エピソード

  • When Bots Go Rogue: Sysdig and the Agentic Threat Actors
    2026/07/21

    This week we follow-up on a story from last week's episode about the rise of Agentic Threat Actors (ATAs). Christina & Rory chat with Michael Clark, Senior Director of Threat Research at Sysdig about their discovery of JADEPUFFER, an ATA considered to be the first instance of agentic ransomware - an attack where a Large Language Model (LLM) is on the other end of the connection rather than a human operator. By exploiting the Langflow platform, the agent then autonomously attempted to perform automated database extortion against MySQL instances. But did it achieve its objectives?

    Leave us a message!

    Want to leave some feedback and suggestions but would prefer not to write an email? You can leave us a voicemail (90 seconds max). We will share any that are not too spicy in the following episode.

    SpeakPipe link - https://www.speakpipe.com/Cyber_Sidekicks

    Or, send us an email:

    • Christina Richmond – christina@richmondadvisorygroup.com
    • Rory Duncan – rory@richmondadvisorygroup.com

    Subscribe to our Newsletter - "Signal, not noise" Our monthly newsletter is free to subscribers! Sign-up now at Richmond Advisory Group.

    Technology we use

    • Podcast Recording Platform – Cleanfeed.com
    • Cyber Sidekicks Show Host – Podbean.com
    • Edited & mastered in GarageBand
    続きを読む 一部表示
    31 分
  • Putting Humpty Dumpty Back Together: Fenix24 On The Reality of Cyber Recovery
    2026/07/14

    In this week's episode, Christina & Rory talk with guest Heath Renfrow, co-founder of breach recovery specialist Fenix24. Warning: It's a sobering look at the "cleanup" side of cybersecurity, emphasizing that most organizations are fundamentally unprepared for the complexity of full system restoration after a major attack. From the failure of backups and the hidden cost of business interruption, the discussion concludes the need for resiliency to be the top security control in every organization.

    NEWS

    JADEPUFFER: Agentic ransomware for automated database extortion

    Startup sues Palo Alto Networks' Koi Security, saying an AI-hallucinated report falsely linked it to Chinese espionage

    Leave us a message!

    Want to leave some feedback and suggestions but would prefer not to write an email? You can leave us a voicemail (90 seconds max). We will share any that are not too spicy in the following episode.

    SpeakPipe link - https://www.speakpipe.com/Cyber_Sidekicks

    Or, send us an email:

    • Christina Richmond – christina@richmondadvisorygroup.com
    • Rory Duncan – rory@richmondadvisorygroup.com

    Subscribe to our Newsletter - "Signal, not noise" Our monthly newsletter is free to subscribers! Sign-up now at Richmond Advisory Group.

    Technology we use

    • Podcast Recording Platform – Cleanfeed.com
    • Cyber Sidekicks Show Host – Podbean.com
    • Edited & mastered in GarageBand
    続きを読む 一部表示
    36 分
  • AI-native AppSec: IBM on the Importance of Context, Agent Verification & Secure By Design
    2026/07/07

    In this week's episode, guest Jayesh Kamat, Global Competency Leader in Application Security at IBM, chats with Christina about the profound impact of AI frontier models on cybersecurity and the necessity of shifting toward an "AI-native" security posture.

    With machines now generating code at an exponential rate through agents like "IBM Bob," traditional application security (AppSec) methods are no longer sufficient. Kamat advocates for AI-native security, which integrates protection directly into the development lifecycle:

    • Secure by Design: Security requirements, such as whitelisted libraries and functions, should be defined in the specifications before any code is generated.
    • Agent Verification: AI agents should be tasked with reviewing their own code, verifying its security, and explaining their "thought process" for human oversight.
    • The Security Harness: This new approach involves using a specialized "harness" to deploy frontier models to identify vulnerabilities and map exploit paths.
    • Once a path is identified, other agents can auto-remediate the code or update firewall controls in real-time

    Ultimately, Kamat views this as a "moment under the sun" for application security, which has shifted from a neglected back-office function to a primary focus of enterprise strategy

    Leave us a message!

    Want to leave some feedback and suggestions but would prefer not to write an email? You can leave us a voicemail (90 seconds max). We will share any that are not too spicy in the following episode.

    SpeakPipe link - https://www.speakpipe.com/Cyber_Sidekicks

    Or, send us an email:

    • Christina Richmond – christina@richmondadvisorygroup.com
    • Rory Duncan – rory@richmondadvisorygroup.com

    Subscribe to our Newsletter - "Signal, not noise" Our monthly newsletter is free to subscribers! Sign-up now at Richmond Advisory Group.

    Technology we use

    • Podcast Recording Platform – Cleanfeed.com
    • Cyber Sidekicks Show Host – Podbean.com
    • Edited & mastered in GarageBand
    続きを読む 一部表示
    33 分
  • Supply Chain Security: SecurityScorecard On Why Traditional Risk Management Is Failing
    2026/06/30

    In this week's show, Brandon Dobrec, VP of Product at SecurityScorecard, chats with Christina & Rory about the escalating challenges of supply chain security and why traditional risk management is failing in the face of modern complexity.

    NEWS

    SailPoint to Acquire Entro in Reported $200 Million Deal

    “FortiBleed”: Sweeping Credential-Harvesting Heist Compromises 30K+ Fortinet Devices

    Leave us a message!

    Want to leave some feedback and suggestions but would prefer not to write an email? You can leave us a voicemail (90 seconds max). We will share any that are not too spicy in the following episode.

    SpeakPipe link - https://www.speakpipe.com/Cyber_Sidekicks

    Or, send us an email:

    • Christina Richmond – christina@richmondadvisorygroup.com
    • Rory Duncan – rory@richmondadvisorygroup.com

    Subscribe to our Newsletter - "Signal, not noise" Our monthly newsletter is free to subscribers! Sign-up now at Richmond Advisory Group.

    Technology we use

    • Podcast Recording Platform – Cleanfeed.com
    • Cyber Sidekicks Show Host – Podbean.com
    • Edited & mastered in GarageBand
    続きを読む 一部表示
    29 分
  • Identity & AI: A Strategic Guide for Cybersecurity Professionals
    2026/06/23

    It's another special episode this week!

    Hosts Christina Richmond and Rory Duncan examine the evolution of the identity market from a back-office IT function to a central pillar of modern business risk management. The discussion traces the shift from simple human credential management to a complex landscape dominated by non-human identities (NHIs), such as service accounts, APIs, and emerging AI agents.

    Why is this such a risk? Attackers are now much more likely to "log in" rather than "hack in," and organisations must move toward a model of accountability and zero standing privileges to secure their digital perimeters.

    Which vendors and service providers should you consider? Establish players include IBM/HashiCorp, Cisco, CrowdStrike, Palo Alto Networks, Sailpoint, Securonix, Sphere Technology Solutions and others. Newer and emerging firms include Glide Security, Token Security, Silverfort, SingulrAI and more!

    What do we recommend? The need for identity hygiene and the integration of behavioural detection to manage the exponential growth of autonomous machine identities.

    Leave us a message!

    Want to leave some feedback and suggestions but would prefer not to write an email? You can leave us a voicemail (90 seconds max). We will share any that are not too spicy in the following episode.

    SpeakPipe link - https://www.speakpipe.com/Cyber_Sidekicks

    Or, send us an email:

    • Christina Richmond – christina@richmondadvisorygroup.com
    • Rory Duncan – rory@richmondadvisorygroup.com

    Subscribe to our Newsletter - "Signal, not noise" Our monthly newsletter is free to subscribers! Sign-up now at Richmond Advisory Group.

    Technology we use

    • Podcast Recording Platform – Cleanfeed.com
    • Cyber Sidekicks Show Host – Podbean.com
    • Edited & mastered in GarageBand
    続きを読む 一部表示
    不明
  • AI & Pre-emptive Threat Hunting: who are the 'early movers' and what's next?
    2026/06/02

    This week, another in our series of Special Episodes - this one dedicated to an analysis of the state of the Threat Hunting market, the key players and the early movers in pre-emptive cybersecurity. Richmond Advisory Group's Principal Analysts Christina Richmond & Rory Duncan outline the evolution of threat hunting from reactive, through proactive, to pre-emptive, debating the use of AI agents and "machine speed" defence. The team also look at some of the more prominent early movers, including Netcraft, Bfore.ai, Nisos, DeepWatch, IBM and Sweet Security.

    Leave us a message!

    Want to leave some feedback and suggestions but would prefer not to write an email? You can leave us a voicemail (90 seconds max). We will share any that are not too spicy in the following episode.

    SpeakPipe link - https://www.speakpipe.com/Cyber_Sidekicks

    Or, send us an email:

    • Christina Richmond – christina@richmondadvisorygroup.com
    • Rory Duncan – rory@richmondadvisorygroup.com

    Subscribe to our Newsletter - "Signal, not noise" Our monthly newsletter is free to subscribers! Sign-up now at Richmond Advisory Group.

    Technology we use

    • Podcast Recording Platform – Cleanfeed.com
    • Cyber Sidekicks Show Host – Podbean.com
    • Edited & mastered in GarageBand
    続きを読む 一部表示
    35 分
  • Browser Security & Agentic Automation: with Neon Cyber's Cody Pierce
    2026/05/26

    Cody Pierce, Co-Founder & CEO of Neon Cyber chat with Rory this week about visibility, context, and the importance of decentralized security as he proposes that the browser will become the operating system for most people's daily work.

    NEWS

    Christina & Rory discuss healthcare and data confidentiality this week - outlining the alarming increase in cyber-attacks in this sector: 118 large-scale healthcare data breaches in the first 2 months of 2026 alone! What’s behind it and what can we do about it? Counter measures, strategies and tactics are debated and discussed in a wide-ranging discussion!

    Leave us a message!

    Want to leave some feedback and suggestions but would prefer not to write an email? You can leave us a voicemail (90 seconds max). We will share any that are not too spicy in the following episode.

    SpeakPipe link - https://www.speakpipe.com/Cyber_Sidekicks

    Or, send us an email:

    • Christina Richmond – christina@richmondadvisorygroup.com
    • Rory Duncan – rory@richmondadvisorygroup.com

    Subscribe to our Newsletter - "Signal, not noise" Our monthly newsletter is free to subscribers! Sign-up now at Richmond Advisory Group.

    Technology we use

    • Podcast Recording Platform – Cleanfeed.com
    • Cyber Sidekicks Show Host – Podbean.com
    • Edited & mastered in GarageBand
    続きを読む 一部表示
    40 分