45 episodios
EP 41 - iMerit Technology's Georgeo X. Pulikkathara on the 82 non-human accounts created for every human one
26/08/2026 | 39 minWhat if the file itself decided who gets access, carried its own encryption, and refused unauthorized requests? Georgeo X. Pulikkathara, Global CIO and CISO at iMerit Technology, sees that future arriving fast.
With 34 years in IT security and active service as a Colonel in the US Army Reserve, Georgeo breaks down 40-minute AI-enabled breaches, the flood of non-human accounts, and why human oversight remains the one control that will never go away.
Topics discussed:
34 years in IT security and Army Reserve service
iMerit Technology's AI data solutions
AI-enabled attacks and the 40-minute breach
Non-human accounts flooding enterprise networks
Human-in-the-loop oversight for AI systems
Self-protecting data with built-in encryption
Quantum-resistant encryption and post-quantum security
Competency, character, and commitment in security teams
Get in touch with your host, Jean Le Bouthillier:
LinkedIn
Listen to more episodes:
Apple
Spotify
YouTubeEP 40 - Avanade's Jon Rohrich on why security teams should start with why before deploying AI
11/08/2026 | 25 minGartner predicts 40% of enterprise applications will incorporate agentic AI by year's end, but Jon Rohrich is asking a more basic question: why? Leading Avanade's Canadian cybersecurity practice with nearly 30 consultants, Jon keeps watching proof of concepts succeed, only to collapse when unmodeled risks surface in production.
Jon tells Jean why zero trust is the right framework for governing AI agents, how to challenge stakeholders stuck in outdated security programs, and what a candidate's home lab reveals about their real passion for security.
Topics discussed:
Applying zero trust principles to AI agent access control
Why proof of concepts collapse at production scale
Managing AI agent identities like human user identities
Board pressure to deploy AI without proper threat modeling
Using lab environments to evaluate technical passion in hiring
Challenging long-tenured stakeholders to modernize security programs
Recognizing and overcoming imposter syndrome in cybersecurity careers
Get in touch with your host, Jean Le Bouthillier:
LinkedIn
Listen to more episodes:
Apple
Spotify
YouTubeEP 39 - Podium's Taylor Lobb on why AI agents should read files but never export them
29/07/2026 | 26 minGiving an AI agent your access does not mean giving it your judgment. The fix is data that knows the difference, so the same document a person can export, an agent can only summarize, never share externally, never train on.
Taylor Lobb, Chief Security Officer at Podium, tells Jean why identity now covers agents and service accounts, how visibility beats blocking shadow AI, and why every agentic workflow needs its own scoped security agent.
Topics discussed:
- Extending identity models to agents, APIs, and service accounts
- Making data identity-aware so access matches the requester
- Beating shadow AI with visibility instead of blocking tools
- Pairing every agentic workflow with a scoped security agent
- Why build-versus-buy has inverted for AI-native engineering teams
- Vendor value shifting from interfaces to proprietary data enrichment
- Running security as an enablement and partnership function
- Exposing tool data through MCP for internally built systems
Get in touch with your host, Jean Le Bouthillier:
LinkedIn
Listen to more episodes:
Apple
Spotify
YouTubeEP 38 — Capital One's Leon Bian on why IAM tells you who but agentic AI needs to know why
14/07/2026 | 26 minAI is not creating a new data problem. Leon Bian, VP and Head of Product, AI & Data Security (Databolt) at Capital One, argues it is exposing the ones enterprises already had: fragmented data, unclear ownership, weak classification, and broad access controls never designed for agents running at machine speed. At most enterprises, 80 to 90 percent of that data is unstructured, and until recently it was almost entirely outside the scope of protection.
Leon tells Jean why three controls most large organizations treat as solved fail the moment agentic AI enters the picture: strong IAM, role-based and attribute-based access, and on-behalf-of-user permissions. IAM tells you who is asking, not whether they should access specific data for a specific purpose. RBAC and ABAC tell you who and what and when, but agentic AI requires a fourth dimension: why. And when agents inherit user permissions accumulated over years, you get permission creep running at machine speed. He also lays out why frontier AI models collapsing the time from vulnerability discovery to exploitation to near zero demands a hardened data layer as the last line of defense, and why using AI to close vulnerabilities is no longer optional.
Topics discussed:
AI revealing data problems enterprises already had
Why strong IAM is a false signal of data security
RBAC and ABAC insufficient when agent context determines risk
Intent as the missing governance dimension in agentic AI
On-behalf-of-user access enabling permission creep at machine speed
Frontier models collapsing vulnerability-to-exploitation timelines to near-zero
Using AI to close vulnerabilities at machine speed
Tokenization preserving data utility and referential integrity where encryption cannot- Vivek Menon's board stopped asking about patching schedules and vulnerability counts. Their questions now center on AI risk posture, and the governance tools meant to answer them lag one to two months behind at best. Vivek, CISO and Head of Enterprise Data at Digital Turbine, tells Jean how he runs AI SOC agents that compressed a 10-person workload to 4 while holding headcount flat from this point forward.
Vivek also breaks down the agentic AI risks he tracks in active pilots: executives with the most privileged access and the most sensitive data on their laptops are the ones pushing hardest for adoption, sub-agents spawn and drift from original tasks with decreasing oversight, and an employee at his company recently downloaded a malicious tax prep skill from an AI marketplace. He frames the current cost picture as opex capping rather than opex saving, and predicts the CISO role is already converging with data trust into something closer to a Chief Data Trust Officer.
Topics discussed:
Shadow AI lapping shadow IT as top ungoverned risk
Privileged executives as high-risk AI adopters
Sub-agent spawning and diminishing task control
Malicious AI marketplace skills targeting employees
AI SOC agents compressing 10-person teams to 4
AI governance tools lagging months behind board questions
Opex capping through older models for 98% of use cases
CISO role converging into Chief Data Trust Officer
Get in touch with your host, Jean Le Bouthillier:
LinkedIn
Listen to more episodes:
Apple
Spotify
YouTube
Más podcasts de Tecnología
Podcasts a la moda de Tecnología
Acerca de Future of Data Security
Welcome to Future of Data Security, the podcast where industry leaders come together to share their insights, lessons, and strategies on the forefront of data security. Each episode features in-depth interviews with top CISOs and security experts who discuss real-world solutions, innovations, and the latest technologies that are shaping the future of cybersecurity across various industries. Join us to gain actionable advice and stay ahead in the ever-evolving world of data security.
Sitio web del podcastEscucha Future of Data Security, Apple Events y muchos más podcasts de todo el mundo con la aplicación de radio.net

Descarga la app gratuita: radio.net
- Añadir radios y podcasts a favoritos
- Transmisión por Wi-Fi y Bluetooth
- Carplay & Android Auto compatible
- Muchas otras funciones de la app
Descarga la app gratuita: radio.net
- Añadir radios y podcasts a favoritos
- Transmisión por Wi-Fi y Bluetooth
- Carplay & Android Auto compatible
- Muchas otras funciones de la app


Future of Data Security
Escanea el código,
Descarga la app,
Escucha.
Descarga la app,
Escucha.
Future of Data Security: Podcasts del grupo



























