The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/AI & Data/Enterprise AI Defenders
Enterprise AI Defenders artwork

AI Threats Aren't New, Just Faster with Tyson Foods VP & Global CISO Matt Bunch

Enterprise AI Defenders · 2026-06-24 · 31 min

0:00--:--

Key moments - from our scoring

Substance score

45 / 100

Five dimensions, 20 points each

Insight Density9 / 20
Originality9 / 20
Guest Caliber13 / 20
Specificity & Evidence7 / 20
Conversational Craft7 / 20

Tyson Foods' Matt Bunch brings nearly 30 years of experience managing security at a multinational $54 billion protein company that supplies 23% of U.S. protein consumption. The conversation centers on how Tyson approached AI adoption in their security operations, particularly through migrating to next-generation AI-enabled SIEM platforms that combine threat intelligence, vulnerability data, and live alerts into daily digests. This resulted in significantly faster mean time to detection and mean time to response, with analysts arriving at alerts with far more context. Bunch challenges the industry narrative around novel AI threats - framing prompt injection as a data validation problem and configuration issues as risks security teams have managed for years. His pragmatic view is that most so-called AI-specific threats are variations of existing vulnerabilities (data access, configuration management, asset visibility) that organizations have been accepting quietly. He emphasizes that security leaders must partner across silos with infrastructure, data, and business teams, focusing first on business objectives and fundamental hygiene (asset management, identity, data governance) before deploying AI solutions. Bunch also discusses how AI is enabling his team to shift from writing code to solving business problems and using advanced analytics to surface root causes previously hidden in operational data. For security leaders managing large enterprises or supply chain complexity, his framework prioritizes business value, data quality, and governance guardrails over technological novelty.

Key takeaways

  • →Prompt injection and AI-specific security threats are primarily data validation and configuration issues that security teams have managed for years - not fundamentally new risk categories.
  • →Tyson migrated to AI-enabled SIEM platforms that combine threat intelligence, vulnerability data, and live alerts, resulting in significantly faster mean time to detection and response with more contextual insights for analysts.
  • →Security teams should prioritize business value and outcomes (SLAs, KPIs, time recovery) when evaluating AI opportunities, treating security as a business partner rather than a gating function.
  • →The basics of security - asset visibility, identity management, configuration management, and data governance - must be solid before deploying AI; most enterprises get these fundamentals wrong through siloed, disconnected teams.
  • →Security organizations must shift from being 'the organization of no' to finding guardrailed pathways forward, breaking down silos between security, infrastructure, application, data, and business teams.

Guests

Matt Bunch

Topics in this episode

Prompt injection attacksMean time to detection (MTTD)Data validationThreat IntelligenceConfiguration ManagementSupply chain securityVulnerability management and prioritizationSIEM platforms (Security Information and Event Management)Identity and access controlMean time to response (MTTR)

Questions this episode answers

How did Tyson Foods improve mean time to detection and response with AI?

Tyson migrated to next-generation AI-enabled SIEM platforms that combine threat intelligence, vulnerability data, and live alerts into consumable daily digests, enabling analysts to reach alerts much faster with significantly more context than before.

Is prompt injection a net new security threat?

According to Bunch, prompt injection is fundamentally a data validation issue - a problem security teams have managed in applications for years. Most AI-specific threats map to existing vulnerabilities like configuration issues and access control that the industry has accepted for a long time.

What framework should security leaders use to prioritize AI opportunities?

Bunch recommends starting with business objectives: identify manual processes, quantify time spent, assess data requirements and quality, and map back to SLAs and KPIs - treating AI investments as business decisions, not technology exercises.

What are the foundational security practices that matter most before adopting AI?

Asset visibility, identity management, configuration management, data governance, and network segmentation are core fundamentals that must be solid; enterprises often fail here by operating in silos instead of partnering across teams.

How does Tyson approach managing cybersecurity across a complex supply chain?

Bunch emphasizes collective security posture - partnering with ingredient suppliers, transportation companies, and external providers to raise the security bar industry-wide, recognizing mutual dependence on utilities and critical infrastructure.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

9 / 20

There are a handful of genuinely interesting reframes - prompt injection as a data validation problem, challenging the team on whether AI risks are truly net-new - but the episode is padded with leadership platitudes, a generic lightning round, and repetitive calls to 'go back to basics.' The insight-per-minute ratio is low for a 31-minute runtime.

what's a prompt injection issue? It's a data validation issue. That's really all it is. We've had data validation issues for years on applications
I've challenged my team to really focus on are these net new risks or are these just risks that we've been accepting for a long time and nobody's really stepped up to the plate

Originality

9 / 20

The reframing of AI-specific threats (prompt injection, configuration drift) as legacy security problems wearing new clothes is the one genuinely contrarian take, and the 'AI is just the next thing' closing is a reasonable counternarrative. Everything else - security as 'organization of yes,' change management via champions, go back to basics - is well-worn CISO conference material.

what's a prompt injection issue? It's a data validation issue. That's really all it is
AI is just the next thing? It's just the next thing. We will have more things coming. It is the next tool, it's the next set of techniques

Guest Caliber

13 / 20

Matt Bunch is a genuine 29-year practitioner who rose from intern to Global CISO at a $54B food manufacturer with an exceptionally complex OT/supply-chain surface - this is real operational credibility. The conversation, however, does not extract depth commensurate with his experience; most answers stay at a conceptual leadership level rather than surfacing hard-won specifics.

I've been at tyson for almost 29 years now. I, uh, started off as an intern
we supply protein to almost 23% of the United States

Specificity & Evidence

7 / 20

Company-scale statistics (23% of US protein, 7,000+ farmers, 44,000 houses) add color, but operational claims about the SOC overhaul are entirely unquantified - no actual MTTR before/after, no vendor named, no percentage improvement cited. The episode gestures at specificity without delivering it.

we did a massive change this past year... what we're seeing is just much faster meantime detection, meantime to response
Over 44,000 houses are involved in that across just the United States

Conversational Craft

7 / 20

The hosts ask a few structurally interesting questions (watching the risk landscape evolve over 29 years, net-new vs. accepted risk) but never follow up to extract numbers or push back on vague claims. The 'I like that, that's great advice' response and a formulaic lightning round reveal the inherent softball dynamic of a branded vendor podcast.

I like that, that's great advice.
Are there like new threat vectors that you kind of worry about today? Or is there maybe some operating assumptions that kind of, as a cybersecurity community have kind of assumed to be true that are maybe less valid

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker D71%
  • Speaker C16%
  • Speaker B8%
  • Speaker A6%

Most-used words

team24security17today16organization15data14back14teams12tyson10operations10vulnerabilities10matt9supply9sure9real8chain8tools8

Episode notes

On the 41st episode of Enterprise AI Defenders, hosts Evan Reiser (CEO and co-founder, Abnormal AI ) and Mike Britton (CIO, Abnormal AI ) talk with Matt Bunch , VP & Global CISO at Tyson Foods , about how Tyson Foods is modernizing its security operations with AI, and why AI-speed threats make the basics more important, not less. Quick Hits from Matt: On AI adoption across every role: "We're using the mantra 'all in on AI.' And when we say all in, it is everyone all in on AI." On AI risk: "What is a prompt injection issue? It's a data validation issue. That's really all it is." On agentic AI governance: "We're going to have to put guardrails in place that don't exist today to understand what the models are doing, what the agents are doing. Are they really doing what we asked them to do, or are they trying to go outside of their defined scope?" Book Recommendation: The Art of Negotiating by Gerard I. Nierenberg . Like what you hear? Leave us a review and

Full transcript

31 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Hi there and welcome to Enterprise AI Defenders, a, uh, show that highlights how enterprise security leaders are using innovative technologies to stop the most sophisticated cyber attacks. In each episode, Fortune 500 CISOs share how AI has changed the threat landscape, real world examples of modern attacks, and the role AI will play in the future of cybersecurity. I'm Evan Reiser, the founder and CEO of Abnormal AI.

Speaker B: And I'm Mike Britton, the CIO of Abnormal AI.

Speaker A: Today on the show, we're bringing you a conversation with Matt Bo Bunch, VP and Global Chief Information Security Officer at Tyson Foods. Tyson is a $54 billion multinational protein company that supplies roughly 23% of all protein consumed in the United states. With over 11,000 independent farmers in their supply chain alone. A few things stuck with me from this conversation. First, Tyson overhauled their SOC platform this past year, migrating to next generation AI enabled SIM that combines threat intelligence, vulnerability data and live alerts into a daily digest. The result? Significantly faster mean time to detection and response, with analysts arriving at alerts with far more conf context than before. Second, Matt's take on AI specific threats like prompt injection is blunt. It's just a data validation problem and configuration issues and AI tools are problems security has managed for years. His challenge to his team is to honestly assess whether these are net new risks or risks the industry has quietly been accepting all along. And finally, Matt sees security operations becoming significantly more autonomous in the next few years, but says that this future requires governance guardrails that don't yet exist.

Speaker C: Well, Matt, thank you so much for joining us today. Maybe to, uh, kick us off, do you mind sharing a little bit about your background, what you've been doing at Tyson for the last, uh, 20, 30 years?

Speaker D: Well, thanks, Evan. It's a, uh, pleasure to be on with you today. Matt Bunch, Global CSO here at Tyson Foods. I've been at tyson for almost 29 years now. I, uh, started off as an intern, so had the great opportunity to join the organization as an intern. Been able to work through a lot of different infrastructure teams throughout my journey here, as well as leading inte efforts as we've, uh, merged, acquired, divested of companies over the years. Tyson has grown by that kind of growth into what we are today, which is a multinational $54 billion protein company.

Speaker B: Matt, you know, it's, it's got to be very challenging defending an organization of, of the size and scale of Tysons. What's probably the hardest part about running security for such a large, dynamic organization

Speaker D: like yours, if you really think about you know the size and scale and scope of the operations that we run. One of the most challenging things that we can continue to do or think about as we defend the organization is just the depth of operations and the number of points where our supply chain is successful or could fail. So one, just the diversity of business processes and operations that we need to manage across not just poultry, but beef, pork, prepared foods, all are very different business units and how they manage their operations. And if you think about the kind of equipment that they need and the team members that we have to support, there are just a uh, number of different factors. So all of those iterations really requires us to think simply about how we manage our operations. And so I'm an engineer by trade and so keep it simple is really one of those core practices. And so we try to approach that every day and how we as technology and cybersecurity professionals approach supporting our business.

Speaker C: Hoping maybe you can kind of share a little bit about just like, you know, a bit of like the scale of your guys operations. Right. Um, you guys are at 50 plus billion in revenue, which is, you know, incredible. But like when you guys get hacked isn't just like a passive reset, right? There's kind of real, there's real risk, right. And the, the impact of you, of you guys running such a great cybersecurity program is more than just protecting the company. It's right, protecting a lot of the consumers and the entire kind of, you know, supply chain both up and down.

Speaker D: Can you share a little bit kind

Speaker C: of like what's at stake, right. Why does it matter so much?

Speaker D: What is at stake for us is again going back to that supply chain example is that we are here to help sustain things that grow and when they grow, they have a life cycle. And if we do not make sure that our operations are working effectively at the right time, then we're not going to achieve the kind of goals that we need to at the end of the day. And so when we think of partnering with others, we have to really think about that entire supply chain and how each component works. If we think about our independent farmers, just on the poultry side, over 7,000 independent farmers help us be successful. We want them to be successful. They are dependent upon us, we're dependent upon them. Over 44,000 houses are involved in that across just the United States. So if you think of all the fuel that's that those locations use, if you think about all the feed and ingredients, all the corn, the soybeans, all the agriculture that is used in those processes, Think about all the protein producers, the beef farmers that are really surviving on how well their product moves to market. If you think about that scale, we are really impacting thousands upon thousands of lives. But then on the other side of that, if you think about uh, what we do on a daily basis, we supply protein to almost 23% of the United States. And so that's a core component of everybody's meal, uh, meal or dinner. And so making sure that we're doing it the right way, at the right quality, at the right cost structure and at the right level of sustainability can really help us benefit everyone. So there's a huge scale involved in what we do.

Speaker B: Maybe you could tell us or share some examples of how AI has changed your team's ability to triage and detect threats and how your organization has kind of evolved with, with the new technology as well.

Speaker D: We're using the mantra all in on AI. Uh, and when we say all in it is everyone is all in on AI. So doesn't matter what role you play in the organization, whether you're a developer on our team, uh, you're an incident responder, you're part of our managed services solutions, you are responsible for thinking about those activities that you do on a daily basis and where can AI come in and assist you. If I think about looking at our threat landscape, plenty of organizations have these daily threat reports or week over weekend reports. What's happening, what's going on in the world. What if we can take all of this intelligence that's coming in, marry that up with our vulnerabilities, marry that up with the actual alerts that we're seeing within a time period and put that into a very consumable uh, format that delivers that to us so that we can get actionable insights every single day. Uh, that takes a lot of work to get your data in the right spot. And so we have really positioned ourselves from our SOC technologies to the next generation of AI enabled SIM platforms, the SOC platform. We did a massive change this past year. And so what we're seeing is just much faster meantime detection, meantime to response. And so our teams are able to get to alerts m much more quickly, which with much more insight to work on them as quickly as possible and then we can pass that intelligence back to our business teams, our technology teams in case they need to take some action.

Speaker C: Are the things that kind of you guys are doing with AI today. Again, if you told your team uh, 10 years ago, hey, we're going to be doing this and here's how your job's going to be shifting. It would have felt like science fiction, but it feels very real today.

Speaker D: It is very real today. And the real big change for me and my role and where I started was I was one of the only developers in an infrastructure organization. And so I built solutions, I wrote code and, as well as general systems administration across a number of infrastructure domains. And so what if I didn't have to worry about writing the code? What if I could trust the code more reliably and I could really think about solutioning? And so back 20 years ago, we didn't have monitoring systems, we didn't have some of these capabilities in place, and so we had to write our own. Well, we're back now to a point where we can not really worry about the code as much, and we can go back and be solution providers and builders again and really think about how to take our organizations to that next level of automation. So I think that's the real fundamental change for me and for our team. Just the ability to analyze data sets and problems in a way that we had never done that before. You know, can I take incident, uh, data, uh, from our ITSM system and just put it into an AI model and say, hey, what are the anomalies? Let's just see what it will give us at the end of the day and then we can start applying some additional insights. So, thinking about problem management and other things, maybe there's some problems that have been underlying everything that we've been doing for a while, but it's never really surfaced so that we can actually find a root cause. So I think it's going to open up a lot of avenues for us to work on a root cause and, and find challenges that we've never seen before.

Speaker C: What you described is not just like a technology shift. Right.

Speaker A: It's also a bit of a cultural

Speaker C: shift in terms of, like, how the, you know, it and security team kind of show up what they're capable of doing. Um, it sounds like you've been, you've been leading from the front to kind of demonstrate what's possible. Do you have any kind of pro tips for maybe some of your peers out there about how do you, how do you kind of really, um, educate or kind of like make you more aware about like, the things you're able to do in this new AI world that maybe were outside of their original job responsibilities?

Speaker D: I would say step into an uncomfortable area. That's one of the biggest areas of growth that we can all have is try something new and so if you're not comfortable with these AI solutions, uh, giving you an answer, test it out, trial it, make sure that you're pressure testing it the right way. Our own human insights take us a long way. And so we're still going to have to have that human in the loop making decisions, understanding if the answers AI uh, systems are giving us are really the right thing. But if we're not willing to take that chance, then you're already stopping yourself. If you're not willing to give the business a chance, you are preventing the business from maybe making a leap forward in some areas. And so get your hands dirty, go and run the tools, get your own personal licenses if you need to go back to the playground and uh, let's play a little bit more.

Speaker C: I like that, that's great advice.

Speaker B: So along those same lines, have you run into situations with your team on maybe some of your team that's also been there a while or not as maybe AI forward? How do you kind of get them to accept the new reality of AI solutions and how do you kind of help your team along that journey? Do you have certain that you've kind of pulled out as champions or kind of what's, what's been your experience with getting everybody in your organization to that, that same level of experimentation that she described?

Speaker D: We know that our own time is challenged. So if there's an advantage that we can take advantage of a tool, AI is a tool, let's do it and let's get the tools in front of our team members hands. Now for those who are scared, they're really worried about what is to come and there's an org change effort. And so you as a leader have to step out as an example and demonstrate how it's helping you, how it's helping you be more productive, how it's helping you be a better leader so that you can focus more on them spending time walking around talking to people, understanding their concerns, uh, showing that empathy and listening to them if they do have those concerns. So it's a multi phase approach where you have to be the example, you have to demonstrate that it is really helping you demonstrate that you're on board with it and then providing a safe path for them to try to make mistakes and then ultimately if they have successes, celebrate those successes. And so within my team I'm really happy that we have a number of AI champions who are leading from that front. And you know, we want people to step up and be leaders within the organization and not just wait for me not not just wait for my leadership team. So our team has got some really great leaders that are trying AI in a number of different situations. And it may not be AI, uh, it may just be some advanced analytics, some automation, but they're challenging the status quo and I want them to be the example at the end of the day because again, they're closest to the work. They're going to be able to show us where the true value is.

Speaker C: Are there like new threat vectors that you kind of worry about today? Or is there maybe some operating assumptions that kind of, as a cybersecurity community have kind of assumed to be true that are maybe less valid in kind of the AI era? And like, ah, what are maybe some things you're worried about today that were not really quite on the radar even a year or two ago as AI

Speaker D: uh continues to develop in our understanding of how it can be used in an evil way, as you mentioned, yes, there are going to be novel approaches on how threat actors can take advantage of the tools. Whether that be prompt injection or any other kind of a technique. There will be unique things that we have to address and unique tools that we're going to have to look at implementing capabilities that we have to implement. And so as long as we stay open minded and really start pushing the boundaries of um, what is expected and what's not expected, I think that we'll continue to find those novel approaches. But if you really look at the challenges, what's a prompt M injection issue? It's a data validation issue. That's really all it is. We've had data validation issues for years on applications and if you think about configuration of AI tools, we've had configuration issues in all of these tools for years. If you think about data issues, you've got access control issues. Again, we've had these things for years. And so in a lot of instances these are not net new risks that businesses have to face. But as we have matured our capabilities and people have built their uh, security organizations, we've been working on each one of those domains separately or individually to mature them. We now have to think about it with that AI lens. And so you will have new metrics to think about, you will have new threat vectors to think about, new capabilities. But going back to the originals, we've had these issues from day one in all kinds of other areas. And so I've challenged my team to really focus on are these net new risks or are these just risks that we've been accepting for a long time and nobody's really stepped up to the plate to say this is acceptable or this is not. So really rethinking what our risk profile looks like and how comfortable can we really get, you know, if it doesn't hit certain flags? Needing a human in the loop, you know, hitting a regulatory requirement, hitting a pii phi PCI type requirement, how much do we really care? We do care, but let's make sure that we're judging the risk appropriately.

Speaker B: So one area, you know, it's been all over the news uh, lately too with the newer models finding, you know, never before found vulnerabilities and things like that. Where do you feel that you, you might have to adjust how you do things at, at uh, Tyson's, given that AI in the hands of bad guys is making things like social engineering more effective, is finding vulnerabilities faster? It's really just changing the whole SPE pace of how fast the attacker can move. Is it changing how you approach things at Tyson's a little bit different?

Speaker D: It is. We're really thinking about the ways that we work and you know, how does the service desk and our HR teams, how do they engage with our customers, our team members when they call in, how are we thinking about identity verification and should we employ some new mechanisms, uh, now that we didn't before? How do we think about vulnerabilities, you know, and our speed to remediation? What, what do we need to put in place? Many organizations have a lot of vulnerabilities. They're drowning in vulnerabilities and really lack the, the ability to prioritize them on the exploitability, you know. And so there are new ways of thinking about vulnerabilities, how you're doing your network segmentation, how you're putting in these mitigating controls that quite honestly we're all going to have to accelerate. So the vulnerabilities are still there. The new models are going to potentially find some novel ways of chaining these vulnerabilities together that uh, traditional humans haven't been able to do yet. They're going to find net new vulnerabilities that we've never seen. But it's how we respond to it no differently than in previous past of incident response and business continuity. How do we now think about vulnerability management, patch management in that same vein, where again we focus on the highest level risks, we understand what our security posture is today better than we ever have before, and think about asset management, think about configuration management, those core fundamental principles that we just need to go back and revisit and make sure that those processes are solid. Those are the areas that make and break security organizations. And too often times technology teams, IT teams and the business. Forget about the basics. We've got to go back to the basics.

Speaker C: Matt, when I was doing some preparation for this show, I think I read some online you talking about, um, different frameworks for safe AI adoption. And so I was kind of curious for you, like, when you think about, um, say a team member, someone, your team's coming to you with some new ideas for where maybe AI can be used inside, inside of, um, kind of the security program, where maybe like the first questions you would kind of ask, right, to kind of figure out kind of where to invest. I think one of the challenges like we have at our company is that, like, AI lets you do everything, and when you can do everything for a lot cheaper, right? You kind of want to do everything, especially when you love building stuff. And so how do you kind of figure out where to prioritize? How do you figure out kind of where the risks are?

Speaker D: I think the challenge for technology and security leaders is to, you know, we're very happy when we see net new capabilities and we want to test things. And, you know, being an engineer, I, uh, want to get down in 30 and really try to understand what they're trying to do. But I've got to remove myself from that a little bit and think about what's the business objective? What is the value of doing this, uh, activity? Is it a manual process today? If so, how much time is being spent doing that activity? How much time can we recover to? If, uh, we want to think about that, what kind of data is involved? You know, is this going to be something that we can roll out very easily, or are we going to have to go create data for this process in order to get better or improve the data quality before we can make, make progress? So what we, what we turn everything back into is a business discussion. We are in the business of running our business. So if we don't think about it from a business user's perspective, even when we're running our own operations, then we're missing the whole point. We can be technologists all day long, we can go home, we can have our labs, we can do all this. But when we get into our workplace, we can bring those learnings in and apply it to real business lessons. So what are those business challenges that our team is having? Are we not hitting, uh, an SLA or a KPI the right way? How can we accelerate so that we are hitting Those the right way. What is that business value? That's really, really where I drive our team to think about those opportunities and that it's been very helpful so far in helping us prioritize what is the most important thing we can focus on.

Speaker B: What's something that you've seen on the risk landscape at Tysons that you can only see because you've watched it evolve?

Speaker D: I think one of the biggest changes that we've really come to appreciate is the overall complexity of supply chain and the complete dependence of our organization and other organizations on other suppliers, the utilities core critical infrastructure. And so as we have scaled the reliance that we all have on each other. And so if you think of that from a community standpoint, that means we all need to be in it together. And so it's not about us just going, you know, and solving our mission and focusing on our business, but what can we be doing to help raise the bar for other, in our instance, protein providers, ingredient suppliers, others that are supplying our supply chain, outside cold storages, transportation companies. What can we do to help influence as well as partner with them to collectively raise everybody's security posture and so that scale, that size around supply chain and how dependent we are, uh, on each other, that, that's been one of the biggest lessons for me.

Speaker B: You've spoken publicly about the basics every company should get right before adopting AI and just, you know, the core fundamentals like asset visibility, identity, data governance. Where do you think most enterprises get it wrong with just basic hygiene?

Speaker D: I think that we forget that we all need to be partners together instead of just in these siloed areas. I've heard many times security organizations are the organization of no. They need to be the organization of yes. And so they need to walk beside infrastructure teams, application teams, data teams, the business teams, in order to find solutions. Are there red lines that we need to say no? There are. There are absolutely things that we need to put in place. There are guardrails. But if we have an avenue to find a yes and put those guardrails in place, we need to be pursuing that. Yes. And so yes, our organization is no differently where really focusing on those partnerships, breaking down those silos, uh, again, basic fundamental relationships. And so if you can understand why those silos even exist, whether it be a political reason, somebody's ego, somebody's greed, what those human elements that we all have to fight against and, and really think about showing how you can partner as a security organization, you will start to achieve those benefits the right way.

Speaker C: What are some of the Skills you look for in your team that are kind of rising in value. Right. Presumably some knowledge is going down, but things like agency and curiosity are going up. I'd love to hear how you think about what the future is going to look like and how that applies to shaping and architecting the team going forward.

Speaker D: What I really look for in a team member are some of those basic characteristics. I really like curiosity. Somebody who's willing to ask why and continue asking why until they can really come to a full understanding. I've got a team member who works for us right now and she uh, is in a non technical role but she's always asking why, why, why? And she's pushing us every day to be better at our processes, being able to explain things. And so I really apprec from her and pushing me to grow in how I can even better explain things to our business as well as our other teams. And so where I think that we're gonna be in a year, 18 months, two years from a uh, uh, security operations standpoint is that we're going to come to a place where we are fully trusting some of these tools to be more autonomous than what they are today. But we're gonna have to back that up with good governance. We're going to have to put some guardrails in place that do not exist today. What are the models doing? What are uh, the agents doing? Are they really doing what we ask them to do or are they trying to get outside of their self and do something else? So I think we all have a lot of learning to do about what agents can do. And as we look to put some of these into production, we're going to have to think about trusting them to some extent. But trust, if you trust, you've got to verify. And so we've got to still verify and run that governance at a layer that is not obtrusive, has the right observability, right scalability in place so that we can focus on the next cool thing.

Speaker C: Is there kind of a use case or a product category where you're like this hasn't really been solved by kind uh, of conventional software. But I think if AI, given some time and the kind of applied AI usage, this use case could be totally crushed with AI, anything in that category.

Speaker D: I really think that given the amount of data that we as technologists have coming to a point where we can fully understand what is happening in our environment at any one time, that takes a lot of structure, a lot of planning today, I think that is where one area that's really going to help us in the future. The second is going back to that development methodology where, what if we didn't have to code anymore and spend our time doing that? What else could we be doing for

Speaker C: our last kind of like five, ten minutes here? We, um, like to do kind of a lightning round at the end. We basically give you some short questions and try to get your, like, one tweet response and you're kind of like, unfair questions I can possibly answer in one tweet. So, you know, please, please forgive me and Mike, uh, you know, afterwards. But Mike, do you want to kick it off for us?

Speaker B: Sure. So what advice do you have for a security leader who's stepping into their very first CISO job? Something they might either overestimate or underestimate about the job.

Speaker D: What I like to encourage them to do is get out of their comfort zone, go try something new that will allow them to grow. I think that'll allow them to challenge their own paradigms and their own thought processes. So go try something new, go try something different that they've never tried before. But then on the other side of that, go do the things you know are successful. Go reinforce those things. So continue to get better at your strengths, uh, every single day. And, uh, focus on those strengths and make sure that you're still driving those strengths in what you're trying to deliver.

Speaker C: You seem to be pretty up to date with some of, kind of the latest technology, some of the latest trends. What, um, would be your advice to ASISU out there about how they can kind of make sure they're staying close to the frontier, especially around kind of AI when things are changing every week or two.

Speaker D: The only thing that we can all do, which is continue to learn. Go read, go read, go read. Sign up for Reddit, listen to podcasts, go and discover something. If you don't understand what Quantum is actually, go and open up the engineering document behind it. When a new novel model comes out or a frontier model comes out, go spend some time playing and getting your hands dirty. We're going to have to go back to education. That's the only way to stay on top of things, to continuously grow. Otherwise you're going to be moving backwards every single day.

Speaker B: What's a book that you've read that's had a big impact on you and why? And it doesn't have to be cyber or even work related.

Speaker D: I read a book and it's been years, but it was called the Art of Negotiating. And so that book really taught me that there's never anything that's finite in either direction. And so you need to look for the positives in every single negotiation, every single relationship. And so if you can find commonality, then you're going to find a successful outcome. So everybody is seeking an answer when you're working on a software agreement or a contract or trying to work through or change within an organization. So, so that art of negotiating is really critical.

Speaker C: What do you think is to be true about the future of AI and cybersecurity that most people consider science fiction today?

Speaker D: That AI is just the next thing? It's just the next thing. We will have more things coming. It is the next tool, it's the next set of techniques. And so what we're going to continue to see with it is that we're going to go back and revisit problems that we've already seen. And so we continue to think that AI is this net new thing. And while it is, and there are definite technology benefits and it is a revolutionary leap forward in a lot of areas, we're still just doing the same thing, but faster.

Speaker C: Matt, thank you so much for joining us today. Looking forward to chatting again soon.

Speaker D: Thanks, Evan. Thanks, Mike, for the time. Great to talk to you.

Speaker A: That was Matt Bunch, VP and Global Chief Information Security Officer at Tyson Foods.

Speaker B: I'm Mike Britton, the CIO of Abnormal AI.

Speaker A: And I'm Evan Reiser, the founder and CEO of Abnormal AI. Thanks for listening to Enterprise AI Defenders. Please be sure to subscribe so you never miss an episode. Learn more about how AI is transforming cybersecurity at enterprisesoftware blog.

Speaker B: This show is produced by Abnormal Studios. See you next.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • The GRC Illusion: Why Third-Party Risk Is Still Broken ft Val Dobrushkin, Director of GRC @ TricentisSecurity & GRC Decoded · on Supply chain security86 / 100
  • Ep 10. Endor Labs on Code Vulnerabilities, Sketchy Open Source Developers, and Software Supply ChainGenealogy of Cybersecurity - Startup Podcast · on Supply chain security85 / 100
  • The USB Problem for AI: Phil Stafford on Agents, Governance, and MCP RiskAI Security, Cyber Risk, and Cloud Strategy on ClearTech Loop · on Supply chain security84 / 100
  • The Evolution of Human RiskSimplifying Cyber · on Threat Intelligence83 / 100
  • OEM Partnerships: What Every Practitioner, Vendor, and Investor Needs to UnderstandCybersecurity Ecosystem Show · on Threat Intelligence82 / 100
  • Crown Jewels In, Crown Jewels Out - The Hidden Risk of AI with Devan Shah (IBM)ShipTalk · on Prompt injection attacks82 / 100

More from Enterprise AI Defenders

All episodes →
  • Defending Clients and Securing AI Agents with CIBC Chief Security Officer Keith Gordon
  • Governing AI Risk in Healthcare with Montefiore Health System CISO Mark Ballister
  • Identity Is the Perimeter in AI-era Fraud with Lockton Global CISO TJ Mann
  • Fraud Moves Faster With AI, Verification Must Too with KPMG US CSO Matt Posid
  • Secure by Design AI for a Modern Utility with Eversource Energy VP & CISO Chris Leigh
Explore the best B2B AI & Data podcasts →
All Enterprise AI Defenders episodes →