Ctrl+Alt+AI

BigID

Rebooting the way we think about AI, data, & risk.

  1. Why Agent Identity Is Now a Security Priority

    12/10/2025

    Why Agent Identity Is Now a Security Priority

    AI agents are moving fast, and security teams are scrambling to keep up. Join us as Heather Ceylan, SVP & Chief Information Security Officer at Box, who has spent the last several years leading security teams through rapid change from the explosive growth years at Zoom to her current work shaping Box’s AI posture. Heather shares what it actually feels like to run security at a time when agents can be created in minutes, permissions matter more than ever, and governance committees are struggling to keep pace. She explains why treating agents as identities fundamentally changes the model, how MCP servers introduce new exposure points, and why her team is embedding AI directly into SOC work, design reviews, and vulnerability remediation. It’s a grounded look at how a CISO makes sense of AI while everything around the role continues to shift. In this episode, you’ll learn: Why agents need their own identities and permissions rather than inheriting access from the people who create them How SOC teams can shift from constant alert triage to real threat hunting with the help of AI agents How AI can speed up vulnerability remediation by creating pull requests that engineers only need to review and merge Things to listen for:  (00:00) Meet Heather Ceylan (00:58) Career path from healthcare to Zoom to Box (03:58) Risks of AI agents accessing unstructured content (05:18) Why agent identity and permissions are the new priority (06:50) The challenge of discovering and governing ephemeral agents (08:16) How sandboxes and policies support safe experimentation (09:20) AI governance gaps and the need for dedicated ownership (13:10) Defining AI governance across technical and legal domains (16:17) The rise of MCP servers and new exposure points (18:05) Four AI bets transforming Box’s SOC and security workflows (23:31) KPIs and measuring AI’s impact on security teams (25:27) Resource trade-offs when adopting AI in security (27:58) Managing the complexity of model selection and trust (29:58) Should companies form dedicated AI security teams?

    32 min
  2. Privacy Professionals on the Front Lines of AI Risk

    11/26/2025

    Privacy Professionals on the Front Lines of AI Risk

    Security and privacy leaders are under pressure to sign off on AI, manage data risk, and answer regulators’ questions while the rules are still taking shape and the data keeps moving.  On this episode of Ctrl + Alt + AI, host Dimitri Sirota sits down with Trevor Hughes, President & CEO of the IAPP, to unpack how decades of privacy practice can anchor AI governance, why the shift from consent to data stewardship changes the game, and what it really means to “know your AI” by knowing your data.  Together, they break down how CISOs, privacy leaders, and risk teams can work from a shared playbook to assess AI risk, apply practical controls to data, and get ahead of emerging regulation without stalling progress. In this episode, you’ll learn: Why privacy teams already have methods that can be adapted to oversee AI systems Boards and executives want simple, defensible stories about risk from AI use The strongest programs integrate privacy, security, and ethics into a single strategy Things to listen for:  (00:00) Meet Trevor Hughes (01:39) The IAPP’s mission and global privacy community (03:45) What AI governance means for security leaders (05:56) Responsible AI and real-world risk tradeoffs (08:47) Aligning privacy, security, and AI programs (15:20) Early lessons from emerging AI regulations (18:57) Know your AI by knowing your data (22:13) Rethinking consent and data stewardship (28:05) Vendor responsibility for AI and data risk (31:26) Closing thoughts and how to find the IAPP

    32 min
4.8
out of 5
12 Ratings

About

Rebooting the way we think about AI, data, & risk.