Most security teams are still betting that hygiene problems and AI-scale problems live in separate categories. Nicole Beckwith, Senior Director of Security Engineering and Operations at Cribl, has seen exactly how that bet goes wrong from the inside.
Nate and Lior caught up with Nicole to talk about why the basics still break organizations faster than any AI threat, what it actually takes to secure AI agents as identities rather than tools, and where defenders are quietly getting ahead of attackers for the first time in years.
Organizations are racing to get ahead of AI-driven threats while the thing that actually takes most of them down is something mundane: a stale account, a siloed team, or a SIEM nobody's feeding properly. AI doesn't replace the need for fundamentals, it raises the stakes of skipping them, and Nicole has the breach story to prove it.
00:00 – Introduction
02:30 – Nicole Beckwith joins Do Human Work
06:30 – Why Mythos is a canary in the coal mine
09:50 – The Register story: a city water utility's ransomware breach
15:00 – Why AI agents need identity security like any employee
17:40 – Shadow AI: the new shadow IT problem
22:05 – The Cribl/7AI feedback loop and building together
27:30 – Where defenders are getting ahead
29:35 – Breaking SOC silos: intelligence, hunting, and response as one cycle
32:00 – The "push-button forensic analyst" problem, and AI's version of it
33:30 – Trust, verify, and interrogate: working with an AI investigator
37:40 – The magic wand question: what Nicole would do with 25% more time
39:20 – Lightning round questions with Nicole Beckwith
Interested in being a guest or want to recommend someone? Reach out to us at [email protected]