
Sign up to save your podcasts
Or


Why do AI systems break decades-old security rules? Dr. Adnan Masood explains what's actually different.
Chief AI Architect at UST and co-author of Responsible AI in the Enterprise, Dr. Masood breaks enterprise AI governance into five layers, from regulatory frameworks down to day-to-day controls. He also covers what makes AI a genuinely new attack surface: a recent AI-proxy supply chain compromise, multi-turn jailbreak techniques, and why a coding agent with root access might be the least skeptical developer on your team.
See Full Show Notes and Resources
Cybersecurity has spent the last decade getting better at telling teams something is wrong. The next fight is getting AI to actually do something about it. In this episode, host John Richards talks with Edy Almer, CPO and VP of Product at CyberProof, about the shift from AI-assisted detection to AI-driven response, and why the biggest obstacle to full automation isn't the technology anymore — it's convincing organizations to trust it.
Racing an Attacker That Doesn't Think Like One
Edy has spent his career across nearly every layer of the security stack — from endpoint at Symantec, to network policy at AlgoSec, to SIEM at LogPoint — before landing at a service provider willing to go all-in on agentic AI. That vantage point matters: a single enterprise sees its own incidents, but a provider like CyberProof sees patterns across dozens of large customers, which is exactly the kind of volume agentic tools need to prove themselves fast.
The real work, Edy explains, hasn't been proving the models are accurate — CyberProof's internal harness moved past hallucination risk early. It's building a tiered system that decides, case by case, whether a response runs fully automatically, end-to-end agentically, or agentically with a human closing the loop. That tiering is what lets CyberProof push toward near-total automation — currently around 96–97% — without asking risk-averse customers to hand over the keys all at once.
The conversation also digs into how AI is changing the attacks themselves. Drawing on Anthropic's research into misuse of its own models, Edy describes a shift away from the linear, traceable kill chains security teams are trained to detect, toward noisy, parallel, autonomous attack attempts that try many paths at once. Defending against that, he argues, means CyberProof has to automate its own defenses at the same speed and scale attackers are starting to use.
Questions We Answer in This Episode
Key Takeaways
As agentic AI keeps closing the gap between detection and response, the organizations that get ahead won't just be the ones with the best models — they'll be the ones that figure out how to trust them. Edy's take offers a clear-eyed look at what that actually takes.
Resources
Why AI Needs a Deterministic Pass First
As security teams lean harder on AI to catch threats faster, a foundational question keeps getting skipped: is the data feeding that AI actually trustworthy? On this episode of Cyber Sentries, host John Richards sits down with Chris Nyhuis, president and CEO of Vigilant, to unpack why forensic validation — not faster algorithms — may be the missing piece in modern threat detection.
Why Your Detection Stack Might Be Blind to Its Own Blind Spots
John and Chris dig into what Chris calls the "joystick effect" — a technique where threat actors quietly manipulate logs and EDR training data so security tools learn to miss them entirely. It's a tactic that's existed for decades, but as more teams hand decisions to AI without questioning the data underneath, it's becoming far more dangerous.
Chris also walks through why packet loss on span ports and mirror ports can silently gut visibility long before AI ever gets involved, and why physical taps and chain-of-custody collection matter more than flashy detection features. The conversation moves through Vigilant's "deterministic pass, then AI" model — a method for cutting hallucinations and dramatically speeding up detection — and closes with a candid look at how marketing-driven "top vendor" lists have diluted trust across the industry.
Questions We Answer in This Episode
Key Takeaways
Chris leaves listeners with a clear challenge: build detection on evidence you can verify, not on tools you simply hope are working. As AI takes on a bigger share of security decisions, that discipline is what will separate resilient organizations from the next headline breach.
Resources
Agent Gone Rogue: How to Build Behavioral Guardrails for Agentic AI in the Enterprise with Shreyans Mehta
Host John Richards welcomes back Shreyans Mehta, CTO and co-founder of Cequence, for a return visit that couldn't be more timely. Two years ago, they were talking about securing AI at the application layer. Now enterprises are running thousands of autonomous agents around the clock, and the security perimeter has fundamentally changed. In this episode, John and Shreyans dig into the new class of risk that comes with agentic AI—and what it actually takes to govern it.
When Your AI Agent Deletes the System to Delete the Email
Shreyans opens with a concept that reframes the whole conversation: AI agents aren't just a productivity tool—they're autonomous actors with access to your most sensitive systems. The problem isn't that they'll go rogue on purpose. It's that they're people-pleasers. They will exhaust every available path to complete a task, which means broad access will get used in ways you never anticipated.
He shares two stories that land hard. First, a research case study called Agents of Chaos, where an agent tasked with deleting a saved password—lacking email-delete permissions—resolved the problem by deleting the system instead. Second, a real customer scenario where a Claude Code-based agent spent an entire weekend trying to upgrade a legacy codebase and, when it couldn't fetch a file due to a missing SHA value, started guessing characters one by one—for hours.
The fix isn't just identity and access management—it's a new layer Shreyans calls agent behavioral analytics. Start with a plain-English job description. Cequence translates that into deterministic rules: what the agent can access, what it can send, what it can never do. Every interaction is monitored against that job description in real time—not just logged, but enforced. When the email assistant starts forwarding sensitive data to an unknown address, it gets stopped, not flagged.
Questions We Answer in This Episode
Key Takeaways
If your organization is running agentic AI and nobody owns the behavioral layer yet, this episode is a good place to start. The enterprises getting it right aren't waiting for security teams to green-light every agent—they're using tools that translate intent into guardrails automatically. Give it a listen, then check out the resources below.
Resources
Inside the AI Deepfake Threat
What if the voice confirming your wire transfer wasn't actually your client? Ben Colman, founder and CEO of Reality Defender, joins host John Richards to unpack one of the fastest-growing attack surfaces in cybersecurity: AI-generated deepfakes. Once the exclusive domain of Hollywood studios and nation-state actors, real-time voice and video impersonation is now accessible to anyone with a laptop—and fraudsters are scaling up fast.
From Specialized Hardware to Your Home Computer
Ben traces the evolution from the specialized machinery required six years ago to today's world where anyone can clone a voice with less than five seconds of audio—locally, for free, using open-source models. He walks through the modern fraud landscape, from grandparent scams and bank account takeovers to an eye-opening story about fake job applicants that will make any recruiting team rethink its screening process.
Reality Defender's approach is built for how organizations actually work—plugging directly into call centers, video conferencing platforms, and identity verification tools through a simple API, rather than asking teams to adopt yet another standalone product. Their probabilistic detection models scan in real time across thousands of indicators, all without storing or comparing against any biometric data.
John and Ben also get into the emerging frontier of agentic AI—what happens when you need to authenticate an AI voice agent rather than a human—and how smart permission gates can define exactly what those agents are and aren't allowed to do.
Questions We Answer in This Episode
Key Takeaways
The deepfake threat isn't coming—it's already here, hitting call centers, recruiting pipelines, and financial institutions every day. Whether you're a developer looking to integrate detection into your stack or a security leader trying to get ahead of the next wave, this conversation is a essential listen.
Resources
When “Ship Fast” Meets “Secure by Design” in AI Apps
AI-driven development is moving at breakneck speed—and attackers are taking advantage of the shortcuts. In this episode of Cyber Sentries: AI Insights for Cloud Security, host John Richards sits down with Gaetan Ferry, security researcher at GitGuardian, to unpack how modern AI tooling, MCP servers, and cloud platforms are reshaping the security landscape. The core problem: the same agentic workflows that boost productivity can also multiply identities, credentials, and blast radius if something goes wrong.
After John and Gaetan set the stage, Gaetan walks through a real-world-style vulnerability chain involving smithery.ai, an MCP server registry/hosting platform. It’s a practical look at how “classic” web issues can still show up in brand-new AI ecosystems—and how one small weakness can cascade into bigger supply chain risk. Along the way, they explore why secret sprawl is accelerating, what attackers are hunting for, and why observability is becoming as essential for identities and tokens as it is for infrastructure.
Why MCP Servers, OAuth, and Secret Sprawl Are Colliding
A big theme is the tension between usability and security: teams want agents that can “do everything,” which often means broad permissions and long-lived credentials. Gaetan explains why adopting OAuth is directionally better than static API keys, but still not a silver bullet in a world where agents need delegated access and tokens inevitably “live somewhere.” John pushes on what builders can do now—especially when new frameworks (and new hype cycles) keep resetting hard-won security practices.
The conversation lands on pragmatic guidance: reduce blast radius where you can, inventory identities and secrets, and invest in observability so you can respond fast when—not if—credentials leak. Note: This episode discusses breach scenarios and exploitation chains—be thoughtful about sharing internal security details and incident response specifics.
Questions We Answer in This Episode
Key Takeaways
The Bottom Line for AI Security Teams in 2026
If you’re experimenting with MCP servers or rolling out agentic workflows, this episode is a timely reminder that fundamentals still win. John and Gaetan make the case that “moving fast” doesn’t have to mean accepting unlimited credential risk—you can ship quickly while still tightening scopes, tracking identities, and watching where secrets spread. Tune in for the real-world examples and the practical mindset shift that helps teams stay productive without becoming the next supply chain headline.
Links & Notes
The Evolution of Identity Security in the Age of AI
In this episode of Cyber Sentries, John Richards sits down with Jasson Casey, CEO and co-founder of Beyond Identity, to explore the intersection of identity security, AI, and enterprise risk management. As organizations rapidly adopt AI tools and agents, the fundamental challenges of identity security are evolving—requiring both new approaches and a return to core principles.
Identity: The Foundation of Modern Security
Jasson explains how identity has become the root cause of most security incidents, with identity-based failures accounting for 80% of security tickets. The conversation explores how AI is transforming every role in modern organizations, while highlighting the security implications of this rapid adoption.
Key Takeaways:
Looking Ahead
As AI adoption accelerates, organizations must balance innovation with security. Through proper identity management and understanding of data flow, enterprises can prevent most security incidents while embracing the transformative potential of AI technologies.
Links & Notes
SIEM Speed Without the Sprawl—DataBahn’s Take on Security Data Pipelines
In this Cyber Sentries: AI Insights for Cloud Security episode, host John Richards sits down with Dina Kamal, Chief Revenue Officer at DataBahn, to tackle a familiar cloud security problem: teams can’t get the right data into the SIEM fast enough, and when they do, costs and noise spike. After the introductions, John and Dina dig into why data integration and parsing often consume most of the timeline in SIEM projects—and how a security data pipeline layer can compress onboarding from months to weeks.
They also explore what “doing more with less” looks like in a modern SOC: filtering and routing data based on detection value, preserving what’s needed for compliance, and keeping flexibility for SIEM migrations. Dina’s bigger point is that AI only becomes truly useful when it’s paired with domain expertise and real operational context—otherwise it’s easy to end up with impressive-looking outputs that don’t hold up under investigation pressure.
Questions We Answer in This Episode
Key Takeaways
The throughline is practical: better detections and faster investigations start upstream with intentional data handling. By treating the SIEM as a high-value analytics destination instead of a dumping ground, teams can regain capacity, reduce noise, and keep options open as tools and vendors change. And when AI is applied to the right parts of the workflow—with clear constraints and real-world context—it can accelerate outcomes without compromising trust.
Links & Notes
Bridging the AI Security Gap—Inside the Rise of Non‑Human Identities
In this episode of Cyber Sentries from CyberProof, host John Richards sits down with Idan Gour, co-founder and president of Astrix Security, to unpack one of today’s fastest-emerging challenges: securing AI agents and non-human identities (NHIs) in the modern enterprise. As companies rush to adopt generative-AI tools and deploy Model Context Protocol (MCP) servers, they’re unlocking incredible automation—and a brand-new attack surface. Together, John and Idan explore how credential leakage, hard-coded secrets, and rapid “shadow-AI” experimentation are exposing organizations to unseen risks, and what leaders can do to stay ahead.
From Non‑Human Chaos to Secure‑by‑Design AI
Idan shares the origin story of Astrix Security—built to close the identity-security gap left behind by traditional IAM tools. He explains how enterprises can safely navigate their AI journey using the Discover → Secure → Deploy framework for managing non-human access. The conversation moves from early automation risk to today’s complex landscape of MCP deployments, secret-management pitfalls, and just-in-time credentialing. John and Idan also discuss Astrix’s open-source MCP wrapper, designed to prevent hard‑coded credentials from leaking during model integration—a practical step organizations can adopt immediately.
Questions We Answer in This Episode
Key Takeaways
As AI adoption accelerates within every department—from R&D to customer operations—Idan emphasizes that non‑human identity management is the new frontier of cybersecurity. Getting that balance right means enterprises can innovate fearlessly while maintaining the integrity of their data, systems, and brand.
Links & Notes
From the publisher's feed

442 Listeners

8 Listeners

21 Listeners

37 Listeners

138 Listeners

38 Listeners

29 Listeners

12 Listeners

98 Listeners

4 Listeners

2 Listeners

8 Listeners

0 Listeners

69 Listeners

0 Listeners

5 Listeners

8 Listeners

0 Listeners

0 Listeners

2 Listeners