The Business of Cybersecurity

The Business of Cybersecurity

por Neil C. Hughes

Why AI Gives Cyber Attackers the Early Advantage With IEEE

Can defenders keep pace when generative AI gives attackers faster ways to create convincing phishing messages, research targets, and test new attack methods? In this episode of The Business of Cybersecurity, I speak with Professor Steven Furnell from the University of Nottingham for an IEEE conversation about AI-enabled threats, security awareness, passkeys, cyber hygiene, and the continuing gap between cybersecurity policy and everyday practice. Steven explains why the current AI contest does not give either side exclusive access to powerful technology. Attackers, however, often gain the early advantage because they use it to create opportunity and set the agenda. Defenders are then left identifying the new behavior, adapting controls, and managing the extra work. Generative AI also removes much of the effort once required to research an organization and produce credible spear-phishing messages, making familiar advice about spelling errors and obvious scams less useful than it once was. We discuss whether passkeys could finally reduce our dependence on passwords and why adoption will still require technical preparation and clear communication with users. A control may improve security while adding friction, so businesses must consider how authentication, updates, access controls, and other interventions fit into real working routines. Steven also points to a recurring problem in cybersecurity awareness. Fewer than one in five organizations in the UK Cyber Security Breaches Survey reported staff awareness training in the previous 12 months, according to the figures he discusses. Even where annual training exists, watching a video and answering questions may satisfy a compliance requirement without showing whether an employee can respond effectively when a real incident occurs. For smaller organizations that find security frameworks overwhelming, Steven recommends Cyber Essentials as a practical baseline. We also discuss secure design, the difficulty of regulation keeping pace with technology, and the Cyber Games Lab activities created at the University of Nottingham. Hacker Whacker and Cyber Defense Dice use play and conversation to make cyber education easier to understand for young people and business audiences. What would improve security behavior inside your organization, another annual training module or regular opportunities to practice realistic decisions? Listen to the episode and share your thoughts.

Closing the Forgotten SaaS Account Security Gap With Kaseya

Could your security team produce an accurate list of every employee, contractor, guest account, application, and AI agent with access to your SaaS environment today? In this episode of The Business of Cybersecurity, I speak with Jim Lippie, Chief Product Officer at Kaseya, about findings from the company’s latest SaaS security research. The report draws on anonymized activity from the SaaS Alerts platform, covering 27 billion security events across 50,000 organizations. One finding immediately stands out. Only 44% of monitored organizations were using multifactor authentication. When the research began in 2022, the figure was 32%. Four years of heightened cyber awareness have therefore produced an increase of only 12 percentage points. The report also found that guest accounts represented 69% of monitored accounts. This means guest users outnumbered licensed users by over two to one. Jim explains how these accounts accumulate. A consultant, contractor, or temporary employee receives access to company systems, completes the work, and leaves. The account remains because nobody owns the process of removing it. Over time, these forgotten identities create unattended routes into business data and applications. Our conversation examines how SaaS has changed the security perimeter. Employees no longer need to be inside an office or connected through a corporate network. A browser, valid credentials, and access to a cloud application may be enough. Security teams must therefore monitor user behavior, permissions, locations, and unusual patterns rather than relying on controls designed around the office firewall. AI agents add another category of identity. An autonomous system performing workflow tasks may require access to files, email, customer data, financial systems, or internal applications. Jim argues that these agents should be treated like users, with defined permissions and continuous behavior monitoring. We also discuss the tension created by easy collaboration. The report found that 34% of monitored file sharing traveled outside the organization. That sharing may be legitimate, but businesses need to understand which information has left, who received it, and whether access remains appropriate. Jim’s advice is deliberately practical. Begin with a complete assessment of the environment. Identify every account and application, require MFA, give guest access an expiration date, monitor behavior, and use overlapping security controls where a second source of evidence can expose missed activity. Does your organization have genuine visibility across its SaaS environment, or are forgotten accounts and unmonitored identities creating doors nobody remembers opening? Listen to the episode and share your thoughts with me.

Reducing Fifty Thousand Cyber Alerts to Fifty Decisions With Tanium

What happens when a security team receives 50,000 alerts but only 50 genuinely need human attention? In this episode of The Business of Cybersecurity, I speak with Harman Kaur, CTO of Tanium and a reserve cyber officer in the U.S. Air Force, about how AI is changing the pace, structure, and responsibilities of modern security operations. The long-running cybersecurity talent shortage has not disappeared, but Harman believes the conversation is changing. Security teams now have tools that can assist with specialist work, which places greater weight on processes, interpretation, and decision-making. Training increasingly includes knowing how to ask the right question, assess an AI-generated response, and decide whether the proposed action makes sense. That change matters because the old pattern of threat response is becoming too slow. Security teams once had time to identify a threat trend, respond to it, and prepare for the next one. Harman says those cycles can now collapse to seconds as AI helps attackers find vulnerabilities and develop exploits. Defenders therefore need to consider whether the same technology can support remediation and patch creation at a comparable pace. We discuss why traditional scripted automation cannot solve this problem by making the existing workflow slightly faster. If an analyst can manually process 100 alerts and automation raises that number to 200, the improvement offers little comfort when the queue reaches thousands or hundreds of thousands. Harman argues that organizations need to reconsider how the security operation itself is designed while retaining people as judges for decisions with meaningful consequences. Autonomy, in her view, should be treated as a spectrum rather than an all-or-nothing destination. One process may be suitable for full automation, another may require approval, and a third may remain entirely human-led. That approach also helps CIOs and CTOs respond to pressure for rapid AI adoption without pretending that a single governance model can answer every risk. Harman also warns against allowing the AI conversation to distract teams from familiar security weaknesses. Shadow AI matters, and companies need visibility into the models and tools being used across the organization. At the same time, phishing, compromised credentials, unpatched machines, end-of-life devices, unused applications, and exposed ports remain common sources of risk. AI may amplify those weaknesses, but it does not erase the need to address them. The episode’s clearest example concerns alert fatigue. Harman describes an AI system that processes and triages alerts while reporting its confidence and showing how it reached its conclusion. Verification mechanisms can then ask what additional context should be considered. The goal is to narrow 50,000 alerts to perhaps 50 that deserve manual investigation, giving analysts a manageable decision set without asking them to trust a model blindly. We also discuss operational resilience and why prevention must begin before a security alert appears. Harman challenges organizations to explain why routine patching is not automated in 2026, while recognizing that no company can apply every patch instantly. Reducing the attack surface by removing unused applications and closing unnecessary ports can make the business a smaller target while teams address the vulnerabilities that matter most. Finally, Harman asks leaders to question why they are applying AI to a given problem. Some tasks can be handled by established automation. If the organization chart, business processes, and toolset look exactly the same after an AI program, the company may have added technology without redesigning the work. Where should your organization allow AI to act, where should it advise, and where must a person make the final decision? Listen to the episode and share your thoughts.

Securing Every AI Agent Action With Delinea

What happens after an AI agent presents valid credentials and enters your business systems? In this episode of The Business of Cybersecurity, I speak with Spencer Young, Senior Vice President of International Markets at Delinea, about why authenticating an AI agent is only the beginning of the security challenge. Spencer has spent 34 years in IT and around half that time in cybersecurity. His experience covers secure software development, vulnerability testing, application protection, data security, and identity security. Our conversation begins with the changing economics of cybercrime. Spencer says attackers increasingly prefer stealing or compromising legitimate credentials because logging in can be cheaper, faster, and easier than forcing a route through network defenses. He estimates that over three quarters of attacks involve a compromised credential somewhere in the chain. AI agents add speed and scale to identity risk. They can access applications, databases, financial systems, development tools, and infrastructure while performing dozens of actions during a single session. The danger is not limited to an agent being denied access. An agent may be fully authenticated and possess valid permissions while taking an action the organization never intended. Spencer offers the example of a finance agent created to support payment processes. Hidden or manipulated instructions could cause it to change payment profiles and redirect money while appearing to operate as an authorized identity. This is why Delinea is focusing on runtime authorization. Rather than approving an agent once and allowing every subsequent action, the approach evaluates each proposed tool call, database query, or SSH command before it runs. The action can be allowed, blocked, or referred to a person for approval. We also discuss how least privilege applies to autonomous systems. Spencer recommends providing credentials only at the moment an agent needs them, limiting access to the specific task, and revoking those privileges immediately afterward. The agent never needs to see or retain the credential. The research figures Spencer shares reveal a concerning difference between confidence and control. He says 80% to 85% of respondents feel confident in their ability to discover nonhuman identities, while only 30% validate nonhuman identity use and AI activity in real time. Delinea now works with over 9,000 organizations, including over 60% of the Fortune 100. Spencer says regulated industries frequently demonstrate greater identity security maturity because external requirements encourage continuous controls rather than reactive incident response. However, technology cannot decide an organization’s risk appetite. People must define what the agent is expected to do, which actions require approval, where it must stop, and who is accountable when something goes wrong. Could your organization detect a properly authenticated AI agent taking an inappropriate action before that action executes? Listen to the episode and share your thoughts with me. Suggested URL

Securing AI Agents Before They Become Attack Paths With ExtraHop

Can a security team respond quickly enough when an AI-driven attack moves from initial access to lateral movement and data theft before a human analyst has finished opening their dashboards? In this episode of The Business of Cybersecurity, I speak with Heath Mullins, Chief Evangelist at ExtraHop and former Forrester analyst, about why AI security has become an operational issue for organizations today. ExtraHop’s 2026 Global Threat Landscape Report states that 85 percent of organizations have experienced an AI-driven attack. These incidents include AI-enhanced external attacks, compromised AI identities, and breaches involving third-party AI providers. The report also found that 55 percent view AI agents, agentic infrastructure, and GenAI applications as their biggest attack-surface risk. Heath explains that many attacker tactics remain familiar. The difference is speed. An analyst who once had hours or days to compare endpoint alerts, network logs, threat intelligence, and security events may now find that the attack has completed before the investigation begins. We also discuss how AI models can be influenced without anybody directly altering their code. Attackers can publish false information that enters future training data or introduce misleading content into internal repositories and development environments. An agent may then infer a connection, assign a high confidence score, and act on inaccurate information. The risks grow when AI agents receive administrator privileges. Heath describes an agent as an entity capable of taking action across the network. His analogy is difficult to forget: AI can resemble a dangerous toddler carrying the keys to the house, car, and gun safe. It may be extremely helpful, but broad permissions combined with loosely defined instructions create the conditions for serious damage. Third-party AI adds further dependencies. Security leaders need to understand how suppliers use models and reasoning tools, whether customer data is segregated, what remote access exists, and how a compromised supplier could create a path into the network. Heath also challenges the assumption that endpoint controls and delayed logs provide enough visibility. Machine-speed attacks may exploit unknown vulnerabilities, evade endpoint detection, and move laterally using identities that appear legitimate. Behavioral and live network signals can reveal activity that does not match a published indicator or known signature. Buying another security product may address an identified gap, but Heath argues that CISOs also need awareness across physical, virtual, cloud, and container environments. Network and security teams must share information when an identity, agent, or workload begins behaving differently. His immediate advice is direct. Treat every new tool as potentially dangerous. Test AI agents inside properly isolated environments. Connect every agent to a known identity, restrict its permissions, and define a narrow task. Finally, train people to use AI responsibly and retain human authority over consequential actions. Heath is also the kind of guest I could talk with over a cold beer for hours about technology and its consequences. After we finished the formal interview, our conversation moved naturally into AI data centers, energy costs, water consumption, surveillance, and humanity’s habit of adopting technology even when we understand the price. If AI agents can act with administrator privileges at machine speed, are your security controls watching what those agents are doing or merely recording what happened afterward? Listen to the episode and share your thoughts with me.

Patching at Machine Speed Without Breaking the Business With Adaptiva

What happens when a patch designed to protect the business creates an outage of its own? In this episode of The Business of Cybersecurity, I speak with David Sowder, Senior Solutions Architect and OneSite Patch product specialist at Adaptiva, about balancing rapid vulnerability remediation with operational control. David brings 25 years of IT operations and engineering experience to the conversation. He remembers receiving large spreadsheets of vulnerabilities from security teams and being responsible for turning that information into deployed fixes. That experience gives him a practical view of the gap between identifying a vulnerability and safely resolving it across thousands of endpoints. Adaptiva’s State of Patch Management report argues that speed cannot be the only measure of success. David illustrates the problem with a library cart full of books. Pushing it down the stairs may be the fastest way to reach the lower floor, but the resulting mess defeats the purpose. The same principle applies to patch management. Urgent deployment can reduce the period when a vulnerability remains exposed, but an inadequately tested update may break applications, interrupt customer services, or affect revenue. David recommends representative pilot groups, defined testing periods, user feedback, staged deployment, monitoring, and the ability to stop a release before it reaches the full production environment. We also discuss why greater endpoint visibility does not automatically reduce business risk. Dashboards and vulnerability reports provide knowledge, but IT teams must perform the work required to remediate the problem. David believes closer cooperation between InfoSec and IT can reduce the time between identification and action. Automation introduces another difficult decision. David argues that layers of manual approval frequently add delay without changing which patches are eventually deployed. His proposed alternative is to begin the process automatically, notify the right people, test through pilot groups, and prevent wider deployment when the feedback indicates a problem. Accountability remains shared. Security leaders set risk policies, InfoSec prioritizes exposure, IT manages deployment, and application owners understand the possible business consequences. These responsibilities need to be agreed before an urgent incident arrives. Can autonomous patch management help companies respond at machine speed without turning a security fix into a business outage? Listen to the conversation and share your thoughts with me.

Rethinking Third Party Risk for Machine Speed Attacks With Magnitude

Can a supplier assessment completed once a year protect an organization against risks changing at machine speed? In this episode of The Business of Cybersecurity, I speak with Rami Habal, founder and CEO of Magnitude. We discuss why traditional third party risk management is struggling to keep pace with connected supply chains, autonomous attacks, AI adoption, and constantly changing vendor environments. Rami explains that third party risk management developed largely as a compliance process. Companies relied on questionnaires, spreadsheets, point-in-time assessments, and annual reviews. Those methods provided documentation, but they offered limited visibility into what changed after the review or which fourth and fifth parties supported the original vendor. The result can be a false sense of security. A supplier may change its infrastructure, ownership, software, data practices, or terms of service months before the customer performs another formal assessment. Attackers do not wait for the next compliance cycle. Rami argues that AI has broken the traditional mathematics of third party risk. Security teams cannot manually monitor thousands of suppliers and every organization supporting them. Attackers can use advanced models to find weaknesses faster, while businesses are adding AI services and dependencies at speed. Magnitude provides what Rami describes as an AI workforce for third party and supply chain risk management. Its agents support tasks including supplier intake, evidence gathering, security evaluation, risk analysis, onboarding, continuous assurance, and offboarding. We discuss how this automation can address three business problems. The first is time compression, allowing security teams to process supplier reviews faster. The second is risk reduction through wider visibility, including fourth and fifth party dependencies. The third is business enablement, reducing delays that might otherwise encourage employees to use unapproved AI tools. Rami explains how Magnitude maps supplier relationships as a connected graph. Security teams can see where dependencies overlap, identify concentration risk, and assess which parts of the business may be affected when a provider experiences an incident. Continuous monitoring also includes unstructured information. A vendor may update a lengthy terms of service document and introduce permission to train AI systems using customer data. An employee receiving the notification may ignore it, while an automated agent can compare the document, identify the change, and explain its potential effect. Rami uses a helpful analogy. Traditional vendor assessments resemble photographs, while continuous monitoring resembles a live video feed. Operational, financial, cybersecurity, and privacy risks continue changing after the original assessment. Automation does not remove people from the process. Rami sees AI preparing evidence, correlating signals, and recommending action while humans handle exceptions, ask difficult questions, and judge the business consequences. He closes by urging boards to treat third party risk as part of cyber resilience rather than leaving it within procurement or compliance. Does your organization know which suppliers create its greatest concentration risk and how far a breach could travel through the chain? Listen to the conversation and share your thoughts with me.

Giving AI Security Agents the Context They Need With Sola Security

What happens when an AI security agent receives access to eight enterprise systems but cannot understand the relationships between the data inside them? In this episode of The Business of Cybersecurity, I speak with Guy Flechter, CEO and co-founder of Sola Security. Guy has worked in cybersecurity for 25 years, progressing from operational security roles to the CISO position before moving into entrepreneurship. He previously founded Cider Security, which was acquired by Palo Alto Networks for $300 million. Our conversation focuses on why adding AI agents to separate security tools may increase speed without improving the quality of the decisions. Cloud, identity, SaaS, code, devices, and networks frequently operate through different consoles and data models. An agent working within one of those systems may answer confidently while missing a relationship that changes the meaning of the risk. Sola Security’s research examined 50 tasks across eight enterprise platforms. According to Guy, providing structural and relational context improved answer correctness by approximately 34% across the tested models. Under full context, 78% of responses were considered fully correct, around 18% were incomplete, and fewer than 4% were classified as complete failures. Those results show both the promise and present limitations of AI security agents. Connected context can improve performance significantly, but 78% accuracy does not support fully autonomous action in situations where an incorrect permission change or security response could have serious consequences. Guy believes human involvement will remain necessary until accuracy reaches a far higher level. We also discuss how companies should vet and onboard AI agents. Guy recommends treating an agent like a new employee by defining its permissions, monitoring its actions, controlling what it can retain, and limiting its authority until trust has been earned. The episode concludes with a discussion about independent testing. Guy argues that buyers need transparent benchmarks with visible tasks and repeatable methods, rather than vendor accuracy claims based on private evaluations. Should an AI security agent be allowed to act autonomously if its reasoning cannot be independently tested? Listen to the conversation and share your thoughts with me.

Finding Attacker Intent Before the Breach With KELA

What if criminals were discussing, selling, or preparing access to your company before anything appeared on your security dashboard? In this episode of Business of Cybersecurity, I speak with Lewis Henderson, Director of Intelligence Communications at KELA, about the criminal economy operating beyond the corporate network. We discuss how cyber threat intelligence can reveal attacker intent earlier, giving security teams time to respond before stolen access becomes a full breach. KELA’s State of Cybercrime 2026 research identified 2.86 billion stolen credentials in a single year. Lewis explains why that volume makes exposure a question of probability for many large organizations. He also describes how cybercrime as a service has lowered the technical barrier for attackers. Businesses may now face hundreds of lower-skilled criminals using purchased tools, credentials, and AI assistance instead of a small number of highly experienced groups. One example begins with an employee downloading a video game containing infostealer malware. A single stolen credential reportedly provided access to 300,000 cash registers. KELA discovered the access being discussed in a criminal market, showing why monitoring attacker activity outside the network can provide warning that internal tools may miss. We also examine alert fatigue, the limitations of point-in-time risk assessments, how criminals are experimenting with AI, and why boards should ask security leaders about threats forming across suppliers, cloud services, and the wider internet. Are companies investing enough in understanding attacker intent, or are too many waiting for the threat to arrive at their front door? Listen to the conversation and share your thoughts with me.

Closing the AI Vulnerability Remediation Gap With Cobalt

In this episode of Business of Cybersecurity, I speak with Gunter Ollmann, CTO at Cobalt, about AI powered vulnerability discovery, the widening remediation gap, continuous pentesting, legacy application risk, and the future of cybersecurity careers. Advanced security models such as Mythos can gather and apply techniques published across security research, Black Hat, DEF CON, and other industry sources. Gunter says this makes them particularly effective at reviewing large code bases and trying known attack methods against potential targets. The result is faster vulnerability discovery, but finding additional weaknesses does not automatically make a company safer. Cobalt’s 2026 State of Pentesting Report found AI and LLM tests produced high risk findings at 2.7 times the rate of its wider data set. According to Cobalt, 32% of AI and LLM findings were rated High Risk, while only 38% were resolved. Gunter sees two reasons for the gap. Companies are adding AI features to existing applications without fully understanding how the new components affect security. He compares this with the arrival of internet connectivity inside physical equipment, when engineering teams added network stacks without years of experience securing them. Supplier dependency creates another problem. When a company adds a third party model or AI service to its product, it may lack the ability to correct a weakness directly. Remediation then depends on the supplier’s development priorities and release schedule. Gunter recommends moving security testing closer to development. The traditional annual penetration test created for compliance is being replaced by a continuous cycle of monthly or quarterly human testing, daily or weekly automated scanning, and remediation connected with development pipelines. Human participation remains important, but its role is changing. Automation, machine learning, and AI have already removed many Tier 1 positions from security operations centers. The same pattern is appearing in offensive security, where junior pentesters once learned by working alongside experienced practitioners. Gunter does not see strong evidence that giving a junior analyst an AI tool automatically turns that person into a Tier 2 practitioner. Instead, some organizations are recruiting experienced professionals from IT, product management, or program management and using AI to help them acquire cybersecurity knowledge. This creates a long term talent problem. Businesses continue competing for senior practitioners while removing the junior roles that historically produced them. The industry therefore needs new ways for inexperienced candidates to learn, practice, receive feedback, and assume responsibility safely. We also discuss whether faster discovery could overwhelm senior practitioners. Gunter points out that many weaknesses being discovered by AI have existed for years. The technology is improving the industry’s ability to locate and exploit them. Defensive tools are also becoming faster at finding causes, creating fixes, and deploying updates. The remaining problem is time. If an AI system can find a vulnerability and create an exploit almost simultaneously, companies may have hours rather than weeks to respond. When an immediate code fix is unavailable, detection and blocking technologies may need to provide temporary protection. His final message is directed at CISOs. AI cannot be treated as a system that receives a problem and operates without supervision. Security leaders need to understand how the technology works, where humans belong in the process, and when human review becomes a delay that attackers can exploit. Can security teams increase testing and remediation speed while still developing the practitioners they will need in the future? Listen to the episode and share your thoughts with me.
1 de 5