エピソード

  • Security Begins at Procurement with Jessie Schofer
    2026/07/22

    Bringing new software or SaaS into your organization is a security risk - how do you assess it? Richard chats with Jessie Schofer about her experiences in HR software acquisition, which led to the creation of secureless.ai. Jessie tells the story of evaluating various SaaS and other software products and realizing that, while the website says they are compliant with GDPR and/or SOC 2, are they really? This leads to a conversation about the product procurement process and about actually understanding the security risk you take on every time a new product is added to your organization. At what point does security block an acquisition? And after being acquired, how often do you reassess? Supply chain security hygiene starts at procurement - are you part of the evaluation?

    Links

    • Secureless.ai
    • GDPR Enforcement Tracker

    Recorded June 23, 2026

    続きを読む 一部表示
    37 分
  • Finding Security Vulnerabilities using AI with Sami Laiho
    2026/07/15

    How are large language models changing the way security vulnerabilities are found? Richard chats with Sami Laiho about the rapidly changing landscape in security exploits. Certain LLM models like Anthropic's Mythos and Microsoft MDASH are optimized to find software vulnerabilities - and potentially fix them. And so there is an arms race of sorts, repairing old vulnerabilities before LLMs in the hands of black hats can exploit them. But what about everyone else? Sami talks about getting LLMs working for your organization to test for potential security risks and assess the impact of new vulnerabilities as they appear.

    Links

    • Palo Alto Networks
    • Claude Mythos
    • Microsoft MDASH
    • Zero Day Clock
    • Security Update Guide

    Recorded June 19, 2026

    続きを読む 一部表示
    38 分
  • Implementing Azure Policies with Barbara Forbes
    2026/07/08

    How can Azure Policies help you? While at Techorama in Belgium, Richard sat down with Barbara Forbes to discuss how Azure Policies have evolved and the techniques sysadmins are using to improve security, cost controls, efficiency, and more. Barbara talks about how the default policies are designed to get folks started in Azure quickly - not necessarily optimally. And there are plenty of policy templates out there, but before you implement them, it's worthwhile to review each policy and ask the question "why?" Keeping good documentation on policies makes it easier to know intent, especially when it comes to changing them - and you'll need to change them! There are a number of ways to apply policies, but in the end, they are just more Infrastructure-as-Code, and so easily repeatable. Azure Policies are there to help you provide freedom with guardrails if you implement them carefully!

    Links

    • Azure Policy
    • Microsoft Cloud Security Benchmark
    • Azure Management Groups
    • Azure Bicep
    • Terraform on Azure

    Recorded May 12, 2026

    続きを読む 一部表示
    36 分
  • AI-Accelerated Supply Chain Attacks with Mackenzie Jackson
    2026/07/01

    How are supply-chain attacks evolving? Richard chats with Mackenzie Jackson about his work helping companies protect their software supply chains from malware attacks. Mackenzie discusses the vulnerability of developers to attacks, since their accounts are often highly privileged and invariably contain access to exploitable secrets. The conversation digs into the challenges of securing various code distribution mechanisms like npm and how you can protect your organization - starting with, don't install packages as soon as they are released! There are effective tools for detecting malware in code, but they take time. Waiting 48 hours can eliminate a lot of risk!

    Links

    • Aikido Software
    • Trivy
    • Claude Mythos
    • OpenClaw
    • Shai-Hulud Guidance
    • ClawHub
    • Open Source Malware
    • Windows Update Management

    Recorded June 15, 2026

    続きを読む 一部表示
    37 分
  • Securing Developers with Tanya Janca
    2026/06/24

    How can sysadmins help software developers work securely and make more secure applications? While at NDC in Toronto, Richard sat down with Tanya Janca of SheCodesPurple to discuss what admins can do to help address the security challenges software developers face. Tanya talks about securing development environment and pipelines - developers routinely work from high privilege accounts because their tools require it, and as a result, have become the targets of black hats to get access to accounts, keys, and other exploitable resources. There are plenty of tools available to help work through the issues, including the latest AI-powered tools. LLMs can also help generate more secure code in the first place, and Tanya has created a set of prompts you can use to create more secure software. The threat landscape is shifting with these tools, and we need to act quickly to resist the new attacks!

    Links

    • SheHacksPurple
    • Canadian Guidance on Resisting Supply Chain Attacks
    • OWASP Top 10 Security Risks for 2025
    • Prompts for Generating Secure Code

    Recorded May 8, 2026

    続きを読む 一部表示
    34 分
  • How Machine Learning Fails with Megan Robertson
    2026/06/10

    What can go wrong with machine learning? While at NDC in Toronto, Richard chatted with Megan Robertson about her experience with machine learning projects, often using retail datasets, and where they can go wrong. Megan talks about getting clear expectations and metrics for projects, so you know when you succeed, but then digs into the specifics of problems in machine learning, such as overfitting on test data. Your results are only as good as the data you put in, so a lot of focus goes into building good sets, carefully developing the model with those sets, and using techniques like cross-validation to ensure the model is behaving appropriately. There's a lot that can go wrong, but the results with an effective model can be very powerful - it is worth the effort!

    Links

    • Cross Validate Model
    • Megan's Website

    Recorded May 7, 2026

    続きを読む 一部表示
    37 分
  • Data API Builder and SQL MCP with Jerry Nixon
    2026/06/03

    How do you intelligently surface access to your database? While at NDC Toronto, Richard spoke with Jerry Nixon about Data API Builder, Microsoft's tool that enables data professionals using Microsoft databases, including SQL Server, Postgres, CosmosDB, and MySQL, to provide an API layer with security, schema extraction, and governance policies. You can expose the API as a REST interface, a GraphQL interface, and an MCP server! This is a powerful tool for providing controlled access to data while still allowing for ad-hoc access. The potential is huge - you need to check it out!

    Links

    • Data API Builder
    • GraphQL

    Recorded May 7, 2026

    続きを読む 一部表示
    37 分