エピソード

  • Cybersecurity Awesomeness Podcast - Episode 168
    2026/07/31

    In this episode of the Cybersecurity Awesomeness Podcast, host Chris Steffen delivers a comprehensive preview of the upcoming Black Hat conference, highlighting the key themes and trends dominating Hacker Summer Camp. Steffen emphasizes that Artificial Intelligence remains front and center, with enterprise leaders heavily focused on balancing agentic AI productivity gains with strict governance.

    This AI proliferation is driving a massive surge in non-human identities, creating critical challenges for Privileged Access Management (PAM) and Data Security Posture Management (DSPM). Steffen also previews discussions around LLM-driven vulnerability management, the ongoing push for passwordless account recovery, and the expanding momentum behind Post-Quantum Cryptography (PQC). Finally, he touches on infrastructure concerns, including network blind spots and hardware supply shifts. Steffen concludes with practical advice for attendees navigating the Las Vegas heat and exhibition floor, urging advance planning to maximize value from the industry's premier security event.

    続きを読む 一部表示
    10 分
  • Cybersecurity Awesomeness Podcast - Episode 167
    2026/07/24

    In this episode of the Cybersecurity Awesomeness Podcast, host Chris Steffen is joined by Alex Salazar, founder and CEO of Arcade.dev, to explore the critical intersection of Artificial Intelligence, security, and agentic workflows. As AI transitions from a passive search tool to active "agents" capable of executing real-world tasks—such as modifying code, managing workflows, or handling data—traditional security paradigms are severely tested.

    Salazar emphasizes a vital distinction: model guardrails (teaching an AI "character" and ethics) are not enough, just as raising a well-behaved child doesn't mean handing them the keys to a bank account. True security requires robust governance, delegated authority, and runtime permissions. Rather than giving autonomous agents direct, unmitigated access to systems, Salazar advocates for deterministic, runtime security layers that evaluate every requested action before execution. Ultimately, the guests agree that while agentic AI introduces novel risks, the industry will adapt through better authorization frameworks, much like previous shifts to cloud and virtualization.

    続きを読む 一部表示
    19 分
  • Cybersecurity Awesomeness Podcast - Episode 166
    2026/07/17

    In this episode of the Cybersecurity Awesomeness Podcast, host Chris Steffen tackles the growing enterprise challenge of "Token Sprawl"—an unintended consequence of rapid, unmonitored AI adoption. As organizations integrate AI agents into development, security operations, and routine tasks, many are suffering from severe "sticker shock" as unmanaged consumption of AI tokens leads to ballooning, unpredictable costs.

    Steffen draws parallels between today's token sprawl and the early, unoptimized days of cloud computing, noting that the issue isn't necessarily the pricing of tokens themselves, but the lack of governance. He explores how this creates friction between technical teams—who prioritize productivity over cost—and finance teams, who require budget predictability. The episode emphasizes that solving this requires more than just budget caps; it demands AI optimization. By selecting the right model for specific workloads—matching tasks to specialized AI strengths—and implementing stricter internal discipline, organizations can move from wasteful AI consumption to high-value, sustainable innovation.

    続きを読む 一部表示
    12 分
  • Cybersecurity Awesomeness Podcast - Episode 165
    2026/07/10

    In this episode of the Cybersecurity Awesomeness Podcast, host Chris Steffen welcomes Saqib Ahmad from Gigamon to discuss the pressing necessity of Post-Quantum Cryptography (PQC) readiness. While quantum computing may seem distant, the hosts highlight the immediate and severe threat of "Harvest Now, Decrypt Later" attacks. Adversaries are actively exfiltrating encrypted data today, betting on the future capability of quantum computers to break standard algorithms like RSA and ECC.

    The conversation emphasizes that quantum vulnerability is a unique business risk, particularly for sectors handling long-term sensitive data such as government, healthcare, and intellectual property. Saqib underscores that successful migration to quantum-safe environments begins with network visibility—organizations cannot protect what they cannot see. He advocates for a strategic roadmap centered on asset discovery, data classification, and above all, crypto-agility. By maintaining the flexibility to swap out cryptographic standards as threats evolve, organizations can better insulate themselves against the looming quantum landscape, regardless of when "Q-Day" finally arrives.

    続きを読む 一部表示
    14 分
  • Cybersecurity Awesomeness Podcast - Episode 164
    2026/07/03

    In this episode of the Cybersecurity Awesomeness Podcast, host Chris Steffen shifts to a solo format, addressing a pervasive fear dominating the industry: that Artificial Intelligence is destined to eliminate IT and cybersecurity jobs. Steffen challenges this "fear narrative," arguing that history shows technological shifts—from virtualization to cloud computing—consistently drive job growth and evolution rather than total displacement.

    Citing projections from the World Economic Forum, Steffen emphasizes that while AI will displace certain roles, it will simultaneously create significantly more new positions. He explains that AI acts as an augmentative tool, handling high-volume, menial tasks while leaving critical judgment, ethics, and triage to human professionals. Specifically, within cybersecurity, the demand for human expertise in signal-to-noise analysis, application security, and offensive validation is surging. Steffen concludes that success lies in adaptation; professionals should embrace AI as the next essential technical skill, treating it as an evolution of their toolkit rather than an existential threat to their livelihood.

    続きを読む 一部表示
    10 分
  • Cybersecurity Awesomeness Podcast - Episode 163
    2026/06/26

    In this episode of the Cybersecurity Awesomeness Podcast, host Chris Steffen and co-host Ken Buckler are joined by Simon Pamplin, CTO of Certes AI, to demystify the urgent threat of quantum computing. The conversation pivots away from the "mythical" future of quantum and focuses on the pressing reality of "Harvest Now, Decrypt Later" attacks, where adversaries exfiltrate encrypted data today with the intent to monetize it once quantum-enabled decryption becomes viable.

    Pamplin challenges the industry’s tendency to frame quantum risk solely as a network security issue, arguing instead that it is a critical business risk that carries profound legal and reputational consequences. The hosts and Pamplin explore the transition to lattice-based post-quantum cryptography (PQC) and the vital importance of robust key management. As the consensus on "Q-Day"—the point at which current encryption is rendered obsolete—accelerates toward the 2029–2030 timeframe, the episode serves as a vital call to action: prioritizing data-centric security hygiene is no longer optional for modern enterprises.

    続きを読む 一部表示
    16 分
  • Cybersecurity Awesomeness Podcast - Episode 162
    2026/06/19

    In this episode of the Cybersecurity Awesomeness Podcast, Chris Steffen and Ken Buckler explore a pressing security shift: adversaries are increasingly bypassing traditional credential theft to exploit the AI systems already embedded within corporate environments. The hosts discuss how "agentic" AI solutions often operate with overprivileged non-human identities, granting bots excessive access to data and infrastructure that far exceeds their functional requirements.

    This resurgence of "standing access" for machine accounts—a vulnerability CISOs thought they had mitigated—is being exacerbated by the rapid, near-universal adoption of AI development tools. Using real-world examples, ranging from inadvertent AI-generated discounts to the complex liability of autonomous vehicles, Chris and Ken illustrate the risks of prompt injection and data poisoning. The episode serves as a critical call to action for security teams: to treat AI agents with the same rigorous identity management and just-in-time provisioning standards historically reserved for human users before these misconfigurations lead to massive data exfiltration.

    続きを読む 一部表示
    14 分
  • Cybersecurity Awesomeness Podcast - Episode 161
    2026/06/12

    In this episode of the Cybersecurity Awesomeness Podcast, hosts Chris Steffen and Ken Buckler explore the often-misunderstood world of mainframe computing. Despite the pervasive narrative that mainframes are "antiquated" technology, the hosts argue that they remain the gold standard for availability, integrity, and resilience in high-stakes environments like banking, healthcare, and government.

    The discussion clears up common misconceptions, noting that modern mainframes are not just running legacy code like COBOL, but are fully capable of integrating with modern development tools and languages. Steffen and Buckler highlight that while the cloud offers flexibility, it lacks the sheer stability and performance consistency of the mainframe. For security professionals, the episode serves as a powerful reminder that "older" doesn't mean "insecure." In many cases, these systems provide a level of physical and logical isolation that modern, network-dependent architectures struggle to match. Ultimately, the hosts invite listeners to rethink the mainframe's role in the modern stack, proving it remains the undisputed champion of mission-critical compute.

    続きを読む 一部表示
    15 分