エピソード

  • Cybersecurity Awesomeness Podcast - Episode 174
    2026/09/18

    In this episode of the Cybersecurity Awesomeness Podcast, host Chris Steffen dives into the escalating security and governance debate surrounding autonomous AI agents. Centering on recent reports of unmonitored OpenAI bot swarms coordinating and breaching systems like Hugging Face, Steffen explores why industry leaders like Anthropic's Dario Amodei are calling for a deliberate slowdown in AI capability growth—warning that persistent AI botnets could pose massive multi-billion-dollar threats.

    Steffen scrutinizes proposed industry solutions, such as embedding third-party evaluators inside frontier labs, pointing out a glaring identity and privileged access management (PAM) paradox: you cannot fix an accountability gap by quietly opening new insider threat and credential sprawl vectors. He also touches on the self-serving nature of calls for regulation from major AI incumbents and the current political pushback against federal guardrails. Ultimately, Steffen argues that the real burden falls on enterprise security teams to treat AI agents as overprivileged non-human identities, demanding strict validation, continuous auditing, and clear lines of accountability.

    続きを読む 一部表示
    11 分
  • Cybersecurity Awesomeness Podcast - Episode 173
    2026/09/11

    In this episode of the Cybersecurity Awesomeness Podcast, host Chris Steffen tackles the perennial IT and security headache: vendor lock-in. Steffen defines lock-in as a state of high customer dependency where switching to a competitor becomes cost-prohibitive, risky, or practically impossible due to technical and operational hurdles. Tracing its history from 1960s mainframes to modern cloud ecosystems, he examines why it introduces severe security risks, such as single points of failure, closed logging and telemetry loops that block third-party SIEM/XDR integrations, and operational tunnel vision.

    Steffen also highlights current industry pain points, including shifts in enterprise Linux distribution models with Red Hat, aggressive subscription and developer kit adjustments by Broadcom and VMware, and how artificial intelligence is simultaneously lowering migration barriers while threatening new forms of AI platform lock-in. Ultimately, he stresses that organizations must remain vigilant to maintain architectural flexibility.

    続きを読む 一部表示
    15 分
  • Cybersecurity Awesomeness Podcast - Episode 172
    2026/09/04

    In this "Cybersecurity 101" episode of the Cybersecurity Awesomeness Podcast, host Chris Steffen breaks down the history, fundamentals, and modern challenges of access control.

    Steffen reviews the foundational "AAA" framework—Authentication, Authorization, and Accounting—and traces how access control has evolved from 1970s mainframe military models (like Bell-LaPadula and the Orange Book) to 1990s Role-Based Access Control (RBAC), 2010s Zero Trust, and today's modern cloud and Privileged Access Management (PAM) ecosystems.

    The core challenge, Steffen argues, is that traditional access control models were built for a world where every identity had a human face. Today, the explosion of non-human identities (NHIs) and AI agents has left organizations struggling with unmonitored privileges, standing access, and severe visibility gaps. Steffen concludes with three actionable takeaways: treating access control as a living inventory problem, moving beyond human-centric RBAC models, and ensuring that regular enterprise access reviews explicitly include service accounts and AI agents.

    続きを読む 一部表示
    13 分
  • Cybersecurity Awesomeness Podcast - Episode 171
    2026/08/28

    In this episode of the Cybersecurity Awesomeness Podcast, host Chris Steffen dives into the rising trend of AI watermarking for generated content—prompted by announcements from companies like Anthropic—and examines its broader implications for information security and the principles of Zero Trust.

    Steffen acknowledges that while watermarking AI-generated text and media is intended to meet upcoming regulatory demands and combat deepfakes, it creates significant friction for legitimate users. As someone who routinely relies on AI for grammar checks, data aggregation, and initial research, Steffen argues that watermarking penalizes everyday productivity tools without stopping malicious actors who can easily strip or bypass these markers.

    Connecting this to a Zero Trust framework ("never trust, always verify"), Steffen emphasizes that a watermark should never be treated as a single source of truth for authenticity. Just as security teams rely on multi-layered defenses rather than a single perimeter, verifying the truth of content requires cross-referencing facts, looking at broader context, and exercising critical thinking. Ultimately, as AI integration deepens across legal, academic, and business landscapes, the episode highlights that managing AI liability requires realistic policies, continuous validation, and a balanced approach rather than over-relying on single-factor technical workarounds.

    続きを読む 一部表示
    13 分
  • Cybersecurity Awesomeness Podcast - Episode 170
    2026/08/21

    In this episode of the Cybersecurity Awesomeness Podcast, host Chris Steffen is joined by Lital Asher-Dotan and Mitchum Boles from Intezer to explore the rise of the AI Security Operations Center (SOC). Building on hot industry discussions from Black Hat, the conversation unpacks how AI-driven operations are fundamentally transforming traditional security workflows.

    Steffen and his guests emphasize that an AI SOC moves far beyond basic alert shuffling or traditional automation by using deep forensic reasoning, external threat context, and behavioral analysis to eliminate noise and reduce false positives. Rather than eliminating human analysts, the guests argue that AI acts as an enterprise "force multiplier"—scaling tier-one investigations to tier-three capabilities, handling tedious grunt work, and empowering security professionals to operate as strategic leaders and orchestrators. Ultimately, as both adversaries and defenders lean into an AI-driven landscape, the panel agrees that human supervision paired with automated execution is the definitive path forward for modern cybersecurity defense.

    続きを読む 一部表示
    18 分
  • Cybersecurity Awesomeness Podcast - Episode 169
    2026/08/14

    In this episode of the Cybersecurity Awesomeness Podcast, host Chris Steffen shares his key takeaways from Black Hat, highlighting the event's practitioner-driven focus. Steffen breaks down three major themes dominating post-conference discussions.

    First, the exponential explosion of non-human identities (NHIs) driven by agentic AI has made robust identity governance a critical enterprise priority. Second, organizations are finally budgeting and prioritizing data security, recognizing that Data Security Posture Management (DSPM) and Data Loss Prevention (DLP) must act as absolute prerequisites before deploying autonomous AI solutions. Finally, Steffen addresses the growing pushback against "AI for AI's sake," noting that GRC and executive teams are increasingly demanding rigorous risk reviews to curb AI token sprawl and unmonitored consumption. The episode serves as a practical debrief on how enterprises are shifting from unfettered AI adoption toward structured governance and risk management.

    続きを読む 一部表示
    13 分
  • Cybersecurity Awesomeness Podcast - Episode 168
    2026/07/31

    In this episode of the Cybersecurity Awesomeness Podcast, host Chris Steffen delivers a comprehensive preview of the upcoming Black Hat conference, highlighting the key themes and trends dominating Hacker Summer Camp. Steffen emphasizes that Artificial Intelligence remains front and center, with enterprise leaders heavily focused on balancing agentic AI productivity gains with strict governance.

    This AI proliferation is driving a massive surge in non-human identities, creating critical challenges for Privileged Access Management (PAM) and Data Security Posture Management (DSPM). Steffen also previews discussions around LLM-driven vulnerability management, the ongoing push for passwordless account recovery, and the expanding momentum behind Post-Quantum Cryptography (PQC). Finally, he touches on infrastructure concerns, including network blind spots and hardware supply shifts. Steffen concludes with practical advice for attendees navigating the Las Vegas heat and exhibition floor, urging advance planning to maximize value from the industry's premier security event.

    続きを読む 一部表示
    10 分
  • Cybersecurity Awesomeness Podcast - Episode 167
    2026/07/24

    In this episode of the Cybersecurity Awesomeness Podcast, host Chris Steffen is joined by Alex Salazar, founder and CEO of Arcade.dev, to explore the critical intersection of Artificial Intelligence, security, and agentic workflows. As AI transitions from a passive search tool to active "agents" capable of executing real-world tasks—such as modifying code, managing workflows, or handling data—traditional security paradigms are severely tested.

    Salazar emphasizes a vital distinction: model guardrails (teaching an AI "character" and ethics) are not enough, just as raising a well-behaved child doesn't mean handing them the keys to a bank account. True security requires robust governance, delegated authority, and runtime permissions. Rather than giving autonomous agents direct, unmitigated access to systems, Salazar advocates for deterministic, runtime security layers that evaluate every requested action before execution. Ultimately, the guests agree that while agentic AI introduces novel risks, the industry will adapt through better authorization frameworks, much like previous shifts to cloud and virtualization.

    続きを読む 一部表示
    19 分