Zero Signal

Conor Sherman

Zero Signal is a podcast for CISOs and senior security leaders who are expected to have answers about AI risk before the industry has standards. We go after the strategic questions that don't yet have clean answers — the ones your board is asking and the industry is still debating. Each episode is an honest conversation with someone navigating that pressure — not with perfect answers but with principles, frameworks, and lived experience. We host guests who've had to make real calls under uncertainty and are willing to talk about what worked, what didn't, and what they're still figuring out

  1. 5d ago

    Matt Hillary: The CISO's Evolution to Chief Trust Officer

    Welcome back to Zero Signal! In this episode, hosts Conor Sherman and Stuart Mitchell sit down with Matt Hillary, CISO for Drata. Drawing from his experience building security programs at organizations like AWS, Adobe, and Lumio, Matt explores how the CISO role is morphing into a field-facing Chief Trust Officer. He breaks down why establishing internal and external trust requires far more than chasing audit framework badges or vanity scores—it demands radical transparency, operational consistency, and alignment across engineering, legal, and executive teams. The conversation covers the shift toward continuous assurance and GRC engineering, examining how automated monitoring and AI capabilities can eliminate sampling-based audits while helping teams navigate new AI governance complexities. Matt candidly shares the realities of serving as CISO at a high-visibility security company, addressing the intense field demands, product feedback loops, and mental health challenges. From setting personal boundaries to navigating anxiety and avoiding burnout, this episode delivers practical leadership insights for modern security executives. About the Guest Matt Hillary is the Chief Information Security Officer at Drata. Over his career, he has held senior security leadership positions at organizations including AWS, Adobe, Instructure, Weave, Workfront, and Lumio. Key Moments The Evolution of the CISO into Chief Trust Officer Building Continuous Assurance & The Rise of GRC Engineering AI Governance & Managing Non-Deterministic Workflows CISO Leadership: Navigating High-Stakes Roles, Anxiety, and Burnout Meet our Sponsors Hampton North is the premier US-based cybersecurity search firm: https://hamptonnorth.com/?utm_source=website&utm_medium=podcast&utm_campaign=aware_global_swsd_all&utm_content=zero-signal Sysdig is the leader in AI-powered real-time cloud defense: https://www.sysdig.com/?utm_source=website&utm_medium=podcast&utm_campaign=aware_global_swsd_all&utm_content=zero-signal RISCPoint Security & compliance consulting tailored to your business: https://www.riscpoint.com/

  2. Aug 26

    Chris Hughes: The Security Democratization Gap

    Welcome back to Zero Signal! In this episode, hosts Conor Sherman and Stuart Mitchell sit down with Chris Hughes, founder of Resilient Cyber, three-time author, and Cyber Innovation Fellow at CISA. Facing a projected surge of up to 66,000 CVEs in 2026, Chris breaks down why the industry's historical vulnerability backlog is colliding with AI-driven discovery. He addresses the growing gap between vulnerability volume and actual exploitability, urging security leaders to move beyond dumping raw, context-free spreadsheets onto development teams and instead embrace true business alignment. The discussion explores the exponential expansion of the modern attack surface—highlighting GitHub's trajectory from 1 billion to 14 billion commits in a single year—and the security implications of democratized, AI-assisted coding. Chris, Conor, and Stu examine the current state of autonomous remediation, discussing why AI-generated patches often prove brittle or fail to address root causes. Finally, the conversation tackles the intersection of AI governance, the shift from model-centric security to securing the entire system harness, and the delicate balance between policy frameworks and maintaining national competitive advantage. About the Guest Chris Hughes is the founder of Resilient Cyber, a publication read by tens of thousands of security professionals weekly. He is a three-time author and serves as a Cyber Innovation Fellow at CISA. Key Moments The 2026 Vulnerability Explosion & Focusing on Real Exploitability Shifting Security Left vs. "Shifting Sh*t Left": Moving Beyond Spreadsheet Dumps The Attack Surface Exponential: Managing 14 Billion Commits & AI-Generated Code AI Governance & Policy: Securing System Harnesses Without Stifling Innovation Meet our Sponsors RISCPoint Security & compliance consulting tailored to your business: https://www.riscpoint.com/ Hampton North is the premier US-based cybersecurity search firm: https://hamptonnorth.com/?utm_source=website&utm_medium=podcast&utm_campaign=aware_global_swsd_all&utm_content=zero-signal Sysdig is the leader in AI-powered real-time cloud defense: https://www.sysdig.com/?utm_source=website&utm_medium=podcast&utm_campaign=aware_global_swsd_all&utm_content=zero-signal

  3. Aug 21

    Myke Lyons: "Mise en Place" for CISO Operations

    Welcome back to Zero Signal! In this episode, hosts Conor Sherman and Stuart Mitchell sit down with Myke Lyons, CISO for Cribl. Starting his career as a chef before making the leap into cybersecurity, Myke brings a unique "mise en place" philosophy to enterprise security operations—emphasizing the critical need for preparation, clean workflows, and sharp fundamentals. He breaks down why modern security challenges aren't just about write-once detections, but about mastering the unit economics of security data. As AI agents proliferate and exponentially increase telemetry volumes, security leaders must navigate the financial realities of data tiering, processing costs, and egress fees alongside CFOs. The conversation dives into the operational discipline required to build high-fidelity detection pipelines without inducing alert fatigue and team burnout. Myke shares actionable strategies on evaluating data pipelines, maintaining ownership over enterprise logs, and leveraging field-facing security trust programs to drive true business growth. From handling high-stress incidents with empathy and transparency to avoiding the "data swamp" trap, this episode provides CISOs with a pragmatic blueprint for balancing financial constraints with resilient defense. About the Guest Myke Lyons is the Chief Information Security Officer at Cribl. With over two decades of experience in telemetry and security operations, Myke previously served in executive security leadership roles at companies such as ServiceNow. He began his career working in professional restaurant kitchens, bringing culinary operational discipline to cybersecurity. Key Moments The Unit Economics of Data & Partnering with the CFO "Mise en Place" in Cyber: Applying Culinary Discipline to Security Operations Data Tiering, Egress Costs, and Avoiding Data Swamps Transparency, Empathy, and Building Field-Facing Trust Programs Meet our Sponsors RISCPoint Security & compliance consulting tailored to your business: https://www.riscpoint.com/ Hampton North is the premier US-based cybersecurity search firm: https://hamptonnorth.com/?utm_source=website&utm_medium=podcast&utm_campaign=aware_global_swsd_all&utm_content=zero-signal Sysdig is the leader in AI-powered real-time cloud defense: https://www.sysdig.com/?utm_source=website&utm_medium=podcast&utm_campaign=aware_global_swsd_all&utm_content=zero-signal

  4. Aug 19

    Phil Venables: Moving Security from Artisanal to Industrial

    Welcome back to Zero Signal! In this episode, hosts Conor Sherman and Stuart Mitchell sit down with Phil Venables, Venture Partner at Ballistic Ventures and former CISO for both Google Cloud and Goldman Sachs. Phil shares his strategic vision for modern security programs, breaking down why defenders must transition from "artisanal" craft to "industrial" scale. By adopting automation, platform-embedded security, and Site Reliability Engineering principles—such as Control Reliability Engineering—security teams can drastically accelerate their OODA loop to outpace evolving threats. The conversation explores the rise of "CISO 2.0," examining how modern security executives must act as peer business leaders who drive commercial outcomes, demonstrate technical empathy with engineering teams, and manage broader digital risk spanning AI safety, privacy, and compliance. Phil offers a candid look at the future of cybersecurity, discussing the shift toward continuous control validation, the emerging challenge of managing multiple concurrent incidents, and why AI ultimately gives defenders a structural "home field advantage" over attackers. About our Guest: Phil Venables is a Venture Partner at Ballistic Ventures. He previously served as the CISO for Google Cloud and was the long-time CISO and Chief Risk Officer at Goldman Sachs. He is a widely respected thought leader, author, and board member across the cybersecurity industry. Key Moments Moving from Artisanal Craftsmen to Industrial Scale Security The Evolution of CISO 2.0 & Navigating Chief Digital Risk Responsibilities Continuous Control Validation & Preparing for Concurrent Incidents Defenders' Structural Advantage: Why AI Long-Term Favors Defense Meet our Sponsors: Hampton North is the premier US-based cybersecurity search firm: https://hamptonnorth.com/?utm_source=website&utm_medium=podcast&utm_campaign=aware_global_swsd_all&utm_content=zero-signal Sysdig is the leader in AI-powered real-time cloud defense: https://www.sysdig.com/?utm_source=website&utm_medium=podcast&utm_campaign=aware_global_swsd_all&utm_content=zero-signal RISCPoint Security & compliance consulting tailored to your business: https://www.riscpoint.com/

  5. Aug 14

    Jacob DePriest: Why AI Patching Fails

    Welcome back to Zero Signal! In this episode, Conor Sherman and Stuart Mitchell sit down with Jacob DePriest, CISO and CIO at 1Password and former Deputy CSO at GitHub. Jacob shares his unique perspective on bridging the gap between security and IT enablement, breaking down how 1Password balances velocity and protection through a velocity-weighted risk framework. The discussion dives deep into the rapidly changing identity landscape, challenging traditional non-human identity paradigms. Jacob explains why today's AI agent activity is actually rooted in human-delegated identity—where finance, HR, and casual builders are using local AI agents to get their daily work done. Conor, Stu, and Jacob explore the rise of agentic privileged access, the critical need to keep credentials out of LLM context windows, and why storing secrets on disk is an enterprise habit that must die. Finally, Jacob unpacks groundbreaking research from 1Password's Off-By-1 Labs. The team evaluated whether top frontier models can reliably generate code patches for vulnerabilities, uncovering surprising results that every security leader relying on automated AI remediation needs to hear. About the Guest: Jacob DePriest is the CISO and CIO at 1Password. Prior to joining 1Password, he served as the Deputy Chief Security Officer at GitHub and led various engineering and technology initiatives across multiple high-scale organizations. Continued Reading & Resources: Off-By-1 Labs AI-Generated Vulnerability Research: https://1password.com/blog/why-ai-generated-patches-still-require-human-review 1Password Research Hub: https://1password.com/research#article 1Password SAGE Blog (Part 1 - Scaling Security Reviews): https://1password.com/blog/scaling-security-reviews-ai-powered-pipeline 1Password SAGE Blog (Part 2 - Context & Nondeterminism): https://1password.com/blog/scaling-security-reviews-solving-context-and-nondeterminism Key Moments: Human-Delegated Identity vs. Non-Human Identities in AI Workflows The Dual Role of CISO & CIO: Implementing Velocity-Weighted Risk Agentic Privileged Access & Keeping Credentials Out of LLM Context Off-By-1 Labs Research: Can AI Frontier Models Reliably Patch Vulnerabilities? Meet our Sponsors: RISCPoint Security & compliance consulting tailored to your business:  https://www.riscpoint.com/  Hampton North is the premier US-based cybersecurity search firm: https://hamptonnorth.com/?utm_source=website&utm_medium=podcast&utm_campaign=aware_global_swsd_all&utm_content=zero-signal Sysdig is the leader in AI-powered real-time cloud defense: https://www.sysdig.com/?utm_source=website&utm_medium=podcast&utm_campaign=aware_global_swsd_all&utm_content=zero-signal

  6. Aug 12

    LIVE: "Vibe Hunting" with Damien Lewke at Black Hat 2026

    Welcome to a special live episode of Zero Signal, recorded on the ground at Black Hat 2026 in Las Vegas! Hosts Conor Sherman and Stuart Mitchell are joined by Damien Lewke, CEO and founder of Nebulock, to break down the rapid evolution of agentic threat actors and what it means for enterprise defense. Damien shares his perspective as a veteran detection researcher, exploring how autonomous attacker pipelines are fundamentally shifting the economics of cybersecurity by compressing time-to-exploit from months down to minutes. The discussion explores the rise of "vibe hunting"—a proactive threat hunting framework designed to match the speed and veracity of modern AI-driven attacks. Damien and the hosts analyze the strategic role of open-weight models in incident response, the breakdown of traditional attribution models, and why context engines are essential for defenders to gain the upper hand. Packed with insights on democratizing elite security skills and managing automated lateral movement, this live session offers a practical roadmap for building resilient, AI-native security operations. About the Guest: Damien Lewke is the founder and CEO of Nebulock. A veteran detection and response strategist, Damien specialized in adversarial game theory at UCLA, built integrations engineering at CrowdStrike through its IPO, researched NLP algorithms at MIT's CSAIL, and led AI detection and security research at Arctic Wolf.

  7. Jul 31

    Herman Errico: Inside the AARM Standard

    Welcome back to Zero Signal! In this episode, hosts Conor Sherman and Stuart Mitchell speak with Herman Errico, Product Manager for Technical Research at Vanta. Driven by the shift of AI agents moving from text generation to autonomous execution, Herman authored the paper that established the Autonomous Action Runtime Management (AARM) specification. Now a system category specification housed under the Cloud Security Alliance (CSA), the initiative has quickly united over 90 supporting organizations. Herman breaks down why traditional applications, firewalls, and endpoint defenses fail at the "action boundary"—which he defines as the true new security boundary—and how pre-execution interception and accumulated session context are essential for governing non-deterministic AI behavior. The conversation dives deep into the mechanics of AARM, exploring how it expands beyond binary allow/block controls to introduce five distinct authorization decisions, including action modification, step-up verification, and deferral to human-in-the-loop oversight. Herman addresses why static Markdown files and instruction skills cannot reliably govern AI fleets due to context window limits, confused deputy risks, and competition for LLM attention. From vendor-neutral collaboration within the CSA working group to the future of securing autonomous hardware and robotics, this episode provides security leaders with a definitive framework to benchmark agentic security solutions and govern non-human execution safely. Herman Errico is the Product Manager for Technical Research at Vanta with a decade of experience in security operations and incident response. He is the author and creator of the Autonomous Action Runtime Management (AARM) specification, which he contributed to the Cloud Security Alliance (CSA) to establish an open, vendor-neutral standard for agent runtime security. Black Hat USA 2026 The Zero Signal team recorded this episode live on the ground as we gear up to attend Black Hat USA 2026! Catch up on our interviews and deep dives from last year by checking out our Black Hat YouTube Playlist: https://www.youtube.com/watch?v=sb-C-XPJQ_Q&list=PLvtGUUDFmi-b-fELkdzirA9yYEcNVfVVJ Autonomous Action Runtime Management (AARM) Specification: https://aarm.dev AARM Working Group & Conformance Standard: https://aarm.dev/working-group Cloud Security Alliance (CSA) Official Site: https://cloudsecurityalliance.org CSA Agentic AI Security Initiative: https://cloudsecurityalliance.org/artifacts/agentic-trust-framework Vanta Official Site: https://vanta.com Model Context Protocol (MCP) Specification: https://modelcontextprotocol.io 00:00 Defining the Action Boundary & The Origin of AARM 04:15 Layer 8 Execution & Pre-Execution Interception 09:30 Community-Led Specifications vs. Traditional Standards 15:30 Pre-Execution Interception & Five Authorization Decisions 19:40 Session Context Accumulation & Computing Agent Intent 34:30 Why Markdown Files Fail to Govern AI Fleets 38:30 Cross-Vendor Collaboration in the CSA Working Group 42:30 The 12-Month Outlook: Extending AARM to Hardware & Robotics Hampton North is the premier US-based cybersecurity search firm: https://hamptonnorth.com/?utm_source=website&utm_medium=podcast&utm_campaign=aware_global_swsd_all&utm_content=zero-signal Sysdig is the leader in AI-powered real-time cloud defense: https://www.sysdig.com/?utm_source=website&utm_medium=podcast&utm_campaign=aware_global_swsd_all&utm_content=zero-signal About the GuestContinued Reading & ResourcesKey Topics & TimestampsMeet our Sponsors

  8. Jul 24

    Daniel Bardenstein: Why Third-Party Risk Is Broken

    Welcome back to Zero Signal! In this episode, hosts Conor Sherman and Stuart Mitchell sit down with Daniel Bardenstein, founder and CEO of Manifest Cyber, former Chief of Technology Strategy at CISA, and former cybersecurity lead for Operation Warp Speed. With open-weight models like GLM 5.2 rapidly challenging proprietary AI providers like ChatGPT and Claude on performance while offering up to 5x to 6x cost savings, Daniel unpacks why basic arithmetic is driving an enterprise shift back toward open-weight models. He breaks down the complex supply chain dynamics behind AI datasets, fine-tuning, and model dependencies, highlighting how untracked data inputs can quietly introduce massive legal, compliance, and security liabilities. The conversation addresses the ongoing breakdown of traditional Third-Party Risk Management (TPRM). Daniel explains why relying on static paper questionnaires, SOC 2 reports, and superficial web scans fails to capture non-deterministic AI risks or the hidden fourth- and fifth-party software dependencies lurking inside modern vendor products. To solve this, he advocates for treating AI as a subset of software and leveraging machine-readable AI Bills of Materials (AI BOMs) to automate inventory management, streamline license compliance, and protect pipelines against shadow AI created by developers using tools like Claude Code. Daniel Bardenstein is the founder and CEO of Manifest Cyber. He previously served as the Chief of Technology Strategy at the Cybersecurity and Infrastructure Security Agency (CISA), led cybersecurity for Operation Warp Speed, and helped architect national-level cross-sector Security Performance Goals. CISA Cross-Sector Cybersecurity Performance Goals: https://cisa.gov/cpgs CycloneDX SBOM/AIBOM Standard Specification: https://cyclonedx.org SPDX Software & AI Bill of Materials Standard: https://spdx.dev NIST Software Supply Chain Security Guidance: https://nist.gov/software-supply-chain OWASP Top 10 for Large Language Model Applications: https://owasp.org/www-project-top-10-for-large-language-model-applications LAION-5B Dataset Research Analysis (Stanford University): https://cyber.fsi.stanford.edu 00:00 Open-Weight Models & The Economics of GLM 5.2 04:15 The Shift from Proprietary APIs to Open-Weight Models 08:50 Mapping Supply Chain Risks in Datasets and Fine-Tuning 12:20 Software Supply Chain Models Applied to AI Inventory 18:10 Navigating Complex AI Model Licensing & Compliance 24:00 Shadow AI, Local Models, and "Vibe Coding" Developer Risks 33:00 The Failure of Traditional Third-Party Risk Management (TPRM) 40:30 Operationalizing AI Bills of Materials (AI BOMs) for Automation Hampton North is the premier US-based cybersecurity search firm: https://hamptonnorth.com/?utm_source=website&utm_medium=podcast&utm_campaign=aware_global_swsd_all&utm_content=zero-signal Sysdig is the leader in AI-powered real-time cloud defense: https://www.sysdig.com/?utm_source=website&utm_medium=podcast&utm_campaign=aware_global_swsd_all&utm_content=zero-signal About the GuestContinued Reading & ResourcesKey Topics & TimestampsMeet our Sponsors

5
out of 5
4 Ratings

About

Zero Signal is a podcast for CISOs and senior security leaders who are expected to have answers about AI risk before the industry has standards. We go after the strategic questions that don't yet have clean answers — the ones your board is asking and the industry is still debating. Each episode is an honest conversation with someone navigating that pressure — not with perfect answers but with principles, frameworks, and lived experience. We host guests who've had to make real calls under uncertainty and are willing to talk about what worked, what didn't, and what they're still figuring out

You Might Also Like