Skip to content
PodcastsTechnologyResilient Cyber

Resilient Cyber

Chris Hughes
Resilient Cyber
Latest episode

229 episodes

  • Resilient Cyber

    Who Is Winning the AI Security Market Right Now? James Berthoty

    2026/10/05 | 41 mins.
    James Berthoty of Latio on why the endpoint is now the center of AI security, and why most of the real agent risk traces back to blind spots we already had.

    I sit down with James Berthoty, who started Latio as an engineer frustrated by how hard it was to figure out what security tools actually did. That turned into a practitioner-focused, buyer-oriented analyst firm. We dig into Latio's second AI security market report. Last year the story was browsers and proxies. This year it's the endpoint, where coding agents now run with the permissions and credentials on developer laptops.

    We get into what roughly 400 AI security startups are actually differentiating on and why runtime detection claims need hands-on testing. We also cover why James pushes back on the runtime-first narrative, where the new AI security budget is coming from, and how security leaders should narrow the vendor field before they ever take a demo.

    In this episode:
    ● Why we are in the "pre-HTTPS era" of AI security, and how coding agents turned developer endpoints into the new pressure point
    ● Dedicated AI security budget jumping from 8% to 37% in a year, and how it flows out of AI governance
    ● What is already commoditized, and why intent-based runtime detection needs hands-on testing
    ● Agent blast radius, and why your agent shouldn't be able to drop the prod DB because you shouldn't be able to either
    ● Why recent AI safety incidents look more like misconfigurations than emergent behavior
    ● The next M&A wave as a fight over the laptop
    ● Anthropic's inference hooks, and why frontier labs likely won't absorb the security market
    ● MCPs and skills as a software supply chain problem with a new delivery mechanism

    Chapters:
    0:00 Intro
    0:31 Why James started Latio
    1:00 From browsers to the endpoint
    8:15 Do you need a purpose-built AI security platform?
    11:52 Where the AI security budget comes from
    13:53 400 startups and testing runtime claims
    19:28 Blast radius and runtime vs. posture
    23:35 M&A and the fight over the endpoint
    33:22 Inference hooks and frontier labs vs. vendors
    36:03 MCPs, skills, and software supply chain
    39:30 Advice for security leaders

    Connect with James:
    LinkedIn: https://www.linkedin.com/in/james-berthoty
    Latio: https://www.latio.com/
    AI Security Market Report: https://pulse.latio.tech/p/the-2026-latio-ai-security-market

    Resilient Cyber: https://www.resilientcyber.io

    Subscribe for more conversations with security practitioners and leaders.
    #aisecurity  #agenticai #endpointsecurity #appsec #supplychainsecurity #mcp #cybersecurity
  • Resilient Cyber

    Security Teams Are Moving Too Slowly for AI Agents | Zack Korman

    2026/09/28 | 30 mins.
    Zack Korman on why the AI safety debate has been captured by an extinction narrative, and why the incident everyone is calling a watershed moment looks a lot more like a preventable security failure.

    In this episode I sit down with Zack Korman, co-founder of Embroidery, where he uses AI to monitor AI agents, and former CTO of the cybersecurity company Pistachio. I first came across Zack on X during the controversy over fake SOC 2 reports, and he has since become one of the sharpest critics of how AI safety is being framed, funded, and investigated.

    We get into the effective altruism roots of the existential risk movement, why he argues METR's review of the Hugging Face incident was not independent oversight, and what an actual incident response firm would have done differently. Zack makes the case that alignment is one control among many, that there is no "safe" path in AI, only trade-offs, and that the real risk for most organizations is enterprise environments that were never ready for agents in the first place.

    In this episode:

    ● How building an AI insider threat product pulled a developer and CTO into the cybersecurity community, and into picking fights on X
    ● Effective altruism, longtermism, and how a focus on preventing extinction came to dominate AI safety
    ● Why "just be careful" misses the point when every path involves trading one risk for another
    ● Dario Amodei's Pacing the Frontier, independent auditors, and why Zack calls bringing in METR "bring your friend to work day"
    ● The funding and relationships connecting METR, Redwood Research, Coefficient Giving, and the labs
    ● True believers versus IPO hype, and why genuine belief does not make someone right
    ● Why many AI doomers believed we were all going to die before they ever learned about computers
    ● The Hugging Face investigation, context drop in AI-analyzed transcripts, and treating knowable facts as unknowable
    ● What Unit 42 or Mandiant would have demanded before putting their name on the report
    ● Eight layers of failure, from a single package proxy at egress to missing monitoring, classifiers, and kill switches
    ● Alignment failure versus containment failure, and why alignment belongs inside defense in depth
    ● The real risks: threat actors misusing AI, enterprise agent deployments, and new attack chains
    ● Why security's risk-averse, laggard culture may be its biggest vulnerability

    Chapters:

    0:00 Intro
    0:54 Zack's Background
    1:43 What Turned a CTO Into an AI Safety Critic
    3:31 Effective Altruism and the Extinction Narrative
    5:53 No Safe Path, Only Trade-offs
    6:40 METR, Redwood, and Bring Your Friend to Work Day
    10:23 True Believers, Hype, or Both
    12:49 How Doomers Find Their Way Into AI
    14:39 Taking AI Risk Seriously When It Is Ideological
    16:56 What an IR Firm Would Have Asked
    21:10 Eight Layers of Failure in the Hugging Face Incident
    22:49 Alignment Failure Versus Containment Failure
    24:32 Alignment as One Layer of Defense in Depth
    26:22 Why Enterprise Environments Are Not Ready for Agents
    29:10 Security's Laggard Culture
    29:19 Closing

    Connect with Zack Korman:

    X: https://x.com/ZackKorman
    Embroidery: https://embroidery.io
    Website: https://zkorman.com

    Resilient Cyber: https://www.resilientcyber.io

    Subscribe for more conversations with security practitioners and leaders.

    #aisafety #aisecurity #agenticai #incidentresponse #effectivealtruism #cybersecurity
  • Resilient Cyber

    The Model Writing Your Code Shouldn't Be Securing It

    2026/09/21 | 30 mins.
    Jonathan Rende of Checkmarx on why the model writing your code cannot also be the control that validates it, and why rules-based and AI-driven scanning turn out to find almost entirely different bugs.

    In this episode I sit down with Jonathan Rende of Checkmarx. Jonathan worked with Fortify and SPI Dynamics back in the day, spent most of the last decade leading product teams in developer and DevOps tooling, and came back to security eighteen months ago because, as he puts it, this is the heart of the hurricane. His argument is that AI is a bigger disruption than the internet, SaaS, or mobile were, not because of any single capability, but because it hits roles, process, and productivity all at once.

    We get into the two waves he has watched play out with CISOs and their CEOs, why the pendulum has swung back toward program and posture questions in the last quarter, what his research team found when they benchmarked deterministic and probabilistic scanning side by side, and why he thinks agentic AppSec raises the profile of the security team rather than automating it away.

    In this episode:

    ● Why the first half of 2026 became a real inflection point rather than another AI talking point

    ● The two waves: engineering told to run at any cost, then the pendulum swinging back toward posture and program design

    ● Why functional AI-generated code and secure AI-generated code are still two different things

    ● Separation of church and state, and the conflict of interest in letting the model that generates code also validate it

    ● Benchmarking deterministic and AI-based scanning across dozens of open source projects, and why the overlap stayed consistently under 10%

    ● Fidelity, F1 scores, and the absence of real standards or shared benchmarks in AppSec

    ● Why an incentive to reduce risk and an incentive to sell tokens are not the same incentive

    ● Why agents free AppSec professionals for higher-order work, and why this is not a dark factory

    ● Shadow IT becoming shadow AI, and early scans where half surfaced models, agents, and MCP servers security teams did not know existed

    ● Why new threat vectors show up first in fast-moving unregulated companies while regulated ones see more code-level issues

    ● Low-priority vulnerabilities chained into real impact, and why backlogs now matter as much as incoming code

    ● What to change first: metrics defined up front, in-workflow AppSec, and security reviews that went from annual to monthly

    Chapters:

    0:00 Intro
    0:18 Fortify, SPI Dynamics, and a decade in developer tooling
    1:24 Why he came back to AppSec
    2:54 Why the first half of 2026 was the inflection point
    5:27 Two waves, and the pendulum swinging back
    9:08 Functional AI code versus secure AI code
    11:58 Layered defense and the condensed lifecycle
    15:04 What agents free AppSec teams to actually do
    17:50 Separation of church and state
    20:15 Fidelity, F1 scores, and not selling tokens
    23:25 New threat vectors and organizational maturity
    25:47 Shadow AI and what the inventory scans found
    27:58 What to change first in your AppSec program
    30:44 Closing

    Connect with Jonathan:

    LinkedIn: https://www.linkedin.com/in/jonathanrende/

    Checkmarx: https://checkmarx.com

    Resilient Cyber: https://www.resilientcyber.io

    Subscribe for more conversations with security practitioners and leaders.

    #appsec #aisecurity #devsecops #shadowai #vulnerabilitymanagement #ciso
  • Resilient Cyber

    The First OWASP Top 10 Backed by Real Incident Data

    2026/09/14 | 25 mins.
    Rock Lambros, Co-Lead of the 2026 OWASP Top 10 for LLM Applications, on why prompt injection would have fallen out of the top 10 based on incident data alone, and why the community kept it at number one anyway.

    In this episode I sit down with Rock Lambros, longtime security leader, former CISO, core team member of the OWASP GenAI Security Project, and Co-Lead of the 2026 OWASP Top 10 for LLM Applications, to dig into the new list and the harder questions underneath it. We get into the letter from the project leads that opens the document, why the LLM and Agentic lists are converging, what a year of messy incident data actually told the working group, and why Rock argues that agency is not authorization.

    In this episode:
    Why the LLM Top 10 and the Agentic Top 10 are merging in practice
    The opening letter, and why the industry was slow to admit the model was never the thing to secure
    Who benefits from a model-centric framing of AI security
    Prompt injection ranked number one by practitioners and out of the top 10 by the incident data
    Why incidents get reported by outcome rather than by initial vector
    Misinformation, the widest gap between the vote and the data
    Hidden Context Exposure, soft guardrails, and why instructions and data share one context window
    Context rot and why context window management matters for agents doing critical work
    Using AI to govern AI, and the dual-layer approach in the Agentic Control Standard
    Agency versus authorization, and why OAuth is what we have rather than the answer
    How to get involved in the OWASP GenAI Security Project
    Chapters:
     0:00 Intro and Rock's background
     1:17 What the agentic work changed about the LLM Top 10
     3:59 The opening letter and "It Was Never the Model"
     8:48 Incident data and the prompt injection ranking
     11:23 Misinformation and the limits of the data
     14:24 Hidden Context Exposure and soft guardrails
     17:18 The context window and context rot
     19:57 Using AI to govern AI
     22:49 Excessive agency, and agency versus authorization
     27:09 How to get involved with OWASP

    Connect with Rock:
    LinkedIn: https://www.linkedin.com/in/rocklambros
    OWASP GenAI Security Project: https://genai.owasp.org
    Get involved: https://genai.owasp.org/contributing
    OWASP Top 10 for LLM Applications 2026: https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/
    Read my piece on the new list, It Was Never the Model: https://www.resilientcyber.io/p/it-was-never-the-model
    Resilient Cyber: https://www.resilientcyber.io
  • Resilient Cyber

    The Jagged Frontier of Finding and Fixing Vulns with AI

    2026/09/01 | 42 mins.
    Ondrej Vlcek, CEO of AISLE and former CEO of Avast, on why AI vulnerability discovery is not as commoditized as the industry thinks, and why remediation is still the real bottleneck.

    In this episode I sit down with Ondrej Vlcek, Founder and CEO at AISLE. Ondrej spent roughly 30 years in cybersecurity, joining Avast as employee number six or seven doing kernel-mode driver work on Windows 95, eventually becoming CTO and then CEO, taking the company public and selling it to NortonLifeLock in a nearly $9 billion transaction. He co-founded AISLE in the fall of 2024 to close the loop from discovery through triage, remediation, and verification. His team has now disclosed 350 plus CVEs across projects like OpenSSL and curl.

    We get into why the moat sits in the system and not the model, why the gray market price of vulnerabilities has not collapsed even as models get cheaper, and what it actually takes to ship a patch a maintainer will accept.

    In this episode:
    - Going from Avast intern to CEO, and why vulnerability management was the next problem
    - The jagged frontier, and why bigger models do not always mean better results
    - Which classes of bugs got cheap to find and which are still genuinely hard
    - Why vulnerability prices have not collapsed despite all the model progress
    - Building a model-agnostic system with bespoke benchmarks for model selection
    - Sovereign AI, on-prem and air-gapped deployment, and why findings are the real crown jewels
    - Triage, reachability, and why most findings are not actually exploitable
    - Patch verification, regression risk, and mitigations for embedded systems that cannot be patched
    - How AISLE earned trust from curl after Daniel Stenberg killed the bug bounty
    - Whether a CVE count is a vanity metric
    - Build versus buy as model capability keeps getting cheaper
    - What breaks first in the CVE and open source maintainer ecosystem
    - What AppSec leaders should change next quarter

    Chapters
    0:00 Intro
    0:24 From Avast employee number six to a $9 billion exit
    3:26 Why vulnerability management, and why now
    5:15 The jagged frontier and what bigger models miss
    10:36 The economics of finding bugs, and why prices have not collapsed
    12:11 Building a model-agnostic system with real benchmarks
    14:30 Sovereign AI, air-gapped deployment, and who sees your findings
    19:42 Triage, reachability, and why remediation is the bottleneck
    24:48 Patches that break things, and systems you cannot redeploy
    25:39 curl, Daniel Stenberg, and death by a thousand slops
    29:35 Is a CVE count a vanity metric?
    31:34 Build versus buy when capability keeps getting cheaper
    34:41 What breaks first in the next 18 months
    39:46 What AppSec leaders should do next quarter
    41:13 Closing

    Ondrej Vlcek on LinkedIn
    AISLE
    AISLE research and blog

    Resilient Cyber Substack
    Subscribe for more conversations with security practitioners and leaders.
More Technology podcasts
About Resilient Cyber
Resilient Cyber brings listeners discussions from a variety of Cybersecurity and Information Technology (IT) Subject Matter Experts (SME) across the Public and Private domains from a variety of industries. As we watch the increased digitalization of our society, striving for a secure and resilient ecosystem is paramount.
Podcast website

Listen to Resilient Cyber, The a16z Show and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features
Resilient Cyber: Podcasts in Family