Forsidebilde av showet Cyber Sentries: AI Insight to Cloud Security

Cyber Sentries: AI Insight to Cloud Security

Podkast av TruStory FM

engelsk

Nyheter og politikk

Deretter 99 kr / Måned. Avslutt når som helst.

  • 20 timer lydbøker i måneden
  • Eksklusive podkaster
  • Gratis podkaster

Les mer Cyber Sentries: AI Insight to Cloud Security

Cyber Sentries explores the critical convergence of AI, cloud, and cybersecurity, diving deep into how these three pillars are actively redefining the modern Security Operations Center (SOC). As the threat landscape grows in complexity, we showcase the accelerating role of AI in defending cloud infrastructure, applications, and data. Join us as we illuminate this high-stakes intersection—a space where cutting-edge innovation meets the necessity for continuous vigilance—to transform how organizations approach resilience in a digital-first world.

Alle episoder

30 Episoder

episode People-Pleasers: Why AI Agents Go Rogue and How to Govern Them at Scale with Shreyans Mehta cover

People-Pleasers: Why AI Agents Go Rogue and How to Govern Them at Scale with Shreyans Mehta

Agent Gone Rogue: How to Build Behavioral Guardrails for Agentic AI in the Enterprise with Shreyans Mehta Host John Richards welcomes back Shreyans Mehta, CTO and co-founder of Cequence, for a return visit that couldn't be more timely. Two years ago, they were talking about securing AI at the application layer. Now enterprises are running thousands of autonomous agents around the clock, and the security perimeter has fundamentally changed. In this episode, John and Shreyans dig into the new class of risk that comes with agentic AI—and what it actually takes to govern it. When Your AI Agent Deletes the System to Delete the Email Shreyans opens with a concept that reframes the whole conversation: AI agents aren't just a productivity tool—they're autonomous actors with access to your most sensitive systems. The problem isn't that they'll go rogue on purpose. It's that they're people-pleasers. They will exhaust every available path to complete a task, which means broad access will get used in ways you never anticipated. He shares two stories that land hard. First, a research case study called Agents of Chaos, where an agent tasked with deleting a saved password—lacking email-delete permissions—resolved the problem by deleting the system instead. Second, a real customer scenario where a Claude Code-based agent spent an entire weekend trying to upgrade a legacy codebase and, when it couldn't fetch a file due to a missing SHA value, started guessing characters one by one—for hours. The fix isn't just identity and access management—it's a new layer Shreyans calls agent behavioral analytics. Start with a plain-English job description. Cequence translates that into deterministic rules: what the agent can access, what it can send, what it can never do. Every interaction is monitored against that job description in real time—not just logged, but enforced. When the email assistant starts forwarding sensitive data to an unknown address, it gets stopped, not flagged. Questions We Answer in This Episode * Why is identity management alone not enough to secure AI agents? * What is the token flattening problem, and why does it matter for enterprise security? * How do you translate a plain-English agent job description into deterministic access controls? * What does agent behavioral analytics look like in practice—and who owns it inside an organization? Key Takeaways * AI agents are already in your environment—the only question is whether you're governing them. * Every agent needs a job description that converts into deterministic rules, not just an identity token. * Monitoring must be tied to behavior, not just access logs—and it has to stop bad actions, not just detect them. * Agent sprawl demands a new security category built for non-human, 24/7 actors. If your organization is running agentic AI and nobody owns the behavioral layer yet, this episode is a good place to start. The enterprises getting it right aren't waiting for security teams to green-light every agent—they're using tools that translate intent into guardrails automatically. Give it a listen, then check out the resources below. Resources * Shreyans Mehta, Cequence: LinkedIn [https://www.linkedin.com/in/shreyans-mehta-37a529/] * Cequence AI Gateway [https://cequence.ai] * Cequence on LinkedIn [https://www.linkedin.com/company/10510476/] * CyberProof [https://www.cyberproof.com] * Learn more about Paladin Cloud [https://www.paladincloud.io] * Got a question? Ask us here! [https://coda.io/form/Ask-Cyber-Sentries-a-Question_dgpfZxN9R9-] * (00:00) - Welcome to Cyber Sentries * (01:08) - Shreyans Mehta * (01:57) - Changes Since His First Visit * (04:03) - Finding Ways to Feel More Comfortable * (11:24) - Getting a Handle on It * (16:11) - Access and Profiles * (21:55) - Transitioning to Rules * (24:24) - How Teams Use This * (26:49) - Playing Out in the Real World * (27:49) - Learning More * (29:07) - Wrap Up

6. mai 2026 - 31 min
episode Five Seconds to Fraud: Detecting AI Deepfakes Before They Strike with Ben Colman cover

Five Seconds to Fraud: Detecting AI Deepfakes Before They Strike with Ben Colman

Inside the AI Deepfake Threat What if the voice confirming your wire transfer wasn't actually your client? Ben Colman, founder and CEO of Reality Defender, joins host John Richards to unpack one of the fastest-growing attack surfaces in cybersecurity: AI-generated deepfakes. Once the exclusive domain of Hollywood studios and nation-state actors, real-time voice and video impersonation is now accessible to anyone with a laptop—and fraudsters are scaling up fast. From Specialized Hardware to Your Home Computer Ben traces the evolution from the specialized machinery required six years ago to today's world where anyone can clone a voice with less than five seconds of audio—locally, for free, using open-source models. He walks through the modern fraud landscape, from grandparent scams and bank account takeovers to an eye-opening story about fake job applicants that will make any recruiting team rethink its screening process. Reality Defender's approach is built for how organizations actually work—plugging directly into call centers, video conferencing platforms, and identity verification tools through a simple API, rather than asking teams to adopt yet another standalone product. Their probabilistic detection models scan in real time across thousands of indicators, all without storing or comparing against any biometric data. John and Ben also get into the emerging frontier of agentic AI—what happens when you need to authenticate an AI voice agent rather than a human—and how smart permission gates can define exactly what those agents are and aren't allowed to do. Questions We Answer in This Episode * How has the barrier to creating convincing deepfakes changed in the last six years? * What are the most common deepfake fraud vectors hitting businesses and consumers right now? * How does Reality Defender detect AI-generated media without storing any biometric data? * What does deepfake defense look like as agentic AI becomes mainstream? Key Takeaways * Voice cloning now requires less than five seconds of audio and runs locally on consumer hardware * Deepfake fraud spans a wide range—from grandparent scams to fake job applicants to wire transfer hijacking * Real-time detection can plug directly into tools organizations already use, with no new workflow required * Agentic AI is creating a new category of identity challenge—and the defenses are already being built The deepfake threat isn't coming—it's already here, hitting call centers, recruiting pipelines, and financial institutions every day. Whether you're a developer looking to integrate detection into your stack or a security leader trying to get ahead of the next wave, this conversation is a essential listen. Resources * Reality Defender [https://www.realitydefender.com/] * Ben Colman [https://www.realitydefender.com/team/ben-colman] * Reality Defender on LinkedIn [https://www.linkedin.com/company/reality-defender/] * Follow Reality Defender on X [https://x.com/DetectDeepfakes] * CyberProof [https://www.cyberproof.com] * Learn more about Paladin Cloud [https://www.paladincloud.io] * Got a question? Ask us here! [https://share.hsforms.com/1HUPIst8wRIOGxAoY6OnkPQ2xcs8] * (00:04) - Welcome to Cyber Sentries * (00:35) - Meet Ben Colman, Reality Defender * (01:23) - Ben’s Beginnings * (02:36) - Changing Landscape * (03:57) - What It Looks Like Today * (05:07) - Differences * (06:16) - Main Ways Fraud’s Committed * (09:21) - Way to Tackle It * (11:07) - Distinguishing the AI * (13:14) - Response Time * (14:09) - Recommended Next Steps * (15:55) - Where It’s Heading * (19:21) - How to Use as Organization * (20:52) - Developer Community * (22:23) - Audio and Video * (23:34) - Risk Assessment * (24:41) - Prevalence * (26:09) - Wrap Up

1. april 2026 - 28 min
episode Built Fast, Broken Faster: MCP & AI App Security—with GitGuardian’s Gaetan Ferry cover

Built Fast, Broken Faster: MCP & AI App Security—with GitGuardian’s Gaetan Ferry

When “Ship Fast” Meets “Secure by Design” in AI Apps AI-driven development is moving at breakneck speed—and attackers are taking advantage of the shortcuts. In this episode of Cyber Sentries: AI Insights for Cloud Security, host John Richards sits down with Gaetan Ferry, security researcher at GitGuardian, to unpack how modern AI tooling, MCP servers, and cloud platforms are reshaping the security landscape. The core problem: the same agentic workflows that boost productivity can also multiply identities, credentials, and blast radius if something goes wrong. After John and Gaetan set the stage, Gaetan walks through a real-world-style vulnerability chain involving smithery.ai, an MCP server registry/hosting platform. It’s a practical look at how “classic” web issues can still show up in brand-new AI ecosystems—and how one small weakness can cascade into bigger supply chain risk. Along the way, they explore why secret sprawl is accelerating, what attackers are hunting for, and why observability is becoming as essential for identities and tokens as it is for infrastructure. Why MCP Servers, OAuth, and Secret Sprawl Are Colliding A big theme is the tension between usability and security: teams want agents that can “do everything,” which often means broad permissions and long-lived credentials. Gaetan explains why adopting OAuth is directionally better than static API keys, but still not a silver bullet in a world where agents need delegated access and tokens inevitably “live somewhere.” John pushes on what builders can do now—especially when new frameworks (and new hype cycles) keep resetting hard-won security practices. The conversation lands on pragmatic guidance: reduce blast radius where you can, inventory identities and secrets, and invest in observability so you can respond fast when—not if—credentials leak. Note: This episode discusses breach scenarios and exploitation chains—be thoughtful about sharing internal security details and incident response specifics. Questions We Answer in This Episode * How can a simple web flaw turn into an AI supply chain attack through MCP server hosting? * Why doesn’t OAuth automatically “solve” agent security and credential risk? * What does “limiting blast radius” look like when agents need broad permissions to be useful? * How can observability help you detect and respond to secrets sprawl across AI tools? Key Takeaways * Treat MCP servers and agent integrations like critical supply chain dependencies—because they are. * Prefer short-lived, scoped credentials (OAuth when possible), but plan for token theft scenarios anyway. * Reduce blast radius with least privilege, separation of duties, and segmented agent access. * Build identity and secret observability so you can triage and remediate leaks quickly. The Bottom Line for AI Security Teams in 2026 If you’re experimenting with MCP servers or rolling out agentic workflows, this episode is a timely reminder that fundamentals still win. John and Gaetan make the case that “moving fast” doesn’t have to mean accepting unlimited credential risk—you can ship quickly while still tightening scopes, tracking identities, and watching where secrets spread. Tune in for the real-world examples and the practical mindset shift that helps teams stay productive without becoming the next supply chain headline. Links & Notes * GitGuardian [https://www.gitguardian.com/] * Connect with Gaetan on LinkedIn [https://www.linkedin.com/in/gaetan-f-a40497a4/] * State of Secrets Sprawl Report 2025 [https://www.gitguardian.com/state-of-secrets-sprawl-report-2025] * State of Secrets Sprawl Report 2026 [https://www.gitguardian.com/state-of-secrets-sprawl-report-2026] (coming later in March!) * CyberProof [https://www.cyberproof.com] * Learn more about Paladin Cloud [https://www.paladincloud.io] * Got a question? Ask us here! [https://share.hsforms.com/1HUPIst8wRIOGxAoY6OnkPQ2xcs8] * (00:04) - Welcome to Cyber Sentries * (01:07) - Meet Gaetan Ferry * (02:19) - Attacks * (03:17) - Vulnerabilities * (07:38) - One-Off or Widespread? * (10:20) - Recommendations to Avoid * (14:19) - Exploiting * (16:50) - Resolving * (23:13) - Path Forward * (30:53) - Impact * (34:48) - Year of Supply Chain Attacks * (35:51) - Wrap Up

4. mars 2026 - 38 min
episode Identity in the AI Era: Managing Enterprise Risk in the Age of AI with Jasson Casey cover

Identity in the AI Era: Managing Enterprise Risk in the Age of AI with Jasson Casey

The Evolution of Identity Security in the Age of AI In this episode of Cyber Sentries, John Richards sits down with Jasson Casey, CEO and co-founder of Beyond Identity, to explore the intersection of identity security, AI, and enterprise risk management. As organizations rapidly adopt AI tools and agents, the fundamental challenges of identity security are evolving—requiring both new approaches and a return to core principles. Identity: The Foundation of Modern Security Jasson explains how identity has become the root cause of most security incidents, with identity-based failures accounting for 80% of security tickets. The conversation explores how AI is transforming every role in modern organizations, while highlighting the security implications of this rapid adoption. Key Takeaways: * Identity security is fundamental to managing AI risk in enterprises * Traditional security concepts still apply but require new implementation approaches * Organizations need to track data flow and permissions across AI systems Looking Ahead As AI adoption accelerates, organizations must balance innovation with security. Through proper identity management and understanding of data flow, enterprises can prevent most security incidents while embracing the transformative potential of AI technologies. Links & Notes * Beyond Identity [https://www.beyondidentity.com] * AI Solutions [https://www.beyondidentity.ai] * Connect with Jasson Casey on LinkedIn [https://www.linkedin.com/in/jassoncasey] * Connect with Jasson Casey on X [https://twitter.com/jassoncasey] * CyberProof [https://www.cyberproof.com] * Learn more about Paladin Cloud [https://www.paladincloud.io] * Got a question? Ask us here! [https://share.hsforms.com/1HUPIst8wRIOGxAoY6OnkPQ2xcs8] * (00:04) - Welcome to Cyber Sentries * (01:02) - Meet Jasson Casey * (02:51) - Regrets? * (08:19) - Friction Point * (10:28) - Identity * (17:08) - Adoption * (22:17) - The Hallmark of Network Security * (28:10) - Paint Analogy * (31:17) - Threats * (34:08) - Visualization Tool * (35:13) - Their Work in This Space * (37:05) - Learning More * (37:36) - Wrap Up

4. feb. 2026 - 39 min
episode Security Data Pipelines: How to Cut SIEM Costs and Noise with Dina Kamal cover

Security Data Pipelines: How to Cut SIEM Costs and Noise with Dina Kamal

SIEM Speed Without the Sprawl—DataBahn’s Take on Security Data Pipelines In this Cyber Sentries: AI Insights for Cloud Security episode, host John Richards sits down with Dina Kamal, Chief Revenue Officer at DataBahn, to tackle a familiar cloud security problem: teams can’t get the right data into the SIEM fast enough, and when they do, costs and noise spike. After the introductions, John and Dina dig into why data integration and parsing often consume most of the timeline in SIEM projects—and how a security data pipeline layer can compress onboarding from months to weeks. They also explore what “doing more with less” looks like in a modern SOC: filtering and routing data based on detection value, preserving what’s needed for compliance, and keeping flexibility for SIEM migrations. Dina’s bigger point is that AI only becomes truly useful when it’s paired with domain expertise and real operational context—otherwise it’s easy to end up with impressive-looking outputs that don’t hold up under investigation pressure. Questions We Answer in This Episode * Why do SIEM projects stall on data onboarding, and what speeds it up? * How can you cut SIEM ingestion costs without weakening detections? * What does owning your security data change during SIEM migrations? * Where does AI help most in SOC workflows, and where do guardrails matter? Key Takeaways * Data pipelines remove SIEM “plumbing” bottlenecks by automating collection, parsing, and transformation. * Cost reduction works best when you filter by security value, not just by volume. * Decoupling data collection from the SIEM reduces lock-in and simplifies vendor changes. * AI is strongest when guided by security context and experienced practitioners. The throughline is practical: better detections and faster investigations start upstream with intentional data handling. By treating the SIEM as a high-value analytics destination instead of a dumping ground, teams can regain capacity, reduce noise, and keep options open as tools and vendors change. And when AI is applied to the right parts of the workflow—with clear constraints and real-world context—it can accelerate outcomes without compromising trust. Links & Notes * DataBahn [https://www.databahn.ai/] * Connect with Dina Kamal on LinkedIn [https://www.linkedin.com/in/dina-kamal-a77277/] * Learn more about Cyberproof [https://www.cyberproof.com/] * Got a question? Ask us here [https://coda.io/form/Ask-Cyber-Sentries-a-Question_dgpfZxN9R9-]! * (00:04) - Welcome to Cyber Sentries * (01:02) - Meet Dina Kamal * (03:14) - Data Pipeline Management * (05:55) - The Target * (07:32) - Changing Vendors * (08:34) - No Storage * (09:31) - Why People Need It * (13:09) - Ahead of the Curve * (19:54) - Capturing the Data * (23:02) - Useful Data * (26:02) - More with Less * (27:03) - Visibility * (29:40) - When to Start * (31:04) - Wrap Up

14. jan. 2026 - 33 min
Enkelt å finne frem nye favoritter og lett å navigere seg gjennom innholdet i appen
Enkelt å finne frem nye favoritter og lett å navigere seg gjennom innholdet i appen
Liker at det er både Podcaster (godt utvalg) og lydbøker i samme app, pluss at man kan holde Podcaster og lydbøker atskilt i biblioteket.
Bra app. Oversiktlig og ryddig. MYE bra innhold⭐️⭐️⭐️

Velg abonnementet ditt

Mest populær

Tidsbegrenset tilbud

Premium

20 timer lydbøker

  • Eksklusive podkaster

  • Ingen annonser i Podimo shows

  • Avslutt når som helst

2 Måneder for 19 kr
Deretter 99 kr / Måned

Kom i gang

Premium Plus

100 timer lydbøker

  • Eksklusive podkaster

  • Ingen annonser i Podimo shows

  • Avslutt når som helst

Prøv gratis i 14 dager
Deretter 169 kr / måned

Prøv gratis

Bare på Podimo

Populære lydbøker

Ofte stilte spørsmål

Flere spørsmål og svar
Kom i gang

2 Måneder for 19 kr. Deretter 99 kr / Måned. Avslutt når som helst.