エピソード

  • Start Here: What Is AI Security Multipliers?
    2026/09/22

    Send us Fan Mail

    New to AI Security Multipliers? Start here.

    In this short introduction, Steve explains what the podcast is about, why he created it, and the perspective he brings to the rapidly changing worlds of AI, cybersecurity and governance.

    No hype. No fearmongering. Just practical conversations about what matters, what’s changing, and how we can use AI to multiply what people and organizations are capable of achieving.

    続きを読む 一部表示
    3 分
  • AI Is Coming for Cybersecurity
    2026/09/22

    Send us Fan Mail

    AI Is Coming for Cybersecurity

    We hear plenty about how attackers are going to use AI. But what about the defenders?

    In this episode of AI Security Multipliers, Steve looks at the other side of the AI security story: how AI can help cybersecurity teams work faster, prioritize better, investigate incidents, improve detection, strengthen identity security, and deal with the enormous amount of information modern security environments generate.

    From SOC operations and threat hunting to vulnerability management, incident response, phishing defense, and security awareness, the opportunity isn't about replacing security professionals. It's about giving them more time to think and multiplying what they can accomplish.

    We also tackle the harder question: how much should AI actually be allowed to do on its own?

    And in this week's Multiplier, there's a simple place to start: ask your security team what repetitive task they wish they didn't have to do.

    AI is coming for cybersecurity.

    Good. Let's use it.

    続きを読む 一部表示
    22 分
  • AI Governance Without Killing Innovation
    2026/09/19

    Send us Fan Mail

    AI governance is supposed to help organizations use AI safely. But what happens when the governance itself becomes the reason people go around it?

    In this episode of AI Security Multipliers, Steve explores how organizations can govern AI without becoming the Department of No.

    As AI adoption accelerates, many organizations are responding with policies, committees, risk assessments, approval processes and new governance structures. Those controls can be important, but treating every AI use case as though it carries the same level of risk can quickly create bureaucracy rather than meaningful governance.

    A developer using an approved AI tool to explain non-sensitive code isn't the same risk as an autonomous agent capable of changing production systems or approving financial transactions.

    So why would we govern them the same way?

    We look at how risk-tiered governance can create a faster path for low-risk AI use while applying greater scrutiny where the consequences actually matter. We also explore why organizations should build on existing security, privacy, data, procurement and technology governance rather than creating an entirely separate AI bureaucracy.

    Because good governance shouldn't make safe AI harder to use.

    It should make the safe path the easiest path.

    In this episode:
    • Why AI governance can unintentionally create Shadow AI
    • Why organizations should govern the risk, not the buzzword
    • How risk tiers can prevent every AI use case becoming a major approval exercise
    • Why governance should start with the business use case
    • How to create a fast path to yes
    • Why approved AI platforms and safe experimentation environments matter
    • How existing security, privacy, data and technology governance can support AI
    • Why AI policies need to be understandable enough that employees actually read them
    • How cybersecurity can become an accelerator rather than a gatekeeper
    • Why AI governance needs to evolve as capabilities change
    • How to measure whether your governance model is actually working
    • The role of executives and boards in AI oversight
    • Practical steps for improving your AI governance process now

    The Multiplier:
    Take your organization's AI governance process and actually try to use it.

    Choose a simple, low-risk AI use case and follow the process from beginning to end.

    How many forms?
    How many approvals?
    How many meetings?
    How many days?

    And most importantly:

    At any point would a reasonable employee decide it was easier just to go around you?

    If the answer is yes, don't immediately blame the employee.

    Fix the path.

    Because one of the best ways to reduce Shadow AI isn't another monitoring tool. It's making approved AI easier to use than unapproved AI.

    Good governance doesn't just control risk. It creates a faster path to yes.

    Govern the risk, not the buzzword.


    続きを読む 一部表示
    23 分
  • AI Agents Change the Security Model
    2026/09/19

    Send us Fan Mail

    AI is moving from answering questions to taking actions. And that changes the security model.

    In this episode of AI Security Multipliers, Steve explores what happens when AI evolves from an assistant that recommends what to do into an agent that can actually do it.

    An AI agent may read email, access enterprise data, update records, call APIs, initiate workflows, modify permissions or interact with other systems. At that point, the security question is no longer simply, "What can the AI see?"

    It's "What is the AI allowed to do?"

    We look at why agent identity and authorization are becoming critical security boundaries, how delegated authority changes risk, and why familiar concepts such as least privilege, separation of duties, human approval and auditability become even more important when the actor isn't human.

    Because every time you give an agent another tool, you're not just adding a feature. You're adding authority.

    In this episode:
    • The difference between AI that advises, assists and acts
    • Why autonomy is really about delegated authority
    • Why every AI agent needs an identity
    • Whose permissions an agent should use
    • The difference between capability and authority
    • Why agents could recreate the service-account problem at enormous scale
    • How tools and APIs increase an agent's authority
    • What happens when an autonomous agent gets something wrong
    • Why prompt injection becomes more serious when AI can take actions
    • When "human in the loop" actually provides meaningful oversight
    • Why logging and auditability matter for autonomous systems
    • How separation of duties applies when the actor isn't human
    • Why least privilege and just-in-time access matter for AI agents
    • Practical steps for discovering and governing agents already inside the enterprise

    The Multiplier:
    Choose one AI agent your organization is using, building or seriously considering and ask five questions:

    What identity does it use?

    What data can it access?

    What actions can it take?

    Who can authorize those actions?

    And how do we stop it?

    If you can answer all five clearly, you've got the beginnings of a security model.

    If you can't, the agent may already have more autonomy than your governance does.

    Govern the risk, not the buzzword.


    続きを読む 一部表示
    24 分
  • Your Data Is the Real AI Security Boundary
    2026/09/18

    Send us Fan Mail

    AI may not change what your employees are allowed to access. But it can dramatically change what they can find.

    In this episode of AI Security Multipliers, Steve explores why enterprise AI is changing the traditional security boundary and making data, identity and access governance more important than ever.

    For years, organizations accumulated SharePoint sites, file shares, security groups, inherited permissions and old documents. Much of that information was technically accessible but difficult to discover. AI changes the equation by allowing employees to search, summarize and connect information across enormous amounts of enterprise data in seconds.

    The permission may not have changed. The value of the permission has.

    We look at why permission isn't necessarily the same as intent, how AI exposes years of accumulated access decisions, why identity effectively becomes part of every AI query, and why data classification and ownership suddenly matter a great deal more.

    We also explore RAG, oversharing, public AI services, DLP, and why simply locking everything down isn't the answer.

    In this episode:
    • Why AI changes data discovery, not just data access
    • Why permission isn't necessarily the same as intent
    • How AI exposes old SharePoint and access-control problems
    • Why identity becomes part of the AI security boundary
    • Why data classification matters again
    • The importance of clear data ownership
    • How AI changes the risk of overshared information
    • Why RAG doesn't automatically make enterprise data safe
    • The risks of employees putting sensitive information into public AI services
    • Where DLP helps, and where it doesn't
    • Why locking everything down can undermine the value of AI
    • Practical steps CISOs can take now

    The Multiplier:
    Choose one AI-enabled enterprise application and one ordinary employee account. Ask a few normal business questions about information that employee probably doesn't need for their day-to-day job.

    Don't bypass controls. Don't jailbreak the model. Just use the AI normally.

    If it finds something surprising, don't immediately blame the AI.

    Ask a better question:

    Why could this employee access the data in the first place?

    Because AI isn't just changing the threat landscape. It's changing the value of permissions you already granted.

    Govern the risk, not the buzzword.


    続きを読む 一部表示
    25 分