Find partners
On Security (a podcast powered by tact.)

On Security (a podcast powered by tact.)

Hosted by Tact IT

BusinessInterviews guests

Episodes

86

Latest episode

Aug 2026

Language

EN

About the show

Where cyber security founders, investors, sellers and operators talk. One guest per episode, one journey. How they built it, backed it or sold it, the mistakes they made and the advice they'd give anyone on the same path. Hosted by Jack Brandwood. New episodes weekly. Watch on YouTube: https://www.youtube.com/@startandscale Follow on LinkedIn: https://www.linkedin.com/company/start-and-scale/posts/?feedView=all

Listen to episodes

60 recent
August 28, 202656 min

Howard Ting (CEO, Opal Security): Why AI Agents Break Identity | S6 E1

Ask any attacker the best way into a company: compromise an identity. 26 years into cybersecurity, Howard Ting says the problems he worked on at RSA in 2000 are still unsolved. This episode is about why, and what AI agents are about to do to the identity stack. Covered in this episode: Why standing permissions are still the easiest way into an organisation, and why nobody revokes access once the need expires Rubber stamping: what actually happens when a manager faces 100 access requests every morning Why agent access decisions will run a million to one against human capacity, and why AI narrowing the funnel is the only way through How Opal's Paladin agent reads tickets and Slack context to cut the review volume going to humans by 95 to 99 percent How Howard picks companies (80 percent of the decision is the market) and his three S's framework for career growth: scale, space, scope About Howard: • CEO of Opal Security, the Greylock-backed access governance company • Started in identity at RSA in 2000, launched Microsoft's identity federation product at Bill Gates' last RSA keynote • Joined Palo Alto Networks at roughly employee 60 and Nutanix at roughly employee 40. Both grew from a couple of million in revenue to a billion, with an IPO at each • Five years as CEO of Cyberhaven, worth $1B when he left • Now back in identity to work on what he calls unfinished business 🔗 Howard Ting: https://www.linkedin.com/in/howardting/ 🏢 Opal Security: https://www.linkedin.com/company/opalsecurity/ 👤 Jack Brandwood: https://lnkd.in/dFMyDUEN 🎵 Spotify: https://lnkd.in/eij7j2m 📲 On Security LinkedIn: https://www.linkedin.com/company/onsecuritypodcast/

August 21, 202627 min

SECURE& | “4,000 Malware Families Soon 15,000” with Danny Quist | S5 Ep13

AI has made malware easier, cheaper and faster to develop. 🤖 But is it actually making malware better — or just creating more of it ? On the latest Secure & Scale Podcast, Jack Brandwood sits down with Danny Quist, CTO at PolySwarm and a malware reverse engineer with 20 years of experience, to explore how AI is changing the threat landscape. 🎙️ They discuss: • AI and the democratisation of malware • The future of malware detection • How AI could transform analysis • Why human judgement still matters “The human in the loop is always gonna be there.” 🔗 Danny's LinkedIn: https://lnkd.in/edKA-rRk 🏢 PolySwarm: https://lnkd.in/egzPT_xP 👤 Jack Brandwood: https://lnkd.in/dFMyDUEN 🎵 Spotify: https://lnkd.in/eij7j2m ▶️ YouTube: https://lnkd.in/evEFhtb2

August 19, 202634 min

SECURE& | “Guardrails Mean You Already Crashed” with Ian Amit | S5 Ep12

AI is getting faster. But faster doesn't always mean better. 🎙️In the latest Secure & Scale Podcast, we sit down with Ian Amit, Founder of Gomboc, to explore where AI delivers in cybersecurity, and where it falls short. 🤖The key issue? Precision.Generative AI is great for creative tasks. But when you're fixing cloud infrastructure, “almost correct” isn't good enough.Inside the conversation:• Why deterministic AI matters for security engineering• How cloud misconfigurations create massive attack surfaces• Where AI agents fit into cloud security• Why policy as code needs to become proactive• How attackers are using AI to move faster ⚡One of the biggest takeaways:“For an engineer like myself, what I hear is it's incorrect.”Attackers only need to be right once. Defenders need to be right every time. 🛡️If you're a cybersecurity or cloud security leader, this is one worth watching.🔗 Ian's LinkedIn: https://www.linkedin.com/in/iamit/🏢 Gomboc: https://www.linkedin.com/company/gomboc-ai/👤 Jack Brandwood: https://lnkd.in/dFMyDUEN🎵 Spotify: https://lnkd.in/eij7j2m▶️ YouTube: https://lnkd.in/evEFhtb2

August 17, 202643 min

SECURE& | “AI Is a JET - You’re Driving It” with Michael Brown | S5 Ep11

AI isn't going to replace everyone in cybersecurity. But it is going to change which work humans do. 🤖🔐🎙️ The latest episode of the Secure & Scale Podcast features Michael Brown, who has worked for companies like Trail of Bits, US Army and Georgia Tech Research Institute. Michael has spent years working at the intersection of AI, machine learning and software security. In the conversation, he breaks down where AI genuinely belongs in security, and where we're forcing it into problems it was never designed to solve. 🧠💻 We get into: • Why AI and conventional security techniques work best together• Why AI-generated code becomes riskier as complexity increases• How AI agents should be secured and permissioned • Why shadow AI is becoming a growing security problem • Which cybersecurity roles are likely to remain human • Where AI could create the next major software supply chain risk 💡 One of the biggest takeaways:"AI is not going to outperform writing an algorithm for something." The real skill is knowing when AI is actually the right tool. 🎯 If you're working in cybersecurity, software engineering or AI, this is one worth watching. 🚀 Michael's LinkedIn: https://www.linkedin.com/in/michael-brown-47949515/ Jack Brandwood: https://lnkd.in/dFMyDUEN Spotify: https://lnkd.in/eij7j2m YouTube: https://lnkd.in/evEFhtb2

August 12, 202623 min

SECURE& | “Your Brand Is the Attack Surface” with David Promisel | S5 Ep10

As AI makes impersonation easier than ever, how do organisations build and maintain trust online? In this episode of the Secure & Scale Podcast, Jack Brandwood sits down with David Promisel, Founding Engineer at Outtake, to explore why digital trust has become one of cybersecurity's biggest challenges. Inside the conversation: • Why automation should always follow trust • The growing threat of AI-powered impersonation • How brands can measure and protect digital trust • Why evidence matters more than assumptions • What the future of identity and trust looks like If you're building, securing, or scaling digital products, this episode offers a practical perspective on one of cybersecurity's fastest-growing challenges. David Promisel's LinkedIn: https://www.linkedin.com/in/david-promisel/ Outtake: https://www.linkedin.com/company/outtakeai/ Jack Brandwood: https://lnkd.in/dFMyDUEN Spotify: https://lnkd.in/eij7j2m YouTube: https://lnkd.in/evEFhtb2

August 11, 202625 min

SECURE& | “We Don't Know What AI Costs Yet” with Sonali Shah | S5 Ep9

AI won't replace pentesters.But it might replace average ones. 🎙️The latest Secure & Scale Podcast features Sonali Shah, CEO of Cobalt, on the future of offensive security.AI will automate more of the work. But human creativity, business context and judgement still matter.Inside the conversation:• Why annual pentesting isn't enough anymore• What continuous pentesting actually means• Where AI could cover 75% of vulnerabilities• Why humans still find complex business logic flaws• How AI agents are expanding the attack surfaceOne of the biggest takeaways:"AI is absolutely getting better, but the human is still very relevant."You don't need more pentesters.You need the best ones.🔗 Sonali Shah's LinkedIn: https://www.linkedin.com/in/sonalinshah/🏢 Cobalt LinkedIn: https://www.linkedin.com/company/cobalt-io/👤 Jack Brandwood: https://lnkd.in/dFMyDUEN🎵 Spotify: https://lnkd.in/eij7j2m▶️ YouTube: https://lnkd.in/e_ZYPusr

August 7, 202626 min

SECURE& | “The Internets Biggest Point of Failure” with Tod Beardsley | S5 Ep8

From teenage hacker to shaping the future of vulnerability management. 🎙️ In this episode of the Secure & Scale Podcast , Jack Brandwood sits down with Tod Beardsley, Vice President of Security Research at runZero, to explore the evolution of vulnerability management and the challenges facing defenders today. Tod shares his journey from hacking as a teenager to helping shape the systems the industry relies on, including the future of CVE, AI-driven security research, and why vulnerability standards matter. In this episode, we dive into: • Why CVE became the industry's shared language • The risk of vulnerability databases fragmenting • How AI is changing security research • The future of vulnerability disclosure • Why attackers ignore vulnerability identifiers while defenders rely on them One of the biggest takeaways: "Attackers give no spits about which vulnerability identifier it is. As long as they get shells, they're good." If you're a security leader, researcher, or vulnerability management professional, this episode is worth watching. Tod Beardsley's LinkedIn: https://lnkd.in/ei6Db5aA Jack Brandwood: https://lnkd.in/dFMyDUEN runZero: https://lnkd.in/ev92cT-b Spotify: https://lnkd.in/eij7j2m YouTube: https://lnkd.in/evEFhtb2

July 31, 202614 min

SECURE& | “Nobody Has A Spare Factory” with Rob King | S5 Ep7

OT systems can be 25 years old and still be running critical infrastructure. ⚙️🔒 In this episode of the Secure & Scale Podcast, Jack Brandwood sits down with Rob King, Director of Applied Security Research at runZero, to explore the challenge of securing the systems that keep the world moving. Rob shares why OT devices often stay in place for decades, the risks of unpatched technology, how IT and OT teams are learning to work together, and why network segmentation is critical for protecting industrial environments. One of the biggest takeaways: "Nobody has a spare factory. If the factory goes down, it's millions of dollars an hour." If you're working in cybersecurity, OT, or critical infrastructure, this is one worth watching. 🎙️ 🔗 Rob King's LinkedIn: https://lnkd.in/evDXV-Cj 🏢 runZero: https://lnkd.in/ev92cT-b 👤 Jack Brandwood: https://lnkd.in/dFMyDUEN 🎵 Spotify: https://lnkd.in/eij7j2m ▶️ YouTube: https://lnkd.in/e_ZYPusr

July 10, 202631 min

SECURE& | “AI Won’t Take Your Job… It Will Change It” with Jake Bernardes | S5 Ep6

AI isn't the problem. The foundations are.In the latest Secure & Scale Podcast episode, Jack Brandwood sits down with Jake Bernardes, CISO at Anecdotes, to unpack why the future of security isn't about adding AI everywhere.It's about understanding the problems first.From GRC automation to AI governance, Jake shares why companies need to fix the foundations before they can expect AI to deliver real value.Inside the conversation:• Why AI is becoming the wrong question to ask• How GRC is moving from manual to automated workflows• Why poor inputs create poor AI outputs• How to build trust through verification, not assumptions• Why security professionals need to become orchestrators• How AI agents can be governed safelyOne of the biggest takeaways:"You can't automate something which doesn't work. It's like trying to build a house really fast, but not knowing how to build a house to begin with."If you're a cybersecurity leader navigating the future of AI, this is one worth watching.🔗 Jake Bernardes' LinkedIn: https://lnkd.in/eR9QA2A5🏢 Anecdotes: https://lnkd.in/ei3iFxpA👤 Jack Brandwood: https://lnkd.in/dFMyDUEN🎵 Spotify: https://lnkd.in/eij7j2m▶️ YouTube: https://lnkd.in/e_ZYPusr

June 19, 202633 min

SECURE& | “75% of Security Reviews Aren’t Code” with Emily Choi-Greene | S5 Ep5

Security teams don’t review software. They review systems. In this Secure & Scale Podcast episode, we sit down with Emily Choi-Greene from Clearly AI to unpack what that actually means in practice, and why most security tooling is still only solving a slice of the problem 🎙️ Emily breaks down why 75% of modern security reviews aren’t code at all, and why system-level context is where real risk lives. We get into: • Why AI is not the perfect solution to every problem 🤖 • Why security teams review systems, not just code 🧠 • What breaks when teams only focus on code vulnerabilities • Raising the floor with baseline security controls 📈 • Where humans are still essential in security decisions 👥 • Why security has to move at the speed of shipping software ⚡ One of the biggest takeaways: Security isn’t a checklist of tools. It’s understanding how systems interact, where data flows, and where those connections quietly break. If you’re building in security or shipping AI-native products, this is a must-listen conversation 🎧 🔗 Emily Choi-Greene’s LinkedIn: https://lnkd.in/eTMEVvVj 🏢 Clearly AI: https://lnkd.in/e9MV6jdG 👤 Jack Brandwood: https://lnkd.in/dFMyDUEN 🎵 Spotify: https://lnkd.in/eij7j2m ▶️ YouTube: https://lnkd.in/evEFhtb2

Is this your show?

Claim this listing to keep it up to date, reach guests who want to pitch you, and manage bookings with Guestify.

Claim this listing

More Business podcasts