Security Visionaries

Security Visionaries

By NetskopeBusinessTechnology
Download on the App Store

Security Visionaries episodes

  • Architecting Amid Regulations in Finance
    Key topics
    • Does regulation shape cloud architecture from the start, or get applied after the fact?
    • What percentage of enterprise cloud spend goes to waste? 
    • How does a hybrid estate complicate zero trust and entitlement management?
    • Where is AI actually useful inside a regulated architecture team?
    • What happens when you stop letting an AI assistant simply agree with you?


    Regulation comes first. Seb's team only builds on cloud services that have already cleared a rigorous compliance review, then designs around what's approved rather than retrofitting compliance onto a finished architecture. That same discipline covers data and AI sovereignty: jurisdiction, data center location, and backup zones are core to the design, not overhead bolted on afterward.

    On cost: roughly 30% of all cloud spend is waste, according to Seb, mostly from over-provisioning rather than unused services. His team runs an annual OKR specifically to find and cut that waste.

    On AI: Seb treats it as a second opinion, not a replacement for his team. He uses it to pressure-test architecture documents, prompt for edge cases, and even diagnose a broken home CCTV system from raw log files. Emily and Seb also compare notes on what changes when you stop letting an AI assistant simply agree with you, after Emily's own experiment asking Claude to drop the sycophancy and get blunt.

    The throughline: in a heavily regulated environment, guardrails and good architecture patterns move faster than ad hoc decisions, and the same discipline that keeps regulators satisfied is what makes room for AI experimentation without losing control.


     

    31 min
  • Why Netskope Let AI Hack Its Own Software

    On the latest episode of Security Visionaries, host Emily Wearmouth sits down with Mohit Kulamkolly, senior engineer on Netskope’s security red team, for a candid look at what happens when you point frontier AI models at your own product’s code. Mohit draws on his team’s research (using Claude Mythos and ChatGPT 5.5), explains what a memory corruption bug actually is, and why it remains one of the hardest and most dangerous flaws to find. From building isolated sandbox labs that let AI agents hunt for crashes, to a second experiment where the AI got more control and its findings were checked by a completely separate AI, Mohit walks through two very different ways of putting these models to work. The discussion explores why you can never just trust a model’s claim that it found a bug, how sub agents kept the hunt moving for days without giving up, and why AI is even more useful earlier, threat modeling a product before it’s built, than after the fact.  

    Mohit and Emily also tackle what this means for security teams that don’t have frontier model access yet, and why finding thousands of vulnerabilities is only half the job without a real remediation plan. This episode’s bottom line? AI is changing vulnerability research at every level, and the security teams that get ahead of it will be the ones that give it the right tools early.

     

    Blogs:
    https://www.netskope.com/blog/teaching-openai-5-5-to-hunt-memory-corruption-bugs 
    https://www.netskope.com/blog/when-mythos-owns-the-loop-self-verifying-vulnerability-research 

    35 min
  • The AI Public-Private Divide

    On the latest episode of Security Visionaries, host Bailey Popp sits down with Teresa Carlson, Global Head of Public Sector at Anthropic and former CEO of the General Catalyst Institute, for a wide-ranging conversation on the intersection of AI, cybersecurity, and public-private collaboration. Teresa draws on nearly three decades in technology to share what it truly takes to work with government. From navigating compliance frameworks like FedRAMP to building sponsor networks that accelerate the path to authority to operate. The discussion explores how security leaders can shift from a checklist culture to an outcomes-based mindset, and why going in as a partner, not a vendor, is the defining factor for success. Teresa and Bailey also tackle the fragmented global AI regulatory landscape, the challenge of data sovereignty, and why startups bear a disproportionate burden in a world of conflicting mandates. This episode's bottom line? AI is minting a new generation of citizen developers and the opportunity has never been bigger.

    35 min
  • Live @ RSAC 2026: AI FOMO

    On the latest episode of Security Visionaries, host Max Havey and guest James Robinson, CISO at Netskope, connect live and in-person at RSAC 2026 to discuss the cutting edge of security in the age of AI, particularly for highly regulated industries. They dive into the conference's biggest trends, focusing on the rise of agentic AI, the necessity of heavy guardrails, and the complex challenge of data sovereignty in a global regulatory landscape. James offers insights on the major hurdles facing highly regulated industries as they adopt AI, and shares practical advice for security leaders on shifting their AI governance approach from "no" to enablement. The discussion also covers innovative data governance strategies like moving from data classification to detailed data categorization, and the critical importance of utilizing red teaming and incident investigation to build robust defenses against emerging threats like prompt injection. If you couldn’t make it to the conference, hopefully this will fill you in on some of what you missed.

    18 min
  • Crucial Conversations With Your CEO

    In this episode of Security Visionaries, host Emily Wearmouth welcomes Nycholas Szucko, a board member for many security companies who is based in Brazil, to discuss better approaches to solving misaligned communication between CEOs, boards, and security leaders. Using key data points from the Crucial Conversations report as a jumping off point, Nycholas offers practical strategies for CISOs and CIOs to bridge the gap. Together they cover the essential skills needed, from communication and storytelling to selling skills and understanding financials. They also offer advice around becoming a CEO’s "trusted lieutenant," determining your CEO's risk appetite (even using AI role-play for preparation), navigating frustration with technology as a "black box," and shifting investment from short-term "band-aid" fixes to strategic, long-term platform modernization. This episode provides constructive approaches for improving alignment, becoming proactive in strategic planning, and leading the business into the age of agentic AI. This conversation is a must-listen, whether you’re a CEO, board member, security leader, or anything in between.

    33 min
  • Taking the Fear out of Risk

    In this episode of Security Visionaries, host Max Havey speaks with Beth Miller, Field CISO at Mimecast and author of Risk Reframing: How to Navigate Uncertainty With Resilience, about moving to a human-centered approach to cybersecurity. They discuss why fear-based training is ineffective, how the rise of AI makes human judgment more critical than ever, and how security leaders can redefine risk from a negative to an opportunity to "dare." Additionally Beth introduces some frameworks as practical tools for shifting security culture from one of control and compliance to one of resilience and navigation.

    25 min
  • Jenny Radcliffe on the Louvre Heist, Arrogant Cultures, and AI

    On this episode of Security Visionaries hosts Max Havey and Emily Wearmouth are joined by renowned social engineering expert Jenny Radcliffe, "The People Hacker," for a deep dive into the world of physical, and psychological, hacking. Jenny shares the unconventional path of her storied career, and further explores the role of physical infiltration in security. Additionally she digs into how the rise of AI is changing the reconnaissance process and creating new vulnerabilities, her thoughts on the 2025 Louvre heist, and the simple value of shutting up. This one is not to be missed!

    45 min
  • AI, Boardroom Influence, and Impact with Kirk Ball, CIO

     On this episode of Security Visionaries host Bailey Popp and guest Kirk Ball, CIO at Worldpay, explore the intricacies of the CIO role, particularly as it relates to AI, boardroom communication, and more. Together, Bailey and Kirk discuss balancing quarterly results with long-term risk management through strong architectural discipline, how to effectively communicate technical and cybersecurity value to a non-technical board audience, and the strategic approach CIOs should take in navigating the "organizational opportunity" of AI. Plus, Kirk shares his perspective on the long-term decisions that define a CIO’s legacy, emphasizing the importance of talent, culture, and empathy.

    28 min
  • Two Truths and a Lie? The SV Hosts Plan 2026.

    On the latest episode of Security Visionaries, we have all three co-hosts, Max Havey, Emily Wearmouth, and Bailey Popp, together to reintroduce themselves and talk about 2026. Together, they dig into the topics they gravitate toward, tips they’ve learned from past episodes, and some topics they’re hoping to cover in the year to come. Plus, stick around for a rousing game of Two Truths and a Lie to cap things off and get to know the hosts a little bit better.

    24 min
  • What is MCP? We Ask Steve

     On the latest Security Visionaries podcast, host Emily Wearmouth invites Steve Riley back to demystify another key acronym in the AI world: MCP, or model context protocol.  They break down what MCP actually is, how it functions, and why it is critical to understanding AI interactions. From there, they pivot into a discussion about the critical security implications of MCP, covering the risks of unauthenticated servers and the necessity of building both an authorization layer and an external policy layer to ensure granular access, data security, and compliance as AI agents proliferate. As always, this conversation with Steve offers illuminating context and perspective on one of the key security terms going into 2026. You won’t want to miss it.

    23 min

About Security Visionaries

From the publisher's feed

Security Visionaries is a podcast all about the world of cyber, data, and tech infrastructure, bringing together experts from around the world and across domains. In each episode, your hosts Emily…