224 episodes
- Lovable CISO Igor Andriushchenko on soft guardrails vs. hard boundaries, securing vibe coding for non-developers, and building a security program at a 10x company.
I sit down with Igor Andriushchenko, Head of Security and CISO at Lovable, the AI development platform behind one of the fastest growth stories in the space. Igor joined as the first security hire when the company was around 40 people. A year later he is running a 20+ person team covering product security, GRC, IT, and platform safety for a company with 400 laptops in MDM and no sign of slowing down.
We get into what it actually takes to secure AI-native development, both inside a hypergrowth startup and on a platform where most of the people shipping software are not developers and definitely not security practitioners.
In this episode:
Building a security program for the company you will be in 12 months instead of the one you are in today
Soft guardrails versus hard guardrails, and how to decide which one a problem deserves
Why hard blocks push AI-assisted workflows into the shadows
Rooting guardrail decisions in business goals, risks, and threats rather than tool defaults
Democratized development without democratized security, and what a platform owes the 99%
Lovable's auto-fix toggle, per-app threat models, and the goal of an app with no security tab at all
Whether models will ever produce secure code by default, and why defense in depth still carries the load
Governing the reality that every employee vibe coding an app looks a lot like a new vendor
GRC engineering as the way to measure control efficiency layer by layer against AI-powered attackers
CRA, NIS2, and the EU AI Act landing on citizen developers who never thought of themselves as software manufacturers
Chapters: 0:00 Intro 0:23 Igor's background from DevOps to CISO 3:54 Scaling security at a 10x company 6:07 Reinventing the team when growth breaks it 08:26 Soft guardrails versus hard blocks 14:05 Tying guardrails to business risk 17:32 Democratized development, undemocratized security 18:52 Shared responsibility on an AI dev platform 21:16 Auto-fix, per-app threat models, and no security tab 25:21 Will models produce secure code by default? 29:56 Every employee vibe coding is a new vendor 30:57 Enterprise controls, publishing gates, and PII scanning 36:39 AI-powered attackers and why good enough changed 40:43 GRC engineering and measuring control efficiency 46:19 CRA, NIS2, and the citizen developer 52:41 Trust centers for builder apps 54:08 Closing thoughts on the vibe coding community
Guest links: Igor on LinkedIn: https://www.linkedin.com/in/igor-andriushchenko Lovable: https://lovable.dev
Resilient Cyber: Newsletter and episode archive: https://www.resilientcyber.io Subscribe for more conversations with security practitioners and leaders. - CISOs have a stack of tools but no system built to run the security program itself. Mike Armistead wants to fix that.
In this episode I sit down with Mike Armistead, co-founder and CEO of Pulse Security AI and a longtime security founder behind Fortify and Respond Software. We dig into why the security leader has never had a system of truth the way the CFO has an ERP and the CRO has a CRM, and how an agentic layer on top of the existing tools can finally close that gap. Mike is measured about where AI gets to decide and where the human stays in the seat, and he shares what surprised him most from research with more than 80 senior practitioners and corporate directors.
In this episode:
- Why two exits later Mike came back to build a third company around the AI wave
- The silos that left CISOs with an acronym soup of tools and no way to run the program
- What a system of truth for the CISO actually means and how it layers on top of existing structured and unstructured data
- Where agents do the heavy lifting on regulatory monitoring, vendor intelligence, and status reporting
- Governing the guardrails, not the keystrokes, and why closing the loop still involves people
- What corporate directors actually want to hear in the 15 to 20 minutes a CISO gets each quarter
- The findings that stood out, including that 55% of boards have never defined the cyber risk they are willing to accept, and only 12.5% of CISOs are very confident the board leaves with a true picture of the risk
- Institutionalizing the tribal knowledge every security program runs on
Chapters:
0:00 Intro
0:18 Mike's background and two prior exits
1:08 Why the AI wave pulled him back
2:21 Why the CISO has no system to run the program
4:09 Starting at the program level, not the SOC or AppSec
5:28 What a system of truth for the CISO means
8:19 Speaking the language of the business
9:09 Where AI does the heavy lifting on a typical Tuesday
11:57 Govern the guardrails, not the keystrokes
15:44 Bringing deputies into the conversation
16:46 What the research with senior practitioners found
20:37 Boards, risk tolerance, and the reporting gap
24:57 AI as a double-edged sword for security leaders
25:35 Joanna Burkey and institutionalizing tribal knowledge
27:31 A year from now for the security leader
Guest links:
Mike Armistead on LinkedIn
Pulse Security on AI
More Resilient Cyber:
Substack: https://www.resilientcyber.io
Subscribe for more conversations with security practitioners and leaders. - Alex Pinto, who leads Verizon's DBIR team, joins me to break down the new Breach Impact Study and what data breaches actually cost organizations.
For years the industry has argued past itself on breach costs. One camp says the market doesn't care, the other says a single breach ends your business. Alex and his team finally got their hands on roughly 70,000 cyber insurance claims through CyberAcuView, and the Breach Impact Study puts real numbers behind the question. In this conversation we dig into what the data shows, where it stops, and how a security leader should actually use it.
Alex Pinto runs the Data Breach Investigations Report team at Verizon Business and has been building the report for close to a decade. The Breach Impact Study is the team's first focused spin-off from the DBIR.
In this episode:
- How the Breach Impact Study came together and why the DBIR team finally got cyber insurance claims data
- Why the study measures insurable loss as a floor, not a ceiling, of real economic impact
- The case for reporting medians over averages, and why the team refuses to publish the average
- Business interruption versus contingent business interruption, and why downtime moves the needle
- Whether an $83,000 median breach impact sends executives the wrong message
- The SMB paradox, where the smallest companies take the hardest proportional hit
- What the claims data does and does not show about AI on offense and defense
- Third-party risk, coverage sub-limits, and the single biggest takeaway for security leaders
Chapters
0:00 Intro
0:24 Meet Alex Pinto and the DBIR team
2:51 Launching the Breach Impact Study
3:26 Getting cyber insurance claims data
7:32 Why insurable loss is a floor, not a ceiling
11:14 Medians over averages, and why the average is meaningless
15:13 Business interruption vs contingent business interruption
19:49 Does an $83K median send the wrong message?
22:44 The SMB paradox and the cybersecurity poverty line
26:05 Where AI shows up, offense vs defense
34:48 The CVE explosion and marketing hype
36:59 Third-party risk and coverage limits
41:34 Wrap-up
Guest links
Alex Pinto on LinkedIn: https://www.linkedin.com/in/alexcpsec/
Alex Pinto on X: https://x.com/alexcpsec
Verizon DBIR and Breach Impact Study: https://www.verizon.com/business/resources/reports/dbir/
More from Resilient Cyber
Substack: https://www.resilientcyber.io
Subscribe for more conversations with security practitioners and leaders.
#cyberrisk #databreach #cyberinsurance #ransomware #aisecurity #dbir - What happens to security investing when vulnerability discovery becomes continuous and exploitation windows shrink from weeks to hours? I sit down with Chenxi Wang of Rain Capital to dig into it.
Chenxi is the Founder and Managing General Partner at Rain Capital, a venture fund focused on early-stage cybersecurity companies. She's been a Carnegie Mellon professor, a Forrester VP, and a strategy leader at Intel Security and Twistlock, and her portfolio includes companies like Claroty, ProjectDiscovery, Ox Security, runZero, and Straiker. She closes out my July run of conversations with security investors.
In this episode:
The AI Exploit Age and why vulnerability discovery is becoming continuous
Guardian Agents and the case that it takes an AI to govern an AI
Separating AI agent identity from traditional machine identity
The signals that predict enterprise adoption for early-stage security startups
The barbell funding market and the squeeze on Series B and C
What security leaders should do differently over the next twelve months
Connect with Chenxi:
 LinkedIn: https://www.linkedin.com/in/chenxiwang88/
Rain Capital: https://raincap.vc/
Rain Capital Insights: https://raincapital.substack.com
Subscribe to Resilient Cyber for more conversations with security practitioners and leaders: https://www.resilientcyber.io - Bugcrowd founder Casey Ellis joins me to dig into what AI is actually doing to bug bounties, vulnerability discovery, and open source security. We get into his "slopdemic" framing, the curl bug bounty saga, VDP readiness, the pentest market correction, and where security research policy heads next.
Casey Ellis is the founder of Bugcrowd, co-founder of disclose.io, and a board member of the Security Research Legal Defense Fund. These days he advises and invests through Tall Poppy Group and works at the intersection of security, AI, and policy. His argument is that the vulnpocalypse was already here, and AI has made the cost of both finding and reporting vulnerabilities collapse at the same time.
In this episode:
Casey's path from building Bugcrowd to advising, investing, and policy work
Why more practitioners need to get involved in policy, and why law is just code
The slopdemic vs. the vulnpocalypse, and what actually changed in submissions
AI lowering the bar for a broader, less predictable pool of threat actors
Daniel Stenberg, curl, and maintainers below the security poverty line
The lightning rod vs. rockets distinction between VDPs and bug bounties
The pentest market correction underway from AI pricing pressure
Collapsing OODA loops, hack-back, CFAA reform, SRLDF, and disclose.io
Chapters:
0:00 Intro and Casey's background
 2:56 Why practitioners belong in policy
 6:22 The slopdemic vs. the vulnpocalypse
 9:40 AI lowering the bar for threat actors
 11:47 Open source, curl, and the security poverty line
 15:37 VDP vs. bug bounty readiness
 19:20 The pentest market correction
 24:20 What breaks first in vulnerability management
 27:20 Hack-back and non-cooperative defense
 28:43 A near-term playbook for security leaders
 31:40 CFAA, SRLDF, and disclose.io
Connect with Casey:
 LinkedIn: https://www.linkedin.com/in/caseyjohnellis
Blog: https://cje.io
disclose.io: https://disclose.io
Bugcrowd: https://www.bugcrowd.com
Resilient Cyber: https://www.resilientcyber.io
Subscribe for more conversations with security practitioners and leaders.
More Technology podcasts
Trending Technology podcasts
About Resilient Cyber
Resilient Cyber brings listeners discussions from a variety of Cybersecurity and Information Technology (IT) Subject Matter Experts (SME) across the Public and Private domains from a variety of industries. As we watch the increased digitalization of our society, striving for a secure and resilient ecosystem is paramount.
Podcast websiteListen to Resilient Cyber, All-In with Chamath, Jason, Sacks & Friedberg and many other podcasts from around the world with the radio.net app

Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features


Resilient Cyber
Scan code,
download the app,
start listening.
download the app,
start listening.
Resilient Cyber: Podcasts in Family




























