Resilient Cyber
Resilient Cyber brings listeners discussions from a variety of Cybersecurity and Information Technology (IT) Subject Matter Experts (SME) across the Public and Private domains from a variety of industries. As we watch the increased digitalization of our society, striving for a secure and resilient ecosystem is paramount.
Episodes
227 episodes
The Model Writing Your Code Shouldn't Be Securing It
Jonathan Rende of Checkmarx on why the model writing your code cannot also be the control that validates it, and why rules-based and AI-driven scanning turn out to find almost entirely different bugs.In this episode I sit down with Jona...
The First OWASP Top 10 Backed by Real Incident Data
Rock Lambros, Co-Lead of the 2026 OWASP Top 10 for LLM Applications, on why prompt injection would have fallen out of the top 10 based on incident data alone, and why the community kept it at number one anyway.In this episode I s...
The Jagged Frontier of Finding and Fixing Vulns with AI
Ondrej Vlcek, CEO of AISLE and former CEO of Avast, on why AI vulnerability discovery is not as commoditized as the industry thinks, and why remediation is still the real bottleneck.In this episode I sit down with Ondrej Vlcek, Founder ...
Secure Vibe Coding and the 99%
Lovable CISO Igor Andriushchenko on soft guardrails vs. hard boundaries, securing vibe coding for non-developers, and building a security program at a 10x company.I sit down with Igor Andriushchenko, Head of Security and CISO at Lovable,...
Building a System of Truth for the CISO
CISOs have a stack of tools but no system built to run the security program itself. Mike Armistead wants to fix that.In this episode I sit down with Mike Armistead, co-founder and CEO of Pulse Security AI and a longtime security founder...
The Real Price Tag On Cyber Breaches
Alex Pinto, who leads Verizon's DBIR team, joins me to break down the new Breach Impact Study and what data breaches actually cost organizations.For years the industry has argued past itself on breach costs. One camp says the market doe...
Cyber Investing in the AI Exploit Era
What happens to security investing when vulnerability discovery becomes continuous and exploitation windows shrink from weeks to hours? I sit down with Chenxi Wang of Rain Capital to dig into it.Chenxi is the Founder and Managing General...
AI, Bug Bounties & the Vulnerability "Slopdemic"
Bugcrowd founder Casey Ellis joins me to dig into what AI is actually doing to bug bounties, vulnerability discovery, and open source security. We get into his "slopdemic" framing, the curl bug bounty saga, VDP readiness, the pentest market cor...
AI's Cyber Boom
Jon Sakoda of Decibel joins me to break down AI's impact on cybersecurity startups, venture funding, and why endpoint is the Super Bowl of cyber.Jon is the Founding Partner at Decibel, an early-stage firm backing technical founders in se...
Why AI Security Is Getting Rebuilt From Scratch
In this episode I sit down with Ed Sim, founder and managing partner of Boldstart Ventures, to dig into where AI security, agentic infrastructure, and the venture market are actually heading.Ed has been an inception-stage investor for n...
Resilient Cyber w/ Joshua Saxe - Why Restricting AI Makes Us Less Secure
Does restricting frontier AI in the name of safety actually make us less secure? Joshua Saxe joins me to make the case that it does, and that AI cybersecurity will be won through defender adoption, not restriction.Josh has spent 15 year...
Cyber Valuations, Moats & the Road to Black Hat
Cybersecurity investor Sid Trivedi of Foundation Capital joins me to dig into AI SOC valuations, services-as-software, moats, and what founders should know heading into Black Hat.Sid is a Partner at Foundation Capital, where he invests ...
Building an AI AppSec Engineer
JJ of Gecko Security and former Disney and Costco CISO Ryan Knisley on why AppSec needs an AI security engineer, not another scanner.DescriptionAppSec has been stuck for year...
Why Finding Vulnerabilities Was Never the Hard Part
Every headline wants you to believe AI has rewritten the rules of cybersecurity. Eric Doerr, the Chief Product Officer at
Rain Versus Flood, Making Sense of the 2026 CVE Surge
CVEs are on pace to hit nearly 70,000 in 2026, but Jerry Gamblin explains why the actual exploitable risk is staying surprisingly flat.DescriptionJerry Gamblin runs RogoLabs and built CVE.ICU, and he co-authored the FIRST m...
You Don't Need A Frontier Model to Find Zero Days
Niels Provos on why you don't need a frontier model to find zero days, why the Vulnpocalypse is overstated, and how security invariants change the game.DescriptionNiels Provos has spent twenty-five years in security, from w...
AI Industrialized the Vuln Lifecycle and Broke the System of Record
VulnCheck's Patrick Garrity on the NVD collapse, the first real AI disclosure wave, and why remediation, not finding bugs, is the bottleneck.DescriptionVulnerability management spent years as the chore everyone dreaded, and...
AI Is Winning the Cyber Arms Race
For twenty years the security playbook started in the same place, find a vulnerability, prioritize it, and patch it. Doug Merritt, CEO of Aviatrix and former CEO of Splunk, thinks that playbook is quietly breaking, and his explanation has nothi...
Securing the Agentic SDLC
In this episode of Resilient Cyber, I sit down with Katie Norton, Research Manager for DevSecOps and Software Supply Chain Security at IDC, to unpack what application security looks like as AI moves from copilot to autonomous teammate across th...
The Agentic GRC Revolution
In this episode, we sat down with Richa Kaul, CEO of Complyance, the AI-first enterprise GRC platform that recently raised a $20M Series A led by GV (Google Ventures), to dig into how legacy GRC is fina...
Identity as Infrastructure in the Agentic Era
In this episode of Resilient Cyber, I sat down with Karl McGuinness — author of Control Plane and one of the sharpest voices working on identity in the agentic era — to unpack what most of the industry is still getting wrong about IAM ...
Why AI Security Feels So Fragile
AI security feels fragile right now — and in this episode, Ron Bennatan, VP of Strategy, AI and Database Security at Varonis and founder of Guardium, JSonar, and AllTrue.ai, explains exactly why.Ron unpacks what "fragile" actually means ...
You Can't Trust What You Can't Verify — The Case for AI Model Identity
Most organizations deploying AI today cannot answer a deceptively simple question. Which model is actually running in their environment?It is not a hypothetical concern. Model substitution, supply chain compromise, adversarial fin...
Securing the Vibe: Tanya Janca on AI-Generated Code, Mythos, and the New AppSec Reality
A new episode of the Resilient Cyber Show just dropped, and this one is a conversation I’ve been looking forward to for a long time.I sat down with Tanya Janca, better known to most of the AppSec world as SheHacksPurple. Ta...