The Art of Security

Fortra

Cybersecurity isn't an exact science. It's where art and science meet, informed by experience, tested in battle and reimagined to tackle evolving adversaries. In The Art of Security, Josh Davies and Tyler Reguly break down how security actually works in practice. From zero-day exploits and emerging threats to rethinking long-standing best practices, they explore what holds up — and what doesn't — in today's rapidly changing landscape. While the science of cybersecurity focuses on what's repeatable, the art of security is about making the right decisions in the moment. Each episode delivers practical insights, informed perspectives, and real-world context to help security professionals and tech enthusiasts stay ahead of evolving threats and build smarter, more resilient defenses.

  1. 2d ago

    Security Theater: Feeling Safe vs. Being Secure

    What happens when cybersecurity programs prioritize visible activity over meaningful risk reduction? Security theater can reassure executives and end users, but that reassurance becomes dangerous when dashboards, checkbox compliance, and inflated metrics distract teams from the controls that actually reduce exposure. In this episode of The Art of Security, Josh Davies and Tyler Reguly examine the line between communicating security effectively and merely performing it. They challenge conventional thinking about security metrics, product marketing, threat hype, compliance, and the pressure to make security programs look productive. Key takeaways Why activity metrics such as alerts triaged, vulnerabilities patched, and detections created may not reflect improved security How threat hype and named vulnerabilities can redirect limited resources away from higher-priority risk Why security visibility and clearly assigned asset ownership provide a stronger foundation for meaningful measurement How security teams can demonstrate control effectiveness without relying on checkbox compliance or misleading ROI calculations Security should create confidence because controls are validated, assets are monitored, and responsibilities are clear, not because a dashboard looks impressive. 👍 Like the video if the discussion challenged how you measure security 💬 Tell us which cybersecurity metrics your team finds genuinely useful 🔔 Subscribe for practical conversations with cybersecurity practitioners and researchers

  2. Jul 22

    AI Governance in Action: How to Secure AI Without Slowing Innovation

    Your AI has access. But does It have too much? AI can help organizations move faster, automate work, and unlock new opportunities. But when AI systems can access sensitive data, connect to business tools, or take actions on a user's behalf, governance becomes an operational security priority. In this episode of The Art of Security, co-host Josh Davies speaks with Gina Cardelli, Principal Security Strategist at Fortra, about how organizations can adopt AI without losing visibility or control. They examine what recent AI security incidents can teach businesses about excessive permissions, exposed infrastructure, third-party tools, shadow AI, and the risks of moving too quickly. Gina also explains how threat modeling, continuous monitoring, least privilege, and cross-functional AI councils can help organizations understand an AI system's potential blast radius and manage risk as its capabilities evolve. Listen to learn: Why AI governance cannot be treated as a one-time policy exercise How to threat model AI use cases before deployment Why continuous monitoring is essential for AI systems and agents How third-party AI tools can introduce data and supply chain risks What organizations can do about shadow AI Why many AI security failures still begin with familiar vulnerabilities How to introduce practical controls without bringing AI innovation to a halt AI governance doesn't have to be perfect on day one. But organizations need to understand how AI is being used, what it can access, and what could happen if something goes wrong. AI security is evolving quickly. Subscribe to The Art of Security for more conversations that help you keep pace.

5
out of 5
4 Ratings

About

Cybersecurity isn't an exact science. It's where art and science meet, informed by experience, tested in battle and reimagined to tackle evolving adversaries. In The Art of Security, Josh Davies and Tyler Reguly break down how security actually works in practice. From zero-day exploits and emerging threats to rethinking long-standing best practices, they explore what holds up — and what doesn't — in today's rapidly changing landscape. While the science of cybersecurity focuses on what's repeatable, the art of security is about making the right decisions in the moment. Each episode delivers practical insights, informed perspectives, and real-world context to help security professionals and tech enthusiasts stay ahead of evolving threats and build smarter, more resilient defenses.

You Might Also Like