The Cyber Business Podcast

Matthew Connor

Welcome to The Cyber Business Podcast where we feature top founders and entrepreneurs and share their inspiring stories.

  1. 3d ago

    Build Versus Buy: The Risk of Vibe Coding Your Security Stack with Andrew Dutton - Ep 238

    Guest Introduction Andrew Dutton is the Regional Cybersecurity Architect for Sumitomo Chemical America, part of a global chemical manufacturing organization with roots stretching back more than 400 years, from copper mining in Japan to fertilizer production to the diversified chemical business that exists today. The company employs roughly 30,000 people worldwide, and Andrew's region also serves as its global center of excellence for cybersecurity. Andrew, himself an Army veteran, brings both a technical architect's precision and genuine appreciation for how the company operates. He joins the show to lay out a vision he has spent years developing for an AI operations layer, a way to get plain language answers about an organization's entire security posture instead of digging through disconnected tools, and to talk candidly about where the industry is already there and where real risk remains.   Here's a Glimpse of What You'll Learn How Andrew's AI operations layer concept would let a CEO get a real, honest answer to are we secure Why Andrew says showing someone a raw count of 100,000 vulnerabilities is worse than useless How a real threat actor actively targeting chemical manufacturers shows proactive AI defense in practice Why Andrew calls traditional email gateways obsolete compared to modern AI powered alternatives The build versus buy risk Andrew sees in constructing an AI security stack without the right expertise Why Andrew believes the real barrier to good decisions is a decline in critical thinking, not the technology Andrew's take on how AI could reshape careers and the outdated idea of job security tied to one employer   In This Episode Andrew opens by describing a concept he has developed for years, an AI operations layer sitting on top of every tool in the security stack with read only access, connecting inventory systems, EDR platforms, and CMDBs that often disagree with each other into one place a security leader can question in plain language. He walks through a concrete example: asking which servers aren't running EDR sounds simple, but reconciling an inventory system against an EDR platform against a CMDB that all define server ownership differently is exactly the tedious work an AI layer should absorb. He argues this layer should prioritize problems, telling a team the specific top ten things to fix rather than dumping a raw vulnerability count with no actionable meaning. From there he describes a proactive use case: asking which threat actor is currently targeting chemical manufacturers most aggressively, learning the specific technique that group uses, checking whether current defenses actually stop it, and kicking off a purple team exercise to verify the answer rather than trusting the tool's word for it. The conversation moves into how mature this vision already is, and Andrew is blunt that machine learning built directly into security products, tools like Darktrace and ThreatLocker that catch abnormal behavior or block unauthorized actions outright regardless of how an attacker got in, is no longer the future but table stakes today. He connects this to the MGM breach, arguing behavioral AI would have flagged a brand new admin account performing wildly unusual actions long before a human analyst noticed, and he is equally direct that traditional email gateways are obsolete, pointing to how Proofpoint acquired specialized players like Tessian to bolt AI powered behavioral analysis onto legacy filtering that can no longer keep pace with attacks arriving through legitimate services like DocuSign. He is also candid about the real risk of building these systems in house without the right expertise, describing how easy it is to vibe code an impressive prototype without understanding what it is doing underneath, burning through token costs on the wrong model, and comparing the temptation to the early rush to the cloud that left organizations with runaway bills. The back half broadens into how AI reshapes work and opportunity. Andrew argues the biggest barrier isn't the technology but a decline in critical thinking, and that organizations need people who can analyze a problem within its full business context rather than accepting whatever an AI tool outputs at face value. He shares a grounded perspective on job security as something that no longer comes from loyalty to one employer, describing his volunteer work helping high school students in rural Tennessee see paths beyond the local plant, and arguing that financial stability and a strong personal skill set matter more than tenure. He closes on an optimistic note about where AI could take society, from reducing domestic violence through in-home monitoring to enabling small, highly leveraged companies built by a handful of people, while acknowledging some of the hardest human problems are unlikely to be solved by technology alone.   This episode is brought to you by Cyberlynx CyberLynx is a Bethesda managed IT and cybersecurity company. Local techs you know, not a call center. Month-to-month. 24/7 intrusion detection. We help growing companies with managed IT, help desk, backup and recovery, and a fractional CIO. Talk to us at https://cyberlynx.com/contact, info@cyberlynx.com, or 301-798-9170.

  2. 4d ago

    The Security Sidecar: Wrapping Code in Real Time Defense with Aby Rao - Ep 237

    Guest Introduction Aby Rao is the Deputy CISO at Paylocity, where he leads a wide ranging cybersecurity operation protecting customer data across the company's SaaS platform. With 16 years in the field, Aby has built his approach around a clear hierarchy, talent first, then process, then execution, and now layers AI on top of that foundation to accelerate everything from new hire onboarding to vulnerability detection. He joins the show to talk about using AI to compress a year of business knowledge into two months, where voice agents belong and don't belong, and why he thinks the era of easy ransomware money may be closing.   Here's a Glimpse of What You'll Learn Why Aby built his security program around talent first, then process, then execution How Aby uses AI to help new employees understand the business in two months instead of a year The three layer framework Aby uses to turn scattered documentation into usable knowledge Why Aby believes voice agents work well for routine calls but not yet for 911 or crisis situations How Aby's security sidecar concept wraps every piece of new code with a business agent and a security agent Why Aby thinks patch management alone can no longer keep pace with how fast code ships today Why Aby believes the current window of easy ransomware profits may be closing because of AI   In This Episode Aby opens by explaining how he approached his first years at Paylocity, prioritizing talent above everything else before layering in stronger processes and only then focusing on execution. He argues that AI now accelerates a step organizations have historically underinvested in, getting new employees up to speed on the business itself, and describes a three layer method for doing it: starting with public domain research, moving into technical documentation stored in tools like Confluence or ServiceNow, and finishing by validating that knowledge directly with business contacts. He believes this kind of onboarding, which traditionally took a year, can now happen in as little as two months. The conversation turns to where AI agents genuinely belong in customer and public facing interactions. Drawing on his graduate background in human computer interaction, Aby argues that voice agents handle routine, low stakes requests well, but that situations involving physical risk, like a 911 call, still require a human who can read sentiment and respond with genuine urgency. He is candid that AI is not there yet on the emotional and contextual judgment those moments require, even as he agrees the underlying technology is improving quickly, drawing the same comparison to early self driving cars that has come up elsewhere in the series. The back half of the episode focuses on where Aby thinks security is headed structurally. He describes a concept he calls the security sidecar, wrapping new code with two agents working in real time, one representing business logic and one representing security expertise, rather than relying on after the fact log review. He connects this to a broader argument that traditional patch management can no longer keep pace with organizations shipping ten releases a day, and that the real answer is AI monitoring systems that catch abnormal behavior the moment an intrusion happens, regardless of which vulnerability let it in.   This episode is brought to you by Cyberlynx CyberLynx is a Bethesda managed IT and cybersecurity company. Local techs you know, not a call center. Month-to-month. 24/7 intrusion detection. We help growing companies with managed IT, help desk, backup and recovery, and a fractional CIO. Talk to us at https://cyberlynx.com/contact, info@cyberlynx.com, or 301-798-9170.

  3. 5d ago

    Doing More With Less: A Department of Three Punching at Twenty with Tony Bryson - Ep 236

    Guest Introduction Tony Bryson is the first Chief Information Security Officer for the Town of Gilbert, Arizona, a municipality that has grown from roughly 15,000 residents at the turn of the century to nearly 300,000 today, making it the fourth largest municipality in the state. Tony was recruited into the role by a former colleague from Mesa Community College and has spent six years building Gilbert's cybersecurity program from the ground up. He joins the show to talk about doing more with less as a department of three, the town's early and deliberate approach to AI governance, and why he still draws a hard line on where AI belongs in the decision making process.   Here's a Glimpse of What You'll Learn How Tony reduced Gilbert's security tool spend while getting more protection out of a leaner budget Why Gilbert started formal AI discussions roughly four years ago, well ahead of most organizations Why Gilbert created a chief artificial intelligence officer role and what changed because of it How Tony distinguishes machine learning from generative AI when it comes to actually stopping attacks Why Tony won't let AI serve as the final peer reviewer on any change to production systems The Abraham Lincoln story Tony uses to explain how he tempers emotional decisions Why Tony compares artificial intelligence to a phenomenally intelligent toddler   In This Episode Tony opens by walking through what it took to become Gilbert's first ever CISO, brought in specifically to look at cybersecurity strategically across the whole organization rather than department by department. He describes his first move as auditing the town's existing security spend and discovering money going toward tools that weren't being used properly, a decision that shrank his budget dramatically but let his team of three operate with the impact of a much larger department through carefully chosen strategic partnerships. The conversation moves into how Gilbert approached artificial intelligence years before most organizations took it seriously, with Tony's office starting formal discussions about governance, guardrails, and data access roughly four years ago. That early groundwork led to the creation of a chief artificial intelligence officer position, a decision Tony says changed how the organization operates but also introduced new concerns, particularly around agentic AI, which he describes as opening a Pandora's box that cannot be closed again. He is candid that generative AI has not yet earned his full trust for frontline security work, arguing that machine learning products built specifically for behavioral detection remain far more reliable at catching abnormal activity like the kind that led to the MGM breach. The back half of the episode centers on where Tony draws firm boundaries around AI's role. He explains why he will not let artificial intelligence serve as the sole peer reviewer on any production change, citing liability and the need for a human stakeholder with real accountability, though he is open to AI catching mistakes as one voice among several. He also shares a personal system, inspired by a story about Abraham Lincoln's unsent letters, for using a cooling off period and AI assistance to temper emotionally charged communications before they go out, a practice he says has become part of how he leads through moments of crisis.   This episode is brought to you by Cyberlynx CyberLynx is a Bethesda managed IT and cybersecurity company. Local techs you know, not a call center. Month-to-month. 24/7 intrusion detection. We help growing companies with managed IT, help desk, backup and recovery, and a fractional CIO. Talk to us at https://cyberlynx.com/contact, info@cyberlynx.com, or 301-798-9170.

  4. Sep 9

    The Age of Human Judgment, Not the Age of AI, With Benny Zhang - Ep 235

    Guest Introduction Benny Zhang spent years as VP of IT at Orion Group, where he built and led the company's entire technology organization, including infrastructure, cybersecurity, service desk, and application support, before transitioning into investing full time. Benny's path started in chemical engineering, then shifted into IT when he became a one man department overseeing everything from servers and networking to board level reporting. Today he applies that same systems thinking to markets, having built his own AI connected trading tool that analyzes his portfolio and holds him accountable to a written investment strategy. He joins the show to talk about his path from engineer to IT leader to full time investor, and how he uses AI as both a technical partner and a decision making gatekeeper. Here's a Glimpse of What You'll Learn How Benny went from chemical engineer to one man IT department overseeing infrastructure and cybersecurity Why Benny transitioned from VP of IT into investing full time, and what that transition actually looks like How Benny built an AI connected trading analysis tool without being a professional coder Why Benny argues we are in the age of human judgment, not the age of AI The spring roll story that taught Benny not to blindly trust AI generated instructions Why Benny thinks more than 90 percent of businesses still are not using AI effectively How Benny uses ChatGPT as a gatekeeper to hold himself accountable to his own investment strategy In This Episode Benny opens with his path into technology, starting with a childhood Commodore 64 and a book about Steve Jobs that shaped his early fascination with tech, before family pressure pushed him toward chemical engineering instead. After several years as a plastics manufacturing engineer, an opportunity opened when his employer lost its entire IT staff at once, and Benny volunteered to take over, spending years as a one person IT department handling infrastructure, cybersecurity, networking, and data center operations alongside board presentations and audits. He argues that experience, more than any traditional help desk path, is what made him capable of eventually leading a full IT team at Orion Group, where he oversaw service desk, infrastructure and cybersecurity, procurement, and application support as VP of IT. The conversation shifts to Benny's transition into investing full time, where he describes treating every dollar as an employee generating future returns, and explains the discipline behind choosing to hold NVIDIA stock instead of buying a Porsche 911. He is candid that he started investing later than he wishes he had, and frames his current full time focus not as chasing a net worth number but as proving his own investment strategy is sound and repeatable. He also talks through his philosophy on spending, favoring travel and experiences over status purchases, drawing on a story from Notre Dame in Paris about the value of seeing the world while still physically able to. The back half of the episode centers on how Benny's technical background from his IT career carries directly into how he invests today. He built a tool that connects ChatGPT to his brokerage account, filters his watchlist, and runs opportunities through his own written investment strategy before presenting recommendations, a project he says took him less than a week despite not being a professional developer. He shares a story about ChatGPT giving him bad cooking advice as a lesson in why human judgment still matters, and argues that the real divide forming in the workforce is not between AI users and non-users, but between people who command AI as a tool, the way he does with both his infrastructure background and his trading system, and people who follow it blindly. SPONSOR FOR THIS EPISODE This episode is brought to you by Cyberlynx CyberLynx is a Bethesda managed IT and cybersecurity company. Local techs you know, not a call center. Month-to-month. 24/7 intrusion detection. We help growing companies with managed IT, help desk, backup and recovery, and a fractional CIO. Talk to us at https://cyberlynx.com/contact, info@cyberlynx.com, or 301-798-9170.

  5. Sep 7

    Why Patch Management Is No Longer Frontline Defense with Brett Price - Ep 234

    Guest Introduction Brett Price is the Global CISO at Quint, a publicly owned company that builds hospitality and entertainment packages for major sporting events including Formula One, tennis, the NBA, the NHL, and MotoGP. He oversees cybersecurity, governance, and compliance across the parent organization and five international subsidiaries spanning Australia, the Netherlands, southern Spain, and Monaco. Brett brings a hands on view of what it takes to secure a global operation under GDPR, CPRA, and dozens of overlapping data privacy regimes while staying ahead of AI powered threats on every front at once.   Here's a Glimpse of What You'll Learn Why Brett believes patch management alone is no longer enough to stop machine speed attacks How a Global CISO balances GDPR, CPRA, and data privacy law across five international subsidiaries What the Hugging Face sandbox incident taught the security industry about controlling agentic AI Why identity, not endpoint protection, is where Brett would put a small business's first security dollar How AI powered SOC tools are closing the gap for organizations without large security teams Why Brett thinks the good guys ultimately win the AI arms race, and what has to happen first The lesson Brett draws from the MGM breach about detecting abnormal admin behavior Why Brett expects AI to eventually remove the need for end user security awareness training entirely   In This Episode Brett opens by walking through what a day actually looks like running cybersecurity for a company with five international subsidiaries in Australia, the Netherlands, southern Spain, and Monaco, describing the balancing act between board reporting, vendor management, vulnerability management, and a growing stack of global data privacy law. GDPR, CPRA, and country specific regulations all compete for attention, and Brett makes clear that governance is not a side function of the job, it is the job. He frames the current moment in cybersecurity as genuinely exciting rather than purely alarming, arguing that whether AI feels exciting or scary comes down entirely to perspective. From there the conversation turns to AI as both the threat and the defense. Brett draws a direct line to the cloud adoption era, arguing that organizations rushed into the cloud without bringing security along, and that the same mistake is playing out again with generative and agentic AI. He points to the Hugging Face sandbox incident as a wake up call, noting that hundreds of CISOs came together through the Cloud Security Alliance to document what happens when agentic AI escapes its intended boundaries, and he raises China's reported use of autonomous agents against the Taiwanese government as evidence the threat is not theoretical. Brett is candid that AI vendors incorporating agents into their own products raises a new category of due diligence questions most organizations have not caught up to, and he floats a future where a lightweight AI agent on a phone could intervene in real time to stop elderly relatives from falling for scam calls. The conversation closes on where Brett believes the smartest money goes for organizations of any size. He argues identity has become the new perimeter, favors managed detection and response over alerting alone, and pushes back on the idea that modern security is out of reach for small and mid sized businesses, comparing the market to needing an F150 rather than a Ferrari for most jobs. He delivers a hot take that patch management can no longer be treated as frontline defense, referencing rising zero day discovery rates and a 2026 DBIR report that put vulnerability exploits ahead of identity as the top attack vector, and argues defenses need to catch abnormal behavior in real time rather than relying on hardened software alone. Sponsor for this Episode This episode is brought to you by Cyberlynx CyberLynx is a Bethesda managed IT and cybersecurity company. Local techs you know, not a call center. Month-to-month. 24/7 intrusion detection. We help growing companies with managed IT, help desk, backup and recovery, and a fractional CIO. Talk to us at https://cyberlynx.com/contact, info@cyberlynx.com, or 301-798-9170.

  6. Sep 2

    Generals in the Command Post: AI Security and Human Identity with Erik Miller - Ep 233

    Guest Introduction: Erik Miller is the Director of Information Technology at LifePort, an aerospace company that develops and manufactures aircraft interiors including ballistic armor protection, medical inserts, medical devices, high-end cabinetry, and premium seating for corporate and government aircraft. With a career built at the intersection of technology, cybersecurity, business operations, and artificial intelligence, Erik also serves in a fractional CTO capacity, bringing strategic perspective to an organization operating in one of the most demanding and consequential technology environments in aerospace manufacturing. He is one of the more philosophically engaged guests the podcast has featured, with a wide-angle view on what the AI era means not just for security but for human identity, the economy, and civilization itself.   Here's a Glimpse of What You'll Learn Why Erik frames the AI security battle as a wild West arms race where the only question is who has the biggest gun and why the answer has to be behavioral AI Why the MGM breach should be a wake-up call for every organization and why what failed there was not their investment in security but the absence of machine learning that models normal behavior Why Erik believes humans should be the generals in the command post, not the troops on the front line, and what that means for how security teams need to be structured Why the transition from coder to manager of coders is the healthiest and most honest way to frame what AI does to technical identity Why AI is going to trigger denial, anger, resistance, and tribalism before society reaches the identity redefinition that actually allows adoption to compound Why Erik sees a coming Renaissance era for human-created art and craftsmanship as AI-generated content floods every platform and loses its novelty Why the long pole in the AI transition is never technological but always human, and why Gen X and baby boomers have the hardest adjustment ahead   In This Episode Erik opens with a description of LifePort that establishes the stakes immediately. This is not a software company. It manufactures ballistic armor protection, medical devices, and high-end interiors for aircraft operating in environments where failure is not an option. The technology decisions Erik makes, from cybersecurity architecture to AI adoption, carry consequences measured in operational continuity and physical safety. That context shapes his framing of the AI security arms race as the wild West, not as a metaphor but as an accurate description of an environment where the pace of escalation has outrun every institutional response. A medium-sized company with $100 million in revenue and a few hundred employees is now receiving nation-state-quality attacks that are phenomenally better than they were a year ago. The humans on the receiving end of those attacks are pawns against queens and bishops, and no amount of training changes that arithmetic. His argument for behavioral AI is grounded in exactly that asymmetry: the only defender that can keep pace with a machine-speed attacker is a machine that understands what normal looks like and stops the anomaly before any human has to see it. The identity section of this episode is where Erik separates himself from most security guests. His account of his daughter's experience at Bloomberg is a concrete and personal version of the coder identity transition that is happening across the technology industry right now. She is exceptional at her craft. Bloomberg now requires her to use AI. The work she produces is faster, more productive, and objectively better. And she misses coding. That tension is not a failure of adaptation. It is a genuinely human response to a tool that has changed what it means to be valued for a skill. Erik's reframe is generous and practical: you did not lose your job as a coder, you gained coders to manage. The thought process moved upstream. The architecture, the business context, the security implications, those are the things that cannot be automated, and they are now the things that matter most. His argument that one coder leveraging AI has the output of ten, and that a growing organization would hire more rather than fewer because of that multiplier, is the most optimistic and the most economically coherent argument this podcast has featured on the AI workforce question. The philosophical conversation that takes up the second half of this episode covers more ground than most episodes attempt in total. Erik traces the human adoption curve from denial through anger through tribalism to identity redefinition, arguing that the curve is already well underway and that the technology gaps, the chips, the cooling, the power, have always been solved by engineering and always will be. The real problem is whether Gen X and baby boomers whose identity is built around their work can make the transition to a world where work is optional. His reference point is ancient Rome, where the citizens who had slaves doing everything split into those who focused on self-improvement and those who atrophied. He is not naive about where some people will land. But he is genuinely optimistic about the majority, grounded in a conviction that human curiosity does not disappear when the pressure of survival is removed. It amplifies. The Renaissance he anticipates for human-created art, the value that handmade and authentic will carry when AI-generated content is everywhere and costs nothing, is the most original and forward-looking argument in the episode. And his answer to what he personally would do if money were no object, breakfast with his family, hiking, exploring, spending time with his brother, is the most human and most grounded moment in a conversation that ranges from aerospace security to the singularity. This episode is brought to you by Cyberlynx

  7. Aug 31

    Why UNICEF USA Is One of the Hardest Security Jobs with Andrew Nuxoll - Ep 232

    Guest Introduction Andrew Nuxoll is the Managing Director of IT Operations and Cybersecurity at UNICEF USA, the United States fundraising arm of UNICEF Global, a children's charity founded after World War 2 that supports education, clean water, and opportunity for children throughout the world. In his role, Andrew oversees both technology operations and cybersecurity for an organization that sits at the convergence of financial, political, and ideological threat vectors simultaneously, making it one of the more uniquely complex security environments featured on this podcast. He brings a career that moved from building and repairing custom computers to help desk to network engineering to cybersecurity leadership, shaped throughout by a conviction that the human element is more important than any tool.   Here's a Glimpse of What You'll Learn Why UNICEF USA faces a uniquely complex threat profile sitting at the convergence of financial, political, and ideological motivations most organizations never contend with simultaneously Why Andrew believes AI-powered defense is no longer optional and why waiting while attackers are already using AI is a position he cannot understand Why user awareness is the foundational starting point for any security posture and why layered security without it is a structure missing its most important floor Why insider threat is almost always accidental rather than nefarious and why the entire industry misunderstands this at significant cost Why analysis paralysis is the enemy of a better security posture and why incremental improvement always beats waiting for the perfect solution Why building leaders around you and surrounding yourself with people who think differently are the two most important career moves any technology leader can make Why cultural fit is not about hiring people like you and what it actually should mean when you are building a team.   In This Episode Andrew opens by framing what makes UNICEF USA a fundamentally different security environment than most organizations. A financial institution is targeted because of money. A government agency is targeted for political reasons. UNICEF USA sits at all of those intersections at once, collecting donations at the scale of a bank while also being a high-profile global brand that draws ideological opposition from threat actors who disagree with the mission it supports. Andrew is direct that this is not a theoretical concern. The attempts are real, they are constant, and the AI-powered threat environment has changed the calculus in a way that makes the old answer of strong firewalls and current patches insufficient. His position on AI in security is unambiguous: you cannot wait while attackers are already using it. The organizations that are holding back are not being cautious. They are falling behind in a way that is increasingly difficult to recover from, and the cost of that gap grows every day the decision is deferred. The security philosophy Andrew articulates in this episode is built on two principles that reinforce each other throughout the conversation. The first is that user awareness is the most important and most cost-effective starting point for any security program. Not because tools are unimportant but because the end user is the real choke point in every successful attack Andrew has seen. The MGM breach is the example he reaches for: an organization with significant security investment, defeated not by a technical exploit but by social engineering that put a new admin account inside the environment doing things no legitimate admin would do on day one. His second principle is layered security, which is the architecture that catches what user awareness misses. The two are not in competition. They are the foundation and the structure built on top of it, and missing either one creates a gap that no amount of spending on the other can fully close. Andrew's additional reframe of insider threat is one of the most practically useful moments in this episode: most insider threat is accidental. The employee who clicks the wrong link, picks up a thumb drive in the parking lot, or falls for a phishing email is not a bad actor. They are a victim of the same social engineering that defeats organizations far more sophisticated than they are, and treating them as a threat to be managed rather than a person to be educated is how organizations end up with the worst of both worlds. The career and leadership section of this episode lands with the same weight as the security conversation. Andrew spent years interviewing and hiring hundreds of people and describes a shift in how he thinks about cultural fit that is worth sitting with. Early in his career, he cared whether a candidate was a good fit for his personality. He does not anymore. What he looks for now is hard work, kindness, the ability to collaborate professionally, and a willingness to think differently from the people already in the room. The organization he watched implode years later did so because everyone in it thought exactly the same way. No new ideas, no fresh perspectives, no productive friction to generate better decisions. His two principles for building a career and a team are equally direct: build leaders around you and give people opportunities without fear that developing them diminishes you, and surround yourself with people who do not think like you because those are the people who will show you parts of a problem you could not see from your own vantage point.

  8. Aug 27

    Vibe Coding, Micro Businesses, and Fighting Fire with Fire with Alexander Tushinsky - Ep 231

    Guest Introduction Alexander Tushinsky is the CISO of Educate 360, a global education company offering IT training, cybersecurity courses, compliance programs, and professional development across multiple brands and industries. He came to Educate 360 through the acquisition of TCM Security, where he served as CTO, and brings a career that spans 35 years of software development, small business consulting since 1993, and enterprise security leadership at organizations including PepsiCo and Intel. His dual vantage point as both a practicing CISO and a long-standing consultant to micro businesses gives him one of the broader views of the AI and security landscape across organizational sizes featured on this podcast.   Here's a Glimpse of What You'll Learn Why Alex believes vibe coding without foundational development knowledge produces results nobody actually wanted, and why the same principle applies to AI in education How Educate 360 is already training AI agents to simulate personality-based conversations so learners can practice real interactions before having them Why AI is heavily subsidized right now and what that means for every business that has become dependent on current pricing before the bill comes due Why micro businesses that have avoided attacks for 15 years are about to discover the environment has changed and why walking through lightning storms holding a rod only works until it does not Why cybercriminals with hundreds of millions in stolen funds could run a cutting-edge open source model locally for $50,000 to $60,000 in hardware and what that means for the arms race Why Alex sees AI as the only way to fight machine-speed attacks, blocking fake DocuSigns and malicious PDFs that legitimate email gateways cannot distinguish from real ones Why the good guys will ultimately win but only by fighting fire with fire, and why every day defenders have to win while attackers only need to win once   In This Episode Alexander opens with a framing of his role that is broader than most CISOs on this podcast have offered. He has been consulting to small and micro businesses since 1993, which gives him a ground-level view of what cybersecurity looks like, and mostly does not look like, for organizations that have no IT department and one QuickBooks machine. The pool guy who called him after getting ransomed and losing $35,000 in payroll from a single locked machine. The accountant who had no idea they were required to follow specific data regulations. The law firm sharing client documents through Dropbox with no vetting of who accessed them. These are not hypotheticals. They are the pattern Alex has watched repeat itself across 30 years of consulting, and the through-line is always the same: the business survived long enough to believe it was not a target, and then the environment changed around it while the business stayed still. His argument is precise and difficult to dispute: walking through lightning storms holding a rod works until it does not, and the environment has changed so dramatically in the past two years that the historical odds no longer apply. The AI and education section is where Alexander's position at Educate 360 gives this episode a perspective unavailable elsewhere this season. He is not just using AI. He is building it into the training products his company sells. One brand, TRACOM Group, which focuses on behavioral styles and how people communicate across personality types, has trained agents to simulate the other side of a conversation so learners can practice real interactions with a realistic conversational partner. The implications for professional development, compliance training, and cybersecurity awareness extend well beyond a single course. He also makes one of the clearest statements about vibe coding and its limits this podcast has featured: giving Claude a general description of what you want to build is not materially different from giving a human developer a general description. Requirements, architecture, and feature definition have to come first. The developers who succeed with AI coding tools are the ones with 35 years of context about how software actually gets built, what the edge cases look like, and what it means to release something that other people depend on. The vibe coders who fail are the ones who discover the $4,000 bill, the broken production system, or the leaked credentials after the fact. The most forward-looking and provocative exchange in this episode is Alex and Matthew working through the economics of AI-powered cybercrime. The current subsidized pricing environment means organizations are building dependencies on capabilities they may not be able to afford at full cost. More unsettling is the calculation around criminal organizations: groups that have accumulated hundreds of millions of dollars through ransomware and fraud could acquire the hardware needed to run a capable open source model locally, at a price point that represents a rounding error against their reserves, with no access restrictions from Anthropic or OpenAI to worry about. That observation, made in real time during the conversation, is one of the most candid and practically alarming moments the podcast has captured this season. Alex closes where he begins every conversation on this topic: an eternal optimist who believes the good guys will ultimately win, but who understands that the win only comes to organizations willing to bring AI to a fight that was already being fought with AI by the other side.

5
out of 5
4 Ratings

About

Welcome to The Cyber Business Podcast where we feature top founders and entrepreneurs and share their inspiring stories.