The Business of Cybersecurity

The Business of Cybersecurity is a podcast from the Tech Talks Network that explores where security and business strategy converge. Hosted by Neil C. Hughes, creator of the Tech Talks Daily Podcast, this series examines how today’s enterprises are managing cyber risk while still moving fast and innovating. Through insightful conversations with industry leaders, CISOs, product strategists, and security architects, the podcast brings clarity to the real-world decisions shaping cybersecurity in modern business. Each episode dives into how companies are responding to regulatory pressure, increasing complexity in cloud environments, and rising expectations from boards and customers. From AI-driven defense and zero trust to skills gaps and risk quantification, we go beyond technical jargon to explore what actually works—and what doesn’t—on the road to building resilient organisations. Whether you're leading a security team, sitting at the executive table, or simply want to understand the business impact of cybersecurity, this podcast offers honest, grounded perspectives designed to help you make better decisions in an environment that never stands still. Search Tech Talks Network to discover more shows covering the voices at the heart of enterprise technology.

  1. Sep 27

    Why AI Gives Cyber Attackers the Early Advantage With IEEE

    Can defenders keep pace when generative AI gives attackers faster ways to create convincing phishing messages, research targets, and test new attack methods? In this episode of The Business of Cybersecurity, I speak with Professor Steven Furnell from the University of Nottingham for an IEEE conversation about AI-enabled threats, security awareness, passkeys, cyber hygiene, and the continuing gap between cybersecurity policy and everyday practice. Steven explains why the current AI contest does not give either side exclusive access to powerful technology. Attackers, however, often gain the early advantage because they use it to create opportunity and set the agenda. Defenders are then left identifying the new behavior, adapting controls, and managing the extra work. Generative AI also removes much of the effort once required to research an organization and produce credible spear-phishing messages, making familiar advice about spelling errors and obvious scams less useful than it once was. We discuss whether passkeys could finally reduce our dependence on passwords and why adoption will still require technical preparation and clear communication with users. A control may improve security while adding friction, so businesses must consider how authentication, updates, access controls, and other interventions fit into real working routines. Steven also points to a recurring problem in cybersecurity awareness. Fewer than one in five organizations in the UK Cyber Security Breaches Survey reported staff awareness training in the previous 12 months, according to the figures he discusses. Even where annual training exists, watching a video and answering questions may satisfy a compliance requirement without showing whether an employee can respond effectively when a real incident occurs. For smaller organizations that find security frameworks overwhelming, Steven recommends Cyber Essentials as a practical baseline. We also discuss secure design, the difficulty of regulation keeping pace with technology, and the Cyber Games Lab activities created at the University of Nottingham. Hacker Whacker and Cyber Defense Dice use play and conversation to make cyber education easier to understand for young people and business audiences. What would improve security behavior inside your organization, another annual training module or regular opportunities to practice realistic decisions? Listen to the episode and share your thoughts.

    Why AI Gives Cyber Attackers the Early Advantage With IEEE
  2. Sep 23

    Closing the Forgotten SaaS Account Security Gap With Kaseya

    Could your security team produce an accurate list of every employee, contractor, guest account, application, and AI agent with access to your SaaS environment today? In this episode of The Business of Cybersecurity, I speak with Jim Lippie, Chief Product Officer at Kaseya, about findings from the company’s latest SaaS security research. The report draws on anonymized activity from the SaaS Alerts platform, covering 27 billion security events across 50,000 organizations. One finding immediately stands out. Only 44% of monitored organizations were using multifactor authentication. When the research began in 2022, the figure was 32%. Four years of heightened cyber awareness have therefore produced an increase of only 12 percentage points. The report also found that guest accounts represented 69% of monitored accounts. This means guest users outnumbered licensed users by over two to one. Jim explains how these accounts accumulate. A consultant, contractor, or temporary employee receives access to company systems, completes the work, and leaves. The account remains because nobody owns the process of removing it. Over time, these forgotten identities create unattended routes into business data and applications. Our conversation examines how SaaS has changed the security perimeter. Employees no longer need to be inside an office or connected through a corporate network. A browser, valid credentials, and access to a cloud application may be enough. Security teams must therefore monitor user behavior, permissions, locations, and unusual patterns rather than relying on controls designed around the office firewall. AI agents add another category of identity. An autonomous system performing workflow tasks may require access to files, email, customer data, financial systems, or internal applications. Jim argues that these agents should be treated like users, with defined permissions and continuous behavior monitoring. We also discuss the tension created by easy collaboration. The report found that 34% of monitored file sharing traveled outside the organization. That sharing may be legitimate, but businesses need to understand which information has left, who received it, and whether access remains appropriate. Jim’s advice is deliberately practical. Begin with a complete assessment of the environment. Identify every account and application, require MFA, give guest access an expiration date, monitor behavior, and use overlapping security controls where a second source of evidence can expose missed activity. Does your organization have genuine visibility across its SaaS environment, or are forgotten accounts and unmonitored identities creating doors nobody remembers opening? Listen to the episode and share your thoughts with me.

    Closing the Forgotten SaaS Account Security Gap With Kaseya
  3. Sep 12

    Reducing Fifty Thousand Cyber Alerts to Fifty Decisions With Tanium

    What happens when a security team receives 50,000 alerts but only 50 genuinely need human attention? In this episode of The Business of Cybersecurity, I speak with Harman Kaur, CTO of Tanium and a reserve cyber officer in the U.S. Air Force, about how AI is changing the pace, structure, and responsibilities of modern security operations. The long-running cybersecurity talent shortage has not disappeared, but Harman believes the conversation is changing. Security teams now have tools that can assist with specialist work, which places greater weight on processes, interpretation, and decision-making. Training increasingly includes knowing how to ask the right question, assess an AI-generated response, and decide whether the proposed action makes sense. That change matters because the old pattern of threat response is becoming too slow. Security teams once had time to identify a threat trend, respond to it, and prepare for the next one. Harman says those cycles can now collapse to seconds as AI helps attackers find vulnerabilities and develop exploits. Defenders therefore need to consider whether the same technology can support remediation and patch creation at a comparable pace. We discuss why traditional scripted automation cannot solve this problem by making the existing workflow slightly faster. If an analyst can manually process 100 alerts and automation raises that number to 200, the improvement offers little comfort when the queue reaches thousands or hundreds of thousands. Harman argues that organizations need to reconsider how the security operation itself is designed while retaining people as judges for decisions with meaningful consequences. Autonomy, in her view, should be treated as a spectrum rather than an all-or-nothing destination. One process may be suitable for full automation, another may require approval, and a third may remain entirely human-led. That approach also helps CIOs and CTOs respond to pressure for rapid AI adoption without pretending that a single governance model can answer every risk. Harman also warns against allowing the AI conversation to distract teams from familiar security weaknesses. Shadow AI matters, and companies need visibility into the models and tools being used across the organization. At the same time, phishing, compromised credentials, unpatched machines, end-of-life devices, unused applications, and exposed ports remain common sources of risk. AI may amplify those weaknesses, but it does not erase the need to address them. The episode’s clearest example concerns alert fatigue. Harman describes an AI system that processes and triages alerts while reporting its confidence and showing how it reached its conclusion. Verification mechanisms can then ask what additional context should be considered. The goal is to narrow 50,000 alerts to perhaps 50 that deserve manual investigation, giving analysts a manageable decision set without asking them to trust a model blindly. We also discuss operational resilience and why prevention must begin before a security alert appears. Harman challenges organizations to explain why routine patching is not automated in 2026, while recognizing that no company can apply every patch instantly. Reducing the attack surface by removing unused applications and closing unnecessary ports can make the business a smaller target while teams address the vulnerabilities that matter most. Finally, Harman asks leaders to question why they are applying AI to a given problem. Some tasks can be handled by established automation. If the organization chart, business processes, and toolset look exactly the same after an AI program, the company may have added technology without redesigning the work. Where should your organization allow AI to act, where should it advise, and where must a person make the final decision? Listen to the episode and share your thoughts.

    Reducing Fifty Thousand Cyber Alerts to Fifty Decisions With Tanium
  4. Aug 30

    Securing Every AI Agent Action With Delinea

    What happens after an AI agent presents valid credentials and enters your business systems? In this episode of The Business of Cybersecurity, I speak with Spencer Young, Senior Vice President of International Markets at Delinea, about why authenticating an AI agent is only the beginning of the security challenge. Spencer has spent 34 years in IT and around half that time in cybersecurity. His experience covers secure software development, vulnerability testing, application protection, data security, and identity security. Our conversation begins with the changing economics of cybercrime. Spencer says attackers increasingly prefer stealing or compromising legitimate credentials because logging in can be cheaper, faster, and easier than forcing a route through network defenses. He estimates that over three quarters of attacks involve a compromised credential somewhere in the chain. AI agents add speed and scale to identity risk. They can access applications, databases, financial systems, development tools, and infrastructure while performing dozens of actions during a single session. The danger is not limited to an agent being denied access. An agent may be fully authenticated and possess valid permissions while taking an action the organization never intended. Spencer offers the example of a finance agent created to support payment processes. Hidden or manipulated instructions could cause it to change payment profiles and redirect money while appearing to operate as an authorized identity. This is why Delinea is focusing on runtime authorization. Rather than approving an agent once and allowing every subsequent action, the approach evaluates each proposed tool call, database query, or SSH command before it runs. The action can be allowed, blocked, or referred to a person for approval. We also discuss how least privilege applies to autonomous systems. Spencer recommends providing credentials only at the moment an agent needs them, limiting access to the specific task, and revoking those privileges immediately afterward. The agent never needs to see or retain the credential. The research figures Spencer shares reveal a concerning difference between confidence and control. He says 80% to 85% of respondents feel confident in their ability to discover nonhuman identities, while only 30% validate nonhuman identity use and AI activity in real time. Delinea now works with over 9,000 organizations, including over 60% of the Fortune 100. Spencer says regulated industries frequently demonstrate greater identity security maturity because external requirements encourage continuous controls rather than reactive incident response. However, technology cannot decide an organization’s risk appetite. People must define what the agent is expected to do, which actions require approval, where it must stop, and who is accountable when something goes wrong. Could your organization detect a properly authenticated AI agent taking an inappropriate action before that action executes? Listen to the episode and share your thoughts with me. Suggested URL

    Securing Every AI Agent Action With Delinea
  5. Aug 28

    Securing AI Agents Before They Become Attack Paths With ExtraHop

    Can a security team respond quickly enough when an AI-driven attack moves from initial access to lateral movement and data theft before a human analyst has finished opening their dashboards? In this episode of The Business of Cybersecurity, I speak with Heath Mullins, Chief Evangelist at ExtraHop and former Forrester analyst, about why AI security has become an operational issue for organizations today. ExtraHop’s 2026 Global Threat Landscape Report states that 85 percent of organizations have experienced an AI-driven attack. These incidents include AI-enhanced external attacks, compromised AI identities, and breaches involving third-party AI providers. The report also found that 55 percent view AI agents, agentic infrastructure, and GenAI applications as their biggest attack-surface risk. Heath explains that many attacker tactics remain familiar. The difference is speed. An analyst who once had hours or days to compare endpoint alerts, network logs, threat intelligence, and security events may now find that the attack has completed before the investigation begins. We also discuss how AI models can be influenced without anybody directly altering their code. Attackers can publish false information that enters future training data or introduce misleading content into internal repositories and development environments. An agent may then infer a connection, assign a high confidence score, and act on inaccurate information. The risks grow when AI agents receive administrator privileges. Heath describes an agent as an entity capable of taking action across the network. His analogy is difficult to forget: AI can resemble a dangerous toddler carrying the keys to the house, car, and gun safe. It may be extremely helpful, but broad permissions combined with loosely defined instructions create the conditions for serious damage. Third-party AI adds further dependencies. Security leaders need to understand how suppliers use models and reasoning tools, whether customer data is segregated, what remote access exists, and how a compromised supplier could create a path into the network. Heath also challenges the assumption that endpoint controls and delayed logs provide enough visibility. Machine-speed attacks may exploit unknown vulnerabilities, evade endpoint detection, and move laterally using identities that appear legitimate. Behavioral and live network signals can reveal activity that does not match a published indicator or known signature. Buying another security product may address an identified gap, but Heath argues that CISOs also need awareness across physical, virtual, cloud, and container environments. Network and security teams must share information when an identity, agent, or workload begins behaving differently. His immediate advice is direct. Treat every new tool as potentially dangerous. Test AI agents inside properly isolated environments. Connect every agent to a known identity, restrict its permissions, and define a narrow task. Finally, train people to use AI responsibly and retain human authority over consequential actions. Heath is also the kind of guest I could talk with over a cold beer for hours about technology and its consequences. After we finished the formal interview, our conversation moved naturally into AI data centers, energy costs, water consumption, surveillance, and humanity’s habit of adopting technology even when we understand the price. If AI agents can act with administrator privileges at machine speed, are your security controls watching what those agents are doing or merely recording what happened afterward? Listen to the episode and share your thoughts with me.

    Securing AI Agents Before They Become Attack Paths With ExtraHop
  6. Aug 23

    Patching at Machine Speed Without Breaking the Business With Adaptiva

    What happens when a patch designed to protect the business creates an outage of its own? In this episode of The Business of Cybersecurity, I speak with David Sowder, Senior Solutions Architect and OneSite Patch product specialist at Adaptiva, about balancing rapid vulnerability remediation with operational control. David brings 25 years of IT operations and engineering experience to the conversation. He remembers receiving large spreadsheets of vulnerabilities from security teams and being responsible for turning that information into deployed fixes. That experience gives him a practical view of the gap between identifying a vulnerability and safely resolving it across thousands of endpoints. Adaptiva’s State of Patch Management report argues that speed cannot be the only measure of success. David illustrates the problem with a library cart full of books. Pushing it down the stairs may be the fastest way to reach the lower floor, but the resulting mess defeats the purpose. The same principle applies to patch management. Urgent deployment can reduce the period when a vulnerability remains exposed, but an inadequately tested update may break applications, interrupt customer services, or affect revenue. David recommends representative pilot groups, defined testing periods, user feedback, staged deployment, monitoring, and the ability to stop a release before it reaches the full production environment. We also discuss why greater endpoint visibility does not automatically reduce business risk. Dashboards and vulnerability reports provide knowledge, but IT teams must perform the work required to remediate the problem. David believes closer cooperation between InfoSec and IT can reduce the time between identification and action. Automation introduces another difficult decision. David argues that layers of manual approval frequently add delay without changing which patches are eventually deployed. His proposed alternative is to begin the process automatically, notify the right people, test through pilot groups, and prevent wider deployment when the feedback indicates a problem. Accountability remains shared. Security leaders set risk policies, InfoSec prioritizes exposure, IT manages deployment, and application owners understand the possible business consequences. These responsibilities need to be agreed before an urgent incident arrives. Can autonomous patch management help companies respond at machine speed without turning a security fix into a business outage? Listen to the conversation and share your thoughts with me.

    Patching at Machine Speed Without Breaking the Business With Adaptiva
  7. Aug 21

    Rethinking Third Party Risk for Machine Speed Attacks With Magnitude

    Can a supplier assessment completed once a year protect an organization against risks changing at machine speed? In this episode of The Business of Cybersecurity, I speak with Rami Habal, founder and CEO of Magnitude. We discuss why traditional third party risk management is struggling to keep pace with connected supply chains, autonomous attacks, AI adoption, and constantly changing vendor environments. Rami explains that third party risk management developed largely as a compliance process. Companies relied on questionnaires, spreadsheets, point-in-time assessments, and annual reviews. Those methods provided documentation, but they offered limited visibility into what changed after the review or which fourth and fifth parties supported the original vendor. The result can be a false sense of security. A supplier may change its infrastructure, ownership, software, data practices, or terms of service months before the customer performs another formal assessment. Attackers do not wait for the next compliance cycle. Rami argues that AI has broken the traditional mathematics of third party risk. Security teams cannot manually monitor thousands of suppliers and every organization supporting them. Attackers can use advanced models to find weaknesses faster, while businesses are adding AI services and dependencies at speed. Magnitude provides what Rami describes as an AI workforce for third party and supply chain risk management. Its agents support tasks including supplier intake, evidence gathering, security evaluation, risk analysis, onboarding, continuous assurance, and offboarding. We discuss how this automation can address three business problems. The first is time compression, allowing security teams to process supplier reviews faster. The second is risk reduction through wider visibility, including fourth and fifth party dependencies. The third is business enablement, reducing delays that might otherwise encourage employees to use unapproved AI tools. Rami explains how Magnitude maps supplier relationships as a connected graph. Security teams can see where dependencies overlap, identify concentration risk, and assess which parts of the business may be affected when a provider experiences an incident. Continuous monitoring also includes unstructured information. A vendor may update a lengthy terms of service document and introduce permission to train AI systems using customer data. An employee receiving the notification may ignore it, while an automated agent can compare the document, identify the change, and explain its potential effect. Rami uses a helpful analogy. Traditional vendor assessments resemble photographs, while continuous monitoring resembles a live video feed. Operational, financial, cybersecurity, and privacy risks continue changing after the original assessment. Automation does not remove people from the process. Rami sees AI preparing evidence, correlating signals, and recommending action while humans handle exceptions, ask difficult questions, and judge the business consequences. He closes by urging boards to treat third party risk as part of cyber resilience rather than leaving it within procurement or compliance. Does your organization know which suppliers create its greatest concentration risk and how far a breach could travel through the chain? Listen to the conversation and share your thoughts with me.

    Rethinking Third Party Risk for Machine Speed Attacks With Magnitude
  8. Aug 17

    Giving AI Security Agents the Context They Need With Sola Security

    What happens when an AI security agent receives access to eight enterprise systems but cannot understand the relationships between the data inside them? In this episode of The Business of Cybersecurity, I speak with Guy Flechter, CEO and co-founder of Sola Security. Guy has worked in cybersecurity for 25 years, progressing from operational security roles to the CISO position before moving into entrepreneurship. He previously founded Cider Security, which was acquired by Palo Alto Networks for $300 million. Our conversation focuses on why adding AI agents to separate security tools may increase speed without improving the quality of the decisions. Cloud, identity, SaaS, code, devices, and networks frequently operate through different consoles and data models. An agent working within one of those systems may answer confidently while missing a relationship that changes the meaning of the risk. Sola Security’s research examined 50 tasks across eight enterprise platforms. According to Guy, providing structural and relational context improved answer correctness by approximately 34% across the tested models. Under full context, 78% of responses were considered fully correct, around 18% were incomplete, and fewer than 4% were classified as complete failures. Those results show both the promise and present limitations of AI security agents. Connected context can improve performance significantly, but 78% accuracy does not support fully autonomous action in situations where an incorrect permission change or security response could have serious consequences. Guy believes human involvement will remain necessary until accuracy reaches a far higher level. We also discuss how companies should vet and onboard AI agents. Guy recommends treating an agent like a new employee by defining its permissions, monitoring its actions, controlling what it can retain, and limiting its authority until trust has been earned. The episode concludes with a discussion about independent testing. Guy argues that buyers need transparent benchmarks with visible tasks and repeatable methods, rather than vendor accuracy claims based on private evaluations. Should an AI security agent be allowed to act autonomously if its reasoning cannot be independently tested? Listen to the conversation and share your thoughts with me.

    Giving AI Security Agents the Context They Need With Sola Security

About

The Business of Cybersecurity is a podcast from the Tech Talks Network that explores where security and business strategy converge. Hosted by Neil C. Hughes, creator of the Tech Talks Daily Podcast, this series examines how today’s enterprises are managing cyber risk while still moving fast and innovating. Through insightful conversations with industry leaders, CISOs, product strategists, and security architects, the podcast brings clarity to the real-world decisions shaping cybersecurity in modern business. Each episode dives into how companies are responding to regulatory pressure, increasing complexity in cloud environments, and rising expectations from boards and customers. From AI-driven defense and zero trust to skills gaps and risk quantification, we go beyond technical jargon to explore what actually works—and what doesn’t—on the road to building resilient organisations. Whether you're leading a security team, sitting at the executive table, or simply want to understand the business impact of cybersecurity, this podcast offers honest, grounded perspectives designed to help you make better decisions in an environment that never stands still. Search Tech Talks Network to discover more shows covering the voices at the heart of enterprise technology.

More From Tech Talks Network