Info

Enterprise Security Weekly (Video)

News, analysis, and insights into enterprise security. We put security vendors under the microscope, and explore the latest trends that can help defenders succeed. Hosted by Adrian Sanabria. Co hosts: Katie Teitler-Santullo, Ayman Elsawah, Jason Wood, Jackie McGuire, Sean Metcalf.
RSS Feed Subscribe in Apple Podcasts
Enterprise Security Weekly (Video)
2026
February
January


2025
December
November
October
September
August
July
June
May
April
March
February
January


2024
December
November
October
September
August
July
June
May
April
March
February
January


2023
December
November
October
September
August
July
June
May
April
March
February
January


2022
December
November
October
September
August
July
June
May
April
March
February
January


2021
December
November
October
September
August
July
June
May
April
March
February
January


2020
December
November
October
September
August
July
June
May
April
March
February
January


2019
December
November
October
September
August
July
June
May
April
March
February
January


2018
December
November
October
September
August
July
June
May
April
March
February
January


2017
December
November
October
September
August
July
June
May
April
March
February
January


2016
December
November
October
September
August
July
June
May
April


Categories

All Episodes
Archives
Categories
Now displaying: October, 2025
Oct 27, 2025

Segment 1: Interview with Dave Lewis from 1Password

In this week's sponsored interview, we dive into the evolving security landscape around AI agents, where we stand with AI agent adoption. We also touch on topics such as securing credentials in browser workflows and why identity is foundational to AI agent security.

This segment is sponsored by 1Password. Visit https://securityweekly.com/1password to learn more!

Segment 2: Enterprise News

In this week's enterprise security news,

  1. one big acquisition, two small fundings
  2. not all AI is bad
  3. deepfakes are getting crazy good
  4. make sure you log what your AI agents do
  5. Copilot prompt injection
  6. NordVPN tries to pull a jedi mind trick on us
  7. failure rate in AI adoption is a feature not a bug?
  8. using facial recognition to find Tinder profiles
  9. a predictable squirrel story

All that and more, on this episode of Enterprise Security Weekly.

Segment 3: Two interviews from Oktane 2025

Interview with Connor Mulherin of TechSoup

The cybersecurity landscape in the nonprofit sector is evolving quickly, with organizations facing unique challenges due to limited resources, sensitive mission-driven work, and developing policies and training programs. Connor Mulherin, Director and GM of Validation Services at TechSoup, will discuss the industry's need for accessible and collaborative solutions to provide affordable technology leadership and security guidance. It will highlight how nonprofit organizations can build long-term digital resilience and combat these growing challenges.

Segment Resources:

Interview with Mike Poole, Director of Cyber Security at Werner Enterprises

In today's digital landscape, cybersecurity is not just a technical issue—it’s a business imperative. Organizations that prioritize cybersecurity culture see fewer incidents and stronger resilience against evolving threats. But how do you foster a security-first mindset across an organization?

This session will explore the critical components of building and maintaining a robust cybersecurity culture, starting with executive leadership buy-in—a fundamental step in securing resources and driving organizational change. We’ll then dive into the power of monthly phishing exercises, which reinforce awareness and preparedness. Attendees will also learn how to develop effective training programs that engage employees at all levels and create lasting behavioral change. Finally, we’ll discuss the role of cybersecurity-themed events, particularly during Cybersecurity Awareness Month, as a powerful tool to capture attention and reinforce key security principles.

This segment is sponsored by Oktane by Okta. Visit https://securityweekly.com/oktane to learn more about them!

Show Notes: https://securityweekly.com/esw-430

Oct 20, 2025

Segment 1: David Brauchler on AI attacks and stopping them

David Brauchler says AI red teaming has proven that eliminating prompt injection is a lost cause. And many developers inadvertently introduce serious threat vectors into their applications – risks they must later eliminate before they become ingrained across application stacks.

NCC Group’s AI security team has surveyed dozens of AI applications, exploited their most common risks, and discovered a set of practical architectural patterns and input validation strategies that completely mitigate natural language injection attacks. David's talk aimed at helping security pros and developers understand how to design/test complex agentic systems and how to model trust flows in agentic environments. He also provided information about what architectural decisions can mitigate prompt injection and other model manipulation risks, even when AI systems are exposed to untrusted sources of data.

More about David's Black Hat talk:

Additional blogs by David about AI security:

Segment 2: Should we replace the CIA triad?

An op-ed on CSO Online made us think - should we consider the CIA triad 'dead' and replace it? We discuss the value and longevity of security frameworks, as well as the author's proposed replacement.

Segment 3: The Weekly Enterprise News

Finally, in the enterprise security news,

  1. Slow week for funding, older companies raising via debt financing
  2. A useful AI framework from the Cloud Security Alliance
  3. two interesting essays, one of which is wrong
  4. Folks are out here blasting unencrypted data to and from Satellites, while anyone can sniff and capture it
  5. getting hacked during a job interview
  6. LLM poisoning is far easier than previously thought
  7. F5 got breached
  8. Be careful when patching your Jeep (’s software)

All that and more, on this episode of Enterprise Security Weekly.

Show Notes: https://securityweekly.com/esw-429

Oct 13, 2025

Segment 1 - Interview with Dr. Anand Singh

We're always thrilled to have authors join us to discuss their new book releases, and this week, it is Dr. Anand Singh. He seriously hustled to get his new book, Data Security in the Age of AI, out as soon as possible so that it could help folks dealing with securing AI rollouts right now! We'll discuss why he wrote it, how he got it done so quickly, and who needs to read it.

Segment Resources:

Segment 2 - Topic: The reasons why CISOs buy (and the things that don't matter to them)

Val Tsanev, founder of ExecWeb, part of the CyberRisk Alliance family, posted shared some VERY spicy insights about how CISOs buy products. This elicited some passionate responses.

There are many interesting insights, but the biggest and most interesting is that 76% of CISOs choose products that presents the least risk to them, personally. Career safety trumps product performance, it would seem.

Segment 3 - News

In the enterprise security news,

  1. Shifting Zero
  2. Cyber insurance, unlike cyber crime, doesn’t pay
  3. New AI security categories are popping up to serve Agentic and MCP servers
  4. how tech companies measure AI impact
  5. first malicious MCP server in the wild
  6. is your computer mouse listening to you?
  7. The Korean government did not follow the backup rule of three
  8. Think you’ve seen the absolute worst idea for a mobile app? Wait until you hear about Neon.
  9. We have no less than three squirrel stories involving bullets, lasers, and greasy snacks

All that and more, on this episode of Enterprise Security Weekly.

Show Notes: https://securityweekly.com/esw-428

Oct 6, 2025

At Oktane 2025, leaders from across the security ecosystem shared how identity has become the new front line in protecting today’s AI-driven enterprises. As SaaS adoption accelerates and AI agents proliferate, organizations face an explosion of human and non-human identities—and with it, growing risks like misconfigured access, orphaned accounts, and identity-based attacks.

In this special Enterprise Security Weekly episode, we bring together insights from top experts:

  • Dor Fledel (Okta) explains how teams can gain visibility into AI agents, uncover risks, and enforce appropriate access controls.
  • Alexander Makarov (Adyen) shares how a global fintech unified and streamlined identity with Okta, improving both security and employee experience across 200+ countries.
  • Aaron Parecki (Okta) highlights the importance of open standards—like IPSIE, MCP, and A2A—for building secure, interoperable AI ecosystems and centralized control over AI-driven interactions.
  • Heather Ceylan (Box) discusses how Box embeds AI into workflows to enhance data protection, even for highly regulated industries.
  • Matt Immler (Okta) offers lessons from the field on strengthening defenses with behavioral monitoring, automation, and a security-first culture to counter attackers who now “log in” instead of hacking in.
  • Nitin Raina (Thoughtworks) warns about AI-driven social engineering—from deepfakes to multi-channel phishing—and shares practical strategies like phishing-resistant MFA, zero-trust architecture, and better employee training.

From open standards to privileged access management and AI-powered defense, these Oktane 2025 conversations explore how identity-driven strategies are shaping the future of enterprise security.

Segment Resources: https://www.okta.com/newsroom/articles/old-security-challenges--new-ai-risks--managing-authorization-in https://www.okta.com/newsroom/press-releases/okta-introduces-cross-app-access-to-help-secure-ai-agents-in-the/ https://www.okta.com/blog/ai/securing-the-ai-agent-ecosystem/ https://www.okta.com/customers/adyen/ https://www.okta.com/newsroom/?sort=featured&filters=okta%3Acategories%2Fidentity-security https://www.okta.com/customers/thoughtworks/

This segment is sponsored by Oktane by Okta. Visit https://securityweekly.com/oktane to learn more about them!

Show Notes: https://securityweekly.com/esw-427

1