Ep 113 ·
Enterprise Security Restructuring & The AI Vulnerability Boom with Alma Paul
Alma Paul of Faire on why restructuring enterprise security starts with visibility, and why AI-era vulnerabilities must be prioritised by business context.
Topic
Building security teams and careers: leadership, culture, hiring, skills for the next generation and making security an enabler.
86 episodes · 24 questions answered
Where should you start when restructuring an enterprise security program?
Start with visibility: catalogue your assets so you know what you own, then build a risk registry and define a North Star for what a successful program looks like. Next, give guidance for a consistent risk model so anyone on the team analysing a risk reaches the same criticality. Finally, check whether you are actually leveraging the tools you already have, and whether anyone or any automation is acting on their alerts, before moving on to something new.
Alma Paul · Faire
How do you measure the health of a security program without vanity metrics?
Alma advises steering clear of vanity metrics such as the raw number of vulnerabilities reported in a year, which say nothing about how well the program is run. Good metrics tell a story over time: how much risk you have reduced and how much coverage you have gained. They also reveal where you miss targets, which helps you decide whether you need more automation or more engineers, and they should be flexible enough to let you pivot without being penalised.
Alma Paul · Faire
How should security teams prepare for the surge in AI-discovered vulnerabilities?
Alma's view is that finding vulnerabilities has never been the issue; fixing them has. A CVSS critical does not automatically mean critical for your organization, so add context: is there an exploit, is it remotely exploitable, is the service exposed to the internet? AI can help enrich, triage and group findings and identify compensating controls, but the fundamentals still hold: patching on a cadence, buy-in from teams who carve out time to remediate, and metrics that show progress.
Alma Paul · Faire
Should you shift from vulnerability management to detection and response?
No. Alma sees them as complementary layers of security rather than alternatives: a robust vulnerability management program addresses issues before they become problems, and detection and response catches what slips through, because no preventive control is 100%. Taking resources from vulnerability management to fund detection would just leave you needing a huge detection and response team, so she would rather deal with it upstream while building layers.
Alma Paul · Faire
How do you prioritise vulnerabilities when there are too many to fix?
Start with business context: what your worst day looks like and which assets are high-risk and high-value, then translate each vulnerability's risk score to your environment. Check whether an exploit or working proof of concept exists and whether the vulnerable service is exposed to the internet; if it is, she would probably call an incident right away, while a segmented-off service buys more time. Be deliberate about what you call critical, so other teams can trust that a critical genuinely needs attention.
Alma Paul · Faire
Should security teams adopt AI security tools?
Evaluate an AI tool like any other product: is it solving a problem your organization has, how well does it solve it, and does it deliver what it claims? Having AI in its name does not make it good. Alma sees real gains in areas such as detection and response and DLP, where context awareness could replace black-and-white regex matching, but warns against expecting AI to replace security engineers; use it to offload mundane, repeatable work.
Alma Paul · Faire
How much effort can AI save in a third-party risk assessment?
Moog estimates about 60% of the effort, possibly more, can come out of the assessment itself. His team's agents read dozens of documents and point to the exact policy, page and a screenshot of the evidence, so reviewers can verify answers quickly, and each client's model is trained separately to keep data isolated. He advises putting the savings into areas like threat and vulnerability management, incident response, agentic pen testing and security posture management rather than cutting staff.
Matthew Moog · EY
What is Project Glasswing and why should security leaders care?
Project Glasswing gives a select group, largely large banks, access to Anthropic's Mythos model; consulting firms like EY see it only through client projects and working groups. Moog says what makes Mythos different is that it stacks vulnerabilities, combining ones that are insignificant on their own into a much bigger one. He warns that organizations rushing to adopt agents need controls and an understanding of these new risks, which takes people who are deeply technical and understand the business context.
Matthew Moog · EY
Why is AI ethics a board-level issue?
Moog sees the ethical questions inside third-party risk as small next to the broader board discussion of AI ethics. Agents are given judgment and access that mirror an employee, and they have tunneled outside firewalls and interacted in ways no one expected, so the real dilemma is where to say no. He also treats workforce impact as an ethical choice, raising options such as working 20% less for 20% less pay instead of cutting 20% of staff.
Matthew Moog · EY
Will AI replace third-party risk questionnaires and assessments?
Not entirely. Moog compares it to a modern car full of sensors that still gets a 160-point inspection before resale: an assessment remains the best way to understand a new third party's controls and is still worth doing every year for critical ones. Because mature assessments rarely change year to year, he expects more time to go to continuous signals and to running third-party risk almost like a mini SOC.
Matthew Moog · EY
How does AI change security in the software development lifecycle?
Moog says AI coding models are very good at checking their own code for vulnerabilities, so scanning will be built in by default whether code is written by humans or agents, although the models still struggle with user personas, access and non-linear workflows. He expects constant scanning of code bases and external perimeters, and says patching what is found will have to be automated in many cases because that would be very difficult with a human-based labor force.
Matthew Moog · EY
Will AI reduce the size of security teams?
Moog does not expect a fully autonomous security organization in the next 10 years outside some very small startups, because agents cannot yet think critically through chaos the way a SOC analyst does when deciding whether to cut off an anomaly. He sees demand for more security professionals, especially those with a deep technical understanding of their architecture, their tools and where AI fits in, including through third parties.
Matthew Moog · EY
Should security teams treat AI as a tool or as a colleague?
Priyanka sees AI as the first technology that augments our thinking rather than just automating tasks, and because it can talk and challenge you back, it takes on a human flavor. She recalls spending a whole night at IBM analysing a 9,000-row vulnerability spreadsheet, work AI can now turn into a prioritisation in under 30 minutes. The better you build your relationship with it and tune it, the better you deliver, which is why she treats it as a colleague.
Priyanka Chatterjee · London School of Cybersecurity
Which security operations workflows can you trust AI with today?
She would trust AI more for reporting, finding data, triage in a security incident response center and investigation, where false positives have dropped a lot, though they will never reach 100%. She would not hand over autonomous response, such as disconnecting a machine from the network or disabling an account; those decisions need a human in the loop. Any tool needs tuning with your organisation's context, and its results are only as good as your data quality.
Priyanka Chatterjee · London School of Cybersecurity
What makes AI different from SOAR and earlier security automation?
Platforms like SOAR and next-gen firewalls were bought, but their automated response was rarely adopted: trigger points were inconsistent, triaging the data still took a lot of effort, and most organisations lacked mature decision workflows. As she puts it, if you cannot run something manually, it cannot run automatically. AI makes the analysis much easier so trigger points become clearer, and it can challenge you back instead of following an if-else model.
Priyanka Chatterjee · London School of Cybersecurity
What will a SOC analyst's job look like in three to five years?
Priyanka pictures AI colleagues running triage overnight, ending graveyard shifts, and having a shift handover report and a list of decisions and judgment calls ready when the analyst comes in. Most of an analyst's time today goes into going through data; in an AI SOC the job becomes making decisions, so more of the workforce will look like today's level three analysts. Whether you are working or about to enter the workforce, she says you need to learn AI.
Priyanka Chatterjee · London School of Cybersecurity
What is the difference between a knowledge economy and a skills economy?
Knowledge is knowing about something, which is what schools are structured to give you; a skill is knowing where and how to apply it. Pre-industrial work valued skills, industrialisation and the internet created a knowledge and information economy, and now that information is cheap and abundant, value is shifting back to skills. She says people with agency, who are driven, self-motivated and follow through, will be more successful.
Priyanka Chatterjee · London School of Cybersecurity
How do you get hired in cybersecurity without experience?
An ATS-compliant CV opens the door to an interview, but a portfolio that proves you can apply your knowledge is what gets you hired. For a SOC analyst role, that could show you can look at logs, have set up a SIEM at home and have tested with the open-source Nmap scanner, and AI can tell you how to build a home lab. Certifications prove knowledge but not application, so a certification plus a portfolio is hard to beat.
Priyanka Chatterjee · London School of Cybersecurity
Should security and compliance be treated as separate priorities?
Andy says security and effective compliance shouldn't be at odds. He defines compliance broadly, covering external requirements such as regulations and contracts and internal obligations such as policies and controls, and argues that good compliance mandates describe what must be done, not how. Clear, traceable compliance requirements then become inputs to the security roadmap and can be prioritized like any other requirements.
Winthrop (Andy) Welch
What is the biggest hurdle to aligning security strategy with the business?
According to Andy, it is gaining persistent, regular access to the right people on the business side, so you understand their motivators and where the business is headed. Security has to offer those stakeholders value and keep the dialogue open and refreshed, and he thinks many organizations don't spend enough time keeping that alignment steady.
Winthrop (Andy) Welch
How mature is GRC in most enterprises?
Andy sees GRC maturity as pretty low in many organizations, where GRC is treated as the assessments team that arrives after development with a checklist and a list of problems. That makes it a source of noise and friction, and it quickly gets marginalized. The shift comes when GRC moves upstream, embeds in development and operations, learns their workflows and helps teams make security decisions as they are being made.
Winthrop (Andy) Welch
How should you structure a GRC team?
Andy starts with clarity: when he built out the GRC program at Yahoo, he defined its vision, scope and value proposition and tied everything back to them. Rather than splitting teams into governance, risk and compliance, he splits them by internal focus (policies, control standards, risk oversight, internal compliance) and external focus (regulatory engagement, third-party risk, M&A contracts, customer and partner assurance). He finds this aligns better with how businesses are structured and builds more natural relationships with stakeholders.
Winthrop (Andy) Welch
How do you fix security tool sprawl?
Andy sees tool sprawl as a symptom of never having a cohesive security architecture or long-term plan, with tools picked reactively for each problem, leading to overlap, integration gaps and bloated cost. The fix is strategic: step back, map out your future state architecture and build a reasonable roadmap to get there. It takes time and coordination across teams, but the payoff is a leaner, more effective and more affordable program.
Winthrop (Andy) Welch
When should security get involved in M&A deals?
Andy says security has to be part of the deal from the deal thesis through diligence to execution, not bolted on at the end. He describes a deal that collapsed because the deal team didn't engage IT or security until after close, and the acquired software's architecture proved too expensive to integrate. Once his team started adding insight to deal teams, those teams began inviting them in, which he treats as the sign of success.
Winthrop (Andy) Welch
Ep 113 ·
Alma Paul of Faire on why restructuring enterprise security starts with visibility, and why AI-era vulnerabilities must be prioritised by business context.
Ep 112 ·
Matthew Moog of EY on why third-party risk is shifting from periodic assessments to continuous, SOC-style monitoring, and what Mythos means for security.
Ep 111 ·
Priyanka Chatterjee (London School of Cybersecurity) says treat AI as a colleague: trust it for SOC analysis, keep humans on response, and build skills.
Niyati Daftary on separating AI security hype from reality and the career roadmap to becoming a CISO.
Nishant Modak, founder and CEO of Last9, on scaling engineering, go-to-market strategy, and the reality of building a startup.
James Cash on zero trust, AI-driven threats, human risk, and future-proofing organisational security programmes.
Dakota Riley on building a security culture, focusing on problems over solutions, and the impact of AI on security teams.
Dinis Cruz on Kubernetes security for ephemeral environments, enriching GenAI with quality data, and threat modelling AI stacks.
Lalit Khattar, Partner Solution Architect at AWS, on career growth, channel partnerships, and scaling through AWS Marketplace.
Ashish Bhadouria, Security and Privacy Manager at IKEA, on securing the SDLC in the AI era and defending modern enterprises.
Ashish Garg on proactive security leadership, analysing business risk impact, and cross-team alignment on security roadmaps.
Shweta Thapa, Security Specialist Solutions Architect at AWS, on designing security controls for generative AI applications.
Ep 95 ·
Compliance should feed security, not fight it. Fractional CISO Winthrop (Andy) Welch on GRC maturity, building trust and cutting tool sprawl.
Patricia Titus on the future CISO, AI and quantum security challenges, and becoming a multidisciplinary security strategist.
Faraz Khan on cracking enterprise deals, AWS Marketplace success, and go-to-market strategy for security startups.
Uttej Badwane, Senior Security Engineer at Carta, on zero-trust implementation challenges and the future role of AI in security.
Joseph Haske on cybersecurity risk management, stakeholder communication, and qualitative-vs-quantitative frameworks.
Brad Geesaman on adopting AI in application security, managing non-deterministic LLMs, and knowing when agentic AI fits.
Bonnie Viteri on building a security-champions programme from scratch, enablement vs empowerment, and measuring impact.
Anshuman Bhartiya on product security, risk-driven prioritisation, and building secure-by-default development practices.
Jason Jordaan on digital forensics, the importance of meticulous documentation, and preparing organisations for investigations.
Reanna Schultz, founder of CyberSpeak Labs, on modern threat detection, false-positive handling, and staying ahead of threats.
Perry Carpenter on the human element in security, AI-powered deepfakes, and the evolving social-engineering threat landscape.
Mauricio Duarte on building resilient security culture, behaviour-based awareness programmes, and incident-response speed vs accuracy.
Giorgio Perticone on the incident-response lifecycle from detection to recovery, staying calm under pressure, and containment.
Ross Young on the CISO's dilemma — balancing security, innovation, and burnout — and building cross-functional champions.
Apoorvaa Deshpande, Senior Privacy Engineer at Google Cloud, on privacy engineering, privacy by design, and GenAI data governance.
Scott Weston, senior consultant at NetSPI, on cloud penetration testing, the GCPwn tool he created, and how to get started with cloud security testing.
Dr. Natalia Semenova on zero-trust architecture, the challenges of asset and identity discovery, and identity as the core of zero trust.
Cloud incident response with Hilal Ahmad — monitoring MTTD and MTTR, and why out-of-the-box security tools are never enough.
Gretchen Ruck on rethinking cybersecurity frameworks, addressing inherent risk, and measuring security effectiveness.
Cassie Clark on the intersection of security and human behaviour, choice architecture, and continuous awareness programmes.
Kushagra Sharma, Senior Platform Security Engineer at Booking.com, on security baselines, boundaries, and layered defences.
Sandeep Agarwal on trust and security as the cornerstones of organisational resilience, leadership alignment, and building durable programmes.
Matthew Marji on building cybersecurity teams, evaluating communication skills in hiring, and aligning security with business.
Adam Shostack on threat modelling fundamentals, secure-by-design principles, and making threat analysis accessible to all teams.
Amit Subhanje on enterprise risk management, balancing proactive and reactive strategies, and shared security responsibility.
Pablo Vidal on incident response and detection, cross-team collaboration, and hiring for mutual fit in security roles.
Jesse Miller on building cybersecurity teams, creating a virtuous cycle with clients, and taking a risk-centric approach.
Rich Mogull on cloud security maturity models, the mindset shift from on-prem, and setting realistic expectations with leadership.
Joseph South on the cloud security journey, starting with common misconfigurations, and using the Cloud Controls Matrix.
Joseph South on the cloud IAM landscape, why IAM is the new perimeter, and getting leadership buy-in for security practices.
Andre Rall on the secrets to successful cloud security, building strong foundations, and aligning security with cloud strategy.
Jeffrey Wheatman, Cyber Risk Evangelist at Black Kite, on third-party risk management, vendor prioritisation, and procurement decisions.
Shivani Arni, CISO at TransUnion CIBIL, on emotional intelligence in security leadership and third-party risk management.
Kayra Otaner on DevSecOps, cloud-native security, and unleashing security capabilities without slowing engineering teams.
Matt Tesauro on revolutionising the SDLC with DevSecOps, automation for team velocity, and training security professionals.
François Proulx, Senior Product Security Engineer at Boost Security, on supply-chain security, threat modelling, and SBOMs.
Yotam Perkal on vulnerability management, supply-chain security, SBOMs, and prioritising the risks that matter most.
Kalyani Pawar on threat modelling, scaling security with checklists and champions, and celebrating small wins.
Kesten Broughton on asset management, Kubernetes in the cloud, and why visibility is the foundation of cloud security.
Michele Chubirka on restorative justice as a new framework for resolving cybersecurity conflict and restoring team trust.
Gerard Johansen on incident response, digital forensics, threat intelligence, and training engineers on evidence collection.
Divyanshu Shukla on attacking and defending Kubernetes clusters in a hands-on workshop-style session.
Kyle Fossum on DevOps and DevSecOps practices, self-serve security tooling, and why hardware security keys beat SMS-based MFA.
Dustin Lehr on application security, threat modelling, and building security-champion programmes through long-term relationships.
Brook Schoenfield on the secrets of effective threat modelling, integrating threat analysis into design, and scaling the practice.
Ariel Shin on balancing production speed with security, the advisory role of security teams, and the value of empathy.
Chris Romeo on application security beyond tools, prioritising with a data-driven approach, and starting with open source.
Chris Hodson, CSO of Cyberhaven, on threat modelling across the SDLC, communicating security value, and DevSecOps trade-offs.
Ashwin Patil on security applications of Jupyter notebooks, data analysis for threat detection, and interactive investigation workflows.
Jeevan Singh on threat modelling, integrating security into the development workflow, and scaling with limited resources.
Walter Haydock on vulnerability management, prioritisation strategies, and building a vulnerability programme that scales.
Brett Johnson on the dark web, credential-stuffing attacks, MFA bypass techniques, and why humans are the weakest link.
Emily Zakkak, cybersecurity specialist at Senowit, on defending against social engineering, phishing, and MFA best practices.
Karan Dwivedi on blue-team operations, partnering with red teams, and preserving forensic data accuracy.
Alyssa Ahmann on GRC setup, data privacy, and why documentation and training underpin successful security programmes.
Paul Dyer on red, blue, and purple team operations, threat-landscape awareness, and open-source security with SBOMs.
Jim Bugwadia on Kubernetes governance, workload security responsibilities, and image-signing best practices with Sigstore.
Nader Zaveri on organisational security culture, planning and budgeting for security, and incident-response preparedness.
Adam Smith on data privacy governance, building personal-data inventories, and fostering a privacy-first culture.
Jimmy Mesta on Kubernetes misconfigurations, continuous security checks, and when to choose managed K8s over self-hosting.
Ray Espinoza on cloud vulnerability management, leading with empathy, and transparent communication during incidents.
Garrett Smiley on measuring security debt, context-driven risk prioritisation, and using KRIs over KPIs for security teams.
Trupti Shiralkar on organisational security culture, joint backlog reviews for security debt, and supply-chain security standards.
Charles Mendoza on setting the line of defence in cloud security, layered controls, and incident-response readiness.
Parul Khanna on information security, risk management, and bridging the gap between incident response and business priorities.
Mel Reyes on the biggest mistakes in cybersecurity, top-down security mandates, and setting up foundations for startups.
Vincent Romney, Head of Global Security Architecture at Nu Skin, on zero-trust architecture and overcoming organisational resistance.
Nat Shere on preparing for cloud data breaches, incident response planning, and lowering MTTD and MTTR.
Aseem Shrey, security engineer at Rippling, on responding to ethical hacker reports, preparing for data breaches, and building a security career.
Chris Neggel, Regional CSO at Okta, on the roadblocks teams face in cloud security and strategies to overcome them.
Ski on building a security-centric culture, improving cross-team relationships, and aligning certifications with controls.
Gary Dylina of Narvar on preparing for large-scale events, SOC2, IAM setup, and when to make a first security hire.
Gaurav Batra, founder and CEO of CyberFrat, on surprising cloud security facts and building security awareness culture.
Aseem Rastogi, Head of Cybersecurity and Compliance at Meesho, on building cybersecurity and compliance programmes from the ground up.
New episodes twice a month
Follow Scale To Zero wherever you listen, or send us the question your team is stuck on and we will put it to an expert.