Rob Hughes returns to Behind the Shield for his second appearance, making him the show’s first returning guest. This episode picks up in the middle of a year defined by rapid change, especially across AI, cybersecurity, identity, and federal compliance. Rob joins the InfusionPoints team for a wide-ranging conversation about how security leaders are thinking through the speed, scale, and uncertainty being introduced by AI, and what that means for organizations trying to keep pace without losing control.
The discussion explores how AI is reshaping vulnerability management, identity security, social engineering, data governance, and security culture. Rob shares perspective on how security teams are evaluating AI’s impact in real environments, including how AI can help prioritize vulnerabilities, assess risk faster, and surface issues that may have previously taken much longer to identify. At the same time, the group digs into the challenges AI introduces, including AI agents, non-human identities, permission creep, unclear data retention, model transparency, and the rise of shadow AI.
A major theme throughout the episode is that AI may be new, but many of the security fundamentals still matter more than ever. Strong identity controls, clean data, least privilege, layered defense, human accountability, and clear governance all become even more important when AI can move quickly, access large amounts of information, and operate across systems. Rob also discusses what good security culture looks like inside a company built around security, and why organizations need to educate employees on responsible AI use without stifling innovation.
The conversation also turns toward FedRAMP 20x and the broader federal authorization landscape. Rob and the team discuss how trust, automation, 3PAO expectations, agency adoption, and ATO challenges are evolving as the federal market looks for faster, more scalable ways to evaluate cloud security. From AI risk to FedRAMP 20x, this episode looks at what is changing, what still needs to be solved, and how security leaders can prepare for what comes next.
What You’ll Learn:
• Why AI is accelerating the pace of change across cybersecurity
• How AI is changing vulnerability discovery, analysis, and prioritization
• What security teams should consider when evaluating AI agents in the enterprise
• Why identity, permissions, and non-human identities are becoming even more critical
• How shadow AI creates new risks around data visibility, retention, and control
• Why security culture still depends on people, not just tools
• How organizations can encourage AI adoption without ignoring risk
• What good security culture looks like inside a company built around security
• Why FedRAMP 20x is forcing new conversations about trust, automation, and accountability
• Where agencies, vendors, and 3PAOs may still be struggling with authorization expectations
• What needs to improve to make ATOs more accessible, repeatable, and scalable
Chapters:
0:09 - AI Overview
1:55 - Rapid Change
10:14 - Identity Management
12:54 - Social Engineering
20:45 - Government Security
28:17 - Data Transparency
32:19 - AI Ethics
36:56 - Robotics
41:57 - Human Trust
49:49 - Authorization Process
55:41 - Shadow AI
Guest Links:
https://www.linkedin.com/in/robert-hughes-816067a4/
https://www.linkedin.com/company/rsasecurity/
https://www.rsa.com/
Learn more about InfusionPoints:
https://www.linkedin.com/company/infusionpoints/
Jason Shropshire: https://www.linkedin.com/in/shrop/
Mike Strohecker: https://www.linkedin.com/in/michael-strohecker-238326172/
Request a Demo: https://xbu40.com/
FedRAMP 20x Quick Look Assessment: https://xbu40.com/assessment
InfusionPoints & AWS:
InfusionPoints is proud to be an Amazon Web Services Premier Tier Services Partner, supporting organizations in building, managing, and defending secure cloud environments.
About Us:
InfusionPoints is a trusted cybersecurity, cloud engineering, and compliance partner helping organizations Build, Manage, and Defend secure, mission-ready environments in highly regulated markets.
We specialize in FedRAMP, FedRAMP 20x, DoD, and enterprise security frameworks, supporting organizations from initial authorization through continuous monitoring and optimization. Our team brings deep technical expertise and real-world operational insight to every engagement.
Through our independent, security-first approach, we integrate people, processes, and technology to deliver scalable, compliant, and resilient solutions. From strategy and architecture to operations and defense, we help customers move faster without sacrificing security.