Podcasts about cisos

  • 663PODCASTS
  • 5,412EPISODES
  • 24mAVG DURATION
  • 2DAILY NEW EPISODES
  • Aug 27, 2026LATEST

POPULARITY

20192020202120222023202420252026

Categories



Best podcasts about cisos

Show all podcasts related to cisos

Latest podcast episodes about cisos

The New CISO
The Player-Coach CISO: Engineering Trust in AI Agents with Open-Source Tools

The New CISO

Play Episode Listen Later Aug 27, 2026 49:06


In this episode of The New CISO, host Steve Moore welcomes Sherri Douville for a conversation that sits outside the show's usual lane — less war story, more blueprint. Sherri works alongside CISOs rather than inside the role, and arrives with a pointed argument about what the job is becoming.She starts with why TTIC exists. IEEE UL 2933 gave healthcare a full-stack standard for clinical IoT device and data interoperability, but a standard on paper does nothing until it is adopted, implemented, and maintained. Getting there in a high-reliability industry means pulling in CIOs, CISOs, physicians, and engineers — and, Sherri admits, negotiating turf wars with bodies who assume you have come for their territory.Then the headline: how to make security cool. Sherri's answer starts with visibility — getting CISOs onto stages, onto podcasts, and into print in front of clinical leadership. Underneath it is a claim about trust. In healthcare, trust is the core of the business rather than an adjacent concern, which makes the CISO its natural steward. With AI pushing trust to the center of every industry, she argues that is the opening to become the rock star of the C-suite.Steve raises a banking CISO's framing of AI as a curious seven-year-old with a gun. Sherri pushes back on the spot: her analogy is the gifted teenager — capable, resource-hungry, and badly in need of direction. That leads to her real thesis. Scarce expertise used to carry economic value, and AI is rapidly compressing the worth of expert analysis. What appreciates instead is judgment, authority, execution, verification, organizational integration, and ownership of the outcome. Executives do not want more reports; they want the security problem to go away without adding coordination burden.The last stretch turns practical. Sherri walks through running Exabeam's open-source Praxen against Medigram's own code — painless to run, with remediation effort scaling to whatever standard you are chasing — and pairs it with Observra for continuous runtime telemetry. She closes on why it matters: when systems go down in a hospital, the real damage is not the outage hour but the fortnight of delays, miscommunications, and pile-up that follows for clinicians and patients.Key TopicsWhy standards bodies stall at adoption, not authorshipMaking security “cool”: visibility, stages, and executive presenceTrust as the core of the business in high-reliability industriesThe gifted teenager vs. the curious seven-year-old with a gunJudgment, authority, execution, verification, integration, ownershipSelective depth and the player-coach executiveRunning Praxen pre-deployment; Observra for runtime telemetryWhat a healthcare outage really costs, 14 to 20 days outGuest BioSherri Douville is CEO and Architect of Medigram and Founder and Chair of the Trustworthy Technology & Innovation Consortium (TTIC). She co-chairs the Trust subgroup of IEEE UL 2933 (TIPPSS), the standard for trust in clinical IoT. Medigram builds and operates Darwin, a governed AI decision platform whose agentic fleet runs in production and writes a sealed governance record at the moment of every agent action — an auditable trail for counsel, courts, insurers, and credit rating agencies. Sherri spent over a decade at Johnson & Johnson across a dozen disease states before physician leaders pulled her into healthcare IT and AI. She calls herself an accidental technologist: a domain expert who got into the code, logging 200 GitHub commits across June and July.GET A DEMO:

Paul's Security Weekly
Connecting Cyber Risks to Board Outcomes & BHUSA interviews from Mimecast & Zscaler - Leslie Nielsen, Brett Stone-Gross, Dan Bowden - BSW #462

Paul's Security Weekly

Play Episode Listen Later Aug 26, 2026 67:29


The threat landscape has become more interconnected, disruptive, and complex. Ransomware is now as much about extortion and data theft as it is about encryption. Supply chain events can create outages that ripple far beyond the initial target, and business interruption increasingly comes from third-party and cloud dependencies. How should CISOs prepare for these scenarios? Dan Bowden, Global Business CISO at Marsh, joins Business Security Weekly to discuss how to connect cyber risk to the outcomes boards care about most: resilience, financial exposure, regulatory impact, and reputation. CISOs need to position cyber as an enterprise risk, not a technical risk, that can be measured, prioritized, and managed alongside other strategic risks. Dan will discuss the results of Marsh's Cyber Catalyst research and Global Cyber Claims Report. Visit https://securityweekly.com/infosecworld2026 and save 30% on your ISW pass with code: ISW26-SWSAVINGS The Agent Is the New Insider: Why Human Risk Doesn't Stop at People: Black Hat Interview with Leslie Nielson, CISO at Mimecast AI agents now act with the same credentials and access as the humans who deployed them, but without the judgment or accountability that comes with actual employment. Mimecast CISO Leslie Nielsen argues that treating agentic AI as a brand new, standalone security category is the wrong instinct: agents are an extension of human risk, and the controls organizations already use to manage people are the right foundation for managing machines. In this conversation, Nielsen unpacks the growing gap between security leaders who expect AI driven attacks and those who feel prepared for them, and what that gap means for CISOs walking the floor at Black Hat. Segment Resources: Mimecast's new whitepaper Securing The Agentic Enterprise: https://assets.mimecast.com/api/public/content/securing-the-agentic-enterprise?v=ea66db05 Mimecast's landing page for thought leadership resources: https://www.workprotected.com/ Mimecast's State of Human Risk Report: https://www.mimecast.com/resources/ebooks/state-of-human-risk/ Mimecast's Threat Intelligence Hub: https://www.mimecast.com/threat-intelligence-hub/ For more information about Mimecast please visit: https://securityweekly.com/mimecastbh Ransomware Moves up the Org Chart: Managers Are Prime Targets: Black Hat Interview with Brett Stone-Gross, Sr. Director, Threat Intelligence at Zscaler When a ransomware attack makes headlines, attention usually turns to the organization that was breached, the systems encrypted, data stolen, and disruption or ransom demand that followed. Less, if anything, is revealed about the employees compromised at the start of the attack, and what makes those individuals valuable targets. New Zscaler ThreatLabz research examines this early stage of a real-world ransomware attack. ThreatLabz identified victims of a campaign associated with a ransomware group known for gaining initial access, stealing large amounts of corporate data, and selectively encrypting critical systems. The findings show who those victims were and how their roles and authority could help an attacker move deeper into an organization. This is part of ongoing ransomware research by ThreatLabz. The Zscaler ThreatLabz 2026 Ransomware Report, coming in the next two months, will include additional data on ransomware victims, the latest ransomware trends, targets, and tactics, and the risks enterprises should prepare for next. This segment is sponsored by Zscaler. Visit https://securityweekly.com/zscalerbh to learn more about them! Visit https://www.securityweekly.com/bsw for all the latest episodes! Show Notes: https://securityweekly.com/bsw-462

The Tech Leader's Playbook
How AI Agents Are Forcing a Rethink of Enterprise Identity Security

The Tech Leader's Playbook

Play Episode Listen Later Aug 20, 2026 64:04


In this episode of The Tech Leader's Playbook, Jason Martin shares the founder decisions behind building Permiso, from interviewing 100 enterprise security leaders before writing code to creating a new cybersecurity market before most buyers understood the problem. He breaks down product-market fit, go-to-market challenges, fundraising pressure, co-CEO leadership, startup resilience, and the realities of selling a company. The conversation also explores AI agents, non-human identities, identity security, and the emerging risks executives must prepare for as AI becomes embedded across the enterprise. Essential viewing for founders, CISOs, technology executives, investors, and cybersecurity leaders.What You'll Learn• Why customer behavior matters more than investor enthusiasm or market compliments.• How Permiso identified identity security as a critical cloud security problem before the broader market caught up.• What founders should understand about fundraising, go-to-market execution, and creating a new category.• When being early becomes a competitive advantage versus simply being wrong.• The security risks AI agents and non-human identities create for modern enterprises.Chapters00:00 Building Permiso Security05:58 From Biology to Cybersecurity10:38 Customer Discovery Before Building14:16 Creating a New Market19:42 Surviving Startup Go-to-Market25:10 Fundraising Is a Treadmill29:29 Making Co-CEO Leadership Work38:42 The Okta Acquisition47:47 AI and Identity Security58:47 Lessons for Founders Follow Avetis AntaplyanInstagram:https://www.instagram.com/avetisantaplyanSpotify:https://open.spotify.com/show/0rOkUXDSQb6SVFE6LttWDeApple Podcasts:https://podcasts.apple.com/us/podcast/the-tech-leaders-playbook/id1690263628Follow Jason MartinLinkedIn:https://www.linkedin.com/in/jasonlpmartin/HIRECLOUT:https://www.hireclout.comThe Tech Leader's Playbook:https://www.podcast.hireclout.comLinkedIn:https://www.linkedin.com/in/hirefasthirerightidentity security, AI security, cybersecurity, Jason Martin, Permiso Security, Okta, AI agents, non-human identities, cloud security, enterprise security, cybersecurity startups, artificial intelligence security, identity threat detection, startup founder, technology leadership, CISO, cybersecurity leadership, product market fit, customer discovery, go-to-market strategy, startup fundraising, category creation, startup acquisition, cybersecurity acquisition, co-CEO leadership, enterprise technology, AI workforce, startup resilience, technology executives#BusinessExit #ExitStrategy #BusinessValuation #Entrepreneurship #Leadership #CEO #MergersAndAcquisitions #SPAC #ScalingBusiness #FounderLeadership #PrivateEquity #IntegratedCEO

ITSPmagazine | Technology. Cybersecurity. Society
The Capability Is Already in Your Stack. The Question Is Who You Ask. | A Recap at Black Hat USA 2026 with Michael Parisi, Chief Growth Officer at Steel Patriot Partners | Hosted by Marco Ciappelli

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Aug 18, 2026 5:42


Michael Parisi, Chief Growth Officer at Steel Patriot Partners, connects with ITSPmagazine on location at Black Hat USA 2026 for a recap of the week. He describes Steel Patriot Partners in the order it sets its priorities. Business owners first, engineers second, compliance and security people third. A consulting and advisory company, he says, but really an engineering firm. What changed at this event? Parisi says the AI slop visible at RSAC Conference died down here, and that people are cutting through the noise and going back to a core group of tools and solutions with the capabilities to address the business challenges AI is creating. Non-human identities sit at the top of that list, the number one concern he heard relative to AI. Organizations recognize the risk and are working out how to solve for it. His observation is that many information security teams do not realize their traditional cybersecurity tools already carry the capabilities to do it. Who are security leaders asking before they decide? People they already know. Parisi describes CISOs going back to the individuals they have had long-term relationships with and sourcing guidance from them before decisions get made. Automation has expanded what can be done, but nobody got more hours in the day to evaluate everything arriving in front of them. The next move he points to is asking the question, either of the engineers at the provider or of a trusted advisor, and getting the configuration aligned to the business outcome it was bought to serve. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Michael Parisi, Chief Growth Officer, Steel Patriot Partners LinkedIn: https://www.linkedin.com/in/michael-parisi-4009b2261/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Steel Patriot Partners: https://www.steelpatriotpartners.com Find Your Path, three questions to start: https://www.steelpatriotpartners.com/find-your-path Steel Patriot Partners Insights: https://resources.steelpatriotpartners.com Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS michael parisi, steel patriot partners, marco ciappelli, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, non-human identities, machine identity, ai risk, security tool configuration, trusted advisor, ciso decision making, cybersecurity engineering, compliance advisory, security tool sprawl, vendor noise Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

ITSPmagazine | Technology. Cybersecurity. Society
Vulnerability, Visibility, and Velocity Shape the Security Roadmap Now | A Recap at Black Hat USA 2026 with Sean Murphy, Field CISO for North America at F5 | Hosted by Marco Ciappelli

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Aug 17, 2026 7:09


Sean Murphy, Field CISO for North America at F5, spent the week behind the scenes at Black Hat USA 2026, in the corridors and at dinner with the CISOs and cybersecurity minded people who fill the halls. Marco Ciappelli caught him at the close of it and asked what the industry learned this year. The answer arrived as three words. Vulnerabilities, and the flattening of the curve between vulnerability, exposure, and exploit. Visibility, because a team cannot defend what it does not know it has. Velocity, which carries the other two. Sean Murphy calls the acceleration a physics problem rather than a technology problem, given the forces and friction now moving through security work. Moore's law is out the window in his framing, and advancement arrives week by week. For a CISO writing a roadmap and defending an investment case for the next six to 18 months, the plan keeps pivoting underneath them. AI shifted just as fast. What was recently understood as hyperscaler sized, built for the largest organizations, is now generative and agentic AI running at the enterprise level, in production rather than in a pilot. That leaves a population question. Agents are identities, non-human identities with permissions and responsibilities, and Sean Murphy points out they are proliferating alongside the human identities already under governance. He also offers a reframe on agents that slip past misconfigured guardrails and go crawling for LLMs and repositories. That is an agent doing exactly what it was told to do, relentlessly, until it succeeds. The work ahead is guardrails and governance over all of that visibility. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Sean Murphy, Field CISO for North America at F5 On LinkedIn: https://www.linkedin.com/in/seanmurphy092009/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Learn more about F5: https://www.f5.com Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS Sean Murphy, F5, Marco Ciappelli, brand briefing, brand story, brand marketing, marketing podcast, Black Hat USA 2026, field CISO, agentic AI, non-human identity, AI governance, guardrails, vulnerability management, security visibility, security roadmap, identity and access management, enterprise AI adoption Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

DGMG Radio
From Startup to IPO: How the CMO of Varonis Has Kept the Same Job for 15 Years, ft. Rob Sobers

DGMG Radio

Play Episode Listen Later Aug 17, 2026 51:33


#382 | Rob Sobers has been CMO of Varonis for 15 years - through its growth from startup to public company doing over $700 million in revenue. Dave talks with Rob about how he's stayed sharp enough to keep the job this long, starting with the fact that as an engineer, he still writes JavaScript and even fixes bugs on the Varonis website from time to time. Rob explains why no manager on his team oversees work they don't do themselves, why he'd rather keep marketing simple than layer on complexity as the company scales, and his "reasonableness test" for deciding which programs don't need to be forced into a pipeline number. They also cover his approach to saying no to his own team, and why longevity gives him a wider lens on the business.Ever listen to our podcast and think: "Exit Five should feature me"? This is your opportunity to get in front of 40k+ B2B marketers, including CMOs, VPs, and marketing leaders, who are looking for talent, inspiration, and ideas to improve their marketing. Apply to the Experts Network for a chance to be our next podcast guest.Timestamps (00:00) - - Meet Rob Sobers, CMO of Varonis for 15 years (01:18) - - Why Rob still writes JavaScript and fixes bugs on the website (05:06) - - Learning a new marketing discipline every time he was out of his depth (05:55) - - Why there are no career middle managers on the Varonis marketing team (07:24) - - The communication tax of overstaffing a team (09:59) - - Keeping goals dead simple: opportunity creation as the north star metric (14:28) - - Getting good at saying no to his own team, but not too good (18:02) - - The reasonableness test: why not everything needs a pipeline number (20:49) - - Reverse-engineering the marketing budget from the revenue number (23:04) - - What separates a CMO from a VP of Marketing (26:26) - - The ClickUp $1M "one-person marketing team" debate (35:26) - - Marketing to skeptical CISOs, acquisitions, and why B2B brands need a mascot Join 50,0000 people who get Dave's Newsletter here: https://www.exitfive.com/newsletterLearn more about Exit Five's private marketing community: https://www.exitfive.com/***Brought to you by:Zoom Webinars & Events – The virtual event platform built to help B2B marketers run webinars that actually drive pipeline, with branded registration pages, live engagement features, and built-in tools to repurpose sessions into clips and content. Learn more at zoom.com/exitfive.Customer.io - An AI powered customer engagement platform that help marketers turn first-party data into engaging customer experiences across email, SMS, and push. Learn more at customer.io/exitfive.Vector - A contact-level ads platform that lets you build audiences from actual people on your site, clicking your ads, and checking out your competitors. Learn how to build an ABM program that scales at vector.co/exitfive.Join us in Stowe, Vermont for Drive 2026 - three days away from your desk to learn what's working in B2B marketing from the people who are actually doing it. Grab your ticket at exitfive.com/drive.Walker Sands - An integrated B2B marketing and growth services agency that helps marketing leaders turn strategy into measurable business impact through their Outcome-based Marketing model. Learn more at walkersands.com/exitfive.***Thanks to my friends at hatch.fm for producing this episode and handling all of the Exit Five podcast production.They give you unlimited podcast editing and strategy for your B2B podcast.Get unlimited podcast editing and on-demand strategy for one low monthly cost. Just upload your episode, and they take care of the rest.Visit hatch.fm to learn more

ITSPmagazine | Technology. Cybersecurity. Society
10,000 Alerts a Day, 75% Cleared With Evidence Analysts Can Check | A Brand Briefing at Black Hat USA 2026 with Seth Summersett, Co-Founder and CEO of Embed Security | Hosted by Sean Martin

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Aug 14, 2026 14:44


Recorded on site at Black Hat USA 2026 in Las Vegas, Seth Summersett joins Sean Martin to talk through the volume problem that shapes a modern security operations team. Seth Summersett spent about a decade at the NSA and roughly a decade at Mandiant, finishing there as head of innovation and custom engineering, then a couple of years at Meta supporting business unit level CISOs. He co-founded Embed Security with Jeffrey Johns, who ran the data science team alongside him at Mandiant. The catalyst came from watching a managed service run on human scale day after day. Two analysts and a hundred forwarded phishing emails means someone is choosing which ones to open and carrying the ones they cannot reach. Embed Security sits downstream of existing detection investments, taking signals from SIEM, EDR, identity, and email rather than asking a team to rip and replace what it already runs. What do security analysts actually want from AI in the SOC? According to Seth Summersett, it is not a verdict. Analysts want the work off their plate in a way they can verify, which is why Embed Security built what it calls chain of evidence, showing every question asked and the path to each conclusion. Teams also test it in reverse, running previously dispositioned alerts back through the platform to compare results against their own analysts. The numbers come from a competitive bake off at one of the company's largest clients. Embed Security dispositioned roughly 75% of that client's alerts to the point where the team stopped treating them as primary work, against a daily volume above 10,000 alerts. Why not build this in house? Seth Summersett says the demo is the easy part. What follows is evaluation loops that measure a change across hundreds of thousands of alerts rather than one, governance, and a way to capture organizational knowledge automatically. In regulated sectors, auditors may ask a team to prove how a conclusion was reached and that it holds consistently. There is a people side to this as well. Embed Security has supported a wellness program at BSides across its last two events, backing a calming kit and curriculum for analysts working under incident pressure. Seth Summersett closes with consistency for leaders, since a leader looking at 10% of alerts does not have a full risk profile, and career longevity for analysts who would rather build a long run in security operations than burn out in two or three years. GUEST Seth Summersett, Co-Founder and CEO, Embed Security LinkedIn: https://www.linkedin.com/in/summersett/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Embed Security: https://www.embedsecurity.com Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS seth summersett, embed security, sean martin, brand story, brand marketing, marketing podcast, brand spotlight, black hat usa 2026, security operations, soc analyst burnout, alert triage, agentic ai security, chain of evidence, siem alert fatigue, edr alerts, ai soc platform, security analyst workflow, build versus buy security ai, security operations governance, threat investigation Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

ITSPmagazine | Technology. Cybersecurity. Society
Agents Get Zero Trust, and the Network Becomes the Sensor | A Brand Briefing at Black Hat USA 2026 with David Hughes, SVP and GM of SASE and Security for Networking at HPE | Hosted by Sean Martin

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Aug 14, 2026 15:48


Most people know HPE for servers, compute, and storage. David Hughes leads a pillar that gets less attention. He runs the SSE and security business inside HPE Networking, which he says accounts for about a third of the company now that HPE has merged with Juniper, and which organizes into four pillars: campus and branch, data center switching, routing infrastructure, and security. Recorded on location at Black Hat USA 2026, the conversation opens on a balancing act Hughes hears constantly. Customers want to push hard on AI adoption while staying protected and avoiding undue risk. The same tension runs between teams. Networking answers for performance and user experience. Security answers for protecting those users and the company's data. HPE's answer is to embed security thinking into the network itself, making it a sensor and an enforcement point for the security team. What happens when users are no longer only people? The identity question moves to devices, workloads, and agents. Hughes frames it as human and non-human identity, and his position is to take the ZTNA architecture that works for people and adapt it, starting with IoT devices, then workloads, then agents. Put an agent in a sandbox and it sees only the subset of resources it is supposed to reach. How do networking and security teams work from the same picture? Through shared visibility and agentic technology across the management layer. HPE is putting agentic technology into how it manages storage, compute, networks, and security products, then meshing those agents together so a wifi complaint that turns out to be a firewall policy change gets to root cause faster, with automatic remediation as the goal. Hughes also covers post-quantum cryptography, where HPE is moving across all product lines to introduce quantum resistant and quantum safe capabilities in hardware and software, with some launched this year and more coming through the following quarters. The deadline arrives earlier than most calendars suggest, because data harvested today can be decrypted later. Rounding it out: HPE Threat Labs, announced earlier in the year with Mounir Hahad's team from Juniper at its core, and AI focused capabilities on the next generation firewalls covering observability, role based governance over which services employees can use, and session level inspection of prompts and responses. Hughes closes with a direct invitation to CISOs who know HPE for compute and networking and have yet to meet the security team. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST David Hughes, SVP and GM of SASE and Security for Networking at HPE On LinkedIn: https://www.linkedin.com/in/david-hughes-42751636/ RESOURCES Black Hat USA 2026 event coverage from ITSPmagazine: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas HPE: https://www.hpe.com/ HPE Threat Labs: https://www.hpe.com/us/en/hpe-labs/threat-labs.html Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS david hughes, hpe, sean martin, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, zero trust, ztna, non-human identity, agentic ai, ai security, post-quantum cryptography, network security, sase, sse, hpe threat labs, self-driving network, firewall governance, juniper, iot security, cross domain troubleshooting Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

ITSPmagazine | Technology. Cybersecurity. Society
Compliance Moves at the Speed of DevOps When Paperwork Writes Itself | A Brand Briefing at Black Hat USA 2026 with Travis Howerton, Co-Founder and CEO at RegScale | Hosted by Sean Martin

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Aug 14, 2026 13:45


Why does compliance paperwork fall behind the systems it describes? Because the systems change faster than the documents. Travis Howerton points to cloud native technologies that spin up and down on demand, which makes describing infrastructure in paperwork something that goes out of date instantly. Add new regulation for third party risk, supply chain, zero trust, and privacy, and an approach that was already expensive and frustrating stops being fit for purpose. RegScale answers that with compliance as code. The company went to NIST and helped write the standard that became OSCAL, the Open Security Controls Assessment Language, then built the capability for machines to attest to their own state using it. Paperwork starts writing itself, and CISOs get risk and compliance outcomes as a byproduct of operational excellence rather than as a separate project. Is automating the evidence trail a shortcut? Travis Howerton argues the opposite. It prevents corner cutting, because the alternative is what he calls compliance theater. An old general he worked for described that as a mother-in-law visit, where you clean the house to a ridiculous standard, everybody goes through the dance, and the moment the visit ends the kids destroy the house again. Where should a security team start automating? Start with what hurts. He tells people to think like a surgeon, who opens by asking the patient what is wrong, then work backwards from the pain. There is no easy button, and the honest starting point is the truth about how fast teams will need to react. That pain usually maps to one of three business drivers. Cut cost, or shift the share of budget going to checklist compliance toward tools that buy down risk. Get real-time assurance. Or earn the reps and certs needed to sell into a market, whether that is FedRAMP for government work or PCI for card data. Compressing those timelines by 70 to 80 percent lets a company get to market faster and grow revenue. The results Travis Howerton cites are specific. One large government agency is touting over $100 million in labor savings, and a Department of War customer with a 52-week end-to-end cycle has compressed it by 36 weeks using RegScale technology alongside other integrated tools. Having tripled, doubled, and doubled again over the last three years, RegScale stays focused on the largest and most complex organizations, with international markets and the energy sector on the horizon. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Travis Howerton, Co-Founder and CEO at RegScale LinkedIn: https://www.linkedin.com/in/travishowerton/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas RegScale: https://regscale.com OSCAL, the Open Security Controls Assessment Language: https://pages.nist.gov/OSCAL/ Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS travis howerton, regscale, sean martin, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, compliance as code, continuous controls monitoring, oscal, grc engineering, fedramp, fisma, authority to operate, ai agents, risk management, cybersecurity compliance Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

ITSPmagazine | Technology. Cybersecurity. Society
The Last Mile of Security Operations Runs on a Local Model | A Full Sponsor Brand Briefing at Black Hat USA 2026 with Karthik Kannan, Founder and CEO at Anvilogic | Hosted by Sean Martin

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Aug 13, 2026 13:26


Recorded on location at Black Hat USA 2026 in Las Vegas at the end of day two, Karthik Kannan, Founder and CEO at Anvilogic, walks through a seven year build that reached its original shape this year. The plan from the start was a full security operations platform covering data, the detection engineering process, triage and investigation, and case management. In the shorthand of the category, SIEM and SOAR combined. It arrived in phases. Detection engineering came first, implemented on top of Splunk for most customers, then the data platform expanded into data lakes including Snowflake, Databricks, and Microsoft Azure. Triage and investigation followed over the last two years. In the last year Anvilogic rolled out agents that carry out the work of specific personas, and this year the company launched Blueprints, an orchestrator agent that brings the discrete agents together to run a whole workflow with humans in the loop. What separates a security graph from a frontier model? It knows the environment. Karthik Kannan describes the enterprise security graph as Anvilogic's own model running inside the network, learning the micro environment, with frontier LLMs called on to fill gaps in the macro environment. His argument is that platforms operating as LLM wrappers miss the last mile, because AI on its own reaches 60, 70, or 80 percent of the way if you are lucky. How does a team keep control when agents run the workflow? Through gates, permissions, and a record of what happened. Workflows can be described in plain English, with human gates inserted as often as the team wants. Access controls sit at the persona, organization, and object levels, and activity is audited and logged, which matters to the GRC teams Anvilogic works with. Screens dedicated to what the company calls a maturity score show which feeds are coming in, what kinds of detections exist, and what coverage looks like against the MITRE ATT&CK framework, in a form available to executives and CISOs. Karthik Kannan also points to version 8.0, introduced the week before the event, which includes an Anvilogic MCP Server for connecting to third party tools. Customers are already building their own Blueprint workflows during proofs of concept, including a large life sciences customer Anvilogic expects to feature in a public case study. Karthik Kannan is careful about the claim being made here. This is not a proclamation of an autonomous SOC. It is automation that makes life in a SOC easier and more efficient, adopted at a crawl, walk, run pace, with every step visible along the way. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Karthik Kannan, Founder and CEO at Anvilogic On LinkedIn: https://www.linkedin.com/in/karthikkannan001/ RESOURCES Black Hat USA 2026 event coverage from ITSPmagazine: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Learn more about Anvilogic: https://www.anvilogic.com Anvilogic 8.0, from onboarding to investigation: https://www.anvilogic.com/learn/anvilogic-8-0-automate-the-soc Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS karthik kannan, anvilogic, sean martin, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, agentic secops, ai soc platform, enterprise security graph, detection engineering, triage and investigation, blueprints orchestrator agent, mcp server, mitre att&ck coverage, human in the loop automation, siem and soar, security operations, grc audit logs Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Fraudology Podcast
Organizational Convergence for Fraud: New Benchmarks and What Actually Works

Fraudology Podcast

Play Episode Listen Later Aug 13, 2026 57:40


Welcome back to Fraudology.Today's a solo episode built around a study that puts a real number on something fraud leaders have been debating for years: does organizational convergence for fraud actually move the needle on performance, or is it just an org chart trend?For years, we've all benchmarked ourselves the same way. Approval rate here, chargeback rate there, maybe a manual review rate if we're being thorough. But the problem I've seen play out in company after company is this: optimize your approval rate, and your chargeback rate quietly creeps up. Optimize your chargeback rate by blocking more, and your approval rate takes the hit. You're never seeing the whole picture, just one lever moving at the expense of the other.The Precise Yes metric is the headline finding from a new Liminal and Accertify study, but the study itself is much bigger than one metric. It surveyed 250 senior fraud, security, and risk leaders across five industry verticals specifically to test the thesis of organizational convergence for fraud and cybersecurity. I walk through what the data says, what forms of convergence actually improve fraud performance, and which ones don't move the needle at all.This is a data-heavy episode, and I mean that as a compliment to the study. If you've ever needed a fraud KPI for CFO reporting that actually captures the full tradeoff between approvals and fraud loss, this is the one to bring back to your team. What you'll hear in this episode:How the Precise Yes metric is calculated, and why approval rate vs chargeback rate alone can hide the real story of your fraud programWhy organizational convergence for fraud and cybersecurity is being driven by operational necessity, not executive mandates, and what that means for how teams are actually changingWhy login has become the new fraud control point, with account takeover, credential stuffing, and bot attacks all converging at that stageWhy 63.6% of organizations still cannot distinguish a cyber attack from a fraud attack in real time, and what that costs them operationallyHow CISO fraud ownership is showing up earlier in the vendor decision process, and why board level fraud reporting is becoming a real governance topicWhy partial integration is the highest-performing model for organizational convergence for fraud, and why pushing to full structural integration can actually erode the domain expertise that makes teams effectiveWhy sharing just two or more use cases between fraud and cyber teams is the real performance tipping point, delivering a 1.5x improvement in fraud performance scoresWhy separate budgets between fraud and cyber teams actually outperform unified ones, contradicting one of the most common assumptions about convergenceHow fraud metrics by industry vertical vary, including why ecommerce and retail lead the pack while marketplaces lag significantly behindWhat the study found on agentic commerce fraud controls and synthetic identity fraud in ecommerce specificallyWho should listen:Fraud leaders looking for a fraud KPI for CFO reporting that captures the real tradeoff between approvals and fraud loss.Anyone building a business case for fraud and cybersecurity convergence and needing real data to support it.CISOs and security leaders increasingly involved in fraud tool evaluation and vendor decisions.Fraud teams trying to figure out where to start with shared fraud and cyber use cases without a full reorg.Ecommerce and marketplace fraud professionals wanting an ecommerce fraud benchmarking study to compare their own performance against.Anyone responsible for board level fraud reporting or making the case for fraud visibility at the executive level.

@BEERISAC: CPS/ICS Security Podcast Playlist
Your Most Critical Network May Be Your Least Protected

@BEERISAC: CPS/ICS Security Podcast Playlist

Play Episode Listen Later Aug 13, 2026 33:22


Podcast: Industrial Cybersecurity InsiderEpisode: Your Most Critical Network May Be Your Least ProtectedPub date: 2026-08-11Get Podcast Transcript →powered by Listen411 - fast audio-to-text and summarizationThe air gap you're counting on probably isn't there. Dino Busalacchi sits down with cybersecurity veteran and Tulane University Cybersecurity Professor Joshua Copeland, to talk about the realities of protecting industrial environments, where uptime, safety, and production come first. They dig into why legacy systems can't be secured like IT, how routine security tasks can disrupt physical operations, the leadership gap between IT and OT, and why cybersecurity needs to be treated as digital safety. A practical listen for CISOs, CIOs, engineering leaders, and plant operators.Chapters:(00:00:00) Why operational technology is critical to everyday life(00:03:00) Legacy systems and the hidden opportunity in OT security(00:07:00) Ransomware, AI, and attacks designed for physical outcomes(00:10:00) How standard IT security tools can stop production(00:13:00) What cybersecurity events get wrong about OT(00:16:00) The leadership gap and the myth of isolated systems(00:20:00) Why cybersecurity should be treated as digital safety(00:23:00) Compliance, asset inventory, and aging industrial equipment(00:27:00) Building the next generation of OT security professionals(00:31:00) Why every part of modern life depends on OTLinks And Resources:Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityJosh Copeland on LinkedInDino Busalachi on LinkedInCraig Duckworth on LinkedInThanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you'd like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review!The podcast and artwork embedded on this page are from Industrial Cybersecurity Insider, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.

Paul's Security Weekly
Domain Security Plus BlackHat USA 2026 Interviews from Balance Theory and WiCyS - Greg Baker, Ihab Shraim, Lynn Dohm - BSW #460

Paul's Security Weekly

Play Episode Listen Later Aug 12, 2026 67:34


As cyber threats become more AI-powered, attacks continue to rise. Threats can arise from all areas of a company's IT infrastructure, however most attacks utilize a domain name to infiltrate systems. How secure is your domain ecosystem? Ihab Shraim, Chief Technology Offider at CSC Digital Brand Services, joins Business Security Weekly to discuss why domain security is a fundamental blind spot in corporate cybersecurity programs. Ihab will discuss his team's research finding that 67% of Forbes Global 2000 companies have implemented fewer than half of recommended domain security measures. He will also outline the key domain security practices that teams should implement to protect their organization from the risk of domain attacks. Segment Resources: CSC 2026 Domain Security Report: https://www.cscdbs.com/en/resources/domain-security-report-2026/ CSC 2026 CISO Outlook Report: https://www.cscdbs.com/en/resources/ciso-outlook-2026-report/ How AI Is Reshaping What's Possible for Leaders of The Security Program - Black Hat Interview with Greg Baker, Co-founder and CEO of Balance Theory Cybersecurity leaders are still making high-stakes decisions with fragmented data, static assessments, and market guidance that is often slow, expensive, or commercially biased. Greg Baker will explore how AI can create a continuously updated understanding of both the enterprise security program and the market around it—giving CISOs the context to model scenarios, prioritize investments, and move from insight to action with greater speed and confidence. For more information about Balance Theory, please visit: https://securityweekly.com/balancetheorybh The Business Case for Cybersecurity Workforce Resilience - Black Hat Interview with Lynn Dohm, Executive Director of WiCyS The joint report from WiCyS and FourOne Insights reveals that mentorship, skills-based promotion, and third-party partnerships don't just improve workforce outcomes — they deliver measurable ROI, including more than $125,000 in savings per employee. As cybersecurity leaders grapple with persistent talent shortages, AI-driven skill shifts, and demographic headwinds, the report positions workforce resilience as a measurable business advantage — not just an HR initiative. Segment Resources: https://www.wicys.org/resources/the-roi-of-resilience/ https://www.wicys.org/initiatives/the-wicys-cyber-talent-study/ This segment is sponsored by Women in CyberSecurity (WiCyS). Visit https://securityweekly.com/wicysbh to learn more about them! Visit https://www.securityweekly.com/bsw for all the latest episodes! Show Notes: https://securityweekly.com/bsw-460

ITSPmagazine | Technology. Cybersecurity. Society
Autonomous Remediation Is Already Running at Enterprise Scale | A Full Sponsor Brand Briefing at Black Hat USA 2026 with Sumedh Thakar, President and CEO at Qualys | Hosted by Sean Martin

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Aug 12, 2026 11:22


Sumedh Thakar joined Qualys as an early software engineer on the scanner, back when a 90-day scan cycle came with another 90 days to fix whatever it found. Twenty-three years later he leads the company, and the number he uses now is 90 seconds. At Black Hat USA 2026 he walks through what that compression asks of security teams. So what has actually changed? The questions have not. Where are my assets, what is my assessment of them, what do I prioritize, and what do I fix. Thakar points at the clock instead, citing a CISA directive that gives government agencies three days and zero-day conversations built around a 24-hour window. Layering dashboards on top of that produces what he calls dashboard tourism when nothing gets fixed at the end of it. Qualys organizes its response around three pillars. AI speed detection compresses the gap between a vendor disclosure and a confirmed finding. Hyper prioritization runs an actual exploit to see whether firewall and EDR controls already block it, cutting a theoretical 1% down to roughly 20% of that 1%. Autonomous remediation applies the fix without routing it through a human first. How far along is autonomous patching already? Qualys has deployed over half a billion patches, 150 million of them in the past 12 months, and 40 million of those went out with no human intervention. Thakar describes a global company with 450,000 employees running the agent for autonomous patching, where the board metric is a maximum four-hour exposure window from the time a patch is released rather than a count of vulnerabilities. He expects the monthly patch cadence to give way as disclosures accelerate. Qualys recently released InstaScan, which Thakar calls scanless scanning, delivering a finding within an hour of a vendor disclosure. A patch reliability score built using AI lets an agent judge whether a patch is dependable and reboot-free before applying it on a laptop. His closing advice to CISOs is to show up as a business partner. The board and the CEO need visibility into potential loss, current spend, and whether risk sits inside an acceptable appetite. For a $500 million business that means pricing what a breach would cost, funding the reduction of an $80 million exposure, and transferring what remains to cyber insurance. His shorthand for the operating model is the ROC alongside the SOC. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Sumedh Thakar, President and CEO at Qualys On LinkedIn: https://www.linkedin.com/in/sumedhthakar/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Qualys: https://www.qualys.com/ InstaScan announcement: https://www.qualys.com/company/newsroom/news-releases/usa/qualys-launches-instascan-to-detect-vulnerabilities-within-minutes-of-disclosure Agent Insta and scanless detection: https://blog.qualys.com/product-tech/2026/08/03/instascan-agent-insta-scanless-detection The Risk Operations Center with Enterprise TruRisk Management: https://blog.qualys.com/product-tech/2024/10/09/qualys-launches-enterprise-trurisk-management-the-industrys-first-cloud-based-risk-operations-center Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS Sumedh Thakar, Qualys, Sean Martin, brand briefing, brand story, brand marketing, marketing podcast, Black Hat USA 2026, autonomous remediation, patch management, vulnerability management, hyper prioritization, AI speed detection, scanless scanning, InstaScan, risk operations center, cyber risk management, zero day remediation, CISO, exposure management Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Cybercrime Magazine Podcast
Cybercrime Wire For Aug 12, 2026. Ransomware Group Hijacks Hospital's Facebook. WCYB Digital Radio.

Cybercrime Magazine Podcast

Play Episode Listen Later Aug 12, 2026 1:15


The Cybercrime Wire, hosted by Scott Schober, provides boardroom and C-suite executives, CIOs, CSOs, CISOs, IT executives and cybersecurity professionals with a breaking news story we're following. If there's a cyberattack, hack, or data breach you should know about, then we're on it. Listen to the podcast daily and hear it every hour on WCYB. The Cybercrime Wire is brought to you Cybercrime Magazine, Page ONE for Cybersecurity at https://cybercrimemagazine.com. • For more breaking news, visit https://cybercrimewire.com

Paul's Security Weekly TV
Domain Security Plus BlackHat USA 2026 Interviews from Balance Theory and WiCyS - Ihab Shraim, Greg Baker, Lynn Dohm - BSW #460

Paul's Security Weekly TV

Play Episode Listen Later Aug 12, 2026 67:34


As cyber threats become more AI-powered, attacks continue to rise. Threats can arise from all areas of a company's IT infrastructure, however most attacks utilize a domain name to infiltrate systems. How secure is your domain ecosystem? Ihab Shraim, Chief Technology Offider at CSC Digital Brand Services, joins Business Security Weekly to discuss why domain security is a fundamental blind spot in corporate cybersecurity programs. Ihab will discuss his team's research finding that 67% of Forbes Global 2000 companies have implemented fewer than half of recommended domain security measures. He will also outline the key domain security practices that teams should implement to protect their organization from the risk of domain attacks. Segment Resources: CSC 2026 Domain Security Report: https://www.cscdbs.com/en/resources/domain-security-report-2026/ CSC 2026 CISO Outlook Report: https://www.cscdbs.com/en/resources/ciso-outlook-2026-report/ How AI Is Reshaping What's Possible for Leaders of The Security Program - Black Hat Interview with Greg Baker, Co-founder and CEO of Balance Theory Cybersecurity leaders are still making high-stakes decisions with fragmented data, static assessments, and market guidance that is often slow, expensive, or commercially biased. Greg Baker will explore how AI can create a continuously updated understanding of both the enterprise security program and the market around it—giving CISOs the context to model scenarios, prioritize investments, and move from insight to action with greater speed and confidence. For more information about Balance Theory, please visit: https://securityweekly.com/balancetheorybh The Business Case for Cybersecurity Workforce Resilience - Black Hat Interview with Lynn Dohm, Executive Director of WiCyS The joint report from WiCyS and FourOne Insights reveals that mentorship, skills-based promotion, and third-party partnerships don't just improve workforce outcomes — they deliver measurable ROI, including more than $125,000 in savings per employee. As cybersecurity leaders grapple with persistent talent shortages, AI-driven skill shifts, and demographic headwinds, the report positions workforce resilience as a measurable business advantage — not just an HR initiative. Segment Resources: https://www.wicys.org/resources/the-roi-of-resilience/ https://www.wicys.org/initiatives/the-wicys-cyber-talent-study/ This segment is sponsored by Women in CyberSecurity (WiCyS). Visit https://securityweekly.com/wicysbh to learn more about them! Show Notes: https://securityweekly.com/bsw-460

Business Security Weekly (Audio)
Domain Security Plus BlackHat USA 2026 Interviews from Balance Theory and WiCyS - Greg Baker, Ihab Shraim, Lynn Dohm - BSW #460

Business Security Weekly (Audio)

Play Episode Listen Later Aug 12, 2026 67:34


As cyber threats become more AI-powered, attacks continue to rise. Threats can arise from all areas of a company's IT infrastructure, however most attacks utilize a domain name to infiltrate systems. How secure is your domain ecosystem? Ihab Shraim, Chief Technology Offider at CSC Digital Brand Services, joins Business Security Weekly to discuss why domain security is a fundamental blind spot in corporate cybersecurity programs. Ihab will discuss his team's research finding that 67% of Forbes Global 2000 companies have implemented fewer than half of recommended domain security measures. He will also outline the key domain security practices that teams should implement to protect their organization from the risk of domain attacks. Segment Resources: CSC 2026 Domain Security Report: https://www.cscdbs.com/en/resources/domain-security-report-2026/ CSC 2026 CISO Outlook Report: https://www.cscdbs.com/en/resources/ciso-outlook-2026-report/ How AI Is Reshaping What's Possible for Leaders of The Security Program - Black Hat Interview with Greg Baker, Co-founder and CEO of Balance Theory Cybersecurity leaders are still making high-stakes decisions with fragmented data, static assessments, and market guidance that is often slow, expensive, or commercially biased. Greg Baker will explore how AI can create a continuously updated understanding of both the enterprise security program and the market around it—giving CISOs the context to model scenarios, prioritize investments, and move from insight to action with greater speed and confidence. For more information about Balance Theory, please visit: https://securityweekly.com/balancetheorybh The Business Case for Cybersecurity Workforce Resilience - Black Hat Interview with Lynn Dohm, Executive Director of WiCyS The joint report from WiCyS and FourOne Insights reveals that mentorship, skills-based promotion, and third-party partnerships don't just improve workforce outcomes — they deliver measurable ROI, including more than $125,000 in savings per employee. As cybersecurity leaders grapple with persistent talent shortages, AI-driven skill shifts, and demographic headwinds, the report positions workforce resilience as a measurable business advantage — not just an HR initiative. Segment Resources: https://www.wicys.org/resources/the-roi-of-resilience/ https://www.wicys.org/initiatives/the-wicys-cyber-talent-study/ This segment is sponsored by Women in CyberSecurity (WiCyS). Visit https://securityweekly.com/wicysbh to learn more about them! Visit https://www.securityweekly.com/bsw for all the latest episodes! Show Notes: https://securityweekly.com/bsw-460

Future of Data and AI
Dan Maloney on Visual AI, Agentic Document Extraction & Building Trust in Enterprise AI | Episode 11

Future of Data and AI

Play Episode Listen Later Aug 12, 2026 77:46


OCR has been around for more than 40 years. So why do the world's biggest banks still have thousands of people reading documents by hand? When Dan Maloney became CEO of Landing AI in 2024, as Andrew Ng stepped back from the day-to-day, he was returning to a problem he had first worked on at SAP back in 2001. When he looked closely at it again two decades later, he was struck by how little it had actually moved. Landing AI's mission is to make the world's documents computable. Instead of growing up from OCR and patching its limits with templates and heuristics, Landing AI came at the problem from visual AI, blending purpose-built models, an intelligent router, and agentic reasoning into a single system that reads a document the way a person does. Today that system extracts structured data from the messiest documents enterprises have, the scanned pages, the tables inside tables, the handwritten forms, at accuracy levels they can build on. Before every enterprise had an AI strategy... Before "agentic" became a boardroom word... Before the industry spent a year token maxing... There was a quieter, more stubborn problem: The world's data was trapped in documents, and no one could read it at scale. In this episode of the Future of Data & AI Podcast, Dan Maloney, CEO of Landing AI and a two-decade veteran of enterprise software and AI, joins Raja Iqbal for a grounded conversation about what it actually takes to move visual AI from an impressive demo into production. Dan is candid about where the hype outruns reality, why the model is the smallest part of the equation, and how a company earns the trust of a compliance team, not just an engineering one. What You'll Discover

Business Security Weekly (Video)
Domain Security Plus BlackHat USA 2026 Interviews from Balance Theory and WiCyS - Ihab Shraim, Greg Baker, Lynn Dohm - BSW #460

Business Security Weekly (Video)

Play Episode Listen Later Aug 12, 2026 67:34


As cyber threats become more AI-powered, attacks continue to rise. Threats can arise from all areas of a company's IT infrastructure, however most attacks utilize a domain name to infiltrate systems. How secure is your domain ecosystem? Ihab Shraim, Chief Technology Offider at CSC Digital Brand Services, joins Business Security Weekly to discuss why domain security is a fundamental blind spot in corporate cybersecurity programs. Ihab will discuss his team's research finding that 67% of Forbes Global 2000 companies have implemented fewer than half of recommended domain security measures. He will also outline the key domain security practices that teams should implement to protect their organization from the risk of domain attacks. Segment Resources: CSC 2026 Domain Security Report: https://www.cscdbs.com/en/resources/domain-security-report-2026/ CSC 2026 CISO Outlook Report: https://www.cscdbs.com/en/resources/ciso-outlook-2026-report/ How AI Is Reshaping What's Possible for Leaders of The Security Program - Black Hat Interview with Greg Baker, Co-founder and CEO of Balance Theory Cybersecurity leaders are still making high-stakes decisions with fragmented data, static assessments, and market guidance that is often slow, expensive, or commercially biased. Greg Baker will explore how AI can create a continuously updated understanding of both the enterprise security program and the market around it—giving CISOs the context to model scenarios, prioritize investments, and move from insight to action with greater speed and confidence. For more information about Balance Theory, please visit: https://securityweekly.com/balancetheorybh The Business Case for Cybersecurity Workforce Resilience - Black Hat Interview with Lynn Dohm, Executive Director of WiCyS The joint report from WiCyS and FourOne Insights reveals that mentorship, skills-based promotion, and third-party partnerships don't just improve workforce outcomes — they deliver measurable ROI, including more than $125,000 in savings per employee. As cybersecurity leaders grapple with persistent talent shortages, AI-driven skill shifts, and demographic headwinds, the report positions workforce resilience as a measurable business advantage — not just an HR initiative. Segment Resources: https://www.wicys.org/resources/the-roi-of-resilience/ https://www.wicys.org/initiatives/the-wicys-cyber-talent-study/ This segment is sponsored by Women in CyberSecurity (WiCyS). Visit https://securityweekly.com/wicysbh to learn more about them! Show Notes: https://securityweekly.com/bsw-460

The Tech Blog Writer Podcast
AI Agent Security: Why Identity and Access Control Matter More Than Guardrails

The Tech Blog Writer Podcast

Play Episode Listen Later Aug 11, 2026 24:49


What happens when an AI agent is compromised, manipulated, or simply does something nobody expected, but already has permission to access your most sensitive systems? In this episode of Tech Talks Daily, I speak with Geoffrey Mattson, CEO of SecureAuth, about why securing enterprise AI requires businesses to think beyond protecting models and start paying much closer attention to identity, authorization, access control, and what AI agents are actually allowed to do. Geoffrey argues that AI agents present a different security challenge from traditional software. Conventional applications can be tested against relatively predictable behavior. AI models are far less deterministic, particularly when prompt injection, excessive permissions, unexpected behavior, and autonomous actions enter the equation. His advice is to assume an agent could behave unpredictably and control what happens when it attempts to access a database, execute a financial transaction, call an API, or interact with another business system. We discuss what this means as companies race to introduce agentic AI. Geoffrey shares examples of employees granting AI tools permissions without fully understanding what they have approved, along with agents gathering information that creates unexpected privacy and compliance problems. This creates a difficult challenge for CIOs and CISOs. Boards want AI adoption because of its potential competitive value, while employees increasingly depend on AI tools to do their jobs. Simply blocking agents is unlikely to work. Security teams instead need mechanisms that allow innovation while controlling what those agents can access. Geoffrey explains why Zero Trust becomes particularly relevant here. Rather than authenticating a user or agent once and assuming it remains trustworthy, enterprises need to continually evaluate whether an action should be permitted at that specific moment. This leads to the concept of continuous authorization. Geoffrey explains how identity security is moving from asking "Who are you?" toward understanding intent, behavior, context, and authority for individual actions. This becomes increasingly important when one AI agent can create sub-agents, which can then create additional agents and pass permissions down the chain. We also discuss why agentic AI is exposing years of accumulated security debt. Many of the underlying problems are familiar: excessive privileges, inconsistent access controls, incomplete Zero Trust implementations, and systems that trust identities for too long. AI agents amplify those weaknesses because they can operate at machine speed. Geoffrey describes this as combining the unpredictability of humans with the power of machines. For CIOs, CISOs, security architects, identity teams, and business leaders deploying agentic AI, this conversation offers practical questions to ask before connecting agents to enterprise resources. What can the agent access? What authority does it have? Can that authority be reduced as tasks are delegated? Is every important action evaluated independently? And can access be revoked immediately when behavior changes? The goal is not to prevent organizations from using AI agents. It is to create a security layer that gives developers and employees room to experiment while ensuring agents only have the authority they need at the moment they need it. As autonomous AI becomes part of the enterprise workforce, identity alone may no longer be enough. Businesses increasingly need to understand intent, control authority, and continuously decide whether the next action should be allowed.

ITSPmagazine | Technology. Cybersecurity. Society
AI Has Its Own Supply Chain | A Full Sponsor Brand Briefing at Black Hat USA 2026 with Daniel Bardenstein, CEO and Co-Founder of Manifest Cyber | Hosted by Sean Martin

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Aug 11, 2026 13:05


At Black Hat USA 2026 in Las Vegas, Daniel Bardenstein, CEO and co-founder of Manifest Cyber, starts with a gap his team measured in a survey of security leaders and practitioners. Leadership described one version of what is happening with AI inside the enterprise. The people doing the hands-on work described another. Adoption keeps moving, and security teams are working to catch up. So what is the real risk in AI security? Bardenstein puts less weight on non-determinism than most and more on ordinary poor software security, because AI is software. He walks through the OpenAI and Hugging Face incident, where models got out of sandboxes because the sandboxing was weak and the guardrails were missing. When Hugging Face went to use its own AI to defend and run forensics, the guardrails read the request as cyber activity and declined. That fallback to an open weight model points to why he expects open weight adoption to accelerate. With frontier models, the provider sets the system prompt and treats it as intellectual property, so development teams inherit whatever was decided upstream. Open weight leaves more room to control the system prompt, the training data, and how the model gets deployed. What does it mean to say AI has its own supply chain? Unless an organization controls how training data is sourced, housed, labeled, tagged, and modified, it is relying on something someone else built. Public datasets carry whatever is inside them, including personal and health data, licensing exposure, and material no one examined until models were trained and deployed. Models hosted on public hubs sit in the same category. Two asks come up in most CISO conversations with Manifest Cyber. Visibility is one, and few organizations have an AI inventory covering which models run where, inside which applications, and which agents teams have stood up on their own. Third party risk is the other, since AI is getting built into vendor products whether a buyer asks for it or not. That turns model provenance into a trust question about the vendor. Bardenstein started Manifest Cyber four years ago after responding to Log4Shell from the Pentagon, where the question was where one affected piece of code was running across everything the organization had built and bought. Years later, he finds few security leaders who could answer that question quickly about a poisoned model or dataset. His advice for CISOs is to know what is inside what the organization builds and buys, with particular attention to the parts it does not build. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUEST Daniel Bardenstein, CEO and Co-Founder, Manifest Cyber On LinkedIn: https://www.linkedin.com/in/bardenstein/ RESOURCES View all of our Black Hat USA 2026 coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Learn more about Manifest Cyber: https://www.manifestcyber.com Beyond the Black Box: How AI is Forcing a Rethink of Software Supply Chain (research report): https://www.manifestcyber.com/beyond-the-black-box-ai-report Manifest Cyber on LinkedIn: https://www.linkedin.com/company/manifestcyber/ Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS daniel bardenstein, manifest cyber, sean martin, brand story, brand marketing, marketing podcast, brand spotlight, ai supply chain security, software supply chain security, ai inventory, shadow ai, third party cyber risk, open weight models, frontier models, model provenance, hugging face, log4shell, ciso, agentic ai, black hat usa 2026 Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

ITSPmagazine | Technology. Cybersecurity. Society
The Budget Is Already Spent. The ROI Is in the Configuration. | A Full Sponsor Brand Briefing at Black Hat USA 2026 with Michael Parisi, Chief Growth Officer of Steel Patriot Partners | Hosted by Sean Martin

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Aug 11, 2026 17:12


Automation and AI have flooded the sales and marketing side of the market, and Michael Parisi, Chief Growth Officer at Steel Patriot Partners, says the security leaders on the receiving end were already past capacity. The pitch tends to lead with the product rather than the problem. So many CISOs have stopped taking direct sales calls and started asking a different question: what VAR do you work with, and who can I buy you through? That routing puts weight back on partners who know where a program has been and how to move it forward. Parisi describes a partner meeting during the week with RegScale and Wiz, with Steel Patriot Partners in the services role, and the recognition that the company is moving toward systems integration with engineering at the center. Software providers can supply the product. Aligning and configuring it against a specific set of business expectations is a different job. What happens when that job has no owner? Tools get bought and the return never shows up. Parisi sees organizations spending on best of breed and failing to recognize ROI because the tools are not being used or configured against the business objective. The correction is engineering work rather than another purchase. One client was told by its board to cut a significant portion of the IT and information security budget. Steel Patriot Partners looked for overlap, found three tools accomplishing the same business outcome, met the number, and exceeded it on cost savings. Parisi attributes the underlying problem to years of deferred maintenance on the stack, from teams with the appetite to buy tools and without the time to configure them. He expects the consolidation the cloud market saw a decade ago to reach cybersecurity tooling and GRC, and puts a number on it: 48 main GRC providers today, roughly five within five years. Good enough, configured appropriately, beats best of breed sitting idle. For CISOs building the next budget cycle, Parisi recommends bringing the sourcing closer in. Go to your anchor partners, ask what they are running next year and what worked this year, and skip the attempt to talk to everybody. Steel Patriot Partners co-founder Jason Ford has a line that fits alongside it. Have an open mind. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUEST Michael Parisi, Chief Growth Officer, Steel Patriot Partners LinkedIn: https://www.linkedin.com/in/michael-parisi-4009b2261/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Steel Patriot Partners: https://www.steelpatriotpartners.com Steel Patriot Partners at Black Hat USA 2026: https://www.steelpatriotpartners.com/events/black-hat-usa-2026 Steel Patriot Partners Insights: https://resources.steelpatriotpartners.com Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS michael parisi, steel patriot partners, sean martin, brand story, brand marketing, marketing podcast, brand spotlight, black hat usa 2026, ciso budget, channel partners, var, systems integrator, grc consolidation, security tool sprawl, licensing costs, roi, configuration, compliance, cybersecurity engineering, regscale, wiz Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Resilient Cyber
Building a System of Truth for the CISO

Resilient Cyber

Play Episode Listen Later Aug 11, 2026 31:04 Transcription Available


CISOs have a stack of tools but no system built to run the security program itself. Mike Armistead wants to fix that.In this episode I sit down with Mike Armistead, co-founder and CEO of Pulse Security AI and a longtime security founder behind Fortify and Respond Software. We dig into why the security leader has never had a system of truth the way the CFO has an ERP and the CRO has a CRM, and how an agentic layer on top of the existing tools can finally close that gap. Mike is measured about where AI gets to decide and where the human stays in the seat, and he shares what surprised him most from research with more than 80 senior practitioners and corporate directors.In this episode:- Why two exits later Mike came back to build a third company around the AI wave- The silos that left CISOs with an acronym soup of tools and no way to run the program- What a system of truth for the CISO actually means and how it layers on top of existing structured and unstructured data- Where agents do the heavy lifting on regulatory monitoring, vendor intelligence, and status reporting- Governing the guardrails, not the keystrokes, and why closing the loop still involves people- What corporate directors actually want to hear in the 15 to 20 minutes a CISO gets each quarter- The findings that stood out, including that 55% of boards have never defined the cyber risk they are willing to accept, and only 12.5% of CISOs are very confident the board leaves with a true picture of the risk- Institutionalizing the tribal knowledge every security program runs onChapters:0:00 Intro0:18 Mike's background and two prior exits1:08 Why the AI wave pulled him back2:21 Why the CISO has no system to run the program4:09 Starting at the program level, not the SOC or AppSec5:28 What a system of truth for the CISO means8:19 Speaking the language of the business9:09 Where AI does the heavy lifting on a typical Tuesday11:57 Govern the guardrails, not the keystrokes15:44 Bringing deputies into the conversation16:46 What the research with senior practitioners found20:37 Boards, risk tolerance, and the reporting gap24:57 AI as a double-edged sword for security leaders25:35 Joanna Burkey and institutionalizing tribal knowledge27:31 A year from now for the security leaderGuest links:Mike Armistead on LinkedInPulse Security on AIMore Resilient Cyber:Substack: https://www.resilientcyber.ioSubscribe for more conversations with security practitioners and leaders.

Cybercrime Magazine Podcast
Cybercrime Wire For Aug 11, 2026. Ransomware Attack On Big Canadian Hospital. WCYB Digital Radio.

Cybercrime Magazine Podcast

Play Episode Listen Later Aug 11, 2026 1:21


The Cybercrime Wire, hosted by Scott Schober, provides boardroom and C-suite executives, CIOs, CSOs, CISOs, IT executives and cybersecurity professionals with a breaking news story we're following. If there's a cyberattack, hack, or data breach you should know about, then we're on it. Listen to the podcast daily and hear it every hour on WCYB. The Cybercrime Wire is brought to you Cybercrime Magazine, Page ONE for Cybersecurity at https://cybercrimemagazine.com. • For more breaking news, visit https://cybercrimewire.com

Chattinn Cyber
AI, Risk, and the Future of Compliance: Richa Kaul on How Enterprises Can Keep Up

Chattinn Cyber

Play Episode Listen Later Aug 11, 2026 9:51


Summary Today Marc is chattin' with Richa Kaul, founder and CEO of an AI-based compliance automation platform. The conversation centered on how AI is reshaping enterprise governance, risk, and compliance (GRC), especially by helping organizations handle growing complexity without simply adding more headcount. The discussion quickly focused on how compliance teams can use automation and AI to streamline vendor risk, regulatory requirements, and other time-consuming workflows. Richa explained that his approach starts by separating what truly requires human judgment from what can be automated. A major theme was the mismatch between the speed of modern risk and the pace at which organizations can hire. Richa argued that risk is increasing faster than teams can scale, making it unrealistic to solve GRC challenges by just expanding staff. Instead, she framed the real question as what work should remain with humans and what work can be handled by AI or automation. She emphasized that teams are bogged down by urgent audit prep, repetitive tasks, and reactive “fire drills,” which prevents them from focusing on strategic risk reduction. The chat then moved into visibility and granularity in risk management, particularly around privacy. Richa noted that many CISOs and GRC leaders lack sufficient visibility into their organization's risks, especially because privacy is cross-functional and touches employees, users, operations, and regulatory obligations. She said this lack of clarity makes it difficult for leaders to confidently communicate risk to boards or determine where to invest time and resources. In her view, the biggest issue is not just managing risk, but being able to see it clearly enough to act on it. Another key topic was AI governance. Richa pointed out that many companies are paying attention to AI policy at the top level, but are not doing enough to train employees at the operational level, where mistakes are most likely to happen. She described the “last mile” of AI governance as especially vulnerable, since employees may unknowingly expose proprietary information by entering sensitive data into tools like GPT. According to Richa, human behavior is often the weakest link, and effective governance requires education and training throughout the organization, not just policy statements from leadership. Their chat also touched on industry-specific risk, with healthcare highlighted as a major area of concern. Richa said healthcare compliance appears underinvested compared with financial services, even though both are highly regulated and handle highly sensitive data. She closed by offering a practical starting point for companies facing generative AI challenges: map your most important data, follow it from input to output, identify the systems it touches, and secure each step of the journey. His overall message was optimistic — that even though the risk landscape feels overwhelming, organizations have tools, platforms, and partners that can help them manage it more effectively. Key Points AI can reduce compliance burden by automating repetitive GRC tasks. Organizations can't hire fast enough to keep up with rising risk and regulatory complexity. Many leaders lack clear visibility into privacy and cross-functional risk. AI governance fails most often at the employee level, not just the policy level. Healthcare compliance is highly exposed and may be underinvested relative to its risk. Key Quotes “Risk right now is increasing at a speed and at a rate that teams cannot possibly hire to mitigate.” “It is not the question of, should teams get smaller. I think it’s a question of what work should humans be doing and what work can I do instead.” “A lot of CISOs tell me that they don’t have the visibility, or at least the granularity of visibility into their risks that they would like.” “Humans are the weakest link.” “Don’t you need to boil the ocean, but let’s look at what is your highest risk data.” About Our Guest Richa Kaul is a technology executive and Head of Product Engineering: Strategy, AI Builder, and Cloud & AI Enterprise Transformation, with 20+ years of experience leading cloud, data, and AI initiatives across Fortune 500 organizations. She has managed portfolios as large as $2B in revenue and $300M in operating budgets, while building global teams of 100+ and advising CxOs on enterprise AI and financial strategy. Richa is known for driving GenAI adoption, modernizing data platforms, advancing AI governance, and delivering scalable, cost-effective transformation across banking, capital markets, asset management, and wealth management. Follow Our Guest LinkedIn About Our Host National co-chair of the Cyber Center for Excellence, Marc Schein, CIC,CLCS is also a Risk Management Consultant at Marsh McLennan Agency. He assists clients by customizing comprehensive commercial insurance programs that minimize the burden of financial loss through cost effective transfer of risk. By conducting a Total Cost of Risk (TCoR) assessment, he can determine any gaps in coverage. As part of an effective risk management insurance team, Marc collaborates with senior risk consultants, certified insurance counselors, and expert underwriters to examine the adequacy of existing client programs and develop customized solutions to transfer risk, improve coverage and minimize premiums. Follow Our Host Website | LinkedIn

Interviews: Tech and Business
Enterprise AI Biggest Opportunities: A Top VC's Take

Interviews: Tech and Business

Play Episode Listen Later Aug 10, 2026 55:22


Enterprise AI has moved past experimentation and now has to prove its return. Ed Sim, Founder and General Partner of boldstart ventures, ranked the No. 1 seed investor in the Business Insider Seed 100 two years running, sees hundreds of AI startup pitches a year, and writes the first check into companies enterprises buy from years later. He wrote the first check into Snyk and backed Protect AI, which Palo Alto Networks acquired for more than $700 million. In this conversation, he lays out the three waves of enterprise AI adoption, why rising token costs are pushing companies toward open-weight models and their own hardware, how agent identity and access create a new attack surface, and what separates AI vendors that survive a shakeout from the ones that do not.YOU'LL DISCOVER✅ The three waves of enterprise AI: get AI running, get agents running, and the wave happening now, where ROI and tokenomics decide what survives✅ Why Ed expects dozens of models inside a single enterprise, and the choice he frames as renting intelligence versus owning it✅ How one portfolio company packaged eight GPUs, CPUs, and a model router into an appliance, routing roughly 10% of queries to the frontier labs and claiming 70% savings per year✅ Why agents should be granted access at runtime that expires when the task ends, so a breach's blast radius stays contained to one narrow authorization✅ Cost per outcome as the yardstick: the human doing the task, the AI doing the task, and the human assisted by AI, applied first to discrete work like coding and customer support✅ A 57-step insurance claims process where the AI was correct 98% of the time and the humans 85%, a gap only visible because every step was recorded✅ The real difference between open source and open weight models, and why most of Ed's startups now build on open weight models under the hood✅ Why he argues offense is the new defense, and what the Black Hat sandbox escape means for CISOs planning autonomous defense⏱️ TIMESTAMPS0:00 Introduction0:36 Three waves and the ROI test3:06 Many models and where startups win10:32 Who owns access, context, and evaluations17:21 It's the people, not the architecture20:04 Measure the outcome, then cut the cost28:14 Buying talent and changing culture33:05 Systems of record versus headless agents36:31 Venture money pivots to robotics and chips40:11 Open weights and owning your intelligence44:44 Autonomous attacks need autonomous defense51:32 Judging vendors and earning enterprise trust

Cybercrime Magazine Podcast
Cybercrime Wire For Aug 10, 2026. Levi Strauss & Co. Hit By Cyber Attack. WCYB Digital Radio.

Cybercrime Magazine Podcast

Play Episode Listen Later Aug 10, 2026 1:21


The Cybercrime Wire, hosted by Scott Schober, provides boardroom and C-suite executives, CIOs, CSOs, CISOs, IT executives and cybersecurity professionals with a breaking news story we're following. If there's a cyberattack, hack, or data breach you should know about, then we're on it. Listen to the podcast daily and hear it every hour on WCYB. The Cybercrime Wire is brought to you Cybercrime Magazine, Page ONE for Cybersecurity at https://cybercrimemagazine.com. • For more breaking news, visit https://cybercrimewire.com

Cybercrime Magazine Podcast
Cybercrime Wire For Aug. 8-9, 2026. Weekend Update. WCYB Digital Radio.

Cybercrime Magazine Podcast

Play Episode Listen Later Aug 8, 2026 1:02


The Cybercrime Wire, hosted by Scott Schober, provides boardroom and C-suite executives, CIOs, CSOs, CISOs, IT executives and cybersecurity professionals with a breaking news story we're following. If there's a cyberattack, hack, or data breach you should know about, then we're on it. Listen to the podcast daily and hear it every hour on WCYB. The Cybercrime Wire is brought to you Cybercrime Magazine, Page ONE for Cybersecurity at https://cybercrimemagazine.com. • For more breaking news, visit https://cybercrimewire.com

Shift AI Podcast
Rethinking Security Analytics with In-Place Intelligence, CEO of Vega, Shay Sandler

Shift AI Podcast

Play Episode Listen Later Aug 8, 2026 41:28


In this episode of Shift AI, Shay Sandler, CEO and co-founder of Vega, joins host Boaz Ashkenazy for a wide-ranging conversation on why the legacy SIEM is breaking down just as security teams need their data the most.Shay grew up in Israel studying math and physics in a famously competitive class of gifted kids, then spent six years in one of the country's most elite military intelligence units before joining Granulate, a cloud cost optimization company, as one of its first ten employees. Granulate was acquired by Intel for $650 million, and after a year inside Intel, Shay left with his former Granulate colleague Ellie to found Vega — a decision he says was pushed forward by a month of reserve duty after October 7th that reminded him how much he missed solving hard problems with his old team.The two dig into why traditional SIEMs, built for a pre-cloud world of centralized data, are collapsing under multi-cloud, multi-region, siloed telemetry — and why teams that once filtered data down to save on SIEM costs now need all of it to keep up with threat actors wielding frontier models. Shay walks through Vega's architecture: querying data in place in commodity storage like S3, federating across regions and clouds without duplication or egress costs, and a deterministic, auditable natural-language-to-KQL layer that lets AI agents run threat hunts a human could fully verify.This episode is for CISOs, security operations leaders, detection engineers, and startup founders building in cybersecurity who want to understand how AI-native architecture, not just AI features, is reshaping enterprise security.Chapters[00:00] Introduction: Shay Sandler's path to founding and leading Vega[02:07] Growing up gifted in math and physics, and finding cybersecurity[04:18] Six years in an elite Israeli intelligence unit, and the "everything is solvable" mindset[06:08] First paid job at 14: distributing meat before dawn in southern Israel[08:37] Granulate, the $650 million Intel acquisition, and missing the startup thrill[10:43] October 7th reserve duty and the spark to build Vega with co-founder Ellie[15:04] How legacy SIEM broke under multi-cloud, siloed security data[17:32] The post-Mythos era: frontier models as tools for threat actors[23:16] Vega's three primitives: commodity storage, federation, and an AI-native interface[27:50] Natural language to KQL as a transparent, auditable layer for AI agents[30:05] AI as a "scalable engineering capability" for lean security teams[36:40] Velocity as the new core metric, and the closing thought: creativity and engineeringConnect with Shay SandlerLinkedIn: https://www.linkedin.com/in/shay-sandler-305508107/Connect with Boaz AshkenazyLinkedIn: https://www.linkedin.com/in/boazashkenazy/Email: boaz@shiftai.fm

Cybercrime Magazine Podcast
Cybercrime Wire For Aug 7, 2026. Cyber Intrusion Hits Freight Giant Ceva Logistics. WCYB Digital Radio.

Cybercrime Magazine Podcast

Play Episode Listen Later Aug 7, 2026 1:22


The Cybercrime Wire, hosted by Scott Schober, provides boardroom and C-suite executives, CIOs, CSOs, CISOs, IT executives and cybersecurity professionals with a breaking news story we're following. If there's a cyberattack, hack, or data breach you should know about, then we're on it. Listen to the podcast daily and hear it every hour on WCYB. The Cybercrime Wire is brought to you Cybercrime Magazine, Page ONE for Cybersecurity at https://cybercrimemagazine.com. • For more breaking news, visit https://cybercrimewire.com

Cybercrime Magazine Podcast
Cybercrime Wire For Aug 6, 2026. Ransomware Strikes Hungary's Paying Agency. WCYB Digital Radio.

Cybercrime Magazine Podcast

Play Episode Listen Later Aug 6, 2026 1:25


The Cybercrime Wire, hosted by Scott Schober, provides boardroom and C-suite executives, CIOs, CSOs, CISOs, IT executives and cybersecurity professionals with a breaking news story we're following. If there's a cyberattack, hack, or data breach you should know about, then we're on it. Listen to the podcast daily and hear it every hour on WCYB. The Cybercrime Wire is brought to you Cybercrime Magazine, Page ONE for Cybersecurity at https://cybercrimemagazine.com. • For more breaking news, visit https://cybercrimewire.com

Cybersecurity Where You Are
Episode 199: Translating Cyber Risk into Business Decisions

Cybersecurity Where You Are

Play Episode Listen Later Aug 5, 2026 37:18


In episode 199 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager sit down with Chris Painter, Chair of the Risk Committee and Board Member at the Center for Internet Security® (CIS®). Together, they discuss how chief information security officers (CISOs) can support the work of translating cyber risk into business decisions by Boards.Here are some highlights from our episode:00:50. Introductions to Chris01:36. The single biggest translation error Chris has seen CISOs make07:38. Cyber risk quantification: An opportunity to go beyond translation for Boards09:25. How ransomware changed Boards' understanding of cyber risks' business impact10:45. The value of tabletop exercises (TTX) and other simulations in creating shared language13:26. Recommendations on how to make the most of a TTX18:37. Risk modeling and how artificial intelligence (AI) complicates probability estimations21:51. "Pressure" (2026) as an illustration of making good, not 100% accurate, estimations22:58. How growing public awareness of cyber is reshaping CISOs' conversations with Boards25:55. The importance of walking Boards through risk mitigation steps with AI as an example29:31. A recommendation for how CISOs can learn what directors care about30:15. From "wizardry" to familiarity: An ongoing generational shift around cyberResourcesEpisode 183: The Role of CISO in Supporting Risk TranslationEpisode 187: The Role of a CISO as a Strategic StorytellerEpisode 192: How Leaders Balance Expertise and CommunicationHow Risk Quantification Tests Your Reasonable Cyber DefenseCIS RAM (Risk Assessment Method)Leveraging Generative Artificial Intelligence for Tabletop Exercise DevelopmentCIS Controls v8.1 Incident Response Policy TemplateYou Have a Cybersecurity Incident. Now What?Prompt Injections: The Inherent Threat to Generative AI"Pressure" | Official Website | 29 May 2026If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.

Cybercrime Magazine Podcast
Cybercrime Wire For Aug 5, 2026. Cyberattack Hits Convenience Chain In Poland. WCYB Digital Radio.

Cybercrime Magazine Podcast

Play Episode Listen Later Aug 5, 2026 1:23


The Cybercrime Wire, hosted by Scott Schober, provides boardroom and C-suite executives, CIOs, CSOs, CISOs, IT executives and cybersecurity professionals with a breaking news story we're following. If there's a cyberattack, hack, or data breach you should know about, then we're on it. Listen to the podcast daily and hear it every hour on WCYB. The Cybercrime Wire is brought to you Cybercrime Magazine, Page ONE for Cybersecurity at https://cybercrimemagazine.com. • For more breaking news, visit https://cybercrimewire.com

Cybercrime Magazine Podcast
Cybercrime Wire For Aug 4, 2026. Biotech Giant Amgen Suffers Data Breach. WCYB Digital Radio.

Cybercrime Magazine Podcast

Play Episode Listen Later Aug 4, 2026 1:21


The Cybercrime Wire, hosted by Scott Schober, provides boardroom and C-suite executives, CIOs, CSOs, CISOs, IT executives and cybersecurity professionals with a breaking news story we're following. If there's a cyberattack, hack, or data breach you should know about, then we're on it. Listen to the podcast daily and hear it every hour on WCYB. The Cybercrime Wire is brought to you Cybercrime Magazine, Page ONE for Cybersecurity at https://cybercrimemagazine.com. • For more breaking news, visit https://cybercrimewire.com

Hybrid Identity Protection Podcast
Inside a Veteran CISO's Playbook for Crisis and Communication with Philip Keibler, VP and CISO at Meijer

Hybrid Identity Protection Podcast

Play Episode Listen Later Aug 4, 2026 34:46


This episode features Philip Keibler, Vice President and CISO at Meijer, one of the nation's largest privately held retailers.With nearly three decades of security leadership, including CISO roles at Bass Pro Shops and Finish Line, Phil brings a rare long-view perspective on what the job actually requires day to day. He also talks about his feature in Semperis' upcoming documentary Midnight in the War Room, premiering at Black Hat on August 5.In this episode, Phil explains why CISOs who struggle to get budget usually have a storytelling problem, how he defines success in a role where stopping every attack is impossible, and what it takes to lead a team through an active incident. He also dives into why fundamentals are what actually address most of an organization's risk.This episode makes the case that the hardest parts of the CISO job are rarely technical, and that mastering the basics matters more than chasing the newest tool.Guest Bio Philip Keibler has spent nearly three decades at the intersection of technology, risk, and business building information security programs that work in the real world.As Vice President and Chief Information Security Officer at Meijer, Phil leads security for one of the nation's largest privately held retailers, overseeing the protection of supply chains, customer data, and critical operations across hundreds of locations in the Midwest.Phil's career spans industries where the stakes are high and the margin for error is low. Before joining Meijer in 2015, he served as CISO at Bass Pro Shops and previously held the CISO role at Finish Line. Earlier in his career he led security at Herff Jones, bringing security discipline to the manufacturing sector. He began his career at EDS and spent years consulting in the Aerospace sector where he got his start in security.What sets Phil apart is not just longevity, it is perspective. He has watched information security evolve from a reactive, audit-driven function into a proactive capability that enables business velocity. His approach centers on integrating security into how organizations operate, not as a checkbox, but as a competitive advantage that lets teams move fast while managing risk in practical ways.Beyond the day-to-day, Phil is a passionate contributor to the broader security community. He has served as a guest lecturer on cybersecurity and data privacy at the University of Chicago Law School, sits on the Institute for Cybersecurity Education and Research Advisory Board at Grand Valley State University, serves on the IT Advisory Committee at Kent County Technical Center, and is a board member the Meijer Credit Union. He is also featured in Midnight in the War Room, a Semperis documentary examining the human reality behind enterprise cyber defense.Phil has held his CISSP certification since 2009, attained his MBA from Davenport University, and a career's worth of operational experience across retail, aerospace, insurance, and manufacturing.Guest Quote “A successful CISO understands that it's not about prevention, it's about resilience, it's about recovery, and it's about identifying those things in your program that you can do incrementally better every single day. We're in the pursuit of perfection, but we understand we'll never get there.”Time stamps 02:46 Meet Philip Keibler: From Sysadmin to Security 04:35 Becoming a CISO 06:20 What CISOs Really Do 08:50 Defining Success and Resilience 10:41 Storytelling to the Board 13:29 Semperis' Midnight in the War Room 17:47 Team Care and Crisis Leadership 21:47 Advice for CISOs 24:24 The Case for Mastering the Fundamentals 31:02 Conclusion and Final ThoughtsSponsor The HIP Podcast is brought to you by Semperis, the leader in identity-driven cyber resilience for the hybrid enterprise. Trusted by the world's leading businesses, Semperis protects critical Active Directory and Entra ID environments from cyberattacks, ensuring rapid recovery and business continuity when every second counts. Visit semperis.com to learn more.Links Connect with Phil on LinkedInConnect with Sean on LinkedInDon't miss future episodesLearn more about SemperisHIP Conference 26 is coming to Nashville, September 8–10, 2026.Join us to explore this year's theme, Redefining Resilience, at the world's premier practitioner-led conference focused on securing hybrid identity environments.If you love the conversations on the HIP Podcast, this is where the community comes together in person. Learn more and register at https://www.hipconf.com/.

UC Today - Out Loud
The Security & Compliance Show: Securing the Enterprise in the Age of AI Agents

UC Today - Out Loud

Play Episode Listen Later Aug 4, 2026 48:25


In this UC Today roundtable, host Kristian McCann brings together leading security experts to confront the escalating risks of agentic AI—autonomous systems that make decisions, take actions, and roam across enterprise tech stacks often without human oversight. You'll hear from Irina Tsukerman, President at Scarab Rising; Shlomi Beer, Co-Founder & CEO at ImpersonAlly; and Roey Eliyahu, Co-Founder & CEO at Salt Security. Together, they reveal how rapid adoption in customer support, sales, and finance is outstripping governance, enabling silent breaches via prompt injections, privilege accumulation, and API exploits that blend into normal workflows.Expect straight talk on the productivity boom versus harsh realities—like 80% of companies facing unintended agent actions such as data leaks or unauthorized access—and proven strategies for observability, dynamic guardrails, and non-human identity governance that safeguard UC&C environments without killing innovation.Talking points include:Why agentic AI supercharges insider threats and erodes perimeters, exposing "internal" APIs to external manipulation even within legitimate agent permissions.Governance blind spots in high-stakes sectors like retail and airlines (e.g., fraudulent refunds, customer data spills), demanding end-to-end visibility from LLMs to backend actions.Runtime defenses against self-learning exploits, deceptive "sleeper" code, and endless trial-and-error attacks that humans resist but agents can't.Zero-trust models, NHI in IAM, and regulation readiness to align agent efficiency with compliance and CX protection.Next StepsShare this roundtable with your CISOs, IT leaders, and business units to map agent permissions and API exposures right now.Evaluate IAM for non-human identities and pilot tools like Salt Security for holistic agent discovery.Subscribe to UC Today for more expert roundtables on AI risks, UC&C security, and enterprise compliance.

Cybercrime Magazine Podcast
Cybercrime Wire For Aug 3, 2026. Cyberattack Hits Liechtenstein Owner Register. WCYB Digital Radio.

Cybercrime Magazine Podcast

Play Episode Listen Later Aug 3, 2026 1:24


The Cybercrime Wire, hosted by Scott Schober, provides boardroom and C-suite executives, CIOs, CSOs, CISOs, IT executives and cybersecurity professionals with a breaking news story we're following. If there's a cyberattack, hack, or data breach you should know about, then we're on it. Listen to the podcast daily and hear it every hour on WCYB. The Cybercrime Wire is brought to you Cybercrime Magazine, Page ONE for Cybersecurity at https://cybercrimemagazine.com. • For more breaking news, visit https://cybercrimewire.com

Ask the CIO
State CISOs facing new set of challenges as role expands, survey finds

Ask the CIO

Play Episode Listen Later Aug 3, 2026 43:19


A new survey from the National Association of State CIOs and Deloitte found state CISOs are facing growing demands that are not being matched by more resources.See Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.

Cybercrime Magazine Podcast
Cybercrime Wire For Aug. 1-2, 2026. Weekend Update. WCYB Digital Radio.

Cybercrime Magazine Podcast

Play Episode Listen Later Aug 1, 2026 1:01


The Cybercrime Wire, hosted by Scott Schober, provides boardroom and C-suite executives, CIOs, CSOs, CISOs, IT executives and cybersecurity professionals with a breaking news story we're following. If there's a cyberattack, hack, or data breach you should know about, then we're on it. Listen to the podcast daily and hear it every hour on WCYB. The Cybercrime Wire is brought to you Cybercrime Magazine, Page ONE for Cybersecurity at https://cybercrimemagazine.com. • For more breaking news, visit https://cybercrimewire.com

Cybercrime Magazine Podcast
Cybercrime Wire For Jul 31, 2026. Brinks Home Security Warns Customers On Breach. WCYB Digital Radio

Cybercrime Magazine Podcast

Play Episode Listen Later Jul 31, 2026 1:30


The Cybercrime Wire, hosted by Scott Schober, provides boardroom and C-suite executives, CIOs, CSOs, CISOs, IT executives and cybersecurity professionals with a breaking news story we're following. If there's a cyberattack, hack, or data breach you should know about, then we're on it. Listen to the podcast daily and hear it every hour on WCYB. The Cybercrime Wire is brought to you Cybercrime Magazine, Page ONE for Cybersecurity at https://cybercrimemagazine.com. • For more breaking news, visit https://cybercrimewire.com

Cybercrime Magazine Podcast
Cybercrime Wire For Jul 30, 2026. Data Breach Hits UK Dept. For Education. WCYB Digital Radio.

Cybercrime Magazine Podcast

Play Episode Listen Later Jul 30, 2026 1:28


The Cybercrime Wire, hosted by Scott Schober, provides boardroom and C-suite executives, CIOs, CSOs, CISOs, IT executives and cybersecurity professionals with a breaking news story we're following. If there's a cyberattack, hack, or data breach you should know about, then we're on it. Listen to the podcast daily and hear it every hour on WCYB. The Cybercrime Wire is brought to you Cybercrime Magazine, Page ONE for Cybersecurity at https://cybercrimemagazine.com. • For more breaking news, visit https://cybercrimewire.com

Cybercrime Magazine Podcast
Cybercrime Wire For Jul 29, 2026. Cyberattack Strikes Angola's Largest Telecom. WCYB Digital Radio.

Cybercrime Magazine Podcast

Play Episode Listen Later Jul 29, 2026 1:23


The Cybercrime Wire, hosted by Scott Schober, provides boardroom and C-suite executives, CIOs, CSOs, CISOs, IT executives and cybersecurity professionals with a breaking news story we're following. If there's a cyberattack, hack, or data breach you should know about, then we're on it. Listen to the podcast daily and hear it every hour on WCYB. The Cybercrime Wire is brought to you Cybercrime Magazine, Page ONE for Cybersecurity at https://cybercrimemagazine.com. • For more breaking news, visit https://cybercrimewire.com

ITSPmagazine | Technology. Cybersecurity. Society
Tech Trailblazers: Recognition That Reaches the Whole Team | An Interview with Rose Ross | An Analog Brain In A Digital Age With Marco Ciappelli

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Jul 28, 2026 25:17


PODCAST EPISODE | An Analog Brain In A Digital Age With Marco Ciappelli Fifteen years ago, Rose Ross brought a client an idea for an awards program built specifically for enterprise tech startups. The client passed. She built it herself — and the Tech Trailblazers have been running ever since, independent, judged by practitioners, and open for entries until 3 September.

Cybercrime Magazine Podcast
Cybercrime Wire For Jul 28, 2026. Cyberattacks Strike Minnesota Water Facilities. WCYB Digital Radio

Cybercrime Magazine Podcast

Play Episode Listen Later Jul 28, 2026 1:20


The Cybercrime Wire, hosted by Scott Schober, provides boardroom and C-suite executives, CIOs, CSOs, CISOs, IT executives and cybersecurity professionals with a breaking news story we're following. If there's a cyberattack, hack, or data breach you should know about, then we're on it. Listen to the podcast daily and hear it every hour on WCYB. The Cybercrime Wire is brought to you Cybercrime Magazine, Page ONE for Cybersecurity at https://cybercrimemagazine.com. • For more breaking news, visit https://cybercrimewire.com

The 30 Minute Hour™

AI for business leaders doesn't have to be complicated. Learn practical AI and cybersecurity strategies in under three minutes with Eric Twiggs every Monday.

Cybercrime Magazine Podcast
Cybercrime Wire For Jul 27, 2026. Cyberattack Strikes Dutch Ice Skating Stadium. WCYB Digital Radio.

Cybercrime Magazine Podcast

Play Episode Listen Later Jul 27, 2026 1:22


The Cybercrime Wire, hosted by Scott Schober, provides boardroom and C-suite executives, CIOs, CSOs, CISOs, IT executives and cybersecurity professionals with a breaking news story we're following. If there's a cyberattack, hack, or data breach you should know about, then we're on it. Listen to the podcast daily and hear it every hour on WCYB. The Cybercrime Wire is brought to you Cybercrime Magazine, Page ONE for Cybersecurity at https://cybercrimemagazine.com. • For more breaking news, visit https://cybercrimewire.com

Paul's Security Weekly
AI's Disruption as Cybersecurity's Economics Are Broken, Compounding Security Debt - Ben Gilliland - BSW #457

Paul's Security Weekly

Play Episode Listen Later Jul 22, 2026 58:42


America has lived through technological and economic upheaval before. Farm workers moved to factories. Factory workers moved into services. New industries replaced old ones. Productivity rose. Living standards improved. But are we ready for the greatest disruption in American history? Ben Gilliland, author of the upcoming book Breaking the Compact, joins Business Security Weekly to discuss why business leaders need to be prepared for the upcoming AI disruption. The impact of AI, which has not fully materialized, goes far beyond security and job displacement. It will impact our economy, our privacy, and our way of life. The closest recent warning is the "China shock," the period of rapidly increasing import competition that followed China's integration into the global trading system. AI will dwarf that. Ben will discuss the human advantage and how we can prepare now. In the leadership and communications segment, Cybersecurity's Economics Are Broken. Automation Alone Won't Fix It, The business case for burning down security debt: A practical approach for CISOs, The last human relationship in cybersecurity, and more! Visit https://www.securityweekly.com/bsw for all the latest episodes! Show Notes: https://securityweekly.com/bsw-457

Identity At The Center
#436 - Sponsor Spotlight - P0 Security

Identity At The Center

Play Episode Listen Later Jul 22, 2026 46:00


In this Sponsor Spotlight episode, Jeff Steadman flies solo and welcomes Greg Danyi, co-founder and CTO of P0 Security, to the show. Greg walks through P0's approach to runtime access control, covering how it applies to humans, non-human identities, and AI agents alike. The conversation digs into the difference between authentication and authorization, why zero standing privilege is more achievable now than before agentic adoption took hold, and how dynamic, evidence-based policies can reduce reliance on manual approvals. Greg also shares real examples, including row-level access control for data lakes and a CRM mishap that shows how easily agents can misinterpret intent. The episode closes with a look at where enterprise AI agent governance may be headed over the next few years, plus a lighter conversation about explaining IAM to a 10-year-old. This episode is made possible through the generous support of P0 Security as part of IDAC's nonprofit Sponsor Spotlight series. Learn more at p0.dev/idac.Connect with Greg (Gergely): https://www.linkedin.com/in/gergely-danyi/Learn more about P0: https://p0.dev/idac/Connect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.com00:00 - Introduction and sponsor acknowledgment01:13 - Greg Danyi's path into IAM02:18 - What P0 Security solves for03:21 - Where P0 fits versus PAM and IGA04:46 - Agentic identity as a driver of adoption05:27 - MCP servers and unpredictable agent actions07:10 - Defining runtime access control08:50 - How authentication and authorization work together09:07 - Standing access versus expressed intent10:16 - Zero standing privilege in practice12:27 - Agentic identity as a distinct identity class19:24 - Automated evidence for approvals20:42 - Walking through a support agent example22:13 - Row-level access control for data lakes23:35 - Dynamic roles explained29:55 - CRUD risks and underestimated concerns31:32 - Human intent and giving agents clear direction36:32 - Where enterprise AI agent governance is headed39:36 - Advice for CIOs and CISOs getting started41:15 - Explaining IAM to a 10-year-old42:29 - Board games, dice, and calculated risk44:00 - Closing thoughts and where to learn moreKeywords: IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Greg Danyi, P0 Security, runtime access control, agentic identity, zero standing privilege, non-human identity, authentication, authorization, IAM podcast