
Sign up to save your podcasts
Or


When your app's "brain" is a non-deterministic LLM and your agents can roam autonomously, who owns security — and can you even secure the beehive?
Alex Belotsky sits down with Peter Holcomb, founder and CEO of Optimo IT, for a classically-trained CISO's field guide to deploying AI in regulated enterprises. Peter walks through starting with an AI governance and maturity assessment before writing a line of code, the crawl-walk-run path from Microsoft Copilot to custom agents, and why messy, unclassified data (across OneDrive, S3, Azure blobs) is the real blocker — solved with a data enclave and the medallion (bronze/silver/gold) framework. The conversation digs into the concrete new attack surface: model risk across Anthropic, OpenAI, Gemini and open-source models, prompt injection, vector-database and API risks, and the rise of "shadow AI" — including autonomous tools like OpenClaw/Clawbot pulling unvetted third-party skills and triggering infostealer infections. Peter argues human-in-the-loop is still the best available brake, sketches a "unified agentic mesh" pulling together DSPM, DLP, SOAR (Tines, Torq, BlinkOps) and CNAPP tooling (Wiz, Aqua, Orca), and makes the case for zero-trust agent identity with short time-to-live machine identities. They close on a spirited debate over recursive self-coding, hallucination-as-a-feature, whether Claude is "conscious," and how far off real AGI actually is. Practical, opinionated and grounded in what regulated businesses are actually facing right now.
**In this episode:**
**Guest:** Peter Holcomb — Founder & CEO, Optimo IT
> "Security is like the brakes to a fast driving car where you allow the car to run and go fast, but you have the brakes on there so that you can go around the corners in a good speed and not derail the whole car and go off the boundaries."
🎧 *Subscribe to Ctrl-Alt-Deploy on Apple Podcasts, Spotify and YouTube for conversations on building and shipping reliable AI to production, QA, testing and AI governance.*
## Hashtags
By Automation CyborgWhen your app's "brain" is a non-deterministic LLM and your agents can roam autonomously, who owns security — and can you even secure the beehive?
Alex Belotsky sits down with Peter Holcomb, founder and CEO of Optimo IT, for a classically-trained CISO's field guide to deploying AI in regulated enterprises. Peter walks through starting with an AI governance and maturity assessment before writing a line of code, the crawl-walk-run path from Microsoft Copilot to custom agents, and why messy, unclassified data (across OneDrive, S3, Azure blobs) is the real blocker — solved with a data enclave and the medallion (bronze/silver/gold) framework. The conversation digs into the concrete new attack surface: model risk across Anthropic, OpenAI, Gemini and open-source models, prompt injection, vector-database and API risks, and the rise of "shadow AI" — including autonomous tools like OpenClaw/Clawbot pulling unvetted third-party skills and triggering infostealer infections. Peter argues human-in-the-loop is still the best available brake, sketches a "unified agentic mesh" pulling together DSPM, DLP, SOAR (Tines, Torq, BlinkOps) and CNAPP tooling (Wiz, Aqua, Orca), and makes the case for zero-trust agent identity with short time-to-live machine identities. They close on a spirited debate over recursive self-coding, hallucination-as-a-feature, whether Claude is "conscious," and how far off real AGI actually is. Practical, opinionated and grounded in what regulated businesses are actually facing right now.
**In this episode:**
**Guest:** Peter Holcomb — Founder & CEO, Optimo IT
> "Security is like the brakes to a fast driving car where you allow the car to run and go fast, but you have the brakes on there so that you can go around the corners in a good speed and not derail the whole car and go off the boundaries."
🎧 *Subscribe to Ctrl-Alt-Deploy on Apple Podcasts, Spotify and YouTube for conversations on building and shipping reliable AI to production, QA, testing and AI governance.*
## Hashtags