
Hosted by Mike Shema
About all things AppSec, DevOps, and DevSecOps. Hosted by Mike Shema and John Kinsella, the podcast focuses on helping its audience find and fix software flaws effectively.
403 episodes · publishes weekly · latest 2026-06-30 · ~63 min/episode
Rank
#335
Substance
78.0
/ 100
Breakdown
Scored 2026-07
Updated monthly
Across the index
#335 of 6183
Substance
Top 5%
outscores 95% of the index
Application Security Weekly ranks #335 on The B2B Podcast Index with a substance score of 78.0 out of 100, scored across 1 recent episode. It scores highest on guest caliber and specificity & evidence. Both interview guests are active CEOs and co-founders of companies building in the agent identity/security space with real customer deployments and proprietary research data, making them genuine practitioners rather than thought leaders; the co-host Tyler Shields contributes substantively but is not a named guest, and overall seniority stops short of CISO or large-enterprise operator level.
Averaged across 1 recently scored episode, with cited evidence.
The two Identiverse interviews yield genuine operational insight - blended identity, dynamic least-privilege scoped to agent goal, and the counterintuitive expansion of plain-text credentials due to local agent adoption. However the news segment is padded with long discursive exchanges that rarely land a crisp novel point, diluting the per-minute yield considerably.
“finding count parity is not capability parity”
“secrets credentials that are just being stored, you know plain text in the endpoint which was something that we thought is shrinking over time because of Vault and other things is now actually expanding”
A handful of genuinely fresh framings emerge - agents as a mix of human unpredictability and machine scale, 'blended identity' with time-scoped rights, and the 'what agents can do vs what they say' reframe - but the surrounding discussion defaults to familiar AppSec commentary about checklists, shadow IT, and least privilege without meaningfully extending those ideas.
“next year I hope that people will start to think more about what the AI can do and not what it says”
“agents pursue a goal, but in a much larger scale continuously do so. So we need to think about them a bit differently”
Both interview guests are active CEOs and co-founders of companies building in the agent identity/security space with real customer deployments and proprietary research data, making them genuine practitioners rather than thought leaders; the co-host Tyler Shields contributes substantively but is not a named guest, and overall seniority stops short of CISO or large-enterprise operator level.
“we have a customer. They're a, ah, large investment company, okay. And um, they've decided to give all of their employees access to Claude, either Claude Webb or Claude Desktop”
“82% of CISOs share that they found an unsanctioned AI agent. They discovered shadow AI. Uh uh, although they have some programs to control and to inventory those agents”
Notable concrete data points appear - 82% of CISOs statistic from Token Security's own two-month-old research, 362 Linux kernel patches over six years with one contributor responsible for ~200, the large investment-company deployment architecture using Claude plus MCP servers - but many claims in the news segment are unsourced generalisations and customer examples remain anonymised.
“one contributor however did about 200 of them. So two thirds of those commits were one contributor”
“we're just releasing Copilot support for Microsoft Copilot Studio. So you're having third party apps, uh, connect Intelligence”
Mike Shima asks pointed and specific follow-ups in both interviews - notably pressing on agent debt and on how granular RBAC stays granular in practice - and occasionally names the specific risk rather than accepting vague answers; the news-segment banter with Tyler is collegial but meandering, with both parties tending to agree and expand rather than probe or challenge.
“Have you encountered agent debt so far? Organization organizations where these agents are running. They have they. But the, the employee has left but the agent didn't get spun”
“How has that granular access control actually stayed granular without becoming just give them everything”
First period on the Index - history builds from here.
1 scored on substance · 60 tracked in total.
Add this badge to your site - it links back here and updates automatically as you rank.
<a href="https://index.fame.so/show/application-security-weekly-audio" target="_blank" rel="noopener">
<img src="https://index.fame.so/badge/application-security-weekly-audio/badge.svg" alt="Ranked #44 on The B2B Podcast Index" width="360" height="136" />
</a>Track Application Security Weekly's rank
Get an email whenever this show moves up or down the Index. Monthly at most, no spam.
The themes that come up most across this show's episodes.
Podcasts that dig into the same topics.