Skip to content
Scale To Zero by Cloudanix

The security podcast by Cloudanix

No security question left unanswered.

Security practitioners and leaders answer the questions security teams actually ask — about cloud, AppSec, identity, AI security, risk and building a career in security.

Episodes
113
Guests
109
New episodes
2× a month

Latest episode · Aug 5, 2026 · 48 min

Enterprise Security Restructuring & The AI Vulnerability Boom with Alma Paul

Alma Paul, Faire

Recent

Latest episodes

All episodes

Straight answers

Questions answered on the show

Every episode is broken down into the questions it answers, each linked to the moment in the conversation.

Where should you start when restructuring an enterprise security program?

Start with visibility: catalogue your assets so you know what you own, then build a risk registry and define a North Star for what a successful program looks like. Next, give guidance for a consistent risk model so anyone on the team analysing a risk reaches the same criticality. Finally, check whether you are actually leveraging the tools you already have, and whether anyone or any automation is acting on their alerts, before moving on to something new.

Alma Paul · Faire

How much effort can AI save in a third-party risk assessment?

Moog estimates about 60% of the effort, possibly more, can come out of the assessment itself. His team's agents read dozens of documents and point to the exact policy, page and a screenshot of the evidence, so reviewers can verify answers quickly, and each client's model is trained separately to keep data isolated. He advises putting the savings into areas like threat and vulnerability management, incident response, agentic pen testing and security posture management rather than cutting staff.

Matthew Moog · EY

Should security teams treat AI as a tool or as a colleague?

Priyanka sees AI as the first technology that augments our thinking rather than just automating tasks, and because it can talk and challenge you back, it takes on a human flavor. She recalls spending a whole night at IBM analysing a 9,000-row vulnerability spreadsheet, work AI can now turn into a prioritisation in under 30 minutes. The better you build your relationship with it and tune it, the better you deliver, which is why she treats it as a colleague.

Priyanka Chatterjee · London School of Cybersecurity

What security controls are non-negotiable when building products for AI-powered workplaces?

Start with the fundamentals, because AI-generated code is built on the same patterns humans have written for years. Neelu lists authentication that can identify every entity making changes (users, machines and agents), data security, auditing, hardened configurations, and logging and monitoring beyond application telemetry. AI-specific controls are added on top of these.

Neelu Tripathy · Adobe

How has ransomware changed compared to five years ago?

Behnaz Karimi says encryption is becoming almost secondary: many groups now steal sensitive data and apply pressure through legal, compliance and reputational threats, DDoS attacks, or by contacting customers, partners and regulators. Attackers also go after managed service providers to hit thousands of organizations at once, and the human factor, including insiders, is growing. Even strong backups no longer make you safe.

Behnaz Karimi · Tramarena

How do you stop treating compliance as a checklist?

Advait says treating compliance as a document checklist no longer works. Patching, visibility, logs and tracking who accessed or changed what need to be in place from day one, not added after something is found. With controls, guardrails and visibility from the start, you are not scrambling when auditors arrive, and engineers feel confident in the product and in passing any security or compliance review.

Advait Patel · Broadcom

On the show

Recent guests

New episodes twice a month

No security question left unanswered.

Follow Scale To Zero wherever you listen, or send us the question your team is stuck on and we will put it to an expert.