Episodes

  • The Model Writing Your Code Shouldn't Be Securing It
    Sep 21 2026

    Jonathan Rende of Checkmarx on why the model writing your code cannot also be the control that validates it, and why rules-based and AI-driven scanning turn out to find almost entirely different bugs.

    In this episode I sit down with Jonathan Rende of Checkmarx. Jonathan worked with Fortify and SPI Dynamics back in the day, spent most of the last decade leading product teams in developer and DevOps tooling, and came back to security eighteen months ago because, as he puts it, this is the heart of the hurricane. His argument is that AI is a bigger disruption than the internet, SaaS, or mobile were, not because of any single capability, but because it hits roles, process, and productivity all at once.

    We get into the two waves he has watched play out with CISOs and their CEOs, why the pendulum has swung back toward program and posture questions in the last quarter, what his research team found when they benchmarked deterministic and probabilistic scanning side by side, and why he thinks agentic AppSec raises the profile of the security team rather than automating it away.

    In this episode:

    ● Why the first half of 2026 became a real inflection point rather than another AI talking point

    ● The two waves: engineering told to run at any cost, then the pendulum swinging back toward posture and program design

    ● Why functional AI-generated code and secure AI-generated code are still two different things

    ● Separation of church and state, and the conflict of interest in letting the model that generates code also validate it

    ● Benchmarking deterministic and AI-based scanning across dozens of open source projects, and why the overlap stayed consistently under 10%

    ● Fidelity, F1 scores, and the absence of real standards or shared benchmarks in AppSec

    ● Why an incentive to reduce risk and an incentive to sell tokens are not the same incentive

    ● Why agents free AppSec professionals for higher-order work, and why this is not a dark factory

    ● Shadow IT becoming shadow AI, and early scans where half surfaced models, agents, and MCP servers security teams did not know existed

    ● Why new threat vectors show up first in fast-moving unregulated companies while regulated ones see more code-level issues

    ● Low-priority vulnerabilities chained into real impact, and why backlogs now matter as much as incoming code

    ● What to change first: metrics defined up front, in-workflow AppSec, and security reviews that went from annual to monthly

    Chapters:

    0:00 Intro
    0:18 Fortify, SPI Dynamics, and a decade in developer tooling
    1:24 Why he came back to AppSec
    2:54 Why the first half of 2026 was the inflection point
    5:27 Two waves, and the pendulum swinging back
    9:08 Functional AI code versus secure AI code
    11:58 Layered defense and the condensed lifecycle
    15:04 What agents free AppSec teams to actually do
    17:50 Separation of church and state
    20:15 Fidelity, F1 scores, and not selling tokens
    23:25 New threat vectors and organizational maturity
    25:47 Shadow AI and what the inventory scans found
    27:58 What to change first in your AppSec program
    30:44 Closing

    Connect with Jonathan:

    LinkedIn: https://www.linkedin.com/in/jonathanrende/

    Checkmarx: https://checkmarx.com

    Resilient Cyber: https://www.resilientcyber.io

    Subscribe for more conversations with security practitioners and leaders.

    #appsec #aisecurity #devsecops #shadowai #vulnerabilitymanagement #ciso

    Show more Show less
    31 mins
  • The First OWASP Top 10 Backed by Real Incident Data
    Sep 14 2026

    Rock Lambros, Co-Lead of the 2026 OWASP Top 10 for LLM Applications, on why prompt injection would have fallen out of the top 10 based on incident data alone, and why the community kept it at number one anyway.

    In this episode I sit down with Rock Lambros, longtime security leader, former CISO, core team member of the OWASP GenAI Security Project, and Co-Lead of the 2026 OWASP Top 10 for LLM Applications, to dig into the new list and the harder questions underneath it. We get into the letter from the project leads that opens the document, why the LLM and Agentic lists are converging, what a year of messy incident data actually told the working group, and why Rock argues that agency is not authorization.

    In this episode:

    • Why the LLM Top 10 and the Agentic Top 10 are merging in practice
    • The opening letter, and why the industry was slow to admit the model was never the thing to secure
    • Who benefits from a model-centric framing of AI security
    • Prompt injection ranked number one by practitioners and out of the top 10 by the incident data
    • Why incidents get reported by outcome rather than by initial vector
    • Misinformation, the widest gap between the vote and the data
    • Hidden Context Exposure, soft guardrails, and why instructions and data share one context window
    • Context rot and why context window management matters for agents doing critical work
    • Using AI to govern AI, and the dual-layer approach in the Agentic Control Standard
    • Agency versus authorization, and why OAuth is what we have rather than the answer
    • How to get involved in the OWASP GenAI Security Project

    Chapters:
    0:00 Intro and Rock's background
    1:17 What the agentic work changed about the LLM Top 10
    3:59 The opening letter and "It Was Never the Model"
    8:48 Incident data and the prompt injection ranking
    11:23 Misinformation and the limits of the data
    14:24 Hidden Context Exposure and soft guardrails
    17:18 The context window and context rot
    19:57 Using AI to govern AI
    22:49 Excessive agency, and agency versus authorization
    27:09 How to get involved with OWASP

    Connect with Rock:
    LinkedIn: https://www.linkedin.com/in/rocklambros
    OWASP GenAI Security Project: https://genai.owasp.org
    Get involved: https://genai.owasp.org/contributing
    OWASP Top 10 for LLM Applications 2026: https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/

    Read my piece on the new list, It Was Never the Model: https://www.resilientcyber.io/p/it-was-never-the-model

    Resilient Cyber: https://www.resilientcyber.io

    Show more Show less
    26 mins
  • The Jagged Frontier of Finding and Fixing Vulns with AI
    Sep 1 2026

    Ondrej Vlcek, CEO of AISLE and former CEO of Avast, on why AI vulnerability discovery is not as commoditized as the industry thinks, and why remediation is still the real bottleneck.

    In this episode I sit down with Ondrej Vlcek, Founder and CEO at AISLE. Ondrej spent roughly 30 years in cybersecurity, joining Avast as employee number six or seven doing kernel-mode driver work on Windows 95, eventually becoming CTO and then CEO, taking the company public and selling it to NortonLifeLock in a nearly $9 billion transaction. He co-founded AISLE in the fall of 2024 to close the loop from discovery through triage, remediation, and verification. His team has now disclosed 350 plus CVEs across projects like OpenSSL and curl.

    We get into why the moat sits in the system and not the model, why the gray market price of vulnerabilities has not collapsed even as models get cheaper, and what it actually takes to ship a patch a maintainer will accept.

    In this episode:
    - Going from Avast intern to CEO, and why vulnerability management was the next problem
    - The jagged frontier, and why bigger models do not always mean better results
    - Which classes of bugs got cheap to find and which are still genuinely hard
    - Why vulnerability prices have not collapsed despite all the model progress
    - Building a model-agnostic system with bespoke benchmarks for model selection
    - Sovereign AI, on-prem and air-gapped deployment, and why findings are the real crown jewels
    - Triage, reachability, and why most findings are not actually exploitable
    - Patch verification, regression risk, and mitigations for embedded systems that cannot be patched
    - How AISLE earned trust from curl after Daniel Stenberg killed the bug bounty
    - Whether a CVE count is a vanity metric
    - Build versus buy as model capability keeps getting cheaper
    - What breaks first in the CVE and open source maintainer ecosystem
    - What AppSec leaders should change next quarter

    Chapters
    0:00 Intro
    0:24 From Avast employee number six to a $9 billion exit
    3:26 Why vulnerability management, and why now
    5:15 The jagged frontier and what bigger models miss
    10:36 The economics of finding bugs, and why prices have not collapsed
    12:11 Building a model-agnostic system with real benchmarks
    14:30 Sovereign AI, air-gapped deployment, and who sees your findings
    19:42 Triage, reachability, and why remediation is the bottleneck
    24:48 Patches that break things, and systems you cannot redeploy
    25:39 curl, Daniel Stenberg, and death by a thousand slops
    29:35 Is a CVE count a vanity metric?
    31:34 Build versus buy when capability keeps getting cheaper
    34:41 What breaks first in the next 18 months
    39:46 What AppSec leaders should do next quarter
    41:13 Closing

    Ondrej Vlcek on LinkedIn
    AISLE
    AISLE research and blog

    Resilient Cyber Substack
    Subscribe for more conversations with security practitioners and leaders.

    Show more Show less
    42 mins
  • Secure Vibe Coding and the 99%
    Aug 24 2026

    Lovable CISO Igor Andriushchenko on soft guardrails vs. hard boundaries, securing vibe coding for non-developers, and building a security program at a 10x company.

    I sit down with Igor Andriushchenko, Head of Security and CISO at Lovable, the AI development platform behind one of the fastest growth stories in the space. Igor joined as the first security hire when the company was around 40 people. A year later he is running a 20+ person team covering product security, GRC, IT, and platform safety for a company with 400 laptops in MDM and no sign of slowing down.

    We get into what it actually takes to secure AI-native development, both inside a hypergrowth startup and on a platform where most of the people shipping software are not developers and definitely not security practitioners.

    In this episode:

    • Building a security program for the company you will be in 12 months instead of the one you are in today
    • Soft guardrails versus hard guardrails, and how to decide which one a problem deserves
    • Why hard blocks push AI-assisted workflows into the shadows
    • Rooting guardrail decisions in business goals, risks, and threats rather than tool defaults
    • Democratized development without democratized security, and what a platform owes the 99%
    • Lovable's auto-fix toggle, per-app threat models, and the goal of an app with no security tab at all
    • Whether models will ever produce secure code by default, and why defense in depth still carries the load
    • Governing the reality that every employee vibe coding an app looks a lot like a new vendor
    • GRC engineering as the way to measure control efficiency layer by layer against AI-powered attackers
    • CRA, NIS2, and the EU AI Act landing on citizen developers who never thought of themselves as software manufacturers

    Chapters: 0:00 Intro 0:23 Igor's background from DevOps to CISO 3:54 Scaling security at a 10x company 6:07 Reinventing the team when growth breaks it 08:26 Soft guardrails versus hard blocks 14:05 Tying guardrails to business risk 17:32 Democratized development, undemocratized security 18:52 Shared responsibility on an AI dev platform 21:16 Auto-fix, per-app threat models, and no security tab 25:21 Will models produce secure code by default? 29:56 Every employee vibe coding is a new vendor 30:57 Enterprise controls, publishing gates, and PII scanning 36:39 AI-powered attackers and why good enough changed 40:43 GRC engineering and measuring control efficiency 46:19 CRA, NIS2, and the citizen developer 52:41 Trust centers for builder apps 54:08 Closing thoughts on the vibe coding community

    Guest links: Igor on LinkedIn: https://www.linkedin.com/in/igor-andriushchenko Lovable: https://lovable.dev

    Resilient Cyber: Newsletter and episode archive: https://www.resilientcyber.io Subscribe for more conversations with security practitioners and leaders.

    Show more Show less
    56 mins
  • Building a System of Truth for the CISO
    Aug 11 2026

    CISOs have a stack of tools but no system built to run the security program itself. Mike Armistead wants to fix that.

    In this episode I sit down with Mike Armistead, co-founder and CEO of Pulse Security AI and a longtime security founder behind Fortify and Respond Software. We dig into why the security leader has never had a system of truth the way the CFO has an ERP and the CRO has a CRM, and how an agentic layer on top of the existing tools can finally close that gap. Mike is measured about where AI gets to decide and where the human stays in the seat, and he shares what surprised him most from research with more than 80 senior practitioners and corporate directors.

    In this episode:
    - Why two exits later Mike came back to build a third company around the AI wave
    - The silos that left CISOs with an acronym soup of tools and no way to run the program
    - What a system of truth for the CISO actually means and how it layers on top of existing structured and unstructured data
    - Where agents do the heavy lifting on regulatory monitoring, vendor intelligence, and status reporting
    - Governing the guardrails, not the keystrokes, and why closing the loop still involves people
    - What corporate directors actually want to hear in the 15 to 20 minutes a CISO gets each quarter
    - The findings that stood out, including that 55% of boards have never defined the cyber risk they are willing to accept, and only 12.5% of CISOs are very confident the board leaves with a true picture of the risk
    - Institutionalizing the tribal knowledge every security program runs on

    Chapters:
    0:00 Intro
    0:18 Mike's background and two prior exits
    1:08 Why the AI wave pulled him back
    2:21 Why the CISO has no system to run the program
    4:09 Starting at the program level, not the SOC or AppSec
    5:28 What a system of truth for the CISO means
    8:19 Speaking the language of the business
    9:09 Where AI does the heavy lifting on a typical Tuesday
    11:57 Govern the guardrails, not the keystrokes
    15:44 Bringing deputies into the conversation
    16:46 What the research with senior practitioners found
    20:37 Boards, risk tolerance, and the reporting gap
    24:57 AI as a double-edged sword for security leaders
    25:35 Joanna Burkey and institutionalizing tribal knowledge
    27:31 A year from now for the security leader

    Guest links:
    Mike Armistead on LinkedIn

    Pulse Security on AI

    More Resilient Cyber:
    Substack: https://www.resilientcyber.io
    Subscribe for more conversations with security practitioners and leaders.

    Show more Show less
    31 mins
  • The Real Price Tag On Cyber Breaches
    Aug 5 2026

    Alex Pinto, who leads Verizon's DBIR team, joins me to break down the new Breach Impact Study and what data breaches actually cost organizations.

    For years the industry has argued past itself on breach costs. One camp says the market doesn't care, the other says a single breach ends your business. Alex and his team finally got their hands on roughly 70,000 cyber insurance claims through CyberAcuView, and the Breach Impact Study puts real numbers behind the question. In this conversation we dig into what the data shows, where it stops, and how a security leader should actually use it.

    Alex Pinto runs the Data Breach Investigations Report team at Verizon Business and has been building the report for close to a decade. The Breach Impact Study is the team's first focused spin-off from the DBIR.

    In this episode:
    - How the Breach Impact Study came together and why the DBIR team finally got cyber insurance claims data
    - Why the study measures insurable loss as a floor, not a ceiling, of real economic impact
    - The case for reporting medians over averages, and why the team refuses to publish the average
    - Business interruption versus contingent business interruption, and why downtime moves the needle
    - Whether an $83,000 median breach impact sends executives the wrong message
    - The SMB paradox, where the smallest companies take the hardest proportional hit
    - What the claims data does and does not show about AI on offense and defense
    - Third-party risk, coverage sub-limits, and the single biggest takeaway for security leaders

    Chapters
    0:00 Intro
    0:24 Meet Alex Pinto and the DBIR team
    2:51 Launching the Breach Impact Study
    3:26 Getting cyber insurance claims data
    7:32 Why insurable loss is a floor, not a ceiling
    11:14 Medians over averages, and why the average is meaningless
    15:13 Business interruption vs contingent business interruption
    19:49 Does an $83K median send the wrong message?
    22:44 The SMB paradox and the cybersecurity poverty line
    26:05 Where AI shows up, offense vs defense
    34:48 The CVE explosion and marketing hype
    36:59 Third-party risk and coverage limits
    41:34 Wrap-up

    Guest links
    Alex Pinto on LinkedIn: https://www.linkedin.com/in/alexcpsec/
    Alex Pinto on X: https://x.com/alexcpsec
    Verizon DBIR and Breach Impact Study: https://www.verizon.com/business/resources/reports/dbir/

    More from Resilient Cyber
    Substack: https://www.resilientcyber.io
    Subscribe for more conversations with security practitioners and leaders.

    #cyberrisk #databreach #cyberinsurance #ransomware #aisecurity #dbir

    Show more Show less
    42 mins
  • Cyber Investing in the AI Exploit Era
    Aug 1 2026

    What happens to security investing when vulnerability discovery becomes continuous and exploitation windows shrink from weeks to hours? I sit down with Chenxi Wang of Rain Capital to dig into it.

    Chenxi is the Founder and Managing General Partner at Rain Capital, a venture fund focused on early-stage cybersecurity companies. She's been a Carnegie Mellon professor, a Forrester VP, and a strategy leader at Intel Security and Twistlock, and her portfolio includes companies like Claroty, ProjectDiscovery, Ox Security, runZero, and Straiker. She closes out my July run of conversations with security investors.

    In this episode:

    • The AI Exploit Age and why vulnerability discovery is becoming continuous
    • Guardian Agents and the case that it takes an AI to govern an AI
    • Separating AI agent identity from traditional machine identity
    • The signals that predict enterprise adoption for early-stage security startups
    • The barbell funding market and the squeeze on Series B and C
    • What security leaders should do differently over the next twelve months

    Connect with Chenxi:
    LinkedIn: https://www.linkedin.com/in/chenxiwang88/
    Rain Capital: https://raincap.vc/
    Rain Capital Insights: https://raincapital.substack.com

    Subscribe to Resilient Cyber for more conversations with security practitioners and leaders: https://www.resilientcyber.io

    Show more Show less
    33 mins
  • AI, Bug Bounties & the Vulnerability "Slopdemic"
    Jul 30 2026

    Bugcrowd founder Casey Ellis joins me to dig into what AI is actually doing to bug bounties, vulnerability discovery, and open source security. We get into his "slopdemic" framing, the curl bug bounty saga, VDP readiness, the pentest market correction, and where security research policy heads next.

    Casey Ellis is the founder of Bugcrowd, co-founder of disclose.io, and a board member of the Security Research Legal Defense Fund. These days he advises and invests through Tall Poppy Group and works at the intersection of security, AI, and policy. His argument is that the vulnpocalypse was already here, and AI has made the cost of both finding and reporting vulnerabilities collapse at the same time.

    In this episode:

    • Casey's path from building Bugcrowd to advising, investing, and policy work
    • Why more practitioners need to get involved in policy, and why law is just code
    • The slopdemic vs. the vulnpocalypse, and what actually changed in submissions
    • AI lowering the bar for a broader, less predictable pool of threat actors
    • Daniel Stenberg, curl, and maintainers below the security poverty line
    • The lightning rod vs. rockets distinction between VDPs and bug bounties
    • The pentest market correction underway from AI pricing pressure
    • Collapsing OODA loops, hack-back, CFAA reform, SRLDF, and disclose.io

    Chapters:

    0:00 Intro and Casey's background
    2:56 Why practitioners belong in policy
    6:22 The slopdemic vs. the vulnpocalypse
    9:40 AI lowering the bar for threat actors
    11:47 Open source, curl, and the security poverty line
    15:37 VDP vs. bug bounty readiness
    19:20 The pentest market correction
    24:20 What breaks first in vulnerability management
    27:20 Hack-back and non-cooperative defense
    28:43 A near-term playbook for security leaders
    31:40 CFAA, SRLDF, and disclose.io

    Connect with Casey:
    LinkedIn: https://www.linkedin.com/in/caseyjohnellis
    Blog: https://cje.io
    disclose.io: https://disclose.io
    Bugcrowd: https://www.bugcrowd.com

    Resilient Cyber: https://www.resilientcyber.io
    Subscribe for more conversations with security practitioners and leaders.

    Show more Show less
    34 mins