495 episodes
Cyber Resilience with Cohesity, When to use AI for Writing, and the News - Rob Sadowski - ESW #477
2026/09/21 | 1h 37 mins.Interview with Rob Sadowsky from Cohesity
Global Cyber Resilience Report: Cyber Recovery Plans Weren't Designed for this Moment
Cyber recovery plans weren't designed for this moment. Most were built around assumptions that made sense when they were written: incidents could be understood, dependencies mapped, recovery could follow a predictable sequence, and decision-makers would have enough information to act.
In practice, major cyber incidents unravel those assumptions. AI and autonomous agents are creating new paths to compromise, while cloud and SaaS expansion increases the systems, services, and dependencies involved in recovery. Vulnerabilities are discovered and weaponized faster than ever, and AI is accelerating that cycle. As incidents unfold, scope expands, dependencies appear only when they break, and recovery plans no longer match reality.
With assumptions under greater strain, confidence is beginning to erode. This year, the percentage of survey respondents reporting complete confidence in their cyber resilience strategy fell.
To understand how recovery unfolds today, Cohesity commissioned Vanson Bourne to survey 3,200 IT and security decision-makers at organizations with 1,000 or more employees across 11 countries.
This report examines where recovery becomes more difficult than expected, the obstacles organizations encounter, how they define and test a Minimum Viable Company (MVC), and how AI is reshaping cyber threats and cyber resilience.
https://www.cohesity.com/dm/global-cyber-resilience-report/
This segment is sponsored by Cohesity. Visit https://securityweekly.com/cohesity to learn more about them!
Topic: When should we use AI for writing and when should we avoid it?
I've had an essay in draft form for a month now, trying to get my feelings across on why AI writing drives me so crazy. I struggled to put it into words.
Fortunately, Charity Majors figured out how to put it into words and I think she nailed not just how I feel about AI, but the reasons why I feel so strongly about it. She uses a scale to help explain this, with "personal" at one end and "functional" at the other.
https://charity.wtf/p/confessions-of-an-unrepentant-slop
When I ask AI to create a company profile for me, 10 minutes before I meet with them, I don't need poetry - just facts. But when I read something that is supposedly someone's opinions and analysis on a topic, and it's clearly 100% AI-generated, I angrily dismiss it.
I love that this writeup isn't just an "I hate slop" rant - it actually quantifies why a personal touch matters and how to gauge when it is necessary and when outsourcing the task to AI is totally fine.
In both cases, Charity notes that quality matters. My most recent complaints come from cases where things are not only clearly written by AI, but where quality went out the window and they're unrecognizable as a human-readable language.
And yes, I brought an example: https://dispatch.cybersecurityhq.com/p/escalation-voided-on-construct-failure-timing-condition-placed-under-review
Weekly Enterprise News
Finally, in the enterprise security news,
We check the vibes, funding, and acquisitions
Tenable now has Mythos built-in???
We check in on how vulnerability remediation is going
Microsoft is creating a code of conduct for AI
OpenAI just got called to the principal's office
Booz Allen created new cybersecurity AI benchmarks
50% of CISOs see Mythos as a sign to resign???
Ayman read the latest Anthropic AI misuse report
MIT explains the 12 possible AI outcomes (very ominous)
a 9-year old decided to promote his YouTube account… with his dad's corporate card
All that and more, on this episode of Enterprise Security Weekly.
Visit https://www.securityweekly.com/esw for all the latest episodes!
Show Notes: https://securityweekly.com/esw-477Safely exploiting vulnerabilities at scale, TVs attack privacy, and the news. - Snehal Antani - ESW #476
2026/09/14 | 1h 40 mins.Interview with Snehal Antani
Snehal Antani, CEO and co-founder of Horizon3 joins us to talk about how automated validation can help with exposure management. As vulnerability counts spike, security teams are looking for a way to prioritize. Automated penetration testing offers a way to quickly separate exploitable vulnerabilities from the rest.
This segment is sponsored by Horizon3. Visit https://securityweekly.com/horizon3 to learn more about them!
Topic Segment - SmartTVs and Privacy
For this week's topic segment, we explore privacy and TVs. LG has been in the news for allegedly collecting data from its customers, but the facts are unclear.
We share our recent experiences and dive into some of the primary concerns and theories about what's going on here.
If you want to opt out of some of your TV's data collection, Consumer Reports has a collection of instructions for a variety of TV platforms.
Weekly Enterprise News
Finally, in the enterprise security news,
We check the vibes
We check finding and acquisitions
Nightmare Eclipse or Good Night of Sleep Eclipse?
Update on Anthropic's Glasswing project
How long would it take for a mobile phone worm to spread?
Don't expose SSH to the public Internet
Massive amounts of cryptocurrency continue to get stolen
Did you actually read your third party's SOC 2?
Your boss may be reading your AI chat history
All that and more, on this episode of Enterprise Security Weekly.
Visit https://www.securityweekly.com/esw for all the latest episodes!
Show Notes: https://securityweekly.com/esw-476Shadow AI Epidemic: Uncovering Agents on the Endpoint, British Library Breach, & News - Amit Assaraf - ESW #475
2026/09/07 | 1h 45 mins.Interview - Amit Assaraf
As employees rapidly adopt local AI models, autonomous agents, and browser extensions to boost productivity, enterprise endpoints are quietly accumulating unchecked security risks. This episode explores how traditional EDR solutions miss non-binary software, leaving critical blind spots for prompt injection and data exfiltration. Discover how Cortex Agentic Endpoint Security (AES) uses LLM-based classifiers and an AI powered risk engine to surface shadow AI and protect the modern workspace without stalling innovation.
This segment is sponsored by Palo Alto Networks. Visit https://securityweekly.com/paloalto to learn more about them!
Topic - The British Library Cyber-Attack
For this week's topic segment, we're discussing the British Library cyber-attack.
In October 2023, the British Library, one of the largest libraries in the world, was breached by the Rhysida ransomware group. The attack encrypted systems across the organization, led to over 500,000 files being leaked, and set off a recovery effort that consumed a significant portion of the Library's £17.5 million cash reserves. With no clear end date, this is a story of what could happen when all of an organization's tech debt comes due at once.
Resources
https://www.defendersinitiative.com/p/breach-lessons-the-2023-british-library
The Weekly Enterprise News
Finally, in the enterprise security news,
We check the vibes
the funding
the acquisitions
and the closures
is the vulnpocalypse real, or not?
TeamPCP finds out why being perpetually online isn't great if you're doing cybercrimes
millions of IDs get leaked online
What's the bigger story: Huggingface and NVIDIA or Microduck?
Dyson enters a new product category. Try to guess what it is without cheating and looking it up before the end of the episode!
All that and more, on this episode of Enterprise Security Weekly.
Visit https://www.securityweekly.com/esw for all the latest episodes!
Show Notes: https://securityweekly.com/esw-475Life as a CISO in Hollywood: Keeping New Films Leak-Free & 4 Black Hat Interviews - Dan Meacham, Ellen Boehm, Ronan Murphy, Frank Vukovits, John Hultquist - ESW #474
2026/08/31 | 1h 36 mins.Interview with Dan Meacham, CISO at Legendary Entertainment
Dan Meacham joined us to share a preview of his leadership panel at InfoSec World. At this CRA event in October, Dan will be discussing The Augmented Defender - What AI Actually Changes on the Front Line with Daniel Bowden, the Global CISO at Marsh.
Dan dives into the unique world of securing data and assets when film production is largely handled by partners and contractors, working from systems you'll likely have limited access to and definitely can't install agents on. It's a fascinating conversation you should check out!
Visit https://securityweekly.com/infosecworld2026 and save 30% on your ISW pass with code: ISW26-SWSAVINGS
Black Hat Interview 1 - Google Cloud
Outpacing the Adversary with AI Threat Defense - Black Hat interview with John Hultquist, Chief Analyst, Google Threat Intelligence Group at Google
The cybersecurity landscape is undergoing a radical shift. AI is no longer just a productivity accelerator for developers and analysts—it has become actively weaponized by sophisticated threat actors to discover and exploit vulnerabilities at unprecedented speed. We'll discuss Google's own approach to combating today's threats and the need for security teams to transform vulnerability management with machine-speed defense.
Segment Resources:
https://cloud.google.com/blog/products/identity-security/introducing-google-ai-threat-defense
https://services.google.com/fh/files/misc/ebookgooglecloudsecurityaithreatdefense.pdf
https://services.google.com/fh/files/misc/whitepapercombatingaidriventhreatsgooglemachinespeed_defense.pdf
This segment is sponsored by Google Cloud. Visit https://securityweekly.com/googlebh to learn more!
Black Hat Interview 2 - Forcepoint
Decoding Agentic: Securing the Data Layer AI Just Set on Fire - Black Hat interview with Ronan Murphy, Chief Data Strategy Officer of Forcepoint
AI didn't ask permission — and it permanently changed what data risk looks like. Forcepoint Chief Data Strategy officer and member of the Artificial Intelligence Advisory Council in Ireland, shares insights on a clear call to action for agentic enterprises: stop locking AI down and start securing it where the risk actually lives, in the data itself. Learn why data trust is the foundation of the agentic era and how the world's leading enterprises are ending the false choice between AI innovation and data safety.
Segment Resources:
https://www.forcepoint.com/resources/ebooks/enterprise-guide-ai-data-security
https://www.forcepoint.com/blog/insights/forcepoint-announces-ai-data-security
This segment is sponsored by Forcepoint. Visit https://securityweekly.com/forcepointbh to learn more!
Black Hat Interview 3 - Keyfactor
From Secrets to Verified Workload Identity—at Enterprise Scale - Black Hat interview with Ellen Boehm, SVP, Strategy & AI Innovation at Keyfactor
As AI agents become autonomous participants inside enterprise environments, organizations can no longer rely on static credentials and traditional identity models to establish trust. Enterprise AI is driving a shift from possession-based access to cryptographically verified identity, as AI agents, cloud-native workloads, and automated services increasingly make decisions and interact with critical systems. In this discussion, we'll discuss why organizations need to continuously establish trust, govern machine identities and cryptography, and build a resilient foundation for securing AI across increasingly dynamic environments.
Segment Resources:
https://www.keyfactor.com/blog/ai-agents-the-identity-problem-nobody-owns-yet/
https://www.keyfactor.com/education-center/what-is-trust-infrastructure/
https://www.keyfactor.com/resources/topic/col/products/the-trust-control-plane?pflpid=60788&pfsid=HsCXvwPWB1
This segment is sponsored by Keyfactor. Visit https://securityweekly.com/keyfactorbh to learn more!
Black Hat Interview 4 - Delinea
Delinea Delivers Runtime Authorization for AI Agents, Closing Access Control Gap - Black Hat interview with Frank Vukovits, Chief Security Scientist at Delinea
As AI agents move from experiments to autonomous operators inside production databases, cloud consoles, and Kubernetes clusters, enterprises face a new problem: agents with legitimate credentials taking actions no one authorized. Frank breaks down why verifying access at connection time is no longer enough and what it takes to enforce policy on every agent action before it executes. He explains how runtime authorization closes the gap between hiding credentials and actually controlling what agents do once they're inside a session.
This segment is sponsored by Delinea. Visit https://securityweekly.com/delineabh to learn more!
Visit https://www.securityweekly.com/esw for all the latest episodes!
Show Notes: https://securityweekly.com/esw-474Can employees safely use AI agents? AI pentesting agent liabilities, and the news - Rob Allen - ESW #473
2026/08/24 | 1h 39 mins.Interview with Rob Allen from Threatlocker
Safely enabling agentic AI for Businesses
OpenClaw was the wakeup call and businesses wanted to know how to block it. "Easy," Rob Allen said, "it's already blocked if you're using Threatlocker." Now that things have settled down a bit, those same businesses want to allow their employees to experiment with agents. We discuss how they can do it safely.
This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them!
Topic Segment
For this week's topic segment, we're discussing AI pentesting agents and how likely they are to get you into big legal trouble. You came home from Black Hat with a new, shiny AI pentesting agent. How can you be sure it isn't hacking the wrong company?
News Segment
Finally, in the enterprise security news,
we check the vibes
New MCP standard and AI text watermarking
what does combatting "cyber-enabled crime" mean?
A closer look at Cl0p
One 3rd party was responsible for all the AI sandbox escapes and hacking
reports
vulnerabilities
Comcast can track your movements with WiFi
A novel solution to the AI datacenter water use concerns
All that and more, on this episode of Enterprise Security Weekly.
Visit https://www.securityweekly.com/esw for all the latest episodes!
Show Notes: https://securityweekly.com/esw-473
More Education podcasts
Trending Education podcasts
About Enterprise Security Weekly (Audio)
News, analysis, and insights into enterprise security. We put security vendors under the microscope, and explore the latest trends that can help defenders succeed. Hosted by Adrian Sanabria. Co hosts: Katie Teitler-Santullo, Ayman Elsawah, Jason Wood, Jackie McGuire, Sean Metcalf.
Podcast websiteListen to Enterprise Security Weekly (Audio), How to Be a Better Human and many other podcasts from around the world with the radio.net app

Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features


Enterprise Security Weekly (Audio)
Scan code,
download the app,
start listening.
download the app,
start listening.































