• Cyber Sentries: AI Insight to Cloud Security

  • By: TruStory FM
  • Podcast

Cyber Sentries: AI Insight to Cloud Security

By: TruStory FM
  • Summary

  • Dive deep into AI's accelerating role in securing cloud environments to protect applications and data. In each episode, we showcase its potential to transform our approach to security in the face of an increasingly complex threat landscape. Tune in as we illuminate the complexities at the intersection of AI and security, a space where innovation meets continuous vigilance.
    © TruStory FM
    Show More Show Less
Episodes
  • The Adaptive CISO: Digital Defense Evolution with Timothy Youngblood
    Nov 13 2024

    Securing the Digital Future with Former Fortune 500 CISO Tim Youngblood

    John Richards welcomes Timothy Youngblood, a four-time Fortune 500 CISO and current CISO in Residence at Asterix Security, to discuss the evolving landscape of cybersecurity leadership. With experience at Dell, Kimberly Clark, McDonald's, and T-Mobile, Tim brings unique insights into how security leadership must adapt to emerging threats while maintaining operational effectiveness.

    The conversation explores Tim's journey from Dell's first CISO to handling security across diverse industries. John and Tim delve into fascinating security incidents, including a notable McFlurry API DDoS attack at McDonald's, demonstrating how modern security challenges can emerge from unexpected places. The discussion shifts to the critical topic of non-human identity attacks and the growing importance of managing machine identities in cloud environments. Tim shares his perspective on how AI is reshaping security practices and why education remains fundamental to effective security programs.

    Questions we answer in this episode:

    • How do companies integrate security during acquisitions and mergers?
    • What unique challenges do global companies face in cybersecurity?
    • How should organizations approach non-human identity security?

    Key Takeaways:

    • Security leadership requires strong business acumen alongside technical expertise
    • Education and culture-building are crucial for successful security programs
    • The scale of non-human identities poses a major security blind spot for many organizations

    This episode offers invaluable insights for security professionals navigating complex organizational challenges while adapting to emerging threats. Whether you're a seasoned CISO or aspiring security leader, Tim's practical experiences and strategic approaches provide actionable wisdom for building robust security programs in any environment.


    Links & Notes

    • Securing Non-human Identities
    • Find Tim on LinkedIn
    • Learn more about Paladin Cloud
    • Got a question? Ask us here!
    • (00:04) - Welcome to Cyber Sentries
    • (01:12) - Meet Tim Youngblood
    • (08:07) - Challenges
    • (11:03) - Change Management
    • (11:37) - Transitioning to Next Role
    • (16:21) - McDonald’s
    • (19:57) - Flexibility
    • (21:50) - Handling New Challenges
    • (26:11) - Non-Human Identity Attacks
    • (33:55) - Wrap Up
    Show More Show Less
    36 mins
  • Open Source AI Unleashed: Transparency, Sovereignty, and Data Control with JJ Asghar
    Oct 9 2024

    Open Source AI: Transparency, Sovereignty, and Who Controls the Data

    In this episode of Cyber Sentries, host John Richards is joined by JJ Asghar, an Open Source Champion and Developer Advocate at IBM. They explore the importance of open source in the AI world, how transparency can allow for AI sovereignty, and why we should care about who controls the data.

    JJ shares his journey into the AI space at IBM and his strong opinions formed from working on open source AI projects. The discussion delves into the differences between mainstream closed-source AI models and the emerging open-source alternatives, highlighting the privacy and trust aspects that are becoming increasingly important, especially outside the United States.

    Questions we answer in this episode:

    • How does open source fit into the recent surge of AI?
    • What are the benefits of open-source AI models compared to closed-source ones?
    • Why is AI sovereignty important, and how does it relate to open source?

    The conversation covers the challenges of building and running AI models, the compute resources required, and how open-source approaches can provide more transparency and control. JJ explains the concept of AI sovereignty, where countries and organizations want to run AI within their borders and under their own rules and restrictions. This brings up issues of hardware accessibility and the lifecycle of AI models.

    Key Takeaways:

    • Open-source AI allows for greater transparency and trust compared to closed-source models
    • AI sovereignty is becoming increasingly important for countries with strict privacy laws
    • The lifecycle of AI involves training, fine-tuning, and inferencing, each with different compute requirements

    While open source offers many benefits, the discussion also touches on the challenges, such as the potential for model poisoning and the current lack of genealogy in AI models. Despite these hurdles, open source remains a powerful force in the AI world, with the potential to provide more eyes on the code and faster problem resolution.

    This episode offers valuable insights into the complex world of AI, the role of open source, and the importance of data control and transparency. Whether you're a developer, a security professional, or simply interested in the future of AI, this conversation provides a thought-provoking look at the challenges and opportunities ahead.

    Links & Notes

    • IBM's open source foundational model Granite
    • Granite Foundation Models Paper
    • Hugging Face
    • IBM's coding assistance project
    • InstructLab
    • Crew AI
    • AI Sovereignty Paper
    • Learn more about Paladin Cloud
    • Got a question? Ask us here!
    • (00:04) - Welcome to Cyber Sentries
    • (00:55) - Meet JJ Asghar
    • (03:17) - Working with AI
    • (04:29) - AI and Open Source
    • (10:31) - Approach
    • (14:38) - Sovereignty
    • (18:20) - Inferencing
    • (20:47) - Black Box Situation
    • (30:10) - Weighing the Differences
    • (35:09) - Timeline
    • (40:39) - Finding JJ
    • (42:06) - Communities
    • (44:49) - Wrap Up
    Show More Show Less
    46 mins
  • Demystifying Zero Trust: Key Policy Checks for Cloud Native Security with Zack Butcher
    Sep 11 2024

    Decoding Zero Trust Security for Cloud Native Environments

    In this episode of Cyber Sentries, John Richards welcomes Zack Butcher, Founding Engineer at Tetrate, to explore the critical components of zero trust security for cloud native and microservice environments. Zack, with deep expertise from his time at Google and work with NIST, shares practical insights on achieving a zero trust posture.

    John and Zack dive into the fundamental mindset shift required for zero trust - moving from implicit to explicit trust. They break down the five key policy checks that define runtime zero trust, and how these controls can enable identity-based segmentation. Zack illuminates how this approach allows organizations to boost assurance while strategically relaxing painful network-level constraints.

    Questions we answer in this episode:
    • What does Zero Trust really mean in practice?
    • How can organizations adopt a Zero Trust mindset?
    • What role does a service mesh play in Zero Trust?

    Key Takeaways:
    • Zero Trust requires making all trust explicit
    • 5 key runtime policy checks define a Zero Trust posture
    • Identity-based policies boost assurance and agility

    Whether you're wrestling with Zero Trust definitions, microservice security, or cloud native challenges, this episode delivers a wealth of battle-tested wisdom. Zack's clear explanations and examples, combined with John's knack for extracting practical takeaways, make this a must-listen for anyone navigating the complex world of cloud native security.

    Links & Notes

    • Zack on LinkedIn
    • Security Strategies for Microservices-based Application Systems (Sidebar has the A-D publications)
    • A Zero Trust Architecture Model for Access Control in Cloud-Native Applications in Multi-Cloud Environments
    • Tetrate Academy
    • Learn more about Paladin Cloud
    • Got a question? Ask us here!
    • (00:04) - Welcome to Cyber Sentries
    • (01:01) - Meet Zack
    • (04:55) - Reflecting on the Journey
    • (05:46) - Deep on Security Aspect
    • (09:52) - Zero Trust and Definitions
    • (15:35) - Consensus
    • (18:09) - Availability and Assurance
    • (22:28) - Driving Growth
    • (25:44) - How AI Can Be Used for Security
    • (30:07) - Links and Finding Zack
    • (30:36) - Wrap Up
    Show More Show Less
    33 mins

What listeners say about Cyber Sentries: AI Insight to Cloud Security

Average Customer Ratings

Reviews - Please select the tabs below to change the source of reviews.

In the spirit of reconciliation, Audible acknowledges the Traditional Custodians of country throughout Australia and their connections to land, sea and community. We pay our respect to their elders past and present and extend that respect to all Aboriginal and Torres Strait Islander peoples today.