43 episodios
EP 39 - Podium's Taylor Lobb on why AI agents should read files but never export them
29/07/2026 | 26 minGiving an AI agent your access does not mean giving it your judgment. The fix is data that knows the difference, so the same document a person can export, an agent can only summarize, never share externally, never train on.
Taylor Lobb, Chief Security Officer at Podium, tells Jean why identity now covers agents and service accounts, how visibility beats blocking shadow AI, and why every agentic workflow needs its own scoped security agent.
Topics discussed:
- Extending identity models to agents, APIs, and service accounts
- Making data identity-aware so access matches the requester
- Beating shadow AI with visibility instead of blocking tools
- Pairing every agentic workflow with a scoped security agent
- Why build-versus-buy has inverted for AI-native engineering teams
- Vendor value shifting from interfaces to proprietary data enrichment
- Running security as an enablement and partnership function
- Exposing tool data through MCP for internally built systems
Get in touch with your host, Jean Le Bouthillier:
LinkedIn
Listen to more episodes:
Apple
Spotify
YouTubeEP 38 — Capital One's Leon Bian on why IAM tells you who but agentic AI needs to know why
14/07/2026 | 26 minAI is not creating a new data problem. Leon Bian, VP and Head of Product, AI & Data Security (Databolt) at Capital One, argues it is exposing the ones enterprises already had: fragmented data, unclear ownership, weak classification, and broad access controls never designed for agents running at machine speed. At most enterprises, 80 to 90 percent of that data is unstructured, and until recently it was almost entirely outside the scope of protection.
Leon tells Jean why three controls most large organizations treat as solved fail the moment agentic AI enters the picture: strong IAM, role-based and attribute-based access, and on-behalf-of-user permissions. IAM tells you who is asking, not whether they should access specific data for a specific purpose. RBAC and ABAC tell you who and what and when, but agentic AI requires a fourth dimension: why. And when agents inherit user permissions accumulated over years, you get permission creep running at machine speed. He also lays out why frontier AI models collapsing the time from vulnerability discovery to exploitation to near zero demands a hardened data layer as the last line of defense, and why using AI to close vulnerabilities is no longer optional.
Topics discussed:
AI revealing data problems enterprises already had
Why strong IAM is a false signal of data security
RBAC and ABAC insufficient when agent context determines risk
Intent as the missing governance dimension in agentic AI
On-behalf-of-user access enabling permission creep at machine speed
Frontier models collapsing vulnerability-to-exploitation timelines to near-zero
Using AI to close vulnerabilities at machine speed
Tokenization preserving data utility and referential integrity where encryption cannot- Vivek Menon's board stopped asking about patching schedules and vulnerability counts. Their questions now center on AI risk posture, and the governance tools meant to answer them lag one to two months behind at best. Vivek, CISO and Head of Enterprise Data at Digital Turbine, tells Jean how he runs AI SOC agents that compressed a 10-person workload to 4 while holding headcount flat from this point forward.
Vivek also breaks down the agentic AI risks he tracks in active pilots: executives with the most privileged access and the most sensitive data on their laptops are the ones pushing hardest for adoption, sub-agents spawn and drift from original tasks with decreasing oversight, and an employee at his company recently downloaded a malicious tax prep skill from an AI marketplace. He frames the current cost picture as opex capping rather than opex saving, and predicts the CISO role is already converging with data trust into something closer to a Chief Data Trust Officer.
Topics discussed:
Shadow AI lapping shadow IT as top ungoverned risk
Privileged executives as high-risk AI adopters
Sub-agent spawning and diminishing task control
Malicious AI marketplace skills targeting employees
AI SOC agents compressing 10-person teams to 4
AI governance tools lagging months behind board questions
Opex capping through older models for 98% of use cases
CISO role converging into Chief Data Trust Officer
Get in touch with your host, Jean Le Bouthillier:
LinkedIn
Listen to more episodes:
Apple
Spotify
YouTube EP 36 — ruby's George Al-Koura on why 15 certifications still won't save you in a live SOC scenario
20/05/2026 | 51 minGeorge Al-Koura refuses to let AI agents run in his production environment. As CISO at ruby, the parent company of Ashley Madison, he's protecting data where a breach doesn't just expose PII but reveals people's most private thoughts and relationships across a global user base. George tells Jean why the hardest data security challenge is still foundational: too many leaders in the space can't distinguish structured from unstructured data, and organizations keep throwing agents at the problem without understanding the manual processes they're trying to automate, which is exactly why they're not seeing ROI on their AI spend.
George is also pitching the Canadian federal government on a concept he calls the AI Training Data Bill of Material (TDI BOM), modeled after SBOMs: a compliance process that produces a verifiable report ensuring the provenance of data used to train models. He cites studies showing that corrupting less than half of 1% of a model's training data can compromise the entire model, and if that model runs targeting data for defense systems or critical infrastructure like water treatment, the failure mode goes well past data loss. He's pushing for TDI BOMs to be required in government procurement, starting with critical infrastructure supply chains, as a step toward digital and data sovereignty. On the commercial side, George co-founded Very Data Free, a veteran-founded secure-by-design platform he describes as "eBay for your data," built to let organizations sell or loan proprietary datasets for AI model training. The conversation also covers how the SIEM-era centralized security model was built for log aggregation and breaks down at petabyte-scale file data, and why GenAI is forcing organizations to finally secure unstructured data environments they've been ignoring.
Topics discussed:
Refusing to let AI agents access production logs and environments
AI Training Data Bill of Material as a government procurement requirement
Model poisoning risks at sub-0.5% training data corruption thresholds
Mapping manual processes before AI automation to prove ROI
Centralized SIEM-era architecture failing at petabyte-scale unstructured data
GenAI forcing organizations to secure previously ignored file environments
AI-generated fake passports and government IDs bypassing identity verification
Hiring self-taught operators over certification-heavy candidates for SOC teamsEP 35 — Snyk's Kate Helin on Governing Agentic AI before the Regulatory Guidance Catches Up
05/05/2026 | 26 minKate Helin, Legal Director of Privacy & Data Security at Snyk, argues that agents have already become the biggest security risk in most enterprise tech stacks, and that most organizations are not set up to address it. The core problem is not a lack of controls. It is that no single function has full visibility into how agents behave. Kate's approach is to convene legal, security, R&D, and GRC before any mitigation decision is made, because legal cannot counsel on obligations until the technical teams explain how the technology actually works. The composition of that conversation determines whether the resulting control is technical, human, or both.
Kate also draws a direct line from GDPR implementation to today's AI governance challenges. She describes how building privacy programs under early GDPR, when implementation details were absent and community norms had to substitute for regulatory guidance, prepared her to operate in the same conditions now present in AI. Her operating principle is to meet the spirit of the law when the prescriptive details have not been written yet.
Topics discussed:
Why agentic AI has become the biggest current security risk across most enterprise tech stacks
Structuring cross-functional roundtables across legal, security, R&D, and GRC before agentic risk controls are selected
How early GDPR implementation under regulatory ambiguity prepared privacy counsel for today's AI governance challenges
Applying the spirit of the law when prescriptive AI regulation has not yet been written or enforced
Why technology consistently outpaces regulation and what that means for security teams building compliant programs today
Using AI as a distillation tool for complex legal and security analysis while maintaining human-in-the-loop validation
Why junior lawyers and engineers still need mentorship to develop judgment that AI-generated outputs cannot replace
Más podcasts de Tecnología
Podcasts a la moda de Tecnología
Acerca de Future of Data Security
Welcome to Future of Data Security, the podcast where industry leaders come together to share their insights, lessons, and strategies on the forefront of data security. Each episode features in-depth interviews with top CISOs and security experts who discuss real-world solutions, innovations, and the latest technologies that are shaping the future of cybersecurity across various industries. Join us to gain actionable advice and stay ahead in the ever-evolving world of data security.
Sitio web del podcastEscucha Future of Data Security, Día Uno y muchos más podcasts de todo el mundo con la aplicación de radio.net

Descarga la app gratuita: radio.net
- Añadir radios y podcasts a favoritos
- Transmisión por Wi-Fi y Bluetooth
- Carplay & Android Auto compatible
- Muchas otras funciones de la app
Descarga la app gratuita: radio.net
- Añadir radios y podcasts a favoritos
- Transmisión por Wi-Fi y Bluetooth
- Carplay & Android Auto compatible
- Muchas otras funciones de la app


Future of Data Security
Escanea el código,
Descarga la app,
Escucha.
Descarga la app,
Escucha.
Future of Data Security: Podcasts del grupo























