Skip to content
PodcastsBusinessThe Security Strategist

The Security Strategist

EM360Tech
The Security Strategist
Latest episode

240 episodes

  • The Security Strategist

    Defensible Prioritisation: A Story CISOs Can Stand Behind

    2026/08/11 | 20 mins.
    Prioritisation is the way to tackle enterprise data challenges. It may seem like a simple solution, and it might be too. If you’re an enterprise overwhelmed by vulnerabilities in data, especially with the evolution of AI and automation, this conversation is for you.
    In the recent episode of The Security Strategist podcast, host Shubhangi Dua, Podcast Producer and B2B Tech Journalist at EM360Tech, sat down with James Walta, Vice President of Product Management at Brinqa. The agenda for this episode was to break down why enterprises are overwhelmed by vulnerability data. Additionally, Walta lays out a strategic plan of action to help enterprises prioritise vulnerabilities proactively rather than reactively.
    The discussion builds on the previous episode, where Brinqa CSO Brad Hibbert and host Richard Stiennon, Chief Research Analyst at IT-Harvest, talked about how AI is helping attackers with faster scanning, smarter exploit chaining, and machine-speed intrusions.
    Walta continues this conversation with EM360Tech’s Dua, focusing on prioritisation in exposure management strategies. He puts up a case noting AI will not rescue security teams from unorganisation unless the underlying data is ‘good’ and reliable.
    Takeaways
    Context is crucial for effective cybersecurity management.
    The chaos in cybersecurity is amplified by AI-driven vulnerabilities.
    Data quality is foundational for prioritisation and remediation.
    Patching faster is not always the best approach; understanding risk is key.
    Operational clarity can be achieved by unifying asset visibility.
    Prioritisation must be based on business context and asset sensitivity.
    AI can help but may also amplify confusion if data is poor.
    CISOs should focus on outcome metrics rather than activity metrics.
    Effective vulnerability management requires a clear understanding of ownership.
    The conversation around cybersecurity must evolve to address real risk reduction.

    Chapters
    00:00 Navigating Cybersecurity Chaos
    02:52 The Importance of Context in Cybersecurity
    06:07 Bridging the Gap: From Vulnerability Detection to Remediation
    09:09 Understanding Risk Over Speed
    11:46 Enhancing Data Quality for Better Decision Making
    14:57 Operational Clarity: Transforming Overload into Insight
    18:05 Measuring Success Beyond Vulnerability Counts

    Visit brinqa.com for more information on how enterprises should prioritise vulnerabilities proactively.
    Vulnerability Management, Exposure Management, Cybersecurity Strategy, AI in Security, Risk Prioritisation, Brinqa, EM360Tech, The Security Strategist, Cyber Risk, Data Quality, CISO, Threat Exposure Management, Asset Visibility, IT Security, Risk Reduction, James Walta
  • The Security Strategist

    Why CISOs Struggle to Explain Cyber Risk to the Board

    2026/08/07 | 23 mins.
    Every CISO out there faces one key challenge: the challenge of getting the board to acknowledge cybersecurity as a top enterprise risk management priority.
    According to the ClearPoint Strategy Strategic Planning Report, only 51 per cent of active strategic and corporate projects maintain a steady Green status. The remaining 49 per cent fluctuate between Amber and Red, requiring varying levels of intervention.
    This goes to show that many investment decisions are reliant on red, amber and green dashboards and not on financial exposure. According to Mike Saxton, CRO at MyCiso, the issue relates to cyber reporting often lacking portability. “A director may be highly experienced and commercially sophisticated, but still struggle to compare risk posture between organisations because the underlying reporting models are inconsistent.”
    With AI also in the picture now, the speed and scale of attacks is rapidly rising; that gap is becoming harder to defend.
    This is why in the recent episode of The Security Strategist podcast, E360Tech’s host Shubhangi Dua, Tech Journalist and Podcast Producer, was joined by Asdrúbal Pichardo, CEO at Squalify, 3x SaaS CEO, Board Advisor, Start-Up Mentor, Non-Executive Director.
    This podcast breaks down how to actually turn technical risk into something the rest of the business can realistically manage, measure, and report on.
    Translating Cyber Risk for the Boardroom: A CISO’s Guide to Financial Quantification
    Pichardo says when it comes to cyber risk, it's time to avoid reporting based on qualitative metrics; instead, portray more quantitative metrics. This means really talking to the executives and the boards in the language of business “which is money.”
    "CISOs need to rely less on qualitative assessments. They need to translate the cyber risk into financial figures so the board will understand the implications of cyber."
    CISOs typically present cyber risk through technical metrics, maturity scores and vulnerability reports, but boardrooms tend to avoid making decisions based on technical language. This is why translating that cybersecurity technical jargon into metrics is essential for boardrooms. They think in terms of financial exposure, business resilience and return on investment (ROI).
    The CEO of Squalify explains why the future of cybersecurity leadership depends less on explaining threats and more on quantifying business impact. He puts up a case for enterprises requiring a common language that is comprehensible by both security teams and executives instead of relying on technical dashboard data.
    Leveraging AI Vulnerability Detection: The Strategic Advantage of Mythos
    Artificial intelligence (AI) has made it more complex from every corner. AI-driven cyber attacks are on the rise. On the other side, AI is being deployed by defenders to protect their platforms as well as to optimise the speed and effectiveness of AI tools and integrate it into their workflows. Ultimately, AI has, for better or worse, blurred the line between cybersecurity, governance and business continuity.
    To put into perspective, Dua asked Pichardo about Anthropic's Mythos model’s incredible vulnerabilities-spotting capabilities. He said that Mythos is causing a lot of dialogue in the industry right now, but the vulnerability-discovering capabilities had existed for years, and those tools went unnoticed.
    While industry individuals may be concerned about attackers taking advantage of AI tools like Mythos, enterprises should be able to access the same technology to identify and fix those weaknesses before attackers exploit them. However, geopolitical tensions and other economic disparities have made it hard for enterprises to access.
    The key idea is that defenders have an advantage because they know their own systems. He says, “The hacker doesn't have the knowledge, or the source code from your enterprise. You already have it, so enterprises need to get there with Mythos before the hacker comes to you with Mythos.”
    The issue he spotlights is that American companies have been given access to Mythos, but the US government has restricted access outside of the nation.
    “At the end it should it should it should get into the right hands because it's probably already in the wrong hands,” the CEO states.
    The conversation around Anthropic’s Mythos model depicts a shift in the enterprise tech and cybersecurity industry. While much of the discussion has focused on how attackers might exploit increasingly capable AI, Pichardo sees the greater opportunity for defenders.
    Also Read: Fraud Tops CEO Cyber Concerns as Ransomware Attacks Continue to Surge
    Converting Cyber Risk into Strategic Investment
    For boardrooms, the new question they must pose is whether enterprises are optimising AI quickly, efficiently, and, most of all, safely to minimise risks before adversaries get to it. The recent cyberattack by a rogue OpenAI AI model on Hugging Face was an eye-opener for all. In a worst-case scenario, imagine if the hackers’ AI agents began penetrating secure enterprise tech platforms at a rate that’s hard to fend off their strikes.
    AI has moved from being a technical capability to a strategic investment decision one that should be measured in business impact rather than technology adoption.
    “If you can demonstrate that the likelihood of experiencing a disruption because of AI is higher in numbers, that will change the minds of any boardroom. This applies to any industry, from public sector and banking, financial, manufacturing, defence, energy,” notes Pichardo.
    He added that at Squalify’s mother company, Munich Re, the world's largest cyber reinsurer ensures that AI’s impact on cyber risk is visible not only from a technical perspective but a business perspective as well.
    "It goes beyond tech or IT; it's processes, governance, business operations.”
    Ultimately, enterprises need to quantify cyber risk so they are better able to defend against the AI-driven threat landscape at any given time.
    Takeaways
    Cyber risk quantification is becoming a boardroom necessity
    AI is increasing attack velocity, not just sophistication
    Defensive AI can create a competitive advantage
    Cyber and AI risk are converging into enterprise risk
    Board AI literacy is becoming a strategic capability

    Chapters
    00:00 Understanding Cyber Risk in Business
    02:42 The Differences in Cyber Risk Management: US vs Europe
    05:42 The Evolution of Risk Management with AI
    08:46 Quantifying Cyber Risk: The Role of Squalify
    11:34 Real-World Applications: Onboarding Clients at Squalify
    14:53 The Importance of Financial Metrics in Cybersecurity
    17:38 AI's Impact on Cybersecurity and Business Operations
    20:20 The Future of AI in Cyber Risk Management
    23:32 Key Takeaways for CISOs and Board Members

    Watch the full episode of The Security Strategist Podcast to hear Asdrúbal Pichardo discuss cyber risk quantification, AI governance, boardroom communication and what enterprise leaders should prioritise next.
  • The Security Strategist

    Can Runtime Security Keep Autonomous AI Under Control?

    2026/08/03 | 26 mins.
    The one key thing that could aid enterprise success in the agentic AI cybersecurity space today is its ability to understand agents' intent. It’s easy to state but hard to convert into an actionable security strategy.
    This is why in the recent episode of The Security Strategist podcast, host John Tolbert is joined by Dror Zelber, VP Product Marketing at Radware and Dhanesh Ramachandran, Product Marketing Manager at Radware. They got together to discuss the emerging challenges of agentic AI security and how to tackle it realistically.
    More specifically, they break down what it actually means to secure AI agents, whether they are interacting with internet-facing applications on behalf of users or operating within enterprise environments, emphasising the importance of behavioural monitoring and visibility in managing AI agent interactions.
    The conversation further spotlighted the need for enterprises to establish trust and governance frameworks for AI agents while prioritising security budgets and strategies.
    Also Watch: Unmasking the Invisible Threat: Defend Your APIs Before Attackers Do
    Takeaways
    Agentic AI introduces new security challenges compared to traditional applications.
    The attack surface for AI agents is significantly broader and easier to exploit.
    Behavioural monitoring is crucial for understanding AI agent actions and intent.
    Enterprises must prioritise visibility into AI agent activity.
    Trust and identity verification are key challenges in the agentic era.
    CISOs should allocate budgets for AI security solutions early in the deployment process.
    Strict policies and governance are necessary for deploying AI agents.
    Monitoring and auditing are essential to prevent unauthorised actions by agents.
    Enterprises need to distinguish between beneficial and risky AI agent behaviour.
    The future of security lies in enabling beneficial AI interactions while maintaining safeguards.

    Chapters
    00:00 Introduction to Agentic AI Security
    01:25 Emerging Security Challenges with Agentic AI
    05:37 Traditional Security Measures vs. Agentic AI
    10:44 Current Activity of AI Agents in Enterprises
    14:29 Distinguishing Beneficial vs. Risky AI Agent Activity
    17:13 Establishing Agent Identity and Authority
    23:18 Priorities for CISOs in the Agentic Era

    Watch the full episode for complete insights on autonomous AI agents, the future of AI cybersecurity and how enterprises can effectively manage risky AI agent behaviour while still taking advantage of the agentic technology. For further information, visit radware.com.
  • The Security Strategist

    How Do You Govern AI Agents in Real Time?

    2026/07/30 | 21 mins.
    Autonomous AI agents are becoming a part of most enterprise workflows today. But how are enterprises protecting their platforms from rogue agents? For instance, the recent attack on Hugging Face was discovered to be carried out by an OpenAI rogue AI model that escaped testing from a secure environment.
    To answer how best enterprises can protect themselves from unique, unpredictable attacks by upcoming technologies such as rogue AI agents, Sagi Rodin, CEO and Co-Founder of Agen.co by Frontegg, joins host Alejandro Leal, Lead Analyst at Kuppinger Cole Analysts firm, on an episode of The Security Strategist podcast.
    They talk about the constantly changing nature of AI agent governance, identity management, and security in enterprise environments.
    They further explore how autonomous AI agents challenge traditional security models and what strategies enterprises need to adopt to stay secure.
    What is Agen.co?
    When asked about the dynamics of AI agents and how they individually carry risk, the focus seems to be moving to governance of specific actions in real-time. Instead of relying on the agent's initial authentication status, agents are going beyond identity to “per-action” governance.
    Rodin puts it into context: “We [Frontegg] released Agen.co, a product that governs runtime agentic activity. We take an identity-first approach by connecting to identity providers, agent repositories, and user directories. In addition to managing users, we now maintain a registry of AI agents.”
    The goal is to connect all those principles and manage unique identities in an enterprise. These include conventional automated machines, human users, user-controlled AI agents, autonomous AI agents that run on their own post-deployment, as well as malicious bots that need to be identified quickly and blocked. Rodin said that Frontegg is bringing all of those identities together under a single governance model.
    How to Stop AI Agent-Driven Malicious Actions in Real-Time?
    As an identity-native platform that connects to the IDP, the agent repository and user repositories, Agen.co by Frontegg has become a registry for agents.
    “The industry has a broken mental model today,” Rodin tells Leal. When asked why, he said that while identity tools pose the question of identity, they may not ask the purpose of entry. That means an agent with valid credentials passes every identity check. It’s called “role-based access”, originally designed for humans.
    An agent conducts thousands of actions per day, but each of those actions carries a risk. This is why individual governance of each action by those AI agents is critical. This is why Agen.co provides a very quick verdict in under thirty milliseconds to avoid obstructing workflows while stopping malicious actions in real-time.
    “We must operate on the runtime side because an agent can bypass static gates established during login or registration,” Rodin says. “We need to be present the moment an agent accesses organisational data, attempts a prompt, or executes a potentially damaging command, like 'rm -rf' on an endpoint.”
    Simply granting an agent a ticket at registration is insufficient to keep up with the dynamic and fast-paced scale of modern agent operations.
    While enterprises cannot be obstacles in the path of automation, they can use a platform to operate extremely quickly and efficiently to stop threats from occurring.
    As AI agents adapt with more autonomous capabilities and proliferate across departments in an enterprise, be it engineering, finance or marketing, these AI agents act without clear ownership.
    Rodin says there shouldn’t be any agents running without a named human owner. He says that with governance, enterprises must take accountability.
    “Every single action needs to be traced back to a person. AI agents don't get a pass on ownership.”
    “When the regulator, the board, or the department owner asks who was responsible for this action, at the end of the day you need a name, so this is a core principle we impose for our AI native activity,” he added.
    Takeaways
    Identity verifies who; runtime governance verifies every action.
    Identity proves who—runtime proves what's safe.
    Every AI agent action needs its own security decision.
    Static IAM can't govern autonomous AI behaviour.
    Every enterprise AI agent needs a named owner.
    Agent governance is becoming a runtime security challenge.

    Chapters
    00:00 Introduction to AI Agents and Security Challenges
    06:23 The Shift from Identity to Behaviour in Security
    10:09 The Importance of Continuous Validation
    16:09 Accountability in the Age of Autonomous Agents
    20:19 Key Takeaways for Security Leaders
  • The Security Strategist

    Is Your SOC Below the AI Poverty Line?

    2026/07/20 | 26 mins.
    The future of inequality in cybersecurity has been coming to light since the beginning of the AI evolution. Greg Notch, the Chief Technology Officer (CTO) at Expel, recently predicted that the “AI poverty line” is projected to be more severe than the traditional security line.
    "The AI poverty line will be even crazier in some ways because you will either have the ability to understand and wield AI properly or you will not,” he stated. “That gulf is going to be interesting."
    In the recent episode of The Security Strategist podcast, host Brad LaPorte, Gartner Veteran and Advisor at Lionfish Tech Advisors, sat down with Greg Notch, CTO at Expel, to address the impact of AI on security operations. They discuss the AI poverty line and lay out a plan for how enterprises can adapt to the rapid pace of change introduced by AI.
    They also explore the balance between automation and human oversight, trust versus impact, and future trends in AI-driven security.
    What is the AI Poverty Line?
    According to Notch, the AI poverty line is the growing divide between security capabilities and one’s ability to effectively optimise AI.
    While a security poverty line has existed for a long time, an AI version will begin appearing. It could be more complex and niche. Security teams may face difficulties defining their roles and responsibilities, and only those who can wield AI skillfully and effectively.
    For instance, he alludes to an example of a large tech enterprise such as CrowdStrike, Palo Alto or even Microsoft. As a large enterprise employing AI-skilled professionals, “you would want to leverage as much of that as you can because your head count is is is limited. If you can't hire enough people to manage the operation, you may have to outsource that” to an AI-skilled professional.
    However, with attackers' increasing sophistication, the enterprise should be capable of equally able to detect and responding to vulnerabilities. This is why automation alone is not enough.
    A resilient cybersecurity strategy requires a team equipped to use AI-backed security tools to actively monitor, manage, and respond to threats, using automation. This should help human decisions rather than replace them with a bot.
    Also Read: What Is AI Value Management and Why Are Enterprises Suddenly Prioritising It?
    Where Does AI Belong in the Security Operations Centre (SOC)?
    AI and automation ultimately exist to aid Security Operations Centre (SOC) teams. Its capabilities allow assistance to human analysts, acting autonomously and contribute to how enterprises can effectively optimise AI to boost their security posture.
    Both LaPorte and Notch agree that the role of AI in SOC is collaborative. It’s a hybrid model where humans maintain control.
    LaPorte takes the example of a motorcycle, stating it’s like a motorcycle “with a sidecar.” “The human is riding the motorcycle, but the AI is along for the ride. It adds additional capability, additional storage and functionality.
    “It's a new world, but it's a hybrid world."
    While Notch rhetorically questions whether a SOC is needed. He asks the audience to imagine a scenario without SOC analysts. It’s not possible even if it’s intermediated by AI. “I believe we’ll have more humans in the loop.”
    Why Automation is Essential?
    As attackers become more sophisticated in their threat intelligence strategies, enterprises too have to keep up. That means they too need to leverage automation capabilities of AI.
    Some easy actions that can be automated without human intervention are to block known malicious IPs or contain compromised devices. This becomes extremely crucial during high-stakes situations where time is of the essence.
    Automation is essential to address two primary business and operational challenges – mitigating the risk of active attackers and resolving the inefficiency caused by alert fatigue.
    Notch argues that the risk of failing to stop an active attack outweighs the risks associated with introducing automation into the environment. "All security leadership decisions should be grounded in risk.”
    Security leadership should think about “what is the risk of not doing a particular task versus the risk of doing it? For instance, automation.”
    “We're accepting different risks, but we believe the risk of not being able to stop an active attacker in our environment is worth that. That's the trade-off you have to make,” Notch tells LaPorte.
    Where Expel comes in?
    Notch describes Expel's approach as a solution for security operations—specifically pertinent to auto-remediation before AI was a thing.
    Expel launched an auto-remediation feature about seven or eight years ago based on heuristics. It wasn't driven by AI back then. It was unclear whether Expel’s customers would adopt it, as trust had to be established before adoption.
    Notch explains that's because customers had to be comfortable letting a third-party security provider automatically take actions. For instance, letting the party isolate infected laptops, shutting down compromised cloud systems, stopping malicious programs, and responding to attacks without waiting for someone from the company to approve it.
    Expel discovered that customers were willing to trust this automation because it could stop attacks much faster than waiting for a person within the company to act.
    Today, many enterprises would rather let the system stop or contain an attack immediately and investigate what happened afterwards.
    By understanding where AI can effectively assist or act autonomously, enterprises can enhance their cybersecurity posture while managing risks.
    The key is to develop a thoughtful approach that balances automation with human expertise, ensuring that AI serves as a powerful ally in the fight against cyber threats.
    Watch the podcast on em360tech.com for a deeper understanding and expert thought leadership insights.
    For further information, visit expel.com.
    Takeaways
    AI is transforming the speed and nature of cyber attacks.
    Automation in security must be balanced with human oversight.
    Trust is crucial when implementing AI in security operations.
    AI can enhance detection but requires careful implementation.
    The future of SOCs will involve more human-AI collaboration.
    Organisations must adapt to the evolving threat landscape.
    False positives remain a significant challenge in SOCs.
    AI can help streamline operations but is not a silver bullet.
    Security decisions should be grounded in risk management.
    The hype around AI in cybersecurity often oversells its capabilities.

    Chapters
    00:00 Introduction to AI in Cybersecurity
    03:03 The Speed of AI-Driven Attacks
    06:00 Automation and Trust in Security Operations
    09:01 AI's Role: Acting Alone vs. Assisting
    12:00 The Future of AI in Security Operations
    14:46 The Hype vs. Reality of AI in SOCs
    17:59 Navigating the AI Landscape in Cybersecurity
    20:51 Conclusion and Key Takeaways

    Cybersecurity, AI in Cybersecurity, SOC, Security Operations Centre, Expel, Greg Notch, Brad LaPorte, AI Poverty Line, Cyber Defence, Automated Security, Threat Intelligence, Security Leadership, Risk Management, Human-in-the-loop AI, Enterprise Cyber Strategy
    #AIPovertyLine #Cybersecurity #SOC #AISecurity #TheSecurityStrategist #InfoSec #Expel #EnterpriseSecurity
More Business podcasts
About The Security Strategist
With cyber attacks more common than ever before and each attack becoming increasingly sophisticated, security teams need to be one step ahead of cybercrime at all times. “The Security Strategist” podcast delves into the depths of the cybercriminal underworld, revealing practical strategies to keep you one step ahead. We dissect the latest trends and threats in cybersecurity, providing insights and expect-backed solutions to protect your organisation effectively. Tune into this cybersecurity podcast as we dissect major threats, explore emerging trends, and share proven prevention strategies to fortify your defences.
Podcast website

Listen to The Security Strategist, The Diary Of A CEO with Steven Bartlett and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features
The Security Strategist: Podcasts in Family