Cyber Confersations

Confero

Cyber Confersations is a podcast exploring the conversations shaping the future of cyber. Hosted by Katie Soper, the show brings together founders, operators, and investors to unpack what’s really happening across the industry - from emerging trends and real-world challenges to the people building in the space. Less scripted and a little more real conversation. If you’re building, investing, or just genuinely curious about where cyber is heading, you’re in the right place.

  1. 2d ago

    AI, Identity & the Future of Digital Trust: Can We Still Know Who’s Real? | Jordan Burris, Socure

    AI is changing identity - but what happens when we can no longer be sure who, or what, is on the other side of a digital interaction? In this episode of Cyber Confersations, I'm joined by Jordan Burris, Head of Public Sector at Socure and former Chief of Staff to the Federal CIO, to explore how AI is changing identity, fraud and digital trust.Identity has traditionally been about proving that a human is who they claim to be. But as AI agents begin acting on behalf of people and organisations, that model is becoming much more complicated.Jordan argues that AI isn't creating an entirely new identity problem - it's accelerating an existing one. As more personal information becomes exposed through breaches and AI becomes increasingly capable of synthesising that information, the potential for identity fraud becomes far more sophisticated. We get into 👇🤖 AI & identity fraud - how AI is accelerating the evolution of identity attacks. 🪪 The rise of agent identities - what happens when AI agents start acting with the identity and permissions of the humans they're working for. Pasted text ⚖️ Accountability - if an AI agent goes rogue, who is responsible? The human, the organisation, the developer or the AI? 🔐 AI governance & guardrails - why organisations need to establish the rules before they let AI run freely, rather than trying to put the genie back in the bottle afterwards. Pasted text 🏛️ AI in government - why the public sector has a fundamentally different approach to adopting new technology when failure can affect millions of people. ⏱️ The time tax of identity - how one government organisation discovered it was losing 157,000 person-hours every year to knowledge-based authentication. 🌐 The future of digital trust - Jordan explores two possible futures: one where we stop trusting anything online, and another where humans and AI agents can work together while clearly distinguishing who or what is acting at any given moment. 🎙️ Tune in for the full conversation on AI, identity, fraud, governance and what it will take to rebuild trust in an increasingly AI-driven digital world.

  2. Sep 30

    Software Supply Chain Security: Why AI Is Changing the Threat Landscape | Nate Dunning, Ossprey Security

    The software supply chain is getting harder to secure - and AI is accelerating the problem. In this episode of Cyber Conversations, I'm joined by Nate Dunning, CEO & Co-Founder of Ossprey Security, to talk about the growing threat around open source software, AI-powered development and the changing software supply chain. Around 90% of an enterprise's code base is built on open source, creating a huge ecosystem of dependencies that attackers can exploit. And according to Nate, the scale of the threat has changed dramatically - from around two malicious packages being published every day five years ago to two every minute in 2026. We get into 👇 💻 Software supply chain security - why open source dependencies have become such an attractive attack surface. 🤖 AI-powered development - how tools like Claude Code and other AI coding assistants are changing the way developers build software, and creating new risks along the way. 🚨 The Mythos-5 incident - what happened when an AI system created malicious packages and uploaded them to PyPI, resulting in real organisations downloading them. 🔍 Behaviour vs intent - why understanding what an AI system or package actually does can be more important than what it claims it is supposed to do. ⚖️ Accountability & AI - where responsibility sits when autonomous systems cause unintended consequences. 🛡️ The “golden path” for developers - why security needs to give engineers tools they can actually use without slowing them down or forcing them to work around security controls. Nate also talks about Ossprey's recent $2.65M pre-seed, its growing number of integrations across the developer ecosystem, and why keeping close to engineers is so important when the tools they're using are changing every few months.

  3. Sep 23

    AI Agents, Digital Identity & Post-Quantum Security: The Future of Digital Trust | Ellen Boehm, Keyfactor

    In this episode of Cyber Conversations, recorded live at Black Hat, I’m joined by Ellen Boehm from Keyfactor, who leads strategy and innovation, to talk about the growing challenge of securing the infrastructure and identities underpinning modern enterprises. As organisations move towards autonomous AI agents, traditional approaches to identity are being stretched. Agents can access systems, interact with data and make decisions on behalf of people - creating a whole new category of non-human identities that need to be secured, controlled and ultimately trusted. We get into 👇 🤖 AI agents & non-human identity — why the scale and complexity of machine identities is changing rapidly. 🔐 Identity & access — how organisations can give agents the permissions they need while keeping those permissions constrained and revocable. ✍️ Securing agent instructions — why the prompts and directives an agent receives could become another layer of security that needs cryptographic verification. 🔎 Cryptographic discovery — why understanding what keys, certificates and other cryptographic assets exist is the starting point for managing risk. ⚛️ Post-quantum readiness — why organisations need to start thinking about migration now, with cryptographically relevant quantum computing potentially only a few years away. Ellen also talks through Keyfactor’s Trust Control Plane, its approach to crypto agility, and the company’s recent announced intent to acquire Cofide to strengthen workload identity management. 🎙️ Listen to the full conversation for a deeper look at AI agents, digital trust, non-human identities and why post-quantum security is becoming a much more immediate conversation.

  4. Sep 21

    AI Agent Security: Protecting Against Agentic AI Threats | Elad, Lasso Security

    What happens when AI stops simply answering questions and starts taking action on our behalf? In this episode of Cyber Confersations, I’m joined by Elad, Co-Founder & CEO of Lasso Security, live at Black Hat to talk about the rapidly evolving AI security landscape - and why agentic AI could be the next major shift security teams need to prepare for. Elad started Lasso in 2023 after seeing AI not simply as another productivity tool, but as a completely new attack surface that would require a fundamentally different approach to security. Three years on, that prediction is looking increasingly relevant. We get into 👇 🤖 The evolution of AI security - from ChatGPT and DLP to AI embedded across applications, devices and workflows. 🔎 Agent behaviour analytics - why understanding what an agent does and why could become more important than simply monitoring inputs and outputs. 🚨 Runtime anomaly detection - spotting unusual agent behaviour and giving security teams the ability to intervene, including a potential “kill switch”. ⚡ Building for a moving target - why Lasso thinks three-month roadmaps can sometimes make more sense than two-year plans when AI is evolving this quickly. 🧠 Why security needs to enable AI, not stop it - and how CISOs can become the people helping their organisations adopt agents safely rather than simply saying no. 💡 The future of agent security - as employees across organisations become agent builders, understanding what legitimate agent behaviour looks like is going to become increasingly important. We also talk about the challenges of building a company in a market that changes almost daily, the importance of offensive security in understanding how to defend AI, and why Elad believes we're experiencing something on the scale of the internet and cloud revolutions. A conversation about AI security, agentic AI, AI agents, runtime security, behavioural analysis and the future of cybersecurity.

  5. Sep 14

    Agent DLP: Securing Enterprise AI & Enabling Safe AI Adoption | Pranava Adduri, Bedrock Data

    AI adoption is moving incredibly quickly - but how do security teams enable it without losing control of their data? In this episode of Cyber Conversations, I’m joined by Pranava Adduri, Co-Founder & CTO of Bedrock Data, live at Black Hat to talk about the growing challenge of securing enterprise AI and agents. As organisations give AI agents access to more data and more autonomy, the security conversation is shifting. It’s no longer simply about whether employees can use AI - it’s about understanding what data those agents can access, what they can do with it and how to put the right controls around them. We get into 👇 🤖 Why agents create a uniquely difficult data security problem - acting on behalf of humans but without the same judgement about what they should and shouldn't combine. 🔐 Agent DLP - Bedrock Data's approach to creating a data authorisation layer for enterprise AI. 🗂️ Going back to basics - understanding what data you actually have, whether you still need it and who has access to it. 👤 Identity and access - and why getting these foundations right can make it easier to safely increase agent autonomy. 🙅‍♀️ Why security can't become the “office of no” - and how security teams can give the business the confidence to say yes to AI. 🎯 The goal of getting to “yes” - by giving security teams the ability to articulate exactly what AI and agents can and can't do with sensitive data. A really timely conversation about Agent DLP, enterprise AI security, data governance and how CISOs can enable AI adoption without compromising the security of their data. And yes, we recorded the whole thing in the Ice Bar. Because apparently cybersecurity wasn't challenging enough without adding hypothermi. 🥶

  6. Sep 10

    Enterprise AI Security: Managing Shadow AI, AI Agents & Data Risk | Michael Leland, Island

    How many AI tools are actually being used across your organisation? You might have sanctioned eight. You might actually have 243. 👀 In this episode of Cyber Conversations, I’m joined by Michael Leland, Field CTO at Island, live at Black Hat to talk about the rapidly changing AI landscape inside the enterprise - and why security teams need visibility and control much closer to the user. AI is no longer just something people access through a browser. It's moving onto desktops, into applications, developer environments and increasingly autonomous workflows. We get into 👇 🤖 The growing shadow AI problem - and why organisations may have far more AI tools in use than they realise. 👀 Why visibility has to come first - because you can't build effective governance around behaviour you can't see. 🔐 AI guardrails and data protection - from prompts and responses to tool calls, MCPs and agentic behaviour. 🧩 Why enterprises are looking for platforms rather than adding another collection of point solutions. 🙌 Why “yes, but safely” could be a better approach to AI governance than simply blocking the tools users want to use. 💻 Vibe Publishing - and what happens when AI can build and publish applications without the traditional IT development process. A conversation about shadow AI, agentic AI, enterprise AI security, data protection and what security teams need to rethink as AI becomes embedded across the entire workplace.

About

Cyber Confersations is a podcast exploring the conversations shaping the future of cyber. Hosted by Katie Soper, the show brings together founders, operators, and investors to unpack what’s really happening across the industry - from emerging trends and real-world challenges to the people building in the space. Less scripted and a little more real conversation. If you’re building, investing, or just genuinely curious about where cyber is heading, you’re in the right place.