Skip to content
PodcastsEducationEnterprise Security Weekly (Audio)

Enterprise Security Weekly (Audio)

Adrian Sanabria
Enterprise Security Weekly (Audio)
Latest episode

489 episodes

  • Enterprise Security Weekly (Audio)

    Three interviews: system fragility, operational clarity, and Identity for AI agents - Todd Thiemann, Robin Macfarlane, Kyle Sandy - ESW #471

    2026/08/10 | 1h 37 mins.
    Interview 1: Robin Macfarlane from RRMac Associats
    The Mattress Money Principle: What a 50-Year Veteran Knows About System Fragility
    In this interview, Robin and Adrian discuss how technology has evolved over the past 50 years. Despite massive technological changes over the decades: the PC revolution, the Internet, smartphones, the Cloud, and now Generative AI - the majority of financial institutions still use mainframes and midrange machines. Why?
    We explore the reasons why older technology persists alongside the new and the lessons retiring technologists can pass on to new generations inheriting an increasingly diverse tech landscape.
    Interview 2 with Kyle Sandy from Logically
    Operational Clarity as the New Customer Experience
    Kyle Sandy joins Adrian to discuss how prioritizing resilience affects how organizations should plan for incident response. In the past, security teams were focused on prevention and limiting breach damage. Today, boards want to know how long it will take to recover operations.
    The interview wraps up with a discussion of the right and wrong way to handle a breach and the three most important things every company must get right in order to handle an incident well.
    Interview 3 with Todd Thiemann from Omdia
    AI Agents and Identity Security: How Enterprises Are Rewriting the Rules
    Todd joins ESW with some eye-opening survey insights on the topic of IAM for AI agents. While cybersecurity conversations about internal AI use often revolve around the SOC and security operations, Omdia surveyed identity professionals for a more holistic enterprise perspective.
    Unsurprisingly, AI agent use is as diverse as enterprise business units. The surprises are around where the budget comes from for these AI projects, and how authentication is handled.
    Visit https://www.securityweekly.com/esw for all the latest episodes!
    Show Notes: https://securityweekly.com/esw-471
  • Enterprise Security Weekly (Audio)

    AppSec, Shopify-Style; State of Mobile Security; the News - Kern Smith, Andrew Dunbar - ESW #470

    2026/08/03 | 1h 37 mins.
    Interview with Andrew Dunbar, CISO at Shopify
    After 13 years at Shopify, Andrew has some valuable insights to share on application security. In this episode, we discuss how AI has changed application security processes where bug bounty now fits in a post-Mythos, post-AI harness world.
    Andrew's Resources:
    https://shopify.engineering/building-an-agentic-harness-that-outlasts-the-model
    Interview with Kern Smith
    Kern Smith, VP of Global Solutions at Zimperium, joins us to talk about the state of mobile security. This was a great conversation, talking about the history of mobile devices in the enterprise and how challenging securing mobile apps is in the age of vibe-coding.
    Segment Resources
    https://zimperium.com/resources/new-zimperium-research-reveals-that-ai-based-attacks-are-targeting-and-succeeding-on-mobile
    Global Mobile Threat Report 2026
    Enterprise Security News
    Finally, in the enterprise security news,
    Pre-black hat funding goes nuts
    we have 4 new cybersecurity unicorns!
    Cyera acquires Oasis for one BILLION dollars
    Lots of new product announcements with hacker summer camp next week
    Hugging Face got hacked by a competitor's agent and are cool with it?
    Finding out that wiping a burner phone is illegal the week before DEF CON is not ideal
    Are open, local models the future of AI?
    AI isn't coming for your job
    lots of vendor reports
    bad cybersecurity takes are apparently mainstream memes now???
    All that and more, on this episode of Enterprise Security Weekly.
    Visit https://www.securityweekly.com/esw for all the latest episodes!
    Show Notes: https://securityweekly.com/esw-470
  • Enterprise Security Weekly (Audio)

    Exploring AI Network Protocols; Vulnerability Truths and Guarantees; and the News - Jeremiah Grossman, O'Shea Bowens - ESW #469

    2026/07/27 | 1h 50 mins.
    Segment 1 - Interview with O'Shea Bowens
    What do we really know about "AI Network Protocols"? Network security is about to get popular all over again.
    Generative AI caused a disruptive explosion across all of tech and every company's roadmap. The move from chatbots to AI agents doubled down on that disruption. Now agents need to talk to each other?
    Boom: we have MCP. A2A. Universal Commerce Protocol. General purpose and specialized protocols for agent communication. What does this look like from the network perspective, though? O'Shea Bowen joins us to answer this question, and he thinks the results are interesting enough to spark a resurgence of interest in network security tooling.
    Segment Resources:
    https://www.nsa.gov/Portals/75/documents/Cybersecurity/CSIMCPSECURITY.pdf?ver=bmgiSbNQLP6Z_GiWtRt6bg%3D%3D
    https://labs.cloudsecurityalliance.org/research/csa-research-note-mcp-security-crisis-20260504-csa-styled/
    https://cyberone.security/blog/building-an-ai-security-strategy-without-stalling-business-growth
    Segment 2 - Interview with Jeremiah Grossman
    Jeremiah Grossman on why we've been measuring cyber risk wrong for 20 years
    After decades helping shape modern web security, and building companies that were ultimately acquired by Synopsys and Tenable, Jeremiah Grossman believes cybersecurity has arrived at an inflection point. His argument is a provocative one: for years, the industry has optimized around the wrong metrics. His latest venture, Root Evidence, aims to help security teams identify which risks are most likely to cause meaningful business loss, and he has the evidence - real-world breach data, cyber insurance claims, digital forensics intelligence, attack surface intelligence, and observed attacker behavior - to back it up.
    Find all of CyberRisk TV's Black Hat 2026 coverage at: https://www.securityweekly.com/blackhat
    Segment 3 - Weekly Enterprise News
    Finally, in the enterprise security news,
    We vibe check the AI model situation
    hidden devices in California cars causes concerns
    OpenAI's models escape sandboxes and breaches another AI company, totally by accident, they promise!
    Grok Build uploads all your files, totally by accident, they promise!
    Eclipsium debuts a firmware version of patch tuesday!
    HTTP gets a new method
    common problems with incident response
    Which one of the security weekly hosts would consider switching to a "dumb phone"?
    All that and more, on this episode of Enterprise Security Weekly.
    Visit https://www.securityweekly.com/esw for all the latest episodes!
    Show Notes: https://securityweekly.com/esw-469
  • Enterprise Security Weekly (Audio)

    AI Security at Scale, CMMC phase II paused, and the Weekly Enterprise News - Keith Hollender - ESW #468

    2026/07/20 | 1h 42 mins.
    Interview with Keith Hollender, CEO and Co-Founder of Arcova
    Why AI Security Is Becoming an Execution Problem, Not Just a Governance Problem
    As enterprises move from AI experimentation to adoption at scale, security leaders are under pressure to enable innovation without introducing unmanaged risk. The challenge is no longer whether organizations should pursue AI, but how they can govern it, secure it, and operationalize it in ways that stand up to real-world business and threat conditions.
    In this conversation, Keith Hollender discusses what Arcova is seeing across enterprise environments as organizations work to connect cybersecurity, AI governance, resilience, and broader transformation priorities. He explores where companies are getting stuck, why traditional siloed approaches are falling short, and what it takes to move from strategy decks to secure execution.
    Keith also shares how Arcova's practitioner-led, relationship-driven model helps organizations turn complexity into clarity by embedding with client teams, solving urgent problems hands-on, and building capabilities designed to last. The conversation also covers Arcova's continued growth, including expansion into the Middle East, and what global demand signals reveal about the next phase of cybersecurity and AI consulting.
    Segment Resources:
    https://arcova.com/sectors/
    https://arcova.com/category/blog/
    For more information about Arcova and how they can help your enterprise shape what's next, please visit:
    https://securityweekly.com/arcova
    Topic: CMMC Pause creating chaos among federal contractors
    This one sent some shockwaves through the CMMC community, particularly the hundreds or thousands of folks gearing up to assist with the validation that phase 2 aimed to provide. The TL;DR - defense contractors have been required to comply with CMMC controls for years, but self-attestation means that many probably haven't been meeting the requirements. Perhaps, rather than have tons of defense contractors fail the test, they just suspended the requirement for the test itself.
    I think Howard Holton nails it here when he says:
    "100,000 defense contractors needed third-party assessments. Roughly 100 authorized assessors exist. That's 1,000 assessments each, with the deadline in November."
    PCI already created a model that works for a scenario like this. If you're small, you self-assess. If you're big enough, an independent auditor comes to check you out once a year. I'm sure they were probably aware of this and chose not to go down that path for some reasons. I'm not aware of those reasons.
    What this means:
    Phase II is paused
    Phase I self-assessments still in place (note, however, that phase II existed, because self-attestation didn't work)
    NIST SP 800-171 Rev 2 and DFARS 252.204-7012 compliance still required
    60-day review aims to reform CMMC
    DoW opened an RFI for industry perspectives on what they should do
    CMMC characterized as a "compliance burden" and "red tape"
    False Claims Act and DOJ's cyber-fraud enforcement are still on the table
    More resources:
    CIO Davies' post on Twitter
    Administrator of the Small Business Administration, Kelly Loeffler's post
    A useful LinkedIn post that breaks down a lot of what this really means (and doesn't)
    Weekly Enterprise News
    Finally, in the enterprise security news,
    will AI eliminate more cybersecurity jobs than it creates?
    Linus's law, amended
    the biggest patch Tuesday ever
    AI context bombs
    AI workflows are a security disaster
    people using AI in areas they don't understand
    ransomware crews are hitting legal firms hard
    lessons learned from CISA's recent github leak
    demystify your USB cables!
    All that and more, on this episode of Enterprise Security Weekly.
    Visit https://www.securityweekly.com/esw for all the latest episodes!
    Show Notes: https://securityweekly.com/esw-468
  • Enterprise Security Weekly (Audio)

    Hungry? We talk Smoked Meat, Poutine, and Bagel - also, Identiverse Interviews! - John Pritchard, Cassie Christensen, Jaime Lewis-Gross, François Proulx, Kim Brown - ESW #467

    2026/07/13 | 1h 38 mins.
    Interview with François Proulx from Boost Security
    Software Supply Chain Security: Build Pipeline (CI/CD) Exploitation
    Boost Security is the creator of some very popular build pipeline security tools, like Bagel and Poutine. Today, we discuss their latest tool, Smoked Meat. They describe it as "Like Metasploit, but for CI/CD pipelines".
    Segment Resources:
    Smoked Meat announcement
    Smoked Meat github
    Smoked Meat demo with Guillaume and François
    Identiverse Interview with Dr. John Prichard from Radiant Logic
    The Three Identity Problem: Surviving Identity Security's Chaotic Era
    Identity security has entered its chaotic era. Human, non-human, and agentic AI identities no longer just coexist. They form an uncontrolled inheritance chain in which a human creates an agent, the agent spins up service principals, OAuth grants, and role assignments, and that whole chain keeps running long after the human changes roles or leaves. Most of these chains are being spawned by business users on low-code and enterprise AI platforms, outside traditional identity controls and largely invisible to security.
    In this segment, Radiant Logic CEO Dr. John Pritchard joins us to unpack why this is no longer a visibility problem. It is an observability problem. And it is shifting the center of gravity in identity security from authentication to authorization. Listeners will leave with a clearer view of where their current IAM, IGA, and NHI programs fall short, and a practical lens for governing the rapidly expanding population of AI agents already inside their environments.
    To go deeper on what John discussed today, watch Radiant Logic's on-demand webinar Identities Under Attack: How Adversaries Exploit the Human-Machine-Agent Divide at https://securityweekly.com/radiantlogicidv.
    Identiverse Interview with Cassie Christensen from Saviynt
    Everyone Wants an AI Assistant. Few Are Ready to Govern One
    Explore a growing reality many professionals can relate to: the appeal of using AI agents to handle the work that keeps piling up - from inbox management to research and logistics - and the governance challenges that quickly follow. The real barrier to scaling personal or enterprise AI agents isn't the technology itself, but defining clear roles, access boundaries, oversight, and lifecycle management. As organizations deploy more autonomous AI agents, the same identity frameworks used to govern workforce and non-employee identities must now evolve to manage AI-driven access before scale and risk outpace control.
    This segment is sponsored by Saviynt. Learn more or get a free demo at https://securityweekly.com/saviyntidv
    Identiverse Interview with Jaime Lewis-Gross from Saviynt
    From Sales Engineer to Forward Deployed Engineer: The Rise of Hybrid Technical Roles
    As technology organizations evolve, technical roles are becoming increasingly fluid - particularly at the intersection of product, engineering, and customer success. This conversation explores what it means to be a modern sales engineer and how the role is increasingly expanding into responsibilities often associated with forward deployed engineers: translating complex technical capabilities into real-world outcomes, solving customer challenges in real time, and serving as a critical bridge between product teams and end users. At the center of this evolution is a customer-first mindset - one that prioritizes listening, adaptability, and long-term partnership. As organizations race to innovate, the companies that stand out will be those that remain deeply focused on customer needs while empowering technical teams to operate beyond traditional role boundaries.
    This segment is sponsored by Saviynt. Learn more or get a free demo at https://securityweekly.com/saviyntidv
    Identiverse Interview with Kim Brown from LexisNexis
    Stop Identity Fraud: Modern Strategies for Insurance and Healthcare
    Identity fraud is growing more sophisticated across both insurance and healthcare, making identity management a critical line of defense. In this executive interview, Kim Brown, VP of Product Management, will explore how organizations can strengthen identity verification, authentication, and risk assessment to reduce fraud while improving user experiences. The discussion will highlight emerging threats, evolving regulatory expectations, and practical strategies for deploying identity solutions at scale. Attendees will gain actionable insights to protect customers, patients, and their organizations without adding friction.
    This segment is sponsored by LexisNexis Risk Solutions. Visit https://securityweekly.com/lexisnexisidv to learn more about them!
    Visit https://www.securityweekly.com/esw for all the latest episodes!
    Show Notes: https://securityweekly.com/esw-467
More Education podcasts
About Enterprise Security Weekly (Audio)
News, analysis, and insights into enterprise security. We put security vendors under the microscope, and explore the latest trends that can help defenders succeed. Hosted by Adrian Sanabria. Co hosts: Katie Teitler-Santullo, Ayman Elsawah, Jason Wood, Jackie McGuire, Sean Metcalf.
Podcast website

Listen to Enterprise Security Weekly (Audio), Pepp Talk Podcast and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features