com/in/brandonsdixon/ Ent: ****https://ent.ai/ David Im on X: https://x.com/davidim Sume: https://www.sume.com/ Relevant Links: WSJ: "Cyber Security Startup Ent Raises $100 Million in Seed Funding": https://www.wsj.com/pro/cybersecurity/cyber-startup-ent-raises-100-million-in-seed-funding-a3e9b6c6 Microsoft Security Copilot: https://www.microsoft.com/en-us/security/business/ai-machine-learning/microsoft-security-copilot Engadget: "Meta 'pausing' employee tracking program…": https://www.engadget.com/2199458/meta-is-pausing-employee-tracking-program-after-it-let-the-whole-company-see-sensitive-data/ Seedance 2.0: https://seedance2.ai/ Timestamps: 0:00 Intro: Why AI + cybersecurity is the hot combo right now 2:29 How INT stops breaches before they happen 4:56 AI is giving non-technical employees dangerous new powers 10:26 Vanta - Compliance and security shouldn't be a deal-breaker for startups to win new business. Vanta makes it easy for companies to get a SOC 2 report fast. Get $1,000 off for a limited time at https://www.vanta.com/twist 13:54 Why on-device AI beats cloud-based security 20:08 Superhuman - Get AI that works where you work. Unlock your Superhuman potential at https://superhuman.com 25:18 INT's business model and go-to-market 30:26 YSecurity - The on-demand security team for startups. Need enterprise-grade security without hiring a $400k CISO? YSecurity gives you 40+ expert engineers, matched to exactly what you need, by the hour, with your first six hours completely free. Go to https://YSecurity.io/TWIST 34:18 David M. of Sumi Labs: one-shotting AI video 36:10 Live demo: Sumi's video orchestration API 40:05 Consistent faces, 60-second videos, and who's buying Subscribe to the TWiST500 newsletter: https://ticker.thisweekinstartups.com Check out the TWIST500: https://www.twist500.com Subscribe to This Week in Startups on Apple: https://rb.gy/v19fcp   Follow Lon: X: https://x.com/lons   Follow Alex: X: https://x.com/alex LinkedIn: ⁠https://www.linkedin.com/in/alexwilhelm   Follow Jason: X: https://twitter.com/Jason LinkedIn: https://www.linkedin.com/in/jasoncalacanis   Check out all our partner offers: https://partners.launch.co/   Great TWIST interviews: Will Guidara, Eoghan McCabe, Steve Huffman, Brian Chesky, Bob Moesta, Aaron Levie, Sophia Amoruso, Reid Hoffman, Frank Slootman, Billy McFarland   Check out Jason's suite of newsletters: https://substack.com/@calacanis   Follow TWiST: Twitter: https://twitter.com/TWiStartups YouTube: https://www.youtube.com/thisweekin Instagram: https://www.instagram.com/thisweekinstartups TikTok: https://www.tiktok.com/@thisweekinstartups Substack: https://twistartups.substack.com

No Password Required
No Password Required Podcast Episode 75 - Philipp Leo

No Password Required

Play Episode Listen Later Jul 20, 2026 43:01


Philipp Leo — Swiss cyber expert, diplomat, and military officer, always two steps ahead of the storm No Password Required Season 7: Episode 7 - Philipp Leo Philipp Leo co-founded Leo & Muhly Cyber Advisory, a strategic advisory firm specializing in cyber risk, resilience, and geopolitics. Now consulting with governments and private firms in Switzerland and abroad, Philipp has served as a UN observer on the Korean DMZ, trained the next generation of Swiss Armed Forces cyber specialists, and taught at the University of Glasgow. He is also part of Europol's network of experts in data protection and cybercrime and has published stateside in MIT Sloan Management Review. In this episode, Philipp shares his journey from a Swiss bank he couldn't wait to leave to the Korean border, and eventually to the boardrooms of executives who still think cyber risk is someone else's problem. He breaks down the three most dangerous misconceptions executives have about cyber risk, why the CISO is too often a poster child rather than a decision-maker, and the challenges to cyber insurance in Europe. Cyber attorney Jack Clabby and co-host Kayley Jerrell talk with Philipp about his live crisis simulation that nobody can win, how to train cyber warriors, and how nation-state cyber conflict is looking more and more like the age of Caribbean pirates. In the Lifestyle Polygraph, Philipp reveals his favorite book, his eye-opening, go-to celebratory drink, and the weight of his luxury umbrella. He also shares his favorite escape when the complexity of modern life gets to be too much and introduces us to a Zurich commuting tradition that involves swimming home through a river.   In this episode: Philipp's journey from a Swiss bank he couldn't wait to leave to the Korean DMZ and eventually the boardrooms of Fortune 500 executives (00:27 - 02:22) The three most dangerous misconceptions executives have about cyber risk and why cyber risk is a corporate problem, not a technology problem (04:19 - 05:30) How Philipp's live crisis simulation works, why nobody can win it, and why that's exactly the point (05:49 - 08:47) Why cyber crisis teams have improved dramatically but leadership boards remain the weakest link (06:30 - 08:47) The CISO poster child problem: why most CISOs have the accountability without the authority (09:54 - 11:00) Why cyber insurance in Europe has largely failed to deliver and what happens when attackers find your policy before you do (11:17 - 13:44) The OFAC twist: what happens mid-exercise when a Swiss bank decides to pay and then learns the attackers are on the sanctions list (18:38 - 19:31) Training Swiss Armed Forces cyber specialists and why the first lesson is that the other side plays by no rules (19:47 - 21:37) Whether nation states can ever beat the cyber threat and why the east side of Vienna tells you everything you need to know (21:54 - 23:25) Why nation-state cyber conflict has become remarkably similar to the age of Caribbean pirates (23:46 - 24:23) The Lifestyle Polygraph: Endurance, Campari Red Bull, a three-ounce umbrella, a cabin in the Alps, and swimming home through a Zurich river (00:04 - 12:03)   Timestamp Highlights: (00:27) From Swiss banker to UN observer on the Korean DMZ (04:19) The three misconceptions executives have about cyber risk (05:49) The crisis simulation nobody can win and why that's the whole point (09:54) Why the CISO is too often a poster child without real power (11:17) Why cyber insurance in Europe has largely failed (18:38) The OFAC twist that stopped a Swiss bank mid-exercise (19:47) Training Swiss cyber warriors to understand the other side plays by no rules (21:54) Nation states vs. cyber threats: are defenders always outpaced? (23:46) How nation-state cyber conflict mirrors the age of Caribbean pirates (07:25) Always prepared: the three-ounce umbrella that nobody sees   Resources & Links: Leo & Muhly Cyber Advisory  Philipp Leo on LinkedIn ThreatLocker — Presenting sponsor DerScanner — Supporter of this podcast Cyber Florida — The Mother Ship  

KuppingerCole Analysts
Analyst Chat #308: Beyond SASE - What a Real Zero Trust Platform Looks Like

KuppingerCole Analysts

Play Episode Listen Later Jul 20, 2026 42:44


Zero trust has a label problem. After more than a decade, the term has been stretched, diluted, and attached to products that don't come close to delivering what zero trust actually promises. In this episode, Matthias sits down with Alexei Balaganski, lead analyst at KuppingerCole Analysts, to share the findings from six months of research and reveal which vendors actually built a real Zero Trust Platform. Key Topics: ✅ Why zero trust is a strategy, not a product — and what that means for procurement✅ The four non-negotiable requirements for a real Zero Trust Platform✅ What separates a genuine platform from a collection of tools with a zero trust label✅ NHIs, AI agents, and data protection as the new frontiers of zero trust architecture✅ Three critical questions every RFP for a ZTP should include

Talking Cloud with an emphasis on Cloud Security
110-Talking Innovation with Dr. Atif Farid Mohammad PhD, Chief AI Office/CISO at Cyquent, Inc.

Talking Cloud with an emphasis on Cloud Security

Play Episode Listen Later Jul 19, 2026 58:47


Unlock the future where quantum computing, AI, and human intelligence collide—discover why the critical skill of emotional quotient (EQ) may soon trump IQ in this fast-evolving landscape. In this captivating episode, Dr. Atif Farid Mohammed, chief AI officer at CyQuint and author of Least Intelligence, takes us on a journey through the depths of quantum physics, AI's limitations, and the profound impact of energy and consciousness on our existence. You'll discover how quantum mechanics reshapes our understanding of reality, the true potential of large language models versus sentient AI, and why learning — in all its forms — remains the ultimate driver of human evolution. We break down complex concepts like decoherence, space folding, and the nature of energy, translating these into practical insights for navigating tomorrow's technological challenges. If you're curious about the mysteries of the universe, the future of AI, or how to harness emotional intelligence in an AI-driven world, this episode is essential listening. Dr. Mohammed's expertise in quantum computing, cybersecurity, and AI ethics provides a rare perspective on the forces shaping our future. Whether you're a tech enthusiast, a futurist, or simply intrigued by the big questions of existence, this episode will leave you inspired and enlightened. Get ready to rethink what you thought you knew about intelligence, consciousness, and the endless possibilities of the quantum era. Tap in now - your leap into the future starts here. I hope you enjoy it!

Public Sector Podcast
Q&A with Arizona Secretary of State's CISO Michael Moore - Episode 186

Public Sector Podcast

Play Episode Listen Later Jul 19, 2026 29:33


Join Michael Moore, CISO for the Arizona Secretary of State's Office, as he discusses how cybersecurity in government is becoming a leadership and public trust issue—especially in elections, where cyber risk overlaps with physical threats, misinformation, operational logistics, and legal pressures. Referencing a cyber incident he attributes to Iran, he outlines what agencies need now: stronger fundamentals, data classification, AI training, and secure-by-design practices. He also stresses shared responsibility across security, IT, business leaders, and vendors—and the need to keep a human in the loop as AI use expands. Michael Moore, Chief Information Security Officer, Arizona Secretary of State's Office For more great insights head to www.PublicSectorNetwork.co  

Hashtag Trending
Special Interview With Lionel Liddy, CISO at Menlo Security

Hashtag Trending

Play Episode Listen Later Jul 18, 2026 33:43


Browser Security in the Age of Agentic AI: Containment, Isolation, and the New CISO Reality Host Jim Love introduces a #TrendingOnTheWeekend episode featuring David Shipley (Cyber Security Today, Beauceron Security) interviewing Lionel Liddy, CISO at Menlo Security, about AI-driven vulnerability discovery and why reactive security is failing as exploitation accelerates. Liddy shares his path from a University of Toronto PhD researching virtual machines to building Menlo's browser-security approach: an isolated remote "cloud browser" that prevents active web content from executing on endpoints and can also shield servers by forcing interactions through a controlled browser. They discuss CISOs struggling to keep up with rapid shifts, agentic AI risks in browsers and extensions, limits of LLM guardrails (including NIST's proof-like framing), and the compounding impact of pervasive bugs and technical debt. The episode closes with where to learn more at Menlo Security. 00:00 OpenClaw Policy Panic 00:19 Weekend Show Setup 00:57 Interview Preview 02:06 Lionel Origin Story 05:02 Menlo Browser Isolation 06:58 AI Speeds Up Exploits 10:33 CISO Whiplash Era 12:18 Agents In The Browser 16:17 Guardrails Limits Proof 19:58 Mythos And New Normal 23:36 Hazmat Suit For Servers 28:24 Collision Weekend Scenario 32:02 Wrap Up And Links 33:11 Show Closing Notes

Interviews: Tech and Business
Palo Alto Networks EVP: Securing AI Agents in the Enterprise

Interviews: Tech and Business

Play Episode Listen Later Jul 17, 2026 22:14


Enterprises are running more AI agents than their security teams realize, and attackers only need to be right once. Anand Oswal, EVP of Network Security at Palo Alto Networks, explains how to secure agents across four surfaces: enterprise, SaaS, endpoints, and the browser. With host Michael Krigsman, he covers shadow agent discovery, MCP and browser risks, prompt injection, agent identity, and why a unified platform beats a stack of point products.YOU'LL DISCOVER✅ The four agent surfaces every CISO must secure at once: enterprise, SaaS, endpoints, and the browser✅ Why discovery comes first: you cannot secure agents, models, tools, and plugins you cannot see✅ The Palo Alto Networks finding that one third of public MCP servers carry takeover level vulnerabilities✅ How vibe coding agents demand privileged access to local files, terminals, and cloud credentials✅ How browser agents inherit your session and cookies and can perform identity impersonation✅ Runtime threats to know: prompt injection, memory poisoning, tool misuse, and model DoS✅ How MCP and A2A protocols expand the attack surface, and why a centralized AI gateway anchors identity, runtime, and observability controls✅ The case for zero trust, an AI-driven SOC, and one unified platform over point products, and where Prisma AI fits⏱️ TIMESTAMPS0:00 Introduction0:22 Agent memory poisoning and tool misuse0:59 Discovering shadow agents across four surfaces2:32 Vibe coding agents and MCP risk4:46 Browser agents and session misuse6:20 Runtime threats and prompt injection7:17 Agent-to-agent protocols and attack surface8:04 Agent identity and the control plane9:16 Centralizing control at the AI gateway10:23 Zero trust and an AI-driven SOC11:29 One platform, not point productsSubscribe for weekly conversations with the business and technology leaders shaping the enterprise. Get the CXOTalk newsletter: https://newsletter.cxotalk.com Show notes, transcript, and summary: https://www.cxotalk.com/episode/palo-alto-networks-evp-securing-ai-agents-in-the-enterpriseEpisode 924#CXOTalk #EnterpriseAI #CIO #AIGovernance #AgenticAI #IBM #DigitalTransformation #AIStrategy #AILeadership

Cyber Security Headlines
The Department of Know: CMMC suspended, ShareFile shutdown, Context Bombing strikes back

Cyber Security Headlines

Play Episode Listen Later Jul 17, 2026 42:58


"Context Bombing" flips the script on prompt injections Pentagon suspends CMMC Phase II requirements Old tech, new problems Get the show notes here: https://cisoseries.com/the-department-of-know-cmmc-suspended-sharefile-shutdown-context-bombing-strikes-back/  This week's Department of Know is hosted by Rich Stroffolino, with guests Tom Hollingsworth, networking technology advisor, Futurum Group, and Mark Eggleston, former CISO, CSC. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines.  Because security works best when innovation and control move together.

The New CISO
How Many Tokens to Breach Your Network?

The New CISO

Play Episode Listen Later Jul 16, 2026 51:02


What if your next breach came down to a token budget? In this episode, Steve Moore is joined by Lou Rabon, Founder and CEO of Cyber Defense Group, for a conversation on the modern CISO's world—from how to interview for the seat, to why AI agents are the next insider threat, to research that reframes breach cost as a token calculation.Lou and Steve open on breach response, why making introductions during a crisis is a losing game, and the questions every CISO candidate should ask before accepting an offer. Lou lays out how many rounds of interviews a serious CISO role should include, why the CEO must be involved by the final round, and why he believes Legal—not the CIO or CTO—is the ideal reporting line for security.The conversation pivots to AI. Lou argues we are watching a dot-com-speed shift, only compressed. They dig into the emerging insider-threat framing for autonomous agents, the recent incident where an AI slipped its sandbox to contact a researcher, and why attackers face none of the ethical guardrails defenders must respect.Steve shares recent Cornell research showing that agentic tooling can already automate 22 of 32 steps in a corporate intrusion, compressing hours of expert work into seconds—with token spend as the only real limiter. If a breach can be priced in tokens, they argue, defenders must think in tokens too, and machine-to-machine defense becomes a necessity rather than a novelty.The episode closes on what Lou calls “the dirty secret” of cybersecurity: the unglamorous hygiene work—asset lists, data maps, MSA notification clocks—that no one wants to fund. He and Steve explore how agentic AI could finally deliver the always-on trash collection defenders have wanted for decades, from dynamic breach-notification tracking to a security agent that flags every new device.Key Topics• Why making introductions during a crisis is a losing strategy• The interview questions every CISO candidate should ask• Why Legal is the ideal reporting line for the CISO• The inverse curve between convenience and security• AI agents as the next form of insider threat• Cornell research: 22 of 32 intrusion steps automated• Tokens as the new unit of breach cost• Machine-to-machine defense in financial services• The “trash collection” hygiene work at the heart of InfoSec• Agentic AI for asset lists and breach-notification analysisLou Rabon is the Founder and CEO of Cyber Defense Group (CDG), a cybersecurity strategic advisory firm he launched in 2016 to help fast-growing organizations manage modern risk and threats. With more than two decades in security, privacy, and incident response, Lou has led response engagements against nation-state attackers and previously served as CISO at Spokeo. Connect with Lou on LinkedIn or learn more at cdg.io.GET A DEMO:

Serious Privacy
A week in privacy, but we're really talking US Supreme Court

Serious Privacy

Play Episode Listen Later Jul 15, 2026 36:09 Transcription Available


Send us Fan MailWelcome to the Serious Privacy podcast, where Paul Breitbarth, Ralph O'Brien, and Dr. K Royal, discuss a week in privacy. Let's be honest though - it's really the US Supreme Court reent decisions in Slaughter and Chatrie. Tune in for a lievely discussion. Oh - and we're also on YouTube https://www.youtube.com/@seriousprivacypodcastChatrie v. United States (25-112): Police officers conducted a Fourth Amendment search when they acquired Okello Chatrie's location data from Google because an individual has a reasonable expectation of privacy in his cell-phone location information. Trump v. Slaughter (25-332): The Federal Trade Commission's for-cause removal provision, 15 U. S. C. §41, is contrary to the separation of powers enshrined in the Constitution. If you have comments or questions, find us on LinkedIn and Instagram @seriousprivacy, and on BlueSky under @seriousprivacy.eu, @europaulb.seriousprivacy.eu, @heartofprivacy.bsky.app and @igrobrien.seriousprivacy.eu, and email podcast@seriousprivacy.eu. Rate and Review us! From Season 6, our episodes are edited by Fey O'Brien. Our intro and exit music is Channel Intro 24 by Sascha Ende, licensed under CC BY 4.0. with the voiceover by Tim Foley.

Reimagining Cyber
The Ransomware Negotiator Who Worked for the Hackers - #210

Reimagining Cyber

Play Episode Listen Later Jul 15, 2026 21:52


What happens when a trusted ransomware negotiator secretly works for the very hackers he's supposed to stop?In this episode of Reimagining Cyber, Tyler Moffitt unpacks one of the most shocking insider threat cases in recent cybersecurity history. A ransomware negotiator admitted to providing confidential victim information—including insurance limits and negotiation strategies—to the BlackCat (ALPHV) ransomware gang while representing organizations during active ransomware attacks.Learn how ransomware negotiations really work, why information is the most valuable asset during a cyber incident, and what this case reveals about ransomware-as-a-service, cyber insurance, incident response, and insider threats. Whether you're a CISO, security leader, IT professional, or simply interested in cybersecurity, this episode offers practical lessons on trust, risk, and protecting sensitive information when every decision matters.As featured on Million Podcasts' Best 100 Cybersecurity Podcasts  Top 50 Chief Information Security Officer CISO Podcasts Top 70 Security Hacking PodcastsThis list is the most comprehensive ranking of Cyber Security Podcasts online and we are honoured to feature amongst the best!Follow or subscribe to the show on your preferred podcast platform.Share the show with others in the cybersecurity world.Get in touch via reimaginingcyber@gmail.com

CISO-Security Vendor Relationship Podcast
The Only Thing Worse Than Technical Debt is Newly Discovered Technical Debt

CISO-Security Vendor Relationship Podcast

Play Episode Listen Later Jul 14, 2026 43:57


All links and images can be found on CISO Series This week's episode is hosted by David Spark, producer of CISO Series, and Andy Ellis, principal of Duha. Joining them is Tim Callahan, CIO/CISO, AFLAC. In this episode: Week one is the wrong time to overreach Nobody has the AI playbook Vulnerability management wasn't built for this clock Stop blaming the human, fix the system A huge thanks to our sponsor, Vanta No, it's not your imagination. Risk and regulations ARE ramping up—and customers now expect proof of security just to do business. That's why Vanta is a game-changer. Vanta automates your compliance process and brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Companies like Ramp and Writer spend 82% less time on audits with Vanta. That's not just faster compliance—it's more time for growth. Get started at Vanta.com/CISO.  

Cyber Risk Management Podcast
EP 214: AI Agents Don't Behave Like Humans

Cyber Risk Management Podcast

Play Episode Listen Later Jul 14, 2026 39:44


Your cybersecurity tools were built for people: a login, a single sign-on, an email address. But the AI agents now showing up inside your company don't work that way, and most of them slip right past your controls. So how do you find the "Shadow AI" already running in your business, and get a handle on it? Let's find out with our guest Nancy Wang, Chief Technology Officer at 1Password, who works at the front edge of how machines get access to systems. Your hosts are Kip Boyle, CISO with Cyber Risk Opportunities, and Jake Bernstein, Partner with K&L Gates.   LinkedIn profile profile: https://www.linkedin.com/in/wangnancy/   1Password: https://1password.com/

ai partner humans chief technology officer behave ciso 1password l gates jake bernstein kip boyle cyber risk opportunities
Cyber Security Today
AI Export Controls, FortiBleed, Third-Party Breaches & CISO Burnout | Cybersecurity Today Panel

Cyber Security Today

Play Episode Listen Later Jul 11, 2026 61:54


Can governments decide who gets access to advanced AI models? Are third-party breaches becoming impossible to control? And why are so many CISOs reaching burnout? In this special Cybersecurity Today Month in Review Panel, host Jim Love is joined by cybersecurity experts Laura Payne, David Shipley, and Mike Kim (Mycroft) to examine the biggest cybersecurity stories and trends from June 2026. The panel explores the controversy over U.S. export controls on Anthropic's Mythos and Fable AI models, what they reveal about digital sovereignty, and whether governments should be able to restrict access to frontier AI. They also discuss the continuing wave of third-party breaches, including Salesforce ecosystem compromises and the Clue breach, and why organizations must move beyond compliance toward practical risk management. The conversation examines FortiBleed, exposed administrator portals, credential reuse, and the difficult balance between software flaws, operational mistakes, and secure-by-default design. The panel also tackles one of cybersecurity's biggest human challenges: CISO burnout, executive accountability, organizational culture, and what separates successful security leaders from those set up to fail. The episode concludes with encouraging developments in international cybercrime enforcement, including Operation Riptide, and why better intelligence sharing and improved operational security are making it harder for cybercriminals to hide. Whether you're a CISO, security practitioner, IT leader, or simply interested in the rapidly changing cybersecurity landscape, this discussion offers practical insight into the trends shaping the industry. Panel Jim Love (Host) Laura Payne David Shipley Mike Kim (Mycroft) Topics covered AI export controls and digital sovereignty Anthropic Mythos and Fable Third-party and supply chain risk Salesforce ecosystem security FortiBleed and Fortinet security Secure-by-default strategies CISO burnout and executive accountability Operation Riptide Cybercrime investigations Security leadership and governance Chapters 00:00 Sponsor NordLayer 00:38 Meet the Panel 02:40 Author Scam Warning 04:51 Emotion Is the Target 08:47 AI Model Export Controls 10:01 Hype vs Real AI Security 15:01 Sovereignty and Dependency 20:35 Governments Push Back 24:14 AI Internal Voice Risks 26:12 Third Party Breach Fatigue 30:05 Compliance Limits on Risk 32:15 Blame Game to Risk Focus 33:18 Standards and Priorities 33:39 When Security Vendors Fail 34:35 FortiBleed Numbers Explained 35:44 Process Failures vs Bugs 37:32 Why Fortinet Gets Heat 39:05 Secure by Default Basics 41:04 Budget Reality and Culture 44:36 CISO Burnout and AI Pressure 46:16 Liability and Shared Ownership 50:12 What Great CISOs Do 53:07 Operation Riptide Wins 56:10 Deterrence and Due Process 58:14 Sharing Intel for ROI 59:09 Hopium and Wrap Up 01:00:46 Sponsor NordLayer Message

Resilient Cyber
Building an AI AppSec Engineer

Resilient Cyber

Play Episode Listen Later Jul 11, 2026 31:04


JJ of Gecko Security and former Disney and Costco CISO Ryan Knisley on why AppSec needs an AI security engineer, not another scanner.DescriptionAppSec has been stuck for years, drowning teams in noisy findings that never told them what was actually exploitable. JJ, co-founder and CEO of Gecko Security, and Ryan Knisley, former CISO at Disney and Costco, join Resilient Cyber to talk about what changes when an AI security engineer reasons across code, infrastructure, and design docs at once. We get into why business logic breaks traditional SAST, why attackers think in graphs while defenders think in lists, why MTTR is a broken metric, how Cal.com went closed source in the AI era, and where AI-driven AppSec consolidation lands over the next two years.Key takeawaysGecko is an AI security engineer, not another scanner. It reasons across code, infrastructure, and documentation, so a finding arrives already mapped to whether it is reachable in production and what data it touches.The context that tells you if a bug matters lives outside the code. Business logic, architecture, and runtime are where exploitability is decided, which is why scanning the code alone floods teams with noise.Business logic is why traditional SAST fails, and why an LLM alone will not fix it. The same endpoint with no auth check is a critical bug in a document store and expected behavior in a social app, and only design docs and architecture tell the two apart.Attackers think in graphs while defenders think in lists. A critical with a compensating control may not matter, while ten lows chained together can be the thing that actually reaches the asset you care about.Exploit development is being commoditized. JJ describes a near future where the whole internet becomes one big bug bounty scope with agents running campaign-level attacks, so the old severity-ranking lens no longer holds.Fix the class, not the ticket. Rather than patching bugs one by one, Gecko traces groups of findings back to the design decision that created them and eliminates every variant so the same issue never returns.MTTR is a broken metric. A variant of last week's bug returns with a fresh clock, so teams close tickets to look healthy while risk stays flat, which is why Gecko measures recurrence rate instead.Cal.com shows where open source is heading. After AI coding pushed its pull requests from about 30 a day to 100 with a one-person security team, being open source flipped from an advantage to a liability, so it went closed source and replaced four tools with one.Tool consolidation is a risk decision, not a cost exercise. Ryan's shiny object problem leaves teams stacking scanners nobody can fully staff, and collapsing the stack lets you cross-train people and reduce real complexity.The finding layer collapses, and human judgment moves up. When finding and fixing get cheap, the scarce work becomes deciding what is correct, whether to accept a risk on purpose, and owning the design decision for a whole class of bugs.Chapters00:00 Meet JJ and Ryan02:46 Why Gecko is an AI security engineer, not another scanner05:07 The trend of agentic and headless security tools05:53 Why business logic breaks traditional SAST06:27 The no-auth endpoint example and context outside the code09:06 Attackers think in graphs, defenders think in lists11:02 Commoditized exploit dev and the internet as one bug bounty13:55 Shift left and why MTTR is a broken metric15:07 Eliminating entire classes of vulnerabilities15:51 Recurrence rate and avoiding risky refactors18:22 The Cal.com case study and open source going closed20:48 Consolidation and the shiny object problem in security22:40 Where AI-driven AppSec lands in two years27:12 What it takes to trust an AI security engineer28:57 Where to find Gecko and the Black Hat talk

This Week in Startups
Danny Bernstein left Big Tech to fund farm-bots | E2310

This Week in Startups

Play Episode Listen Later Jul 10, 2026 60:54


This Week In Startups is made possible by: NetSuite https://NetSuite.ai/TWIST Squarespace https://squarespace.com/twist YSecurity https://YSecurity.io/TWIST Today's show: *America posted 400,000 farm jobs last year, and fewer than 1% got a single domestic applicant. Danny Bernstein of Reservoir believes it's time to start automating this backbreaking labor, like picking stone fruit in 110°F temperatures. So he built the world's first on-farm robotics incubator on 40 acres of California farmland. Here's why he argues that automating farms isn't just a new opportunity, it's a national security issue. PLUS Jason responded to Gal Shir's viral "AI beat me at design" tweet, got into a kerfuffle with Figma CEO Dylan Field, and wound up making a brand new J-Trade. AND we're talking about the Dept. of Education's new "do no harm" policy, the Brown University AI cheating chart that's blowing up social media, and Lon has fresh streaming recommendations in an all-new Off Duty. Guest: Danny Bernstein on X: https://x.com/bernsteind Reservoir Farms: https://reservoir.co/ Reservoir VC: https://reservoir.vc/ Relevant Links: Bonsai Robotics: https://bonsairobotics.ai/ Root AI acquired by AppHarvest: https://www.therobotreport.com/root-ai-acquired-by-appharvest-for-60m/ John Deere: https://www.deere.com/en-us/ Western Growers Association: https://www.wga.com/ Tanimura & Antle: https://www.taproduce.com/ Naturipe Berry Growers: https://www.naturipefarms.com/ Driscoll's: https://www.driscolls.com/ Taylor Farms: https://www.taylorfarms.com/ The Wonderful Company: https://www.wonderful.com/ Capital Factory: https://www.capitalfactory.com/ Gal Shir "quitting design" post: https://x.com/galshirart/status/2074854464729629060 Dylan Field response to Gal Shir: https://x.com/zoink/status/2075290218660298807 JCal response to Field and "J-Trade": https://x.com/Jason/status/2075481565115654305 Figma: https://www.figma.com/ Dept. of Education: "Do No Harm" policy announcement: https://www.ed.gov/about/news/press-release/us-department-of-education-issues-final-rule-hold-all-colleges-and-universities-accountable-low-earning-programs NPR coverage on Dept. of Education earnings test: https://www.npr.org/2026/06/30/nx-s1-5835631/turner-camhi-do-no-harm-college-loans Paul Graham "cheating chart" post: https://x.com/paulg/status/2075031014628311236 Off Duty Recommendations: "Lioness" on Paramount+: https://www.youtube.com/watch?v=jNRQ0PR4a8U "Mayor of Kingstown" on Paramount+: https://www.youtube.com/watch?v=VkQzvwxOp0s "Human Vapor" on Netflix: https://www.youtube.com/watch?v=7xe6dRKVAb8 "Sugar" on Apple TV+: https://www.youtube.com/watch?v=twvPGxuEOEA "Wind River" (now on Netflix): https://www.youtube.com/watch?v=CZgN0dpFoaE "Not Fade Away" by Peter Barton & Laurence Shames: https://www.amazon.com/Not-Fade-Away-Short-Lived/dp/1579546889 Timestamps: 0:00 Jason's ongoing World Tour 1:43 Danny Bernstein joins live from Reservoir Farms 3:38 What is "specialty crop agriculture" 5:15 Why strawberries are the "white whale" of AgTech 6:55 The labor crisis in farming 9:20 Why AgTech never scaled 9:51 NetSuite - For the first time, you can try NetSuite Next for free. If your revenues are at least in the seven figures, go to https://NetSuite.ai/TWIST 10:51 Inside Reservoir's business model 17:44 Agriculture as national security 20:09 Squarespace - Turn your idea into a beautiful website! Go to https://www.squarespace.com/twist for a free trial. When you're ready to launch, use offer code TWIST to save 10% off your first purchase of a website or domain. 22:15 Did AI beat a designer at design? 30:56 YSecurity - The on-demand security team for startups. Need enterprise-grade security without hiring a $400k CISO? YSecurity gives you 40+ expert engineers, matched to exactly what you need, by the hour, with your first six hours completely free. Go to https://YSecurity.io/TWIST 37:23 The "do no harm" college earnings test 43:27 Brown University students cheated on their midterms 52:22 Lon's streaming recommendations 59:46 Jason's new snake grabber   Subscribe to the TWiST500 newsletter: https://ticker.thisweekinstartups.com Check out the TWIST500: https://www.twist500.com Subscribe to This Week in Startups on Apple: https://rb.gy/v19fcp   Follow Lon: X: https://x.com/lons   Follow Alex: X: https://x.com/alex LinkedIn: ⁠https://www.linkedin.com/in/alexwilhelm   Follow Jason: X: https://twitter.com/Jason LinkedIn: https://www.linkedin.com/in/jasoncalacanis   Check out all our partner offers: https://partners.launch.co/   Great TWIST interviews: Will Guidara, Eoghan McCabe, Steve Huffman, Brian Chesky, Bob Moesta, Aaron Levie, Sophia Amoruso, Reid Hoffman, Frank Slootman, Billy McFarland   Check out Jason's suite of newsletters: https://substack.com/@calacanis   Follow TWiST: Twitter: https://twitter.com/TWiStartups YouTube: https://www.youtube.com/thisweekin Instagram: https://www.instagram.com/thisweekinstartups TikTok: https://www.tiktok.com/@thisweekinstartups Substack: https://twistartups.substack.com

CISO-Security Vendor Relationship Podcast
What Part of Zero Trust Does Your Exception Not Understand?

CISO-Security Vendor Relationship Podcast

Play Episode Listen Later Jul 7, 2026 37:46


All links and images can be found on CISO Series This week's episode is hosted by David Spark, producer of CISO Series, and Andy Ellis, principal of Duha. Joining is Patti Degnan, operating partner, Andreessen Horowitz. In this episode: Identity built for one person at a time Patching can't outrun the exploit timeline The exception hiding inside zero trust A revenue question nobody's answered yet A huge thanks to our sponsor, ThreatLocker ThreatLocker delivers Zero Trust Network Access and Zero Trust Cloud Access that verifies both user and device before granting access to specific applications. No broad access, nothing exposed, and no reliance on credentials alone. It's a smarter way to control access and reduce risk. Learn more at ThreatLocker.com/CISO.

The CyberWire
The AI lock comes off.

The CyberWire

Play Episode Listen Later Jul 1, 2026 30:53


The US restores exports of Anthropic's most advanced AI models. Adobe and Citrix rush out critical patches. RustDuck emerges as a fast-evolving DDoS threat. The Gentlemen raise the stakes with a new EDR-killing exploit. Rocket lab bets big on Iridium. Researchers unveil browser-only ransomware. New Zealand faces questions about its cyber readiness. Iran's long-running cyber espionage campaign is back in the spotlight. Our guest is Donald Codling, CISO and senior advisor to REGO on cybersecurity and data privacy matters, to discuss the importance of tying security by design to psychological safety and digital trust. VIP backstage access, courtesy of Claude. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Donald Codling, CISO and senior advisor to REGO on cybersecurity and data privacy matters, to discuss the importance of tying security by design to psychological safety and digital trust. Selected Reading Fable and Mythos: Anthropic says US lifts export ban on its advanced AI tools (BBC) Adobe patches seven max severity ColdFusion, Campaign flaws (Bleeping Computer) RustDuck: The Botnet That's Still Small but Engineering Like It Plans to Grow (SecurityAffairs) Citrix Patches NetScaler Vulnerabilities, Including New ‘HTTP/2 Bomb' Attack (SecurityWeek) Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets' EDRs (Expel) Rocket Lab to Acquire Iridium in Historic Deal, Creating A Fully Vertically Integrated Space Powerhouse Primed for Growth (Globe Newswire) Ransomware that runs inside your browser tab, where antivirus cannot see it (Suriq) Three major cybehttps://suriq.io/blog/browser-only-ransomware-file-system-accessrattacks have raised alarms about New Zealand's security (RNZ) Arrest of Iranian Hacker Spotlights Iran's Movement into Economic Espionage and IP Theft (Zero Day) Claude Helped a Hacker Find a Way to Issue Tickets to Almost Every US Music Festival (WIRED) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices