Ep 113 ·
Enterprise Security Restructuring & The AI Vulnerability Boom with Alma Paul
Alma Paul of Faire on why restructuring enterprise security starts with visibility, and why AI-era vulnerabilities must be prioritised by business context.
The archive
113 conversations with the people doing the work. Search by guest, company or topic.
113 episodes
Ep 113 ·
Alma Paul of Faire on why restructuring enterprise security starts with visibility, and why AI-era vulnerabilities must be prioritised by business context.
Ep 112 ·
Matthew Moog of EY on why third-party risk is shifting from periodic assessments to continuous, SOC-style monitoring, and what Mythos means for security.
Ep 111 ·
Priyanka Chatterjee (London School of Cybersecurity) says treat AI as a colleague: trust it for SOC analysis, keep humans on response, and build skills.
Ep 110 ·
Adobe's Neelu Tripathy on bridging product security gaps: foundational controls first, then security built into the platforms and pipelines engineers use.
Ep 109 ·
Behnaz Karimi (Tramarena) explains how ransomware now targets AI models, pipelines and supply chains, and how incident response must change for AI.
Ep 103 ·
Advait Patel (Broadcom): automate just-in-time access, build IAM up from least privilege, and keep AI agents on low-risk tasks until you can trust them.
Niyati Daftary on separating AI security hype from reality and the career roadmap to becoming a CISO.
Sana Talwar on product security at scale, reducing friction for developers, and defending AI integrations in the enterprise.
Ammar Ekbote, Cloud Security Engineer at Pinterest, on eBPF, MCP server adoption, and kernel-level AI security monitoring.
Nishant Modak, founder and CEO of Last9, on scaling engineering, go-to-market strategy, and the reality of building a startup.
Sneha Malshetti, Senior Security Engineer at Ethos, on IAM differences between AWS and GCP and balancing least privilege with velocity.
James Cash on zero trust, AI-driven threats, human risk, and future-proofing organisational security programmes.
Dakota Riley on building a security culture, focusing on problems over solutions, and the impact of AI on security teams.
Dinis Cruz on Kubernetes security for ephemeral environments, enriching GenAI with quality data, and threat modelling AI stacks.
Lalit Khattar, Partner Solution Architect at AWS, on career growth, channel partnerships, and scaling through AWS Marketplace.
Ashish Bhadouria, Security and Privacy Manager at IKEA, on securing the SDLC in the AI era and defending modern enterprises.
Ashish Garg on proactive security leadership, analysing business risk impact, and cross-team alignment on security roadmaps.
Shweta Thapa, Security Specialist Solutions Architect at AWS, on designing security controls for generative AI applications.
Ep 95 ·
Compliance should feed security, not fight it. Fractional CISO Winthrop (Andy) Welch on GRC maturity, building trust and cutting tool sprawl.
Patricia Titus on the future CISO, AI and quantum security challenges, and becoming a multidisciplinary security strategist.
Faraz Khan on cracking enterprise deals, AWS Marketplace success, and go-to-market strategy for security startups.
Uttej Badwane, Senior Security Engineer at Carta, on zero-trust implementation challenges and the future role of AI in security.
Stephen Kuenzli on IAM, AI-driven cloud security, and using agents and MCPs to improve security decision-making at scale.
Joseph Haske on cybersecurity risk management, stakeholder communication, and qualitative-vs-quantitative frameworks.
Brad Geesaman on adopting AI in application security, managing non-deterministic LLMs, and knowing when agentic AI fits.
Lalit Kumar on building good and lasting cloud security, transforming AWS India Security, and advising CXOs on cloud posture.
Bonnie Viteri on building a security-champions programme from scratch, enablement vs empowerment, and measuring impact.
Rowan Udell on AWS IAM best practices for production environments, least-privilege strategies, and role-based access patterns.
Anshuman Bhartiya on product security, risk-driven prioritisation, and building secure-by-default development practices.
Jason Jordaan on digital forensics, the importance of meticulous documentation, and preparing organisations for investigations.
Reanna Schultz, founder of CyberSpeak Labs, on modern threat detection, false-positive handling, and staying ahead of threats.
Perry Carpenter on the human element in security, AI-powered deepfakes, and the evolving social-engineering threat landscape.
Mauricio Duarte on building resilient security culture, behaviour-based awareness programmes, and incident-response speed vs accuracy.
Giorgio Perticone on the incident-response lifecycle from detection to recovery, staying calm under pressure, and containment.
Ross Young on the CISO's dilemma — balancing security, innovation, and burnout — and building cross-functional champions.
Apoorvaa Deshpande, Senior Privacy Engineer at Google Cloud, on privacy engineering, privacy by design, and GenAI data governance.
Scott Weston, senior consultant at NetSPI, on cloud penetration testing, the GCPwn tool he created, and how to get started with cloud security testing.
Dr. Natalia Semenova on zero-trust architecture, the challenges of asset and identity discovery, and identity as the core of zero trust.
Richard Stiennon on the ultimate guide to cloud security, the evolving threat landscape, and building defence in depth.
Cloud incident response with Hilal Ahmad — monitoring MTTD and MTTR, and why out-of-the-box security tools are never enough.
Gretchen Ruck on rethinking cybersecurity frameworks, addressing inherent risk, and measuring security effectiveness.
Lily Chau on auto-remediation in AWS, overcoming stakeholder buy-in challenges, and prioritising security fixes.
John Giglio on demystifying IAM, the security-vs-compliance debate, and data-perimeter controls for read, write, and download.
Cassie Clark on the intersection of security and human behaviour, choice architecture, and continuous awareness programmes.
Kushagra Sharma, Senior Platform Security Engineer at Booking.com, on security baselines, boundaries, and layered defences.
Sandeep Agarwal on trust and security as the cornerstones of organisational resilience, leadership alignment, and building durable programmes.
Jan Hertsens, Senior Security Consultant at AWS, on continuous security, the compliance debate, and incident-response segmentation.
Tom Adamski on network segmentation, risk assessment before design, and layering AWS security tools for defence in depth.
Kailash Havildar on logging, monitoring, and detective controls in cloud security — what to capture and how to act on it.
Matthew Marji on building cybersecurity teams, evaluating communication skills in hiring, and aligning security with business.
Adam Shostack on threat modelling fundamentals, secure-by-design principles, and making threat analysis accessible to all teams.
Amit Subhanje on enterprise risk management, balancing proactive and reactive strategies, and shared security responsibility.
Pablo Vidal on incident response and detection, cross-team collaboration, and hiring for mutual fit in security roles.
Jesse Miller on building cybersecurity teams, creating a virtuous cycle with clients, and taking a risk-centric approach.
Josh Pyorre on threat hunting, creative security research, and the role of GenAI in uncovering new attack vectors.
Rich Mogull on cloud security maturity models, the mindset shift from on-prem, and setting realistic expectations with leadership.
Joseph South on the cloud security journey, starting with common misconfigurations, and using the Cloud Controls Matrix.
Htet Naing Aung on supply-chain security, container-image signing, SBOMs, and using SCA tools in CI/CD pipelines.
Joseph South on the cloud IAM landscape, why IAM is the new perimeter, and getting leadership buy-in for security practices.
Andre Rall on the secrets to successful cloud security, building strong foundations, and aligning security with cloud strategy.
Jim Manico on safeguarding applications in the AI era, verifying AI-generated code, and applying OWASP best practices on top of frameworks.
Jeffrey Wheatman, Cyber Risk Evangelist at Black Kite, on third-party risk management, vendor prioritisation, and procurement decisions.
Shivani Arni, CISO at TransUnion CIBIL, on emotional intelligence in security leadership and third-party risk management.
Chad Lorenc, Security Practice Manager at AWS, on cloud IAM beyond access control, showing value to leadership, and production-account security.
Kayra Otaner on DevSecOps, cloud-native security, and unleashing security capabilities without slowing engineering teams.
Matt Tesauro on revolutionising the SDLC with DevSecOps, automation for team velocity, and training security professionals.
François Proulx, Senior Product Security Engineer at Boost Security, on supply-chain security, threat modelling, and SBOMs.
Yotam Perkal on vulnerability management, supply-chain security, SBOMs, and prioritising the risks that matter most.
Kalyani Pawar on threat modelling, scaling security with checklists and champions, and celebrating small wins.
Kesten Broughton on asset management, Kubernetes in the cloud, and why visibility is the foundation of cloud security.
Divyanshu Shukla on practical strategies for defending Kubernetes clusters, detection techniques, and open-source defence tools.
Michele Chubirka on restorative justice as a new framework for resolving cybersecurity conflict and restoring team trust.
Divyanshu Shukla on red-teaming Kubernetes clusters, understanding attacker mindset, and exploiting common cluster weaknesses.
Gerard Johansen on incident response, digital forensics, threat intelligence, and training engineers on evidence collection.
Divyanshu Shukla on attacking and defending Kubernetes clusters in a hands-on workshop-style session.
Steve Giguere on Kubernetes security, when monoliths beat containers, and vetting open-source dependencies with SBOMs.
Kyle Fossum on DevOps and DevSecOps practices, self-serve security tooling, and why hardware security keys beat SMS-based MFA.
Dustin Lehr on application security, threat modelling, and building security-champion programmes through long-term relationships.
Brook Schoenfield on the secrets of effective threat modelling, integrating threat analysis into design, and scaling the practice.
Ariel Shin on balancing production speed with security, the advisory role of security teams, and the value of empathy.
Chris Romeo on application security beyond tools, prioritising with a data-driven approach, and starting with open source.
Chris Hodson, CSO of Cyberhaven, on threat modelling across the SDLC, communicating security value, and DevSecOps trade-offs.
Ashwin Patil on security applications of Jupyter notebooks, data analysis for threat detection, and interactive investigation workflows.
Jeevan Singh on threat modelling, integrating security into the development workflow, and scaling with limited resources.
Walter Haydock on vulnerability management, prioritisation strategies, and building a vulnerability programme that scales.
Brett Johnson on the dark web, credential-stuffing attacks, MFA bypass techniques, and why humans are the weakest link.
Emily Zakkak, cybersecurity specialist at Senowit, on defending against social engineering, phishing, and MFA best practices.
Karan Dwivedi on blue-team operations, partnering with red teams, and preserving forensic data accuracy.
Alyssa Ahmann on GRC setup, data privacy, and why documentation and training underpin successful security programmes.
Rodrigo Montoro on AWS security monitoring, threat modelling for new services, and restricting high-impact IAM permissions.
Paul Dyer on red, blue, and purple team operations, threat-landscape awareness, and open-source security with SBOMs.
Jim Bugwadia on Kubernetes governance, workload security responsibilities, and image-signing best practices with Sigstore.
Nader Zaveri on organisational security culture, planning and budgeting for security, and incident-response preparedness.
Adam Smith on data privacy governance, building personal-data inventories, and fostering a privacy-first culture.
Jimmy Mesta on Kubernetes misconfigurations, continuous security checks, and when to choose managed K8s over self-hosting.
Syed Shareef, Senior Security Engineer at AWS, on data perimeters, combining SCP and IAM policies, and use-case-driven security.
Ray Espinoza on cloud vulnerability management, leading with empathy, and transparent communication during incidents.
Garrett Smiley on measuring security debt, context-driven risk prioritisation, and using KRIs over KPIs for security teams.
Trupti Shiralkar on organisational security culture, joint backlog reviews for security debt, and supply-chain security standards.
Charles Mendoza on setting the line of defence in cloud security, layered controls, and incident-response readiness.
Aakash Yadav on security debt, risk prioritisation, and building a pragmatic approach to reducing organisational risk.
Parul Khanna on information security, risk management, and bridging the gap between incident response and business priorities.
Mel Reyes on the biggest mistakes in cybersecurity, top-down security mandates, and setting up foundations for startups.
Vincent Romney, Head of Global Security Architecture at Nu Skin, on zero-trust architecture and overcoming organisational resistance.
Vincent Romney, Head of Global Security Architecture at Nu Skin, on zero-trust architecture, programme design, and security planning.
Nat Shere on preparing for cloud data breaches, incident response planning, and lowering MTTD and MTTR.
Aseem Shrey, security engineer at Rippling, on responding to ethical hacker reports, preparing for data breaches, and building a security career.
Chris Neggel, Regional CSO at Okta, on the roadblocks teams face in cloud security and strategies to overcome them.
Ski on building a security-centric culture, improving cross-team relationships, and aligning certifications with controls.
Gary Dylina of Narvar on preparing for large-scale events, SOC2, IAM setup, and when to make a first security hire.
Gaurav Batra, founder and CEO of CyberFrat, on surprising cloud security facts and building security awareness culture.
Swati Anuj Arya, CISO Office leader at Amazon Pay, on simplifying cloud security and responding to data breaches.
Aseem Rastogi, Head of Cybersecurity and Compliance at Meesho, on building cybersecurity and compliance programmes from the ground up.
New episodes twice a month
Follow Scale To Zero wherever you listen, or send us the question your team is stuck on and we will put it to an expert.