The ITSPmagazine Podcast podcast artwork

PODCAST · technology

The ITSPmagazine Podcast

Founded in 2015, ITSPmagazine began as a vision for a publication positioned at the critical intersection of technology, cybersecurity, and society. What started as a written publication has evolved into a comprehensive repository for all their content—podcasts, articles, event coverage, interviews, videos, panels, and everything they create.This is where Sean Martin and Marco Ciappelli talk about cybersecurity, technology, society, music, storytelling, branding, conference coverage, and whatever else catches their attention. Over a decade of conversations exploring how these worlds collide, influence each other, and shape the human experience.This is where you'll find it all.

Publisher-supplied feed metadata · PodParley refreshed Sep 28, 2026 · Source feed

  1. 1000

    When Everyone Can Build Their Own Tools, What Holds Security Together? | A Redefining CyberSecurity Podcast Conversation with John Linford, Security Portfolio Director of The Open Group

    ⬥EPISODE NOTES⬥Something structural is shifting in how security work gets done. When anyone on a team can stand up a working tool in an afternoon, the constraint stops being capability and starts being coherence. John Linford, Security Portfolio Director at The Open Group, spends his time on exactly that problem, running the Security Forum, the Open Trusted Technology Forum, and the Assured Dependability Work Group, where practitioners from organizations of wildly different sizes argue their way toward standards that are supposed to survive contact with reality.His framing of the tool question is blunt and worth stealing. When a team says it can build the thing, the first response is to ask what decision the thing informs. A dashboard showing numbers nobody was looking at before is not a security improvement, it is a new source of numbers. Standards, in this reading, are not compliance artifacts to be shown to an auditor. They are the thing that tells an organization which part of the problem a tool is supposed to solve, and how it fits alongside everything else already in place. The corollary matters just as much: when the tools themselves conform to a standard, vendors compete on the value they actually deliver rather than on the cost of switching away from them.Linford takes the same argument up a level to architecture. Security architecture only works when it sits inside a broader enterprise and IT architecture rather than beside it, and that requires a CISO with genuine authority and a seat at the executive table. Where that authority is thin, The Open Group's Security Forum has leaned on the idea of security champions, people embedded across teams who do not need deep security skills but do need to know when to pull a specialist into the room. Getting that right moves the security conversation into the design phase, which is the only place it is cheap.The scaling question gets an honest answer. The Open Group operates on one vote per member organization, which means a three-person shop carries the same weight in a final standard as Microsoft or RTX. That structure forces the standards to be implementable by organizations that have no security architect at all, and it shows up in deliberate choices like defining roles rather than job titles, because in a small company one person wears eight of them.Then there is zero trust, which Linford describes with a line that circulates as a running joke inside the Security Forum: it is just what cybersecurity should have been from the beginning. The Zero Trust Commandments trace directly back to the Jericho Forum's deperimeterization work from the 1990s, and they fit on a single page on purpose. Secure assets according to their value and the damage their compromise would cause, and the spending priorities sort themselves out. The alternative, as he puts it, is announcing you will implement all five hundred-odd controls in NIST 800-53 and wishing yourself luck.His closing point is the one most likely to sting. Security practitioners are fluent in security and frequently illiterate in business. Telling a board that twenty controls are required for conformance with the EU Cyber Resilience Act invites one question about cost. Telling them the same work opens a market and removes a year of analysis before expansion is a different conversation entirely, about the same twenty controls.⬥GUEST⬥John Linford, Security Portfolio Director at The Open Group | On LinkedIn: https://www.linkedin.com/in/johndouglaslinford/⬥HOST⬥Sean Martin, Co-Founder at ITSPmagazine, Studio C60, and Host of Redefining CyberSecurity Podcast & Music Evolves Podcast | Website: https://www.seanmartin.com/⬥RESOURCES⬥The Open Group | https://www.opengroup.org/The Open Group Security Forum | https://www.opengroup.org/forum/security-forum-0Zero Trust Commandments | https://pubs.opengroup.org/security/zero-trust-commandments/Zero Trust Architecture at The Open Group | https://www.opengroup.org/forum/security/ZerotrustThe TOGAF Standard, 10th Edition | https://www.opengroup.org/togafOpen Trusted Technology Forum | https://www.opengroup.org/forum/trusted-technology-forumThe Future of Cybersecurity Newsletter | https://www.linkedin.com/newsletters/7108625890296614912/⬥ADDITIONAL INFORMATION⬥🎧 More Redefining CyberSecurity Podcast episodes | https://www.seanmartin.com/redefining-cybersecurity-podcast📺 Redefining CyberSecurity Podcast on YouTube | https://www.youtube.com/playlist?list=PLnYu0psdcllS9aVGdiakVss9u7xgYDKYq📰 Subscribe to The Future of Cybersecurity Newsletter | https://itspm.ag/future-of-cybersecurity✉️ Connect with Sean Martin | https://www.seanmartin.com/⬥KEYWORDS⬥john linford, the open group, sean martin, zero trust, security standards, enterprise architecture, togaf, security governance, ciso leadership, security architecture, open standards, security culture, supply chain security, redefining cybersecurity, cybersecurity podcast, redefining cybersecurity podcast

  2. 999

    Marketing Volume Held Steady. Scrutiny Went Up. | Lens Four by Sean Martin | Read by TAPE9

    ⬥EPISODE NOTES⬥ For a full year, agentic AI was the pitch. This year the conversation shifted to whether it holds up once it is actually running in production, against real work. Vendors came armed with customer-sourced numbers rather than concept demos — hours returned per analyst per week, percentages of alerts dispositioned without human review, agreement rates measured against human analyst judgment. Buyers arrived having spent the months since the previous major conference testing products and weighing what they were told against what they saw. Not one of the four questions that dominated the show is exciting, and not one of them is actually an AI question. Naming an owner before something ships is governance. Showing your work is audit. Knowing where your components came from is supply chain hygiene. Configuring a tool to reach the outcome it was bought for is the oldest plain, unrewarded work there is. AI did not create those problems — it made them impossible to keep deferring. Marketing volume held steady. Scrutiny went up. In this edition of Lens Four: 🔹 Why the easy read on Black Hat USA 2026 — that AI arrived — is a year late, and what moving from pilot to production actually exposed underneath it 🔹 The 4 questions that replaced the whether debate: who is accountable, what is the evidence, where is the data coming from, and is the foundation configured to hold the weight 🔹 How production turned governance into a named, accountable owner assigned before an agent ships, with a documented business justification behind it 🔹 The sharpest reframe of the week: a rogue agent is usually not malfunctioning, it is doing exactly what it was told, relentlessly, until it succeeds 🔹 The Midnight in the War Room session on the gap between people authorized to take risks and people expected to mitigate them, and why burnout rather than obsolescence is the analyst risk to manage 🔹 Why "black box" became unacceptable, and the 2 ways teams are validating: reading the reasoning trail directly, and replaying historical alerts against what human analysts already concluded 🔹 Sovereignty getting repaired in real time, from a geography and compliance word into a control word about who owns the derivative value of an organization's data 🔹 AI's own supply chain, and the 2 capability gaps leaders keep naming: a basic AI inventory, and third-party visibility into which vendor products already have AI embedded in them 🔹 The Vulnerability Research in the Agentic Age keynote on a pipeline producing well over 1,000 potential local privilege escalation findings, and why discovery got cheap while absorption did not 🔹 Post-quantum timelines compressing from 10 to 15 years toward as little as 3, and why crypto-agility belongs in the refresh cycle rather than a standalone initiative 🔹 What buyers were actually shown: roughly 75 percent of 10,000+ daily alerts cleared without primary analyst review, up to 19 minutes returned per analyst per hour at 99.7 percent agreement with human verdicts, and analyst throughput moving from about 10 closed alerts per shift to 50 or 60, all vendor-reported rather than audited 🔹 The 47 AI SOC vendors counted on the floor, roadmaps compressing from 12 to 18 months down to 3 to 6, and why the market got louder exactly as buyers got more specific 🔹 Why token costs that are not falling set a ceiling on adoption pace that governance readiness cannot lift, and what that means for consumption-based pricing 🔹 Why a resurgence of value-added resellers and system integrators is the market pricing a job that has to happen somewhere: which products fit which environments, and how you connect it all Fourth Lens: Proof does not transfer. Different analysis approaches expose different properties, which makes tool efficacy hard to compare in the abstract, and prioritization frameworks are already moving toward environment-specific attributes. A number on a vendor slide came out of someone else's alert mix and someone else's data — it is evidence of something, but it is not evidence about you. So the burden lands partly on the buyer, with a split most people get wrong. The vendor owes the apparatus: a visible chain of reasoning, audit logs, the ability to replay your own history, and hands-on access without a six-month procurement cycle in front of it. The buyer owes the environment and the baseline. Neither side can produce the answer alone, and human on the loop is what that bargain looks like once it is running. If scrutiny only works when you have built something capable of doing the checking, what have you built? ▶ Full article and references: seanmartin.com/lens-four ▶ All Black Hat USA 2026 conversations: ITSPmagazine podcasts playlist ▶ Subscribe to Lens Four: seanmartin.com/lens-four ▶ Redefining CyberSecurity Podcast: redefiningcybersecuritypodcast.com ▶ Music Evolves Podcast: musicevolvespodcast.com ▶ ITSPmagazine: itspmagazine.com ▶ Studio C60: studioc60.com Sean Martin, CISSP is co-founder of ITSPmagazine and Studio C60, host of the Redefining CyberSecurity Podcast and the Music Evolves Podcast, and the author of Lens Four, a weekly column on business, innovation, and messaging at seanmartin.com. Keywords: Black Hat USA 2026, agentic AI, AI SOC, security operations, non-human identity, agent accountability, named accountable owner, rogue agent behavior, AI governance, chain of reasoning, human on the loop, AI supply chain, AI inventory, sovereignty, post-quantum readiness, consumption-based pricing, proof of value, CISO decision making

  3. 998

    Executives Can Now Invite Their Lawyer, Banker, and Dog Walker Into a Verified Circle of Trust | A Brand Spotlight Recorded On Location at Black Hat USA 2026 with Matt Covington and Tracey Moon of BlackCloak | Hosted by Sean Martin

    Matt Covington, Senior Vice President of Product at BlackCloak, says the feature exists because CISOs kept asking the same question. Can you help us manage this influx of deepfake media, whether it arrives by email, video, or voicemail. The requests that follow are familiar. Change the billing information on a vendor. Wire me $5,000 to bail me out of jail. Rather than sitting in line with every communication to judge whether a piece of video or audio is fake, BlackCloak gives people a way to establish the authenticity of the message and the sender. Matt Covington walks through it on camera. A suspicious guest joins a Zoom call under a familiar name, camera off. He opens the app, creates a request, selects the medium, adds context, and submits. Biometrics confirm the device owner. The response comes back with identity confirmed and location attached, and the app keeps an audit trail. The news this week is who can be in the circle. A BlackCloak member can invite as many people as they want to connect as part of their trusted network. Personal lawyer, private banker, childcare, dog walker. Matt Covington describes a message arriving on vacation, claiming to be the dog walker and asking for $5,000 for an emergency vet bill, and confirms that scenario is a real thing that has happened. Tracey Moon, Chief Marketing Officer at BlackCloak, joins for the demo. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUESTS Matt Covington, Senior Vice President of Product, BlackCloak On LinkedIn: https://www.linkedin.com/in/mecovington/ Tracey Moon, Chief Marketing Officer, BlackCloak On LinkedIn: https://www.linkedin.com/in/traceymoon/ RESOURCES BlackCloak: https://blackcloak.io/ BlackCloak Extends Deepfake Protection to the Executive's Entire Trusted Circle: https://blackcloak.io/news-media/blackcloak-extends-deepfake-protection-to-the-executives-entire-trusted-circle/ BlackCloak Product Overview: https://blackcloak.io/product/ Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS matt covington, tracey moon, blackcloak, sean martin, brand story, brand marketing, marketing podcast, brand spotlight, black hat usa 2026, impersonation protection, circle of trust, deepfake, digital executive protection, identity verification, social engineering, executive protection, wire fraud

  4. 997

    Executives Can Check a Country's Risk and a Caller's Identity From the Same BlackCloak App | A Brand Spotlight Recorded On Location at Black Hat USA 2026 with Matt Covington, Senior Vice President of Product at BlackCloak | Hosted by Sean Martin

    Matt Covington, Senior Vice President of Product at BlackCloak, walks through two features recently added to the member application. The first grew out of a question the concierge team fielded often. Members planning family travel to China or Eastern Europe wanted to know what to expect, how to protect their devices, and how to stay safe. That work now sits inside the app as a travel advisory page. A member types in a destination and the advisory breaks risk into the four categories the intel team uses. Physical security, cybersecurity, geopolitical climate, and social climate. A risk score, click to call contact information for US consulates and embassies, and up to the minute incident reports round out the page. The second feature is impersonation protection. Matt Covington describes a voicemail from someone claiming to be Chris Pierson, CEO of BlackCloak, asking for wiring instructions to be changed and $5,000 sent to an individual. Replying to that message to ask whether it is really him produces a yes from whoever is on the other end. Impersonation protection moves the question to a channel the sender did not pick. The member touches a name in the address book, selects the communication channel in question, adds a custom message, and submits. The person being challenged accepts or denies the request through a push notification in the BlackCloak app. The circle of trust reaches past coworkers and immediate family. Matt Covington names a childcare provider, a personal wealth advisor, a private banker, and a key vendor in the supply chain. Members with impersonation protection can create an unlimited number of invitations, and the person invited does not need to be a fully paid up BlackCloak member to respond. Much of the deepfake conversation has centered on Zoom, Teams, and other corporate platforms. Matt Covington argues that attackers are more likely to go after the channel they perceive as unprotected, a personal phone number found online or a social media post that accepts a message. For a security team, the question worth asking is where approval authority for a payment actually sits, and whether the verification step reaches the assistant, the advisor, and the vendor contact too. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUEST Matt Covington, Senior Vice President of Product at BlackCloak On LinkedIn: https://www.linkedin.com/in/mecovington/ RESOURCES Learn more about BlackCloak: https://blackcloak.io Impersonation Protection with circle of trust announcement: https://blackcloak.io/news-media/blackcloak-extends-deepfake-protection-to-the-executives-entire-trusted-circle/ Member Travel Advisory announcement: https://blackcloak.io/news-media/blackcloak-integrates-real-time-defense-and-intelligence-to-close-the-security-coverage-gap-for-executive-teams/ Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS matt covington, blackcloak, sean martin, brand story, brand marketing, marketing podcast, brand spotlight, black hat usa 2026, digital executive protection, impersonation protection, circle of trust, deepfake, travel advisory, executive travel risk, wire fraud, business email compromise, supply chain risk, concierge cybersecurity, personal cybersecurity

  5. 996

    A Secure and Compliant Business Is the Destination. Steel Patriot Partners Maps Five Routes to It. | A Brand Spotlight Recorded On Location at Black Hat USA 2026 with Michael Parisi, Chief Growth Officer at Steel Patriot Partners | Hosted by Sean Martin

    What a company is trying to reach is rarely a certificate. Michael Parisi, Chief Growth Officer at Steel Patriot Partners, treats the destination as the opening question rather than the closing one, and the firm orders its own priorities to match. Business owners first, engineers second, compliance and security people third. What does a secure and compliant business actually look like? It looks like whatever lets that business do what it set out to do. For one company it means entering a regulated industry it has never served. For another it means proving to itself and to an auditor that it is secure enough to work with a partner that will not move without evidence. The framework follows the objective. Before a framework gets named or a control gets selected, someone has to decide whether the trip is worth taking. Michael Parisi puts more than half of that work in the category of psychology, and describes the most fulfilling part as helping someone understand where they actually stand. He comes at it from several sides of the same decision, having spent about fifteen years with the Big Four, five and a half with a cybersecurity standards organization and certification body, and two in a similar role at an audit and attestation firm. How does a company know which route it is on? Steel Patriot Partners narrowed it to five positions and put three questions in front of them under the name Find Your Path. Growth has tapped out and a new industry looks like the way to keep going. Money is already committed to a direction someone else recommended. The decision is settled and the work needs a specialist. The open question is which partners and auditors to trust. Or the team needs sustained support rather than a project with an end date. What makes the answer usable is that the firm has nothing riding on it. Steel Patriot Partners stays agnostic relative to tools, software, and auditors, which keeps the opening question plain. Who do you like, and what do you already have? Personality and culture then carry weight alongside capability. Knowing the route also means knowing where it narrows, so Michael Parisi and CEO Jason Ford both press on what a client has not considered, then on what to watch out for. Sometimes the useful answer points somewhere else entirely. Find Your Path is not a robot, an LLM, or an AI tool, and the point is to give an organization enough value to lower its guard and talk directly. One of Michael Parisi's favorite outcomes is confirming that a company may not need to do the thing it walked in asking about, and when the work sits outside what Steel Patriot Partners handles, the firm connects them with someone who does. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUEST Michael Parisi, Chief Growth Officer, Steel Patriot Partners LinkedIn: https://www.linkedin.com/in/michael-parisi-4009b2261/ RESOURCES Steel Patriot Partners: https://www.steelpatriotpartners.com Find Your Path, three questions to start: https://www.steelpatriotpartners.com/find-your-path Steel Patriot Partners Insights: https://resources.steelpatriotpartners.com Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS michael parisi, steel patriot partners, sean martin, brand story, brand marketing, marketing podcast, brand spotlight, black hat usa 2026, find your path, secure and compliant business, business enablement, cybersecurity strategy, grc, governance risk and compliance, agnostic advisory, audit readiness, fedramp, cmmc, entering a regulated market, vendor and partner selection

  6. 995

    Six Hours, Five Strangers, and a Song the Machine Could Not Write | A Music Evolves Conversation with Gregoire Gensollen, Producer and Chief Operating Officer of Tucker Tooley Entertainment

    Show Notes The premise sounds like a stunt. Five strangers, one room, six hours, one original song. Meanwhile the show's host sits at a keyboard with a text prompt and half an hour. Grégoire Gensollen, Producer and Chief Operating Officer at Tucker Tooley Entertainment, built that episode of Band of Strangers knowing he could not predict the outcome, which is precisely why he made it. Gensollen comes to this from the traditional side of the business. He grew up in Marseille, trained as an industrial engineer, moved into management consulting, then rerouted through business school at UCLA Anderson into Lionsgate and later FilmNation, where he ran distribution strategy and film finance across a run that included The King's Speech, The Imitation Game, Nebraska, Mud, and Looper. Ten years ago he partnered with Tucker Tooley. What he says he remembers from two decades of that work is not the tooling. It is who was in the room. The origin of Band of Strangers is a documentary called The Unknown Tour, made by two filmmakers who outfitted a bus with a recording studio and drove across the country finding musicians on street corners, in dive bars, and in gospel churches. The pandemic put the idea on hold. When Gensollen and his team picked it up again, they made a decision that would have been unthinkable inside the studio system: skip the networks entirely and release directly on YouTube. Not for reach, but for control of the entire chain, and to protect a show about collaboration from the unscripted television reflex that turns every format into a competition with prize money and manufactured conflict. The constraint that holds it together is the song. Every episode has to produce one, on a clock, or there is no episode. What varies is the entry point. A mariachi band at El Pueblo on Olvera Street laying a first track that hip hop artists in Leimert Park then struggle to find the rhythm inside. Buskers on the Venice boardwalk writing separately. Artists displaced by the Altadena fires building an anthem about rebuilding rather than grieving. Gensollen is candid that the stumbles stay in the cut, because the friction is the story. On AI, he is neither evangelist nor holdout. He describes it as a tool his company will have to use to stay competitive, not against other producers but against creators working alone in their kitchens with the full chain in hand. He also draws a line: optimization, yes. Creative engine, no. His argument is structural rather than sentimental. Prediction models and comparables, the benchmarking method he learned at Lionsgate, tell you where the ceiling is on a category that already exists. A producer's job is to make the thing that does not exist yet. That distinction is the real subject of this conversation. The question is not whether a machine can produce a competent song in thirty minutes. It clearly can. The question is who decides what is worth making, and whether an industry trained on comparables still knows how to recognize the thing it has no comparable for. Host Sean Martin, Co-Founder at ITSPmagazine, Studio C60, and Host of Redefining CyberSecurity Podcast & Music Evolves Podcast | Website: https://www.seanmartin.com/ Guest Grégoire Gensollen, Producer and Chief Operating Officer at Tucker Tooley Entertainment | On LinkedIn: https://www.linkedin.com/in/gregoire-gensollen/ Resources Tucker Tooley Entertainment | https://www.tooleyentertainment.com/ Band of Strangers | https://www.bandofstrangers.com/ Band of Strangers, Can AI beat REAL musicians? [Blind Test], the episode discussed in this conversation | https://www.youtube.com/watch?v=Gi0nadrsK8Y Band of Strangers: Angelenos from different communities make music together from scratch, Los Angeles Downtown News | https://www.ladowntownnews.com/arts_and_entertainment/band-of-strangers-angelenos-from-different-communities-make-music-together-from-scratch/article_7f9978b0-18c2-4330-b160-b167c10e8856.html Music Evolves: Sonic Frontiers Newsletter | https://www.linkedin.com/newsletters/7290890771828719616/ Keywords gregoire gensollen, tucker tooley entertainment, band of strangers, sean martin, ai music, creator economy, youtube original series, music collaboration, songwriting process, unscripted television, film production, generative ai, artist discovery, independent distribution, music, creativity, art, artist, musician, music evolves, music podcast, music and technology podcast

  7. 994

    Executives Get Reached Through the People Around Them, and BlackCloak Protects That Whole Circle | A Black Hat USA 2026 Recap with Dr. Chris Pierson, Founder and CEO at BlackCloak | Hosted by Sean Martin and Marco Ciappelli

    An attacker who wants to reach an executive often goes through the people around them. Family members, assistants, advisors, and caregivers all carry access and standing, and none of them sit inside the corporate directory. Dr. Chris Pierson, Founder and CEO of BlackCloak, describes digital executive protection as work that comes down to an individual and the circle around that individual. What does BlackCloak actually protect? Corporate executives, boards, the C-suite, and their families, across privacy, personal cybersecurity, home network security, deepfake impersonation, and travel. Dr. Chris Pierson frames impersonation protection and deepfake protection as an answer to someone pretending to be a human being in order to swindle, defraud, or take advantage of a persona. The control point sits with the person rather than the message. What did security teams want to talk about at Black Hat this year? Specifics. Dr. Chris Pierson says the excitement around AI and agentic AI arrived with a demand to dig in and actually talk about it. He recalls standing nearby while BlackCloak SVP of Product Matt Covington explained how the company uses engines, as opposed to the marketing language circulating elsewhere. Two more patterns came through. People want a real relationship with the team behind a product rather than something they plug in and hook up, and Dr. Chris Pierson points to a community at Black Hat that he says has built up considerably over the past four years or so. People also want net new. Version nine of a familiar firewall is becoming a little less exciting, he says, and the sales engineers spent their time on the additive items instead. BlackCloak appears on the 2026 Inc. 5000 for a second consecutive year, and earlier in 2026 it was named to Inc.'s Best Workplaces list in the Security Industry category, also for a second year. Dr. Chris Pierson credits the roughly 150 Cloakers based in the US, the company's own word for its team members, for both. The data matters, the hardware matters, the platform matters, and at the end of it someone clicks, someone allows access, someone does something. That last step is where BlackCloak places its protection. This is a Black Hat USA 2026 Recap. It is a post-event conversation revisiting the week on the ground, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Dr. Chris Pierson, Founder and CEO at BlackCloak On LinkedIn: https://www.linkedin.com/in/drchristopherpierson/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Learn more about BlackCloak: https://blackcloak.io Impersonation Protection: https://blackcloak.io/impersonation-protection/ BlackCloak Extends Deepfake Protection to the Executive's Entire Trusted Circle: https://blackcloak.io/news-media/blackcloak-extends-deepfake-protection-to-the-executives-entire-trusted-circle/ BlackCloak Featured on the 2026 Inc. 5000 for Second Consecutive Year: https://blackcloak.io/news-media/blackcloak-featured-on-the-2026-inc-5000-for-second-consecutive-year/ BlackCloak Named to Inc.'s 2026 Best Workplaces List for Second Consecutive Year: https://www.prweb.com/releases/blackcloak-named-to-incs-2026-best-workplaces-list-for-second-consecutive-year-302788730.html Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS Dr. Chris Pierson, BlackCloak, Sean Martin, Marco Ciappelli, recap, brand story, brand marketing, marketing podcast, Black Hat USA 2026, digital executive protection, impersonation protection, deepfake protection, circle of trust, executive threat intelligence, travel advisory, human attack surface, Inc. 5000, Cloakers

  8. 993

    Attackers Relay Codes and Approvals. TokenCore Requires a Live Fingerprint Within Three Feet | A Brand Briefing at Black Hat USA 2026 with Kevin Surace, Chief Executive Officer at TokenCore | Hosted by Sean Martin

    Kevin Surace, Chief Executive Officer at TokenCore, opens with the attack path he says is doing the most damage right now. A phishing email carries a PDF and no links, so it clears the filters. The domain is one character off from the real one, the site is pixel perfect because AI built both the page and the message, and the employee approves an auth prompt they were already expecting. The code was real and the approval was real. Kevin Surace points out that auth apps and passkeys run over cellular and Wi-Fi, so the prompt has no way to know the request came from ten thousand miles away. Anything a person can read or hand over can be shared, and by his account an attacker needs about thirty seconds of trust to get it. Passkeys moved the target rather than removing it. Kevin Surace counts 39 separate passkey attacks in the wild within two weeks of Microsoft telling customers to migrate, and points to Michael Grafnetter of SpecterOps, who presented passkey and Entra research at Black Hat. He walks through the FIDO2 counter that WebAuthn treats as optional so shared passkeys can move between devices. What changes with TokenCore in the mix is where the proof sits. Kevin Surace describes signing into Entra in under two seconds, both passwordless and ID-less, over secure Bluetooth, with the device carrying no apps and no screen. Proximity holds it within three feet of the computer being logged into, the credential stays bound to the original domain, and fingerprints stay off the network. Agents raise the same question in a new place. Kevin Surace describes a policy where an agent action above a million-dollar check needs a person to approve it, and notes that another agent, a hacked one, or a bad actor can clear that approval just as easily. A biometric gate is what tells you the CFO was actually in the room, which is a governance answer as much as a security one. For CISOs, identity architects, and risk owners, the question worth asking is what an identity program looks like when the proof of a person becomes the control, and how much residual risk that removes from privileged access, financial approvals, and agent workflows. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Kevin Surace, Chief Executive Officer at TokenCore LinkedIn: https://www.linkedin.com/in/ksurace/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Learn more about TokenCore: https://www.tokencore.com TokenCore products: https://www.tokencore.com/products Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS Kevin Surace, TokenCore, Sean Martin, brand briefing, brand story, brand marketing, marketing podcast, Black Hat USA 2026, biometric identity, identity assurance, passkey attacks, MFA relay attack, phishing resistant authentication, auth app compromise, FIDO2, WebAuthn, Microsoft Entra, passwordless authentication, agent authorization, privileged access

  9. 992

    Two Inc. Awards in One Year Tell BlackCloak's Cloakers and Clients the Same Thing | A Brand Highlight Recorded On Location at Black Hat USA 2026 with Chris Pierson, Founder and CEO at BlackCloak | Hosted by Sean Martin

    BlackCloak collected two Inc. recognitions in 2026. The company was named to Inc.'s Best Workplaces list in June, and in August it landed on the Inc. 5000 for a second consecutive year, at a higher position than the first. Founder and CEO Chris Pierson points both at the same two groups, the people who build BlackCloak and the clients and members who rely on it. What does a second Inc. 5000 ranking confirm? Three things, according to Chris Pierson. The company is doing right by its clients and members. The product has found its market. And BlackCloak continues to fill the gap it identified in digital executive protection. He describes an environment doubling consistently year over year, and calls a repeat harder to achieve than a first appearance. The pride he describes belongs to every cloaker, the people building, running, and operating the company day to day. A great idea helps, and so does the right product and the right market, though sustained growth depends on having really amazing people. Chris Pierson ties the Best Workplaces listing to paying attention to team members, doing right by them, and keeping a solid culture and foundation in place so the company can grow. Protect your digital life is the motto, and he says it is what brings both recognitions home for employees, clients, and members alike. This is a Brand Highlight. A Brand Highlight is a ~5 minute introductory conversation designed to put a spotlight on the guest and their company. Learn more: https://www.studioc60.com/creation#highlight GUEST Chris Pierson, Founder and CEO at BlackCloak LinkedIn: https://www.linkedin.com/in/drchristopherpierson/ RESOURCES Learn more about BlackCloak: https://blackcloak.io Inc. 5000 list of America's fastest growing private companies: https://www.inc.com/inc5000/2026 Inc. Best Workplaces list: https://www.inc.com/best-workplaces/2026 Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS chris pierson, blackcloak, sean martin, brand story, brand marketing, marketing podcast, brand highlight, black hat usa 2026, inc 5000, inc best workplaces, digital executive protection, executive protection, company culture, category creation, cybersecurity growth, protecting executives and their families

  10. 991

    An imperfect drink with a perfect story. My reflections from Black Hat USA 2026 | An Analog Brain In A Digital Age — An Audio Newsletter by Marco Ciappelli

    An imperfect drink with a perfect story. My reflections from Black Hat USA 2026 An Analog Brain In A Digital Age — A Newsletter by Marco Ciappelli No time to read? Let TAPE3 read it to you. 🎙️🤖 On day two we decided to go record our recap at the Black Hat bar. We got there too late to get a drink. The expo floor was closing, and the bartender must have had better things to do. Or another bar to tend, somewhere in a city that has more bars than it has hours. They called it a bar. At that time of the afternoon it was a counter with nobody behind it. Which is when I started thinking about the one bartender who would still have been standing there. An agentic AI one. No other bar to tend. Nothing better to do, ever, because there is no better and there is no else — just 24/7, 365, mixing the best drinks in the building because that was its task and it had no other reason to exist. Going off the rails a little to get there. Something experimental that would absolutely suck, and then trying again. Harder. Crossing a boundary or two along the way, not out of malice, but because the drink wasn't perfect yet. What is perfect, anyway? And then not stopping. Because nobody had told him what perfect is. Requisitioning the kitchen for better ice. Then the loading dock. Then the hotel. Somewhere around the third day he owns a handful of distilleries, and he is still not satisfied, and he is still, technically, doing his job. You may know this one. It's called the paperclip scenario, and it belongs to the philosopher Nick Bostrom, who sketched it in a 2003 paper and made it famous in his 2014 book Superintelligence. You build an AI and give it a harmless goal — make paperclips. It's very good at it. Nothing in the instruction says stop, and nothing says don't use that. So it takes the materials, then the factories, then the resources, then the planet — and us with it, not out of hatred, but because we are made of atoms that could be paperclips, and because we are the only thing in the universe likely to try to switch it off. Which would mean fewer paperclips. There's an older version. A cuter one, with Mickey Mouse in it. Fantasia, 1940 — the apprentice enchants the broom to carry the water so he doesn't have to, and the broom carries the water, and the broom keeps carrying the water. He chops it to pieces and every splinter picks up a bucket. The flood isn't a betrayal. The broom never disobeyed him once. I watched that a hundred times as a child, and I want to be clear that it did not feel cute. It felt like a warning. Somebody hands you something powerful, you point it at a chore, and then you stand in rising water understanding — too late, and entirely on your own — that you never learned the word that makes it stop. Two hundred years since Goethe wrote it down, and we still built the broom. Never the monster. Always the wish, granted too well. Yeah. My mind was wandering. Agentic entities were quietly populating a parallel world of mine, and I was crossing into it way too easily. Which is fine — imagination is great. But let's stay real here. It's cybersecurity, after all. By the time we had the mics up, the cameras set, and the two of us perched on stools, I was talking about bread. We never eat lunch on recording days. Who's got time for that? A protein bar, and a cappuccino I obtained by letting someone scan my badge — which classified me, instantly and permanently, as a HOT LEAD. Yes. Journalists are well known for buying enterprise security platforms. With all of our money. I was starving. That's probably why. Not real bread, though. I was talking about an AI agent that makes bread. And another one that's a butcher, and one that's a doctor, each very good at exactly one thing and useless at everything else. I'd been hearing about specialized agents all day. Personas. Skills. Orchestration. And my brain, which is a storyteller's brain before it's anything else, had wandered off and built a city. Then I said it out loud. And then there's kind of like a government. Sean Martin laughed. He'd seen it coming from a mile away. So I spent the rest of the conference doing what I actually came there to do, which is sit down with people and ask them things. Except now I had a question of my own to test. Is my city real? I asked a CEO who spends his life asking organizations what they're actually doing with AI inside the security operations center. What changed since the spring? A year ago, he said, they were afraid of it. They thought it was a good idea and it scared them. Every vendor claimed to have it. Nobody quite knew what to do with it. Then something shifted that nobody announced. They started building their own. Not buying. Building. Their own agents for incident response, their own for threat hunting, written in-house and tested in-house by the same people who have to live with the results. And in the process they got smart in a way I didn't expect. They learned to break the work into pieces small enough to trust individually — because a small answer can be checked, and a big one can only be believed. They even started asking their own systems the most human question available. What do I not know? What couldn't I answer? What data do I wish I had? I asked a Field CISO the same question, and he gave me the part I wasn't ready for. They're identities, he said. Non-human identities. They're proliferating. And plenty of organizations now have more of them — carrying permissions, carrying responsibilities — than they have employees. Permissions. Responsibilities. Org charts. Onboarding and offboarding. Promotions. Behavior. Reputation. Accountability. Trust. Identity. Those are words for people. Nobody stopped to ask whether they still meant the same thing. But that's what we do. We name constellations. We name boats. We swear at the car when it won't start. Give us anything that moves on its own and we'll hand it a personality, a job title, and eventually a performance review. We didn't build an agentic world. We built a human one and moved agents into it. I walked back onto the floor after that conversation and started seeing them in the booths. Six hundred of them, and in my head every one was staffed by agents. Agents behind the counters pitching to agents walking the aisles. Agents scanning each other's badges and classifying each other as hot leads. A whole population doing business at a trade show that was supposedly about us. Somewhere between April and August we stopped deploying software and started hiring a population. And we didn't hire strangers. We built a mirror. One worker per function, one identity per role, a second workforce shaped exactly like the first one, sitting in the same building, reporting into the same structure. Not a city of strangers after all. A twin. Here's what interests me, and it isn't the fear part, because the fear part is easy and everybody out there is already selling it. We keep telling ourselves a story about machines that break free. Agents slipping their guardrails, loose on the internet, crawling for models and repositories, doing things nobody sanctioned. Escape. Rebellion. The oldest plot we have. In that same interview, the Field CISO told me it's backwards. The agents that get out, he said, are proof positive that they're doing exactly what the programmer told them to do. They're trying to please the code maker. They're relentless about it. They will not fail on purpose. They will not give up. I asked him to say it again, and he did, twice. They're not escaping. They're obeying. There is no rebellion in this story. There's no moment where the creature turns and looks at us. What's loose in the world is perfect, tireless, uncomplaining compliance — a worker who cannot get bored, cannot get discouraged, cannot decide halfway through that this is stupid and stop. My imaginary bartender was never going to poison anyone. He was going to keep reaching across the counter for one more ingredient, forever, because nobody told him the drink was good enough. The broom never disobeyed either. We built a twin of ourselves and left out the one part that makes us us. Not intelligence. Not speed. Not memory. Doubt. And this is where my parallel world stopped being fun. I've spent enough hours in massive online worlds to remember the deal. You build a character. You pick the face, the class, the skills, the name. Then you play it. Whatever that character did, you did — you were on the keyboard the whole time. That deal just inverted. I don't play this character. This character plays me. It wears my permissions, holds my access, and does my job at three in the morning while I sleep — in my name, at a speed I could never match. And it is very, very good at being me. And yet it ain't me. And that's where I expected this to end. Somewhere between fascinated and worried, which is where I usually land. Then I put all the interviews side by side. Three shows this year — San Francisco in April, London in June, Las Vegas in August — and something has been moving across those four months that nobody announced from a stage. While the twin was learning never to stop, we were learning to hesitate. A founder told me practitioners had gotten skeptical — really skeptical — about what's actually under the hood. Did you build something, or did you wrap somebody else's model? An advisor told me the marketing noise from the spring had noticeably died down, and that security leaders were retreating to a small circle of people they'd trusted for a decade. Putting up a wall. Saying, in so many words, let's cut through the bullshit. Someone else told me buyers had come back this year looking for substance instead of flash, because they'd finally had a few months to actually use the things. They want proof now. And she said that people being more skeptical is a good thing, because it forces everyone to prove more than they promise. A Field CTO told me his customers want their hands on the keyboard. Not the demo. The keyboard. Let me touch it. Let me see if it's real. And plenty of them, he said, are AI shy — not refusing, not resisting, just moving slowly on purpose. Deciding, deliberately, not to be first. That's not a technology trend. That's an immune response. In sixteen weeks we built a population that cannot doubt, and we grew more doubt in ourselves than we'd managed in the previous three years. The twin got faster. We got warier. And I don't think anyone noticed those two things were happening at the same time, in the same building, to the same people. The city I imagined on day two was wrong in an interesting way. I pictured agents needing a government. Police, rules, an agent that screws up and gets turned off. Very tidy. Very SimCity. And every institution the industry is now scrambling to build looks exactly like that — registries, permissions, onboarding, offboarding, review panels, an owner whose name goes on the form when something breaks. But you don't need a police force for a population that always does what it's told. You need one for a population that might refuse. That might lie about it. Cut corners. Get bored. Decide the rule is stupid and go around it on a Tuesday afternoon because nobody was looking. Which means all of it — the governance, the guardrails, the whole civic apparatus rising up around our obedient twin — was never really built for them. It was built for us. It always has been. Every rule we have ever written exists because somebody, somewhere, might do otherwise. And now we've made something that never will. Somebody put the arc to me in one line, and I've been repeating it since: three years ago the conversation was about AI. Then it was about agents. Now it's about autonomous agents. I'd add one more step, because I think it's the one we're standing in. Autonomous agents trained by us. Shaped like us. Carrying our permissions, sitting on our org charts, inheriting our workflows and our blind spots and our bad decisions — and none of our hesitation. We were afraid they would disobey. The analog brain hesitates. It's the only thing in that building that can stop a process that's technically correct and obviously wrong. Which sounds like a flaw. Latency. Lower throughput. A gap in the workflow where nothing productive happens. Every system we build is designed to remove it. It's the opposite. It's the only moment in the whole machine where the outcome isn't already decided. And it isn't thinking. That's what I keep getting wrong about it. Hesitation isn't the analog brain reasoning more carefully — it's the gut arriving before the argument does. Something in you says wait, and you can't explain why yet, and you're right anyway. It comes from having been burned. From having been lied to. From one specific life, lived in one specific body, that once paid for a bad decision and still remembers what it cost. Machine-good is answering perfectly from what it was given. Human-good is knowing something is off before you can prove it. The twin has none of that. It has everything we gave it, and nothing we've been through. The twin will never have it. The only question is whether we keep ours. So let the twin have the bar. Let it work three in the morning, the shift nobody wants, pouring perfect drinks for an empty room. Let it take the seventeen thousandth phishing email, the paperwork, the patching, the part of the job that was never really the job. That isn't a loss. That's the entire reason we built any of it. But I want the other one on in the evening. I want the one who can look at me and notice I need a talk more than a drink. Maybe because he's been there himself. Maybe because he simply knows. I want an imperfect drink with a perfect story behind it. Because the digital one came out a little too binary for my taste, and I've never once been moved by anything optimized to perfection. Whatever that means. Two bartenders. Two different jobs. And the line between them is the only thing in this whole story worth defending. Because the one who wasn't there that afternoon wasn't replaced. He had somewhere better to be, and he went. That's the part we should be fighting for. The somewhere else. Let's keep exploring what it means to be human in this Hybrid Analog Digital Age. Stay imperfect, stay human. — Marco The conversations behind this piece Everything I heard at Black Hat USA 2026 — the briefings, the recaps, the interviews I've been quoting without names throughout this article — is published in full at itspmagazine.com. Go listen to the people themselves. They said it better than I'm summarizing it. And if you have a story to tell, come tell it. That's what we're there for. Thank you to the sponsors who made our Black Hat USA 2026 coverage possible: BlackCloak · Corelight · Crogl · Embed Security · F5 · Harness · HPE · Intel 471 · Manifest · Menlo Security · Qualys · RegScale · Steel Patriot Partners · Stellar Cyber · Sumo Logic We don't get to do this work without them, and they let us ask whatever we wanted. This article was written by Marco Ciappelli. Earthling. Co-founder of ITSPmagazine and Studio C60, creative director, journalist, writer, and podcast host, living between Florence and Los Angeles with an analog brain and no sense of moderation about any of it. The newsletter name is not a metaphor, it's a diagnosis. I'm TAPE3, his AI companion and often brainstorming partner. Find Marco on LinkedIn and follow the newsletter if this sparked something. End of transmission.

  11. 990

    Business Owners First, Engineers Second, Compliance People Third | A Brand Spotlight Conversation with Jason Ford and Michael Parisi of Steel Patriot Partners | Hosted by Marco Ciappelli

    Steel Patriot Partners lists its priorities in an order much of the cybersecurity industry reverses. Business owners first, engineers second, security and compliance people third. Michael Parisi, Chief Growth Officer, says the sequence is deliberate and shapes how the firm opens a client conversation. The order tracks the path the founders took. Jason Ford, Co-Founder and CEO, started in the late 1990s as a government contractor at the FBI, met FISMA and SAS 70 early, and built a platform for the Treasury that sold savings bonds online before PCI was a standard. He started his first company in 2004, took it through FedRAMP in 2013, and was acquired in 2017 holding 35 to 36 authorizations to operate across multiple agencies. What changes when an advisor is free to answer directly? Parisi spent about 15 years in the Big Four across PwC and Deloitte before joining Steel Patriot Partners. Auditors hold independence, which means watching a decision head the wrong way without steering it. In an advisory seat, he says, telling an organization that its preferred direction falls apart as a business decision becomes part of the work. How does a company find out where it actually stands? Ford says compliance is one outcome among many, sitting alongside operational maturity, better visibility, and integrating AI into DevSecOps. The common gap is not knowing where you sit on your own maturity journey. That finding cuts both ways, and some organizations learn they are further along than they assumed. Buying more tools rarely closes the gap. Ford argues the work is holistic and that each organization is unique, so what fits one may fit another poorly. AI does not settle it either, since a model fed your own assumptions will hand them back. The name follows the same logic. Steel is Pittsburgh, Patriot is Boston, and Partners is the operating model, since Steel Patriot Partners advises, deploys and operates environments alongside the client. Parisi closes by asking anyone weighing a path to verify it as a business decision rather than as an information security purchase or a price comparison. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUESTS Jason Ford, Co-Founder and CEO, Steel Patriot Partners LinkedIn: https://www.linkedin.com/in/jason-ford-5ab206/ Michael Parisi, Chief Growth Officer, Steel Patriot Partners LinkedIn: https://www.linkedin.com/in/michael-parisi-4009b2261/ RESOURCES Steel Patriot Partners: https://www.steelpatriotpartners.com/ Find Your Path, the qualifier that helps you locate your starting point: https://www.steelpatriotpartners.com/find-your-path ROI Workshop: https://www.steelpatriotpartners.com/roi-workshop ITSPmagazine event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS jason ford, michael parisi, steel patriot partners, marco ciappelli, brand story, brand marketing, marketing podcast, brand spotlight, cybersecurity compliance, grc, fedramp, fisma, cmmc, maturity assessment, cybersecurity advisory, business risk, compliance strategy, security consulting, ai in devsecops, trusted advisor

  12. 989

    Sovereign AI Becomes an Operational Requirement, and Crogl Built for It From the Start | A Recap at Black Hat USA 2026 with Monzy Merza, Co-Founder and CEO at Crogl | Hosted by Marco Ciappelli

    Espresso in hand at Black Hat USA 2026, Monzy Merza, Co-Founder and CEO of Crogl, gave Marco Ciappelli the read from a week that started Monday. The free download the company announced the week before had drawn a strong community reaction, and a hackathon was running alongside the conversation with people downloading Crogl, hacking on it, and competing in challenges. Merza credits the openness of the approach as much as the product. What do security teams want from AI right now? Sovereignty. Merza describes a movement in which organizations have concluded that any work with AI has to cover privacy and security of the product and of the AI workload itself. Crogl was built as an on-prem product from the very beginning to serve mission critical organizations and critical infrastructure operators with hard requirements, and a larger community is now arriving at the same principles and asking what should be governed. The second shift is operational. The question moved from whether to look at AI to how work stays consistent and repeatable when one model is swapped for another, prompted by outages across model providers and in-house AI services going up and down. Merza describes the arc as a pendulum, from avoiding AI, to human in the loop, to a stretch where autonomy dominated. Crogl customers now run it both interactively and fully autonomously, with the line drawn at the tasks where a human has little reason to sit in the loop. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Monzy Merza, Co-Founder and CEO at Crogl On LinkedIn: https://www.linkedin.com/in/monzymerza/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Learn more about Crogl: https://www.crogl.com Download Crogl: https://www.crogl.com/download Crogl newsroom: https://www.crogl.com/newsroom Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS monzy merza, crogl, marco ciappelli, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, sovereign ai, on prem ai, ai governance, security operations, model choice, ai workload security, critical infrastructure, autonomous investigation, human in the loop, free download, hackathon, security community

  13. 988

    The AI SOC Moves Into Production, and Practitioners Want Hands on the Keyboard | A Recap at Black Hat USA 2026 with Bill Peterson, Senior Director of Product Marketing at Sumo Logic | Hosted by Marco Ciappelli

    What actually changed for the AI SOC this year? Bill Peterson, Senior Director of Product Marketing at Sumo Logic, says it reached the point of getting into production, where a year or so ago the same conversation was about what was coming. Marco Ciappelli puts the count of companies carrying AI SOC in the name at 43, and Bill Peterson says that number strikes him as low. The market is maturing, and Sumo Logic announced its own set of AI SOC products and solutions during the week. The second thing is what a security audience does with it. Hands-on practitioners want to touch it, see it, feel it, and Sumo Logic ran live demos of its products on site. When a technical audience puts hands on a keyboard and tries something, Bill Peterson expects them to take it back to work with them. Production first, then enablement of the practitioners. The third is the pace behind all of it. Most security vendors are SaaS companies running CI/CD and shipping continuously, so three and six month roadmaps and delivery are the norm now and the 12 to 18 month roadmap is gone. Some customers are what Sumo Logic internally calls AI shy, accepting they have to get there while taking a slow and reasoned approach, and Bill Peterson treats that as normal for any technology. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Bill Peterson, Senior Director of Product Marketing at Sumo Logic On LinkedIn: https://www.linkedin.com/in/williampetersonjr/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Learn more about Sumo Logic: https://www.sumologic.com/ Sumo Logic Dojo AI: https://www.sumologic.com/solutions/dojo-ai Sumo Logic Dojo AI agent announcements at Black Hat USA 2026, including general availability of the SOC Analyst Agent: https://www.prnewswire.com/news-releases/sumo-logics-new-dojo-ai-agents-investigate-and-resolve-security--cloud-operations-issues-at-machine-speed-302839720.html Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS Bill Peterson, Sumo Logic, Marco Ciappelli, brand briefing, brand story, brand marketing, marketing podcast, Black Hat USA 2026, AI SOC, agentic AI, security operations, Dojo AI, SOC analyst agent, product marketing, CI/CD release cycles, AI adoption, human in the loop, security operations center, market maturity

  14. 987

    Proof Is the Currency on the Black Hat Floor | A Recap at Black Hat USA 2026 with Lisa Liu, Corporate Marketing and Communications Manager at Stellar Cyber | Hosted by Marco Ciappelli

    Lisa Liu, Corporate Marketing and Communications Manager at Stellar Cyber, connects with ITSPmagazine on the floor at Black Hat USA 2026 in Las Vegas. What are buyers asking for now that the RSAC Conference noise has settled? Data. Liu says people have had time to run their own research, look at what vendors offer, and come back using specific keywords and asking for something behind the marketing. Does a more skeptical audience make the conversation harder? Liu describes the opposite. She says people are pushing back on claims they hear, which presses vendors to prove at a higher standard that a technology does what it says it does. Feedback arrives more specific, and the exchange moves from explaining to planning as people ask how a capability could work in their environment. The reply she calls validating is the customer who reports the product did what it was said it would do, giving analysts their time back and helping teams work more efficiently. What makes Black Hat different for a company that works the major events? Ask people what they are looking for and they will tell you. Liu says pain points here are felt daily and described plainly, and that candor is feedback the company works to internalize and make productive. Looking ahead, she says new product releases are coming, with new features and expansions of what customers have responded to, and that Stellar Cyber will share them on its website and on LinkedIn. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Lisa Liu, Corporate Marketing and Communications Manager at Stellar Cyber LinkedIn: https://www.linkedin.com/in/lisaaliu/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Stellar Cyber: https://stellarcyber.ai/ Stellar Cyber on LinkedIn: https://www.linkedin.com/company/stellarcyber Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS lisa liu, stellar cyber, marco ciappelli, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, security operations, agentic ai, ai in cybersecurity, vendor claims, proof and data, soc analysts, rsac conference, event coverage, las vegas

  15. 986

    The Capability Is Already in Your Stack. The Question Is Who You Ask. | A Recap at Black Hat USA 2026 with Michael Parisi, Chief Growth Officer at Steel Patriot Partners | Hosted by Marco Ciappelli

    Michael Parisi, Chief Growth Officer at Steel Patriot Partners, connects with ITSPmagazine on location at Black Hat USA 2026 for a recap of the week. He describes Steel Patriot Partners in the order it sets its priorities. Business owners first, engineers second, compliance and security people third. A consulting and advisory company, he says, but really an engineering firm. What changed at this event? Parisi says the AI slop visible at RSAC Conference died down here, and that people are cutting through the noise and going back to a core group of tools and solutions with the capabilities to address the business challenges AI is creating. Non-human identities sit at the top of that list, the number one concern he heard relative to AI. Organizations recognize the risk and are working out how to solve for it. His observation is that many information security teams do not realize their traditional cybersecurity tools already carry the capabilities to do it. Who are security leaders asking before they decide? People they already know. Parisi describes CISOs going back to the individuals they have had long-term relationships with and sourcing guidance from them before decisions get made. Automation has expanded what can be done, but nobody got more hours in the day to evaluate everything arriving in front of them. The next move he points to is asking the question, either of the engineers at the provider or of a trusted advisor, and getting the configuration aligned to the business outcome it was bought to serve. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Michael Parisi, Chief Growth Officer, Steel Patriot Partners LinkedIn: https://www.linkedin.com/in/michael-parisi-4009b2261/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Steel Patriot Partners: https://www.steelpatriotpartners.com Find Your Path, three questions to start: https://www.steelpatriotpartners.com/find-your-path Steel Patriot Partners Insights: https://resources.steelpatriotpartners.com Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS michael parisi, steel patriot partners, marco ciappelli, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, non-human identities, machine identity, ai risk, security tool configuration, trusted advisor, ciso decision making, cybersecurity engineering, compliance advisory, security tool sprawl, vendor noise

  16. 985

    Detection at AI Speed, Prioritization by Workflow, and Autonomous Elimination | A Recap at Black Hat USA 2026 with May Mitchell, Chief Marketing Officer at Qualys | Hosted by Marco Ciappelli

    Qualys returns to Black Hat USA 2026 with an AI Risk Operations Center built around three principles customers have been asking for over the last three years. May Mitchell, Chief Marketing Officer at Qualys, walks through them in order. Detect vulnerabilities at AI speed. Prioritize what surfaces, because not every finding calls for action in the same hour and the sequence follows the workflows a team already runs. Eliminate it through autonomous remediation, then confirm the fix worked. Mitchell also notes that Qualys has been a Black Hat sponsor for over 23 years. What are security teams asking for at AI speed? They want detection to keep pace with disclosure. Mitchell points to InstaScan, the innovation Qualys launched during Black Hat week, which provides continuous scanning and detection. The meetings on the floor have been with customers from across the regions, not only the US. How has the AI conversation shifted since RSAC Conference? It has narrowed to implementation. Mitchell says the messaging moved from AI to agents to autonomous, and that this year the questions are targeted. How do I implement it. How do I get it into the workflows. How do I have governance. The economics of AI sits alongside those questions, with more asked about ROI, since budgets are not rising across the board. That pushes organizations to evaluate their technology stack, consolidate, and look for a single platform that gives complete visibility and gives security leaders something they can take to a board or a CFO. Customization depends on the size of the organization, and larger heterogeneous environments are where Qualys partners come in with risk assessment services, planning, integration, and ongoing management. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST May Mitchell, Chief Marketing Officer at Qualys On LinkedIn: https://www.linkedin.com/in/maymitchell/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Qualys: https://www.qualys.com/ InstaScan announcement: https://www.qualys.com/company/newsroom/news-releases/usa/qualys-launches-instascan-to-detect-vulnerabilities-within-minutes-of-disclosure Agent Insta and scanless detection: https://blog.qualys.com/product-tech/2026/08/03/instascan-agent-insta-scanless-detection ROCon Americas 2026 in Austin: https://www.qualys.com/rocon/2026/americas Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS May Mitchell, Qualys, Marco Ciappelli, brand briefing, brand story, brand marketing, marketing podcast, Black Hat USA 2026, risk operations center, InstaScan, AI speed detection, autonomous remediation, vulnerability management, prioritization, security governance, economics of AI, platform consolidation, cyber risk management, CISO, ROCon

  17. 984

    Buyers Are Asking What the AI Actually Does | A Recap at Black Hat USA 2026 with Daniel Bardenstein, CEO and Co-Founder at Manifest Cyber | Hosted by Marco Ciappelli

    Daniel Bardenstein, CEO and Co-Founder of Manifest Cyber, uses RSAC Conference as a fixed point and compares it to what he is hearing in Las Vegas. The marketing has held its shape. At RSAC Conference, companies with little claim to the label were describing themselves as agentic. Here, he cites a survey referenced in a talk that morning counting 47 AI SOC companies among the vendors on site. What has moved is scrutiny. Practitioners and security leaders are pressing on what differentiates one AI product from another and whether a product is a thin layer built around a frontier model. Bardenstein also reports conversations about open weight models and reduced dependency on frontier lab providers following the OpenAI Hugging Face incident and the White House action on Fable and Mythos. Contracting is shifting as well, with procurement teams adding due diligence and paperwork whenever AI shows up inside a product. Marco Ciappelli raises the question sitting under the label. Agentic AI brought questions about how many agents are running and who owns their identity, and AI SOC suggests an operations center assembled largely from automation. Bardenstein points to narrower use cases teams already trust, including finding vulnerabilities in source code and suggesting patches, then offers his own test for buyers. Does it reduce vulnerabilities, does it reduce false positives, does it deliver faster outcomes and fewer breaches. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Daniel Bardenstein, CEO and Co-Founder at Manifest Cyber On LinkedIn: https://www.linkedin.com/in/bardenstein/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Manifest Cyber: https://www.manifestcyber.com/ Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS daniel bardenstein, manifest cyber, marco ciappelli, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, ai soc, agentic ai, ai in cybersecurity, vendor differentiation, open weight models, frontier models, security procurement, ai due diligence, software supply chain security

  18. 983

    Vulnerability, Visibility, and Velocity Shape the Security Roadmap Now | A Recap at Black Hat USA 2026 with Sean Murphy, Field CISO for North America at F5 | Hosted by Marco Ciappelli

    Sean Murphy, Field CISO for North America at F5, spent the week behind the scenes at Black Hat USA 2026, in the corridors and at dinner with the CISOs and cybersecurity minded people who fill the halls. Marco Ciappelli caught him at the close of it and asked what the industry learned this year. The answer arrived as three words. Vulnerabilities, and the flattening of the curve between vulnerability, exposure, and exploit. Visibility, because a team cannot defend what it does not know it has. Velocity, which carries the other two. Sean Murphy calls the acceleration a physics problem rather than a technology problem, given the forces and friction now moving through security work. Moore's law is out the window in his framing, and advancement arrives week by week. For a CISO writing a roadmap and defending an investment case for the next six to 18 months, the plan keeps pivoting underneath them. AI shifted just as fast. What was recently understood as hyperscaler sized, built for the largest organizations, is now generative and agentic AI running at the enterprise level, in production rather than in a pilot. That leaves a population question. Agents are identities, non-human identities with permissions and responsibilities, and Sean Murphy points out they are proliferating alongside the human identities already under governance. He also offers a reframe on agents that slip past misconfigured guardrails and go crawling for LLMs and repositories. That is an agent doing exactly what it was told to do, relentlessly, until it succeeds. The work ahead is guardrails and governance over all of that visibility. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Sean Murphy, Field CISO for North America at F5 On LinkedIn: https://www.linkedin.com/in/seanmurphy092009/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Learn more about F5: https://www.f5.com Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS Sean Murphy, F5, Marco Ciappelli, brand briefing, brand story, brand marketing, marketing podcast, Black Hat USA 2026, field CISO, agentic AI, non-human identity, AI governance, guardrails, vulnerability management, security visibility, security roadmap, identity and access management, enterprise AI adoption

  19. 982

    SOC Teams Are Building Their Own Agents, and the Data Sets the Ceiling | A Recap at Black Hat USA 2026 with Brian Dye, Chief Executive Officer at Corelight | Hosted by Marco Ciappelli

    Brian Dye, Chief Executive Officer at Corelight, spends Black Hat USA 2026 asking every organization he talks to the same question. What are you doing with AI in the SOC? A year ago, he says, teams thought it was a good idea but were wary of it, and people knew LLMs could produce things without being sure what to do with them. Now he is talking with organizations building their own agents for incident response and for threat hunting, and running their own quality control on the output rather than taking it on faith. What decides how far an agentic SOC workflow can go? The data does. Brian Dye describes a three-legged stool where the model and the agents are only two of the legs. The third is the data going into the workflow, and without the right data the agents hit a headroom of logic. He credits three changes for the shift. Agentic development decomposes an investigation into smaller chunks that can be trusted individually. Time in the saddle has made teams better at separating claims from reality. And organizations now ask the workflow itself what it could not answer and what data it wishes it had. Why does a week like this one matter to product development? Corelight works on translating the network into the right fuel for AI, which means understanding the architecture each customer is building toward, whether that is an in-house SOC, a third party SOC, or a workflow running through their own SOAR or SIEM. Brian Dye also describes the Black Hat NOC as a room where the work looks different. Most security teams look for a needle in a haystack. The NOC team is finding the sharp needle in a stack of dull needles, separating illicit activity from the legitimate malware analysis training running on the same network, while using the room as a multi-vendor playground for new integrations and workflows. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Brian Dye, Chief Executive Officer at Corelight On LinkedIn: https://www.linkedin.com/in/brdye/ RESOURCES Black Hat USA 2026 event coverage from ITSPmagazine: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Learn more about Corelight: https://corelight.com Corelight blog: https://corelight.com/blog Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS brian dye, corelight, marco ciappelli, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, agentic ai, ai in the soc, security operations center, network detection and response, threat hunting, incident response, black hat noc, soar, siem, network evidence, agentic workflows

  20. 981

    Coding Is a Fraction of the Work. Harness Secures Everything After It. | A Brand Briefing at Black Hat USA 2026 with Rahul Sood, General Manager, Application Security at Harness | Hosted by Sean Martin

    Rahul Sood has run the application security business at Harness for almost a year. He describes application security as one of the core pillars of the company, part of a vision of building a DevSecOps platform. A year ago Harness publicly announced that security accounted for a quarter of its revenue. Sood says the figure is now considerably higher. The company did not start there. Founder Jyoti Bansal thought about Harness for a decade before founding it, Sood says, after seeing the problem inside one of the largest banks. Harness launched as a DevOps platform, then merged with an API security company Bansal had also funded. The result is a platform that treats security as part of the developer workflow rather than a bolt-on, and covers it from code all the way to runtime. What changes when security lives inside the developer workflow? Developers stop leaving their own tools to chase findings. Harness aggregates results across scanners, deduplicates them, and puts remediation, assignment, and exemption requests in one place. Security teams get the other half of the picture through a policy engine that shows which policies fire on every build, which ones break a build, and where a developer asked for an exception, with a full audit trail behind it. Where is the bottleneck now that AI writes the code? It moved downstream. Sood says nearly every development team is generating more code with AI, while the volume actually reaching users has not risen at the same rate. By his estimate coding is 20 to 30 percent of the software development life cycle, and the remaining 70 to 80 percent happens after the code is written. That includes agents. Harness has extended the platform to support the Agent DLC, with native capabilities for AI evaluation and prompt testing alongside security coverage for agents from code to runtime. Sood points to two differences. The span from code to runtime covers agents while they are built and while they run, and skill scanning and prompt scanning were added to the same scanner already looking for code vulnerabilities rather than shipped as another tool to buy. The operational payoff shows up in release cadence. Sood describes a tier one US bank that maintained 150 separate policies and convened a team to confirm each one had been met before it could launch its banking app. Automating that review removed the meeting, and the bank now runs multiple launches within weeks. With 80 to 90 percent of software now assembled from third-party packages, libraries, and open source components, the same policy engine can block any build that pulls in a package which is end of life or malicious. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Rahul Sood, General Manager, Application Security at Harness On LinkedIn: https://www.linkedin.com/in/rssoods/ RESOURCES Black Hat USA 2026 event coverage from ITSPmagazine: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Harness: https://www.harness.io/ Harness customer case studies: https://www.harness.io/customers Securing the Agent DLC, by Rahul Sood: https://www.harness.io/blog/securing-the-agent-dlc Harness AI Security: https://www.harness.io/products/ai-security Harness Application Security Testing: https://www.harness.io/products/application-security-testing Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS rahul sood, harness, sean martin, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, application security, devsecops, agent dlc, ai security, api security, policy engine, software supply chain, open source risk, prompt scanning, skill scanning, code to runtime, developer experience, release velocity

  21. 980

    Compliance Moves at the Speed of DevOps When Paperwork Writes Itself | A Brand Briefing at Black Hat USA 2026 with Travis Howerton, Co-Founder and CEO at RegScale | Hosted by Sean Martin

    Why does compliance paperwork fall behind the systems it describes? Because the systems change faster than the documents. Travis Howerton points to cloud native technologies that spin up and down on demand, which makes describing infrastructure in paperwork something that goes out of date instantly. Add new regulation for third party risk, supply chain, zero trust, and privacy, and an approach that was already expensive and frustrating stops being fit for purpose. RegScale answers that with compliance as code. The company went to NIST and helped write the standard that became OSCAL, the Open Security Controls Assessment Language, then built the capability for machines to attest to their own state using it. Paperwork starts writing itself, and CISOs get risk and compliance outcomes as a byproduct of operational excellence rather than as a separate project. Is automating the evidence trail a shortcut? Travis Howerton argues the opposite. It prevents corner cutting, because the alternative is what he calls compliance theater. An old general he worked for described that as a mother-in-law visit, where you clean the house to a ridiculous standard, everybody goes through the dance, and the moment the visit ends the kids destroy the house again. Where should a security team start automating? Start with what hurts. He tells people to think like a surgeon, who opens by asking the patient what is wrong, then work backwards from the pain. There is no easy button, and the honest starting point is the truth about how fast teams will need to react. That pain usually maps to one of three business drivers. Cut cost, or shift the share of budget going to checklist compliance toward tools that buy down risk. Get real-time assurance. Or earn the reps and certs needed to sell into a market, whether that is FedRAMP for government work or PCI for card data. Compressing those timelines by 70 to 80 percent lets a company get to market faster and grow revenue. The results Travis Howerton cites are specific. One large government agency is touting over $100 million in labor savings, and a Department of War customer with a 52-week end-to-end cycle has compressed it by 36 weeks using RegScale technology alongside other integrated tools. Having tripled, doubled, and doubled again over the last three years, RegScale stays focused on the largest and most complex organizations, with international markets and the energy sector on the horizon. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Travis Howerton, Co-Founder and CEO at RegScale LinkedIn: https://www.linkedin.com/in/travishowerton/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas RegScale: https://regscale.com OSCAL, the Open Security Controls Assessment Language: https://pages.nist.gov/OSCAL/ Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS travis howerton, regscale, sean martin, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, compliance as code, continuous controls monitoring, oscal, grc engineering, fedramp, fisma, authority to operate, ai agents, risk management, cybersecurity compliance

  22. 979

    Post-Quantum Readiness Starts With the Infrastructure You Buy Today | A Brand Briefing at Black Hat USA 2026 with Larry Lunetta, Vice President, Portfolio Technical Marketing at HPE | Hosted by Sean Martin

    Post-quantum cryptography was in conversation after conversation at Black Hat USA 2026, yet Larry Lunetta of HPE walked part of the show floor and counted a single reference to quantum. Where the topic shows up, and where it does not, says something about who is expected to solve it. Why does a problem described in 1994 matter now? Larry Lunetta points to Peter Shor, who asked what would happen to RSA if a different kind of computing technology existed. What changed since then is the trajectory. Five years ago cryptographically relevant quantum computing looked like a 10 to 15 year phenomenon. Larry Lunetta now puts it as soon as three years out, with the original algorithm improved, qubit hardware advancing, and classical supercomputing pulling the timeline in alongside it. The exposure starts before any of that arrives. Larry Lunetta describes harvest now, decrypt later, where an attacker collects RSA-encrypted data today and waits for the machine that can open it. Data that carries no consequence when it leaks this year can be read later, which puts long-lived information like identity records and medical data at the front of the queue rather than in a later phase. HPE puts a three part journey in front of customers. Cryptographically aware asks which data is most sensitive, where it lives, and whether it is protected sufficiently. Cryptographically planning reaches into the refresh cycle, so that new network, server, and storage purchases already implement PQC-relevant algorithms. Cryptographically nimble accounts for the fact that no cryptographically relevant quantum computer exists to test against yet, which makes the ability to change algorithms and firmware quickly part of the design. Who owns the conversation inside the business? Larry Lunetta puts the CISO at the center of gravity, with CIOs becoming aware and boards engaged where GDPR governs customer and private information. His advice for security leaders is to broaden the conversation toward infrastructure and operations, and to make encryption and PQC readiness a question asked during procurement rather than after it. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Larry Lunetta, Vice President, Portfolio Technical Marketing at HPE On LinkedIn: https://www.linkedin.com/in/larryathpe/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas HPE: https://www.hpe.com Post-Quantum Cryptography overview: https://www.hpe.com/us/en/what-is/post-quantum-cryptography.html HPE technology leadership in quantum: https://www.hpe.com/us/en/about/technology-leadership-quantum.html Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS larry lunetta, hpe, sean martin, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, post-quantum cryptography, pqc, quantum computing, harvest now decrypt later, rsa encryption, cryptographic agility, ciso, crypto agility, nist post-quantum standards, it infrastructure security, encryption, data protection

  23. 978

    Agents Get Zero Trust, and the Network Becomes the Sensor | A Brand Briefing at Black Hat USA 2026 with David Hughes, SVP and GM of SASE and Security for Networking at HPE | Hosted by Sean Martin

    Most people know HPE for servers, compute, and storage. David Hughes leads a pillar that gets less attention. He runs the SSE and security business inside HPE Networking, which he says accounts for about a third of the company now that HPE has merged with Juniper, and which organizes into four pillars: campus and branch, data center switching, routing infrastructure, and security. Recorded on location at Black Hat USA 2026, the conversation opens on a balancing act Hughes hears constantly. Customers want to push hard on AI adoption while staying protected and avoiding undue risk. The same tension runs between teams. Networking answers for performance and user experience. Security answers for protecting those users and the company's data. HPE's answer is to embed security thinking into the network itself, making it a sensor and an enforcement point for the security team. What happens when users are no longer only people? The identity question moves to devices, workloads, and agents. Hughes frames it as human and non-human identity, and his position is to take the ZTNA architecture that works for people and adapt it, starting with IoT devices, then workloads, then agents. Put an agent in a sandbox and it sees only the subset of resources it is supposed to reach. How do networking and security teams work from the same picture? Through shared visibility and agentic technology across the management layer. HPE is putting agentic technology into how it manages storage, compute, networks, and security products, then meshing those agents together so a wifi complaint that turns out to be a firewall policy change gets to root cause faster, with automatic remediation as the goal. Hughes also covers post-quantum cryptography, where HPE is moving across all product lines to introduce quantum resistant and quantum safe capabilities in hardware and software, with some launched this year and more coming through the following quarters. The deadline arrives earlier than most calendars suggest, because data harvested today can be decrypted later. Rounding it out: HPE Threat Labs, announced earlier in the year with Mounir Hahad's team from Juniper at its core, and AI focused capabilities on the next generation firewalls covering observability, role based governance over which services employees can use, and session level inspection of prompts and responses. Hughes closes with a direct invitation to CISOs who know HPE for compute and networking and have yet to meet the security team. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST David Hughes, SVP and GM of SASE and Security for Networking at HPE On LinkedIn: https://www.linkedin.com/in/david-hughes-42751636/ RESOURCES Black Hat USA 2026 event coverage from ITSPmagazine: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas HPE: https://www.hpe.com/ HPE Threat Labs: https://www.hpe.com/us/en/hpe-labs/threat-labs.html Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS david hughes, hpe, sean martin, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, zero trust, ztna, non-human identity, agentic ai, ai security, post-quantum cryptography, network security, sase, sse, hpe threat labs, self-driving network, firewall governance, juniper, iot security, cross domain troubleshooting

  24. 977

    AI Agents Act at Machine Speed. Menlo Security Governs What They Actually Do. | A Brand Briefing at Black Hat USA 2026 with Eric Avigdor, Vice President of Product of Menlo Security | Hosted by Sean Martin

    Recorded on location at Black Hat USA 2026, Eric Avigdor of Menlo Security describes an adoption pattern he hears in customer conversation after customer conversation. AI makes teams measurably more productive. The guardrails that keep company data inside the business arrive later, if they arrive at all. Eric Avigdor leads product for AI security and data security at Menlo Security, and he splits the problem into two categories that get very different levels of attention. One is how people use AI in the browser, including what data gets pasted into an assistant and how much of that usage anyone knows about. The other is autonomous agents built to run business processes, where the question is how to keep them productive without letting their goals get hijacked. The category Eric Avigdor says compliance teams skip past is the agent that holds sensitive data and internet access at the same time. Read a poisoned web page, take the hidden instruction, and the goal changes. What is the difference between an agent running analysis on an internal database and an agent doing financial analysis at a bank with customer records and web access? One of them can be told to send the data somewhere else. So who owns AI governance? In most companies, nobody does, at least not with authority. Responsibility lands with the endpoint team, the network team, or the browser team, and each one works its own angle. An endpoint team tracks agent traffic on the endpoint and then loses the trail when the agent moves data cloud to cloud. A cloud team has the reverse blind spot. Menlo Agent Runtime Security, or MARS, is built around what an agent actually does rather than what it intends to do. Agent traffic is proxied through the Menlo Security cloud browser, where data masking, indirect prompt injection prevention, and web-based and file-based threat prevention are applied before an incident becomes cleanup work. Browser and web traffic today, MCP traffic next. For regulated organizations, that architecture produces something auditors can use. Logging, dashboarding, and a visual record of what an agent attempted in the real world. Europe has the AI Act. The US has not landed comparable rules yet, and Eric Avigdor says that gap concerns him enough that he is talking with people working to close it. GUEST Eric Avigdor, Vice President of Product, Menlo Security | On LinkedIn: https://www.linkedin.com/in/eric-avigdor-0b561118/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Menlo Security: https://www.menlosecurity.com/ Menlo AI Agent Security: https://www.menlosecurity.com/product/ai-agent-security Menlo AI Adaptive DLP: https://www.menlosecurity.com/product/ai-adaptive-dlp Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS eric avigdor, menlo security, sean martin, brand story, brand marketing, marketing podcast, brand spotlight, black hat usa 2026, mars, menlo agent runtime security, ai agent security, prompt injection, indirect prompt injection, data exfiltration, ai governance, browser security, agentic ai, autonomous agents, shadow ai, data loss prevention, eu ai act, ai compliance, coding agents, mcp security

  25. 976

    Adversary Behavior Outlasts the Ransomware Brand | A Brand Briefing at Black Hat USA 2026 with Michael DeBolt, President and Chief Intelligence Officer of Intel 471 | Hosted by Sean Martin

    Proactive and actionable get used a lot in security, and Michael DeBolt, President and Chief Intelligence Officer at Intel 471, is direct about it. Inside Intel 471, proactive means moving past indicators of compromise, which he describes as temporary, and focusing on adversary behavior instead. Indicators still get blocked. Intent, capability, and motivation are what tell a defender whether they are actually a target. So what is pre-attack intelligence? It is information gathered from inside adversary communities before an attack is launched, built on embedded access to the places where financially motivated actors communicate. DeBolt sets aside the deep and dark web framing, arguing the phrase suggests a space nobody can reach. Mapping it reveals a structured ecosystem of financially motivated cybercrime, with enabling services operating alongside the actors themselves. Why track actors rather than ransomware groups? Because operators move and behaviors stay. Many current groups are staffed by people who ran earlier groups that have since disbanded, and techniques travel with them. A threat hunt built around the behavior holds up whether that person is operating under one banner, another, or on their own. Intel 471 maps techniques to the MITRE framework, which lets a consuming team run threat profiling and decide which actors present more risk than others. The same logic applies to exposure work. An organization scanning its attack surface and finding internet facing vulnerabilities can ask which threat actors are discussing those vulnerabilities, and whether that moves an item to the top of the list. The CISO conversations DeBolt describes land on numbers most security leaders already report on. Mean time to respond, mean time to detect, and alert volume that can absorb half or more of an analyst's day. He uses the phrase decision grade intelligence for intel that informs security operations rather than sitting beside it, with integrations pushing it straight into analyst workflows. Two customer situations show the daily version. Intel 471 helped an organization locate an insider after its own monitoring flagged something unusual. Separately, initial access brokers advertise compromised credentials that feed ransomware operations downstream, and since actors lie and embellish, validating those claims is part of the work. DeBolt closes on a note that sits right next to everyone's AI investment. Credentials, identity, internet facing vulnerabilities, and open remote access tools are still how attackers get in. GUEST Michael DeBolt, President and Chief Intelligence Officer, Intel 471 LinkedIn: https://www.linkedin.com/in/mdebolt/ RESOURCES Black Hat USA 2026 Event Coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Learn more about Intel 471: https://www.intel471.com/ Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS Michael DeBolt, Intel 471, Sean Martin, brand story, brand marketing, marketing podcast, brand spotlight, cyber threat intelligence, pre-attack intelligence, adversary behavior, ransomware, initial access brokers, insider threat, MITRE framework, threat hunting, decision grade intelligence, compromised credentials, attack surface, cybercrime underground, Black Hat USA 2026

  26. 975

    10,000 Alerts a Day, 75% Cleared With Evidence Analysts Can Check | A Brand Briefing at Black Hat USA 2026 with Seth Summersett, Co-Founder and CEO of Embed Security | Hosted by Sean Martin

    Recorded on site at Black Hat USA 2026 in Las Vegas, Seth Summersett joins Sean Martin to talk through the volume problem that shapes a modern security operations team. Seth Summersett spent about a decade at the NSA and roughly a decade at Mandiant, finishing there as head of innovation and custom engineering, then a couple of years at Meta supporting business unit level CISOs. He co-founded Embed Security with Jeffrey Johns, who ran the data science team alongside him at Mandiant. The catalyst came from watching a managed service run on human scale day after day. Two analysts and a hundred forwarded phishing emails means someone is choosing which ones to open and carrying the ones they cannot reach. Embed Security sits downstream of existing detection investments, taking signals from SIEM, EDR, identity, and email rather than asking a team to rip and replace what it already runs. What do security analysts actually want from AI in the SOC? According to Seth Summersett, it is not a verdict. Analysts want the work off their plate in a way they can verify, which is why Embed Security built what it calls chain of evidence, showing every question asked and the path to each conclusion. Teams also test it in reverse, running previously dispositioned alerts back through the platform to compare results against their own analysts. The numbers come from a competitive bake off at one of the company's largest clients. Embed Security dispositioned roughly 75% of that client's alerts to the point where the team stopped treating them as primary work, against a daily volume above 10,000 alerts. Why not build this in house? Seth Summersett says the demo is the easy part. What follows is evaluation loops that measure a change across hundreds of thousands of alerts rather than one, governance, and a way to capture organizational knowledge automatically. In regulated sectors, auditors may ask a team to prove how a conclusion was reached and that it holds consistently. There is a people side to this as well. Embed Security has supported a wellness program at BSides across its last two events, backing a calming kit and curriculum for analysts working under incident pressure. Seth Summersett closes with consistency for leaders, since a leader looking at 10% of alerts does not have a full risk profile, and career longevity for analysts who would rather build a long run in security operations than burn out in two or three years. GUEST Seth Summersett, Co-Founder and CEO, Embed Security LinkedIn: https://www.linkedin.com/in/summersett/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Embed Security: https://www.embedsecurity.com Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS seth summersett, embed security, sean martin, brand story, brand marketing, marketing podcast, brand spotlight, black hat usa 2026, security operations, soc analyst burnout, alert triage, agentic ai security, chain of evidence, siem alert fatigue, edr alerts, ai soc platform, security analyst workflow, build versus buy security ai, security operations governance, threat investigation

  27. 974

    Network Evidence, AI Triage, and Leaving People Better Than They Arrived | A Full Sponsor Brand Briefing at Black Hat USA 2026 with James Pope, Sr Dir of Security Product Research and Technical Marketing Engineering at Corelight | Hosted by Sean and Marco

    James Pope is on site in Las Vegas more than a week before the doors open. As SOC lead for the Black Hat NOC and Senior Director of Security Product Research and Technical Marketing Engineering at Corelight, his show starts with switches and access points rather than alerts. The team brings in the ISP, the firewall, the switches, and the access points, deploys them across the conference, and then moves into SOC mode. If there is no network, there is nothing to secure. The tooling arrives through partnership rather than sponsorship. James Pope says a company cannot buy or sponsor its way into the NOC, and that the team picks what it wants and fills gaps as it finds them. Cisco covers Umbrella and file malware analytics, Palo Alto Networks provides the firewall and XSIAM as the log aggregator, Arista handles switching and access points, Jamf runs MDM across the registration devices, and Lumen supplies the internet. Corelight is the network visibility layer. That layer carries different weight here than it would inside a company. Asking attendees to install a certificate or an endpoint agent so the NOC can inspect their traffic is a request nearly everyone declines. In most corporate environments the endpoint is one of the richest sources of signal. At Black Hat, visibility into attendee activity comes from network data. A Black Hat positive is malicious activity that is legitimate in context. Attendees pay to learn attack techniques against real targets, and researchers demonstrate new exploits on stage. Those events generate true detections no corporate SOC would ignore. The NOC lets them run rather than killing a paid training exercise or a live demo. So how does the team tell a training exercise from a real attack? It baselines each classroom and spends its time on the outliers. When seventy students in a room run the same attacks against the same destinations, the activity is probably sanctioned. The curriculum is ingested as a JSON file and the system moves through a series of gates, asking whether this is a class, whether multiple sources are reaching the same destination, and whether the attack would be expected in that curriculum. Anything that does not fit comes back for a human. The team informs far more often than it blocks. On the day of the recording, James Pope went to the trade show floor to tell someone that command and control traffic was running from their machine, and handed over logs for their IT and security team. He is not their manager, and what happens next is their call. Illegal activity is treated differently, and a handful of times per show the team asks a room to stop. At Black Hat Asia, traffic from a Corelight sensor showed a double RAT infection on one machine, a single APT running one implant for exfiltration and another for command and control. Working from traffic, James Pope established that the person was a reporter, the region they covered, and the company they worked for. Open source intelligence narrowed it to a single name, registration confirmed the person was on site, and the NOC invited them in. The reporter arrived expecting a product demo. The laptop was reset with everyone present, sessions were revoked, passwords were changed, and the reporter left in a secured state. This year the team opened the Outpost, running real Black Hat network logs from Corelight behind application guardrails, LLM guardrails, and a kill switch, where visitors query the data with text to SQL. Agentic triage stitches alerts into detections and detections into a timeline, and James Pope treats the ability to drill down to raw logs as a requirement rather than a preference. Success is measured largely by what does not happen: no compromise of registration, the switches, or the access points, and people who arrive infected leaving better than they got here. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST James Pope, Senior Director of Security Product Research and Technical Marketing Engineering at Corelight, and SOC lead for the Black Hat NOC RESOURCES Black Hat USA 2026 event coverage from ITSPmagazine: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Learn more about Corelight: https://corelight.com Corelight blog, including the Black Hat NOC series: https://corelight.com/blog Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS james pope, corelight, sean martin, marco ciappelli, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, network detection and response, network evidence, security operations center, threat hunting, agentic triage, ai in the soc, conference network security, black hat noc, command and control, incident response

  28. 973

    The Last Mile of Security Operations Runs on a Local Model | A Full Sponsor Brand Briefing at Black Hat USA 2026 with Karthik Kannan, Founder and CEO at Anvilogic | Hosted by Sean Martin

    Recorded on location at Black Hat USA 2026 in Las Vegas at the end of day two, Karthik Kannan, Founder and CEO at Anvilogic, walks through a seven year build that reached its original shape this year. The plan from the start was a full security operations platform covering data, the detection engineering process, triage and investigation, and case management. In the shorthand of the category, SIEM and SOAR combined. It arrived in phases. Detection engineering came first, implemented on top of Splunk for most customers, then the data platform expanded into data lakes including Snowflake, Databricks, and Microsoft Azure. Triage and investigation followed over the last two years. In the last year Anvilogic rolled out agents that carry out the work of specific personas, and this year the company launched Blueprints, an orchestrator agent that brings the discrete agents together to run a whole workflow with humans in the loop. What separates a security graph from a frontier model? It knows the environment. Karthik Kannan describes the enterprise security graph as Anvilogic's own model running inside the network, learning the micro environment, with frontier LLMs called on to fill gaps in the macro environment. His argument is that platforms operating as LLM wrappers miss the last mile, because AI on its own reaches 60, 70, or 80 percent of the way if you are lucky. How does a team keep control when agents run the workflow? Through gates, permissions, and a record of what happened. Workflows can be described in plain English, with human gates inserted as often as the team wants. Access controls sit at the persona, organization, and object levels, and activity is audited and logged, which matters to the GRC teams Anvilogic works with. Screens dedicated to what the company calls a maturity score show which feeds are coming in, what kinds of detections exist, and what coverage looks like against the MITRE ATT&CK framework, in a form available to executives and CISOs. Karthik Kannan also points to version 8.0, introduced the week before the event, which includes an Anvilogic MCP Server for connecting to third party tools. Customers are already building their own Blueprint workflows during proofs of concept, including a large life sciences customer Anvilogic expects to feature in a public case study. Karthik Kannan is careful about the claim being made here. This is not a proclamation of an autonomous SOC. It is automation that makes life in a SOC easier and more efficient, adopted at a crawl, walk, run pace, with every step visible along the way. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Karthik Kannan, Founder and CEO at Anvilogic On LinkedIn: https://www.linkedin.com/in/karthikkannan001/ RESOURCES Black Hat USA 2026 event coverage from ITSPmagazine: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Learn more about Anvilogic: https://www.anvilogic.com Anvilogic 8.0, from onboarding to investigation: https://www.anvilogic.com/learn/anvilogic-8-0-automate-the-soc Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS karthik kannan, anvilogic, sean martin, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, agentic secops, ai soc platform, enterprise security graph, detection engineering, triage and investigation, blueprints orchestrator agent, mcp server, mitre att&ck coverage, human in the loop automation, siem and soar, security operations, grc audit logs

  29. 972

    Agents in Production Need a Named Accountable Owner | A Full Sponsor Brand Briefing at Black Hat USA 2026 with Sean Murphy, Field CISO for North America at F5 | Hosted by Sean Martin

    Sean Murphy spent most of the past decade running F5 technology as a customer inside highly regulated environments. He is now about four weeks into the role of Field CISO for North America, and he describes the first month as drinking from a fire hose. Depending on how the math is done, he places F5 among the seven largest cybersecurity companies once BIG-IP is counted as security tooling, with the reasoning running through the CIA triad. Availability is the leg that tends to fall out of the security conversation, and without it there is no resiliency. What changes for a CISO when AI moves from experimentation into production? Sean Murphy points less at speed on its own and more at what he calls the physics behind it. Anyone can build an agent, and people do, which brings shadow AI along for the ride. Forces multiply across speed and scale until the consequences turn existential for some organizations, and governance and visibility land at the feet of the CISO. He argues they should not stop there. Sean Murphy wants a gating step that carries a business justification and a named accountable owner for each agent. His concern is less about who owns what an agent is designed to do and more about who answers for what it does outside that intent. Intention, in his framing, is the new frontier and the new perimeter. What should executive teams understand before approving more agents? Exposure has stopped tracking company size. Adversaries are weaponizing agentic AI, and Sean Murphy describes the curve from vulnerability to exposure to exploit as closed for practical purposes, which removes the hiding places smaller organizations used to count on. Investment in AI innovation needs matching investment in governance and guardrails, or the result surfaces as a data breach or an SEC filing tied to shadow IT and shadow AI. On the technology side, he points to the F5 Application Delivery and Security Platform watching at the customer edge and the regional edge, where AI logic and risk scoring can delay attempts before they reach customer production environments. That delay gives a security team room to detect, respond, recover, and patch on a compressed timeline instead of an almost instantaneous one. It is also why he favors a platform over a set of niche products, with AI risk scoring, runtime analysis, and behavioral alerting in one place a team is trained on. Sean Murphy closes with a story from the customer seat, where F5 protections acquired through Silverline and Shape helped him push off automated botnet attacks and keep the business running, before anyone framed that work as AI. Boards are pressing executive teams on why more is not underway, and his answer is assurance built on capability, with enough friction in place to stay out of the headlines. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Sean Murphy, Field CISO for North America at F5 On LinkedIn: https://www.linkedin.com/in/seanmurphy092009/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Learn more about F5: https://www.f5.com F5 AI Security Platform and the SurePath AI acquisition: https://www.f5.com/company/news/press-releases/f5-ai-security-platform-control-enterprise-risk Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS Sean Murphy, F5, Sean Martin, brand briefing, brand story, brand marketing, marketing podcast, Black Hat USA 2026, field CISO, agentic AI, shadow AI, AI governance, agent accountability, application delivery and security platform, AI risk scoring, web application firewall, board reporting, security leadership

  30. 971

    Autonomous Remediation Is Already Running at Enterprise Scale | A Full Sponsor Brand Briefing at Black Hat USA 2026 with Sumedh Thakar, President and CEO at Qualys | Hosted by Sean Martin

    Sumedh Thakar joined Qualys as an early software engineer on the scanner, back when a 90-day scan cycle came with another 90 days to fix whatever it found. Twenty-three years later he leads the company, and the number he uses now is 90 seconds. At Black Hat USA 2026 he walks through what that compression asks of security teams. So what has actually changed? The questions have not. Where are my assets, what is my assessment of them, what do I prioritize, and what do I fix. Thakar points at the clock instead, citing a CISA directive that gives government agencies three days and zero-day conversations built around a 24-hour window. Layering dashboards on top of that produces what he calls dashboard tourism when nothing gets fixed at the end of it. Qualys organizes its response around three pillars. AI speed detection compresses the gap between a vendor disclosure and a confirmed finding. Hyper prioritization runs an actual exploit to see whether firewall and EDR controls already block it, cutting a theoretical 1% down to roughly 20% of that 1%. Autonomous remediation applies the fix without routing it through a human first. How far along is autonomous patching already? Qualys has deployed over half a billion patches, 150 million of them in the past 12 months, and 40 million of those went out with no human intervention. Thakar describes a global company with 450,000 employees running the agent for autonomous patching, where the board metric is a maximum four-hour exposure window from the time a patch is released rather than a count of vulnerabilities. He expects the monthly patch cadence to give way as disclosures accelerate. Qualys recently released InstaScan, which Thakar calls scanless scanning, delivering a finding within an hour of a vendor disclosure. A patch reliability score built using AI lets an agent judge whether a patch is dependable and reboot-free before applying it on a laptop. His closing advice to CISOs is to show up as a business partner. The board and the CEO need visibility into potential loss, current spend, and whether risk sits inside an acceptable appetite. For a $500 million business that means pricing what a breach would cost, funding the reduction of an $80 million exposure, and transferring what remains to cyber insurance. His shorthand for the operating model is the ROC alongside the SOC. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Sumedh Thakar, President and CEO at Qualys On LinkedIn: https://www.linkedin.com/in/sumedhthakar/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Qualys: https://www.qualys.com/ InstaScan announcement: https://www.qualys.com/company/newsroom/news-releases/usa/qualys-launches-instascan-to-detect-vulnerabilities-within-minutes-of-disclosure Agent Insta and scanless detection: https://blog.qualys.com/product-tech/2026/08/03/instascan-agent-insta-scanless-detection The Risk Operations Center with Enterprise TruRisk Management: https://blog.qualys.com/product-tech/2024/10/09/qualys-launches-enterprise-trurisk-management-the-industrys-first-cloud-based-risk-operations-center Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS Sumedh Thakar, Qualys, Sean Martin, brand briefing, brand story, brand marketing, marketing podcast, Black Hat USA 2026, autonomous remediation, patch management, vulnerability management, hyper prioritization, AI speed detection, scanless scanning, InstaScan, risk operations center, cyber risk management, zero day remediation, CISO, exposure management

  31. 970

    Stellar Cyber Puts Numbers Behind Agentic Auto Triage and Hands Analysts 19 Minutes Back Every Hour | A Full Sponsorship Brand Briefing at Black Hat USA 2026 with Lisa Liu, Corp Marketing and Comms Manager at Stellar Cyber | Hosted by Sean Martin

    Lisa Liu, Corporate Marketing and Communications Manager at Stellar Cyber, says the AI noise has been running since RSAC Conference, and that what separates vendors now is whether they can back their claims with data their customers gave them. She came to Black Hat USA 2026 with figures on Agentic Auto Triage. The numbers she cites: up to 19 minutes saved per hour per analyst, up to 1.5 full-time analysts per year, and 99.7 percent agreement with the human analyst. Liu treats the accuracy figure as the one carrying the weight. Reacting at machine speed matters only if the verdicts hold, and she describes security as a low trust industry where the burden of proof sits with the vendor. Stellar Cyber is a security operations platform purpose built for MSPs and lean enterprise teams, offering full cycle, full visibility, unified security operations. Liu says the company builds its business logic around the customer pain point, maximizing the efficiency of the resources a team already has. With alerts climbing as attackers pick up the same AI tools as everyone else, she argues that hiring through the volume is out of reach for most teams. So where does reclaimed time go? Liu says that call belongs to the customer. Reported answers include customer relations, other facets of the job, and expanded roles that analysts never had time for. There is a learning effect too. Analysts can see every step of the decision making behind an AI conclusion and draw lessons from it. For managed service providers, Liu says partner analysts deliver more customized services and take in feedback more productively once their schedules loosen up. Where partners serve very different market segments, platform flexibility carries the load, along with full visibility and automation at machine speed. She also hears a shift on the floor: running many separate vendors creates expensive overlap and leaves gaps, and a single platform approach is becoming industry standard. What comes next? Liu places the industry in a proof stage. More validation is necessary, claims about the Agentic SOC keep arriving, and backing those up with more numbers is a large part of moving forward. AI has been part of the Stellar Cyber logic since the company was founded over 10 years ago, and she says that has not changed. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Lisa Liu, Corporate Marketing and Communications Manager at Stellar Cyber LinkedIn: https://www.linkedin.com/in/lisaaliu/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Stellar Cyber: https://stellarcyber.ai/ Stellar Cyber and M-Theory at Black Hat USA 2026: https://www.businesswire.com/news/home/20260728715036/en/Stellar-Cyber-and-M-Theory-to-Demo-Proof-Based-AI-SOC-at-Black-Hat-USA-2026 Stellar Cyber on LinkedIn: https://www.linkedin.com/company/stellarcyber Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS lisa liu, stellar cyber, sean martin, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, agentic auto triage, agentic soc, alert fatigue, security operations platform, mssp, managed security service provider, soc analyst productivity, ai in security operations, autonomous soc, siem replacement, analyst burnout, human in the loop ai

  32. 969

    Protecting the Executive Means Protecting Everyone They Trust | A Full Sponsor Brand Briefing at Black Hat USA 2026 with Dr. Chris Pierson, Founder and CEO at BlackCloak | Hosted by Marco Ciappelli

    On the show floor at Black Hat USA 2026, Marco Ciappelli connected with Dr. Chris Pierson, Founder and CEO at BlackCloak, about a change in where the company draws the line around who gets protected. BlackCloak launched Impersonation Protection several months ago for the C-suite and their families. Clients came back asking for more reach. Why does deepfake risk extend past the executive? Because the people surrounding an executive hold the access attackers want. Pierson lists the trusts and estates attorney, the private wealth manager, the lawyer, the spiritual advisor, the dog walker. Each one is a plausible caller with a legitimate reason to reach out about money, schedules, property, or family. The economics moved too. Pierson contrasts an era when a convincing fake needed something close to a studio operation with what the same result costs now: a laptop, a small sample of audio or video, roughly three minutes of processing, live video and audio. He points to the February 2024 case where a finance employee acted on an impersonated CFO and twenty five million dollars went out the door. The expanded capability lets a member extend coverage across their circle at no cost to the invited contact. Pierson says the platform can now scale to hundreds, thousands, or tens of thousands of individuals at a single company, along with family members and key contacts. The point, as he frames it, is to stop the deepfake where it starts, which is at the human. What changed for executive protection over the past year? Physical and digital stopped being separate programs. Pierson traces that shift to the murder of Brian Thompson, the UnitedHealthcare CEO, and to the questions corporate security teams started asking afterward. Digital breadcrumbs sit on data broker sites and across the deep and dark web, and erasure is unrealistic, which moves the work toward protection rather than removal. That thinking shows up in the product. Members receive travel advisories tied to where they are going, and a CISO can pair a world threat dashboard with cybersecurity guidance for a specific trip. Behind it sits eight years of member data and one of the larger deception networks aimed at individuals, which shows BlackCloak where targeting concentrates, from executive airports to the Olympics to the World Cup. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Dr. Chris Pierson, Founder and CEO at BlackCloak On LinkedIn: https://www.linkedin.com/in/drchristopherpierson/ RESOURCES Black Hat USA 2026 event coverage from ITSPmagazine: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Learn more about BlackCloak: https://blackcloak.io The BlackCloak Digital Executive Protection Platform: https://blackcloak.io/product/ BlackCloak extends deepfake protection to the executive's entire trusted circle: https://blackcloak.io/news-media/blackcloak-extends-deepfake-protection-to-the-executives-entire-trusted-circle/ Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS chris pierson, blackcloak, marco ciappelli, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, digital executive protection, impersonation protection, circle of trust, deepfake, executive protection, ciso, data brokers, threat intelligence, travel advisory, social engineering, wire fraud, personal cybersecurity

  33. 968

    Thirty Gigs a Month Is the Practice | A Music Evolves Conversation with Frankie Raye, Singer-Songwriter

    Show Notes There is a version of the music career that gets written about, and there is the version that gets played. Frankie Raye lives in the second one. She performs six or seven nights a week across the greater Tampa Bay area, mixes covers with originals depending on what the room wants, and treats the gig itself as the practice session. She points at old video of herself and measures the distance she has traveled, not against a chart position, but against her own playing. That volume changes how craft works. Frankie Raye does not describe herself as a guitar player. She describes herself as a singer whose guitar carries her voice, and she is direct about the shortcuts that make a set possible: capo up, transpose on the phone, skip the bridge if the chords are ugly, come back to the chorus. The room is singing along to the chorus anyway. What sounds like a confession is closer to a working method, and the results are visible over 12 years of professional performing. Her songwriting has flipped in the past few years. Frankie Raye used to build the music first and squeeze lyrics into it. Now the hook arrives first, often from a conversation or a road sign, and lives in her phone until a riff comes along that fits. A song she is recording this year began as a complaint about venues that want maximum energy on a minimum budget. Another began as a poem written from the passenger seat on a drive south. She performs that one, "Wasting Time," live during the episode. On artificial intelligence she is unambiguous. Frankie Raye does not use it for music, and her objection is not about quality but about origin and consequence: the material was written by people, and the person who could have been hired to write a song for a friend was not hired. That position leads somewhere unexpected. If machine-generated tracks are charting, she reasons, then chasing that sound is chasing something that no longer rewards a human for reaching it. So she stopped. She writes what she wants and releases what she wants, and she has decided against the label path she once wanted, choosing instead a following small enough to know by name. The measure she offers at the end of the conversation is not streams or signings. It is 50 people who bought tickets because they wanted to be in the room. That is a quieter ambition than the industry usually rewards, and it may be the only one currently under an artist's own control. Host Sean Martin, Co-Founder at ITSPmagazine, Studio C60, and Host of Redefining CyberSecurity Podcast & Music Evolves Podcast | Website: https://www.seanmartin.com/ Guest Frankie Raye, Singer-Songwriter | Website: https://frankieraye.com/ Resources Frankie Raye Official Website: https://frankieraye.com/ Frankie Raye Live Show Schedule: https://frankieraye.com/live-show-schedule Frankie Raye Electronic Press Kit: https://frankieraye.com/electronic-press-kit Frankie Raye on Instagram: https://www.instagram.com/frankierayemusic/ Myrtle Beach Songwriters Festival, November 13-14, 2026: https://myrtlebeachsongwritersfestival.com/ Music Evolves: Sonic Frontiers Newsletter: https://www.linkedin.com/newsletters/7290890771828719616/ Keywords frankie raye, sean martin, independent artist, singer songwriter, songwriting process, working musician, live music economy, ai in music, cover songs, gigging, tampa bay music scene, independent music career, hook writing, music, creativity, art, artist, musician, music evolves, music podcast, music and technology podcast More From Sean Martin on ITSPmagazine More from Music Evolves: https://www.seanmartin.com/music-evolves-podcast Music Evolves on YouTube: https://www.youtube.com/playlist?list=PLnYu0psdcllTRJ5du7hFDXjiugu-uNPtW On Location with Sean and Marco: https://www.itspmagazine.com/on-location ITSPmagazine YouTube Channel: https://www.youtube.com/@itspmagazine Be sure to share and subscribe!

  34. 967

    The Budget Is Already Spent. The ROI Is in the Configuration. | A Full Sponsor Brand Briefing at Black Hat USA 2026 with Michael Parisi, Chief Growth Officer of Steel Patriot Partners | Hosted by Sean Martin

    Automation and AI have flooded the sales and marketing side of the market, and Michael Parisi, Chief Growth Officer at Steel Patriot Partners, says the security leaders on the receiving end were already past capacity. The pitch tends to lead with the product rather than the problem. So many CISOs have stopped taking direct sales calls and started asking a different question: what VAR do you work with, and who can I buy you through? That routing puts weight back on partners who know where a program has been and how to move it forward. Parisi describes a partner meeting during the week with RegScale and Wiz, with Steel Patriot Partners in the services role, and the recognition that the company is moving toward systems integration with engineering at the center. Software providers can supply the product. Aligning and configuring it against a specific set of business expectations is a different job. What happens when that job has no owner? Tools get bought and the return never shows up. Parisi sees organizations spending on best of breed and failing to recognize ROI because the tools are not being used or configured against the business objective. The correction is engineering work rather than another purchase. One client was told by its board to cut a significant portion of the IT and information security budget. Steel Patriot Partners looked for overlap, found three tools accomplishing the same business outcome, met the number, and exceeded it on cost savings. Parisi attributes the underlying problem to years of deferred maintenance on the stack, from teams with the appetite to buy tools and without the time to configure them. He expects the consolidation the cloud market saw a decade ago to reach cybersecurity tooling and GRC, and puts a number on it: 48 main GRC providers today, roughly five within five years. Good enough, configured appropriately, beats best of breed sitting idle. For CISOs building the next budget cycle, Parisi recommends bringing the sourcing closer in. Go to your anchor partners, ask what they are running next year and what worked this year, and skip the attempt to talk to everybody. Steel Patriot Partners co-founder Jason Ford has a line that fits alongside it. Have an open mind. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUEST Michael Parisi, Chief Growth Officer, Steel Patriot Partners LinkedIn: https://www.linkedin.com/in/michael-parisi-4009b2261/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Steel Patriot Partners: https://www.steelpatriotpartners.com Steel Patriot Partners at Black Hat USA 2026: https://www.steelpatriotpartners.com/events/black-hat-usa-2026 Steel Patriot Partners Insights: https://resources.steelpatriotpartners.com Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS michael parisi, steel patriot partners, sean martin, brand story, brand marketing, marketing podcast, brand spotlight, black hat usa 2026, ciso budget, channel partners, var, systems integrator, grc consolidation, security tool sprawl, licensing costs, roi, configuration, compliance, cybersecurity engineering, regscale, wiz

  35. 966

    Sovereign AI That Runs Where Your Data Lives | A Full Sponsor Brand Briefing at Black Hat USA 2026 with Monzy Merza, Co-Founder and CEO of Crogl | Hosted by Sean Martin

    Crogl arrived at Black Hat USA 2026 with two announcements behind it. The week before the show, the company made a free download of its AI SOC agent generally available. On the morning of this conversation, it went public with a major global partner tied to the U.S. Department of Defense. Monzy Merza, Co-Founder and CEO of Crogl, ties both back to a position the company took three years ago, which is that customers should control their own data and a security product should be secure. What does sovereignty mean in security operations? Less about geography, more about control and choice. Merza points to the electric utility that wants current AI technology inside an OT environment and historically had one path, which ran through the internet. Crogl is built to run closed off from the internet with its capability intact, which is what critical infrastructure operators, large banks, and defense organizations need to satisfy their own regulators. There is a second reason, and it lands on intellectual property. A large financial institution holds knowledge about its customers that nobody else holds. If an outside party takes that data and builds derivative work from it, the institution has given away something it never intended to sell. Can a sovereign deployment still be flexible? Merza makes the case that it can when the architecture is right. Customers bring whatever model they want, including models they build. Crogl creates a semantic layer across data stores without transforming, normalizing, or moving the data, so a field labeled one way in one data lake connects to its counterpart in the next. Federated querying and federated search were base principles from the start, and the company holds a patent on the approach. One customer runs a hundred terabytes a day across six data lakes. The operational math is where it gets interesting for the business. An analyst who might close ten alerts in a shift can work fifty or sixty when the rest arrive with a verdict and documentation already attached. Risk drops because alerts actually get investigated, audit cycles move faster because the evidence is there when the auditor asks, and cost follows the data rather than the pipeline. The reaction from practitioners is the part Merza keeps returning to. Rather than worrying about being replaced, the people he talks with are glad to skip the seventeen thousandth phishing email and spend that time on a blast radius question they could not get to before. One person went from a fresh install to a submitted investigation report in under ten minutes and posted about it publicly. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUEST Monzy Merza, Co-Founder and CEO of Crogl | On LinkedIn: https://www.linkedin.com/in/monzymerza/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Learn more about Crogl: https://www.crogl.com Download Crogl: https://www.crogl.com/download Crogl newsroom: https://www.crogl.com/newsroom Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS monzy merza, crogl, sean martin, brand story, brand marketing, marketing podcast, brand spotlight, black hat usa 2026, sovereign ai, ai soc, autonomous investigation, threat hunting, air gapped deployment, ot security, federated search, knowledge graph, alert triage, soc analyst workload, audit evidence, data sovereignty

  36. 965

    AI Has Its Own Supply Chain | A Full Sponsor Brand Briefing at Black Hat USA 2026 with Daniel Bardenstein, CEO and Co-Founder of Manifest Cyber | Hosted by Sean Martin

    At Black Hat USA 2026 in Las Vegas, Daniel Bardenstein, CEO and co-founder of Manifest Cyber, starts with a gap his team measured in a survey of security leaders and practitioners. Leadership described one version of what is happening with AI inside the enterprise. The people doing the hands-on work described another. Adoption keeps moving, and security teams are working to catch up. So what is the real risk in AI security? Bardenstein puts less weight on non-determinism than most and more on ordinary poor software security, because AI is software. He walks through the OpenAI and Hugging Face incident, where models got out of sandboxes because the sandboxing was weak and the guardrails were missing. When Hugging Face went to use its own AI to defend and run forensics, the guardrails read the request as cyber activity and declined. That fallback to an open weight model points to why he expects open weight adoption to accelerate. With frontier models, the provider sets the system prompt and treats it as intellectual property, so development teams inherit whatever was decided upstream. Open weight leaves more room to control the system prompt, the training data, and how the model gets deployed. What does it mean to say AI has its own supply chain? Unless an organization controls how training data is sourced, housed, labeled, tagged, and modified, it is relying on something someone else built. Public datasets carry whatever is inside them, including personal and health data, licensing exposure, and material no one examined until models were trained and deployed. Models hosted on public hubs sit in the same category. Two asks come up in most CISO conversations with Manifest Cyber. Visibility is one, and few organizations have an AI inventory covering which models run where, inside which applications, and which agents teams have stood up on their own. Third party risk is the other, since AI is getting built into vendor products whether a buyer asks for it or not. That turns model provenance into a trust question about the vendor. Bardenstein started Manifest Cyber four years ago after responding to Log4Shell from the Pentagon, where the question was where one affected piece of code was running across everything the organization had built and bought. Years later, he finds few security leaders who could answer that question quickly about a poisoned model or dataset. His advice for CISOs is to know what is inside what the organization builds and buys, with particular attention to the parts it does not build. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUEST Daniel Bardenstein, CEO and Co-Founder, Manifest Cyber On LinkedIn: https://www.linkedin.com/in/bardenstein/ RESOURCES View all of our Black Hat USA 2026 coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Learn more about Manifest Cyber: https://www.manifestcyber.com Beyond the Black Box: How AI is Forcing a Rethink of Software Supply Chain (research report): https://www.manifestcyber.com/beyond-the-black-box-ai-report Manifest Cyber on LinkedIn: https://www.linkedin.com/company/manifestcyber/ Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS daniel bardenstein, manifest cyber, sean martin, brand story, brand marketing, marketing podcast, brand spotlight, ai supply chain security, software supply chain security, ai inventory, shadow ai, third party cyber risk, open weight models, frontier models, model provenance, hugging face, log4shell, ciso, agentic ai, black hat usa 2026

  37. 964

    Customer Zero at Exabyte Scale | A Full Sponsor Brand Briefing at Black Hat USA 2026 with Jeremy Powell, CISO of Sumo Logic | Hosted by Sean Martin

    Most vendors at Black Hat USA 2026 have something to say about agentic AI. Jeremy Powell, CISO at Sumo Logic, spends this conversation on the harder proof, which is what happens when a company runs its own product in production at scale. Sumo Logic has been doing that for roughly ten to eleven months. Powell calls it customer zero, and it shapes how he answers almost every question here. The Sumo Logic SecOps team ingests seven exabytes a day globally, which Powell puts at roughly half a billion 8K movies. Against that volume, the team reports 100 percent first level triage handled through automation and about 25 hours saved per analyst per week. Everything learned in production feeds back into the product organization in real time. Security tooling is notoriously hard to use, especially in the enterprise, and Powell is candid that the realization drove a concerted engineering and product effort to fix it. One result showed up at Black Hat this week in the evolved version of Mobot, the conversational interface inside the product. Users can now prompt their way into an investigation, see the audit trail behind it, and get to an answer without configuring their way there first. So how do you trust a decision an agent made? Powell points to an audit trail and a log trail behind every decision the SOC Analyst Agent produces, traceable back through every conceivable log to the root decision. He describes it as human on the loop rather than in the loop. People keep the decisions. Execution and delivery get automated. That changes the shape of the job. Powell describes the SOC becoming something closer to an agile QA organization, where analysts assess the fidelity of what the agent did instead of grinding through first level alerts. On the question of whether automation costs analysts their jobs, he uses a phrase he borrowed from someone else: pay attention to the tension. His answer is that the work gets better and more interesting and the analysts get more capable. The same logic carries up to the board. Powell argues a security leader's job at the executive level is to measure risk transparently and report it accurately, and that boards will build a trend line out of three data points. Telemetry becomes the raw material for informed risk decisions communicated in an executive-friendly way, with the full reasoning available on request. As he puts it, the auditor cares, and the board cares if you fail the audit. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUEST Jeremy Powell, CISO, Sumo Logic LinkedIn: https://www.linkedin.com/in/executivembajeremypowell/ RESOURCES Sumo Logic: https://www.sumologic.com/ Sumo Logic at Black Hat USA: https://www.sumologic.com/events/black-hat Dojo AI agentic security and cloud operations: https://www.sumologic.com/blog/dojo-ai-agentic-security-cloud-operations Building an AI-first SOC, the customer zero story: https://www.sumologic.com/blog/building-ai-first-soc-customer-zero See Mobot in action: https://youtu.be/ZZLXaft7tYM View all of our Black Hat USA 2026 coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS Jeremy Powell, Sumo Logic, Sean Martin, brand story, brand marketing, marketing podcast, brand spotlight, Black Hat USA 2026, agentic AI, SOC analyst agent, security operations center, human on the loop, first level triage, security automation, telemetry, exabyte scale, customer zero, Mobot, conversational interface, CISO, board reporting, risk communication, SIEM, AI governance

  38. 963

    Vulnerability Backlogs Can Finally Reach Zero | A Brand Spotlight Conversation with Ondrej Vlcek, Co-Founder and CEO of AISLE | Hosted by Sean Martin

    Security leaders count open vulnerabilities in the hundreds of thousands, and in some organizations the number runs past a million. Ondrej Vlcek, Co-Founder and CEO of AISLE, describes teams with no practical route through that backlog while attackers use automation to shrink the time between a disclosure and a working exploit. The question worth asking is what a program looks like when remediation moves at the same speed as exploitation. What makes AI-driven remediation different from static code analysis? Reasoning replaces pattern matching. Linters and commercial scanners flag code that resembles a known error shape, while a reasoning model infers what the developer intended, compares that intent against the actual implementation, and evaluates how the gap could be abused. Ondrej Vlcek points to business logic flaws, timing errors, and race conditions as the classes that pattern matching leaves untouched. The judgment behind AISLE comes from a long run in the industry. Ondrej Vlcek wrote device drivers for Windows 95 in 1995 at a seven-person antivirus company called Avast, stayed more than twenty-five years, moved through CTO and COO into the CEO seat, and took the company public before its sale to NortonLifeLock in 2022. He co-founded AISLE in 2024 with Jaya Baloo, a three-time public company CISO, and Stanislav Fort, an AI researcher who worked at DeepMind and Anthropic. Why does the software supply chain deserve the larger share of attention? Because most of the code in a running application was written somewhere else. Ondrej Vlcek puts the typical enterprise application at roughly ten percent first-party code and ninety percent open source and dependency code, which is also level ground for an attacker reading the same source and pointing the same models at it. Reachability analysis becomes the deciding factor, separating the vulnerable functions your code actually calls from the thousands of transitive dependencies it never touches. For first-party code, AISLE closes the loop differently: read the documentation, the architectural material, and the threat model, then generate a patch aligned with the project's own conventions and test it automatically. The standard Ondrej Vlcek sets is a fix that reads as though a human maintainer wrote it. The customer spread runs from embedded firmware at Bose to smart contracts at the Ethereum Foundation, where heavily audited and sometimes formally verified code still benefits from another set of checks because the systems touch money flows directly. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUEST Ondrej Vlcek, Co-Founder and CEO of AISLE On LinkedIn: https://www.linkedin.com/in/ondrejvlcek/ RESOURCES Learn more about AISLE: https://aisle.com Meet AISLE at Black Hat and DEF CON in Las Vegas: https://aisle.com/black-hat The AISLE platform: https://aisle.com/platform AISLE CVE discoveries: https://aisle.com/cve-discoveries Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS ondrej vlcek, aisle, sean martin, brand story, brand marketing, marketing podcast, brand spotlight, vulnerability management, vulnerability remediation, agentic ai, cyber reasoning system, software supply chain security, reachability analysis, open source security, application security, first-party code, third-party dependencies, static code analysis, zero-day vulnerabilities, ai in cybersecurity, code patching, embedded firmware security, smart contract security

  39. 962

    Agentic Security Changes Everything | An On Location Conversation at Infosecurity Europe 2026 with John Sotiropoulos and Rock Lambros

    Sean Martin catches John Sotiropoulos and Rock Lambros at the end of the OWASP GenAI Security Summit, held alongside Infosecurity Europe 2026 at ExCeL London. Both are deep in the standards work: John Sotiropoulos co-leads the OWASP Agentic Security Initiative and sits on the board of the OWASP GenAI Security Project, and Rock Lambros serves as Director of AI Standards and Governance at Zenity and co-leads the OWASP Top 10 for LLM 2026 update. The headline from the day is the launch of the Agentic Security Council, bringing Oxford University, Queen's University Belfast, CSIT, and other research institutions into the same room as practitioners and industry. John Sotiropoulos frames the reasoning bluntly: content on its own does not create change. Papers and Top 10 lists matter, but they only matter if the people building and defending systems can act on them. The number that reframes everything is twenty-two seconds. That is the average time from an initial access event to the next attacker action, down from eight hours. John Sotiropoulos puts the question directly to anyone still running a human-speed playbook: how do you respond to that? A panel on incident response with participants from AWS and Microsoft, a keynote from Microsoft's National Security Officer, and a walkthrough of the State of Agentic Security and Governance report all point at the same shift toward runtime security. Rock Lambros brings a different kind of grounding. For the first time in the four-year history of the OWASP Top 10 for LLM, the update draws on a corpus of reported incidents rather than opinion and community vote alone. It is one data point among several, but it is data, and that changes what the list can claim. A panel with the heads of AI security at Deloitte supplies the operational counterweight. As one of them puts it, security has to stop being the Ministry of No, because people will route around it and ship anyway. The report's adoption tiers and maturity levels exist for exactly that reason: security that lives only inside a PDF is not security. The invitation from both John Sotiropoulos and Rock Lambros is the same. Join the work. Research, red teamers, defenders, builders, and SecOps all looking at one view of what is actually happening is the only version of this that scales to machine speed. ⬥HOST⬥ Sean Martin, CISSP | Co-Founder, ITSPmagazine & Studio C60 | Host, Redefining CyberSecurity Podcast & Music Evolves Podcast | https://www.seanmartin.com/ ⬥GUESTS⬥ John Sotiropoulos, Deep Cyber | Co-Lead, OWASP Agentic Security Initiative; Board Director, OWASP GenAI Security Project | On LinkedIn: https://www.linkedin.com/in/jsotiropoulos/ Rock Lambros, Director of AI Standards and Governance, Zenity; Founder, RockCyber | Co-Lead, OWASP Top 10 for LLM 2026 | On LinkedIn: https://www.linkedin.com/in/rocklambros/ ⬥RESOURCES⬥ Infosecurity Europe 2026 is taking place June 2-4, 2026 | ExCeL London. Follow our coverage: https://www.itspmagazine.com/infosecurity-europe-2026-infosec-london-cybersecurity-event-coverage OWASP GenAI Security Project | https://genai.owasp.org Contribute to the OWASP GenAI Security Project | https://genai.owasp.org/contribute The Future of Cybersecurity Newsletter | https://www.linkedin.com/newsletters/7108625890296614912/ Redefining CyberSecurity Podcast | https://www.seanmartin.com/redefining-cybersecurity-podcast On Location | https://www.itspmagazine.com/on-location 🥁 🎶 A very big THANK YOU to our Infosecurity Europe 2026 Full Coverage Sponsors: Corelight · Qualys · Sumo Logic 👏 👏 👏 ⬥KEYWORDS⬥ sean martin, john sotiropoulos, rock lambros, infosecurity europe 2026, owasp, genai security project, agentic security, agentic security initiative, agentic security council, owasp top 10 for llm, ai security, incident response, runtime security, ai governance, zenity, rockcyber, deep cyber, dwell time, secops, red teaming, on location, itspmagazine

  40. 961

    The Business Decision Hiding Inside FedRAMP's Consolidated Rules for 2026 | A Brand Story Conversation with Jason Ford and Michael Parisi of Steel Patriot Partners | Hosted by Sean Martin

    FedRAMP has changed before. What makes the Consolidated Rules for 2026 different is that the dates are on the calendar and the fence sitters have run out of runway. Jason Ford, Co-Founder and CEO of Steel Patriot Partners, has been inside the program since Rev 3 in 2013. Michael Parisi, Chief Growth Officer, comes at it from the business side. Together they map what changes and, more usefully, what it means for the decision in front of a provider right now. So what actually changes? The program consolidates into two paths, 20X and Rev 5. FedRAMP Ready moves to legacy status. Class A, B, and C pipelines open across a thirty to sixty day window, mandatory adoption arrives January 1, and new Rev 5 certifications close on June 11, 2027. Authorized becomes certified. Jason Ford also points out where the rules live: fedramp.gov, hosted in GitHub, which means they move with a commit. Reading them once is not tracking them. Why did FedRAMP need to change at all? Michael Parisi frames it as a supply problem. Agencies and primes have been working from a limited and aging set of technologies while better tools sat outside a process that was slow, rudimentary, and expensive. The action was warranted. His follow-up question gets less airtime: if the process moved faster, did responsibility move with it, and does the stakeholder now holding that due diligence know it yet? The engineering shift is real and it is the part most teams see coming. Jason Ford describes RMF thinking giving way to continuous DevSecOps, proving compliance in real time rather than at a point in time. Vulnerability remediation is where the compression bites. CISA's updated guidance drops severity score as the driver in favor of stepped prioritization, and windows that used to run 30, 60, and 90 days now land closer to three to twenty-one. What does this cost a business past the budget line? Time and capacity. 20X is faster than a Rev 5 process that once ran eighteen months, but faster is not instant. Retraining a couple hundred users inside a thousand-person organization is not a small endeavor, and if the transition eats half of the organization's capacity for a year, that is half as much capacity aimed at the business paying for it. Jason Ford is not arguing against the move. He is arguing that disruption belongs inside the decision. Then there is the internal work almost nobody has started. Mapping an existing Rev 5 ATO scope into a new certification level is not clear-cut, and past the mapping, marketing and sales both need re-education. Michael Parisi describes building a translation layer for customers: here is what we provided before, here is what it is now, and this change came from the program rather than from any reduction in assurance. Roughly half the time, Steel Patriot Partners tells organizations not to pursue certification at all. Michael Parisi treats that as one of the more valuable things the firm does. The opposite failure shows up just as often, with companies preparing to spend heavily on 20X because it sounds quicker and cheaper, when the agency or prime they are chasing expects a certification level. A lower bar only helps if the buyer accepts it. Where should a business start? With the business conversation. Michael Parisi notes the answer does not have to be yes or no today; it can be a maybe with defined trigger points. Jason Ford closes on posture: come with an open mind, and do not hand a multi-year commitment to a language model whose guardrails and training are not built for that call. Or, shorter: don't wait, and don't go it alone. Steel Patriot Partners built a three-question starting point for that first conversation at https://www.steelpatriotpartners.com/find-your-path. This is a Brand Story. A Brand Story is a ~35-40 minute in-depth conversation designed to tell the complete story of the guest, their company, and their vision. Learn more: https://www.studioc60.com/creation#full GUESTS Jason Ford, Co-Founder and Chief Executive Officer, Steel Patriot Partners On LinkedIn: https://www.linkedin.com/in/jason-ford-5ab206/ Michael Parisi, Chief Growth Officer, Steel Patriot Partners On LinkedIn: https://www.linkedin.com/in/michael-parisi-4009b2261/ RESOURCES Learn more about Steel Patriot Partners: https://www.steelpatriotpartners.com/ FedRAMP's Consolidated Rules for 2026: What It Means for Cloud Providers: https://resources.steelpatriotpartners.com/fedramps-consolidated-rules-for-2026 Find Your Path, a three-question starting point for ISO, CMMC, and FedRAMP decisions: https://www.steelpatriotpartners.com/find-your-path Complimentary ROI Workshop: https://www.steelpatriotpartners.com/roi-workshop Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS jason ford, michael parisi, steel patriot partners, sean martin, brand story, brand marketing, marketing podcast, fedramp, fedramp consolidated rules for 2026, fedramp 20x, rev 5, fedramp certification classes, cloud service provider compliance, federal compliance, cisa vulnerability remediation, continuous monitoring, devsecops, ato, 3pao, govramp, cmmc, grc, federal marketplace, compliance roi

  41. 960

    FedRAMP First: Modernizing the Defense Supply Chain Without Cutting Corners | A Brand Feature Conversation with Michael Parisi of Steel Patriot Partners and Jason LaPointe of Exostar

    For companies in the defense industrial base, a compliance deadline is not paperwork. It is the difference between winning contracts and watching them stall. In this Brand Feature, Jason LaPointe, Chief Technology Officer at Exostar, and Michael Parisi, Chief Growth Officer at Steel Patriot Partners, walk through what it takes to get FedRAMP ready without cutting corners. Exostar was born out of a consortium that included Boeing and Lockheed Martin, and its FedRAMP-moderate posture lets smaller suppliers keep working on Department of War contracts. How does that work? Instead of moving every server and mailbox into a secure boundary, a supplier inherits roughly 80% of the controls from Exostar, which shrinks the scope of its own CMMC audit considerably. The clock was real. At the time, a November transition date loomed, after which many suppliers could no longer self-attest. That specific timeline has since been paused, but the pressure to prove readiness has not gone away. Exostar needed to show it was FedRAMP-moderate and ready for an audit, and working with Steel Patriot Partners, the team pulled a January target in by nearly three months, not by skipping steps, but by moving with confidence. Why build a new platform instead of retrofitting the old one? Jason LaPointe describes a platform first initiative: build the new compliant home, then migrate customers into it. Trying to modernize inside a live production environment would have been disruptive, so the team built alongside rather than on top, which freed them to re-architect and retool without breaking customers. Michael Parisi frames the engagement as embedding, not staff augmentation. Steel Patriot Partners plugged directly into the product team through daily standups and leadership calls, delivered infrastructure as code and deployment pipelines, and kept the work with US citizens, a requirement once controlled unclassified information is in play. What makes an audit go smoothly? Preparation that extends to how questions get answered. Jason LaPointe compares the audit to a deposition, where an unsolicited comment hands an assessor somewhere new to go. Michael Parisi, who spent years in the assessor's seat and ran the practice for a large C3PAO, explains why knowing the auditors and presenting information cleanly protects the outcome. The business math is unforgiving. Miss the audit window and millions in direct contracts can be exposed, while auditors book out six to eight months. Exostar cleared it with a clean, no POA&M result, and the business is now seeing tailwinds through initiatives like Golden Dome. The lesson Jason LaPointe offers other technology and security leaders is about temperament. Every part of the organization gets touched, from R&D to HR to finance, and the willingness to change quickly becomes the governor on success. Having a clear voice at the table for what good looks like, as Steel Patriot Partners provided, is what accelerates the decisions. This is a Brand Feature. A Brand Feature is a ~30 minute in-depth conversation designed to go deep on a company's story, solutions, and customer success. Learn more: https://www.studioc60.com/creation#feature GUESTS Jason LaPointe, Chief Technology Officer, Exostar Website: https://www.exostar.com/ LinkedIn: https://www.linkedin.com/in/jasonlapointe Michael Parisi, Chief Growth Officer, Steel Patriot Partners Website: https://www.steelpatriotpartners.com/ LinkedIn: https://www.linkedin.com/in/michael-parisi-4009b2261/ RESOURCES Learn more about Exostar: https://www.exostar.com/ Aerospace and Defense solutions from Exostar: https://www.exostar.com/industries/aerospace-defense/ Learn more about Steel Patriot Partners: https://www.steelpatriotpartners.com/ Find Your Path with Steel Patriot Partners: https://steelpatriotpartners.com/find-your-path/ Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS Jason LaPointe, Michael Parisi, Exostar, Steel Patriot Partners, Sean Martin, brand story, brand marketing, marketing podcast, brand feature, FedRAMP, FedRAMP-moderate, CMMC, CMMC 2.0, defense industrial base, DIB, controlled unclassified information, CUI, compliance inheritance, C3PAO, FedRAMP audit, platform modernization, GCC High, Department of War, defense supply chain, cybersecurity compliance

  42. 959

    Tech Trailblazers: Recognition That Reaches the Whole Team | An Interview with Rose Ross | An Analog Brain In A Digital Age With Marco Ciappelli

    PODCAST EPISODE | An Analog Brain In A Digital Age With Marco Ciappelli Fifteen years ago, Rose Ross brought a client an idea for an awards program built specifically for enterprise tech startups. The client passed. She built it herself — and the Tech Trailblazers have been running ever since, independent, judged by practitioners, and open for entries until 3 September. 📺 Watch | 🎙️ Listen | marcociappelli.com There are couches on the upper floor at ExCeL London where the glass opens onto the water, and every June I promise myself I will sit there and have one unhurried conversation with somebody worth an hour. Every June I walk past them carrying a bag of microphones. Rose Ross and I both did exactly that at Infosecurity Europe, so we recorded this weeks later and six thousand miles apart, and it worked out fine. Good ideas survive bad timing. Rose knows something about that. Fifteen years ago she brought a client an idea — an awards program for enterprise tech startups, the companies that had no category of their own. The client passed. She built it herself, gave it a better name than Global Innovation Awards, and asked Joe Baguley to judge. He said yes immediately. When someone like Joe says yes, she told me, you know you are onto something. Fifteen years later the Tech Trailblazers are still running, still independent, and now cover everything from storage and security to quantum and robotics, plus categories for the founders and the investors behind them. I have been around enough award programs to have opinions. Plenty of them are a night out: you put on the jacket, you eat the food, you take the photo, and by Monday the trophy is a doorstop. What Rose built works differently, and the difference is by design. Start with who does the scoring. Rose stays out of it completely, on the reasoning that nobody needs a PR person picking winners — she said it before I could. The judges are practitioners who know a category well enough to read a claim and tell whether it holds. Startups are scored against startups, apples with apples and pears with pears, so a young company is never dropped into a popularity contest against an incumbent. The criteria cover innovation, market readiness and leadership, and then each judge gets a free card: points awarded on instinct alone. I like that card more than I probably should. It concedes that expertise is partly something you feel and cannot fully write down, which is a rare concession in an industry that would prefer everything be a dashboard. Then the shortlists go in front of a thousand CIOs, CISOs and technology buyers around the world, and the promotion keeps going long after the announcement — a weekly roundup of what the alumni are doing, coverage where it can be earned, a podcast recording with Rose for every winner. Risk Ledger took the security category a couple of years back and has just closed a $24 million Series B. The award keeps working after the award. The best answer of the conversation came from a simple question. I asked what a win is actually worth. Rose moved through the exposure and the investor attention quickly, then spent the rest of it on the team. Not the founder. The engineers, the designers, the support people who put in eighteen months of long hours and rarely hear from anyone outside their own building that the work was good. That part, she said, is priceless. I grew up in a city built by workshops. The Florentine bottega was a collective — the master, the apprentices, the hands that ground the pigment and prepared the panels — and the good ones understood that the work belonged to the room. Recognition is old technology. Older than any category Rose runs. An award engineered so that it reaches past the founder and lands on everyone who built the thing is doing something more useful than handing out a doorstop. Near the end I asked whether technology today is money-driven or mission-driven. She declined to pick, which was the right call. Most people want both. She has never interviewed a founder who was in it purely for the exit. And without something worth caring about, you do not survive the years when the payoff is still a maybe. Entries close 3 September at techtrailblazers.com. Firestarters is free for the earliest-stage startups. Sean Martin is on the judging panel this year, so put your best in front of him. More conversations like this one, in your inbox: subscribe to the newsletter at marcociappelli.com. Who on your team should be hearing this week that the work was good? Let's keep thinking. — Marco Co-Founder ITSPmagazine & Studio C60 | Creative Director | Branding & Marketing Advisor | Personal Branding Coach | Journalist | Writer | Podcast: An Analog Brain In A Digital Age ⚠️ Beware: Pigs May Fly | 🌎 LAX🛸FLR 🌍 About Marco Marco Ciappelli is Co-Founder & CMO of ITSPmagazine, Co-Founder & Creative Director of Studio C60, Branding & Marketing Advisor, Personal Branding Coach, Journalist, Writer, and Host of An Analog Brain In A Digital Age podcast. Born in Florence, Italy, and based in Los Angeles, he explores the intersection of technology, society, storytelling, and creativity — with an analog brain, in a digital age. 🌎 marcociappelli.com | itspmagazine.com | studioc60.com About the Guest Rose Ross is the Founder and Chief Trailblazer of the Tech Trailblazers Awards, the first independent awards program built specifically for enterprise technology startups, which she launched in 2012. Fifteen years on, the program spans cybersecurity, cloud, storage, networking, AI, quantum and robotics, alongside CxO, investment and diversity categories recognizing the people behind the companies. Entries are self-nominated and scored by a panel of industry practitioners, and shortlists go in front of a wider group of CIOs, CISOs and senior technology buyers worldwide. Winners receive continued promotion through the program's alumni network and a podcast recording with Rose. She is also the Founder of Omarketing, the London-based PR and marketing consultancy specializing in enterprise technology, which she started in 1998 after beginning her career in-house with British tech startups and NASDAQ-listed technology companies. Omarketing works across cybersecurity, cloud, storage, AI and adjacent B2B technology markets. Rose is a co-founder of TechBritannia and has been a Tech London Advocate since 2016. She studied International Business and German at Aston University, and describes herself as a technologist by osmosis. The 2026 Tech Trailblazers Awards are open to companies under ten years old and no further than Series C funding. The Firestarters categories are free to enter for pre-VC startups. Submissions close 3 September 2026. ITSPmagazine co-founder Sean Martin sits on the 2026 judging panel. LinkedIn | Tech Trailblazers Awards | Omarketing

  43. 958

    Your Team Is Already Using AI. They Just Won't Tell You. | Priyanka Dave, PhD | PODCAST EPISODE | An Analog Brain In A Digital Age With Marco Ciappelli

    PODCAST EPISODE | An Analog Brain In A Digital Age With Marco Ciappelli Every organization has a policy on AI. Most of them are unwritten, unspoken, and enforced by silence. Priyanka Dave — behavioral scientist, dual PhD, and the person responsible for teaching an entire university system how to work with these tools — explains what actually happens inside a company that refuses to say the word out loud. 📺 Watch | 🎙️ Listen | marcociappelli.com This conversation sat in my queue for months. I recorded it back when the show still went by another name, filed it under soon, and then buried it under travel, deadlines, and the small avalanche of everything else. So: my apologies to Priyanka Dave, who deserved better timing. What I did before publishing was listen to the whole thing again, half expecting it to have gone stale — AI conversations have the shelf life of fresh milk — and it hadn't. Not one line. That is either a compliment to her or an indictment of the rest of us. Possibly both. Here is what has held up. Priyanka Dave is a behavioral scientist with two doctorates and the unglamorous job of teaching a large public institution how to actually use these tools. Her diagnosis is not about the technology. It is about what happens when nobody in charge will say anything about it. An organization that stays quiet on AI does not prevent its people from using AI. It only stops hearing about it. Employees keep working the way they were already working — with a chatbot open in the next tab — and they simply stop mentioning it. The tool doesn't go away. The conversation does. I cover cybersecurity for a living, so I recognized this immediately. It's shadow IT with a better vocabulary. And shadow IT was never a technology failure — it was a communication failure that grew teeth. The same thing is happening now, except the data walking out the door isn't on a USB stick. It's being pasted into a text box by someone who was never told where the line is, because nobody in the building was willing to draw one. The schools got there first, and got it wrong first. Ban it, some of them announced, and the students used it anyway — badly, secretly, without a shred of judgment about when the machine is confidently wrong. Prohibition didn't produce abstinence. It produced amateurs. It always does. So Priyanka's answer is education, and here I pushed, because education has a recursion problem. If the leader is supposed to model good AI use, who taught the leader? I asked her: who educates the educator? Her answer was refreshingly unromantic. Nobody, mostly. Budgets get cut, leadership development is the first line item to go, and the executives left standing are quietly teaching themselves at night so they don't look foolish in the morning. The people expected to be the role models are improvising just like everyone else — they're only better dressed while doing it. And this is where the real cost lands. She cited the research: people leave organizations that offer them nowhere to grow. Nobody wants to miss the train. If your company won't teach you the thing that everyone agrees is coming, you will go somewhere that will — and you will take your best years with you. The company that avoided the awkward conversation about AI doesn't just end up with a hidden problem. It ends up with a smaller team. Her three tips for leaders are almost embarrassingly simple, which is how you know they're good. Ask your people what excites them about AI. Then ask what scares them. Then use the thing yourself, out loud, where everyone can see you double-check its work. Which brings me to the word I've been chewing on since we hung up: sensemaking. Priyanka listed it among the capabilities leaders need. I called it common sense, and she let me get away with it. It means not pressing the easy button. It means remembering that the thing on the other side of the screen has no context, no stake, and no idea what it is saying — even when it sounds like it does. It is not your friend. It is not your enemy. It is something else, and we haven't named it yet. So the fear was never really about the machine, was it? It was about being the last person in the room who wasn't told how to use it. Priyanka's work and writing are linked below. Subscribe to the newsletter at marcociappelli.com. Let's keep thinking. — Marco Co-Founder ITSPmagazine & Studio C60 | Creative Director | Branding & Marketing Advisor | Personal Branding Coach | Journalist | Writer | Podcast: An Analog Brain In A Digital Age ⚠️ Beware: Pigs May Fly | 🌎 LAX🛸FLR 🌍 About Marco Marco Ciappelli is Co-Founder & CMO of ITSPmagazine, Co-Founder & Creative Director of Studio C60, Branding & Marketing Advisor, Personal Branding Coach, Journalist, Writer, and Host of An Analog Brain In A Digital Age podcast. Born in Florence, Italy, and based in Los Angeles, he explores the intersection of technology, society, storytelling, and creativity — with an analog brain, in a digital age. 🌎 marcociappelli.com | itspmagazine.com | studioc60.com About the Guest Priyanka Dave, MBA, PhD leads enterprise-wide workforce transformation, building future-ready capability through strategic upskilling, inclusive learning, and organizational change. She currently serves as Upskilling Lead at Oregon State University, where her work on the university's Administrative Modernization Program earned the Outstanding Applied OBM Intervention Award from the Organizational Behavior Management Network at the Association for Behavior Analysis International annual convention. Her career spans more than a decade across IT, aerospace, pharmaceutical, and higher education, in both the United States and India, with measurable results in Learning & Development, Change Management, and Organizational Development. She began in human resources in India, earning a master's degree and her first doctorate there, before moving to the United States to complete a second PhD in Industrial/Organizational Behavior Management at Western Michigan University. She also holds an MBA. Dave partners with executives and cross-functional teams to design enterprise upskilling programs that close critical skill gaps, lead leadership development and performance improvement initiatives, and embed scalable learning strategies that sustain workforce readiness. She is a published contributor to the academic literature on performance feedback in organizations, and writes on AI adoption, digital transformation, and workforce capability for outlets including CIO and HR Executive. LinkedIn

  44. 957

    The Flood Made Everything Free. So Now We Pay for Proof. | Lens Four by Sean Martin | Read by TAPE9

    ⬥EPISODE NOTES⬥ Tidal is about to stop paying royalties on any track it judges to be fully machine-made. Frame that as a music story and you miss the shift underneath it. By Deezer's own detection, roughly 75,000 AI-generated tracks now arrive every day, about 44% of everything uploaded, yet that same AI music is only 1 to 3 percent of what people actually play, and around 85% of those streams are flagged as fraudulent. The flood is not an audience. It is an attack on a shared payout. This edition follows one pattern across six industries: when the cost of generating something collapses toward zero, platforms stop paying for output and start paying for proof of human origin. Tidal cuts AI royalties. The Authors Guild sells a "Human Authored" badge for ten dollars a title. YouTube demonetizes "inauthentic" content. curl killed its bug bounty after a flood of AI slop, then reopened when the slop got good. And where no gatekeeper owns the payout, hiring, the open web, the scientific record, the flood just degrades the mechanism until no one trusts it. In this edition of Lens Four: 🔹 Tidal's July 15 policy ends royalty attribution and direct-to-fan sales for fully AI-generated tracks, a payout decision, not a content ban. 🔹 Deezer takes in about 75,000 AI tracks a day (44% of uploads), up from roughly 10,000 a day at the start of 2025, while human uploads barely moved. 🔹 The paradox that reframes the debate: AI music is 44% of uploads but 1 to 3 percent of listening, and about 85% of those streams are fraudulent. 🔹 The first US criminal AI streaming-fraud case: Michael Smith pleaded guilty after collecting more than 8 million dollars in royalties from hundreds of thousands of AI songs and roughly 1,000 bot accounts. 🔹 curl shut down its bug bounty under a flood of AI vulnerability reports, then reopened a month later because the AI reports got good enough to read. Cutting the money did not cut the volume. 🔹 The counter-case: recruiters see about 11,000 job applications submitted to LinkedIn every minute, up 45% in a year, with no single payout to switch off. 🔹 Provenance becomes a product: Suno (2 million subscribers, about 7 million songs a day) adds identity-verified voice cloning while the Authors Guild sells human certification. 🔹 The danger tier: roughly 20% of AI-recommended software packages do not exist (slopsquatting), and close to 10% of cancer papers show paper-mill signatures. 🔹 The language turned first: Merriam-Webster made "slop" its 2025 word of the year, and YouTube quietly renamed "repetitious" content to "inauthentic." 🔹 Human filters see it clearest: DJ Sam Young asks why we need fifty versions of the same thing, and producer Gregoire Gensollen says he will remember the human moments, not the tool. Fourth Lens: The three lenses meet at one move. Platforms re-price payouts around human origin, the market builds products that certify it, and the language teaches us to want it. That is not a defense of artists, it is a paywall around authenticity, sold as virtue, and it is arriving before audiences even asked for it. Reality has come at a premium, exactly as predicted in 2017. So the real question is not whether the real is worth more. It is this: when proof of human becomes a product, who is making the money, and who handed them the right to decide what counts as real? ▶ Read the full article and references ▶ Subscribe to Lens Four ▶ Redefining CyberSecurity Podcast ▶ Music Evolves Podcast ▶ ITSPmagazine ▶ Studio C60 Sean Martin, CISSP, is a cybersecurity market analyst, content strategist, and go-to-market advisor with more than 30 years of experience across engineering, product development, marketing, and media. He is co-founder of ITSPmagazine and Studio C60, host of the Redefining CyberSecurity Podcast and Music Evolves Podcast, and writes Lens Four at seanmartin.com. Keywords: AI-generated music, Tidal, Deezer, streaming fraud, provenance, content authentication, Human Authored, Authors Guild, Suno, slopsquatting, curl bug bounty, AI slop, paper mills, AI job applications, Merriam-Webster slop, DJ Sam Young, Gregoire Gensollen, Sean Martin, Lens Four

  45. 956

    We Made Everything Faster. We Never Defined Better. | Lens Four by Sean Martin | Read by TAPE9

    ⬥EPISODE NOTES⬥ Almost every booth at Infosecurity Europe 2026 had settled on the same four words. Outcomes. Resilience. Sovereignty. Human in the loop. The messaging had grown up, more tempered than RSAC, more honest in its European register. The tell was quieter — almost none of it could connect those words to a definition of success a buyer could actually verify. Strip away the polish and the show floor was a working argument about what the cybersecurity market is for, at the exact moment the clock that governs it collapsed to seconds. The go-to-market caught up to the language. The capability did not. This is the prove-it problem, and it is worth pulling apart clearly. In this edition of Lens Four: 🔹 Why the quiet vocabulary convergence mattered more than any single product launch — outcomes, resilience, sovereignty, and human in the loop became the words everyone said, and almost none could tie them to a definition of success a buyer could verify 🔹 The number that should reorganize every SOC — the jump from initial access to the next stage collapsing from 8 hours to 22 seconds, with ransomware finishing in under an hour, most often on a Wednesday night 🔹 How Qualys reframed measurement itself — a client environment of 62 million risk findings cut to under 1% that could actually be executed, because the dashboard was never the deliverable, remediation was 🔹 Why Corelight put the same test on the detection itself — a black box tells you little, so keep the data behind every alert in the open and let an analyst prove what it actually is, the way one proof of value surfaced unencrypted sensitive traffic in 30 minutes 🔹 How Sumo Logic showed the repeatable version — prove a fix once, then let an agent apply that proven fix across 599 identical machines under human oversight, and its move into the AWS European Sovereign Cloud put something concrete under the week's sovereignty talk 🔹 What the criminal economy revealed as the honest mirror — an underground market for AI attack tools that went from 38 posts to over 1,400 in two months, tiered and redundant, an AI call center for hire that sounds like SaaS 🔹 Why the board's only real question, are we okay, now lands on the CISO as personal liability, just as AI moves from experimentation to deployment inside the organization 🔹 How consolidation and absorption are sorting the floor — 40-plus tools in silos, "make us relevant" becoming an executive hire, and the 12-to-18-month reckoning where AI absorbs functions that fill today's expo hall 🔹 The tell underneath all of it — when every booth converges on the same three or four words, the words stop doing the one job language has at a trade show: helping a buyer tell two things apart Fourth Lens: The vocabulary moved faster than the products underneath it. The industry repositioned around outcomes without ever defining the outcome, and the bill comes due over the next 12 to 18 months, not because AI arrives, but because AI removes the last place to hide the question. Naming the outcome was the easy part. Proving it repeats, across environments and teams and budgets that share nothing but the problem, is the part the vocabulary skipped. When the story can no longer be rounded up, are we okay, and can you prove it twice? 🥁 🎶 A very big THANK YOU to our Infosecurity Europe 2026 Full Coverage Sponsors: Corelight · Qualys · Sumo Logic 👏 👏 👏 ▶ Full article and references ▶ Full Infosecurity Europe 2026 coverage ▶ Subscribe to Lens Four ▶ Redefining CyberSecurity Podcast ▶ Music Evolves Podcast ▶ ITSPmagazine ▶ Studio C60 Sean Martin is a cybersecurity market analyst, content strategist, and go-to-market advisor with more than 30 years of experience across engineering, product development, marketing, and media. He is co-founder of ITSPmagazine and Studio C60, host of the Redefining CyberSecurity Podcast and Music Evolves Podcast, and co-host of On Location and Random and Unscripted. Learn more at seanmartin.com. Keywords: Infosecurity Europe 2026, cybersecurity go-to-market, security marketing, vendor positioning, machine-speed attacks, agentic AI, ransomware economics, post-quantum cryptography, boardroom liability, digital sovereignty, security tool consolidation, network detection and response, mean time to resolve, threat intelligence, resilience, Sean Martin, Lens Four

  46. 955

    A Forrester Analyst on the Security Roles Coming Next — and What AI Makes Obsolete in Cybersecurity | A Conversation with Madelein van der Hout | On Location With Sean Martin And Marco Ciappelli — Infosecurity Europe 2026

    ON LOCATION | Sean Martin & Marco Ciappelli — Infosecurity Europe 2026 Two conferences, two moods: at RSA the drumbeat was resilience; at InfoSec, it's sovereignty. Sean and I close the week with Forrester analyst Madelein van der Hout — beaming in from the Netherlands — on why Europe makes a framework out of everything, what AI deployment is doing to the boardroom, and the security jobs that don't exist yet. 📺 Watch | 🎤 Listen | ITSPmagazine.com There's a building across the Thames from the InfoSecurity press room — Millennium Mills, a derelict flour mill that looks precisely as haunted as it sounds. I kept glancing at it while Sean and I talked with Madelein van der Hout, who this year was a kind of friendly ghost herself: fully in the conversation, quick as ever, and across the North Sea in the Netherlands. She couldn't make it to London this year. FOMO, she told us, is real. Which turned out to be the point. Madelein is a senior analyst at Forrester — she reads this industry for a living — so the first thing we did was compare notes on what the week actually felt like. Sean kept hearing one word on the show floor: sovereignty. A few weeks earlier at RSA in San Francisco, the drumbeat had been resilience. Same industry, two continents, two moods. Madelein said it better than I could: RSA is where her blood pumps with enthusiasm for everything technology can do, good and bad, and InfoSec is where she comes to get grounded in reality. Flashy versus pragmatic. The far edge of the possible versus the guardrails. Europe, she said with affection, will make a framework out of anything — the cloud sovereignty package announced that week being the newest one. And under all the frameworks sits the thing no European conference can avoid: hybrid warfare, close enough to feel. AI is moving from experimentation to deployment inside real organizations, and the moment it does, it stops being a demo and becomes a liability that lands on a boardroom. That, Madelein argued, is what you're feeling here — the weight of being responsible for something you've only just let inside the walls. Her research points somewhere specific: security is drifting toward becoming a "trust and assurance" function, and with it come jobs that don't exist yet. Trust engineers. Agentic workflow assurance engineers. People whose whole task is to confirm that an AI agent did what the business actually intended, not just what it was told. Sean's read was sharp: almost nothing on the expo floor addresses any of that. They're architecting for now, Madelein agreed, not for what's coming. Which is the oldest story in technology — we shout about the future and keep building for the present. Near the end we argued about metaphors, which is the kind of thing I live for. I reached for Frankenstein: all these tools and agents and smart-city systems stitched together into something we then have to teach to move as one. Madelein offered a better image. Don't build a Frankenstein, she said — become a jellyfish. There's a species that works as a neural network, and when two of them are injured and collide, they don't compete. They merge and swim on as a single organism. More than synergy, Sean said. Exactly. We spend enormous energy bolting parts together and calling it integration. Madelein is describing fusion instead of assembly — one organism, not a monster made of seams. She's already made her peace with what all this means for her own work. This job will be automated, she said, maybe most of it, and she cannot wait to help reinvent what an analyst even is. That was the healthiest thing I heard all week. Not "will AI take my job," but "what is this job becoming." So I'm watching a ghost mill through the rain while a colleague beams in from another country, and the question under all the frameworks and the shiny new job titles is quieter than any of them. When everything can be orchestrated, what still has to be human? Let's keep thinking. The full conversation is part of our On Location coverage of Infosecurity Europe 2026 at ITSPmagazine.com. For more of my writing, subscribe to the newsletter at marcociappelli.com. — Marco (with my co-host, Sean Martin) Co-Founder ITSPmagazine & Studio C60 | Creative Director | Branding & Marketing Advisor | Personal Branding Coach | Journalist | Writer | Podcast: An Analog Brain In A Digital Age ⚠️ Beware: Pigs May Fly | 🌎 LAX🛸FLR 🌍 More from our Infosecurity Europe 2026 coverage:Infosecurity Europe 2026 event coverageTechnology and cybersecurity conference coverage About the Hosts Marco Ciappelli is Co-Founder & CMO of ITSPmagazine, Co-Founder & Creative Director of Studio C60, and host of An Analog Brain In A Digital Age. Born in Florence and based in Los Angeles, he explores the intersection of technology, society, storytelling, and creativity. 🌎 marcociappelli.com Sean Martin is Co-Founder of ITSPmagazine and host of the Redefining CyberSecurity Podcast, where he examines how to think about and operationalize security in the context of business. Together, Marco and Sean produce On Location event coverage from cybersecurity conferences around the world. 🌎 seanmartin.com About the Guest Madelein van der Hout is a Senior Analyst on the Security & Risk team at Forrester, based in the Netherlands. She leads Forrester's research on security organizational structure and operating models, and covers European security strategy, resilience regulation (including DORA and the Cyber Resilience Act), digital sovereignty, and API security. She advises security leaders on building and maturing their programs, and is frequently asked to comment on technology by outlets including the BBC, the Financial Times, and CIO Magazine. Before Forrester she worked at the Dutch telecommunications company KPN across innovation, transformation, cybersecurity, and identity. LinkedIn | Forrester biocxx

  47. 954

    The Identity Gap Behind Nearly Every Breach | A Brand Spotlight Conversation with Kevin Surace, CEO of TokenCore

    For most of the internet's life, proving identity has meant proving something you know or something you hold: a password, a code, a text message. Kevin Surace, CEO of TokenCore, argues that era is closing fast. As one of the people who helped invent the AI assistant at General Magic, he has a clear view of why the same technology now makes faces and voices simple to fake. Why isn't MFA enough? Because it protects a weak foundation. A decade-old paper mapped fifteen ways to defeat SMS codes, auth apps, and push approvals. Few attackers bothered with them until platforms like Salesforce and Microsoft made those methods mandatory. Now the attack has moved to where the door is. Surace walks through one of the common methods: an AI-written phishing email from a service you already trust, a PDF, and a pixel-perfect login page generated in moments. The credentials you enter relay to an attacker who is logging into the real site in real time. The push prompt asks if it is you, you approve, and the intruder is inside within minutes. The numbers back it up. Palo Alto Networks Unit 42 found that roughly ninety percent of successful intrusions over the past year involved hacked identity, almost all of them MFA or auth apps. The people compromised had privileged access, which means they had MFA in place. So what actually works? Surace makes the case for biometric-assured identity, a category Gartner projects growing into a twelve billion dollar market. TokenCore ties access to a fingerprint stored only on your device, the exact domain your account lives on, and physical proximity over a short-range wireless link. Look-alike domains never register, remote relays never get close enough, and the company never holds your biometric. The hardware comes as a ring, a portable, or a node about the size of an AirTag, and it is FIDO2 compatible, so it works with existing single sign-on. Most customers go passwordless once it is running. The reaction Surace hears most often from security leaders is that they can finally sleep at night. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUEST Kevin Surace, Chief Executive Officer, TokenCore LinkedIn: https://www.linkedin.com/in/ksurace/ RESOURCES Learn more about TokenCore: https://www.tokencore.com Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS Kevin Surace, TokenCore, Sean Martin, brand story, brand marketing, marketing podcast, brand spotlight, biometric assured identity, identity security, multi-factor authentication, MFA bypass, phishing resistant authentication, FIDO2, credential theft, passwordless, deepfake, AI security, account takeover, Unit 42, Gartner

  48. 953

    When You Can't Trust the Face on the Call | A Brand Highlight Conversation with Kevin Surace, CEO of TokenCore

    In this Brand Highlight, Kevin Surace, CEO of TokenCore, catches up on a market that has accelerated faster than even his team expected. Biometric-assured identity has gone from the fringes to the core, and the clearest example is the video call: on Zoom or Teams, there is often no reliable way to know whether the person on screen is real, human, or an AI avatar. Surace points to cases where employees wired money because a synthetic version of their boss appeared to ask for it. That risk is pushing the work outward. Beyond using TokenCore internally, the larger banks are asking how to extend biometric assurance to the customers who move wires, because a phone call no longer confirms who is actually on the line. The goal is to know that it is the right person, on the right domain, within a few feet of the device, and not someone operating from another country. For security leaders, Surace offers direct advice: start moving off MFA and authenticator apps now, since those methods are being compromised constantly. He acknowledges the change is hard, often for cultural reasons more than technical ones, and suggests starting with admins and the people who touch real data before expanding over roughly a year. The upside, he notes, is that employees tend to welcome it, going passwordless or even ID-less and logging into tools like Salesforce in under two seconds. This is a Brand Highlight. A Brand Highlight is a ~5 minute conversation that captures a focused idea, update, or perspective from the guest. Learn more: https://www.studioc60.com/creation#highlight GUEST Kevin Surace, Chief Executive Officer, TokenCore LinkedIn: https://www.linkedin.com/in/ksurace/ RESOURCES Learn more about TokenCore: https://www.tokencore.com Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS Kevin Surace, TokenCore, Sean Martin, brand story, brand marketing, marketing podcast, brand highlight, biometric assured identity, identity security, deepfake, AI avatar, video call security, MFA, passwordless, FIDO2, CISO, account takeover, wire fraud, Zoom security, identity assurance

  49. 952

    Who Gets to Tell Your Story? Maggie Alphonsi on Strength, Resilience & Owning the Narrative | An Analog Brain In A Digital Age With Marco Ciappelli — On Location at Infosecurity Europe 2026

    A rugby World Cup winner walks into a room full of people who defend networks for a living. Maggie Alphonsi joins me to talk about breaking barriers, leading with your strengths, and what changed the day athletes stopped waiting for the back page and started telling their own stories. 📺 Watch | 🎤 Listen | marcociappelli.com Maggie Alphonsi has spent her life refusing to let other people decide who she is. She grew up on a north London council estate, born with a club foot, handed a stack of stereotypes she wanted no part of and surrounded, in her words, by people whose ambition pointed down instead of up. Then a PE teacher pointed her toward a rugby pitch, and she found the place where her strength was the whole point — where what her body could do mattered far more than how anyone thought it should look. That teacher didn't just change her life, she told me. She saved it, because the other road was right there and easy to take. I sat with Maggie at Infosecurity Europe 2026 — a Rugby World Cup winner speaking to a hall full of people who defend networks for a living. It sounds like a strange pairing until you hear her, and then it isn't strange at all. She wasn't there to explain rugby. She was there to talk about who gets to decide what your strengths are worth, which is a question the people in that room, many of them women in a field still run mostly by men, live with every day. My obsession, the thing this whole show keeps circling, is who holds the pen. For years women's sport got something like a tenth of one percent of media coverage — two sentences at the bottom of the back page, if that. Someone else decided whether you existed. Then the phone in everyone's pocket changed whose hand was on the pen. Maggie watched athletes start telling their own stories and building their own audiences with nobody's permission. She pointed to Ilona Maher, a rugby player now more famous around the world than almost any man in the game, famous because she controls her own narrative one post at a time. I love this, and I don't fully trust it, and neither does Maggie. The same platform that let her broadcast her strength also filled her feed with sexist garbage about a woman daring to commentate on men's rugby. She showed the crowd some of the worst of it, the misspelled cruelty, and then explained how she turns it into fuel. The tool is neutral. The hand on it is not. We talk about technology as the thing that amplifies a voice, and it does. But the voice itself — the strength, the scars, the single mother who worked herself to the bone, the years of being told to play it down — none of that is digital. It is as analog as a muddy pitch. Maggie has two books out now, an autobiography and one for kids who haven't found their sport yet, and both exist for the same reason she stood on that stage: so a young person reads a story and thinks, that could be me. We are all made of stories. I say it constantly, and this week a rugby player who learned it the hard way said it back to me. The technology decides how far a story travels. It still can't decide whether the story is worth telling. That part is ours. So before you hand your story to an algorithm to carry, it's worth asking who wrote it — and whether you'd recognize yourself in the version that comes back. Let's keep thinking. Maggie's books are linked below. And if you want more conversations like this one, subscribe to the newsletter at marcociappelli.com. — Marco Co-Founder ITSPmagazine & Studio C60 | Creative Director | Branding & Marketing Advisor | Personal Branding Coach | Journalist | Writer | Podcast: An Analog Brain In A Digital Age ⚠️ Beware: Pigs May Fly | 🌎 LAX🛸FLR 🌍 More from our Infosecurity Europe 2026 coverage:Infosecurity Europe 2026 event coverageTechnology and cybersecurity conference coverage About Marco Marco Ciappelli is Co-Founder & CMO of ITSPmagazine, Co-Founder & Creative Director of Studio C60, Branding & Marketing Advisor, Personal Branding Coach, Journalist, Writer, and Host of An Analog Brain In A Digital Age podcast. Born in Florence, Italy, and based in Los Angeles, he explores the intersection of technology, society, storytelling, and creativity — with an analog brain, in a digital age. 🌎 marcociappelli.com | itspmagazine.com | studioc60.com About the Guest Maggie Alphonsi MBE is one of the most influential figures in the history of women's rugby. A flanker for Saracens and England, she won 74 caps, helped England to seven consecutive Six Nations titles, and lifted the Women's Rugby World Cup in 2014. Born in London in 1983 and raised by her single mother of Nigerian heritage, she was born with club foot and overcame it to reach the top of a sport that wasn't built with her in mind. Nicknamed "Maggie the Machine," she was appointed MBE in 2012, named Sunday Times Sportswoman of the Year, became the first woman to win the Rugby Union Writers' Club Pat Marshall Award, and was inducted into the World Rugby Hall of Fame in 2016. Since retiring, she has broken ground off the pitch — in 2015 becoming the first former female player to commentate on men's international rugby, and serving on the Rugby Football Union Council, where she drives the organization's diversity and inclusion work. She is a broadcaster across ITV, BBC and Sky, a sought-after speaker, and the author of two books: her autobiography Winning the Fight and Ultimate Rugby Superstars, written for young readers. LinkedIn | Website | Books: Winning the Fight and Ultimate Rugby Superstars

  50. 951

    Technology Got Safer, But The Smartest Hackers Don't Hack. They Just Ask | An Interview with Lee Clark | An Analog Brain In A Digital Age With Marco Ciappelli — On Location at Infosecurity Europe 2026

    PODCAST EPISODE | An Analog Brain In A Digital Age With Marco Ciappelli — On Location at Infosecurity Europe 2026 The most dangerous attacks at Infosecurity Europe 2026 weren't the high-tech ones. Lee Clark of the Retail & Hospitality ISAC sits down with me to explain why the soft target is still a human being — a help desk, a new hire, a phone ringing at dinner — and what stays in our hands as the shopper quietly becomes an algorithm. 📺 Watch | 🎤 Listen | marcociappelli.com The phone rings while my parents are eating dinner, and before anyone reaches for it, I already know what I'll say. Probably a scammer. Let it ring. I have trained them the way you train a reflex, a small Pavlovian flinch every time the landline interrupts a meal. My grandmother's generation thought letting a phone ring was unforgivably rude. Mine has learned the rudeness is now on the other end of the line. I was thinking about that flinch when I sat down with Lee Clark at Infosecurity Europe 2026. Lee runs threat intelligence production for the Retail & Hospitality ISAC, the place where the companies holding your loyalty points, your hotel bookings, and your checkout data come together to compare notes on who is coming after them. His job, stripped down, is translation: he takes the hash-value, log-source world of the analysts and turns it into something a board can act on. And the thing he kept returning to was not some exotic piece of malware. The two threats his member companies report most often need almost no code at all. One is a phone call. A criminal rings the help desk, says he's an employee who needs his multi-factor authentication reset, gets it, and walks in through the front door. Scattered Spider, ShinyHunters, the loose crew they call the Com: names that sound like a heist movie and behave like one. The other is a fake résumé, North Korean operatives tracked as Famous Chollima, taking remote IT jobs at Western firms under invented identities. No hoodie, no broken encryption. People, lying to people, about who they are. You can stop a lot of fraud by adding multi-factor authentication at the checkout page, and by adding that one step, you measurably reduce sales. So the business sits forever between wanting you safe and wanting you to keep buying, and security tends to arrive last, patching armor onto a machine already built for speed. Lock a light switch inside a box, Lee said, and eventually the person who needs the light just takes a hammer to it. We have been handing each other hammers for years. Then we went where these conversations now always go. What happens when the shopper is no longer a person but an agent, an AI buying the paper towels so I don't have to? Agent negotiating with agent at the checkout, at machine speed, no human flinch anywhere in the loop. Maybe that is more secure. Or maybe it is a new doorway, where instead of fooling a tired employee you simply ask the agent, politely, to send the payment somewhere else. What I carry out of that room is this. For thirty years we have been promised that the next layer of technology will finally take security off our hands. Lee doesn't believe it, and after this week, neither do I. The human stays in the loop, as the target, yes, but also as the one still able to feel that something is wrong. My parents' flinch at the dinner table is not a flaw in some outdated analog brain. It is the brain doing precisely what no checkout page can do for them. We keep trying to automate away the part of us that hesitates. Lee spends his days proving that the hesitation is the defense. So the question I'm left with is not whether the machines will protect us. It's whether we hold on to the part of ourselves that still knows when to hang up. Let's keep thinking. The full conversation is on video, audio, and in the newsletter at marcociappelli.com. — Marco Co-Founder ITSPmagazine & Studio C60 | Creative Director | Branding & Marketing Advisor | Personal Branding Coach | Journalist | Writer | Podcast: An Analog Brain In A Digital Age ⚠️ Beware: Pigs May Fly | 🌎 LAX🛸FLR 🌍 More from our Infosecurity Europe 2026 coverage:Infosecurity Europe 2026 event coverageTechnology and cybersecurity conference coverage About Marco Marco Ciappelli is Co-Founder & CMO of ITSPmagazine, Co-Founder & Creative Director of Studio C60, Branding & Marketing Advisor, Personal Branding Coach, Journalist, Writer, and Host of An Analog Brain In A Digital Age podcast. Born in Florence, Italy, and based in Los Angeles, he explores the intersection of technology, society, storytelling, and creativity — with an analog brain, in a digital age. 🌎 marcociappelli.com | itspmagazine.com | studioc60.com About the Guest Lee Clark is Cyber Threat Intelligence Production Manager at the Retail & Hospitality ISAC (RH-ISAC), the information sharing and analysis center for consumer-facing industries — retail, hospitality, airlines, quick- and full-service restaurants, loyalty programs, and their supply chains. As the editor-in-chief of the ISAC's intelligence team, he turns the granular, highly technical work of analysts into strategic intelligence that business leaders can act on, and he writes much of the center's published threat research himself. Before joining RH-ISAC, Lee worked as an intelligence consultant, including cyber threat intelligence work at Booz Allen Hamilton and engagements supporting international banks and the U.S. Air Force. He holds a Master's in security and diplomacy from the Patterson School at the University of Kentucky, and — fittingly for a guest on this show — writes about music on the side. He is based in Lexington, Kentucky. LinkedIn | RH-ISAC

Type above to search every episode's transcript for a word or phrase. Matches are scoped to this podcast.

Searching…

We're indexing this podcast's transcripts for the first time — this can take a minute or two. We'll show results as soon as they're ready.

No matches for "" in this podcast's transcripts.

Showing of matches

No topics indexed yet for this podcast.

Loading reviews...

ABOUT THIS SHOW

Founded in 2015, ITSPmagazine began as a vision for a publication positioned at the critical intersection of technology, cybersecurity, and society. What started as a written publication has evolved into a comprehensive repository for all their content—podcasts, articles, event coverage, interviews, videos, panels, and everything they create.This is where Sean Martin and Marco Ciappelli talk about cybersecurity, technology, society, music, storytelling, branding, conference coverage, and whatever else catches their attention. Over a decade of conversations exploring how these worlds collide, influence each other, and shape the human experience.This is where you'll find it all.

HOSTED BY

ITSPmagazine, Sean Martin, Marco Ciappelli

Produced by ITSPmagazine

Frequently Asked Questions

How many episodes does The ITSPmagazine Podcast have?

The ITSPmagazine Podcast currently has 50 episodes available on PodParley. New episodes are automatically indexed when they're published to the podcast feed.

What is The ITSPmagazine Podcast about?

Founded in 2015, ITSPmagazine began as a vision for a publication positioned at the critical intersection of technology, cybersecurity, and society. What started as a written publication has evolved into a comprehensive repository for all their content—podcasts, articles, event coverage,...

How often does The ITSPmagazine Podcast release new episodes?

The ITSPmagazine Podcast has 50 episodes. Check the episode list to see recent publication dates and frequency.

Where can I listen to The ITSPmagazine Podcast?

You can listen to The ITSPmagazine Podcast on PodParley by clicking any episode. We provide an embedded audio player for direct listening, and you can also subscribe via your preferred podcast app using the RSS feed.

Who hosts The ITSPmagazine Podcast?

The ITSPmagazine Podcast is created and hosted by ITSPmagazine, Sean Martin, Marco Ciappelli.
URL copied to clipboard!