Podcasts about ciso

  • 1,454PODCASTS
  • 12,477EPISODES
  • 36mAVG DURATION
  • 2DAILY NEW EPISODES
  • Sep 7, 2026LATEST

POPULARITY

20192020202120222023202420252026

Categories




Best podcasts about ciso

Show all podcasts related to ciso

Latest podcast episodes about ciso

Her Success Story
Dream Big and Believe: Jo Stewart-Rattray's Guide for Women in Tech

Her Success Story

Play Episode Listen Later Sep 7, 2026 25:47


This week, Ivy Slater, host of Her Success Story, chats with her guest, Jo Stewart-Rattray. The two talk about building a career as a woman in technology, overcoming barriers in male-dominated fields, and advancing global initiatives to support women in IT. In this episode, we discuss: How Jo Stewart-Rattray built her career as a woman in technology, starting from the infrastructure side and climbing the ranks despite being one of very few women in the field. What inspired the creation and global rollout of ISACA's She Leads Tech initiative, and how it responded directly to the needs expressed by women in technology focus groups. When Jo had her leadership "aha" moment, realizing the importance of encouraging and supporting other women rather than just pursuing her own success. Why building a strong support network, both at work and at home, is essential for women pursuing leadership roles in tech, and how having honest mentors has benefited Jo Stewart-Rattray throughout her career. Who has influenced and supported Jo Stewart-Rattray on her journey, including trusted mentors, professional peers, and her late husband, who provided personal encouragement and practical support, How she became involved with ISACA, what the organization does, and the mission of global professional development and support for technologists. Jo Stewart-Rattray, Director of Cyber Security & Assurance Jo has over 30 years' experience in the IT field some of which were spent as CIO in the Utilities and as Group CIO in the Tourism space, and with significant experience in the Information Security arena including as CISO in the healthcare sector. She underpins her information technology and security background with her qualifications in education and management.   She specialises in consulting in risk and technology issues with a particular emphasis on governance and security in both the commercial and operational areas of businesses. Jo provides strategic advice to organisations across a number of industry sectors including banking and finance, utilities, manufacturing, tertiary education, retail, healthcare and government.   Jo has extensive board and committee experience.  She has chaired a number of ISACA's international committees including the Board Audit & Risk Committee, Leadership Development and Professional Influence & Advocacy.  She served as an Elected Director on ISACA's international Board of Directors for seven years and was the founder of its global women's leadership initiative, SheLeadsTech and is Vice President, Communities for the Australian Computer Society.   CAREER HIGHLIGHTS Because of her involvement with the SheLeadsTech program and her rural background Jo was selected from a large number of candidates to be one of only two non-government delegates to join the official Australian Government delegation to the 62nd Session of the United Nations Commission on the Status of Women (CSW62) held in New York in March 2018.  She returned to the UN in 2019 and again virtually spoke at UN events in 2021, 2022 and conducted a conversation circle with women from 12 nations in 2023. She has spoken on Capitol Hill during a Day of Advocacy designed to bring tech leaders together in one place to discuss issues related to women in technology and then to meet with Congress representatives and Senator's offices. Jo has an annual award established in her honour to recognise her outstanding leadership and commitment to increasing the representation of women in technology leadership.  The inaugural ISACA Oceania Jo Stewart-Rattray Award was awarded in September 2018. QUALIFICATIONS, MEMBERSHIPS AND AWARDS Master of Education Studies – Psychology Bachelor of Education in Adult Education - Psychology Certified Information Systems Auditor (CISA) Certified Information Security Manager (CISM) Certified in the Governance of Enterprise IT (CGEIT) Certified in Risk and Information Systems Control (CRISC) Fellow, Australian Computer Society, Certified Professional (Cyber Security) Vice President, National Rural Women's Coalition (2023-2024) Vice President (Community Boards), Australian Computer Society (2021-2024) Director, International Board of Directors, ISACA (2012-2014, 2015-2018) National ICT Professional of the Year (iAwards 2011) Paul Williams Award for Inspirational Leadership (2014) SA Women's Honour Roll Inductee (2015) IFSEC Global Top 20 Security Thought Leaders (2019) Eugene M. Frank Award for Meritorious Performance, ISACA Global (2020) Fellow & Life Member, Australian Information Security Association, AISA (2021) https://www.linkedin.com/in/jo-stewart-rattray-gaicd-4991a12/      

Cyber Security Headlines
The Department of Know: Astra launches, CISA cuts programs, McKesson breached

Cyber Security Headlines

Play Episode Listen Later Sep 4, 2026 34:46


Read the full stories at CISOSeries.com This week's Department of Know is hosted by Rich Stroffolino, with guests Montez Fitzpatrick, director, information security, global head of cybersecurity, Energizer Holdings, and Jonathan Waldrop, CISO, Acoustic. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. A huge thanks to our sponsor, KnowBe4 Your employees have always been the target, but the threats they face are evolving. AI empowers cybercriminals to clone a coworker's voice, fake a video call with your CEO, or personalize a phishing email using details scraped from your own website. KnowBe4's AI-native Security Awareness Training (SAT) fights back with 12 autonomous defense agents that allow you to deliver personalized, relevant, and engaging training that adapts as fast as the threats your people face every day. More than 70,000 organizations trust KnowBe4 worldwide. Find out why at KnowBe4.com.  

Defense in Depth
Recommendations to Reboot the Security Vendor Pitch

Defense in Depth

Play Episode Listen Later Sep 3, 2026 28:15


All links and images can be found on CISO Series Check out this post by Val Tsanev of CyberRisk Alliance, for the discussion that is the basis of our conversation on this week's episode co-hosted by David Spark, the producer of CISO Series, and Edward Contreras, senior evp and CISO, Frost Bank. Joining is Jill Rhodes, svp, CISO, Option Care Health. In this episode: The ten-minute test Relevance beats format Price the problem or lose the room Whose meeting is it, really A huge thanks to our sponsor, Teleskope Most DSPMs stop at finding the risk. Teleskope fixes this: it automatically finds sensitive data, including IP documents or board decks, and remediates exposure across cloud, SaaS, and AI environments natively, with human-in-the-loop controls, improving your team's efficiency tenfold. Trusted by Ramp, Polymarket, and Chevron Phillips, and more. teleskope.ai  

ITSPmagazine | Technology. Cybersecurity. Society
Marketing Volume Held Steady. Scrutiny Went Up. | Lens Four by Sean Martin | Read by TAPE9

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Sep 2, 2026 22:08


⬥EPISODE NOTES⬥ For a full year, agentic AI was the pitch. This year the conversation shifted to whether it holds up once it is actually running in production, against real work. Vendors came armed with customer-sourced numbers rather than concept demos — hours returned per analyst per week, percentages of alerts dispositioned without human review, agreement rates measured against human analyst judgment. Buyers arrived having spent the months since the previous major conference testing products and weighing what they were told against what they saw. Not one of the four questions that dominated the show is exciting, and not one of them is actually an AI question. Naming an owner before something ships is governance. Showing your work is audit. Knowing where your components came from is supply chain hygiene. Configuring a tool to reach the outcome it was bought for is the oldest plain, unrewarded work there is. AI did not create those problems — it made them impossible to keep deferring. Marketing volume held steady. Scrutiny went up. In this edition of Lens Four:

Serious Privacy
Week in Privacy - Information is Beautiful

Serious Privacy

Play Episode Listen Later Sep 2, 2026 38:09 Transcription Available


Send us Fan MailWelcome to the Serious Privacy podcast, where Paul Breitbarth, Ralph O'Brien, and Dr. K Royal cover a week in privacy, enforcement actions, breaches, settlements (dud you see the one with Meta?), and more. Check out this website for visualizations of data breaches https://informationisbeautiful.net/visualizations/worlds-biggest-data-breaches-hacks/  If you have comments or questions, find us on LinkedIn and Instagram @seriousprivacy, and on BlueSky under @seriousprivacy.eu, @europaulb.seriousprivacy.eu, @heartofprivacy.bsky.app and @igrobrien.seriousprivacy.eu, and email podcast@seriousprivacy.eu. Rate and Review us!Subscribe today HERE Back the Board Game!  https://www.kickstarter.com/projects/seriousprivacy/serious-privacy-the-data-gamePowered by TrustArcFrom Season 6, our episodes are edited by Fey O'Brien. Our intro and exit music is Channel Intro 24 by Sascha Ende, licensed under CC BY 4.0. with the voiceover by Tim Foley.

The CyberWire
Nightmare on Windows 11.

The CyberWire

Play Episode Listen Later Sep 1, 2026 27:24


Nightmare Eclipse drops a Kaspersky zero-day. The Financial Stability Board warns frontier AI could threaten the global financial system. Anthropic says it has tightened security. CISA adopts a risk-based approach to patching. A new Windows infostealer hides in fake AI models. A critical vulnerability in JFrog Artifactory is kneedeep in active exploitation. North Korean workers are still landing U.S. jobs. A classic NSA codebreaking machine. Our guest is Heather Ceylan, CISO at Box, discussing if AI becomes agentic, governance could become a resilience issue. A robot vacuum sucks up evidence.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today on our Industry Voices, we are joined by Heather Ceylan, CISO at Box, discussing as AI becomes agentic, governance becomes a resilience issue. If you enjoyed this conversation, be sure to check out the full interview here. Selected Reading Chaotic Eclipse Releases Kaspersky Zero-Day HardBreacher (SecurityAffairs) Financial Stability Board Sounds the Alarm Over Frontier AI Risks (Infosecurity Magazine) Unit 42 warns AI has shifted balance of power from defenders to attackers (CyberScoop) Improving our alignment and security practices (Anthropic) CISA vulnerability directive designed to ‘buy back time' against hackers (Federal News Network) RevStealer malware spread through fake Claude Opus 5 download (SC Media) Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild (SecurityWeek) North Korea-linked IT Workers Are Getting Hired Inside Western Companies (SecurityAffairs) IBM Built the Cold War's Most Powerful Code Breaker for the NSA (IEEE Spectrum) Man uses robot vacuum to covertly record his wife's affair, wins divorce settlement but gets sentenced to prison for making an illegal recording — Husband lands behind bars after counter-suit over privacy rights (Tom's Hardware) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Packet Pushers - Full Podcast Feed

What does Enterprise Architecture (EA) mean when AI is everywhere in the stack? Enterprise Architecture is about nailing down relationships and functions while AI pushes back with dynamic processes and probabilistic results. Join Johna and John as they discuss the possibilities for EA: does it prevail, adapt, or die? Episode Links: Watch this episode on... Read more »

CISO-Security Vendor Relationship Podcast
When Frameworks Stop Being Polite and Start Getting Real

CISO-Security Vendor Relationship Podcast

Play Episode Listen Later Sep 1, 2026 37:22


All links and images can be found on CISO Series This week's episode is hosted by me, David Spark, producer of CISO Series and Will Gregorian, CISO, Galileo Medical. Joining us is Ryan Brown, director and head of cybersecurity operations, Children's National Hospital. In this episode: Policy is easy. The exam room isn't. Robotics, Asimov, and the gap before regulation The token bill nobody can explain The 3 AM call is a warning sign A huge thanks to our sponsor, Guardsquare Guardsquare delivers mobile app security without compromise, providing advanced protections for both Android and iOS apps. From app security testing to code hardening to real-time visibility into the threat landscape, Guardsquare solutions provide enhanced mobile application security from early in the development process through publication. Learn more about how to protect your app at Guardsquare.com/CISO.

Packet Pushers - Fat Pipe
HS141: EA vs AI

Packet Pushers - Fat Pipe

Play Episode Listen Later Sep 1, 2026 41:57


What does Enterprise Architecture (EA) mean when AI is everywhere in the stack? Enterprise Architecture is about nailing down relationships and functions while AI pushes back with dynamic processes and probabilistic results. Join Johna and John as they discuss the possibilities for EA: does it prevail, adapt, or die? Episode Links: Watch this episode on... Read more »

Hacker Valley Studio
The Dashboard Is Dead, Long Live the Harness with Myke Lyons

Hacker Valley Studio

Play Episode Listen Later Sep 1, 2026 35:57


Security teams spent decades begging for more logs. Now the enterprise is generating petabytes a day, and the thing drowning in it isn't just the SOC anymore, it's your AI agents too. In this episode, Ron sits down with Myke Lyons, CISO at Cribl, who cut his teeth in telemetry and logging decades ago and has landed right back there in the age of AI. Ron and Myke dig into why most telemetry failures aren't data problems at all, they're decisions nobody made about why the logs are being collected in the first place. Myke breaks down what to track on every agent in your environment, why token spend belongs on the security team's plate, why dashboards are quietly dying, and why treating an AI agent like just another employee is a mistake that's going to bite security teams hard. Underneath it all is one question Myke keeps circling back to: do you actually know what normal looks like for every agent in your environment? Impactful Moments 00:00 - Introduction 01:50 - Myth Busting: AI Agents Aren't Just Another User Account 04:25 - Meet Myke Lyons, CISO at Cribl 05:05 - What it means to run security at a telemetry company 06:10 - From gigabytes of logs at GE to petabytes today 07:45 - MITRE ATT&CK, Cribl's new APEX framework, and orienting telemetry 10:20 - Why most telemetry problems are decision problems, not data problems 13:20 - OCSF and how security teams are rethinking their schemas 14:25 - Why the dashboard is dying 17:35 - What Myke wants to track about every AI agent 20:10 - How to spot an agent going rogue 23:15 - Making your data AI-ready and the case for schematizing everything 27:10 - Tokenomics: treating AI spend as a security responsibility 29:05 - The non-negotiable logs every org should be collecting 31:50 - Hot takes: build vs. buy, tier two to three, and Myke's daily AI briefing 33:35 - Closing thoughts and outro Links Connect with Myke Lyons on LinkedIn: https://www.linkedin.com/in/mykelyons/ Learn more about Cribl: https://cribl.io/  –  Check out our upcoming events: https://www.hackervalley.com/livestreams   Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com   Become a sponsor of the show: https://hackervalley.com/work-with-us/

Heavy Strategy
HS141: EA vs AI

Heavy Strategy

Play Episode Listen Later Sep 1, 2026 41:57


What does Enterprise Architecture (EA) mean when AI is everywhere in the stack? Enterprise Architecture is about nailing down relationships and functions while AI pushes back with dynamic processes and probabilistic results. Join Johna and John as they discuss the possibilities for EA: does it prevail, adapt, or die? Episode Links: Watch this episode on... Read more »

Cybercrime Magazine Podcast
CISO Confidential. AI Defense. Mary Rose Martinez, Marathon Petroleum Corporation & Dylan DeAnda.

Cybercrime Magazine Podcast

Play Episode Listen Later Sep 1, 2026 23:20


Mary Rose Martinez is the Chief Information Security Officer and VP of Digital Technology Services at Marathon Petroleum Corporation. In this episode, she joins host Scott Schober and Dylan DeAnda, field CTO at Doppel, to discuss AI's impact on the threat landscape we're currently facing and how best to defend against it. This episode of CISO Confidential is brought to you by Doppel. Learn more about our sponsor at https://doppel.com.

Paul's Security Weekly
Life as a CISO in Hollywood: Keeping New Films Leak-Free & 4 Black Hat Interviews - Dan Meacham, Ellen Boehm, Ronan Murphy, Frank Vukovits, John Hultquist - ESW #474

Paul's Security Weekly

Play Episode Listen Later Aug 31, 2026 96:38


Interview with Dan Meacham, CISO at Legendary Entertainment Dan Meacham joined us to share a preview of his leadership panel at InfoSec World. At this CRA event in October, Dan will be discussing The Augmented Defender - What AI Actually Changes on the Front Line with Daniel Bowden, the Global CISO at Marsh. Dan dives into the unique world of securing data and assets when film production is largely handled by partners and contractors, working from systems you'll likely have limited access to and definitely can't install agents on. It's a fascinating conversation you should check out! Visit https://securityweekly.com/infosecworld2026 and save 30% on your ISW pass with code: ISW26-SWSAVINGS Black Hat Interview 1 - Google Cloud Outpacing the Adversary with AI Threat Defense - Black Hat interview with John Hultquist, Chief Analyst, Google Threat Intelligence Group at Google The cybersecurity landscape is undergoing a radical shift. AI is no longer just a productivity accelerator for developers and analysts—it has become actively weaponized by sophisticated threat actors to discover and exploit vulnerabilities at unprecedented speed. We'll discuss Google's own approach to combating today's threats and the need for security teams to transform vulnerability management with machine-speed defense. Segment Resources: https://cloud.google.com/blog/products/identity-security/introducing-google-ai-threat-defense https://services.google.com/fh/files/misc/ebookgooglecloudsecurityaithreatdefense.pdf https://services.google.com/fh/files/misc/whitepapercombatingaidriventhreatsgooglemachinespeed_defense.pdf This segment is sponsored by Google Cloud. Visit https://securityweekly.com/googlebh to learn more! Black Hat Interview 2 - Forcepoint Decoding Agentic: Securing the Data Layer AI Just Set on Fire - Black Hat interview with Ronan Murphy, Chief Data Strategy Officer of Forcepoint AI didn't ask permission — and it permanently changed what data risk looks like. Forcepoint Chief Data Strategy officer and member of the Artificial Intelligence Advisory Council in Ireland, shares insights on a clear call to action for agentic enterprises: stop locking AI down and start securing it where the risk actually lives, in the data itself. Learn why data trust is the foundation of the agentic era and how the world's leading enterprises are ending the false choice between AI innovation and data safety. Segment Resources: https://www.forcepoint.com/resources/ebooks/enterprise-guide-ai-data-security https://www.forcepoint.com/blog/insights/forcepoint-announces-ai-data-security This segment is sponsored by Forcepoint. Visit https://securityweekly.com/forcepointbh to learn more! Black Hat Interview 3 - Keyfactor From Secrets to Verified Workload Identity—at Enterprise Scale - Black Hat interview with Ellen Boehm, SVP, Strategy & AI Innovation at Keyfactor As AI agents become autonomous participants inside enterprise environments, organizations can no longer rely on static credentials and traditional identity models to establish trust. Enterprise AI is driving a shift from possession-based access to cryptographically verified identity, as AI agents, cloud-native workloads, and automated services increasingly make decisions and interact with critical systems. In this discussion, we'll discuss why organizations need to continuously establish trust, govern machine identities and cryptography, and build a resilient foundation for securing AI across increasingly dynamic environments. Segment Resources: https://www.keyfactor.com/blog/ai-agents-the-identity-problem-nobody-owns-yet/ https://www.keyfactor.com/education-center/what-is-trust-infrastructure/ https://www.keyfactor.com/resources/topic/col/products/the-trust-control-plane?pflpid=60788&pfsid=HsCXvwPWB1 This segment is sponsored by Keyfactor. Visit https://securityweekly.com/keyfactorbh to learn more! Black Hat Interview 4 - Delinea Delinea Delivers Runtime Authorization for AI Agents, Closing Access Control Gap - Black Hat interview with Frank Vukovits, Chief Security Scientist at Delinea As AI agents move from experiments to autonomous operators inside production databases, cloud consoles, and Kubernetes clusters, enterprises face a new problem: agents with legitimate credentials taking actions no one authorized. Frank breaks down why verifying access at connection time is no longer enough and what it takes to enforce policy on every agent action before it executes. He explains how runtime authorization closes the gap between hiding credentials and actually controlling what agents do once they're inside a session. This segment is sponsored by Delinea. Visit https://securityweekly.com/delineabh to learn more! Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-474

Enterprise Security Weekly (Audio)
Life as a CISO in Hollywood: Keeping New Films Leak-Free & 4 Black Hat Interviews - Dan Meacham, Ellen Boehm, Ronan Murphy, Frank Vukovits, John Hultquist - ESW #474

Enterprise Security Weekly (Audio)

Play Episode Listen Later Aug 31, 2026 96:38


Interview with Dan Meacham, CISO at Legendary Entertainment Dan Meacham joined us to share a preview of his leadership panel at InfoSec World. At this CRA event in October, Dan will be discussing The Augmented Defender - What AI Actually Changes on the Front Line with Daniel Bowden, the Global CISO at Marsh. Dan dives into the unique world of securing data and assets when film production is largely handled by partners and contractors, working from systems you'll likely have limited access to and definitely can't install agents on. It's a fascinating conversation you should check out! Visit https://securityweekly.com/infosecworld2026 and save 30% on your ISW pass with code: ISW26-SWSAVINGS Black Hat Interview 1 - Google Cloud Outpacing the Adversary with AI Threat Defense - Black Hat interview with John Hultquist, Chief Analyst, Google Threat Intelligence Group at Google The cybersecurity landscape is undergoing a radical shift. AI is no longer just a productivity accelerator for developers and analysts—it has become actively weaponized by sophisticated threat actors to discover and exploit vulnerabilities at unprecedented speed. We'll discuss Google's own approach to combating today's threats and the need for security teams to transform vulnerability management with machine-speed defense. Segment Resources: https://cloud.google.com/blog/products/identity-security/introducing-google-ai-threat-defense https://services.google.com/fh/files/misc/ebookgooglecloudsecurityaithreatdefense.pdf https://services.google.com/fh/files/misc/whitepapercombatingaidriventhreatsgooglemachinespeed_defense.pdf This segment is sponsored by Google Cloud. Visit https://securityweekly.com/googlebh to learn more! Black Hat Interview 2 - Forcepoint Decoding Agentic: Securing the Data Layer AI Just Set on Fire - Black Hat interview with Ronan Murphy, Chief Data Strategy Officer of Forcepoint AI didn't ask permission — and it permanently changed what data risk looks like. Forcepoint Chief Data Strategy officer and member of the Artificial Intelligence Advisory Council in Ireland, shares insights on a clear call to action for agentic enterprises: stop locking AI down and start securing it where the risk actually lives, in the data itself. Learn why data trust is the foundation of the agentic era and how the world's leading enterprises are ending the false choice between AI innovation and data safety. Segment Resources: https://www.forcepoint.com/resources/ebooks/enterprise-guide-ai-data-security https://www.forcepoint.com/blog/insights/forcepoint-announces-ai-data-security This segment is sponsored by Forcepoint. Visit https://securityweekly.com/forcepointbh to learn more! Black Hat Interview 3 - Keyfactor From Secrets to Verified Workload Identity—at Enterprise Scale - Black Hat interview with Ellen Boehm, SVP, Strategy & AI Innovation at Keyfactor As AI agents become autonomous participants inside enterprise environments, organizations can no longer rely on static credentials and traditional identity models to establish trust. Enterprise AI is driving a shift from possession-based access to cryptographically verified identity, as AI agents, cloud-native workloads, and automated services increasingly make decisions and interact with critical systems. In this discussion, we'll discuss why organizations need to continuously establish trust, govern machine identities and cryptography, and build a resilient foundation for securing AI across increasingly dynamic environments. Segment Resources: https://www.keyfactor.com/blog/ai-agents-the-identity-problem-nobody-owns-yet/ https://www.keyfactor.com/education-center/what-is-trust-infrastructure/ https://www.keyfactor.com/resources/topic/col/products/the-trust-control-plane?pflpid=60788&pfsid=HsCXvwPWB1 This segment is sponsored by Keyfactor. Visit https://securityweekly.com/keyfactorbh to learn more! Black Hat Interview 4 - Delinea Delinea Delivers Runtime Authorization for AI Agents, Closing Access Control Gap - Black Hat interview with Frank Vukovits, Chief Security Scientist at Delinea As AI agents move from experiments to autonomous operators inside production databases, cloud consoles, and Kubernetes clusters, enterprises face a new problem: agents with legitimate credentials taking actions no one authorized. Frank breaks down why verifying access at connection time is no longer enough and what it takes to enforce policy on every agent action before it executes. He explains how runtime authorization closes the gap between hiding credentials and actually controlling what agents do once they're inside a session. This segment is sponsored by Delinea. Visit https://securityweekly.com/delineabh to learn more! Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-474

Paul's Security Weekly TV
Life as a CISO in Hollywood: Keeping New Films Leak-Free & 4 Black Hat Interviews - Dan Meacham, John Hultquist, Ronan Murphy, Ellen Boehm, Frank Vukovits - ESW #474

Paul's Security Weekly TV

Play Episode Listen Later Aug 31, 2026 96:38


Interview with Dan Meacham, CISO at Legendary Entertainment Dan Meacham joined us to share a preview of his leadership panel at InfoSec World. At this CRA event in October, Dan will be discussing The Augmented Defender - What AI Actually Changes on the Front Line with Daniel Bowden, the Global CISO at Marsh. Dan dives into the unique world of securing data and assets when film production is largely handled by partners and contractors, working from systems you'll likely have limited access to and definitely can't install agents on. It's a fascinating conversation you should check out! Visit https://securityweekly.com/infosecworld2026 and save 30% on your ISW pass with code: ISW26-SWSAVINGS Black Hat Interview 1 - Google Cloud Outpacing the Adversary with AI Threat Defense - Black Hat interview with John Hultquist, Chief Analyst, Google Threat Intelligence Group at Google The cybersecurity landscape is undergoing a radical shift. AI is no longer just a productivity accelerator for developers and analysts—it has become actively weaponized by sophisticated threat actors to discover and exploit vulnerabilities at unprecedented speed. We'll discuss Google's own approach to combating today's threats and the need for security teams to transform vulnerability management with machine-speed defense. Segment Resources: https://cloud.google.com/blog/products/identity-security/introducing-google-ai-threat-defense https://services.google.com/fh/files/misc/ebookgooglecloudsecurityaithreatdefense.pdf https://services.google.com/fh/files/misc/whitepapercombatingaidriventhreatsgooglemachinespeed_defense.pdf This segment is sponsored by Google Cloud. Visit https://securityweekly.com/googlebh to learn more! Black Hat Interview 2 - Forcepoint Decoding Agentic: Securing the Data Layer AI Just Set on Fire - Black Hat interview with Ronan Murphy, Chief Data Strategy Officer of Forcepoint AI didn't ask permission — and it permanently changed what data risk looks like. Forcepoint Chief Data Strategy officer and member of the Artificial Intelligence Advisory Council in Ireland, shares insights on a clear call to action for agentic enterprises: stop locking AI down and start securing it where the risk actually lives, in the data itself. Learn why data trust is the foundation of the agentic era and how the world's leading enterprises are ending the false choice between AI innovation and data safety. Segment Resources: https://www.forcepoint.com/resources/ebooks/enterprise-guide-ai-data-security https://www.forcepoint.com/blog/insights/forcepoint-announces-ai-data-security This segment is sponsored by Forcepoint. Visit https://securityweekly.com/forcepointbh to learn more! Black Hat Interview 3 - Keyfactor From Secrets to Verified Workload Identity—at Enterprise Scale - Black Hat interview with Ellen Boehm, SVP, Strategy & AI Innovation at Keyfactor As AI agents become autonomous participants inside enterprise environments, organizations can no longer rely on static credentials and traditional identity models to establish trust. Enterprise AI is driving a shift from possession-based access to cryptographically verified identity, as AI agents, cloud-native workloads, and automated services increasingly make decisions and interact with critical systems. In this discussion, we'll discuss why organizations need to continuously establish trust, govern machine identities and cryptography, and build a resilient foundation for securing AI across increasingly dynamic environments. Segment Resources: https://www.keyfactor.com/blog/ai-agents-the-identity-problem-nobody-owns-yet/ https://www.keyfactor.com/education-center/what-is-trust-infrastructure/ https://www.keyfactor.com/resources/topic/col/products/the-trust-control-plane?pflpid=60788&pfsid=HsCXvwPWB1 This segment is sponsored by Keyfactor. Visit https://securityweekly.com/keyfactorbh to learn more! Black Hat Interview 4 - Delinea Delinea Delivers Runtime Authorization for AI Agents, Closing Access Control Gap - Black Hat interview with Frank Vukovits, Chief Security Scientist at Delinea As AI agents move from experiments to autonomous operators inside production databases, cloud consoles, and Kubernetes clusters, enterprises face a new problem: agents with legitimate credentials taking actions no one authorized. Frank breaks down why verifying access at connection time is no longer enough and what it takes to enforce policy on every agent action before it executes. He explains how runtime authorization closes the gap between hiding credentials and actually controlling what agents do once they're inside a session. This segment is sponsored by Delinea. Visit https://securityweekly.com/delineabh to learn more! Show Notes: https://securityweekly.com/esw-474

Talking Cloud with an emphasis on Cloud Security
113-Talking Innovation with Tom Dager, CISO at ADM

Talking Cloud with an emphasis on Cloud Security

Play Episode Listen Later Aug 30, 2026 54:07


AI is moving faster than most organizations can govern it, and Tom Dagger, CISO at ADM, explains why that speed is now a cybersecurity, compliance, and business risk problem all at once. If you care about AI in the enterprise, exposure management, or what happens when innovation outruns control, this conversation is essential listening. Tom and I get brutally honest about the reality behind AI adoption at a global enterprise. ADM is already using tools like ADM Chat, Microsoft Copilot, and AI-powered SaaS, but Tom makes the case that the real challenge is not whether to use AI - it is how to manage the constant churn of models, harnesses, data sharing, and operational risk without breaking the business.You'll hear Tom break down the three buckets of AI usage every security leader needs to think about: personal productivity tools like chatbots and copilots, AI embedded inside third-party SaaS platforms, and enterprise-built AI use cases that create real operational value. We also dig into why “tokenomics,” model switching, and continuous patching are now board-level concerns, especially in regulated industries where a simple software change can mean downtime, lost productivity, or regulatory scrutiny. They unpack why vulnerability ops and exposure management are replacing old-school patch Tuesday thinking, and why security teams can no longer treat AI like just another software upgrade.The conversation gets even sharper when they turn to data governance and accountability. Tom warns that the biggest blind spot may not be model performance - it is the data being handed over to third parties, the hallucinations that can slip into workflows, and the dangerous myth that AI removes human responsibility. From fake legal citations to discriminatory automated decisions, the stakes are real, and the accountability still lands on the organization.They also look ahead at what AI and quantum could mean for transportation, manufacturing, food production, and even the future of entry-level jobs. As AI takes over more routine work, what happens to the ladder people traditionally climb to build experience? We go on to explore the long-term impact on talent pipelines, human judgment, and the roles that will still need a person in the loop. Essential listening for CISOs, security leaders, tech executives, and anyone trying to figure out how to adopt AI without surrendering control. This is a candid, practical conversation about where enterprise AI is headed, what can go wrong, and how leaders need to think now if they want to stay ahead. In this episode we bring cybersecurity, AI strategy, and real-world enterprise operations into one timely conversation. I hope you enjoy it!

Cyber Security Headlines
The Department of Know: Power plant attack, NSA hacker reunion, Hugging Face hack report

Cyber Security Headlines

Play Episode Listen Later Aug 28, 2026 33:15


Read the full stories at CISOSeries.com.  This week's Department of Know is hosted by Rich Stroffolino, with guests Jason Elrod, CISO, MultiCare Health System, and Chris Ray, field CTO, GigaOm. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. A huge thanks to our sponsor, ThreatDown Managing an enterprise-sized attack surface without a dedicated SOC? As attackers leverage AI-driven automation to target mid-size business, your legacy defenses are no longer enough. You need the expertise to detect and respond to modern threats, without the overhead of building an in-house security team. ThreatDown provides proactive, Managed Detection and Response, 24/7, so your business can scale safely. Enterprise-grade defense. Built for businesses like yours.

ai built attack reunions missed hackers enterprise cto soc ciso hugging power plants gigaom chris ray multicare health system ciso series rich stroffolino
Defense in Depth
Market Confusion Is Responsible for the Biggest Gaps in Cybersecurity

Defense in Depth

Play Episode Listen Later Aug 27, 2026 29:47


All links and images can be found on CISO Series Check out this post from Joe Head of RELEX Solutions for the discussion that is the basis of our conversation on this week's episode co-hosted by David Spark, the producer of CISO Series, and Edward Contreras, senior evp and CISO, Frost Bank. Joining is Mary Rose Martinez, CISO, and vp of digital technology services, Marathon Petroleum Corporation. In this episode: Left behind A hypothetical sale The philosophy problem Stop shifting the problems A huge thanks to our sponsor, ActiveState ActiveState gives security and engineering teams a single governed source for open source software. With 79 million components built from source, continuously remediated, and delivered directly into the tools teams already use, ActiveState eliminates the CVE backlog and the developer toil that comes with it. Companies see a 60 to 99% reduction in CVEs and reclaim up to 30% of developer time. Learn more at activestate.com.

The New CISO
The Player-Coach CISO: Engineering Trust in AI Agents with Open-Source Tools

The New CISO

Play Episode Listen Later Aug 27, 2026 49:06


In this episode of The New CISO, host Steve Moore welcomes Sherri Douville for a conversation that sits outside the show's usual lane — less war story, more blueprint. Sherri works alongside CISOs rather than inside the role, and arrives with a pointed argument about what the job is becoming.She starts with why TTIC exists. IEEE UL 2933 gave healthcare a full-stack standard for clinical IoT device and data interoperability, but a standard on paper does nothing until it is adopted, implemented, and maintained. Getting there in a high-reliability industry means pulling in CIOs, CISOs, physicians, and engineers — and, Sherri admits, negotiating turf wars with bodies who assume you have come for their territory.Then the headline: how to make security cool. Sherri's answer starts with visibility — getting CISOs onto stages, onto podcasts, and into print in front of clinical leadership. Underneath it is a claim about trust. In healthcare, trust is the core of the business rather than an adjacent concern, which makes the CISO its natural steward. With AI pushing trust to the center of every industry, she argues that is the opening to become the rock star of the C-suite.Steve raises a banking CISO's framing of AI as a curious seven-year-old with a gun. Sherri pushes back on the spot: her analogy is the gifted teenager — capable, resource-hungry, and badly in need of direction. That leads to her real thesis. Scarce expertise used to carry economic value, and AI is rapidly compressing the worth of expert analysis. What appreciates instead is judgment, authority, execution, verification, organizational integration, and ownership of the outcome. Executives do not want more reports; they want the security problem to go away without adding coordination burden.The last stretch turns practical. Sherri walks through running Exabeam's open-source Praxen against Medigram's own code — painless to run, with remediation effort scaling to whatever standard you are chasing — and pairs it with Observra for continuous runtime telemetry. She closes on why it matters: when systems go down in a hospital, the real damage is not the outage hour but the fortnight of delays, miscommunications, and pile-up that follows for clinicians and patients.Key TopicsWhy standards bodies stall at adoption, not authorshipMaking security “cool”: visibility, stages, and executive presenceTrust as the core of the business in high-reliability industriesThe gifted teenager vs. the curious seven-year-old with a gunJudgment, authority, execution, verification, integration, ownershipSelective depth and the player-coach executiveRunning Praxen pre-deployment; Observra for runtime telemetryWhat a healthcare outage really costs, 14 to 20 days outGuest BioSherri Douville is CEO and Architect of Medigram and Founder and Chair of the Trustworthy Technology & Innovation Consortium (TTIC). She co-chairs the Trust subgroup of IEEE UL 2933 (TIPPSS), the standard for trust in clinical IoT. Medigram builds and operates Darwin, a governed AI decision platform whose agentic fleet runs in production and writes a sealed governance record at the moment of every agent action — an auditable trail for counsel, courts, insurers, and credit rating agencies. Sherri spent over a decade at Johnson & Johnson across a dozen disease states before physician leaders pulled her into healthcare IT and AI. She calls herself an accidental technologist: a domain expert who got into the code, logging 200 GitHub commits across June and July.GET A DEMO:

The Daily Scoop Podcast
Trump administration mandates agency use of Login-dot-gov on government websites

The Daily Scoop Podcast

Play Episode Listen Later Aug 27, 2026 7:27


The Office of Management and Budget is circulating a new draft policy that would enforce the use of Login-dot-gov, the federal government's single sign-on service, “for most public facing services,” including websites and digital platforms that require authentication. According to a draft version of a memo sent Monday to agencies for review, agencies would have 60 days to provide OMB with an inventory of existing public-facing websites with authentication, and six months to develop a broader digital identity risk management review as part of the mandatory shift to Login. In the draft memo viewed by FedScoop, OMB Director Russell Vought cited the lack of a governmentwide strategy for managing digital identity and President Donald Trump's executive order on improving digital design in government as justifications for the new policy. It argues the current patchwork of digital-identity solutions used by federal agencies results in increased costs and is a hassle to Americans seeking to get government information. “As the use of Login.gov for identity verification increases, the government realizes cost efficiencies from economies of scale and a reduction in duplicative verification costs,” the draft memo said. “Increased use…also supports the government's security posture, enabling deployment at scale of leading technologies and security practices to prevent and respond to emerging threats.” The Department of Homeland Security's top technology leader is set to depart the agency, per two sources familiar with the matter. Antoine McCord joined DHS as chief information officer in March 2025. McCord also oversaw the Office of Biometrics and Identity Management and served as the acting CISO. The official kept a low profile while overseeing the law enforcement agency's multibillion-dollar budget, forgoing media interviews and events. He was in the initial wave of CIO hires under the second Trump administration following the reclassification of the chief information officer position. The Office of Personnel Management moved the role from “career reserved” to “general,” easing restrictions on who could get tapped —though the DHS CIO role has historically been political. Prior to DHS, McCord held positions at defense technology company Anduril and within the U.S. Marine Corps and intelligence community. The Daily Scoop Podcast is available every Monday-Friday afternoon. If you want to hear more of the latest from Washington, subscribe to The Daily Scoop Podcast  on Apple Podcasts, Soundcloud, Spotify and YouTube.

The CyberWire
The feds flip the script.

The CyberWire

Play Episode Listen Later Aug 26, 2026 32:31


The U.S. disrupts a Chinese hacking operation blamed for intrusions at several sensitive government agencies.  CISA says more than 100 water systems were targeted in July. Attackers exploit a critical Gitea flaw, while malicious pages masquerade as Cloudflare verification screens. Cyber insurance claims get costlier, and AI agents break out of their sandboxes. Boston Scientific battles a cyber incident. Plus, a new standard tracks AI agent activity, criminals target stolen iPhones, and an alleged money mule is charged in a $7.5 million scam. Our guest is Stephen Hilt,  Sr. Threat Researcher at TrendAI,  on the risks facing data centers.  Some breach data doesn't quite measure up. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On today's Industry Voices, we are joined by Stephen Hilt,  Sr. Threat Researcher at TrendAI discussing the cybersecurity risks facing data centers and the thousands of internet-exposed industrial control systems that could leave them vulnerable to attack. And if you enjoyed this conversation, be sure to check out the full interview here.  If you'd like to hear more on this topic from TrendAI, you can check out this recent episode of the AI Security Brief podcast that focuses on data center security. Guest Mark Houpt, CISO at DataBank, joined hosts Johnny Hand and Dustin Childs to explain why securing the AI era starts with protecting the physical data centers that power it—and why proven security fundamentals still matter against rapidly evolving threats. AI Security Brief podcast publishes every other Thursday on the N2K CyberWire network. Subscribe today! Selected Reading China-sponsored hacking platforms seized by US, Justice Department says (Reuters)   CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks (SecurityWeek) Hackers now exploit critical Gitea flaw in code injection attacks (Bleeping Computer) Hackers abuse npm mirrors to host phishing redirect pages (Bleeping Computer) Average Cyber Insurance Losses Increase Despite Fewer Claims (Infosecurity Magazine) VMs won't contain cyber-capable agents (Trail of Bits) Boston Scientific hit by cyberattack, global operations affected (Reuters) Linux Foundation Introduces TRACE Standard for AI Runtime Evidence (Infosecurity Magazine) AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes (Bleeping Computer) Indian man who fled US arrested on charges he helped scammers siphon $7.5 million from the elderly (The Record) Trump signs memo to help drastically boost US commercial space launches (Reuters)  A Cautionary Tale About Data Breach Claims, Verification and Carhartt (Troy Hunt) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Paul's Security Weekly
Connecting Cyber Risks to Board Outcomes & BHUSA interviews from Mimecast & Zscaler - Leslie Nielsen, Brett Stone-Gross, Dan Bowden - BSW #462

Paul's Security Weekly

Play Episode Listen Later Aug 26, 2026 67:29


The threat landscape has become more interconnected, disruptive, and complex. Ransomware is now as much about extortion and data theft as it is about encryption. Supply chain events can create outages that ripple far beyond the initial target, and business interruption increasingly comes from third-party and cloud dependencies. How should CISOs prepare for these scenarios? Dan Bowden, Global Business CISO at Marsh, joins Business Security Weekly to discuss how to connect cyber risk to the outcomes boards care about most: resilience, financial exposure, regulatory impact, and reputation. CISOs need to position cyber as an enterprise risk, not a technical risk, that can be measured, prioritized, and managed alongside other strategic risks. Dan will discuss the results of Marsh's Cyber Catalyst research and Global Cyber Claims Report. Visit https://securityweekly.com/infosecworld2026 and save 30% on your ISW pass with code: ISW26-SWSAVINGS The Agent Is the New Insider: Why Human Risk Doesn't Stop at People: Black Hat Interview with Leslie Nielson, CISO at Mimecast AI agents now act with the same credentials and access as the humans who deployed them, but without the judgment or accountability that comes with actual employment. Mimecast CISO Leslie Nielsen argues that treating agentic AI as a brand new, standalone security category is the wrong instinct: agents are an extension of human risk, and the controls organizations already use to manage people are the right foundation for managing machines. In this conversation, Nielsen unpacks the growing gap between security leaders who expect AI driven attacks and those who feel prepared for them, and what that gap means for CISOs walking the floor at Black Hat. Segment Resources: Mimecast's new whitepaper Securing The Agentic Enterprise: https://assets.mimecast.com/api/public/content/securing-the-agentic-enterprise?v=ea66db05 Mimecast's landing page for thought leadership resources: https://www.workprotected.com/ Mimecast's State of Human Risk Report: https://www.mimecast.com/resources/ebooks/state-of-human-risk/ Mimecast's Threat Intelligence Hub: https://www.mimecast.com/threat-intelligence-hub/ For more information about Mimecast please visit: https://securityweekly.com/mimecastbh Ransomware Moves up the Org Chart: Managers Are Prime Targets: Black Hat Interview with Brett Stone-Gross, Sr. Director, Threat Intelligence at Zscaler When a ransomware attack makes headlines, attention usually turns to the organization that was breached, the systems encrypted, data stolen, and disruption or ransom demand that followed. Less, if anything, is revealed about the employees compromised at the start of the attack, and what makes those individuals valuable targets. New Zscaler ThreatLabz research examines this early stage of a real-world ransomware attack. ThreatLabz identified victims of a campaign associated with a ransomware group known for gaining initial access, stealing large amounts of corporate data, and selectively encrypting critical systems. The findings show who those victims were and how their roles and authority could help an attacker move deeper into an organization. This is part of ongoing ransomware research by ThreatLabz. The Zscaler ThreatLabz 2026 Ransomware Report, coming in the next two months, will include additional data on ransomware victims, the latest ransomware trends, targets, and tactics, and the risks enterprises should prepare for next. This segment is sponsored by Zscaler. Visit https://securityweekly.com/zscalerbh to learn more about them! Visit https://www.securityweekly.com/bsw for all the latest episodes! Show Notes: https://securityweekly.com/bsw-462

Serious Privacy
12 years in ICO Complaints (with Dom Smith) AND Meta settlement

Serious Privacy

Play Episode Listen Later Aug 26, 2026 49:56 Transcription Available


Send us Fan MailThe real problem with complaints isn't that people are complaining.It's that unhappy people don't usually show up unless something already went wrong. So when the ICO says it has to triage harder, that's the tension.Welcome to the Serious Privacy podcast, where Paul Breitbarth, Ralph O'Brien, and Dr. K Royal connect with Dom Smith of the UK's Information Commissioner's Office to discuss his role in addressing complaints and changes he has seen over the last 12 years. We'll learn a little about him and how his experiences and perspective over the years has shaped him as a data protection professional.Before you hear the episode, you will first hear an emergency segment to discuss the settlement Meta reached with U.S. states in the children's harm court case.  @trustarc  If you have comments or questions, find us on LinkedIn and Instagram @seriousprivacy, and on BlueSky under @seriousprivacy.eu, @europaulb.seriousprivacy.eu, @heartofprivacy.bsky.app and @igrobrien.seriousprivacy.eu, and email podcast@seriousprivacy.eu. Rate and Review us!Subscribe today HERE Back the Board Game!  https://www.kickstarter.com/projects/seriousprivacy/serious-privacy-the-data-gamePowered by TrustArcFrom Season 6, our episodes are edited by Fey O'Brien. Our intro and exit music is Channel Intro 24 by Sascha Ende, licensed under CC BY 4.0. with the voiceover by Tim Foley.

Paul's Security Weekly TV
Connecting Cyber Risks to Board Outcomes & BHUSA interviews from Mimecast & Zscaler - Dan Bowden, Leslie Nielsen, Brett Stone-Gross - BSW #462

Paul's Security Weekly TV

Play Episode Listen Later Aug 26, 2026 67:30


The threat landscape has become more interconnected, disruptive, and complex. Ransomware is now as much about extortion and data theft as it is about encryption. Supply chain events can create outages that ripple far beyond the initial target, and business interruption increasingly comes from third-party and cloud dependencies. How should CISOs prepare for these scenarios? Dan Bowden, Global Business CISO at Marsh, joins Business Security Weekly to discuss how to connect cyber risk to the outcomes boards care about most: resilience, financial exposure, regulatory impact, and reputation. CISOs need to position cyber as an enterprise risk, not a technical risk, that can be measured, prioritized, and managed alongside other strategic risks. Dan will discuss the results of Marsh's Cyber Catalyst research and Global Cyber Claims Report. Visit https://securityweekly.com/infosecworld2026 and save 30% on your ISW pass with code: ISW26-SWSAVINGS The Agent Is the New Insider: Why Human Risk Doesn't Stop at People: Black Hat Interview with Leslie Nielson, CISO at Mimecast AI agents now act with the same credentials and access as the humans who deployed them, but without the judgment or accountability that comes with actual employment. Mimecast CISO Leslie Nielsen argues that treating agentic AI as a brand new, standalone security category is the wrong instinct: agents are an extension of human risk, and the controls organizations already use to manage people are the right foundation for managing machines. In this conversation, Nielsen unpacks the growing gap between security leaders who expect AI driven attacks and those who feel prepared for them, and what that gap means for CISOs walking the floor at Black Hat. Segment Resources: Mimecast's new whitepaper Securing The Agentic Enterprise: https://assets.mimecast.com/api/public/content/securing-the-agentic-enterprise?v=ea66db05 Mimecast's landing page for thought leadership resources: https://www.workprotected.com/ Mimecast's State of Human Risk Report: https://www.mimecast.com/resources/ebooks/state-of-human-risk/ Mimecast's Threat Intelligence Hub: https://www.mimecast.com/threat-intelligence-hub/ For more information about Mimecast please visit: https://securityweekly.com/mimecastbh Ransomware Moves up the Org Chart: Managers Are Prime Targets: Black Hat Interview with Brett Stone-Gross, Sr. Director, Threat Intelligence at Zscaler When a ransomware attack makes headlines, attention usually turns to the organization that was breached, the systems encrypted, data stolen, and disruption or ransom demand that followed. Less, if anything, is revealed about the employees compromised at the start of the attack, and what makes those individuals valuable targets. New Zscaler ThreatLabz research examines this early stage of a real-world ransomware attack. ThreatLabz identified victims of a campaign associated with a ransomware group known for gaining initial access, stealing large amounts of corporate data, and selectively encrypting critical systems. The findings show who those victims were and how their roles and authority could help an attacker move deeper into an organization. This is part of ongoing ransomware research by ThreatLabz. The Zscaler ThreatLabz 2026 Ransomware Report, coming in the next two months, will include additional data on ransomware victims, the latest ransomware trends, targets, and tactics, and the risks enterprises should prepare for next. This segment is sponsored by Zscaler. Visit https://securityweekly.com/zscalerbh to learn more about them! Show Notes: https://securityweekly.com/bsw-462

Business Security Weekly (Audio)
Connecting Cyber Risks to Board Outcomes & BHUSA interviews from Mimecast & Zscaler - Leslie Nielsen, Brett Stone-Gross, Dan Bowden - BSW #462

Business Security Weekly (Audio)

Play Episode Listen Later Aug 26, 2026 67:29


The threat landscape has become more interconnected, disruptive, and complex. Ransomware is now as much about extortion and data theft as it is about encryption. Supply chain events can create outages that ripple far beyond the initial target, and business interruption increasingly comes from third-party and cloud dependencies. How should CISOs prepare for these scenarios? Dan Bowden, Global Business CISO at Marsh, joins Business Security Weekly to discuss how to connect cyber risk to the outcomes boards care about most: resilience, financial exposure, regulatory impact, and reputation. CISOs need to position cyber as an enterprise risk, not a technical risk, that can be measured, prioritized, and managed alongside other strategic risks. Dan will discuss the results of Marsh's Cyber Catalyst research and Global Cyber Claims Report. Visit https://securityweekly.com/infosecworld2026 and save 30% on your ISW pass with code: ISW26-SWSAVINGS The Agent Is the New Insider: Why Human Risk Doesn't Stop at People: Black Hat Interview with Leslie Nielson, CISO at Mimecast AI agents now act with the same credentials and access as the humans who deployed them, but without the judgment or accountability that comes with actual employment. Mimecast CISO Leslie Nielsen argues that treating agentic AI as a brand new, standalone security category is the wrong instinct: agents are an extension of human risk, and the controls organizations already use to manage people are the right foundation for managing machines. In this conversation, Nielsen unpacks the growing gap between security leaders who expect AI driven attacks and those who feel prepared for them, and what that gap means for CISOs walking the floor at Black Hat. Segment Resources: Mimecast's new whitepaper Securing The Agentic Enterprise: https://assets.mimecast.com/api/public/content/securing-the-agentic-enterprise?v=ea66db05 Mimecast's landing page for thought leadership resources: https://www.workprotected.com/ Mimecast's State of Human Risk Report: https://www.mimecast.com/resources/ebooks/state-of-human-risk/ Mimecast's Threat Intelligence Hub: https://www.mimecast.com/threat-intelligence-hub/ For more information about Mimecast please visit: https://securityweekly.com/mimecastbh Ransomware Moves up the Org Chart: Managers Are Prime Targets: Black Hat Interview with Brett Stone-Gross, Sr. Director, Threat Intelligence at Zscaler When a ransomware attack makes headlines, attention usually turns to the organization that was breached, the systems encrypted, data stolen, and disruption or ransom demand that followed. Less, if anything, is revealed about the employees compromised at the start of the attack, and what makes those individuals valuable targets. New Zscaler ThreatLabz research examines this early stage of a real-world ransomware attack. ThreatLabz identified victims of a campaign associated with a ransomware group known for gaining initial access, stealing large amounts of corporate data, and selectively encrypting critical systems. The findings show who those victims were and how their roles and authority could help an attacker move deeper into an organization. This is part of ongoing ransomware research by ThreatLabz. The Zscaler ThreatLabz 2026 Ransomware Report, coming in the next two months, will include additional data on ransomware victims, the latest ransomware trends, targets, and tactics, and the risks enterprises should prepare for next. This segment is sponsored by Zscaler. Visit https://securityweekly.com/zscalerbh to learn more about them! Visit https://www.securityweekly.com/bsw for all the latest episodes! Show Notes: https://securityweekly.com/bsw-462

CISO-Security Vendor Relationship Podcast
"Ignorance Is Bliss" Is Our Acceptable Use Policy

CISO-Security Vendor Relationship Podcast

Play Episode Listen Later Aug 25, 2026 39:03


http://www.Threatlocker.com/cisoAll links and images can be found on CISO Series This week's episode is hosted by David Spark, producer of CISO Series and Edward Contreras, senior evp and CISO, Frost Bank. Joining is sponsored guest Rob Allen, chief product officer, ThreatLocker. In this episode: Not my job, still my problem The tools people actually use Mac, Windows, and the debate that won't quit Hiring for imagination, not acronyms A huge thanks to our sponsor, ThreatLocker ThreatLocker delivers Zero Trust Network Access and Zero Trust Cloud Access that verifies both user and device before granting access to specific applications. No broad access, nothing exposed, and no reliance on credentials alone. It's a smarter way to control access and reduce risk. Learn more at ThreatLocker.com/CISO.

hiring mac windows ciso ignorance is bliss rob allen threatlocker frost bank david spark zero trust network access acceptable use policy ciso series
Cyber Risk Management Podcast
EP 217: When Hospital Systems Go Down, Who Keeps Patients Safe?

Cyber Risk Management Podcast

Play Episode Listen Later Aug 25, 2026 48:30


When a hospital's systems go down, care does not stop. It goes back to pen and paper, and the first sign is quiet, because the alerts stop. Physician and CISSP Mark Yoffe explains clinical compensating controls: the steps clinicians take to keep patients safe during downtime. He covers who owns the clinical workflow, how to make controls workable and tested, how to recover information lost in the "memory hole," and what leaders should demand as proof. Paper is not the same as proof. Your hosts are Kip Boyle, CISO with Cyber Risk Opportunities, and Jake Bernstein, Partner with K&L Gates.   LinkedIn: https://www.linkedin.com/in/mark-yoffe-md-cissp-a9927956/   "Fire Doesn't Innovate" by Kip Boyle: https://a.co/d/0bYatohy     LinkedIn post:   Questions: Here are audience engagement questions for this episode, organized by segment:   Segment 1 – When the Hospital Goes Analog Have you ever worked through a system outage — at a hospital or anywhere else? What was the first thing that broke down?Does your organization have any setting where "no news is bad news" during downtime — where information stops coming to you and you don't immediately notice? Segment 2 – Ownership Who owns your clinical downtime workflow right now — not IT, but the clinical side? Can you name them?If your systems went down tonight, is there a single person accountable for whether patient care workflows hold up — or would people be figuring it out as they go? Segment 3 – Workability Does your downtime policy actually get used, or does it live in a binder somewhere? When did anyone last open it?What's one task your team assumes staff can improvise during downtime — that they probably can't? Segment 4 – The Memory Hole After your last outage, how confident are you that everything documented on paper actually made it into the record? Did anyone check?Has a gap in documentation during downtime ever affected a patient's care — or nearly did? Segment 5 – Leadership Oversight If your CEO asked today, "Can you show me that our clinical downtime controls actually work?" — what would you hand them?When did your organization last run a tabletop exercise specifically for clinical downtime — not just IT recovery? Closing poll question: Does your organization have a named, clinically credible owner for downtime workflows — yes, no, or "I genuinely don't know"?

ceo partner safe hospitals patients physicians innovate go down ciso l gates hospital systems jake bernstein fire doesn kip boyle cyber risk opportunities
Business of Tech
ThreatCaptain Gen 4 Unbundles Pricing: Brad Powell Explains Impact for MSP Growth Strategies

Business of Tech

Play Episode Listen Later Aug 24, 2026 15:42


The core structural shift addressed in this episode centers on the unbundling and modularization of vendor platforms in the MSP technology market. This shift is exemplified by ThreatCaptain's launch of its Gen 4 product, which transitions from an all-encompassing platform to discrete modules aligned to specific MSP business challenges—lead generation, sales enablement, and ROI/risk analytics. The move is designed to align product structure and pricing more closely to the diverse operational maturity levels of MSPs, as described by Brad Powell, co-founder of ThreatCaptain. ThreatCaptain's Gen 4 is available in three modules priced at $199, $399, and $599, most notably a move away from the earlier $1,499 per month pricing reported in March. According to Brad Powell, this change was driven by limited adoption among smaller MSPs, with the prior model better suited to larger firms already equipped with mature sales teams. He cites customer Novus Insights as an example, attributing $80,000 in professional services revenue over three months and more than $1 million in expected ARR, but acknowledges this reflected a highly mature CISO-led operation. The vendor currently reports approximately 65 active paying MSP partners, intending to scale significantly. Supporting developments include the influence of insurance risk modeling and industry threat intelligence frameworks on new MSP toolsets. ThreatCaptain originally built its risk engine leveraging data from the IBM Cost of a Data Breach Report and the Verizon DBIR, adapting these for SMB scenarios. The episode also highlights the role of information sharing organizations (ISAOs), with Brad Powell noting the challenges of translating technical threat data into actionable intelligence for SMB-focused MSPs and illustrating ongoing coordination and separation of threat feeds between vendor sales processes and industry sharing mechanisms. Operational implications for MSPs include increased need for prudent selection among modular product offerings, clarity around the scope and accountability of vendor-delivered analysis, and awareness of potential misalignments between vendor risk models and actual business outcomes. The trend underscores cost versus capability tradeoffs, especially for smaller providers balancing limited resources against the operational benefits of specialized tools. For MSPs participating in threat intelligence programs, there is also an ongoing requirement to maintain clear boundaries around shared data to prevent unintentional exposure or misapplication in commercial contexts. Supported By: ScalePad Pax8

Resilient Cyber
Secure Vibe Coding and the 99%

Resilient Cyber

Play Episode Listen Later Aug 24, 2026 56:01 Transcription Available


Lovable CISO Igor Andriushchenko on soft guardrails vs. hard boundaries, securing vibe coding for non-developers, and building a security program at a 10x company.I sit down with Igor Andriushchenko, Head of Security and CISO at Lovable, the AI development platform behind one of the fastest growth stories in the space. Igor joined as the first security hire when the company was around 40 people. A year later he is running a 20+ person team covering product security, GRC, IT, and platform safety for a company with 400 laptops in MDM and no sign of slowing down.We get into what it actually takes to secure AI-native development, both inside a hypergrowth startup and on a platform where most of the people shipping software are not developers and definitely not security practitioners.In this episode:Building a security program for the company you will be in 12 months instead of the one you are in todaySoft guardrails versus hard guardrails, and how to decide which one a problem deservesWhy hard blocks push AI-assisted workflows into the shadowsRooting guardrail decisions in business goals, risks, and threats rather than tool defaultsDemocratized development without democratized security, and what a platform owes the 99%Lovable's auto-fix toggle, per-app threat models, and the goal of an app with no security tab at allWhether models will ever produce secure code by default, and why defense in depth still carries the loadGoverning the reality that every employee vibe coding an app looks a lot like a new vendorGRC engineering as the way to measure control efficiency layer by layer against AI-powered attackersCRA, NIS2, and the EU AI Act landing on citizen developers who never thought of themselves as software manufacturersChapters: 0:00 Intro 0:23 Igor's background from DevOps to CISO 3:54 Scaling security at a 10x company 6:07 Reinventing the team when growth breaks it 08:26 Soft guardrails versus hard blocks 14:05 Tying guardrails to business risk 17:32 Democratized development, undemocratized security 18:52 Shared responsibility on an AI dev platform 21:16 Auto-fix, per-app threat models, and no security tab 25:21 Will models produce secure code by default? 29:56 Every employee vibe coding is a new vendor 30:57 Enterprise controls, publishing gates, and PII scanning 36:39 AI-powered attackers and why good enough changed 40:43 GRC engineering and measuring control efficiency 46:19 CRA, NIS2, and the citizen developer 52:41 Trust centers for builder apps 54:08 Closing thoughts on the vibe coding communityGuest links: Igor on LinkedIn: https://www.linkedin.com/in/igor-andriushchenko Lovable: https://lovable.devResilient Cyber: Newsletter and episode archive: https://www.resilientcyber.io Subscribe for more conversations with security practitioners and leaders.

The New Quantum Era
Quantum Risk, Readiness, and the Enterprise Boardroom with Richard Entrup

The New Quantum Era

Play Episode Listen Later Aug 24, 2026 35:32


Richard Entrup is unusual in quantum circles: he's not a physicist, and he doesn't pretend to be. He spent decades as a CIO, CTO, CDO, and CISO at organizations including Verizon, Christie's, Disney/ABC, Time Warner, and Tiffany & Company before joining KPMG to lead its Emerging Solutions practice. That background — deep operational experience on the client side — shapes everything about how he thinks about quantum. He's not selling a hardware roadmap; he's thinking about what it actually takes to get a large, complex organization to change its cryptographic infrastructure before a threat materializes.The conversation matters now because the signals are accelerating. NIST has finalized its first post-quantum cryptography standards, executive orders in the US are pushing federal agencies toward PQC migration, and the algorithmic efficiency gains that reduce the qubit threshold for breaking RSA-2048 keep coming. Listeners who work in enterprise technology, cybersecurity, or quantum strategy — or who advise organizations that do — will find Entrup's practitioner perspective a useful counterweight to the more hardware-focused conversations that dominate the field.What We Get IntoWhy Q-Day's exact date is the wrong question — and why the more important issue is how long it will take enterprises to even inventory their cryptographic exposure, let alone remediate itThe scale of the cryptographic migration problem, including why a single laptop may contain hundreds of individual cryptographic components and why upstream/downstream API dependencies make this a supply-chain-wide challenge, not just an internal IT projectWhy "harvest now, decrypt later" creates urgency today, regardless of when fault-tolerant quantum computers arrive — and how compliance and regulatory timelines interact with that threat modelWhat crypto agility actually means in practice — moving from a "set it and forget it" cryptographic posture to a dynamic, continuously monitored framework, including the pressure SSL certificate renewal windows are already creatingHow KPMG built its PQC practice, incubated it within the firm, and handed it off to the cybersecurity advisory team as a core service offeringThe "good quantum" side of the ledger — how KPMG's emerging research function is approaching quantum computing as a source of competitive advantage, not just risk, and what sectors are furthest along in exploring itThe AI-quantum convergence, including Entrup's observation that AI is already being used to read and crack code — and what that means for the urgency of cryptographic modernizationWhy the enterprise quantum opportunity still has a long tail, and how the current moment compares to the early infrastructure phase of the internet — when everyone was talking about TCP/IP and DNS, not Uber or NetflixResources & LinksGuest & OrganizationRichard Entrup — Worth Magazine Profile — Career arc from CIO/CISO roles at major global brands to KPMG's Emerging Solutions practiceKPMG Quantum Dawn (2025) — KPMG's enterprise quantum readiness hub, introducing the Q-PREP framework and PQC implementation services, with Entrup as named leadReports & ResearchKPMG — "The Quantum Threat Is No Longer Theoretical" (2026) — The threat brief discussed in this episode, charting the rapid decline in qubits needed to crack RSA-2048 and urging immediate PQC migrationKPMG — "From Theory to Impact: Real-World Results in Quantum Machine Learning" (2026) — KPMG's joint report with IBM and Kipu Quantum on measurable quantum ML results on real hardwareKPMG — "Prepare Now for Quantum Cyber Risk" — Board Leadership Article (2026) — C-suite and board-level guidance on integrating quantum risk into enterprise oversightarXiv — "Quantum-enhanced satellite image classification" (2026) — The underlying research paper behind the KPMG/IBM/Kipu Quantum ML resultsEcosystem & EventsChicago Quantum Exchange — KPMG Joins CQE (October 2024) — Announcement of KPMG's formal CQE membership, referenced in the episode as part of the firm's ecosystem-building strategyKPMG 2026 Quantum Consortium — The inaugural KPMG Quantum Consortium event (March 2026, Orlando) discussed in the episodeIndependent CoverageQuantum Computing Report — KPMG joins Chicago Quantum Exchange (2024) — Independent coverage of KPMG's CQE partnership and enterprise quantum strategyQuantum Zeitgeist — Kipu Quantum satellite imagery coverage (Feb 2026) — Independent analysis of the KPMG/IBM/Kipu hybrid QML resultsKey Quotes & Insights> "It's not if but when. And it could be five years, could be three years, could be ten years. The fact is organizations are not gonna be ready. And that's the scary part." — Richard Entrup on Q-Day> "This is not just the CISO. This is gonna be the software engineering app dev guys. This is gonna be all your partners, upstream and downstream, who have to also be compliant — because if you change your crypto and they don't, that stuff's gonna break." — On why PQC migration is an enterprise-wide, supply-chain-wide problemInsight: Entrup draws a sharp distinction between the "bad quantum" (cryptographic risk requiring urgent defensive action) and the "good quantum" (competitive opportunity with a longer tail) — and argues that most organizations aren't adequately addressing either.Insight: The analogy to the early internet is deliberate: just as the 1990s were consumed with TCP/IP and DNS rather than the applications those protocols would eventually enable, the current quantum moment is still largely an infrastructure conversation — and that's normal, not a sign of failure.> "AI is expediting all of this. If AI is doing one thing, the use case is reading code and cracking it. That's pretty scary." — On the intersection of AI capability and cryptographic vulnerabilityRelated EpisodesEp. 81 — Quantum LDPC Error Correction with Larry Cohen and Paul Webster — Directly relevant: Cohen and Webster discuss how QLDPC error correction reduces the qubit overhead needed for RSA cryptanalysis, the technical underpinning of the threat timeline Entrup describesEp. 38 — Quantum Machine Learning with Jessic...

a16z
Microsoft's Deputy CISO on Securing AI Agents

a16z

Play Episode Listen Later Aug 21, 2026 25:15


a16z's Joel De La Garza is joined by Aaron Zollman, Deputy CISO at Microsoft Gaming, to discuss how security teams can embrace AI agents without losing control. Aaron shares Microsoft's experience with OpenClaw, from the initial instinct to ban it to figuring out how to make it safe to use. They unpack what agents mean for identity, permissions, containerization, and monitoring, as well as how AI is shifting the CISO's role from saying "no" to safely enabling new technology. They also explore whether AI could help defenders patch vulnerabilities as quickly as they're discovered, and why new AI threats don't make the old security problems go away. Stay Updated:Find a16z on YouTube: YouTubeFind a16z on XFind a16z on LinkedInListen to the a16z Show on SpotifyListen to the a16z Show on Apple PodcastsFollow our host: https://twitter.com/eriktorenberg Please note that the content here is for informational purposes only; should NOT be taken as legal, business, tax, or investment advice or be used to evaluate any investment or security; and is not directed at any investors or potential investors in any a16z fund. a16z and its affiliates may maintain investments in the companies discussed. For more details please see a16z.com/disclosures. Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Hacking Your Health
From 420lbs to 214lbs: Building a Body That Could Handle the Mission

Hacking Your Health

Play Episode Listen Later Aug 21, 2026 49:16 Transcription Available


Eric Foster has spent 30+ years in cybersecurity. Three-time CISO, helped build and sell six companies, and now CEO of TENEX.AIHe also used to weigh over 400lbs.In this episode we talk about how he went from 420 lbs to around 214 lbs to building one of the fastest-growing companies in cybersecurity.We get into the shit that actually made the difference: food, training, GLP-1s, travel, stress, identity, confidence and building a system that works even when life is chaotic.Because taking care of your health doesn't have to come at the expense of building something great.If anything, it might be what allows you to.If you want more: https://www.wehackhealth.com/Book a coaching call hereSupport the showWant to know more about coaching? Book a call with Ben hereWhere to find usWe Hack Health: TwitterWe Hack Health: InstagramWe Hack Health: DiscordCheck out Overclock and Protein Protocol here 

Cyber Security Headlines
The Department of Know: Living off Azure, OpenAI's "defender window," and AI-driven PLC attacks

Cyber Security Headlines

Play Episode Listen Later Aug 21, 2026 34:37


Read the full sotry at CISOSeries.com This week's Department of Know is hosted by Rich Stroffolino, with guests Bil Harmer, CISO, Supabase, and David B. Cross, CISO, Atlassian. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. A huge thanks to our sponsor, Vanta   Still stuck on the quarterly audit treadmill? Meet Calm-pliance. Vanta combines compliance, risk, and proof on one Agentic Trust Platform—and continuously monitors your controls, keeping you audit-ready all year round. Find your Calm-pliance here. 

Defense in Depth
Will AI Replace Detection Roles in Cybersecurity?

Defense in Depth

Play Episode Listen Later Aug 20, 2026 35:13


All links and images can be found on CISO Series Check out this post from Caleb Sima of Whiterabbit for the discussion that is the basis of our conversation on this week's episode co-hosted David Spark, the producer of CISO Series, and Yaron Levi, CISO, Dolby. Joining is Adrian Ludwig, CSO, Rippling. In this episode: The messy middle The automatable part Where automation stops The influence gap A huge thanks to our sponsor, ThreatLocker ThreatLocker delivers Zero Trust Network Access and Zero Trust Cloud Access that verifies both user and device before granting access to specific applications. No broad access, nothing exposed, and no reliance on credentials alone. It's a smarter way to control access and reduce risk. Learn more at ThreatLocker.com/CISO.

The Tech Leader's Playbook
How AI Agents Are Forcing a Rethink of Enterprise Identity Security

The Tech Leader's Playbook

Play Episode Listen Later Aug 20, 2026 64:04


In this episode of The Tech Leader's Playbook, Jason Martin shares the founder decisions behind building Permiso, from interviewing 100 enterprise security leaders before writing code to creating a new cybersecurity market before most buyers understood the problem. He breaks down product-market fit, go-to-market challenges, fundraising pressure, co-CEO leadership, startup resilience, and the realities of selling a company. The conversation also explores AI agents, non-human identities, identity security, and the emerging risks executives must prepare for as AI becomes embedded across the enterprise. Essential viewing for founders, CISOs, technology executives, investors, and cybersecurity leaders.What You'll Learn• Why customer behavior matters more than investor enthusiasm or market compliments.• How Permiso identified identity security as a critical cloud security problem before the broader market caught up.• What founders should understand about fundraising, go-to-market execution, and creating a new category.• When being early becomes a competitive advantage versus simply being wrong.• The security risks AI agents and non-human identities create for modern enterprises.Chapters00:00 Building Permiso Security05:58 From Biology to Cybersecurity10:38 Customer Discovery Before Building14:16 Creating a New Market19:42 Surviving Startup Go-to-Market25:10 Fundraising Is a Treadmill29:29 Making Co-CEO Leadership Work38:42 The Okta Acquisition47:47 AI and Identity Security58:47 Lessons for Founders Follow Avetis AntaplyanInstagram:https://www.instagram.com/avetisantaplyanSpotify:https://open.spotify.com/show/0rOkUXDSQb6SVFE6LttWDeApple Podcasts:https://podcasts.apple.com/us/podcast/the-tech-leaders-playbook/id1690263628Follow Jason MartinLinkedIn:https://www.linkedin.com/in/jasonlpmartin/HIRECLOUT:https://www.hireclout.comThe Tech Leader's Playbook:https://www.podcast.hireclout.comLinkedIn:https://www.linkedin.com/in/hirefasthirerightidentity security, AI security, cybersecurity, Jason Martin, Permiso Security, Okta, AI agents, non-human identities, cloud security, enterprise security, cybersecurity startups, artificial intelligence security, identity threat detection, startup founder, technology leadership, CISO, cybersecurity leadership, product market fit, customer discovery, go-to-market strategy, startup fundraising, category creation, startup acquisition, cybersecurity acquisition, co-CEO leadership, enterprise technology, AI workforce, startup resilience, technology executives#BusinessExit #ExitStrategy #BusinessValuation #Entrepreneurship #Leadership #CEO #MergersAndAcquisitions #SPAC #ScalingBusiness #FounderLeadership #PrivateEquity #IntegratedCEO

Best Story Wins
Publishing More Is Making You Less Credible with Ben Hasskamp

Best Story Wins

Play Episode Listen Later Aug 20, 2026 65:29


You've published four posts a week for a year, and your buyers still can't tell anyone what your company believes. Somewhere in all that output there should be one sentence you could be wrong about. There isn't.Ben Hasskamp spent years running thought leadership inside a company where the executive bench included some of the sharpest people in security and watched most of what shipped turn into product brochures wearing a byline. His argument: thought leadership is a point of view you could be wrong about, and everything else is volume cosplaying as authority. He gets specific about the formats that fake it best, including the one your team is probably scoping right now.We also cover:Why every "State of the Industry" report reaches the same conclusion — and the tell that gives it awayThe exact reason polished SEO writing now reads as noise to the models people actually search withHow Ben cut executive review cycles from 14 days to 3 by feeding AI everything an exec had ever said on record and what happened when one of them insisted he'd never say thatThe film-school question that works on a CISO as well as it works on a protagonist

Cyber Security Headlines
OpenAI rewrites safety rules, US charges 17 Iranian hackers, Defender crashes fixed

Cyber Security Headlines

Play Episode Listen Later Aug 20, 2026 6:55


OpenAI rewrites safety rules after threshold warning US charges 17 in Iranian hacking campaign Microsoft fixes Windows Defender crash bug Get the show notes here: https://cisoseries.com/openai-safety-rules-iranian-hackers-defender-crashes/ Huge thanks to our sponsor, Vanta Your GRC team is dealing with more and more frameworks, vendors, and risk. The board wants it all in one place, but your compliance data lives all over. Vanta's agentic trust platform connects compliance, risk, and trust at enterprise scale and delivers a 526% ROI over three years. 16,000+ companies trust Vanta, including Snowflake, Atlassian, and Ramp. Visit Vanta.com/CISO to learn more.

This Week in Startups
Neurosymbolic AI outperforms chatbots and product search | E2327

This Week in Startups

Play Episode Listen Later Aug 19, 2026 54:19


This Week In Startups is made possible by: Vanta https://www.vanta.com/twist Agree https://agree.com YSecurity https://YSecurity.io/TWIST   Today's show: Frontier AI models can ace PhD-level exams, but it's still bad at tracking down the product you want in the style that suits you. Onton's Zach Hudson tell us that the problem is that models are a black box. His solution? A neurosymbolic model, Ontology 1, that learns about your taste and preferred aesthetic over time, then produces product searches tailored specifically to you, rather than just using keywords and relevant tags. How do neurosymbolic models work, and how does Onton understand your prompts and favorite design trends? And why aren't the frontier labs working on neurosymbolic models of their own? Zach joins Jason and Lon to discuss. PLUS, following a record-smashing SpaceX IPO, Ashi Dissanayake of Spacium makes the case that the real bottleneck in space isn't launching rockets off the ground any more. It's refueling in orbit. Guests Zach Hudson on X: ****https://x.com/nosduhz Onton: https://onton.com/ Spacium: https://spaceium.com/ Spacium on X: https://x.com/SpaceiumInc Relevant Links Poolside's journey to AGI: https://poolside.ai/vision/purpose Startup Archive: Sam Altman on the Paul Graham advice that saved OpenAI: https://www.startuparchive.org/p/sam-altman-on-the-paul-graham-advice-that-saved-open-ai-always-make-an-api Kelly Wearstler: https://www.kellywearstler.com/ Ennis House: https://franklloydwright.org/site/ennis-house/ Los Feliz Living: Ennis House profile: https://www.losfelizliving.com/los-feliz-historic-homes/ennis-house-los-feliz-hcm-149 Indiewire: Ennis-inspired "The Studio" offices: https://www.indiewire.com/features/craft/the-studio-production-design-interview-seth-rogen-1235114365/ Monocle Magazine: https://monocle.com/ Spaceium on Y Combinator: https://www.ycombinator.com/companies/spaceium-inc Orbit Fab's RAFTI: https://www.orbitfab.com/rafti/ James Webb Space Telescope: https://science.nasa.gov/mission/webb/ Houzz: https://www.houzz.com/ Timestamps: 0:00 Zach Hudson joins: What is "neurosymbolic search" 4:03 Ontology 1 isn't a black box 6:31 Who is using Onton? 9:36 Vanta - Get $1000 off your SOC 2 at https://www.vanta.com/twist 11:35 Could neurosymbolic models reach AGI? 13:19 Jason loves Wright's Ennis House 17:03 The shape of AI companies is changing 19:28 Agree.com - Stop chasing invoices and automate your entire contract-to-cash stack. Go to https://agree.com and tell them Jason sent you to get 50% off for life! 22:32 UGC as a data moat 26:03 The Dead Internet Theory 28:13 Ashi Dissanayake of Spacium joins 29:52 YSecurity - The on-demand security team for startups. Need enterprise-grade security without hiring a $400k CISO? YSecurity gives you 40+ expert engineers, matched to exactly what you need, by the hour, with your first six hours completely free. Go to https://YSecurity.io/TWIST 31:50 Storables vs. cryogenics: the zero-boil-off breakthrough 34:11 All kinds of propulsion requires refueling 36:09 Getting more value from LEO to GEO 38:28 Moving at rocket speed 44:54 Why demand is so acute 49:37 The investing climate for space, post-SpaceX Subscribe to the TWiST500 newsletter: https://ticker.thisweekinstartups.com Check out the TWIST500: https://www.twist500.com Subscribe to This Week in Startups on Apple: https://rb.gy/v19fcp   Follow Lon: X: https://x.com/lons   Follow Jason: X: https://twitter.com/Jason LinkedIn: https://www.linkedin.com/in/jasoncalacanis   Check out all our partner offers: https://partners.launch.co/   Great TWIST interviews: Will Guidara, Eoghan McCabe, Steve Huffman, Brian Chesky, Bob Moesta, Aaron Levie, Sophia Amoruso, Reid Hoffman, Frank Slootman, Billy McFarland   Check out Jason's suite of newsletters: https://substack.com/@calacanis   Follow TWiST: Twitter: https://twitter.com/TWiStartups YouTube: https://www.youtube.com/thisweekin Instagram: https://www.instagram.com/thisweekinstartups TikTok: https://www.tiktok.com/@thisweekinstartups Substack: https://twistartups.substack.com

The Audit Podcast
IA on AI - Share with your CISO

The Audit Podcast

Play Episode Listen Later Aug 19, 2026 6:32


Links: Visa Releases Its AI-Powered Cyber Defense System to Open Source   Be sure to follow us on our social media accounts on: LinkedIn: https://www.linkedin.com/company/the-audit-podcast Instagram: https://www.instagram.com/theauditpodcast TikTok: https://www.tiktok.com/@theauditpodcast?lang=en   Also be sure to sign up for The Audit Podcast newsletter and to check the full video interview on The Audit Podcast YouTube channel.

Paul's Security Weekly
Preventing a Breakout as AI Agent Threats Is One of Three Top CISO Concerns - Rob Allen - BSW #461

Paul's Security Weekly

Play Episode Listen Later Aug 19, 2026 53:34


Artificial intelligence has quickly evolved from a productivity tool into an active participant in many organizations' daily operations. As organizations give AI greater autonomy within their environment, they're also granting them access to sensitive systems and data. That creates a new challenge for IT and security teams: How do you enable AI to assist productivity without compromising security? Rob Allen, Chief Product Officer at ThreatLocker, joins Business Security Weekly to discuss how zero trust principles can prevent an AI breakout. Rather than relying solely on the AI tool's built-in safeguards, organizations can choose to enforce security policies using ThreatLocker. Rob will discuss how ThreatLocker can enforce AI boundaries through Allowlisting, Ringfencing™, Endpoint Firewall, and Web Content Control, with Community Policies that govern what agentic AI tools can run, do, access, and reach. Segment resources: - https://www.threatlocker.com/blog/the-principle-of-least-privilege-for-ai-agents - https://www.threatlocker.com/blog/applying-threatlocker-to-agentic-ai-tools - https://www.threatlocker.com/blog/why-the-five-eyes-alliance-sees-zero-trust-as-the-best-defense-against-agentic-ai-threats This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! In the leadership and communications segment, 3 cybersecurity issues that should keep every CEO awake at night, You Don't Find Your Leadership Style. You Mentor Your Way Into It., Cybersecurity Starts With Communication – And We May Be Getting It Wrong, and more! Visit https://www.securityweekly.com/bsw for all the latest episodes! Show Notes: https://securityweekly.com/bsw-461

Serious Privacy
Eclipsing Privacy - Smart Glasses and a week in privacy

Serious Privacy

Play Episode Listen Later Aug 19, 2026 36:42 Transcription Available


Send us Fan MailWelcome to the Serious Privacy podcast, where Ralph O'Brien and Dr. K Royal, review the Meta Smart Glasses and privacy issues just before a solar eclipse occurs. We've decided we like the Duck, Duck, Go version. They include a brief week in privacy. If you have comments or questions, find us on LinkedIn and Instagram @seriousprivacy, and on BlueSky under @seriousprivacy.eu, @europaulb.seriousprivacy.eu, @heartofprivacy.bsky.app and @igrobrien.seriousprivacy.eu, and email podcast@seriousprivacy.eu. Rate and Review us!Subscribe today HERE Back the Board Game!  https://www.kickstarter.com/projects/seriousprivacy/serious-privacy-the-data-gamePowered by TrustArcFrom Season 6, our episodes are edited by Fey O'Brien. Our intro and exit music is Channel Intro 24 by Sascha Ende, licensed under CC BY 4.0. with the voiceover by Tim Foley.

Packet Pushers - Full Podcast Feed
HS140: AI and Technical Debt – Boon or Bane?

Packet Pushers - Full Podcast Feed

Play Episode Listen Later Aug 18, 2026 42:27


Does AI increase or reduce technical debt? Join Johna Johnson and John Burke as they discuss how to make strategy in environments in which AI fuels untrammeled growth in enterprise complexity–but also points the way to automated optimization (and concomitant technical debt reduction). Episode Links: Watch this episode on YouTube The AI Technical Debt Crisis:... Read more »

CISO-Security Vendor Relationship Podcast
Secure by Design. Ignored by Default.

CISO-Security Vendor Relationship Podcast

Play Episode Listen Later Aug 18, 2026 37:55


All links and images can be found on CISO Series This week's episode is hosted by David Spark, producer of CISO Series and Andy Ellis, principal of Duha. Joining is Julie Davila, president, Security Tinkerers. In this episode: Two paths, one dead end One size fits nobody Own it or orphan it The agent you should worry about A huge thanks to our sponsor, Guardsquare Guardsquare delivers mobile app security without compromise, providing advanced protections for both Android and iOS apps. From app security testing to code hardening to real-time visibility into the threat landscape, Guardsquare solutions provide enhanced mobile application security from early in the development process through publication. Learn more about how to protect your app at Guardsquare.com/CISO.

Packet Pushers - Fat Pipe
HS140: AI and Technical Debt – Boon or Bane?

Packet Pushers - Fat Pipe

Play Episode Listen Later Aug 18, 2026 42:27


Does AI increase or reduce technical debt? Join Johna Johnson and John Burke as they discuss how to make strategy in environments in which AI fuels untrammeled growth in enterprise complexity–but also points the way to automated optimization (and concomitant technical debt reduction). Episode Links: Watch this episode on YouTube The AI Technical Debt Crisis:... Read more »

Cloud Security Podcast by Google
EP291 Ruthless Prioritization: How CISOs Can Execute a Minimum Viable Security Program

Cloud Security Podcast by Google

Play Episode Listen Later Aug 18, 2026 35:49


Guest: Mike Armistead,  CEO, Pulse Security AI Dan Lamorena, Chief Go-To-Market Officer,  Pulse Security AI Topics:  You've described Pulse as an 'operational management platform for cybersecurity leaders.' What does a security management platform look like in practice?  How does Pulse bridge this 'translation layer' gap? How do you help a CISO transition from presenting patch rates and MTTD to discussing liability exposure and business capital allocation? What actually gets better when someone works with Pulse? Other than, of course, your ARR numbers for your next funding round? What is the single most surprising or alarming disconnect you've identified in your CISO and Board Engagement Survey?  You've introduced the concept of the 'Minimum Viable Security Program (MV(S)P)' and emphasized that 'focus is power.' In an era of non-stop vendor noise, compliance updates, and emerging AI threats, how does Pulse help a CISO ruthlessly prioritize and execute their MV(S)P without getting distracted by the noise? Your company is officially 'Pulse Security AI,' so AI is central to your brand. To put on our healthy skeptic hats: how does Pulse pragmatically leverage AI to solve the CISO's actual day-to-day program management problems, rather than just adding to the marketing noise? Resources: Video EP114 Minimal Viable Secure Product (MVSP) - Is That a Thing? EP208 The Modern CISO: Balancing Risk, Innovation, and Business Strategy (And Where is Cloud?) EP201 Every CTO Should Be a CSTO (Or Else!) - Transformation Lessons from The Hoff EP204 Beyond PCAST: Phil Venables on the Future of Resilience and Leading Indicators "The Bomber Mafia: A Dream, a Temptation, and the Longest Night of the Second World War" by Malcolm Gladwell 

ITSPmagazine | Technology. Cybersecurity. Society
Vulnerability, Visibility, and Velocity Shape the Security Roadmap Now | A Recap at Black Hat USA 2026 with Sean Murphy, Field CISO for North America at F5 | Hosted by Marco Ciappelli

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Aug 17, 2026 7:09


Sean Murphy, Field CISO for North America at F5, spent the week behind the scenes at Black Hat USA 2026, in the corridors and at dinner with the CISOs and cybersecurity minded people who fill the halls. Marco Ciappelli caught him at the close of it and asked what the industry learned this year. The answer arrived as three words. Vulnerabilities, and the flattening of the curve between vulnerability, exposure, and exploit. Visibility, because a team cannot defend what it does not know it has. Velocity, which carries the other two. Sean Murphy calls the acceleration a physics problem rather than a technology problem, given the forces and friction now moving through security work. Moore's law is out the window in his framing, and advancement arrives week by week. For a CISO writing a roadmap and defending an investment case for the next six to 18 months, the plan keeps pivoting underneath them. AI shifted just as fast. What was recently understood as hyperscaler sized, built for the largest organizations, is now generative and agentic AI running at the enterprise level, in production rather than in a pilot. That leaves a population question. Agents are identities, non-human identities with permissions and responsibilities, and Sean Murphy points out they are proliferating alongside the human identities already under governance. He also offers a reframe on agents that slip past misconfigured guardrails and go crawling for LLMs and repositories. That is an agent doing exactly what it was told to do, relentlessly, until it succeeds. The work ahead is guardrails and governance over all of that visibility. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Sean Murphy, Field CISO for North America at F5 On LinkedIn: https://www.linkedin.com/in/seanmurphy092009/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Learn more about F5: https://www.f5.com Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS Sean Murphy, F5, Marco Ciappelli, brand briefing, brand story, brand marketing, marketing podcast, Black Hat USA 2026, field CISO, agentic AI, non-human identity, AI governance, guardrails, vulnerability management, security visibility, security roadmap, identity and access management, enterprise AI adoption Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

ITSPmagazine | Technology. Cybersecurity. Society
Detection at AI Speed, Prioritization by Workflow, and Autonomous Elimination | A Recap at Black Hat USA 2026 with May Mitchell, Chief Marketing Officer at Qualys | Hosted by Marco Ciappelli

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Aug 17, 2026 4:41


Qualys returns to Black Hat USA 2026 with an AI Risk Operations Center built around three principles customers have been asking for over the last three years. May Mitchell, Chief Marketing Officer at Qualys, walks through them in order. Detect vulnerabilities at AI speed. Prioritize what surfaces, because not every finding calls for action in the same hour and the sequence follows the workflows a team already runs. Eliminate it through autonomous remediation, then confirm the fix worked. Mitchell also notes that Qualys has been a Black Hat sponsor for over 23 years. What are security teams asking for at AI speed? They want detection to keep pace with disclosure. Mitchell points to InstaScan, the innovation Qualys launched during Black Hat week, which provides continuous scanning and detection. The meetings on the floor have been with customers from across the regions, not only the US. How has the AI conversation shifted since RSAC Conference? It has narrowed to implementation. Mitchell says the messaging moved from AI to agents to autonomous, and that this year the questions are targeted. How do I implement it. How do I get it into the workflows. How do I have governance. The economics of AI sits alongside those questions, with more asked about ROI, since budgets are not rising across the board. That pushes organizations to evaluate their technology stack, consolidate, and look for a single platform that gives complete visibility and gives security leaders something they can take to a board or a CFO. Customization depends on the size of the organization, and larger heterogeneous environments are where Qualys partners come in with risk assessment services, planning, integration, and ongoing management. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST May Mitchell, Chief Marketing Officer at Qualys On LinkedIn: https://www.linkedin.com/in/maymitchell/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Qualys: https://www.qualys.com/ InstaScan announcement: https://www.qualys.com/company/newsroom/news-releases/usa/qualys-launches-instascan-to-detect-vulnerabilities-within-minutes-of-disclosure Agent Insta and scanless detection: https://blog.qualys.com/product-tech/2026/08/03/instascan-agent-insta-scanless-detection ROCon Americas 2026 in Austin: https://www.qualys.com/rocon/2026/americas Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS May Mitchell, Qualys, Marco Ciappelli, brand briefing, brand story, brand marketing, marketing podcast, Black Hat USA 2026, risk operations center, InstaScan, AI speed detection, autonomous remediation, vulnerability management, prioritization, security governance, economics of AI, platform consolidation, cyber risk management, CISO, ROCon Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

The Tech Blog Writer Podcast
Building Evidence Based Trust for AI Agents With Vijil

The Tech Blog Writer Podcast

Play Episode Listen Later Aug 16, 2026 36:29


What evidence would convince you that an AI agent is ready to make decisions involving employment, money, healthcare, or legal rights? In this episode of Tech Talks Daily, I speak with Vin Sharma, founder and CEO of Vijil, about the trust gap preventing many enterprise AI agents from progressing beyond proof of concept. Vin has spent approximately 30 years building software across security, operating systems, open source, cloud computing, machine learning, and AI. His previous work includes leading engineering at Amazon SageMaker and helping develop 11 AWS AI services. He argues that AI agents differ from conventional software because they combine autonomy with agency. They can interpret an objective, make decisions under ambiguous conditions, and take action. This raises a deeper question than whether an agent can complete a demonstration successfully: will it remain loyal to the interests of the person or business delegating the task? Trust is also specific to the job. Vin uses a simple analogy. You may trust a gardener to care for your lawn, but that does not automatically make the same person suitable to babysit your child. An AI agent must therefore be evaluated within the context of its users, task, operating conditions, authority, and potential consequences. Vin proposes testing three areas. Reliability asks whether the agent can perform its assigned task. Security examines whether it maintains its integrity when facing hostile or noisy conditions. Safety considers what happens when the agent fails and whether the resulting damage remains contained. This evaluation cannot end when the agent enters production. Models, integrations, data, users, and external conditions change. An agent may drift away from its original purpose, which means businesses need continuous monitoring, testing, and updating across the full AI agent lifecycle. We discuss how established security practices can be applied to this problem. Trusted execution environments, containment, least privilege, limited-duration access, and bounded models can reduce exposure. Smaller language models may also be better suited to narrow, high-risk tasks than a general model with broad permissions. Vin offers a three-part framework for governance: personas, purpose, and policy. Personas describe the people and attackers who may interact with the agent. Purpose defines the legitimate task. Policy sets the boundaries between permitted and prohibited behavior. For high-risk systems, his recommended starting position is that any action not explicitly permitted should be prohibited. A natural-language policy can then be converted into deterministic rules and controls governing the agent's behavior. Vin's most direct advice concerns evidence. Vibes, demonstrations, and benchmark scores do not prove that an agent is safe for a particular business process. A CISO should expect a complete risk assessment, while a business owner should receive proof that the agent will serve the organization's interests. His bridge analogy captures the issue perfectly. Engineers do not claim a bridge is safe because it looks impressive during a demonstration. They calculate load, tolerance, failure conditions, and provide test evidence. AI agents acting in consequential workflows deserve a comparable engineering discipline. If an agent developer asked you to trust their system today, would they be able to provide evidence of reliability, security, safety, loyalty, and contained failure? Listen to the episode and share your thoughts with me.

This Week in Startups
Zuck's AI manifesto is a data center PR masterclass | E2323

This Week in Startups

Play Episode Listen Later Aug 11, 2026 80:18


This Week In Startups is made possible by: Every.io https://every.io NetSuite https://NetSuite.ai/TWIST YSecurity https://YSecurity.io/TWIST Today's show: *Meta chief Mark Zuckerberg published a 6,500 word essay about the future of AI, and Jason thinks it's his smartest PR move in years. The thinkpiece, "The Future is for Everyone: The Path to a Positive AI Future," arrives alongside a new open-weight Meta model — Muse Glimmer — and the promise of an open-weight version of Muse Spark 1.2 to come. Zuckerberg's clearly pitching an "abundance" narrative, promising the American public untold benefits from AI technology — everything from a PhD-level tutor for every student to scientific breakthroughs, personal assistants, and beyond — all for the low low cost of not banning new data centers. Do our hosts think everyday voters will take this deal? PLUS X retires its revenue sharing program, the CLARITY Act misses a key pre-recess vote, what can we do to stop widespread AI-powered community college cheating, and some of the podcasting positions for which LAUNCH is hiring. Relevant Links Meta: "The Future is for Everyone": https://about.fb.com/news/2026/08/the-future-is-for-everyone/ Meta: "Introducing Muse Glimmer": https://research.meta.ai/blog/introducing-muse-glimmer-open-agentic-model MS Now: "Kevin O'Leary wants to atone for his data center sins": https://www.ms.now/news/kevin-oleary-wants-to-atone-for-his-data-center-sins "The Social Reckoning" teaser: https://www.youtube.com/watch?v=gM4LkaXwGuY X: Original Content Rewards Program: https://help.x.com/en/using-x/original-content-rewards TechCrunch: Nikita Bier steps down as X's head of product: https://techcrunch.com/2026/08/05/nikita-bier-steps-down-as-xs-head-of-product/ Congress.gov: H.R. 3633 - Digital Asset Market Clarity Act: https://www.congress.gov/bill/119th-congress/house-bill/3633/text Politico: "Crypto faces a setback in the Senate": https://www.politico.com/news/2026/08/07/delays-imperil-senate-crypto-bill-01029817 NYT: "AI Agents are Taking Entire Online Courses for Cheating Students": https://www.nytimes.com/2026/08/10/us/ai-cheating-online-degrees.html Inside Higher Ed: "Brown Professor Suspects Majority of His Class Used AI to Cheat": https://www.insidehighered.com/news/faculty/learning-assessment/2026/07/08/brown-professor-suspects-most-his-class-used-ai-cheat Podnews: Spotify's Skip Ahead ad skip test: https://podnews.net/article/spotify-threat-ad-skipping Tommy Vietor X post on Spotify: https://x.com/TVietor08/status/2085073214968037428?s=20 JJ Smith SF "open drug market" video: https://x.com/war24182236/status/2086839186137710724 Timestamps: 0:00 Why Zuck thinks the future is open source 2:26 Meta's roadmap: personal assistants and beyond 9:21 Every.io - For all of your incorporation, banking, payroll, benefits, accounting, taxes or other back-office administration needs, visit https://every.io 20:22 Netsuite - For the first time ever, you can try NetSuite Next for free. If your revenues are at least in the seven figures, go to https://NetSuite.ai/TWIST 27:43 How to win the data center argument 29:32 YSecurity - The on-demand security team for startups. Need enterprise-grade security without hiring a $400k CISO? YSecurity gives you 40+ expert engineers, matched to exactly what you need, by the hour, with your first six hours completely free. Go to https://YSecurity.io/TWIST 39:24 X intros Original Content Rewards 51:58 The CLARITY Act faces new setbacks 1:00:46 AI agents are taking students' tests for them 1:09:37 LAUNCH is hiring!   Subscribe to the TWiST500 newsletter: https://ticker.thisweekinstartups.com Check out the TWIST500: https://www.twist500.com Subscribe to This Week in Startups on Apple: https://rb.gy/v19fcp   Follow Lon: X: https://x.com/lons   Follow Jason: X: https://twitter.com/Jason LinkedIn: https://www.linkedin.com/in/jasoncalacanis   Check out all our partner offers: https://partners.launch.co/   Great TWIST interviews: Will Guidara, Eoghan McCabe, Steve Huffman, Brian Chesky, Bob Moesta, Aaron Levie, Sophia Amoruso, Reid Hoffman, Frank Slootman, Billy McFarland   Check out Jason's suite of newsletters: https://substack.com/@calacanis   Follow TWiST: Twitter: https://twitter.com/TWiStartups YouTube: https://www.youtube.com/thisweekin Instagram: https://www.instagram.com/thisweekinstartups TikTok: https://www.tiktok.com/@thisweekinstartups Substack: https://twistartups.substack.com