63 avsnitt
- When non-technical employees can spin up fully functioning apps in days and AI agents are running parallel workflows that babysit their own pull requests, the traditional SDLC is dead. In this episode, Ashish sits down with Prahathess Rengasamy, Senior Security Engineer at SpaceX AI, to discuss how the staggering compression of development time requires an entirely new approach to security engineering. Prahathess explains why legacy 10-minute PR wait times are incompatible with multi-agent workflows, and how security teams can build internal Model Context Protocol (MCP) servers to inject compliance and security guardrails directly into an agent's context window. We unpack the differences between Q&A chatbots and autonomous coding agents, the critical need to preserve foundational preventative cloud controls (like AWS SCPs and GCP Org Policies), and why holding an autonomous machine accountable for management decisions is a critical architectural flaw. Finally, Prahathess breaks down the "build vs. buy" debate, revealing how small security teams can leverage AI to rapidly deploy internal platforms and paved roads that previously took months to engineer.
Questions asked:
(00:00) Introduction: Compressing the Software Development Life Cycle (SDLC)(01:50) Prahathess Rengasamy’s Background (Block, Apple, SpaceX AI)(02:50) How Non-Technical Employees Are Bypassing Traditional CI/CD Pipelines(07:30) Injecting Security Context into Agents Using MCP (Model Context Protocol)(10:30) The Anti-Pattern: Abandoning Preventative Cloud Controls for AI Buzzwords(12:20) Identity and Accountability: Why Machines Shouldn't Make Management Decisions(15:30) Why Legacy Pull Requests Are Too Slow for Multi-Agent Workflows(18:20) Moving Security Left: Giving Agents Feedback During Local Execution(22:30) The "Build vs. Buy" Shift: Security Teams Deploying Their Own AI Paved Roads(25:40) Killing the Excel Sheet: Building AI Bots to Explain 403 Errors to Developers(29:00) How to Evaluate AI Workflows Without a Deep Technical Background(32:00) Securing Complex Agent Infrastructure and Maintaining Egress Controls(36:00) Treating AI Agents Like Microservices to Control Sprawl(38:30) Coding Agents vs. Q&A Chatbots: Defining the Threat Model(42:30) Applying Inward Security Policies to the SOC and Threat Hunting Teams
Resources discussed during the interview:
fwd:cloudsec talk - Agentic Paved Roads: Shifting Security Left to the Machine That Thinks - How does a global financial engine moving trillions annually manage cyber risk in the age of AI?
In this episode, Ashish sits down with Subra Kumaraswamy, CISO of Visa. Subra discusses Visa's journey as part of Anthropic's Glasswing Project testing the Mythos model, revealing why a majority of Mythos-discovered vulnerabilities were non-exploitable due to robust zero-trust architecture and micro-segmentation.
Subra explains why Visa open-sourced VVAH (Visa Vulnerability Agentic Harness) to help security teams scale vulnerability discovery, prioritization, and remediation across any model. He also breaks down how Visa triages 98% of Level 1 SOC incidents with AI agents, why "Mean Time to Adapt" (MTTA) is replacing legacy patch timelines, and how cross-functional AI governance enables innovation while maintaining strict production controls
(00:00) Introduction: Securing $18 Trillion in Global Transactions(01:50) Subra Kumaraswamy’s 30-Year Career: Netscape, Sun, and Visa(04:30) Improving Visa’s Cyber Maturity Score from 3.2 to 4.9(07:30) Inside Project Glasswing and Testing Anthropic’s Mythos(09:30) Why Visa Open-Sourced VVAH (Visa Vulnerability Agentic Harness)(13:30) Mythos vs. Zero Trust: Why Only 0.03% of Vulns Were Exploitable(16:30) Defining MTTA: Mean Time to Adapt at Machine Speed(19:00) The Threat of Multi-Service Vulnerability Chaining(24:00) Prioritizing Exploits and Automating PRs with Developer Agents(28:30) Moving to Autonomous Defense in High-Stakes Environments(33:00) AI Governance: Balancing Vibe-Coding with Production Gates(36:00) Collapsing Silos: Unifying Endpoint, Identity, and AppSec Signals(39:00) Building Custom Control Planes with Agent Harnesses(45:30) Triaging 98% of Level 1 Incidents with AI Agents(48:30) Hiring for CQ (Curiosity Quotient) & Developer Mindsets(53:00) The "You Laugh, You Lose" Cybersecurity Joke Challenge
Resources spoken about during the episode:
VVAH - Visa Vulnerability Agentic Harness - Is the AI "vulnpocalypse" already here? According to Casey Ellis, Founder of Bugcrowd and pioneer of Disclose.io, we aren't quite in an apocalypse yet, we're actually in a "slopdemic." The cost of discovering vulnerabilities has plummeted, flooding bug bounty and SOC triage queues with low-quality, noisy submissions. Because these queues are so overwhelmed, many highly skilled researchers are simply hoarding zero-days because reporting them has become too difficult.
In this episode, Ashish sits down with Casey to unpack the major themes and mindset shifts from RSA and Black Hat 2026. Casey breaks down how AI is shrinking the OODA loop for defenders, forcing the industry to adopt a true "assume breach" mentality and reconsider deception technology to frustrate active adversaries. They also explore the risks of non-technical employees "vibe coding" corporate applications and why CISOs must get hands-on with AI tools at home if they want to understand the risks their workforce is taking.
Questions asked:
(00:00) Introduction to Offensive AI and Black Hat 2026(02:00) Casey Ellis’s Background (Bugcrowd, Disclose.io)(04:00) Major Themes from RSA and Black Hat 2026(09:00) The Impact of Mythos and Daybreak on Security Awareness(12:30) Why Threat Researchers Are Hoarding Zero-Days(14:00) The "Slopdemic" vs. The "Vulnpocalypse"(17:30) Managing Noisy Bug Bounty Queues and Risk Models(20:00) The Futility of Export Controls on Frontier Models(25:00) Point-and-Pwn vs. Building Complex Attack Graphs(29:30) The Defender’s Dilemma and the Shrinking OODA Loop(34:00) Shadow AI and the Risks of Non-Technical "Vibe Coding"(38:30) Why CISOs Need Hands-On Experience with AI Tools(45:30) The Resurgence of Deception Technology
Resources spoken about during the episode:
Casey's Blog Why Prompt Filters Fail & How to Explain AI Risk to the Board | Cezary Piekarski, Standard Chartered.
2026-09-02 | 37 min.Is the cybersecurity industry repeating the same mistakes with prompt injection that it made with buffer overflows decades ago? As attackers iterate through 50 to 60 prompt filter bypasses daily, attempting to artificially separate instruction from data is becoming a futile effort. In this episode, Ashish sits down with Cezary Piekarski, Group CISO of Standard Chartered. Cezary shares his techno-optimist view on how AI will ultimately benefit defenders, while also unpacking the hard realities of securing an enterprise that ingests 50-plus terabytes of observable data every single day. He explains why reactive security operations are dead, why User Behavior Analytics (UBA) often fails at scale due to stochastic human behavior, and why deception technology must be built directly into your ecosystem to actually work. Cezary shares his thoughts on executive communication, detailing a proven three-step framework for explaining complex AI risks to a board of directors without relying on fear-mongering. Finally, we explore why the tension between AI data hunger and user privacy is largely a "fake dilemma" for security teams.
Questions asked:
(00:00) Introduction: The Futility of Prompt Filters & AI Attack Evolutions(02:30) Cezary Piekarski’s Background and Role at Standard Chartered(03:30) What "Security as a Business Enabler" Actually Means(06:30) The Techno-Optimist View of AI in Cybersecurity(08:50) Why Reactive Security and Manual Triage Are Dead at 50TB/Day(11:30) Doing Deception Technology Right (No More "Surplus Bug" Buying)(15:20) The Flaws of UBA and Behavioral Anomaly Detection(22:30) The Buffer Overflow Analogy: Why Prompt Injection Needs an Architectural Fix(27:30) Under-Discussed Threats: Image-Based Prompt Injection & Data Poisoning(30:00) A 3-Step Masterclass for Explaining AI Risk to the Board(34:30) Why the AI Privacy vs. Security Debate is a "Fake Dilemma"
Resources spoken about during the episode:
Cyber security and fraud safety | Standard CharteredWhy 95% of AI Projects Fail: Model Risk & AI Governance | Sandip Wadje, BNP Paribas
2026-08-27 | 45 min.Why do 95% of enterprise AI implementations fail? According to Sandip Wadje, Managing Director at BNP Paribas, many organizations attempt complex reasoning tasks on day one rather than building a mature foundation around data hygiene and simple summarization workflows. In this episode, Ashish sits down with Sandip to explore how global financial institutions navigate Model Risk Management (MRM), GenAI governance, and regulatory expectations across regions like the UK, EU, and US. Sandip breaks down why classical 20-year-old MRM frameworks fall short when applied to non-deterministic black-box LLMs, and why security leaders must focus on output drift and event taxonomies rather than just input prompt filtering. We also examine the concept of the "AI Kitchen" - a cross-functional governance model bringing together IT, CISOs, legal, and Data Protection Officers alongside practical strategies for calculating AI blast radius, cleaning up overprivileged non-human identity (NHI) permissions, and training CSIRT teams for ML SecOps incidents.
Questions asked:
(00:00) Introduction: AI Risk in Regulated Financial Institutions(01:50) Sandip Wadje’s Background at BNP Paribas(02:50) Classical Model Risk Management (MRM) vs. Generative AI(04:40) Governing the Black Box: Finding the Security Delta(08:00) The CMDB Problem: Building an Accurate AI Use Case Inventory(11:30) Why 95% of AI Projects Fail: Summarize, Write, Reason(15:00) Continuous Evaluation (Evals) and Catching Output Drift(18:50) Event Taxonomy: What Happens When AI Decisions Drift?(25:40) Training CSIRT and SOC Teams for ML SecOps Incidents(30:00) Compensating Controls: Remote Browser Isolation & Prompt Monitoring(34:30) Non-Human Identities (NHI) & Cleaning Birthright Permissions(36:30) Balancing a $1M Savings Against a 4% Revenue Fine(38:30) Open-Weight Models vs. Frontier LLMs in Financial Services(41:00) The "AI Kitchen": Cross-Functional AI Governance(44:30) The #1 Rule for AI Security: Understand Your Data First
Fler podcasts i Teknologi
Trendiga poddar i Teknologi
Om AI Security Podcast
The #1 source for AI Security insights for CISOs and cybersecurity leaders.
Hosted by two former CISOs, the AI Security Podcast provides expert, no-fluff discussions on the security of AI systems and the use of AI in Cybersecurity. Whether you're a CISO, security architect, engineer, or cyber leader, you'll find practical strategies, emerging risk analysis, and real-world implementations without the marketing noise.
These conversations are helping cybersecurity leaders make informed decisions and lead with confidence in the age of AI.
Podcast-webbplatsLyssna på AI Security Podcast, Veckans AI och många andra poddar från världens alla hörn med radio.se-appen

Hämta den kostnadsfria radio.se-appen
- Bokmärk stationer och podcasts
- Strömma via Wi-Fi eller Bluetooth
- Stödjer Carplay & Android Auto
- Många andra appfunktioner
Hämta den kostnadsfria radio.se-appen
- Bokmärk stationer och podcasts
- Strömma via Wi-Fi eller Bluetooth
- Stödjer Carplay & Android Auto
- Många andra appfunktioner


AI Security Podcast
Skanna koden,
ladda ner appen,
börja lyssna.
ladda ner appen,
börja lyssna.
AI Security Podcast: Poddsändningar i Familj




























