AI Security, Cyber Risk, and Cloud Strategy on ClearTech Loop

ClearTech Research / Jo Peterson

Season 2 of ClearTech Loop is built around three questions:  How is AI changing the way organizations think about risk?  What does stronger cybersecurity leadership look like right now?  How should leaders rethink cloud strategy as business and technology keep shifting? Hosted by Jo Peterson, Chief Analyst at ClearTech Research, ClearTech Loop is a fast, focused podcast covering AI, cybersecurity, and cloud risk through a business leadership lens.  Each 10-15 minute episode explores the issues shaping modern technology strategy and the decisions leaders cannot afford to ignore. From governance and resilience to infrastructure change and emerging risk, ClearTech Loop helps leaders make sense of what is shifting, what matters most, and what comes next.

  1. 16h ago

    AI Agent Governance: Who Owns the Risk? with Benny Czarny of OPSWAT

    Guest  Benny Czarny  CEO, Founder & Chairman of the Board  OPSWAT  Host  Jo Peterson  CIO, Clarify360  Chief Analyst, ClearTech Research  AI agents have credentials. They access enterprise data. They make decisions. And increasingly, they can act without waiting for a human.  So who actually owns the risk?  Jo Peterson sits down with Benny Czarny, CEO, Founder & Chairman of the Board at OPSWAT, to talk about what AI agent governance needs to look like as autonomous AI moves deeper into the enterprise.  They discuss why every AI agent needs its own identity and a human owner, how least privilege should apply to agents and sub-agents, and why understanding what data an agent can access may be just as important as securing the model itself.  Benny also shares where CISOs should start if they don’t yet have an AI agent inventory or governance framework in place.  In This Episode  Why every AI agent needs a human owner Least privilege for AI agents and sub-agents The growing risk around AI data access Why AI governance needs real authority The first step CISOs should take in the next 30 days Chapter Markers  00:00 Meet Benny Czarny of OPSWAT 01:40 Protecting critical infrastructure 02:05 Least privilege for AI agents 03:58 Permanent credentials and autonomous agents 05:15 Does AI governance actually work? 07:23 Where CISOs should start 09:29 Protecting the AI data lake 12:34 What AI can learn from OT security 13:12 Cloud, on-prem and air-gapped AI 13:54 OPSWAT’s own AI journey  Resource Links  OPSWAT https://www.opswat.com/ OPSWAT Academy https://opswatacademy.com/ Cybersecurity Upside Down — Benny Czarny https://www.amazon.com/dp/B0GH8SZXJ9 ClearTech Research https://cleartechresearch.com/ ClearTech Loop Newsletter https://www.linkedin.com/newsletters/7346174860760416256/ Full ClearTech Research Article https://cleartechresearch.com/ai-agent-governance-benny-czarny/ 🎧 Listen: In Buzzsprout Player ▶ Watch on YouTube: https://www.youtube.com/@ClearTechResearch/videos 📰 Subscribe to the Newsletter: https://www.linkedin.com/newsletters/7346174860760416256/

    AI Agent Governance: Who Owns the Risk? with Benny Czarny of OPSWAT
  2. Aug 18

    Your AI Agents Are Already Running. Can You See Them? | Alvaro Gonzalez

    AI agents can hold credentials, access sensitive data, make decisions and even create other identities. But many organizations still cannot answer a basic question: what is actually running in the environment?  In this episode of ClearTech Loop, Jo Peterson sits down with Alvaro Gonzalez, SVP of Product and Go-to-Market at Assured Data Protection, to talk about what AI governance looks like when identity and access are changing at machine speed.  Alvaro explains why organizations should start with three things: inventory, observability and remediation. They also discuss whether AI governance committees are actually governing or merely documenting, why CISOs should inventory agents before building more policy, and how Alvaro’s idea of “controlled aggression” can help enterprises experiment with AI without losing the ability to recover when something goes wrong.  You cannot govern what you cannot see.  Listen to Learn  Why AI agent governance should start with inventory What least privilege looks like when identities can create other identities Why observability matters alongside access control Why remediation belongs in the AI identity conversation Whether AI governance committees are really changing behavior What Alvaro means by “librarians and warriors” How “controlled aggression” can help organizations move faster without losing control Featured Soundbite  “You cannot govern what you cannot see.”  — Alvaro Gonzalez  Featured Guest  Alvaro Gonzalez  SVP of Product and Go-to-Market  Assured Data Protection  Alvaro leads product, alliance, marketing and go-to-market functions at Assured Data Protection, with a focus on data protection, cyber resilience and the systems that support field and channel execution.  Host  Jo Peterson  CIO, Clarify360  Chief Analyst, ClearTech Research  Episode Links  Full episode webpage: https://cleartechresearch.com/ai-agent-governance-alvaro-gonzalez/  Subscribe to ClearTech Loop: https://www.linkedin.com/newsletters/7346174860760416256/  Watch on YouTube: https://www.youtube.com/@ClearTechResearch  Additional Resources  Assured Data Protection: 5 Ways You Can Improve Your Cyber Recovery Plan https://assured-dp.com/guides/5-ways-you-can-improve-your-cyber-recovery-plan-with-assured-data-protection/  NIST AI Risk Management Framework https://www.nist.gov/itl/ai-risk-management-framework  Model Context Protocol — Security Best Practices https://modelcontextprotocol.io/specification/draft/basic/security_best_practices  Previous ClearTech Loop: AI Agents Shouldn’t Be Trusted by Default with Elliott Mattice https://cleartechresearch.com/ai-governance-trust-elliott-mattice/  🎧 Listen: In Buzzsprout Player ▶ Watch on YouTube: https://www.youtube.com/@ClearTechResearch/videos 📰 Subscribe to the Newsletter: https://www.linkedin.com/newsletters/7346174860760416256/

    Your AI Agents Are Already Running. Can You See Them? | Alvaro Gonzalez
  3. Aug 11

    AI Agents Are New. The Security Fundamentals Are Not

    The conversation around AI is shifting from what agents can do to how enterprises actually govern and secure them.  In this episode of ClearTech Loop, Jo Peterson sits down with cybersecurity professional Marcus Cylar to talk about least-privilege access for AI agents, shadow AI, security awareness and what CISOs should prioritize as agentic AI becomes part of the enterprise.  Marcus challenges the idea that AI automatically requires an entirely new security playbook. His argument: before organizations rush toward new controls and platforms, they need to make sure the cybersecurity fundamentals are actually working.  The conversation covers why least privilege, role-based access, system inventory and clear ownership still matter; why shadow AI can reveal unmet employee needs; and why creating a culture where employees can honestly disclose the tools they are using is critical to effective governance.  For CISOs starting from zero, Marcus offers a practical first step: know what you have.  Before you can govern AI agents, you need visibility into the systems, permissions, ownership and AI tools already operating inside your organization.  In this episode:  Why AI agents do not eliminate traditional cybersecurity fundamentals Least-privilege access in an agentic environment Why security awareness matters even more with AI Shadow AI and the “Department of No” The importance of system and AI inventory What CISOs should prioritize in the next 30 days Why trust and transparency are part of AI governance Featured Guest:  Marcus Cylar, DMin  Cybersecurity professional focused on GRC, security culture, awareness training and program development.  Hosted by:  Jo Peterson  CIO, Clarify360 | Chief Analyst, ClearTech Research  Episode Quote:  “That path starts with a passionate return to the fundamentals of cybersecurity.” — Marcus Cylar  🎧 Listen: In Buzzsprout Player ▶ Watch on YouTube: https://www.youtube.com/@ClearTechResearch/videos 📰 Subscribe to the Newsletter: https://www.linkedin.com/newsletters/7346174860760416256/

    AI Agents Are New. The Security Fundamentals Are Not
  4. Jul 21

    Can AI Agents Earn Your Trust? Elliott Mattice on AI Governance

    What if an AI agent had to earn—and keep—its access based on how it behaved?  In this episode of ClearTech Loop, Jo Peterson sits down with Elliott Mattice, founder of Exprima, to examine trust as the missing operating layer between AI security and AI governance.  Traditional controls can define an agent’s identity and permissions. Governance frameworks can establish policies and accountability. Elliott argues that organizations still need something in the middle: continuous behavioral trust that can raise, lower or revoke an agent’s access based on what it actually does.  Jo and Elliott discuss why accountability must still land with a human, how organizations can balance useful autonomy against unrestrained risk and why an MCP server could function as an enforcement point—not merely a bridge to enterprise tools and data.  The agent does not need to feel guilty when it crosses a boundary. The systems around it need the authority to say no.  What We Cover  Why policies and technical guardrails are not enough to operationalize AI governance How behavioral trust could be continuously measured and tied to access Why human accountability remains necessary when an agent takes an unauthorized action How MCP servers could evaluate identity, permissions and current trust before granting access Why autonomy is both the value of an AI agent and the source of its risk What an agent may need to do to rebuild trust after crossing a boundary Featured Soundbite  “We can give AI enough room to be independent, to be autonomous, as long as we hold it accountable for its outputs.” — Elliott Mattice  Guest  Elliott Mattice is the founder of Exprima, an advisory and consulting firm focused on cybersecurity compliance, federal procurement risk and decision realism. He has more than 25 years of experience across federal IT operations, cybersecurity, compliance and regulated environments.  Guest website: https://elliottmattice.work/  Host  Jo Peterson is the CIO of Clarify360 and Chief Analyst at ClearTech Research.    Full episode webpage: https://cleartechresearch.com/cleartech-loop-elliot-mattice-on-ai-governance-missing-trust-layer/ Subscribe to ClearTech Loop: https://www.linkedin.com/newsletters/7346174860760416256/  Watch on YouTube: https://www.youtube.com/@ClearTechResearch  Topics  AI governance, agentic AI, behavioral trust, AI agent accountability, MCP security, non-human identity, AI access control, defense in depth, AI risk management  Tags / Keywords  AI governance; agentic AI security; behavioral trust; AI agents; MCP servers; AI accountability; non-human identity; cybersecurity governance; autonomous agents; ClearTech Loop; Elliott Mattice; Jo Peterson  🎧 Listen: In Buzzsprout Player ▶ Watch on YouTube: https://www.youtube.com/@ClearTechResearch/videos 📰 Subscribe to the Newsletter: https://www.linkedin.com/newsletters/7346174860760416256/

    Can AI Agents Earn Your Trust? Elliott Mattice on AI Governance
  5. Jul 14

    What Happens When an AI Agent Acts Without Permission?

    What happens when an AI agent takes an action no one authorized?  The answer is not, “The model did it.”  In this episode of ClearTech Loop, Jo Peterson sits down with cybersecurity and technology executive Billy Spears to unpack the gap between AI policy and actual AI control.  They discuss:  Who is accountable when an AI agent makes an unauthorized decision Why agents should never inherit broad permissions by default How identity and authorization must work at runtime Why third-party MCP servers should be treated as untrusted What organizations need to prove when something goes wrong Billy’s warning is simple:  “AI is not eliminating risk; it’s amplifying the consequence of weak controls.”  If your AI governance lives in a PDF while your agents operate with broad access, this episode is for you.  Listen now to learn what real AI governance looks like when systems begin to act.  About Billy Spears  Billy Spears is a technology and cybersecurity executive with more than 25 years of experience across security, IT, privacy and business operations. He has held executive roles at Dell, Hyundai and loanDepot and currently advises executives and boards while building a stealth cybersecurity startup.  Connect with ClearTech Loop  Watch on YouTube: https://www.youtube.com/@ClearTechResearch  Subscribe to the LinkedIn newsletter: https://www.linkedin.com/newsletters/7346174860760416256/  🎧 Listen: In Buzzsprout Player ▶ Watch on YouTube: https://www.youtube.com/@ClearTechResearch/videos 📰 Subscribe to the Newsletter: https://www.linkedin.com/newsletters/7346174860760416256/

    What Happens When an AI Agent Acts Without Permission?
  6. Jul 9

    Okta’s AI Blueprint: Moving AI Agents from Shadow to Governed

    AI agents are becoming part of the enterprise workforce, but many organizations still do not know where those agents are, what they can access, or what they are allowed to do.  In this ClearTech Loop Special Edition sponsored by Okta, Jo Peterson speaks with Matthew Hansen, Regional Chief Security Officer and Head of Customer Audit at Okta, about the identity challenge behind agentic AI.  They discuss Okta’s AI Blueprint, Okta for AI Agents, and why enterprises need to treat AI agents as first-class, non-human identities with clear ownership, lifecycle management, runtime enforcement, and a way to revoke access fast when something goes wrong.  EPISODE DESCRIPTION:  Agentic AI is creating a new security problem: identity sprawl.  AI agents can connect to systems, access data, trigger workflows, and act on behalf of users. But if organizations cannot see those agents, govern their access, or understand what they are doing, productivity gains can quickly turn into security risk.  In this episode, Jo Peterson talks with Matthew Hansen from Okta about how organizations can move from Shadow AI and unmanaged agent activity toward verified, governed AI environments.  The conversation covers:  Why every AI agent needs an identity How Shadow AI extends beyond employee chatbot use The three questions organizations need to answer: where agents are, what they connect to, and what they can do Why static credentials and broad permissions create risk How runtime enforcement and human-in-the-loop controls help govern agent behavior Why an AI kill switch may become a critical backstop for enterprise AI This ClearTech Loop Special Edition is sponsored by Okta.  Learn more about Okta for AI Agents platform: https://bit.ly/4dZ5FkU  🎧 Listen: In Buzzsprout Player ▶ Watch on YouTube: https://www.youtube.com/@ClearTechResearch/videos 📰 Subscribe to the Newsletter: https://www.linkedin.com/newsletters/7346174860760416256/

    Okta’s AI Blueprint: Moving AI Agents from Shadow to Governed
  7. Jul 1

    Derek Fisher on AI Governance, AI Agents & MCP Risk

    AI governance is no longer just a policy conversation. As AI moves into business workflows, sanctioned platforms, employee tools, local models, agents, and third-party services, organizations need to understand where AI is being used, what it can access, who approved it, and who owns the outcome when something goes wrong.  In this episode of ClearTech Loop, Jo Peterson speaks with Derek Fisher, founder of Securely Built, cybersecurity educator, author, and Director of Temple University’s Cyber Defense and Information Assurance Program.  Derek brings a practical security lens to AI governance, AI agents, and third-party MCP risk. The conversation covers why governance needs clear ownership, how organizations should think about AI agents as non-human actors with access and authority, and why MCP servers and AI-enabled services should be evaluated through a third-party risk management lens.  This episode is especially relevant for security leaders, technology leaders, compliance teams, and business executives trying to move AI from experimentation into controlled, accountable use.  In This Episode: Why many organizations still do not know where AI is being used Why AI governance needs executive ownership, cross-functional standards, and business accountability How AI agents create new access control and auditability challenges Why agents should be treated more like privileged non-human actors than simple tools What organizations should ask before adopting third-party MCP servers or AI-enabled services Why AI governance is not about slowing the business down, but making the approved path usable enough that people follow it Key Questions: How do we operationalize AI governance, and who is legally accountable when an AI agent makes an unauthorized decision? How do we prevent agents from executing actions the user should not be allowed to perform? How do organizations verify the authenticity and security of third-party MCP servers and services? Featured Guest: Derek Fisher  Founder, Securely Built  Director, Cyber Defense and Information Assurance Program, Temple University  Derek Fisher is a cybersecurity leader, educator, author, and speaker with experience across product security, secure software development, governance, risk management, regulatory compliance, incident response, and cybersecurity education.  Host: Jo Peterson  CIO, Clarify360  Chief Analyst, ClearTech Research  Additional Resources:  Securely Built  https://securelybuilt.substack.com/ The Application Security Program Handbook https://www.manning.com/books/application-security-program-handbook Derek Fisher on SecureWorld News  https://www.secureworld.io/industry-news/author/derek-fisher Your AI Coding Assistant Has Root Access—and That Should Terrify You https://www.secureworld.io/industry-news/your-ai-coding-assistant-has-root-access Watch More ClearTech Loop:  Subscribe to ClearTech Research on YouTube:  https://www.youtube.com/@ClearTechResearch  Stay in the Loop Follow ClearTech Research for more conversations on cybersecurity, AI governance, cloud, enterprise technology, and emerging risk. 🎧 Listen: In Buzzsprout Player ▶ Watch on YouTube: https://www.youtube.com/@ClearTechResearch/videos 📰 Subscribe to the Newsletter: https://www.linkedin.com/newsletters/7346174860760416256/

    Derek Fisher on AI Governance, AI Agents & MCP Risk

About

Season 2 of ClearTech Loop is built around three questions:  How is AI changing the way organizations think about risk?  What does stronger cybersecurity leadership look like right now?  How should leaders rethink cloud strategy as business and technology keep shifting? Hosted by Jo Peterson, Chief Analyst at ClearTech Research, ClearTech Loop is a fast, focused podcast covering AI, cybersecurity, and cloud risk through a business leadership lens.  Each 10-15 minute episode explores the issues shaping modern technology strategy and the decisions leaders cannot afford to ignore. From governance and resilience to infrastructure change and emerging risk, ClearTech Loop helps leaders make sense of what is shifting, what matters most, and what comes next.

You Might Also Like