Musings from the Cyber Trench

Vishal Masih

Musings from the Cyber Trench Podcast is where cybersecurity gets real. It’s for leaders battling red tape, tech debt, and chaos, looking for straight answers, not vendor fluff. Each episode goes deep with people solving the hard problems others avoid.The vision? Bring clarity to complex, high-risk environments. Guests are sharp thinkers and operators from agencies, universities, nonprofits, and regulated industries. This is not selling; This is sharing what it actually takes to protect systems that matter.

  1. 6d ago

    Have We Shifted Cybersecurity Too Far Left? | Rick Clark | Episode 115

    Send us Fan Mail Moving security left was supposed to reduce risk. Instead, many organizations have made developers responsible for hundreds of controls they cannot realistically understand, manage, or consistently enforce. In this episode of Musings from the Cyber Trench, I sit down with Rick Clark, a cloud, open-source, Linux, and platform engineering leader with three decades of experience, to discuss whether cybersecurity has shifted too far left. We examine how organizations can build security controls directly into their platforms, reduce control sprawl, respond faster to vulnerabilities, and measure software delivery based on business and security outcomes, not deployment speed alone. Rick shares practical insights on:  Embedding security controls into CI/CD platforms so they are applied automatically  Keeping control ownership with information security while reducing the burden on developers  Restoring architectural oversight without unnecessarily slowing delivery  Reviewing legacy controls instead of carrying them unchanged from on-premises environments into the cloud  Using AI to enforce security controls rather than simply producing code faster  Measuring software delivery against business value, compliance, and risk  Recovering from zero-day vulnerabilities through standardized containers and centralized platform control  Using mutual TLS and end-to-end identity tracking to secure platform communications  Protecting sensitive data, private keys, and certificates from immature AI agents The central takeaway is straightforward: developers should write secure code, but they cannot carry the organization’s entire cybersecurity, operations, compliance, and cost-management burden. Security teams must define the controls, and platform teams must make those controls consistent, automatic, and easier to use. ABOUT RICK CLARK Rick Clark has 30 years of experience across cloud computing, open source, Linux, platform engineering, and security. He led the development of Ubuntu Server, led engineering for the Rackspace Cloud and helped found OpenStack, worked in the CTO’s office at Cisco Systems, and helped build the Reliance Jio cloud infrastructure in India. ZERO TRUST READINESS ASSESSMENT Responsible for ICAM, Zero Trust, or identity security within a federal agency, prime contractor, or large regulated enterprise? If you are trying to move from strategy to execution, start with Zephon’s Zero Trust Readiness Assessment: https://zephon.tech/zt Questions or guest suggestions? defend@zephon.tech Responsible for ICAM, Zero Trust, or identity security in a federal agency, prime, or large regulated enterprise? If you’re trying to move from strategy to execution, start with Zephon’s Zero Trust Readiness Assessment: zephon.tech/zt Questions or guest ideas? Email defend@zephon.tech

  2. Sep 14

    Prompt Injection Is a Data Access Problem | Sundar Krishnamurthy | EP 114

    Send us Fan Mail You cannot secure AI by filtering prompts alone. If an AI agent can retrieve sensitive data or execute actions, prompt injection becomes an identity, authorization, and architecture problem. In this episode of Musings from the Cyber Trench, I sit down with Sundar Krishnamurthy, Senior Security Architect at Expedia Group, to discuss how organizations can secure AI in real enterprise environments. We examine why prompt-level guardrails are not enough, how non-human identities should remain connected to the people they represent, and why security controls must be enforced close to the data and action being requested. Sundar shares practical insights on: Turning security assumptions into automated testsUsing LLMs to support code reviews and threat modelingHow indirect prompts can bypass basic guardrailsEnforcing authorization at the point of data retrievalMaintaining human and non-human identity contextIsolating vector stores to reduce cross-tenant exposureAvoiding security shortcuts during MVP developmentProtecting private data when using AI modelsThe central message is simple: AI security cannot depend on trusting the model or recognizing every malicious prompt. Identity, authorization, data isolation, logging, and defense in depth must be built into the underlying architecture. ABOUT SUNDAR KRISHNAMURTHY Sundar Krishnamurthy is a Senior Security Architect at Expedia Group. He conducts architecture reviews across applications, cloud, networks, infrastructure, and AI and machine learning security. His background includes work with AWS, SAP Concur, and Microsoft. Responsible for ICAM, Zero Trust, or identity security in a federal agency, prime, or large regulated enterprise? If you’re trying to move from strategy to execution, start with Zephon’s Zero Trust Readiness Assessment: zephon.tech/zt Questions or guest ideas? Email defend@zephon.tech

  3. May 31

    Compliance, GRC, cybersecurity maturity, audit readiness, AI, CMMC, and continuous security

    Send us Fan Mail Too many organizations still treat compliance as a one-time audit exercise: get the certification, satisfy the customer, and move on. In this episode of Musings from the Cyber Trench, I sit down with Sarah Lynn, a seasoned IT, cybersecurity, GRC, advisory, and audit preparation leader, to discuss why that mindset breaks down fast. We talk about what happens when compliance is treated as “paperwork,” where programs usually fail first, and why people, process, and technology all have to work together for compliance to become part of daily operations. Sarah also shares practical insights on:  Why undocumented processes are a major red flag  How leaders can move from checklist compliance to security maturity  Where organizations underinvest and overspend in compliance programs  Why buying a tool before understanding the process usually backfires  AI’s role in compliance, automation, meeting notes, artifact collection, and risk  Why CMMC, SOC 2, ISO, FedRAMP, and other frameworks require continuous effort  How trusted advisors and peer groups can help leaders avoid reinventing the wheel The core message: compliance is not something you “get through.” Done right, it becomes a habit, a management discipline, and a foundation for stronger security. Guest: Sarah Lynn brings 25+ years across IT, cybersecurity, GRC, audit readiness, risk, continuity, and technology operations, helping SaaS/IaaS-driven organizations turn compliance into practical, business-aligned security. Responsible for ICAM, Zero Trust, or identity security in a federal agency, prime, or large regulated enterprise? If you’re trying to move from strategy to execution, start with Zephon’s Zero Trust Readiness Assessment: zephon.tech/zt Questions or guest ideas? Email defend@zephon.tech

About

Musings from the Cyber Trench Podcast is where cybersecurity gets real. It’s for leaders battling red tape, tech debt, and chaos, looking for straight answers, not vendor fluff. Each episode goes deep with people solving the hard problems others avoid.The vision? Bring clarity to complex, high-risk environments. Guests are sharp thinkers and operators from agencies, universities, nonprofits, and regulated industries. This is not selling; This is sharing what it actually takes to protect systems that matter.