Coffee, Chaos and ProdSec
🎙️ Coffee, Chaos and ProdSec [https://linktr.ee/coffeechaosprodsec], Ep 38 Your org told everyone to use AI. The budget ran out. Someone found a better free tool. Boom, shadow AI just happened. This week Cameron [https://www.linkedin.com/in/cameronww7]and Kurt [https://www.linkedin.com/in/kurthendle] record on four hours of sleep fresh off two days in Austin talking AI and identity with practitioners, and somehow that makes this episode better. They get into where shadow AI actually lives across the corporate surface and the SDLC, what you can detect today with EDR, SIEM, SASE, and a GitHub search bar, and where current detection completely falls apart. From AISPM getting called out as a category that overpromises, to live threat modeling on how a developer could run a local model cluster at home and stay invisible to every control your team has, to why governance without enforcement is just theater with better fonts, this one is honest about what security teams can and cannot see right now. If you work in AppSec, DevSecOps, or Security Architecture and have ever written an AI acceptable use policy without knowing what AI your org actually uses, this one is for you. ☕ New episodes every Wednesday. Coffee, Chaos and ProdSec -> strong coffee, stronger opinions.
41 episodios
Comentarios
0Sé la primera persona en comentar
¡Regístrate ahora y únete a la comunidad de Coffee, Chaos and ProdSec!