PODCAST · technology
Secured by Design - IAM & Cybersecurity Podcast
by Santosh Subramanian
Great security solution are designed from the ground up..Secured by Design is a podcast where Santosh shares practical insights, frameworks, and perspectives on identity security and other aspects of cybersecurity.Each episode breaks down complex concepts into actionable ideas for professionals protecting digital identities, designing secure systems, and leading security initiatives. Because true security is built and not bolted on...
-
15
Mastering AI Security: Top 10 Risks and Mitigations for LLMs
SummaryThis episode explores the top 10 security risks associated with deploying large language models (LLMs) and AI systems. It provides practical insights and mitigation strategies to help organizations secure their AI implementations effectively.KeywordsAI security, LLM risks, prompt injection, data leakage, supply chain security, poisoning, output handling, system prompt leakage, misinformation, resource exhaustionKey topicsPrompt injection vulnerabilitiesSensitive data leakage in AI systemsSupply chain risks in AI deploymentData and model poisoning techniquesHandling AI-generated outputs securelyManaging AI agent autonomy and permissionsSystem prompt leakage and its implicationsWeaknesses in vector and embedding systemsHallucinations and misinformation in AIResource exhaustion and denial of service in AIChapters00:00 Introduction to AI Security Risks04:55 Prompt Injection: The King of Vulnerabilities11:48 Supply Chain Vulnerabilities in AI Systems18:47 Improper Output Handling and Its Risks24:59 Misinformation and Hallucination ProblemsResourcesOWASP Top 10 for Large Language Models (https://owasp.org/www-project-top-10-for-large-language-model-applications/)Let’s Stay Connected📧 Email: [email protected]🔗 LinkedIn: linkedin.com/in/kssantosh
-
14
Securing Autonomous AI: The OWASP Top 10 Risks Explored
SummaryThis episode explores the security risks associated with AI agents, focusing on the OWASP top 10 vulnerabilities and practical mitigation strategies. Learn how autonomous systems can be secured to prevent catastrophic failures and protect organizational assets.Key topicsAI agent security risksOWASP top 10 for agent applicationsMitigation strategies for autonomous systemsChapters00:00 The Nine-Second Database Incident01:42 The Growing Threat of Autonomous System Incidents02:19 Defining AI Agents and Their Architecture03:14 Understanding Policies and Human in the Loop (HITL)05:50 Agent Goal Hijacking and Prompt Injection07:14 Tool Misuse, Poisoning, and Exploitation08:53 Identity and Privilege Abuse in AI Agents09:48 Supply Chain Vulnerabilities in AI Systems11:40 Unexpected Code Execution Risks12:55 Memory and Context Poisoning14:16 Insecure Interagent Communication15:53 Cascading Failures and Uncontrolled Amplification17:22 Human Trust Exploitation and Social Engineering19:01 Rogue Agents and Goal Misalignment20:35 Five Themes for Securing AI Agents22:46 Starting Your AI Security InventoryResourcesOWASP Top 10 for Agent Tech Applications - https://owasp.org/www-project-top-ten-for-agent-tech-applications/Cloud Security Alliance Report on AI Incidents - https://cloudsecurityalliance.org/research/ai-security/Let’s Stay Connected📧 Email: [email protected]🔗 LinkedIn: linkedin.com/in/kssantosh
-
13
How Vercel's Supply Chain Attack Unfolded
SummaryThis episode dissects the recent Vercel breach, a supply chain attack involving third-party AI tools, OAuth vulnerabilities, and insider risks. It highlights practical steps organizations can take to enhance cybersecurity and prevent similar incidents.Key topicsSupply chain attack involving third-party AI toolsOAuth vulnerabilities and permissions managementBest practices for environment variable securityIncident response and credential rotation strategiesChapters00:00 The Vercel Breach: An Overview05:43 The Supply Chain Attack Unfolds12:45 The Shift in Cybersecurity Paradigms19:11 The Importance of Trust in SecurityKeywordscybersecurity, supply chain attack, OAuth, Vercal breach, AI security, cloud security, incident response, third-party risk, environment variables, credential rotationLet’s Stay Connected📧 Email: [email protected]🔗 LinkedIn: linkedin.com/in/kssantosh
-
12
The Mythos Inflection: AI and the Future of Cyber Defense
SummaryThis episode explores the groundbreaking capabilities of Anthropic's Mythos AI model, its implications for cybersecurity, and how defenders can adapt to this new threat landscape. We discuss the model's ability to autonomously identify and exploit vulnerabilities, the strategic responses from industry leaders, and the importance of critical evaluation amidst hype.Key TopicsMythos AI capabilities and evaluationsIndustry responses and strategic implicationsVulnerability discovery and management in the AI eraChapters00:00 The Changing Landscape of Cybersecurity06:38 The Power of Mythos13:18 OpenAI's Response and Different Approaches21:46 Strategic Recommendations for Organizations27:45 The Future of AI in CybersecurityResourcesAnthropic Cloud MythosGPT-5.4-Cyber by OpenAIAI Security Institute - Mythos EvaluationHeidy Khlaaf's evaluationLet’s Stay Connected📧 Email: [email protected]🔗 LinkedIn: linkedin.com/in/kssantosh
-
11
Why Identity Is The Hidden Keystone in Effective GRC Programs
SummaryThis episode explores the critical relationship between identity and access management (IDAM) and holistic Governance, Risk, and Compliance (GRC) programs. Hosted by Santosh, it delves into how integrated identity management enhances security, compliance, and organizational resilience in the digital age.Key TopicsThe connection between identity and GRCThe evolution of IDAM and its role in securityRegulatory frameworks and compliance mappingRisk management lifecycle and identity risk scoringFuture trends: Zero Trust, AI, decentralized identityChapters00:00 The Importance of GRC and IDAM Integration02:32 The Holistic Approach to GRC07:50 The GRC Challenge Landscape11:21 Defining Identity and Access Management (IDAM)15:46 How IDAM Enables Governance18:48 IDAM's Role in Risk Management22:54 IDAM and Compliance23:17 Compliance and IDAM: Meeting Regulatory Requirements27:22 Maturity Levels of IDAM Programs29:54 Common Pitfalls and How to avoid them32:42 Key Performance Indicators for GRC and IDAM35:19 The Future..37:56 Conclusion: The Central Role of Identity in GRCKeywordsIDAM, GRC, cybersecurity, identity management, compliance, risk management, zero trust, digital transformation, security architectureLet’s Stay Connected📧 Email: [email protected]🔗 LinkedIn: linkedin.com/in/kssantosh
-
10
How SCA, SAST, and DAST Protect Modern Apps (Application Security)
SummaryThis episode explores the core tools in application security - SCA, SAST, and DAST and how they form a comprehensive, shift-left security strategy to protect modern applications from vulnerabilities throughout the development lifecycle.Key TopicsShift-left security strategySCA (Software Composition Analysis)SAST (Static Application Security Testing)DAST (Dynamic Application Security Testing)Chapters00:00 Introduction to Application Security05:08 Understanding SCA: Software Composition Analysis08:22 Exploring SASD: Static Application Security Testing13:23 Diving into DAST: Dynamic Application Security Testing17:37 Integrating Security Tools for Comprehensive Protection21:31 Conclusion and Key TakeawaysKeywords#Application Security, #SCA, #SAST, #DAST, #Shift-Left Security, #Cybersecurity, #SoftwareVulnerabilities, #OpenSourceSecurity, #DevSecOps, #SecurityToolsLet’s Stay Connected📧 Email: [email protected]🔗 LinkedIn: linkedin.com/in/kssantosh
-
9
How LiteLLM Became a Weapon in a Supply Chain Attack
SummaryThis episode explores the recent security breach involving Lite LLM, a popular open-source Python library, and discusses the implications for cybersecurity in AI development. Learn how a trusted tool was exploited, the attack's mechanics, and essential security lessons for organizations.Key TopicsSupply chain attack on Lite LLMMulti-stage compromise via CI/CD pipelineMalicious package injection and persistenceLessons on dependency pinning and credential rotationThe AI tool chain as a new attack surfaceChapters00:00 The Importance of Speed and Convenience in AI Development04:16 The Attack Methodology10:08 Key Lessons Learned from the IncidentKeywordscybersecurity, AI security, supply chain attack, open source, LiteLLM, credential theft, DevSecOps, dependency management, zero trust, threat intelligenceLet’s Stay Connected📧 Email: [email protected]🔗 LinkedIn: linkedin.com/in/kssantosh
-
8
How ITDR Can Prevent the Next Major Data Breach
SummaryThis episode explores the critical importance of Identity Threat Detection and Response (ITDR) in modern cybersecurity. Hosted by Santosh, it covers how identity infrastructure is the most targeted layer in enterprises, the rise of identity-based attacks, and practical strategies to enhance security posture.Key TopicsThe rise of identity-based attacks and their impactThe three pillars of ITDR: visibility, detection, responseReal-world examples: SolarWinds, MGM, Striker attackHow AI is transforming cyber threats and defensesPractical steps to assess and improve your identity securityChapters00:00 The Reality of Data Breaches02:29 Understanding Identity Threat Detection and Response (ITDR)06:58 The Urgency of ITDR in Today's Landscape10:33 Case Study: Learning from the Striker Attack13:18 Key Takeaways for Organizations16:09 Identity as the New PerimeterKeywordscybersecurity, ITDR, identity security, data breaches, identity attacks, zero trust, cloud security, breach prevention, cybersecurity strategyLet’s Stay Connected📧 Email: [email protected]🔗 LinkedIn: linkedin.com/in/kssantosh
-
7
How Nation-States Target Critical Infrastructure: The Stryker Case Study
SummaryThis episode explores the March 2026 cyber attack on Stryker Corporation, a leading medical technology company, highlighting the attack's mechanics, motives, and lessons for organizations worldwide. Learn how nation-state actors target critical infrastructure and how to defend against such destructive threats.Key TopicsThe timeline and impact of the Stryker cyber attackThe role of nation-state actors and geopolitical motivesTechnical mechanics of the Wiper malware attackLessons learned: privilege management, network segmentation, and threat intelligencePractical cybersecurity measures for organizationsChapters00:00 The Calm Before the Storm02:28 Who are Stryker Corporation04:07 What really happened?08:36 Understanding the Attacker: Handala10:15 How did they do it? Technical breakdown14:15 Lessons Learned from the Stryker Incident17:51 Some practical best practices22:47 Closing thoughtsKeywordscybersecurity, critical infrastructure, nation-state attack, Wiper malware, privilege management, zero trust, threat intelligence, healthcare cybersecurityLet’s Stay Connected📧 Email: [email protected]🔗 LinkedIn: linkedin.com/in/kssantosh
-
6
The Day the Internet Broke: Cloudflare's Outage Explained
SummaryIn this episode of 'Secured by Design', we discuss the root cause for significant Cloudflare outage that occurred on November 18, 2025, which disrupted major internet services and highlighted the fragility of digital infrastructure. The conversation delves into the causes of the outage, its financial impact on businesses, and the lessons learned regarding cybersecurity and infrastructure reliance.Chapters00:00 The Financial Impact of the Cloudflare Outage03:40 The Role of Cloudflare in Internet Infrastructure07:16 The Technical Failure Behind the Outage09:54 Security Implications of the Outage12:00 Learnings and ConclusionsCloudflare's official explaination of the outage:https://blog.cloudflare.com/18-november-2025-outage/#Cloudflare #outage #cybersecurity #digitalinfrastructure #security #internetreliability #digitalrelianceLet’s Stay Connected📧 Email: [email protected]🔗 LinkedIn: linkedin.com/in/kssantosh
-
5
Unlocking the Future of Customer Identity Management
SummaryIn this episode of 'Secured by Design', we delve into Customer Identity and Access Management (CIAM), exploring its significance in enhancing customer experiences while ensuring security and privacy. The discussion highlights the digital experience gap, the differences between CIAM and traditional IAM, and the core concepts that underpin effective CIAM systems. We emphasizes the importance of a seamless customer journey and the future growth potential of CIAM in the digital landscape.Chapters00:00 Introduction to Customer Identity Management05:22 Understanding Customer Identity and Access Management (CIAM)12:17 Core Concepts of CIAM17:29 Enhancing Customer Journey with CIAM#CIAM, #CustomerIdentity #AccessManagement #DigitalExperience #Cybersecurity #Identity Management #BusinessGrowth #security #privacyLet’s Stay Connected📧 Email: [email protected]🔗 LinkedIn: linkedin.com/in/kssantosh
-
4
The Invisible Workforce: Understanding Non-Human Identities
SummaryIn this episode of Secured by Design, we discuss the growing prevalence of non-human identities (NHIs) in organisations, which outnumber human identities significantly. We highlight the security risks associated with NHIs, including their lack of oversight and the potential for exploitation by attackers. The conversation emphasises the need for organisations to adopt a modern playbook for managing NHIs, especially in light of the increasing integration of AI technologies. We also outline the steps necessary for effective NHI governance, including discovery, classification, and monitoring, to mitigate risks and protect sensitive data.Chapters00:00 The Rise of Non-Human Identities05:13 The Security Blind Spot of NHIs09:54 The Business Impact of NHI Compromises#Non-Human Identities #NHI #Cybersecurity #Identity Management #Digital Security #AI Risks #NHIGovernance #ZeroTrustLet’s Stay Connected📧 Email: [email protected]🔗 LinkedIn: linkedin.com/in/kssantosh
-
3
From Passwords to Passkeys: The Future of Authentication
SummaryIn this episode of 'Secured by Design', we discusses the critical shift from traditional passwords to passkeys in the realm of cybersecurity. We also highlight the alarming statistics surrounding password breaches and the vulnerabilities they present. The conversation delves into the mechanics of passkeys, their advantages over passwords, and the growing adoption of this technology across various industries. The episode emphasize the importance of transitioning to a passwordless future for enhanced security and user experience, while also addressing the challenges organizations face during this transition.Chapters00:00 The Password Crisis10:33 Introduction to Passkeys16:58 The Rise of Passkeys25:53 Real-World Adoption and Success Stories#CyberSecurity #DataBreach #Passkeys #DigitalSecurity #TechTalk #SecureYourData #IdentitySecurity #Passwordless Let’s Stay Connected📧 Email: [email protected]🔗 LinkedIn: linkedin.com/in/kssantosh
-
2
Modern Identity Governance and Administration
Summary In this episode of Secured by Design, we delve into the complexities of modern identity governance and administration (IGA). We discuss the challenges organizations face in managing access for a multitude of identities and applications, and how IGA solutions can streamline this process. To explain how a modern IGA solution does this, we follow the journey of an employee, James, from onboarding to offboarding, highlighting the importance of automated workflows, access certification, and risk management through segregation of duties. Chapters00:00 Introduction to Identity Governance04:51 The Employee Lifecycle in IGA09:47 Managing Access and Permissions15:20 Automating Deprovisioning and SecurityKeywordsidentity security, cybersecurity, secured by design, identity governance, IAM, access requests, birthright provisioning, access certification, access creep, segregation of duties, sod, iga, converged iga platformLet’s Stay Connected📧 Email: [email protected]🔗 LinkedIn: linkedin.com/in/kssantosh
-
1
What Does "Secured by Design" Really Mean?
SummaryIn this (First) episode of Secured by Design, we explore the critical role of identity in cybersecurity. We emphasise that identity should be the foundation of security, rather than an afterthought. Through real-world examples, we illustrate the risks associated with poor identity management and the benefits of adopting an identity-first approach. The conversation also highlights the cultural shift needed within organisations to prioritise identity governance and security as a means to enable business velocity and innovation.Chapters00:00 Introduction to Secured by Design01:00 Understanding 'Secured by Design'07:43 Real-World Examples of Identity Security09:36 Cultural Shift in Security Mindset11:44 The Future of Identity SecurityKeywordsidentity security, cybersecurity, secured by design, insider threats, access management, identity governance, IAM, security best practices, business velocity, digital transformationLet’s Stay Connected📧 Email: [email protected]🔗 LinkedIn: linkedin.com/in/kssantosh
We're indexing this podcast's transcripts for the first time — this can take a minute or two. We'll show results as soon as they're ready.
No matches for "" in this podcast's transcripts.
No topics indexed yet for this podcast.
Loading reviews...
ABOUT THIS SHOW
Great security solution are designed from the ground up..Secured by Design is a podcast where Santosh shares practical insights, frameworks, and perspectives on identity security and other aspects of cybersecurity.Each episode breaks down complex concepts into actionable ideas for professionals protecting digital identities, designing secure systems, and leading security initiatives. Because true security is built and not bolted on...
HOSTED BY
Santosh Subramanian
CATEGORIES
Loading similar podcasts...