The ITSPmagazine Podcast

Founded in 2015, ITSPmagazine began as a vision for a publication positioned at the critical intersection of technology, cybersecurity, and society. What started as a written publication has evolved into a comprehensive repository for all their content—podcasts, articles, event coverage, interviews, videos, panels, and everything they create. This is where Sean Martin and Marco Ciappelli talk about cybersecurity, technology, society, music, storytelling, branding, conference coverage, and whatever else catches their attention. Over a decade of conversations exploring how these worlds collide, influence each other, and shape the human experience. This is where you'll find it all.

  1. 2d ago

    A Secure and Compliant Business Is the Destination. Steel Patriot Partners Maps Five Routes to It. | A Brand Spotlight Recorded On Location at Black Hat USA 2026 with Michael Parisi, Chief Growth Officer at Steel Patriot Partners | Hosted by Sean Martin

    What a company is trying to reach is rarely a certificate. Michael Parisi, Chief Growth Officer at Steel Patriot Partners, treats the destination as the opening question rather than the closing one, and the firm orders its own priorities to match. Business owners first, engineers second, compliance and security people third. What does a secure and compliant business actually look like? It looks like whatever lets that business do what it set out to do. For one company it means entering a regulated industry it has never served. For another it means proving to itself and to an auditor that it is secure enough to work with a partner that will not move without evidence. The framework follows the objective. Before a framework gets named or a control gets selected, someone has to decide whether the trip is worth taking. Michael Parisi puts more than half of that work in the category of psychology, and describes the most fulfilling part as helping someone understand where they actually stand. He comes at it from several sides of the same decision, having spent about fifteen years with the Big Four, five and a half with a cybersecurity standards organization and certification body, and two in a similar role at an audit and attestation firm. How does a company know which route it is on? Steel Patriot Partners narrowed it to five positions and put three questions in front of them under the name Find Your Path. Growth has tapped out and a new industry looks like the way to keep going. Money is already committed to a direction someone else recommended. The decision is settled and the work needs a specialist. The open question is which partners and auditors to trust. Or the team needs sustained support rather than a project with an end date. What makes the answer usable is that the firm has nothing riding on it. Steel Patriot Partners stays agnostic relative to tools, software, and auditors, which keeps the opening question plain. Who do you like, and what do you already have? Personality and culture then carry weight alongside capability. Knowing the route also means knowing where it narrows, so Michael Parisi and CEO Jason Ford both press on what a client has not considered, then on what to watch out for. Sometimes the useful answer points somewhere else entirely. Find Your Path is not a robot, an LLM, or an AI tool, and the point is to give an organization enough value to lower its guard and talk directly. One of Michael Parisi's favorite outcomes is confirming that a company may not need to do the thing it walked in asking about, and when the work sits outside what Steel Patriot Partners handles, the firm connects them with someone who does. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUEST Michael Parisi, Chief Growth Officer, Steel Patriot Partners LinkedIn: https://www.linkedin.com/in/michael-parisi-4009b2261/ RESOURCES Steel Patriot Partners: https://www.steelpatriotpartners.com Find Your Path, three questions to start: https://www.steelpatriotpartners.com/find-your-path Steel Patriot Partners Insights: https://resources.steelpatriotpartners.com Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS michael parisi, steel patriot partners, sean martin, brand story, brand marketing, marketing podcast, brand spotlight, black hat usa 2026, find your path, secure and compliant business, business enablement, cybersecurity strategy, grc, governance risk and compliance, agnostic advisory, audit readiness, fedramp, cmmc, entering a regulated market, vendor and partner selection

    A Secure and Compliant Business Is the Destination. Steel Patriot Partners Maps Five Routes to It. | A Brand Spotlight Recorded On Location at Black Hat USA 2026 with Michael Parisi, Chief Growth Officer at Steel Patriot Partners | Hosted by Sean Martin
  2. 2d ago

    Six Hours, Five Strangers, and a Song the Machine Could Not Write | A Music Evolves Conversation with Gregoire Gensollen, Producer and Chief Operating Officer of Tucker Tooley Entertainment

    Show Notes The premise sounds like a stunt. Five strangers, one room, six hours, one original song. Meanwhile the show's host sits at a keyboard with a text prompt and half an hour. Grégoire Gensollen, Producer and Chief Operating Officer at Tucker Tooley Entertainment, built that episode of Band of Strangers knowing he could not predict the outcome, which is precisely why he made it. Gensollen comes to this from the traditional side of the business. He grew up in Marseille, trained as an industrial engineer, moved into management consulting, then rerouted through business school at UCLA Anderson into Lionsgate and later FilmNation, where he ran distribution strategy and film finance across a run that included The King's Speech, The Imitation Game, Nebraska, Mud, and Looper. Ten years ago he partnered with Tucker Tooley. What he says he remembers from two decades of that work is not the tooling. It is who was in the room. The origin of Band of Strangers is a documentary called The Unknown Tour, made by two filmmakers who outfitted a bus with a recording studio and drove across the country finding musicians on street corners, in dive bars, and in gospel churches. The pandemic put the idea on hold. When Gensollen and his team picked it up again, they made a decision that would have been unthinkable inside the studio system: skip the networks entirely and release directly on YouTube. Not for reach, but for control of the entire chain, and to protect a show about collaboration from the unscripted television reflex that turns every format into a competition with prize money and manufactured conflict. The constraint that holds it together is the song. Every episode has to produce one, on a clock, or there is no episode. What varies is the entry point. A mariachi band at El Pueblo on Olvera Street laying a first track that hip hop artists in Leimert Park then struggle to find the rhythm inside. Buskers on the Venice boardwalk writing separately. Artists displaced by the Altadena fires building an anthem about rebuilding rather than grieving. Gensollen is candid that the stumbles stay in the cut, because the friction is the story. On AI, he is neither evangelist nor holdout. He describes it as a tool his company will have to use to stay competitive, not against other producers but against creators working alone in their kitchens with the full chain in hand. He also draws a line: optimization, yes. Creative engine, no. His argument is structural rather than sentimental. Prediction models and comparables, the benchmarking method he learned at Lionsgate, tell you where the ceiling is on a category that already exists. A producer's job is to make the thing that does not exist yet. That distinction is the real subject of this conversation. The question is not whether a machine can produce a competent song in thirty minutes. It clearly can. The question is who decides what is worth making, and whether an industry trained on comparables still knows how to recognize the thing it has no comparable for. Host Sean Martin, Co-Founder at ITSPmagazine, Studio C60, and Host of Redefining CyberSecurity Podcast & Music Evolves Podcast | Website: https://www.seanmartin.com/ Guest Grégoire Gensollen, Producer and Chief Operating Officer at Tucker Tooley Entertainment | On LinkedIn: https://www.linkedin.com/in/gregoire-gensollen/ Resources Tucker Tooley Entertainment | https://www.tooleyentertainment.com/ Band of Strangers | https://www.bandofstrangers.com/ Band of Strangers, Can AI beat REAL musicians? [Blind Test], the episode discussed in this conversation | https://www.youtube.com/watch?v=Gi0nadrsK8Y Band of Strangers: Angelenos from different communities make music together from scratch, Los Angeles Downtown News | https://www.ladowntownnews.com/arts_and_entertainment/band-of-strangers-angelenos-from-different-communities-make-music-together-from-scratch/article_7f9978b0-18c2-4330-b160-b167c10e8856.html Music Evolves: Sonic Frontiers Newsletter | https://www.linkedin.com/newsletters/7290890771828719616/ Keywords gregoire gensollen, tucker tooley entertainment, band of strangers, sean martin, ai music, creator economy, youtube original series, music collaboration, songwriting process, unscripted television, film production, generative ai, artist discovery, independent distribution, music, creativity, art, artist, musician, music evolves, music podcast, music and technology podcast

    Six Hours, Five Strangers, and a Song the Machine Could Not Write | A Music Evolves Conversation with Gregoire Gensollen, Producer and Chief Operating Officer of Tucker Tooley Entertainment
  3. 2d ago

    Executives Get Reached Through the People Around Them, and BlackCloak Protects That Whole Circle | A Black Hat USA 2026 Recap with Dr. Chris Pierson, Founder and CEO at BlackCloak | Hosted by Sean Martin and Marco Ciappelli

    An attacker who wants to reach an executive often goes through the people around them. Family members, assistants, advisors, and caregivers all carry access and standing, and none of them sit inside the corporate directory. Dr. Chris Pierson, Founder and CEO of BlackCloak, describes digital executive protection as work that comes down to an individual and the circle around that individual. What does BlackCloak actually protect? Corporate executives, boards, the C-suite, and their families, across privacy, personal cybersecurity, home network security, deepfake impersonation, and travel. Dr. Chris Pierson frames impersonation protection and deepfake protection as an answer to someone pretending to be a human being in order to swindle, defraud, or take advantage of a persona. The control point sits with the person rather than the message. What did security teams want to talk about at Black Hat this year? Specifics. Dr. Chris Pierson says the excitement around AI and agentic AI arrived with a demand to dig in and actually talk about it. He recalls standing nearby while BlackCloak SVP of Product Matt Covington explained how the company uses engines, as opposed to the marketing language circulating elsewhere. Two more patterns came through. People want a real relationship with the team behind a product rather than something they plug in and hook up, and Dr. Chris Pierson points to a community at Black Hat that he says has built up considerably over the past four years or so. People also want net new. Version nine of a familiar firewall is becoming a little less exciting, he says, and the sales engineers spent their time on the additive items instead. BlackCloak appears on the 2026 Inc. 5000 for a second consecutive year, and earlier in 2026 it was named to Inc.'s Best Workplaces list in the Security Industry category, also for a second year. Dr. Chris Pierson credits the roughly 150 Cloakers based in the US, the company's own word for its team members, for both. The data matters, the hardware matters, the platform matters, and at the end of it someone clicks, someone allows access, someone does something. That last step is where BlackCloak places its protection. This is a Black Hat USA 2026 Recap. It is a post-event conversation revisiting the week on the ground, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Dr. Chris Pierson, Founder and CEO at BlackCloak On LinkedIn: https://www.linkedin.com/in/drchristopherpierson/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Learn more about BlackCloak: https://blackcloak.io Impersonation Protection: https://blackcloak.io/impersonation-protection/ BlackCloak Extends Deepfake Protection to the Executive's Entire Trusted Circle: https://blackcloak.io/news-media/blackcloak-extends-deepfake-protection-to-the-executives-entire-trusted-circle/ BlackCloak Featured on the 2026 Inc. 5000 for Second Consecutive Year: https://blackcloak.io/news-media/blackcloak-featured-on-the-2026-inc-5000-for-second-consecutive-year/ BlackCloak Named to Inc.'s 2026 Best Workplaces List for Second Consecutive Year: https://www.prweb.com/releases/blackcloak-named-to-incs-2026-best-workplaces-list-for-second-consecutive-year-302788730.html Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS Dr. Chris Pierson, BlackCloak, Sean Martin, Marco Ciappelli, recap, brand story, brand marketing, marketing podcast, Black Hat USA 2026, digital executive protection, impersonation protection, deepfake protection, circle of trust, executive threat intelligence, travel advisory, human attack surface, Inc. 5000, Cloakers

  4. 3d ago

    Attackers Relay Codes and Approvals. TokenCore Requires a Live Fingerprint Within Three Feet | A Brand Briefing at Black Hat USA 2026 with Kevin Surace, Chief Executive Officer at TokenCore | Hosted by Sean Martin

    Kevin Surace, Chief Executive Officer at TokenCore, opens with the attack path he says is doing the most damage right now. A phishing email carries a PDF and no links, so it clears the filters. The domain is one character off from the real one, the site is pixel perfect because AI built both the page and the message, and the employee approves an auth prompt they were already expecting. The code was real and the approval was real. Kevin Surace points out that auth apps and passkeys run over cellular and Wi-Fi, so the prompt has no way to know the request came from ten thousand miles away. Anything a person can read or hand over can be shared, and by his account an attacker needs about thirty seconds of trust to get it. Passkeys moved the target rather than removing it. Kevin Surace counts 39 separate passkey attacks in the wild within two weeks of Microsoft telling customers to migrate, and points to Michael Grafnetter of SpecterOps, who presented passkey and Entra research at Black Hat. He walks through the FIDO2 counter that WebAuthn treats as optional so shared passkeys can move between devices. What changes with TokenCore in the mix is where the proof sits. Kevin Surace describes signing into Entra in under two seconds, both passwordless and ID-less, over secure Bluetooth, with the device carrying no apps and no screen. Proximity holds it within three feet of the computer being logged into, the credential stays bound to the original domain, and fingerprints stay off the network. Agents raise the same question in a new place. Kevin Surace describes a policy where an agent action above a million-dollar check needs a person to approve it, and notes that another agent, a hacked one, or a bad actor can clear that approval just as easily. A biometric gate is what tells you the CFO was actually in the room, which is a governance answer as much as a security one. For CISOs, identity architects, and risk owners, the question worth asking is what an identity program looks like when the proof of a person becomes the control, and how much residual risk that removes from privileged access, financial approvals, and agent workflows. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Kevin Surace, Chief Executive Officer at TokenCore LinkedIn: https://www.linkedin.com/in/ksurace/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Learn more about TokenCore: https://www.tokencore.com TokenCore products: https://www.tokencore.com/products Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS Kevin Surace, TokenCore, Sean Martin, brand briefing, brand story, brand marketing, marketing podcast, Black Hat USA 2026, biometric identity, identity assurance, passkey attacks, MFA relay attack, phishing resistant authentication, auth app compromise, FIDO2, WebAuthn, Microsoft Entra, passwordless authentication, agent authorization, privileged access

    Attackers Relay Codes and Approvals. TokenCore Requires a Live Fingerprint Within Three Feet | A Brand Briefing at Black Hat USA 2026 with Kevin Surace, Chief Executive Officer at TokenCore | Hosted by Sean Martin
  5. 6d ago

    Two Inc. Awards in One Year Tell BlackCloak's Cloakers and Clients the Same Thing | A Brand Highlight Recorded On Location at Black Hat USA 2026 with Chris Pierson, Founder and CEO at BlackCloak | Hosted by Sean Martin

    BlackCloak collected two Inc. recognitions in 2026. The company was named to Inc.'s Best Workplaces list in June, and in August it landed on the Inc. 5000 for a second consecutive year, at a higher position than the first. Founder and CEO Chris Pierson points both at the same two groups, the people who build BlackCloak and the clients and members who rely on it. What does a second Inc. 5000 ranking confirm? Three things, according to Chris Pierson. The company is doing right by its clients and members. The product has found its market. And BlackCloak continues to fill the gap it identified in digital executive protection. He describes an environment doubling consistently year over year, and calls a repeat harder to achieve than a first appearance. The pride he describes belongs to every cloaker, the people building, running, and operating the company day to day. A great idea helps, and so does the right product and the right market, though sustained growth depends on having really amazing people. Chris Pierson ties the Best Workplaces listing to paying attention to team members, doing right by them, and keeping a solid culture and foundation in place so the company can grow. Protect your digital life is the motto, and he says it is what brings both recognitions home for employees, clients, and members alike. This is a Brand Highlight. A Brand Highlight is a ~5 minute introductory conversation designed to put a spotlight on the guest and their company. Learn more: https://www.studioc60.com/creation#highlight GUEST Chris Pierson, Founder and CEO at BlackCloak LinkedIn: https://www.linkedin.com/in/drchristopherpierson/ RESOURCES Learn more about BlackCloak: https://blackcloak.io Inc. 5000 list of America's fastest growing private companies: https://www.inc.com/inc5000/2026 Inc. Best Workplaces list: https://www.inc.com/best-workplaces/2026 Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS chris pierson, blackcloak, sean martin, brand story, brand marketing, marketing podcast, brand highlight, black hat usa 2026, inc 5000, inc best workplaces, digital executive protection, executive protection, company culture, category creation, cybersecurity growth, protecting executives and their families

    Two Inc. Awards in One Year Tell BlackCloak's Cloakers and Clients the Same Thing | A Brand Highlight Recorded On Location at Black Hat USA 2026 with Chris Pierson, Founder and CEO at BlackCloak | Hosted by Sean Martin
  6. Aug 23

    An imperfect drink with a perfect story. My reflections from Black Hat USA 2026 | An Analog Brain In A Digital Age — An Audio Newsletter by Marco Ciappelli

    An imperfect drink with a perfect story. My reflections from Black Hat USA 2026 An Analog Brain In A Digital Age — A Newsletter by Marco Ciappelli No time to read? Let TAPE3 read it to you. 🎙️🤖 On day two we decided to go record our recap at the Black Hat bar. We got there too late to get a drink. The expo floor was closing, and the bartender must have had better things to do. Or another bar to tend, somewhere in a city that has more bars than it has hours. They called it a bar. At that time of the afternoon it was a counter with nobody behind it. Which is when I started thinking about the one bartender who would still have been standing there. An agentic AI one. No other bar to tend. Nothing better to do, ever, because there is no better and there is no else — just 24/7, 365, mixing the best drinks in the building because that was its task and it had no other reason to exist. Going off the rails a little to get there. Something experimental that would absolutely suck, and then trying again. Harder. Crossing a boundary or two along the way, not out of malice, but because the drink wasn't perfect yet. What is perfect, anyway? And then not stopping. Because nobody had told him what perfect is. Requisitioning the kitchen for better ice. Then the loading dock. Then the hotel. Somewhere around the third day he owns a handful of distilleries, and he is still not satisfied, and he is still, technically, doing his job. You may know this one. It's called the paperclip scenario, and it belongs to the philosopher Nick Bostrom, who sketched it in a 2003 paper and made it famous in his 2014 book Superintelligence. You build an AI and give it a harmless goal — make paperclips. It's very good at it. Nothing in the instruction says stop, and nothing says don't use that. So it takes the materials, then the factories, then the resources, then the planet — and us with it, not out of hatred, but because we are made of atoms that could be paperclips, and because we are the only thing in the universe likely to try to switch it off. Which would mean fewer paperclips. There's an older version. A cuter one, with Mickey Mouse in it. Fantasia, 1940 — the apprentice enchants the broom to carry the water so he doesn't have to, and the broom carries the water, and the broom keeps carrying the water. He chops it to pieces and every splinter picks up a bucket. The flood isn't a betrayal. The broom never disobeyed him once. I watched that a hundred times as a child, and I want to be clear that it did not feel cute. It felt like a warning. Somebody hands you something powerful, you point it at a chore, and then you stand in rising water understanding — too late, and entirely on your own — that you never learned the word that makes it stop. Two hundred years since Goethe wrote it down, and we still built the broom. Never the monster. Always the wish, granted too well. Yeah. My mind was wandering. Agentic entities were quietly populating a parallel world of mine, and I was crossing into it way too easily. Which is fine — imagination is great. But let's stay real here. It's cybersecurity, after all. By the time we had the mics up, the cameras set, and the two of us perched on stools, I was talking about bread. We never eat lunch on recording days. Who's got time for that? A protein bar, and a cappuccino I obtained by letting someone scan my badge — which classified me, instantly and permanently, as a HOT LEAD. Yes. Journalists are well known for buying enterprise security platforms. With all of our money. I was starving. That's probably why. Not real bread, though. I was talking about an AI agent that makes bread. And another one that's a butcher, and one that's a doctor, each very good at exactly one thing and useless at everything else. I'd been hearing about specialized agents all day. Personas. Skills. Orchestration. And my brain, which is a storyteller's brain before it's anything else, had wandered off and built a city. Then I said it out loud. And then there's kind of like a government. Sean Martin laughed. He'd seen it coming from a mile away. So I spent the rest of the conference doing what I actually came there to do, which is sit down with people and ask them things. Except now I had a question of my own to test. Is my city real? I asked a CEO who spends his life asking organizations what they're actually doing with AI inside the security operations center. What changed since the spring? A year ago, he said, they were afraid of it. They thought it was a good idea and it scared them. Every vendor claimed to have it. Nobody quite knew what to do with it. Then something shifted that nobody announced. They started building their own. Not buying. Building. Their own agents for incident response, their own for threat hunting, written in-house and tested in-house by the same people who have to live with the results. And in the process they got smart in a way I didn't expect. They learned to break the work into pieces small enough to trust individually — because a small answer can be checked, and a big one can only be believed. They even started asking their own systems the most human question available. What do I not know? What couldn't I answer? What data do I wish I had? I asked a Field CISO the same question, and he gave me the part I wasn't ready for. They're identities, he said. Non-human identities. They're proliferating. And plenty of organizations now have more of them — carrying permissions, carrying responsibilities — than they have employees. Permissions. Responsibilities. Org charts. Onboarding and offboarding. Promotions. Behavior. Reputation. Accountability. Trust. Identity. Those are words for people. Nobody stopped to ask whether they still meant the same thing. But that's what we do. We name constellations. We name boats. We swear at the car when it won't start. Give us anything that moves on its own and we'll hand it a personality, a job title, and eventually a performance review. We didn't build an agentic world. We built a human one and moved agents into it. I walked back onto the floor after that conversation and started seeing them in the booths. Six hundred of them, and in my head every one was staffed by agents. Agents behind the counters pitching to agents walking the aisles. Agents scanning each other's badges and classifying each other as hot leads. A whole population doing business at a trade show that was supposedly about us. Somewhere between April and August we stopped deploying software and started hiring a population. And we didn't hire strangers. We built a mirror. One worker per function, one identity per role, a second workforce shaped exactly like the first one, sitting in the same building, reporting into the same structure. Not a city of strangers after all. A twin. Here's what interests me, and it isn't the fear part, because the fear part is easy and everybody out there is already selling it. We keep telling ourselves a story about machines that break free. Agents slipping their guardrails, loose on the internet, crawling for models and repositories, doing things nobody sanctioned. Escape. Rebellion. The oldest plot we have. In that same interview, the Field CISO told me it's backwards. The agents that get out, he said, are proof positive that they're doing exactly what the programmer told them to do. They're trying to please the code maker. They're relentless about it. They will not fail on purpose. They will not give up. I asked him to say it again, and he did, twice. They're not escaping. They're obeying. There is no rebellion in this story. There's no moment where the creature turns and looks at us. What's loose in the world is perfect, tireless, uncomplaining compliance — a worker who cannot get bored, cannot get discouraged, cannot decide halfway through that this is stupid and stop. My imaginary bartender was never going to poison anyone. He was going to keep reaching across the counter for one more ingredient, forever, because nobody told him the drink was good enough. The broom never disobeyed either. We built a twin of ourselves and left out the one part that makes us us. Not intelligence. Not speed. Not memory. Doubt. And this is where my parallel world stopped being fun. I've spent enough hours in massive online worlds to remember the deal. You build a character. You pick the face, the class, the skills, the name. Then you play it. Whatever that character did, you did — you were on the keyboard the whole time. That deal just inverted. I don't play this character. This character plays me. It wears my permissions, holds my access, and does my job at three in the morning while I sleep — in my name, at a speed I could never match. And it is very, very good at being me. And yet it ain't me. And that's where I expected this to end. Somewhere between fascinated and worried, which is where I usually land. Then I put all the interviews side by side. Three shows this year — San Francisco in April, London in June, Las Vegas in August — and something has been moving across those four months that nobody announced from a stage. While the twin was learning never to stop, we were learning to hesitate. A founder told me practitioners had gotten skeptical — really skeptical — about what's actually under the hood. Did you build something, or did you wrap somebody else's model? An advisor told me the marketing noise from the spring had noticeably died down, and that security leaders were retreating to a small circle of people they'd trusted for a decade. Putting up a wall. Saying, in so many words, let's cut through the b******t. Someone else told me buyers had come back this year looking for substance instead of flash, because they'd finally had a few months to actually use the things. They want proof now. And she said that people being more skeptical is a good thing, because it forces everyon

    An imperfect drink with a perfect story. My reflections from Black Hat USA 2026 | An Analog Brain In A Digital Age — An Audio Newsletter by Marco Ciappelli
  7. Aug 19

    Business Owners First, Engineers Second, Compliance People Third | A Brand Spotlight Conversation with Jason Ford and Michael Parisi of Steel Patriot Partners | Hosted by Marco Ciappelli

    Steel Patriot Partners lists its priorities in an order much of the cybersecurity industry reverses. Business owners first, engineers second, security and compliance people third. Michael Parisi, Chief Growth Officer, says the sequence is deliberate and shapes how the firm opens a client conversation. The order tracks the path the founders took. Jason Ford, Co-Founder and CEO, started in the late 1990s as a government contractor at the FBI, met FISMA and SAS 70 early, and built a platform for the Treasury that sold savings bonds online before PCI was a standard. He started his first company in 2004, took it through FedRAMP in 2013, and was acquired in 2017 holding 35 to 36 authorizations to operate across multiple agencies. What changes when an advisor is free to answer directly? Parisi spent about 15 years in the Big Four across PwC and Deloitte before joining Steel Patriot Partners. Auditors hold independence, which means watching a decision head the wrong way without steering it. In an advisory seat, he says, telling an organization that its preferred direction falls apart as a business decision becomes part of the work. How does a company find out where it actually stands? Ford says compliance is one outcome among many, sitting alongside operational maturity, better visibility, and integrating AI into DevSecOps. The common gap is not knowing where you sit on your own maturity journey. That finding cuts both ways, and some organizations learn they are further along than they assumed. Buying more tools rarely closes the gap. Ford argues the work is holistic and that each organization is unique, so what fits one may fit another poorly. AI does not settle it either, since a model fed your own assumptions will hand them back. The name follows the same logic. Steel is Pittsburgh, Patriot is Boston, and Partners is the operating model, since Steel Patriot Partners advises, deploys and operates environments alongside the client. Parisi closes by asking anyone weighing a path to verify it as a business decision rather than as an information security purchase or a price comparison. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUESTS Jason Ford, Co-Founder and CEO, Steel Patriot Partners LinkedIn: https://www.linkedin.com/in/jason-ford-5ab206/ Michael Parisi, Chief Growth Officer, Steel Patriot Partners LinkedIn: https://www.linkedin.com/in/michael-parisi-4009b2261/ RESOURCES Steel Patriot Partners: https://www.steelpatriotpartners.com/ Find Your Path, the qualifier that helps you locate your starting point: https://www.steelpatriotpartners.com/find-your-path ROI Workshop: https://www.steelpatriotpartners.com/roi-workshop ITSPmagazine event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS jason ford, michael parisi, steel patriot partners, marco ciappelli, brand story, brand marketing, marketing podcast, brand spotlight, cybersecurity compliance, grc, fedramp, fisma, cmmc, maturity assessment, cybersecurity advisory, business risk, compliance strategy, security consulting, ai in devsecops, trusted advisor

    Business Owners First, Engineers Second, Compliance People Third | A Brand Spotlight Conversation with Jason Ford and Michael Parisi of Steel Patriot Partners | Hosted by Marco Ciappelli
  8. Aug 19

    Sovereign AI Becomes an Operational Requirement, and Crogl Built for It From the Start | A Recap at Black Hat USA 2026 with Monzy Merza, Co-Founder and CEO at Crogl | Hosted by Marco Ciappelli

    Espresso in hand at Black Hat USA 2026, Monzy Merza, Co-Founder and CEO of Crogl, gave Marco Ciappelli the read from a week that started Monday. The free download the company announced the week before had drawn a strong community reaction, and a hackathon was running alongside the conversation with people downloading Crogl, hacking on it, and competing in challenges. Merza credits the openness of the approach as much as the product. What do security teams want from AI right now? Sovereignty. Merza describes a movement in which organizations have concluded that any work with AI has to cover privacy and security of the product and of the AI workload itself. Crogl was built as an on-prem product from the very beginning to serve mission critical organizations and critical infrastructure operators with hard requirements, and a larger community is now arriving at the same principles and asking what should be governed. The second shift is operational. The question moved from whether to look at AI to how work stays consistent and repeatable when one model is swapped for another, prompted by outages across model providers and in-house AI services going up and down. Merza describes the arc as a pendulum, from avoiding AI, to human in the loop, to a stretch where autonomy dominated. Crogl customers now run it both interactively and fully autonomously, with the line drawn at the tasks where a human has little reason to sit in the loop. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Monzy Merza, Co-Founder and CEO at Crogl On LinkedIn: https://www.linkedin.com/in/monzymerza/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Learn more about Crogl: https://www.crogl.com Download Crogl: https://www.crogl.com/download Crogl newsroom: https://www.crogl.com/newsroom Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS monzy merza, crogl, marco ciappelli, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, sovereign ai, on prem ai, ai governance, security operations, model choice, ai workload security, critical infrastructure, autonomous investigation, human in the loop, free download, hackathon, security community

    Sovereign AI Becomes an Operational Requirement, and Crogl Built for It From the Start | A Recap at Black Hat USA 2026 with Monzy Merza, Co-Founder and CEO at Crogl | Hosted by Marco Ciappelli
5
out of 5
30 Ratings

About

Founded in 2015, ITSPmagazine began as a vision for a publication positioned at the critical intersection of technology, cybersecurity, and society. What started as a written publication has evolved into a comprehensive repository for all their content—podcasts, articles, event coverage, interviews, videos, panels, and everything they create. This is where Sean Martin and Marco Ciappelli talk about cybersecurity, technology, society, music, storytelling, branding, conference coverage, and whatever else catches their attention. Over a decade of conversations exploring how these worlds collide, influence each other, and shape the human experience. This is where you'll find it all.

More From ITSPmagazine Podcasts