Resilient Cyber

40 Episodes
Subscribe

By: Chris Hughes

Resilient Cyber brings listeners discussions from a variety of Cybersecurity and Information Technology (IT) Subject Matter Experts (SME) across the Public and Private domains from a variety of industries. As we watch the increased digitalization of our society, striving for a secure and resilient ecosystem is paramount.

Resilient Cyber: Ravid Circus - Tackling the Prioritization Crisis in Cyber
04/14/2025

In this episode, we sit down with the Co-Founder and CPO of Seemplicity, Ravid Circus, to discuss tackling the prioritization crisis in cybersecurity and how AI is changing vulnerability management.

We dove into a lot of great topics, including:

The massive challenge of not just finding and managing vulnerabilities but also remediation, with Seemplicity’s Year in Review report finding organizations face 48.6 million vulnerabilities annually and only 1.7% of them are critical. That still means hundreds of thousands to millions of vulnerabilities need to be remedied - an...


Resilient Cyber w/ Varun Badhwar - AI for AppSec - Beyond the Buzzwords
04/11/2025

In this episode, we sit down with Varun Badhwar, Founder and CEO of Endor Labs, to discuss the state of AI for AppSec and move beyond the buzzwords. 

We discussed the rapid adoption of AI-driven development, its implications for AppSec, and how AppSec can leverage AI to address longstanding challenges and mitigate organizational risks at scale.

Varun and I dove into a lot of great topics, such as:

The rise of GenAI and LLMs and their broad implications on CybersecurityThe dominant use case of AI-driven development with Copilots and LLM w...


Resilient Cyber w/ Jit - Agentic AI for AppSec is Here
04/08/2025

In this episode, we sit down with David Melamed and Shai Horovitz of the Jit team. 

We discussed Agentic AI for AppSec and how security teams use it to get real work done.

We covered a lot of key topics, including:

What some of the systemic problems facing AppSec are, even before the widespread adoption of AI, such as vulnerability prioritization, security technical debt and being outnumbered exponentially by Developers.The surge of interest and investment in AI and agentic workflows for AppSec, and why AppSec is an appealing space for this sort of i...


Resilient Cyber w/ Piyush Sharrma - AI-Powered Defense & Security Mesh
03/28/2025

In this episode, we sit down with Piyush Sharrma, CEO and co-founder of the Tuskira team. They're an AI-powered defense optimization platform innovating around leveraging an Agentic Security Mesh.

We will dive into topics such as Platform vs. Point Solutions, Security Tool Sprawl, Alert Fatigue, and how AI can create "intelligent" layers to unify and enhance security tooling ROI.

We discussed:

What drove Piyush to jump back into the startup space after successfully exiting from a previous startup he helped foundThe industry debate around Platform vs. Point Solutions or Best-of-Breed and the perspectives between...


Resilient Cyber w/ Elad Schulman - Secure Enterprise LLM/GenAI Adoption
03/28/2025

We sit with Lasso Security CEO and Co-Founder Elad Schulman in this episode.

Lasso focuses on secure enterprise LLM/GenAI adoption, from LLM Applications, GenAI Chatbots, Code Protection, Model Red Teaming, and more. Check them out at https://lasso.security

We dove into a lot of great topics, such as:

Dealing with challenges around visibility and governance of AI, much like previous technological waves such as mobile, Cloud, and SaaSUnique security considerations for different paths of using and building with AI, such as self-hosted models and consuming models as-a-service from SaaS LLM...


Resilient Cyber w/ Sergej Epp - Cloud-native Runtime Security & Usage
03/19/2025

In this episode, we sit with security leader and venture investor Sergej Epp to discuss the Cloud-native Security Landscape. Sergej currently serves as the Global CISO and Executive at Cloud Security leader Sysdig and is a Venture Partner at Picus Capital. We will dive into some insights from Sysdig's recent "2025 Cloud-native Security and Usage Report."

Big shout out to our episode sponsor, Yubico!

Passwords aren’t enough. Cyber threats are evolving, and attackers bypass weak authentication every day. YubiKeys provides phishing-resistant security for individuals and businesses—fast, frictionless, and pass...


Resilient Cyber w/ Lior Div & Nate Burke - Agentic AI & the Future of Cyber
03/17/2025

In this episode, we sit down with Lior Div and Nate Burke of 7AI to discuss Agentic AI, Service-as-Software, and the future of Cybersecurity. Lior is the CEO/Co-Founder of 7AI and a former CEO/Co-Founder of Cybereason, while Nate brings a background as a CMO with firms such as Axonius, Nagomi, and now 7AI.

Lior and Nate bring a wealth of experience and expertise from various startups and industry-leading firms, which made for an excellent conversation.

We discussed:

The rise of AI and Agentic AI and its...


Resilient Cyber w/ Chenxi Wang - The Intersection of AI & Cybersecurity
03/17/2025

In this episode, we sit down with Investor, Advisor, Board Member, and Cybersecurity Leader Chenxi Wang to discuss the interaction of AI and Cybersecurity, what Agentic AI means for Services-as-a-Software, as well as security in the boardroom

Chenxi and I covered a lot of ground, including:

When we discuss AI for Cybersecurity, it is usually divided into two categories: AI for Cybersecurity and Securing AI. Chenxi and I walk through the potential for each and which one she finds more interesting at the moment.Chenxi believes LLMs are fundamentally changing the nature...


Resilient Cyber w/ Rob Shavell - Personal Data & Online Privacy
03/03/2025

In this episode, we sit down with Rob Shavell, CEO and Co-Founder of DeleteMe, an organization focused on safeguarding exposed personal data on the public web and addressing user privacy challenges.

We dove into a lot of great topics, such as:

The rapidly growing problem of personal data ending up on the public web and some of the major risks many may not think about or realizeTrends contributing to personal data exposure, from the Internet itself to social media, mobile phones/apps, IoT devices, COVID, and now AIWhere to get started when it comes...


Resilient Cyber w/ Steve Martano - CISO's, Security Budgets & Careers
02/28/2025

In this episode of Resilient Cyber, we sit down with Steve Martano, Partner in the cyber Security Practice at Artico Search, to discuss the recent IANS & Artico Search Publications on the 2025 State of the CISO, security budgets, and broader security career dynamics.

Steve and I touched on some great topics, including:

The 2025 State of the CISO report and key findingsBoard reporting cadences for CISO’s and the importance of Boardroom involvement in CybersecurityThe three archetypes of CISO’s: Tactical, Functional and StrategicHow security leaders can advance their career to becoming strategic CISO’s as well as key co...


Resilient Cyber w/ Katie Norton - AppSec Industry Analysis & Trends
02/24/2025

In this episode of Resilient Cyber, we catch up with Katie Norton, an Industry Analyst at IDC who focuses on DevSecOps and Software Supply Chain Security. We will dive into all things AppSec, including 2024 trends and analysis and 2025 predictions.

Katie and I discussed:

Her role with IDC and transition from Research and Data Analytics into being a Cyber and AppSec Industry Analyst and how that background has served her during her new endeavor.Key themes and reflections in AppSec through 2024, including disruption among Software Composition Analysis (SCA) and broader AppSec testing vendors.The age-old...


Resilient Cyber w/ Ed Merrett - AI Vendor Transparency: Understanding Models, Data and Customer Impact
02/13/2025

In this episode of Resilient Cyber, Ed Merrett, Director of Security & TechOps at Harmonic Security, will dive into AI Vendor Transparency.

We discussed the nuances of understanding models and data and the potential for customer impact related to AI security risks.

Ed and I dove into a lot of interesting GenAI Security topics, including:

Harmonic’s recent report on GenAI data leakage shows that nearly 10% of all organizational user prompts include sensitive data such as customer information, intellectual property, source code, and access keys.Guardrails and measures to prevent data le...


Resilient Cyber w/ Sounil Yu - The Intersection of AI and Need-to-Know
02/03/2025

In this episode, we sit down with Sounil Yu, Co-Founder and CTO at Knostic, a security company focusing on need-to-know-based access controls for LLM-based Enterprise AI.

Sounil is a recognized industry security leader and the author of the widely popular Cyber Defense Matrix.

Sounil and I dug into a lot of interesting topics, such as:

The latest news with DeepSeek and some of its implications regarding broader AI, cybersecurity, and the AI arms race, most notably between China and the U.S.The different approaches to AI security and safety...


Resilient Cyber w/ Grant Oviatt - Transforming SecOps with AI SOC Analysts
01/27/2025

SecOps continues to be one of the most challenging areas of cybersecurity. It involves addressing alert fatigue, minimizing dwell time and meantime-to-respond (MTTR), automating repetitive tasks, integrating with existing tools, and leading to ROI.

In this episode, we sit with Grant Oviatt, Head of SecOps at Prophet Security and an experienced SecOps leader, to discuss how AI SOC Analysts are reshaping SecOps by addressing systemic security operations challenges and driving down organizational risks.

Grant and I dug into a lot of great topics, such as:

Systemic issues impacting the SecOps space include...


Resilient Cyber w/ Mick Leach - 5 Email Threats to Watch For in 2025
01/21/2025

While cybercriminals can (and do) infiltrate organizations by exploiting software vulnerabilities and launching brute force attacks, the most direct—and often the most effective—route is via the inbox. As the front door of an enterprise and the gateway upon which employees rely to do their jobs, the inbox represents an ideal access point for attackers.

And it seems that, unfortunately, cybercriminals aren’t lacking when it comes to identifying new ways to sneak in. Abnormal Security’s Field CISO, Mick Leach, will discuss some of the sophisticated threats we anticipate escalating in the coming year—including cryptocurr...


Resilient Cyber w/ Rajan Kapoor - Native Cloud Workspace Gaps and Risks
01/21/2025

In this episode, we sit down with Rajan Kapoor, Field CISO of Material Security, to discuss the security risks and shortcomings of native cloud workspace security offerings and the role of modern platforms for email security, data governance, and posture management.

Email and Cloud Collaboration Workspace Security continues to be one of the most pervasive and challenging security environments, and Rajan provided a TON of excellent insights. We covered:

Why email and cloud workspaces are some of the most highly targeted environments by cyber criminals, what they can do once they do compromise the...


Resilient Cyber w/ Greg Martin - Agentic AI and AppSec
01/10/2025

We’ve heard a ton of excitement about AI Agents, Agentic AI, and its potential for Cybersecurity. This ranges in areas such as GRC, SecOps, and Application Security (AppSec).

That is why I was excited to sit down with Ghost Security Co-Founder/CEO Greg Martin.

In this episode, we sit down with Ghost Security CEO and Co-Founder Greg Martin to chat about Agentic AI and AppSec. Agentic AI is one of the hottest trends going into 2025, and we will discuss what it is, its role in AppSec, and what system industry challenges it may help ta...


Resilient Cyber w/ Filip Stojkovski & Dylan Williams - Agentic AI & SecOps
12/11/2024

In this episode, we will be sitting down with Filip Stojkovski and Dylan Williams to dive into AI, Agentic AI, and the intersection with cybersecurity, specifically Security Operations (SecOps).

I’ve been following Filip and Dylan for a bit via LinkedIn and really impressed with their perspective on AI and its intersection with Cyber, especially SecOps. We dove into that in this episode including:

What exactly Agentic AI and AI Agents are, and how they workWhat a Blueprint for AI Agents in Cybersecurity may look like, using their example in their blog with the same titleThe ro...


Resilient Cyber w/ Walter Haydock - Implementing AI Governance
11/22/2024

In this episode, we sit down with StackAware Founder and AI Governance Expert Walter Haydock. Walter specializes in helping companies navigate AI governance and security certifications, frameworks, and risks. We will dive into key frameworks, risks, lessons learned from working directly with organizations on AI Governance, and more.

We discussed Walter’s pivot with his company StackAware from AppSec and Supply Chain to a focus on AI Governance and from a product-based approach to a services-oriented offering and what that entails.Walter has been actively helping organizations with AI Governance, including helping them meet emerging and newly formed st...


Resilient Cyber w/ Jim Dempsey - Navigating the Cyber Regulatory Landscape
11/18/2024

In this episode, we sit with the return guest, Jim Dempsey. Jim is the Managing Director of the Cybersecurity Law Center at IAPP, Senior Policy Advisory at Stanford, and Lecturer at UC Berkeley. We will discuss the complex cyber regulatory landscape, where it stands now, and implications for the future based on the recent U.S. Presidential election outcome.

We dove into a lot of topics including:

The potential impact of the latest U.S. Presidential election, including the fact that while there are parallels between Trump’s first term and Joe Biden’s, there are also...


Resilient Cyber w/ Tyler Shields and James Berthoty - Is "Shift Left" Losing its Shine?
11/01/2024

In this episode of Resilient Cyber I will be chatting with industry leaders Tyler Shields and James Berthoty on the topic of "Shift Left".

This includes the origins and early days of the shift left movement, as well as some of the current challenges, complaints and if the shift left movement is losing its shine.

We dive into a lot of topics such as:

Tyler and Jame’s high-level thoughts on shift left and where it may have went wrong or run into challengesTyler’s thoughts on the evolution of shift left over the last...


Resilient Cyber w/ Shyam Sankar - The Primacy of Digital Dominance
10/18/2024

In this episode we sit down Shyam Sankar, Chief Technology Officer (CTO) of Palantir Technologies. We will dive into a wide range of topics, from cyber regulation, software liability, navigating Federal/Defense cyber compliance and the need for digital defense of the modern national security ecosystem.

- First off, for those unfamiliar with you and your background, can you tell us a bit about yourself, as well as Palantir?

You're a big proponent on the role that software plays now, and will play in the future when it comes the fifth domain of warfare, cybersecurity...


Resilient Cyber w/ Mark Simos - Cybersecurity Anti-Patterns
10/17/2024

In this episode we sit down with Mark Simos to dive into his RSA Conference talk "You're Doing It Wrong - Common Security AntiPatterns" to dig into several painfully true anti-patterns in cybersecurity and how we often are our own worst enemy.

-

- First off, for those not familiar with you or your background, can you tell us a bit about that.

- So you delivered this talk at RSA, focused on Cybersecurity "Anti-Patterns". How did the talk come about and how was it received by the audience?

We won't...


Resilient Cyber w/ Ross Young - How to Become a CISO
10/08/2024

- First off, for those who don't know you, can you tell us a bit about your background?

- You've been providing a deep dive talk into how to become a CISO. I'm curious, what made you put together the presentation, and how has it been received so far when you've had a chance to deliver it?

- You have broken down what you call "four stages of the journey" that encompasses skills in areas such as Technical, Management, Leadership and Political. This to me comes across as CISO's need to be multidisciplinary professionals with...


Resilient Cyber w/ Helen Oakley - Exploring the AI Supply Chain
10/08/2024

- First off, for folks not familiar with your background, can you tell us a bit about that and how you got to the role you're in now?

- We see rapid adoption of AI and security inevitably trying to keep up, where should folks start?

- There are some really interesting intersections when it comes to AI and supply chain, what are some of them?

- We see a thriving OSS ecosystem around AI, including communities and platforms like Hugging Face. What are some key things to keep in mind here?
<...


Resilient Cyber w/ Jit - Exploring the Emerging ASPM Ecosystem
10/01/2024

In this episode we sit down with Amir Kessler and Aviram Shmueli of AppSec innovator Jit to dive into the complexities of the modern AppSec landscape and explore the emerging Application Security Posture Management (ASPM) ecosystem.

- First off, for folks not familiar with your backgrounds, can you tell us a bit about both of your backgrounds and how you got to the roles you're in now?

- We're seeing a ton of interest in the topic of ASPM in the AppSec space. What do you think has led...


Resilient Cyber w/ Christina Liaghati - Navigating Threats to AI Systems
09/06/2024

- For those that don't know you, can you tell us a bit about your background and your current role?

- I know you help lead the ATLAS project for MITRE, what exactly is ATLAS and how did it come about?

- The AI threat landscape is evolving quickly, as organizations are rapidly adopting GenAI, LLM's and AI more broadly. We are still flushing out some fundamental risks, threats and vulnerabilities to consider. Why is it so important to have a way to characterize it all?

- When it comes to AI Security...


Resilient Cyber w/ Steve Wilson - Securing the Adoption of GenAI & LLM's
08/28/2024

In this episode we sit down with GenAI and Security Leader Steve Wilson to discuss securing the explosive adoption of GenAI and LLM's. Steve is the leader of the OWASP Top 10 for LLM's and the upcoming book The Developer's Playbook for LLM Security: Building Secure AI Applications

-

- First off, for those not familiar with your background, can you tell us a bit about yourself and what brought you to focusing on AI Security as you have currently?

- Many may not be familiar with the OWASP LLM Top 10, can you tell...


Resilient Cyber w/ Snehal Antani - Building and Scaling a Security Startup
08/21/2024

In this episode we sit down with the Founder/CEO of Horizon3.ai to discuss disrupting the Pen Testing and Offensive Security ecosystem, and building and scaling a security startup - from a founders perspective.

From HP, to Splunk to JSOC - all leading to founding Horizon3, Snehal brings a unique perspective of business acumen and technical depth and puts on a masterclass around venture, founding and scaling a team and disrupting the industry!

---

- For those not familiar with your background who Horizon3AI, can you tell us a bit about...


Resilient Cyber w/ Rob Allen - Endpoint Protection, VulnMgt & Zero Trust
08/19/2024

- For those not familiar with you and ThreatLocker, can you tell us a bit about yourself and the ThreatLocker team?

- When we look out at the endpoint protection landscape, what do you feel some of the most pressing threats and risks are?

- There of course has been a big push for Zero Trust in the industry being led by CISA, NIST, and industry. How does ThreatLocker approach Zero Trust when it comes to the Endpoint Protection Platform?

- Another thing that caught my eye is the ThreatLocker Allowlisting capability. We...


Resilient Cyber w/ Chloe Messdaghi - AI Security & the Threat Landscape
08/19/2024

In this episode we sit down with Chloe Messdaghi, Head of Threat Intelligence at HiddenLayer, an AI Security startup focused on securing the quickly evolving AI security landscape. HiddenLayer was the 2023 RSAC Innovation Sandbox Winner and offers a robust platform including AI Security, Detection & Response and Model Scanning.

- For folks now familiar with you or the HiddenLayer team, can you tell us a bit about your background, as well as that of HiddenLayer?

- When you look at the AI landscape, and discussions around securing AI, what is the current state of things as...


Resilient Cyber w/ Travis McPeak - Securing Cloud-native Infrastructure
07/25/2024

- For folks not familiar with you and your background, can you tell us a bit about that?

- How about Resourcely, how did it come about and what problem did you set out to tackle?

- Why do you think Cloud Misconfigurations are still so pervasive, despite being fairly well into the Cloud adoption lifecycle?

- How have organizations traditionally tried to handle secure configurations, in terms of establishing them, maintaining them, monitoring for drift and so on?

- Where do you think we're headed, I know you all recently...


Resilient Cyber w/ Stuart Mitchell Cyber Talent, Recruiting & the Workforce
07/19/2024

- First off, for folks now familiar with your background, can you tell us a bit about yourself?

- You made the leap from working for a firm to founding your own talent and recruiting company. Can you tell us about that decisions and experience?

- Before we dive into specific topics, what are some of the biggest workforce trends you are seeing in cyber currently? I have seen you talk about the pendulum shift from workers to employers on aspects like remote roles, and so on. What is the current dynamic across the cyber...


S6E22: Daniel Shechter - Application Detect & Response (ADR)
#22
07/07/2024

- For folks not familiar with you or the Miggo team, can you tell us a bit about your background?

- How do you define ADR and why do you think we have seen the need for this new category of security tooling to come about?

- Most organizations are struggling with vulnerability overload, with massive vulnerability backlogs and struggles around vulnerability prioritization. Can you share some insights on how you all tackle this problem?

- We're increasingly seeing the AppSec space become more complex, with Cloud, API's, Microservices, IaC and more. What...


S6E21: Christoph Kern - Dissecting Secure-by-Design
06/13/2024

- First off, for those that don't know you or your work, would you mind telling us a bit about your background?

- You recently published a paper titled "Secure-by-Design at Google" which got a lot of attention. Can you tell us about the paper and some of the key themes it emphasizes?

- In the paper you discuss some of the unique aspects of software that are different from mass-produced physical systems. Such as their dynamic and iterative nature. On one hand you mention how the risk of introducing a new defect over time...


S6E20: Joe McCaffrey - Securing the Digital Arsenal of Democracy
06/12/2024

- First off, for folks that don't know you, can you tell us a bit about your current role and background?

- On that same note, can you tell the audience a bit about Anduril, the mission of the organization and some of the current initiatives it is working on?

- What are some of the biggest challenges of being a new entrant in a space such as the DoD, which has longstanding system integrators and large prime contractors who have deep relationships, industry expertise/experience and so on?

- I know you're...


S6E19: Madison Oliver - Open Source & GitHub Advisory Database
06/12/2024

- For those that don't know you or haven't come across you quite yet, can you tell us a bit about your background in tech/cyber and your role with GitHub?

- What exactly is the GitHub Advisory Database and what is the mission of the team there?

- There's been a big focus on vulnerability databases, especially lately with some of the challenges of the NVD. What role do you see among the other vulnerability databases in the ecosystem, including GHAD and how it fits into the ecosystem?

- GitHub has a...


S6E18: Stephen Carter - VulnMgt Modernization & FedRAMP
06/04/2024

- For those don't know your background or Nucleus Security, can you start by telling us a bit about both?

- You have experience and a background in the Federal environment, and Nucleus recently achieved their FedRAMP authorization, can you tell us a bit about that process?

- When you look at the Federal/Defense/IC VulnMgt landscape, what are some of the biggest problems from your experience and where do you think innovative products and solutions can help?

- Going broader, we have seen a recent uptick in the interest around VulnMgt...


S6E17: Jimmy Mesta - Kubernetes, Runtime and Supply Chains
06/04/2024

- For those unfamiliar, please tell us a bit about your background, as well as about RAD Security. What do you all focus on and specialize in?

- Your team recently was part of the RSAC Innovation Sandbox. Can you tell us a bit about that experience, and being able to highlight the innovative capabilities of RAD to such a key audience?

- You recently published a comprehensive resource on Kubernetes Security Posture Management (KSPM), what are some of the key items in there folks need to be focusing on?

- The RAD...


S6E17: Steve Carter - Vulnerability Management Modernization & FedRAMP
#17
05/31/2024

- For those don't know your background or Nucleus Security, can you start by telling us a bit about both?

- You have experience and a background in the Federal environment, and Nucleus recently achieved their FedRAMP authorization, can you tell us a bit about that process?

- When you look at the Federal/Defense/IC VulnMgt landscape, what are some of the biggest problems from your experience and where do you think innovative products and solutions can help?

- Going broader, we have seen a recent uptick in the interest around VulnMgt...