Podcasts about exabeam

  • 92PODCASTS
  • 182EPISODES
  • 38mAVG DURATION
  • 1EPISODE EVERY OTHER WEEK
  • Jul 16, 2026LATEST

POPULARITY

20192020202120222023202420252026


Best podcasts about exabeam

Latest podcast episodes about exabeam

The New CISO
How Many Tokens to Breach Your Network?

The New CISO

Play Episode Listen Later Jul 16, 2026 51:02


What if your next breach came down to a token budget? In this episode, Steve Moore is joined by Lou Rabon, Founder and CEO of Cyber Defense Group, for a conversation on the modern CISO's world—from how to interview for the seat, to why AI agents are the next insider threat, to research that reframes breach cost as a token calculation.Lou and Steve open on breach response, why making introductions during a crisis is a losing game, and the questions every CISO candidate should ask before accepting an offer. Lou lays out how many rounds of interviews a serious CISO role should include, why the CEO must be involved by the final round, and why he believes Legal—not the CIO or CTO—is the ideal reporting line for security.The conversation pivots to AI. Lou argues we are watching a dot-com-speed shift, only compressed. They dig into the emerging insider-threat framing for autonomous agents, the recent incident where an AI slipped its sandbox to contact a researcher, and why attackers face none of the ethical guardrails defenders must respect.Steve shares recent Cornell research showing that agentic tooling can already automate 22 of 32 steps in a corporate intrusion, compressing hours of expert work into seconds—with token spend as the only real limiter. If a breach can be priced in tokens, they argue, defenders must think in tokens too, and machine-to-machine defense becomes a necessity rather than a novelty.The episode closes on what Lou calls “the dirty secret” of cybersecurity: the unglamorous hygiene work—asset lists, data maps, MSA notification clocks—that no one wants to fund. He and Steve explore how agentic AI could finally deliver the always-on trash collection defenders have wanted for decades, from dynamic breach-notification tracking to a security agent that flags every new device.Key Topics• Why making introductions during a crisis is a losing strategy• The interview questions every CISO candidate should ask• Why Legal is the ideal reporting line for the CISO• The inverse curve between convenience and security• AI agents as the next form of insider threat• Cornell research: 22 of 32 intrusion steps automated• Tokens as the new unit of breach cost• Machine-to-machine defense in financial services• The “trash collection” hygiene work at the heart of InfoSec• Agentic AI for asset lists and breach-notification analysisLou Rabon is the Founder and CEO of Cyber Defense Group (CDG), a cybersecurity strategic advisory firm he launched in 2016 to help fast-growing organizations manage modern risk and threats. With more than two decades in security, privacy, and incident response, Lou has led response engagements against nation-state attackers and previously served as CISO at Spokeo. Connect with Lou on LinkedIn or learn more at cdg.io.GET A DEMO:

ChannelBuzz.ca
The Buzz: OpenAI launches partner network, Carbon60 makes the MSP 501, and RecordPoint goes channel-first

ChannelBuzz.ca

Play Episode Listen Later Jul 16, 2026 4:09


Today’s headline news for Canadian IT solution providers: OpenAI Partner Network: OpenAI‘s inaugural Partner Network is officially live as of July 15, with vice president of strategic global partnerships Colleen Kapase confirming the three-tier program is backed by $150 million in channel investment. Partners can progress through Select, Advanced, and Elite tiers while earning specializations in areas like Codex, cybersecurity, and AI agents. OpenAI says it aims to train 300,000 certified consultants by year-end and is recruiting solution providers of all sizes that can put AI systems into production. OpenAI Carbon60 MSP 501: Carbon60, a Toronto-based managed cloud services provider, has been named to the 2026 MSP 501 at position 206, ranking among the world’s top managed services firms by revenue and operational discipline. The company has built a differentiated practice around Canada-first sovereign cloud and Azure expertise, and the ranking follows a broader push by Canadian MSPs to demonstrate global competitiveness in compliance-heavy verticals. Carbon60 RecordPoint channel-first: RecordPoint has launched a global partner program that CRN describes as a channel-first move, enabling resellers, consultancies, and systems integrators to resell, co-sell, and refer its data and AI governance platform. Partners will receive enablement, joint sales support, and platform access to build practices around data retention, compliance, and AI-ready data classification. Channel Insider Blackpoint Cyber 2026 threat report: Blackpoint Cyber has released its 2026 Annual Threat Report, finding that attackers are increasingly exploiting trusted IT tools rather than using perimeter breaches. The report highlights abuse of remote monitoring and management platforms, VPNs, and identity credentials as primary vectors. ChannelPro Network Managed security market growth: Acronis and Omdia project the global managed security market will grow from $93 billion in 2025 to $106 billion in 2026, a 14.4 percent increase. The growth reflects sustained demand for outsourced security operations among mid-market organizations that lack internal SOC capacity. RAMageddon pressures PC refresh: Industry analysts and OEMs continue to signal significant PC RAM price increases through 2026 due to the ongoing memory supply shortage. Channel partners should advise clients on refresh timing and alternative configurations to manage budget impact. CNET Exabeam MSSP licensing: Exabeam has expanded its APEX partner program with pooled and federated licensing options designed specifically for MSSPs. The new framework is intended to reduce onboarding friction and simplify compliance across multi-tenant security operations centers. Security Brief Read Full Transcript Welcome to The Buzz from ChannelBuzz.ca, I’m Robert Dutt, today is Thursday, July 16, and here’s what’s happening in the channel today. OpenAI’s inaugural Partner Network is officially live as of yesterday, July 15, with the company backing the three-tier program with $150 million in channel investment. Vice president of strategic global partnerships Colleen Kapase confirmed the program is open to solution providers of all sizes, not just global systems integrators. Partners can progress through Select, Advanced, and Elite tiers based on sales performance, technical capability, and deployment experience. The program includes specializations in Codex, cybersecurity, and AI agents. OpenAI says it aims to train 300,000 certified consultants by the end of 2026, and is actively recruiting solution providers that can put AI systems into production. Philip Larson, senior director of the OpenAI Partner Network and a former Google Cloud channel leader, said the program is designed to reward partners for the value they create with customers. Canadian VARs and MSPs with existing AI practices should evaluate the program alongside their current AWS, Google, and Microsoft partnerships, as the specializations in Codex and AI agents may create differentiation in automation-heavy verticals. Carbon60, a Toronto-based managed cloud services provider, has been named to the 2026 MSP 501 at position 206, marking the company as one of the world’s top managed services firms by revenue and operational discipline. The ranking, published by Channel Futures, evaluates financial health, operational maturity, and recurring revenue growth. Carbon60’s inclusion follows a broader trend of Canadian MSPs demonstrating global competitiveness in specialized infrastructure and compliance-heavy verticals. The company has built a differentiated practice around Canada-first sovereign cloud and deep Azure expertise. As Canadian public sector and healthcare clients face stricter data residency requirements, sovereign cloud capabilities are becoming a key differentiator for domestic MSPs seeking to compete with larger global firms on government and enterprise contracts. RecordPoint has gone channel-first with the launch of a global partner program enabling resellers, consultancies, and systems integrators to resell, co-sell, and refer its data and AI governance platform. The program arrives as AI adoption drives a surge in demand for data governance across regulated industries. RecordPoint says partners will receive enablement, joint sales support, and platform access to build practices around data retention, compliance, and AI-ready data classification. CRN reports that the move represents a strategic shift for the company. Canadian partners serving regulated industries like finance, government, and healthcare may find particular opportunity as clients confront unstructured data sprawl ahead of AI deployments. In Brief – OpenAI commits $150 million to launch its inaugural Partner Network with tiered AI specializations. Acronis and Omdia project the managed security market will reach $106 billion in 2026. Blackpoint Cyber’s 2026 Annual Threat Report highlights attackers hiding inside trusted IT tools and RMM platforms. RAMageddon memory shortages continue to pressure PC pricing and enterprise refresh cycles. Exabeam adds pooled and federated licensing options to its APEX partner program for MSSPs. Full details and links in the show notes or the blog post. Later today on In The Channel, we’re talking specialist distribution in Canada with Carrie Hopkins of Exclusive Networks. We get into the Ignition program, what broadliners can’t deliver, and why the model might feel familiar to channel veterans. And if you haven’t heard it yet, yesterday we wrapped our HPE Discover 2026 arc with HPE vice president of North America channels Jeremiah Jenson. He talks about the quote-cycle win, the Canadian angle on data sovereignty, and what partners should stop doing. That’s how we’re seeing the headlines today. I’m Robert Dutt for ChannelBuzz.ca, thanks for listening. Have a great day.

Packet Pushers - Full Podcast Feed
NB582: Infoblox Adds Network Observability with Kentik Buy; Satellite Data Centers vs. the Environment

Packet Pushers - Full Podcast Feed

Play Episode Listen Later Jul 13, 2026 31:27


Take a Network Break! We start with a critical vulnerability in Adobe Coldfusion. On the news front, Infoblox acquires Kentik to add network observability to its portfolio, data center electricity consumption jumps worldwide, and Exabeam rolls out AI-agent focused detection in its Agent Behavior Analytics platform. DriveNets and WhiteFiber connect two AI data centers over... Read more »

Packet Pushers - Network Break
NB582: Infoblox Adds Network Observability with Kentik Buy; Satellite Data Centers vs. the Environment

Packet Pushers - Network Break

Play Episode Listen Later Jul 13, 2026 31:27


Take a Network Break! We start with a critical vulnerability in Adobe Coldfusion. On the news front, Infoblox acquires Kentik to add network observability to its portfolio, data center electricity consumption jumps worldwide, and Exabeam rolls out AI-agent focused detection in its Agent Behavior Analytics platform. DriveNets and WhiteFiber connect two AI data centers over... Read more »

Packet Pushers - Fat Pipe
NB582: Infoblox Adds Network Observability with Kentik Buy; Satellite Data Centers vs. the Environment

Packet Pushers - Fat Pipe

Play Episode Listen Later Jul 13, 2026 31:27


Take a Network Break! We start with a critical vulnerability in Adobe Coldfusion. On the news front, Infoblox acquires Kentik to add network observability to its portfolio, data center electricity consumption jumps worldwide, and Exabeam rolls out AI-agent focused detection in its Agent Behavior Analytics platform. DriveNets and WhiteFiber connect two AI data centers over... Read more »

Sales Game Changers | Tip-Filled  Conversations with Sales Leaders About Their Successful Careers
How AI Is Powering Outcome-Driven Partner Ecosystems with Craig Patterson

Sales Game Changers | Tip-Filled Conversations with Sales Leaders About Their Successful Careers

Play Episode Listen Later Jul 1, 2026 33:06


This is episode 856. Read the complete transcription on the Sales Game Changers Podcast website. Watch the video of this podcast on YouTube here. The Sales Game Changers Podcast was recognized by YesWare as the top sales podcast. Read the announcement here. FeedSpot named the Sales Game Changers Podcast at a top 20 Sales Podcast and top 8 Sales Leadership Podcast! Subscribe to the Sales Game Changers Podcast now on Apple Podcasts! Purchase Fred Diamond's best-sellers Love, Hope, Lyme: What Family Members, Partners, and Friends Who Love a Chronic Lyme Survivor Need to Know and Insights for Sales Game Changers now! Today's show featured an interview with Craig Patterson, Global Channel and Ecosystem Chief at Exabeam. Find Craig on LinkedIn. CRAIG'S TIP: "Stop measuring activity and start driving outcomes. It's easy to become focused on how much you're doing, but the real question is: what are you actually trying to achieve? The best sales professionals measure success by the business outcomes they create."

The New CISO
CISO 3.0: The Playbook for Delivering Impact and Influence

The New CISO

Play Episode Listen Later Jun 25, 2026 58:06


What separates a CISO who survives from one who shapes the boardroom? In this episode, Steve Moore sits down with Walt Powell, Lead Field CISO at CDW and author of The CISO 3.0, to unpack the modern CISO playbook—why technical credentials alone no longer cut it, how to build personal eminence, and why most security leaders are still treated as second-class C-suite citizens.Walt traces his path from teaching networking before stateful firewalls existed, to writing CISSP exam questions for ISC2, to running CDW's Global Security Strategy Office. He explains what a field CISO does, why the role is harder than ex-CISOs realize, and how one bad meeting can tarnish a brand built over decades.He and Steve break down the four pillars Walt uses to measure his team—embedded advisory, eminence building, sales enablement, and voice of the customer—and how a karate-style “belt system” maps each consultant's competency. Walt explains why the same skills matrix from The CISO 3.0 works for any CISO trying to spot their own gaps.Walt argues a CISO who is not liked cannot succeed: you are the talent magnet, the culture builder, and the person proving in every board meeting that you belong in the seat. He shares the questions every candidate should ask before accepting the role—from D&O coverage to 10-K disclosure access—and why the 30-60-90 plan should be written before the second interview, not after the offer.The conversation closes with what Walt calls “strategic debt”—the identity and data governance work organizations skipped a decade ago that is now blocking AI adoption. Walt shares lessons from running OpenClaw on a Mac mini, why non-human identity tops every 2026 CISO worry list, and how Deep Research is reshaping senior architects.Key Topics• The modern field CISO role and the four pillars of impact• Why CISOs are still treated as second-class C-suite citizens• Building personal eminence through books, speaking, and writing• The CISO 3.0 skills matrix and self-assessment spider wheel• Two paths to the CISO seat: technical vs. MBA, and the gaps each leaves• Why likability is not optional for a successful CISO• Board readiness and proving you belong in the seat• Interview questions every CISO candidate must ask• Strategic debt: identity and data governance blocking AI adoption• OpenClaw, non-human identity, and the future of senior architectsGuest Bio:Walt Powell is the Lead Field CISO at CDW and a founding member of CDW's Global Security Strategy Office, where he leads a team of former CISOs advising security leaders in the field. A longtime executive coach and ISC2 exam development committee member, Walt is the author of The CISO 3.0: A Guide to Next-Generation Cybersecurity Leadership and Quantum Ready, his book on post-quantum cryptography. Connect with Walt on LinkedIn or at ciso30.com.GET A DEMO:

The New CISO
Rogue Agents: The New Era of AI Insider Threats (part 2)

The New CISO

Play Episode Listen Later Jun 4, 2026 43:04


What happens when an AI agent inside your company starts behaving like an insider threat? In part two, Steve Moore picks the thread back up with former FBI operative Eric O'Neill to explore how agentic AI is rewriting cybersecurity, the legal traps that follow a breach, and why the modern CISO must think like a spy hunter.Eric opens with a sobering reality: ransomware victims who decline to pay are re-attacked at staggering rates. He explains why criminals treat cybercrime as a business, invest weeks in reconnaissance—mapping SharePoint, harvesting file trees, and studying access patterns—and why a botched recovery hands them the same door twice.The conversation turns to the new insider threat hiding in plain sight: rogue AI agents. Eric shares a real case in which one executive's casual query exposed the next round of layoffs and triggered coordinated lawsuits. They unpack how agents inherit excessive access, how attackers hijack them once inside, and why organizations are now building insider-threat programs to monitor AI behavior.Eric argues AI is an accelerant on every unresolved problem—weak identity management, entitlement drift, missing asset inventories, and absent data classification. They debate whether IT and security should be unified under the CISO, why the CISO needs a direct line to the board, and the legal landmines that follow a breach, from cyber insurance to the “reasonable steps” standard.The episode closes with Eric's advice for any new CISO: put “spy hunter” on your resume. Counterintelligence, not perimeter defense, is the discipline that wins today. Tune in for part two of a story-driven conversation on why preparation, mindset, and threat hunting beat any single technology.Key Topics• Why ransomware victims who decline to pay get re-attacked• How attackers map SharePoint, file trees, and access patterns• The new insider threat: rogue and hijacked AI agents• A real case of an AI agent exposing an HR layoff list• Shadow IT and the cost of banning AI outright• Permission structures and second-level reviews for agent actions• Why AI exposes gaps in identity, asset, and data classification• Unifying IT and security under the CISO• Why the CISO needs a direct line to the board• Legal traps: cyber insurance, reasonable steps, and missed alerts• The CISO as counterintelligence officer and spy hunterGuest BioEric O'Neill is a former FBI counterintelligence operative, attorney, and bestselling author who helped bring down Robert Hanssen—the most damaging spy in FBI history. He is the founder of NeXasure AI and co-founder of The Georgetown Group, and his undercover work was dramatized in the film Breach. Eric is the author of Gray Day and Spies, Lies, and Cybercrime.Connect with Eric on LinkedIn or at ericoneill.net.GET A DEMO:

The New CISO
Lessons From a Spy Hunter: The Real Cost of a Breach (Part 1)

The New CISO

Play Episode Listen Later May 14, 2026 34:30


What does it feel like to stand in the smoking ruin of a ransomware attack? In this episode, Steve Moore is joined by former FBI undercover operative Eric O'Neill—the man who helped capture Robert Hanssen—to explain why modern cybercrime is just traditional espionage repackaged, and why the dark web has quietly become the world's third-largest economy.Eric traces his path from the FBI's counterintelligence trenches to founding NeXasure AI and writing cybersecurity books that read like spy thrillers. He and Steve unpack the staggering scale of cybercrime, which Eric predicts could reach $20 trillion in global GDP within years—a marketplace selling everything from ransomware kits to stolen credentials.They dismantle the “it won't happen to me” mindset that still lingers in boardrooms. Eric describes how attackers use AI agents to scan for vulnerable systems, walks through how Scattered Spider socially engineered MGM in a ten-minute phone call, and explains why disabled MFA remains the leading point of failure for small and mid-size businesses.Eric then unpacks the painful calculus of paying a ransom. He explains why the FBI says never pay, when OFAC sanctions make payment a federal crime, and why—even after paying—an organization must still do the same forensic, legal, and architectural work. Steve and Eric also detail how attackers resell access and treat victims as repeat customers. The episode closes with a candid look at recovery. Eric and Steve explore why most companies fail at restoration, why rolling back to “before the attack” leaves the original flaw wide open, and why preparation always beats panic. Tune in for a part-one masterclass for any leader who thinks their organization is too small to be a target.Key Topics• How traditional espionage evolved into modern cybercrime• The dark web as the world's third-largest economy• Why every organization is a target, regardless of size• The MGM ransomware attack and Scattered Spider's playbook• Disabled MFA as the leading cause of SMB compromise• Vulnerability assessments versus fire-time remediation costs• The pay-versus-don't-pay ransomware calculus• OFAC sanctions and the legal risks of paying• Why restoring backups is not the same as recovery• The how, where, why, what, and when of breach forensicsGuest BioEric O'Neill is a former FBI counterintelligence operative, attorney, and bestselling author who helped bring down Robert Hanssen—the most damaging spy in FBI history. He is the founder of NeXasure AI and co-founder of The Georgetown Group, and his undercover work was dramatized in the film Breach. Eric is the author of Gray Day and Spies, Lies, and Cybercrime.Connect with Eric on LinkedIn or at ericoneill.net.GET A DEMO:

The New CISO
Your Most Valuable Skills Aren't Technical

The New CISO

Play Episode Listen Later Apr 23, 2026 52:32


Cybersecurity debates tend to center on tools, frameworks, and threats. But Rob Knoblauch has built a 25-year career in global security leadership by focusing on the soft skills that determine whether a CISO survives, thrives, or burns out. In this episode of The New CISO, Rob joins Steve Moore to trace the through-line from running a multi-node BBS as a kid to serving as Deputy CISO of one of the world's largest banks — and the career lessons he's carried through every chapter.Rob's path wasn't engineered. It began with a VIC-20, a love of video games, and a side passion for DJing that eventually clinched his first big bank interview. Running a BBS taught him identity management, patching, and infrastructure long before those were industry terms, and responding to the Melissa and “I Love You” outbreaks as a twenty-something Toronto Stock Exchange analyst launched his pivot into information security.The conversation turns to leading at scale. Rob walks through the three mentors who shaped him — “the teacher” who grounded him in fundamentals at Bank of Montreal, “the coach” who taught him the collaborative nature of global operations at Scotiabank, and “the general” who sharpened his leadership edge. He frames these not as phases but as lenses he still applies situationally today.Rob and Steve dig into incident response — from taking down Canada's first phishing site with no playbook to running tabletop exercises at the board, C-suite, and technical levels. Rob argues every organization needs a breach coach and that communications is the biggest make-or-break factor in a breach. He also offers a candid take on CISO politics — short tenures, CIO friction, and why trust with your boss matters more than being right.The episode closes with Rob's take on why this may be the best time in history to be a new CISO. AI is stripping away the commodity work that defined earlier generations of the role, leaving more room for strategy, leadership, and real influence. For anyone stepping into the seat, Rob's message is simple: the most valuable skills aren't technical at all.Key Topics• Rob's path from a VIC-20 and a grade-school BBS to the CISO seat• How DJing as “Robbie Knobs” clinched his first big bank interview — and why “notables” matter on a resume• Taking down the first phishing website in Canada with no playbook and a lot of cold calls• The three mentors who shaped his leadership: the teacher, the coach, and the general• Why tabletop exercises at the board, C-suite, and technical levels each matter — and how they differ• The case for engaging a breach coach before a breach happens, not during one• Why communications is the single biggest make-or-break factor in incident response• How AI is reshaping the CISO role by stripping away commodity workGuestRob Knoblauch — Chief Information Security OfficerRob Knoblauch is a seasoned CISO with 25+ years of global information security leadership. He began his career at the Toronto Stock Exchange during the Y2K era and later held increasingly senior roles at Bank of Montreal and Scotiabank, where he spent years as Deputy CISO and VP of Global Security Services. Rob is also a startup advisor and longtime house music DJ performing as “Robbie Knobs.” Connect with Rob on LinkedIn.GET A DEMO:

Application Security PodCast
Steve Wilson--OpenClaw and Advanced AI Agents

Application Security PodCast

Play Episode Listen Later Apr 15, 2026 49:30


In this episode of the Application Security Podcast, Chris Romeo and Robert Hurlbut welcome back Steve Wilson, a global leader in AI security and Chief AI and Product Officer at Exabeam, as well as founder of the OWASP Gen AI Security Project.Steve shares how his AI assistant was “hacked” using a simple phishing attack, highlighting a major shift in security—AI agents behave more like humans than traditional software. The conversation explores how this changes the threat model, why AppSec is struggling to keep up, and how organizations should approach the practical security of AI systems.They also cover the risks of autonomous agents, the expanding blast radius of failures, and what AppSec professionals can do now to adapt.FOLLOW OUR SOCIAL MEDIA:➜Twitter: @AppSecPodcast➜LinkedIn: The Application Security Podcast➜YouTube: https://www.youtube.com/@ApplicationSecurityPodcastThanks for Listening!~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

The New CISO
From Chef to CISO: Unlocking the Recipe to Security Leadership

The New CISO

Play Episode Listen Later Apr 2, 2026 44:59


What does sharpening a knife over a case of onions have to do with incident response? For Myke Lyons, CISO at Cribl, the answer is everything. Myke trained at the Culinary Institute of America — learning speed and accuracy under the clock of a professional kitchen — before a summer IT job in Manhattan set him on an entirely different path. In this episode of The New CISO, host Steve Moore traces that journey and the surprising parallels between culinary craft and security leadership.The conversation moves through a career that evolved organically: a summer job moving refrigerator-sized printers in a Manhattan ad agency, a crash course in executive white-glove IT support, a breakthrough moment finally cracking subnetting, and a slow expansion from NOC operator to global security leader. Myke credits the kitchen — its insistence on precision and calm under fire — for instilling an operator's mindset that still defines how he leads through incidents today.Mentorship, both formal and accidental, threads through Myke's story. A curmudgeonly colleague who threatened to "replace him with a script" taught him the value of continuous improvement. A trusted mentor reframed the CISO's role with a single line about house fires and lock changes. And years in executive IT support gave Myke an early education in empathy and knowing when not to fix what wasn't asked.Myke and Steve examine a vendor incident where a product leader's dismissive response to a forensics question destroyed credibility with hundreds of customers. The lesson: saying "I don't know, but we'll find out" is not a weakness — it is the most powerful tool a leader has. The same insight applies to M&A due diligence, where reframing technical conversations as expectation-setting exercises turns adversarial interviews into collaborative ones.For Myke, the new CISO is defined by empathy and culture. Know your audience. Think like your customers. Communicate policy changes as explanations, not mandates. Find your internal advocates and invest in them before you need them. The recipe for great security leadership is less about technology than it is about people — and that lesson translates perfectly from the kitchen to the boardroom.Key Topics• Career pivots: from culinary school to IT and cybersecurity• Speed, accuracy, and craft — what kitchen discipline teaches security professionals• Building an operator's mindset and staying calm during security incidents• White-glove executive IT support and the patience, precision, and empathy it develops• Mentorship — formal and accidental — and the lessons that only land in retrospect• The dangers of filling silence with false confidence vs. the power of saying "I don't know"• Crisis communication best practices and what not to do during a vendor incident call• Managing M&A security due diligence with low-emotion, expectation-setting conversations• Building security culture through empathy, clear communication, and internal advocates• Telemetry, log management, and Cribl's role as the data engine for IT and security Guest BioMyke Lyons is the Chief Information Security Officer at Cribl, the AI platform for telemetry trusted by organizations worldwide — including half of the Fortune 100 — to manage IT and security data at any scale.He trained at the Culinary Institute of America with aspirations of becoming a food critic — until a summer IT job in Manhattan set him on an entirely different course. Myke went on to build expertise across networking, NOC operations, and log management, holding CISO positions at Snyk and Collibra before joining Cribl in 2024.Connect with Myke on LinkedIn and learn more about Cribl at cribl.io.GET A DEMO:

ChannelBuzz.ca
ICYMI: Bell Canada bets big on AI in Saskatchewan, WBM says buy your RAM now, and AWS brings AI agents to partner selling

ChannelBuzz.ca

Play Episode Listen Later Mar 23, 2026 5:02


Today is Monday, March 23, 2026. Welcome to In Case You Missed It, our weekly five-minute rundown of important channel news stories that might have flown under the radar last week. This episode of In Case You Missed It is brought to you by ESET Canada. ESET's Women in Cybersecurity Scholarship is now open for 2026, with three $5,000 awards available to women pursuing careers in cybersecurity. Applications close April 8. Learn more and apply. On this episode: Bell Canada bets big on AI in Saskatchewan. Bell Canada and the Government of Saskatchewan announced a 300-megawatt AI data center outside Regina — Canada’s largest purpose-built facility, projected to generate up to $12 billion in economic value for the province. Cerebras Systems and CoreWeave are signed on as anchor tenants. For the Canadian channel, the downstream opportunities in connectivity, edge infrastructure, and AI professional services are worth watching, as is the data sovereignty angle of keeping AI compute on Canadian soil. The Globe and Mail’s take on what this signals about Bell’s broader AI strategy. WBM Technologies says buy your RAM now. WBM’s March IT Procurement Update is the most useful thing a Canadian partner has published this month. Every vendor category is listed as constrained. HPE has seen a 24-30% list price increase in March alone. Fortinet is implementing monthly 10% price increases. HP is coming with another 10%+ increase April 1. WBM’s recommendation: buy the RAM and storage you need for the lifetime of the system. Nature magazine is calling it “RAMmageddon.” AWS brings AI agents to partner selling. At its Global Partner Summit, AWS announced AI-powered sales agents in Partner Central, built on Amazon Bedrock AgentCore. Partners can upload meeting notes, auto-update opportunity records, check funding eligibility, and generate draft MAP funding requests. AWS reports 15% higher win rates and 44% faster close times from its solution matching engine. Another signal that vendors are using AI to fix the administrivia of partner selling. Exabeam launches new MSSP commercial framework. Exabeam expanded its APEX Partner Program with two new licensing models for MSSPs: a single pooled multi-tenant option and a federated subscription model. For partners building or scaling MSSP practices, it’s designed to offer more flexibility in packaging and pricing Exabeam’s SIEM and analytics platform. This week on In The Channel: Canadian MSPs plan the lowest pay increases of any region, and that might not be a bad thing (Tuesday) Most MSP contracts wouldn’t survive a courtroom — here’s where to start fixing that (Wednesday) Cisco Canada sees a “perfect storm” driving multi-year infrastructure refresh (Thursday) From NetSuite President’s Club to grain-to-bottle whisky in the Eastern Townships — our first Life After the Channel episode (Friday) Read Full Transcript Welcome to In Case You Missed It from ChannelBuzz.ca. I’m Robert Dutt, editor of ChannelBuzz.ca. Today is Monday, March 23rd, 2026. Let’s get your week started right. This week’s In Case You Missed It is brought to you by ESET Canada. ESET’s Women in Cybersecurity Scholarship is now open for 2026, with three $5,000 awards available to women pursuing careers in cybersecurity. Applications close April 8th. Learn more and apply at eset.com/ca. ESET – protecting progress. The biggest Canadian tech infrastructure story in a while landed last week, and it didn’t come from Toronto or Montreal or Vancouver. Bell Canada announced a partnership with SaskTel and SaskPower to build a 300-megawatt AI data center outside Regina, Saskatchewan. The facility is projected to generate up to $12 billion in economic value for the province, and it’s being positioned as Canada’s largest purpose-built data center. The anchor tenants tell you where this is headed: Cerebras Systems and CoreWeave, two of the biggest names in AI compute infrastructure, are signed on. This isn’t a general-purpose facility — it’s built for the kind of GPU-dense, power-hungry workloads that AI training and inference demand. For the Canadian channel, there are a few things to watch. Local IT providers in Saskatchewan and Western Canada could see downstream opportunities in connectivity, edge infrastructure, and professional services around AI deployments. The data sovereignty angle is real — keeping AI compute on Canadian soil is increasingly a selling point with public sector and regulated-industry customers. And the scale of this investment signals that Canada is becoming a serious destination for AI infrastructure, not just a market that consumes AI services built somewhere else. If you’re quoting hardware right now, you need to see WBM Technologies’ March procurement update. It’s the most useful thing a Canadian partner has published this month, and the message is blunt: They're telling customers to buy the RAM and storage you need to support your systems for the lifetime of that system. Every single vendor category WBM tracks is now listed as constrained. HPE has seen a 24 to 30 percent list price increase in March alone, with quote validity down to just 14 days. Fortinet is implementing monthly 10 percent price increases. Dell expects further adjustments on March 30th. And HP is coming with another minimum 10 percent increase on April 1st. WBM is linking to Nature magazine, which is calling this “RAMmageddon.” If you’ve been following our coverage of the component shortage over the past few weeks, this is the same story, but it’s accelerating. We’ll have a link to the full WBM update in the show notes. It’s worth bookmarking. Two weeks ago on this podcast, we talked about Ingram Micro’s AgenTeq platform and the push to bring agentic AI into the distribution workflow. Now AWS is doing something similar inside Partner Central. At its Global Partner Summit, AWS announced AI-powered sales agents built on Amazon Bedrock AgentCore. Partners can upload meeting notes and have opportunity records auto-updated. The agent flags whether a deal qualifies for AWS funding programs like MAP and can generate draft funding requests pre-filled with deal details. AWS says partners using its solution matching engine are seeing 15 percent higher win rates and 44 percent faster close times. The pattern is becoming clear: vendors are using AI to fix the messy middle of partner selling — the admin, the quoting, the funding applications, the administrivia. Worth watching how quickly this becomes table stakes. And finally, Exabeam launched a new commercial framework for MSSPs last week, offering two licensing models: a single pooled multi-tenant option and a federated subscription model. The idea is to give managed security service providers more flexibility in how they package and price Exabeam’s SIEM and analytics platform for their customers. For partners building or scaling MSSP practices, it’s worth a look. We’ll have a link in the show notes. Those are some of the things we were paying attention to last week.  Big week ahead on In The Channel.  Peter Kujawa from ConnectWise’s Service Leadership practice on why Canadian MSPs are planning the lowest pay increases of any region — and why that might not be a bad thing.  Rob Scott from Monjur on why most MSP contracts wouldn’t survive a courtroom.  Cisco Canada on the perfect storm driving a multi-year infrastructure refresh.  And our very first Life After the Channel episode, with Martin McNicoll, who went from NetSuite President’s Club to making grain-to-bottle whisky in the Eastern Townships.  For ChannelBuzz.ca, I’m Robert Dutt. Have a great week, and I’ll see you in the channel.

The New CISO
Architect and Firefighter: How a Modern CISO Leads in Crisis

The New CISO

Play Episode Listen Later Mar 12, 2026 48:43


Alan Lucas always wanted to be an architect or a firefighter — as CISO of Worldstream and Greenhouse Datacenters, he has become both. In this episode, he joins host Steve Moore to explore leading cybersecurity at the intersection of design and crisis response.Alan traces his path from Fox-IT through a Dutch cryptocurrency exchange where he arrived post-breach to an organization under near-constant attack from nation-state threat actors. Leading a technically sophisticated but security-anxious leadership team, he learned the lasting power of transparency and directness — and his most memorable measure of success was not a technical control, but a CTO who finally slept through the night.The conversation goes deep into crisis communication. Alan and Steve discuss how the industry has matured from reflexive silence around breaches to embracing transparency as a trust-building tool, the danger of well-meaning legal edits that send customers chasing the wrong narrative, and why the CISO should hold final review over all public incident communications. He also shares his Security Champions Program, tabletop exercise design, and why knowing who to call in a crisis must be mapped out before that crisis arrives.Alan also covers his volunteer work with the DIVD, coaching ethical hackers and supporting responsible disclosure worldwide — an extension of his belief that security, done well, creates trust and enables growth for everyone.The episode closes on "bouncing forward" — the idea that true resilience means using every incident as a forcing function for improvement, not just a return to baseline. Alan frames lessons learned as the most important resilience KPI a security team can own. A masterclass in leading through both calm and chaos. Key Topics• The architect-and-firefighter mindset: building security programs while fighting live fires• Alan's career path from Fox-IT (MSSP) to post-breach CISO at a cryptocurrency exchange• Leading security post-breach — and what "sleeping well again" actually means• The unique threat landscape facing cryptocurrency companies, including nation-state adversaries• The Dutch Institute for Vulnerability Disclosure (DIVD): coordinated, ethical vulnerability disclosure worldwide• Mentoring young ethical hackers: communication, confidence, and responsible disclosure process• Crisis communication: balancing transparency with operational security during active incidents• Why legal edits to breach notifications can mislead customers and create dangerous distractions• The CISO's role as final reviewer of all incident communications• Security Champions Programs: bridging the gap between security and non-technical departments• Tabletop exercise design: running effective simulations in under an hour with non-technical staff• Writing the breach notification letter before the breach happens• Bouncing forward, not bouncing back: using lessons learned as a resilience KPI• Security as a business enabler: positioning the CISO role for organizational growth and confidenceGuest BioAlan Lucas is CISO at Worldstream and Greenhouse Datacenters, two of the Netherlands' leading cloud and data center infrastructure providers. With over a decade of cybersecurity experience, he leads security strategy for mission-critical IT and cloud environments. Prior roles include Fox-IT (MSSP) and LiteBit, a Dutch cryptocurrency exchange where he served as CISO post-breach. Alan also volunteers as a coach at the Dutch Institute for Vulnerability Disclosure (DIVD), mentoring ethical hackers and supporting responsible disclosure globally. He is passionate about security as a catalyst for innovation — and about building a safer digital society, one step at a time.LEARN MORE:

The Data Exchange with Ben Lorica
The Developer's Guide to LLM Security

The Data Exchange with Ben Lorica

Play Episode Listen Later Dec 18, 2025 40:12


Steve Wilson, Chief AI and Product Officer at Exabeam and lead of the OWASP GenAI Security Project, discusses the practical realities of securing Large Language Models and agentic workflows. Subscribe to the Gradient Flow Newsletter

Outcomes Rocket
Why AI Systems Fail When We Assume They Behave Like Software with Steve Wilson, Chief AI & Product Officer for Exabeam

Outcomes Rocket

Play Episode Listen Later Dec 18, 2025 25:35


This podcast is brought to you by Outcomes Rocket, your exclusive healthcare marketing agency. Learn how to accelerate your growth by going to⁠ outcomesrocket.com AI security is no longer optional; it's the foundation that determines whether innovation in healthcare will thrive or fail. In this episode, Steve Wilson, Chief AI & Product Officer for Exabeam and author, discusses the hidden vulnerabilities inside modern AI systems, why traditional software assumptions break down, and how healthcare must rethink safety, trust, and security from the ground up. He explains the risks of prompt injection and indirect prompt injection, highlights the fragile nature of AI “intuition,” and compares securing AI to training unpredictable employees rather than testing deterministic code. Steve also explores issues such as supply chain integrity, output filtering, trust boundaries, and the growing need for continuous evaluation rather than one-time testing. Finally, he shares stories from his early career at Sun Microsystems, Java's early days, startup lessons from the 90s, and how modern AI agents are reshaping cybersecurity operations. Tune in and learn how today's most advanced AI systems can be both powerful and dangerously gullible, and what it takes to secure them! Resources Connect with and follow Steve Wilson on LinkedIn. Follow Exabeam on LinkedIn and visit their website! Buy Steve Wilson's book The Developer's Playbook for Large Language Model Security here.

MONEY FM 89.3 - Workday Afternoon with Claressa Monteiro
Industry Insight: The race to defend against AI before it goes rogue

MONEY FM 89.3 - Workday Afternoon with Claressa Monteiro

Play Episode Listen Later Oct 22, 2025 20:30


In a world where employees can now include autonomous identities with operational access and decision-making power, traditional security models are being pushed to the limit. AI agents have become embedded across enterprise operations and they’re unlocking new frontiers of productivity which is exposing unseen vulnerabilities. On Industry Insight, Lynlee Foo speaks to Kevin Kirkwood, Chief Information Security Officer at Exabeam to find out why conventional defences are falling short, and what best practices global companies are adopting to safeguard enterprise environments against a new class of AI-powered insider threats.See omnystudio.com/listener for privacy information.

The New CISO
From Breach to BISO: Becoming a Security Influencer

The New CISO

Play Episode Listen Later Oct 2, 2025 41:47


Most security professionals know what a CISO does. But what about a BISO? And why are Fortune 500 companies increasingly creating this executive role?In this episode of The New CISO Podcast, host Steve Moore sits down with Evan Ferree, Staff Vice President and Business Information Security Officer at a Fortune 50 company, to decode one of cybersecurity's most misunderstood leadership positions.What You'll Learn:Understanding the BISO Role:What a Business Information Security Officer actually does (and how it differs from a Deputy CISO)When organizations need a BISO - the size, industry, and complexity indicatorsWhy the BISO serves as a "force multiplier" for the security organizationHow to measure and defend BISO value during organizational changeThe Career Journey:Evan's unconventional path from IT infrastructure to executive security leadershipHow a major cybersecurity breach became his "MBA in cybersecurity" in six monthsWhy volunteering for uncomfortable work during crisis creates career opportunitiesThe progression from vulnerability analyst to SOC leadership to Staff VPThe 90% Influence Principle:Why the BISO role is about influence, not authorityHow to navigate multiple business units with different security needsMastering the "why" behind security initiatives for non-technical audiencesBuilding relationships and organizational awareness over timeExecutive Skills That Matter:The "log lines" storytelling framework from Deloitte CISO AcademyDeveloping executive presence through failure and self-awarenessWhen to end a meeting and start over (and why that's okay)Speaking plain English vs. technical jargon with business leadersPractical Career Advice:Transitioning from tactical security operations to strategic leadership rolesWhy getting uncomfortable is essential for growthBuilding business acumen alongside technical expertiseWhy Evan's best security hires came from outside cybersecurityKey Insight: "You are 90% an influencer in this role. Unlike tactical security work where authority and urgency create credibility, the BISO must master explaining why security matters to the business - in terms the business understands."Whether you're a security professional planning your path to executive leadership, a CISO considering adding a BISO function, or a business leader trying to understand how security enables business outcomes, this episode delivers actionable insights from someone who's lived the journey.Guest: Evan Ferree, Staff Vice President & Business Information Security Officer at a Fortune 50 company, with 11 years of progressive security leadership experience spanning Security Operations, threat management, vulnerability management, and business information security.Hosted by: Steve Moore | Produced in partnership with: Exabeam

Channel Chat
#250 James Anderson: You have to do AI - it's not even a debate.

Channel Chat

Play Episode Listen Later Sep 29, 2025 36:47


This week Marc sits down with James Anderson, Channel Director (International) at Abnormal AI. From starting out as a biochemistry graduate and aspiring rugby pro, James has built a career shaping channel strategies across Trend, Quest, Ivanti, Exabeam – and now Abnormal.

Product Thinking
Episode 234: What Product Leaders Are Saying About AI

Product Thinking

Play Episode Listen Later Jul 30, 2025 32:00


In this episode, we delve into the transformative role of AI in product management through conversations with some of the best Product leaders. You'll hear from Anthony Maggio (VP Product Management at Airtable), Jessica Hall (CPO at Just Eat Takeaway), Karthik Suri (CPO at Cornerston OnDemand), Mario Rodriguez (CPO at Github), Steve Wilson (CPO at Exabeam), Darren Wilson (CPO at Soul Machines), and Tamar Yehoshua (Former Glean President of Product and Technology).We explore how AI tools are reshaping strategy and efficiency, while personalizing customer experiences. Join us as we discuss the impact of AI, and the future of product strategy. Are you curious about how AI can revolutionize your product management approach? Tune in to discover insights and practical applications that could redefine your strategies and customer interactions.You'll hear us talk about:10:05 - AI's Role in Product StrategyExplore how product leaders are integrating AI into their strategic planning, focusing on addressing significant business and customer problems. The discussion highlights the experimental applications of AI in enhancing customer journeys and optimizing backend processes.18:45 - Enhancing Customer Interaction with Digital AvatarsWe dive into the world of digital avatars and their role in creating empathetic and personalized customer interactions. This section covers how avatars can be used for language learning and practicing difficult conversations in a non-judgmental setting.27:30 - Cybersecurity in the Age of AIUnderstand the evolving landscape of cybersecurity with AI's influence. Learn about the dual nature of AI in enhancing defenses and creating new threat vectors, emphasizing the importance of rapid AI adoption to stay competitive in the cybersecurity arena.Episode Resources:Anthony Maggio (VP Product Management at Airtable): https://www.linkedin.com/in/anthonymaggio/Jessica Hall (CPO at Just Eat Takeaway): https://www.linkedin.com/in/jessicalrhall/Karthik Suri (CPO at Cornerston OnDemand): http://linkedin.com/in/surikarthik/Mario Rodriguez (CPO at Github): https://www.linkedin.com/in/mariorodriguez3/Steve Wilson (CPO at Exabeam): https://www.linkedin.com/in/wilsonsd/Darren Wilson (CPO at Soul Machines): https://www.linkedin.com/in/dpjwilson/Tamar Yehoshua (Former President of Product): https://www.linkedin.com/in/tamar-yehoshua-886217/Check our new course: https://productinstitute.com/p/mastering-product-strategy-overviewTimestamps:00:00 Coming Up01:37 Intro02:57 AI raising the bar for PMs06:57 Using AI to improve personalization10:52 Reimagining products with emerging AI14:55 AI behind GitHub Copilot20:21 AI's risks and impact on cybersecurity24:22 AI avatars and emotional interaction30:42 How PMs can stay relevant in the AI age

Easy Prey
Why Everyone's A Target

Easy Prey

Play Episode Listen Later Jun 4, 2025 39:04


Some scams are so convincing, they're almost impossible to spot. With phishing emails that look like they're from your bank, deep fake videos that mimic real people, and AI-generated messages that feel personal, it's getting harder to know what's real and what's a trap. In this episode, I sit down with Gabrielle Hempel, a security operations specialist at Exabeam and a current law student at Purdue University. Gabrielle brings a sharp perspective shaped by years in cybersecurity, a master's in cybersecurity and global affairs from NYU, and hands-on experience navigating everything from vulnerability management to executive risk consulting. She even wrote her graduate thesis on critical infrastructure security. We talk about the new era of digital deception, why younger people are actually falling for scams more often, and how criminals are using AI and current events to build trust and bypass defenses. Gabrielle shares practical advice, personal stories, and a fresh way to think about digital safety that could help you spot the next scam before it costs you. Show Notes: [01:09] Gabrielle has held quite a few jobs in cybersecurity. She's currently the Security Operations Strategist at Exabeam.  [01:40] She's involved with anything to do with the internal security operation. [02:04] She majored in psychology and neuroscience. Working in Pharma and with medical devices led her to the path of cybersecurity. [04:34] We learn about an incident that she was involved in. Her parents were attempting to file their taxes with TurboTax, but they were flagged as already filing. This led to a lot of shenanigans with the IRS. [06:29] Most everyone has been a victim to some type of fraud or scam. [07:20] Our information is out there. It's more about staying vigilant and keeping an eye on things. [08:05] A lot of the current scams are blending with the cybercrime ecosystem. [09:17] AI has made it easier for people to craft more convincing phishing emails. [12:51] Are modern phishing emails getting through the spam filters more often? [15:48] How it's not retirees being the people most frequently caught in scams. [16:42] Why 20 to 29 year-olds frequently fall for scams. It could be because of their comfort with technology. [21:12] Better education surrounding threats might be a good idea for young people. [22:47] As scammers get more information about us, targeting will be easier. [24:32] Big trends are voice cloning and deep fakes. [27:51] Scams around shipping fees and tariffs are skyrocketing. [29:15] Advice includes adopting zero trust with communication. [33:10] If you're not expecting it. It's potentially suspect. [34:45] Best practices include doing your due diligence, and if you feel like something may not be legitimate go around and check. Thanks for joining us on Easy Prey. Be sure to subscribe to our podcast on iTunes and leave a nice review.  Links and Resources: Podcast Web Page Facebook Page whatismyipaddress.com Easy Prey on Instagram Easy Prey on Twitter Easy Prey on LinkedIn Easy Prey on YouTube Easy Prey on Pinterest Gabrielle Hempel - LinkedIn Exabeam @gabsmashh on X

ITSPmagazine | Technology. Cybersecurity. Society
Book | The Developer's Playbook for Large Language Model Security: Building Secure AI Applications | A Conversation with Steve Wilson | Redefining CyberSecurity with Sean Martin

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Sep 24, 2024 34:35


Guest: Steve Wilson, Chief Product Officer, Exabeam [@exabeam] & Project Lead,  OWASP Top 10 for Larage Language Model Applications [@owasp]On LinkedIn | https://www.linkedin.com/in/wilsonsd/On Twitter | https://x.com/virtualsteve____________________________Host: Sean Martin, Co-Founder at ITSPmagazine [@ITSPmagazine] and Host of Redefining CyberSecurity Podcast [@RedefiningCyber]On ITSPmagazine | https://www.itspmagazine.com/sean-martinView This Show's Sponsors___________________________Episode NotesIn this episode of Redefining CyberSecurity, host Sean Martin sat down with Steve Wilson, chief product officer at Exabeam, to discuss the critical topic of secure AI development. The conversation revolved around the nuances of developing and deploying large language models (LLMs) in the field of cybersecurity.Steve Wilson's expertise lies at the intersection of AI and cybersecurity, a point he emphasized while sharing his journey from founding the Top 10 group for large language models to authoring his new book, "The Developer's Playbook for Large Language Model Security." In this insightful discussion, Wilson and Martin explore the roles of developers and product managers in ensuring the safety and security of AI systems.One of the key themes in the conversation is the categorization of AI applications into chatbots, co-pilots, and autonomous agents. Wilson explains that while chatbots are open-ended, interacting with users on various topics, co-pilots focus on enhancing productivity within specific domains by interacting with user data. Autonomous agents are more independent, executing tasks with minimal human intervention.Wilson brings attention to the concept of overreliance on AI models and the associated risks. Highlighting that large language models can hallucinate or produce unreliable outputs, he stresses the importance of designing systems that account for these limitations. Product managers play a crucial role here, ensuring that AI applications are built to mitigate risks and communicate their reliability to users effectively.The discussion also touches on the importance of security guardrails and continuous monitoring. Wilson introduces the idea of using tools akin to web app firewalls (WAF) or runtime application self-protection (RASP) to keep AI models within safe operational parameters. He mentions frameworks like Nvidia's open-source project, Nemo Guardrails, which aid developers in implementing these defenses.Moreover, the conversation highlights the significance of testing and evaluation in AI development. Wilson parallels the education and evaluation of LLMs to training and testing a human-like system, underscoring that traditional unit tests may not suffice. Instead, flexible test cases and advanced evaluation tools are necessary. Another critical aspect Wilson discusses is the need for red teaming in AI security. By rigorously testing AI systems and exploring their vulnerabilities, organizations can better prepare for real-world threats. This proactive approach is essential for maintaining robust AI applications.Finally, Wilson shares insights from his book, including the Responsible AI Software Engineering (RAISE) framework. This comprehensive guide offers developers and product managers practical steps to integrate secure AI practices into their workflows. With an emphasis on continuous improvement and risk management, the RAISE framework serves as a valuable resource for anyone involved in AI development.About the BookLarge language models (LLMs) are not just shaping the trajectory of AI, they're also unveiling a new era of security challenges. This practical book takes you straight to the heart of these threats. Author Steve Wilson, chief product officer at Exabeam, focuses exclusively on LLMs, eschewing generalized AI security to delve into the unique characteristics and vulnerabilities inherent in these models.Complete with collective wisdom gained from the creation of the OWASP Top 10 for LLMs list—a feat accomplished by more than 400 industry experts—this guide delivers real-world guidance and practical strategies to help developers and security teams grapple with the realities of LLM applications. Whether you're architecting a new application or adding AI features to an existing one, this book is your go-to resource for mastering the security landscape of the next frontier in AI.___________________________SponsorsImperva: https://itspm.ag/imperva277117988LevelBlue: https://itspm.ag/attcybersecurity-3jdk3___________________________Watch this and other videos on ITSPmagazine's YouTube ChannelRedefining CyberSecurity Podcast with Sean Martin, CISSP playlist:

Redefining CyberSecurity
Book | The Developer's Playbook for Large Language Model Security: Building Secure AI Applications | A Conversation with Steve Wilson | Redefining CyberSecurity with Sean Martin

Redefining CyberSecurity

Play Episode Listen Later Sep 24, 2024 34:35


Guest: Steve Wilson, Chief Product Officer, Exabeam [@exabeam] & Project Lead,  OWASP Top 10 for Larage Language Model Applications [@owasp]On LinkedIn | https://www.linkedin.com/in/wilsonsd/On Twitter | https://x.com/virtualsteve____________________________Host: Sean Martin, Co-Founder at ITSPmagazine [@ITSPmagazine] and Host of Redefining CyberSecurity Podcast [@RedefiningCyber]On ITSPmagazine | https://www.itspmagazine.com/sean-martinView This Show's Sponsors___________________________Episode NotesIn this episode of Redefining CyberSecurity, host Sean Martin sat down with Steve Wilson, chief product officer at Exabeam, to discuss the critical topic of secure AI development. The conversation revolved around the nuances of developing and deploying large language models (LLMs) in the field of cybersecurity.Steve Wilson's expertise lies at the intersection of AI and cybersecurity, a point he emphasized while sharing his journey from founding the Top 10 group for large language models to authoring his new book, "The Developer's Playbook for Large Language Model Security." In this insightful discussion, Wilson and Martin explore the roles of developers and product managers in ensuring the safety and security of AI systems.One of the key themes in the conversation is the categorization of AI applications into chatbots, co-pilots, and autonomous agents. Wilson explains that while chatbots are open-ended, interacting with users on various topics, co-pilots focus on enhancing productivity within specific domains by interacting with user data. Autonomous agents are more independent, executing tasks with minimal human intervention.Wilson brings attention to the concept of overreliance on AI models and the associated risks. Highlighting that large language models can hallucinate or produce unreliable outputs, he stresses the importance of designing systems that account for these limitations. Product managers play a crucial role here, ensuring that AI applications are built to mitigate risks and communicate their reliability to users effectively.The discussion also touches on the importance of security guardrails and continuous monitoring. Wilson introduces the idea of using tools akin to web app firewalls (WAF) or runtime application self-protection (RASP) to keep AI models within safe operational parameters. He mentions frameworks like Nvidia's open-source project, Nemo Guardrails, which aid developers in implementing these defenses.Moreover, the conversation highlights the significance of testing and evaluation in AI development. Wilson parallels the education and evaluation of LLMs to training and testing a human-like system, underscoring that traditional unit tests may not suffice. Instead, flexible test cases and advanced evaluation tools are necessary. Another critical aspect Wilson discusses is the need for red teaming in AI security. By rigorously testing AI systems and exploring their vulnerabilities, organizations can better prepare for real-world threats. This proactive approach is essential for maintaining robust AI applications.Finally, Wilson shares insights from his book, including the Responsible AI Software Engineering (RAISE) framework. This comprehensive guide offers developers and product managers practical steps to integrate secure AI practices into their workflows. With an emphasis on continuous improvement and risk management, the RAISE framework serves as a valuable resource for anyone involved in AI development.About the BookLarge language models (LLMs) are not just shaping the trajectory of AI, they're also unveiling a new era of security challenges. This practical book takes you straight to the heart of these threats. Author Steve Wilson, chief product officer at Exabeam, focuses exclusively on LLMs, eschewing generalized AI security to delve into the unique characteristics and vulnerabilities inherent in these models.Complete with collective wisdom gained from the creation of the OWASP Top 10 for LLMs list—a feat accomplished by more than 400 industry experts—this guide delivers real-world guidance and practical strategies to help developers and security teams grapple with the realities of LLM applications. Whether you're architecting a new application or adding AI features to an existing one, this book is your go-to resource for mastering the security landscape of the next frontier in AI.___________________________SponsorsImperva: https://itspm.ag/imperva277117988LevelBlue: https://itspm.ag/attcybersecurity-3jdk3___________________________Watch this and other videos on ITSPmagazine's YouTube ChannelRedefining CyberSecurity Podcast with Sean Martin, CISSP playlist:

ITSPmagazine | Technology. Cybersecurity. Society
OWASP Top 10 For Large Language Models: Project Update | An OWASP 2024 Global AppSec San Francisco Conversation with Steve Wilson | On Location Coverage with Sean Martin and Marco Ciappelli

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Aug 20, 2024 23:31


Guest: Steve Wilson, Chief Product Officer, Exabeam [@exabeam] & Project Lead,  OWASP Top 10 for Larage Language Model Applications [@owasp]On LinkedIn | https://www.linkedin.com/in/wilsonsd/On Twitter | https://x.com/virtualsteve____________________________Hosts: Sean Martin, Co-Founder at ITSPmagazine [@ITSPmagazine] and Host of Redefining CyberSecurity Podcast [@RedefiningCyber]On ITSPmagazine | https://www.itspmagazine.com/sean-martinMarco Ciappelli, Co-Founder at ITSPmagazine [@ITSPmagazine] and Host of Redefining Society PodcastOn ITSPmagazine | https://www.itspmagazine.com/itspmagazine-podcast-radio-hosts/marco-ciappelli____________________________Episode NotesIn this episode of the Chat on the Road On Location series for OWASP AppSec Global in San Francisco, Sean Martin hosts a compelling conversation with Steve Wilson, Project Lead for the OWASP Top 10 for Large Language Model AI Applications. The discussion, as you might guess, centers on the OWASP Top 10 list for Large Language Models (LLMs) and the security challenges associated with these technologies. Wilson highlights the growing relevance of AppSec, particularly with the surge in interest in AI and LLMs.The conversation kicks off with an exploration of the LLM project that Wilson has been working on at OWASP, aimed at presenting an update on the OWASP Top 10 for LLMs. Wilson emphasizes the significance of prompt injection attacks, one of the key concerns on the OWASP list. He explains how attackers can craft prompts to manipulate LLMs into performing unintended actions, a tactic reminiscent of the SQL injection attacks that have plagued traditional software for years. This serves as a stark reminder of the need for vigilance in the development and deployment of LLMs.Supply chain risks are another critical issue discussed. Wilson draws parallels to the Log4j incident, stressing that the AI software supply chain is currently a weak link. With the rapid growth of platforms like Hugging Face, the provenance of AI models and training datasets becomes a significant concern. Ensuring the integrity and security of these components is paramount to building robust AI-driven systems.The notion of excessive agency is also explored—a concept that relates to the permissions and responsibilities assigned to LLMs. Wilson underscores the importance of limiting the scope of LLMs to prevent misuse or unauthorized actions. This point resonates with traditional security principles like least privilege but is recontextualized for the AI age. Overreliance on LLMs is another topic Martin and Wilson discuss.The conversation touches on how people can place undue trust in AI outputs, leading to potentially hazardous outcomes. Ensuring users understand the limitations and potential inaccuracies of LLM-generated content is essential for safe and effective AI utilization.Wilson also provides a preview of his upcoming session at the OWASP AppSec Global event, where he plans to share insights from the ongoing work on the 2.0 version of the OWASP Top 10 for LLMs. This next iteration will address how the field has matured and new security considerations that have emerged since the initial list.Be sure to follow our Coverage Journey and subscribe to our podcasts!____________________________This Episode's SponsorsAre you interested in sponsoring our event coverage with an ad placement in the podcast?Learn More

Redefining CyberSecurity
OWASP Top 10 For Large Language Models: Project Update | An OWASP 2024 Global AppSec San Francisco Conversation with Steve Wilson | On Location Coverage with Sean Martin and Marco Ciappelli

Redefining CyberSecurity

Play Episode Listen Later Aug 20, 2024 23:31


Guest: Steve Wilson, Chief Product Officer, Exabeam [@exabeam] & Project Lead,  OWASP Top 10 for Larage Language Model Applications [@owasp]On LinkedIn | https://www.linkedin.com/in/wilsonsd/On Twitter | https://x.com/virtualsteve____________________________Hosts: Sean Martin, Co-Founder at ITSPmagazine [@ITSPmagazine] and Host of Redefining CyberSecurity Podcast [@RedefiningCyber]On ITSPmagazine | https://www.itspmagazine.com/sean-martinMarco Ciappelli, Co-Founder at ITSPmagazine [@ITSPmagazine] and Host of Redefining Society PodcastOn ITSPmagazine | https://www.itspmagazine.com/itspmagazine-podcast-radio-hosts/marco-ciappelli____________________________Episode NotesIn this episode of the Chat on the Road On Location series for OWASP AppSec Global in San Francisco, Sean Martin hosts a compelling conversation with Steve Wilson, Project Lead for the OWASP Top 10 for Large Language Model AI Applications. The discussion, as you might guess, centers on the OWASP Top 10 list for Large Language Models (LLMs) and the security challenges associated with these technologies. Wilson highlights the growing relevance of AppSec, particularly with the surge in interest in AI and LLMs.The conversation kicks off with an exploration of the LLM project that Wilson has been working on at OWASP, aimed at presenting an update on the OWASP Top 10 for LLMs. Wilson emphasizes the significance of prompt injection attacks, one of the key concerns on the OWASP list. He explains how attackers can craft prompts to manipulate LLMs into performing unintended actions, a tactic reminiscent of the SQL injection attacks that have plagued traditional software for years. This serves as a stark reminder of the need for vigilance in the development and deployment of LLMs.Supply chain risks are another critical issue discussed. Wilson draws parallels to the Log4j incident, stressing that the AI software supply chain is currently a weak link. With the rapid growth of platforms like Hugging Face, the provenance of AI models and training datasets becomes a significant concern. Ensuring the integrity and security of these components is paramount to building robust AI-driven systems.The notion of excessive agency is also explored—a concept that relates to the permissions and responsibilities assigned to LLMs. Wilson underscores the importance of limiting the scope of LLMs to prevent misuse or unauthorized actions. This point resonates with traditional security principles like least privilege but is recontextualized for the AI age. Overreliance on LLMs is another topic Martin and Wilson discuss.The conversation touches on how people can place undue trust in AI outputs, leading to potentially hazardous outcomes. Ensuring users understand the limitations and potential inaccuracies of LLM-generated content is essential for safe and effective AI utilization.Wilson also provides a preview of his upcoming session at the OWASP AppSec Global event, where he plans to share insights from the ongoing work on the 2.0 version of the OWASP Top 10 for LLMs. This next iteration will address how the field has matured and new security considerations that have emerged since the initial list.Be sure to follow our Coverage Journey and subscribe to our podcasts!____________________________This Episode's SponsorsAre you interested in sponsoring our event coverage with an ad placement in the podcast?Learn More

Gestalt IT Rundown
Announcements from Dell Tech World and Dell's New AI PCs | The Gestalt IT Rundown: May 22, 2024

Gestalt IT Rundown

Play Episode Listen Later May 22, 2024 50:51


Pat Moorhead and Daniel Newman sat down with Sam Burd to discuss AI PCs at Dell Tech World. These new PCs include significant new AI integrations, and Dell expects these to initiate a "super cycle" of PC upgrades. We discussed the importance of Qualcomm Snapdragon X Elite earlier in the program, but what should we make of the market for AI PCs? This and more announcements from Dell Tech World on The Rundown. Time Stamps: 0:00 - Welcome to The Rundown 1:00 - Dell Writes a HYCU in their PowerProtect DataDomain 3:36 - GitHub Patches Massive Security Hole in Enterprise Servers 6:45 - Palo Alto Networks Acquires IBM QRadar 10:35 - Exabeam and LogRhythm to Merge to Strengthen AI-Driven Security Future 14:00 - PC Makers Debut AI PCs with Microsoft CoPilot+ 19:36 - CoPilot+ Totally Recalls Everything 23:09 - Announcements from Dell Tech World 23:55 - Dell AI Factory Using NVIDIA for AI Adoption 26:55 - Dell collaborates with NVIDIA, Microsoft, and ServiceNow on Dell NativeEdge 32:50 - Dell PowerStore using APEX AI innovations to Improve Storage Performance, Efficiency, and Resiliency 36:08 - Dell's AI PCs using Copilot+ 47:22 - The Weeks Ahead Hosts: Tom Hollingsworth: https://www.twitter.com/NetworkingNerd Stephen Foskett: https://www.twitter.com/SFoskett Follow Gestalt IT Website: https://www.GestaltIT.com/ Twitter: https://www.twitter.com/GestaltIT LinkedIn: https://www.linkedin.com/company/Gestalt-IT Tags: #Rundown, #DellTechWorld, #Copilot, #AI, @TheSixFiveMedia, @TheFuturumGroup, @TechFieldDay, @GestaltIT, @SFoskett, @NetworkingNerd, @DellTech, @DanielNewmanUV, @Krista_Lee, @PatrickMoorhead, @HYCU_Inc, @GitHub, @IBM, @PaloAltoNtwks, @LogRhythm, @Exabeam, @Qualcomm, @DellTech, @Lenovo, @HP, @Microsoft, @NVIDIA, @ServiceNow,

Packet Pushers - Full Podcast Feed
NB479: Solar Storm Survival; Cisco's Sinking Revenue Doesn't Dampen Wall Street

Packet Pushers - Full Podcast Feed

Play Episode Listen Later May 20, 2024 41:52


Take a Network Break! This week we discuss what IBM and Palo Alto Networks get out of a deal for Palo Alto Networks to buy the SaaS version of the QRadar SIEM from IBM, why LogRhythm is merging with Exabeam, and how Google is positioning its latest AI chip to take on the Nvidia juggernaut.... Read more »

Packet Pushers - Network Break
NB479: Solar Storm Survival; Cisco's Sinking Revenue Doesn't Dampen Wall Street

Packet Pushers - Network Break

Play Episode Listen Later May 20, 2024 41:52


Take a Network Break! This week we discuss what IBM and Palo Alto Networks get out of a deal for Palo Alto Networks to buy the SaaS version of the QRadar SIEM from IBM, why LogRhythm is merging with Exabeam, and how Google is positioning its latest AI chip to take on the Nvidia juggernaut.... Read more »

Packet Pushers - Fat Pipe
NB479: Solar Storm Survival; Cisco's Sinking Revenue Doesn't Dampen Wall Street

Packet Pushers - Fat Pipe

Play Episode Listen Later May 20, 2024 41:52


Take a Network Break! This week we discuss what IBM and Palo Alto Networks get out of a deal for Palo Alto Networks to buy the SaaS version of the QRadar SIEM from IBM, why LogRhythm is merging with Exabeam, and how Google is positioning its latest AI chip to take on the Nvidia juggernaut.... Read more »

TechCrunch Startups – Spoken Edition
Thoma Bravo's LogRhythm merges with Exabeam in more cybersecurity consolidation

TechCrunch Startups – Spoken Edition

Play Episode Listen Later May 20, 2024 3:36


Private equity giant Thoma Bravo has announced that its security information and event management (SIEM) company LogRhythm will be merging with Exabeam, a rival cybersecurity company backed by the likes of Cisco and Lightspeed Venture Partners. Learn more about your ad choices. Visit podcastchoices.com/adchoices

Paul's Security Weekly
Post-RSAC, Our Heads Are Spinning, and Big News Keeps on Coming! Plus On-Site Interviews from RSAC - ESW #362

Paul's Security Weekly

Play Episode Listen Later May 16, 2024 147:32


Suddenly SIEMs are all over the news! In a keynote presentation, Crowdstrike CEO George Kurtz talked about the company's "next-gen" SIEM. Meanwhile, Palo Alto, who was taken to task by some for not having an active presence on the RSAC expo floor, hits the headlines for acquiring IBM's SIEM product, just to shut it down! Meanwhile, LogRhythm and Exabeam merge, likely with the hopes of weathering the coming storm. The situation seems clear - there's no such thing as "best of breed" SIEM anymore. It's a commodity to be attached to the existing dominant security platforms. Are the days numbered for the older pure-play SIEM/SOAR vendors out there? Crowdstrike and Palo Alto alone could displace a lot of incumbents, even with a less than stellar product. Visit the show notes for full descriptions on each RSAC executive interview! Show Notes: https://securityweekly.com/esw-362

PSFK's PurpleList
Cisco Systems Earnings Call - CSCO

PSFK's PurpleList

Play Episode Listen Later May 16, 2024 3:20


During the earnings call, Cisco Systems acknowledged the competitive landscape in cybersecurity and observability, as evidenced by Palo Alto Networks' acquisition of Exabeam. However, Cisco highlighted its strategic strengths in these areas, emphasizing the value of an integrated, unified platform for end-to-end security and insightful solutions.The company stated its focus on the immediate integration of its XDR (Extended Detection and Response) solution with Splunk Enterprise Security, showcasing its commitment to harnessing the combined strengths of Cisco and Splunk. This integration represents progress in developing seamless product alliances, innovative solutions, and robust go-to-market strategies.Furthermore, Cisco has integrated AI capabilities into its cybersecurity offerings, such as Cisco Hypershield, to differentiate itself from competitors relying on standalone products. The company asserted that embedding security within the network fabric provides a unique and significant market differentiation.Cisco's strategic emphasis on integration, AI capabilities, and unified platforms in cybersecurity and observability positions the company to leverage market opportunities and address evolving industry challenges effectively.Navigating Macroeconomic Challenges and Sector-Specific DynamicsWhile Cisco experienced revenue declines in its core networking business due to inventory implementations, its security and observability segments saw growth driven by innovations and the integration of Splunk. The company acknowledged the ongoing macroeconomic challenges, particularly in the telco and cable segments, although some stabilization was noted in the Webscale sector.Cisco's CEO, Chuck Robbins, stated, "So from a macro perspective, what I would say is that ironically, we saw the quarter actually slow -- showed slight improvement as we move through the quarter." The company's strong cash flow and strategic investments in AI, security, and the Splunk integration position it well for future growth, despite these headwinds.Balancing Growth Opportunities and Competitive PressuresCisco Systems reported mixed financial results, with revenues for Q3 down 13% year-over-year at $12.7 billion, primarily due to reduced product revenue. However, service revenue saw a 6% uptick, and the recent acquisition of Splunk added $413 million post-close, boosting annualized recurring revenue to $29.2 billion. Gross margins remained strong at 68.3%, and operating margins stayed steady.While the company faced declines in its core networking business, key customer sectors like data center and campus switching, security, and collaboration witnessed order increases. Capital returns to shareholders amounted to a robust $2.9 billion in Q3.Moving forward, Cisco Systems must navigate the competitive waters while capitalizing on growth opportunities in cybersecurity and observability. The company's strategic focus on integration, AI capabilities, and unified platforms positions it to address evolving industry challenges and leverage market opportunities effectively. This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit theearningscall.substack.com

Enterprise Security Weekly (Audio)
Post-RSAC, Our Heads Are Spinning, and Big News Keeps on Coming! Plus On-Site Interviews from RSAC - ESW #362

Enterprise Security Weekly (Audio)

Play Episode Listen Later May 16, 2024 147:32


Suddenly SIEMs are all over the news! In a keynote presentation, Crowdstrike CEO George Kurtz talked about the company's "next-gen" SIEM. Meanwhile, Palo Alto, who was taken to task by some for not having an active presence on the RSAC expo floor, hits the headlines for acquiring IBM's SIEM product, just to shut it down! Meanwhile, LogRhythm and Exabeam merge, likely with the hopes of weathering the coming storm. The situation seems clear - there's no such thing as "best of breed" SIEM anymore. It's a commodity to be attached to the existing dominant security platforms. Are the days numbered for the older pure-play SIEM/SOAR vendors out there? Crowdstrike and Palo Alto alone could displace a lot of incumbents, even with a less than stellar product. Visit the show notes for full descriptions on each RSAC executive interview! Show Notes: https://securityweekly.com/esw-362

Paul's Security Weekly TV
Post-RSAC, Our Heads Are Spinning, and Big News Keeps on Coming! - ESW #362

Paul's Security Weekly TV

Play Episode Listen Later May 16, 2024 57:29


Suddenly SIEMs are all over the news! In a keynote presentation, Crowdstrike CEO George Kurtz talked about the company's "next-gen" SIEM. Meanwhile, Palo Alto, who was taken to task by some for not having an active presence on the RSAC expo floor, hits the headlines for acquiring IBM's SIEM product, just to shut it down! Meanwhile, LogRhythm and Exabeam merge, likely with the hopes of weathering the coming storm. The situation seems clear - there's no such thing as "best of breed" SIEM anymore. It's a commodity to be attached to the existing dominant security platforms. Are the days numbered for the older pure-play SIEM/SOAR vendors out there? Crowdstrike and Palo Alto alone could displace a lot of incumbents, even with a less than stellar product. Show Notes: https://securityweekly.com/esw-362

Enterprise Security Weekly (Video)
Post-RSAC, Our Heads Are Spinning, and Big News Keeps on Coming! - ESW #362

Enterprise Security Weekly (Video)

Play Episode Listen Later May 16, 2024 57:29


Suddenly SIEMs are all over the news! In a keynote presentation, Crowdstrike CEO George Kurtz talked about the company's "next-gen" SIEM. Meanwhile, Palo Alto, who was taken to task by some for not having an active presence on the RSAC expo floor, hits the headlines for acquiring IBM's SIEM product, just to shut it down! Meanwhile, LogRhythm and Exabeam merge, likely with the hopes of weathering the coming storm. The situation seems clear - there's no such thing as "best of breed" SIEM anymore. It's a commodity to be attached to the existing dominant security platforms. Are the days numbered for the older pure-play SIEM/SOAR vendors out there? Crowdstrike and Palo Alto alone could displace a lot of incumbents, even with a less than stellar product. Show Notes: https://securityweekly.com/esw-362

The Modern People Leader
176 - Building an AI roadmap for HR & 6 use cases for AI in HR: Gianna Driver (CHRO, Exabeam)

The Modern People Leader

Play Episode Listen Later May 6, 2024 57:49


Gianna Driver, CHRO at Exabeam, joined us on The Modern People Leader. We talked about how Exabeam's HR team built their AI roadmap and which AI for HR use cases have been the most successful for them. ---- [02:00] - Good news stories [06:00] - Gianna's career journey and her unexpected path into HR [10:00] - Discussion on pivotal career moments and the importance of supportive leadership [13:00] - Learning from failures [17:00] - Gianna talks about the integration and challenges of implementing AI within HR at Exabeam [21:00] - Initial failures and subsequent successes in adopting AI for HR at Exabeam [25:00] - Practical applications of AI in writing job descriptions and updating employee handbooks [30:00] - The potential and limitations of AI in handling complex HR tasks and strategic decision-making [34:00] - Gianna offers her perspectives on the future roles of AI in enhancing employee experience and development [40:00] - Discussing the ethical considerations and policy frameworks necessary for AI deployment in HR [45:00] - Closing thoughts on the importance of courage and innovation in HR ----

The Talent Tango
From Contributor to Leader: Navigating the Shift

The Talent Tango

Play Episode Listen Later Feb 28, 2024 4:52


In this podcast episode, Angelique Cuevas, the Director of Talent Acquisition at Exabeam, shares insights about her journey from an individual contributor role to a leadership position. Discussing her initial struggle with the shifting dynamics of peer relationships, Cuevas presents various strategic approaches and methods implemented to ensure smooth transitions within the company. She highlights the need to learn and unlearn in this ever-evolving professional landscape. She also emphasizes the role of communication, delegation, and understanding individual career growth paths in successful people management.  Highlights: 01:19 Transitioning from Individual Contributor to Leader 02:22 Angelique's Journey to Leadership 04:39 Challenges of Becoming a People Leader 07:03 The Importance of Talent Acquisition 08:33 Navigating Relationship Dynamics as a New Manager 12:39 Learning from Mistakes and Adapting Strategy 18:36 Empowering Team Members and Facilitating Growth Guest: Angelique Cuevas began her career in social work, volunteering as the Outreach Counselor. In this role, she attended county events to promote the services of the group home, a period during which she discovered a passion for connecting with and assisting people. This realization prompted a career transition into the tech startup sector, where she worked closely with the HR department. Eventually, Angelique took on full responsibility for managing all aspects of Recruiting, including training, system implementation, interview best practices, and the hiring and onboarding processes. https://www.linkedin.com/in/angelique-cuevas-918864a3/ ------ Thank you so much for checking out this episode of The Talent Tango, and we would appreciate it if you would take a minute to rate and review us on your favorite podcast player. Want to learn more about us? Head over at https://www.elevano.com Have questions or want to cover specific topics with our future guests? Please message me at https://www.linkedin.com/in/amirbormand (Amir Bormand)  

Talent Acquisition Trends & Strategy
EP 132: Best of innovation and culture chats, with three leading experts.

Talent Acquisition Trends & Strategy

Play Episode Listen Later Oct 31, 2023 22:50 Transcription Available


In this episode we wanted to put together for our listeners some of the best of our innovations in talent and culture chats.  Shauna Geraghty, SVP & Global Head of People & Talent at Talkdesk, will share invaluable insights on optimizing the quality of hire. Debbie Shotwell, CPO at Stack Overflow, will delve into the secrets of developing a strong and vibrant company culture. Gianna Driver, CHRO at Exabeam, will challenge traditional notions of 'culture fit' and explore how embracing 'culture add' can ignite innovation within your organization. 1:15 Shauna Geraghty, SVP & Global Head of People & Talent at Talkdesk - Optimizing the quality of hire9:18 Debbie Shotwell, CPO at Stack Overflow - Employee well-being and onboarding process15:03 Gianna Driver, CHRO at Exabeam - Shifting culture fit to culture add Thank you to our sponsor, SecureVision, for making this show possible! Our host James Mackey Follow us:https://www.linkedin.com/company/82436841/#1 Rated Embedded Recruitment Firm on G2!https://www.g2.com/products/securevision/reviewsThanks for listening!

Talent Acquisition Trends & Strategy
EP 118: Building high-performing teams in late stage: Shifting from culture fit to culture add with Gianna Driver, CHRO at Exabeam.

Talent Acquisition Trends & Strategy

Play Episode Listen Later Sep 12, 2023 27:38 Transcription Available


Ready to revolutionize your hiring process and build high-performing teams that add value to your organization? Join our host James Mackey and Gianna Driver, Chief Human Resources Officer at Exabeam, and discover how to redefine 'culture fit' as 'culture add,' and boost innovation. They share insights on measuring diversity impact, addressing performance issues, and handling workplace toxicity in the tech sector.   0:34 Gianna Driver's background   1:43 Effective hiring for high-performing teams11:38 Building diverse and inclusive workplaces16:52 Handling workplace toxicity in the tech sector.21:35 Importance of employee sentiment and feedback Thank you to our sponsor, SecureVision, for making this show possible! Our host James Mackey Follow us:https://www.linkedin.com/company/82436841/#1 Rated Embedded Recruitment Firm on G2!https://www.g2.com/products/securevision/reviewsThanks for listening!

Cribl: The Stream Life
Cribl and Exabeam Aim to Accelerate Technology Adoption for Customers

Cribl: The Stream Life

Play Episode Listen Later Aug 10, 2023 25:06


In this episode of The Stream Life Podcast, Cribl's Desi Gavis-Hughson and Exabeam's Chris Stewart join the show to talk about the big news out of Black Hat 2023: Cribl and Exabeam's strategic partnership! Resources Press Release Blog Cribl's solutions with Exabeam If you want to automatically get every episode of the Stream Life podcast, you can subscribe on your favorite podcast app.

Aarna's News | Inspiring and Uplifting Stories of Women In STEM
056 Ronit Polak: Breaking the Glass Ceiling & Overcoming Bias In The Workplace

Aarna's News | Inspiring and Uplifting Stories of Women In STEM

Play Episode Listen Later Jul 10, 2023 31:15


Join industry experts, trailblazers, and advocates, including Ronit Polak, VP of Engineering at Exabeam and President of Women in Cybersecurity Silicon Valley Affiliate, as we explore strategies for overcoming gender bias in the workplace. Gain insights into personal stories, challenges faced by women, and practical solutions to foster equality and create inclusive work environments. Let's shatter the glass ceiling and empower everyone to thrive. Don't miss this thought-provoking episode! Ronit's Information Resources Mentioned: Lean In by Sheryl Sandberg --- Support this podcast: https://podcasters.spotify.com/pod/show/aarna-sahu/support

Modern Business Operations
Leading With Empathy

Modern Business Operations

Play Episode Listen Later May 18, 2023 25:35


This week, host Sagi Eliyahu is joined by Gianna Driver, Chief Human Resources Officer at Exabeam. The focus of the conversation is on empathy and transparency with the people in an organization.Topics discussed include:- The amount of change and destabilization humans have gone through in the past few years.- The role of empathy in attracting and retaining talent in the workplace.- The importance of being empathic while still holding people accountable.- Tools and technology that allow people to anonymously express their opinions or feelings.- Transparency and openness in an organization.Gianna Driver - https://www.linkedin.com/in/gianna-driver-6183391/Exabeam - https://www.linkedin.com/company/exabeam/This episode is brought to you by Tonkean. Tonkean is the operating system for business operations and is the enterprise standard for process orchestration. It provides businesses with the building blocks to orchestrate any process, with no code or change management required. Contact us at tonkean.com to learn how you can build complex business processes. Fast.#Operations #BusinessOperations

The Empathy Edge
Gianna Driver: The Link Between Diversity, Inclusivity, and Performance

The Empathy Edge

Play Episode Listen Later Jan 31, 2023 33:22


When we talk about diversity, equity, and inclusion, or DEI, some leaders still roll their eyes or assume they have bigger fish to fry. But, happily, the trendline shows that companies that can move beyond diversity into true inclusivity experience sustained growth, higher performance, and more revenue. They are the ones harnessing more innovation, attracting top talent, getting more ideas and innovation from their people, and frankly, making smarter business decisions.Today, I talk to Gianna Driver about how DEI efforts support organizational goals and the link between DEI efforts and bottom-line performance. She shares how a company can make the leap from a diverse culture to a truly inclusive one in order to better enjoy those benefits. Gianna shares the ground rules you need to set to make DEI work, and how to be empathetic to - yet manage executive resistance to change. And we talk about her personal story growing up Filipino-American and how it shaped her passion for empowering people. Key Takeaways:People are at the heart and center of everything you do. If you are trying to make a change in your organization, you need to remember that. Healthy relationships have conflict. What matters is not the existence of conflict, but how individuals resolve conflict; the same is true of organizations.We do not leave our humanity at the door when we come to work. Employees need to be treated as humans with respect and multiple facets of their lives. When employees thrive, they bring their best selves to work and have higher performance as a result.  "Conflict is necessary for high performance and innovation. What differentiates are those organizations who have found ways to create spaces where people can respectfully and healthfully disagree and come up with better solutions together." —  Gianna Driver About Gianna Driver, CHRO, ExabeamGianna Driver is Chief Human Resources Officer (CHRO) at Exabeam, a global cybersecurity leader that adds intelligence to every IT and security stack. As CHRO, Driver manages the strategy and processes related to building, investing in, and retaining top talent at Exabeam, enabling employees to do their best work. She is responsible for architecting the company's talent strategy, driving corporate culture and diversity, equity and inclusion (DEI) initiatives, and leading the global human resources function. Prior to Exabeam, Driver was the Chief People Officer at BlueVine, a private fin-tech company based in Redwood City, CA. Driver has also led HR and People functions in high-growth technology, gaming, consumer, and SaaS organizations including Playstudios, Aristocrat, Actian Corporation, Talend, and Balsam Brands. She is passionate about building high-performance cultures, establishing operational excellence, and creating joy at work. Driver is a graduate of The Wharton School of the University of Pennsylvania.References MentionedThe Empathy Edge podcast: M.E. Hart: How to Have Honest Conversations at WorkConnect with Gianna DriverWebsite: https://exabeam.comLinkedIn: https://www.linkedin.com/in/gianna-driver-6183391/  Don't forget to download your free guide! Discover The 5 Business Benefits of Empathy: http://red-slice.com/business-benefits-empathy  Connect with Maria: Get the podcast and book: TheEmpathyEdge.comLearn more about Maria and her work: Red-Slice.comHire Maria to speak at your next event: Red-Slice.com/Speaker-Maria-RossTake my LinkedIn Learning Course! Leading with EmpathyLinkedIn: Maria RossInstagram: @redslicemariaTwitter: @redsliceFacebook: Red Slice

The Empathy Edge
Gianna Driver: The Link Between Diversity, Inclusivity, and Performance

The Empathy Edge

Play Episode Listen Later Jan 31, 2023 33:21


When we talk about diversity, equity, and inclusion, or DEI, some leaders still roll their eyes or assume they have bigger fish to fry. But, happily, the trendline shows that companies that can move beyond diversity into true inclusivity experience sustained growth, higher performance, and more revenue. They are the ones harnessing more innovation, attracting top talent, getting more ideas and innovation from their people, and frankly, making smarter business decisions.Today, I talk to Gianna Driver about how DEI efforts support organizational goals and the link between DEI efforts and bottom-line performance. She shares how a company can make the leap from a diverse culture to a truly inclusive one in order to better enjoy those benefits. Gianna shares the ground rules you need to set to make DEI work, and how to be empathetic to - yet manage executive resistance to change. And we talk about her personal story growing up Filipino-American and how it shaped her passion for empowering people. Key Takeaways:People are at the heart and center of everything you do. If you are trying to make a change in your organization, you need to remember that. Healthy relationships have conflict. What matters is not the existence of conflict, but how individuals resolve conflict; the same is true of organizations.We do not leave our humanity at the door when we come to work. Employees need to be treated as humans with respect and multiple facets of their lives. When employees thrive, they bring their best selves to work and have higher performance as a result.  "Conflict is necessary for high performance and innovation. What differentiates are those organizations who have found ways to create spaces where people can respectfully and healthfully disagree and come up with better solutions together." —  Gianna Driver About Gianna Driver, CHRO, ExabeamGianna Driver is Chief Human Resources Officer (CHRO) at Exabeam, a global cybersecurity leader that adds intelligence to every IT and security stack. As CHRO, Driver manages the strategy and processes related to building, investing in, and retaining top talent at Exabeam, enabling employees to do their best work. She is responsible for architecting the company's talent strategy, driving corporate culture and diversity, equity and inclusion (DEI) initiatives, and leading the global human resources function. Prior to Exabeam, Driver was the Chief People Officer at BlueVine, a private fin-tech company based in Redwood City, CA. Driver has also led HR and People functions in high-growth technology, gaming, consumer, and SaaS organizations including Playstudios, Aristocrat, Actian Corporation, Talend, and Balsam Brands. She is passionate about building high-performance cultures, establishing operational excellence, and creating joy at work. Driver is a graduate of The Wharton School of the University of Pennsylvania.References MentionedThe Empathy Edge podcast: M.E. Hart: How to Have Honest Conversations at WorkConnect with Gianna DriverWebsite: https://exabeam.comLinkedIn: https://www.linkedin.com/in/gianna-driver-6183391/  Don't forget to download your free guide! Discover The 5 Business Benefits of Empathy: http://red-slice.com/business-benefits-empathy  Connect with Maria: Get the podcast and book: TheEmpathyEdge.comLearn more about Maria and her work: Red-Slice.comHire Maria to speak at your next event: Red-Slice.com/Speaker-Maria-RossTake my LinkedIn Learning Course! Leading with EmpathyLinkedIn: Maria RossInstagram: @redslicemariaTwitter: @redsliceFacebook: Red Slice

Leaders in the Trenches
Leading a Company to Scale Fast with Michael DeCesare at Exabeam

Leaders in the Trenches

Play Episode Listen Later Dec 8, 2022 23:12


Companies don't scale fast without the right people on the team. Leaders must focus on a strategy to develop people and create a place where culture is everything. Building the right team is essential if you want your company to scale fast. So slow down and make a sustainable plan to scale fast. Today's guest is Michael DeCesare, President, and CEO at Exabeam. Inc Magazine ranked his company #2945 on the 2022 Inc 5000 list. Exabeam is a global cybersecurity leader that created New-Scale SIEM™ for advancing security operations. Built for security people by security people, they reduce business risk and elevate human performance. In this episode, Michael talks about how to lead a company to scale fast and what it takes to build a strong team. He also talks about how the leadership team should be responsible for developing people. Discover how to take your business to the next level and continue to scale fast the way you want it.   Get the show notes for Leading a Company to Scale Fast with Michael DeCesare at Exabeam Click to Tweet: Listening to a fantastic episode on Growth Think Tank featuring #MichaelDeCesare with your host @GeneHammett https://bit.ly/gttMichaelDeCesare   #ScaleFast #GeneHammettPodcast #GHepisode945 #Inc2022 #globalcybersecurity #SIEM Give Growth Think Tank a review on iTunes!

Show Up as a Leader with Dr. Rosie Ward
Humans First, Employees Second with Gianna Driver

Show Up as a Leader with Dr. Rosie Ward

Play Episode Listen Later Nov 23, 2022 41:50


To be successful, businesses and leaders have to be willing to embrace opportunities for change. This has played out in recent years as modern workplaces have openly acknowledged the importance of diversity. As part of this critical shift, more leaders are focsing on creating environments where employees feel safe being their authentic selves. Unfortunately, doing so is often easier said than done. Gianna Driver, Chief Human Resources Officer of Exabeam, teaches leaders how modeling vulnerability can empower their teams and establish a more positive, inclusive workplace. One of the first and most important steps is prioritizing humanness by recognizing that we are humans first and employees second. In this episode, Gianna explains why authenticity is key to developing a work culture that promotes not only learning and innovation but also kindness and communication. Listen to learn how reflection, a willingness to make mistakes, and a focus on empathy can enable transformation and growth.

The New CISO
Bridging the Effectiveness Gap: A CISO's Perspective on New-Scale SIEM with Tyler Farrar

The New CISO

Play Episode Listen Later Nov 3, 2022 43:56


In this episode of The New CISO, Steve is joined by Tyler Farrar, the CISO at Exabeam. With malware-free attacks becoming increasingly common, Tyler understands the best ways to bridge the effectiveness gap. With this in mind, he shares his SOC philosophy and the importance of threat detection. Listen to the episode to learn more about the act of prevention, the pillars of a SIEM product, and why attackers gravitate toward credential techniques. Listen to Steve and Tyler discuss the steps to success in an age of constantly increasing data : Meet Tyler (2:06) Host Steve Moore introduces our guest today, his colleague, Tyler Farrar. Before working at Exabeam, Tyler was a customer. With his impressive background in the security field, Tyler explains Exabeam's perspective on "defender behavior" and balancing incident response and crisis management with prevention. The Focus On Prevention (5:50) Steve presses Tyler on how you should balance your methods to increase prevention. Tyler lists different preventative tools, such as firewalls, and stresses the importance of detecting suspicious activity early on. Tyler gives his take on how response becomes prevention in crisis management. Preventative tools can fail, so being able to detect suspicious behaviors is critical. Addressing The Gap (10:36) Addressing the gap in analytics, Tyler recognizes that there is a difference between what the security team needs and what the SIEM product delivers.  Every company faces an immense volume of data, an inefficient manual cyber process, and software that can fail to detect the attacker's behaviors. Tyler lists the solutions that can counteract these problems, including behavioral analytics. The Rise Of Malware-Free Attacks (14:32) Steve points out how 71% of cyber-attacks are credentialed and malware-free. Tyler explains that attackers use the compromised credentials approach because it is easy. CISOs can miss the mark because legacy software can be ineffective at detecting threats. New-Scale SIEM (20:43) According to Tyler, new-scale SIEMs would be able to securely ingest data from anywhere, parse through that information quickly, and then store that information and make it searchable. Tyler also explores his philosophy on how to design a SOC. One example of a productive SOC is conducting risk assessments throughout the organization to identify gaps and then acting on those results. Life Of The Analyst (28:52) Steve presses Tyler on how the experience of the investigation factors into meaningful work for the analyst.  Tyler stresses the importance of SOC leadership to make the team effective. A stressed SOC can lead to the loss of talented workers and affect the company's security. New Software Ahead  (33:16) Tyler discusses the products he is looking forward to on the horizon. Every CISO's goal is to keep their company safe. Being able to show all the threats and vulnerabilities in place would be hugely valuable, which is why Tyler is interested in Systems Navigator. SOC Philosophy (49:55) Tyler's top SOC philosophy is to be aligned with your adversaries and learn how they think in addition to your defenders. Understanding both perspectives can create a culture of empowerment and protect the organization from threats. Links mentioned: https://www.linkedin.com/in/tyler-j-farrar/ (LinkedIn)

The Invisible Vault
The Holy Grail of Finance: Real Time Data, Sustainable Growth and a Solid Bottom Line with Manish Sarin, CFO at Sprinklr

The Invisible Vault

Play Episode Listen Later Oct 26, 2022 38:17


This episode features an interview with Manish Sarin, CFO at Sprinklr, a cloud-based customer experience management company. Manish brings to the table more than 20 years working with high-growth technology and cybersecurity companies. Previously, he was CFO at Exabeam, EVP of Finance at ProofPoint, and led Software Strategy and Corporate Development at Hewlett-Packard. On this episode, Manish talks about collecting unstructured data from Twitter, Facebook and Reddit to grasp the public narrative around Sprinklr, using AI to predict what will happen in the quarter, and achieving the holy grail of finance, of real time data, sustainable growth, and a solid bottom line.Quotes*”We take all of this information, which is unstructured, could be Twitter feeds, could be posts, and we pull it together using a variety of AI models to get at what is the insight in terms of what groups of users are saying about our business. And so that gives me a sense for, at least in terms of my public narrative, what do I need to change or tweak or at least be aware of as we go and have our earnings calls?”*”I mentored under a public company CFO, and one of the things he would always tell me is, 'Don't be afraid to break glass.' And I've always taken that to heart, which is, rarely is there any other function in today's enterprise that has the level of insight on what's going on with the business, and therefore has a very defined point of view on what needs to happen going forward.”*”I would encourage people who are evaluating being a CFO that it is a very empowering role. And at no point should they feel like their voice is not gonna be heard because they have probably more insights on the business than even the people running sales or marketing or product. And to me, that is something that should be embraced [by] any new CFO. Very empowering role. Do not be worried about breaking glass. Go make sure your voice and opinion is heard.”*”We're growing much faster than a lot of the competitors in our space. That tells me there is enough total addressable market for us to go after. And you never wanna build your business to the vagaries of the market right now. So in other words, you should keep growing no matter what is happening on Wall Street. Of course, you don't want to overspend in an environment where spend is under increasing scrutiny. But I would also argue this wouldn't be the time to pull back on spend as long as you fundamentally believe you're in a high growth segment. So for us, it's been trying to find that balance between the two… we're now showing investors that we can actually achieve sustainably high levels of growth while being prudent on the bottom line.”Time Stamps[3:03] Manish's path to CFO[6:54] How the CFO is a strategic partner to the business[11:23] Cash Crossroads: Manish's technology vision at Sprinklr[14:16] How Manish manages a data lake to structure Sprinklr's data[19:07] All about Sprinklr[22:42] The Playbook: Finance Strategy at Sprinklr[25:35] Risk management at Sprinklr[28:59] How Sprinklr uses AI[29:52] Report from the Future: Manish on the next generation of finance leaders[34:02] Quick Hits: Rapid fire questions with Manish SarinSponsorThe Invisible Vault is powered by the team at Kyriba, the global leader in cloud treasury and finance solutions, empowering CFOs and their teams to transform how they activate liquidity as a dynamic, real-time vehicle for growth and value creation. To learn more visit www.kyriba.comLinksConnect with Manish on LinkedInConnect with Daniel on LinkedInFollow Daniel on Twitter

Being [at Work]
126: Offer Up Your Differentness with Gianna Driver

Being [at Work]

Play Episode Listen Later Aug 11, 2022 31:10


Do you pretend to be someone different? If you threw all those habits aside, would you be able to say you know who you are? Gianna Driver, Chief Human Resource Officer atExabeam, found her voice by embracing what makes her different. And the best part? As soon as she started showing up as her authentic self, her community embraced her and encouraged her to do more of the same. In this episode, Gianna shares her story and discusses the lessons she learned around feeling like she didn't belong and finding commonality in shared struggles. Listen in for guidance around reflecting on who you intrinsically are so you can show up as your true self and, in turn, encourage others to do the same. Quick Links: Connect with Gianna: https://www.linkedin.com/in/gianna-driver-6183391/ Learn more about Exabeam: https://www.exabeam.com Connect with Andrea: https://www.linkedin.com/in/leaderdevelopmentcoach Learn more about HRD: https://hrdleadership.com/