The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/AI & Data/Cybersecurity Where You Are
Cybersecurity Where You Are artwork

Episode 194: 2026 Cybersecurity Predictions Mid-Year Review

Cybersecurity Where You Are · 2026-07-01 · 51 min

0:00--:--

Key moments - from our scoring

Substance score

50 / 100

Five dimensions, 20 points each

Insight Density10 / 20
Originality10 / 20
Guest Caliber14 / 20
Specificity & Evidence9 / 20
Conversational Craft7 / 20

Sean Atkinson (CISO at CIS), Tony Sager (SVP and Chief Evangelist), and Ed Skoudis (President of SANS Technical Institute) conduct a mid-year review of 2026 cybersecurity predictions made by CIS experts earlier in the year. The discussion centers on AI's dominance across defensive and offensive domains, with particular emphasis on agentic AI emerging as both a vulnerability discovery tool and autonomous attack vector. Speakers highlight how AI-powered penetration testing is commodifying low-end security assessments - one NYU professor demonstrated a basic pen test using GenAI for under $4 - while simultaneously raising the bar for sophisticated threats. The conversation covers supply chain vulnerabilities in source code and the looming transition to compiled code scanning, the threat of adversaries dynamically shifting APT profiles mid-campaign to evade attribution, and critical SLTT (state, local, tribal, territorial) government cybersecurity challenges. With funding constraints coinciding with rising AI threats, speakers emphasize that underfunded jurisdictions face systemic disadvantage without coordinated national-level infrastructure strategies beyond traditional threat feeds. This episode serves CISOs, security leaders, and government IT decision-makers confronting AI-augmented threat landscapes and resource allocation pressures.

Key takeaways

  • →AI has moved from novelty to strategic business imperative, with defenders needing to focus on genuinely useful applications rather than automating processes just because they're automatable.
  • →Agentic AI is enabling low-cost, continuous vulnerability discovery and penetration testing at massive scale, with autonomous systems soon able to identify exploits in compiled code within 3-6 months.
  • →Adversaries can now dynamically shift their APT profiles and false flags throughout campaigns, making attribution analysis through traditional indicators (language, text fragments, source IPs) significantly harder.
  • →Supply chain attacks are being accelerated by AI's ability to find vulnerabilities in source code at scale and manipulate packages, representing a major shift in attack tactics.
  • →Underfunded state, local, and tribal governments face a critical resource gap as AI capabilities raise defense requirements while budgets are being cut, requiring systemic solutions beyond threat feeds sent to individual organizations.

Guests

Tony SagerEd Skoudis

Topics in this episode

MythosChatGPT 5.5 CyberProject GlasswingCIS BenchmarksSANSCounter Hack ChallengesAdvanced Persistent Threats (APTs)Agentic AI penetration testingCIS hardened imagesSLTT (State, Local, Tribal, Territorial) governments

Questions this episode answers

How is AI being used in supply chain attacks in 2026?

AI is being used to discover vulnerabilities in source code at mass scale and is expected to transition to compiled code and bytecode within 3-6 months. Attackers are using AI to find vulnerabilities autonomously, create exploit packages, and manipulate software packages during the development supply chain process.

What is the pen test puppy mill and how is AI changing it?

The pen test puppy mill refers to low-quality penetration testing services that provide basic scans and limited value. AI is replacing these services by automating straightforward penetration tests at scale - a NYU professor demonstrated a basic pen test using GenAI for under $4, enabling daily testing instead of annual assessments.

What threat does dynamic APT profile shifting create for defenders?

Adversaries can now use AI to dynamically shift their apparent advanced persistent threat (APT) profile mid-campaign, appearing as different nation-state actors (North Korean, Russian, Chinese) simultaneously. This makes attribution nearly impossible and allows attackers to waste defender resources on false attribution at minimal cost.

How are state and local governments struggling with cybersecurity in 2026?

SLTT governments face compounding challenges: funding cuts are reducing resources at the same time as AI-powered threats are escalating, creating a 'cyber have nots' problem. These underfunded organizations lack the resources to adopt new AI-powered defense tools or maintain adequate staffing, requiring national-level infrastructure strategies rather than traditional threat intelligence approaches.

What is the risk of automating vulnerability disclosure through AI?

Speakers warn against 'paving the cow paths' - automating traditional processes without questioning whether the underlying approach is effective. Rapid AI-generated vulnerability bulletins may not improve actual defense outcomes if the information model doesn't match how defenders assess risk and remediate vulnerabilities differently than before.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

10 / 20

A handful of genuinely interesting claims - compiled-code vulnerability discovery timeline, dynamic APT profile shifting, authorization sprawl as the post-Zero-Trust attack surface - are buried under extended AI platitudes, policy hand-wringing, and ceremonial rambling that pads a 51-minute runtime without adding proportionate substance.

give it three or at the very most six months and you're going to start seeing that in compiled code. Finding vulnerabilities and creating exploits for it autonomously
authorization sprawl is the new pivoting

Originality

10 / 20

The dynamic mid-campaign APT persona switching and the authorization-sprawl framing are genuinely fresh angles; however the bulk of the episode recycles well-worn takes - AI favors attackers, compliance ≠ security, SLTTs are underfunded - that any B2B security listener has heard dozens of times.

A single adversary dynamically shifting their APT profile in the middle of a campaign or throughout a campaign. So today they look like this North Korean actor, tomorrow they look like this Russian actor
AI is just going to replace the pen test puppy mill. It's going to drain the swamp of low quality pen tests

Guest Caliber

14 / 20

Ed Skoudis is a legitimate top-tier offensive-security practitioner with real operational depth, and Tony Sager's NSA Red Team oversight background adds credibility; the weakness is that this is essentially a CIS house podcast with one outside guest, limiting breadth of perspective.

Torkel Opsol from my team...he is working on a framework that is looking very promising, um, along those fronts
I was working on a case...I called some friends and they hooked me up with a linguistics expert in the army. And I said...she said very quickly, oh, that's Farsi

Specificity & Evidence

9 / 20

A few concrete anchors exist - the $4 NYU pen test, Josh Wright's RSAC presentation, Torkel Opsol's named research, the Tenable survey result - but the majority of the episode operates at high abstraction with no hard metrics on adoption rates, breach costs, or prediction accuracy against a defined baseline.

there's a professor from NYU who was talking about, he did a, I assume a fairly low level pen test using a Gentek AI for $4
authorization sprawl that was coined by Josh Wright, uh, sans instructor...He presented on that at RSAC last year

Conversational Craft

7 / 20

Sean's questions routinely pre-answer themselves before inviting the guest to respond, and neither host challenges a single claim across 51 minutes; the conversation is collegial and supportive throughout with no productive friction or probing follow-up when Ed makes specific predictions about compiled-code exploitation timelines.

Ed, um, in terms of what you're seeing in the space from a um, Red Team perspective. Do we see effective implementation of Zero Trust or it's not filling some of the gaps that are some of the usual uh, elements of infiltration that uh, you see
I know you've been doing some phenomenal things in the space. Uh, the sans course, uh, that's uh, both developed and future development in the space. The application, the offensive elements

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker B49%
  • Speaker A27%
  • Speaker C24%

Most-used words

security30different27sean18zero18space17trust17level15compliance15tony14terms13team12predictions11thoughts11seeing11attackers11part11

Episode notes

In episode 194 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager sit down with Ed Skoudis , President of SANS Technology Institute. Together, they conduct a mid-year review of 2026 cybersecurity predictions from seven Center for Internet Security® (CIS®) experts, as shared on the CIS website . Here are some highlights from our episode: 01:50 . Ongoing conversations about improving defense with artificial intelligence (AI) 05:19 . A trap to avoid: Automating things with AI because we can regardless of utility 06:54 . Ed's prediction about a near-term transition for AI-enabled vulnerability discovery 09:27 . How AI agents change the economics around conducting a penetration test 11:26 . Adversary emulation: A blurry proposition when threat actors use AI to look like anybody 14:02 . Ed's prediction about threat actors shifting APT profiles within a single attack campaign 17:00 . The need to systematically rethink cyber defense to support state and local cybersecurity 23:34 . How adversaries are pivoting to the "authorization sprawl" in light of zero trust efforts 29:20 . Industry-specific threat intelligence as a way to keep organizations informed 32:10 .

Full transcript

51 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Welcome to Cybersecurity, where you are, uh, the center for Internet Security's podcast. I'm Sean Atkinson, CISO at cis.

Speaker B: And I'm Tony Sager, senior Vice President and Chief Evangelist at cis. Cybersecurity affects us all whether we're online at home, managing a company, supporting clients, or running a state or local government.

Speaker A: So join us on Wednesdays as we discuss trends and threats, explore security best practices, and interview experts in the industry.

Speaker B: Together we'll clarify these issues and creating confidence in the connected world.

Speaker A: Hello and welcome to the show Cybersecurity where youe Are. I'm Sean Atkinson, ciso here at the center for Internet Security, joined by the host with the most, the hall of famer, the difference maker, uh, Mr. Tony Sager. Tony, how are you, sir?

Speaker B: Great, Sean. Great to be back. And great to be joined by somebody special.

Speaker A: Absolutely. And Ed, joining us here for our prediction, uh, review, the president of the SANS Technical Institute, the founder of Counter Hack Challenges, the godfather himself, Mr. Ed Scotus. Ed, how are you, sir?

Speaker C: Great to be here. Thank you. Thank you for the invite. I'm super happy to be here. Got some great stuff to go over. Other people's predictions, not my own.

Speaker B: Exactly. What a great gig, I'm telling you.

Speaker A: Exactly.

Speaker C: I, I got a little bag of rocks here. I'm ready to throw them. I'm not in a glass house.

Speaker A: Yeah, I'm ready to dodge. I'm ready to dodge. So, so we start. Ed and, um, myself and Tony had reviewed, uh, when these first came out early 2026, we went through, did a review, uh, and so it's um, called seven cis experts, 2026 cybersecurity predictions. Now, I did at the time say it's six experts and Sean, but we'll digress and we'll jump in, um, to the review. So, you know, as we were going through, and again, I took another quick look at these, uh, before the episode, um, I think for me. So we'll start with mine. Mine are at the top for some reason. But, uh, AI, I mean, it was shooting fish in a barrel at this point. With respect to if I put AI as a prediction, fantastic, you win. Um, but in this space, um, and Ed, we've been doing some work in the space, Tony. We've had a lot of, um, elements coming through with Mythos and project Glasswing, um, ChatGPT 5.5 Cyber. There's a lot going on in this space. And, um, I think when we start to address dominating the headlines, I think it's dominating the Economy. It's dominating all of our security policy conversations. It's how are we going to start to approach this? And I, I think there's many different avenues we can go in the space. And one of the things thematically that we see, see, um, Don freely mentions the same thing. He, uh. I think he actually hit it really very nicely in terms of the shortening the time frame of publications, of bulletins and uh, really leaning into some of the differential engineering of patches to then look at exploitability. Very, very key. Lee Noriega says the same thing. And again, they put it in a lot of different ways here. But, you know, it's A.I. i mean, like I said, it's something that we see, we continue to discuss. And I think it continues to be one of these elements that, where I think we're beyond that. This is, oh, a neat technology that this is strategically aligned to everybody's business plan now and moving forward. But. Tony, want to get your thoughts?

Speaker B: Yeah, I think, um. Yeah, you couldn't go wrong, right. In fact, you had to say AI in every document or whatever. But, you know, the. I think what I was not prepared for was the sort of this total discussion that you mentioned, right, about the economic implications and, you know, the battling it out by, uh, press releases by the major companies. Right? Who's. Who's in the lead and who's got the most mysterious or most dangerous and all the social discussion about the meaning of this to people. Uh, you know, our focus is on, on work, right? The work of defense and the work. And. And I think both you and I were optimistic in that, uh, you know, in this sort of like, better for the good guys or the bad guys. Um, a point we've made before is that good, uh, bad guys are, Are more naturally capitalistic, right? If it, if it works and gives them an advantage, they're quicker to jump on it and they're less encumbered by things like cranky users and CSOs that won't give them the policy permission to experiment and all that kind of stuff. So, you know, they're, they're, they're going for it. And so you see some rapid returns. But, you know, in the midterm, um, it just feels like there's so much opportunity to improve defense. You know, this volume of stuff, you know, the grunt work, the details, the gazillions of data points that poor human beings are trying to bring together, correlate, convert from one form to another. It's just overwhelmed offenders for my entire, uh, career. And there's so much opportunity, I think for better.

Speaker A: Uh.

Speaker B: So I think. I think that uh, really matters. But one of the things also to just mention here, right, Is one thing you have. You want to avoid some traps, right? There's a trap I call, uh, paving the cow paths. Right. Maybe we could dump certain kinds of information out there in a tenth the time it used to be and so forth. But is that information really useful? Is it really. Is it sort of based upon a particular model of the way adversaries work and our ability to respond? Or is that irrelevant in a. In a different way that we think of how I learn about my vulnerabilities, uh, and assess the risk to them and then remediate that. Could we do that by a different path? So we have to avoid the trap of, you know, uh, automating things because we can, you know, um, throwing AI, uh, I call it Peyton, a little, uh, you know, put a little, uh, AI lipstick on that pig. You know, it's. It's still a pig. And so, you know, I'm not saying we shouldn't look at every possibility, but we don't want to get kind of carried away with the automate. The easy stuff, because it's easy to automate. But is it in fact a useful thing to do? But, you know, and I think there were some big ideas in there. But I just wanted to leave with the point, Sean, that uh, you know, again, I, you know, the discussion of stock prices and who's got the best relationship with the federal government and you know, who's in the lead with a more clever model. Like I just wouldn't. I wasn't kind of thinking of all those things when we talked about it. We were. You know, as a technologist, we tend to focus kind of in our domain. But it's been fascinating to watch the. The popular discussion and people ask me about this kind of stuff. Right. Non technologists in my neighborhood. And I go. I was like, wow, this really has hit the, uh, popular conversation now.

Speaker A: Absolutely. Ed, I know you've been doing some phenomenal things in the space. Uh, the sans course, uh, that's uh, both developed and future development in the space. The application, the offensive elements. And we saw one element I just, I'm just going to um, reference it very quickly is Marcus, uh, Sachs had mentioned offensive, uh, autonomous and agentic AI will start to emerge as mainstream. Um, I think you've lent into that hugely with new, uh, capability and things you're assessing too.

Speaker C: Yeah. Yeah. So, uh, first off, let me just point out how novel it is that, um, you have, you know, a prediction show and then six months later you actually followed up with saying, hey, how did our predictions work out? I don't think I've ever heard of that in this industry, let alone other industries. Right. So this is, this is a very unique thing and my hat is literally off to you, uh, for doing this. Um, and thankfully you're not holding me to account yet because I'm not on the list. Um, but with respect to your specific question, uh, yeah, I think Marcus nailed it right there. Offensive, autonomous and agentic AI will emerge as a mainstream threat. You know, we are seeing that attackers are using it. Um, and then there are some other parts like what you said, uh, Sean and uh, Randy Rose's uh, predictions about supply chain attack. Where I think the AI stuff in the first six months of this year has really taken off is finding vulnerabilities in source code, um, at mass scale. We've seen that, um, and you kind of tease that out and others do a little bit. Um, but then the mass use of AI in these supply chain attacks, uh, creating whole packages or hacking in and uh, manipulating packages and such. So AI has been used a lot for that. Um, so I think those predictions and that directionality that you and Randy Rose pointed out are spot on. And, and if I may make a prediction here, I think that's about to transition very quickly. The vulnerability discovery in source code is about to transition to vulnerability discovery in compiled code bytecode. Uh, my team is doing a lot of experimentation with that, specifically Torkel Opsol from my team, I think Sean, you've met Torkel, brilliant guy, um, and he is working on a framework that is looking very promising, um, along those fronts. So that's a little mini prediction. The stuff that you're seeing with source code now, give it three or at the very most six months and you're going to start seeing that in compiled code. Finding vulnerabilities and creating exploits for it autonomously, which is again back toward uh, what uh, Marcus X was talking about.

Speaker A: Yeah, you know, one of the things there is the, um, the capabilities that we're starting to see in this space, the agentic AI penetration test and the application in these different areas. Really fascinating in terms of all the new use cases that I'm starting to see where it's becoming. Well, I don't have resources in terms of personnel, but I do have an agentic AI capability to augment certain activities and capabilities within an organization. Really starting to see that take, um, get some traction I think in the space too, very interesting. But I think that differentiates now a new risk profile it in that area and uh, what we should be thinking in terms of the agency that's provided to the uh, agents in this area. And um, so I think that'll be an interesting thing that we'll be looking at uh, uh, moving forward as well.

Speaker C: I agree. You know, there's this term I coined years ago, the pen test puppy mill. That's the place where you go for a really low quality pen test. It's not. And look, I guess they provide some value because they're doing some low level scans and may find some things. And I think AI is just going to replace the pen test puppy mill. It's going to drain the swamp of low quality pen tests. I still do in my heart of hearts believe that there is a need for human, you know, assisted directed, uh, high end pen tests. I think that's very important and I'm trying to make sure we build our team to that. But um, clearly things are moving so that these, these low level, rather straightforward pen tests again that provide some value. They're going to find some things doing that with agentic AI and doing it on a regular basis instead of once a year, maybe once a day. Um, you know, I don't know if you saw the presentation at the event that we were at earlier this week, but um, there's a professor from NYU who was talking about, he did a, I assume a fairly low level pen test using a Gentek AI for $4. So it's less than the price of a cup of coffee, uh, at Starbucks, certainly in New York City. So I think that changes as Tony was talking about. The economics of this is changing, uh, rapidly.

Speaker B: Yeah, you know, and you know, part of my past life, right. Was the oversight uh, of the NSA Red Team, which was the pioneer for a lot of large scale. And there was a lot of thinking at the time about emulation, uh, of the adversary. So, and different adversaries, right, from different, say parts of the world, different nations, different criminal elements clearly had characteristics or they, they um, had preferences. For example, some would do anything to avoid visibility or discovery or attribution back to a source. Other adversaries didn't seem to care if they got caught. Right. Because they could blame it on somebody else. And so you would think about, you know, a lot of thought went into this. What's a, um, what adversary are we emulating? What are the characteristics which can be everything from technical tradecraft to behavior to the risk model? And it seems to me all that's starting to blur now that you can look like whatever you want to look like, you know, or you could be a really. The profile doesn't help you so much to, to understand how to defend yourself because anybody could look like anybody. Right. You could build the entire package and you could say I want to look like I'm. Or maybe my preference function is um, discovery is less important to me than, you know, this. Or maybe I'm looking for a single strike, but not necessarily a str, A sustained uh, infrastructure of uh, exfiltration. And all those are, are you know, they go from hard to relatively straightforward. Right. But so if you looked at the classical red teams as they stood up, I mean you'd have an army of people who work the front end, you know, who can run scripts. Right. Do the scans and simple things, but couldn't, couldn't adjust. You'd have kind of people who could direct, you know, the, the front line. You had tool makers in the back room. You had kind of a reconnaissance, oversight, management, you know, and again that becomes a technical package of a lot of that could be just bundled together in a really clever way and made to have characteristics which could be part of your deception. Right. Maybe you, maybe you want to look like.

Speaker C: Yeah, I mean it used to be hard and required a lot of expertise to pose as different APTs, advanced persistent threats. Uh, and we would study them. We'd have a customer say, you know, do a red team against us and we want you to pretend to be, you know, APT number xyz and we have to research that and figure it out. But now, you know, with AI you can just tell it to poses that it kind of has it studied the playbook of that given APT and all the write ups of it. And it can do that also. It occurs to me, Tony, as you were just describing that. So here's another prediction, um, that by

Speaker B: the way, we have to schedule a episode six months from now. It's predictions exactly. Sorry, you're trapped.

Speaker C: Now a single adverse. I'm. Bring it, bring it. A single adversary dynamically shifting their APT profile in the middle of a campaign or throughout a campaign. So today they look like this North Korean actor, tomorrow they look like this Russian actor. This afternoon they look, you know, like some Chinese actor. And it's all the same actor.

Speaker B: So, uh, how many times did you, were you looking at these kind of issues and you know, oh, we think it's so and so because we found a fragment of a text string.

Speaker C: Yes.

Speaker B: Or it Looks like this or that came from a library. I said, I mean now you can just leave a few breadcrumbs, uh, in there. Oh, totally. You know, build the package around that. Sorry, sorry. But uh, I mean that's like, oh my gosh, now we have another way to pin down the defense, right? A way to, to sort of get them to waste resources in analysis at essentially no cost.

Speaker C: Attrition becomes so much harder. You know, I remember years ago I was, I was working on a case and it was, you know, if you just look at where the package going to and from, it was Russia. Um, and uh, but there were these words, you know, the account names and some of the language they were using and chatting back and forth with each other. I didn't know what they were. So I called some friends and they hooked me up with a linguistics expert in the army. And I said, hey, I'm not going to tell you what I'm up to, but I'm just going to read some words to you, you tell me where they're from and I'm going through these words and, and she said very quickly, oh, that's Farsi. Very, that's easy, that's Farsi. So, and yeah, I think they were just pivoting through Russia. Um, but, but those things are going to become harder and harder now with AI so attrition becomes very difficult indeed. And uh, this dynamic shifting of apt profiles in uh, the middle of a campaign. Yeah, what a world. What a world we live in.

Speaker A: What a world. Interesting. We're going to take a quick break. We'll be right back with more predictions and our uh, thoughts. We'll be right back. You know Tony, cloud security is like setting up a new home security system.

Speaker B: You know you have responsibilities like setting up alarms and locking certain doors.

Speaker A: But unlike a home security system, cloud security doesn't come with a manual.

Speaker B: You don't have a definitive guide to what you need to harden in your cloud environments or how.

Speaker A: There's got to be a better way.

Speaker B: Thankfully there is. CIS hardened images. These virtual machine images come pre hardened to the CIS benchmarks providing built in cloud security and compliance without any guesswork.

Speaker A: CIS hardened images are also available for just cents per compute hour, saving you time and money managing your cloud security

Speaker B: posture and all while using major cloud service platforms like aws, Azure, GCP and oci.

Speaker A: Cost effective cloud configurations. CIS hardened images are ready to go when you are.

Speaker B: Spin one up today by visiting cisecurity.org

Speaker A: okay, so we're back. So Ed, we'll move now through ah, and Tony, um, I got a couple other elements here. One was an SLTT focus but I think Karen Cerrati had really focused um very neatly on some of the elements that we would see with state, local, tribal and territorial issues that we're starting to see as both targets uh underfunded and continue to try to um, build capability um when the resources may not be as available as they once were. And this is uh, an issue of both preparation, training, a new dynamic because we just talked about threat landscape that's continuing to evolve daily. Very, very difficult in this space. And I think it's um, one of those things that we want to attribute to um, continued development and continued um, assessment of these constraints. Ah and really trying to be a trusted partner in this space from a CIS Ms. ISAC perspective, but also facilitating the conversations of understanding both the context of the threat and being able to uh, work with them, um, to address these risks uh kind of in real time in a lot of cases. It's very, very interesting. It's a uh, very dynamic year and some uh, that we want to see um, you know I would say consistency in our approach uh again from a government perspective in terms of um, trying to address these issues um judiciously and not as a secondary afterthought, uh not at the federal level. But let's bring it down to state local levels I think very, very important. Uh, and. But we continue to see challenges in that space.

Speaker B: Yeah, just offer Sean that uh, you know, underfunded, state, local and below governments. Right. Who couldn't afford to defend themselves in a traditional way are, aren't much better off, you know in an AI empowered world. And so we need to you know at a, at a infrastructure, at a national level, uh, need to think about this problem. What. And, and we actually again we have the opportunity for scaling that we couldn't have dreamed of in the past to help folks understand it. But, but it's not going to be by teaching every county to have three AI people on staff who are clever enough to do all the you know, management. Right. They can barely run the it. I mean they're just so under resourced here. But, but I think thinking of this as a strategic imperative that this is the majority of our economy that is small and a lot of that is about essential services from state, local and below governments. And so how do we who work in sort of larger scale have access to more resources, think of defense differently. Right. So that, that's a case where speeding up, you know this is the cow Pass thing, right? Speeding up, you know, can they get the right threat feed? Can they integrate it with the right defending, uh, blocking and close this port? That's not, that's not the solution to this problem. The solution is really at a higher level. Um, we need the. And so we need that level of cooperation, right from folks who can see this, see the larger picture and help implement things, sort of decide, you know, this is exciting. What's exciting is you get to think about um, systematically what is going on. There's an old saw I think, you know, and in the business, right, attacks succeed because the attackers attack systems and the defenders are defending their turf. Right. The thing that they own. And wouldn't it be great to be able to turn that on its head, right, that we're design, you know, we're designing defenses that are meant to be part of a system that we're all codependent and we have to be able to say I look but I have the ability to learn from every corner of this and bring it together in a way that allows me then to say whatever's going on, I've got visibility, right, that become all these underfunded folks become part of uh, a visibility network that allows you then to say I'm seeing things and I can deal with them at scale and not ask everyone, not, not just send email to every sysadmin in county government across the country and hope for the best. But how can I empower defenses in much greater scale?

Speaker C: And it's interesting the timing when this is happening, right? There's the funding cuts and uh, you know, impacting folks at the same time as the rise of AI. So in a lot of these AI meetings, um, there's discussion of the cyber have nots. Right. And it occurs, you know, some of the local uh, governments and the tribal uh, organizations and then you know, things like small water supplies, um, or charities and such, um, you know, what do they do if, you know, if you're a big rich company, well you've got optionality, you can invest, you could, you know, there's talk about, hey to deal with, you know, this, these new major frontier models or you're gonna have to spend more on something like Volnobs and you'd have to invest here and now's the time to go to your board and ask for more money. Yeah, but if you're a cyber have not or you know, you know, somebody who's been impacted by the funding changes over the last say 18 months or so, um, that's just a really Hard thing. And it's all happening at the same time. It's, it's really pretty stunning.

Speaker B: No, and that, you know, again, looking at the social context that Sean mentioned, right, That m. That that request is competing with lots of social needs, right? Health care, food, you know, all that. And so how do you, how does that, um, uh, you know, how do you integrate that picture right, into sensible investment decisions for the, for the overloaded decision makers who are part of that. But again, part of that is you don't want, you want to avoid the trap. You know that it's not about sending the right threat feed information to every county government and, you know, asking them to action it, right? What action can we take at a different level so that there's less of this chaos, um, that we've grown up with? So there, there's, I mean, the next short period of time. And Ed, I know you watch these kind of things, like Sean does too, um, will be fascinating, right? This race. And you've, you've heard, we've heard the terms there's a short window for the defenders or whatever, you know, they're all kind of, everyone's got a different model of what this means and we have time to do this before the bad guys can really mobilize or is it vice versa? And I, I don't have a good prediction. I'm not, uh, you know, I'm not going to do what that did and put my neck on the line for six months from now. But it's, we're all watching this, this kind of, you know, this, this sort of play out and seeing where is the advantage. What's really clear, I guess is fair, is that we as defenders need to get to work.

Speaker A: Right.

Speaker B: Uh, this is, this is, this is important stuff and really worth our time and attention and our, our best thinking. Agreed.

Speaker A: Completely agree. So one of the things we see. So myself and Don very closely aligned in terms of our overall predictions. But one thing he mentioned is zero trust. And I think there's a life cycle to buzzwords in cybersecurity. You know, if there was a timeline, um, we're in the AI, um, buzzword age now. Before that was zero trust. Before that, identity, access, management, et cetera, et cetera. But zero trust still very important in terms of the underlying principles of what we're seeing from the threats in, uh, the environment. A zero trust architecture makes a lot of sense. Um, for organizations that have an ability to not only implement but continuously monitor, there is an underlying operational overhead. Could that be offset by AI, um, again I think everything can be offset by AI eventually but they're very important. But both Don and Lee uh, mentioned that in their assessment and really want to lean into something um, that Lee said as uh, Zero Trust becoming this compliance mandate. We're starting to see that come from, from CISA and others looking at Zero Trust as an enablement from a uh, federal perspective that the integration of this type of mindset, I don't think it's a technology. I really do think Zero Trust is a mindset is very, very important and something that we're really all working towards. One thing I do in the organization, um, anything that has security connotation I say is it is a small piece of that Zero Trust project. You know, this is a small component of continuing this journey. You don't get to Zero Trust, you continue down the path of Zero Trust. I think it's very important. I thought it was ah, good that both ah, Don and uh, Lee mentioned it, but want to get your thoughts Ed, um, in terms of what you're seeing in the space from a um, Red Team perspective. Do we see effective implementation of Zero Trust or it's not filling some of the gaps that are some of the usual uh, elements of infiltration that uh, you see.

Speaker C: So I think there's actually good news here. I think uh, Zero Trust implementations are proceeding. That uh, is fantastic. I think Lee nailed it on the compliance mandate piece because I'm seeing that uh, even in the commercial sector. So you know, he mentions it specifically in uh, government sector. So it's happening and as attackers always do, they move. So while Zero Trust is being implemented on the underlying computing computer systems themselves and maybe some of the cloud assets etc. Now attackers like scattered spider and such focus on the authorization sprawl all happening up in the authorization level. So you've got computers that have less trust, zero trust against each other, but then you have different accounts and different um, paths between accounts and role based access control, etc. Um, so attackers are now spanning that. So the good news is Zero Trust is happening. It's not just a buzzword, it's being mandated. That's great. But the attackers are getting such success by moving into the authorization level itself through and the word or the phrase authorization sprawl that was coined by Josh Wright, uh, sans instructor and I think friend of all of ours, um, and I think he nailed it. He presented on that at RSAC last year. Uh, talking about authorization sprawl is the new pivoting. Right?

Speaker B: Yeah, absolutely. And it's a great phrase that really captures it. As Sean said, it's not a thing.

Speaker C: Right.

Speaker B: It's a philosophy of design and architecture. And so it has to have an infrastructure of validation, uh, essentially asking and getting the right response. Managing all that is complicated. And know that's, that's where bad things can happen. Is this complication another example also like the um, you know, the attacker is uh, economically sensible go where the weakness is. And so you know, oh, you've protected this. Then I will look at where. What allows me to get to that. Oh, it's this higher layer. Okay. And that's. But you know, that it all again and this idea, we won't ever get there. What's happening. The risk is changing. Right? The risk is moving to elsewhere. Uh, and so Sean talked about having a plan for, you know, and you're. You. You watch that kind of thing. Sean. All I know about C says is what I've learned from talking to Sean over the years. And uh, thank heaven I never had that job because I mean my enterprise would have come crashing down in a heap pretty quick. But, but knowing that says, you know, I, as I fix one thing, I, I've got to move sensibly to the next thing, right? To the, you know, defense is not an event, it's a whole program of activity. And so designing it to, to be uh, aware of the risks, where they're going and what my next step is.

Speaker C: I remember when I first started my career, I was working at Bell, uh, communications research. Bellcore is the part of the Bell system that was sort of like Bell Labs for the baby bells. And I was working with the anti fraud team there. They called them the fraud team, which I always thought was kind of silly to be called the fraud team. Their job was anti fraud. And I learned very early on in my career that um, this is what somebody said very senior. They said, we push down fraud here. The current way fraud is being committed and it goes up over there. Don't be mad about it going up or that's just the way it works. I mean if these people stay, the bad people stay in business. And same thing with cybersecurity. You know, we go to zero trust implemented on our systems themselves. They start attacking, you know, the interrelations between accounts and authorization. If the attackers don't pivot like that, they can't eat. They just go out of business. And they're not going to go out of business. They've been with us since the start. And um, so they will pivot flexibly we just have to try to stay as far ahead as we can.

Speaker B: Yep, agreed.

Speaker A: The other thing Lee mentions, and it really falls into some of the, um, multiple thoughts that Randy and his team have. Ed, when we did this last time, we had to have a whole episode for just Randy's predictions, um, because, because there were so many and really good as well. Ah, they put a lot of thought into this. But one was the. So, um, Lee mentions the law enforcement centric, ah, threat intelligence platform. And I think it also evolves into where we're starting to see compartmentalization and specific detection type threats for industry that are now being curated versus here's everything you make sense of it. There's now a curated program of threat intelligence ingestion that I think helps. Uh, you know, the way I've, I've framed it before is you don't take the mitre, ATT and CK framework and do everything right. You try to, you know, look at the advanced persistent threats and some of the threat profiles. What's the most likely thing? And let's start protecting against that versus trying to do the entire framework. And it's something Randy goes into, um, where we're seeing cross platform platform campaigns, semi autonomous malware, AI assisted malware. All of these elements are now part of that threat intelligence that we're trying to ingest to see what are the attackers doing, what protections do we have? Have those protections been tested and how effective are they? And this, it seems like this new life cycle of consumption. But I wanted to get your thoughts, Ed, on how that, how we see that information being ingested, compartmentalized and actually used effectively.

Speaker C: Well, first off, you know, Lee and Randy both said some amazing things. There are a lot and a whole lot of things. When I was first reading their predictions, I was thinking, do they get paid by the word? It's incredible. But it's not just a bunch of words though. It's more than that. I mean they're organized and they're thoughtful and such. Um, but yeah, I think this rise of uh, domain specific and industry specific intelligence is certainly a good thing. Uh, law enforcement helping to influence that. We do see attackers very much, uh, focusing on certain industries. Like right now the big thing is to go after education. There was the issue with canvas. So, you know, higher education and middle education, I suppose, uh, canvas and those campaigns are continuing right now, um, so learning things about that. It could influence people outside of the higher ed, but certainly within the higher education area. You need to learn what these attackers are doing right now because they're hitting us all up. And I could say that, you know, from the Sands College to uh, that that is something we keep an eye on very carefully and other industries, financial services, um, etc. Etc. Need uh, to stay abreast of what's happening in their industry at that time. So Lee's prediction there was I think spot on.

Speaker A: Yeah, agreed, agreed. Tony. We look then at Marcus um, as well, the operational technology, critical infrastructure. Obviously we've, you know, a lot of attention in this space, a lot of need for protective capability. Uh, and he's looking at uh, higher impact cyber incidents, geopolitical conflict, which you know we're seeing um, currently, uh, and then looking at some mandatory federal standards for water comms, agriculture, transport. Don't know if I've seen that yet, but it's certainly a need. Uh, and I think as we raise the um, kind of the table stakes with capabilities addressing operational technology and critical infrastructure, it's certainly something that um, we need to push toward in terms of both. Well, here's where I diverge a little bit. Setting a policy doesn't mean setting a security control policy is not security in some cases. What we need to see is kind uh, of table stakes in the space of being able to provide capability for the organizations to transition from um, currently I'd say weaker security postures in some cases, not all cases, to a higher level of capability that needs, then they need assistance. I mean it's, you know, I align with the state, local, tribal and territorial approach is there are specific needs in these industries. And um, I think we've all got to listen and look at the requirements for operational technology as a uh, as an opportunity at this point because our tech is certainly looking at. As an opportunity.

Speaker C: Yeah.

Speaker B: Just a couple of quick reflections. Yeah, Marcus was very thoughtful I think, and he's lived in that area. Um, one is that you know, for those say, critical, uh, utility kind of things like power, water, transportation, whatever. I mean as citizens. Right. What is a social expectation we expect? We don't know, we can't really define it. We expect a certain level of safety, a certain level of quality right in our food, in our water and so forth. And that's a social expectation. And that gets implemented right through regulatory inspection. You know all there's a whole. And we just accept that as part of the. And it's built into the cost, it's built into the regulatory uh, uh, oversight, the rates, all that kind of stuff. And then this IT stuff, the cyber stuff, you know, it's, it's seen different or that traditionally has been seen differently as something we're adding on. And yet it feels like in terms of IT technology there, there ought to be some notion of social expectation. There's a, some level of quality, of safety, of security in the uh, and reliability in those services. Now we can argue endlessly about, you know, how mandatory, how high, how low, but it feels like that's kind of where we need to go, right? That is, it's built in, rates reflect that social cost is, you know, is part of what we uh, uh, pay in order to get what we socially expect out of it. So this, so is there a notion of a kind of standard baseline? Right. Uh, must be this tall to enter. It feels like there should. The challenge has been, you know, the way we've approached it nationally is fragmentation. I mean, I asked to ask the National Academy Sciences Group I was on one time, would somebody please collect all the different Federal Agency top 10 lists, top fives, top tens, top whatever recommendation. Because I'm going to guess if we actually looked at them at the same level of abstraction, they're probably 80, 90% the same, but they're all published differently in different languages, in different formats, in different places. So that's, that's crazy. That's absolutely, you know, we have folks like NIST whose job it is to bring that together and make it less fragmented. So that's one issue. But the other thing, I think, and I forget exactly what Marcus said about that, but OTIT is a place where you have to look at, I think more holistically at the attackers and objectives. So we're always fighting on multiple levels. If we think of this as a giant fight, a technology fight, but also maybe a national security economic fight. Right. And so if you were coupling national objectives with the uh, technology attacks, and if your goal, for example, is to create chaos or the, or lower the confidence of US citizens in the safety of their food supply or things like that, you don't have to succeed in the same way technically, uh, as you might think, technically, what you're trying to manipulate is confidence is public perception. And so you have to be aware of these higher order objectives and how they are coupled to the technical things that we're used to fighting. We're always fighting on multiple levels, uh, especially in this sort of, uh, nation state kind of things. And so we have to be conscious of that because we might think we succeeded. Technically we stopped them. But if the citizens don't believe in their elections, for example, or don't believe that their water supply is safe. We have a national crisis on our hands. And so those are different objectives and the, the specifics of the technical thing. Right. And the way we assess them might be seen differently by the technologist versus the public policy person. So, so that's an area that I think really is for something. And again, Marcus has worked the entire spectrum of the activity in it and ot so no one's better than him to think about. The other is remember m a few years ago and Ed, I'm sure you noticed, right, this idea of critical sectors, these nice neat verticals, that was kind of thinking of quite some years ago. And it's still relevant, but it's not complete. Uh, there is no. And DHS started to think more holistically. I forgot what they called them now. Do you remember security functions or something? Critical functions, right. Any critical function of our economy is going to cut across multiple sectors. The uh, transportation safety coupled with the fuel to cause it to run to cause it, you know, all, any, anything worth caring about. You, you need to look, maybe say horizontally if you were looking vertically before. And therefore you cannot say, well, you know, some of these sectors are pretty good and some not so good and some I don't know. Then you have no way to assess the risk. You have no way to understand what's going on. Again, that speaks to some system, uh, wide structural thinking about risk. And that's what DHS was trying to accomplish. I think it was, you know, that was in the right direction to think about that. Which then speaks to say, okay, then I should be thinking about these holistically. What is the sort of minimum social expectation or technical baseline for pieces of it for the command and control that flows across the array. What, what, I can't have weak spots in that. You know, I'm going to call it horizontal, um, critical function. Either or, or that because the adversary will see that they will. They're inevitably going to go for the weak link in the j. That's just the history of, of defense. And so uh, so I think that's something that's been a struggle for us nationally to kind of get that together because you know, by nature we tend to be fragmented by. Right. Different regulatory agencies have different. And they're aligned with these critical sectors of the economy. And again, I'm not saying those are less relevant. I'm saying they're incomplete and therefore we need to think about that. You see that crystal clear in the itot world. I think that's just where it always has jumped up to me. So thanks for letting me rant. But I always enjoy, uh, reading what Marcus has to say about such.

Speaker A: Absolutely agree. Absolutely agree. Well, then we'll finish up, um, uh, with Felicia. Felicia Stucchetti, senior cybersecurity engineer. She had some great thoughts about the rapid and growing, uh, complex threat landscape. And we've seen the actualization of her thoughts in the work of the Verizon data, uh, breach investigation report of 2026. She references 2025, but everything she had mentioned and identified certainly coming to fruition in that great body of work. Um, we had the opportunity of speaking with Phil Languire in a previous episode. Uh, so if you haven't listened to that one, certainly check that one out with, uh, his thoughts and insights into what we've seen in that space. And we finish up with her second prediction. And it also aligns with Lee Noriega. Uh, so we're talking about regulations, compliance. Lee was talking about the integration of privacy and cybersecurities. We see, um, really the introduction of GDPR, uh, May 25, 2018. I'll never forget, get it, is where we then look at, um, how these converge and where, um, we're starting to see that compliance is not security. And we want to use, um, security to build the byproduct, which will be compliance as an appropriate program to follow regulatory, uh, alignment. And so she mentions, you know, regular auditing, regular, uh, updates in the space is going to be treated as really building this culture and where we want to introduce a culture of security and not a culture of compliance. And we're starting to see that in some spaces, but not everywhere. Uh, and um, I don't know if you've seen this, Ed, but there's certain organizations that will do exactly what is required in terms of a compliance checklist. We've done this checkbox, pci, you know, any, um, of the, uh, acronym SOUP in terms of frameworks. And I think maybe we're approaching it. And hopefully this is an AI enablement where you'll ask a question of, well, what do I need to do to be compliant? Well, you know, these are the things. But here's the security, underlying pinning and things of this nature to help encourage skill development in this space. And that's where I want to use AI is really that multiplier in skill, skill and training and understanding of, uh, what's read between the lines of a compliance standard to an actual security capability. But what have you been seeing, Ed? Any thoughts there?

Speaker C: Yeah, um, well, Valisha. Is that how you say her name? Valisha?

Speaker A: Yes, that's correct.

Speaker C: I thought she was, uh, she did a great job describing it. What I liked most was about how compliance is just not a single time thing. I have complied. I'm done. Uh, but to get real security, it's a continuous compliance, uh, operation, and you need to continually apply things. I used to, you know, tell my sans classes. You know, if you look at a compliance, um, maybe a standard or specification like say, pci, like you did for an example, I would always tell them, don't view PCI as a ceiling that you strive to bump your head on. View it as a floor that you like to stand upon. Right. Um, because, uh, I mean, look, this is. These various standards are written as, you know, one size fits all. But, uh, it is for the. If you look at pci, it's for the baseline of companies accept credit cards. I mean, if you're the center for Internet security, you need to be way better than that. Right. Or financial services firm or what have you. Um, so. And I think what Felicia has teased out there is, is that, um, you know, I always love to use compliance to help drive security, but on a continuous perspective, we got to comply with this. And if you're going to invest in it, you might as well even do better than it can require, because you can with little incremental extra cost. And you've tried to find those wins for, uh, the organization big time.

Speaker A: Now I would be remiss because of all the acronym soup if I didn't mention fog of more. Um, so again, another $5 to Tony for me using this. But Tony, this is, I mean, this is a line to really those thoughts as well.

Speaker B: Yeah. You know, having grown up on the flip side of that, I, I mean, I, I've never had a real job like you, Sean, but, you know, as. But people would show up, you know, hey, could the NSA Red Team do a penetration test of us? Because that's. Because it's a requirement for compliance.

Speaker A: Right.

Speaker B: And so. And, and you guys are free. I always have to go get a contractor to come do it. And, and it was. Yeah, and it was. It was, uh, well intended, but really all. All always for the wrong reasons. Right. The point was to get through. It wasn't the floor that Ed was aiming for, it was the ceiling. I just got to get through this. This thing. And, uh, you know, there's a lot of good intentions in those frameworks too, but, you know, they're also not written to support the kind of continuous, uh, thinking that I mentioned. And remember, the continuous Diagnostics and mitigation program, other dhs. Right. It was kind of in that spirit. That is, it was more important to have continuous visibility into the state of configuration of assets than it was any one snapshot, you know, so, so that, and I was a strong supporter, you know, that that auditor should be trained to look for. It's not what it says on this given moment is in the mach. Is the machinery in place and active to make that determination is the more important. Certain question. Right. And so, so. But it's also not necessarily easy. Easy to test for. Right. What is that. That meaning? And um, so I think that, uh, so that, you know that, that fog of more thing, that's what I was observing at the time, Sean. And uh, you know, there was just too many of them. And we did a survey at one point, I think with our friends at Tenable and okay, uh, Enterprise. How many security frameworks do you either have to pay attention to, to or choose to. And the answer was almost never one. It was either zero or two or more. Right. So, so I, and I said, well, if it's zero, you have a framework, it's complete obliviousness. You know, it's, you know, you are making choices about it, right? You might be ignoring risk or whatever, but you're, you've made choices about your security. But, but it was this, uh, you know, explosion, which has only gotten worse universe of these, uh, well intended security frameworks at all different levels, different languages, different, um, domains like, you know, medical, medical thing, medical service, uh, credit cards, all these kinds of things, all of which were essentially designed independently using a different language. Assuming that they're the only framework on earth and everyone else is on their own, and who's left to integrate all that is the poor ciso, Sean, and the IT team at the company. Right. Your job becomes. Oh my. It says this, but this auditor likes red versus green or yellow versus blue. And I got to change it for the next auditor that comes in and you know, complete waste of energy. And, and so, but there won't. You have to recognize, right. There won't be a single, uh, one framework to rule them all. That's just not realistic, uh, economically, socially, politically. So there were going to be multiples. So how do we then reconcile them? In a way, I like to. I think it's true. And Sean, you study this kind of stuff. We're one of the few. We don't really own a legal or compliance framework, but you know, people use our work as part of those there. But we recognize this problem. And we've done work about it. We, whenever possible we give you a cross mapping that we generate and give away free to basically everything we do to everything else that somebody else does, right to PCI, ISO, you know, uh, etc. Etc. Because otherwise you have to do it for the next auditor or the auditor has his own opinion which is different than the previous auditor's opinion, et cetera, et cetera. So, so this is um, by the way, I've been urged to write a op ed on this very topic which I've always called the great self inflicted wound of the industry, which creates a lot of work which may or may not lead to security improvement. And it's not to make fun of, you know, of all these things, they're all, they all have good intentions. There's legal reasons why. But if we don't design them. Well, yeah, if you look at the proliferation of them, it's clear no one designed this mess. Right? No, no sensible person could possibly design it. Those are. Okay, one more story if we have a minute. There's, there was a, uh, uh, a DOD like glossy magazine, you know, with all kinds of. And around communications and so forth the DISA produced. And there was a chart in there at one point and a couple of contractors had taken like every possible IT and cyber DOD policy and put it together on a giant chart and it was like, you know, here, here, here and this, I mean it was, it's a wondrous work of art. It would have filled a wall if you actually printed it full size. And you could only have two reactions to that chart. My God, what a wonderful job that those people put all that together into one place. You know, we can kindly see it. The other reaction, which is the one I had is what a God awful mess of spaghetti. No, no human designed this insanity. You know, and you know, you, there's no in between. You have to pick one side or the other. But it was, and what it creates though is lots of work confusion, uh, rework work, ah, re representation of the same work over and over again. So this, this world, uh, um, of uh, complexity are things that we have done to ourselves. And again we need oversight, right? We need to be able to pull from technology confidence by policymakers, by decision makers, by business executives. We need things like this, but we don't need this kind of crazy chaos of the, you know, the fog of these things that don't really interact with each other. So uh, this is my rant, this was my prediction 10 years ago. That by the way, at one point, I predicted I could solve this problem in a few years. I'll never say that again because clearly guys like you would track me down to, you know, to get me to talk about what a miserable failure I was as a predictor. But anyway, yes, I agree with you. The Felicia characterized really a complicated world very nicely. Exactly.

Speaker A: Wonderful. Well, Tony, Ed, that brings us to the end of, uh, the episode reviewing the predictions. Thank you so much to you both and thank you to our audience. Remember, um, to subscribe in all the usual ways with your preferred podcast provider. Catch us on YouTube Ah, the CI security. Got a question? Comment? Concern? Drop us a line at ah podcast@ah, cisecurity.org and with that we'll talk to you soon.

Speaker B: Thank you for listening to the podcast today.

Speaker A: The thoughts and opinions expressed by our podcast guests are solely theirs and do not necessarily reflect those of cis.

Speaker B: Tune in on Wednesdays for a new episode and in the meantime visit our website@cisecurity.org Together we'll continue our efforts of

Speaker A: creating confidence in the connected world.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Weathering the AI Vulnerability Storm with Gadi Evron, Rob Lee and Ed SkoudisCyber Leaders · features Ed Skoudis89 / 100
  • Tony Sager: The Case for Cyber Hygiene FirstAfternoon Cyber Tea with Ann Johnson · features Tony Sager65 / 100
  • Ship It Conversations: Kat Traxler of Vectra AI on AI Security, the Zero-Day Clock, IAM, and Cloud RiskShip It Weekly · on Project Glasswing96 / 100
  • Mythos And The Disappearing Patch WindowAI Proving Ground Podcast · on Mythos96 / 100
  • 512. Is SpaceX Over or Undervalued, Why Consensus Kills, How Chewy Beat Amazon, and the GameStop Saga from a Board Member (Larry Cheng)The Full Ratchet (TFR) · on Mythos86 / 100
  • Mythos is not the AI ApocalypseThreat Talks · on Mythos80 / 100

More from Cybersecurity Where You Are

All episodes →
  • Episode 193: AI Security and Responsibility in EO 14409
  • Episode 192: How Leaders Balance Expertise and Communication
  • Episode 191: GenAI Misuse for Physical Threat Planning
  • Episode 190: Separating Mythos AI Fact from Fiction
  • Episode 189: The Present and Future of AI-enabled Pentesting
Explore the best B2B AI & Data podcasts →
All Cybersecurity Where You Are episodes →