
Sign up to save your podcasts
Or


Recorded live at Black Hat 2026, this episode features Sarah Gosler, Managing Director and Head of Cyber Resiliency and Human Defense at Wells Fargo. Sarah explains why humans are the largest attack surface and how—when AI has industrialized social engineering and cybersecurity is an "everybody problem"—the role of the CISO has shifted to encompass both the technical and the operational. Sarah makes the case that the more automated attacks get, the more the human side of defense matters.
Before Wells Fargo, Sarah was Global Head of Cyber Human Defense and Readiness Products at BNY Mellon, where she built the firm's first commercial cyber product and earned two patents for a dynamic wargaming system. A former chief marketing officer, she brings a user-experience lens to cyber defense and is a featured cast member in Semperis’ new documentary Midnight in the War Room.
Guest Bio
As Managing Director and Head of Cyber Resiliency & Human Defense at Wells Fargo, Sarah leads initiatives that strengthen how the firm prepares for and responds to cyber incidents. She integrates advanced wargaming, human defense strategy, and behavioral science to enhance institutional coordination, executive decision-making, and organizational performance under stress.
Previously, at the Bank of New York, she built and scaled the firm’s global Cyber Human Defense program and pioneered its first commercial cyber readiness product, earning two patents in cyber wargaming and advancing industry approaches to social engineering resilience.
Sarah is a frequent keynote speaker, media contributor, and published author of white papers on the psychological and organizational dimensions of cyber risk. She is widely recognized for bridging technical resilience with executive leadership and dynamics — shaping how financial institutions address cyber as both a technological and human challenge.
With more than two decades at the intersection of finance, technology, and organizational performance, Sarah continues to influence the global conversation on institutional resilience, crisis leadership, and the evolving human front line of cyber defense.
Guest Quote
Time stamps
Sponsor
Links
Connect with Sean on LinkedIn
Don't miss future episodes
Learn more about Semperis
Midnight in the War Room tells the story of cyber defenders on the front lines. See this pioneering documentary at an upcoming screening near you: https://www.semperis.com/midnight-in-the-war-room/events/
This episode features Wylie Shanks, a cybersecurity consultant who leads an OT cybersecurity program for a large North American energy company's business unit.
Wylie has spent more than twenty-five years working with critical infrastructure organizations, designing, defending, and recovering environments that span enterprise IT through industrial control systems. In this conversation, he walks Sean Deuby through the Purdue model level by level, then explains what changed when Windows servers, domain controllers, and vendor-managed accounts moved into environments built to run for decades without interruption.
Wylie and Sean cover why safety and availability outrank everything else on the plant floor, why MFA and patch cycles that work in IT can be unworkable in OT, how forest architectures set up twenty years ago constrain organizations today, and how new resilience mandates in the US and Canada are pushing operators to prove they can run disconnected for 90 days.
This episode makes the case that OT security is less about importing IT controls than about translating between two groups of experts who have never had to speak the same language.
Guest Bio
Wylie Shanks is a cybersecurity consultant who currently leads an OT cybersecurity program for a large North American energy company's business unit. With over twenty-five years of experience working with critical infrastructure organizations, he designs, defends, and recovers environments spanning enterprise IT to industrial control systems. His expertise spans security architecture, incident response, privileged access management, and cyber risk management, translating complex challenges into practical, auditable solutions. Wylie holds numerous certifications, including GIAC Security Expert (GSE), ISSAP, GIAC Response in Industrial Defense (GRID), and GIAC Cyber Incident Leader (GCIL).
Guest Quote
"Safety, of course, is critical. That's one of the differences between, say, an IT and an OT environment is in OT, there can be lives at stake. The environment can be impacted. You have different concerns about reliability and safety."
Time stamps
02:40 Meet Wylie Shanks: 25 Years in Critical Infrastructure
04:59 Defining the OT Environment
05:51 Walking Through the Purdue Model
08:45 Explaining OT with a Thermostat
12:11 Ranking Safety, Reliability, and Integrity
13:39 Revisiting Stuxnet
15:21 Why MFA Breaks on the Plant Floor
18:36 Finding Windows and Active Directory in OT
21:29 Applying PAM and Least Privilege
27:14 Comparing AD Forest Architectures
31:19 Earning Trust with Plant Operators
35:41 Meeting New Resilience Mandates
40:49 Mapping the Threat Vectors
44:49 Facing AI-Assisted Attacks
47:41 Learning from Colonial Pipeline
53:15 Making Resilience Measurable
56:42 Conclusion and Final Thoughts
Sponsor
The HIP Podcast is brought to you by Semperis, the leader in identity-driven cyber resilience for the hybrid enterprise. Trusted by the world's leading businesses, Semperis protects critical Active Directory and Entra ID environments from cyberattacks, ensuring rapid recovery and business continuity when every second counts. Visit semperis.com to learn more.
Links
Connect with Wylie on LinkedIn
Connect with Sean on LinkedIn
Don't miss future episodes
Learn more about Semperis
This episode features Marc Jason Grens, President of Chaintrax.
Marc has led Chaintrax for twelve years, growing it from a compliance and anti-money-laundering firm in cash-to-crypto services into a licensed blockchain forensics practice after entering the ransomware payment business in 2017. He has since advised on more than 4,000 incidents.
In this episode, Marc explains why ransomware victims decide to pay, why that payment can violate US sanctions law if it isn't vetted first, and why tracking the money afterward is how law enforcement works to recover it.
This episode makes the case that paying a ransom is only the beginning of a compliance and recovery process, not the end of one.
Guest Bio
Marc Grens is the President of Chaintrax, which has been providing cutting-edge financial, technological, and consulting services for the payments and incident response industry for the last 12 years. He is a serial entrepreneur with more than 15 years of experience in the investment industry. Prior to Chaintrax, Marc held senior positions at Charles Schwab, HighTower Advisors, and Alpha Strategies. He received his M.B.A. from the Kellstadt Graduate School of Business at DePaul University in 2010, and a B.A. from Illinois State University. Marc is an active angel investor and serves on multiple advisory boards of companies in the Chicago tech community.
Sponsor
The HIP Podcast is brought to you by Semperis, the leader in identity-driven cyber resilience for the hybrid enterprise. Trusted by the world’s leading businesses, Semperis protects critical Active Directory and Entra ID environments from cyberattacks, ensuring rapid recovery and business continuity when every second counts. Visit semperis.com to learn more.
Links
Connect with Marc on LinkedIn
Connect with Sean on LinkedIn
Connect with Jeff on LinkedIn
Don't miss future episodes
Learn more about Semperis
HIP Conference 26 is coming to Nashville, September 8–10, 2026.
Join us to explore this year's theme, Redefining Resilience, at the world's premier practitioner-led conference focused on securing hybrid identity environments.
If you love the conversations on the HIP Podcast, this is where the community comes together in person. Learn more and register at https://www.hipconf.com/.
This episode features Chris Steinke, Director of Product Strategy at Semperis.
Chris has spent more than 20 years across cybersecurity, digital identity, infrastructure, and operations, including leadership roles at American Express and Early Warning Services (Zelle) and early work at MightyID, where he helped bring one of the industry's first dedicated identity resilience platforms to market.
In this episode, Chris explains why moving identity to the cloud creates a single point of failure, why backup and recovery alone aren't enough, and why the next frontier is making trust portable, so applications aren't locked to a single identity provider.
This episode reframes identity resilience as a continuity problem: not just recovering after an outage but keeping the business running through one.
Guest Bio
Today, his work focuses on the future of digital trust, including identity resilience, multi-IdP architectures, and trust portability - the next evolution in ensuring business continuity in an identity-centric world.
Guest Quote
Time stamps
Sponsor
Links
Connect with Chris on LinkedIn
Connect with Sean on LinkedIn
Don't miss future episodes
Learn more about Semperis
HIP Conference 26 is coming to Nashville, September 8–10, 2026.
Join us to explore this year's theme, Redefining Resilience, at the world's premier practitioner-led conference focused on securing hybrid identity environments.
If you love the conversations on the HIP Podcast, this is where the community comes together in person. Learn more and register at https://www.hipconf.com/.
This episode features Philip Keibler, Vice President and CISO at Meijer, one of the nation's largest privately held retailers.
With nearly three decades of security leadership, including CISO roles at Bass Pro Shops and Finish Line, Phil brings a rare long-view perspective on what the job actually requires day to day. He also talks about his feature in Semperis' upcoming documentary Midnight in the War Room, premiering at Black Hat on August 5.
In this episode, Phil explains why CISOs who struggle to get budget usually have a storytelling problem, how he defines success in a role where stopping every attack is impossible, and what it takes to lead a team through an active incident. He also dives into why fundamentals are what actually address most of an organization's risk.
This episode makes the case that the hardest parts of the CISO job are rarely technical, and that mastering the basics matters more than chasing the newest tool.
Guest Bio
As Vice President and Chief Information Security Officer at Meijer, Phil leads security for one of the nation's largest privately held retailers, overseeing the protection of supply chains, customer data, and critical operations across hundreds of locations in the Midwest.
Phil's career spans industries where the stakes are high and the margin for error is low. Before joining Meijer in 2015, he served as CISO at Bass Pro Shops and previously held the CISO role at Finish Line. Earlier in his career he led security at Herff Jones, bringing security discipline to the manufacturing sector. He began his career at EDS and spent years consulting in the Aerospace sector where he got his start in security.
What sets Phil apart is not just longevity, it is perspective. He has watched information security evolve from a reactive, audit-driven function into a proactive capability that enables business velocity. His approach centers on integrating security into how organizations operate, not as a checkbox, but as a competitive advantage that lets teams move fast while managing risk in practical ways.
Beyond the day-to-day, Phil is a passionate contributor to the broader security community. He has served as a guest lecturer on cybersecurity and data privacy at the University of Chicago Law School, sits on the Institute for Cybersecurity Education and Research Advisory Board at Grand Valley State University, serves on the IT Advisory Committee at Kent County Technical Center, and is a board member the Meijer Credit Union. He is also featured in Midnight in the War Room, a Semperis documentary examining the human reality behind enterprise cyber defense.
Phil has held his CISSP certification since 2009, attained his MBA from Davenport University, and a career's worth of operational experience across retail, aerospace, insurance, and manufacturing.
Guest Quote
Time stamps
Sponsor
Links
Connect with Sean on LinkedIn
Don't miss future episodes
Learn more about Semperis
HIP Conference 26 is coming to Nashville, September 8–10, 2026.
Join us to explore this year's theme, Redefining Resilience, at the world's premier practitioner-led conference focused on securing hybrid identity environments.
If you love the conversations on the HIP Podcast, this is where the community comes together in person. Learn more and register at https://www.hipconf.com/.
This episode features Andre Priebe, Chief Technology Officer at iC Consult Group, the world's largest independent provider of identity security services.
Andre has spent more than two decades leading IAM projects for large-scale enterprises across workforce, customer, and device identity domains. As CTO, he steers iC Consult's Centers of Excellence, service portfolio, and vendor strategy, and advises strategic customers on shaping their identity programs.
In this episode, Andre explains why the gap between identity security awareness and actual maturity is growing every day, and how AI is making it faster and easier for attackers to find the weaknesses organizations already know they have. He breaks down why recovery is the most underestimated phase of the NIST cybersecurity framework and what it really costs when organizations haven't prepared for it.
This episode is a candid look at the state of identity security from someone who sees it across hundreds of organizations every year.
Guest Bio
Andre's role involves a deep focus on emerging approaches, trends, and technologies within the IAM sector, assessing their business value for iC Consult's clientele. He is an innovator with a patent in DevOps-related IAM methodologies, and he holds a B.Sc. and an MBA.
Guest Quote
Time stamps
Sponsor
Links
Connect with Andre on LinkedIn
Connect with Sean on LinkedIn
Don't miss future episodes
Learn more about Semperis
HIP Conference 26 is coming to Nashville, September 8–10, 2026.
Join us to explore this year's theme, Redefining Resilience, at the world's premier practitioner-led conference focused on securing hybrid identity environments.
If you love the conversations on the HIP Podcast, this is where the community comes together in person. Learn more and register at https://www.hipconf.com/.
This episode features Tim Wolf, Senior Solutions Architect at Semperis, and Tim Springston, Principal Product Manager for Recovery Solutions at Semperis.
Tim Wolf spent years as a Microsoft Premier Field Engineer helping enterprise customers architect identity solutions at scale. Tim Springston brings 25 years in identity and security and served as Microsoft's product manager for Azure AD recoverability, including direct involvement in building the Entra ID shared responsibility model documentation.
In this episode, they walk through what the shared responsibility model actually means for Entra tenant data, how token-based attacks sidestep phishing-resistant authentication, and what happens when a threat actor hard-deletes objects and locks you out.
They examine where Microsoft's new Entra ID Identity Resilience Recovery feature stops short, and why planning your recovery before anything goes wrong is the only call to action that matters.
Guest Bios
Tim Wolf
Tim Springston
Guest Quotes
“If Entra ID is going down... This is business critical today. You're not available to sign in to Teams, to SharePoint, to Salesforce, to your business critical application. So to really understand Entra ID is business critical.” - Tim Wolf
Time stamps
Sponsor
Links
Connect with Tim Springston on LinkedIn
Connect with Sean on LinkedIn
Don't miss future episodes
Learn more about Semperis
This episode features Jim Bowie, VP and CISO at Tampa General Hospital, joined by co-host Courtney Guss, Director of Crisis Management at Semperis.
Jim began his career in EMS and law enforcement before moving into cybersecurity, giving him a grounded understanding of how operational continuity and human outcomes intersect during a crisis. At Tampa General, he leads teams spanning network security, operations, IAM, and GRC, and has built a training culture centered on adversarial simulation, monthly range of exercises, and regular DR drills.
In this episode, Jim argues that rehearsal is the highest-leverage move for resource-constrained security teams and explains why an outage is an outage regardless of cause. He covers why identity is consistently the weak point in every simulation and why the relationships you build before an incident are the ones that matter most.
If your organization is still treating recovery as an afterthought, this episode will change how you think about it.
Guest Bios
Jim Bowie
Courtney Guss
Guest Quote
Time stamps
Sponsor
Links
Connect with Jim on LinkedIn
Connect with Courtney on LinkedIn
Connect with Sean on LinkedIn
Don't miss future episodes
Learn more about Semperis
This episode features Geoffrey Mattson, CEO of SecureAuth, joined by co-host Sarah Cicchetti, Director of Product Management at Semperis.
Geoffrey has spent decades building and leading companies at the intersection of AI and cybersecurity, including MistNet.ai, an AI-native threat detection platform acquired by LogRhythm, and Xage Security, where he drove zero trust adoption across the U.S. military, global energy firms, and Fortune 500 enterprises. At SecureAuth, he leads a platform built around continuous, real-time identity authority across workforces, APIs, and AI agents.
In this episode, Geoffrey argues that agents combine the speed of automation with the unpredictability of humans, making real-time per-action authorization the only viable control model. He discusses why “friendly fire” from well-meaning employees is the biggest threat vector right now, how MCP vendors are ignoring their own OAuth spec, and what a practical agent rollout with real guardrails actually looks like.
This episode reframes authorization as the problem the identity industry has been deferring for years and can no longer avoid.
Guest Bio
He is currently CEO of SecureAuth, a leader in AI-driven identity and access management with its Continuous Authority, ensuring ongoing verification across workforces, customers, APIs, and AI agents. This is enabled through its Private Authority Platform, which puts authentication and authorization under your control through any deployment model (cloud, on prem, hybrid, air-gapped).
Prior to SecureAuth, Mattson served as CEO of Xage Security, where he led the company in Zero Trust for critical environments from energy to agentic AI. Under his leadership, Xage achieved rapid adoption across the U.S. military, global energy firms, and Fortune 500 enterprises.
Previously, Geoffrey Mattson was co-founder and CEO of MistNet.ai, an AI-native threat detection platform acquired by LogRhythm. He pioneered decentralized analytics and machine learning approaches for real-time cyber defense, and later served as SVP of Product at LogRhythm, driving global expansion and shaping the next generation of SIEM/SOAR solutions.
Earlier, he held senior executive roles at Juniper Networks, overseeing a $2B product portfolio and leading major M&A efforts, and at Huawei Technologies as SVP and CTO for networking and data center platforms. His engineering leadership at Corona Networks, Caspian, and Bay Networks helped build foundational technologies in network and security architecture.
Guest Quote
Time stamps
Sponsor
Links
Connect with Geoffrey on LinkedIn
Connect with Sarah on LinkedIn
Connect with Sean on LinkedIn
Don't miss future episodes
Learn more about Semperis
This episode features Mark Diodati, Managing Vice President for Identity and Access Management at Gartner.
Mark has spent two decades shaping how the industry thinks about authentication, privileged access, and cloud identity, working with renowned companies like Ping Identity, CA, RSA, and now, Gartner. Today, he leads Gartner's global IAM for Leaders analyst team and sets its research agenda across the full identity stack.
In this episode, Mark explains how Gartner's research model works and what his team is prioritizing across identity verification, authorization, ITDR, and decentralized identity. He also breaks down what AI means for identity right now and why securing AI agents is harder than most teams realize.
This episode is a deep dive into where identity is heading from someone whose job is to listen to everyone.
Guest Bio
Mark is a longtime identity pioneer who helped shape the way the industry thinks about authentication, privileged access management, and cloud identity. He leads a large team of analysts, sets the global IAM research agenda, and rigorously reviews every document to keep the bar high. Before that, he guided Gartner’s IAM research for technical professionals, chaired major industry conferences like Catalyst Europe and the Cloud Identity Summit, and drove triple-digit growth in attendance and sponsorships. Earlier in his career, he held key leadership roles at CA, RSA, and Ping Identity, influencing product strategy and partnerships that many identity practitioners rely on today.
Guest Quote
Time stamps
Sponsor
Links
Connect with Mark on LinkedIn
Connect with Sean on LinkedIn
Don't miss future episodes
Learn more about Semperis
From the publisher's feed

888 Listeners

374 Listeners

83 Listeners

651 Listeners

1,028 Listeners

65 Listeners

8,055 Listeners

41 Listeners

38 Listeners

25 Listeners

138 Listeners

15 Listeners

24 Listeners

46 Listeners

5 Listeners