Podcasts about ciso

  • 1,441PODCASTS
  • 12,327EPISODES
  • 36mAVG DURATION
  • 2DAILY NEW EPISODES
  • Jul 28, 2026LATEST

POPULARITY

20192020202120222023202420252026

Categories




Best podcasts about ciso

Show all podcasts related to ciso

Latest podcast episodes about ciso

CISO-Security Vendor Relationship Podcast
Why Don't You Tell Me Which Metrics Sound Most Impressive?

CISO-Security Vendor Relationship Podcast

Play Episode Listen Later Jul 28, 2026 48:02


All links and images can be found on CISO Series This week's episode is hosted by me, David Spark, producer of CISO Series and Andy Ellis, principal of Duha. Joining is Pavi Ramamurthy, Global CISO and CIO, Blackhawk Network. In this episode: Numbers that make the board feel good and nothing else The audit is not the same thing as the truth Receipts aren't a strategy Stop blaming the human, fix the system they're standing in A huge thanks to our sponsor, ThreatLocker ThreatLocker delivers Zero Trust Network Access and Zero Trust Cloud Access that verifies both user and device before granting access to specific applications. No broad access, nothing exposed, and no reliance on credentials alone. It's a smarter way to control access and reduce risk. Learn more at ThreatLocker.com/CISO.  

sound numbers metrics cio impressive receipts ciso duha andy ellis global ciso threatlocker david spark zero trust network access blackhawk network ciso series
Packet Pushers - Full Podcast Feed
HS138: When “One Cloud To Rule Them All” Is NOT the Answer: Repatriation for AI and more

Packet Pushers - Full Podcast Feed

Play Episode Listen Later Jul 21, 2026 30:56


Some enterprises are finding reasons to pull back from a cloud-first IT strategy and run workloads in on-premises data centers. John and Johna dig into why companies are making the change, including cost and AI security. They also discuss and the strategic implications for IT, and what organizations stand to gain—and lose—from repatriation.  Episode Links:... Read more »

This Week in Startups
An AI that watches your every click may be the future of work | E2314

This Week in Startups

Play Episode Listen Later Jul 20, 2026 42:01


This Week In Startups is made possible by: Vanta https://www.vanta.com/twist Superhuman https://superhuman.com YSecurity https://YSecurity.io/TWIST Today's show: *Cybersecurity has long focused on cleaning up a system AFTER a breach but Ent founder Brandon Dixon says that's backwards. He just raised a $100M seed round to put an AI agent on everyone's company laptops that catches the risky clicks, leaked files, or rogue agents BEFORE they wreck havoc. PLUS Clawra creator David Im return swith his new project, Sume's Avatar, a multi-model orchestration layer that generates 60-second UGC videos from a single prompt… and gets it right on the first try, rather than falling back on trial and error. Guests: Brandon Dixon on LinkedIn: https://www.linkedin.com/in/brandonsdixon/ Ent: ****https://ent.ai/ David Im on X: https://x.com/davidim Sume: https://www.sume.com/ Relevant Links: WSJ: "Cyber Security Startup Ent Raises $100 Million in Seed Funding": https://www.wsj.com/pro/cybersecurity/cyber-startup-ent-raises-100-million-in-seed-funding-a3e9b6c6 Microsoft Security Copilot: https://www.microsoft.com/en-us/security/business/ai-machine-learning/microsoft-security-copilot Engadget: "Meta 'pausing' employee tracking program…": https://www.engadget.com/2199458/meta-is-pausing-employee-tracking-program-after-it-let-the-whole-company-see-sensitive-data/ Seedance 2.0: https://seedance2.ai/ Timestamps: 0:00 Intro: Why AI + cybersecurity is the hot combo right now 2:29 How INT stops breaches before they happen 4:56 AI is giving non-technical employees dangerous new powers 10:26 Vanta - Compliance and security shouldn't be a deal-breaker for startups to win new business. Vanta makes it easy for companies to get a SOC 2 report fast. Get $1,000 off for a limited time at https://www.vanta.com/twist 13:54 Why on-device AI beats cloud-based security 20:08 Superhuman - Get AI that works where you work. Unlock your Superhuman potential at https://superhuman.com 25:18 INT's business model and go-to-market 30:26 YSecurity - The on-demand security team for startups. Need enterprise-grade security without hiring a $400k CISO? YSecurity gives you 40+ expert engineers, matched to exactly what you need, by the hour, with your first six hours completely free. Go to https://YSecurity.io/TWIST 34:18 David M. of Sumi Labs: one-shotting AI video 36:10 Live demo: Sumi's video orchestration API 40:05 Consistent faces, 60-second videos, and who's buying Subscribe to the TWiST500 newsletter: https://ticker.thisweekinstartups.com Check out the TWIST500: https://www.twist500.com Subscribe to This Week in Startups on Apple: https://rb.gy/v19fcp   Follow Lon: X: https://x.com/lons   Follow Alex: X: https://x.com/alex LinkedIn: ⁠https://www.linkedin.com/in/alexwilhelm   Follow Jason: X: https://twitter.com/Jason LinkedIn: https://www.linkedin.com/in/jasoncalacanis   Check out all our partner offers: https://partners.launch.co/   Great TWIST interviews: Will Guidara, Eoghan McCabe, Steve Huffman, Brian Chesky, Bob Moesta, Aaron Levie, Sophia Amoruso, Reid Hoffman, Frank Slootman, Billy McFarland   Check out Jason's suite of newsletters: https://substack.com/@calacanis   Follow TWiST: Twitter: https://twitter.com/TWiStartups YouTube: https://www.youtube.com/thisweekin Instagram: https://www.instagram.com/thisweekinstartups TikTok: https://www.tiktok.com/@thisweekinstartups Substack: https://twistartups.substack.com

Talking Cloud with an emphasis on Cloud Security
110-Talking Innovation with Dr. Atif Farid Mohammad PhD, Chief AI Office/CISO at Cyquent, Inc.

Talking Cloud with an emphasis on Cloud Security

Play Episode Listen Later Jul 19, 2026 58:47


Unlock the future where quantum computing, AI, and human intelligence collide—discover why the critical skill of emotional quotient (EQ) may soon trump IQ in this fast-evolving landscape. In this captivating episode, Dr. Atif Farid Mohammed, chief AI officer at CyQuint and author of Least Intelligence, takes us on a journey through the depths of quantum physics, AI's limitations, and the profound impact of energy and consciousness on our existence. You'll discover how quantum mechanics reshapes our understanding of reality, the true potential of large language models versus sentient AI, and why learning — in all its forms — remains the ultimate driver of human evolution. We break down complex concepts like decoherence, space folding, and the nature of energy, translating these into practical insights for navigating tomorrow's technological challenges. If you're curious about the mysteries of the universe, the future of AI, or how to harness emotional intelligence in an AI-driven world, this episode is essential listening. Dr. Mohammed's expertise in quantum computing, cybersecurity, and AI ethics provides a rare perspective on the forces shaping our future. Whether you're a tech enthusiast, a futurist, or simply intrigued by the big questions of existence, this episode will leave you inspired and enlightened. Get ready to rethink what you thought you knew about intelligence, consciousness, and the endless possibilities of the quantum era. Tap in now - your leap into the future starts here. I hope you enjoy it!

Hashtag Trending
Special Interview With Lionel Liddy, CISO at Menlo Security

Hashtag Trending

Play Episode Listen Later Jul 18, 2026 33:43


Browser Security in the Age of Agentic AI: Containment, Isolation, and the New CISO Reality Host Jim Love introduces a #TrendingOnTheWeekend episode featuring David Shipley (Cyber Security Today, Beauceron Security) interviewing Lionel Liddy, CISO at Menlo Security, about AI-driven vulnerability discovery and why reactive security is failing as exploitation accelerates. Liddy shares his path from a University of Toronto PhD researching virtual machines to building Menlo's browser-security approach: an isolated remote "cloud browser" that prevents active web content from executing on endpoints and can also shield servers by forcing interactions through a controlled browser. They discuss CISOs struggling to keep up with rapid shifts, agentic AI risks in browsers and extensions, limits of LLM guardrails (including NIST's proof-like framing), and the compounding impact of pervasive bugs and technical debt. The episode closes with where to learn more at Menlo Security. 00:00 OpenClaw Policy Panic 00:19 Weekend Show Setup 00:57 Interview Preview 02:06 Lionel Origin Story 05:02 Menlo Browser Isolation 06:58 AI Speeds Up Exploits 10:33 CISO Whiplash Era 12:18 Agents In The Browser 16:17 Guardrails Limits Proof 19:58 Mythos And New Normal 23:36 Hazmat Suit For Servers 28:24 Collision Weekend Scenario 32:02 Wrap Up And Links 33:11 Show Closing Notes

Interviews: Tech and Business
Palo Alto Networks EVP: Securing AI Agents in the Enterprise

Interviews: Tech and Business

Play Episode Listen Later Jul 17, 2026 22:14


Enterprises are running more AI agents than their security teams realize, and attackers only need to be right once. Anand Oswal, EVP of Network Security at Palo Alto Networks, explains how to secure agents across four surfaces: enterprise, SaaS, endpoints, and the browser. With host Michael Krigsman, he covers shadow agent discovery, MCP and browser risks, prompt injection, agent identity, and why a unified platform beats a stack of point products.YOU'LL DISCOVER✅ The four agent surfaces every CISO must secure at once: enterprise, SaaS, endpoints, and the browser✅ Why discovery comes first: you cannot secure agents, models, tools, and plugins you cannot see✅ The Palo Alto Networks finding that one third of public MCP servers carry takeover level vulnerabilities✅ How vibe coding agents demand privileged access to local files, terminals, and cloud credentials✅ How browser agents inherit your session and cookies and can perform identity impersonation✅ Runtime threats to know: prompt injection, memory poisoning, tool misuse, and model DoS✅ How MCP and A2A protocols expand the attack surface, and why a centralized AI gateway anchors identity, runtime, and observability controls✅ The case for zero trust, an AI-driven SOC, and one unified platform over point products, and where Prisma AI fits⏱️ TIMESTAMPS0:00 Introduction0:22 Agent memory poisoning and tool misuse0:59 Discovering shadow agents across four surfaces2:32 Vibe coding agents and MCP risk4:46 Browser agents and session misuse6:20 Runtime threats and prompt injection7:17 Agent-to-agent protocols and attack surface8:04 Agent identity and the control plane9:16 Centralizing control at the AI gateway10:23 Zero trust and an AI-driven SOC11:29 One platform, not point productsSubscribe for weekly conversations with the business and technology leaders shaping the enterprise. Get the CXOTalk newsletter: https://newsletter.cxotalk.com Show notes, transcript, and summary: https://www.cxotalk.com/episode/palo-alto-networks-evp-securing-ai-agents-in-the-enterpriseEpisode 924#CXOTalk #EnterpriseAI #CIO #AIGovernance #AgenticAI #IBM #DigitalTransformation #AIStrategy #AILeadership

Cyber Security Headlines
The Department of Know: CMMC suspended, ShareFile shutdown, Context Bombing strikes back

Cyber Security Headlines

Play Episode Listen Later Jul 17, 2026 42:58


"Context Bombing" flips the script on prompt injections Pentagon suspends CMMC Phase II requirements Old tech, new problems Get the show notes here: https://cisoseries.com/the-department-of-know-cmmc-suspended-sharefile-shutdown-context-bombing-strikes-back/  This week's Department of Know is hosted by Rich Stroffolino, with guests Tom Hollingsworth, networking technology advisor, Futurum Group, and Mark Eggleston, former CISO, CSC. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines.  Because security works best when innovation and control move together.

RSA Conference
Preparing for Quantum: A CISO's Roadmap to Resilience

RSA Conference

Play Episode Listen Later Jul 16, 2026 32:28


Quantum computing is no longer a distant threat. It is now a present-day concern for security leaders who must protect data that could be harvested today and decrypted tomorrow. In this episode, Noopur Davis, Chief Information Security and Product Privacy Officer at Comcast, cuts through the hype to explain what quantum resilience really means for enterprise security programs. She shares a practical roadmap for getting started now and tackles the harder organizational challenges: making the business case to executive leadership and helping teams develop the skills they'll need for this shift. Whether your organization is just beginning to think about quantum readiness or looking to accelerate progress, this episode offers clear, actionable guidance on where to start.

Serious Privacy
A week in privacy, but we're really talking US Supreme Court

Serious Privacy

Play Episode Listen Later Jul 15, 2026 36:09 Transcription Available


Send us Fan MailWelcome to the Serious Privacy podcast, where Paul Breitbarth, Ralph O'Brien, and Dr. K Royal, discuss a week in privacy. Let's be honest though - it's really the US Supreme Court reent decisions in Slaughter and Chatrie. Tune in for a lievely discussion. Oh - and we're also on YouTube https://www.youtube.com/@seriousprivacypodcastChatrie v. United States (25-112): Police officers conducted a Fourth Amendment search when they acquired Okello Chatrie's location data from Google because an individual has a reasonable expectation of privacy in his cell-phone location information. Trump v. Slaughter (25-332): The Federal Trade Commission's for-cause removal provision, 15 U. S. C. §41, is contrary to the separation of powers enshrined in the Constitution. If you have comments or questions, find us on LinkedIn and Instagram @seriousprivacy, and on BlueSky under @seriousprivacy.eu, @europaulb.seriousprivacy.eu, @heartofprivacy.bsky.app and @igrobrien.seriousprivacy.eu, and email podcast@seriousprivacy.eu. Rate and Review us! From Season 6, our episodes are edited by Fey O'Brien. Our intro and exit music is Channel Intro 24 by Sascha Ende, licensed under CC BY 4.0. with the voiceover by Tim Foley.

Reimagining Cyber
The Ransomware Negotiator Who Worked for the Hackers - #210

Reimagining Cyber

Play Episode Listen Later Jul 15, 2026 21:52


What happens when a trusted ransomware negotiator secretly works for the very hackers he's supposed to stop?In this episode of Reimagining Cyber, Tyler Moffitt unpacks one of the most shocking insider threat cases in recent cybersecurity history. A ransomware negotiator admitted to providing confidential victim information—including insurance limits and negotiation strategies—to the BlackCat (ALPHV) ransomware gang while representing organizations during active ransomware attacks.Learn how ransomware negotiations really work, why information is the most valuable asset during a cyber incident, and what this case reveals about ransomware-as-a-service, cyber insurance, incident response, and insider threats. Whether you're a CISO, security leader, IT professional, or simply interested in cybersecurity, this episode offers practical lessons on trust, risk, and protecting sensitive information when every decision matters.As featured on Million Podcasts' Best 100 Cybersecurity Podcasts  Top 50 Chief Information Security Officer CISO Podcasts Top 70 Security Hacking PodcastsThis list is the most comprehensive ranking of Cyber Security Podcasts online and we are honoured to feature amongst the best!Follow or subscribe to the show on your preferred podcast platform.Share the show with others in the cybersecurity world.Get in touch via reimaginingcyber@gmail.com

CISO-Security Vendor Relationship Podcast
The Only Thing Worse Than Technical Debt is Newly Discovered Technical Debt

CISO-Security Vendor Relationship Podcast

Play Episode Listen Later Jul 14, 2026 43:57


All links and images can be found on CISO Series This week's episode is hosted by David Spark, producer of CISO Series, and Andy Ellis, principal of Duha. Joining them is Tim Callahan, CIO/CISO, AFLAC. In this episode: Week one is the wrong time to overreach Nobody has the AI playbook Vulnerability management wasn't built for this clock Stop blaming the human, fix the system A huge thanks to our sponsor, Vanta No, it's not your imagination. Risk and regulations ARE ramping up—and customers now expect proof of security just to do business. That's why Vanta is a game-changer. Vanta automates your compliance process and brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Companies like Ramp and Writer spend 82% less time on audits with Vanta. That's not just faster compliance—it's more time for growth. Get started at Vanta.com/CISO.  

Cyber Risk Management Podcast
EP 214: AI Agents Don't Behave Like Humans

Cyber Risk Management Podcast

Play Episode Listen Later Jul 14, 2026 39:44


Your cybersecurity tools were built for people: a login, a single sign-on, an email address. But the AI agents now showing up inside your company don't work that way, and most of them slip right past your controls. So how do you find the "Shadow AI" already running in your business, and get a handle on it? Let's find out with our guest Nancy Wang, Chief Technology Officer at 1Password, who works at the front edge of how machines get access to systems. Your hosts are Kip Boyle, CISO with Cyber Risk Opportunities, and Jake Bernstein, Partner with K&L Gates.   LinkedIn profile profile: https://www.linkedin.com/in/wangnancy/   1Password: https://1password.com/

ai partner humans chief technology officer behave ciso 1password l gates jake bernstein kip boyle cyber risk opportunities
Cyber Security Today
AI Export Controls, FortiBleed, Third-Party Breaches & CISO Burnout | Cybersecurity Today Panel

Cyber Security Today

Play Episode Listen Later Jul 11, 2026 61:54


Can governments decide who gets access to advanced AI models? Are third-party breaches becoming impossible to control? And why are so many CISOs reaching burnout? In this special Cybersecurity Today Month in Review Panel, host Jim Love is joined by cybersecurity experts Laura Payne, David Shipley, and Mike Kim (Mycroft) to examine the biggest cybersecurity stories and trends from June 2026. The panel explores the controversy over U.S. export controls on Anthropic's Mythos and Fable AI models, what they reveal about digital sovereignty, and whether governments should be able to restrict access to frontier AI. They also discuss the continuing wave of third-party breaches, including Salesforce ecosystem compromises and the Clue breach, and why organizations must move beyond compliance toward practical risk management. The conversation examines FortiBleed, exposed administrator portals, credential reuse, and the difficult balance between software flaws, operational mistakes, and secure-by-default design. The panel also tackles one of cybersecurity's biggest human challenges: CISO burnout, executive accountability, organizational culture, and what separates successful security leaders from those set up to fail. The episode concludes with encouraging developments in international cybercrime enforcement, including Operation Riptide, and why better intelligence sharing and improved operational security are making it harder for cybercriminals to hide. Whether you're a CISO, security practitioner, IT leader, or simply interested in the rapidly changing cybersecurity landscape, this discussion offers practical insight into the trends shaping the industry. Panel Jim Love (Host) Laura Payne David Shipley Mike Kim (Mycroft) Topics covered AI export controls and digital sovereignty Anthropic Mythos and Fable Third-party and supply chain risk Salesforce ecosystem security FortiBleed and Fortinet security Secure-by-default strategies CISO burnout and executive accountability Operation Riptide Cybercrime investigations Security leadership and governance Chapters 00:00 Sponsor NordLayer 00:38 Meet the Panel 02:40 Author Scam Warning 04:51 Emotion Is the Target 08:47 AI Model Export Controls 10:01 Hype vs Real AI Security 15:01 Sovereignty and Dependency 20:35 Governments Push Back 24:14 AI Internal Voice Risks 26:12 Third Party Breach Fatigue 30:05 Compliance Limits on Risk 32:15 Blame Game to Risk Focus 33:18 Standards and Priorities 33:39 When Security Vendors Fail 34:35 FortiBleed Numbers Explained 35:44 Process Failures vs Bugs 37:32 Why Fortinet Gets Heat 39:05 Secure by Default Basics 41:04 Budget Reality and Culture 44:36 CISO Burnout and AI Pressure 46:16 Liability and Shared Ownership 50:12 What Great CISOs Do 53:07 Operation Riptide Wins 56:10 Deterrence and Due Process 58:14 Sharing Intel for ROI 59:09 Hopium and Wrap Up 01:00:46 Sponsor NordLayer Message

Resilient Cyber
Building an AI AppSec Engineer

Resilient Cyber

Play Episode Listen Later Jul 11, 2026 31:04


JJ of Gecko Security and former Disney and Costco CISO Ryan Knisley on why AppSec needs an AI security engineer, not another scanner.DescriptionAppSec has been stuck for years, drowning teams in noisy findings that never told them what was actually exploitable. JJ, co-founder and CEO of Gecko Security, and Ryan Knisley, former CISO at Disney and Costco, join Resilient Cyber to talk about what changes when an AI security engineer reasons across code, infrastructure, and design docs at once. We get into why business logic breaks traditional SAST, why attackers think in graphs while defenders think in lists, why MTTR is a broken metric, how Cal.com went closed source in the AI era, and where AI-driven AppSec consolidation lands over the next two years.Key takeawaysGecko is an AI security engineer, not another scanner. It reasons across code, infrastructure, and documentation, so a finding arrives already mapped to whether it is reachable in production and what data it touches.The context that tells you if a bug matters lives outside the code. Business logic, architecture, and runtime are where exploitability is decided, which is why scanning the code alone floods teams with noise.Business logic is why traditional SAST fails, and why an LLM alone will not fix it. The same endpoint with no auth check is a critical bug in a document store and expected behavior in a social app, and only design docs and architecture tell the two apart.Attackers think in graphs while defenders think in lists. A critical with a compensating control may not matter, while ten lows chained together can be the thing that actually reaches the asset you care about.Exploit development is being commoditized. JJ describes a near future where the whole internet becomes one big bug bounty scope with agents running campaign-level attacks, so the old severity-ranking lens no longer holds.Fix the class, not the ticket. Rather than patching bugs one by one, Gecko traces groups of findings back to the design decision that created them and eliminates every variant so the same issue never returns.MTTR is a broken metric. A variant of last week's bug returns with a fresh clock, so teams close tickets to look healthy while risk stays flat, which is why Gecko measures recurrence rate instead.Cal.com shows where open source is heading. After AI coding pushed its pull requests from about 30 a day to 100 with a one-person security team, being open source flipped from an advantage to a liability, so it went closed source and replaced four tools with one.Tool consolidation is a risk decision, not a cost exercise. Ryan's shiny object problem leaves teams stacking scanners nobody can fully staff, and collapsing the stack lets you cross-train people and reduce real complexity.The finding layer collapses, and human judgment moves up. When finding and fixing get cheap, the scarce work becomes deciding what is correct, whether to accept a risk on purpose, and owning the design decision for a whole class of bugs.Chapters00:00 Meet JJ and Ryan02:46 Why Gecko is an AI security engineer, not another scanner05:07 The trend of agentic and headless security tools05:53 Why business logic breaks traditional SAST06:27 The no-auth endpoint example and context outside the code09:06 Attackers think in graphs, defenders think in lists11:02 Commoditized exploit dev and the internet as one bug bounty13:55 Shift left and why MTTR is a broken metric15:07 Eliminating entire classes of vulnerabilities15:51 Recurrence rate and avoiding risky refactors18:22 The Cal.com case study and open source going closed20:48 Consolidation and the shiny object problem in security22:40 Where AI-driven AppSec lands in two years27:12 What it takes to trust an AI security engineer28:57 Where to find Gecko and the Black Hat talk

This Week in Startups
Danny Bernstein left Big Tech to fund farm-bots | E2310

This Week in Startups

Play Episode Listen Later Jul 10, 2026 60:54


This Week In Startups is made possible by: NetSuite https://NetSuite.ai/TWIST Squarespace https://squarespace.com/twist YSecurity https://YSecurity.io/TWIST Today's show: *America posted 400,000 farm jobs last year, and fewer than 1% got a single domestic applicant. Danny Bernstein of Reservoir believes it's time to start automating this backbreaking labor, like picking stone fruit in 110°F temperatures. So he built the world's first on-farm robotics incubator on 40 acres of California farmland. Here's why he argues that automating farms isn't just a new opportunity, it's a national security issue. PLUS Jason responded to Gal Shir's viral "AI beat me at design" tweet, got into a kerfuffle with Figma CEO Dylan Field, and wound up making a brand new J-Trade. AND we're talking about the Dept. of Education's new "do no harm" policy, the Brown University AI cheating chart that's blowing up social media, and Lon has fresh streaming recommendations in an all-new Off Duty. Guest: Danny Bernstein on X: https://x.com/bernsteind Reservoir Farms: https://reservoir.co/ Reservoir VC: https://reservoir.vc/ Relevant Links: Bonsai Robotics: https://bonsairobotics.ai/ Root AI acquired by AppHarvest: https://www.therobotreport.com/root-ai-acquired-by-appharvest-for-60m/ John Deere: https://www.deere.com/en-us/ Western Growers Association: https://www.wga.com/ Tanimura & Antle: https://www.taproduce.com/ Naturipe Berry Growers: https://www.naturipefarms.com/ Driscoll's: https://www.driscolls.com/ Taylor Farms: https://www.taylorfarms.com/ The Wonderful Company: https://www.wonderful.com/ Capital Factory: https://www.capitalfactory.com/ Gal Shir "quitting design" post: https://x.com/galshirart/status/2074854464729629060 Dylan Field response to Gal Shir: https://x.com/zoink/status/2075290218660298807 JCal response to Field and "J-Trade": https://x.com/Jason/status/2075481565115654305 Figma: https://www.figma.com/ Dept. of Education: "Do No Harm" policy announcement: https://www.ed.gov/about/news/press-release/us-department-of-education-issues-final-rule-hold-all-colleges-and-universities-accountable-low-earning-programs NPR coverage on Dept. of Education earnings test: https://www.npr.org/2026/06/30/nx-s1-5835631/turner-camhi-do-no-harm-college-loans Paul Graham "cheating chart" post: https://x.com/paulg/status/2075031014628311236 Off Duty Recommendations: "Lioness" on Paramount+: https://www.youtube.com/watch?v=jNRQ0PR4a8U "Mayor of Kingstown" on Paramount+: https://www.youtube.com/watch?v=VkQzvwxOp0s "Human Vapor" on Netflix: https://www.youtube.com/watch?v=7xe6dRKVAb8 "Sugar" on Apple TV+: https://www.youtube.com/watch?v=twvPGxuEOEA "Wind River" (now on Netflix): https://www.youtube.com/watch?v=CZgN0dpFoaE "Not Fade Away" by Peter Barton & Laurence Shames: https://www.amazon.com/Not-Fade-Away-Short-Lived/dp/1579546889 Timestamps: 0:00 Jason's ongoing World Tour 1:43 Danny Bernstein joins live from Reservoir Farms 3:38 What is "specialty crop agriculture" 5:15 Why strawberries are the "white whale" of AgTech 6:55 The labor crisis in farming 9:20 Why AgTech never scaled 9:51 NetSuite - For the first time, you can try NetSuite Next for free. If your revenues are at least in the seven figures, go to https://NetSuite.ai/TWIST 10:51 Inside Reservoir's business model 17:44 Agriculture as national security 20:09 Squarespace - Turn your idea into a beautiful website! Go to https://www.squarespace.com/twist for a free trial. When you're ready to launch, use offer code TWIST to save 10% off your first purchase of a website or domain. 22:15 Did AI beat a designer at design? 30:56 YSecurity - The on-demand security team for startups. Need enterprise-grade security without hiring a $400k CISO? YSecurity gives you 40+ expert engineers, matched to exactly what you need, by the hour, with your first six hours completely free. Go to https://YSecurity.io/TWIST 37:23 The "do no harm" college earnings test 43:27 Brown University students cheated on their midterms 52:22 Lon's streaming recommendations 59:46 Jason's new snake grabber   Subscribe to the TWiST500 newsletter: https://ticker.thisweekinstartups.com Check out the TWIST500: https://www.twist500.com Subscribe to This Week in Startups on Apple: https://rb.gy/v19fcp   Follow Lon: X: https://x.com/lons   Follow Alex: X: https://x.com/alex LinkedIn: ⁠https://www.linkedin.com/in/alexwilhelm   Follow Jason: X: https://twitter.com/Jason LinkedIn: https://www.linkedin.com/in/jasoncalacanis   Check out all our partner offers: https://partners.launch.co/   Great TWIST interviews: Will Guidara, Eoghan McCabe, Steve Huffman, Brian Chesky, Bob Moesta, Aaron Levie, Sophia Amoruso, Reid Hoffman, Frank Slootman, Billy McFarland   Check out Jason's suite of newsletters: https://substack.com/@calacanis   Follow TWiST: Twitter: https://twitter.com/TWiStartups YouTube: https://www.youtube.com/thisweekin Instagram: https://www.instagram.com/thisweekinstartups TikTok: https://www.tiktok.com/@thisweekinstartups Substack: https://twistartups.substack.com

Bite Size Sales
How Cybersecurity Buyers Are Influenced by Marketing: The Surprising Truth About CISO Buying Decisions and Where Your Cybersecurity GTM Spend is Wasted - Emily Matthews Principal NOLA Marketing

Bite Size Sales

Play Episode Listen Later Jul 9, 2026 40:12 Transcription Available


Emily Matthews, founder and principal of NOLA Marketing, partnered with the Ponemon Institute to ask CISOs directly how vendor marketing influences their buying decisions. The resulting State of Cybersecurity Marketing Influence Report 2026 holds some surprises: webinars beat CISO dinners, hands-on workshops build the peer references buyers trust most, and the first visitor to your website is increasingly a machine.In this episode:The top two CISO complaints about cyber marketing: it differs from product reality, and it's too high-level. Emily's fix starts with coffee-walk conversations with your engineers.Why 44% of security leaders ranked webinars the most valuable event format, while peer roundtables and CISO dinners came last.Why hands-on workshops should always be free: "You should be paying them, not them paying you."How workshops become "investments in peer influence," the #1 credibility source in the research.The shift to answer engines: Bain's 80% zero-click prediction and how to make your website a better "buffet for LLMs."Emily's case study method: start with your selling points, validate them in the customer's voice, and pack the piece with reusable quotes.Why buyers rely on analysts less than they used to, and what fills the gap for the ~3,700 vendors outside the magic quadrants.Her advice for marketers coming from outside tech: keep asking why. "Fast is not an answer."About the guest: Emily Matthews is the founder and principal of NOLA Marketing. A history and English major who started in mainframe system software, she has spent her career in technical product marketing and previously worked with the Ponemon Institute on the original Cost of a Data Breach report.Notable quotes:"You should be paying them, not them paying you.""If it sounds like BS to us, it's probably going to smell bad to them too.""If you make up a case study, it sounds made up. Interview someone. Because it's real, it comes across." Support the showThe Cyber Go-To-Market Talk is the show for cybersecurity sales leaders, founders, CROs, and go-to-market operators looking to improve cyber sales performance and build more predictable revenue growth. Hosted by Andrew Monaghan, founder of Unstoppable.do, covering cyber sales leadership, revenue leadership, sales onboarding, forecasting, pipeline generation, and cybersecurity go-to-market execution.Follow me on LinkedIn for regular posts about growing your cybersecurity startupWant to grow your revenue faster? Check out my cybersecurity sales consulting and trainingNeed ideas about how to grow your pipeline? Sign up for my newsletter.

Cybercrime Magazine Podcast
Culture Shapes Security. Changing Behavior. David Cross, Atlassian & Flavius Plesu, OutThink.

Cybercrime Magazine Podcast

Play Episode Listen Later Jul 9, 2026 19:34


David Cross is the CISO at Atlassian. In this episode, he joins host Scott Schober and Flavius Plesu, CEO at OutThink, to discuss the gap between what organizations measure and what actually tells you behavior is changing, including what proof looks like, the success of phishing programs, and more. Culture Shapes Security is a Cybercrime Magazine podcast series brought to you by OutThink. To learn more about our sponsor, visit https://outthink.io.

CISO-Security Vendor Relationship Podcast
What Part of Zero Trust Does Your Exception Not Understand?

CISO-Security Vendor Relationship Podcast

Play Episode Listen Later Jul 7, 2026 37:46


All links and images can be found on CISO Series This week's episode is hosted by David Spark, producer of CISO Series, and Andy Ellis, principal of Duha. Joining is Patti Degnan, operating partner, Andreessen Horowitz. In this episode: Identity built for one person at a time Patching can't outrun the exploit timeline The exception hiding inside zero trust A revenue question nobody's answered yet A huge thanks to our sponsor, ThreatLocker ThreatLocker delivers Zero Trust Network Access and Zero Trust Cloud Access that verifies both user and device before granting access to specific applications. No broad access, nothing exposed, and no reliance on credentials alone. It's a smarter way to control access and reduce risk. Learn more at ThreatLocker.com/CISO.

Cybercrime Magazine Podcast
CISO Confidential. Leadership In High-Growth Periods. Adrian Giboi, Solenis & Dylan DeAnda, Doppel.

Cybercrime Magazine Podcast

Play Episode Listen Later Jul 7, 2026 18:48


Adrian Giboi CISO & VP of Infrastructure Operations and Security at Solenis. In this episode, he joins Dylan DeAnda, Field CTO at Doppel, and host Scott Schober to discuss navigating leadership during high-growth periods, including artificial intelligence developments, strategic team building, and more. This episode of CISO Confidential is brought to you by Doppel. Learn more about our sponsor at https://doppel.com.

Capital, la Bolsa y la Vida
Congreso EnerTIC: La transformación digital del sector energético español: retos y oportunidades en infraestructuras críticas

Capital, la Bolsa y la Vida

Play Episode Listen Later Jul 7, 2026 26:11


Debate con Claudio Fernandez, Head of Utilities & Energy de Babel; Javier Sánchez Salas, CISO de Engie España; Ignacio Moratalla, Energy & Utilities Presales Director & KAM de Ayesa Digital; Moisés Baena, Industry, Energy, TMT & Services Director de Izertis; y Ángel Guevara, Consulting Manager - Manufacturing, Logistics, Energy & Utilities de Cognizant.

Talking Cloud with an emphasis on Cloud Security
109-Talking Innovation with Todd Beebe, Fortune 500' CISO

Talking Cloud with an emphasis on Cloud Security

Play Episode Listen Later Jul 5, 2026 45:09


Most organizations are fighting an uphill battle to prevent breaches—yet many still ignore the real costs demanded by vulnerable software. In this episode, cybersecurity veteran Todd Beebe explains why the pace of cyber threats is forcing teams to move from reactive patching to proactive security. You'll hear why old perimeter defenses are no longer enough, how AI is helping attackers find weaknesses faster, and why modern attacks are becoming quicker and more aggressive. Todd also breaks down the hidden risk of insecure software, the importance of vulnerability checks during acquisitions, and why human behavior still plays a huge role in security outcomes. Perfect for CISOs, IT leaders, procurement teams, and security practitioners, this conversation offers a practical look at how to stay ahead in a threat landscape that changes by the hour.

Cyber Security Headlines
The Department of Know: PeopleSoft exploit, Ford brings back gray beards, LLM vetting

Cyber Security Headlines

Play Episode Listen Later Jul 3, 2026 49:47


This week's Department of Know is hosted by Rich Stroffolino, with guests David Cross, CISO, Atlassian; Kathleen Mullin, Director, SABSA Institute; Montez Fitzpatrick, CISO, Navvis; and Howard Holton, former CEO, GigaOm. Get the show notes here: https://cisoseries.com/the-department-of-know-peoplesoft-exploit-ford-brings-back-gray-beards-llm-vetting/  Huge thanks to our sponsor, Silent Push Most cybersecurity approaches are completely reactive. Victim organizations are hit with an attack and the chase ensues.  Silent Push closes this gap with its Preemptive Cyber Defense platform. Silent Push tracks adversary infrastructure and infrastructure changes across the Internet during the attack preparation phase - while attackers are still staging domains, IPs, and hosting and Silent Push turns that into Indicators of Future Attack® to defend with confidence. For a CISO, that turns invisible risk into early warning, an average of 140 days before a campaign shows up in your environment. Time to act, and a smaller window of exposure, before a threat ever reaches your environment.

Cyber Security Headlines
Consumer security worries, Vought supervises spy budgets, Fortibleed exposes Fortinet

Cyber Security Headlines

Play Episode Listen Later Jul 3, 2026 8:20


Card data theft remains top concern for U.S. consumers OMB chief to oversee spy agency budgets Fortibleed leads to ransomware attacks and 430,000 Fortinet firewalls exposed Get the show notes here: https://cisoseries.com/cybersecurity-news-consumer-security-worries-vought-supervises-spy-budgets-fortibleed-exposes-fortinet/ Huge thanks to our sponsor, Silent Push Most cybersecurity approaches are completely reactive. Victim organizations are hit with an attack and the chase ensues.  Silent Push closes this gap with its Preemptive Cyber Defense platform. Silent Push tracks adversary infrastructure and infrastructure changes across the Internet during the attack preparation phase - while attackers are still staging domains, IPs, and hosting and Silent Push turns that into Indicators of Future Attack® to defend with confidence. For a CISO, that turns invisible risk into early warning, an average of 140 days before a campaign shows up in your environment. Time to act, and a smaller window of exposure, before a threat ever reaches your environment. Learn more at silentpush.com

Cloud Security Podcast
Who Governs Your AI Agents? Identity, Offboarding & Open Standards

Cloud Security Podcast

Play Episode Listen Later Jul 2, 2026 34:42


Are overprivileged AI agents the biggest emerging threat in cybersecurity? In a recent high-profile attack, a vibe-coding company had its entire source code stolen because an attacker exploited a long-lived, overprivileged token tied to a third-party AI agent.In this episode, Ashish sits down with Ely Kahn, CPO at Okta, to unpack the challenge of managing Non-Human Identities (NHI) in the AI era. Ely explains why traditional, static human permissions completely break down when applied to autonomous agents. To solve this, Okta has spearheaded Cross-App Access (XAA), an extension of OAuth that uses an Identity Assertion Grant (ID JAG). This open protocol, backed by 25+ partners, including Anthropic, XAA securely passes the baton between apps without annoying consent pop-ups or dangerous static API keys.We also explore the four maturity levels of agent authorization, ranging from broad API keys to the ultimate "North Star" of intent-based security. Learn the difference between SPIFFE (for internal cryptographic identity) and XAA (for downstream resource authorization), how the Linux Foundation is building an Agent Domain System, and why every CISO needs an immediate "kill switch" for rogue AI agents.Guest Socials -⁠⁠ ⁠⁠⁠⁠⁠Ely's Linkedin Podcast Twitter - ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠@CloudSecPod⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:-⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security Podcast- Youtube⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠- ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security Newsletter ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠If you are interested in AI Security, you can check out our sister podcast -⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ AI Security Podcast⁠Questions asked:(00:00) Introduction(02:50) Ely Kahn's Background: From DHS to Okta CPO(04:00) Why AI Agent Identity is Different from Human IAM(06:30) The Danger of Overprivileged Tokens: A Source Code Breach Case Study(08:30) Introducing Cross-App Access (XAA) and ID JAG(11:00) Agent Identities: Acting on Behalf of a User vs. Autonomous Scopes(13:00) SPIFFE vs. XAA: Workload Identity vs. Resource Authorization(14:30) The Linux Foundation's Agent Domain System for Cross-Company Passports(18:00) Assuming Breach: Why Prompt Injection Makes Identity the Highest ROI Security Action(19:30) The 4 Maturity Levels of AI Agent Authorization(21:00) Intent-Based Security and Zero Standing Privilege(23:00) How to Offboard AI Agents and Manage Identity Governance (IGA)(27:00) The 3 Governance Questions Every CISO Must Answer(28:50) Implementing a Universal Kill Switch for Rogue AgentsResources spoken about during the episode:Learn more about how Okta and XAA are setting the new security standard for the AI era

Defense in Depth
Even With All These Security Vendors We Still Have Glaring Gaps

Defense in Depth

Play Episode Listen Later Jul 2, 2026 33:56


All links and images can be found on CISO Series There are thousands of cybersecurity vendors across categories. If there's a gap in the market, it's likely not for technical reasons. So, how do you actually find vendors that are a good fit rather than one that just meets technical requirements? Check out this post by Joe Head of REFLEX Solutions for the discussion that is the basis of our conversation on this week's episode, co-hosted by me, David Spark, the producer of CISO Series, and Edward Contreras, senior evp and CISO, Frost Bank. Joining us is Ajit Girn, CIO, Employment Development Department (EDD). In this episode: Built for vendors, not users Signal versus noise Priced out The elegance gap A huge thanks to our sponsor, ThreatLocker ThreatLocker takes a deny-by-default approach to endpoint security — controlling what applications can run, what can access data, and what can elevate privileges. Used by organizations that want to reduce attack surface without relying on detection alone. Learn more at threatlocker.com/ciso.

HealthcareNOW Radio - Insights and Discussion on Healthcare, Healthcare Information Technology and More

S3E9: Shadow AI, Quantum Risk, and CISO Burnout - The Threats Healthcare Isn't Ready For Host: Frank Cutitta Guest: Dave Bailey, EMBA, CISSP, Vice President of Consulting Solutions & Strategy at Clearwater Security To stream our Station live 24/7 visit www.HealthcareNOWRadio.com or ask your Smart Device to “….Play Healthcare NOW Radio”. Find all of our network podcasts on your favorite podcast platforms and be sure to subscribe and like us. Learn more at www.healthcarenowradio.com/listen

Cyber Security Headlines
Hide My Email bug shows real addresses, Fable 5 gets the greenlight, Microsoft Teams hits back on AI bots

Cyber Security Headlines

Play Episode Listen Later Jul 2, 2026 6:44


Hide My Email bug shows real addresses Fable 5 gets the greenlight DHS confirms hackers breached HSIN Get the show notes here: https://cisoseries.com/cybersecurity-news-hide-my-email-shows-real-addresses-fable-5-gets-greenlight-microsoft-teams-hits-back-on-bots/ Huge thanks to our sponsor, Silent Push Most cybersecurity approaches are completely reactive. Victim organizations are hit with an attack and the chase ensues.  Silent Push closes this gap with its Preemptive Cyber Defense platform. Silent Push tracks adversary infrastructure and infrastructure changes across the Internet during the attack preparation phase - while attackers are still staging domains, IPs, and hosting and Silent Push turns that into Indicators of Future Attack® to defend with confidence. For a CISO, that turns invisible risk into early warning, an average of 140 days before a campaign shows up in your environment. Time to act, and a smaller window of exposure, before a threat ever reaches your environment. Learn more at silentpush.com

The CyberWire
The AI lock comes off.

The CyberWire

Play Episode Listen Later Jul 1, 2026 30:53


The US restores exports of Anthropic's most advanced AI models. Adobe and Citrix rush out critical patches. RustDuck emerges as a fast-evolving DDoS threat. The Gentlemen raise the stakes with a new EDR-killing exploit. Rocket lab bets big on Iridium. Researchers unveil browser-only ransomware. New Zealand faces questions about its cyber readiness. Iran's long-running cyber espionage campaign is back in the spotlight. Our guest is Donald Codling, CISO and senior advisor to REGO on cybersecurity and data privacy matters, to discuss the importance of tying security by design to psychological safety and digital trust. VIP backstage access, courtesy of Claude. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Donald Codling, CISO and senior advisor to REGO on cybersecurity and data privacy matters, to discuss the importance of tying security by design to psychological safety and digital trust. Selected Reading Fable and Mythos: Anthropic says US lifts export ban on its advanced AI tools (BBC) Adobe patches seven max severity ColdFusion, Campaign flaws (Bleeping Computer) RustDuck: The Botnet That's Still Small but Engineering Like It Plans to Grow (SecurityAffairs) Citrix Patches NetScaler Vulnerabilities, Including New ‘HTTP/2 Bomb' Attack (SecurityWeek) Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets' EDRs (Expel) Rocket Lab to Acquire Iridium in Historic Deal, Creating A Fully Vertically Integrated Space Powerhouse Primed for Growth (Globe Newswire) Ransomware that runs inside your browser tab, where antivirus cannot see it (Suriq) Three major cybehttps://suriq.io/blog/browser-only-ransomware-file-system-accessrattacks have raised alarms about New Zealand's security (RNZ) Arrest of Iranian Hacker Spotlights Iran's Movement into Economic Espionage and IP Theft (Zero Day) Claude Helped a Hacker Find a Way to Issue Tickets to Almost Every US Music Festival (WIRED) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

Serious Privacy
Digital Colonization with Samantha Simma

Serious Privacy

Play Episode Listen Later Jul 1, 2026 41:21 Transcription Available


Send us Fan MailWelcome to the Serious Privacy podcast, where Ralph O'Brien and Dr. K Royal, ( Paul Breitbarth was out) meet with the phenomenal Samantha Simms. We had the best time going deep on some really substantive issues, even starting with Samantha's answer on the unexpected question. Join us as we discuss key issues and the digital colonization. If you have comments or questions, find us on LinkedIn and Instagram @seriousprivacy, and on BlueSky under @seriousprivacy.eu, @europaulb.seriousprivacy.eu, @heartofprivacy.bsky.app and @igrobrien.seriousprivacy.eu, and email podcast@seriousprivacy.eu. Rate and Review us! From Season 6, our episodes are edited by Fey O'Brien. Our intro and exit music is Channel Intro 24 by Sascha Ende, licensed under CC BY 4.0. with the voiceover by Tim Foley.

Cybercrime Magazine Podcast
Inside(r) Scoop. Redefining The Insider Threat. James Rutt, The Dana Foundation & Aviv Nahum, Above.

Cybercrime Magazine Podcast

Play Episode Listen Later Jul 1, 2026 16:55


James Rutt, is the CISO at The Dana Foundation. In this episode, he joins host Scott Schober and Aviv Nahum, CEO at Above Security, to discuss the insider threat and how we can redefine it for the modern cybersecurity landscape. Above Security is an AI-native managed insider-threat platform for proactive risk management. To learn more about our sponsor, visit https://above.security. • For more on cybersecurity, visit us at https://cybersecurityventures.com

Cyber Security Headlines
Bash hits AI, DHS announces ANCHOR-CI, Aikido buys Root

Cyber Security Headlines

Play Episode Listen Later Jul 1, 2026 7:26


Bash can spell trouble GNU for AI agents  DHS to unveil critical infrastructure council  Aikido buys Root Get the show notes here: https://cisoseries.com/cybersecurity-news-bash-hits-ai-dhs-announces-anchor-ci-aikido-buys-root/  Huge thanks to our sponsor, Silent Push Most cybersecurity approaches are completely reactive. Victim organizations are hit with an attack and the chase ensues.  Silent Push closes this gap with its Preemptive Cyber Defense platform. Silent Push tracks adversary infrastructure and infrastructure changes across the Internet during the attack preparation phase - while attackers are still staging domains, IPs, and hosting and Silent Push turns that into Indicators of Future Attack® to defend with confidence. For a CISO, that turns invisible risk into early warning, an average of 140 days before a campaign shows up in your environment. Time to act, and a smaller window of exposure, before a threat ever reaches your environment. Learn more at silentpush.com

Packet Pushers - Full Podcast Feed
HS137: Did AI Turn “Everybody Codes” into “Nobody Codes”?

Packet Pushers - Full Podcast Feed

Play Episode Listen Later Jun 30, 2026 38:23


“Everybody codes” was an enterprise buzzword. In this era of AI vibe-coding and single-use coding, should everyone code? Should anyone code? John and Johna talk about enterprise strategies with respect to coding in the AI era, including what expertise to look for in employees. AdSpot Sponsor: Meter Meter delivers full-stack networking—wired, wireless, and cellular—to leading... Read more »

CISO-Security Vendor Relationship Podcast
These Aren't Speed Bumps, They're Opportunity Ramps! (LIVE in NYC)

CISO-Security Vendor Relationship Podcast

Play Episode Listen Later Jun 30, 2026 42:20


All links and images can be found on CISO Series This week's episode is hosted by David Spark, producer of CISO Series and Nick Vigier, CISO, Oscar Health. Joining is our sponsored guest, Mitchem Boles, field CTO, Intezer. This episode was recorded live at Intezer's AI SOC event held at the NASDAQ in NYC. In this episode: Who owns the risk Before it gets better The SOC of zero The decision bottleneck A huge thanks to our sponsor, Intezer Intezer Forensic AI SOC is designed for enterprises managing high alert volumes across SIEM, EDR Network, identity, phishing, and cloud systems. These organizations often rely on MDRs to fill coverage gaps but face frustration with limited visibility, too many escalations, and missed incidents hiding in low-severity alerts. Learn more at Intezer.com.

Packet Pushers - Fat Pipe
HS137: Did AI Turn “Everybody Codes” into “Nobody Codes”?

Packet Pushers - Fat Pipe

Play Episode Listen Later Jun 30, 2026 38:23


“Everybody codes” was an enterprise buzzword. In this era of AI vibe-coding and single-use coding, should everyone code? Should anyone code? John and Johna talk about enterprise strategies with respect to coding in the AI era, including what expertise to look for in employees. AdSpot Sponsor: Meter Meter delivers full-stack networking—wired, wireless, and cellular—to leading... Read more »

Artificial Intelligence in Industry with Daniel Faggella
Why Data‑Driven Efforts Stall in Fragmented Environments - with Jason Loomis of Freshworks

Artificial Intelligence in Industry with Daniel Faggella

Play Episode Listen Later Jun 30, 2026 21:11


Enterprise AI adoption is moving faster than security and governance frameworks can follow,  forcing organizations to make difficult trade-offs between competitive urgency and operational risk. In this episode, Jason Loomis, CISO at Freshworks, examines why most enterprises have not yet resolved the tension between AI deployment speed and security maturity, and outlines a sequenced approach; beginning with regulatory compliance, advancing through data trust, and extending into AI-specific security frameworks. The conversation covers how leadership can build the investment case for AI, how culture shapes adoption outcomes, and why the biggest executive mistake is expecting returns before committing the resources that make them possible. Connect with ideal enterprise AI through the strategies Emerj employs to help leading AI brands and startups: emerj.com/AD1  

We Talk Cyber
I Tried 5 Cybersecurity Roles - Here's the Truth Nobody Tells You

We Talk Cyber

Play Episode Listen Later Jun 30, 2026 21:49


Stop chasing certifications without direction. If you're trying to break into cybersecurity or grow into a leadership role, this is the real career map. In this video, I walk you through the 5 most in-demand cybersecurity career paths - from hacker to identity, cloud, GRC, and CISO. I've worked in all of them over the last 20 years, and I'm giving you the no-BS truth on what each role really looks like, what hiring managers want in 2025, and what it actually takes to succeed.What we'll cover in this video: what penetration testing really is (Hint: it's not just hacking), why IAM (Identity & Access Management) is exploding in demand, the real-world impact (and pressure) of cloud security leadership, how GRC & privacy are fast tracks to C-suite for legal/finance folks, what it actually takes to become a successful CISO, and the truth nobody tells you: It's not where you start—it's how you grow.This isn't another generic “top 5 jobs” list. This is real experience, real insights, and a real roadmap for building a cybersecurity career that actually leads to leadership.Looking to go from chaos and unpredictability to resilience in the world of AI? Start here with The Predictability Factor newsletter at The Monica Talks Cyber (https://www.monicatalkscyber.com).

Heavy Strategy
HS137: Did AI Turn “Everybody Codes” into “Nobody Codes”?

Heavy Strategy

Play Episode Listen Later Jun 30, 2026 38:23


“Everybody codes” was an enterprise buzzword. In this era of AI vibe-coding and single-use coding, should everyone code? Should anyone code? John and Johna talk about enterprise strategies with respect to coding in the AI era, including what expertise to look for in employees. AdSpot Sponsor: Meter Meter delivers full-stack networking—wired, wireless, and cellular—to leading... Read more »

Cyber Risk Management Podcast
EP 213: The Group Writing the Rules for AI Trust

Cyber Risk Management Podcast

Play Episode Listen Later Jun 30, 2026 47:36


Would you know if the AI tools your team is buying are actually trustworthy to use? Who gets to decide what trustworthy AI even means? Let's find out with our guest Jim Reavis, CEO of the Cloud Security Alliance, the group that helped the world learn to trust the cloud and is now building the standards for trusting AI. Jim explains how AI is changing what attackers, defenders, and governments can do, and walks through the tools his team built so you can adopt AI without guessing. Your hosts are Kip Boyle, CISO with Cyber Risk Opportunities, and Jake Bernstein, Partner with K&L Gates.   Cloud Security Alliance: https://cloudsecurityalliance.org/

ceo trust ai writing partner ciso cloud security alliance l gates jake bernstein kip boyle cyber risk opportunities
Cyber Security Headlines
US seizes illegal World Cup domains, WhatsApp offers usernames for phone privacy, $10M reward for Russia-based cyber campaign

Cyber Security Headlines

Play Episode Listen Later Jun 30, 2026 7:25


US seizes illegal World Cup domains WhatsApp offers usernames for phone number privacy $10M reward for Russia-based cyber campaign Get the show notes here: https://cisoseries.com/cybersecurity-news-us-seizes-illegal-world-cup-domains-whatsapp-offers-usernames-for-phone-privacy-10m-reward-for-cyber-campaign/ Huge thanks to our sponsor, Silent Push Most cybersecurity approaches are completely reactive. Victim organizations are hit with an attack and the chase ensues.  Silent Push closes this gap with its Preemptive Cyber Defense platform. Silent Push tracks adversary infrastructure and infrastructure changes across the Internet during the attack preparation phase - while attackers are still staging domains, IPs, and hosting and Silent Push turns that into Indicators of Future Attack® to defend with confidence. For a CISO, that turns invisible risk into early warning, an average of 140 days before a campaign shows up in your environment. Time to act, and a smaller window of exposure, before a threat ever reaches your environment. Learn more at silentpush.com

Cyber Security Today
US Restricts Frontier AI models

Cyber Security Today

Play Episode Listen Later Jun 29, 2026 11:14


US Loosens Anthropic Claude Mythos Access, Unpatchable iPhone Exploit Emerges, and CISO Burnout Drives Fractional Shift Washington granted a partial reprieve allowing Anthropic's Claude Mythos to be released to more than 100 approved U.S. firms and institutions after export controls paused Mythos and the more restricted Fable 5, with access still limited to vetted American entities; the same day, OpenAI's GPT 5.6 was also restricted to government-approved partners under a Trump executive order requiring review of cyber-capable models.  The episode also covers Canadian hacktivist Aubrey Cottle's 18-month sentence for the 2021 Texas GOP hack and bail breaches, with possible U.S. charges pending. Researchers disclosed "USBliterate," an unpatchable physical USB exploit in the Secure ROM of older A12/A13 iPhones that aids forensic extraction. Finally, a survey finds rising CISO burnout, fewer full-time CISOs, growth in fractional CISO roles, and AI—especially shadow AI—overtaking liability as the top stressor. 00:55 AI Export Controls Shift 03:37 Anonymous Hacker Sentenced 05:32 Unpatchable iPhone Boot Exploit 07:30 CISO Burnout And Exodus 09:40 Wrap Up And Sign Off

Cyber Security Headlines
CISA's Cisco deadline, China's Mythos competitor, Amazon Q flaw

Cyber Security Headlines

Play Episode Listen Later Jun 29, 2026 8:36


CISA sets urgent deadline to fix exploited Cisco flaw Chinese cybersecurity company claims it has a better-than-Mythos bug finder Amazon Q flaw enables cloud credential theft  Get the show notes here: https://cisoseries.com/cybersecurity-news-cisas-cisco-deadline-chinas-mythos-competitor-amazon-q-flaw/ Huge thanks to our sponsor, Silent Push Most cybersecurity approaches are completely reactive. Victim organizations are hit with an attack and the chase ensues.  Silent Push closes this gap with its Preemptive Cyber Defense platform. Silent Push tracks adversary infrastructure and infrastructure changes across the Internet during the attack preparation phase - while attackers are still staging domains, IPs, and hosting and Silent Push turns that into Indicators of Future Attack® to defend with confidence. For a CISO, that turns invisible risk into early warning, an average of 140 days before a campaign shows up in your environment. Time to act, and a smaller window of exposure, before a threat ever reaches your environment. Learn more at silentpush.com

The CyberWire
Factory reset required.

The CyberWire

Play Episode Listen Later Jun 26, 2026 25:13


Tata Electronics and Bajaj Auto continue recovery from cyberattacks. FCC tightens undersea cable rules to bolster national security. CISA warns of actively exploited PTC vulnerability. Gamaredon expands toolkit, hides behind legitimate services. Iran-linked hackers turn public warning systems into psychological weapons. Threat actors target critical infrastructure across Southeast Asia. DCloud framework behind global scam economy. Polish police disrupt SIM-swapping gang. French statistics agency reports cyberattack affecting nearly 13,000 staff. Our guest is Michael Fanning, CISO at Splunk, discussing how AI doesn't create problems, it exposes them. And an open-book exam for hackers. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Michael Fanning, CISO at Splunk, discussing how AI doesn't create problems, it exposes them. Selected Reading Apple supplier Tata tightens internal controls after data breach, sources say (Reuters)  Bajaj Auto resumes normal operations as cyberattack probe continues (Storyboard18)  FCC passes new cybersecurity rules for emergency systems, undersea cables (CyberScoop) U.S. CISA adds Cisco and PTC Windchill and FlexPLM flaws to its Known Exploited Vulnerabilities catalog (SecurityAffairs)  Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances (ESET)  A Cyber-Psychological Operation: Iran-Linked Attackers Target Warning Systems (Claroty)  CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure (Unit 42) From San Pedro to Salinas: How a Chinese Framework “DCloud Uni-App” Powers a Global Scam Economy (Infoblox) Poland busts SIM-swapping gang tied to millions in crypto theft (BleepingComputer) France's statistics department reports cyberattack on staff data (Reuters) UK school's network left wide open for invasion, student found (The Register) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

Defense in Depth
Is the "Attackers Only Need to Be Right Once" a Misnomer?

Defense in Depth

Play Episode Listen Later Jun 25, 2026 27:40


All links and images can be found on CISO Series Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark, the producer of CISO Series, and George Finney, CISO, University of Texas System. Joining is Sean Walls, CISO, Bob's Discount Furniture. In this episode: Asymmetric accounting Sometimes it really is that easy The spirit of the saying The cheapest way in A huge thanks to our sponsor, Native Security Native is the Cloud Security Control Plane. It helps enterprises enforce secure-by-design architecture across multi-cloud environments by translating security intent into the cloud provider's built-in controls, previewing impact before rollout, and keeping enforcement aligned as the environment changes.

university attackers ciso asymmetric misnomer texas system david spark ciso series
The New CISO
CISO 3.0: The Playbook for Delivering Impact and Influence

The New CISO

Play Episode Listen Later Jun 25, 2026 58:06


What separates a CISO who survives from one who shapes the boardroom? In this episode, Steve Moore sits down with Walt Powell, Lead Field CISO at CDW and author of The CISO 3.0, to unpack the modern CISO playbook—why technical credentials alone no longer cut it, how to build personal eminence, and why most security leaders are still treated as second-class C-suite citizens.Walt traces his path from teaching networking before stateful firewalls existed, to writing CISSP exam questions for ISC2, to running CDW's Global Security Strategy Office. He explains what a field CISO does, why the role is harder than ex-CISOs realize, and how one bad meeting can tarnish a brand built over decades.He and Steve break down the four pillars Walt uses to measure his team—embedded advisory, eminence building, sales enablement, and voice of the customer—and how a karate-style “belt system” maps each consultant's competency. Walt explains why the same skills matrix from The CISO 3.0 works for any CISO trying to spot their own gaps.Walt argues a CISO who is not liked cannot succeed: you are the talent magnet, the culture builder, and the person proving in every board meeting that you belong in the seat. He shares the questions every candidate should ask before accepting the role—from D&O coverage to 10-K disclosure access—and why the 30-60-90 plan should be written before the second interview, not after the offer.The conversation closes with what Walt calls “strategic debt”—the identity and data governance work organizations skipped a decade ago that is now blocking AI adoption. Walt shares lessons from running OpenClaw on a Mac mini, why non-human identity tops every 2026 CISO worry list, and how Deep Research is reshaping senior architects.Key Topics• The modern field CISO role and the four pillars of impact• Why CISOs are still treated as second-class C-suite citizens• Building personal eminence through books, speaking, and writing• The CISO 3.0 skills matrix and self-assessment spider wheel• Two paths to the CISO seat: technical vs. MBA, and the gaps each leaves• Why likability is not optional for a successful CISO• Board readiness and proving you belong in the seat• Interview questions every CISO candidate must ask• Strategic debt: identity and data governance blocking AI adoption• OpenClaw, non-human identity, and the future of senior architectsGuest Bio:Walt Powell is the Lead Field CISO at CDW and a founding member of CDW's Global Security Strategy Office, where he leads a team of former CISOs advising security leaders in the field. A longtime executive coach and ISC2 exam development committee member, Walt is the author of The CISO 3.0: A Guide to Next-Generation Cybersecurity Leadership and Quantum Ready, his book on post-quantum cryptography. Connect with Walt on LinkedIn or at ciso30.com.GET A DEMO:

The Tech Trek
Your Team Is Using AI Anyway

The Tech Trek

Play Episode Listen Later Jun 25, 2026 26:43


AI adoption is no longer just a policy conversation. For many organizations, the bigger question is how to move faster without creating avoidable risk.In this episode of The Tech Trek, Amir Bormand sits down with Aimee Cardwell, CIO and CISO in residence at Transcend, to talk about responsible AI deployment, the tension between speed and control, and how leaders should think about security, compliance, productivity, and customer experience as AI moves through the enterprise.Aimee brings a rare view across the CIO, CISO, and board lens. The conversation gets into why blocking AI often backfires, how prompt redaction can help teams move faster safely, where companies should draw the line on risk, and why some teams may need to rethink old assumptions about tech debt, code ownership, and modernization.Practical Takeaways• Responsible AI depends on the lens. Security, compliance, business, board, and technology teams may all define it differently.• Blocking employee AI usage can create worse outcomes. People may use shadow tools anyway, or teams may fall behind in productivity.• Prompt redaction and enterprise agreements can give teams room to experiment while reducing exposure of sensitive data.• Moving fast is not the same as releasing half finished customer experiences. Bad AI tools can train customers to distrust the entire interaction.• AI may change how teams think about tech debt, refactoring, and whether some legacy systems should be rebuilt instead of patched forever.Timestamped Highlights00:00 Responsible AI deployment and why the definition changes by role02:35 Aimee explains the CIO, CISO, and board perspectives on AI adoption05:14 Why companies that block AI may create shadow usage and slower teams06:52 Prompt redaction as a practical way to let employees experiment safely10:40 How AI risk changes when the data exposure model is different from traditional insider theft15:10 Why releasing poor AI customer experiences can damage trust21:50 Using shared enterprise prompts to raise the quality of AI output across engineering teams26:20 How AI could change the way teams approach security debt and code modernizationOne Line That Stuck“The conversation has flipped, and it is really how can I get the company to go faster.”Pro Tips• Start by identifying what truly makes your business defensible. Not every asset carries the same risk.• Give employees safe paths to use AI instead of pretending they will not use it.• Build shared prompts with engineering standards, approved tools, and company context so teams do not start from scratch every time.• Ask whether old assumptions still hold. Some decisions made sense when changes were expensive, slow, or risky. AI may change that equation.Subscribe to The Tech Trek for more conversations on how modern technical teams are building, hiring, operating, and adapting around AI, data, platform, product, and engineering execution.#ai #agentic #techleadership #engineeringleadership 

Serious Privacy
Censorship, Safety, or Something Else? (Social Media Controls with Fey O'Brien)

Serious Privacy

Play Episode Listen Later Jun 25, 2026 40:41 Transcription Available


Send us Fan MailWelcome to the Serious Privacy podcast, where Ralph O'Brien , Dr. K Royal, and Paul Breitbarth explores the implications of proposed social media age restrictions in the UK to under 16s, through the insights of university student (and our editor!) Fey O'Brien, emphasising the importance of digital literacy and open communications.As the debate surrounding social media age restrictions continues, it is vital to consider the implications for minors and their rights. Engaging with younger voices like Fey's adds depth to the discussion, illustrating the importance of balancing safety and freedom in the digital landscape. Instead of imposing blanket bans, fostering digital literacy and open communication can pave the way for a more informed generation of social media users. If you have comments or questions, find us on LinkedIn and Instagram @seriousprivacy, and on BlueSky under @seriousprivacy.eu, @europaulb.seriousprivacy.eu, @heartofprivacy.bsky.app and @igrobrien.seriousprivacy.eu, and email podcast@seriousprivacy.eu. Rate and Review us! From Season 6, our episodes are edited by Fey O'Brien. Our intro and exit music is Channel Intro 24 by Sascha Ende, licensed under CC BY 4.0. with the voiceover by Tim Foley.

ITSPmagazine | Technology. Cybersecurity. Society
When You Can't Trust the Face on the Call | A Brand Highlight Conversation with Kevin Surace, CEO of TokenCore

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Jun 24, 2026 6:00


In this Brand Highlight, Kevin Surace, CEO of TokenCore, catches up on a market that has accelerated faster than even his team expected. Biometric-assured identity has gone from the fringes to the core, and the clearest example is the video call: on Zoom or Teams, there is often no reliable way to know whether the person on screen is real, human, or an AI avatar. Surace points to cases where employees wired money because a synthetic version of their boss appeared to ask for it. That risk is pushing the work outward. Beyond using TokenCore internally, the larger banks are asking how to extend biometric assurance to the customers who move wires, because a phone call no longer confirms who is actually on the line. The goal is to know that it is the right person, on the right domain, within a few feet of the device, and not someone operating from another country. For security leaders, Surace offers direct advice: start moving off MFA and authenticator apps now, since those methods are being compromised constantly. He acknowledges the change is hard, often for cultural reasons more than technical ones, and suggests starting with admins and the people who touch real data before expanding over roughly a year. The upside, he notes, is that employees tend to welcome it, going passwordless or even ID-less and logging into tools like Salesforce in under two seconds. This is a Brand Highlight. A Brand Highlight is a ~5 minute conversation that captures a focused idea, update, or perspective from the guest. Learn more: https://www.studioc60.com/creation#highlight GUEST Kevin Surace, Chief Executive Officer, TokenCore LinkedIn: https://www.linkedin.com/in/ksurace/ RESOURCES Learn more about TokenCore: https://www.tokencore.com Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS Kevin Surace, TokenCore, Sean Martin, brand story, brand marketing, marketing podcast, brand highlight, biometric assured identity, identity security, deepfake, AI avatar, video call security, MFA, passwordless, FIDO2, CISO, account takeover, wire fraud, Zoom security, identity assurance Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Packet Pushers - Full Podcast Feed
HS136: How AI Is Changing Enterprise Software Development (Sponsored)

Packet Pushers - Full Podcast Feed

Play Episode Listen Later Jun 23, 2026 50:41


AI can generate working code quickly. Building reliable software to run infrastructure platforms is still a multi-year engineering challenge. In this sponsored episode, BlueCat chief strategy officer Andrew Wertkin joins John Burke and Scott Robohn to talk through the difference between code generation and enterprise software development, and the challenges and opportunities of engineering reliability... Read more »

Packet Pushers - Fat Pipe
HS136: How AI Is Changing Enterprise Software Development (Sponsored)

Packet Pushers - Fat Pipe

Play Episode Listen Later Jun 23, 2026 50:41


AI can generate working code quickly. Building reliable software to run infrastructure platforms is still a multi-year engineering challenge. In this sponsored episode, BlueCat chief strategy officer Andrew Wertkin joins John Burke and Scott Robohn to talk through the difference between code generation and enterprise software development, and the challenges and opportunities of engineering reliability... Read more »