AI is accelerating attacks faster than most defenders can adapt, but the surprise is how little of that acceleration is actually new. Dustin Brown joins Owahn Bazydlo and Paul Marco for a wide-ranging conversation about agentic AI, third-party risk, critical infrastructure, and why the fundamentals still decide who wins.
The episode opens with a striking finding from the 2026 Verizon Data Breach Investigations Report: less than 2.5% of AI-assisted malware observations involve rare techniques with one or fewer known malware examples, indicating that AI is currently accelerating known attack methods rather than unlocking novel ones. The panel turns that number into practical reality. Dustin, a Texas-based technology leader working across IoT and critical infrastructure, brings a defender's eye to the space where the physical and digital layers meet, while Owahn and Paul draw the line from commodity exploits to enterprise exposure.
You'll discover why agent-driven commerce is reshaping the risk surface, with an estimated 10% of transactions already originating from agents and projections pointing toward 90% within a year. The group unpacks why third-party and fourth-party risk questionnaires have become an operational burden on small and mid-market firms, why trust portals are emerging as a smarter path to vendor transparency, and why the SOC 2 attestation process forces the kind of vendor discipline most organizations delay far too long.
Paul and Owahn then widen the lens into the reality of what Dustin calls vibe-coded "plastic apps," the security debt they generate, and why AI functions as a force multiplier that rewards skilled hands and punishes unskilled ones. The conversation examines how attackers are simply running old playbooks at machine speed and machine volume, why obscurity as security no longer holds, and how observability, asset knowledge, and disciplined patching remain the durable foundation beneath every new wave of tooling.
Dustin, Owahn, and Paul also dig into the deeper shift underneath all of it: the human trade of agency for convenience, the cultural gap in AI literacy, and the growing need for personal security awareness at the same level enterprises have long demanded. It is a practical reminder that cybersecurity outcomes still trace back to intent, discipline, and preparation, no matter how capable the tools become.
Essential listening if you care about AI-enabled threats, third-party risk, critical infrastructure, or the future of agentic systems inside the business. If you are responsible for protecting people, systems, or data, this conversation gives you both the urgency and the perspective to think more clearly about what comes next.
https://www.talas.io/podcast