Enterprise Security Weekly (Audio)

Security Weekly Productions
undefined
13 snips
Sep 22, 2025 • 1h 47min

Disruption is Coming for the Vulnerability Management Market - Tod Beardsley - ESW #425

Tod Beardsley, VP of Security Research at RunZero and an expert in security, discusses the shortcomings of traditional vulnerability management. He emphasizes the failure of CVE-centric approaches and highlights the importance of addressing issues like default credentials and misconfigurations. The conversation dives into recent NPM supply chain attacks, the fragility of the ecosystem, and community-driven solutions. Beardsley also touches on the latest trends in AI acquisitions and the cautious embrace of agentic AI within the banking sector.
undefined
Sep 15, 2025 • 1h 41min

Forrester's AEGIS Framework, the weekly news, and interviews with Fortra and Island - Jeff Pollard, Rohit Dhamankar, Michael Leland - ESW #424

This installment features Jeff Pollard, VP at Forrester Research and co-author of the AEGIS Framework, which addresses the challenges AI poses for security leaders. Rohit Dhamankar from Fortra highlights the importance of offensive security in regulatory compliance. Michael Leland of Island sheds light on compromised credentials and browser security. The discussion dives into the urgent need for proactive measures against AI-driven risks, recent funding news, and the balance between technological advancements and privacy concerns, making for a thought-provoking conversation.
undefined
12 snips
Sep 8, 2025 • 2h 6min

Ransomware, Agentic AI, and Supply Chain Risks: Insights from Black Hat 2025 - HD Moore, Jason Passwaters, J.J. Guy, Theresa Lanowitz, Mickey Bresman, Yuval Wollman, Jawahar “Jawa” Sivasankaran - ESW #423

Join Doug White as he chats with a powerhouse lineup: Theresa Lanowitz from LevelBlue sheds light on the critical risks of software supply chains, while Yuval Wollman from CyberProof dives into how AI agents are reshaping cyber threats. Mickey Bresman of Semperis discusses the evolution of ransomware and extortion tactics. J.J. Guy explores asset visibility challenges, and Jason Passwaters emphasizes the need for precise threat intelligence. Together, they highlight the integration of AI and the increasing complexity of cybersecurity in today's digital landscape.
undefined
19 snips
Sep 1, 2025 • 1h 46min

Dave Lewis talks M&A due diligence, TBD topic, the weekly news - Dave Lewis - ESW #422

Dave Lewis, Global Advisory CISO for 1Password, dives into the crucial role of cybersecurity in mergers and acquisitions. He highlights common pitfalls and emphasizes the need for thorough security assessments to safeguard organizational value. The conversation also touches on the importance of transparency in breach disclosures, arguing that shared insights could enhance industry learning. Additionally, Lewis discusses the challenges of integrating security measures during organizational shifts and the evolving threats posed by AI in the cyber landscape.
undefined
6 snips
Aug 25, 2025 • 1h 49min

Oktane Preview with Harish Peri, Invisible Prompt Attacks, and the weekly news! - Harish Peri - ESW #421

Harish Peri, SVP of Product Marketing at Okta, dives into the future of AI in identity management and previews the upcoming Oktane conference. He discusses the intriguing challenges of integrating agentic AI while maintaining security, particularly how to manage AI agents without granting excessive privileges. The conversation also highlights the risks of indirect prompt injection vulnerabilities, the evolving landscape of identity management in conservative industries, and the excitement surrounding new AI-driven security solutions.
undefined
21 snips
Aug 18, 2025 • 1h 56min

Rethinking risk based vulnerability management, Black Hat expo insights, and the news - Snehal Antani - ESW #420

Snehal Antani, CEO of Horizon 3 AI and former CIO at GE Capital, tackles the pitfalls of vulnerability management in organizations. He argues that traditional methods often lead to ineffective lists, suggesting a need for a more robust approach. The discussion also highlights insights from the recent Black Hat conference, focusing on innovative security tools and engagement strategies. Additionally, they touch on the role of AI in evolving cybersecurity, the skepticism around marketing claims, and the importance of risk-based management for better defenses.
undefined
Aug 11, 2025 • 46min

ESW at BlackHat and the weekly enterprise security news - ESW #419

Topic Segment - What's new at Black Hat? We're coming live from hacker summer camp 2025, so it seemed appropriate to share what we've seen and heard so far at this year's event. Adrian's on vacation, so this episode is featuring Jackie McGuire and Ayman Elsawah! News Segment Then, in the enterprise security news, Tons of funding! SentinelOne picks up an AI security company weeks after Palo Alto closes the Protect AI deal Vendors shove AI agents into everything they’ve got Why SOC analysts ignore your playbooks NVIDA pinkie swears to China: no back doors! ChatGPT was allowing shared chat sessions to be indexed and crawled by search engines like Google Who is gonna secure all this vibe code? Who is gonna triage all these hallucinated bug reports? Perplexity and Cloudflare duke it out When you try to scrub your shady past off the Internet, it might just make things worse. All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-419
undefined
10 snips
Aug 4, 2025 • 1h 46min

Weekly Enterprise Security News and Tips on Building Security From Day 1 - Guillaume Ross - ESW #418

Guillaume Ross, owner and consultant at Caffeine Security, shares his expertise on building security programs from scratch, particularly in the fintech space. He discusses the daunting task of being a CISO with no existing frameworks and outlines essential first steps. The conversation also delves into recent funding news in cybersecurity, key acquisitions, and the role of detection engineers. Listeners gain insights into modern security practices and the importance of resilience over mere prevention in today’s evolving landscape.
undefined
Jul 28, 2025 • 1h 42min

tj-actions Lessons Learned, US Cyber Offense, this week's enterprise security news - Dimitri Stiliadis - ESW #417

Interview Segment - Lessons Learned from the tj-actions GitHub Action Supply Chain Attack with Dimitri Stiliadis Breach analysis is one of my favorite topics to dive into and I’m thrilled Dimitri is joining us today to reveal some of the insights he’s pulled out of this GitHub Actions incident. It isn’t an overstatement to say that some of the lessons to be learned from this incident represent fundamental changes to how we architect development environments. Why are we talking about it now, 4 months after it occurred? In the case of the Equifax breach, the most useful details about the breach didn’t get released to the public until 18 months after the incident. It takes time for details to come out, but in my experience, the learning opportunities are worth the wait. Topic Segment - Should the US Go on the Cyber Offensive? Triggered by an op-ed from Dave Kennedy, the discussion of whether the US should launch more visible offensive cyber operations starts up again. There are a lot of factors and nuances to discuss here, and a lot of us have opinions here. We'll see if we can do any of it justice in 15 minutes. News Segment Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-417
undefined
12 snips
Jul 21, 2025 • 1h 49min

The Cyber Canon, ditching the SOC 2, and the weekly enterprise news - Helen Patton - ESW #416

Helen Patton, Co-founder and Chief of Staff for the Cybersecurity Canon, dives into the fascinating world of cybersecurity literature, introducing a hall-of-fame for essential reads. She shares insights about her book, 'Navigating the Cybersecurity Career Path,' and discusses the controversial idea of ditching SOC 2 in favor of more effective industry-specific frameworks. The conversation also touches on current enterprise security news, including unexpected layoffs and vulnerabilities within the US railway system, showcasing the evolving landscape of cybersecurity.

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app