Ep 113 ·
Enterprise Security Restructuring & The AI Vulnerability Boom with Alma Paul
Alma Paul of Faire on why restructuring enterprise security starts with visibility, and why AI-era vulnerabilities must be prioritised by business context.
Topic
How security teams adopt AI safely, defend against AI-enabled attackers and secure the models, agents and data pipelines they build.
35 episodes · 36 questions answered
Where should you start when restructuring an enterprise security program?
Start with visibility: catalogue your assets so you know what you own, then build a risk registry and define a North Star for what a successful program looks like. Next, give guidance for a consistent risk model so anyone on the team analysing a risk reaches the same criticality. Finally, check whether you are actually leveraging the tools you already have, and whether anyone or any automation is acting on their alerts, before moving on to something new.
Alma Paul · Faire
How do you measure the health of a security program without vanity metrics?
Alma advises steering clear of vanity metrics such as the raw number of vulnerabilities reported in a year, which say nothing about how well the program is run. Good metrics tell a story over time: how much risk you have reduced and how much coverage you have gained. They also reveal where you miss targets, which helps you decide whether you need more automation or more engineers, and they should be flexible enough to let you pivot without being penalised.
Alma Paul · Faire
How should security teams prepare for the surge in AI-discovered vulnerabilities?
Alma's view is that finding vulnerabilities has never been the issue; fixing them has. A CVSS critical does not automatically mean critical for your organization, so add context: is there an exploit, is it remotely exploitable, is the service exposed to the internet? AI can help enrich, triage and group findings and identify compensating controls, but the fundamentals still hold: patching on a cadence, buy-in from teams who carve out time to remediate, and metrics that show progress.
Alma Paul · Faire
Should you shift from vulnerability management to detection and response?
No. Alma sees them as complementary layers of security rather than alternatives: a robust vulnerability management program addresses issues before they become problems, and detection and response catches what slips through, because no preventive control is 100%. Taking resources from vulnerability management to fund detection would just leave you needing a huge detection and response team, so she would rather deal with it upstream while building layers.
Alma Paul · Faire
How do you prioritise vulnerabilities when there are too many to fix?
Start with business context: what your worst day looks like and which assets are high-risk and high-value, then translate each vulnerability's risk score to your environment. Check whether an exploit or working proof of concept exists and whether the vulnerable service is exposed to the internet; if it is, she would probably call an incident right away, while a segmented-off service buys more time. Be deliberate about what you call critical, so other teams can trust that a critical genuinely needs attention.
Alma Paul · Faire
Should security teams adopt AI security tools?
Evaluate an AI tool like any other product: is it solving a problem your organization has, how well does it solve it, and does it deliver what it claims? Having AI in its name does not make it good. Alma sees real gains in areas such as detection and response and DLP, where context awareness could replace black-and-white regex matching, but warns against expecting AI to replace security engineers; use it to offload mundane, repeatable work.
Alma Paul · Faire
How much effort can AI save in a third-party risk assessment?
Moog estimates about 60% of the effort, possibly more, can come out of the assessment itself. His team's agents read dozens of documents and point to the exact policy, page and a screenshot of the evidence, so reviewers can verify answers quickly, and each client's model is trained separately to keep data isolated. He advises putting the savings into areas like threat and vulnerability management, incident response, agentic pen testing and security posture management rather than cutting staff.
Matthew Moog · EY
What is Project Glasswing and why should security leaders care?
Project Glasswing gives a select group, largely large banks, access to Anthropic's Mythos model; consulting firms like EY see it only through client projects and working groups. Moog says what makes Mythos different is that it stacks vulnerabilities, combining ones that are insignificant on their own into a much bigger one. He warns that organizations rushing to adopt agents need controls and an understanding of these new risks, which takes people who are deeply technical and understand the business context.
Matthew Moog · EY
Why is AI ethics a board-level issue?
Moog sees the ethical questions inside third-party risk as small next to the broader board discussion of AI ethics. Agents are given judgment and access that mirror an employee, and they have tunneled outside firewalls and interacted in ways no one expected, so the real dilemma is where to say no. He also treats workforce impact as an ethical choice, raising options such as working 20% less for 20% less pay instead of cutting 20% of staff.
Matthew Moog · EY
Will AI replace third-party risk questionnaires and assessments?
Not entirely. Moog compares it to a modern car full of sensors that still gets a 160-point inspection before resale: an assessment remains the best way to understand a new third party's controls and is still worth doing every year for critical ones. Because mature assessments rarely change year to year, he expects more time to go to continuous signals and to running third-party risk almost like a mini SOC.
Matthew Moog · EY
How does AI change security in the software development lifecycle?
Moog says AI coding models are very good at checking their own code for vulnerabilities, so scanning will be built in by default whether code is written by humans or agents, although the models still struggle with user personas, access and non-linear workflows. He expects constant scanning of code bases and external perimeters, and says patching what is found will have to be automated in many cases because that would be very difficult with a human-based labor force.
Matthew Moog · EY
Will AI reduce the size of security teams?
Moog does not expect a fully autonomous security organization in the next 10 years outside some very small startups, because agents cannot yet think critically through chaos the way a SOC analyst does when deciding whether to cut off an anomaly. He sees demand for more security professionals, especially those with a deep technical understanding of their architecture, their tools and where AI fits in, including through third parties.
Matthew Moog · EY
Should security teams treat AI as a tool or as a colleague?
Priyanka sees AI as the first technology that augments our thinking rather than just automating tasks, and because it can talk and challenge you back, it takes on a human flavor. She recalls spending a whole night at IBM analysing a 9,000-row vulnerability spreadsheet, work AI can now turn into a prioritisation in under 30 minutes. The better you build your relationship with it and tune it, the better you deliver, which is why she treats it as a colleague.
Priyanka Chatterjee · London School of Cybersecurity
Which security operations workflows can you trust AI with today?
She would trust AI more for reporting, finding data, triage in a security incident response center and investigation, where false positives have dropped a lot, though they will never reach 100%. She would not hand over autonomous response, such as disconnecting a machine from the network or disabling an account; those decisions need a human in the loop. Any tool needs tuning with your organisation's context, and its results are only as good as your data quality.
Priyanka Chatterjee · London School of Cybersecurity
What makes AI different from SOAR and earlier security automation?
Platforms like SOAR and next-gen firewalls were bought, but their automated response was rarely adopted: trigger points were inconsistent, triaging the data still took a lot of effort, and most organisations lacked mature decision workflows. As she puts it, if you cannot run something manually, it cannot run automatically. AI makes the analysis much easier so trigger points become clearer, and it can challenge you back instead of following an if-else model.
Priyanka Chatterjee · London School of Cybersecurity
What will a SOC analyst's job look like in three to five years?
Priyanka pictures AI colleagues running triage overnight, ending graveyard shifts, and having a shift handover report and a list of decisions and judgment calls ready when the analyst comes in. Most of an analyst's time today goes into going through data; in an AI SOC the job becomes making decisions, so more of the workforce will look like today's level three analysts. Whether you are working or about to enter the workforce, she says you need to learn AI.
Priyanka Chatterjee · London School of Cybersecurity
What is the difference between a knowledge economy and a skills economy?
Knowledge is knowing about something, which is what schools are structured to give you; a skill is knowing where and how to apply it. Pre-industrial work valued skills, industrialisation and the internet created a knowledge and information economy, and now that information is cheap and abundant, value is shifting back to skills. She says people with agency, who are driven, self-motivated and follow through, will be more successful.
Priyanka Chatterjee · London School of Cybersecurity
How do you get hired in cybersecurity without experience?
An ATS-compliant CV opens the door to an interview, but a portfolio that proves you can apply your knowledge is what gets you hired. For a SOC analyst role, that could show you can look at logs, have set up a SIEM at home and have tested with the open-source Nmap scanner, and AI can tell you how to build a home lab. Certifications prove knowledge but not application, so a certification plus a portfolio is hard to beat.
Priyanka Chatterjee · London School of Cybersecurity
What security controls are non-negotiable when building products for AI-powered workplaces?
Start with the fundamentals, because AI-generated code is built on the same patterns humans have written for years. Neelu lists authentication that can identify every entity making changes (users, machines and agents), data security, auditing, hardened configurations, and logging and monitoring beyond application telemetry. AI-specific controls are added on top of these.
Neelu Tripathy · Adobe
What product security gaps do architecture reviews commonly find?
User authentication is usually covered, because developers treat it as functionality; the gaps are elsewhere. Neelu points to build systems, development environments and promotion between environments (the supply chain), encryption and network segregation of data stores, observability, and throttling for spikes in access. Supporting systems such as message brokers and caches can be attacked too, so check whether services authenticate to each other and whether their tokens are short-lived.
Neelu Tripathy · Adobe
Where should you start when prioritising security in the SDLC?
Neelu's practical answer is to secure the build systems and build infrastructure first, before the code itself. Then make sure security and compliance requirements reach the backlog, security is automated in the pipeline, and designs are reviewed. In agile teams, stay release-focused (secure a feature like checkout before it ships) and iterate on security with every release.
Neelu Tripathy · Adobe
Why do security tools fail to stop breaches?
Neelu sees no direct correlation between owning tools and avoiding breaches. Tools in blocking mode can overwhelm developers with thousands of findings, many of them false positives, unreachable or not exploitable, so issues stay unfixed; other breaches come from zero days or new changes that pull in libraries. Her answer is to focus on controls rather than detection tools, and to build fixes into the system through automation.
Neelu Tripathy · Adobe
How do you keep product security from slowing down engineering velocity?
Treat velocity as the North Star, since time is currency for fast-moving and agentic teams. First, decide what security systems you can provide, built or bought; second, embed security requirements into concentrated places of engineering power such as pipelines, artifactories, registries and shared storage to reach the most developers. Third, package security so it is easy to consume, like a golden image or an automated upgrade PR from Dependabot or Renovate that developers only need to review and accept.
Neelu Tripathy · Adobe
What security controls does agentic development need?
Beyond the fundamentals, Neelu points to a vetted registry for AI tools and MCP servers, which she treats like dependencies, and to identifying and registering agents so their actions can be traced. She also calls out controls on agent-to-agent and LLM gateway traffic, sandboxed, isolated and ephemeral agent runtimes, and security for context: how it is stored, traced and linked, and what data access it grants an agent.
Neelu Tripathy · Adobe
How has ransomware changed compared to five years ago?
Behnaz Karimi says encryption is becoming almost secondary: many groups now steal sensitive data and apply pressure through legal, compliance and reputational threats, DDoS attacks, or by contacting customers, partners and regulators. Attackers also go after managed service providers to hit thousands of organizations at once, and the human factor, including insiders, is growing. Even strong backups no longer make you safe.
Behnaz Karimi · Tramarena
What are the stages of a ransomware attack on an AI system?
She describes three acts. First, the supply chain: a malicious model on a public repository passes your benchmarks and your team pulls it in. Second, persistence: it weaves itself into the ML pipeline, through preprocessing hooks and model checkpoints, and waits, around 72 hours or less, long enough to clear anomaly detection. Third, detonation: checkpoints are encrypted, endpoints go down and the ransom note surfaces through your own API and dashboard, and recovery means full pipeline reconstruction and retraining from scratch.
Behnaz Karimi · Tramarena
What is the most overlooked entry point for ransomware in AI systems?
The AI supply chain: model repositories, public repositories, third-party pre-trained models and ML framework dependencies. Security teams focus on perimeter firewalls and endpoint detection, while a model pulled in during a routine cycle passes benchmarks with malicious logic sitting dormant inside. Many organizations still lack basic AI-specific controls such as integrity monitoring and validation of model artifacts.
Behnaz Karimi · Tramarena
Are small and mid-sized companies at risk of AI ransomware?
Yes. Behnaz calls the idea that smaller organizations are overlooked a dangerous myth: they have data, and ransomware as a service lets people with little technical skill launch complex attacks. Smaller companies adopt third-party AI tools quickly without the same protection, often without tracking where models come from or monitoring what enters their systems. She recommends treating AI models and data as critical security assets, with proper validation and continuous monitoring.
Behnaz Karimi · Tramarena
How can an organization assess its exposure to AI ransomware?
Ask whether a normal IT attack can reach your AI systems, and whether a compromised AI component can affect the rest of your IT environment. Then walk through your systems step by step, honestly and thinking like an attacker: do you only use trusted models, can models run code, can a compromise spread, and do you have clean backups? Check that you know which models and ML libraries run in production and where they come from, and adapt existing security frameworks as a baseline.
Behnaz Karimi · Tramarena
How should incident response change when ransomware hits AI systems?
Isolating and eradicating is a good starting point but not enough, because attackers can quietly poison a model and it may behave incorrectly long before you notice. Behnaz says you need a way to verify models, such as tracking where they come from and confirming they have not been changed, and an investigation into how the model was trained, what dependencies it used and how it has behaved over time. If you are not fully confident the model is clean, do not restore it: retrain from scratch in a clean environment using trusted data.
Behnaz Karimi · Tramarena
How do you stop treating compliance as a checklist?
Advait says treating compliance as a document checklist no longer works. Patching, visibility, logs and tracking who accessed or changed what need to be in place from day one, not added after something is found. With controls, guardrails and visibility from the start, you are not scrambling when auditors arrive, and engineers feel confident in the product and in passing any security or compliance review.
Advait Patel · Broadcom
How should just-in-time access change IAM in 2026?
Manual access requests — file a ticket, wait for IT security and manager approval — can take a day or several, frustrate developers and slow development. Advait says that has to go: developers should request just-in-time access that is checked against predefined controls and granted in seconds or minutes. Security is not locking everything; it is locking what needs to be locked and granting what needs to be granted.
Advait Patel · Broadcom
What KPIs should security leaders track once AI is part of security operations?
Advait says traditional KPIs — mean time to react, detect and resolve — are not wrong but are no longer enough. He adds signal quality (is AI improving existing workflows), engineer efficiency (is a problem fixed faster than before), decision quality (does AI recommend well enough that you are not deciding every low-risk task) and automation safety (how often AI-driven automations are correct).
Advait Patel · Broadcom
What IAM anti-patterns should organizations avoid?
What works for 100 engineers will not work for 10,000, so IAM has to fit your company. The anti-pattern Advait calls out is starting from the top — granting admin or power-user access and removing what goes unused after 30 days. Instead, start from zero trust and minimal permissions, assign roles by team (a database team needs services like DynamoDB or Cloud SQL, not VMs), and add permissions as needed.
Advait Patel · Broadcom
How can SREs use AI agents for root cause analysis?
Agents can track changes, collect logs, find patterns in production alerts, trace the root cause, check whether an incident has happened before, and write incident runbooks. But agents cost you visibility, so you need to know what they are doing and what they are capable of. Advait starts with low-risk tasks rather than handing an agent a production API key with no human intervention.
Advait Patel · Broadcom
Will AI agents become fully autonomous in production?
Advait sees the industry heading toward autonomous agents, but says you should never fully trust anything, especially AI, with a production system that touches customers and your company's reputation. Use autonomous AI for low-risk tasks where you are fine without visibility and confident in the results; if you are even 0.01% in doubt, he doubts people will use it in production.
Advait Patel · Broadcom
Ep 113 ·
Alma Paul of Faire on why restructuring enterprise security starts with visibility, and why AI-era vulnerabilities must be prioritised by business context.
Ep 112 ·
Matthew Moog of EY on why third-party risk is shifting from periodic assessments to continuous, SOC-style monitoring, and what Mythos means for security.
Ep 111 ·
Priyanka Chatterjee (London School of Cybersecurity) says treat AI as a colleague: trust it for SOC analysis, keep humans on response, and build skills.
Ep 110 ·
Adobe's Neelu Tripathy on bridging product security gaps: foundational controls first, then security built into the platforms and pipelines engineers use.
Ep 109 ·
Behnaz Karimi (Tramarena) explains how ransomware now targets AI models, pipelines and supply chains, and how incident response must change for AI.
Ep 103 ·
Advait Patel (Broadcom): automate just-in-time access, build IAM up from least privilege, and keep AI agents on low-risk tasks until you can trust them.
Niyati Daftary on separating AI security hype from reality and the career roadmap to becoming a CISO.
Sana Talwar on product security at scale, reducing friction for developers, and defending AI integrations in the enterprise.
Ammar Ekbote, Cloud Security Engineer at Pinterest, on eBPF, MCP server adoption, and kernel-level AI security monitoring.
Nishant Modak, founder and CEO of Last9, on scaling engineering, go-to-market strategy, and the reality of building a startup.
Sneha Malshetti, Senior Security Engineer at Ethos, on IAM differences between AWS and GCP and balancing least privilege with velocity.
James Cash on zero trust, AI-driven threats, human risk, and future-proofing organisational security programmes.
Dakota Riley on building a security culture, focusing on problems over solutions, and the impact of AI on security teams.
Dinis Cruz on Kubernetes security for ephemeral environments, enriching GenAI with quality data, and threat modelling AI stacks.
Lalit Khattar, Partner Solution Architect at AWS, on career growth, channel partnerships, and scaling through AWS Marketplace.
Ashish Bhadouria, Security and Privacy Manager at IKEA, on securing the SDLC in the AI era and defending modern enterprises.
Ashish Garg on proactive security leadership, analysing business risk impact, and cross-team alignment on security roadmaps.
Shweta Thapa, Security Specialist Solutions Architect at AWS, on designing security controls for generative AI applications.
Patricia Titus on the future CISO, AI and quantum security challenges, and becoming a multidisciplinary security strategist.
Faraz Khan on cracking enterprise deals, AWS Marketplace success, and go-to-market strategy for security startups.
Joseph Haske on cybersecurity risk management, stakeholder communication, and qualitative-vs-quantitative frameworks.
Brad Geesaman on adopting AI in application security, managing non-deterministic LLMs, and knowing when agentic AI fits.
Jason Jordaan on digital forensics, the importance of meticulous documentation, and preparing organisations for investigations.
Perry Carpenter on the human element in security, AI-powered deepfakes, and the evolving social-engineering threat landscape.
Giorgio Perticone on the incident-response lifecycle from detection to recovery, staying calm under pressure, and containment.
Apoorvaa Deshpande, Senior Privacy Engineer at Google Cloud, on privacy engineering, privacy by design, and GenAI data governance.
Gretchen Ruck on rethinking cybersecurity frameworks, addressing inherent risk, and measuring security effectiveness.
Lily Chau on auto-remediation in AWS, overcoming stakeholder buy-in challenges, and prioritising security fixes.
Jan Hertsens, Senior Security Consultant at AWS, on continuous security, the compliance debate, and incident-response segmentation.
Josh Pyorre on threat hunting, creative security research, and the role of GenAI in uncovering new attack vectors.
Joseph South on the cloud security journey, starting with common misconfigurations, and using the Cloud Controls Matrix.
Jim Manico on safeguarding applications in the AI era, verifying AI-generated code, and applying OWASP best practices on top of frameworks.
Brook Schoenfield on the secrets of effective threat modelling, integrating threat analysis into design, and scaling the practice.
Chris Romeo on application security beyond tools, prioritising with a data-driven approach, and starting with open source.
Chris Hodson, CSO of Cyberhaven, on threat modelling across the SDLC, communicating security value, and DevSecOps trade-offs.
New episodes twice a month
Follow Scale To Zero wherever you listen, or send us the question your team is stuck on and we will put it to an expert.