54 afleveringen
- In this episode, Andrea Sivieri, Chief Product and Technology Officer at CoreView, explains how CoreView secures that overlooked layer, the configuration, permissions, and structure of a Microsoft 365 tenant rather than just the data flowing through it. Joining him are Davi Ottenheimer, principal at Flying Penguin, and Will Gregorian, CISO at Galileo Medical.
Want to know:
Why does Microsoft's own admin console give you roughly a thousand ways to configure a single setting?
What's the actual difference between securing your Microsoft 365 data and securing your Microsoft 365 configuration?
How does a "virtual tenant" stop one compromised admin account from exposing your entire company?
How do you stay ahead of a vendor that can change its APIs or shut off access without warning?
How do you catch a change to your tenant that you had no way of seeing in the first place?
How far back can you rewind a tenant's configuration history, and why does that number matter?
What does managing a 2.7 million-user tenant reveal about resilience that a small business never has to think about?
Check out the episode for the answers you need.
A huge thanks to our sponsor, CoreView - In this episode, Abby Kearns, CEO of ActiveState, explains how her company closes that gap by rebuilding open-source packages from verified sources before they ever reach a developer's pipeline, rather than scanning for problems after the fact. Joining her are Doug Mayer, vp and CISO at WCG, and Howard Holton, former CEO at GigaOM.
Want to know:
Why is AI increasing exploitability on both the attacker side and the developer side of the open source supply chain?
How does a package catalog replace your package manager without slowing developers down or pushing them around the process?
What does ActiveState do differently than upstream scanning tools like JFrog Artifactory or Sonatype Nexus?
What happens when a developer needs a package that isn't in the catalog yet?
How is ActiveState thinking about shadow AI and SBOM coverage beyond language libraries?
What upcoming regulatory deadlines, like the EU Cyber Resilience Act, should security teams have on their radar?
What happens to open source security when AI produces more CVEs and patches than the maintainers behind these projects can process?
Huge thanks to our sponsor, ActiveState
ActiveState gives security and engineering teams a single governed source for open source software. With 79 million components built from source, continuously remediated, and delivered directly into the tools teams already use, ActiveState eliminates the CVE backlog and the developer toil that comes with it. Companies see a 60 to 99% reduction in CVEs and reclaim up to 30% of developer time.
Curate a private, vetted repository of open source components from the ActiveState Library that developers use safely without scouring the internet. A Curated Catalog provides your security team total control over what enters their environments while giving engineering teams a fast, secure way to build, onboard, and start new projects. - In this episode, Grant Oviatt, vp of product and co-founder at Prophet Security, explains how his platform deploys AI agents to investigate and respond to alerts the way a skilled analyst would, using REST API integrations across existing security tools rather than absorbing all your data into another SIEM. Joining him are Will Gregorian, CISO at Galileo Medical, and Howard Holton, CEO at GigaOm.
Want to know:
Why are AI-powered SOC tools adding to analyst frustration rather than reducing it?
When an AI agent makes a bad call on an investigation, who actually owns that failure?
How does Prophet Security's audit trail let you trace every query, piece of evidence, and reasoning step an agent used?
Why is Prophet Security using frontier models rather than training its own, and how does security-specific context change the outcome?
What does giving an AI agent remediation authority look like in practice, and where does Prophet Security draw the line?
How long does it realistically take to go from contract to running Prophet Security against live alerts?
Check out the episode for the answers you need.
Huge thanks to our episode sponser, Prophet Security
Prophet AI is an Agentic AI SOC Platform that investigates and responds with context, shows its reasoning, and elevates every part of your SOC. Prophet AI SOC Analyst investigates and responds to alerts in minutes; Threat Hunter streamlines threat hunts with a natural language interface; and Detection Advisor provides insights on detection quality and coverage. - In this episode, Venkat Siva, co-founder and CEO at CompFly AI, explains how his platform gives security, engineering, and business teams a control plane for autonomous AI agents across their full lifecycle. CompFly discovers agents, assigns each one a verifiable distributed identity, runs adversarial and safety simulations before launch, enforces deterministic policies at runtime through a gateway, and produces immutable audit logs for compliance teams after the fact. Joining him are Mike Lockhart, CISO at EagleView, and Gary Chan, System VP and CISO at SSM Health.
Huge thank you to our sponsor, CompFly AI
CompFly is the control plane for the agentic enterprise. We make autonomous AI agents governable at scale discovering them, evaluating their risk, and enforcing real-time guardrails before execution. Enterprises deploy CompFly to move agents from sandbox to production with the evidence trail their boards/management require. - In this episode, Nico Waisman, CISO at XBOW, explains how XBOW uses autonomous AI agents to run continuous, incremental penetration testing without triggering false-positive avalanches or taking down production systems. Joining him are Jacob Combs, CISO at Tandem Diabetes Care, and Davi Ottenheimer, president at Flying Penguin.
Want to know:
Why can't traditional pen tests keep up with modern attack surfaces?
How XBOW's attack credit model maps to the way security teams already size testing effort?
What stops an autonomous pen testing agent from causing real damage in production?
How incremental testing works when a new pull request changes the application?
Where XBOW is headed on prompt injection and LLM-specific vulnerabilities?
How you audit what the AI actually did during an assessment?
What novel vulnerability chains are emerging as AI reasoning models get more capable?
Check out the episode for the answers you need.
Huge thanks to our sponsor, XBOW
Meer Nieuws podcasts
Trending Nieuws -podcasts
Over Security You Should Know
What if you could get a no-nonsense look at security solutions in just 15 minutes? Security You Should Know, the latest podcast from the CISO Series, does just that.
Hosted by Rich Stroffolino, each episode brings together one security vendor and two security leaders to break down a real-world problem and the solution trying to fix it. Expect straight answers on:
How to explain the issue to your CEO
What the solution actually does (and doesn't do)
How the pricing model works
Then, our security leaders ask the tough questions to see what sets this vendor apart.
Subscribe now and and stay ahead of the latest security solutions. Visit CISOseries.com for more details.
Security You Should Know: Connecting security solutions with security leaders.
Podcast websiteLuister naar Security You Should Know, de Volkskrant Elke Dag en vele andere podcasts van over de hele wereld met de radio.net-app

Ontvang de gratis radio.net app
- Zenders en podcasts om te bookmarken
- Streamen via Wi-Fi of Bluetooth
- Ondersteunt Carplay & Android Auto
- Veel andere app-functies
Ontvang de gratis radio.net app
- Zenders en podcasts om te bookmarken
- Streamen via Wi-Fi of Bluetooth
- Ondersteunt Carplay & Android Auto
- Veel andere app-functies


Security You Should Know
Scan de code,
download de app,
luisteren.
download de app,
luisteren.
Security You Should Know: Podcasts in familie

























