Resilient Cyber

By: Chris Hughes
  • Summary

  • Resilient Cyber brings listeners discussions from a variety of Cybersecurity and Information Technology (IT) Subject Matter Experts (SME) across the Public and Private domains from a variety of industries. As we watch the increased digitalization of our society, striving for a secure and resilient ecosystem is paramount.

    © 2024 Resilient Cyber
    Show More Show Less
activate_samplebutton_t1
Episodes
  • Resilient Cyber w/ Christina Liaghati - Navigating Threats to AI Systems
    Sep 6 2024

    - For those that don't know you, can you tell us a bit about your background and your current role?

    - I know you help lead the ATLAS project for MITRE, what exactly is ATLAS and how did it come about?

    - The AI threat landscape is evolving quickly, as organizations are rapidly adopting GenAI, LLM's and AI more broadly. We are still flushing out some fundamental risks, threats and vulnerabilities to consider. Why is it so important to have a way to characterize it all?

    - When it comes to AI Security, there is also a lot of hype, buzz and dare I say FUD out there. Why are you so adamant that we take a data-driven and actionable approach?

    - I know you recently helped participate in the first big AI security incident focused TTX, including with CISA and other Government and Industry partners, can you speak a bit about the experience and why exercises like this are important for organizations to do when it comes to AI security?

    - As someone close to the AI domain, when it comes to security, what are your thoughts on both where we're headed for security of AI, and AI to bolster security?

    - For folks wanting to learn more about ATLAS, and the work MITRE is doing around AI security, where should folks get started?

    - What are some key open questions and opportunities for the community to help shape the future of AI security and assurance?


    https://atlas.mitre.org/
    ← Check out MITRE ATLAS!

    Show More Show Less
    25 mins
  • Resilient Cyber w/ Steve Wilson - Securing the Adoption of GenAI & LLM's
    Aug 28 2024

    In this episode we sit down with GenAI and Security Leader Steve Wilson to discuss securing the explosive adoption of GenAI and LLM's. Steve is the leader of the OWASP Top 10 for LLM's and the upcoming book The Developer's Playbook for LLM Security: Building Secure AI Applications

    -

    - First off, for those not familiar with your background, can you tell us a bit about yourself and what brought you to focusing on AI Security as you have currently?

    - Many may not be familiar with the OWASP LLM Top 10, can you tell us how the project came about, and some of the value it provides the community?

    - I don't want to talk through the list item by item, but I wanted to ask, what are some of the key similarities and key differences when it comes to securing AI systems and applications compared to broader historical AppSec?

    - Where do you think organizations should look to get started to try and keep pace with the businesses adoption of GenAI and LLM's?

    - You've also been working on publishing the Developers Playbook to LLM Security which I've been working my way through an early preview edition of and it is great. What are some of the core topics you cover in the book?

    - One hot topic in GenAI and LLM is the two large paths of either closed and open source models, services and platforms. What are some key considerations from your perspective for those adopting one or the other?

    - I know software supply chain security is a key part of LLM and GenAI security, why is that, and what should folks keep in mind?

    - For those wanting to learn more, where can they find more resources, such as the LLM Top 10, your book, any upcoming talks etc?

    Show More Show Less
    29 mins
  • Resilient Cyber w/ Snehal Antani - Building and Scaling a Security Startup
    Aug 21 2024

    In this episode we sit down with the Founder/CEO of Horizon3.ai to discuss disrupting the Pen Testing and Offensive Security ecosystem, and building and scaling a security startup - from a founders perspective.

    From HP, to Splunk to JSOC - all leading to founding Horizon3, Snehal brings a unique perspective of business acumen and technical depth and puts on a masterclass around venture, founding and scaling a team and disrupting the industry!

    ---

    - For those not familiar with your background who Horizon3AI, can you tell us a bit about both?

    You are building something special at Horizon3AI and I will dive into that here soon, but you've also been posting some great content about building a security startup, the team, the market dynamics and more, so I wanted to spend a little time chatting about that.

    - First off, your company was recently listed by Forbes as one of the top 25 venture backed startups likely to reach a $1 billion dollar valuation. How did that feel and what do you think contributed to your team landing on such a prestigious list?

    - Speaking of venture backed, you recently participated in the Innovators and Investors Summit at BlackHat where you and other panelists dove into the topic of what founders should look for in investors and how VC's can stand out in a highly competitive market. As someone who's navigated that journey and is now being listed on lists such as that from Forbes - what are some of your key lessons learned and recommendations for early-stage founders?

    - You've stressed the importance of the team over the initial idea and what you've called "pace setters" and "ankle weights" within the team and the importance of both. Can you elaborate on the terms and broader context around building a foundational team to scale the company successfully?

    - You also have discussed the 4 advantages iconic companies build over time, what are they and why do they help differentiate you?

    - Pivoting a bit, you have a really unique background, blending both the private and public/defense sector. How do you think that's helped shape you and the way you've build your team and company and approach the market?

    - Horizon3AI is big on the mantra of "offense informed defense". Why is that critical and why do you think we miss the value in this approach in many spaces in the security ecosystem?

    - You all have poked some fun at the way many organizations operate, running vuln scans, doing an annual pen test, and having a false sense of security. How is Horizon3AI disrupting the traditional Pen Testing space and leading to more secure organizational outcomes?

    Show More Show Less
    30 mins

What listeners say about Resilient Cyber

Average customer ratings

Reviews - Please select the tabs below to change the source of reviews.