Great Security Debate

Great Security Debate

By The Great Security DebateSociety & CultureBusinessTechnology
Download on the App Store

Great Security Debate episodes

  • AI is Children

    With the recent disclosures that OpenAI's security testing using its own models broke out of the sandbox and attacked Hugging Face (and others), Erik, Dan, and Brian thought it was worth a moment to discuss and debate the current state of AI, securing AI models, some of the ways that organisations can isolate and test without such risks, and the implications of what could be seen as offensive (and retaliatory) attacks from a corporation.

    And, lest anyone think we are picking on OpenAI, the same thing happened in testing by Google, Anthropic, and Meta (Facebook) resulting in attacks on quite a few other companies. Yep, you're not cool in AI if you haven't tried to attack another business with your AI model. But why on earth are they all annoucing so loudly that they hacked into these other orgs? We live in interesting times, for sure.

    Thanks for watching and listening!

    Show Notes:

    • a

    Some of the links in the show notes contain affiliate links that may earn a commission should you choose to make a purchase using these links. Using these links supports The Great Security Debate and Distilling Security, so we appreciate it when you use them. We do not make our recommendations based on the availability or benefits of these affiliate links.

    50 min
  • Doorbells Ring Hollow

    What on earth were Ring and Amazon thinking when they aired their Super Bowl advert that previewed a “there’s nowhere you can hide” type of dystopian future masked as a way to find your lost dog? With cameras everywhere, are we safer or just more exposed? When camera data is deleted, is it really gone (spoiler alert: not necessarily), and more. Are we approaching the new location of the “creepy line” or as a society are we content to trade privacy for security? And what happens when the glasses with cameras become more pervasive? Are we all on cam all the time whether we like it or not?

    Show notes:

    1. Ring Super Bowl Advert - https://www.nytimes.com/2026/02/19/business/ring-super-bowl-ad-privacy.html
    2. Decoder Podcast - Let’s talk about Ring, lost dogs, and the surveillance state - https://youtu.be/QQjW68B7s8g
    3. Ring and Flock cancel partnership - https://techcrunch.com/2026/02/13/amazons-ring-cancels-partnership-with-flock-a-network-of-ai-cameras-used-by-ice-feds-and-police/
    4. Savanna Guthrie Nest Video Retrieval - https://www.theverge.com/tech/877235/nancy-guthrie-google-nest-cam-video-storage
    5. Apple San Bernardino Matter - https://epic.org/documents/apple-v-fbi-2/
    6. DJI robot vacuum cameras accessible via Internet - https://www.theverge.com/tech/879088/dji-romo-hack-vulnerability-remote-control-camera-access-mqtt
    7. Unifi protect cameras - https://geni.us/isNyY2
    8. Zuck in court to testify on social media addiction - https://apnews.com/article/mark-zuckerberg-trial-testimony-instagram-c8cbaa32ccbf4933ec3a7beebd6cf34b
    9. Glassholes are back - and forbidden in court - https://www.cbsnews.com/news/meta-trial-mark-zuckerberg-ai-glasses/
    10. Movie recommendation - Happy Gilmore - https://geni.us/v96XEgb
    11. Meta/Facebook studies on addictiveness of social media - https://www.cnn.com/2026/02/23/tech/facebook-researchers-study-addictive-features
    12. LinkedIn/Microsoft Verification data being shared with many others, including Persona -= https://thelocalstack.eu/posts/linkedin-identity-verification-privacy/

    Some of the links in the show notes contain affiliate links that may earn a commission should you choose to make a purchase using these links. Using these links supports The Great Security Debate and Distilling Security, so we appreciate it when you use them. We do not make our recommendations based on the availability or benefits of these affiliate links.

    47 min
  • Complacency in the Loop

    AI is growing in use within information security, but are we ready to trust it to do all the things we hope it can, and do so automatically without doing harm? Context is king, and training to that level is only possible when you give all your experience to the AI. What are the tradeoffs to doing so? What happens when we depend on AI and forget (or worse, never learn) the underpinnings of what makes the AI system work (remember the calculator debates of the 1980s?). And does the end justify the means when it comes to AI use? And what is that “ends” anyway? Efficiency, automation, knowledge? Erik, Dan, and Brian discuss it all in this week’s Great Security Debate!

    Show Notes

    1. Report on reasons Israel didn’t catch oct 7 attacks - https://www.npr.org/2025/03/05/nx-s1-5318591/israel-shin-bet-security-failure-october-7-attack
    2. Shin Bet Report - Source Doc (Hebrew) - https://www.documentcloud.org/documents/25551448-yqry-tkhqyr-shyrvt-hbytkhvn-hklly-710/#document/p1
    3. Waymo hits student on bicycle - https://www.theverge.com/2024/2/7/24065063/waymo-driverless-car-strikes-bicyclist-san-francisco-injuries
    4. Waymo violates school bus rules - https://www.cbsnews.com/news/waymo-recall-3000-vehicles-software-school-bus/
    5. Podcast Recommendation - Agentic Dan - https://distillingsecurity.com/episode-64-agentic-dan/
    6. TV Recommendation - Pluribus - https://tv.apple.com/us/show/pluribus/umc.cmc.37axgovs2yozlyh3c2cmwzlza
    7. Trust Issues in AI -
    8. “I bought this Tesla before Elon went crazy” magnet - https://geni.us/DXQYk
    9. OpenAI adds ads - https://apnews.com/article/chatgpt-ads-openai-advertising-83812a066375a805fa2e29b28fc77da1
    10. Satya Nadella AI Internal Memo - https://africa.businessinsider.com/news/nadellas-message-to-microsoft-execs-get-on-board-with-the-ai-grind-or-get-out/sq0fe52
    11. FDA AI Rules - https://www.fda.gov/regulatory-information/search-fda-guidance-documents/considerations-use-artificial-intelligence-support-regulatory-decision-making-drug-and-biological
    12. Utah AI Prescriptions - https://www.politico.com/news/2026/01/06/artificial-intelligence-prescribing-medications-utah-00709122
    13. Movie Recommendation: Terminator - https://geni.us/59025
    14. Book Recommendation: The Cuckoos Egg - https://geni.us/hYE9
    15. Book Recommendation: AI 2041 - https://geni.us/5dtV54h
    16. Anthropic Super Bowl Ad - Scott Galloway on why Anthropic's Super Bowl ad got to Sam ... - Fortune
    17. China facial recognition payments - https://www.chowhound.com/2073279/grocery-store-facial-recognition-china-smile-to-pay/
    18. Movie Recommendation: Sneakers - https://geni.us/P7SB
    19. The Dawn of the Post Literate Society - https://jmarriott.substack.com/p/the-dawn-of-the-post-literate-society-aa1
    20. Leading Causes of Death in the US, 2023 - https://www.cdc.gov/nchs/fastats/leading-causes-of-death.htm
    21. Automated car sex in backseat - https://dailydot.com/driverless-car-sex-autonomous
    22. Podcast Recommendation: The Final Act - https://distillingsecurity.com/new-podcast-coming-soon-the-final-act/
    23. Calculators and Children - https://www.linkedin.com/pulse/crunching-numbers-debate-over-calculator-use-math-education-church-sg6te/
    24. Podcast Recommendation: Mentorcore - https://distillingsecurity.com/tag/mentorcore/

    Some of the links in the show notes contain affiliate links that may earn a commission should you choose to make a purchase using these links. Using these links supports The Great Security Debate and Distilling Security, so we appreciate it when you use them. We do not make our recommendations based on the availability or benefits of these affiliate links.

    44 min
  • WOPR Was Right

    Recently and over the past few years, world events may have included cybersecurity components in their enactment. So, Brian, Erik, and Dan started talking about the role of security in critical infrastructure protection, asking questions about the ethics and thresholds for government and corporate roles in cyber retaliation, whether we as security practitioners have a role (or an obligation, or even a liability) to close vulnerabilities that can be used in primary or retaliatory scenarios. How much of human nature makes cyber retaliation a foregone conclusion, or can we find ways to reduce the need or use or availability of ways in via the technology. From Stuxnet to Iran to Caracas, using cybersecurity is a prevalent vector of retaliation, but does it always have to be that way? Or will it end with WOPR’s recognition that the only way to win the game is not to play at all?

    It’s hard to talk about modern cybersecurity and not bring in current events, and even harder to keep it from turning political. We tried very hard to do a good job in the latter as we talked about the former. 

    Thanks for being part of the debate!


    Show Notes:


    • Caracas Invasion - https://abcnews.go.com/International/explosions-heard-venezuelas-capital-city-caracas/story?id=128861598
    • Stuxnet Explained - https://www.csoonline.com/article/562691/stuxnet-explained-the-first-known-cyberweapon.html
    • Book Recommendation: Countdown to Zero Day: Stuxnet and the Launch of the World’s First Digital Weapon - https://geni.us/swbN
    • San Bernardino vs Apple - https://epic.org/documents/apple-v-fbi-2/
    • Movie Recommendation: Real Genius - https://geni.us/abYUYT
    • Book Recommendation: The Creature from Jekyll Island: A Second Look at the Federal Reserve - https://geni.us/SL21a
    • CIA Triad - https://cybersecuritynews.com/cia-triad-confidentiality-integrity-availability/
    • Book Recommendation: Atomic Habits - https://geni.us/Nn2GSYr
    • Michigan Council of Women in Technology -https://mcwt.org
    • Critical Infrastructure (Sectors) - https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors
    • Shadowbrokers - https://www.theatlantic.com/technology/archive/2017/05/shadow-brokers/527778/
    • AI Prescriptions (Utah) - https://www.politico.com/news/2026/01/06/artificial-intelligence-prescribing-medications-utah-00709122 
    • Japanese Omoiyari - https://www.linkedin.com/posts/herman-singh-b669357_in-japan-it-is-a-recognized-cultural-practice-activity-7408365447953272834-1op9?utm_source=share&utm_medium=member_desktop&rcm=ACoAAABlrqMBKb13DctlHfhW1OWtb-yWqdfUjnE
    • GSD Episode on Japanese Parking Culture - https://distillingsecurity.com/episode-65-signs-signs-everywhere-a-sign/
    • Book Recommendation: Plato’s Republic - https://geni.us/vLBu4
    • Movie Recommendation: Angela’s Christmas - https://geni.us/Vn9n
    • Movie Recommendation: Die Hard - https://geni.us/eMASs
    • Movie Recommendation: Wargames - https://geni.us/L2R5Ij
    • TV Recommendation: West Wing - Proportional Response - https://geni.us/9mU1k4
    • Movie Recommendation: Goldeneye - https://geni.us/0dO0b

    Some of the links in the show notes contain affiliate links that may earn a commission should you choose to make a purchase using these links. Using these links supports The Great Security Debate and Distilling Security, so we appreciate it when you use them. We do not make our recommendations based on the availability or benefits of these affiliate links.

    45 min
  • Signs, Signs. Everywhere A Sign.

    Rules are made and policies are established. But the “how” of implementing and meeting those regulations or policies will be very context specific. In this episode of the Great Security Debate, Dan, Erik, and Brian cover a number of key policies and requirements and some different ways to think about implementing them and how the specific situation, company, risk will affect the way you meet the rule. From driving a car to incident response and everything in between. We debate the need to look back at old rules and see if they all still make sense (a great programme called Kill Stupid Rules), and flexibility in control implementation to meet evolving business needs, to move quickly, and keeping the whole picture of the business, customer, and employees in mind.

    Thanks for Listening!

    Show Notes:

    1. Passing on the right in Michigan: https://legislature.mi.gov/Laws/MCL?objectName=MCL-257-637
    2. Overtake time in Triathlon: https://www.triathlete.com/training/race-tips/9-race-rules-didnt-know-breaking/
    3. Reflex Security (Agentic Tabletop Exercises and Training): https://reflexsecurity.io
    4. Kill Stupid Rules: https://www.wsb.com/blog/employee-retention-secret/
    5. GM Dress Code Change (2020): https://gmauthority.com/blog/2020/06/how-general-motors-ceo-mary-barra-changed-the-companys-dress-code-for-the-better/
    6. Silly State Rules: https://www.buzzfeed.com/rhiannacampbell/weird-old-american-laws-you-wont-believe
    7. Sex in Full Self Driving Cars (Clean): https://www.cbc.ca/news/science/sex-distracted-driving-1.3562029
    8. Movie Recommendation - The Usual Suspects: https://geni.us/wVrLOCB
    9. John Bingham, COO, Speak by Design: https://www.speakbydesign.com/about-us
    10. Movie Recommendation - Gremlins: https://geni.us/qE6NAC
    11. Movie Recommendation -Die Hard: https://geni.us/eMASs
    12. Movie Recommendation - Love Actually: https://geni.us/yj8Fqh

    Some of the links in the show notes contain affiliate links that may earn a commission should you choose to make a purchase using these links. Using these links supports The Great Security Debate and Distilling Security, so we appreciate it when you use them. We do not make our recommendations based on the availability or benefits of these affiliate links.

    55 min
  • Agentic Dan

    We are back for another Great Security Debate.

    In this episode: we discuss the potential role of agentic AI in security, from true “copilot” to automated decider of things, and whether LLMs are just a really cool search engine. Brian, Erik, and Dan also debate the means and extent to which we could replace ourselves with agents and what the inhibitors and risks are (spoiler alert: trust and survival of that agent after employment were big factors), and how do we train those agents of all the steps our brains take to make the decisions that the humans make, and do so without polluting it with aspirational versions of ourselves (think: Instagram vs Reality). And it all leads to a parenting lesson by Brian and an automotive process lesson by Erik? It’s quite a debate. 

    Thanks for listening! We might do one more episode in 2026, but if not have a wonderful holidays and a happy new year!

    Here’s the quote that Brian references at the end of the episode by Tolstoy:

    Patience is waiting. Not passively waiting. That is laziness. But to Keep going when the going is hard and slow - that is patience. The two most powerful warriors are patience and time. The value lies not in reducing "power" (computational energy) but in leveraging that processing power to achieve outcomes that are difficult, slow, or impossible for humans to manage alone.

    Thanks for listening!

    Show Notes:

    • Reflex Security - https://reflexsecurity.io
    • Movie Recommendation: Multiplicity - https://geni.us/7vgKO
    • Plaid Privacy Policy - https://plaid.com/legal/
    • Prompts.ai - https://www.prompts.ai/en
    • Music Recommendation: Take On Me - A-ha - https://www.youtube.com/watch?v=djV11Xbc914
    • Book Recommendation: The Toyota Way - Book - https://geni.us/3LcpM
    • Book Recommendation: Six Sigma - https://geni.us/CS8ql
    • Book Recommendation: Matricide - https://geni.us/Xfn2MB
    • Book Recommendation: The Lorax - https://geni.us/Fy8X4b
    • Perplexity - https://www.perplexity.ai
    • TV Recommendation - Pluribus (Apple TV+) - https://tv.apple.com/us/show/pluribus/umc.cmc.37axgovs2yozlyh3c2cmwzlza

    Some of the links in the show notes contain affiliate links that may earn a commission should you choose to make a purchase using these links. Using these links supports The Great Security Debate and Distilling Security, so we appreciate it when you use them. We do not make our recommendations based on the availability or benefits of these affiliate links.

    49 min
  • Give a Sh!t Posture Management

    On this weeks’ Debate, Brian brings a truckload of acronyms for more single panes of glass to help us consolidate our various single panes of glass, Erik may actually be Brian (or maybe Brian is Erik), and Dan confirms he still (and likely always will) spend the rest of his days living in the house he just built deep in the Trough of Disillusionment.

    What started out as a chat about some new technologies in the space turned into a treatise on the state of leadership and the future talent pipeline’s need for more curiosity (and why we think they are starved of the opportunity to learn to be curious). Along the way we talk about what motivates organisations to do security right from the get go vs leaving it alone based on difficulty to remediate, and the risk balances of both (think: productivity vs security). Throw in a little “binary opinions have dragged us into the mire” and you’ve got a full episode of The Great Security Debate.

    We also drop some hints about a new show coming from The Distilling Security network in 2026 called The Final Act which will bring guests in the later stages of their careers about the urgency of our careers in security and tech, what they want to leave behind as legacy, and what they are doing to prepare their orgs for their eventual departure. Add on how they have and will give back to the community, and what their successors want to see done before this first generation of security and tech leaders hit the road.

    Please subscribe and leave a comment.  If you’d like to sponsor the network, please email [email protected]

    Thanks for listening!

    Show Notes:

    • What is Data Security Posture Management (DSPM) - https://www.ibm.com/think/topics/data-security-posture-management
    • What is Identity Security Posture Management (ISPM) - https://www.sentinelone.com/cybersecurity-101/identity-security/identity-security-posture-management-ispm/
    • What is an Institutional Review Board (IRB) - https://www.hhs.gov/ohrp/education-and-outreach/online-education/human-research-protection-training/lesson-3-what-are-irbs/index.html
    • Lucy pulls the football (hand egg) away from Charlie Brown - https://www.youtube.com/watch?v=9dsm7K1Xkn4
    • Healthy foods are more costly - https://www.cnbc.com/2023/12/27/healthy-foods-are-often-more-expensive-heres-why.html
    • Why Ford cancelled the Bronco after OJ - https://www.slashgear.com/1560204/reason-ford-bronco-discontinued-after-oj-simpson-trial-explained/
    • Not enough data - GSD Episode 62 [Audio] - https://podcasts.apple.com/us/podcast/the-100-years-ai-flood/id1513770103?i=1000735045511
    • Not enough data - GSD Episode 62 [Video] - 
    • Book Recommendation - Anxious Generation by Jonathan Haidt - https://geni.us/lDrdn3
    • Book Recommendation - The Coddling of the American Mind by Jonathan Haidt - https://geni.us/Xqary2V
    • Ford has 5000 skilled mechanic jobs they can’t fill - https://fortune.com/2025/11/12/ford-ceo-manufacturing-jobs-trade-schools-we-are-in-trouble-in-our-country/

    Some of the links in the show notes contain affiliate links that may earn a commission should you choose to make a purchase using these links. Using these links supports The Great Security Debate and Distilling Security, so we appreciate it when you use them. We do not make our recommendations based on the availability or benefits of these affiliate links.

    55 min
  • The 100 Years AI Flood

    The Great Security Debate is *back*! It’s been a busy year, but it’s time to get this show back on the air (and maybe on the road). Dan takes a break from the rat race, Erik took over the world, and Brian uses Elmer’s Glue to splice his network cables.

    Topics in the show this week:

    • AWS and Microsoft make the best cases for business continuity plans, the AI
    • Is public cloud reliable enough? Should we all move back to local data centres? How can we reliably assess that risk?
    • Want an AI Data Centre on your town? NIMBY vs Innovation!

    We will be back every 2 weeks on Mondays. Subscribe on YouTube at https://youtube.com/@greatsecuritydebate to see our smiling faces as you watch, or in your favourite podcast application to listen on your commute or with your whole family around the radio.

    See you on the 17th with more debates! And some entirely new shows coming from Distilling Security very soon, too. Subscribe to the newsletter on our website https://distillingsecurity.com to hear all about them

    Links to mentioned articles and topics:

    • AWS Outage - 20 October 2025 - https://www.bbc.com/news/articles/cev1en9077ro
    • Microsoft Azure Outage - https://www.wsj.com/tech/microsoft-hit-with-azure-365-outage-b3ac0724
    • 37Signals move from AWS to Data Centre - https://world.hey.com/dhh/our-cloud-exit-savings-will-now-top-ten-million-over-five-years-c7d9b5bd
    • 100 Years Flood - usgs.gov - https://www.usgs.gov/water-science-school/science/100-year-flood
    • Great Flood of 1937 - https://www.weather.gov/lmk/flood_37
    • Impact of Jaguar Land Rover Incident - https://www.bbc.com/news/articles/c0qpl0v3gnzo
    • CDK Attack and Outage - https://www.industryweek.com/technology-and-iiot/article/55091142/major-cybersecurity-breach-affects-auto-manufacturers
    • Russian grain blockade against Ukraine - https://www.cfr.org/article/how-ukraine-overcame-russias-grain-blockade
    • Saline, Michigan OpenAI Data Centre & Pushback - https://apnews.com/article/openai-inc-joi-harris-data-management-and-storage-microsoft-corp-oracle-corp-f25196fca5865ed79d94c972249a272c
    • Racine, Wisconsin Foxconn and Microsoft site failures - https://racinecountyeye.com/2025/10/08/microsoft-abandon-1st-caledonia/
    • Racine, Wisconsin What happened to FoxConn? https://www.nbcchicago.com/news/local/what-happened-to-foxconn-a-look-at-the-1-2-billion-spent-and-where-it-all-went/3759518/
    • Gartner Hype Cycle - https://www.gartner.com/en/research/methodologies/gartner-hype-cycle

    48 min
  • Risky Risks: Live from the GTS Security Summit

    The Great Security Debate crew recorded a live episode at the GTS Security Summit in Detroit, Michigan with special guest, Zah Gonzalvo, SVP of Financial, Climate, and Operational Risk at Banco Popular. Tune in for a great discussion on risk, risk mitigation, risk prioritisation, and risk in context. Yep, it's all about risk!

    Takeaways:

    • The evolution of security has shifted from a binary perspective to a more nuanced understanding of risk management, acknowledging the need for flexibility in addressing diverse security challenges.
    • In contemporary discussions, it is increasingly evident that security must be integrated into business strategy, highlighting the imperative for security professionals to communicate effectively with stakeholders.
    • The role of the Chief Information Security Officer (CISO) has transcended traditional technological boundaries, necessitating a comprehensive grasp of business risk and operational efficiency.
    • Effective risk management within organizations requires a shared responsibility model, where every employee contributes to the overall security posture, thus reinforcing the concept that security is a collective endeavor.
    • Scenario analysis is a potent tool in risk management, enabling organizations to anticipate potential threats and understand the implications of various risk scenarios on their operations.
    • Engaging with business units to contextualize security risks in terms of operational impact and financial implications is vital for securing necessary budgets and resources for security initiatives.

    48 min
  • Fantasy Hacker League

    In this episode of The Great Security Debate, Dan, Brian and Erik invent (and copyright) the idea of a Fantasy Hacker League then dig into more serious discussions on deception technology, asset discovery challenges, and resource management. The conversation also delves into the impact of budget constraints on security projects, the mental toll on cybersecurity professionals, and the evolving role of CISOs in digital transformation. Issues such as job stress, burnout, and role mismatches among security leaders are addressed, alongside strategic insights on integrating security within broader business operations.

    00:00 Introduction to the Great Security Debate

    00:39 Humorous Take on Hacker Recruitment

    03:16 Fantasy Hacker League Concept

    09:18 Microsoft's Honeypot Strategy

    22:58 Challenges in Security Budgets and Resources

    31:03 The Reality of Full-Time Positions

    31:31 Introverts vs. Extroverts in Leadership

    32:06 The Challenges of Being a CISO

    33:53 Work-Life Balance and Stress

    37:04 The Role of Security in Business

    39:36 The Future of Security Leadership

    41:00 Adapting to Economic Constraints

    59:28 The Importance of Enjoying Your Work

    01:00:26 Conclusion and Farewell

    1 hr 3 min

About Great Security Debate

From the publisher's feed

Two CISOs and a security-minded friend discuss and debate topics of security and privacy, with a focus on looking at the topic from various angles, both that they support and those they don't.