KBKAST

Unlike every other security podcast, we don’t get stuck down in the technical weeds. Our remit is to speak with experts around the globe at the strategic level – how security technology can improve the experience and risk optimisation for every organisation. The Voice of Cyber® - In Partnership with Vanta

  1. 6d ago

    Episode 387 Deep Dive: Dr Ahana Datta Fasel | China Doesn't Want What You Think It Wants

    Dr. Ahana Datta Fasel has spent years mapping 30 years of China’s cyber operations, and she opens by dismantling the story most of us have absorbed. China isn’t only hunting our secrets. Sometimes it wants to know what we know about them, sometimes it’s watching its own diaspora, and often the intent behind an operation is genuinely hard to read. She walks KB through why cyber has become inseparable from live conflict, from Ukraine’s power grids to the CCTVs of Tehran, and why the line between spying and preparing for war keeps moving. She explains the operation sitting inside America’s major telecom networks, where hackers have held access for three years and done nothing with it, and what that patience might mean. We also get into Five Eyes politics, the Huawei decisions, and why the West still doesn’t have a coherent China strategy. Ahana’s book, Full Stack Spies: Cyber Espionage in the Age of US-China Competition, is out in North America on 1 October. Grab it on Amazon (https://a.co/d/01aovOFW) or from Oxford University Press (https://global.oup.com/academic/product/full-stack-spies-9780197871386), where the code ADISTA5 takes 30 percent off. About Ahana: A former UK Government cyber leader and Financial Times cyber chief, Dr. Ahana Datta Fasel advises global governments and industry on geopolitical, AI and systemic risk strategies. She serves as non-executive director at a leading global digital rights charity, adviser to deep tech start-ups, and a strategic adviser on national security and resilience to the UK body for research, innovation and international partnerships. She has held fellowships at Cornell, Cambridge, Imperial and Durham, and her op-eds have appeared in the FT, Foreign Policy, Euractiv and the Columbia Journalism Review. Keywords: China cyber operations, cyber espionage, US-China competition, Full Stack Spies, geopolitics, Five Eyes, telecom breach, act of war, Taiwan, national security, hybrid warfare, Huawei

  2. Sep 16

    Episode 385 Deep Dive: Reece Corbett-Wilkins | From Crisis to Resilience - Protecting Our Way of Life

    Reece takes us behind the scenes of the Instructure incident, where his team fielded 65 instructions in 48 hours, and explains how a catastrophic cyber event actually gets run across insurers, government and thousands of schools at once. KB & Reece get into the hidden cost almost no one budgets for, business interruption, and what the JLR and Change Healthcare cases reveal about how dependent our economy has become on a handful of suppliers. He also makes the case that AI is quietly splitting security budgets in two, and why that worries him. For any leader thinking seriously about resilience, this one is worth your time. About Reece: Reece Corbett-Wilkins is the Head of First Response Australia, and is the Chief Strategy Officer at Atmos. For over 10 years, Reece has focused exclusively on cyber and privacy risk, having helped 1,000+ organisations through some of their most challenging times. Reece is particularly experienced in managing large scale multi-party data breaches, both locally and globally, and ransomware response. Reece works closely with the incident response industry, government, and law enforcement to achieve optimal outcomes for clients. Keywords: cyber resilience, incident response, business interruption, cyber insurance, critical infrastructure, SPHERE, ransomware, supply chain risk, SOCI reform, AI security budget, CAT event, small business cyber

  3. Sep 9

    Episode 384 Deep Dive: Sumedh Thakar | Mythos Turned 30 Days Into 24 Hours.

    When Mythos hit in April, the security world split between panic and hype. Sumedh Thakar, President and CEO of Qualys, joins KB to make the calmer case that Mythos accelerated an old threat rather than inventing one. They get into why zero-day vulnerabilities now need zero-day remediation, the misread that Mythos runs on your own code while your vendors use it too, the board conversation it reopened, tokenomics and budget pressure, and how much a CISO should really hand to the machines. About Sumedh: As a cybersecurity visionary, Sumedh is passionate about making the world’s digital journey safer. His education and early experiences as a coder led him to Qualys, where he rose from engineer to president and CEO. He joined Qualys in 2003, shortly after the company’s founding and in an era when organizations started using the cloud but didn’t know what to call it. His contributions and leadership helped propel Qualys to its current success in cybersecurity. Sumedh became president and CEO in 2021. In 2019, he was named president, and prior to that, he was chief product officer, driving the company’s vision of making enterprise security more efficient and disrupting the VM space with integrated capabilities like patch management and cybersecurity asset management. A “product fanatic and engineer at heart,” Sumedh was instrumental in dramatically expanding the original Qualys platform’s scope, integrations, and automations. He also scaled the company’s engineering talent internationally with a global 24×7 follow-the-sun product team. He is a co-inventor of five U.S. patents for cybersecurity technology in Qualys offerings. Previously, Sumedh was an engineer at Intacct, an early cloud-based financial and accounting software provider. He also worked at Northwest Airlines developing complex algorithms for its yield and revenue management reservation system. He has a bachelor’s degree in computer engineering with distinction from Savitribai Phule Pune University. Keywords: Mythos, AI security, cybersecurity, zero-day, autonomous remediation, vulnerability management, CISO strategy, board reporting, Qualys, Sumedh Thakar, patch management, true risk, exposure management, AI attacks, first-party code

  4. Sep 3

    Episode 383 Deep Dive: Sarah Sloan | It Still Runs, But Can You Defend It? The End-of-Life Tech Reckoning

    The tech running hospitals, power grids and government services often still works. Sarah Sloan, Cisco’s Head of Cybersecurity Policy for APAC, joins KB to explain why that’s the problem, not the reassurance it sounds like. Drawing on a new ASPI report Cisco funded, “Past its use-by-date,” they get into why so much end-of-life tech is still in place (usually budgets and skills, not negligence), how AI and quantum turned a slow-burn risk into an urgent one, and why most organisations still can’t see the ageing gear in their own environment. Plus the upside: why moving early beats being forced by an incident. About Sarah: Sarah Sloan is Head of Cybersecurity Policy APAC, Cisco where she leads public sector engagement on cybersecurity policy matters across the region. With over 15 years’ experience across government, industry, and consulting — including more than a decade focused on cyber and technology — Sarah has held senior roles in the Australian Government and leading global technology firms, driving policy development, public-private sector partnerships, and national cybersecurity priorities. She holds a Bachelor of Laws (Hons) and Bachelor of Asia-Pacific Studies from the Australian National University (ANU), and postgraduate qualifications in legal practice, international law, and Japanese studies. Sarah is also Chair of the Australian Industry Information Association’s (AIIA) National Security and Cyber Resilience Policy Advisory Network. Keywords: end-of-life technology, legacy systems, critical infrastructure, cybersecurity governance, ASPI, Cisco, Legacy Five, board risk, post-quantum cryptography, AI cyber threats, SOCI Act, technology lifecycle, cost of downtime, CISO, digital resilience

  5. Aug 19

    Episode 381 Deep Dive: Gijo Varghese | When a Cyber Attack Becomes a Public Safety Failure

    Karissa Breen sits down with Gijo Varghese, Chief Security Officer at OT cyber security firm Secolve, to unpack an uncomfortable trade-off: the same connectivity and AI making power, water and transport smarter are also making them easier to break. Gijo explains how IT and OT convergence has widened the attack surface, why decades-old control systems were never built to touch the internet, and how a single IT intrusion can spill into the physical world. He walks through the incidents that prove it, from the 2015 Ukraine grid attack to Colonial Pipeline, where operators went to run the system by hand and found the people who knew how had all retired, to the Jaguar Land Rover breach that rippled through 5,000 suppliers and cost the UK economy billions. The throughline for boards and executives: a cyber incident stops being a security event the moment it becomes a public safety failure. Gijo makes the case for the kill switch, tested manual fallbacks, and treating resilience rather than compliance as the real measure of readiness. About Gijo: Gijo Varghese is a cyber security veteran, critical infrastructure defender, and the Chief Security Officer of Secolve. His passion in life is to protect the systems society depends on – power grids, transport networks, and biomedical health systems – keeping people, communities, and businesses safe from cyberattacks. With over 25 years of experience across IT and OT security, Gijo has spent his career at the frontline of Australia’s most essential industries, most recently leading cyber resilience at Endeavour Energy for six years, with prior roles at Transport for NSW, SA Health, CyberCX and Wipro Consulting.  Secolve is Australia’s leading OT cybersecurity firm, providing cyber advisory, offensive security, and training services to mines, factories, hospitals, transport networks, and energy ecosystems. As Secolve’s first CSO, Gijo leads the firm’s consultancy and professional services team, transforming complex OT cyber risks into practical action across executive, engineering, and operational teams.  Keywords: critical infrastructure security, OT security, IT/OT convergence, SCADA, ICS, cyber resilience, kill switch, Colonial Pipeline, Jaguar Land Rover, SOCI Act, CI45, incident response, operational technology, AI cybersecurity, public safety, board governance, cyber warfare, business continuity

  6. Aug 12

    Episode 380 Deep Dive: Mark Thomas | Owning a Policy PDF Doesn't Mean You Govern Your AI

    In this episode, KB sits down with Mark Thomas, IT governance and risk veteran, ISACA Hall of Famer and president of Escoute Consulting, to pull apart a problem a lot of boards haven’t clocked yet – the gap between owning an AI policy and being able to prove it controls anything. They get into the Air Canada chatbot case and what it says about accountability, why the honest board test is “would anyone notice if this was violated,” and how the risk changes once agents move from recommending to executing. Mark makes the case that human in the loop only counts when the human has the expertise, the authority and the time to say no. He also explains why only a small fraction of organisations have ever tested their ability to shut a system down, and why accountability never transfers to the vendor. A practical, occasionally uncomfortable conversation for anyone putting AI into production. —— About Mark: Mark Thomas is a globally recognised expert in governance, risk management, and digital trust, with more than two decades of experience advising organisations operating in complex, regulated, and rapidly evolving environments. His work sits at a critical intersection where strategy, governance, and execution meet. He works directly with boards and executive leadership to: Strengthen oversight and accountability Improve confidence in decision-making Navigate emerging technologies and digital risk Align governance with real-world execution Mark is known for his ability to translate complex issues into clear, practical insight, helping leaders move from uncertainty to informed, defensible decisions. Keywords: AI governance, AI risk, board accountability, agentic AI, human in the loop, kill switch, digital trust, AI policy, ISACA, Mark Thomas, Escoute Consulting, KBKast, enterprise AI, AI compliance, EU AI Act, shadow AI, Air Canada chatbot

About

Unlike every other security podcast, we don’t get stuck down in the technical weeds. Our remit is to speak with experts around the globe at the strategic level – how security technology can improve the experience and risk optimisation for every organisation. The Voice of Cyber® - In Partnership with Vanta

More From KBI.FM