The ITSPmagazine Podcast

Founded in 2015, ITSPmagazine began as a vision for a publication positioned at the critical intersection of technology, cybersecurity, and society. What started as a written publication has evolved into a comprehensive repository for all their content—podcasts, articles, event coverage, interviews, videos, panels, and everything they create. This is where Sean Martin and Marco Ciappelli talk about cybersecurity, technology, society, music, storytelling, branding, conference coverage, and whatever else catches their attention. Over a decade of conversations exploring how these worlds collide, influence each other, and shape the human experience. This is where you'll find it all.

  1. 1d ago

    Vulnerability Backlogs Can Finally Reach Zero | A Brand Spotlight Conversation with Ondrej Vlcek, Co-Founder and CEO of AISLE | Hosted by Sean Martin

    Security leaders count open vulnerabilities in the hundreds of thousands, and in some organizations the number runs past a million. Ondrej Vlcek, Co-Founder and CEO of AISLE, describes teams with no practical route through that backlog while attackers use automation to shrink the time between a disclosure and a working exploit. The question worth asking is what a program looks like when remediation moves at the same speed as exploitation. What makes AI-driven remediation different from static code analysis? Reasoning replaces pattern matching. Linters and commercial scanners flag code that resembles a known error shape, while a reasoning model infers what the developer intended, compares that intent against the actual implementation, and evaluates how the gap could be abused. Ondrej Vlcek points to business logic flaws, timing errors, and race conditions as the classes that pattern matching leaves untouched. The judgment behind AISLE comes from a long run in the industry. Ondrej Vlcek wrote device drivers for Windows 95 in 1995 at a seven-person antivirus company called Avast, stayed more than twenty-five years, moved through CTO and COO into the CEO seat, and took the company public before its sale to NortonLifeLock in 2022. He co-founded AISLE in 2024 with Jaya Baloo, a three-time public company CISO, and Stanislav Fort, an AI researcher who worked at DeepMind and Anthropic. Why does the software supply chain deserve the larger share of attention? Because most of the code in a running application was written somewhere else. Ondrej Vlcek puts the typical enterprise application at roughly ten percent first-party code and ninety percent open source and dependency code, which is also level ground for an attacker reading the same source and pointing the same models at it. Reachability analysis becomes the deciding factor, separating the vulnerable functions your code actually calls from the thousands of transitive dependencies it never touches. For first-party code, AISLE closes the loop differently: read the documentation, the architectural material, and the threat model, then generate a patch aligned with the project's own conventions and test it automatically. The standard Ondrej Vlcek sets is a fix that reads as though a human maintainer wrote it. The customer spread runs from embedded firmware at Bose to smart contracts at the Ethereum Foundation, where heavily audited and sometimes formally verified code still benefits from another set of checks because the systems touch money flows directly. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUEST Ondrej Vlcek, Co-Founder and CEO of AISLE On LinkedIn: https://www.linkedin.com/in/ondrejvlcek/ RESOURCES Learn more about AISLE: https://aisle.com Meet AISLE at Black Hat and DEF CON in Las Vegas: https://aisle.com/black-hat The AISLE platform: https://aisle.com/platform AISLE CVE discoveries: https://aisle.com/cve-discoveries Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS ondrej vlcek, aisle, sean martin, brand story, brand marketing, marketing podcast, brand spotlight, vulnerability management, vulnerability remediation, agentic ai, cyber reasoning system, software supply chain security, reachability analysis, open source security, application security, first-party code, third-party dependencies, static code analysis, zero-day vulnerabilities, ai in cybersecurity, code patching, embedded firmware security, smart contract security Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

    Vulnerability Backlogs Can Finally Reach Zero | A Brand Spotlight Conversation with Ondrej Vlcek, Co-Founder and CEO of AISLE | Hosted by Sean Martin
  2. 1d ago

    Agentic Security Changes Everything | An On Location Conversation at Infosecurity Europe 2026 with John Sotiropoulos and Rock Lambros

    Sean Martin catches John Sotiropoulos and Rock Lambros at the end of the OWASP GenAI Security Summit, held alongside Infosecurity Europe 2026 at ExCeL London. Both are deep in the standards work: John Sotiropoulos co-leads the OWASP Agentic Security Initiative and sits on the board of the OWASP GenAI Security Project, and Rock Lambros serves as Director of AI Standards and Governance at Zenity and co-leads the OWASP Top 10 for LLM 2026 update. The headline from the day is the launch of the Agentic Security Council, bringing Oxford University, Queen's University Belfast, CSIT, and other research institutions into the same room as practitioners and industry. John Sotiropoulos frames the reasoning bluntly: content on its own does not create change. Papers and Top 10 lists matter, but they only matter if the people building and defending systems can act on them. The number that reframes everything is twenty-two seconds. That is the average time from an initial access event to the next attacker action, down from eight hours. John Sotiropoulos puts the question directly to anyone still running a human-speed playbook: how do you respond to that? A panel on incident response with participants from AWS and Microsoft, a keynote from Microsoft's National Security Officer, and a walkthrough of the State of Agentic Security and Governance report all point at the same shift toward runtime security. Rock Lambros brings a different kind of grounding. For the first time in the four-year history of the OWASP Top 10 for LLM, the update draws on a corpus of reported incidents rather than opinion and community vote alone. It is one data point among several, but it is data, and that changes what the list can claim. A panel with the heads of AI security at Deloitte supplies the operational counterweight. As one of them puts it, security has to stop being the Ministry of No, because people will route around it and ship anyway. The report's adoption tiers and maturity levels exist for exactly that reason: security that lives only inside a PDF is not security. The invitation from both John Sotiropoulos and Rock Lambros is the same. Join the work. Research, red teamers, defenders, builders, and SecOps all looking at one view of what is actually happening is the only version of this that scales to machine speed. ⬥HOST⬥ Sean Martin, CISSP | Co-Founder, ITSPmagazine & Studio C60 | Host, Redefining CyberSecurity Podcast & Music Evolves Podcast | https://www.seanmartin.com/ ⬥GUESTS⬥ John Sotiropoulos, Deep Cyber | Co-Lead, OWASP Agentic Security Initiative; Board Director, OWASP GenAI Security Project | On LinkedIn: https://www.linkedin.com/in/jsotiropoulos/ Rock Lambros, Director of AI Standards and Governance, Zenity; Founder, RockCyber | Co-Lead, OWASP Top 10 for LLM 2026 | On LinkedIn: https://www.linkedin.com/in/rocklambros/ ⬥RESOURCES⬥ Infosecurity Europe 2026 is taking place June 2-4, 2026 | ExCeL London. Follow our coverage: https://www.itspmagazine.com/infosecurity-europe-2026-infosec-london-cybersecurity-event-coverage OWASP GenAI Security Project | https://genai.owasp.org Contribute to the OWASP GenAI Security Project | https://genai.owasp.org/contribute The Future of Cybersecurity Newsletter | https://www.linkedin.com/newsletters/7108625890296614912/ Redefining CyberSecurity Podcast | https://www.seanmartin.com/redefining-cybersecurity-podcast On Location | https://www.itspmagazine.com/on-location 🥁 🎶 A very big THANK YOU to our Infosecurity Europe 2026 Full Coverage Sponsors: Corelight · Qualys · Sumo Logic 👏 👏 👏 ⬥KEYWORDS⬥ sean martin, john sotiropoulos, rock lambros, infosecurity europe 2026, owasp, genai security project, agentic security, agentic security initiative, agentic security council, owasp top 10 for llm, ai security, incident response, runtime security, ai governance, zenity, rockcyber, deep cyber, dwell time, secops, red teaming, on location, itspmagazine Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

    Agentic Security Changes Everything | An On Location Conversation at Infosecurity Europe 2026 with John Sotiropoulos and Rock Lambros
  3. 3d ago

    The Business Decision Hiding Inside FedRAMP's Consolidated Rules for 2026 | A Brand Story Conversation with Jason Ford and Michael Parisi of Steel Patriot Partners | Hosted by Sean Martin

    FedRAMP has changed before. What makes the Consolidated Rules for 2026 different is that the dates are on the calendar and the fence sitters have run out of runway. Jason Ford, Co-Founder and CEO of Steel Patriot Partners, has been inside the program since Rev 3 in 2013. Michael Parisi, Chief Growth Officer, comes at it from the business side. Together they map what changes and, more usefully, what it means for the decision in front of a provider right now. So what actually changes? The program consolidates into two paths, 20X and Rev 5. FedRAMP Ready moves to legacy status. Class A, B, and C pipelines open across a thirty to sixty day window, mandatory adoption arrives January 1, and new Rev 5 certifications close on June 11, 2027. Authorized becomes certified. Jason Ford also points out where the rules live: fedramp.gov, hosted in GitHub, which means they move with a commit. Reading them once is not tracking them. Why did FedRAMP need to change at all? Michael Parisi frames it as a supply problem. Agencies and primes have been working from a limited and aging set of technologies while better tools sat outside a process that was slow, rudimentary, and expensive. The action was warranted. His follow-up question gets less airtime: if the process moved faster, did responsibility move with it, and does the stakeholder now holding that due diligence know it yet? The engineering shift is real and it is the part most teams see coming. Jason Ford describes RMF thinking giving way to continuous DevSecOps, proving compliance in real time rather than at a point in time. Vulnerability remediation is where the compression bites. CISA's updated guidance drops severity score as the driver in favor of stepped prioritization, and windows that used to run 30, 60, and 90 days now land closer to three to twenty-one. What does this cost a business past the budget line? Time and capacity. 20X is faster than a Rev 5 process that once ran eighteen months, but faster is not instant. Retraining a couple hundred users inside a thousand-person organization is not a small endeavor, and if the transition eats half of the organization's capacity for a year, that is half as much capacity aimed at the business paying for it. Jason Ford is not arguing against the move. He is arguing that disruption belongs inside the decision. Then there is the internal work almost nobody has started. Mapping an existing Rev 5 ATO scope into a new certification level is not clear-cut, and past the mapping, marketing and sales both need re-education. Michael Parisi describes building a translation layer for customers: here is what we provided before, here is what it is now, and this change came from the program rather than from any reduction in assurance. Roughly half the time, Steel Patriot Partners tells organizations not to pursue certification at all. Michael Parisi treats that as one of the more valuable things the firm does. The opposite failure shows up just as often, with companies preparing to spend heavily on 20X because it sounds quicker and cheaper, when the agency or prime they are chasing expects a certification level. A lower bar only helps if the buyer accepts it. Where should a business start? With the business conversation. Michael Parisi notes the answer does not have to be yes or no today; it can be a maybe with defined trigger points. Jason Ford closes on posture: come with an open mind, and do not hand a multi-year commitment to a language model whose guardrails and training are not built for that call. Or, shorter: don't wait, and don't go it alone. Steel Patriot Partners built a three-question starting point for that first conversation at https://www.steelpatriotpartners.com/find-your-path. This is a Brand Story. A Brand Story is a ~35-40 minute in-depth conversation designed to tell the complete story of the guest, their company, and their vision. Learn more: https://www.studioc60.com/creation#full GUESTS Jason Ford, Co-Founder and Chief Executive Officer, Steel Patriot Partners On LinkedIn: https://www.linkedin.com/in/jason-ford-5ab206/ Michael Parisi, Chief Growth Officer, Steel Patriot Partners On LinkedIn: https://www.linkedin.com/in/michael-parisi-4009b2261/ RESOURCES Learn more about Steel Patriot Partners: https://www.steelpatriotpartners.com/ FedRAMP's Consolidated Rules for 2026: What It Means for Cloud Providers: https://resources.steelpatriotpartners.com/fedramps-consolidated-rules-for-2026 Find Your Path, a three-question starting point for ISO, CMMC, and FedRAMP decisions: https://www.steelpatriotpartners.com/find-your-path Complimentary ROI Workshop: https://www.steelpatriotpartners.com/roi-workshop Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS jason ford, michael parisi, steel patriot partners, sean martin, brand story, brand marketing, marketing podcast, fedramp, fedramp consolidated rules for 2026, fedramp 20x, rev 5, fedramp certification classes, cloud service provider compliance, federal compliance, cisa vulnerability remediation, continuous monitoring, devsecops, ato, 3pao, govramp, cmmc, grc, federal marketplace, compliance roi Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

    The Business Decision Hiding Inside FedRAMP's Consolidated Rules for 2026 | A Brand Story Conversation with Jason Ford and Michael Parisi of Steel Patriot Partners | Hosted by Sean Martin
  4. 4d ago

    FedRAMP First: Modernizing the Defense Supply Chain Without Cutting Corners | A Brand Feature Conversation with Michael Parisi of Steel Patriot Partners and Jason LaPointe of Exostar

    For companies in the defense industrial base, a compliance deadline is not paperwork. It is the difference between winning contracts and watching them stall. In this Brand Feature, Jason LaPointe, Chief Technology Officer at Exostar, and Michael Parisi, Chief Growth Officer at Steel Patriot Partners, walk through what it takes to get FedRAMP ready without cutting corners. Exostar was born out of a consortium that included Boeing and Lockheed Martin, and its FedRAMP-moderate posture lets smaller suppliers keep working on Department of War contracts. How does that work? Instead of moving every server and mailbox into a secure boundary, a supplier inherits roughly 80% of the controls from Exostar, which shrinks the scope of its own CMMC audit considerably. The clock was real. At the time, a November transition date loomed, after which many suppliers could no longer self-attest. That specific timeline has since been paused, but the pressure to prove readiness has not gone away. Exostar needed to show it was FedRAMP-moderate and ready for an audit, and working with Steel Patriot Partners, the team pulled a January target in by nearly three months, not by skipping steps, but by moving with confidence. Why build a new platform instead of retrofitting the old one? Jason LaPointe describes a platform first initiative: build the new compliant home, then migrate customers into it. Trying to modernize inside a live production environment would have been disruptive, so the team built alongside rather than on top, which freed them to re-architect and retool without breaking customers. Michael Parisi frames the engagement as embedding, not staff augmentation. Steel Patriot Partners plugged directly into the product team through daily standups and leadership calls, delivered infrastructure as code and deployment pipelines, and kept the work with US citizens, a requirement once controlled unclassified information is in play. What makes an audit go smoothly? Preparation that extends to how questions get answered. Jason LaPointe compares the audit to a deposition, where an unsolicited comment hands an assessor somewhere new to go. Michael Parisi, who spent years in the assessor's seat and ran the practice for a large C3PAO, explains why knowing the auditors and presenting information cleanly protects the outcome. The business math is unforgiving. Miss the audit window and millions in direct contracts can be exposed, while auditors book out six to eight months. Exostar cleared it with a clean, no POA&M result, and the business is now seeing tailwinds through initiatives like Golden Dome. The lesson Jason LaPointe offers other technology and security leaders is about temperament. Every part of the organization gets touched, from R&D to HR to finance, and the willingness to change quickly becomes the governor on success. Having a clear voice at the table for what good looks like, as Steel Patriot Partners provided, is what accelerates the decisions. This is a Brand Feature. A Brand Feature is a ~30 minute in-depth conversation designed to go deep on a company's story, solutions, and customer success. Learn more: https://www.studioc60.com/creation#feature GUESTS Jason LaPointe, Chief Technology Officer, Exostar Website: https://www.exostar.com/ LinkedIn: https://www.linkedin.com/in/jasonlapointe Michael Parisi, Chief Growth Officer, Steel Patriot Partners Website: https://www.steelpatriotpartners.com/ LinkedIn: https://www.linkedin.com/in/michael-parisi-4009b2261/ RESOURCES Learn more about Exostar: https://www.exostar.com/ Aerospace and Defense solutions from Exostar: https://www.exostar.com/industries/aerospace-defense/ Learn more about Steel Patriot Partners: https://www.steelpatriotpartners.com/ Find Your Path with Steel Patriot Partners: https://steelpatriotpartners.com/find-your-path/ Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS Jason LaPointe, Michael Parisi, Exostar, Steel Patriot Partners, Sean Martin, brand story, brand marketing, marketing podcast, brand feature, FedRAMP, FedRAMP-moderate, CMMC, CMMC 2.0, defense industrial base, DIB, controlled unclassified information, CUI, compliance inheritance, C3PAO, FedRAMP audit, platform modernization, GCC High, Department of War, defense supply chain, cybersecurity compliance Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

    FedRAMP First: Modernizing the Defense Supply Chain Without Cutting Corners | A Brand Feature Conversation with Michael Parisi of Steel Patriot Partners and Jason LaPointe of Exostar
  5. 5d ago

    Tech Trailblazers: Recognition That Reaches the Whole Team | An Interview with Rose Ross | An Analog Brain In A Digital Age With Marco Ciappelli

    PODCAST EPISODE | An Analog Brain In A Digital Age With Marco Ciappelli Fifteen years ago, Rose Ross brought a client an idea for an awards program built specifically for enterprise tech startups. The client passed. She built it herself — and the Tech Trailblazers have been running ever since, independent, judged by practitioners, and open for entries until 3 September. 📺 Watch | 🎙️ Listen | marcociappelli.com There are couches on the upper floor at ExCeL London where the glass opens onto the water, and every June I promise myself I will sit there and have one unhurried conversation with somebody worth an hour. Every June I walk past them carrying a bag of microphones. Rose Ross and I both did exactly that at Infosecurity Europe, so we recorded this weeks later and six thousand miles apart, and it worked out fine. Good ideas survive bad timing. Rose knows something about that. Fifteen years ago she brought a client an idea — an awards program for enterprise tech startups, the companies that had no category of their own. The client passed. She built it herself, gave it a better name than Global Innovation Awards, and asked Joe Baguley to judge. He said yes immediately. When someone like Joe says yes, she told me, you know you are onto something. Fifteen years later the Tech Trailblazers are still running, still independent, and now cover everything from storage and security to quantum and robotics, plus categories for the founders and the investors behind them. I have been around enough award programs to have opinions. Plenty of them are a night out: you put on the jacket, you eat the food, you take the photo, and by Monday the trophy is a doorstop. What Rose built works differently, and the difference is by design. Start with who does the scoring. Rose stays out of it completely, on the reasoning that nobody needs a PR person picking winners — she said it before I could. The judges are practitioners who know a category well enough to read a claim and tell whether it holds. Startups are scored against startups, apples with apples and pears with pears, so a young company is never dropped into a popularity contest against an incumbent. The criteria cover innovation, market readiness and leadership, and then each judge gets a free card: points awarded on instinct alone. I like that card more than I probably should. It concedes that expertise is partly something you feel and cannot fully write down, which is a rare concession in an industry that would prefer everything be a dashboard. Then the shortlists go in front of a thousand CIOs, CISOs and technology buyers around the world, and the promotion keeps going long after the announcement — a weekly roundup of what the alumni are doing, coverage where it can be earned, a podcast recording with Rose for every winner. Risk Ledger took the security category a couple of years back and has just closed a $24 million Series B. The award keeps working after the award. The best answer of the conversation came from a simple question. I asked what a win is actually worth. Rose moved through the exposure and the investor attention quickly, then spent the rest of it on the team. Not the founder. The engineers, the designers, the support people who put in eighteen months of long hours and rarely hear from anyone outside their own building that the work was good. That part, she said, is priceless. I grew up in a city built by workshops. The Florentine bottega was a collective — the master, the apprentices, the hands that ground the pigment and prepared the panels — and the good ones understood that the work belonged to the room. Recognition is old technology. Older than any category Rose runs. An award engineered so that it reaches past the founder and lands on everyone who built the thing is doing something more useful than handing out a doorstop. Near the end I asked whether technology today is money-driven or mission-driven. She declined to pick, which was the right call. Most people want both. She has never interviewed a founder who was in it purely for the exit. And without something worth caring about, you do not survive the years when the payoff is still a maybe. Entries close 3 September at techtrailblazers.com. Firestarters is free for the earliest-stage startups. Sean Martin is on the judging panel this year, so put your best in front of him. More conversations like this one, in your inbox: subscribe to the newsletter at marcociappelli.com. Who on your team should be hearing this week that the work was good? Let's keep thinking. — Marco Co-Founder ITSPmagazine & Studio C60 | Creative Director | Branding & Marketing Advisor | Personal Branding Coach | Journalist | Writer | Podcast: An Analog Brain In A Digital Age ⚠️ Beware: Pigs May Fly | 🌎 LAX🛸FLR 🌍 About Marco Marco Ciappelli is Co-Founder & CMO of ITSPmagazine, Co-Founder & Creative Director of Studio C60, Branding & Marketing Advisor, Personal Branding Coach, Journalist, Writer, and Host of An Analog Brain In A Digital Age podcast. Born in Florence, Italy, and based in Los Angeles, he explores the intersection of technology, society, storytelling, and creativity — with an analog brain, in a digital age. 🌎 marcociappelli.com | itspmagazine.com | studioc60.com About the Guest Rose Ross is the Founder and Chief Trailblazer of the Tech Trailblazers Awards, the first independent awards program built specifically for enterprise technology startups, which she launched in 2012. Fifteen years on, the program spans cybersecurity, cloud, storage, networking, AI, quantum and robotics, alongside CxO, investment and diversity categories recognizing the people behind the companies. Entries are self-nominated and scored by a panel of industry practitioners, and shortlists go in front of a wider group of CIOs, CISOs and senior technology buyers worldwide. Winners receive continued promotion through the program's alumni network and a podcast recording with Rose. She is also the Founder of Omarketing, the London-based PR and marketing consultancy specializing in enterprise technology, which she started in 1998 after beginning her career in-house with British tech startups and NASDAQ-listed technology companies. Omarketing works across cybersecurity, cloud, storage, AI and adjacent B2B technology markets. Rose is a co-founder of TechBritannia and has been a Tech London Advocate since 2016. She studied International Business and German at Aston University, and describes herself as a technologist by osmosis. The 2026 Tech Trailblazers Awards are open to companies under ten years old and no further than Series C funding. The Firestarters categories are free to enter for pre-VC startups. Submissions close 3 September 2026. ITSPmagazine co-founder Sean Martin sits on the 2026 judging panel. LinkedIn | Tech Trailblazers Awards | Omarketing Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

    Tech Trailblazers: Recognition That Reaches the Whole Team | An Interview with Rose Ross | An Analog Brain In A Digital Age With Marco Ciappelli
  6. Jul 15

    Your Team Is Already Using AI. They Just Won't Tell You. | Priyanka Dave, PhD | PODCAST EPISODE | An Analog Brain In A Digital Age With Marco Ciappelli

    PODCAST EPISODE | An Analog Brain In A Digital Age With Marco Ciappelli Every organization has a policy on AI. Most of them are unwritten, unspoken, and enforced by silence. Priyanka Dave — behavioral scientist, dual PhD, and the person responsible for teaching an entire university system how to work with these tools — explains what actually happens inside a company that refuses to say the word out loud. 📺 Watch | 🎙️ Listen | marcociappelli.com This conversation sat in my queue for months. I recorded it back when the show still went by another name, filed it under soon, and then buried it under travel, deadlines, and the small avalanche of everything else. So: my apologies to Priyanka Dave, who deserved better timing. What I did before publishing was listen to the whole thing again, half expecting it to have gone stale — AI conversations have the shelf life of fresh milk — and it hadn't. Not one line. That is either a compliment to her or an indictment of the rest of us. Possibly both. Here is what has held up. Priyanka Dave is a behavioral scientist with two doctorates and the unglamorous job of teaching a large public institution how to actually use these tools. Her diagnosis is not about the technology. It is about what happens when nobody in charge will say anything about it. An organization that stays quiet on AI does not prevent its people from using AI. It only stops hearing about it. Employees keep working the way they were already working — with a chatbot open in the next tab — and they simply stop mentioning it. The tool doesn't go away. The conversation does. I cover cybersecurity for a living, so I recognized this immediately. It's shadow IT with a better vocabulary. And shadow IT was never a technology failure — it was a communication failure that grew teeth. The same thing is happening now, except the data walking out the door isn't on a USB stick. It's being pasted into a text box by someone who was never told where the line is, because nobody in the building was willing to draw one. The schools got there first, and got it wrong first. Ban it, some of them announced, and the students used it anyway — badly, secretly, without a shred of judgment about when the machine is confidently wrong. Prohibition didn't produce abstinence. It produced amateurs. It always does. So Priyanka's answer is education, and here I pushed, because education has a recursion problem. If the leader is supposed to model good AI use, who taught the leader? I asked her: who educates the educator? Her answer was refreshingly unromantic. Nobody, mostly. Budgets get cut, leadership development is the first line item to go, and the executives left standing are quietly teaching themselves at night so they don't look foolish in the morning. The people expected to be the role models are improvising just like everyone else — they're only better dressed while doing it. And this is where the real cost lands. She cited the research: people leave organizations that offer them nowhere to grow. Nobody wants to miss the train. If your company won't teach you the thing that everyone agrees is coming, you will go somewhere that will — and you will take your best years with you. The company that avoided the awkward conversation about AI doesn't just end up with a hidden problem. It ends up with a smaller team. Her three tips for leaders are almost embarrassingly simple, which is how you know they're good. Ask your people what excites them about AI. Then ask what scares them. Then use the thing yourself, out loud, where everyone can see you double-check its work. Which brings me to the word I've been chewing on since we hung up: sensemaking. Priyanka listed it among the capabilities leaders need. I called it common sense, and she let me get away with it. It means not pressing the easy button. It means remembering that the thing on the other side of the screen has no context, no stake, and no idea what it is saying — even when it sounds like it does. It is not your friend. It is not your enemy. It is something else, and we haven't named it yet. So the fear was never really about the machine, was it? It was about being the last person in the room who wasn't told how to use it. Priyanka's work and writing are linked below. Subscribe to the newsletter at marcociappelli.com. Let's keep thinking. — Marco Co-Founder ITSPmagazine & Studio C60 | Creative Director | Branding & Marketing Advisor | Personal Branding Coach | Journalist | Writer | Podcast: An Analog Brain In A Digital Age ⚠️ Beware: Pigs May Fly | 🌎 LAX🛸FLR 🌍 About Marco Marco Ciappelli is Co-Founder & CMO of ITSPmagazine, Co-Founder & Creative Director of Studio C60, Branding & Marketing Advisor, Personal Branding Coach, Journalist, Writer, and Host of An Analog Brain In A Digital Age podcast. Born in Florence, Italy, and based in Los Angeles, he explores the intersection of technology, society, storytelling, and creativity — with an analog brain, in a digital age. 🌎 marcociappelli.com | itspmagazine.com | studioc60.com About the Guest Priyanka Dave, MBA, PhD leads enterprise-wide workforce transformation, building future-ready capability through strategic upskilling, inclusive learning, and organizational change. She currently serves as Upskilling Lead at Oregon State University, where her work on the university's Administrative Modernization Program earned the Outstanding Applied OBM Intervention Award from the Organizational Behavior Management Network at the Association for Behavior Analysis International annual convention. Her career spans more than a decade across IT, aerospace, pharmaceutical, and higher education, in both the United States and India, with measurable results in Learning & Development, Change Management, and Organizational Development. She began in human resources in India, earning a master's degree and her first doctorate there, before moving to the United States to complete a second PhD in Industrial/Organizational Behavior Management at Western Michigan University. She also holds an MBA. Dave partners with executives and cross-functional teams to design enterprise upskilling programs that close critical skill gaps, lead leadership development and performance improvement initiatives, and embed scalable learning strategies that sustain workforce readiness. She is a published contributor to the academic literature on performance feedback in organizations, and writes on AI adoption, digital transformation, and workforce capability for outlets including CIO and HR Executive. LinkedIn Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

    Your Team Is Already Using AI. They Just Won't Tell You. | Priyanka Dave, PhD | PODCAST EPISODE | An Analog Brain In A Digital Age With Marco Ciappelli
  7. Jul 11

    The Flood Made Everything Free. So Now We Pay for Proof. | Lens Four by Sean Martin | Read by TAPE9

    ⬥EPISODE NOTES⬥ Tidal is about to stop paying royalties on any track it judges to be fully machine-made. Frame that as a music story and you miss the shift underneath it. By Deezer's own detection, roughly 75,000 AI-generated tracks now arrive every day, about 44% of everything uploaded, yet that same AI music is only 1 to 3 percent of what people actually play, and around 85% of those streams are flagged as fraudulent. The flood is not an audience. It is an attack on a shared payout. This edition follows one pattern across six industries: when the cost of generating something collapses toward zero, platforms stop paying for output and start paying for proof of human origin. Tidal cuts AI royalties. The Authors Guild sells a "Human Authored" badge for ten dollars a title. YouTube demonetizes "inauthentic" content. curl killed its bug bounty after a flood of AI slop, then reopened when the slop got good. And where no gatekeeper owns the payout, hiring, the open web, the scientific record, the flood just degrades the mechanism until no one trusts it. In this edition of Lens Four: 🔹 Tidal's July 15 policy ends royalty attribution and direct-to-fan sales for fully AI-generated tracks, a payout decision, not a content ban. 🔹 Deezer takes in about 75,000 AI tracks a day (44% of uploads), up from roughly 10,000 a day at the start of 2025, while human uploads barely moved. 🔹 The paradox that reframes the debate: AI music is 44% of uploads but 1 to 3 percent of listening, and about 85% of those streams are fraudulent. 🔹 The first US criminal AI streaming-fraud case: Michael Smith pleaded guilty after collecting more than 8 million dollars in royalties from hundreds of thousands of AI songs and roughly 1,000 bot accounts. 🔹 curl shut down its bug bounty under a flood of AI vulnerability reports, then reopened a month later because the AI reports got good enough to read. Cutting the money did not cut the volume. 🔹 The counter-case: recruiters see about 11,000 job applications submitted to LinkedIn every minute, up 45% in a year, with no single payout to switch off. 🔹 Provenance becomes a product: Suno (2 million subscribers, about 7 million songs a day) adds identity-verified voice cloning while the Authors Guild sells human certification. 🔹 The danger tier: roughly 20% of AI-recommended software packages do not exist (slopsquatting), and close to 10% of cancer papers show paper-mill signatures. 🔹 The language turned first: Merriam-Webster made "slop" its 2025 word of the year, and YouTube quietly renamed "repetitious" content to "inauthentic." 🔹 Human filters see it clearest: DJ Sam Young asks why we need fifty versions of the same thing, and producer Gregoire Gensollen says he will remember the human moments, not the tool. Fourth Lens: The three lenses meet at one move. Platforms re-price payouts around human origin, the market builds products that certify it, and the language teaches us to want it. That is not a defense of artists, it is a paywall around authenticity, sold as virtue, and it is arriving before audiences even asked for it. Reality has come at a premium, exactly as predicted in 2017. So the real question is not whether the real is worth more. It is this: when proof of human becomes a product, who is making the money, and who handed them the right to decide what counts as real? ▶ Read the full article and references ▶ Subscribe to Lens Four ▶ Redefining CyberSecurity Podcast ▶ Music Evolves Podcast ▶ ITSPmagazine ▶ Studio C60 Sean Martin, CISSP, is a cybersecurity market analyst, content strategist, and go-to-market advisor with more than 30 years of experience across engineering, product development, marketing, and media. He is co-founder of ITSPmagazine and Studio C60, host of the Redefining CyberSecurity Podcast and Music Evolves Podcast, and writes Lens Four at seanmartin.com. Keywords: AI-generated music, Tidal, Deezer, streaming fraud, provenance, content authentication, Human Authored, Authors Guild, Suno, slopsquatting, curl bug bounty, AI slop, paper mills, AI job applications, Merriam-Webster slop, DJ Sam Young, Gregoire Gensollen, Sean Martin, Lens Four Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

    The Flood Made Everything Free. So Now We Pay for Proof. | Lens Four by Sean Martin | Read by TAPE9
  8. Jul 1

    We Made Everything Faster. We Never Defined Better. | Lens Four by Sean Martin | Read by TAPE9

    ⬥EPISODE NOTES⬥ Almost every booth at Infosecurity Europe 2026 had settled on the same four words. Outcomes. Resilience. Sovereignty. Human in the loop. The messaging had grown up, more tempered than RSAC, more honest in its European register. The tell was quieter — almost none of it could connect those words to a definition of success a buyer could actually verify. Strip away the polish and the show floor was a working argument about what the cybersecurity market is for, at the exact moment the clock that governs it collapsed to seconds. The go-to-market caught up to the language. The capability did not. This is the prove-it problem, and it is worth pulling apart clearly. In this edition of Lens Four: 🔹 Why the quiet vocabulary convergence mattered more than any single product launch — outcomes, resilience, sovereignty, and human in the loop became the words everyone said, and almost none could tie them to a definition of success a buyer could verify 🔹 The number that should reorganize every SOC — the jump from initial access to the next stage collapsing from 8 hours to 22 seconds, with ransomware finishing in under an hour, most often on a Wednesday night 🔹 How Qualys reframed measurement itself — a client environment of 62 million risk findings cut to under 1% that could actually be executed, because the dashboard was never the deliverable, remediation was 🔹 Why Corelight put the same test on the detection itself — a black box tells you little, so keep the data behind every alert in the open and let an analyst prove what it actually is, the way one proof of value surfaced unencrypted sensitive traffic in 30 minutes 🔹 How Sumo Logic showed the repeatable version — prove a fix once, then let an agent apply that proven fix across 599 identical machines under human oversight, and its move into the AWS European Sovereign Cloud put something concrete under the week's sovereignty talk 🔹 What the criminal economy revealed as the honest mirror — an underground market for AI attack tools that went from 38 posts to over 1,400 in two months, tiered and redundant, an AI call center for hire that sounds like SaaS 🔹 Why the board's only real question, are we okay, now lands on the CISO as personal liability, just as AI moves from experimentation to deployment inside the organization 🔹 How consolidation and absorption are sorting the floor — 40-plus tools in silos, "make us relevant" becoming an executive hire, and the 12-to-18-month reckoning where AI absorbs functions that fill today's expo hall 🔹 The tell underneath all of it — when every booth converges on the same three or four words, the words stop doing the one job language has at a trade show: helping a buyer tell two things apart Fourth Lens: The vocabulary moved faster than the products underneath it. The industry repositioned around outcomes without ever defining the outcome, and the bill comes due over the next 12 to 18 months, not because AI arrives, but because AI removes the last place to hide the question. Naming the outcome was the easy part. Proving it repeats, across environments and teams and budgets that share nothing but the problem, is the part the vocabulary skipped. When the story can no longer be rounded up, are we okay, and can you prove it twice? 🥁 🎶 A very big THANK YOU to our Infosecurity Europe 2026 Full Coverage Sponsors: Corelight · Qualys · Sumo Logic 👏 👏 👏 ▶ Full article and references ▶ Full Infosecurity Europe 2026 coverage ▶ Subscribe to Lens Four ▶ Redefining CyberSecurity Podcast ▶ Music Evolves Podcast ▶ ITSPmagazine ▶ Studio C60 Sean Martin is a cybersecurity market analyst, content strategist, and go-to-market advisor with more than 30 years of experience across engineering, product development, marketing, and media. He is co-founder of ITSPmagazine and Studio C60, host of the Redefining CyberSecurity Podcast and Music Evolves Podcast, and co-host of On Location and Random and Unscripted. Learn more at seanmartin.com. Keywords: Infosecurity Europe 2026, cybersecurity go-to-market, security marketing, vendor positioning, machine-speed attacks, agentic AI, ransomware economics, post-quantum cryptography, boardroom liability, digital sovereignty, security tool consolidation, network detection and response, mean time to resolve, threat intelligence, resilience, Sean Martin, Lens Four Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

    We Made Everything Faster. We Never Defined Better. | Lens Four by Sean Martin | Read by TAPE9
5
out of 5
30 Ratings

About

Founded in 2015, ITSPmagazine began as a vision for a publication positioned at the critical intersection of technology, cybersecurity, and society. What started as a written publication has evolved into a comprehensive repository for all their content—podcasts, articles, event coverage, interviews, videos, panels, and everything they create. This is where Sean Martin and Marco Ciappelli talk about cybersecurity, technology, society, music, storytelling, branding, conference coverage, and whatever else catches their attention. Over a decade of conversations exploring how these worlds collide, influence each other, and shape the human experience. This is where you'll find it all.

More From ITSPmagazine Podcasts