Find partners
The Security Strategist

The Security Strategist

Hosted by EM360Tech

BusinessManagementNewsInterviews guests

Episodes

241

Latest episode

Aug 2026

Language

EN

About the show

With cyber attacks more common than ever before and each attack becoming increasingly sophisticated, security teams need to be one step ahead of cybercrime at all times. “The Security Strategist” podcast delves into the depths of the cybercriminal underworld, revealing practical strategies to keep you one step ahead. We dissect the latest trends and threats in cybersecurity, providing insights and expect-backed solutions to protect your organisation effectively. Tune into this cybersecurity podcast as we dissect major threats, explore emerging trends, and share proven prevention strategies to fortify your defences.

Listen to episodes

60 recent
August 18, 202624 min

Understanding DDoS Attacks and How to Defend Against Them

Cybersecurity faces the continued onslaught of distributed denial-of-service (DDoS) attacks. Websites, applications, and online services flooded with junk traffic are unable to serve legitimate users. Businesses lose revenue, budgets are strained, and customers lose faith. DDoS may not get the attention of ransomware headlines, but attackers are changing their tactics to launch larger, more sophisticated attacks. In this day and age, it’s easier to orchestrate for a range of purposes, including extortion, disruption, hacktivism, or hurting competitors’ bottom lines. Many are also powered by massive botnets made up of millions of compromised IoT devices. In this podcast episode of Security Strategist , host Richard Stiennon talks with Qrator Labs CTO Andrey Leskin about how these attacks are evolving and what organisations need to do to keep pace. They explore the growing scale and complexity of attacks, the role of massive botnets, practical approaches to DDoS mitigation, and how AI could accelerate existing attack capabilities. The Biggest Trend is Scale Leskin started at Qrator Labs as a developer 14 years ago and worked his way up to chief technology officer. “I started off as the guy in IT who woke up at 3 a.m. because something stopped working,” Leskin tells Stiennon. “Now I’m the lucky guy who gets to wake up and try to fix things for our clients.” Today Qrator Labs manages cloud scrubbing infrastructure, bot management tools, and network monitoring services for hundreds of banks, betting platforms, e-commerce firms, media, education, tourism, and telcos throughout North and South America, Europe, the Middle East and Asia. That broad exposure gives him insight into the latest attack patterns. “Scale is the biggest trend,” Leskin says. An attack earlier this year topped two terabits per second and nearly one billion packets per second. It sustained that traffic rate for more than 40 minutes. During Q2, the company saw a doubling in terabit attacks (meaning attacks of one trillion bits per second or greater) year-over-year. “That used to be a super-rare once-a-quarter type of thing,” Leskin said. “Twelve is not unique. Bandwidth that used to be exceptional is now just regular Tuesday.” Botnets powering these attacks are getting bigger, too. One botnet monitored by Qrator since March of last year grew from around 1.5 million bots to over 13 million within about a year. The geographic diversity of infected hosts also continues to expand, making filtering traffic based on region less effective as an automated mitigation technique. Attacks are also easier to launch than ever before. Today attackers can find DDoS-for-hire services that simplify everything except deciding how much money they want to spend. Make the payment in cryptocurrency, paste in a target IP address or URL, and press launch. Many don’t need advanced technical knowledge. Decentralised command and control systems, including botnets using blockchain technology to coordinate activity, are complicating mitigation efforts further. Existing Mitigations Fall Short A common DDoS myth, Leskin says, is the idea that hosting with a cloud provider or CDN somehow provides adequate protection from DDoS attacks. While a website or app might remain available, those services are designed to maximise uptime and performance, not fend off attacks specifically. Organisations are still on the hook for all of the network resources an attack consumes. “And then when the monthly bill arrives you realise you were DDoS’ed on your wallet,” Leskin said. Attackers are also leveraging multiple attack vectors more frequently. Instead of a single volumetric flood or application-layer attack, defenders might see both plus attempts to overwhelm other dependencies like a firm’s merchant processor. Leskin highlights how betting platforms saw an onslaught of attacks during the recent World Cup. Financial-services firms and fintech companies made up 44 per cent of DDoS attacks in Q1. That figure fell to 22 per cent in Q2 as attackers shifted their focus to gambling platforms, where attacks reached 1.5 terabits per second. Tips for Defending Against Tomorrow’s Attacks Preparing for these evolving threats starts with being operationally prepared, rather than buying into any one silver-bullet technology, Leskin said: Know and understand your normal traffic profile down to the protocol level and by time of day or season. Traffic during a World Cup final will look very different to normal operations for a betting platform. Expect blended attacks that use more than one vector designed to evade traditional DDoS mitigation systems. Botnets are nothing new, but blocking them is still important. In the first quarter of 2026, Qrator blocked an average of 2.5 billion malicious bot requests each month. While not considered DDoS, these attacks can still have a significant impact on performance. Have an incident response plan that you’ve practised so you can respond as quickly as possible when an attack happens. From a tech perspective, there are two main categories of DDoS mitigation, each with advantages and disadvantages: DNS-based protection Easy to implement; works well at mitigating attacks against websites and web applications Doesn’t work for everything routed outside of DNS, like voice services or game servers BGP-based mitigation Handles any type of network traffic at the network layer. You need to own your own network; can take up to one full day to implement. AI and DDoS Attacks Leskin says that he doesn't expect AI to introduce new types of attacks. Instead, he sees it accelerating what already exists, helping attackers scan for vulnerable devices faster, automate reconnaissance, and grow botnets more efficiently. In other words, AI mostly lowers the cost and skill threshold for doing what attackers already do. Combined with the rise of DDoS-for-hire services, pushes more of the "easy attack" trend described earlier. His closing point was less about tools than posture: "Security isn't a state you achieve one time. It's a process you maintain, because whatever you're defending against is actively evolving against you." The figures cited reflect Qrator Labs’ own network telemetry and provide a view into the attack trends observed across its protected infrastructure. While they do not represent the entire global DDoS landscape, they highlight a clear direction. For most organisations, the practical implication isn't "buy more bandwidth." It's building the muscle memory, traffic baselines, tested response plans, and mitigation that matches how you actually operate before an attack forces the issue. If you would like to learn more, visit qrator.net or follow Andrey Leskin on LinkedIn. Takeaways The scale and evolution of DDoS attacks from 2020 to 2026. The role of botnets and their growth in size and geographic diversity. Common motivations behind DDoS attacks. Limitations of CDN and cloud provider protections against DDoS. Best practices for organisations to assess and improve their DDoS resilience. Technical mitigation techniques including DNS and BGP-based protections. The importance of continuous security posture review. Future trends including AI-driven attack methods and multi-vector incidents Chapters 00:00 Introduction to the episode and guest Andrey Leskin 01:04 Overview of Qrator Labs and their cybersecurity services 02:46 The evolution and scale of DDoS attacks from 2020 to 2026 04:09 Growth of botnets and their geographic diversification 05:22 Motivations behind DDoS attacks and attacker profiles 07:49 Limitations of CDN and cloud protections against DDoS 09:16 Technical mitigation strategies: DNS and BGP protections 11:21 Proactive customer acquisition and security readiness 13:06 Key checklist items for organisations to improve resilience 17:24 Technical defences: DNS and BGP mitigation explained 21:07 Current threat landscape across industries and sectors 24:16 Future of DDoS attacks and AI-driven threats

August 13, 202617 min

How to Prep Security Teams in Enterprise DLP Strategy for AI

The biggest cybersecurity challenges when it comes to integrating AI platforms like Microsoft Copilot, ChatGPT Enterprise or any other AI agents for enterprises may seem to be pertinent to governance, acceptable use policies and employee training in AI. However, that is not always the case. Ultimately, it comes down to a challenge with the data. In the recent episode of The Security Strategist podcast , host Shubhangi Dua, Podcast Producer and B2B Tech Journalist , is joined by Itay Maor, Head of Product at Orion Security . They address the foundational issue with deploying agentic AI to enterprise workflows, which comes down to Data Loss Prevention (DLP) . Maor begins the conversation with the statement: “Data loss is preventable. It's not just observable.” He adds that only by dropping assumptions built over 20 years of ineffective DLP can teams successfully make Data Loss Prevention work. What Is Hindering Enterprise Security from Adapting to an AI-First World? For enterprises to become a core part of an AI-first world, data must be protected from an early start. As soon as tools like Copilot or ChatGPT Enterprise enter the picture, sensitive data begins flowing into prompts. The issue is that security teams often lack visibility into what employees are inputting, such as customer records, deal terms, or source code. Firstly, blocking the AI is not going to work in this scenario because AI is here to stay. The issue that needs addressing is that security teams need to be able to see where the enterprise data is flowing. Maor believes AI hasn't created an entirely new security problem; it has exposed one that has existed for years. “Customer records, source code, deal terms- legacy DLP doesn’t help much because they were built to match patterns, credit card numbers, keywords. Pasting a Q3 revenue forecast into a chatbot won't trigger standard security alerts,” he says, putting it into context. “You approve ChatGPT Enterprise, but what if your employee just logged in using their personal account? Same URL, same interface, same browser, and your network controls say chatgpt.com and waves it through,” Maor adds. Security teams need to know which identity the data is flowing to. Right now, it's difficult for them to differentiate. The third layer, however, is where the market is heading because it depicts where the AI is connected to the data. For instance, Microsoft Copilot is wired into SharePoint and ChatGPT. Cloud connects to Google Drive, to Slack, and to email through native connectors. Meanwhile, the agents query internal systems on their own autonomously. “There is no upload, no paste, no human action to inspect at all,” the Head of Product at Orion tells Dua. AI agents end up inheriting 10 years of over-permisioning, he says; “it happily surfaces an M&A document to anyone with access that was never cleaned up, making it searchable in plain English.” Each of these three layers widens the gap that all controls can cover. So, the first challenge isn't blocking AI; it's that you can no longer answer where your data is going, and everything else in AI security starts with that question. How Security Teams Must Move From Detection to Data Loss Prevention Maor proposes that enterprises need to shift their mindset from detection to prevention, asserting that "Prevention is the goal, not just detection with good reporting. “Lead with the mindset before the tactics,” he advises enterprises, “data loss is preventable, and that should be the mindset, not just observable.” This means security teams must stop enumerating every risk as a policy up front, unlike before. Policies are essential for deterministic rules, and they’re not going away. If a rule says ‘PCI data never leaves production’, but the era of managing hundreds of policies is over. Another mindset shift is needed around false positives. Teams need to stop treating high false-positive rates as simply the cost of doing business. They're not some unavoidable force of nature. “They don't have to live with them. The problem is that when false positives become the norm, you train your team to ignore alerts—including the ones that actually matter,” he says to Dua. And finally, enterprises need to stop staffing around the problem instead of solving it. Adding more analysts to a queue that's growing faster than your headcount isn't a scalable strategy. It's better to reduce the noise than to keep expanding the team that's trying to manage it. As enterprises continue embracing AI, Orion's view is that the future of data security won't be defined by more dashboards or more point solutions. It will be defined by knowing where data is moving, understanding why it's moving and preventing loss before it happens. Takeaways DLP tools are overwhelmed with false positives. AI can provide real-time contextual understanding. Traditional DLP systems are not equipped for modern data challenges. The future of data security relies on AI-driven solutions. Guardrails are essential for safe AI usage in enterprises. Real-time monitoring is crucial for effective data protection. Policies should be limited and focused on specific use cases. AI can recognise sensitive data patterns that traditional methods cannot. Data security must adapt to the rapid evolution of AI technologies. Education on new risks is vital for enterprises. Chapters 00:00 The Evolution of Data Loss Prevention (DLP) 02:54 AI's Role in Redefining Data Security 06:12 Challenges of Traditional DLP Systems 09:02 The Need for Contextual Understanding in DLP 12:07 Guardrails for AI in Data Security 15:04 Transitioning from Policies to AI-Driven Solutions 17:54 Real-World Examples of Data Protection 20:49 The Future of DLP and Data Security Watch the full episode of The Security Strategist podcast to hear Itay Maor, Head of Product at Orion, discuss how AI is reshaping enterprise DLP and what security leaders should act on next. Visit orionsec.io . AI-native DLP, Data Loss Prevention, DLP, Enterprise DLP, AI Security, Enterprise AI Security, AI Data Security, Data Security, Microsoft Copilot, ChatGPT Enterprise, AI Agents, Agentic AI, Enterprise Data Protection, Sensitive Data, Cybersecurity, CISO, Contextual DLP, AI-Driven DLP, Data Loss Prevention AI, AI Security Strategy

August 12, 202623 min

Why Backup Immutability Doesn’t Guarantee Ransomware Recovery

You’re in an argument with your AI bot on ChatGPT ; suddenly, your screen is locked. None of the keys on your keyboard work, and then you see a ransom note displayed on the screen. The systems have been encrypted, and the incident response team has been activated. The executives go to the one thing they had been told would save them, which is the backups. Enterprises may believe their data is safe because of their immutable backups. But according to Mark Grazman, CEO of Fenix24 , they are likely mistaken and often realise this after ransomware has already hit them. At some stage of a ransomware attack, the assumptions of cybersecurity come up against reality. In the recent episode of The Security Strategist podcast, host Richard Stiennon, Chief Research Analyst at IT-Harvest , is joined by Mark Grazman, CEO and Co-Founder of the ransomware recovery company Fenix24 . They discuss the critical aspects of ransomware resiliency, including the four pillars of recoverability—survivability, completeness, speed, and assurance. They also talk about how enterprises can better prepare for and respond to attacks. When Stiennon asked Grazman what's the thing he would assess that incident response playbooks miss if he walked into an active incident right now. Grazman says after a scoping call, he would ask the affected enterprise if their data was immutable. Most people say yes. “There’s an 84 per cent chance that they’re wrong,” he adds. “The attack already happened, the data's already gone, and they don't even know it yet.” The issue, he says that enterprises are practising and simulating that the data’s gone along with the infrastructure. “They're practising that there was a hurricane or a fire or a replication or an event as opposed to a true ransomware.” Also Read: Ransomware Attacks: What You Need to Know Find the latest cybersecurity insights, podcast episodes, and expert analysis on EM360Tech.cpm. Visit fenix24.com for more information. Takeaways 84% of enterprises may be wrong about backup immutability. Surviving backups do not guarantee successful recovery. Ransomware recovery depends on four pillars: survivability, completeness, speed, and assurance. Critical applications rely on more infrastructure than enterprises often realise. Traditional disaster recovery tests may not reflect a ransomware attack. Cybersecurity budgets need more investment in recovery readiness. Chapters 00:00 Introduction to ransomware resiliency and Mark Grazman's expertise 01:20 Assessing incident response priorities in real-time attacks 02:06 The myth of immutable data and common misconceptions 03:06 Breaking down the four pillars of resiliency 04:03 Survivability: Protecting critical data and dependencies 05:02 Completeness: Ensuring full data and infrastructure recovery 07:32 Speed: Rehydration, containment, and infrastructure considerations 09:30 The importance of assurance and continuous testing 11:09 Applying resiliency principles to other disasters 12:37 The gap between enterprise expectations and reality 13:05 Evolving offence and defence in ransomware protection 14:39 Pre-attack preparedness and the Argos platform 16:06 The process of resiliency assessment and tuning 19:18 Organisational roles and collaboration for effective recovery 21:18 Key message for CISOs, CIOs, and CEOs on resiliency 23:30 Closing remarks and resources for further information

August 12, 202627 min

Why Identity Is Becoming Security's New Front Line

Security teams around the world have always tried to play a balancing act when it comes to authentication. If there are too many measures put in place, people will always find a way to get through it. In the world of rapid AI advancement, this balancing act is proving to be more difficult for organisations. The reason is that AI agents proliferate; they're now able to perform tasks on behalf of employees and customers without a human overseeing every action. So what needs to be done to prevent your organisation from being exposed? On this episode of the Security Strategist Podcast , host Trisha Pillay talks with Dan Moore , Senior Director of CIAM Strategy and Identity Standards at FusionAuth , about how and why identity has become the new security perimeter. Moore has worked for almost six years at FusionAuth, starting in developer relations before stints in sales engineering and implementation prior to his current role. At FusionAuth, he helps track standards bodies like the IETF and OpenID Foundation and determines which fledgling methods are ready for adoption into the product. The Security-Usability Tension Gets Sharper Finding the right balance between strong security and a smooth user experience is a challenge organisations have faced for years. Moore traces it back to the invention of the first password field in the 1960s. Various industries have adopted different approaches to ensure that there is a balancing act of strong security and a smooth user experience for their customers. For example, banks are willing to require more security checks than a consumer app because the risks are so much higher. The old methods of authentication were designed for a world where every login belonged to a person making decisions at human speed. This has all changed now because of AI agents. Unlike people, AI agents can work independently, run continuously, and complete thousands of tasks in seconds. This speed and scale mean they can also cause far more damage in a matter of seconds if something goes wrong. AI agents need to work independently, so traditional human-focused security measures like MFA and CAPTCHAs often get in the way. It's also important to know that removing those checks doesn't just eliminate the security risks. This simply means those risks can happen so much faster. At the same time, asking humans to approve everything isn't a solution either, because people quickly become overwhelmed and stop paying attention. Adaptive Authentication in Practice This is where identity is shifting from a single check at the door towards continuous and contextual verification. Moore describes it as moving away from a binary model, because risk no longer lives only at the login screen. It follows the session, the device and the ongoing behaviour within an application. FusionAuth worked with a platform connecting caregivers with families needing support, a sector handling sensitive data including that of minors. By adding enterprise single sign-on and multi-factor authentication, the company cut its authentication development time by 90 per cent and opened up business markets it previously couldn't serve, proof, Moore says, that tighter security and a better user experience aren't mutually exclusive when the approach is intelligent about context. Giving AI Agents Their Own Identity One of the biggest shifts discussed is the need to stop thinking of AI agents as just another user account. Instead, organisations need to manage them as separate digital identities with their own permissions and controls. Moore recounts a colleague mentioning they would let an AI assistant drive their browser while logged in as themselves. This becomes indistinguishable, from the system's perspective, from the person acting directly. Without a separate identity, there's no way to apply different policy, add extra checks, or restrict what an agent can do relative to its human counterpart. With all that said, it's no wonder that AI agents need their own identities, provisioning, and scope, along with their own audit trail. The risk comes down to velocity. A compromised employee can only do so much before they're detected, but a misbehaving AI agent can make thousands of decisions, access systems, and execute actions in the same amount of time. Moore frames trust as resting on three interlocking layers: identity validation, audit, and policy enforcement. Validation establishes who or what is acting; audit records what actually happened, which matters given how unpredictable agent behaviour can be; and policy enforcement, built on principles like least privilege and short-lived, task-scoped credentials, limits the damage if something goes wrong. All three layers work together to build trust, he says, because each one compensates for what the others struggle to catch alone. His advice for organisations still finding their footing is to start small rather than wait for a polished strategy: inventory the AI agents and automated processes already running, note what kind of credentials they rely on, and begin shifting static API keys towards short-lived, standardised grants. Above all, he argues, AI identities deserve their own category tied to an accountable human or team, but never simply reused from existing human or service accounts. If you would like to find out more about this, visit FusionAuth or connect with Moore on LinkedIn. Takeaways The changing role of identity in security. Challenges of AI-powered applications and autonomous agents. Adaptive authentication and risk-based security. Building trust through identity validation, audit, and policy enforcement. Practical steps for organisations to enhance security in AI environments. Chapters 00:00 Introduction 01:28 Guest background and role at Fusion Auth 03:07 The security-usability tension in identity management 04:13 Impact of AI and autonomous agents on security 05:56 Balancing security controls with user experience 09:02 The shift to adaptive, context-aware authentication 11:48 Real-world example of security and usability balance 14:04 AI identities versus human identities 17:53 Building trust in AI systems with layered security 23:34 Practical steps for organisations to prepare for AI security 27:30 Closing remarks and resources

August 11, 202620 min

Defensible Prioritisation: A Story CISOs Can Stand Behind

Prioritisation is the way to tackle enterprise data challenges. It may seem like a simple solution, and it might be too. If you’re an enterprise overwhelmed by vulnerabilities in data, especially with the evolution of AI and automation, this conversation is for you. In the recent episode of The Security Strategist podcast , host Shubhangi Dua, Podcast Producer and B2B Tech Journalist at EM360Tech , sat down with James Walta, Vice President of Product Management at Brinqa. The agenda for this episode was to break down why enterprises are overwhelmed by vulnerability data. Additionally, Walta lays out a strategic plan of action to help enterprises prioritise vulnerabilities proactively rather than reactively. The discussion builds on the previous episode, where Brinqa CSO Brad Hibbert and host Richard Stiennon , Chief Research Analyst at IT-Harvest, talked about how AI is helping attackers with faster scanning, smarter exploit chaining, and machine-speed intrusions. Walta continues this conversation with EM360Tech ’s Dua, focusing on prioritisation in exposure management strategies . He puts up a case noting AI will not rescue security teams from unorganisation unless the underlying data is ‘good’ and reliable. Takeaways Context is crucial for effective cybersecurity management. The chaos in cybersecurity is amplified by AI-driven vulnerabilities. Data quality is foundational for prioritisation and remediation. Patching faster is not always the best approach; understanding risk is key. Operational clarity can be achieved by unifying asset visibility. Prioritisation must be based on business context and asset sensitivity. AI can help but may also amplify confusion if data is poor. CISOs should focus on outcome metrics rather than activity metrics. Effective vulnerability management requires a clear understanding of ownership. The conversation around cybersecurity must evolve to address real risk reduction. Chapters 00:00 Navigating Cybersecurity Chaos 02:52 The Importance of Context in Cybersecurity 06:07 Bridging the Gap: From Vulnerability Detection to Remediation 09:09 Understanding Risk Over Speed 11:46 Enhancing Data Quality for Better Decision Making 14:57 Operational Clarity: Transforming Overload into Insight 18:05 Measuring Success Beyond Vulnerability Counts Visit brinqa.com for more information on how enterprises should prioritise vulnerabilities proactively. Vulnerability Management, Exposure Management, Cybersecurity Strategy, AI in Security, Risk Prioritisation, Brinqa, EM360Tech, The Security Strategist, Cyber Risk, Data Quality, CISO, Threat Exposure Management, Asset Visibility, IT Security, Risk Reduction, James Walta

August 7, 202623 min

Why CISOs Struggle to Explain Cyber Risk to the Board

Every CISO out there faces one key challenge: the challenge of getting the board to acknowledge cybersecurity as a top enterprise risk management priority. According to the ClearPoint Strategy Strategic Planning Report , only 51 per cent of active strategic and corporate projects maintain a steady Green status. The remaining 49 per cent fluctuate between Amber and Red, requiring varying levels of intervention. This goes to show that many investment decisions are reliant on red, amber and green dashboards and not on financial exposure. According to Mike Saxton , CRO at MyCiso, the issue relates to cyber reporting often lacking portability. “A director may be highly experienced and commercially sophisticated, but still struggle to compare risk posture between organisations because the underlying reporting models are inconsistent.” With AI also in the picture now, the speed and scale of attacks is rapidly rising; that gap is becoming harder to defend. This is why in the recent episode of The Security Strategist podcast , E360Tech’s host Shubhangi Dua, Tech Journalist and Podcast Producer, was joined by Asdrúbal Pichardo, CEO at Squalify, 3x SaaS CEO, Board Advisor, Start-Up Mentor, Non-Executive Director. This podcast breaks down how to actually turn technical risk into something the rest of the business can realistically manage, measure, and report on. Translating Cyber Risk for the Boardroom: A CISO’s Guide to Financial Quantification Pichardo says when it comes to cyber risk, it's time to avoid reporting based on qualitative metrics; instead, portray more quantitative metrics. This means really talking to the executives and the boards in the language of business “which is money.” "CISOs need to rely less on qualitative assessments. They need to translate the cyber risk into financial figures so the board will understand the implications of cyber." CISOs typically present cyber risk through technical metrics , maturity scores and vulnerability reports, but boardrooms tend to avoid making decisions based on technical language. This is why translating that cybersecurity technical jargon into metrics is essential for boardrooms. They think in terms of financial exposure, business resilience and return on investment (ROI). The CEO of Squalify explains why the future of cybersecurity leadership depends less on explaining threats and more on quantifying business impact. He puts up a case for enterprises requiring a common language that is comprehensible by both security teams and executives instead of relying on technical dashboard data. Leveraging AI Vulnerability Detection: The Strategic Advantage of Mythos Artificial intelligence (AI) has made it more complex from every corner. AI-driven cyber attacks are on the rise. On the other side, AI is being deployed by defenders to protect their platforms as well as to optimise the speed and effectiveness of AI tools and integrate it into their workflows. Ultimately, AI has, for better or worse, blurred the line between cybersecurity, governance and business continuity. To put into perspective, Dua asked Pichardo about Anthropic's Mythos model’s incredible vulnerabilities-spotting capabilities. He said that Mythos is causing a lot of dialogue in the industry right now, but the vulnerability-discovering capabilities had existed for years, and those tools went unnoticed. While industry individuals may be concerned about attackers taking advantage of AI tools like Mythos, enterprises should be able to access the same technology to identify and fix those weaknesses before attackers exploit them. However, geopolitical tensions and other economic disparities have made it hard for enterprises to access. The key idea is that defenders have an advantage because they know their own systems. He says, “The hacker doesn't have the knowledge, or the source code from your enterprise. You already have it, so enterprises need to get there with Mythos before the hacker comes to you with Mythos.” The issue he spotlights is that American companies have been given access to Mythos, but the US government has restricted access outside of the nation. “At the end it should it should it should get into the right hands because it's probably already in the wrong hands,” the CEO states. The conversation around Anthropic’s Mythos model depicts a shift in the enterprise tech and cybersecurity industry. While much of the discussion has focused on how attackers might exploit increasingly capable AI, Pichardo sees the greater opportunity for defenders. Also Read: Fraud Tops CEO Cyber Concerns as Ransomware Attacks Continue to Surge Converting Cyber Risk into Strategic Investment For boardrooms, the new question they must pose is whether enterprises are optimising AI quickly, efficiently, and, most of all, safely to minimise risks before adversaries get to it. The recent cyberattack by a rogue OpenAI AI model on Hugging Face was an eye-opener for all. In a worst-case scenario, imagine if the hackers’ AI agents began penetrating secure enterprise tech platforms at a rate that’s hard to fend off their strikes. AI has moved from being a technical capability to a strategic investment decision one that should be measured in business impact rather than technology adoption. “If you can demonstrate that the likelihood of experiencing a disruption because of AI is higher in numbers, that will change the minds of any boardroom. This applies to any industry, from public sector and banking, financial, manufacturing, defence, energy,” notes Pichardo. He added that at Squalify’s mother company, Munich Re, the world's largest cyber reinsurer ensures that AI’s impact on cyber risk is visible not only from a technical perspective but a business perspective as well. "It goes beyond tech or IT; it's processes, governance, business operations.” Ultimately, enterprises need to quantify cyber risk so they are better able to defend against the AI-driven threat landscape at any given time. Takeaways Cyber risk quantification is becoming a boardroom necessity AI is increasing attack velocity, not just sophistication Defensive AI can create a competitive advantage Cyber and AI risk are converging into enterprise risk Board AI literacy is becoming a strategic capability Chapters 00:00 Understanding Cyber Risk in Business 02:42 The Differences in Cyber Risk Management: US vs Europe 05:42 The Evolution of Risk Management with AI 08:46 Quantifying Cyber Risk: The Role of Squalify 11:34 Real-World Applications: Onboarding Clients at Squalify 14:53 The Importance of Financial Metrics in Cybersecurity 17:38 AI's Impact on Cybersecurity and Business Operations 20:20 The Future of AI in Cyber Risk Management 23:32 Key Takeaways for CISOs and Board Members Watch the full episode of The Security Strategist Podcast to hear Asdrúbal Pichardo discuss cyber risk quantification, AI governance, boardroom communication and what enterprise leaders should prioritise next.

August 3, 202626 min

Can Runtime Security Keep Autonomous AI Under Control?

The one key thing that could aid enterprise success in the agentic AI cybersecurity space today is its ability to understand agents' intent. It’s easy to state but hard to convert into an actionable security strategy. This is why in the recent episode of The Security Strategist podcast , host John Tolbert is joined by Dror Zelber, VP Product Marketing at Radware and Dhanesh Ramachandran, Product Marketing Manager at Radware. They got together to discuss the emerging challenges of agentic AI security and how to tackle it realistically. More specifically, they break down what it actually means to secure AI agents , whether they are interacting with internet-facing applications on behalf of users or operating within enterprise environments, emphasising the importance of behavioural monitoring and visibility in managing AI agent interactions. The conversation further spotlighted the need for enterprises to establish trust and governance frameworks for AI agents while prioritising security budgets and strategies. Also Watch: Unmasking the Invisible Threat: Defend Your APIs Before Attackers Do Takeaways Agentic AI introduces new security challenges compared to traditional applications. The attack surface for AI agents is significantly broader and easier to exploit. Behavioural monitoring is crucial for understanding AI agent actions and intent. Enterprises must prioritise visibility into AI agent activity. Trust and identity verification are key challenges in the agentic era. CISOs should allocate budgets for AI security solutions early in the deployment process. Strict policies and governance are necessary for deploying AI agents. Monitoring and auditing are essential to prevent unauthorised actions by agents. Enterprises need to distinguish between beneficial and risky AI agent behaviour. The future of security lies in enabling beneficial AI interactions while maintaining safeguards. Chapters 00:00 Introduction to Agentic AI Security 01:25 Emerging Security Challenges with Agentic AI 05:37 Traditional Security Measures vs. Agentic AI 10:44 Current Activity of AI Agents in Enterprises 14:29 Distinguishing Beneficial vs. Risky AI Agent Activity 17:13 Establishing Agent Identity and Authority 23:18 Priorities for CISOs in the Agentic Era Watch the full episode for complete insights on autonomous AI agents, the future of AI cybersecurity and how enterprises can effectively manage risky AI agent behaviour while still taking advantage of the agentic technology. For further information, visit radware.com .

July 30, 202621 min

How Do You Govern AI Agents in Real Time?

Autonomous AI agents are becoming a part of most enterprise workflows today. But how are enterprises protecting their platforms from rogue agents? For instance, the recent attack on Hugging Face was discovered to be carried out by an OpenAI rogue AI model that escaped testing from a secure environment. To answer how best enterprises can protect themselves from unique, unpredictable attacks by upcoming technologies such as rogue AI agents, Sagi Rodin, CEO and Co-Founder of Agen.co by Frontegg , joins host Alejandro Leal, Lead Analyst at Kuppinger Cole Analysts firm, on an episode of The Security Strategist podcast . They talk about the constantly changing nature of AI agent governance , identity management, and security in enterprise environments. They further explore how autonomous AI agents challenge traditional security models and what strategies enterprises need to adopt to stay secure. What is Agen.co? When asked about the dynamics of AI agents and how they individually carry risk, the focus seems to be moving to governance of specific actions in real-time. Instead of relying on the agent's initial authentication status, agents are going beyond identity to “per-action” governance. Rodin puts it into context: “We [Frontegg] released Agen.co , a product that governs runtime agentic activity. We take an identity-first approach by connecting to identity providers, agent repositories, and user directories. In addition to managing users, we now maintain a registry of AI agents.” The goal is to connect all those principles and manage unique identities in an enterprise. These include conventional automated machines, human users, user-controlled AI agents, autonomous AI agents that run on their own post-deployment, as well as malicious bots that need to be identified quickly and blocked. Rodin said that Frontegg is bringing all of those identities together under a single governance model. How to Stop AI Agent-Driven Malicious Actions in Real-Time? As an identity-native platform that connects to the IDP, the agent repository and user repositories, Agen.co by Frontegg has become a registry for agents. “The industry has a broken mental model today,” Rodin tells Leal. When asked why, he said that while identity tools pose the question of identity, they may not ask the purpose of entry. That means an agent with valid credentials passes every identity check. It’s called “role-based access”, originally designed for humans. An agent conducts thousands of actions per day, but each of those actions carries a risk. This is why individual governance of each action by those AI agents is critical. This is why Agen .co provides a very quick verdict in under thirty milliseconds to avoid obstructing workflows while stopping malicious actions in real-time. “We must operate on the runtime side because an agent can bypass static gates established during login or registration,” Rodin says. “We need to be present the moment an agent accesses organisational data, attempts a prompt, or executes a potentially damaging command, like 'rm -rf' on an endpoint.” Simply granting an agent a ticket at registration is insufficient to keep up with the dynamic and fast-paced scale of modern agent operations. While enterprises cannot be obstacles in the path of automation, they can use a platform to operate extremely quickly and efficiently to stop threats from occurring. As AI agents adapt with more autonomous capabilities and proliferate across departments in an enterprise, be it engineering, finance or marketing, these AI agents act without clear ownership. Rodin says there shouldn’t be any agents running without a named human owner. He says that with governance, enterprises must take accountability. “Every single action needs to be traced back to a person. AI agents don't get a pass on ownership.” “When the regulator, the board, or the department owner asks who was responsible for this action, at the end of the day you need a name, so this is a core principle we impose for our AI native activity,” he added. Takeaways Identity verifies who; runtime governance verifies every action. Identity proves who—runtime proves what's safe. Every AI agent action needs its own security decision. Static IAM can't govern autonomous AI behaviour. Every enterprise AI agent needs a named owner. Agent governance is becoming a runtime security challenge. Chapters 00:00 Introduction to AI Agents and Security Challenges 06:23 The Shift from Identity to Behaviour in Security 10:09 The Importance of Continuous Validation 16:09 Accountability in the Age of Autonomous Agents 20:19 Key Takeaways for Security Leaders

July 20, 202626 min

Is Your SOC Below the AI Poverty Line?

The future of inequality in cybersecurity has been coming to light since the beginning of the AI evolution. Greg Notch, the Chief Technology Officer (CTO) at Expel , recently predicted that the “AI poverty line” is projected to be more severe than the traditional security line. "The AI poverty line will be even crazier in some ways because you will either have the ability to understand and wield AI properly or you will not,” he stated. “That gulf is going to be interesting." In the recent episode of The Security Strategist podcast, host Brad LaPorte, Gartner Veteran and Advisor at Lionfish Tech Advisors , sat down with Greg Notch, CTO at Expel , to address the impact of AI on security operations. They discuss the AI poverty line and lay out a plan for how enterprises can adapt to the rapid pace of change introduced by AI. They also explore the balance between automation and human oversight, trust versus impact, and future trends in AI-driven security . What is the AI Poverty Line? According to Notch, the AI poverty line is the growing divide between security capabilities and one’s ability to effectively optimise AI. While a security poverty line has existed for a long time, an AI version will begin appearing. It could be more complex and niche. Security teams may face difficulties defining their roles and responsibilities, and only those who can wield AI skillfully and effectively. For instance, he alludes to an example of a large tech enterprise such as CrowdStrike, Palo Alto or even Microsoft. As a large enterprise employing AI-skilled professionals, “you would want to leverage as much of that as you can because your head count is is is limited. If you can't hire enough people to manage the operation, you may have to outsource that” to an AI-skilled professional. However, with attackers' increasing sophistication, the enterprise should be capable of equally able to detect and responding to vulnerabilities. This is why automation alone is not enough. A resilient cybersecurity strategy requires a team equipped to use AI-backed security tools to actively monitor, manage, and respond to threats, using automation. This should help human decisions rather than replace them with a bot. Also Read: What Is AI Value Management and Why Are Enterprises Suddenly Prioritising It? Where Does AI Belong in the Security Operations Centre (SOC)? AI and automation ultimately exist to aid Security Operations Centre (SOC) teams. Its capabilities allow assistance to human analysts, acting autonomously and contribute to how enterprises can effectively optimise AI to boost their security posture. Both LaPorte and Notch agree that the role of AI in SOC is collaborative. It’s a hybrid model where humans maintain control. LaPorte takes the example of a motorcycle, stating it’s like a motorcycle “with a sidecar.” “The human is riding the motorcycle, but the AI is along for the ride. It adds additional capability, additional storage and functionality. “It's a new world, but it's a hybrid world." While Notch rhetorically questions whether a SOC is needed. He asks the audience to imagine a scenario without SOC analysts. It’s not possible even if it’s intermediated by AI. “I believe we’ll have more humans in the loop.” Why Automation is Essential? As attackers become more sophisticated in their threat intelligence strategies, enterprises too have to keep up. That means they too need to leverage automation capabilities of AI . Some easy actions that can be automated without human intervention are to block known malicious IPs or contain compromised devices. This becomes extremely crucial during high-stakes situations where time is of the essence. Automation is essential to address two primary business and operational challenges – mitigating the risk of active attackers and resolving the inefficiency caused by alert fatigue. Notch argues that the risk of failing to stop an active attack outweighs the risks associated with introducing automation into the environment. "All security leadership decisions should be grounded in risk.” Security leadership should think about “what is the risk of not doing a particular task versus the risk of doing it? For instance, automation.” “We're accepting different risks, but we believe the risk of not being able to stop an active attacker in our environment is worth that. That's the trade-off you have to make,” Notch tells LaPorte. Where Expel comes in? Notch describes Expel's approach as a solution for security operations—specifically pertinent to auto-remediation before AI was a thing. Expel launched an auto-remediation feature about seven or eight years ago based on heuristics. It wasn't driven by AI back then. It was unclear whether Expel’s customers would adopt it, as trust had to be established before adoption. Notch explains that's because customers had to be comfortable letting a third-party security provider automatically take actions. For instance, letting the party isolate infected laptops, shutting down compromised cloud systems, stopping malicious programs, and responding to attacks without waiting for someone from the company to approve it. Expel discovered that customers were willing to trust this automation because it could stop attacks much faster than waiting for a person within the company to act. Today, many enterprises would rather let the system stop or contain an attack immediately and investigate what happened afterwards. By understanding where AI can effectively assist or act autonomously, enterprises can enhance their cybersecurity posture while managing risks. The key is to develop a thoughtful approach that balances automation with human expertise, ensuring that AI serves as a powerful ally in the fight against cyber threats. Watch the podcast on em360tech.com for a deeper understanding and expert thought leadership insights. For further information, visit expel.com . Takeaways AI is transforming the speed and nature of cyber attacks. Automation in security must be balanced with human oversight. Trust is crucial when implementing AI in security operations. AI can enhance detection but requires careful implementation. The future of SOCs will involve more human-AI collaboration. Organisations must adapt to the evolving threat landscape. False positives remain a significant challenge in SOCs. AI can help streamline operations but is not a silver bullet. Security decisions should be grounded in risk management. The hype around AI in cybersecurity often oversells its capabilities. Chapters 00:00 Introduction to AI in Cybersecurity 03:03 The Speed of AI-Driven Attacks 06:00 Automation and Trust in Security Operations 09:01 AI's Role: Acting Alone vs. Assisting 12:00 The Future of AI in Security Operations 14:46 The Hype vs. Reality of AI in SOCs 17:59 Navigating the AI Landscape in Cybersecurity 20:51 Conclusion and Key Takeaways Cybersecurity, AI in Cybersecurity, SOC, Security Operations Centre, Expel, Greg Notch, Brad LaPorte, AI Poverty Line, Cyber Defence, Automated Security, Threat Intelligence, Security Leadership, Risk Management, Human-in-the-loop AI, Enterprise Cyber Strategy #AIPovertyLine #Cybersecurity #SOC #AISecurity #TheSecurityStrategist #InfoSec #Expel #EnterpriseSecurity

July 17, 202620 min

Shadow AI to Shadow Agents: What's Actually Changed in 2026?

Key frontier models are now capable of spotting vulnerabilities that no one thought even existed. They are finding software vulnerabilities at scale without any prompting, presenting both opportunities and challenges for security teams. For instance, recently, the Associated Press reported on the Anthropic Mythos model , spotting vulnerabilities in highly sensitive U.S. government computer systems during a testing exercise. Security researchers describe this ability as dual-use. The Mythos model, part of Anthropic’s project Glasswing , partnered with national intelligence agencies to find and fix vulnerabilities in critical systems before attackers get to them, as per AP . The frontier AI model “broke into almost all of our classified systems, not in weeks, but in hours,” Joshua Rudd, National Security Agency (NSA) chief, seems to have informed Senator Mark Warner of Virginia. This kind of scanning capability helps defenders patch vulnerabilities faster, and also provides attackers with a more effective tool. As our guest noted in the recent The Security Strategist podcast episode, it's "almost like a new weapon." Both sides of the security battle believe they can leverage it to their advantage. This tension sets the stage for a conversation that has been growing in enterprise security circles throughout the year – Shadow AI. In this episode of The Security Strategist podcast , host Shubhangi Dua, Podcast Producer and B2B Tech Journalist at EM360Tech , sat down with Guru Sethupathy, Head of AI Governance at Optro , to break down Shadow AI and its looming threats in 2026 and beyond. Over the last couple of years, Shadow AI has mainly involved employees entering sensitive data into ChatGPT while IT teams rushed to respond. This summer, the narrative has changed. The EU AI Act's regulatory clock is ticking. Meanwhile, Shadow AI is transforming into autonomous "shadow agents" that operate without waiting for human approval at every step. Sethupathy believes many enterprises are about to realise they can't comply with regulations for systems they don’t even know they're using. Rogue Chatbots to Rogue Agents Shadow AI isn’t a new concept, but Sethupathy challenged the notion that enterprises have been aware of it for years. "Even into 2024, Shadow AI was not the main priority for enterprises," he said. It only gained traction heading into 2025, and "it has dramatically increased in 2026." Two factors are driving this shift, he explained. The first is the " democratisation of AI ." Any employee within an enterprise can now access and interact with AI tools directly. The second factor is the countless ways AI can enter a company. AI can come through third-party vendor tools, web browsers, internal development, or no-code and low-code platforms. When you combine these entry points with the number of employees interacting with them, he noted, "you can see why there’s so much AI in an organisation that isn’t being tracked." However, the real change, Sethupathy argued, isn’t from chatbots but from what followed. "With chatbots, companies could exert control," he said, highlighting the relative ease of restricting the tools staff could use and controlling how data flowed through them. AI Agents present a different challenge entirely: "It’s not just about data leakage. It’s not just about data security. These agents are taking actions, making decisions, and acting." This, he said, poses "a level of risk that is much higher." Why is Governance Failing Against AI? If agentic AI is the new area of risk , why hasn’t governance caught up? Sethupathy attributes this to tempo. "Governance in the past has typically been a point-in-time exercise," he said. But autonomous agents operate constantly. They learn consistently and take actions, access tools, and data around the clock. "Imagine you’re driving, and your car only informs you of your speed every half hour. That would be pointless,” the Head of AI explained. The same reasoning applies to agents, he argued. With their continuous work, oversight needs to be continuous as well. This creates two major problems for organisations: a process issue (rebuilding governance frameworks around ongoing review) and a technology issue. As Sethupathy plainly stated, "humans cannot do continuous monitoring. We have to sleep." AI needs to monitor other AIs. Why the EU AI Act to Shadow AI? The compliance deadline for high-risk systems under the EU AI Act has not simply been pushed to August 2026 and left there. Sethupathy clarified that the European Commission revised the timeline recently, dividing it into two separate tracks: The first is transparency and watermarking obligations; the rules requiring enterprises to disclose their AI usage have actually been moved forward to December 2026. Secondly, high-risk system obligations involving the detailed governance, risk assessment, and audit requirements for high-risk AI — have been pushed back to December 2027. "There have been updates on the EU Act," Sethupathy told Dua. The rules "around transparency of AI use and watermarking have actually been moved forward to December of this year," while the high-risk governance requirements have "been pushed back to the latter half of next year, particularly December 2027." Alluding to the challenge of shadow AI challenge, he added that enterprises can't run a compliance process for high-risk systems they haven't identified. "You don’t know what high-risk systems you have if you have shadow AI," he said, adding that he doesn’t think most enterprises could have solved that discovery issue by the original August 2026 deadline. Sethupathy believes the extended timeline is a positive development, as long as companies take advantage of it. "I think it’s actually good that the EU has given folks more time. But they need to get started." Ultimately, he asks CISOs to "think of governance as your insurance against that investment," referring to the billions of enterprises that are investing in AI. Without buy-in from the top, Sethupathy warned, "governance will become just a side task. Eventually, something will break." Key Takeaways Shadow AI is becoming a significant concern for enterprises. The rise of AI democratisation has increased risk exposure. Governance must be continuous and real-time to be effective. The EU AI Act's compliance deadlines are crucial for enterprises. Enterprises need to identify high-risk AI systems to comply with regulations. Technology is essential for the continuous monitoring of AI systems. CISOs must take ownership of AI governance within enterprises. Training employees on AI risks is vital for effective governance. Investing in governance is an insurance against AI investments. Top-down support from leadership is necessary for successful governance. Chapters 00:00 Introduction to Shadow AI and Its Implications 03:12 Understanding the Rise of Shadow AI 05:52 Governance Challenges in the Age of AI 09:00 The EU AI Act and Its Impact on Enterprises 12:09 Technological Solutions for Managing Shadow AI 14:50 The Dual Nature of AI in Security 17:34 Strategies for Effective AI Governance 21:06 The Role of the C-Suite in AI Governance For more on Optro’s approach to continuous AI governance, visit optro.ai . #ShadowAI #ShadowAgents #AIGovernance #AgenticAI #Cybersecurity #EUAIAct #EnterpriseTech #CISO #RiskManagement #DataSecurity #TheSecurityStrategist #EM360Tech #Optro

Is this your show?

Claim this listing to keep it up to date, reach guests who want to pitch you, and manage bookings with Guestify.

Claim this listing

More Business podcasts