Filtrer par genre
Resilient Cyber brings listeners discussions from a variety of Cybersecurity and Information Technology (IT) Subject Matter Experts (SME) across the Public and Private domains from a variety of industries. As we watch the increased digitalization of our society, striving for a secure and resilient ecosystem is paramount.
- 226 - The Jagged Frontier of Finding and Fixing Vulns with AI
Ondrej Vlcek, CEO of AISLE and former CEO of Avast, on why AI vulnerability discovery is not as commoditized as the industry thinks, and why remediation is still the real bottleneck. In this episode I sit down with Ondrej Vlcek, Founder and CEO at AISLE. Ondrej spent roughly 30 years in cybersecurity, joining Avast as employee number six or seven doing kernel-mode driver work on Windows 95, eventually becoming CTO and then CEO, taking the company public and selling it to NortonLifeLock in a ...
Tue, 01 Sep 2026 - 225 - Secure Vibe Coding and the 99%
Lovable CISO Igor Andriushchenko on soft guardrails vs. hard boundaries, securing vibe coding for non-developers, and building a security program at a 10x company. I sit down with Igor Andriushchenko, Head of Security and CISO at Lovable, the AI development platform behind one of the fastest growth stories in the space. Igor joined as the first security hire when the company was around 40 people. A year later he is running a 20+ person team covering product security, GRC, IT, and platform saf...
Mon, 24 Aug 2026 - 224 - Building a System of Truth for the CISO
CISOs have a stack of tools but no system built to run the security program itself. Mike Armistead wants to fix that. In this episode I sit down with Mike Armistead, co-founder and CEO of Pulse Security AI and a longtime security founder behind Fortify and Respond Software. We dig into why the security leader has never had a system of truth the way the CFO has an ERP and the CRO has a CRM, and how an agentic layer on top of the existing tools can finally close that gap. Mike is measured abou...
Tue, 11 Aug 2026 - 223 - The Real Price Tag On Cyber Breaches
Alex Pinto, who leads Verizon's DBIR team, joins me to break down the new Breach Impact Study and what data breaches actually cost organizations. For years the industry has argued past itself on breach costs. One camp says the market doesn't care, the other says a single breach ends your business. Alex and his team finally got their hands on roughly 70,000 cyber insurance claims through CyberAcuView, and the Breach Impact Study puts real numbers behind the question. In this conversation we d...
Wed, 05 Aug 2026 - 222 - Cyber Investing in the AI Exploit Era
What happens to security investing when vulnerability discovery becomes continuous and exploitation windows shrink from weeks to hours? I sit down with Chenxi Wang of Rain Capital to dig into it. Chenxi is the Founder and Managing General Partner at Rain Capital, a venture fund focused on early-stage cybersecurity companies. She's been a Carnegie Mellon professor, a Forrester VP, and a strategy leader at Intel Security and Twistlock, and her portfolio includes companies like Claroty, ProjectD...
Sat, 01 Aug 2026 - 221 - AI, Bug Bounties & the Vulnerability "Slopdemic"
Bugcrowd founder Casey Ellis joins me to dig into what AI is actually doing to bug bounties, vulnerability discovery, and open source security. We get into his "slopdemic" framing, the curl bug bounty saga, VDP readiness, the pentest market correction, and where security research policy heads next. Casey Ellis is the founder of Bugcrowd, co-founder of disclose.io, and a board member of the Security Research Legal Defense Fund. These days he advises and invests through Tall Poppy Group and wor...
Thu, 30 Jul 2026 - 220 - AI's Cyber Boom
Jon Sakoda of Decibel joins me to break down AI's impact on cybersecurity startups, venture funding, and why endpoint is the Super Bowl of cyber. Jon is the Founding Partner at Decibel, an early-stage firm backing technical founders in security and infrastructure. He started his career founding IMlogic, an IM security company acquired by Symantec, then spent over a decade at NEA working with companies like Cloudflare, MongoDB, and HackerOne before launching Decibel. We got into why he thinks ...
Wed, 29 Jul 2026 - 219 - Why AI Security Is Getting Rebuilt From Scratch
In this episode I sit down with Ed Sim, founder and managing partner of Boldstart Ventures, to dig into where AI security, agentic infrastructure, and the venture market are actually heading. Ed has been an inception-stage investor for nearly 30 years and has run Boldstart since 2010, backing hardcore technology companies across AI infrastructure, cybersecurity, and physical AI. He was the first investor in Protect AI, which sold to Palo Alto Networks in a reported ~$700M exit roughly a year...
Thu, 23 Jul 2026 - 218 - Resilient Cyber w/ Joshua Saxe - Why Restricting AI Makes Us Less Secure
Does restricting frontier AI in the name of safety actually make us less secure? Joshua Saxe joins me to make the case that it does, and that AI cybersecurity will be won through defender adoption, not restriction. Josh has spent 15 years at the intersection of AI and security. He built and ran the machine learning program at Sophos, then led security for Llama at Meta, covering security post training, evals, agent guardrails, and prompt injection prevention. He recently left to co-found a s...
Mon, 20 Jul 2026 - 217 - Cyber Valuations, Moats & the Road to Black Hat
Cybersecurity investor Sid Trivedi of Foundation Capital joins me to dig into AI SOC valuations, services-as-software, moats, and what founders should know heading into Black Hat. Sid is a Partner at Foundation Capital, where he invests at the seed and Series A stage with a focus on cybersecurity and IT infrastructure. This is our annual pre-Black Hat check-in, and a lot has moved since last year, from massive M&A to record-setting rounds in categories like the AI SOC. In this episode: ...
Thu, 16 Jul 2026 - 216 - Building an AI AppSec Engineer
JJ of Gecko Security and former Disney and Costco CISO Ryan Knisley on why AppSec needs an AI security engineer, not another scanner. Description AppSec has been stuck for years, drowning teams in noisy findings that never told them what was actually exploitable. JJ, co-founder and CEO of Gecko Security, and Ryan Knisley, former CISO at Disney and Costco, join Resilient Cyber to talk about what changes when an AI security engineer reasons across code, infrastructure, and design docs at once.&...
Sat, 11 Jul 2026 - 215 - Why Finding Vulnerabilities Was Never the Hard Part
Every headline wants you to believe AI has rewritten the rules of cybersecurity. Eric Doerr, the Chief Product Officer at Tenable a Resilient Cyber Partner, is not so sure. After running security response at Microsoft and leading security products at Google Cloud, he came on to separate the genuine transformation from the noise, and his read is refreshingly grounded. The tools changed, but the fundamentals did not, and the teams that win are the ones who finally act on that....
Sun, 05 Jul 2026 - 214 - Rain Versus Flood, Making Sense of the 2026 CVE Surge
CVEs are on pace to hit nearly 70,000 in 2026, but Jerry Gamblin explains why the actual exploitable risk is staying surprisingly flat. Description Jerry Gamblin runs RogoLabs and built CVE.ICU, and he co-authored the FIRST mid-year vulnerability forecast that just put 2026 on pace for nearly 70,000 CVEs. He joins Resilient Cyber to separate the scary headline number from what actually matters for defenders. We get into why GitHub now publishes one in five CVEs, the rain versus flood distinct...
Sat, 27 Jun 2026 - 213 - You Don't Need A Frontier Model to Find Zero Days
Niels Provos on why you don't need a frontier model to find zero days, why the Vulnpocalypse is overstated, and how security invariants change the game. Description Niels Provos has spent twenty-five years in security, from writing bcrypt to running security at Google and Stripe, and he came on to push back on the panic around AI and vulnerabilities. He explains why finding zero days is an orchestration problem rather than a frontier-model problem, using his Iron Curtain runtime and an open-w...
Thu, 18 Jun 2026 - 212 - AI Industrialized the Vuln Lifecycle and Broke the System of Record
VulnCheck's Patrick Garrity on the NVD collapse, the first real AI disclosure wave, and why remediation, not finding bugs, is the bottleneck. Description Vulnerability management spent years as the chore everyone dreaded, and now it is one of the hottest topics in security because attackers made exploitation the number one way in. Patrick Garrity of VulnCheck rejoins the show to separate what is real from what is marketing. We get into the honest state of the NIST National Vulnerability...
Mon, 15 Jun 2026 - 211 - AI Is Winning the Cyber Arms Race
For twenty years the security playbook started in the same place, find a vulnerability, prioritize it, and patch it. Doug Merritt, CEO of Aviatrix and former CEO of Splunk, thinks that playbook is quietly breaking, and his explanation has nothing to do with anyone being careless. The economics of offense changed underneath us, and most security programs are still funded as if they did not. Why this conversation matters Doug has sat in two seats that give this argument weight. At Splunk he eva...
Wed, 03 Jun 2026 - 210 - Securing the Agentic SDLC
In this episode of Resilient Cyber, I sit down with Katie Norton, Research Manager for DevSecOps and Software Supply Chain Security at IDC, to unpack what application security looks like as AI moves from copilot to autonomous teammate across the software development lifecycle. We dive into: 🤖 AI's accelerating impact on AppSec and the SDLC – and the productivity-versus-risk equation now that agentic coding tools are shipping code at machine speed 💥 The "Vulnpocalypse" – the explosion of CVEs,...
Fri, 29 May 2026 - 209 - The Agentic GRC Revolution
In this episode, we sat down with Richa Kaul, CEO of Complyance, the AI-first enterprise GRC platform that recently raised a $20M Series A led by GV (Google Ventures), to dig into how legacy GRC is finally being disrupted and what role AI agents play in that transformation. We discussed why GRC has lived in the dark ages for so long, stuck in static documents, snapshot-in-time assessments, system sampling, and self-attestations while the rest of IT moved to cloud, APIs, and automation. We unp...
Tue, 19 May 2026 - 208 - Identity as Infrastructure in the Agentic Era
In this episode of Resilient Cyber, I sat down with Karl McGuinness — author of Control Plane and one of the sharpest voices working on identity in the agentic era — to unpack what most of the industry is still getting wrong about IAM for AI agents. Karl's thesis is a provocation: we spent two decades optimizing authentication and authorization, and we built that stack for human-paced execution. Agents remove the presence, pacing, and natural scope-limiting that made those controls work — and...
Wed, 13 May 2026 - 207 - Why AI Security Feels So Fragile
AI security feels fragile right now — and in this episode, Ron Bennatan, VP of Strategy, AI and Database Security at Varonis and founder of Guardium, JSonar, and AllTrue.ai, explains exactly why. Ron unpacks what "fragile" actually means in the context of AI: it's a black box that requires careful handling, is sensitive to pressure, and is being outpaced by change that isn't linear or polynomial — it's exponential. What took 30 years of AI development previously has been eclipsed by the last ...
Fri, 01 May 2026 - 206 - You Can't Trust What You Can't Verify — The Case for AI Model Identity
Most organizations deploying AI today cannot answer a deceptively simple question. Which model is actually running in their environment? It is not a hypothetical concern. Model substitution, supply chain compromise, adversarial fine-tuning, and jurisdictional compliance gaps are all live risk vectors — and the industry has largely been relying on contractual guarantees from AI vendors rather than technical controls to address them. That gap is exactly what Project VAIL was built to close. In ...
Tue, 28 Apr 2026 - 205 - Securing the Vibe: Tanya Janca on AI-Generated Code, Mythos, and the New AppSec Reality
A new episode of the Resilient Cyber Show just dropped, and this one is a conversation I’ve been looking forward to for a long time. I sat down with Tanya Janca, better known to most of the AppSec world as SheHacksPurple. Tanya is the best-selling author of Alice and Bob Learn Application Security and Alice and Bob Learn Secure Coding, an OWASP Lifetime Distinguished Member, CEO of She Hacks Purple Consulting, and one of the most recognized voices in application security and developer educati...
Mon, 27 Apr 2026 - 204 - AI and the Future of Secure Coding
What happens to application security when AI agents start writing most of the code? Jack Cable knows both sides of this problem better than almost anyone. As a Senior Technical Advisor at CISA, he helped architect the Secure by Design initiative that challenged the entire software industry to stop shipping insecure products and expecting customers to clean up the mess. Now, as the founder of Corridor, he's building at the center of a question that didn't exist two years ago: how do you govern...
Thu, 16 Apr 2026 - 203 - Your AI Agent Is Running As Root
When you fire up Claude Code, Cursor, or any AI coding agent, it launches with your full system permissions, your SSH keys, cloud credentials, browser passwords, every file on your machine. Most developers never think twice about it. Luke Hinds did. And then he built something about it. Luke is the creator of Sigstore, the cryptographic signing infrastructure now used by PyPI, Homebrew, GitHub, and Google as the industry standard for software supply chain security. In this episode, he joins C...
Wed, 08 Apr 2026 - 202 - The 350 Million Problem: Securing the Businesses No One Else Will
Show Description Joe Levy is the CEO of Sophos and a 30-year cybersecurity veteran who has held technical and executive roles across some of the industry's most recognizable brands. In this episode, we dig into a stat that should reframe how the entire industry thinks about its mission: out of roughly 359 million businesses worldwide, fewer than 32,000 have a CISO. That's less than one in 10,000 organizations with a security strategy leader — and it's a number Joe worked with Cybersecurity Ve...
Tue, 17 Mar 2026 - 201 - Before the Breach: The Zero Day Clock and the Race Against Exploitation
Show Description The Zero Day Clock is ticking — and the numbers should make every security leader uncomfortable. In this episode, I sit down with Sergej Epp, CISO at a leading security firm, who built the Zero Day Clock after a weekend experiment using AI to discover vulnerabilities firsthand. What he found shocked him: with no professional vulnerability research background and just a few hours of work, he was successfully finding zero days across major security projects using AI models and...
Wed, 11 Mar 2026 - 200 - Securing the Future with Autonomous Defense
Summary: In this conversation, Chris Hughes and Stanislav Fort discuss the transformative role of AI in cybersecurity, particularly in vulnerability management. Stanislav shares insights on how AI can discover zero-day vulnerabilities in widely used codebases, the challenges of balancing AI-driven discoveries with quality assurance, and the importance of proactive security measures. They also explore the economic sustainability of AI in cybersecurity, the burden on maintainers, and the ongoi...
Mon, 23 Feb 2026 - 199 - Selling Cyber: Deal Flow and Market Signals with Momentum Cyber
In this episode of Resilient Cyber I catch up with Momentum Cyber's Founder & CEO, Eric McAlpine. We will be unpacking 2025's M&A and capital market activities, using Momentum Cyber's 2025 Cybersecurity Almanac Report, as well as discussing some of the overlooked and untold details under the hood of cyber M&A, building world class teams and more.
Wed, 18 Feb 2026 - 198 - Exploiting AI IDEs
In this episode of Resilient Cyber, we will be sat down with Ari Marzuk, the researcher who published "IDEsaster", A Novel Vulnerability Class in AI IDE's. We will be discussing the rise of AI-driven development and modern AI coding assistants, tools and agents, and how Ari discovered 30+ vulnerabilities impacting some of the most widely used AI coding tools and the broader risks around AI coding. Ari's background in offensive security — Ari has spent the past decade in offensive security, i...
Tue, 17 Feb 2026 - 197 - AI is Ready for Production - Security, Risk and Compliance Isn't
In this episode of Resilient Cyber, I sit down with VP, Product Marketing and Strategy for Protegrity, James Rice. We will be discussing how traditional approaches to security aren't solving the AI security challenge, the importance of data-centric approaches for secure AI implementation and addressing issues such as AI data leakage. James and I dove into a lot of great topics, including: Why traditional perimeter-based and infrastructure-centric security models are failing in the era o...
Tue, 10 Feb 2026 - 196 - Hacking the OpenClaw Hype
In this episode of Resilient Cyber, I sit down with Jamieson O'Reilly, Security Researcher and Founder @ Dvuln. Jamieson recently went viral for his hacking activities demonstrating the vulnerabilities and exploitation of OpenClaw (previously ClawdBot and Moltbot), from exposed servers, backdooring skills and demonstrating how to perform potential account takeovers. Jamieson is now helping secure the OpenClaw project. We will walk through his findings, implications of the rise ...
Sat, 07 Feb 2026 - 195 - Switching to Cyber - Navigating Cybersecurity Careers
In this episode of Resilient Cyber, I sit down with longtime Cyber practitioners and leaders Helen Patton and Josiah Dykstra to dive into their latest book, "Switching to Cyber: The Mid-Career Guide to Launching a Cybersecurity Career". The book aims to help mid-career professionals pivot into the cyber career field and navigate finding their cyber niche, bridging skill gaps and conquering tech intimidation among more.
Fri, 06 Feb 2026 - 194 - Resilient Cyber w/ Anshuman Bhartiya - AI-native AppSec
In this episode of Resilient Cyber I sit down with Anshuman Bhartiya to discuss AI-native AppSec. Anshuman is a Staff Security Engineer at Lyft, Host of the The Boring AppSec Community podcast, and author of the AI Security Engineer newsletter on LinkedIn. Anshuman has quickly become an AppSec leader I highly respect and find myself learning from his content and perspectives on AppSec and Security Engineering in the era of AI, LLMs and Agents.
Thu, 22 Jan 2026 - 193 - Resilient Cyber w/ Jerry Gamblin - CVE Retrospective & Looking Forward
In this episode of Resilient Cyber I'm joined by one of my favorite Vulnerability Researchers, Jerry Gamblin. Jerry recently published a comprehensive 2025 CVE retrospective, which we will dive into, as well as his thoughts around trends and patterns we may see emerge in the vulnerability management landscape moving into 2026 and beyond.
Fri, 09 Jan 2026 - 192 - 2025 Cybersecurity Macroeconomic Retrospective
In this episode of Resilient Cyber, I sit down with my friend and the Founder of Return on Security (RoS), 💰 Mike Privette. Mike is the among the best our community has to offer when it comes to analyzing the macroeconomic trends of the cybersecurity ecosystem, from M&A, fundraising, startups, innovation, and venture capital. We will dig into the macroeconomics of cyber this past year, key trends, takeaways, the outsized role AI has or hasn’t had and what 2026 may hold as we look ahead.
Thu, 18 Dec 2025 - 191 - Resilient Cyber w/ Patrick Garrity - 2025 VulnMgt Research Roundup
In this episode I sit down with my friend and Vulnerability Researcher Patrick Garrity 👾🛹💙 of VulnCheck to do a roundup of the latest trends, analysis and insights into the vulnerability and exploitation ecosystem throughout the past year. We covered a lot of great topics, including: - The most notable vulnerability trends over 2025, including what has changed, or stayed the same in the past year. - Continued challenges around the NIST NVD and CVE, the sprawl of competing vulnerability databa...
Fri, 12 Dec 2025 - 190 - Resilient Cyber w/ Jesus and John - Post-Quantum Cryptography for Engineers
In this episode of Resilient Cyber, I'm joined by Jesus Alejandro Cardenes Cabre, SVP of Product Architecture and John Xiaremba, Software Engineer, both from the VIA Knowledge Hub team to dig into all things post-quantum cryptography (PQC). This includes PQC standards, as well as practical steps developers must take today to mitigate future risks.
Wed, 19 Nov 2025 - 189 - Resilient Cyber w/ Kamal Shah - The State of AI in SecOps
In this episode of Resilient Cyber, I sit down with Kamal Shah, Cofounder and CEO at Prophet Security, to discuss the State of AI in SecOps. There continues to be a tremendous amount of excitement and investment in the industry around AI and cybersecurity, with Security Operations (SecOps) arguably seeing the most investment among the various cybersecurity categories. Kamal and I will walk through the actual state of AI in SecOps, how AI is impacting the future of the SOC, what hype v...
Tue, 11 Nov 2025 - 188 - Resilient Cyber w/ Jeff & Naomi - The AI-Driven Shift to Runtime AppSec
In this episode of Resilient Cyber, I sit down with longtime industry AppSec leader and Founder/CTO of Contrast Security, Jeff Williams, along with Contrast Security's Sr. Director of Product Security Naomi Buckwalter, to discuss all things Application Detection & Response (ADR), as well as the implications of AI-driven development.
Fri, 07 Nov 2025 - 187 - Resilient Cyber w/ Ross Young - Mastering the Cybersecurity Budget
In this episode, I sit down with a friend and ex-CIA Officer turned Cybersecurity leader, Ross Young over at CISO Tradecraft. We will be unpacking the topic of mastering the cybersecurity budget. This includes examining whether most cyber budgets are wasted, determining where and how to make investments, justifying spending, and more. Don’t miss this chance to delve into an often-overlooked subject that many Cybersecurity leaders struggle with.
Tue, 04 Nov 2025 - 186 - Resilient Cyber w/ Mitch Herckis - Securing the Public Sector
In this episode, I sit down with Mitchel Herckis, Global Head of Government Affairs at cloud security leader Wiz. We will be discussing all things public sector and cybersecurity, including the evolution of the FedRAMP program, modernizing vulnerability management, and the future of Continuous ATO (cATO). We covered a lot of ground, including: Mitch’s background, both at Wiz and inside Government at roles such as OMBHow Wiz is working with Federal agencies and Defense Industrial Base (...
Wed, 15 Oct 2025 - 185 - Resilient Cyber w/ Kenny Scott - Following the Future of FedRAMP
In this episode of Resilient Cyber, I sit down with Founder & CEO of Paramify, Kenny Scott, to unpack the evolution of the FedRAMP program, FedRAMP 20x, and discuss what the public sector cloud compliance looks like moving into the future. Kenny and I dove into a lot of topics, including: What FedRAMP is and why it mattersWhat FedRAMP 20x is and what longstanding challenges associated with FedRAMP and public sector cloud and compliance it is addressingThe various aspects of FedRAMP 20x, i...
Mon, 06 Oct 2025 - 184 - Resilient Cyber w/ Snehal Antani - AI and Autonomous Pen Testing
In this episode of Resilient Cyber, I sit down with repeat guest Snehal Antani, who serves as the Co-Founder & CEO of Autonomous Pen Testing leader Horizon3.ai. We will discuss the latest developments in AI and Autonomous Pen Testing, as well as the tremendous growth and success of Horizon3.ai, as Snehal balances technical topics with business-centric hard won wisdom of growing an industry leading organization.
Fri, 03 Oct 2025 - 183 - Resilient Cyber w/ Alon Jackson - Enterprise Agentic Security
In this episode of Resilient Cyber, I sit down with Astrix Security Co-Founder and CEO Alon Jackson to discuss the need for secure agentic adoption across the enterprise. This includes Astrix’s approach, which involves enabling enterprises to discover, secure, and deploy AI agents responsibly at scale.
Fri, 26 Sep 2025 - 182 - Resilient Cyber w/ Emre Tinaztepe - Forensics at the Frontline
In this episode of Resilient Cyber, I sit down with Binalyze Founder/CEO Emre Tinaztepe. We will discuss how AI and automation are impacting the future of the SOC and the role that forensics-level data can play in incident response and recovery, as well as proactive threat hunting.
Wed, 24 Sep 2025 - 181 - Resilient Cyber w/ Andy Ellis - Effective Cyber Marketing, Sales & Leadership
In this episode, I sit down with Andy Ellis, a longtime industry security leader who has turned investor, advisor, and mentor. We will discuss how security vendors can build effective marketing and sales teams and Andy's experience identifying and investing in industry-leading security startups. Don't miss this chance to hear from an industry legend who has worn multiple hats and excelled as an operating, investor, and overall security leader.
Mon, 15 Sep 2025 - 180 - Resilient Cyber w/ Cory Michal (AppOmni) - Unpacking the SaaS Security Supply Chain Landscape
- One of the biggest SaaS security incidents recently of course is the Salesloft Drive/Salesforce incident, which impacted hundreds of organizations and involved compromised OAuth tokens. Can you tell us a bit about the incident and the fallout? - In an AppOmni blog on the incident, you all discuss attackers taking advantage of persistent OAuth access, over-permissive access, limited monitoring, and unsecured secrets. Why do these problems continue to plague organizations despite incidents li...
Wed, 10 Sep 2025 - 179 - Resilient Cyber w/ Rob T. Lee - Navigating AI's Impact on Cyber & the Workforce
In this episode of Resilient Cyber, I sit down with the SANS Institute's Chief of Research (COR) & Chief AI Officer (CAIO), Rob T. Lee to discuss AI's impact on cybersecurity and the workforce. We will discuss SANS Critical AI Security Guidelines, the opportunities and obstacles AI presents for cybersecurity, and how practitioners should navigate AI's impact on the workforce.
Sat, 06 Sep 2025 - 178 - Resilient Cyber w/ Gianna & Maria - The State of Cybersecurity Marketing
In this episode of Resilient Cyber, I sit down with Gianna Whitver and Maria Velasquez to chat about the state of marketing in the cybersecurity industry, as well as their popular event "Cyber Marketing Con" In this episode, we discussed: The background of the CyberMarketingCon and what led Gianna and Maria to co-found the event and communityWhere marketers typically fall short and what can be done to drive more effective marketing and selling to security practitioners and leadersWhat practit...
Wed, 27 Aug 2025 - 177 - Resilient Cyber w/ Michael Bargury - The AI Agent Security Imperative
In this episode I sit down with Michael Bargury, Co-Founder and CTO at Zenity to discuss all things AI Agent Security. Michael and the Zenity team have recently disclosed various AI agent risks, vulnerabilities and threats.
Fri, 22 Aug 2025 - 176 - Resilient Cyber w Andrew Carney DARPA AI Cyber Challenge AIxCC
In this episode, I sit down with Andrew Carney, Program Manager for DARPA's AI Cyber Challenge (AIxCC). DARPA's AIxCC recently concluded at Black Hat, and it brought together the industry's leading experts on AI and Cybersecurity with a focus on securing software that is critical to all Americans. Teams had to create novel AI systems to secure critical code, include software involved in critical infrastructure.
Thu, 21 Aug 2025 - 175 - Resilient Cyber w/ Sid Trivedi - Black Hat, Cyber and AI Opportunities
In this episode we sit down with Sid Trivedi, Partner at venture capital firm Foundational Capital and host of the Inside the Network podcast. Sid brings great insights around cybersecurity market trends, industry events such as Black Hat and the impact that AI is having on the startup and venture capital ecosystem.
Mon, 04 Aug 2025 - 174 - Resilient Cyber w/ Daniel Bardenstein - AI Supply Chain Security Risks
In this episode, I sit down with Daniel Bardenstein, CTO & Co-Founder of Manifest Cyber. We discussed the AI supply chain security, including open source risks, AIBOMs, best practices for CISOs, and regulatory approaches in the U.S. and EU. We dove into: What is the same and different between the risks AI introduces across the enterprise compared to open source software, and where and how the two converge.The rise of an “AIBOM” and why it is becoming a critical part of enterprise risk man...
Sat, 26 Jul 2025 - 173 - Resilient Cyber w/ Christian Posta MCP, Agents & IAM in the age of LLMs
In this episode, we sit down with Christian Posta, the Field CTO at Solo.io and an industry author and leader on topics such as Microservices, AI, and IAM. We will explore the rise of Agentic AI and its supporting protocols, such as MCP and A2A, and the broader challenges and considerations of Identity security in the age of LLMs.
Sat, 26 Jul 2025 - 172 - Resilient Cyber w/ Jim Manico - Enhancing Software Security in the Era of AI
In this episode, we sit down with Jim Manico, a longtime industry AppSec Leader, Educator, and Innovator, to discuss enhancing software security in the era of AI. This includes covering recent talks Jim has given about using AI as a force multiplier for software development, the importance of security-centric prompting, and the overall impact of AI on the field of AppSec. We discussed: A recent talk Jim gave where he discussed transforming secure software creation with AI, doing the work of ...
Mon, 14 Jul 2025 - 171 - Resilient Cyber w/ AJ Yawn - Transforming Compliance Through GRC Engineering
In this episode, we sat down with AJ Yawn, Author of the upcoming book GRC Engineering for AWS and Director of GRC Engineering at Aquia, to discuss how GRC engineering can transform compliance. We discussed the current pain points and challenges in Governance, Risk, and Compliance (GRC), how GRC has failed to keep up with software development and the threat landscape, and how to leverage cloud-native services, AI, and automation to bring GRC into the digital era. We dove into: What the phras...
Mon, 30 Jun 2025 - 170 - Resilient Cyber w/ Patrick Duffy: Securing the Modern Workspace
In this episode of Resilient Cyber, we chat with Patrick Duffy, Product Manager at Material Security, on Securing the Modern Workspace. The conversation will include discussions about the increased adoption of cloud office suites, limitations of traditional security approaches, and a deep dive into how Material Security is tackling issues such as securing email and data, identity threat detection, and posture management. Stepping back a bit before we get too specific, we've seen major f...
Thu, 26 Jun 2025 - 169 - Resilient Cyber w/ Wade Baker - Data Driven Incident Impact Analysis
In this episode, I sit down with longtime industry researcher Wade Baker to dive into Cyentia's latest IRIS report. The report provides a data-driven look at incident trends, impacts, costs, and more. Are cyber incidents becoming more or less frequent? Are specific industries doing better than others? What does the average incident impact actually look like? Tune in to learn the answers, along with many other interesting insights! The report found that the number of security incidents conti...
Mon, 23 Jun 2025 - 168 - Resilient Cyber w/ Bob Ritchie - Securing Federal & Defense Digital Modernization
In this episode, I sit down with SAIC Chief Technology Officer (CTO) and longtime Federal/Defense leader Bob Ritchie to discuss his experience securing public sector digital modernization, including everything from large multi-cloud environments to zero trust, identity, and where things are headed with AI. Bob starts discussing SAIC and his background there. He went from intern to CTO over 20 years with this public sector industry leader, including a brief stint with Capital One on the commer...
Mon, 23 Jun 2025 - 167 - Resilient Cyber w Phil Venables Security Leadership: Vulnerabilities to VC
In this episode, I sit down with longtime industry leader and visionary Phil Venables to discuss the evolution of cybersecurity leadership, including Phil's own journey from CISO to Venture Capitalist. We chatted about: A recent interview Phil gave about CISOs transforming into business-critical digital risk leaders and some of the key themes and areas CISOs need to focus on the most when making that transition Some of the key attributes CISOs need to be the most effective in...
Fri, 23 May 2025 - 166 - Resilient Cyber w/ Vineeth Sai Narajala: Model Context Protocol (MCP) - Potential & Pitfalls
In this episode, I discuss the Model Context Protocol (MCP) with the OWASP GenAI Co-Lead for Agentic Application Security, Vineeth Sai Narajala. We will discuss MCP's potential and pitfalls, its role in the emerging Agentic AI ecosystem, and how security practitioners should consider secure MCP enablement. We discussed: MCP 101, what it is and why it mattersThe role of MCP as a double-edged sword, offering opportunities but additional risks and considerations from a security pers...
Wed, 21 May 2025 - 165 - Resilient Cyber w/ Jay Jacobs & Michael Roytman - VulnMgt Modernization & Localized Modeling
In this episode, I sit with long-time vulnerability management and data science experts Jay Jacobs and Michael Roytman, who recently co-founded Empirical Security. We dive into the state of vulnerability management, including: How it is difficult to quantify and evaluate the effectiveness of vulnerability prioritization and scoring schemes, such as CVSS, EPSS, KEV, and proprietary vendor prioritization frameworks, and what can be done betterSystemic challenges include setbacks in the NIST Nat...
Sat, 17 May 2025 - 164 - Resilient Cyber: Ravid Circus - Tackling the Prioritization Crisis in Cyber
In this episode, we sit down with the Co-Founder and CPO of Seemplicity, Ravid Circus, to discuss tackling the prioritization crisis in cybersecurity and how AI is changing vulnerability management. We dove into a lot of great topics, including: The massive challenge of not just finding and managing vulnerabilities but also remediation, with Seemplicity’s Year in Review report finding organizations face 48.6 million vulnerabilities annually and only 1.7% of them are critical. That still means...
Mon, 14 Apr 2025 - 163 - Resilient Cyber w/ Varun Badhwar - AI for AppSec - Beyond the Buzzwords
In this episode, we sit down with Varun Badhwar, Founder and CEO of Endor Labs, to discuss the state of AI for AppSec and move beyond the buzzwords. We discussed the rapid adoption of AI-driven development, its implications for AppSec, and how AppSec can leverage AI to address longstanding challenges and mitigate organizational risks at scale. Varun and I dove into a lot of great topics, such as: The rise of GenAI and LLMs and their broad implications on CybersecurityThe dominant use c...
Fri, 11 Apr 2025 - 162 - Resilient Cyber w/ Jit - Agentic AI for AppSec is Here
In this episode, we sit down with David Melamed and Shai Horovitz of the Jit team. We discussed Agentic AI for AppSec and how security teams use it to get real work done. We covered a lot of key topics, including: What some of the systemic problems facing AppSec are, even before the widespread adoption of AI, such as vulnerability prioritization, security technical debt and being outnumbered exponentially by Developers.The surge of interest and investment in AI and agentic workflows fo...
Tue, 08 Apr 2025 - 161 - Resilient Cyber w/ Elad Schulman - Secure Enterprise LLM/GenAI Adoption
We sit with Lasso Security CEO and Co-Founder Elad Schulman in this episode. Lasso focuses on secure enterprise LLM/GenAI adoption, from LLM Applications, GenAI Chatbots, Code Protection, Model Red Teaming, and more. Check them out at https://lasso.security We dove into a lot of great topics, such as: Dealing with challenges around visibility and governance of AI, much like previous technological waves such as mobile, Cloud, and SaaSUnique security considerations for different paths of using...
Fri, 28 Mar 2025 - 160 - Resilient Cyber w/ Piyush Sharrma - AI-Powered Defense & Security Mesh
In this episode, we sit down with Piyush Sharrma, CEO and co-founder of the Tuskira team. They're an AI-powered defense optimization platform innovating around leveraging an Agentic Security Mesh. We will dive into topics such as Platform vs. Point Solutions, Security Tool Sprawl, Alert Fatigue, and how AI can create "intelligent" layers to unify and enhance security tooling ROI. We discussed: What drove Piyush to jump back into the startup space after successfully exiting from a previous sta...
Fri, 28 Mar 2025 - 159 - Resilient Cyber w/ Sergej Epp - Cloud-native Runtime Security & Usage
In this episode, we sit with security leader and venture investor Sergej Epp to discuss the Cloud-native Security Landscape. Sergej currently serves as the Global CISO and Executive at Cloud Security leader Sysdig and is a Venture Partner at Picus Capital. We will dive into some insights from Sysdig's recent "2025 Cloud-native Security and Usage Report." Big shout out to our episode sponsor, Yubico! Passwords aren’t enough. Cyber threats are evolving, and attackers bypass weak authentication ...
Wed, 19 Mar 2025 - 158 - Resilient Cyber w/ Chenxi Wang - The Intersection of AI & Cybersecurity
In this episode, we sit down with Investor, Advisor, Board Member, and Cybersecurity Leader Chenxi Wang to discuss the interaction of AI and Cybersecurity, what Agentic AI means for Services-as-a-Software, as well as security in the boardroom Chenxi and I covered a lot of ground, including: When we discuss AI for Cybersecurity, it is usually divided into two categories: AI for Cybersecurity and Securing AI. Chenxi and I walk through the potential for each and which one she finds more interest...
Mon, 17 Mar 2025 - 157 - Resilient Cyber w/ Lior Div & Nate Burke - Agentic AI & the Future of Cyber
In this episode, we sit down with Lior Div and Nate Burke of 7AI to discuss Agentic AI, Service-as-Software, and the future of Cybersecurity. Lior is the CEO/Co-Founder of 7AI and a former CEO/Co-Founder of Cybereason, while Nate brings a background as a CMO with firms such as Axonius, Nagomi, and now 7AI. Lior and Nate bring a wealth of experience and expertise from various startups and industry-leading firms, which made for an excellent conversation. We discussed: The rise of AI and Agentic...
Mon, 17 Mar 2025 - 156 - Resilient Cyber w/ Rob Shavell - Personal Data & Online Privacy
In this episode, we sit down with Rob Shavell, CEO and Co-Founder of DeleteMe, an organization focused on safeguarding exposed personal data on the public web and addressing user privacy challenges. We dove into a lot of great topics, such as: The rapidly growing problem of personal data ending up on the public web and some of the major risks many may not think about or realizeTrends contributing to personal data exposure, from the Internet itself to social media, mobile phones/apps, IoT devi...
Mon, 03 Mar 2025 - 155 - Resilient Cyber w/ Steve Martano - CISO's, Security Budgets & Careers
In this episode of Resilient Cyber, we sit down with Steve Martano, Partner in the cyber Security Practice at Artico Search, to discuss the recent IANS & Artico Search Publications on the 2025 State of the CISO, security budgets, and broader security career dynamics. Steve and I touched on some great topics, including: The 2025 State of the CISO report and key findingsBoard reporting cadences for CISO’s and the importance of Boardroom involvement in CybersecurityThe three archetypes of CI...
Fri, 28 Feb 2025 - 154 - Resilient Cyber w/ Katie Norton - AppSec Industry Analysis & Trends
In this episode of Resilient Cyber, we catch up with Katie Norton, an Industry Analyst at IDC who focuses on DevSecOps and Software Supply Chain Security. We will dive into all things AppSec, including 2024 trends and analysis and 2025 predictions. Katie and I discussed: Her role with IDC and transition from Research and Data Analytics into being a Cyber and AppSec Industry Analyst and how that background has served her during her new endeavor.Key themes and reflections in AppSec through 2024...
Mon, 24 Feb 2025 - 153 - Resilient Cyber w/ Ed Merrett - AI Vendor Transparency: Understanding Models, Data and Customer Impact
In this episode of Resilient Cyber, Ed Merrett, Director of Security & TechOps at Harmonic Security, will dive into AI Vendor Transparency. We discussed the nuances of understanding models and data and the potential for customer impact related to AI security risks. Ed and I dove into a lot of interesting GenAI Security topics, including: Harmonic’s recent report on GenAI data leakage shows that nearly 10% of all organizational user prompts include sensitive data such as customer informati...
Thu, 13 Feb 2025 - 152 - Resilient Cyber w/ Sounil Yu - The Intersection of AI and Need-to-Know
In this episode, we sit down with Sounil Yu, Co-Founder and CTO at Knostic, a security company focusing on need-to-know-based access controls for LLM-based Enterprise AI. Sounil is a recognized industry security leader and the author of the widely popular Cyber Defense Matrix. Sounil and I dug into a lot of interesting topics, such as: The latest news with DeepSeek and some of its implications regarding broader AI, cybersecurity, and the AI arms race, most notably between China and the U.S.Th...
Mon, 03 Feb 2025 - 151 - Resilient Cyber w/ Grant Oviatt - Transforming SecOps with AI SOC Analysts
SecOps continues to be one of the most challenging areas of cybersecurity. It involves addressing alert fatigue, minimizing dwell time and meantime-to-respond (MTTR), automating repetitive tasks, integrating with existing tools, and leading to ROI. In this episode, we sit with Grant Oviatt, Head of SecOps at Prophet Security and an experienced SecOps leader, to discuss how AI SOC Analysts are reshaping SecOps by addressing systemic security operations challenges and driving down organization...
Mon, 27 Jan 2025 - 150 - Resilient Cyber w/ Rajan Kapoor - Native Cloud Workspace Gaps and Risks
In this episode, we sit down with Rajan Kapoor, Field CISO of Material Security, to discuss the security risks and shortcomings of native cloud workspace security offerings and the role of modern platforms for email security, data governance, and posture management. Email and Cloud Collaboration Workspace Security continues to be one of the most pervasive and challenging security environments, and Rajan provided a TON of excellent insights. We covered: Why email and cloud workspaces are some...
Tue, 21 Jan 2025 - 149 - Resilient Cyber w/ Mick Leach - 5 Email Threats to Watch For in 2025
While cybercriminals can (and do) infiltrate organizations by exploiting software vulnerabilities and launching brute force attacks, the most direct—and often the most effective—route is via the inbox. As the front door of an enterprise and the gateway upon which employees rely to do their jobs, the inbox represents an ideal access point for attackers. And it seems that, unfortunately, cybercriminals aren’t lacking when it comes to identifying new ways to sneak in. Abnormal Security’s Field C...
Tue, 21 Jan 2025 - 148 - Resilient Cyber w/ Greg Martin - Agentic AI and AppSec
We’ve heard a ton of excitement about AI Agents, Agentic AI, and its potential for Cybersecurity. This ranges in areas such as GRC, SecOps, and Application Security (AppSec). That is why I was excited to sit down with Ghost Security Co-Founder/CEO Greg Martin. In this episode, we sit down with Ghost Security CEO and Co-Founder Greg Martin to chat about Agentic AI and AppSec. Agentic AI is one of the hottest trends going into 2025, and we will discuss what it is, its role in AppSec, and what s...
Fri, 10 Jan 2025 - 147 - Resilient Cyber w/ Filip Stojkovski & Dylan Williams - Agentic AI & SecOps
In this episode, we will be sitting down with Filip Stojkovski and Dylan Williams to dive into AI, Agentic AI, and the intersection with cybersecurity, specifically Security Operations (SecOps). I’ve been following Filip and Dylan for a bit via LinkedIn and really impressed with their perspective on AI and its intersection with Cyber, especially SecOps. We dove into that in this episode including: What exactly Agentic AI and AI Agents are, and how they workWhat a Blueprint for AI Agents in C...
Wed, 11 Dec 2024 - 146 - Resilient Cyber w/ Walter Haydock - Implementing AI Governance
In this episode, we sit down with StackAware Founder and AI Governance Expert Walter Haydock. Walter specializes in helping companies navigate AI governance and security certifications, frameworks, and risks. We will dive into key frameworks, risks, lessons learned from working directly with organizations on AI Governance, and more. We discussed Walter’s pivot with his company StackAware from AppSec and Supply Chain to a focus on AI Governance and from a product-based approach to a services-o...
Fri, 22 Nov 2024 - 145 - Resilient Cyber w/ Jim Dempsey - Navigating the Cyber Regulatory Landscape
In this episode, we sit with the return guest, Jim Dempsey. Jim is the Managing Director of the Cybersecurity Law Center at IAPP, Senior Policy Advisory at Stanford, and Lecturer at UC Berkeley. We will discuss the complex cyber regulatory landscape, where it stands now, and implications for the future based on the recent U.S. Presidential election outcome. We dove into a lot of topics including: The potential impact of the latest U.S. Presidential election, including the fact that while the...
Mon, 18 Nov 2024 - 144 - Resilient Cyber w/ Tyler Shields and James Berthoty - Is "Shift Left" Losing its Shine?
In this episode of Resilient Cyber I will be chatting with industry leaders Tyler Shields and James Berthoty on the topic of "Shift Left". This includes the origins and early days of the shift left movement, as well as some of the current challenges, complaints and if the shift left movement is losing its shine. We dive into a lot of topics such as: Tyler and Jame’s high-level thoughts on shift left and where it may have went wrong or run into challengesTyler’s thoughts on the evolution of ...
Fri, 01 Nov 2024 - 143 - Resilient Cyber w/ Shyam Sankar - The Primacy of Digital Dominance
In this episode we sit down Shyam Sankar, Chief Technology Officer (CTO) of Palantir Technologies. We will dive into a wide range of topics, from cyber regulation, software liability, navigating Federal/Defense cyber compliance and the need for digital defense of the modern national security ecosystem. - First off, for those unfamiliar with you and your background, can you tell us a bit about yourself, as well as Palantir? You're a big proponent on the role that software plays now, and will ...
Fri, 18 Oct 2024 - 142 - Resilient Cyber w/ Mark Simos - Cybersecurity Anti-Patterns
In this episode we sit down with Mark Simos to dive into his RSA Conference talk "You're Doing It Wrong - Common Security AntiPatterns" to dig into several painfully true anti-patterns in cybersecurity and how we often are our own worst enemy. - - First off, for those not familiar with you or your background, can you tell us a bit about that. - So you delivered this talk at RSA, focused on Cybersecurity "Anti-Patterns". How did the talk come about and how was it received by the audience? ...
Thu, 17 Oct 2024 - 141 - Resilient Cyber w/ Helen Oakley - Exploring the AI Supply Chain
- First off, for folks not familiar with your background, can you tell us a bit about that and how you got to the role you're in now? - We see rapid adoption of AI and security inevitably trying to keep up, where should folks start? - There are some really interesting intersections when it comes to AI and supply chain, what are some of them? - We see a thriving OSS ecosystem around AI, including communities and platforms like Hugging Face. What are some key things to keep in mind here? - ...
Tue, 08 Oct 2024 - 140 - Resilient Cyber w/ Ross Young - How to Become a CISO
- First off, for those who don't know you, can you tell us a bit about your background? - You've been providing a deep dive talk into how to become a CISO. I'm curious, what made you put together the presentation, and how has it been received so far when you've had a chance to deliver it? - You have broken down what you call "four stages of the journey" that encompasses skills in areas such as Technical, Management, Leadership and Political. This to me comes across as CISO's need to be mult...
Tue, 08 Oct 2024 - 139 - Resilient Cyber w/ Jit - Exploring the Emerging ASPM Ecosystem
In this episode we sit down with Amir Kessler and Aviram Shmueli of AppSec innovator Jit to dive into the complexities of the modern AppSec landscape and explore the emerging Application Security Posture Management (ASPM) ecosystem. - First off, for folks not familiar with your backgrounds, can you tell us a bit about both of your backgrounds and how you got to the roles you're in now? - We're seeing a ton of interest in the topic of ASPM in the AppSec space. What do you think has led to th...
Tue, 01 Oct 2024 - 138 - Resilient Cyber w/ Christina Liaghati - Navigating Threats to AI Systems
- For those that don't know you, can you tell us a bit about your background and your current role? - I know you help lead the ATLAS project for MITRE, what exactly is ATLAS and how did it come about? - The AI threat landscape is evolving quickly, as organizations are rapidly adopting GenAI, LLM's and AI more broadly. We are still flushing out some fundamental risks, threats and vulnerabilities to consider. Why is it so important to have a way to characterize it all? - When it comes to AI ...
Fri, 06 Sep 2024 - 137 - Resilient Cyber w/ Steve Wilson - Securing the Adoption of GenAI & LLM's
In this episode we sit down with GenAI and Security Leader Steve Wilson to discuss securing the explosive adoption of GenAI and LLM's. Steve is the leader of the OWASP Top 10 for LLM's and the upcoming book The Developer's Playbook for LLM Security: Building Secure AI Applications - - First off, for those not familiar with your background, can you tell us a bit about yourself and what brought you to focusing on AI Security as you have currently? - Many may not be familiar with the OWASP LL...
Wed, 28 Aug 2024 - 136 - Resilient Cyber w/ Snehal Antani - Building and Scaling a Security Startup
In this episode we sit down with the Founder/CEO of Horizon3.ai to discuss disrupting the Pen Testing and Offensive Security ecosystem, and building and scaling a security startup - from a founders perspective. From HP, to Splunk to JSOC - all leading to founding Horizon3, Snehal brings a unique perspective of business acumen and technical depth and puts on a masterclass around venture, founding and scaling a team and disrupting the industry! --- - For those not familiar with your backgroun...
Wed, 21 Aug 2024 - 135 - Resilient Cyber w/ Chloe Messdaghi - AI Security & the Threat Landscape
In this episode we sit down with Chloe Messdaghi, Head of Threat Intelligence at HiddenLayer, an AI Security startup focused on securing the quickly evolving AI security landscape. HiddenLayer was the 2023 RSAC Innovation Sandbox Winner and offers a robust platform including AI Security, Detection & Response and Model Scanning. - For folks now familiar with you or the HiddenLayer team, can you tell us a bit about your background, as well as that of HiddenLayer? - When you look at the AI...
Mon, 19 Aug 2024 - 134 - Resilient Cyber w/ Rob Allen - Endpoint Protection, VulnMgt & Zero Trust
- For those not familiar with you and ThreatLocker, can you tell us a bit about yourself and the ThreatLocker team? - When we look out at the endpoint protection landscape, what do you feel some of the most pressing threats and risks are? - There of course has been a big push for Zero Trust in the industry being led by CISA, NIST, and industry. How does ThreatLocker approach Zero Trust when it comes to the Endpoint Protection Platform? - Another thing that caught my eye is the ThreatLocker...
Mon, 19 Aug 2024 - 133 - Resilient Cyber w/ Travis McPeak - Securing Cloud-native Infrastructure
- For folks not familiar with you and your background, can you tell us a bit about that? - How about Resourcely, how did it come about and what problem did you set out to tackle? - Why do you think Cloud Misconfigurations are still so pervasive, despite being fairly well into the Cloud adoption lifecycle? - How have organizations traditionally tried to handle secure configurations, in terms of establishing them, maintaining them, monitoring for drift and so on? - Where do you think we're ...
Thu, 25 Jul 2024 - 132 - Resilient Cyber w/ Stuart Mitchell Cyber Talent, Recruiting & the Workforce
- First off, for folks now familiar with your background, can you tell us a bit about yourself? - You made the leap from working for a firm to founding your own talent and recruiting company. Can you tell us about that decisions and experience? - Before we dive into specific topics, what are some of the biggest workforce trends you are seeing in cyber currently? I have seen you talk about the pendulum shift from workers to employers on aspects like remote roles, and so on. What is the curre...
Fri, 19 Jul 2024 - 131 - S6E22: Daniel Shechter - Application Detect & Response (ADR)
- For folks not familiar with you or the Miggo team, can you tell us a bit about your background? - How do you define ADR and why do you think we have seen the need for this new category of security tooling to come about? - Most organizations are struggling with vulnerability overload, with massive vulnerability backlogs and struggles around vulnerability prioritization. Can you share some insights on how you all tackle this problem? - We're increasingly seeing the AppSec space become more...
Sun, 07 Jul 2024 - 130 - S6E21: Christoph Kern - Dissecting Secure-by-Design
- First off, for those that don't know you or your work, would you mind telling us a bit about your background? - You recently published a paper titled "Secure-by-Design at Google" which got a lot of attention. Can you tell us about the paper and some of the key themes it emphasizes? - In the paper you discuss some of the unique aspects of software that are different from mass-produced physical systems. Such as their dynamic and iterative nature. On one hand you mention how the risk of intr...
Thu, 13 Jun 2024 - 129 - S6E20: Joe McCaffrey - Securing the Digital Arsenal of Democracy
- First off, for folks that don't know you, can you tell us a bit about your current role and background? - On that same note, can you tell the audience a bit about Anduril, the mission of the organization and some of the current initiatives it is working on? - What are some of the biggest challenges of being a new entrant in a space such as the DoD, which has longstanding system integrators and large prime contractors who have deep relationships, industry expertise/experience and so on? -...
Wed, 12 Jun 2024 - 128 - S6E19: Madison Oliver - Open Source & GitHub Advisory Database
- For those that don't know you or haven't come across you quite yet, can you tell us a bit about your background in tech/cyber and your role with GitHub? - What exactly is the GitHub Advisory Database and what is the mission of the team there? - There's been a big focus on vulnerability databases, especially lately with some of the challenges of the NVD. What role do you see among the other vulnerability databases in the ecosystem, including GHAD and how it fits into the ecosystem? - GitH...
Wed, 12 Jun 2024 - 127 - S6E18: Stephen Carter - VulnMgt Modernization & FedRAMP
- For those don't know your background or Nucleus Security, can you start by telling us a bit about both? - You have experience and a background in the Federal environment, and Nucleus recently achieved their FedRAMP authorization, can you tell us a bit about that process? - When you look at the Federal/Defense/IC VulnMgt landscape, what are some of the biggest problems from your experience and where do you think innovative products and solutions can help? - Going broader, we have seen a r...
Tue, 04 Jun 2024
Podcasts similaires à Resilient Cyber
El Partidazo de COPE COPE
Herrera en COPE COPE
La Linterna COPE
Dante Gebel Live Dante Gebel
Panda Show - Sin Picante El Panda Zambrano
Es la Mañana de Federico esRadio
La noche de Cuesta esRadio
Hondelatte Raconte Europe 1
Au Coeur du Crime Europe1
Affaires sensibles France Inter
LEGEND Guillaume Pley
El colegio invisible OndaCero
La Rosa de los Vientos OndaCero
Les grands dossiers de l'Histoire par Franck Ferrand Radio Classique
Espacio en blanco Radio Nacional
Entrez dans l'Histoire RTL
Le grand récit RTL
Les Grosses Têtes RTL
Les histoires incroyables de Pierre Bellemare RTL
L'Heure Du Crime RTL
El Larguero SER Podcast
SER Historia SER Podcast
Un Libro Una Hora SER Podcast
HISTORIAS DE LA HISTORIA VIVA RADIO
