Find partners
Resilient Cyber

Resilient Cyber

Hosted by Chris Hughes

TechnologyInterviews guests

Episodes

217

Latest episode

Jul 2026

Language

EN-US

About the show

Resilient Cyber brings listeners discussions from a variety of Cybersecurity and Information Technology (IT) Subject Matter Experts (SME) across the Public and Private domains from a variety of industries. As we watch the increased digitalization of our society, striving for a secure and resilient ecosystem is paramount.

Listen to episodes

60 recent
July 23, 202639 min

Why AI Security Is Getting Rebuilt From Scratch

In this episode I sit down with Ed Sim, founder and managing partner of Boldstart Ventures, to dig into where AI security, agentic infrastructure, and the venture market are actually heading.Ed has been an inception-stage investor for nearly 30 years and has run Boldstart since 2010, backing hardcore technology companies across AI infrastructure, cybersecurity, and physical AI. He was the first investor in Protect AI, which sold to Palo Alto Networks in a reported ~$700M exit roughly a year before ChatGPT launched. He is also early in companies like Keycard, Surf AI, and June. About a third of Boldstart's investments are in cyber, so Ed sees this market from the founder and investor side in a way most security conversations do not.We get into why the era of building raw intelligence is giving way to an era of controlling it, what that means for on-prem models and private evals, and why Ed thinks nearly everything in security is going to get rebuilt from scratch.In this episode:- Why a day-one partnership looks different now that anyone can vibe code an MVP- The Protect AI acquisition and what the first exit in AI security signaled to the market- Competing as an inception fund against mega-funds writing giant seed rounds- What founders should actually look for in a venture partner beyond the check- The shift from building intelligence to controlling it, including routing, post-training, and on-prem deployment- Why enterprise data, workflows, and private evals are becoming the crown jewels- Vulnerability chaining, attack path reasoning, and how tools like Mythos are reshaping the security budget conversation- Agentic identity and why Keycard treats agents as short-lived problem solvers rather than digital twins- The Surf AI thesis on automated security hygiene and tying every asset back to an owner- The real bottleneck slowing agent adoption in the enterpriseChapters:0:00 Intro0:35 Ed's background and inception investing1:57 Day-one partnerships in the vibe-coding era3:53 The Protect AI exit to Palo Alto6:14 Competing as an inception fund against mega-funds9:17 What founders should look for in a VC partner11:48 From building intelligence to controlling it15:52 Boldstart's domain-specific model portfolio16:16 Private evals, context, and memory as crown jewels17:18 Mythos, vulnerability chaining, and attack path reasoning20:59 How much access should you give the model22:07 On-prem context and the autonomous workforce24:49 Agentic identity and Keycard28:11 Building brand and community with Insecure Agents31:30 The Surf AI thesis and automated security hygiene34:13 The real bottleneck to agent adoption37:09 The easy button, Palantir, and a multi-model world38:24 Two types of people in this new eraConnect with Ed:LinkedIn: https://www.linkedin.com/in/edsim/Boldstart Ventures: https://boldstart.vcEd's newsletter, What's Hot in Enterprise IT/VC: https://www.whatshotit.vcMore from Resilient Cyber:Substack: https://www.resilientcyber.ioSubscribe for more conversations with security practitioners and leaders.#aisecurity #agenticai #cybersecurity #venturecapital #appsec

July 20, 202637 min

Resilient Cyber w/ Joshua Saxe - Why Restricting AI Makes Us Less Secure

Does restricting frontier AI in the name of safety actually make us less secure? Joshua Saxe joins me to make the case that it does, and that AI cybersecurity will be won through defender adoption, not restriction.Josh has spent 15 years at the intersection of AI and security. He built and ran the machine learning program at Sophos, then led security for Llama at Meta, covering security post training, evals, agent guardrails, and prompt injection prevention. He recently left to co-found a startup reimagining vulnerability and exposure management agentically. He also writes one of the most cited blogs on AI and cyber policy.In this episode:- Why restricting frontier model access harms defenders more than attackers- How monitored closed models put threat actors at a structural disadvantage- The jagged frontier, and why attackers don't need frontier models for most of their tradecraft- The national security and supply chain risks of pushing the world onto Chinese open weights models- Why exploits don't cause cyberattacks, and which attacker constituencies AI actually unblocks- The dual use ceiling on guardrails and classifiers- Where defenders should be adopting AI right now, from access management to SOC automation- Using agents to burn down the mountain of security technical debtChapters:0:00 Intro0:42 Josh's background, from blackhat teen to Llama security lead3:07 The case for diffusion over restriction6:14 Why restriction hurts defenders more than attackers10:19 The jagged frontier and what attackers actually use models for12:49 National security and the supply chain risk of Chinese open weights16:08 Exploits don't cause cyberattacks20:20 Where defenders should adopt AI right now24:20 Guardrails, classifiers, and the dual use problem27:34 Reimagining vulnerability management with agents32:17 The structural advantage defenders hold35:15 Policy wishes and the attacker's Claude Code momentFollow Josh:LinkedIn: https://www.linkedin.com/in/joshua-saxe-01845a1Substack: https://joshuasaxe181906.substack.comFollow Resilient Cyber:Substack: https://www.resilientcyber.ioSubscribe for more conversations with security practitioners and leaders.#aisecurity #cybersecurity #vulnerabilitymanagement #aipolicy #opensourceai

July 16, 202641 min

Cyber Valuations, Moats & the Road to Black Hat

Cybersecurity investor Sid Trivedi of Foundation Capital joins me to dig into AI SOC valuations, services-as-software, moats, and what founders should know heading into Black Hat.Sid is a Partner at Foundation Capital, where he invests at the seed and Series A stage with a focus on cybersecurity and IT infrastructure. This is our annual pre-Black Hat check-in, and a lot has moved since last year, from massive M&A to record-setting rounds in categories like the AI SOC.In this episode:- What has actually changed a year into the AI wave, and what hasn't- Services-as-software, the $4.6 trillion market thesis, and automating cyber workflows across the SOC, IR, pen testing, and threat intel- What AI means for cybersecurity jobs and how practitioners should adapt- Consolidation vs. best-of-breed after Palo Alto's $25B CyberArk deal and Alphabet's $32B Wiz acquisition- AI SOC valuations, including Seven AI's record Series A and Torq crossing a $1B valuation- The double-edged sword of big raises and why founders should be cautious about the valuations they accept- Why you can't simply spend your way to growth in cybersecurity- Moats and defensibility when frontier labs can push into your category- The Black Hat Innovator Investor Summit and the Startup Spotlight competitionChapters:0:00 Intro0:52 What's changed a year into the AI wave2:42 Services-as-software and the AI SOC9:38 AI adoption and forward deployed engineers10:57 M&A, platformization, and best-of-breed14:17 IT and security convergence, plus AI SOC valuations18:48 Seed-stage risk calculus vs. later-stage investors21:43 The double-edged sword of big raises26:20 Why you can't spend your way to growth29:05 Moats and defensibility in the frontier-lab era32:25 Deal flow, pricing, and staying disciplined37:06 Black Hat Innovator Investor Summit40:17 Startup Spotlight competition43:28 Wrap-upBlack Hat is offering listeners $500 off registration with code USA500Resilient.Connect with Sid:LinkedIn: https://www.linkedin.com/in/siddhanttrivedi/Foundation Capital: https://foundationcapital.comResilient Cyber: https://www.resilientcyber.ioSubscribe for more conversations with security practitioners, founders, and leaders.

July 11, 202631 min

Building an AI AppSec Engineer

JJ of Gecko Security and former Disney and Costco CISO Ryan Knisley on why AppSec needs an AI security engineer, not another scanner.DescriptionAppSec has been stuck for years, drowning teams in noisy findings that never told them what was actually exploitable. JJ, co-founder and CEO of Gecko Security, and Ryan Knisley, former CISO at Disney and Costco, join Resilient Cyber to talk about what changes when an AI security engineer reasons across code, infrastructure, and design docs at once. We get into why business logic breaks traditional SAST, why attackers think in graphs while defenders think in lists, why MTTR is a broken metric, how Cal.com went closed source in the AI era, and where AI-driven AppSec consolidation lands over the next two years.Key takeawaysGecko is an AI security engineer, not another scanner. It reasons across code, infrastructure, and documentation, so a finding arrives already mapped to whether it is reachable in production and what data it touches.The context that tells you if a bug matters lives outside the code. Business logic, architecture, and runtime are where exploitability is decided, which is why scanning the code alone floods teams with noise.Business logic is why traditional SAST fails, and why an LLM alone will not fix it. The same endpoint with no auth check is a critical bug in a document store and expected behavior in a social app, and only design docs and architecture tell the two apart.Attackers think in graphs while defenders think in lists. A critical with a compensating control may not matter, while ten lows chained together can be the thing that actually reaches the asset you care about.Exploit development is being commoditized. JJ describes a near future where the whole internet becomes one big bug bounty scope with agents running campaign-level attacks, so the old severity-ranking lens no longer holds.Fix the class, not the ticket. Rather than patching bugs one by one, Gecko traces groups of findings back to the design decision that created them and eliminates every variant so the same issue never returns.MTTR is a broken metric. A variant of last week's bug returns with a fresh clock, so teams close tickets to look healthy while risk stays flat, which is why Gecko measures recurrence rate instead.Cal.com shows where open source is heading. After AI coding pushed its pull requests from about 30 a day to 100 with a one-person security team, being open source flipped from an advantage to a liability, so it went closed source and replaced four tools with one.Tool consolidation is a risk decision, not a cost exercise. Ryan's shiny object problem leaves teams stacking scanners nobody can fully staff, and collapsing the stack lets you cross-train people and reduce real complexity.The finding layer collapses, and human judgment moves up. When finding and fixing get cheap, the scarce work becomes deciding what is correct, whether to accept a risk on purpose, and owning the design decision for a whole class of bugs.Chapters00:00 Meet JJ and Ryan02:46 Why Gecko is an AI security engineer, not another scanner05:07 The trend of agentic and headless security tools05:53 Why business logic breaks traditional SAST06:27 The no-auth endpoint example and context outside the code09:06 Attackers think in graphs, defenders think in lists11:02 Commoditized exploit dev and the internet as one bug bounty13:55 Shift left and why MTTR is a broken metric15:07 Eliminating entire classes of vulnerabilities15:51 Recurrence rate and avoiding risky refactors18:22 The Cal.com case study and open source going closed20:48 Consolidation and the shiny object problem in security22:40 Where AI-driven AppSec lands in two years27:12 What it takes to trust an AI security engineer28:57 Where to find Gecko and the Black Hat talk

July 5, 202636 min

Why Finding Vulnerabilities Was Never the Hard Part

Every headline wants you to believe AI has rewritten the rules of cybersecurity. Eric Doerr, the Chief Product Officer at Tenable a Resilient Cyber Partner, is not so sure. After running security response at Microsoft and leading security products at Google Cloud, he came on to separate the genuine transformation from the noise, and his read is refreshingly grounded. The tools changed, but the fundamentals did not, and the teams that win are the ones who finally act on that.Why this conversation mattersEric sits at a rare intersection, having lived the post-breach world of the SOC and now building the pre-breach world of exposure management. That vantage makes him a sharp guide to what AI actually shifts for defenders, from why cheaper discovery makes prioritization more valuable to how AI becomes its own attack surface once agents start touching your data. If you own vulnerability or exposure management and you are trying to spend your next dollar well, this conversation is a practical map of where the real risk lives and what to automate first.Key takeawaysAttackers are ruthlessly economical. Eric calls bad actors the perfect capitalists, spending the least effort needed to hit their goal, which is why so many still get in through unpatched basics rather than anything AI-powered.AI has not rewritten the offense-defense balance. The attacker only ever had to be right once, layered defense and zero trust still hold, and the real lever is accelerating your program with fewer human loops rather than lamenting the asymmetry.Cheaper discovery makes context more valuable, not less. Reachability and exploitability mean most findings are not worth chasing, so as AI floods teams with more of them, telling the truly scary hundred from the theoretical ten thousand becomes the whole game.Being too small to target is a strategy on borrowed time. As automation drives the cost of attacks toward zero, the quiet bet that adversaries will hit weaker neighbors stops paying off, and Eric would move off that mentality now.Humans should not be the bottleneck on every fix. Getting the workflow and tooling right is most of the work, and the rest is the organizational willingness to let validated automation act, even when a business partner would feel better with a human in the loop.AI is special and not special at the same time. It is mostly just another attack surface, and Eric estimates 80 to 90 percent of securing it maps to patterns the industry already learned during the move to cloud.Shadow AI is the first surprise in almost every environment. When teams scan the endpoints they already interrogate for AI artifacts, nearly all of them find something they never sanctioned, which is why discovery has to come before control.The real AI risk is interconnection. A misconfigured database was a needle in a haystack until you wire it to an agent, and then a harmless question about the budget quietly returns data the asker should never see.Most breaches are not even CVEs. Citing the Verizon DBIR, Eric notes roughly two-thirds of breaches trace to misconfigurations, and since about a third of Tenable’s findings are non-CVE, a third of your findings can carry two-thirds of your risk.Agentic automation is finally killing the toil. Early users are automating drudgery like asset tagging and full remediation workflows, with one manufacturing customer letting automation handle 80 to 90 percent and scheduling the rest for change windows with a human notified.Notable quotes“Bad actors are the most perfect representation of capitalism”Eric Doerr, on why attackers do the least work necessary and often skip AI entirely.“a third of their findings are two-thirds of their risk”Eric Doerr, on why misconfigurations, not CVEs, drive most breaches.“you’re on the wrong side of history”Eric Doerr, on insisting a human eyeball every automated fix.

June 27, 202624 min

Rain Versus Flood, Making Sense of the 2026 CVE Surge

CVEs are on pace to hit nearly 70,000 in 2026, but Jerry Gamblin explains why the actual exploitable risk is staying surprisingly flat.DescriptionJerry Gamblin runs RogoLabs and built CVE.ICU, and he co-authored the FIRST mid-year vulnerability forecast that just put 2026 on pace for nearly 70,000 CVEs. He joins Resilient Cyber to separate the scary headline number from what actually matters for defenders. We get into why GitHub now publishes one in five CVEs, the rain versus flood distinction that explains why exploitable risk is flat even as raw volume explodes, what the NVD collapse means now that the CNAs have to step up, and how teams should really be triaging with EPSS and the CISA KEV catalog.Key takeawaysCVEs are on pace for nearly 70,000 in 2026, up more than 40 percent year over year. Much of the surge traces back to a single source, with GitHub now publishing one in five CVEs after scaling up its advisory team.The three drivers behind the surge are very different forces. AI-assisted discovery that nobody can definitively flag, a 449 percent jump in GitHub security advisories, and VulnCheck acting as a CNA of last resort all get lumped into one scary number.Rain versus flood is the frame that matters. Raw CVE volume is climbing fast, but once you filter for CISA KEV and EPSS the actionable, exploitable risk has stayed essentially flat.Most of the new findings are old human debt, not a new AI threat. The OWASP Top 10 has barely changed in 25 years, and tooling can now find those same mistakes at scale across mostly open source code.The AI moment is useful cover to finally patch. Jerry argues teams are using the AI hype cycle to win the time and resources to fix long-known issues, which is a genuinely good outcome.The NVD was the dam that fell. It was never fair to expect one small organization to enrich every CVE, so responsibility now shifts back to the CNAs and the large vendors that leaned on it for years.Treat CVE data as a product you pay for. Jerry's advice is to use procurement leverage, since demanding better CVE records before you renew a contract is one of the few real forcing functions available.What gets exploited has not really changed. VPN concentrators and the same old vulnerability classes still dominate, and the NSA's annual top 10 exploited bugs are reliably old, with no sign yet of AI driving widespread attacks.Asset inventory is still the real bottleneck. You cannot triage what you cannot see, and most organizations still cannot say with confidence whether they even run the software a given pile of CVEs affects.AI-accelerated exploitation is coming, but not as mass exploits. The bigger shift is a tireless attacker that loops on your network for days until it finds a way in, which is exactly what agents are best at.GuestJerry Gamblin, creator of CVE.ICU and founder of RogoLabs. Resources mentionedFIRST 2026 mid-year vulnerability forecastSubscribewww.resilientcyber.io

June 18, 202640 min

You Don't Need A Frontier Model to Find Zero Days

Niels Provos on why you don't need a frontier model to find zero days, why the Vulnpocalypse is overstated, and how security invariants change the game.DescriptionNiels Provos has spent twenty-five years in security, from writing bcrypt to running security at Google and Stripe, and he came on to push back on the panic around AI and vulnerabilities. He explains why finding zero days is an orchestration problem rather than a frontier-model problem, using his Iron Curtain runtime and an open-weight model to surface net-new bugs for the cost of a cheap scan. We get into security invariants and egress control, why remediation is the real bottleneck, why AI coding tools ignore the security abstractions you build, and why someone this technical keeps coming back to incentives over technology.Key takeawaysYou don't need a frontier model to find zero days. Niels used his Iron Curtain runtime and an open-weight model to surface net-new vulnerabilities, which is why he calls this an orchestration problem rather than a frontier-model problem.The Vulnpocalypse framing is overstated. Companies already sit on more vulnerabilities than they can manage, so more findings do not fundamentally change the picture, and the catchy panic mostly drives engagement.Security invariants beat patching one bug at a time. An invariant is an infrastructure guarantee enforced without ongoing human judgment, which makes entire classes of vulnerabilities irrelevant instead of chasing each one.Egress control is the canonical example. If a production service can only reach a few known domains, most vulnerabilities never get to fetch a second-stage payload, so the exploit chain stalls.The log4j story shows why it matters. As head of security at Stripe, egress control meant the malicious download could not execute, so the team had room to patch calmly instead of fighting an emergency.Remediation, not discovery, is the harder problem. The quality bar of not breaking working code in production is what keeps fixing slow, and AI has not solved that yet even as it makes finding cheap.AI coding tools ignore the security abstractions you build. When Niels asked Claude to add an endpoint to a carefully structured project, it bypassed his abstractions and wrote raw code, which is why frameworks need to be secure by default.The harness is the moat. A finite state machine that decomposes vulnerability finding into stages, each with a fresh context and a tight prompt, gets reliable results from weaker models that otherwise lose the plot.It is the incentives, not the technology. Companies do just enough security to avoid looking negligent, so without accountability shifting through something like Europe's NIS2, better tooling alone will not change outcomes.Open source maintainers need to be empowered. They often cannot afford the latest models or the tokens to run them, yet everyone builds on their free work, so helping them fix vulnerabilities has the broadest payoff in the ecosystem.

June 15, 202640 min

AI Industrialized the Vuln Lifecycle and Broke the System of Record

VulnCheck's Patrick Garrity on the NVD collapse, the first real AI disclosure wave, and why remediation, not finding bugs, is the bottleneck.DescriptionVulnerability management spent years as the chore everyone dreaded, and now it is one of the hottest topics in security because attackers made exploitation the number one way in. Patrick Garrity of VulnCheck rejoins the show to separate what is real from what is marketing. We get into the honest state of the NIST National Vulnerability Database after CISA pulled its funding, the new AI executive order that wants a clearinghouse for AI-discovered vulnerabilities, the first measurable wave of AI-assisted disclosures, and Patrick's audit of Anthropic's Glasswing ledger. We also dig into why cheap AI discovery makes the remediation bottleneck worse, how AI is raising the security poverty line, and whether the 90-day disclosure model still holds.Key takeawaysVulnerability management is hot again because attackers made it the top way in. As Patrick puts it, attention flows to wherever the attacker goes, and right now that is exploitation.The NIST NVD breakdown was worse than a backlog. A recent report confirmed CISA had stopped funding the NVD and NIST lost about half its funding, with no real plan to clear the backlog, which quietly hurts every defender who relies on enriched CVE data.A new AI executive order wants a clearinghouse for AI-discovered vulnerabilities, reportedly under Treasury. Patrick's reaction is that we already have a vulnerability database, the program is optional, and it may turn into a marketing race more than a coordination win.The first measurable AI disclosure wave is real. CVE volumes are up 563 percent for Chrome and GitHub advisories up 470 percent year to date, and Patrick separated genuine AI-assisted discovery from AI slop and from bugs that merely live in AI software by correlating researchers, domains, and email addresses across multiple advisory sources.Patrick audited Anthropic's Glasswing ledger and found the transparency lacking. He had around 80 vulnerabilities in his own database while the public ledger listed 27, several items had blown past their own 90-day disclosure window, and the ledger had not been updated in two weeks.Finding vulnerabilities is not the bottleneck, remediation is. AI makes discovery cheap, but the coordinated disclosure and fix process takes enormous human effort, and the median time to remediate even known exploited bugs is still measured in weeks.Exploitation looks like it is sustaining rather than surging. CISA KEV and VulnCheck KEV are tracking similar year-over-year volumes, partly because attackers already have more than enough to target and partly because you can only count the exploitation you can actually detect.AI is raising the security poverty line, at least for now. Token costs and access-restricted tools concentrate the most powerful discovery capabilities among well-funded teams, while smaller organizations lack the expertise to turn open-weight models into working vulnerability harnesses.The economics are circular. AI drives the surge in findings and attacker velocity, and AI is then sold as the fix, so teams pay to surface the problem and pay again to remediate it, all on consumption-based pricing against finite budgets.The 90-day disclosure norm mostly holds, though it may tighten. VulnCheck runs a strict 120-day policy with no exceptions and averages 45 to 48 days to fix and disclose, and for open source the fixing commit often makes the flaw public anyway.

June 3, 202635 min

AI Is Winning the Cyber Arms Race

For twenty years the security playbook started in the same place, find a vulnerability, prioritize it, and patch it. Doug Merritt, CEO of Aviatrix and former CEO of Splunk, thinks that playbook is quietly breaking, and his explanation has nothing to do with anyone being careless. The economics of offense changed underneath us, and most security programs are still funded as if they did not.Why this conversation mattersDoug has sat in two seats that give this argument weight. At Splunk he evangelized detect and respond, and now at Aviatrix he is arguing that detect and respond, while still important, is no longer enough on its own. That is not a vendor pivot so much as an honest reading of the incentives, and it lands differently coming from someone who built a business on the previous era. If you are a practitioner watching AI rewrite the attacker's cost curve, or a leader trying to defend a prevention-heavy budget to a board, this conversation reframes where the money should actually go.Key takeawaysOffense became a compute problem, and that is permanent. Finding and exploiting a vulnerability is a search task, and the cost per token has been deflating faster than Moore's Law. That is why this is a structural shift rather than a few headline demos, and why throwing compute at offense keeps getting cheaper and faster.Patching has a ceiling that offense does not. Every patch carries the risk of breaking something, so testing, deployment, and organizational friction cap how fast defenders can move. When vulnerability discovery scales freely and patching cannot, "find more and patch faster" turns into a race you are structurally set up to lose.The interesting question is not how they got in, it is where they went. Attackers increasingly arrive with valid credentials and move through the trust graph that runs across cloud services and CI/CD pipelines, including malware injected into trusted repositories. Once they look legitimate inside the environment, lateral movement and egress are where the real damage happens.Cloud rewarded velocity, and security paid the bill. Cloud providers made identity default-deny because someone has to own and pay for a workload, but they left networking wide open because their economic engine is developer velocity and security reads as friction. New agentic frameworks inherit that same wide-open default, connected to the internet with little oversight.A strong identity stance is necessary and not sufficient. Identity answers whether someone is allowed to act, not whether the action is an attack, which is why attackers log in rather than hack in. Human, agent, and workload identities are genuinely different, and workload identity in particular has been underserved.Containment is about blast radius, not about keeping everyone out. The mindset shift is to accept that breaches will occur and to govern every path a workload can take, so an incident stays local and recoverable. Done well, containment holds firm whether or not anyone has detected the attack yet.Blast radius has to become a boardroom metric. Doug's argument is that CISOs, CIOs, CEOs, and boards should be able to answer how reachable anything is from anything else, and treat that number as something to drive down deliberately rather than discover after an incident.AI is the reason containment is finally workable. The historic blocker to micro-segmentation was cognitive load across tens or hundreds of thousands of workloads. AI is strong at synthesis and pattern matching, which makes a staged path of observe, discover, monitor, and then enforce realistic, ideally starting with the internet-exposed workloads that have no filtering at all.

May 29, 202649 min

Securing the Agentic SDLC

In this episode of Resilient Cyber, I sit down with Katie Norton, Research Manager for DevSecOps and Software Supply Chain Security at IDC, to unpack what application security looks like as AI moves from copilot to autonomous teammate across the software development lifecycle.We dive into:🤖 AI's accelerating impact on AppSec and the SDLC – and the productivity-versus-risk equation now that agentic coding tools are shipping code at machine speed💥 The "Vulnpocalypse" – the explosion of CVEs, AI-generated code, and the widening gap between vulnerability discovery and remediation capacity🛠️ Whether legacy AppSec categories like SAST, DAST, SCA, and ASPM can keep pace – or are being fundamentally reinvented for an agentic world🎯 The rise of autonomous pen testing and offensive security agents (XBOW, Project Naptime, Project VAIL) and what it means when offense scales faster than defense🔗 How agentic development is reshaping software supply chain risk – from hallucinated packages to MCP server integrity and the provenance of code no human ever wrote🏛️ Governance models for AI-generated code, the evolving AppSec team of the future, and what CISOs should be prioritizing right now📈 Katie's predictions for where AppSec, software supply chain security, and the SDLC are heading over the next 18-24 monthsWhether you're an AppSec practitioner, security leader, developer, or just trying to make sense of how AI is reshaping software security – this conversation is packed with insights you won't want to miss.🔔 Subscribe for more conversations on cybersecurity, AI security, and the future of resilient software.#Cybersecurity #AppSec #AISecurity #DevSecOps #AgenticAI #SoftwareSupplyChain #ResilientCyber

Is this your show?

Claim this listing to keep it up to date, reach guests who want to pitch you, and manage bookings with Guestify.

Claim this listing

More Technology podcasts