エピソード

  • Resilient Cyber w/ Kenny Scott - Following the Future of FedRAMP
    2025/10/06

    In this episode of Resilient Cyber, I sit down with Founder & CEO of Paramify, Kenny Scott, to unpack the evolution of the FedRAMP program, FedRAMP 20x, and discuss what the public sector cloud compliance looks like moving into the future.

    Kenny and I dove into a lot of topics, including:

    • What FedRAMP is and why it matters
    • What FedRAMP 20x is and what longstanding challenges associated with FedRAMP and public sector cloud and compliance it is addressing
    • The various aspects of FedRAMP 20x, including its phased rollout
    • Changes via FedRAMP 20x when it comes to Key Security Indicators (KSI), and how they differ from “controls”
    • FedRAMP’s modern vulnerability management approach and how it changes from the way vulnerability was historically handled under FedRAMP
    • The importance of automated assessments, machine-readable artifacts, real Continuous Monitoring (ConMon), and more for practical GRC Engineering
    • The role of GRC platforms when it comes to modernizing GRC
    • What are the implications of FedRAMP 20x for other public sector compliance programs, such as DoD’s SWFT, SRG, and RMF


    • Subscribe now
    続きを読む 一部表示
    42 分
  • Resilient Cyber w/ Snehal Antani - AI and Autonomous Pen Testing
    2025/10/03

    In this episode of Resilient Cyber, I sit down with repeat guest Snehal Antani, who serves as the Co-Founder & CEO of Autonomous Pen Testing leader Horizon3.ai.

    We will discuss the latest developments in AI and Autonomous Pen Testing, as well as the tremendous growth and success of Horizon3.ai, as Snehal balances technical topics with business-centric hard won wisdom of growing an industry leading organization.

    続きを読む 一部表示
    39 分
  • Resilient Cyber w/ Alon Jackson - Enterprise Agentic Security
    2025/09/26

    In this episode of Resilient Cyber, I sit down with Astrix Security Co-Founder and CEO Alon Jackson to discuss the need for secure agentic adoption across the enterprise.

    This includes Astrix’s approach, which involves enabling enterprises to discover, secure, and deploy AI agents responsibly at scale.

    続きを読む 一部表示
    19 分
  • Resilient Cyber w/ Emre Tinaztepe - Forensics at the Frontline
    2025/09/24

    In this episode of Resilient Cyber, I sit down with Binalyze Founder/CEO Emre Tinaztepe.

    We will discuss how AI and automation are impacting the future of the SOC and the role that forensics-level data can play in incident response and recovery, as well as proactive threat hunting.

    続きを読む 一部表示
    21 分
  • Resilient Cyber w/ Andy Ellis - Effective Cyber Marketing, Sales & Leadership
    2025/09/15

    In this episode, I sit down with Andy Ellis, a longtime industry security leader who has turned investor, advisor, and mentor. We will discuss how security vendors can build effective marketing and sales teams and Andy's experience identifying and investing in industry-leading security startups.

    Don't miss this chance to hear from an industry legend who has worn multiple hats and excelled as an operating, investor, and overall security leader.

    続きを読む 一部表示
    45 分
  • Resilient Cyber w/ Cory Michal (AppOmni) - Unpacking the SaaS Security Supply Chain Landscape
    2025/09/10

    - One of the biggest SaaS security incidents recently of course is the Salesloft Drive/Salesforce incident, which impacted hundreds of organizations and involved compromised OAuth tokens. Can you tell us a bit about the incident and the fallout?

    - In an AppOmni blog on the incident, you all discuss attackers taking advantage of persistent OAuth access, over-permissive access, limited monitoring, and unsecured secrets. Why do these problems continue to plague organizations despite incidents like this?

    This is part of a broader trend of increased SaaS supply chain attacks. What makes these attacks so enticing for malicious actors and challenging for organizations to prevent entirely?

    You recently published your State of SaaS Security Report, which projects SaaS to grow 20% YoY between 2025 and 2032. This is despite 75% of organizations reporting a SaaS security incident in the past year. Why do you think we're seeing continued growth in adoption but still lagging in SaaS security to accompany the adoption?

    The report discusses the rise of NHIs and GenAI and how this will exacerbate problems around SaaS Access and incidents. Can you unpack that for us?

    I was shocked to see the report find that just 13% of organizations use SSPM tooling despite SaaS's widespread adoption. When you talk to enterprises, for example, nearly everyone is doing some CSPM activity for IaaS. Why are so many neglecting hygiene and posture for their SaaS footprint?

    続きを読む 一部表示
    25 分
  • Resilient Cyber w/ Rob T. Lee - Navigating AI's Impact on Cyber & the Workforce
    2025/09/06

    In this episode of Resilient Cyber, I sit down with the SANS Institute's Chief of Research (COR) & Chief AI Officer (CAIO), Rob T. Lee to discuss AI's impact on cybersecurity and the workforce.

    We will discuss SANS Critical AI Security Guidelines, the opportunities and obstacles AI presents for cybersecurity, and how practitioners should navigate AI's impact on the workforce.

    続きを読む 一部表示
    39 分
  • Resilient Cyber w/ Gianna & Maria - The State of Cybersecurity Marketing
    2025/08/27

    In this episode of Resilient Cyber, I sit down with Gianna Whitver and Maria Velasquez to chat about the state of marketing in the cybersecurity industry, as well as their popular event "Cyber Marketing Con"

    In this episode, we discussed:

    • The background of the CyberMarketingCon and what led Gianna and Maria to co-found the event and community
    • Where marketers typically fall short and what can be done to drive more effective marketing and selling to security practitioners and leaders
    • What practitioners can learn their marketing peers when it comes to communication, empathy, story telling, and building relationships
    • The importance of marketing, brand and broader GTM for security vendors to stand out from their competitors
    • What to keep an eye out for at the upcoming CyberMarketingCon in December in Austin Texas
    続きを読む 一部表示
    18 分