

Resilient Cyber
Chris Hughes
Resilient Cyber brings listeners discussions from a variety of Cybersecurity and Information Technology (IT) Subject Matter Experts (SME) across the Public and Private domains from a variety of industries. As we watch the increased digitalization of our society, striving for a secure and resilient ecosystem is paramount.
Episodes
Mentioned books

8 snips
May 19, 2026 • 32min
The Agentic GRC Revolution
Richa Gual, CEO of Complyance and builder of an AI-native enterprise GRC platform, explains how agentic AI is modernizing governance, risk, and compliance for large organizations. She discusses replacing static audits with continuous, evidence-driven workflows. Short takes cover agent design, avoiding hallucinations, protecting sensitive data, and how AI reshapes analyst roles and vendor assurance.

May 13, 2026 • 34min
Identity as Infrastructure in the Agentic Era
In this episode of Resilient Cyber, I sat down with Karl McGuinness — author of Control Plane and one of the sharpest voices working on identity in the agentic era — to unpack what most of the industry is still getting wrong about IAM for AI agents.Karl's thesis is a provocation: we spent two decades optimizing authentication and authorization, and we built that stack for human-paced execution. Agents remove the presence, pacing, and natural scope-limiting that made those controls work — and no amount of stronger credentials, tighter scopes, or faster JIT provisioning closes the structural gap. The real frontier isn't AuthN or AuthZ. It's delegation: how approved intent becomes bounded authority that stays governed across delegation chains, unfamiliar tools, consent expansion, revocation, and task termination.Chris and Karl dig into:↳ Why the industry optimized for the wrong question, and what changes when agents enter the loop ↳ The Execution Mandate — agents don't need your passport, they need your authority ↳ Why governing the stay matters more than governing the entry, and what continuous evaluation of authority looks like in practice ↳ Mission-Bound OAuth, including Karl's own pessimistic case against it ↳ AAuth vs. OAuth as the substrate for agentic identity, and what signal will tell us which one wins ↳ Why Mission Shaping is necessary but not sufficient when quiet expansion, headless execution, and stale state are in play ↳ Open-world OAuth, MCP, and first-contact trust — what the newer standards solve and the substrate gaps no draft is closing ↳ ID-JAG and Cross-App Access (XAA): why enterprise SaaS needs to abandon app-by-app OAuth islands ↳ The widening gap between IETF drafts and the "agentic IAM" being sold at RSA, and the minimum viable posture for teams running agents in production todayWhether you're a CISO, an identity architect, or a security leader trying to separate vendor narrative from substrate reality, this is a clear-eyed map of where agentic IAM actually is and where it has to go.🔗 Karl's writing: https://notes.karlmcguinness.com/ 🔗 Subscribe to Resilient Cyber on Substack: https://www.resilientcyber.io/ 🔗 Follow Chris on LinkedIn: https://www.linkedin.com/in/resilientcyber/

May 1, 2026 • 23min
Why AI Security Feels So Fragile
A deep look at why AI security feels fragile right now, from black box risks to exponential change. Discussion of how data unification redefines access as AI agents take over. Exploration of agent accountability, the limits of detective controls, and the push toward preventive controls and intent analysis. Practical security tradeoffs when bridging governance and consumability.

Apr 28, 2026 • 1min
You Can't Trust What You Can't Verify — The Case for AI Model Identity
Manish Shah, co-founder and CEO of Project VAIL and repeat founder (LiveRamp), works on verifiable AI model identity. He discusses why behavioral fingerprinting can identify models at runtime. He explains zk-proof techniques for cryptographic verification without revealing model internals. He outlines risks like model substitution, adversarial fine-tuning, and compliance gaps.

Apr 27, 2026 • 38min
Securing the Vibe: Tanya Janca on AI-Generated Code, Mythos, and the New AppSec Reality
A new episode of the Resilient Cyber Show just dropped, and this one is a conversation I’ve been looking forward to for a long time.I sat down with Tanya Janca, better known to most of the AppSec world as SheHacksPurple. Tanya is the best-selling author of Alice and Bob Learn Application Security and Alice and Bob Learn Secure Coding, an OWASP Lifetime Distinguished Member, CEO of She Hacks Purple Consulting, and one of the most recognized voices in application security and developer education on the planet.The timing of this conversation is hard to overstate. The OWASP Top 10 2025 was announced at the Global AppSec Conference last year, with two new categories, Software Supply Chain Failures and Mishandling of Exceptional Conditions, and SSRF folded into Broken Access Control. Recently, Anthropic released the Claude Mythos Preview system card, documenting a model that has already found thousands of high-severity zero-day vulnerabilities autonomously, including bugs in every major operating system and web browser, and a 27-year-old vulnerability in OpenBSD.In other words, AppSec is at a hinge moment, and Tanya is exactly the right person to think out loud with about it.Here’s what we get into:What the OWASP Top 10 2025 got right, what it missed, and how teams should actually use itAI-generated code, “vibe coding,” and Tanya’s brand-new free prompt library for secure coding with AI assistants, SecureMyVibe.caWhat Mythos-class capabilities mean for the offense/defense asymmetry AppSec has always lived withHow AI is genuinely changing the SDLC, where it creates lift, where it creates noise, and where it creates entirely new attack surfaceArchitecting real defenses at the prompt layer, across MCP servers, and inside RAG pipelines, not just bolting content filters onto the front doorWhy developers are the new attack surface, and why a lot of what gets labeled as “supply chain attacks” lately is really a developer compromise that cascaded into the supply chainTanya’s threat model, defense framework, and maturity model for protecting developers themselvesDevSec Station, Tanya’s new podcast delivering 5–10 minute secure coding lessons in a format built for how developers actually consume contentWhat she’d change tomorrow about how AppSec programs are built and run if she could change just one thingThis is one of those conversations that ranges from the practical (what to do Monday morning) to the philosophical (what does it even mean to “secure software” when an AI can find more zero-days in a weekend than a Red Team finds in a year). Tanya brings the rare combination of deep technical chops, real teaching ability, and genuine warmth that makes a hard subject feel approachable.If you lead an AppSec program, write code for a living, run a security team trying to keep up with AI-assisted development, or you’re just trying to figure out where this whole industry is heading, this is the episode for you.Resources from the episode:SecureMyVibeDevSec Station Podcast (Tanya’s new show)She Hacks Purple ConsultingAlice and Bob Learn Application Security and Alice and Bob Learn Secure CodingOWASP Top 10 2025 — https://owasp.org/Top10/2025/Claude Mythos Preview System Card — AnthropicThanks for being here. If this episode landed for you, the best thing you can do is share it with one person on your team who’d find it useful, that’s how this newsletter and show grow.

Apr 16, 2026 • 24min
AI and the Future of Secure Coding
Jack Cable, security researcher and entrepreneur who helped shape CISA’s Secure by Design and founded Corridor. He discusses the rise of AI-written code, why shift-left never cleared vulnerability backlogs, and the new field of agentic security coding management. He weighs AI as both problem and tool, explores governance, provenance, and liability, and outlines how industry and policy may respond.

Apr 8, 2026 • 45min
Your AI Agent Is Running As Root
When you fire up Claude Code, Cursor, or any AI coding agent, it launches with your full system permissions, your SSH keys, cloud credentials, browser passwords, every file on your machine. Most developers never think twice about it.Luke Hinds did. And then he built something about it.Luke is the creator of Sigstore, the cryptographic signing infrastructure now used by PyPI, Homebrew, GitHub, and Google as the industry standard for software supply chain security. In this episode, he joins Chris to talk about why he's watching the industry make the exact same mistake it made a decade ago, and what he built to try to stop it.We cover the full picture: why application-layer guardrails and system prompts fundamentally fail as security boundaries for AI agents (and what kernel-level enforcement actually means), the .md file as an emerging control plane attack surface, the OpenClaw wake-up call and what the skills marketplace ecosystem gets structurally wrong about trust and provenance, the approval fatigue problem and Anthropic's 17% false negative rate on Claude Code's auto-mode classifier, extending SLSA and Sigstore attestation frameworks to AI-generated code, and why LLM-as-a-judge may not be the silver bullet many are hoping for.Luke also makes a broader argument about where this is all heading — volumes of AI-generated code growing faster than human capacity to review it, junior engineers being priced out of the industry, and an aging cohort of engineers who can actually read and reason about code at depth. It's a candid, technically grounded conversation from someone who's been in open source security for 20+ years and has seen this movie before.nono is at nono.sh, one line to install, one line to run. No excuse not to

Mar 17, 2026 • 45min
The 350 Million Problem: Securing the Businesses No One Else Will
Joe Levy, CEO of Sophos and a 30-year cybersecurity veteran, discusses the massive gap: 359M businesses but under 32K security leaders. He explores why the market fails SMEs, how agentic AI can scale CISO-level intuition, real gains and limits of AI in SOCs, and the tough choices behind a five-year nation-state firewall disclosure.

Mar 11, 2026 • 5min
Before the Breach: The Zero Day Clock and the Race Against Exploitation
Show DescriptionThe Zero Day Clock is ticking — and the numbers should make every security leader uncomfortable. In this episode, I sit down with Sergej Epp, CISO at a leading security firm, who built the Zero Day Clock after a weekend experiment using AI to discover vulnerabilities firsthand. What he found shocked him: with no professional vulnerability research background and just a few hours of work, he was successfully finding zero days across major security projects using AI models and basic scaffolding.Sergej breaks down his concept of the "Verifier's Law" — the idea that offense has the cheapest verifier in cybersecurity because feedback is binary and instant (you either popped a shell or you didn't), while defense operates in a space where validation is expensive, ambiguous, and slow. We dig into what this asymmetry means for the industry, why 20 years of warnings from Ross Anderson, Bruce Schneier, Halvar Flake, and others have gone unheeded, and whether coordinated disclosure models are broken now that AI can reverse engineer a patch into a working exploit in minutes.We also discuss the tension between regulation and deregulation playing out in the U.S. and EU, why the answer might be outcome-based accountability rather than prescriptive compliance, and what a realistic defensible posture actually looks like when the mean time to exploit for actively exploited vulnerabilities is under two days — while most organizations are still operating on 30-day patch cycles.Show NotesSergej shares how a weekend AI experiment led him to discover multiple zero days across major security projects with no professional vulnerability research experience — and why that should alarm the entire industryThe "Verifier's Law" explained: offense has cheap, deterministic validators (pop a shell, exfiltrate data, trigger an XSS) while defense faces expensive, ambiguous validation (parsing SIM alerts, measuring security posture), giving AI-accelerated offense a structural advantageThe Zero Day Clock synthesizes 3,500+ CVE-exploit pairs and shows the mean time to exploit for actively exploited vulnerabilities is now under two days — while organizations still operate on 14-to-30-day patch cycles20 years of ignored warnings: from Ross Anderson's 2001 economics paper through Bruce Schneier, Halvar Flake's "the patch is the advisory" insight, and DARPA's Cyber Grand Challenge — the industry has consistently failed to act on clear signalsAI can now reverse engineer patches to identify underlying flaws and generate working exploits in minutes, potentially breaking coordinated disclosure models and compressing the window between patch release and active exploitation to near zeroThe regulation paradox: the EU risks overregulating AI in ways that hamper defenders while attackers face no such constraints, while the U.S. is pushing deregulation that may remove the only forcing function for vendor accountability — Sergej and Chris discuss outcome-based regulation as a potential middle pathDefenders have a data advantage: by understanding their own environments, infrastructure, and processes, security teams can detect AI-driven attacks through behavioral anomalies like hallucinated API calls, non-existent user accounts, and other artifacts of AI-generated attack playbooksThe Zero Day Clock's real power is as a board-level communication tool — a single slide that translates the patching gap into a number executives and policymakers can't ignore, shifting the conversation from "are we compliant?" to "are we fast enough?"

Feb 23, 2026 • 41min
Securing the Future with Autonomous Defense
Summary:In this conversation, Chris Hughes and Stanislav Fort discuss the transformative role of AI in cybersecurity, particularly in vulnerability management. Stanislav shares insights on how AI can discover zero-day vulnerabilities in widely used codebases, the challenges of balancing AI-driven discoveries with quality assurance, and the importance of proactive security measures. They also explore the economic sustainability of AI in cybersecurity, the burden on maintainers, and the ongoing arms race between defenders and attackers. The discussion emphasizes the potential for AI to significantly enhance software security and the aspiration towards achieving zero vulnerabilities in critical infrastructure.Takeaways:AI is revolutionizing vulnerability management in cybersecurity.The ability to find long-hidden vulnerabilities is unprecedented.AI can enhance both offensive and defensive security measures.Proactive security integration into development pipelines is essential.The quality of vulnerability reports is declining due to AI-generated noise.Maintainers face increasing burdens from rapid AI-driven discoveries.AI can help secure open source projects effectively.Sustainability in AI cybersecurity requires financial backing.The arms race between attackers and defenders is intensifying with AI.Achieving zero vulnerabilities is an aspirational yet achievable goal.Chapters00:00 Introduction to AI in Cybersecurity02:52 The Evolution of AI and Vulnerability Discovery05:45 AI's Impact on Software Development08:59 Discovering Zero-Day Vulnerabilities11:48 The Great Bifurcation in Security Research14:52 Balancing AI-Driven Discoveries and Quality17:59 Proactive Security Measures in Software Development20:53 The Role of AI in Securing Open Source Projects23:54 Sustainability of AI in Cybersecurity27:07 Addressing the Burden on Maintainers30:09 The Tension Between Autonomy and Security33:03 The Arms Race Between Defenders and Attackers36:12 Aiming for Zero Vulnerabilities38:58 Conclusion and Future Outlook


