A CyberRisk Alliance Production For Security Professionals, By Security Professionals. #InfoSec #CyberSec #Podcast #Livestream

G-Unit Studios, Warwick, RI
Fire stations exist because fires are a persistent threat. They don't disappear just because a community hasn't had a major fire recently. Cybersecurity works in a similar way. The goal isn't to eliminate every possible threat forever. It's to build a collective capability for dealing with a problem that isn't going away. Simple analogies can make that reality easier to communicate. What analogy best explains cybersecurity to a non-technical audience? #Cybersecurity #SecurityLeadership #CyberRisk
46
Security teams can spend millions on SIEMs, tools, and people—and still struggle to explain the value to decision makers. Part of the problem is visibility. Many security incidents never become public, meaning executives may only see a fraction of the problems security teams are managing. How do you make the value of security understandable to the people controlling the budget? #Cybersecurity #SecurityLeadership #SIEM
60
Cybersecurity keeps changing. The problems don't always change with it. CISOs still need help figuring out what to do, getting technology deployed, and actually operating it once it's in place. The conversation here is about addressing all three instead of treating them as separate problems. #Cybersecurity #CISO #InfoSec
126
Old accounts don’t always disappear when people, software, or automated systems move on. Former employees, forgotten service accounts, and even agentic AI can leave credentials behind after their original purpose is gone. Those “ghost accounts” may remain active without anyone realizing they still exist. How confident are you that every identity in your environment still has a legitimate owner and purpose?
130
An urgent warning called for Kiteworks users to shut down their servers in response to a reported credible threat of a coordinated cyberattack. Kiteworks is used for secure file sharing, transfers, and movement of sensitive data. Taking a production server offline is a serious operational action, but so is leaving potentially exposed infrastructure running during an active threat. The discussion highlights the tension security teams face during a Sev 1 incident: move immediately, while still maintaining authorization and change control. When an urgent vendor warning calls for shutdown, how much process should remain before security teams pull the plug?
1
756
AI is supposed to help security teams find the bad stuff. But without enough context, it can also recreate a problem the industry has spent years trying to reduce: false positives and false negatives. Both matter. Too many false positives create noise, while false negatives can allow real incidents to slip through. How much context should AI have before we trust its security findings? #AISecurity #Cybersecurity #ThreatDetection
1
117
Not all agent drift is a security problem. Upgrades and other known events can legitimately change how a system behaves. The challenge is distinguishing that expected drift from unexplained changes—and deciding how much variance is acceptable before something deserves investigation. As agent systems evolve, how much drift should security teams tolerate? #AISecurity #AgenticAI #Cybersecurity
2
160
AI adoption may be following a familiar path. Business teams moved faster than IT during the early cloud era, and organizations eventually found themselves managing huge cloud environments and spending. Now AI is moving just as quickly. The challenge is protecting intellectual property without getting in the way. Can companies put security around AI without putting the brakes on it? #AI #Cybersecurity #CISO
1
132
Some public-sector technology teams have just two people. They’re responsible for running the technology environment while also trying to bolt on cybersecurity, vulnerability management, and everything else that comes with it. Even larger counties may lack a dedicated cyber team. When cybersecurity keeps expanding, what can a small team realistically cover? #Cybersecurity #PublicSector #VulnerabilityManagement
120
A coding agent shouldn’t have access to everything your developer has. Giving coding agents their own low-privilege identities limits what a compromised agent or malicious plugin can reach. The underlying idea is simple: reduce the value of the environment an attacker can access. It’s a basic security principle, but how often are organizations actually applying least privilege to AI coding agents? #AIAgents #AppSec #Cybersecurity
1
1
2
159
What happens if AI ever becomes conscious? The possibility raises questions that go beyond cybersecurity or AI governance. If an artificial system were genuinely conscious, would it deserve rights or some form of moral consideration? That debate is already emerging in AI research, even though there is currently no established evidence that today’s AI systems are conscious. Where should the line between technology and personhood be drawn? #ArtificialIntelligence #AGI #AISafety
117
An AI agent may act autonomously, but accountability still has to trace back to a human. One approach described here ties services and accounts back to people and establishes a clear lineage when agents create sub-agents. The organization also used real incidents as teaching moments without publicly shaming individuals. What should human accountability look like as AI agents become more autonomous? #AIAgents #AISecurity #IdentitySecurity
120
An AI-generated intelligence report could have consequences far beyond a chatbot conversation. The story describes an alleged incident in which an AI-generated report incorrectly identified material aboard a ship, potentially prompting a serious military response before the error was discovered. The larger concern is straightforward: what happens when AI-generated misinformation enters high-stakes decision-making? How much verification should be required before an AI-generated claim can trigger action? #AI #AISafety #Cybersecurity
118
You can’t treat every vulnerability as a code-patching emergency. The argument here is to focus security resources on what is actually being exploited, while using controls at the firewall, identity, and other layers to reduce risk. Patching still matters when it’s appropriate and possible—but what changes when the goal shifts from “fix every vulnerability” to “reduce the organization’s actual exposure”? #Cybersecurity #AppSec #RiskManagement
134
A document uploaded to an AI model can create a security problem you may not immediately see. Organizations need to know when sensitive documents are being pasted or uploaded, what those documents contain, and what impact that exposure could have. That requires detection tooling alongside clear governance. As AI use expands, what should organizations be monitoring inside documents before they reach a model? #AIsecurity #Cybersecurity #DataProtection
114
Three or four technologies doing similar jobs? That’s the security-stack problem this conversation gets into: finding crossover, identifying duplication, and figuring out which capabilities actually belong in the stack. #Cybersecurity #CISO #SecurityOperations
125
The weirdest consequence of AI writing might not be bad writing. It might be people forgetting how to write at all. And if that happens, knowing how to put words together yourself could become a strangely valuable skill. #AI #Writing #GenerativeAI
1
161
AI was supposed to help us get more done. Instead, one side effect is brutally simple: more things to do. More projects. More expectations. Same number of hours. #AI #Productivity #FutureOfWork
1
1
128
Some attackers don't want to stay hidden. They want to get in and break something as fast as possible. That changes the defensive problem. When attackers are racing defenders to cause damage, speed becomes critical—and AI could give defenders an advantage. How should security teams prepare for attacks where every second matters? #Cybersecurity #AI #CyberWarfare
1
154
AI agents are built like Legos. A plugin here. A skill there. An MCP, a model, an environment. Even when every piece comes from a name-brand source, there’s a problem: you don't necessarily control the pieces—or what happens when they’re assembled together. #AIAgents #Cybersecurity #AISecurity
173