Enterprise AI Defenders

Identity Is the Perimeter in AI-era Fraud with Lockton Global CISO TJ Mann

25 min · 4. mar. 2026
episode Identity Is the Perimeter in AI-era Fraud with Lockton Global CISO TJ Mann cover

Description

On the 38th episode of Enterprise AI Defenders, host Mike Britton talks with TJ Mann [https://www.linkedin.com/in/tjmann1/], Global Chief Information Security Officer at Lockton [https://global.lockton.com/us/en]. TJ argues the fastest path to resilience is not chasing every shiny tool; it is treating identity, APIs, and SaaS configuration as the new frontline, because attackers “don’t need to breach your network anymore,” they need one compromised identity, integration, or misconfiguration. He also breaks down how AI shifts email and impersonation risk toward hyper-personalized social engineering, and why Lockton is investing heavily in employee awareness, muscle memory for reporting, and identity-first controls to keep fraud from becoming a business process. Quick hits from TJ: On AI-driven impersonation: “We are seeing… hyper personalized social engineering… deepfake voice or face or audio or video or both.” On what changed in cloud security: “Identity… is the new perimeter.” On what attackers really need now: “The bad guys don’t need to breach your network anymore. They just need to compromise one identity, one integration or one misconfiguration.” Recent Book Recommendation: Ikigai by Héctor García and Francesc Miralles Like what you hear? Leave us a review and subscribe to the show on Apple, Spotify, and YouTube. Enterprise AI Defenders is a show where security executives explain concrete threat shifts and the defenses that hold up in real environments. Find more great insights from technology leaders and enterprise software experts at https://www.enterprisesoftware.blog/ [https://www.enterprisesoftware.blog/] Enterprise AI Defenders is produced by Abnormal Studios.

Comments

0

Be the first to comment

Sign up now and become a member of the Enterprise AI Defenders community!

Get Started

1 month for 9 kr.

Then 99 kr. / month · Cancel anytime.

  • Podcasts kun på Podimo
  • 20 lydbogstimer pr. måned
  • Gratis podcasts

All episodes

41 episodes

episode AI Threats Aren't New, Just Faster with Tyson Foods VP & Global CISO Matt Bunch artwork

AI Threats Aren't New, Just Faster with Tyson Foods VP & Global CISO Matt Bunch

On the 41st episode of Enterprise AI Defenders, hosts Evan Reiser (CEO and co-founder, Abnormal AI [https://abnormal.ai/]) and Mike Britton (CIO, Abnormal AI [https://abnormal.ai/]) talk with Matt Bunch [https://www.linkedin.com/in/matt-bunch-6019b513/], VP & Global CISO at Tyson Foods [https://www.tysonfoods.com/], about how Tyson Foods is modernizing its security operations with AI, and why AI-speed threats make the basics more important, not less. Quick Hits from Matt: On AI adoption across every role: "We're using the mantra 'all in on AI.' And when we say all in, it is everyone all in on AI." On AI risk: "What is a prompt injection issue? It's a data validation issue. That's really all it is." On agentic AI governance: "We're going to have to put guardrails in place that don't exist today to understand what the models are doing, what the agents are doing. Are they really doing what we asked them to do, or are they trying to go outside of their defined scope?" Book Recommendation: The Art of Negotiating by Gerard I. Nierenberg [https://enterprisesoftware.blog/book-club/the-art-of-negotiating]. Like what you hear? Leave us a review and subscribe to the show on Apple, Spotify, and YouTube. Enterprise AI Defenders is a show where top security executives share specific ways AI changes the threat landscape and the defenses that hold up in real environments. Find more great insights from technology leaders and enterprise software experts at https://www.enterprisesoftware.blog/ [https://www.enterprisesoftware.blog/] Enterprise AI Defenders is produced by Abnormal Studios.

24. juni 202630 min
episode Defending Clients and Securing AI Agents with CIBC Chief Security Officer Keith Gordon artwork

Defending Clients and Securing AI Agents with CIBC Chief Security Officer Keith Gordon

On the 40th episode of Enterprise AI Defenders, host Mike Britton (CIO, Abnormal AI) is joined by Keith Gordon [https://www.linkedin.com/in/keith-gordon-nacd-dc-aa934b5/], Chief Security Officer at CIBC [https://www.cibc.com/en/personal-banking.html]. Keith shares how a top-25 US bank is hardening its client-facing defenses with in-house behavioral biometrics, why third parties are the next exposed layer in financial services, and how the bank is governing agentic identities as the next phase of identity-first defense. Quick Hits from Keith: On the operating principle: "We've got to build AI for security... But we also have to have security for AI." On the client as the new threat surface: "The client is the path of least resistance and the lowest on the maturity scale." On governing agents: “they’re a kind of micro-segmentation in the AI age" Book Recommendation: How to Win Friends and Influence People by Dale Carnegie. [https://enterprisesoftware.blog/book-club/how-to-win-friends-and-influence-people] Like what you hear? Leave us a review and subscribe to the show on Apple, Spotify, and YouTube. Enterprise AI Defenders is a show where top security executives share specific ways AI changes the threat landscape and the defenses that hold up in real environments. Find more great insights from technology leaders and enterprise software experts at https://www.enterprisesoftware.blog/ [https://www.enterprisesoftware.blog/] Enterprise AI Defenders is produced by Abnormal Studios.

10. juni 202626 min
episode Governing AI Risk in Healthcare with Montefiore Health System CISO Mark Ballister artwork

Governing AI Risk in Healthcare with Montefiore Health System CISO Mark Ballister

On the 39th episode of Enterprise AI Defenders, hosts Evan Reiser (CEO and co-founder, Abnormal AI [https://abnormal.ai/]) and Mike Britton (CIO, Abnormal AI [https://abnormal.ai/]) sit down with Mark Ballister [https://www.linkedin.com/in/mark-ballister/], CISO at Montefiore Health System [https://montefioreeinstein.org/], to discuss governing AI risk in a hospital system. Mark shares how his team flipped the default from "no" to "yes, with controls," why work-versus-web toggles are a quiet exposure point, and how his own security team produced 22,000 lines of AI-generated code for an internal risk-evaluation model. Quick Hits from Mark: On the AI governance posture: "We don't look to say no. We look to say yes, as long as we can put controls around it." On the Microsoft Copilot work-versus-web toggle: "By just clicking that button that says 'web,' you are no longer protected." On bringing AI inside the security team: "It wrote all…22,000 lines of code." Book Recommendation: The One Minute Manager [https://www.amazon.com/The-One-Minute-Manager/dp/0688014291] by Ken Blanchard and Spencer Johnson Like what you hear? Leave us a review and subscribe to the show on Apple, Spotify, and YouTube. Enterprise AI Defenders is a show where top security executives share specific ways AI changes the threat landscape and the defenses that hold up in real environments. Find more great insights from technology leaders and enterprise software experts at https://www.enterprisesoftware.blog/ [https://www.enterprisesoftware.blog/] Enterprise AI Defenders is produced by Abnormal Studios.

29. apr. 202627 min
episode Identity Is the Perimeter in AI-era Fraud with Lockton Global CISO TJ Mann artwork

Identity Is the Perimeter in AI-era Fraud with Lockton Global CISO TJ Mann

On the 38th episode of Enterprise AI Defenders, host Mike Britton talks with TJ Mann [https://www.linkedin.com/in/tjmann1/], Global Chief Information Security Officer at Lockton [https://global.lockton.com/us/en]. TJ argues the fastest path to resilience is not chasing every shiny tool; it is treating identity, APIs, and SaaS configuration as the new frontline, because attackers “don’t need to breach your network anymore,” they need one compromised identity, integration, or misconfiguration. He also breaks down how AI shifts email and impersonation risk toward hyper-personalized social engineering, and why Lockton is investing heavily in employee awareness, muscle memory for reporting, and identity-first controls to keep fraud from becoming a business process. Quick hits from TJ: On AI-driven impersonation: “We are seeing… hyper personalized social engineering… deepfake voice or face or audio or video or both.” On what changed in cloud security: “Identity… is the new perimeter.” On what attackers really need now: “The bad guys don’t need to breach your network anymore. They just need to compromise one identity, one integration or one misconfiguration.” Recent Book Recommendation: Ikigai by Héctor García and Francesc Miralles Like what you hear? Leave us a review and subscribe to the show on Apple, Spotify, and YouTube. Enterprise AI Defenders is a show where security executives explain concrete threat shifts and the defenses that hold up in real environments. Find more great insights from technology leaders and enterprise software experts at https://www.enterprisesoftware.blog/ [https://www.enterprisesoftware.blog/] Enterprise AI Defenders is produced by Abnormal Studios.

4. mar. 202625 min
episode Fraud Moves Faster With AI, Verification Must Too with KPMG US CSO Matt Posid artwork

Fraud Moves Faster With AI, Verification Must Too with KPMG US CSO Matt Posid

On the 37th episode of Enterprise AI Defenders, hosts Evan Reiser and Mike Britton talk with Matt Posid [https://www.linkedin.com/in/matthew-posid/], Chief Security Officer at KPMG US [https://kpmg.com/us/en.html]. AI accelerates the attacker’s playbook by increasing overall capability and reducing the time between vulnerability discovery and exploitation. Matt explains why KPMG consolidated cyber, insider risk, physical security, life safety, resilience, and third-party risk into one enterprise security program, and how defenders can keep up by pairing strong controls with AI-enabled workflows and clear governance. Quick hits from Matt: On how AI changes the threat curve: “AI is really good at a couple of things. It is really good at making people better, and it’s really good at making people faster.” On deepfakes and why fundamentals still work: “The controls we’ve had to protect against non AI-based attacks are still, in many cases, effective against the AI-based variants.” On the defender’s response, fight at AI speed: “If the bad guys are using certain tools, the good guys probably have to also, in order to keep up with the capabilities, the velocity that we need to defend.” Recent Book Recommendation: Unreasonable Hospitality by Will Guidara [https://www.enterprisesoftware.blog/book-club/unreasonable-hospitality] Like what you hear? Leave us a review and subscribe to the show on Apple, Spotify, and YouTube. Enterprise AI Defenders is a show where top security executives share how moves to the cloud have created an evolved threat landscape that requires new tools to protect against cybercrime. Find more great lessons from tech leaders and enterprise software experts at https://www.enterprisesoftware.blog/ [https://www.enterprisesoftware.blog/]. Enterprise AI Defenders is produced by Abnormal Studios.

18. feb. 202625 min