KBKAST podcast artwork

PODCAST · technology

KBKAST

Unlike every other security podcast, we don’t get stuck down in the technical weeds. Our remit is to speak with experts around the globe at the strategic level – how security technology can improve the experience and risk optimisation for every organisation. The Voice of Cyber® - In Partnership with Vanta

Publisher-supplied feed metadata · PodParley refreshed Jun 12, 2026 · Source feed

  1. 417

    Episode 380 Deep Dive: Mark Thomas | Owning a Policy PDF Doesn't Mean You Govern Your AI

    In this episode, KB sits down with Mark Thomas, IT governance and risk veteran, ISACA Hall of Famer and president of Escoute Consulting, to pull apart a problem a lot of boards haven’t clocked yet – the gap between owning an AI policy and being able to prove it controls anything. They get into the Air Canada chatbot case and what it says about accountability, why the honest board test is “would anyone notice if this was violated,” and how the risk changes once agents move from recommending to executing. Mark makes the case that human in the loop only counts when the human has the expertise, the authority and the time to say no. He also explains why only a small fraction of organisations have ever tested their ability to shut a system down, and why accountability never transfers to the vendor. A practical, occasionally uncomfortable conversation for anyone putting AI into production. —— About Mark: Mark Thomas is a globally recognised expert in governance, risk management, and digital trust, with more than two decades of experience advising organisations operating in complex, regulated, and rapidly evolving environments. His work sits at a critical intersection where strategy, governance, and execution meet. He works directly with boards and executive leadership to: Strengthen oversight and accountability Improve confidence in decision-making Navigate emerging technologies and digital risk Align governance with real-world execution Mark is known for his ability to translate complex issues into clear, practical insight, helping leaders move from uncertainty to informed, defensible decisions. Keywords: AI governance, AI risk, board accountability, agentic AI, human in the loop, kill switch, digital trust, AI policy, ISACA, Mark Thomas, Escoute Consulting, KBKast, enterprise AI, AI compliance, EU AI Act, shadow AI, Air Canada chatbot

  2. 416

    Episode 379 Deep Dive: Sean Duca | Confidence Is Not Permission - Rethinking Authority in the Autonomous SOC

    Most security vendors are shipping AI that treats capability as authority. Sean Duca thinks that’s the mistake customers are already paying for. Back on KBKast for a third time, now as co-founder and CEO of getsoteria.ai, Sean makes the case that confidence and permission are two separate gates, and that an autonomous SOC needs both before it touches anything. He walks Karissa through governed autonomy: the machine acts on its own, but only inside a boundary it can’t set or cross. A bank teller and a self-driving car do the heavy lifting on the difference between a human in the loop, on the loop, and off it entirely. He gets specific about shadow mode, the 85% agreement bar his threat hunters have to keep clearing, and why his system fails closed and hands everything back to a person the moment it hits a wall. About Sean: Sean Duca has spent 25+ years in cybersecurity, most of it advising boards and security leaders across Asia Pacific. He’s now co-founder and CEO of getsoteria.ai, following senior roles as CTO for Customer Experience at Cisco (APJC), VP and Regional Chief Security Officer at Palo Alto Networks (APJ), and CTO for APAC at Intel Security. He’s a published author on cybersecurity and calls Singapore home. Keywords: autonomous SOC, AI governance, governed autonomy, agentic AI security, confidence vs permission, human in the loop, AI access control, SOC automation, shadow mode, security operations, AI authority model, CISO, board risk, Sean Duca, getsoteria.ai, KBKast

  3. 415

    Episode 378 Deep Dive: Harman Kaur | Automation Isn't Transformation - From Intent to Outcome in Autonomous IT

    The old security math is broken. Teams used to get roughly 60 days between a vulnerability going public and attackers using it. Harman Kaur, Tanium’s CTO, explains why that number has flipped to negative, and what it means when the patch you need does not exist yet. This conversation is about the difference between automation and transformation. Running the same broken process faster is not progress. Harman makes the case for rebuilding security from first principles: changing org charts, retiring tools people have relied on for years, and moving humans out of triage and into judgment. She also gets specific about trust. In her view, trust now sits in the underlying data, because a confident AI acting on stale or incomplete data becomes dangerous at scale. Harman & KB get into the boardroom scramble around Mythos, why there is no single tool that solves it, and why the vendors closest to the data will be the ones left standing. About Harman: As Chief Technology Officer, Harman Kaur leads Tanium’s technology strategy, product management, AI and automation roadmap, and strategic technology partnerships. Harman brings more than a decade of combined experience across the United States Air Force and Tanium. She continues to serve as a Cyber Officer in the U.S. Air Force. At Tanium, Harman has held senior roles across the customer organization, R&D, and most recently led the company’s AI and Autonomous Endpoint Management strategy as head of AI before stepping into the CTO role. Harman received an MBA from the University of Southern California and a BS in Information Systems from Hawaii Pacific University. Keywords: cybersecurity, AI security, vulnerability management, patch management, endpoint security, autonomous endpoint management, Tanium, Harman Kaur, security automation, AI transformation, data quality, zero day, CISO, board risk, Mythos, security operations, KBKast

  4. 414

    Episode 377 Deep Dive: Bradon Rogers | The Forgotten Workspace - Why Nobody Ever Secured the Browser

    Bradon Rogers, Chief Customer Officer at Island, the company that created the enterprise browser category in 2020, joins KB to unpack why the industry spent two decades bolting security around the browser instead of building it in. They dig into whether organisations are solving complexity or just relocating it, why VPNs and VDI survived so long when everybody hated them, and Bradon’s blunt read on SASE: legacy on-prem architecture shoved into the cloud. He explains why SSL inspection leaves blind spots the laws of physics won’t let you close, what zero trust misses after access is granted, and how data boundaries keep company information out of personal AI tenants without turning security into the say no police. Bradon closes with his prediction for the next two years: non-human identities, agents working without human hands on the wheel, and agentic engineers who won’t just be developers but lawyers and doctors shepherding agents through their work. About Bradon: Bradon Rogers is the Chief Customer Officer at Island, where he directs the technical aspects of all customer interactions, leveraging his vast experience in cybersecurity, enterprise software, and cloud technology. Bradon’s career in cybersecurity spans over 25 years, during which he has played an executive leadership role for some of the largest firms in the industry. Keywords: enterprise browser, browser security, Island, zero trust, VPN replacement, VDI, SASE, SSL inspection, DLP, shadow AI, data boundary, agentic AI, AI agents, non-human identity, CISO, cybersecurity podcast

  5. 413

    From SAP Sapphire - KB On The Go | Legacy Risk and the AI Trust Gap

    KB is on the ground at SAP Sapphire 2026 in Orlando, where AI has moved beyond experimentation and into the center of enterprise decision making. In this KB On The Go episode, Maura Hameroff (CMO, Cloud ERP Private and RISE with SAP) makes the case that modernizing your core is a business transformation decision rather than a technical upgrade, and that companies still running on legacy systems carry more operational and security risk than most realize. Then Ted Way, PhD (VP & Chief Product Officer, Business AI Product Engineering, SAP) walks through what responsible enterprise AI actually takes: a governance layer, real business process knowledge, and data you can trust. As he puts it, AI first without security first is just a faster way to a data breach. A grounded look at what it takes to move from AI pilots to AI at scale without cutting corners that come back to bite you.

  6. 412

    Episode 376 Deep Dive: Anna Wheeler | Synthetic Confidence - When the Board Believes the Machine

    In this episode, Anna Wheeler, CEO of SSAW LLC, joins KB as she explains why so many cyber teams are stuck in event-driven strategy while calling it the real thing, why the doers can’t climb out of it because their KPIs won’t let them, and why visionary CEOs keep getting ousted when the board can’t see what they see. Along the way: the CEOs quietly burning more AI tokens than anyone else in their company, vendors winning unicorn exits on marketing rather than technology, adversaries stealing encrypted data as a long game, and what happens when boards start making decisions on synthetic confidence. Her closing advice for leaders: get very comfortable with being uncomfortable, and go looking for the sources you’d normally avoid. About Anna: Anna Wheeler is a cybersecurity strategist and former Army Blackhawk crew chief who has spent the last two decades helping government and industry modernize how they secure missions, data, and critical infrastructure. She has led federal modernization and cyber campaigns across DHS and the wider national security community, shaping multi‑billion‑dollar technology portfolios and advancing cloud, Zero Trust, and AI‑driven approaches to resilience. As CEO of SSAW LLC and a trusted advisor to C‑suites, boards, and policymakers, Anna is known for turning buzzword-heavy innovation into pragmatic, mission‑aligned change. She serves on multiple advisory boards, mentors rising cyber leaders, and speaks frequently on moving from “FOMO to focus” in cybersecurity innovation. Keywords: AI strategy, CISO, board of directors, CEO, cybersecurity leadership, event-driven strategy, strategic thinking, synthetic confidence, AI bias, go-to-market, vendor marketing, Symantec, SBOM, harvest now decrypt later, cybersecurity podcast

  7. 411

    From Cisco Live 2026 Las Vegas – KB On The Go | AI-Speed Attacks and the Race to Quantum-Safe

    Recorded at Cisco Live 2026 in Las Vegas, where 20,000 operators, engineers and executives gathered at Mandalay Bay to shape the future of networking, AI and cybersecurity. KB sits down with two Cisco leaders confronting the problems AI is creating and the infrastructure built to outlast them. Tom Gillis, SVP and GM of Cisco’s Infrastructure and Security Group, explains why the gap between a vulnerability being disclosed and exploited has collapsed from months to hours, and how Live Protect shields critical flaws between patches with no reboot and no downtime. Then Ramana Kompella, Head of Cisco Research and Cisco Fellow, makes the case for quantum networking over ever bigger quantum computers, unpacks the new Universal Quantum Switch, and explains why “harvest now, decrypt later” makes quantum safe infrastructure a today decision, not a 2029 one. Key topics: AI accelerated exploitation, vulnerability shielding and Live Protect, continuous infrastructure updates and digital twins, quantum networking, the Universal Quantum Switch, post quantum cryptography and CNSA 2.0, and the harvest now decrypt later threat.

  8. 410

    Episode 375 Deep Dive: John Deeb | Governance Theater - Why Your AI Policy Is Really Just a Set of Documents

    John leads customer success, presales, and professional services across APAC at Workato and serves as Field CTO for the region. With more than twenty-five years of experience, including roles at Oracle and TIBCO and as co-founder of Rubicon Red, he focuses on helping enterprises unlock real, lasting value from AI and integration. In this episode of KBKast, John joins KB to unpack why 42% of AI initiatives were abandoned in 2025, up from 17% the year before, and why the answer isn’t the technology. It’s trust. John explains why AI is a bigger deal than cloud ever was: what used to be storage and processing is now decision and action inside core enterprise systems. He takes aim at “governance theater,” the steering committees and policy documents that create a feeling of control while nobody can actually see what an agent is doing. And he lands the warning every security leader needs to hear: you got away with over-provisioning access for humans, because humans never went looking. Agents will. Also covered: the tokenomics panic, 700% month-on-month cost blowouts, why AI shouldn’t re-map a purchase order every single time, who owns the agent when things go wrong, and why a central control plane is the only way to govern agents at scale. Keywords: AI agents, agentic AI, AI governance, governance theater, enterprise AI, AI security, control plane, observability, MCP, tokenomics, AI cost management, AI strategy, CISO, agent permissions, Workato, shadow AI, AI ROI, autonomous agents

  9. 409

    From Atmos SPHERE 2026 – KB On The Go | Global Instability, Vendor Accountability, and Why the Energy Sector Is Already Ahead

    KB grabs the mic backstage at SPHERE 2026 by Atmos for two conversations that sit on either end of the same problem: how leaders should be thinking about risk in an unstable world, and what it actually looks like when a sector has been living that instability for years. First up, KB sits down with Chris Krebs, former Director of the U.S. Cybersecurity and Infrastructure Security Agency (CISA). They get into the CISA cuts making headlines, why old assumptions baked into risk registers no longer hold, and the five cracks Chris sees forming in the foundation of modern risk management. He also breaks down why boards need to push vendors harder on third-party risk, and why cyber has become the opening move in every modern conflict. Then Tom Huth, Specialist in Energy Market Cyber Incident Coordination at AEMO, and Ryan McLaren, co-founder and COO of Retrospect Labs, bring it back to ground level. They unpack why the energy sector’s tight-knit supply chain has made it a genuine leader in cyber resilience, the difference between a tabletop exercise and a full functional simulation, and the trust problem nobody’s fully solved: how do you verify who’s really on the other end of the phone when your systems go down? A grounded look at what it takes to build real muscle memory before the bad day arrives.

  10. 408

    From SAP Sapphire - KB On The Go | AI Theater vs the Real Thing

    KB is on the ground at SAP Sapphire in Orlando, where AI has officially moved beyond experimentation and into the core of enterprise decision making. In two conversations, Marielle Ehrmann (Chief Security, Compliance and Risk Officer, SAP) unpacks why AI governance has entered the boardroom as an accelerator rather than a brake, what separates responsible AI from AI theater, and why the biggest risk usually isn’t the model itself but the humans around it. Then Martin Merz (President Sovereign Cloud, SAP) explains why sovereign cloud has surged back into the conversation, the four dimensions SAP uses to define it, and why Australia’s pragmatic regulatory approach puts it among the top countries he works with globally. A grounded look at trust, governance and what it actually takes to innovate at enterprise scale. Keywords: AI governance, sovereign cloud, enterprise AI risk, digital sovereignty, responsible AI

  11. 407

    Episode 374 Deep Dive: Mark Jones | The Department of No Is Over - Why Cyber Has to Lead AI Adoption

    Mark Jones is Co Founder of MosaicalAI and has spent more than 25 years working across cybersecurity, technology risk, governance and resilience in complex environments where decisions need to be defensible and the cost of getting it wrong is high. His work sits at the intersection of security, business leadership and change. He helps organisations understand risk, build capability in their people, create practical operating models, and move with confidence when technology is changing faster than traditional governance can keep up. Today, Mark’s work is focused on AI. At MosaicalAI, he helps Australian organisations rebuild how teams work for the agentic era. His view is that every team runs on three things: people, technology and data, but most teams are still operating on a model built before AI. MosaicalAI maps how a team works today, builds the agentic version beside it, then rebuilds it with them. Mark’s approach is AI native and cybersecurity driven. He does not start with tools or generic productivity use cases. He starts with the team, the workflow, the data, the controls, the risks and the decisions that matter. The goal is practical AI capability that the organisation owns, understands and can govern. Cybersecurity is MosaicalAI’s first proof point because it is where AI adoption gets real quickly. Cyber teams already understand risk, evidence, accountability, control and resilience. When they use AI to improve triage, reporting, exposure management, control mapping, evidence gathering and decision support, they are better placed to guide safe AI adoption across the broader business. Mark believes AI cannot simply be bolted onto an organisation. It needs ownership, guardrails, evidence, accountability, resilience and control from day one. He is a Certified Information Security Manager and Certified Information Systems Security Professional, combining practical executive experience with globally recognised security credentials.

  12. 406

    From Cisco Live 2026 Las Vegas - KB On The Go | Agents, Attacks, and the Invisible Threat

    Recorded at Cisco Live 2026 in Las Vegas, where 20,000 operators, engineers and executives gathered at Mandalay Bay to shape the future of networking, AI and cybersecurity. KB sits down with two Cisco security leaders on the front lines of agentic AI. Peter Bailey, SVP and GM of Cisco Security, breaks down why the security frameworks built over the last 20 years weren’t designed for machine-speed agents, and what governance actually needs to look like now. Then Amy Chang, Head of AI Threat Intelligence and Security Research, reveals how adversarial attacks are moving beyond text into images and audio in ways that are invisible to the human eye but not to your agents. Key topics: agentic AI governance, prompt injection and jailbreaks, multimodal attack vectors, MCP security gaps, identity in AI environments, security by design, and the post-Mythos threat landscape.

  13. 405

    From Atmos SPHERE 2026 - KB On The Go | Everyone's Business: Cyber Resilience from Government to Ground Level

    KB grabs the mic backstage at SPHERE 2026 by Atmos for two conversations that couldn’t look more different on the surface, but end up pointing at the same thing: where cyber threats really come from, and who’s pushing back. First up, KB sits down with Lieutenant General Michelle McGuinness, Australia’s National Cybersecurity Coordinator, and Steph Way, Director of the National Office of Cybersecurity. They get into what those 60 actions under Horizon 1 actually delivered, how limited use legislation is changing the way businesses talk to government after an incident, and why cyber resilience can’t just sit with the technical few — it has to be something every Australian feels some ownership of. Then James Taliento, CEO of AFTRDRK, and Jeremy Kirk, Director of Intelligence at Okta, bring it down to ground level. Cybercrime-as-a-service has made it possible for almost anyone with a internet connection to get in the game, and the latest wave of threat actors isn’t in it for ideology or even the money. It’s the thrill, the bragging rights, and a kind of rockstar lifestyle that’s being actively sold to a younger generation. It’s a candid, practical chat about what all of that means for defenders today.

  14. 404

    Episode 373 Deep Dive: Pete Harteveld | The Digital Insider - Why Your AI Agents Are the Threat You Didn't Hire

    Pete Harteveld was appointed CEO of Exabeam in October 2025 and most recently served as the company’s Chief Revenue Officer.  He has more than two decades of leadership experience having built a reputation for scaling revenue and building high-performing global teams across the cybersecurity and technology sectors. Pete played a pivotal role in uniting Exabeam and LogRhythm in 2024, leveraging his deep expertise in mergers and acquisitions to drive a seamless integration and maximise stakeholder value. His earlier career included leadership roles at Aryaka, Veracode, Compuware, and Deloitte, where he guided complex integrations, redefined go-to-market strategies, and delivered measurable impact for customers and partners alike. At Exabeam, Harteveld is focused on advancing the mission to secure the world from cyberthreats. His leadership centers on empowering customers with cutting-edge solutions, fostering innovation that drives business outcomes, and cultivating a culture of excellence that inspires teams to achieve their best.

  15. 403

    From ISACA 2026 North America Conference - KB On The Go | AI Puts Its Hard Hat On: Agents, ROI, and the Governance Reset

    KB is on the ground at the ISACA 2026 North American Conference in Las Vegas, this time for the AI conversation that’s reshaping ROI, risk and governance all at once. Sushila Nair, Independent Information Security Consultant, and President of the ISACA Greater Washington D.C. chapter, opens with the AI ROI question everyone keeps circling. She walks through ISACA’s latest AI Pulse research, explains why last year’s AI was your friend and this year’s AI has put its hard hat on, and breaks down the shift from chatbots to agents that’s finally moving the numbers. One of her clients went from 4 agents in proof of concept to 140 in production this year. She also covers the workforce transformation underneath all of it, who’s getting displaced first, and why automation is the real driver of cost savings. Then Mark Thomas, Founder & President of Escoute Consulting and board advisor and ISACA hall of Fame entrant, joins to talk about what all of this means for governance and risk. He walks through ISACA’s new AAIR certification (Advanced AI Risk), why traditional frameworks aren’t outdated but incomplete, and how concepts like drift, calibration and model cards are becoming non-negotiable. His central argument: accountability has to come before architecture, and you can’t certify a moving target with a static framework. More about ISACA’s AAIR Certification here: https://www.isaca.org/credentialing/aair ISACA® 2026 AI Pulse Poll: https://www.isaca.org/resources/ai-pulse-poll

  16. 402

    Episode 372 Deep Dive: Vincent Lavergne | The Token Economy, Agentic AI, and the Real State of the Market

    As a specialist in networking and software development, Vincent joined the F5 team in France in 2000 as a pre-sales engineer. Having contributed to F5’s growth initially in the French market and South EMEA region, he took on several managerial roles before overseeing from 2018 the EMEA pre-sales teams as the VP of Solutions Engineering for Europe, Middle East, and Africa (EMEA).  From 2025, Vincent has been appointed into the role of VP Global AI Leader managing an international team of Global Solutions Architects focused on AI.  Vincent holds a degree in network engineering and software development from ESITCOM, and a technical degree in Telecommunications and Network engineering.  He speaks at events across the globe about Artificial Intelligence and specifically about performing AI inference at scale.

  17. 401

    From Atmos SPHERE 2026 - KB On The Go | Same Fight, Different Languages

    KB takes the mic behind the scenes at SPHERE 2026 by Atmos, where 1,500 people from across cyber, legal, tech and government packed a room to do something rare: shift the entire industry’s focus from the moment of crisis to what comes before it. In two conversations, Reece Corbett-Wilkins and Leah Pinto reflect on the day, the speakers, and what it actually takes to change an industry’s centre of gravity. Then Anthony Cooke, James Blakely and Michael Boyd unpack why government can be a friend and a facilitator rather than the fun police, the trust that limited use disclosure has unlocked, and what frameworks like Horizon 2 mean for the small businesses sitting at the underbelly of every supply chain. A practical, hopeful look at collaboration, accountability and what cyber resilience looks like when everyone in the room speaks the same language.

  18. 400

    Episode 371 Deep Dive: Mayank Upadhyay | The Closing Window - Why Human-Speed Security is Already Too Slow

    Snowflake has recently appointed Mayank Upadhyay its Chief Security and Trust Officer to lead security efforts. Mayank brings one of the most influential careers in enterprise security to Snowflake. During his more than two decades at Google, he shaped the modern security landscape, ultimately serving as Vice President of Engineering for Google Cloud where he secured both the public-facing Google Cloud Platform and the private cloud infrastructure powering core Google services. Prior to this, his career progression to Distinguished Engineer was defined by a sequence of foundational technologies he delivered. Today, as CSTO at Snowflake, he secures the data and AI foundation for 11,000+ customers (including over a third of the Fortune Global 2000), giving him a unique, front-row vantage point on how AI is fundamentally reshaping enterprise security.

  19. 399

    From ISACA 2026 North America Conference - KB On The Go | Built on Borrowed Tools: Supply Chain Risk and the AI ROI Flip

    KB is on the ground at ISACA 2026 North American Conference in Las Vegas, sitting down with two guests pulling at the same thread from different angles: the gap between how dependent we’ve become on modern tools and how little we actually understand them. First, Pam Nigro, SVP of Security and Security Officer at Medecision and Board Director at ISACA, unpacks why supply chain has become the most vulnerable area in cyber security right now. She gets into the hidden risks sitting inside SaaS dependencies, API chains and open source libraries deployed once and forgotten, what operational paralysis actually looks like when a critical tool goes down, and why companies need to stop treating supply chain as a vendor risk checkbox and start treating it as a resilience problem. Then Asaf Weisberg, CEO of introSight and Board Director at ISACA, joins to flip the AI ROI conversation. While recent ISACA research shows most companies still can’t measure return on AI investment, Asaf argues the ROI is already obvious if you know where to look. He breaks down why traditional ROI calculations don’t fit AI, what’s happening inside software teams right now with tools like Claude Code, and the very real risk of leaking your most valuable IP through free AI subscriptions. More about ISACA’s AAIR Certification here: https://www.isaca.org/credentialing/aair ISACA® 2026 AI Pulse Poll: https://www.isaca.org/resources/ai-pulse-poll

  20. 398

    Episode 370 Deep Dive: John Wojcik | The Silicon Valley of the Criminal Underworld

    John Wojcik, Senior Threat Researcher, Infoblox: Based in Bangkok, Thailand, John is a seasoned threat intelligence researcher who has spent his career following cybercriminal activity in the Southeast Asia region. Recently, his work at Infoblox has focused on pig butchering as a service, exposing sophisticated global money laundering, human trafficking and slave operations in Cambodia, Laos, Myanmar and the Philippines. John previously worked for the United Nations Office on Drugs and Crime, where he worked with local and international authorities on uncovering major cybercriminal activities in the region.

  21. 397

    From Atmos SPHERE 2026 - KB On The Go | Resilience And Recovery

    In this episode of KB on the Go, recorded at Atmos SPHERE 2026, Karissa Breen brings together two conversations united by one uncomfortable truth: we have built fast, efficient, hyper connected societies, and quietly traded away our resilience. First, Karissa sits down with Admiral Mike Rogers, Global Advisory Board member at CyberCX, and Alastair MacGibbon, Independent Adviser, to unpack what real national resilience looks like in 2026. They explore why cyber is no longer just about protecting data, but about availability and integrity, what happens when you can no longer trust the systems you depend on, and why it so often takes a crisis before meaningful change happens. Then, Karissa is joined by Heather Osborne, Director of Global Events and Programming at NetDiligence, and Stefanie Luhrs, Partner, First Response at Atmos, to dig into what the 2026 cyber loss data is really telling us. The conversation covers the rising cost of business interruption, the long tail of human and reputational impact after a breach, the strain on B2B relationships, and the wave of regulatory activity expected in Australia over the next twelve months. Two conversations, one shared message: we are optimised for cheapest and fastest, but not for when things break, and resilience is the conversation we keep putting off.

  22. 396

    Episode 369 Deep Dive: Dominic Vogel | Cybersecurity's Leadership Crisis - Why the Best People Are Walking Away

    Dominic Vogel is a well-respected cyber security thought leader appearing on media news outlets across the world. As a veteran cyber security expert and thought leader, Dominic holds a proven track record across multitude of industries (financial services, logistics, transportation, healthcare, government, telecommunications, and critical infrastructure). Dominic is a firm believer in delivering sustainable security that supports and protects business goals. Having worked within large and globally diverse organizations he has extensive security experience that has been forged over the past two decades as an information security professional. Dominic is a 2x founder who has focused on providing unbiased actionable cyber security strategic guidance and advice to startups and small businesses across North America. Dominic is the President at Vogel Cyber Leadership & Coaching, a Vancouver-based leadership advisory company specializing in cyber risk management He is also a self-professed positive troll and professional hype man and believes in the power of uplifting others through his high-energy coaching practice.

  23. 395

    Episode 368 Deep Dive: Dmitry Volkov | The Shift from Reactive to Predictive Cybersecurity

    Dmitry Volkov is a cybersecurity veteran, technology entrepreneur, and the dynamic leader of Group-IB and its team of over 250 cyber defenders. Recognized as one of the top seven influencers in global cybersecurity by Business Insider, Dmitry is also a member of the Europol EC3 Advisory Group and the UN Open-ended Intergovernmental Expert Group. In 2003, Dmitry co-founded Group-IB as a cyber investigations startup. Two decades later, the company has evolved into a cybersecurity leader known for its engineering innovations. Group-IB now protects public and private enterprises in more than 60 countries, supported by strategic and autonomous operational units, Digital Crime Resistance Centers (DCRCs), located in the Middle East, Europe, Central Asia, Asia-Pacific, and Chile.  

  24. 394

    From Extreme Connect 2026 Orlando, USA - KB on the Go | Markus Nispel & Michael Jones

    Recorded live from Extreme Connect in Orlando, KB sits down with Markus Nispel, CTO EMEA & Head of Office of the CTO at Extreme Networks, and Michael Jones (MJ), VP of AI and Innovation, Office of the CTO at Extreme Networks. Markus gets into why networks are now a boardroom conversation, what real time data means for agentic systems, and the shift from human in the loop to human on the loop. He also unpacks the guardrails and controls that determine whether agentic AI becomes a trusted operator or a liability. MJ tackles agent sprawl, why context beats the model, and the “jagged edge of intelligence” where AI can do PhD level work one minute and fumble basic tasks the next. Plus why sitting out the experimentation phase is the most expensive thing you can do right now.

  25. 393

    Episode 367 Deep Dive: John Hines | The AI Readiness Gap

    John Hines is the Senior Director of Enterprise Business for the Asia-Pacific and Japan region at Lumen Technologies. With more than 25 years of leadership experience in IT solutions and cybersecurity, John has led and grown businesses across diverse global markets. His expertise spans cybersecurity, risk management, network and cloud solutions, consulting services, and new market acquisitions, serving industries such as manufacturing, government, healthcare, transportation, financial services, energy, and retail. At Lumen, John is responsible for driving enterprise growth by delivering secure, agile, and innovative technology solutions that help customers connect people, data, and applications seamlessly. He is a proven leader in building high-performance teams, modernising operating models, and executing strategic programs that deliver measurable business outcomes. His work has included partnering with global law enforcement on cyber threat takedowns through Lumen’s Black Lotus Labs, underscoring his commitment to safeguarding the digital ecosystem.

  26. 392

    Episode 366 Deep Dive: Davyn Baumann | A New Surge - Threat Intelligence

    Davyn Baumann has been in the threat intelligence industry for over 10 years, and in that time has helped uplift cyber awareness by providing comprehensive strategic level intelligence for Australian government and critical industry organisations. Davyn currently is a member of the Custom Intelligence Team at Mandiant, part of Google Cloud.

  27. 391

    Episode 365 Deep Dive: Ashley Rose | Human Risk - The Next Frontier

    Ashley Rose is the CEO and Co-Founder of Living Security, where she is building the future of workforce security through AI-native Human Risk Management (HRM). Her work sits at the intersection of AI, cybersecurity, and business transformation—helping enterprises turn human and workforce risk into a measurable, manageable business outcome. Since founding Living Security in 2017, Ashley has led the company through rapid growth, raising more than $25M for product development and scale, and driving consecutive years of revenue acceleration. Today, her focus is on helping CISOs and security and risk leaders move beyond traditional awareness to a data-driven, predictive model that reduces real risk and supports organizational growth. Ashley speaks regularly at industry forums including EWF, Security ISACs, and other security and leadership conferences, sharing practical insight on topics such as human risk, AI in the enterprise, and building security programs that executives and boards actually care about. She also contributes thought leadership to outlets such as Forbes and other publications. At her core, Ashley is a builder—of companies, products, teams, and categories. She is committed to creating a diverse and inclusive organization that reflects the communities Living Security serves, and to leading with transparency, curiosity, and accountability. Ashley holds a BBA from the University of Michigan and is a serial entrepreneur with a background in tech and product management. She founded Living Security on a simple belief: when you empower people, they become your strongest security asset—not your weakest link.

  28. 390

    Episode 364 Deep Dive: Malcolm Turnbull | Balancing Innovation, Security, and Risk

    In this episode, we sit down with Malcolm Turnbull, former Prime Minister of Australia, current Chairman of Fortescue Future Industries, Senior Advisor to KKR, and Strategic Advisor at Semperis. Malcolm reflects on his leadership in launching Australia’s first national cybersecurity strategy and examines the evolution of cyber as a vital component of national security and statecraft. He shares insights into the challenges faced by governments and businesses in raising digital awareness, the necessity of mandatory breach reporting, and the importance of sharing intelligence to combat cybercrime. The conversation covers Australia’s approach to critical infrastructure protection, foreign interference reforms, and the nuances of risk management in telecom and utility sectors. Malcolm also discusses the legal landscape around cybersecurity liabilities and the growing impact of class actions on corporate accountability, emphasizing adaptability, setting realistic expectations, and continual vigilance as key lessons for future leaders. The Honourable Malcolm Turnbull AC Australia’s 29th Prime Minister (2015-2018) had international careers in law, business and the media before entering politics at the age of 50. As Prime Minister, he reformed Australia’s personal income tax, education and childcare systems, oversaw the legalisation of same sex marriage and announced the construction of Snowy Hydro 2.0 the biggest pumped hydro scheme in the southern hemisphere. Mr Turnbull embarked on the largest peacetime investment in Australian defence capabilities and set out Australia’s first national cybersecurity strategy. Globally, Mr Turnbull played a leading role in reviving the Trans Pacific Partnership (TPP-11 or CPTPP) after the United States withdrew. He also struck deals with US Presidents Obama and Trump to accept refugees who tried to arrive in Australia illegally by boat. As a young lawyer, Mr Turnbull successfully defended former MI5 agent Peter Wright against the British Government in the 1986 “Spycatcher” trial before entering business where he ran his own investment banking firm for a decade before joining Goldman Sachs as a partner in 1997. Both before and after his political career, Mr Turnbull has been a successful venture capitalist. He co founded OzEmail Limited, the first Australian tech company to be listed on the NASDAQ. Since leaving politics, Mr Turnbull has resumed his business career. He is a senior adviser to KKR and an investor in, and adviser to, many Australian technology businesses. He is a director of the International Hydropower Association and Chairman of Australian Fortescue Future Industries. Mr Turnbull speaks and writes on a range of issues including cyber security, geopolitics and renewable energy.  

  29. 389

    Episode 363 Deep Dive: Nathan Thomas - Inside Oracle’s Multi-Cloud Strategy

    In this episode, we sit down with Nathan Thomas, Senior Vice President of Product Management at Oracle Cloud Infrastructure (OCI), to explore Oracle’s evolving multi cloud strategy and the major trends shaping the cloud landscape. Nathan discusses the company’s shift from an Oracle-first approach to a multi cloud reality, driven by customer expectations for flexibility, governance, and sovereignty of data. He highlights the persistent demand for sovereign solutions, the impact of AI on accelerating multi cloud adoption, and the need for seamless integration and portability as customer loyalty becomes more fluid. Nathan also delves into the complexities of cloud migration, Oracle’s focus on delivering efficient and cost-effective infrastructure, and how maintaining a narrow focus on core services differentiates OCI in a crowded marketplace. Finally, he emphasizes the importance of holding cloud vendors accountable for innovation, value, and enabling truly multi cloud operations. Nathan Thomas is senior vice president of Product Management at Oracle Cloud Infrastructure (OCI), overseeing product strategy and development of Oracle’s cloud and multicloud services. His organization is responsible for providing secure, reliable, and high-performance solutions that enable customers to run Oracle’s industry-leading services across their preferred cloud environments, addressing complex technical challenges and promoting long-term innovation and growth. Prior to Oracle, Nathan held senior product and engineering leadership roles at Amazon Web Services, Epic Games, Google Cloud, and Red Hat. His work has been instrumental in promoting enterprise adoption of open-source technologies, driving the commercialization of cloud computing, and broadening the application of real-time 3D technology across multiple industries. Nathan is based in Nashville, Tennessee.

  30. 388

    Episode 362 Deep Dive: César Cernuda | Trust, Trade & the New Data Diplomacy

    In this episode, we sit down with César Cernuda, President at NetApp, as he explores the growing significance of data and the evolving role of trust, governance, and transparency in managing this strategic asset. César discusses how organizations and nations must build intelligent data infrastructures to enable AI and navigate complex regulatory landscapes, emphasizing the importance of cybersecurity, interoperability, and modernizing data lakes. We also examine the balance between protection and openness, the resurgence of sovereign cloud requirements, and the pressure for leaders to cultivate a data-first mindset to stay competitive. César Cernuda has led NetApp’s integrated go-to-market organization since July 2020, delivering on the company’s promise to meet customers wherever they are on their digital-transformation journeys by providing the superior products, specialist skills, and services they need to architect, build, and manage their data fabrics. César joined NetApp following a long career at Microsoft, where he served as President of Microsoft Asia Pacific, President of Microsoft Latin America, and Global Corporate Vice President of the brand. Having walked in the shoes of NetApp’s enterprise customers, he brings a customer-centric perspective to all he does as president. César serves as the non-executive director and Chairman of the ESG committee at Gestamp, an international organization dedicated to the automotive industry; as an advisory board member of Georgetown University’s McDonough School of Business; and as an international advisory board member of IESE Business School – University of Navarra.    

  31. 387

    Episode 361 Deep Dive: Richard Stiennon | Why AI Security Will Define The Future Of Digital Defence

    Richard Stiennon is Chief Research Analyst for IT-Harvest, the firm he founded in 2005 to cover the 3,051+ vendors that make up the IT security industry. He has presented on the topic of cybersecurity in 31 countries on six continents. He was a lecturer at Charles Sturt University in Australia. He is the author of Surviving Cyberwar (Government Institutes, 2010) and Washington Post Best Seller, There Will Be Cyberwar.  Stiennon was Chief Strategy Officer for Blancco Technology Group, the Chief Marketing Officer for Fortinet, Inc. and VP Threat Research at Webroot Software. Prior to that he was VP Research at Gartner. He has a B.S. in Aerospace Engineering and his MA in War in the Modern World from King’s College, London. His latest book Security Yearbook 2022 was released in June, 2022. Get a copy here.  

  32. 386

    From Elastic{ON} Sydney 2026 – KB On The Go | Mandy Andress

    Data is exploding. Environments are getting noisier and the line between observability and security, it’s basically gone. Search isn’t just a feature anymore, it’s infrastructure. It’s how you see, how you detect, and ultimately how you defend from ai, power detection, engineering to unified visibility across logs, metrics, t races and security telemetry. We’re officially in a world where if you can’t search it in real time, you can’t secure it. This bonus episode features Mandy Andress, CISO at Elastic, live from Elastic{ON} Sydney 2026. As Australia navigates its unique, sector-led approach to AI regulation, Karissa Breen and Mandy Andress explore the challenges—and opportunities—facing CISOs on the front lines of the agentic AI revolution. Mandy Andress is currently the CISO of Elastic and has a long career focused on information risk and security.‬ Prior to Elastic, Mandy led the information security function at MassMutual and established and built information security programs at TiVo, Evant, and Privada. She worked as a security consultant with Ernst & Young and Deloitte & Touche, focusing on energy, financial services, and Internet technology clients with global operations. She also founded an information security consulting company with clients ranging from Fortune‬ 100 companies to start up organizations.‬ ‭She is a published author, with her book Surviving Security having two editions and used at multiple‬ universities around the world as the textbook for foundation information security courses. Mandy also tested‬ and reviewed information security products for multiple publications as well as serving as the author for the weekly InfoWorld security column. She has been a sought after expert in the field, speaking at signature‬ security conferences such as BlackHat and Networld+Interop. In addition, she has taught a graduate level‬ Information Risk Management course for UMass Amherst in the College of Information and Computer‬ Sciences.‬ Mandy has a JD from Western New England University, a Master’s in Management Information Systems from Texas A&M University, and a B.B.A in Accounting from Texas A&M University. Mandy is a CISSP, CPA, and‬ member of the Texas Bar.‬      

  33. 385

    Episode 360 Deep Dive: Simon Cook | The Right To Be Forgotten, Navigating GDPR, IRAP and Global Standards in Physical and Cybersecurity

    In this episode, we sit down with Simon Cook, Director of New Offerings at Genetec, as he discusses the convergence between physical and cybersecurity, and the impact of global standards such as GDPR and IRAP on industry practices. Simon details the shift from siloed teams to collaborative approaches, highlighting how increased connectivity and advancements like generative AI have expanded the attack surface, making cyber risks a broader business concern. He explores the ongoing challenges of device security—from consumer cameras to enterprise solutions—and the market’s growing awareness of attack vectors stemming from seemingly innocuous network devices. Simon also unpacks the complexities of privacy legislation, especially the right to be forgotten, emphasizing the need for technology providers to embed privacy and trust by design at every stage of product development. Finally, he offers insight into the future direction of physical security, predicting the acceleration of proactive, technology-driven systems and deeper integration of compliance frameworks worldwide. Simon is a highly motivated, innovative and creative security professional with almost 20 years’ experience in the Pre-Sales and design space working with hardware, software and cloud solutions. Leadership experience and a proven track record of success growing and evolving teams in both medium and large organisations and on a global scale. Accustomed to speaking up to C- Level, in public forums and to press. A commercial techie that is inspired by good products, and passionate and motivated people.    

  34. 384

    Episode 359 Deep Dive: Omar Khawaja | Data Intelligence for Cybersecurity

    In this episode, we sit down with Omar Khawaja, Vice President of Security and Field CISO at Databricks, as he explores the intersection of data, AI, and cybersecurity defense. Omar addresses the real fatigue facing CISOs amidst rising AI hype, emphasizing that combining high-quality data with AI—not just AI alone—is pivotal to effective cyber defense. He shares insights on the growing need for organizations to get their data in order, challenges in adapting operating models for AI, and the importance of reducing security tool sprawl through robust, unified platforms. Omar also discusses the increasing role of AI agents in automating routine tasks, the evolving skills required to leverage AI securely, and why mature frameworks and a growth mindset are critical as organizations navigate the complexities and risks of AI adoption. Omar Khawaja is the VP, Field CISO at Databricks where he gets to work with CISOs to help them securely shepherd their organisations’ data+AI journey. He leads Databricks’ Field Security practice globally, teaches at Carnegie Mellon’s CISO program, sits on the boards of HITRUST and FAIR Institute, spent 9 years as CISO of a $26B enterprise and is leading a team that developed an actionable AI security framework for 11,000 enterprise data platform customers at Databricks.

  35. 383

    Episode 358 Deep Dive: Lisa Black | How Leaders Survive Major System Failures

    In this episode, we sit down with Lisa Black, Director of Public Sector at Aeon Nexus Corporation, as she shares her perspectives on crisis leadership and organizational resilience when critical systems fail. Lisa draws from her extensive background leading government operations to highlight how real risk in a crisis is often less about technology and more about maintaining trust, clear communication, and effective decision-making under pressure. We explore the pitfalls of traditional and predictable crisis training, the importance of cross-training team members, and the value of embedding continuous improvement and consequence-based learning into daily operations. Lisa also discusses the crucial role of cadence in incident communications, the need to manage rumor mills and public scrutiny, consequences of over-reliance on technology, and why true collaboration between public and private sectors is essential to strengthen defenses against modern threats. Lisa Black is the Director of Public Sector at Aeon Nexus Corporation where she consults with government clients who are committed to enhancing justice through modernizing technology. Utilizing Aeon’s legal case management solution to deliver a single, secure, centralized, cloud-based system to public sector entities Lisa and her company work with public safety agencies, the offices of District Attorneys, Public Defenders, mediators and courts throughout the US. With over two decades of government experience, Lisa previously served as the Chief Deputy County Executive in Suffolk County, NY. There she managed the daily operations of a local government that served 1.5 million residents with a $4 Billion budget and a workforce of approximately 12,000 staff. Lisa has also held leadership roles with two NY State Senate Majority Leaders, two New York City Mayors and a NY Governor serving as Senior Advisor at the NYS Division of Homeland Security and Emergency Services. Lisa’s advantage in serving in both republican and democratic governments has been instrumental in her ability to communicate across the aisle where she has been involved in crisis and emergency management for over half of her career. Formerly trained in emergency management and operational decision-making during crisis, Lisa has also earned certificates in Government Leadership and Cybersecurity Policy and Technology from the JFK School of Government at Harvard University Executive Education Program. Importantly, her skills and training helped her lead the Unified Command Incident Response to a 2022 countywide ransomware attack including incident identification, containment, eradication and operational recovery. She has spoken publicly about the experience at conferences and forums across the US including those with the NY State Association of Counties (NYSAC), the US Secret Service Cyber Fraud Task Force, NY State Local Government Information Technology Directors Association (NYSLGITDA), the National Federation of Municipal Analysts (NFMA), the International Association of Emergency Manager’s (IAEM) Region II Inaugural Conference, the National Association of Counties (NACo) Chief Information Officer Forum, the FBI & Fordham Law School’s International Cyber Security Summit and the 2020Partners Counterterrorism, Counter-Narcotics & Cyber Security Miami Conference.

  36. 382

    From The SimSpace Summit 2026 – KB On The Go | Rushell Hopkins and Stanley McChrystal (Part 2)

    Karissa Breen [00:00:10]: Welcome to KB On The Go. I’m coming to you from my new place of residence, Orlando, Florida. And today I’m being hosted at the SimSpace Summit. Cybersecurity is hitting a breaking point, compliance checklists, tabletop exercises, and confidence claims. Aren’t enough anymore, especially as AI accelerates both attack and defense. This summit is about something different, proving readiness under real pressure, real tools, real teams, real-world chaos. Today, I’m speaking with leaders and former US government officials pushing cyber training testing and validation out of theory and into reality. Because when the next incident hits, what matters isn’t what looks good on paper, it’s what actually holds up. Karissa Breen [00:00:57]: Stay with me, we’re diving into the conversations that matter. This is KB On The Go from SYNSPACE Summit 2026. Karissa Breen [00:01:04]: Let’s get into it. Joining me now in person is Rochelle Hopkins, Professor, Computer Science and Cybersecurity at Florida Southwestern State College, and today we’re discussing the future of cyber workforce. So, Rochelle, thanks for joining and welcome. Rushell Hopkins [00:01:23]: Well, thanks for having me. Karissa Breen [00:01:24]: Okay. So Rochelle, I’m really interested in the work that you do. And when we were talking before, you were sort of describing like how things are nowadays. And I think it’s really interesting to explore that a little bit more. So I want to start perhaps with your view on the growing concern about cognitive atrophy in the younger generation. And what are your thoughts here? Rushell Hopkins [00:01:46]: Absolutely. One of the things I also didn’t share with you is I’m part of a cohort or consortium called the AAC&U, which is the American Association of Colleges and Universities. And I’m in this cohort where we’re trying to bring AI into higher education and kind of look at what that’s going to do. I share concerns with many of the educators in what they’re calling cognitive offloading or cognitive atrophy in our younger generation. In cybersecurity, I tend to have really remarkable, creative, compassionate, and technically advanced students. But what I’m seeing and the shift that I’m seeing is that these students are using AI at a level where it’s eroding their patience, their deep focus, and their willingness to wrestle with the deeper problems. And learning, especially in cybersecurity, requires discomfort. We have to think outside the box. Rushell Hopkins [00:02:33]: It really requires us to sit with something, and if we don’t understand it, we are breaking it down and we’re building up that mental endurance, right, to solve it. And when their answer is just one click away, right, to these problems, that muscle greatly weakens. Karissa Breen [00:02:50]: This is where I think it gets really interesting as well, because I’m a millennial, and even when we were learning things, it’s still fundamentally different. Doesn’t feel that long ago. But when you’re talking about what you’re describing versus when I came up through the ranks, it’s not that long ago, but it does feel a lot longer. So I’m curious to see What does this sort of mean now for how people are actually learning things? You mentioned before 15-minute to 20-minute blocks before you had to say, right, we’re gonna get up, go for a walk, we’re gonna do something else. That’s a very short period of time when you think about it. How, what’s going on here? Rushell Hopkins [00:03:32]: So there’s a lot, there’s a lot of things. People are starting to do a lot of research on attention span, right? And I don’t wanna go down too much that down that road because I don’t have any degrees in psychology or, you know, I teach computer science and cybersecurity. But I’ve watched a lot of content, and I don’t mean social media content, I mean research, where shows like Cocomelon, right, that we put our kids in...

  37. 381

    From The SimSpace Summit 2026 – KB On The Go | Peter Lee and Ernie Ferraresso (Part 1)

    Cybersecurity is hitting a breaking point. Compliance checklists, tabletop exercises and confidence claims aren’t enough anymore, especially as AI accelerates both attack and defense. In this bonus episode, KB sits down with Peter Lee, Chief Executive Officer and President of SimSpace, and Ernie Ferraresso, Senior Director of Cyber Florida. Together they discuss cyber readiness and why Florida treats cyber like a mission. Peter Lee, Chief Executive Officer and President of SimSpace Peter serves as the Chief Executive Officer and President of SimSpace, the realistic, intelligent cyber range that strengthens teams, technologies, and processes to outsmart adversaries before the fight begins. Previously, Peter was co-founder and CEO of DataSynapse, an infrastructure software company acquired by TIBCO; and CEO of RapidMiner, an open source machine learning platform acquired by Altair. At TIBCO, Peter served as Executive Vice President responsible for multiple businesses including the security, cloud computing, B2B, CX, and analytics product groups. Before launching his career in software, Peter was a strategy consultant with Deloitte and an investment banker with JP Morgan. Peter has extensive Board experience collaborating with top tier investors to grow innovative software companies, serving as Chairman for Attivio (acquired by ServiceNow), WorldQuant Predictive, and ActiveState, and as Director for Ektron (acquired by Accel-KKR), Vesta (acquired by TINT), Infomatix (acquired by EPAM), OpenAssemby (acquired by Fulcrum), BlogTalkRadio (acquired by iHeartRadio), Entrio and Chattermill. Peter also serves on the investment committees of Advanced Finance & Investment Group and Communitas Capital Partners. Peter graduated from Harvard College with an AB degree in Government (cum laude), received an MBA degree from The Wharton School in Entrepreneurial Management and an MA degree from The University of Pennsylvania in International Affairs. Peter has been invited twice to speak at the World Economic Forum in Davos and four times at The Milken Institute Global Conferences in LA and Singapore, explaining the impact of AI in terms of its business value and key use cases. Peter is a former Board member of Upwardly Global, alumnus of YPO and a member of the Development Board for Phillips Academy Andover. Ernie Ferraresso, Senior Director of Cyber Florida As the senior director of Cyber Florida, Ernie drives the organization’s strategic vision while overseeing the center’s day-to-day operations. He started with Cyber Florida in 2017 as associate director of programs and partnerships and brings decades of technology expertise and leadership experience to his role. Prior to Cyber Florida, Ernie worked for a small technology design and integration firm as the Director of Operations, overseeing the design and implementation of cybersecurity and emergency operations center technology solutions in the U.S. and throughout Latin America. He is a retired U.S. Marine Intelligence Officer who served in the U.S. and abroad. His work included assignments with the U.S. Special Operations Forces, the intelligence community, the George C. Marshall European Center for Security Studies, and U.S. Cyber Command.

  38. 380

    Episode 357 Deep Dive: James Tennant | Why does AUKUS Need Sovereign Capital?

    In this episode, we sit down with James Tennant, Partner and Head of JAPAC at Boka Capital, as he discusses why AUKUS needs sovereign capital to successfully deliver on its strategic ambitions. James explores the disparity between the headline-grabbing investments of AUKUS Pillar 1 and the overlooked capital shortfalls of Pillar 2, emphasizing the urgent need to build a unified capital architecture across Australia, the UK, and the US. He highlights the challenges faced by defense technology startups, such as the “valley of death” funding gap and ESG constraints that lock out institutional investment, and draws valuable lessons from international examples like In-Q-Tel and Israel’s Yozma. Throughout the conversation, James argues for a coordinated sovereign capital framework, increased public education about dual-use technologies, and transparent government action to move from strategic announcements to real capital deployment, ensuring AUKUS can compete effectively on a global stage. James Tennant, Partner – Head of JAPAC, BOKA Capital James Tennant is a Fellow with ASPI’s Cyber, Technology and Security Program and a Partner at BOKA Capital, a leading AUKUS Investment House in London, Sydney and New York. His key role at BOKA is complemented by his service as an Officer in the Australian Army, where he specialises in Capability Development. He is also a Senior Partner at Gilmour Space Technologies, an Australian-based rocket company innovating in the field of low-cost small satellite launch vehicles. James is a seasoned investor and corporate leader with deep interests and investments in diverse fields such as Quantum, Artificial Intelligence, Space, CyberSec, Machine Learning, Internet of Things, Drones, Enterprise Infrastructure, and Autonomous Vehicles. His professional journey, spanning across different continents and industries, uniquely positions him at the intersection of finance, defence, and technology including artificial intelligence. James holds a Bachelor of Commerce degree with a specialisation in International Business from the University of Sydney, is a Graduate of Applied Finance at Macquarie University, and holds management courses in Private Equity and Venture Capital from Harvard Business School. He has also completed the Company Directors Course at the Australian Institute of Company Directors.

  39. 379

    Episode 356 Deep Dive: Simon Hodgkinson | The Burnout Crisis in the Cybersecurity Community

    In this episode, we sit down with Strategic Advisor at Semperis, as he shares his personal experience with burnout during his tenure as CISO at BP. Simon provides a candid look into the immense pressures and responsibilities of overseeing cybersecurity across a massive, global organisation, highlighting the challenges of balancing work with personal well-being and family life. He discusses the emotional toll of always being “on,” the importance of transparent communication about risks, and the necessity of setting clear boundaries—what he calls “red lines”—to safeguard health and relationships. Simon also reflects on the industry-wide burnout crisis, the tendency for CISOs to prioritize work over their own needs, and the critical role of organisational support and personal maturity in sustaining a long career in cybersecurity leadership. Simon Hodgkinson is a Strategic Advisor at cybersecurity firm Semperis, and a former Chief Information Security Officer at multinational energy company BP. In his 18 year tenure at BP, Simon held several senior IT leadership roles and was responsible for the company’s cybersecurity strategy, governance, architecture, education, counter threat operations, and incident response.   During this time, he drove a significant improvement in IT operational integrity, led a transformation program and spearheaded the commitment to improve employees’ IT experience. He led the CISO function in BP Supply & Trading, where he delivered a program to improve cyber-controls, many of which have been implemented across the BP group. Before joining bp, Simon worked in IT for a dotcom, an investment bank, and commercial software companies

  40. 378

    Episode 355 Deep Dive: Sam Cummings | Will we see current LLM technology reach it's limits in 2026?

    Samuel J. Cummings III is an award-winning data scientist, keynote speaker, and renowned thought leader in AI, specializing in complex reasoning and memory architecture. In his recent work he has created AI model architecture that runs 94% less tokens than standard LLMs. As Director of Education at Gen AI Works, Sam brings over a decade of expertise in AI and runs a podcast called Gen AI Talks. In this episode, we sit down with Sam Cummings, Director of Education at Gen AI Works, as he explores the current and future landscape of large language models (LLMs) and their impact on cybersecurity. Sam unpacks the technical and economic limitations of LLMs, highlighting issues such as model cost, scalability, hallucination, and the looming challenges around reasoning and memory management. The conversation delves into the shift from universal LLMs to specialized models, the inevitability of market monopolization by big tech firms, and the environmental cost of massive data centers. Sam also paints a vivid picture of the “arms race” in the cybersecurity sector, predicting a boom in both offensive and defensive capabilities powered by AI, and offers actionable insights for professionals and entrepreneurs looking to thrive in this rapidly-evolving environment.

  41. 377

    Episode 354 Deep Dive: Lili Infante | The Growing Prevalence of Crime in the Crypto Space

    In this episode, we sit down with Lili Infante, CEO of CAT Labs, as she discusses the evolving landscape of crime in the crypto space and her work combating crypto-enabled criminal activity. Lili, drawing from her experience as a former DOJ and DEA agent who pioneered the DEA Cyber Investigations Task Force, explains the rise of crypto as both a tool for criminals and a unique opportunity for law enforcement due to its traceability. She highlights the challenges surrounding self-custody private keys, the increased risks and opportunities for asset seizure, and the emerging insider threat within law enforcement agencies handling crypto evidence. Lili also shares her perspective on regulatory debates between banks and crypto exchanges, the necessity for policy grounded in technological understanding, and the innovations CAT Labs is bringing to government agencies, including tools for key management, data scanning, and digital asset recovery. Lili Infante is the CEO and Founder of CAT Labs, a technology company helping government agencies find, seize and secure illicit cryptocurrency assets hidden in their seized evidence. As a former DEA Special Agent, she pioneered the first federal task force focused on Dark Web and crypto investigations, leading landmark cases including the takedown of Hydra Market, the world’s largest dark-web marketplace. Her work has earned national awards for cybercrime investigation and helped establish the investigative and policy frameworks now used by law-enforcement agencies worldwide.

  42. 376

    Episode 353 Deep Dive: River Nygryn | Trust, Test, Transform: Executive Playbook for AI Leadership

    In this episode, we sit down with River Nygryn, CISO and AI thought leader, as she explores the critical concepts outlined in the executive playbook for AI leadership: Trust, Test, and Transform. River provides a comprehensive overview of AI’s evolution—from its historical roots in early automated machines and neural networks to the development of large language models (LLMs) and generative assistants. She emphasizes the importance of “trust but verify” in deploying AI, warning against overreliance and the risk of diminishing critical thinking skills. River introduces the 4Ds—dull, dangerous, difficult, and dirty work—where AI delivers the greatest value, and cautions about the loss of creativity and authenticity with widespread use of AI-generated content. She encourages organizations to leverage their unique data sets, underscoring that human judgment and oversight are essential for harnessing AI’s transformative opportunities. River is a visionary cybersecurity and technology leader with a dynamic career spanning traditional banking, cutting-edge blockchain innovation, and Web3 transformation. As a Chief Information Security Officer (CISO) and fractional C-suite executive, River has driven security and operational excellence across highly regulated industries, including healthcare, financial services, and emerging tech. Renowned for bridging the gap between strategic leadership and hands-on execution, River has played a pivotal role in modernising risk and security frameworks, scaling secure systems, and advising on crypto, digital asset infrastructure, and decentralized technologies. Her influence extends beyond the boardroom – she is a powerful voice in the tech community, advocating for digital trust, innovation, and ethical leadership in the AI era. In 2025, River was named one of The CEO Magazine’s Top 50 Women of Influence, recognised not only for her technical expertise but for her commitment to shaping a more secure and inclusive digital future. She is a sought-after speaker, frequently appearing on stage at leading conferences, panels, and keynotes to share insights on cybersecurity resilience, leadership, and the evolving Web3 landscape. With a storytelling style that blends bold insights with deep reflection, River continues to inspire the next generation of cyber leaders and disruptors.

  43. 375

    Episode 352 Deep Dive: Alex Loizou | The Human Impact of a Cyber Incident

    In this episode, we sit down with Alex Loizou, Managing Director at Intrinsic Security and former CISO of Medibank, as he shares firsthand insights into the human impact of navigating a major cyber breach. Alex walks us through the initial moments of discovery, the emotional and psychological toll on teams, and the importance of staying calm under pressure. He dives into Medibank’s approach to incident response, including the use of multiple IR partners for comprehensive investigations and the challenges of coordinating large incident teams in real time. The conversation highlights the value of practical, repeated exposure to incident scenarios, the pitfalls of “ambulance chasing” in the security industry, and the vital role of transparent, evidence-based communication during sensitive events. Alex emphasizes lessons learned about organisational preparedness, collaboration across the cybersecurity community, and the importance of building strong relationships with external media and government agencies. Alex Loizou is a seasoned cybersecurity leader with a proven track record of building and leading high-performing security teams. He has extensive experience as a Chief Information Security Officer (CISO) for major organisations such as Medibank, Flybuys, and Bupa. Notably, he served as the CISO at Medibank during their 2022 cyber incident, where he played a crucial role in leading the response and recovery efforts.

  44. 374

    Episode 351 Deep Dive: Tammy Klotz | Leading with Empathy and Grace

    In this episode, we sit down with Tammy Klotz, cybersecurity and IT executive and author of Leading with Empathy and Grace, as she explores the critical role of intentional empathy in leadership. Tammy unpacks the misconception that empathy and accountability are opposites, arguing they are essential partners for building trust within teams. She discusses the impact of technology on our ability to be present, the importance of transparency during organizational challenges, and the pitfalls of viewing empathy as a “soft skill” in cybersecurity. Tammy also addresses how leaders can be more intentional in their interactions, foster stronger human connections despite remote and hybrid work environments, and why self-care is foundational for personal and professional success. Tammy Klotz is a vibrant and accomplished executive and best-selling author with over three decades of diverse experience in the manufacturing industry, specializing in cybersecurity and transformational leadership. She offers keen expertise in navigating mergers, acquisitions, and divestitures within both publicly-traded and privately-held companies and is seasoned in security, risk, and compliance leadership. Tammy brings a dynamic and positive approach to problem solving, excelling in simplifying intricate IT and cybersecurity concepts and facilitating pragmatic, non-technical dialogues that resonate with business executives. She is recognized as a strong, knowledgeable, thoughtful security executive who excels in public speaking and thought leadership, striving to empower others through knowledge sharing.  

  45. 373

    Episode 350 Deep Dive: George Barnes | Journey from the NSA to the Private Sector

    Mr. George C. Barnes is the President of Red Cell Partner’s Cyber Practice and a Partner at the firm. In this role, he oversees the pursuit of new-start incubations that are focused on cybersecurity opportunities spanning commercial and government sectors. He ensures optimized market gap responsiveness of new incubations and guides Red Cell’s platform team support as young cybersecurity companies progress through their early-stage business life cycles. As a Red Cell Partner, Mr. Barnes applies his national security and cybersecurity domain expertise to Red Cell’s incubation activities and oversees the company’s overall cyber-related investment strategy. Prior to joining Red Cell, Mr. Barnes served as the Deputy Director and senior civilian leader of the U.S. National Security Agency (NSA) from April 2017 through September 2023. In this role, Mr. Barnes served as NSA’s chief operating officer, overseeing strategy, policy, and operations.  As an agency deputy in the U.S. national security system, Mr. Barnes supported the U.S. defense and intelligence enterprise in national security strategy execution and the formulation of supporting policies.  He positioned NSA as an integrated mission partner enabling U.S. decision advantage and security against foreign threats. Over his 36-year career at the NSA, Mr. Barnes held numerous technical and organizational leadership roles spanning intelligence collection operations, intelligence target analysis, foreign liaison and industrial partnership management, workforce support, and global enterprise governance. U.S. Government Service Recognition Includes: Department of Defense Distinguished Civilian Service Medal Joint Chiefs of Staff Joint Meritorious Civilian Service Medal National Intelligence Distinguished Service Medal Under Secretary of Defense for Intelligence & Security Distinguished Service Medallion National Security Agency Distinguished Civilian Service Medal Central Intelligence Agency Seal Medal National Reconnaissance Office Medal of Distinguished Performance National Geospatial Intelligence Agency Medallion for Excellence National Intelligence Medal of Achievement Distinguished Executive Presidential Rank Award Meritorious Executive Presidential Rank Awards (2) Mr. Barnes received a Bachelor of Science in Electrical Engineering from the University of Maryland in 1986. In 2020, he was honored as a Distinguished Alumni by the University of Maryland’s College of Electrical and Computer Engineering.

  46. 372

    From 2020Partners 2025 – KB On The Go | Paul Maddison and Jeff Lindholm (Part 2)

    The 2020 Partners Dialogue sits at the edge of possibility, where security meets technological ambition. In this special bonus episode, KB explores how nations can move beyond simply consuming innovation to actively co-creating strategic dominance. Anchored by AUKUS and empowered by cross-sector collaboration, this conversation features insights from industry leaders Paul Maddison (Australia &New Zealand Country Manager, Strider Technologies) and Jeff Lindholm (Chief Revenue Officer at Lookout). Paul Maddison, Australia & New Zealand Country Manager, Strider Technologies Paul Maddison is the Australia & New Zealand Country Manager at Strider Technologies, where he is responsible for leading Strider’s market expansion and strategic partnerships with Australian universities, corporations, and governments. Prior to joining Strider, Paul worked at the University of New South Wales in Sydney and Canberra as Director of the UNSW Defence Research Institute. This was preceded by a four-year appointment as  Canada’s High Commissioner for Australia. Paul also spent over 35 years in Canadian naval service. As a surface warfare officer, he commanded at all levels culminating in his appointment as Commander of the Royal Canadian Navy at the rank of Vice Admiral. A graduate of Canada’s Royal Military College, and a dual national since 2020, Paul is from Canada but has chosen to make Australia his home. Jeff Lindholm, Chief Revenue Officer at Lookout As the Chief Revenue Officer at Lookout, Jeff oversees all aspects of the company’s global sales, including the Americas, EMEA, and APAC regions, as well as Channel Sales, Commercial Sales and Sales Engineering. He brings a wealth of experience in networking and security sales leadership, having previously served as President and CEO of Plixer, a company focused on network traffic analysis and visibility solutions. Before that, Jeff led sales operations at both Brocade and Juniper Networks. As the Senior Vice President of Worldwide Sales at Brocade, he oversaw a $2.5 billion global sales operation until the company’s acquisition by Broadcom Inc. At Juniper Networks, he served as Chief Revenue Officer, managing $2.5 billion in revenue.” He has also held significant global sales roles at Arbor Networks (the security division of NETSCOUT) and BigBand Networks. Jeff is based in Boston and holds a Bachelor of Science in Marketing from the Carroll School of Management at Boston College.

  47. 371

    From 2020Partners 2025 – KB On The Go | Neha Idnani, James Tennant, and Simon Hodgkinson (Part 1)

    The 2020 Partners Dialogue sits at the edge of possibility, where security meets technological ambition. In this special bonus episode, KB explores how nations can move beyond simply consuming innovation to actively co-creating strategic dominance. Anchored by AUKUS and empowered by cross-sector collaboration, this conversation features insights from industry leaders Neha Idnani (Regional Vice President – APAC, Eutelsat OneWeb), James Tennant (Partner – Head of JAPAC, BOKA Capital), and Simon Hodgkinson (Strategic Advisor at Semperis). Neha delves into the significance of operating one of only two global LEO satellite constellations, emphasizing how satellite networks power resilient connectivity, complement terrestrial infrastructure, and enable sovereign national capabilities amid rising geopolitical tensions. James offers a global investment perspective, highlighting how Australia and other key regions are rapidly adapting to strategic defense imperatives, the challenge of nurturing deep-tech startups, and the necessity of scaling defense technology within complex regulatory frameworks. Simon rounds out the discussion with expert insights on cybersecurity, examining the impact of economic uncertainty, increased insider risk during major corporate events and layoffs, and the criticality of robust cyber operations—even as organizations strive to balance resource constraints and work-life demands. Neha Idnani, Regional Vice President – APAC, Eutelsat OneWeb Neha Idnani is an accomplished leader in the Technology, Media, and Telecom (TMT) sector, currently serving as the Regional Vice President for APAC at Eutelsat OneWeb. With over 18 years of experience across the telecom, space, and infrastructure industries, she leads the Asia Pacific and ANZ business for Eutelsat Group, the world’s first multi-orbit satellite connectivity provider. Prior to her current role, she spent over a decade with Bharti Enterprises and Bharti Airtel, notably serving as Vice President and Chief of Staff to the Chairman’s Office. In that capacity, she managed multi-billion dollar fundraising transactions and drove significant global expansion initiatives. Beyond her corporate leadership, Neha is deeply involved in industry governance and the arts. She serves as a Board Director for OneWeb Communications India, is a Founding Member of the Indian Space Association (ISpA), and acts as a Board Trustee for Improbable, a UK-based non-profit. Academically, she holds an MBA from NMIMS, Mumbai, and a Bachelor’s in Commerce (Honours) from Shri Ram College of Commerce (SRCC), Delhi University. Throughout her career, she has remained a passionate advocate for driving the future of global connectivity through innovation and strategic collaboration. James Tennant, Partner – Head of JAPAC, BOKA Capital James Tennant is a Fellow with ASPI’s Cyber, Technology and Security Program and a Partner at BOKA Capital, a leading AUKUS Investment House in London, Sydney and New York. His key role at BOKA is complemented by his service as an Officer in the Australian Army, where he specialises in Capability Development. He is also a Senior Partner at Gilmour Space Technologies, an Australian-based rocket company innovating in the field of low-cost small satellite launch vehicles. James is a seasoned investor and corporate leader with deep interests and investments in diverse fields such as Quantum, Artificial Intelligence, Space, CyberSec, Machine Learning, Internet of Things, Drones, Enterprise Infrastructure, and Autonomous Vehicles. His professional journey, spanning across different continents and industries, uniquely positions him at the intersection of finance, defence, and technology including artificial intelligence. James holds a Bachelor of Commerce degree with a specialisation in International Business from the University of Sydney, is a Graduate of Ap...

  48. 370

    Episode 349 Deep Dive: Mike Worth | Why Legal SMBs Overlook Cybersecurity

    In this episode, we sit down with Mike Worth, Founder of Indi-tech Consultancy, as he unpacks the unique cybersecurity challenges facing small and medium-sized legal firms. Mike highlights a major misconception in the industry—treating cybersecurity solely as an IT problem rather than a broader business risk—and explains why investing in the human aspect of cybersecurity is more effective than relying on tools alone. He discusses the billable hours mindset prevalent in professional services, the opportunity cost of security training, and the importance of creating a positive, engaging, and competitive security culture tailored to staff demographics. Mike also shares insights into common pitfalls SMBs face, such as overspending on ineffective security tools, gaps in cyber insurance coverage, and the pitfalls of generic training programs. He closes with actionable advice on building a resilient cybersecurity culture, measuring progress through behaviour-based metrics, and fostering open, honest risk discussions within the organisation. Mike is a proud Londoner now living in Hampshire, UK. He has worked across various industries covering local and central Government, manufacturing and more recently 11 years of Legal professional services as an IT professional. Mike’s passion has recently seen him start his own IT consultancy targeting support for SMB’s on Cyber security & virtual IT management.

  49. 369

    Episode 348 Deep Dive: Alex Tilley | DPRK IT Workers Go Global

    In this episode, we sit down with Alex Tilley, Global Threat Research Coordinator at Okta, as he unpacks the evolving threat landscape posed by North Korean IT workers infiltrating global organizations. Alex shares insights from his recent research, emphasizing that this is not just a US big tech problem but a widespread issue affecting various industries—including healthcare, automotive, and construction—across multiple countries. He highlights the sophistication of fake applicants, their use of advanced techniques to bypass hiring filters, and the alarming success rate, even if only for short periods. The conversation explores the challenges companies face in verifying remote candidates, the necessity for ongoing identification checks, and the implementation of least privilege access for new hires. Alex Tilley is a Cyber Intelligence and investigation guy with over 25 years of experience spanning the private sector and federal law enforcement. As the Australian Federal Police’s first Senior Cybercrime Senior Technical Analyst, he specialised in unmasking and prosecuting sophisticated threat actors in global cybercrime and child protection. In his current role as Global Threat Research Coordinator at Okta, he leads law enforcement liaison efforts and drives critical threat research for the world’s leading identity company.

  50. 368

    Episode 347 Deep Dive: Rajesh Ganesan | AI Anxiety and the Global Cyber Balancing Act

    In this episode, we sit down with Rajesh Ganesan, CEO of ManageEngine, as he explores the complexities of AI anxiety within organisations and the global challenges of balancing cybersecurity, privacy, and rapid technological change. Rajesh discusses the uneven pace of AI adoption among businesses of different sizes, the critical role of regulation and capital investment by region, and the growing necessity for upskilling in an evolving digital environment. He highlights the persistent anxiety surrounding job displacement, the shift in workforce requirements, and emphasises the importance of resilience and adaptability. Rajesh concludes by stressing the need for businesses to keep customer needs at the centre and to use technology as an enabler to solve real problems in an age defined by both opportunity and uncertainty. Rajesh Ganesan is the CEO of ManageEngine, a division of Zoho Corp. and a leading provider of enterprise IT management solutions. With over two decades of experience at the company, he plays a pivotal role in shaping ManageEngine’s strategy, direction, and product management while also serving as a key evangelist for the brand. Beyond strategy, his day-to-day work involves being a mentor and coach to teams across various business functions. With deep institutional knowledge and market insight, he helps them navigate decisions with clarity and perspective, ensuring they are equipped to handle the challenges of today’s IT market.

Type above to search every episode's transcript for a word or phrase. Matches are scoped to this podcast.

Searching…

We're indexing this podcast's transcripts for the first time — this can take a minute or two. We'll show results as soon as they're ready.

No matches for "" in this podcast's transcripts.

Showing of matches

No topics indexed yet for this podcast.

Loading reviews...

ABOUT THIS SHOW

Unlike every other security podcast, we don’t get stuck down in the technical weeds. Our remit is to speak with experts around the globe at the strategic level – how security technology can improve the experience and risk optimisation for every organisation. The Voice of Cyber® - In Partnership with Vanta

HOSTED BY

KBI.Media

CATEGORIES

Frequently Asked Questions

How many episodes does KBKAST have?

KBKAST currently has 50 episodes available on PodParley. New episodes are automatically indexed when they're published to the podcast feed.

What is KBKAST about?

Unlike every other security podcast, we don’t get stuck down in the technical weeds. Our remit is to speak with experts around the globe at the strategic level – how security technology can improve the experience and risk optimisation for every organisation. The Voice of Cyber® - In Partnership...

How often does KBKAST release new episodes?

KBKAST has 50 episodes. Check the episode list to see recent publication dates and frequency.

Where can I listen to KBKAST?

You can listen to KBKAST on PodParley by clicking any episode. We provide an embedded audio player for direct listening, and you can also subscribe via your preferred podcast app using the RSS feed.

Who hosts KBKAST?

KBKAST is created and hosted by KBI.Media.
URL copied to clipboard!