
Sign up to save your podcasts
Or


Why AI Needs a Deterministic Pass First
As security teams lean harder on AI to catch threats faster, a foundational question keeps getting skipped: is the data feeding that AI actually trustworthy? On this episode of Cyber Sentries, host John Richards sits down with Chris Nyhuis, president and CEO of Vigilant, to unpack why forensic validation — not faster algorithms — may be the missing piece in modern threat detection.
Why Your Detection Stack Might Be Blind to Its Own Blind Spots
John and Chris dig into what Chris calls the "joystick effect" — a technique where threat actors quietly manipulate logs and EDR training data so security tools learn to miss them entirely. It's a tactic that's existed for decades, but as more teams hand decisions to AI without questioning the data underneath, it's becoming far more dangerous.
Chris also walks through why packet loss on span ports and mirror ports can silently gut visibility long before AI ever gets involved, and why physical taps and chain-of-custody collection matter more than flashy detection features. The conversation moves through Vigilant's "deterministic pass, then AI" model — a method for cutting hallucinations and dramatically speeding up detection — and closes with a candid look at how marketing-driven "top vendor" lists have diluted trust across the industry.
Questions We Answer in This Episode
Key Takeaways
Chris leaves listeners with a clear challenge: build detection on evidence you can verify, not on tools you simply hope are working. As AI takes on a bigger share of security decisions, that discipline is what will separate resilient organizations from the next headline breach.
Resources
By TruStory FM5
66 ratings
Why AI Needs a Deterministic Pass First
As security teams lean harder on AI to catch threats faster, a foundational question keeps getting skipped: is the data feeding that AI actually trustworthy? On this episode of Cyber Sentries, host John Richards sits down with Chris Nyhuis, president and CEO of Vigilant, to unpack why forensic validation — not faster algorithms — may be the missing piece in modern threat detection.
Why Your Detection Stack Might Be Blind to Its Own Blind Spots
John and Chris dig into what Chris calls the "joystick effect" — a technique where threat actors quietly manipulate logs and EDR training data so security tools learn to miss them entirely. It's a tactic that's existed for decades, but as more teams hand decisions to AI without questioning the data underneath, it's becoming far more dangerous.
Chris also walks through why packet loss on span ports and mirror ports can silently gut visibility long before AI ever gets involved, and why physical taps and chain-of-custody collection matter more than flashy detection features. The conversation moves through Vigilant's "deterministic pass, then AI" model — a method for cutting hallucinations and dramatically speeding up detection — and closes with a candid look at how marketing-driven "top vendor" lists have diluted trust across the industry.
Questions We Answer in This Episode
Key Takeaways
Chris leaves listeners with a clear challenge: build detection on evidence you can verify, not on tools you simply hope are working. As AI takes on a bigger share of security decisions, that discipline is what will separate resilient organizations from the next headline breach.
Resources

444 Listeners

8 Listeners

21 Listeners

37 Listeners

136 Listeners

38 Listeners

29 Listeners

12 Listeners

101 Listeners

4 Listeners

2 Listeners

8 Listeners

0 Listeners

69 Listeners

0 Listeners

5 Listeners

8 Listeners

0 Listeners

0 Listeners

2 Listeners