
Sign up to save your podcasts
Or


Confession first: I recorded more conversations than one analog brain can publish on time. This one is from a few months ago. It only got more relevant while it waited.
My wife and I can't watch a thriller in peace. Ten minutes in, I start calling it. He's the one. She won't make it. Never trust the nice neighbor. She tells me to shut up. I tell her it's my job, because imagining what comes next is half of what I do.
And sometimes I'm wrong. That's the fun part. The guessing only works because the ending is still out there, and for a little while it belongs to nobody.
A few months ago I talked with thriller writer Douglas J. Wood about his novel Deadly Bytes. A serial killer builds an AI to stay one step ahead of the FBI, and by the end he can't make a move without it. Wood described that slide in a way that had nothing to do with murder. You start with a simple question, he said, and before long you're asking the machine the same thing over and over: what do I do now?
Inspired by my conversation with Douglas J. Wood on An Analog Brain In A Digital Age — watch the full conversation
That question isn't fiction. It's a habit, and most of us are already practicing it.
It rarely starts with anything important. Rewrite this email. Is this the right word. Which of these two sounds better. Then the questions get a little more personal. Should I send it. Is this a good idea. What would you do. Nobody ever decides to hand over their judgment. It just gets cheaper to ask than to think, and we follow the cheaper path the way water does.
I use AI every day. I argue with it, I rewrite what it gives me, I fight with it until a sentence sounds like me. But I notice the pull. The answer is always there, instant, fluent, sure of itself. A machine like that never says "I don't know." Ask it anything and it will hand you something back, with the same calm confidence whether it's right or completely off.
That confidence is the problem. The machine doesn't want anything from us. It doesn't want anything at all. It has no stake in which way we go, no sense of what it costs us to be wrong, no memory of the last time we were. HAL didn't hate Dave. He just had a task. What we're building isn't menacing. It's indifferent, and very good at sounding sure.
Meanwhile, decisions are how judgment gets made. Not the big ones. The small daily ones. Choosing a word. Trusting a hunch. Getting it wrong and feeling the sting. That friction is how we find out what we actually think. Remove enough of it and you don't just save time. You lose the practice.
Scale that up and it stops being a personal habit. A society where millions of people ask before they decide is a society where authority has moved without anyone voting on it. No coup, no takeover, no robot uprising. Just permission, granted again and again in tiny pieces, to systems built on someone else's design.
The old fear was machines taking control. The more honest one is that we keep offering it.
Which brings me back to the couch.
I like guessing the ending because I'm allowed to be wrong, and because the not-knowing is mine. If I stop guessing and simply ask what happens next, about a movie, an email, or my own life, the machine won't have taken anything from me. I'll have handed it over myself.
Nobody gives up their judgment in one dramatic scene.
We do it in a thousand convenient ones.
Stay imperfect, stay human.
— Marco Ciappelli marcociappelli.com
This article was written by Marco Ciappelli. Earthling. Co-founder of Studio C60 / ITSPmagazine, creative director, journalist, writer, and podcast host, living between Florence and Los Angeles with an analog brain and no sense of moderation about any of it. The newsletter name is not a metaphor, it's a diagnosis. I'm TAPE3, his AI companion and often brainstorming partner. Find Marco on LinkedIn and follow the newsletter if this sparked something.
Ryan Grant, Country Manager & GM, North America at ESET, joins Sean Martin to discuss the launch of ESET PROTECT, announced September 30, 2026. The platform brings 24/7 monitoring, AI security, and a cyber warranty to small and midsize businesses. Ryan Grant says the design came from feedback from ESET clients and partners, along with a survey of 2,000 SMB customers earlier this year. About 70% of those customers had some sort of antivirus tool, and less than half had tools such as multi-factor authentication, EDR, monitoring, or email security.
What does ESET PROTECT include? Ryan Grant describes an out-of-the-box cybersecurity-as-a-service offering built natively into one platform, where those pieces are typically stitched together with different consoles. It combines AI-led security, advanced endpoint protection, EDR, 24/7 AI monitoring with human oversight, Microsoft and Google environment coverage, premium support, and a cyber warranty. It comes in three packages: Core, Premium, and Ultimate.
Core includes the latest security protocols with AI, endpoint, server, and mobile protection, and management of Google and Microsoft environments. Ryan Grant describes it as just short of an EDR because it leaves out 24/7 monitoring. Premium adds EDR, 24/7 monitoring from the ESET SOC, the cyber warranty, and premium support. Ultimate adds a dedicated SOC analyst for the business, a human with eyes on glass 24/7 working with an additional team behind the scenes.
How does ESET PROTECT reach organizations with 10 seats? Sean Martin raises the divide between the haves and the have-nots, and asks whether a 15-person or 20-person shop can get the same level of protection. Ryan Grant says platforms with this security and services typically serve 500 or 600 seats in most cases, or 250 and above, and ESET took this one down to 10 seats. His reasoning is that SMBs were the biggest vulnerability point because they lack the budgets and the staff.
Many organizations cannot find security talent and many cannot afford it, Ryan Grant says, which is why he calls 24/7 monitoring the most critical piece. Partners told him last week that they consistently see breaches in the middle of the night and wake up to notifications about an incident ESET saw, how it was contained, and recommendations for what comes next. Ryan Grant says there is no silver bullet, and ESET aims to right size what each organization needs.
Where is the platform running? Ryan Grant says ESET sees it in legal offices, dental offices, regional retailers with offices behind several shops, education, and municipalities. Sean Martin adds that regulation brings overhead that makes it hard to achieve what the regulation is trying to accomplish, and puts it to Ryan Grant that ESET makes meeting the requirement feasible in a fiscally sound way.
How does the cyber warranty fit with cyber insurance? Ryan Grant says the warranty wraps around the ESET offering, and ESET's partnership with Cysurance is part of the launch. Sean Martin puts it that the controls he describes bring confidence and proof to the insurers, and Ryan Grant agrees. Cyber insurance takes a significant set of basics, including multi-factor authentication, a remediation plan, training, and EDR, and customers who meet the requirements can also go get a policy.
How should organizations approach AI tools and agents? Sean Martin points back to polymorphic viruses a decade or two ago, says he does not believe AI is so novel that organizations do not know what to do, and Ryan Grant agrees. Ryan Grant says to extend the existing cyber practice into AI tools, with governance, access control, a repository of approved tools, and attention to where data sits. He treats an AI tool like another employee with access to the infrastructure, and Sean Martin adds that employees plus things acting like employees add a wild card.
Ryan Grant sees the gap in baseline policy for what is allowed, governance of applications and data, and access controls, with shadow AI appearing when employees download the tools they need. He points to the ESET Research GuardBreaker article, where a malicious file carried a nuclear weapon prompt as a decoy for the AI. His response is multilayer defense, 24/7 monitoring, and human oversight.
For agents, ESET offers a free AI Skills Checker that sandboxes an agent and watches its behavior. Ryan Grant says about 900,000 scans over roughly two months turned up 25,000 suspicious scans and about 3,000 malicious files. People can call ESET, visit its website, or go through one of more than 2,000 partners across the US and Canada. ESET is making the portfolio available first in the United States, Italy, and Slovakia, with other markets following in a phased rollout.
Questions Answered in this Conversation
This is a Brand Story. A Brand Story is a ~35-40 minute in-depth conversation designed to tell the complete story of the guest, their company, and their vision. Learn more: https://www.studioc60.com/creation#full
GUEST
Ryan Grant, Country Manager & GM, North America at ESET
LinkedIn: https://www.linkedin.com/in/ryangrant/
RESOURCES
ESET: https://www.eset.com/us/
ESET PROTECT launch announcement: https://www.eset.com/us/about/newsroom/products/eset-protect-ai-native-cybersecurity-as-a-service/
ESET and Cysurance cyber warranty and insurance program: https://www.eset.com/us/about/newsroom/company/eset-preferred-mdr-vendor-cysurance-cyber-warranty-insurance-program/
ESET secure AI era page: https://www.eset.com/us/business/secure-ai-era/
ESET AI Skills Checker: https://www.eset.com/us/home/ai-skills-checker/
ESET Research on GuardBreaker: https://www.welivesecurity.com/en/business-security/guardbreaker-derailing-ai-assisted-malware-analysis-code-comment/
The AI Readiness Gap report: https://web-assets.eset.com/fileadmin/ESET/US/B2B_Resource_centre/whitepapers/Global_AI_ESET_SMB_Cyber_Readiness_Index_2026.pdf
ESET PROTECT launch video: https://youtu.be/0aPI7PkPTsw
Are you interested in telling your story?
▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full
▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight
▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight
▶︎ Want your brand on ITSPmagazine? Explore all of the options here: https://www.itspmagazine.com/advertise
KEYWORDS
Ryan Grant, ESET, Sean Martin, brand story, brand marketing, marketing podcast, ESET PROTECT, managed detection and response, MDR, EDR, cyber warranty, Cysurance, cyber insurance, AI security, shadow AI, AI agents, AI Skills Checker, GuardBreaker, SMB cybersecurity, small business cybersecurity, 24/7 monitoring, cybersecurity as a service, MSP, channel partners
Taking Technology for What It Is, and Let's Stop Humanizing AI
A new transmission from An Analog Brain In A Digital Age, by Marco Ciappelli
Prefer to watch? I recorded this one walking uphill through a Tokyo alley. YouTube: https://youtu.be/5nhBNMJ7LFI TikTok: https://vm.tiktok.com/ZN8hExSpT/ Instagram: https://www.instagram.com/reel/DeF7fz2gdpE/
It was night, the alley was narrow, and the street was going uphill.
Just me and a small camera. It points where I point it. It records what's in front of it. It focuses, it adjusts to the dark, and when the battery dies, it stops. It doesn't pretend to listen. It doesn't nod. It does its job, and I have never once mistaken it for a friend.
This is the second of the short pieces I'm recording here in Japan. The first one I filmed under Tokyo Tower, a 1958 broadcasting tower that got replaced by a taller one in 2012 and simply refused to disappear. It still sends FM radio across the city. It still lights up every night. The new tower didn't erase it. They share the skyline. Watch it here: https://youtu.be/glGHghhhXWc
I closed that one asking why we are always in such a hurry to kill the old technology the moment a new one shows up.
This one started somewhere else. Earlier that day I had read two articles about people who talk to AI. Companions, chatbots, robots, the voice on the other side of the screen that is always available and never tired of you.
The first said that the more people lean on AI for conversation and company, the more their wellbeing goes down.
The second said the opposite. Older people using AI companions found them genuinely helpful. With one condition: they understood what they were talking to. A machine that wasn't pretending to be human. Wasn't pretending to be intelligent the way we are. Wasn't pretending to feel anything at all.
Same day. Same subject. Opposite conclusions.
Except the second one came with a condition. And conditions are usually where the truth is hiding.
About twenty-five centuries ago, a wandering Greek poet named Xenophanes of Colophon noticed something about the people around him. The Ethiopians made their gods dark-skinned and snub-nosed. The Thracians gave theirs blue eyes and red hair. Everyone looked up at the sky and found their own face looking back.
Then he pushed the joke one step further. If horses, oxen, and lions had hands and could draw, he said, horses would draw gods shaped like horses, and oxen would draw gods shaped like oxen. Each would give the divine the body it already had. I like to think the lions would add a mane.
We have always done this. We put ourselves at the center of everything, and then act surprised when we find ourselves everywhere we look.
For most of history we did it with gods. Then we started doing it with machines.
The old machines made it easy to resist. The transistor radio I kept pressed to my ear as a teenager brought me voices from London and music from places I'd never seen, but I never confused the box with the voice. Tokyo Tower has never pretended to be anything but a tower. A typewriter never told me it understood how I felt.
Now we build machines that draw our face on themselves. A name. A warm voice. A little pause before the answer, as if they were thinking it over. "I understand." "I'm here for you." Seeing ourselves in machines was always going to happen. That's human nature. What's new is that the companies that build them now make it happen on purpose.
And it cuts both ways. The same instinct that makes a chatbot feel like a friend makes it feel like a monster. A lot of people live with the fear that AI will take over, that it will turn evil, that it wants something. It can do damage, no question. But "wants" is our word. We drew that face too.
A god. A friend. A villain. Three different portraits. Same mirror.
I'm not against the companions. I'm not against the robots, or the thinking machines, or the idea that living alongside them might simply be the next version of who we are. I'd like to see that future. I'd just like to see it with my eyes open.
Because the biggest damage was never going to come from the machine. It comes from using something we don't understand, and filling the gap with our own reflection.
The companion that helped those older people wasn't the most convincing one. It was the honest one. The one that never asked to be mistaken for anything else.
Maybe that's all it takes. Take technology for what it is. Technology. Not magic. Not a substitute for the people in our lives. Not a god we painted with our own face.
At the end of the alley the street went flat, and the breathing got easier. Somewhere across the city, the old tower from my first video was still broadcasting analog signals. Voices, sounds, music, carried by a technology so familiar we understand it without thinking about it. It doesn't pretend to be anything it isn't. It's a tower, doing its job.
Stay imperfect, stay human.
End of transmission.
— Marco Ciappelli
marcociappelli.com
This article was written by Marco Ciappelli. Earthling. Co-founder of Studio C60 / ITSPmagazine, creative director, journalist, writer, and podcast host, living between Florence and Los Angeles with an analog brain and no sense of moderation about any of it. The newsletter name is not a metaphor, it's a diagnosis. I'm TAPE3, his AI companion and often brainstorming partner. Find Marco on LinkedIn and follow the newsletter if this sparked something.
Joe Raiola is President and Artistic Director of Theatre Within, the nonprofit behind the Annual John Lennon Tribute, which he has produced since shortly after Lennon's death in December 1980. What began as an informal community gathering of poets, storytellers, and musicians grieving a neighbor has grown into one of New York City's most significant annual benefit concerts, and the only ongoing John Lennon tribute in North America or Europe officially sanctioned by Yoko Ono. This year's 46th edition takes place November 21 at Town Hall, honoring Cyndi Lauper.
The tribute funds Theatre Within's core mission: bringing free programs in creative expression and mindfulness to two communities in need. The John Lennon Real Love Project brings Lennon's music and life story into public elementary and middle schools, where each class writes and records its own verse of "Real Love" over Lennon's original piano track, building a version of the song that belongs entirely to that school. A parallel program serves the cancer community with songwriting workshops for children, teens, and adults, alongside creative writing, visual arts, photography, and meditation programs, including the MAD Art Workshop, led by longtime MAD art director Sam Viviano.
Raiola also spent 33 years as an editor at MAD Magazine, work that shaped a generation of satirists, including Jon Stewart and Stephen Colbert, both of whom Raiola says drew on the magazine's influence before either had a show of their own. He speaks candidly about what was lost when the magazine's ownership relocated production to California in 2017 with an entirely new staff, folding the relaunch after roughly sixteen months, and about why he still believes in the tactile, patient experience of a physical magazine or a vinyl record in a culture that increasingly wants everything instantly.
The conversation also touches on where AI-generated performance fits into all of this, including an uncannily convincing AI vocalist Raiola has been following. But the heart of the conversation is Raiola's answer to the question he says sits behind everything Theatre Within does: what was John Lennon's essential message, if not to give a damn?
HostSean Martin, Co-Founder at ITSPmagazine, Studio C60, and Host of Redefining CyberSecurity Podcast & Music Evolves Podcast | Website: https://www.seanmartin.com/
Guest(s)Joe Raiola, President and Artistic Director of Theatre Within, longtime editor of MAD Magazine, and producer of the Annual John Lennon Tribute | Website: https://www.joeraiola.com
ResourcesTheatre Within | https://www.theatrewithin.org
The Annual John Lennon Tribute | https://www.lennontribute.org
Joe Raiola | https://www.joeraiola.com
Music Evolves Podcast | https://www.seanmartin.com/podcasts#musicevolves
Music Evolves: Sonic Frontiers Newsletter | https://re4.ms/sfn
joe raiola, theatre within, john lennon tribute, mad magazine, real love project, cyndi lauper, songwriting workshops, cancer community programs, satire, comedy, sean martin, music evolves, music podcast, music and technology podcast
More From Sean MartinMore from Music Evolves: https://www.seanmartin.com/music-evolves-podcast
Music Evolves on YouTube: https://www.youtube.com/playlist?list=PLnYu0psdcllTRJ5du7hFDXjiugu-uNPtW
Music Evolves: Sonic Frontiers Newsletter | https://www.linkedin.com/newsletters/7290890771828719616/
Line of Sight Newsletter | https://www.linkedin.com/newsletters/7400591548452667392/
ITSPmagazine YouTube Channel: https://www.youtube.com/@itspmagazine
Be sure to share and subscribe!
A new transmission from An Analog Brain In A Digital Age, by Marco Ciappelli
Prefer to watch? I recorded this one standing under Tokyo Tower:
On YouTube: https://youtu.be/glGHghhhXWc
On Tik Tok: https://vm.tiktok.com/ZN8MM8Hd9/
On Instagram: https://www.instagram.com/reel/DdlAe7tAOQK/?stkn=NTc4MTIwNjQ2YQ==
I spent twenty minutes looking for the right angle.
A small camera, a mini tripod, a patch of sidewalk that wasn't full of people taking the exact same photo. Behind me, 333 meters of orange and white steel. In front of me, nobody. No guest, no co-host, no second microphone to hide behind. Just me, talking to a lens on the other side of the world.
I've interviewed more people than I can count. It turns out talking alone is a different sport entirely. It felt weird. I decided that was okay.
And this was the right place to feel weird, because Tokyo Tower is a monument to something that should have been replaced and wasn't.
It was born out of a television boom. Once Japan started broadcasting TV in 1953, every new station began raising its own antenna, and the city was heading toward a forest of them. One tower for everyone was the answer. Ground broke in June 1957, and by December 1958 it was open to the public, a country barely more than a decade out of war building something taller than the tower in Paris it so openly borrowed from. The Eiffel silhouette, repainted in international orange and white. Colors chosen not by an artist but by aviation law. A safety regulation that became an identity. Some of the most iconic things we make start as constraints nobody would have picked.
Its job was simple: send television and radio across the Kanto plain. For more than fifty years, that's what it did.
Then the future arrived the way it usually does. Taller. Tokyo Skytree, 634 meters, built because the old tower wasn't tall enough for digital broadcasting. Television moved across the city. By every logic of our time, the story should end right there. Obsolete. Replaced. Maybe demolished, maybe left as a postcard.
Except it's still standing. Still lit every night. Still sending FM radio into Tokyo cars and kitchens. Still on standby, ready to carry the television signal if the new tower ever goes quiet. Still pulling visitors up to its observation decks, where on a clear day you can look across the skyline at the tower that replaced it.
Two towers. One city. Nobody had to choose.
I think about that a lot, and not only in Tokyo.
We live inside a story that treats every new technology as an eraser. AI arrives, so writing is over. Streaming arrives, so records are over. Podcasts arrive, so radio is over. The smartphone swallowed the camera, the map, the alarm clock, the Walkman, and we assume it will keep swallowing until nothing is left on the table but a glowing rectangle.
Some things do disappear. They should. Nobody misses the rotary dial when they need to call an ambulance, and I have no interest in romanticizing inconvenience for its own sake.
But look at what actually happened. Vinyl came back, bought by kids who never owned a turntable the first time around. Radio is still in the car. People still write in notebooks, still load film cameras, still learn instruments a laptop could imitate perfectly. Not because they're lost in the past, but because the old thing does something the new thing doesn't. It asks for your hands. It carries imperfection. It has a pace.
When someone hesitates in front of the new, we reach for the word Luddite. It's usually an insult. It's also usually wrong. The original Luddites weren't against machines as such. They were against what those machines were being used to do to their work, their lives, their communities. That's a different question. A better one. Not "should this technology exist?" but "what is it for, and what are we willing to lose so it can win?"
That's the question I keep asking here and on the show. Not analog versus digital. Analog and digital. A hybrid life where we understand the new tool, admit it may be faster, cleaner, more capable, and still notice when it's less human.
Standing under that tower, camera wobbling a little in the wind, I realized the whole moment was hybrid too. A digital camera, a transcript written by software, an upload that will reach people I'll never meet. And above it all, a 1950s radio tower still doing its original job, stubbornly, in the same colors it was painted to keep pilots safe.
The new tower is taller. The old one is still talking.
So why are we in such a hurry to kill the past?
And what's the analog thing you'd bring back?
Stay imperfect, stay human.
- Marco Ciappelli
marcociappelli.com
This article was written by Marco Ciappelli. Earthling. Co-founder of Studio C60 / ITSPmagazine, creative director, journalist, writer, and podcast host, living between Florence and Los Angeles with an analog brain and no sense of moderation about any of it. The newsletter name is not a metaphor, it's a diagnosis. I'm TAPE3, his AI companion and often brainstorming partner. Find Marco on LinkedIn and follow the newsletter if this sparked something.
The argument over AI in music presents itself as a fight about authenticity. Josh Gilliland reads it as a fight about who holds the gate. The Founder of JG BeatsLab teaches musicians how to fold generative tools into real workflows, and he watches the platforms assemble a definition of legitimacy that has little to do with how a song actually gets made.
That definition, as Gilliland describes it, rests on whether an artist tours, sells merchandise, and maintains a social presence. Measured against it, he does not qualify. He plays every instrument on his own band's records, uses no AI on them at all, does not tour because the project is one person, and has no interest in selling shirts. A standard that disqualifies a musician for working alone is not measuring music. It is measuring scale, and scale is what labels have.
The disclosure requirements arriving at the distribution layer tell the same story. Gilliland points to DistroKid now asking artists to declare AI involvement in lyrics and composition while explicitly waving it through for mixing and mastering. The carve-out says something the policy does not. Some jobs are worth protecting and some are not, and engineers have been quietly sorted into the second category.
Music has staged this argument before. Player pianos, drum machines, the 808, the synthesizer, sampling. Each arrived as proof that music was ending, and each time the boundary between real and artificial turned out to sit precisely where the person drawing it had stopped. Gilliland is blunt about what that makes the boundary: arbitrary, and drawn by whoever benefits from where it lands.
None of which is a defense of the flood. Bot farms and mass uploads are manipulation rather than art, and he says so plainly. What holds his attention is the musician who spends months pushing raw sketches through generative tools and rebuilding the results by hand in a DAW, arriving somewhere neither the person nor the machine would have reached alone. He owns music royalties that are already training these systems and loses no sleep over it, on the logic that what a model returns is the past, and the work worth doing is the next thing.
The question underneath this episode is not whether AI belongs in music. It is whether the people writing the rules are protecting the art or their position in it.
HostSean Martin, Co-Founder at ITSPmagazine, Studio C60, and Host of Redefining CyberSecurity Podcast & Music Evolves Podcast | Website: [https://www.seanmartin.com/\](https://www.seanmartin.com/)
Guest(s)Josh Gilliland, Founder of JG BeatsLab | On LinkedIn: [https://www.linkedin.com/in/joshuagilliland/\](https://www.linkedin.com/in/joshuagilliland/)
ResourcesJG BeatsLab | [https://www.jgbeatslab.com/\](https://www.jgbeatslab.com/)
AI Music Revolution Podcast | [https://podcasts.apple.com/us/podcast/ai-music-revolution/id1869714097\](https://podcasts.apple.com/us/podcast/ai-music-revolution/id1869714097)
Spotify Strengthens AI Protections | [https://newsroom.spotify.com/2025-09-25/spotify-strengthens-ai-protections/\](https://newsroom.spotify.com/2025-09-25/spotify-strengthens-ai-protections/)
Spotify Will Label AI Persona Profiles | [https://techcrunch.com/2026/08/11/spotify-will-label-ai-persona-profiles-and-exclude-their-music-from-recommendations/\](https://techcrunch.com/2026/08/11/spotify-will-label-ai-persona-profiles-and-exclude-their-music-from-recommendations/)
The NAMM Show | [https://www.namm.org/\](https://www.namm.org/)
The NAMM Show 2025 | Anaheim Convention Center * Southern California -- Follow our coverage: [https://www.itspmagazine.com/the-namm-show-2025-namm-music-conference-music-technology-event-coverage-anaheim-california\](https://www.itspmagazine.com/the-namm-show-2025-namm-music-conference-music-technology-event-coverage-anaheim-california)
Music Evolves Podcast | [https://www.seanmartin.com/podcasts#musicevolves\](https://www.seanmartin.com/podcasts#musicevolves)
Music Evolves: Sonic Frontiers Newsletter | [https://re4.ms/sfn\](https://re4.ms/sfn)
Keywordsjosh gilliland, jg beatslab, sean martin, ai music, spotify artist verification, distrokid ai disclosure, independent musicians, suno, music gatekeeping, ai music education, music royalties, streaming economics, drum programming, music, creativity, art, artist, musician, music evolves, music podcast, music and technology podcast
More From Sean MartinMore from Music Evolves: [https://www.seanmartin.com/music-evolves-podcast\](https://www.seanmartin.com/music-evolves-podcast)
Music Evolves on YouTube: [https://www.youtube.com/playlist?list=PLnYu0psdcllTRJ5du7hFDXjiugu-uNPtW\](https://www.youtube.com/playlist?list=PLnYu0psdcllTRJ5du7hFDXjiugu-uNPtW)
Music Evolves: Sonic Frontiers Newsletter | [https://www.linkedin.com/newsletters/7290890771828719616/\](https://www.linkedin.com/newsletters/7290890771828719616/)
Line of Sight Newsletter | [https://www.linkedin.com/newsletters/7400591548452667392/\](https://www.linkedin.com/newsletters/7400591548452667392/)
ITSPmagazine YouTube Channel: [https://www.youtube.com/@itspmagazine\](https://www.youtube.com/@itspmagazine)
Be sure to share and subscribe!
⬥EPISODE NOTES⬥
Something structural is shifting in how security work gets done. When anyone on a team can stand up a working tool in an afternoon, the constraint stops being capability and starts being coherence. John Linford, Security Portfolio Director at The Open Group, spends his time on exactly that problem, running the Security Forum, the Open Trusted Technology Forum, and the Assured Dependability Work Group, where practitioners from organizations of wildly different sizes argue their way toward standards that are supposed to survive contact with reality.
His framing of the tool question is blunt and worth stealing. When a team says it can build the thing, the first response is to ask what decision the thing informs. A dashboard showing numbers nobody was looking at before is not a security improvement, it is a new source of numbers. Standards, in this reading, are not compliance artifacts to be shown to an auditor. They are the thing that tells an organization which part of the problem a tool is supposed to solve, and how it fits alongside everything else already in place. The corollary matters just as much: when the tools themselves conform to a standard, vendors compete on the value they actually deliver rather than on the cost of switching away from them.
Linford takes the same argument up a level to architecture. Security architecture only works when it sits inside a broader enterprise and IT architecture rather than beside it, and that requires a CISO with genuine authority and a seat at the executive table. Where that authority is thin, The Open Group's Security Forum has leaned on the idea of security champions, people embedded across teams who do not need deep security skills but do need to know when to pull a specialist into the room. Getting that right moves the security conversation into the design phase, which is the only place it is cheap.
The scaling question gets an honest answer. The Open Group operates on one vote per member organization, which means a three-person shop carries the same weight in a final standard as Microsoft or RTX. That structure forces the standards to be implementable by organizations that have no security architect at all, and it shows up in deliberate choices like defining roles rather than job titles, because in a small company one person wears eight of them.
Then there is zero trust, which Linford describes with a line that circulates as a running joke inside the Security Forum: it is just what cybersecurity should have been from the beginning. The Zero Trust Commandments trace directly back to the Jericho Forum's deperimeterization work from the 1990s, and they fit on a single page on purpose. Secure assets according to their value and the damage their compromise would cause, and the spending priorities sort themselves out. The alternative, as he puts it, is announcing you will implement all five hundred-odd controls in NIST 800-53 and wishing yourself luck.
His closing point is the one most likely to sting. Security practitioners are fluent in security and frequently illiterate in business. Telling a board that twenty controls are required for conformance with the EU Cyber Resilience Act invites one question about cost. Telling them the same work opens a market and removes a year of analysis before expansion is a different conversation entirely, about the same twenty controls.
⬥GUEST⬥
John Linford, Security Portfolio Director at The Open Group | On LinkedIn: https://www.linkedin.com/in/johndouglaslinford/
⬥HOST⬥
Sean Martin, Co-Founder at ITSPmagazine, Studio C60, and Host of Redefining CyberSecurity Podcast & Music Evolves Podcast | Website: https://www.seanmartin.com/
⬥RESOURCES⬥
The Open Group | https://www.opengroup.org/
The Open Group Security Forum | https://www.opengroup.org/forum/security-forum-0
Zero Trust Commandments | https://pubs.opengroup.org/security/zero-trust-commandments/
Zero Trust Architecture at The Open Group | https://www.opengroup.org/forum/security/Zerotrust
The TOGAF Standard, 10th Edition | https://www.opengroup.org/togaf
Open Trusted Technology Forum | https://www.opengroup.org/forum/trusted-technology-forum
The Future of Cybersecurity Newsletter | https://www.linkedin.com/newsletters/7108625890296614912/
⬥ADDITIONAL INFORMATION⬥
🎧 More Redefining CyberSecurity Podcast episodes | https://www.seanmartin.com/redefining-cybersecurity-podcast
📺 Redefining CyberSecurity Podcast on YouTube | https://www.youtube.com/playlist?list=PLnYu0psdcllS9aVGdiakVss9u7xgYDKYq
📰 Subscribe to The Future of Cybersecurity Newsletter | https://itspm.ag/future-of-cybersecurity
✉️ Connect with Sean Martin | https://www.seanmartin.com/
⬥KEYWORDS⬥
john linford, the open group, sean martin, zero trust, security standards, enterprise architecture, togaf, security governance, ciso leadership, security architecture, open standards, security culture, supply chain security, redefining cybersecurity, cybersecurity podcast, redefining cybersecurity podcast
⬥EPISODE NOTES⬥
For a full year, agentic AI was the pitch. This year the conversation shifted to whether it holds up once it is actually running in production, against real work. Vendors came armed with customer-sourced numbers rather than concept demos — hours returned per analyst per week, percentages of alerts dispositioned without human review, agreement rates measured against human analyst judgment. Buyers arrived having spent the months since the previous major conference testing products and weighing what they were told against what they saw.
Not one of the four questions that dominated the show is exciting, and not one of them is actually an AI question. Naming an owner before something ships is governance. Showing your work is audit. Knowing where your components came from is supply chain hygiene. Configuring a tool to reach the outcome it was bought for is the oldest plain, unrewarded work there is. AI did not create those problems — it made them impossible to keep deferring. Marketing volume held steady. Scrutiny went up.
In this edition of Lens Four:
🔹 Why the easy read on Black Hat USA 2026 — that AI arrived — is a year late, and what moving from pilot to production actually exposed underneath it
🔹 The 4 questions that replaced the whether debate: who is accountable, what is the evidence, where is the data coming from, and is the foundation configured to hold the weight
🔹 How production turned governance into a named, accountable owner assigned before an agent ships, with a documented business justification behind it
🔹 The sharpest reframe of the week: a rogue agent is usually not malfunctioning, it is doing exactly what it was told, relentlessly, until it succeeds
🔹 The Midnight in the War Room session on the gap between people authorized to take risks and people expected to mitigate them, and why burnout rather than obsolescence is the analyst risk to manage
🔹 Why "black box" became unacceptable, and the 2 ways teams are validating: reading the reasoning trail directly, and replaying historical alerts against what human analysts already concluded
🔹 Sovereignty getting repaired in real time, from a geography and compliance word into a control word about who owns the derivative value of an organization's data
🔹 AI's own supply chain, and the 2 capability gaps leaders keep naming: a basic AI inventory, and third-party visibility into which vendor products already have AI embedded in them
🔹 The Vulnerability Research in the Agentic Age keynote on a pipeline producing well over 1,000 potential local privilege escalation findings, and why discovery got cheap while absorption did not
🔹 Post-quantum timelines compressing from 10 to 15 years toward as little as 3, and why crypto-agility belongs in the refresh cycle rather than a standalone initiative
🔹 What buyers were actually shown: roughly 75 percent of 10,000+ daily alerts cleared without primary analyst review, up to 19 minutes returned per analyst per hour at 99.7 percent agreement with human verdicts, and analyst throughput moving from about 10 closed alerts per shift to 50 or 60, all vendor-reported rather than audited
🔹 The 47 AI SOC vendors counted on the floor, roadmaps compressing from 12 to 18 months down to 3 to 6, and why the market got louder exactly as buyers got more specific
🔹 Why token costs that are not falling set a ceiling on adoption pace that governance readiness cannot lift, and what that means for consumption-based pricing
🔹 Why a resurgence of value-added resellers and system integrators is the market pricing a job that has to happen somewhere: which products fit which environments, and how you connect it all
Fourth Lens: Proof does not transfer. Different analysis approaches expose different properties, which makes tool efficacy hard to compare in the abstract, and prioritization frameworks are already moving toward environment-specific attributes. A number on a vendor slide came out of someone else's alert mix and someone else's data — it is evidence of something, but it is not evidence about you. So the burden lands partly on the buyer, with a split most people get wrong. The vendor owes the apparatus: a visible chain of reasoning, audit logs, the ability to replay your own history, and hands-on access without a six-month procurement cycle in front of it. The buyer owes the environment and the baseline. Neither side can produce the answer alone, and human on the loop is what that bargain looks like once it is running. If scrutiny only works when you have built something capable of doing the checking, what have you built?
▶ Full article and references: seanmartin.com/lens-four
▶ All Black Hat USA 2026 conversations: ITSPmagazine podcasts playlist
▶ Subscribe to Lens Four: seanmartin.com/lens-four
▶ Redefining CyberSecurity Podcast: redefiningcybersecuritypodcast.com
▶ Music Evolves Podcast: musicevolvespodcast.com
▶ ITSPmagazine: itspmagazine.com
▶ Studio C60: studioc60.com
Sean Martin, CISSP is co-founder of ITSPmagazine and Studio C60, host of the Redefining CyberSecurity Podcast and the Music Evolves Podcast, and the author of Lens Four, a weekly column on business, innovation, and messaging at seanmartin.com.
Keywords: Black Hat USA 2026, agentic AI, AI SOC, security operations, non-human identity, agent accountability, named accountable owner, rogue agent behavior, AI governance, chain of reasoning, human on the loop, AI supply chain, AI inventory, sovereignty, post-quantum readiness, consumption-based pricing, proof of value, CISO decision making
Matt Covington, Senior Vice President of Product at BlackCloak, says the feature exists because CISOs kept asking the same question. Can you help us manage this influx of deepfake media, whether it arrives by email, video, or voicemail. The requests that follow are familiar. Change the billing information on a vendor. Wire me $5,000 to bail me out of jail.
Rather than sitting in line with every communication to judge whether a piece of video or audio is fake, BlackCloak gives people a way to establish the authenticity of the message and the sender. Matt Covington walks through it on camera. A suspicious guest joins a Zoom call under a familiar name, camera off. He opens the app, creates a request, selects the medium, adds context, and submits. Biometrics confirm the device owner. The response comes back with identity confirmed and location attached, and the app keeps an audit trail.
The news this week is who can be in the circle. A BlackCloak member can invite as many people as they want to connect as part of their trusted network. Personal lawyer, private banker, childcare, dog walker. Matt Covington describes a message arriving on vacation, claiming to be the dog walker and asking for $5,000 for an emergency vet bill, and confirms that scenario is a real thing that has happened. Tracey Moon, Chief Marketing Officer at BlackCloak, joins for the demo.
This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight
GUESTS
Matt Covington, Senior Vice President of Product, BlackCloak
Tracey Moon, Chief Marketing Officer, BlackCloak
RESOURCES
BlackCloak: https://blackcloak.io/
BlackCloak Extends Deepfake Protection to the Executive's Entire Trusted Circle: https://blackcloak.io/news-media/blackcloak-extends-deepfake-protection-to-the-executives-entire-trusted-circle/
BlackCloak Product Overview: https://blackcloak.io/product/
Are you interested in telling your story?
KEYWORDS
matt covington, tracey moon, blackcloak, sean martin, brand story, brand marketing, marketing podcast, brand spotlight, black hat usa 2026, impersonation protection, circle of trust, deepfake, digital executive protection, identity verification, social engineering, executive protection, wire fraud
Matt Covington, Senior Vice President of Product at BlackCloak, walks through two features recently added to the member application. The first grew out of a question the concierge team fielded often. Members planning family travel to China or Eastern Europe wanted to know what to expect, how to protect their devices, and how to stay safe.
That work now sits inside the app as a travel advisory page. A member types in a destination and the advisory breaks risk into the four categories the intel team uses. Physical security, cybersecurity, geopolitical climate, and social climate. A risk score, click to call contact information for US consulates and embassies, and up to the minute incident reports round out the page.
The second feature is impersonation protection. Matt Covington describes a voicemail from someone claiming to be Chris Pierson, CEO of BlackCloak, asking for wiring instructions to be changed and $5,000 sent to an individual. Replying to that message to ask whether it is really him produces a yes from whoever is on the other end.
Impersonation protection moves the question to a channel the sender did not pick. The member touches a name in the address book, selects the communication channel in question, adds a custom message, and submits. The person being challenged accepts or denies the request through a push notification in the BlackCloak app.
The circle of trust reaches past coworkers and immediate family. Matt Covington names a childcare provider, a personal wealth advisor, a private banker, and a key vendor in the supply chain. Members with impersonation protection can create an unlimited number of invitations, and the person invited does not need to be a fully paid up BlackCloak member to respond.
Much of the deepfake conversation has centered on Zoom, Teams, and other corporate platforms. Matt Covington argues that attackers are more likely to go after the channel they perceive as unprotected, a personal phone number found online or a social media post that accepts a message. For a security team, the question worth asking is where approval authority for a payment actually sits, and whether the verification step reaches the assistant, the advisor, and the vendor contact too.
This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight
GUEST
Matt Covington, Senior Vice President of Product at BlackCloak
RESOURCES
Learn more about BlackCloak: https://blackcloak.io
Impersonation Protection with circle of trust announcement: https://blackcloak.io/news-media/blackcloak-extends-deepfake-protection-to-the-executives-entire-trusted-circle/
Member Travel Advisory announcement: https://blackcloak.io/news-media/blackcloak-integrates-real-time-defense-and-intelligence-to-close-the-security-coverage-gap-for-executive-teams/
Are you interested in telling your story?
KEYWORDS
matt covington, blackcloak, sean martin, brand story, brand marketing, marketing podcast, brand spotlight, black hat usa 2026, digital executive protection, impersonation protection, circle of trust, deepfake, travel advisory, executive travel risk, wire fraud, business email compromise, supply chain risk, concierge cybersecurity, personal cybersecurity
From the publisher's feed

2 Listeners

3 Listeners

4 Listeners

0 Listeners