Ep 112 ·
The Mythos Era: TPRM Evolution, AI Ethics, and Project Glasswing with Matthew Moog
Matthew Moog of EY on why third-party risk is shifting from periodic assessments to continuous, SOC-style monitoring, and what Mythos means for security.
The security podcast by Cloudanix
Security practitioners and leaders answer the questions security teams actually ask — about cloud, AppSec, identity, AI security, risk and building a career in security.
Latest episode · Aug 5, 2026 · 48 min
Enterprise Security Restructuring & The AI Vulnerability Boom with Alma Paul
Alma Paul, Faire
Recent
Ep 112 ·
Matthew Moog of EY on why third-party risk is shifting from periodic assessments to continuous, SOC-style monitoring, and what Mythos means for security.
Ep 111 ·
Priyanka Chatterjee (London School of Cybersecurity) says treat AI as a colleague: trust it for SOC analysis, keep humans on response, and build skills.
Ep 110 ·
Adobe's Neelu Tripathy on bridging product security gaps: foundational controls first, then security built into the platforms and pipelines engineers use.
Ep 109 ·
Behnaz Karimi (Tramarena) explains how ransomware now targets AI models, pipelines and supply chains, and how incident response must change for AI.
Ep 103 ·
Advait Patel (Broadcom): automate just-in-time access, build IAM up from least privilege, and keep AI agents on low-risk tasks until you can trust them.
Niyati Daftary on separating AI security hype from reality and the career roadmap to becoming a CISO.
Straight answers
Every episode is broken down into the questions it answers, each linked to the moment in the conversation.
Where should you start when restructuring an enterprise security program?
Start with visibility: catalogue your assets so you know what you own, then build a risk registry and define a North Star for what a successful program looks like. Next, give guidance for a consistent risk model so anyone on the team analysing a risk reaches the same criticality. Finally, check whether you are actually leveraging the tools you already have, and whether anyone or any automation is acting on their alerts, before moving on to something new.
Alma Paul · Faire
How much effort can AI save in a third-party risk assessment?
Moog estimates about 60% of the effort, possibly more, can come out of the assessment itself. His team's agents read dozens of documents and point to the exact policy, page and a screenshot of the evidence, so reviewers can verify answers quickly, and each client's model is trained separately to keep data isolated. He advises putting the savings into areas like threat and vulnerability management, incident response, agentic pen testing and security posture management rather than cutting staff.
Matthew Moog · EY
Should security teams treat AI as a tool or as a colleague?
Priyanka sees AI as the first technology that augments our thinking rather than just automating tasks, and because it can talk and challenge you back, it takes on a human flavor. She recalls spending a whole night at IBM analysing a 9,000-row vulnerability spreadsheet, work AI can now turn into a prioritisation in under 30 minutes. The better you build your relationship with it and tune it, the better you deliver, which is why she treats it as a colleague.
Priyanka Chatterjee · London School of Cybersecurity
What security controls are non-negotiable when building products for AI-powered workplaces?
Start with the fundamentals, because AI-generated code is built on the same patterns humans have written for years. Neelu lists authentication that can identify every entity making changes (users, machines and agents), data security, auditing, hardened configurations, and logging and monitoring beyond application telemetry. AI-specific controls are added on top of these.
Neelu Tripathy · Adobe
How has ransomware changed compared to five years ago?
Behnaz Karimi says encryption is becoming almost secondary: many groups now steal sensitive data and apply pressure through legal, compliance and reputational threats, DDoS attacks, or by contacting customers, partners and regulators. Attackers also go after managed service providers to hit thousands of organizations at once, and the human factor, including insiders, is growing. Even strong backups no longer make you safe.
Behnaz Karimi · Tramarena
How do you stop treating compliance as a checklist?
Advait says treating compliance as a document checklist no longer works. Patching, visibility, logs and tracking who accessed or changed what need to be in place from day one, not added after something is found. With controls, guardrails and visibility from the start, you are not scrambling when auditors arrive, and engineers feel confident in the product and in passing any security or compliance review.
Advait Patel · Broadcom
Browse
Security Leadership & Careers
Building security teams and careers: leadership, culture, hiring, skills for the next generation and making security an enabler.
86 episodes →
Cloud Security
Securing AWS, Azure and GCP estates at scale: posture, architecture, guardrails and the operating model that keeps cloud risk in check.
66 episodes →
GRC & Third-Party Risk
Governance, risk and compliance that enables the business — maturity models, third-party risk management and making audits a by-product.
62 episodes →
AI Security
How security teams adopt AI safely, defend against AI-enabled attackers and secure the models, agents and data pipelines they build.
35 episodes →
Identity & Access Management
Identity is the new perimeter. Least privilege, IAM anti-patterns, machine and AI-agent identities, and access that is granted just in time.
30 episodes →
Application Security
Product security and AppSec in practice: threat modeling, secure SDLC, developer-friendly guardrails and closing the gaps tools leave behind.
20 episodes →
Vulnerability Management
Finding and fixing what matters: prioritising by exploitability and business context rather than chasing every CVE the scanners report.
19 episodes →
Detection & Incident Response
Detecting and responding to real attacks — ransomware, SOC operations, incident response playbooks and the shift to detection and response.
18 episodes →
On the show
Senior Corporate Security Engineer, Faire
Principal, Financial Services Risk Managed Services Leader, EY
CEO, London School of Cybersecurity
Senior Security Architect, Adobe
Cybersecurity Engineer & Independent Researcher, Tramarena
Senior SRE, Broadcom
New episodes twice a month
Follow Scale To Zero wherever you listen, or send us the question your team is stuck on and we will put it to an expert.