Cyber Confersations

Confero

Cyber Confersations is a podcast exploring the conversations shaping the future of cyber. Hosted by Katie Soper, the show brings together founders, operators, and investors to unpack what’s really happening across the industry - from emerging trends and real-world challenges to the people building in the space. Less scripted and a little more real conversation. If you’re building, investing, or just genuinely curious about where cyber is heading, you’re in the right place.

  1. 3d ago

    Software Supply Chain Security: Why AI Is Changing the Threat Landscape | Nate Dunning, Ossprey Security

    The software supply chain is getting harder to secure - and AI is accelerating the problem. In this episode of Cyber Conversations, I'm joined by Nate Dunning, CEO & Co-Founder of Ossprey Security, to talk about the growing threat around open source software, AI-powered development and the changing software supply chain. Around 90% of an enterprise's code base is built on open source, creating a huge ecosystem of dependencies that attackers can exploit. And according to Nate, the scale of the threat has changed dramatically - from around two malicious packages being published every day five years ago to two every minute in 2026. We get into 👇 💻 Software supply chain security - why open source dependencies have become such an attractive attack surface. 🤖 AI-powered development - how tools like Claude Code and other AI coding assistants are changing the way developers build software, and creating new risks along the way. 🚨 The Mythos-5 incident - what happened when an AI system created malicious packages and uploaded them to PyPI, resulting in real organisations downloading them. 🔍 Behaviour vs intent - why understanding what an AI system or package actually does can be more important than what it claims it is supposed to do. ⚖️ Accountability & AI - where responsibility sits when autonomous systems cause unintended consequences. 🛡️ The “golden path” for developers - why security needs to give engineers tools they can actually use without slowing them down or forcing them to work around security controls. Nate also talks about Ossprey's recent $2.65M pre-seed, its growing number of integrations across the developer ecosystem, and why keeping close to engineers is so important when the tools they're using are changing every few months.

  2. Sep 23

    AI Agents, Digital Identity & Post-Quantum Security: The Future of Digital Trust | Ellen Boehm, Keyfactor

    In this episode of Cyber Conversations, recorded live at Black Hat, I’m joined by Ellen Boehm from Keyfactor, who leads strategy and innovation, to talk about the growing challenge of securing the infrastructure and identities underpinning modern enterprises. As organisations move towards autonomous AI agents, traditional approaches to identity are being stretched. Agents can access systems, interact with data and make decisions on behalf of people - creating a whole new category of non-human identities that need to be secured, controlled and ultimately trusted. We get into 👇 🤖 AI agents & non-human identity — why the scale and complexity of machine identities is changing rapidly. 🔐 Identity & access — how organisations can give agents the permissions they need while keeping those permissions constrained and revocable. ✍️ Securing agent instructions — why the prompts and directives an agent receives could become another layer of security that needs cryptographic verification. 🔎 Cryptographic discovery — why understanding what keys, certificates and other cryptographic assets exist is the starting point for managing risk. ⚛️ Post-quantum readiness — why organisations need to start thinking about migration now, with cryptographically relevant quantum computing potentially only a few years away. Ellen also talks through Keyfactor’s Trust Control Plane, its approach to crypto agility, and the company’s recent announced intent to acquire Cofide to strengthen workload identity management. 🎙️ Listen to the full conversation for a deeper look at AI agents, digital trust, non-human identities and why post-quantum security is becoming a much more immediate conversation.

  3. Sep 21

    AI Agent Security: Protecting Against Agentic AI Threats | Elad, Lasso Security

    What happens when AI stops simply answering questions and starts taking action on our behalf? In this episode of Cyber Confersations, I’m joined by Elad, Co-Founder & CEO of Lasso Security, live at Black Hat to talk about the rapidly evolving AI security landscape - and why agentic AI could be the next major shift security teams need to prepare for. Elad started Lasso in 2023 after seeing AI not simply as another productivity tool, but as a completely new attack surface that would require a fundamentally different approach to security. Three years on, that prediction is looking increasingly relevant. We get into 👇 🤖 The evolution of AI security - from ChatGPT and DLP to AI embedded across applications, devices and workflows. 🔎 Agent behaviour analytics - why understanding what an agent does and why could become more important than simply monitoring inputs and outputs. 🚨 Runtime anomaly detection - spotting unusual agent behaviour and giving security teams the ability to intervene, including a potential “kill switch”. ⚡ Building for a moving target - why Lasso thinks three-month roadmaps can sometimes make more sense than two-year plans when AI is evolving this quickly. 🧠 Why security needs to enable AI, not stop it - and how CISOs can become the people helping their organisations adopt agents safely rather than simply saying no. 💡 The future of agent security - as employees across organisations become agent builders, understanding what legitimate agent behaviour looks like is going to become increasingly important. We also talk about the challenges of building a company in a market that changes almost daily, the importance of offensive security in understanding how to defend AI, and why Elad believes we're experiencing something on the scale of the internet and cloud revolutions. A conversation about AI security, agentic AI, AI agents, runtime security, behavioural analysis and the future of cybersecurity.

  4. Sep 14

    Agent DLP: Securing Enterprise AI & Enabling Safe AI Adoption | Pranava Adduri, Bedrock Data

    AI adoption is moving incredibly quickly - but how do security teams enable it without losing control of their data? In this episode of Cyber Conversations, I’m joined by Pranava Adduri, Co-Founder & CTO of Bedrock Data, live at Black Hat to talk about the growing challenge of securing enterprise AI and agents. As organisations give AI agents access to more data and more autonomy, the security conversation is shifting. It’s no longer simply about whether employees can use AI - it’s about understanding what data those agents can access, what they can do with it and how to put the right controls around them. We get into 👇 🤖 Why agents create a uniquely difficult data security problem - acting on behalf of humans but without the same judgement about what they should and shouldn't combine. 🔐 Agent DLP - Bedrock Data's approach to creating a data authorisation layer for enterprise AI. 🗂️ Going back to basics - understanding what data you actually have, whether you still need it and who has access to it. 👤 Identity and access - and why getting these foundations right can make it easier to safely increase agent autonomy. 🙅‍♀️ Why security can't become the “office of no” - and how security teams can give the business the confidence to say yes to AI. 🎯 The goal of getting to “yes” - by giving security teams the ability to articulate exactly what AI and agents can and can't do with sensitive data. A really timely conversation about Agent DLP, enterprise AI security, data governance and how CISOs can enable AI adoption without compromising the security of their data. And yes, we recorded the whole thing in the Ice Bar. Because apparently cybersecurity wasn't challenging enough without adding hypothermi. 🥶

  5. Sep 10

    Enterprise AI Security: Managing Shadow AI, AI Agents & Data Risk | Michael Leland, Island

    How many AI tools are actually being used across your organisation? You might have sanctioned eight. You might actually have 243. 👀 In this episode of Cyber Conversations, I’m joined by Michael Leland, Field CTO at Island, live at Black Hat to talk about the rapidly changing AI landscape inside the enterprise - and why security teams need visibility and control much closer to the user. AI is no longer just something people access through a browser. It's moving onto desktops, into applications, developer environments and increasingly autonomous workflows. We get into 👇 🤖 The growing shadow AI problem - and why organisations may have far more AI tools in use than they realise. 👀 Why visibility has to come first - because you can't build effective governance around behaviour you can't see. 🔐 AI guardrails and data protection - from prompts and responses to tool calls, MCPs and agentic behaviour. 🧩 Why enterprises are looking for platforms rather than adding another collection of point solutions. 🙌 Why “yes, but safely” could be a better approach to AI governance than simply blocking the tools users want to use. 💻 Vibe Publishing - and what happens when AI can build and publish applications without the traditional IT development process. A conversation about shadow AI, agentic AI, enterprise AI security, data protection and what security teams need to rethink as AI becomes embedded across the entire workplace.

  6. Sep 2

    AI Deepfakes & Executive Impersonation: The New Cybersecurity Threat | Chris Pierson, BlackCloak

    What happens when cyber criminals can use AI to convincingly impersonate the people your organisation trusts most? In this episode of Cyber Conversations, Katie Soper sits down with Chris Pierson, Founder & CEO of BlackCloak, to explore how the attack surface has expanded beyond the four walls of the organisation - and why executives, their families and the people around them are increasingly becoming targets. Chris shares the story behind BlackCloak and why he saw a gap in traditional cybersecurity when it came to protecting executives in their personal lives. We get into 👇 🏠 Why the home has become another cybersecurity battleground - and how remote work dramatically expanded the attack surface. 🤖 How AI is changing impersonation attacks - with deepfake video and audio becoming increasingly convincing. 💻 Why detection alone isn't enough - particularly when attackers can choose from so many different communication channels. 👤 Why executives are particularly vulnerable - their photos, videos, voices and personal information are already publicly available. 👨‍👩‍👧 The growing importance of the 'circle of trust' - extending protection beyond the executive to family members, assistants, advisors and other trusted contacts. 💸 The financial impact of deepfake fraud - including the real-world consequences of convincing executive impersonation. 🔐 Why security needs to work around people's lives, rather than simply telling them what they can and can't do. As AI continues to make impersonation cheaper, faster and more convincing, protecting an organisation increasingly means thinking about the people behind it - and the digital lives that exist beyond the corporate environment. A conversation about AI deepfakes, executive protection, cyber fraud, privacy and the changing human attack surface.

About

Cyber Confersations is a podcast exploring the conversations shaping the future of cyber. Hosted by Katie Soper, the show brings together founders, operators, and investors to unpack what’s really happening across the industry - from emerging trends and real-world challenges to the people building in the space. Less scripted and a little more real conversation. If you’re building, investing, or just genuinely curious about where cyber is heading, you’re in the right place.