
Hosted by Adrian Sanabria
Listed under Technology, Education › How To
News, analysis, and insights into enterprise security. We put security vendors under the microscope, and explore the latest trends that can help defenders succeed. Hosted by Adrian Sanabria. Co hosts: Katie Teitler-Santullo, Ayman Elsawah, Jason Wood, Jackie McGuire, Sean Metcalf.
484 episodes · publishes weekly · latest 2026-07-06 · ~102 min/episode
Rank
#1199
Substance
71.0
/ 100
Breakdown
Scored 2026-07
Updated monthly
Across the index
#1199 of 6183
Substance
Top 19%
outscores 81% of the index
Enterprise Security Weekly ranks #1199 on The B2B Podcast Index with a substance score of 71.0 out of 100, scored across 1 recent episode. It scores highest on guest caliber and insight density. Sandy Bird brings credible founder-level experience (Q1 Labs/QRadar sold to IBM, now CTO at Sonrai) with hands-on product development perspective. However, the three Identiverse guests (Amir Ofek, Howard Ting, Ajay Gupta) are all CEOs/founders of relatively early-stage identity/security platforms launched to address AI governance - making them invested salespeople rather than operators who have solved agent security at scale in large enterprises. None demonstrate deep battle-scars from real-world agent deployments.
Averaged across 1 recently scored episode, with cited evidence.
The episode contains a mix of valuable technical content on agent permissions and identity governance alongside significant filler. The Sandy Bird segment delivers concrete architectural insights (default deny models, permission routing, MCP servers), but the Identiverse interviews repeat overlapping themes (discovery, ownership, governance) without adding novel operational depth. Substantial time spent on fried chicken discussion, car preferences, and general platitudes ('no easy button', 'moving at machine speed') dilutes insight density.
“What we discovered of course was you would look at someone's cloud and they would have 10,000, some of them way more than 10,000, 100,000 over privileged identities”
“we basically just default deny all of the privilege and give it back to the things that need it based on historical access or people making exceptions”
The episode recycles familiar identity and access governance frameworks applied to a new domain (agents) rather than proposing genuinely novel approaches. The 'default deny' model and JML (Joiner/Mover/Leaver) analogy for agents are sensible but not original. Multiple guests rehash the same discovery-ownership-governance sequence without introducing counterintuitive or first-principles arguments about why agent security might require fundamentally different models.
“you need agent inventory”
“every agent has to have a human owner”
Sandy Bird brings credible founder-level experience (Q1 Labs/QRadar sold to IBM, now CTO at Sonrai) with hands-on product development perspective. However, the three Identiverse guests (Amir Ofek, Howard Ting, Ajay Gupta) are all CEOs/founders of relatively early-stage identity/security platforms launched to address AI governance - making them invested salespeople rather than operators who have solved agent security at scale in large enterprises. None demonstrate deep battle-scars from real-world agent deployments.
“my history again was always in security analytics. Spent huge amounts of time just doing security analytics for years and years and years. Um, and IBM was a great bit, uh, of time for me”
“I started my career in identity 25, 26 years ago at RSA”
The Sandy Bird segment provides concrete numbers (350,000 unique permissions across hyperscalers, 10,000-100,000 over-privileged identities per customer, 30-minute remediation lag) and specific technical details (MCP servers, S3 bucket vectors, VPC and security group rule examples). The Identiverse interviews are almost entirely abstract - discussion of 'discovery,' 'governance,' 'intent drift,' and 'runtime authorization' without named customer examples, metrics, timelines, or deployment specifics. No evidence of actual agents running in production or measurable outcomes.
“between the three hyperscalers you're talking three 50,000 unique permissions now”
“you would look at someone's cloud and they would have 10,000, some of them way more than 10,000, 100,000 over privileged identities”
Adrian Sanabria asks reasonable but mostly soft questions; there is minimal pushback or productive disagreement. The Sandy Bird interview allows the guest to deliver long monologues with few challenging follow-ups (e.g., no pressure on whether default-deny actually scales or costs). The Identiverse interviews are brief, promotional, and hosted by Mike Shima, who asks leading questions designed to elicit positive soundbites rather than stress-test claims. Notable absence of skepticism about vague concepts like 'intent drift' or feasibility of continuous runtime authorization at scale.
“Yeah, no we definitely again there's no doubt. Even in cloud it's interesting”
“I think the challenge is there are a lot of fragmented solutions, a lot of tools”
First period on the Index - history builds from here.
1 scored on substance · 61 tracked in total.
Add this badge to your site - it links back here and updates automatically as you rank.
<a href="https://index.fame.so/show/enterprise-security-weekly-audio" target="_blank" rel="noopener">
<img src="https://index.fame.so/badge/enterprise-security-weekly-audio/badge.svg" alt="Ranked #123 on The B2B Podcast Index" width="360" height="136" />
</a>Track Enterprise Security Weekly's rank
Get an email whenever this show moves up or down the Index. Monthly at most, no spam.
Companies, products and tools that come up most across this show's episodes.
The themes that come up most across this show's episodes.
Podcasts that dig into the same topics.