- 18 minutes 49 secondsSecuring the AI Control Plane with Speakeasy
In this episode, Sagar Batchu, CEO of Speakeasy, explains how the Speakeasy AI control plane lets organizations adopt AI everywhere and still prove it's governed — putting every agent, tool, and MCP server behind a single security layer that authenticates each action, enforces policy, and inspects every session for prompt injection and data exfiltration. Pressure-testing the approach are George Finney, CISO at The University of Texas System, and Nick Espinosa, host of The Deep Dive Radio Show.
Want to know:- Why is knowing what your AI agent can access still an unsolved problem, and how much of it traces back to the identity and data governance we never fixed for humans?
- Should an AI agent ever be allowed to take an action no individual can fully understand, even when it's statistically more effective than the human alternative?
- Where's the line between legitimate governance and surveillance, and how do you assure employees you're not building a panopticon?
- Are there decisions and departments that should stay permanently in human hands, off-limits to agents entirely?
- When an agent acts through a company's API and something goes wrong, who's actually responsible: the employee, the company, the model developer, the API provider, or the governance platform?
- Could a control plane have flagged the week's biggest AI incident before it escalated?
- Is adopting this really as simple as switching on enterprise settings and plugging in an API, whether you're an SMB or the Fortune 1?
- What is "cognitive surrender," and why does Speakeasy's CEO think it's the one quality companies most need to protect?
Check out the episode for the answers you need.
A huge thanks to our sponsor, Speakeasy.Speakeasy is the enterprise AI control plane. It governs every AI agent, tool, and MCP server from one place. Every connection is authenticated, every policy enforced, and every agentic action inspected and logged. So organizations can scale AI adoption with visibility and control. Copy for below Banner: AI usage is outgrowing your enterprise controls. Speakeasy is the AI control plane that governs every agent, assistant, and MCP server from one layer. Each connection is authenticated, each policy enforced, and every action recorded. So you stay in control as AI adoption scales."
17 August 2026, 10:00 am - 18 minutes 12 secondsProving Resilience with Gambit Security
In this episode, Curtis Simpson, CSO at Gambit Security, explains how Gambit moves organizations past that guesswork by continuously mapping a company's minimally viable business capabilities and validating whether the infrastructure, backups, and recovery processes behind them can actually deliver within the timeframes the business requires. Joining him to pressure-test the approach are Howard Holton, former CEO of GigaOm, and Adam Palmer, CISO at First Hawaiian Bank.
Want to know:- Why do so many disaster recovery plans hold up on paper but fail the moment they're actually needed?
- What's the real difference between having something backed up and proving you can recover it?
- What is a "minimally viable company," and how much of mapping it is automated versus built on human input?
- What happens when your infrastructure fails today, versus what Gambit's roadmap has planned for tomorrow?
- What should actually land in front of your CEO or board to demonstrate recovery confidence?
- Is there an organization too small, or too mature, to get value from this kind of resilience assessment?
- Why does decades-old infrastructure like the mainframe often cause the longest, most damaging outages?
- Why is now the moment for security to finally move from a "trust but trust" model to "trust but verify" on recoverability?
Check out the episode for the answers you need.
Huge thanks to our sponsor, Gambit Security Gambit is the AI-native cyber resilience platform for enterprises that can't afford downtime. It continuously maps your live environment, backups, security tools, and infrastructure-as-code, then validates whether your entire stack can actually recover from disruption. Gambit gives security and infrastructure leaders proof of recoverability on demand, so the business keeps running. Balens maps, controls, and proves your recoverability across every layer of your stack - against infrastructure failures, human and AI errors, and cyber threats. One live view of your cloud, IaC, and backups that updates as your environment evolves. Agentless deployment in 15 minutes. Learn more at gambit.security4 August 2026, 6:54 pm - 17 minutes 42 secondsClosing the Configuration Gap with CoreView
In this episode, Andrea Sivieri, Chief Product and Technology Officer at CoreView, explains how CoreView secures that overlooked layer, the configuration, permissions, and structure of a Microsoft 365 tenant rather than just the data flowing through it. Joining him are Davi Ottenheimer, principal at Flying Penguin, and Will Gregorian, CISO at Galileo Medical.
Want to know:- Why does Microsoft's own admin console give you roughly a thousand ways to configure a single setting?
- What's the actual difference between securing your Microsoft 365 data and securing your Microsoft 365 configuration?
- How does a "virtual tenant" stop one compromised admin account from exposing your entire company?
- How do you stay ahead of a vendor that can change its APIs or shut off access without warning?
- How do you catch a change to your tenant that you had no way of seeing in the first place?
- How far back can you rewind a tenant's configuration history, and why does that number matter?
- What does managing a 2.7 million-user tenant reveal about resilience that a small business never has to think about?
Check out the episode for the answers you need.
A huge thanks to our sponsor, CoreView
27 July 2026, 2:18 pm - 18 minutes 29 secondsSecuring the Open Source Supply Chain with ActiveState
In this episode, Abby Kearns, CEO of ActiveState, explains how her company closes that gap by rebuilding open-source packages from verified sources before they ever reach a developer's pipeline, rather than scanning for problems after the fact. Joining her are Doug Mayer, vp and CISO at WCG, and Howard Holton, former CEO at GigaOM.
Want to know:
- Why is AI increasing exploitability on both the attacker side and the developer side of the open source supply chain?
- How does a package catalog replace your package manager without slowing developers down or pushing them around the process?
- What does ActiveState do differently than upstream scanning tools like JFrog Artifactory or Sonatype Nexus?
- What happens when a developer needs a package that isn't in the catalog yet?
- How is ActiveState thinking about shadow AI and SBOM coverage beyond language libraries?
- What upcoming regulatory deadlines, like the EU Cyber Resilience Act, should security teams have on their radar?
- What happens to open source security when AI produces more CVEs and patches than the maintainers behind these projects can process?
Huge thanks to our sponsor, ActiveState
ActiveState gives security and engineering teams a single governed source for open source software. With 79 million components built from source, continuously remediated, and delivered directly into the tools teams already use, ActiveState eliminates the CVE backlog and the developer toil that comes with it. Companies see a 60 to 99% reduction in CVEs and reclaim up to 30% of developer time. Curate a private, vetted repository of open source components from the ActiveState Library that developers use safely without scouring the internet. A Curated Catalog provides your security team total control over what enters their environments while giving engineering teams a fast, secure way to build, onboard, and start new projects.
20 July 2026, 10:00 am - 23 minutes 13 secondsElevating the SOC with Prophet Security
In this episode, Grant Oviatt, vp of product and co-founder at Prophet Security, explains how his platform deploys AI agents to investigate and respond to alerts the way a skilled analyst would, using REST API integrations across existing security tools rather than absorbing all your data into another SIEM. Joining him are Will Gregorian, CISO at Galileo Medical, and Howard Holton, CEO at GigaOm.
Want to know:- Why are AI-powered SOC tools adding to analyst frustration rather than reducing it?
- When an AI agent makes a bad call on an investigation, who actually owns that failure?
- How does Prophet Security's audit trail let you trace every query, piece of evidence, and reasoning step an agent used?
- Why is Prophet Security using frontier models rather than training its own, and how does security-specific context change the outcome?
- What does giving an AI agent remediation authority look like in practice, and where does Prophet Security draw the line?
- How long does it realistically take to go from contract to running Prophet Security against live alerts?
Check out the episode for the answers you need.
Huge thanks to our episode sponser, Prophet SecurityProphet AI is an Agentic AI SOC Platform that investigates and responds with context, shows its reasoning, and elevates every part of your SOC. Prophet AI SOC Analyst investigates and responds to alerts in minutes; Threat Hunter streamlines threat hunts with a natural language interface; and Detection Advisor provides insights on detection quality and coverage.
15 June 2026, 10:00 am - 20 minutes 39 secondsSecuring AI Agents with CompFly AI
In this episode, Venkat Siva, co-founder and CEO at CompFly AI, explains how his platform gives security, engineering, and business teams a control plane for autonomous AI agents across their full lifecycle. CompFly discovers agents, assigns each one a verifiable distributed identity, runs adversarial and safety simulations before launch, enforces deterministic policies at runtime through a gateway, and produces immutable audit logs for compliance teams after the fact. Joining him are Mike Lockhart, CISO at EagleView, and Gary Chan, System VP and CISO at SSM Health.
Huge thank you to our sponsor, CompFly AI
CompFly is the control plane for the agentic enterprise. We make autonomous AI agents governable at scale discovering them, evaluating their risk, and enforcing real-time guardrails before execution. Enterprises deploy CompFly to move agents from sandbox to production with the evidence trail their boards/management require.
8 June 2026, 12:17 pm - 22 minutes 22 secondsAutomating Offensive Security with XBOW
In this episode, Nico Waisman, CISO at XBOW, explains how XBOW uses autonomous AI agents to run continuous, incremental penetration testing without triggering false-positive avalanches or taking down production systems. Joining him are Jacob Combs, CISO at Tandem Diabetes Care, and Davi Ottenheimer, president at Flying Penguin.
Want to know:- Why can't traditional pen tests keep up with modern attack surfaces?
- How XBOW's attack credit model maps to the way security teams already size testing effort?
- What stops an autonomous pen testing agent from causing real damage in production?
- How incremental testing works when a new pull request changes the application?
- Where XBOW is headed on prompt injection and LLM-specific vulnerabilities?
- How you audit what the AI actually did during an assessment?
- What novel vulnerability chains are emerging as AI reasoning models get more capable?
Check out the episode for the answers you need.
Huge thanks to our sponsor, XBOW1 June 2026, 7:59 pm - 17 minutes 27 secondsRethinking Tabletops with Reflex Security
In this episode, Cassio Goldschmidt, co-founder and CTO at Reflex Security, explains how Reflex replaces static, script-driven tabletops with adaptive AI-driven simulations that fight back, measure real human behavior under pressure, and surface the gaps that scripted exercises never reach. Joining him are Nick Espinosa, host of the nationally syndicated Deep Dive Radio Show, and Jay Wilson, CISO and CIO at Insurity.
Want to know:- Why do traditional tabletops train teams to know the plan rather than execute under pressure?
- What's the difference between a team that panics and a team that chokes, and why does it matter?
- How does Reflex use AI agents to adapt the simulation based on what the team actually does?
- Can you run separate tabletops for technical, legal, and executive audiences without multiplying the workload?
- Is there a risk that security leaders optimize for the AI's score rather than genuine preparedness?
- How does an AI agent joining a video conference change the way a tabletop runs?
- How hard should training be relative to the real thing?
Check out the episode for the answers you need.
Huge thanks to our sponsor, Reflex SecurityMost tabletop exercises are static, predictable, and easy to pass. Reflex Security built the first tabletop that fights back, throwing teams into dynamic simulations against intelligent AI adversaries that adapt to your every move. With Reflex, your team can move from checkbox exercises to real crisis readiness.
18 May 2026, 12:55 pm - 16 minutes 57 secondsSecuring Mobile Apps with Guardsquare
In this episode, Ryan Lloyd, Chief Product Officer at Guardsquare, explains how the platform combines code obfuscation, runtime integrity checks, and real-time threat monitoring to secure mobile apps at the binary level, integrated directly into the CI/CD pipeline. Joining him are TC Niedzialkowski, Head of IT & Security at Opendoor, and Montez Fitzpatrick, CISO at Navvis.
Want to know:- Why does organizational apathy around mobile app security persist even as mobile becomes the primary customer channel?
- What's the difference between app integrity and code integrity, and why does it matter for defending against repackaging attacks?
- How does obfuscation function as a real security control rather than just security through obscurity?
- How does Guardsquare fit into the CI/CD pipeline, and what does the actual build overhead look like for development teams?
- What API and webhook capabilities exist for routing threat monitoring data into your existing security stack?
- How does Guardsquare's mobile app attestation model bind server-side APIs to verified legitimate app instances — and why does that matter for stopping bots and credential theft?
Huge thanks to our sponsor, Guardsquare
Guardsquare delivers mobile app security without compromise, providing advanced protections for both Android and iOS apps. From app security testing to code hardening to real-time visibility into the threat landscape, Guardsquare solutions provide enhanced mobile application security from early in the development process through publication. Learn more about how to protect your app at Guardsquare.com.
11 May 2026, 10:00 am - 19 minutes 41 secondsVerifying Identities with Trusona
In this episode, Ori Eisen, founder and CEO at Trusona, makes a case for getting out of the AI detection arms race entirely. He argues that trying to catch AI-generated fakes with AI detection is the antivirus playbook, and we know how that ends. Trusona instead anchors verification to authoritative sources, DMV records and physical-world signals, things AI can mimic on screen but can't actually own. No pre-registered devices required. And it works in both directions: attackers calling your help desk, and attackers calling your employees while pretending to be IT. Joining him are Eduardo Ortiz, VP and Global Head of Cybersecurity at Techtronic Industries, and Mandy Huth, SVP and CISO at Ultra Clean Technology.
Want to know:- Why do MFA and SSO still leave gaps attackers walk right through?
- How Trusona verifies identity with no pre-registered devices or tokens?
- Why building AI detection on top of AI fakes is a losing strategy?
- How is a false rejection rate of zero achievable without locking out real employees?
- What deployment actually looks like, and how fast you can be live?
- Which departments beyond IT need identity verification, and where do you start?
- How to measure the business value of this beyond just counting blocked account takeovers?
- Why is a solid help desk protocol still not enough on its own?
Huge thanks to our sponsor, Trusona
GenAI supercharges identity impersonation and social engineering attacks – rendering legacy identity verification methods obsolete, especially in high-risk workflows like IT Help Desk password/MFA resets, vendor payment changes, remote employee hiring, or customer account access. Trusona ATO Protect empowers your team to thwart these attacks across business units and channels. GenAI supercharges identity impersonation and social engineering. It's rapidly eroding traditional authentication, especially in high-risk workflows like help desk password or MFA resets, vendor payment changes, remote employee hiring, and customer account access. Trusona's ATO Protect addresses deepfakes and social engineering directly—without adding friction or relying on legacy MFA.
4 May 2026, 10:00 am - 17 minutes 33 secondsTransitioning to Quantum-Safe Encryption with enQase
All links and images can be found on CISO Series.
In this episode, Raj Patil, CTO at enQase, explains how enQase's full-stack platform helps enterprises implement quantum-safe security through a structured, integrated approach. This covers everything from cryptographic asset discovery and governance to out-of-band key generation for network appliances, without requiring organizations to rip and replace existing infrastructure. Joining him are Ross Young, co-host at CISO Tradecraft, and Adam Palmer, CISO at First Hawaiian Bank.
Want to know:- Why is the post-quantum cryptography transition harder than simply implementing new standards?
- What three factors should frame every CEO conversation about quantum risk?
- Where should a highly regulated enterprise start, and what can reasonably wait three to five years?
- Why should we be planning for "harvest now, decrypt later" attacks right now?
- How do you build and track a cryptographic bill of materials across hundreds of applications and devices?
- Why is crypto agility more important than picking the perfect algorithm?
Huge thanks to our sponsor, enQase
The enQase Platform empowers enterprises, defense organizations, cloud providers, and critical infrastructure operators to seamlessly adopt quantum-safe technologies while achieving crypto agility across their ecosystems. By combining quantum-grade hardware with software-defined control and interoperability, enQase ensures alignment with NIST standards, delivers unmatched flexibility and compliance readiness, and reduces risk across data, network, and compute layers, all while maintaining business continuity and operational resilience in an evolving cryptographic landscape. Learn more at enqase.com.
16 March 2026, 10:00 am - More Episodes? Get the App