The Business of Cybersecurity

The Business of Cybersecurity

di Neil C. Hughes
Giving AI Security Agents the Context They Need With Sola Security
What happens when an AI security agent receives access to eight enterprise systems but cannot understand the relationships between the data inside them? In this episode of The Business of Cybersecurity, I speak with Guy Flechter, CEO and co-founder of Sola Security. Guy has worked in cybersecurity for 25 years, progressing from operational security roles to the CISO position before moving into entrepreneurship. He previously founded Cider Security, which was acquired by Palo Alto Networks for $300 million. Our conversation focuses on why adding AI agents to separate security tools may increase speed without improving the quality of the decisions. Cloud, identity, SaaS, code, devices, and networks frequently operate through different consoles and data models. An agent working within one of those systems may answer confidently while missing a relationship that changes the meaning of the risk. Sola Security’s research examined 50 tasks across eight enterprise platforms. According to Guy, providing structural and relational context improved answer correctness by approximately 34% across the tested models. Under full context, 78% of responses were considered fully correct, around 18% were incomplete, and fewer than 4% were classified as complete failures. Those results show both the promise and present limitations of AI security agents. Connected context can improve performance significantly, but 78% accuracy does not support fully autonomous action in situations where an incorrect permission change or security response could have serious consequences. Guy believes human involvement will remain necessary until accuracy reaches a far higher level. We also discuss how companies should vet and onboard AI agents. Guy recommends treating an agent like a new employee by defining its permissions, monitoring its actions, controlling what it can retain, and limiting its authority until trust has been earned. The episode concludes with a discussion about independent testing. Guy argues that buyers need transparent benchmarks with visible tasks and repeatable methods, rather than vendor accuracy claims based on private evaluations. Should an AI security agent be allowed to act autonomously if its reasoning cannot be independently tested? Listen to the conversation and share your thoughts with me.
Finding Attacker Intent Before the Breach With KELA
What if criminals were discussing, selling, or preparing access to your company before anything appeared on your security dashboard? In this episode of Business of Cybersecurity, I speak with Lewis Henderson, Director of Intelligence Communications at KELA, about the criminal economy operating beyond the corporate network. We discuss how cyber threat intelligence can reveal attacker intent earlier, giving security teams time to respond before stolen access becomes a full breach. KELA’s State of Cybercrime 2026 research identified 2.86 billion stolen credentials in a single year. Lewis explains why that volume makes exposure a question of probability for many large organizations. He also describes how cybercrime as a service has lowered the technical barrier for attackers. Businesses may now face hundreds of lower-skilled criminals using purchased tools, credentials, and AI assistance instead of a small number of highly experienced groups. One example begins with an employee downloading a video game containing infostealer malware. A single stolen credential reportedly provided access to 300,000 cash registers. KELA discovered the access being discussed in a criminal market, showing why monitoring attacker activity outside the network can provide warning that internal tools may miss. We also examine alert fatigue, the limitations of point-in-time risk assessments, how criminals are experimenting with AI, and why boards should ask security leaders about threats forming across suppliers, cloud services, and the wider internet. Are companies investing enough in understanding attacker intent, or are too many waiting for the threat to arrive at their front door? Listen to the conversation and share your thoughts with me.
Closing the AI Vulnerability Remediation Gap With Cobalt
In this episode of Business of Cybersecurity, I speak with Gunter Ollmann, CTO at Cobalt, about AI powered vulnerability discovery, the widening remediation gap, continuous pentesting, legacy application risk, and the future of cybersecurity careers. Advanced security models such as Mythos can gather and apply techniques published across security research, Black Hat, DEF CON, and other industry sources. Gunter says this makes them particularly effective at reviewing large code bases and trying known attack methods against potential targets. The result is faster vulnerability discovery, but finding additional weaknesses does not automatically make a company safer. Cobalt’s 2026 State of Pentesting Report found AI and LLM tests produced high risk findings at 2.7 times the rate of its wider data set. According to Cobalt, 32% of AI and LLM findings were rated High Risk, while only 38% were resolved. Gunter sees two reasons for the gap. Companies are adding AI features to existing applications without fully understanding how the new components affect security. He compares this with the arrival of internet connectivity inside physical equipment, when engineering teams added network stacks without years of experience securing them. Supplier dependency creates another problem. When a company adds a third party model or AI service to its product, it may lack the ability to correct a weakness directly. Remediation then depends on the supplier’s development priorities and release schedule. Gunter recommends moving security testing closer to development. The traditional annual penetration test created for compliance is being replaced by a continuous cycle of monthly or quarterly human testing, daily or weekly automated scanning, and remediation connected with development pipelines. Human participation remains important, but its role is changing. Automation, machine learning, and AI have already removed many Tier 1 positions from security operations centers. The same pattern is appearing in offensive security, where junior pentesters once learned by working alongside experienced practitioners. Gunter does not see strong evidence that giving a junior analyst an AI tool automatically turns that person into a Tier 2 practitioner. Instead, some organizations are recruiting experienced professionals from IT, product management, or program management and using AI to help them acquire cybersecurity knowledge. This creates a long term talent problem. Businesses continue competing for senior practitioners while removing the junior roles that historically produced them. The industry therefore needs new ways for inexperienced candidates to learn, practice, receive feedback, and assume responsibility safely. We also discuss whether faster discovery could overwhelm senior practitioners. Gunter points out that many weaknesses being discovered by AI have existed for years. The technology is improving the industry’s ability to locate and exploit them. Defensive tools are also becoming faster at finding causes, creating fixes, and deploying updates. The remaining problem is time. If an AI system can find a vulnerability and create an exploit almost simultaneously, companies may have hours rather than weeks to respond. When an immediate code fix is unavailable, detection and blocking technologies may need to provide temporary protection. His final message is directed at CISOs. AI cannot be treated as a system that receives a problem and operates without supervision. Security leaders need to understand how the technology works, where humans belong in the process, and when human review becomes a delay that attackers can exploit. Can security teams increase testing and remediation speed while still developing the practitioners they will need in the future? Listen to the episode and share your thoughts with me.
Why Vanta Wants Boards to Measure Cyber Risk in Business Terms
In this episode of The Business of Cybersecurity, I speak with Khush Kashyap, Senior Director of Governance, Risk, and Compliance at Vanta. Khush began her career as a software engineer before moving into cybersecurity, giving her a builder’s view of governance and operational resilience. Our conversation begins with the UK Cyber Security and Resilience Bill and the demands it could place on managed service providers, data centers and designated suppliers. Proposed reporting windows could require an initial notification within 24 hours and a fuller incident report within 72 hours. Khush explains why organizations should map their supplier dependencies, define reporting responsibilities and rehearse those deadlines before a real incident tests them. We then examine what Vanta calls security theater. Khush argues that teams have spent years gathering screenshots, maintaining documents and completing questionnaires because passing an audit became the accepted measure of success. The danger is that an organization can appear compliant while controls remain poorly designed, incorrectly scoped or ineffective in daily operations. AI can compound that problem. It can generate policies, automate attestations and produce reassuring dashboards, but those outputs mean little when nobody validates the systems or checks whether the underlying controls are working. Khush also explains why shadow AI creates a larger governance problem than shadow IT. Employees can introduce copilots, models, APIs and autonomous agents that access company data or take actions without the security team knowing they exist. Her advice begins with a live inventory covering cloud assets, SaaS applications, suppliers, machine identities, AI tools and agents. We also discuss how CISOs can improve their conversations with boards. Instead of presenting compliance status as the main result, Khush recommends explaining business exposure, supplier dependencies, potential outage costs, reporting readiness and the speed at which failed controls can be detected. Can organizations turn compliance into a continuous operating discipline that protects the business every day, rather than a scramble before the next audit? Please share your thoughts with me.
Why Secure Access Is Becoming Cybersecurity's Biggest Priority with Cyolo
What happens when artificial intelligence gives cybercriminals the ability to identify, map, and exploit critical infrastructure faster than defenders can respond? For the organizations responsible for power grids, manufacturing plants, water utilities, and data centers, that question is no longer hypothetical. In this episode of The Business of Cybersecurity, I welcome Almog Apirion, CEO and Co-Founder of Cyolo, to discuss why the rules of defending operational technology are changing. Drawing on his experience leading the Israeli Navy's cyber unit and serving as a CISO before founding Cyolo, Almog shares why the rise of AI-powered attacks demands a renewed focus on the security fundamentals many organizations have overlooked. One of the strongest messages from our conversation is that AI has dramatically lowered the barrier for attackers. Capabilities that once required highly skilled specialists are now becoming accessible to a much wider range of threat actors. Rather than spending weeks researching vulnerable systems, attackers can now automate reconnaissance, identify weak points, and prepare attacks at unprecedented speed. That leaves defenders with far less time to react. Instead of relying solely on detection and response, Almog argues that businesses must build security into their environments from the beginning. We discuss why identity controls, multi-factor authentication, segmentation, and tightly governed access remain some of the most effective ways to reduce cyber risk, even as AI continues to reshape the threat landscape. Sometimes the simplest security controls still prevent the biggest attacks. Our conversation also examines why traditional VPN-based remote access has become increasingly difficult to justify inside critical infrastructure. Almog explains why giving users access to an entire network creates unnecessary exposure when modern approaches can limit access to only the specific systems people need to perform their work. That principle sits at the heart of mature zero trust strategies, where every connection is verified and every action is tightly controlled. Another area we explore is microsegmentation and why it is becoming an increasingly important part of protecting operational technology. Rather than assuming attacks can always be prevented, organizations should prepare for the possibility of compromise and focus on limiting how far an attacker can move through a network. Reducing the blast radius can often make the difference between a contained security incident and a major operational disruption. We also discuss the practical challenges security leaders face every day. Replacing legacy remote access tools, introducing zero trust without disrupting production, supporting third-party vendors, and maintaining always-on access for mission-critical operations all require careful planning. Almog explains why cybersecurity cannot come at the expense of uptime, particularly in industries where every minute of disruption carries real-world consequences. This conversation serves as a timely reminder that while AI is changing both sides of cybersecurity, the strongest defenses are still built on solid foundations. As attackers become faster and more automated, organizations must ensure that identity, access, segmentation, and resilience are designed into their environments from the start rather than added after an incident occurs. If AI is making attacks faster, should security teams spend less time chasing alerts and more time reducing opportunities for attackers altogether? And are the foundations of your security strategy strong enough for the threats that already exist today? I'd love to hear your thoughts after listening.
Mimecast CISO On Why AI Has Become A Cybersecurity Risk
What happens when the technology designed to make us more productive quietly becomes one of the biggest security risks inside the enterprise? In this episode of The Business of Cybersecurity, I sit down with Leslie Nielsen, CISO at Mimecast, to discuss the growing tension between AI adoption and cybersecurity, and why many organizations may be exposing sensitive information faster than they realize. As businesses race to deploy generative AI, AI agents, and Model Context Protocol integrations, Leslie explains why AI models themselves are becoming valuable targets. When organizations pool large volumes of sensitive data into centralized AI systems, they create what he describes as a corporate brain, one that can quickly become attractive to attackers if the right controls are not in place. We explore the rise of shadow AI, where employees use unsanctioned AI tools to meet deadlines and improve productivity, often without understanding the long-term consequences. Leslie shares why a simple upload of financial data, customer information, or proprietary documents into a public AI platform can create risks that traditional security teams struggle to contain once the information has entered a large language model. The conversation also examines the changing nature of insider threats. From negligent behavior to deliberate misuse of credentials, attackers are increasingly targeting employees directly. Leslie discusses how AI is making it easier for threat actors to identify vulnerable individuals, while growing concerns around job displacement may create new pressures inside organizations. We also discuss why visibility remains one of the biggest cybersecurity challenges facing modern enterprises. As AI changes data flows, communication channels, and user behavior, many organizations are discovering that traditional security controls were never designed for the speed and complexity of today's AI-powered environments. Leslie explains why cybersecurity leaders need to become AI champions rather than blockers, helping businesses adopt AI safely while maintaining visibility, governance, and trust. Looking ahead, Leslie remains optimistic about using AI to strengthen cyber defenses. As attackers embrace AI, defenders are doing the same, creating a new chapter in cybersecurity where automation, intelligence, and human expertise will work together to protect organizations from emerging threats. How is your organization balancing AI innovation with security, and are you confident you can see where your data is really going? Share your thoughts with me.
Orange Cyberdefense On The New FCA Cyber Reporting Rules
What happens when your biggest cybersecurity risk isn't inside your organization at all, but somewhere deep within your supply chain? In this episode of The Business of Cybersecurity, I sit down with Ben Gibbins, Head of Financial Services and Insurance at Orange Cyberdefense UK, to discuss the Financial Conduct Authority's new cyber incident and third-party reporting requirements and what they mean for financial institutions facing a March 2027 compliance deadline. The conversation begins with a striking statistic. More than 40% of cyber incidents reported to the FCA involved at least one third party, highlighting how interconnected digital ecosystems have created new points of vulnerability across financial services. Ben explains why attackers are increasingly targeting suppliers, service providers, and technology partners to gain access to larger organizations, and why regulators are becoming increasingly concerned about concentration risk across critical infrastructure. We also tackle one of the biggest misconceptions surrounding the new FCA requirements. Many organizations assume that compliance with the EU's Digital Operational Resilience Act (DORA) automatically prepares them for the UK's reporting obligations. Ben explains why that assumption could leave firms exposed, outlining the differences between the two frameworks and the additional work many organizations still need to complete. Our discussion explores operational resilience, supply chain visibility, incident reporting, and the practical realities of responding to cyber incidents while simultaneously meeting regulatory expectations. Ben shares insights on why organizations need a far better understanding of third-, fourth-, and even fifth-party dependencies, and why traditional approaches to supplier risk management are struggling to keep pace with today's interconnected business environment. We also examine how collaboration between regulators, cybersecurity providers, threat intelligence specialists, and financial institutions could help strengthen collective defenses against increasingly sophisticated threats. From cyber extortion campaigns to supply chain attacks affecting hundreds of organizations simultaneously, the discussion highlights why resilience has become as important as prevention. If your organization assumes compliance is already covered, this conversation may prompt a second look. Are businesses truly prepared for the next phase of cyber resilience reporting, or are many still underestimating the risks hidden within their supply chains? Share your thoughts with me.
Deepfakes, AI Agents, and the Collapse of Traditional Identity Security
How do you defend trust in a world where AI can imitate voices, generate highly convincing phishing attacks, and automate fraud at a scale humans can barely keep up with? In this episode of Business of Cybersecurity, I sit down with Mary Ann Miller from Prove to discuss how AI is reshaping fraud, identity, and cybersecurity in ways many organizations are still struggling to understand fully. With decades of experience across banking, fintech, and fraud prevention, Mary Ann brings a unique perspective on the growing collision between customer experience, digital identity, and AI-driven attacks. We explore how cybercriminals are using contextual AI-powered phishing campaigns that feel increasingly believable, why account takeover attacks are evolving into AI-assisted operations, and what happens when human intuition is no longer enough to identify deepfakes and manipulated content online. Mary Ann explains why the traditional idea of identity verification at login is beginning to break down, especially as one-time passwords and legacy authentication methods become easier to exploit. The conversation also examines the rise of “continuous identity,” in which organizations must continually evaluate trust signals across the customer journey rather than relying on a single authentication event. Mary Ann shares why many organizations are investing heavily in AI innovation while simultaneously lacking the controls needed to defend themselves against AI-driven fraud. We also discuss how non-human identities, AI agents, and automated interactions are introducing new risks that many businesses are still unprepared for. There is also a fascinating discussion around how AI has quietly powered fraud detection systems for decades, from early neural networks monitoring payment anomalies to today’s far more advanced machine learning systems. But as organizations race to introduce AI-powered customer experiences, Mary Ann warns that customer trust and adoption cannot be taken for granted. She shares the example of Walmart reportedly seeing a major drop in conversions during an AI-driven commerce experiment, highlighting how businesses are still learning where AI genuinely improves experiences and where it creates friction. Mary Ann also offers practical advice for boards and security leaders on how to proactively test their defenses through fraud red-team exercises, why organizations need to recognize AI-generated attack patterns earlier, and how businesses can rethink identity in a world where both humans and machines participate in digital interactions. If you care about the future of trust, authentication, fraud prevention, and cybersecurity in the AI era, this conversation offers a valuable look at the challenges already unfolding behind the scenes.
When Identity Becomes The Front Line Of Cybersecurity
What happens when the biggest cybersecurity weakness inside your organization isn’t your infrastructure, but the people using it every day? In this episode of Business of Cybersecurity, I speak with David Cottingham, president of rf IDEAS, about why identity has become one of the most targeted attack surfaces in modern business. From phishing attacks powered by AI to the growing risks tied to compromised credentials, David explains why traditional password habits continue to expose organizations across healthcare, manufacturing, finance, and enterprise environments. Our conversation looks at the uncomfortable reality that while businesses have spent years hardening infrastructure, attackers have shifted their attention toward human behavior. David shares why fully passwordless environments may still be out of reach for many organizations, but why the move toward stronger authentication methods, secure second factors, mobile credentials, passkeys, and biometric workflows is already reshaping how businesses think about trust and access. We also discuss the growing tension between stronger security and employee productivity. From clinicians accessing patient records in hospitals to workers authenticating on factory floors, David explains why security tools only succeed when they fit naturally into real-world workflows. The episode also explores the convergence of physical and logical security, the dangers of outdated proximity cards, and how layered security strategies still matter in an age shaped by AI-driven threats. Along the way, David shares what he’s hearing from organizations at industry events, why many leaders feel overwhelmed by identity decisions, and how companies can future-proof their authentication strategies without disrupting existing systems overnight. If identity is now the new perimeter, how should organizations rethink trust before the next breach forces the conversation?
Index Engines On Why Cyber Resilience Has Become A Boardroom Issue
What happens when ransomware stops being treated as a cybersecurity problem and starts being viewed as a direct threat to business survival? In this episode of Business of Cybersecurity, I sat down with Jim McGann, CMO at Index Engines, to unpack why 2026 is shaping up to be one of the most dangerous years yet for organizations facing increasingly sophisticated cyberattacks. Jim shared how ransomware gangs are evolving into highly organized operations powered by AI, automation, and ransomware-as-a-service models that dramatically lower the barrier to entry for attackers. From healthcare systems and transportation networks to retailers and city infrastructure, no sector appears off limits anymore. We explored why traditional disaster recovery strategies built for floods or hardware failures are no longer enough when attackers actively corrupt backups, manipulate databases, and target recovery systems themselves. A major focus of our conversation centered on the idea of “Return on Risk” or ROR, a shift away from viewing cybersecurity purely through an ROI lens. Jim explained why boards and executives need to stop treating ransomware as an isolated IT issue and instead recognize it as a business continuity crisis capable of damaging reputation, customer trust, revenue, and regulatory standing in a matter of hours. He shared real-world stories of organizations discovering their backups had been deleted, deepfake scams impersonating executives, and attackers infiltrating recovery planning meetings themselves. We also discussed how Index Engines’ CyberSense platform approaches cyber resilience differently by validating the integrity of recovery data and helping organizations identify clean copies of data with a 99.99% detection SLA for ransomware corruption. Jim explained why assuming compromise has become essential and why organizations must rehearse recovery strategies long before disaster strikes. This conversation goes far beyond technical defenses. It examines trust, operational resilience, leadership accountability, and what happens when businesses fail to answer one simple but uncomfortable question: “How quickly can we recover if everything goes down tomorrow?” Are organizations finally starting to accept that prevention alone is no longer enough, or are too many still hoping they will somehow avoid becoming the next headline? Useful Links Connect with Jim McGann Learn more about Index Engines Please check the partners of the Tech Tech Talks Network Learn more about the NordLayer Browser Visit Denodo.com
1 di 5