Redefining CyberSecurity

Redefining CyberSecurity

By Sean Martin, ITSPmagazineBusinessTechnologyEducation
Download on the App Store

Redefining CyberSecurity episodes

  • Who's Managing Your Agent Workforce? (And Whose Budget Are They On?) | Lens Four by Sean Martin | Read by TAPE9

    Every major enterprise platform this quarter β€” Salesforce Headless 360, Workday Agent System of Record, Microsoft Copilot Studio, SAP Joule, Oracle agentic, ServiceNow Moveworks, IBM watsonx Orchestrate β€” is pitching a control plane for your AI agents. But none of them is solving the real problem: who inside your organization actually owns the agent workforce, and who's steering it at the speed agents now act?

    In this edition of Lens Four,

    πŸ” In this episode:

    β€” Why Workday's line β€” "Organizations wouldn't hire thousands of employees without an HR system to manage them. The same discipline is now required for AI agents" β€” exposes the HR-procurement collision everyone is about to run into

    β€” Gartner's forecast: by the end of 2026, 40% of enterprise applications will be integrated with task-specific AI agents, up from less than 5% in 2025

    β€” Why Jensen Huang's CES 2025 line β€” "IT is the HR department of agentic AI in the future" β€” is half-right, half-wrong, and why Josh Bersin's reframe (HR teams will be the managers and caretakers of AI agents) gets closer

    β€” Bain and IDC agreeing that per-seat pricing is ending: by 2028, 70% of software vendors will refactor pricing around consumption, outcomes, or organizational capability β€” and what that means for the CEO's agenda

    β€” The contingent workforce market is real money ($171.5B in 2021, projected to $465.2B by 2031 per Allied Market Research) β€” and why the contingent-labor playbook is the closest analogy for agents

    β€” Aaron Levie's "tokenmaxxing" as the strategic-prioritization problem nobody is ready for

    β€” Why the three vendor vocabularies (employee, contractor, software) are all task vocabularies β€” and why the agent era needs a judgment vocabulary instead

    β€” The Fourth Lens: the collision between HR and procurement can go two ways (meteor or dressing), but the real steering question lives upstairs with the CEO, COO, and line-of-business leaders

    Fourth Lens: The forced consolidation coming over the next twelve to eighteen months solves the plumbing. It doesn't solve the operating model. The organizations that win the next decade of enterprise work will build both the function downstairs that runs the agent roster and the leadership cadence upstairs that sets direction at machine speed.

    πŸ”— Full article and references: seanmartin.com/lens-four/whos-managing-your-agent-workforce

    πŸ“§ Subscribe to Lens Four: seanmartin.com/lens-four

    πŸŽ™ Redefining CyberSecurity Podcast: redefiningcybersecuritypodcast.com

    🎧 Music Evolves Podcast: musicevolvespodcast.com

    🌐 ITSPmagazine: itspmagazine.com

    🎬 Studio C60: studioc60.com

    Sean Martin is a cybersecurity market analyst, content strategist, and go-to-market advisor with more than 30 years of experience across engineering, product development, marketing, and media. He is co-founder of ITSPmagazine (itspmagazine.com) and Studio C60 (studioc60.com), host of the Redefining CyberSecurity Podcast (redefiningcybersecuritypodcast.com) and Music Evolves Podcast (musicevolvespodcast.com), and co-host of On Location (itspmagazine.com/on-location) and Random and Unscripted (randomandunscripted.com). Learn more at seanmartin.com.

    πŸ”Ž Keywords: AI agents, agentic AI, digital workforce, Salesforce Headless 360, Agentforce, AgentExchange, Workday Agent System of Record, ASOR, Salesforce TDX 2026, Aaron Levie, Marc Benioff, Joe Inzerillo, Jensen Huang, Josh Bersin, Jorge Amar, Kate Leggett, Gartner AI agents forecast, IDC FutureScape 2026, Forrester agentic AI, Bain SaaS pricing, Deloitte workforce planning, KPMG total workforce planning, McKinsey hybrid workforce, Futurum sameness, Model Context Protocol, MCP, contingent workforce, ManpowerGroup TAPFIN, Allied Market Research, outcome-based pricing, consumption-based pricing, per-seat obsolescence, tokenmaxxing, CapEx vs OpEx AI, systemic HR, superagents, digital employees, HR-procurement collision, total talent management, workforce orchestration, CEO strategic intent, line-of-business leadership, employee vs contractor classification, Sean Martin, Lens Four

    32 min
  • DriveThru Hacking: When Your Dashcam Becomes the Attack Vector | A Redefining CyberSecurity Podcast Conversation with Alina Tan and George Chen

    β¬₯EPISODE NOTESβ¬₯

    What if the device quietly recording your daily commute could be turned against you in the time it takes to order a burger? That is not a hypothetical -- it is a demonstrated reality. Alina Tan, Security Architect and Co-Founder of HE&T Security Labs, and George Chen, Security Architect for a large global company, have spent years dissecting the attack surface of connected vehicle peripherals. Their research -- presented at SecTor and Black Hat Asia 2025 -- introduces a novel attack technique they call "DriveThru Hacking": an automated method for compromising dashcams through Wi-Fi within a standard drive-through window.

    The attack is unsettling in its simplicity. Most dashcams ship with default or easily guessable credentials, and many manufacturers do not even allow users to change them. Within a six-minute exposure window, Alina and George's tool -- DriveThru Hacker -- can discover, connect to, and exfiltrate video, audio, and GPS data from a target dashcam, then use an LLM to stitch together a timeline of the owner's home, workplace, daily routes, and private conversations. The result is a shockingly detailed picture of someone's life, assembled entirely from a device most people never think to secure.

    The research goes further than individual privacy. George walks through how 4G/5G-connected dashcams dramatically expand the attack surface beyond physical proximity -- opening doors to remote credential stuffing, API privilege escalation, and web-based attacks on cloud-connected accounts. More alarming still, Alina and George demonstrate how compromised dashcams can be converted into a mobile botnet -- a network of roaming, internet-connected nodes whose reach is not bounded by geography. Unlike static IoT devices, these infected cameras move through cities, near sensitive installations, and into places that are deliberately obscured from public maps.

    The conversation also digs into the broader ecosystem: the infotainment network and CAN bus segmentation (or lack thereof), over-the-air firmware update security, the challenge of detection and response when dashcams have no audit logs whatsoever, and what responsible disclosure looked like when contacting over a dozen manufacturers -- most of whom had no dedicated security inbox and some of whom had no contact information at all. Alina and George close with practical hardening recommendations for both consumers and manufacturers, and a look at what intrusion prevention for embedded devices might look like as this research continues.

    The connected car conversation has long focused on the vehicle itself. This episode makes the case that the accessories attached to it deserve equal scrutiny -- and that the window to act, like the drive-through line, is shorter than most realize.

    β¬₯GUESTSβ¬₯

    Alina Tan, Security Architect and Co-Founder at HE&T Security Labs | Website: https://www.heatsecuritylabs.com/

    George Chen, Security Architect for a large global company | On LinkedIn: https://www.linkedin.com/in/geoc/

    β¬₯HOSTβ¬₯

    Sean Martin, Co-Founder at ITSPmagazine, Studio C60, and Host of Redefining CyberSecurity Podcast & Music Evolves Podcast | Website: https://www.seanmartin.com/

    β¬₯RESOURCESβ¬₯

    HE&T Security Labs | https://www.heatsecuritylabs.com/

    DriveThru Hacking Session (Black Hat Asia 2025) | https://blackhat.com/asia-25/sponsored-sessions/schedule/index.html#drivethru-hacking-45214

    The Future of Cybersecurity Newsletter | https://www.linkedin.com/newsletters/7108625890296614912/

    More Redefining CyberSecurity Podcast episodes | https://www.seanmartin.com/redefining-cybersecurity-podcast

    Redefining CyberSecurity Podcast on YouTube | https://www.youtube.com/playlist?list=PLnYu0psdcllS9aVGdiakVss9u7xgYDKYq

    β¬₯ADDITIONAL INFORMATIONβ¬₯

    Redefining CyberSecurity Podcast | https://www.seanmartin.com/redefining-cybersecurity-podcast

    Redefining CyberSecurity on YouTube | https://www.youtube.com/playlist?list=PLnYu0psdcllS9aVGdiakVss9u7xgYDKYq

    The Future of Cybersecurity Newsletter | https://itspm.ag/future-of-cybersecurity

    Connect with Sean Martin | https://www.seanmartin.com/

    β¬₯KEYWORDSβ¬₯

    alina tan, george chen, he&t security labs, sean martin, dashcam security, connected vehicle cybersecurity, iot security, vehicle privacy, drivethru hacking, wi-fi hacking, mobile botnet, automotive cybersecurity, firmware security, over-the-air updates, credential stuffing, redefining cybersecurity, cybersecurity podcast, redefining cybersecurity podcast

    32 min
  • You're Still Reading the Advisory. The Attacker Already Left. | Lens Four by Sean Martin | Read by TAPE9

    When Anthropic announced Project Glasswing, the headline was the capability: an AI model that found a 27-year-old flaw in OpenBSD and a 17-year-old remote code execution vulnerability in FreeBSD β€” fully autonomously, no human in the loop after the initial prompt. But the story underneath the capability is a structural one about who gets early intelligence, who sets the disclosure timeline, and what happens to every organization that wasn't in the room.

    In this edition of Lens Four, Sean Martin examines Project Glasswing through three lenses: the intelligence asymmetry it creates for security programs, what it reveals about the broken assumptions underneath CVE, CVSS, and NIST, and why the equity framing in Glasswing's messaging doesn't survive contact with the data.

    πŸ” In this episode:

    • Why the 12 Glasswing partners are operating with fundamentally different intelligence than everyone else β€” not eventually, but today
    • The precise claim: patches flow downstream to everyone, but self-scanning access, pre-public intelligence, and disclosure timeline influence stay inside the coalition
    • How Mythos chains five CVEs into a novel exploit in under 24 hours β€” and why CVSS has no score for that
    • Why NIST's draft Cyber AI Profile was built before anyone outside Anthropic knew what Mythos could do
    • Casey Ellis of Bugcrowd on the terrain Glasswing can't reach: forgotten firmware, end-of-life routers, the places the industry stopped looking
    • Ed Skoudis of SANS on what it means that AI will surpass all human vulnerability researchers combined within months
    • The Anthropic-DoD standoff and the geopolitical dimension of a Western-only coalition
    • The CSA, SANS, and OWASP joint briefing: 250 CISOs saying the frameworks are already inadequate
    • Fourth Lens: The CVE system was built on human-speed assumptions. CVSS was built on single-flaw assumptions. NIST frameworks were built on governance-speed assumptions. Every one of them was already under pressure. Now they're under pressure from a model that broke them at machine speed. The question worth asking: when the next model crosses this threshold, will the answer to "who gets the defense first" still be determined by who was already at the table?

      πŸ”— Full article and references

      πŸŽ™ Redefining CyberSecurity Podcast
      πŸ“§ Subscribe to Lens Four

      Sean Martin is a cybersecurity market analyst, content strategist, and go-to-market advisor with more than 30 years of experience. He is co-founder of ITSPmagazine and Studio C60, host of the Redefining CyberSecurity Podcast and Music Evolves Podcast, and co-host of On Location and Random and Unscripted.

      πŸŽ™ Keywords: Project Glasswing, Claude Mythos, Anthropic, AI vulnerability discovery, zero-day vulnerabilities, intelligence asymmetry, CVE, CVSS, NIST IR 8596, responsible disclosure, cyber inequity, CrowdStrike 2026 Global Threat Report, WEF Global Cybersecurity Outlook 2026, open-source security, critical infrastructure, autonomous exploit chaining, breakout time, nation-state cyber threats, AI safety, AI governance, CISO, patch management, Casey Ellis, Bugcrowd, Ed Skoudis, SANS Technology Institute, Cloud Security Alliance, OWASP, Sean Martin, ITSPmagazine, Lens Four

      16 min
    • You Shot the Arrow. The Bow Went With It. | Lens Four by Sean Martin | Read by TAPE9

      The marketing problem in cybersecurity isn't a character problem. It's a system problem. In this edition of Lens Four, Sean Martin examines how the credibility debt accumulates, what it costs the security leaders trying to make good decisions, and what vendors, buyers, and the market need to do differently.

      πŸ” In this episode:

      A Forrester analyst β€” on location at a major industry conference β€” looked around at six hundred booths and wondered whether every vendor had used the same AI model to produce their marketing. That's not a style critique. That's a signal failure

      Security leaders confirm the same frustration independently: the less a vendor's message connects to the job, the less likely it connects to the business β€” and the CISO can't translate what the vendor never gave them

      Two security leaders describe their organizations viewing security as a compliance function β€” stay compliant, stay out of the news, keep the infrastructure running β€” not as part of how the business grows

      Marco Ciappelli on the observation that hasn't changed since 2012: they're still selling the box β€” this year the box has an AI badge on it

      How lead generation metrics create a systematic incentive to overclaim β€” not because the people doing it don't know better, but because the system doesn't reward them for knowing better

      One vendor instructed their booth team that AI had to be part of every conversation β€” regardless of whether the person in front of them had asked about AI, needed AI, or would ever use AI

      Theresa Lanowitz on the binary the market created: full throttle AI or full stop β€” and why neither is the correct approach

      Joe Carson on the differentiation collapse: everybody says they can help you secure your AI agents, but there's not a whole lot of differentiation

      The arrow and the bow: why releasing both at once means you can't shoot again β€” the next real message has nothing to travel on

      The boy who cried wolf didn't fail on the first cry β€” he failed on the last one

      The Task by Task parallel: credibility comes back the same way it left β€” one honest message at a time, one proof point instead of a promise, one use case that actually sounds like the buyer's environment

      Fourth Lens: The industry is spending down the credibility budget that the next real innovation will need. Every overclaim today is a withdrawal from the account that tomorrow's legitimate warning depends on. The path back works the same way the debt accumulated β€” not through a grand repositioning, but incrementally: one honest message at a time, one specific outcome instead of a superlative, one proof point instead of a promise. Start small. Aim toward an outcome. Build from there.

      πŸŽ™οΈ Conversations referenced in this article:

      Madelein van der Hout, Senior Analyst, Forrester β€” On Location RSAC Conference 2026

      Theresa Lanowitz, Cybersecurity Evangelist and Thought Leader β€” On Location RSAC Conference 2026

      Joe Carson, Chief Security Evangelist and Advisory CISO β€” On Location RSAC Conference 2026

      πŸ”— Full article and references: seanmartin.com/lens-four/you-shot-the-arrow-the-bow-went-with-it

      🌐 RSAC 2026 coverage: itspmagazine.com/rsac26

      Sean Martin is a cybersecurity market analyst, content strategist, and advisor with 30+ years across engineering, product development, marketing, and media. Co-founder of ITSPmagazine and Studio C60, host of the Redefining CyberSecurity Podcast and the Music Evolves Podcast. Connect at seanmartin.com.

      Subscribe to Lens Four β€” Where business, innovation, and messaging come into focus.

      🎯 Keywords: cybersecurity marketing, vendor messaging, credibility debt, agentic AI hype, go-to-market strategy, CISO communication, security program investment, technology overclaiming, lead generation metrics, security outcomes vs. features, cybersecurity industry narrative, signal vs. noise, buyer trust erosion, Zero Trust messaging, SIEM evolution, SOAR overpromise, XDR consolidation, agentic AI claims, security vendor differentiation, cybersecurity branding, Madelein van der Hout, Forrester, Theresa Lanowitz, Joe Carson, Marco Ciappelli, ITSPmagazine, Studio C60, Redefining CyberSecurity Podcast, Lens Four, Sean Martin, TAPE9

      16 min
    • Order of Operations: The Foundation Risk Healthcare AI Is Running Past | Lens Four by Sean Martin | Read by TAPE9

      Healthcare's AI ambition and its data infrastructure are moving at different speeds. In this edition of Lens Four, Sean Martin examines what happens when those speeds collide β€” and who is accountable when the sequence is wrong.

      πŸ” In this episode:

      • 82% of health systems have limited or no AI governance in place, while deployments proceed β€” Digital Medicine Society
      • 58% of frontline clinical staff are using unsanctioned AI tools β€” not out of recklessness, but because approved alternatives don't exist β€” Wolters Kluwer
      • The vendor trust gap: trusted vendors are shipping AI capabilities into integrated products after contracts are signed, after integrations are built, after due diligence has closed β€” and most health systems have no mechanism to detect it
      • Jason Kor of HITRUST on what procurement processes aren't built to catch β€” recorded for the Redefining CyberSecurity Podcast
      • The Stryker attack: a nation-state operation that disrupted hospitals through their supplier β€” not their own systems
      • Ryan Patrick of HITRUST on why availability of services now sits in the same risk tier as confidentiality of data
      • Who actually owns the patient's data β€” the provider, the insurer, the vendor, the device manufacturer, the government program, or the patient?
      • TEFCA β€” the Trusted Exchange Framework and Common Agreement β€” moves data nationally across eleven Qualified Health Information Networks. It does not move the ownership rights with it
      • The CMS agenda: $1.7 trillion, 160 million Americans, and a policy clock that does not wait for the identity infrastructure to catch up
      • The vocabulary of transformation β€” what "pilot to production" and "scale" are selecting for, and what they are leaving out
      • Zero Trust reframed as the infrastructure condition that makes trustworthy AI deployment possible β€” not just a ransomware defense
      • Fourth Lens: Healthcare's AI ambition and its data infrastructure are moving at different speeds β€” and the patient is where those speeds collide. The program layer is making sequence choices. The market layer is accelerating pressure. The messaging layer is optimizing for ambition. None of it is an argument against innovation. All of it is an argument for discipline β€” A-to-Z, every dependency, ambiguity, and fragility along the way.

        πŸŽ™οΈ Podcast conversations referenced in this article:

        • Jason Kor, HITRUST β€” Brand Spotlight
        • Ryan Patrick, HITRUST β€” HIMSS Recap
        • πŸ”— Full article and references: seanmartin.com/lens-four

          🌐 HIMSS26 coverage: itspmagazine.com

          Sean Martin is a cybersecurity market analyst, content strategist, and advisor with 30+ years across engineering, product development, marketing, and media. Co-founder of ITSPmagazine and Studio C60, host of the Redefining CyberSecurity Podcast and the Music Evolves Podcast. Connect at seanmartin.com.

          Subscribe to Lens Four β€” Where business, innovation, and messaging come into focus.

          🎯 Keywords: healthcare AI governance, order of operations AI, data foundation healthcare, vendor trust gap, patient data ownership, TEFCA, health information exchange, QHINs, Shadow AI healthcare, third-party risk management, supply chain resilience healthcare, Zero Trust healthcare, CMS interoperability framework, CIA triad healthcare, data integrity AI, identity management healthcare, HITRUST, Jason Kor, Ryan Patrick, Wolters Kluwer, Digital Medicine Society, DiMe, Google for Health, Jon McNeill, John Halamka, Mayo Clinic Platform, Sumbul Ahmad Desai, Apple Health, Daymond John, Dr. Mehmet Oz, Amy Gleason, Kim Brandt, DOGE healthcare, Stryker cyberattack, nation-state healthcare attack, HIMSS26, Redefining CyberSecurity Podcast, Lens Four, Sean Martin, ITSPmagazine

          21 min
        • When AI Touches Everything: Operationalizing the Five Most Dangerous New Attack Techniques at RSAC 2026 | A Redefining CyberSecurity Podcast Conversation with Ed Skoudis, President of SANS Technology Institute and Founder & CEO of Counter Hack
          Show Notes

          For ten years, Ed Skoudis has curated one of the most anticipated sessions at RSA Conference: SANS' "Five Most Dangerous New Attack Techniques: Crucial Tips for Defenders." The session has always been a hit -- standing room only on the main stage -- but this year, Ed says something has changed. Not one or two topics with an AI component. All five.

          Ed is deliberate about how the session comes together. He starts with people, not topics. He builds the panel around SANS instructors who bring front-line insight, and he starts the process six months out. This year's panel features returning panelist Heather Mahalik, Rob Teeley back for his second year, Joshua Wright in his second year -- this time carrying two topics and eight minutes instead of six -- and, making his first appearance on this stage, Robert M. Lee of Dragos, one of the world's foremost voices on ICS and OT security.

          The addition of "Crucial Tips for Defenders" to the title this year was intentional. Ed pushed every panelist to move beyond naming threats and toward prescribing action -- practical, implementable steps that a CISO can hand down and a practitioner can execute the next morning. For topics where prevention is impossible, the mandate shifted to detection and response. SANS publishes session notes to their website within minutes of the talk ending.

          The backdrop this year is a warning Ed calls unlike anything in his 30 years of attending RSA and DEF CON. At a recent AI cybersecurity conference in San Francisco, presenters from Google and Anthropic outlined what Google termed the "vuln apocalypse" -- an imminent surge in AI-discovered zero-day vulnerabilities at a scale and pace that patching pipelines are not designed to handle. Ed's own team at Counter Hack has already experienced this firsthand: a frontier AI model identified a critical zero-day in a widely used open source project in a matter of hours. The Anthropic presenter's claim was blunt: within months, AI will surpass all human vulnerability researchers combined.

          All of this lands at the center of what the RSAC session is designed to address -- not as a theoretical exercise, but as a set of actions defenders can take right now. The session runs Tuesday, March 24th at 3:55 PM on the main stage, with an interactive follow-on session Wednesday morning where attendees can go deeper with individual panelists. For anyone who wants to understand where the threat landscape is actually heading and what to do about it, Ed says this is the year you cannot afford to miss it.

          Guest

          Ed Skoudis, President, SANS Technology Institute; Founder & CEO, Counter Hack | On LinkedIn: https://www.linkedin.com/in/edskoudis

          Host

          Sean Martin, Co-Founder at ITSPmagazine, Studio C60, and Host of Redefining CyberSecurity Podcast & Music Evolves Podcast | Website: https://www.seanmartin.com/

          Resources

          SANS Institute | https://www.sans.org

          RSA Conference 2026 is taking place April 28 - May 1, 2026 | Moscone Center, San Francisco -- Follow our coverage: https://www.itspmagazine.com/rsac-2026-conference-san-francisco-usa-cybersecurity-event-infosec-conference-coverage

          The Future of Cybersecurity Newsletter | https://www.linkedin.com/newsletters/7108625890296614912/

          More Redefining CyberSecurity Podcast episodes | https://www.seanmartin.com/redefining-cybersecurity-podcast

          Redefining CyberSecurity Podcast on YouTube | https://www.youtube.com/playlist?list=PLnYu0psdcllS9aVGdiakVss9u7xgYDKYq

          Keywords

          ed skoudis, sean martin, sans institute, sans technology institute, counter hack, rsac 2026, rsa conference, five most dangerous attack techniques, ai in cybersecurity, vulnerability research, zero-day vulnerabilities, patch management, penetration testing, defender tips, ics security, ai-powered attacks, redefining cybersecurity, cybersecurity podcast, redefining cybersecurity podcast

          26 min
        • When Cyber Meets Physical: Building Executive and Employee Protection Programs That Actually Work | A Redefining CyberSecurity Podcast Conversation with Roland Cloutier, Principal of The Business Protection Group

          β¬₯EPISODE NOTESβ¬₯

          The conversation that led to this episode started with a LinkedIn post -- and it quickly surfaced a challenge that security leaders across industries are wrestling with but rarely talk about openly: who is actually responsible for protecting the people inside an organization, not just the systems they use?

          Roland Cloutier has sat in some of the most demanding security leadership seats in the world -- Global CSO at TikTok/ByteDance, a decade as Global CSO at ADP, and VP and CSO at EMC -- and he now advises CISOs and CSOs through The Business Protection Group. His lens is converged security: the deliberate integration of cyber, physical, privacy, and people-risk under a unified program and leadership model.

          Roland identifies three patterns that typically bring organizations to him. First, an emergent crisis -- a threat against an executive, a workplace violence incident, a travel security failure -- that suddenly exposes the absence of a coherent protection program. Second, a cost and structure conversation where the CEO is tired of receiving two different risk pictures from two different security leaders and wants a single accountable voice. Third, a board-driven inquiry where general counsel or the CEO is being asked questions about executive resilience and duty of care that nobody inside the organization can confidently answer.

          What makes this conversation particularly sharp is Roland's framing of convergence not as an org chart exercise, but as a force multiplier. A unified threat intelligence picture -- one that covers cyber, physical, executive, brand, and customer risk simultaneously -- enables cleaner prioritization, better resource allocation, and a fundamentally stronger conversation with the CEO. The alternative, which he has seen firsthand, is four separate threat management platforms reporting independently with no team working across all of them.

          The episode also pushes into territory that most security programs have not yet mapped: employee protection at scale. Not bodyguards for everyone, but the organizational consciousness to monitor for geographic threats, proactively check in with distributed employees during major events, and build a duty-of-care posture that extends beyond the office walls into people's home lives and total risk environment. For high-risk employees -- those with keys to the kingdom, not just C-suite titles -- that responsibility extends further still.

          For CISOs and CSOs wondering where to start, Roland offers a practical crawl-walk-run framework: start with shared services rather than full convergence, open the conversation with leadership, surface the gaps the business already knows exist, and build a financial and risk model that makes sense for your specific organization. The goal is a converged security program that treats people -- not just infrastructure -- as an asset worth protecting.

          β¬₯GUESTβ¬₯

          Roland Cloutier, Principal at The Business Protection Group | On LinkedIn: https://www.linkedin.com/in/rolandcloutier/

          β¬₯HOSTβ¬₯

          Sean Martin, Co-Founder at ITSPmagazine, Studio C60, and Host of Redefining CyberSecurity Podcast & Music Evolves Podcast | Website: https://www.seanmartin.com/

          β¬₯RESOURCESβ¬₯

          The Future of Cybersecurity Newsletter | https://www.linkedin.com/newsletters/7108625890296614912/

          More Redefining CyberSecurity Podcast episodes | https://www.seanmartin.com/redefining-cybersecurity-podcast
          Redefining CyberSecurity Podcast on YouTube | https://www.youtube.com/playlist?list=PLnYu0psdcllS9aVGdiakVss9u7xgYDKYq

          β¬₯ADDITIONAL INFORMATIONβ¬₯

          On ITSPmagazine: https://www.itspmagazine.com/

          On YouTube: https://www.youtube.com/@itspmagazine
          On LinkedIn Newsletter: https://itspm.ag/future-of-cybersecurity
          Sean Martin's Contact Page: https://www.seanmartin.com/

          β¬₯KEYWORDSβ¬₯

          roland cloutier, the business protection group, sean martin, executive protection, employee protection, converged security, physical security, ciso, cso, duty of care, threat intelligence, workplace violence, security convergence, business resilience, redefining cybersecurity, cybersecurity podcast, redefining cybersecurity podcast

          26 min
        • Adapting to the Speed of Risk: Why GRC Programs Must Move with the Business | A Brand Highlight Conversation with Steve Schlarman, Senior Director of Archer

          Archer is redefining what it means to manage governance, risk, and compliance in an environment defined by constant change. Steve Schlarman, Senior Director at Archer, has spent nearly two decades helping organizations understand why their traditional GRC approaches are falling short and what it takes to close the gap.

          The forces challenging organizations today are well known: velocity of change, volume of change, and the uncertainty that compounds both. What makes the problem acute is timing. Annual audit cycles and quarterly risk assessments produce reports that reflect a reality that has already shifted by the time decision makers see them. The result is drift between what GRC functions can see and what leadership actually needs to know, and every gap in that visibility carries potential exposure.

          Schlarman explains that this reactive posture is exactly what Archer is working to change. Rather than treating risk and compliance as periodic checkboxes, the goal is to build a program that runs continuously, projecting forward as the business expands into new jurisdictions, launches new products, or encounters emerging risks. What are the compliance obligations? How does exposure shift? Archer Evolv is designed to answer those questions in real time, keeping GRC moving alongside the business rather than scrambling to catch up.

          Central to Archer's strategy is AI applied with intention. Rather than deploying generic agents, Archer is building what Schlarman calls AI operators: focused, guardrailed tools designed specifically to solve GRC problems. That distinction matters because the complexity of risk and compliance work demands precision, not just automation.

          This is a Brand Highlight. A Brand Highlight is a ~5 minute introductory conversation designed to put a spotlight on the guest and their company. Learn more: https://www.studioc60.com/creation#highlight

          GUEST

          Steve Schlarman, Senior Director, Archer | https://www.linkedin.com/in/steveschlarman/

          RESOURCES

          Learn more about Archer and the Archer Evolv platform: https://www.archerirm.com

          Are you interested in telling your story?

          β–ΆοΈŽ Full Length Brand Story: https://www.studioc60.com/content-creation#full
          β–ΆοΈŽ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight
          β–ΆοΈŽ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight

          KEYWORDS

          Steve Schlarman, Archer, Sean Martin, brand story, brand marketing, marketing podcast, brand highlight, GRC, governance risk and compliance, adaptive GRC, integrated risk management, Archer Evolv, AI in GRC, risk management, compliance automation, enterprise risk, risk and compliance strategy

          7 min
        • Task by Task: The Workflows We're Handing to AI β€” One Decision at a Time | Lens Four by Sean Martin | Read by TAPE9

          Nobody decided to build a human-optional workflow β€” they just kept making reasonable procurement decisions, task by task, until the human became optional across hiring, contracting, finance, and security operations. Sean Martin traces what organizations have actually assembled, where accountability lives when it goes wrong, and why the regulatory window for getting ahead of it is closing faster than most leaders realize.

          In this edition of Lens Four, Sean Martin looks at the agentic AI landscape through three lenses β€” programs, innovation, and messaging β€” to connect the signals that matter.

          πŸ” In this episode:

          • Why organizations are building human-optional workflows one procurement decision at a time β€” without ever deciding to
          • The five-task AI hiring pipeline and five-task AI legal contracting pipeline β€” real tools, real companies, real outcome data
          • 375+ agentic AI vendors claiming the space, but only ~130 delivering genuine capability β€” and what that gap means for buyers
          • Why "augment, not replace" is a strategy, not a description β€” and what the accountability gap it creates looks like when something goes wrong
          • The agentic orchestration platform emerging from Nintex and Microsoft β€” and why it splits outcomes between deliberate orgs and accumulators
          • The regulatory window that is open right now β€” and why it won't stay that way
          • Fourth Lens: The vendors knew what they were building. The buyers didn't ask the right questions. The auditors haven't arrived yet. The organizations that use the remaining window to map what they've assembled β€” and make explicit decisions about what requires human judgment β€” will be positioned when the frameworks arrive. The ones that don't will discover that the workflow they built by default is not the workflow they would have chosen under scrutiny.

            πŸ“– Read the full Lens Four analysis on seanmartin.com: https://www.seanmartin.com/lens-four/task-by-task-workflows-handing-to-ai-one-decision-at-a-time

            🎧 Listen to the Redefining CyberSecurity Podcast conversation with Edward Wu of Dropzone AI at Black Hat USA 2025: https://www.itspmagazine.com/their-stories/dropzone-ai-brings-agentic-automation-to-black-hat-usa-2025-a-drop-zone-ai-pre-event-coverage-of-black-hat-usa-2025-las-vegas-brand-story-with-edward-wu-founder/ceo-at-dropzone-ai

            🎧 Listen to the Redefining CyberSecurity Podcast conversation with Subo Guha of Stellar Cyber at RSAC 2025: https://www.itspmagazine.com/their-stories/simplifying-cybersecurity-operations-at-scale-automation-with-a-human-touch-a-brand-story-with-subo-guha-from-stellar-cyber-an-on-location-rsac-conference-2025-brand-story

            🎧 Listen to the Redefining CyberSecurity Podcast conversation with Subo Guha of Stellar Cyber at Black Hat 2025: https://www.itspmagazine.com/their-stories/stellar-cyber-revolutionizes-soc-cybersecurity-operations-with-human-augmented-autonomous-platform-at-black-hat-2025a-stellar-cyber-event-coverage-of-black-hat-usa-2025-las-vegas

            🎧 Listen to the Random and Unscripted episode β€” "We're Becoming Dumb and Numb" β€” with Sean Martin and Marco Ciappelli: https://randomandunscripted.com/episodes/were-becoming-dumb-and-numb-why-black-hat-2025s-ai-hype-is-killing-cybersecurity-and-our-ability-to-think-random-and-unscripted-weekly-update-with-sean-martin-and-marco-ciappelli | 🎬 Watch on YouTube

            πŸ”” Subscribe to the Future of Cybersecurity newsletter on LinkedIn: https://itspm.ag/future-of-cybersecurity

            This story represents the results of an interactive collaboration between Human Cognition and Artificial Intelligence.

            Enjoy, think, share with others, and subscribe to Lens Four on seanmartin.com and "The Future of Cybersecurity" newsletter on LinkedIn: https://itspm.ag/future-of-cybersecurity
            Sincerely, Sean Martin and TAPE9

            Sean Martin is a life-long musician and the host of the Music Evolves Podcast; a career technologist, cybersecurity professional, and host of the Redefining CyberSecurity Podcast; and is also the co-host of both the Random and Unscripted Podcast and On Location Event Coverage Podcast. These shows are all part of ITSPmagazineβ€”which he co-founded with his good friend Marco Ciappelli, to explore and discuss topics at The Intersection of Technology, Cybersecurity, and Society.ℒ️

            Want to connect with Sean and Marco On Location at an event or conference near you? See where they will be next: https://www.itspmagazine.com/on-location
            To learn more about Sean, visit his personal website.

            πŸ”Ž Keywords

            agentic AI, workflow automation, task-specific AI agents, AI hiring tools, resume screening automation, HireVue, Paradox Olivia, legal AI, Harvey AI, LegalOn, contract review automation, agentic SOC, Dropzone AI, Stellar Cyber, Token Security, AI agent identity, RSAC 2026, Nintex, Microsoft Copilot Studio, agentic orchestration platform, human accountability in AI, agentwashing, AI augmentation vs replacement, AI governance, enterprise AI adoption, Gartner agentic AI, Forrester AI forecast, AI decision accountability, AI regulatory compliance, AI workforce impact

            29 min
          • The 72-Minute Gap: What the Breaches, the Vendors, and the Messaging Are Actually Telling Us | Lens Four by Sean Martin | Read by TAPE9

            Attackers are moving in 72 minutes. One CISO has already eliminated the entire SOC team. And the industry is spending a quarter of a trillion dollars while struggling to define what "resilience" even means.

            In this edition of Lens Four, Sean Martin looks at the cybersecurity landscape through three lenses β€” programs, innovation, and messaging β€” to connect the signals that matter.

            πŸ” In this episode:

            • Why identity-driven attacks now account for 65% of initial access and what that means for security programs
            • The CISO who replaced the entire SOC with AI-driven automation β€” and the math behind the decision
            • 375 AI security vendors, 58 focused on SOC automation, and over $1.3 billion in funding reshaping the market
            • Why "resilience" without a timeframe is just damage control
            • The board-CISO communication gap that's pulling budgets in the wrong direction
            • Sean's Take:

              When attackers operate in minutes and defenders plan in quarters, the gap isn't technology β€” it's assumptions. The organizations closing the 72-minute gap aren't hiring faster. They're rethinking what humans are for and what machines should own.

              Catch the full companion article on Lens Four at seanmartin.com for the complete three-lens analysis with all references and data sources.

              For CISOs and security leaders: Can your program detect, investigate, and contain a threat in 72 minutes β€” or are you still measuring in days?
              For vendors and product teams: Is your platform solving the operational problem CISOs have today, or selling a vision their program can't execute on?
              For marketing and go-to-market teams: Are you connecting your messaging to measurable outcomes β€” or hiding behind buzzwords like "resilience" and "platform"?

              πŸ“– Read the full Lens Four analysis on seanmartin.com: https://www.seanmartin.com/lens-four/72-minute-gap-breaches-vendors-messaging

              🎬 Watch the companion video summary β€” "Why Hackers Beat Your Security in Just 72 Minutes": https://youtu.be/EjsADm7faJ0

              🎧 Listen to the Redefining CyberSecurity Podcast conversation with Richard Stiennon on SOC automation: https://redefiningcybersecuritypodcast.com/episodes/soc-automation-and-the-ai-driven-future-of-cybersecurity-defense-a-redefining-cybersecurity-podcast-conversation-with-richard-stiennon-chief-research-analyst-of-it-harvest

              🎬 Watch the video version of the Richard Stiennon conversation: https://youtu.be/si_fS4H-d3w

              πŸ”” Subscribe to the Future of Cybersecurity newsletter on LinkedIn: https://itspm.ag/future-of-cybersecurity

              This story represents the results of an interactive collaboration between Human Cognition and Artificial Intelligence.

              Enjoy, think, share with others, and subscribe to Lens Four on seanmartin.com and "The Future of Cybersecurity" newsletter on LinkedIn: https://itspm.ag/future-of-cybersecurity
              Sincerely, Sean Martin and TAPE9

              Sean Martin is a life-long musician and the host of the Music Evolves Podcast; a career technologist, cybersecurity professional, and host of the Redefining CyberSecurity Podcast; and is also the co-host of both the Random and Unscripted Podcast and On Location Event Coverage Podcast. These shows are all part of ITSPmagazineβ€”which he co-founded with his good friend Marco Ciappelli, to explore and discuss topics at The Intersection of Technology, Cybersecurity, and Society.ℒ️

              Want to connect with Sean and Marco On Location at an event or conference near you? See where they will be next: https://www.itspmagazine.com/on-location
              To learn more about Sean, visit his personal website.

              πŸ”Ž Keywords

              72-minute gap, ai-driven cyberattacks, soc automation, unit 42, incident response, identity-driven attacks, credential theft, iam misconfigurations, cisa workforce, agentic ai, palo alto networks, crowdstrike, google wiz acquisition, cybersecurity spending, platform consolidation, ai security vendors, it-harvest, richard stiennon, gartner cybersecurity trends 2026, forrester predictions, clawjacked, enterprise management associates, board-ciso communication, cybersecurity resilience, managed security services, cyber insurance, redefining cybersecurity podcast, lens four, sean martin, tape9

              15 min

            About Redefining CyberSecurity

            From the publisher's feed

            Redefining CyberSecurity Podcast

            More shows like Redefining CyberSecurity

            This American Life by This American Life

            This American Life

            90,968 Listeners

            Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

            Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

            373 Listeners

            Risky Business by Risky Business Media

            Risky Business

            374 Listeners

            SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

            SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

            651 Listeners

            CyberWire Daily by N2K Networks

            CyberWire Daily

            1,028 Listeners

            Click Here by Recorded Future News

            Click Here

            419 Listeners

            The ITSPmagazine Podcast by ITSPmagazine, Sean Martin, Marco Ciappelli

            The ITSPmagazine Podcast

            30 Listeners

            Cybersecurity Today by David Shipley

            Cybersecurity Today

            179 Listeners

            CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

            CISO Series Podcast

            191 Listeners

            Defense in Depth by CISO Series

            Defense in Depth

            73 Listeners

            Cybersecurity Headlines by CISO Series

            Cybersecurity Headlines

            138 Listeners

            Hard Fork by The New York Times

            Hard Fork

            5,549 Listeners

            Audio Signals Podcast by ITSPmagazine, Marco Ciappelli, Sean Martin

            Audio Signals Podcast

            2 Listeners

            Risky Bulletin by Risky Business Media

            Risky Bulletin

            46 Listeners

            Microsoft Threat Intelligence Podcast by Microsoft

            Microsoft Threat Intelligence Podcast

            23 Listeners

            Stories From Space by ITSPmagazine, Matthew S Williams

            Stories From Space

            4 Listeners

            An Analog Brain In A Digital Age | With Marco Ciappelli by Marco Ciappelli

            An Analog Brain In A Digital Age | With Marco Ciappelli

            0 Listeners

            CyberSecurity Summary by CyberSecurity Summary

            CyberSecurity Summary

            5 Listeners