The Security Podcast of Silicon Valley: Recent Episodes

Jon McLachlan

Discover real people, overcoming security problems. 30-minute interviews with entrepreneurs, engineers, and leaders that explore modern security dilemmas and how we overcome them.

A shame-free space to engage in open and honest discussions about what‘s really going on in Security. Interviews of about 30 minutes in length explore the dilemmas and opportunities faced by real entrepreneurs, operators, engineers, and leaders. Join us and catch a glimpse into the proven technologies and techniques that solve real problems, today.

https://peacemakr.io

View Details

Every employee at your company probably has ChatGPT, Claude, and Gemini installed, and nobody's tracking what data goes where. Xia Hua, co-founder and CEO of Traceforce, came back a year after her first appearance to show us what that looks like from the inside. Her team's open source scanner, MCP X-Ray, found a prompt injection flaw in Playwright, one of the most widely used MCPs, and she triggered it live with a single sentence. We also get into Anthropic's report on the espionage campaign that used Claude and a set of MCPs against about 30 organizations. And the bigger problem underneath it all, that data and instructions are now co-mingled, so any tool that reads text can be told what to do by that text.

Xia: www.linkedin.com/in/xia-hua-ph-d
TraceForce: www.traceforce.ai
MCP X-Ray: www.github.com/traceforce/mcp-xray
Jon: www.linkedin.com/in/jon-mclachlan
Sasha: www.linkedin.com/in/aliaksandr-sinkevich
YSecurity: www.ysecurity.io

🔒 Sponsored by YSecurity

Closing a big deal and getting hit with a vendor questionnaire, SOC 2 request, or pen test requirement? That's exactly what we handle.

YSecurity embeds a team of security engineers with backgrounds from Apple, Uber, Microsoft, Robinhood, and Brex directly into your company. No full-time hire, no bloated retainer. You set a monthly cap and we handle everything.

Book a free strategy call and we'll tell you exactly where you stand.

👉 Book your free call: 30 Min Meeting | YSecurity.io | Cal.com

👉 Learn more: YSecurity | On-Demand Cybersecurity Team for Startups — SOC 2 in 5 Months

View Details

Enterprises blame vendors. Vendors blame enterprises. Nobody does a pre-flight check. Ged Ossman, founder of Interf, joins the show to explain why AI adoption keeps stalling out mid-flight, and how a shared protocol for agent context and permissions could finally fix the trust gap between security teams and AI vendors. Recorded in January 2026.

Ged: https://www.linkedin.com/in/gedossman/

Interf: www.interf.com

Jon: https://www.linkedin.com/in/jon-mclachlan

Sasha: https://www.linkedin.com/in/aliaksandr-sinkevich

YSecurity: https://www.ysecurity.io

🔒 Sponsored by YSecurity

Closing a big deal and getting hit with a vendor questionnaire, SOC 2 request, or pen test requirement? That's exactly what we handle.

YSecurity embeds a team of security engineers with backgrounds from Apple, Uber, Microsoft, Robinhood, and Brex directly into your company. No full-time hire, no bloated retainer. You set a monthly cap and we handle everything.

Book a free strategy call and we'll tell you exactly where you stand.

👉 Book your free call: 30 Min Meeting | YSecurity.io | Cal.com

👉 Learn more: YSecurity | On-Demand Cybersecurity Team for Startups — SOC 2 in 5 Months

View Details

What if 80% of your security budget is protecting the wrong thing? Or Eshed built LayerX after realizing that firewalls and network tools were blind to exactly where breaches actually happen, in the browser. In this episode, Or breaks down how to build a future-proof security strategy around where employees actually work. Tune in.

Or: www.linkedin.com/in/or-eshed
LayerX Security: www.layerxsecurity.com
Jon: www.linkedin.com/in/jon-mclachlan
Sasha: www.linkedin.com/in/aliaksandr-sinkevich
YSecurity: www.ysecurity.io

🔒 Sponsored by YSecurity

Closing a big deal and getting hit with a vendor questionnaire, SOC 2 request, or pen test requirement? That's exactly what we handle.

YSecurity embeds a team of security engineers with backgrounds from Apple, Uber, Microsoft, Robinhood, and Brex directly into your company. No full-time hire, no bloated retainer. You set a monthly cap and we handle everything.

Book a free strategy call and we'll tell you exactly where you stand.

👉 Book your free call: 30 Min Meeting | YSecurity.io | Cal.com

👉 Learn more: YSecurity | On-Demand Cybersecurity Team for Startups — SOC 2 in 5 Months

View Details

A hacker who got kicked out of college for finding their vulnerabilities, became a national hacking champion, and is now building what he calls a sovereign-level cyber weapon. Alexis Lingad, founder of Kinosec, built an autonomous AI system that chains exploits across web, IoT, and physical infrastructure the same way a real attacker would, and he's already using it to sell AI pen testing to enterprise security teams. Tune in to hear how he's building the weapon before the bad guys do.

Alexis: www.linkedin.com/in/alexis-lingad
Kinosec: www.kinosec.ai
Jon: www.linkedin.com/in/jon-mclachlan
Sasha: www.linkedin.com/in/aliaksandr-sinkevich
YSecurity: www.ysecurity.io

🔒 Sponsored by YSecurity

Closing a big deal and getting hit with a vendor questionnaire, SOC 2 request, or pen test requirement? That's exactly what we handle.

YSecurity embeds a team of security engineers with backgrounds from Apple, Uber, Microsoft, Robinhood, and Brex directly into your company. No full-time hire, no bloated retainer. You set a monthly cap and we handle everything.

Book a free strategy call and we'll tell you exactly where you stand.

👉 Book your free call: 30 Min Meeting | YSecurity.io | Cal.com

👉 Learn more: YSecurity | On-Demand Cybersecurity Team for Startups — SOC 2 in 5 Months

View Details

Google has said to be concerned about quantum computing by 2029. Kevin Kane, Co-Founder and CEO of American Binary, argues that timeline is already too relaxed and that companies treating post-quantum as a future problem are the ones most exposed right now. He breaks down what a real quantum-resilient architecture takes, why formal verification matters, and what harvest attacks mean for every encrypted message sent today.

Kevin Kane: www.linkedin.com/in/iamkevinpkane
American Binary: https://www.ambit.inc
Jon: www.linkedin.com/in/jon-mclachlan
Sasha: www.linkedin.com/in/aliaksandr-sinkevich
YSecurity:www.ysecurity.io

🔒 Sponsored by YSecurity

Closing a big deal and getting hit with a vendor questionnaire, SOC 2 request, or pen test requirement? That's exactly what we handle.

YSecurity embeds a team of security engineers with backgrounds from Apple, Uber, Microsoft, Robinhood, and Brex directly into your company. No full-time hire, no bloated retainer. You set a monthly cap and we handle everything.

Book a free strategy call and we'll tell you exactly where you stand.

👉 Book your free call: 30 Min Meeting | YSecurity.io | Cal.com

👉 Learn more: YSecurity | On-Demand Cybersecurity Team for Startups — SOC 2 in 5 Months

View Details

Security incidents don't end when the threat is contained. They end when you can confirm no sensitive data left the building and most teams can't confirm that. Pranava Adduri and George Gerchow of Bedrock Data joined the show to talk through what data visibility actually looks like at enterprise scale, why the office of no is dead, and what a DBOM has to do with AI compliance. Together they make the case that data-first security isn't just a better posture, it's the only posture that survives an AI-driven enterprise.

Pranava Adduri: www.linkedin.com/in/padduri

George Gerchow: www.linkedin.com/in/georgegerchow

Bedrock Data: www.bedrockdata.ai

Jon: www.linkedin.com/in/jon-mclachlan

Sasha: www.linkedin.com/in/aliaksandr-sinkevich

YSecurity: www.ysecurity.io

🔒 Sponsored by YSecurity

Closing a big deal and getting hit with a vendor questionnaire, SOC 2 request, or pen test requirement? That's exactly what we handle.

YSecurity embeds a team of security engineers with backgrounds from Apple, Uber, Microsoft, Robinhood, and Brex directly into your company. No full-time hire, no bloated retainer. You set a monthly cap and we handle everything.

Book a free strategy call and we'll tell you exactly where you stand.

👉 Book your free call: 30 Min Meeting | YSecurity.io | Cal.com

👉 Learn more: YSecurity | On-Demand Cybersecurity Team for Startups — SOC 2 in 5 Months

View Details

Your printers know your passwords. They store credentials for your email server, your file shares, and your LDAP. Jim LaRoe, founder of Symphion, explains why 99% of enterprise printers sit at factory defaults, and what a single forgotten device actually costs you.

Jim: www.linkedin.com/in/jim-laroe

Symphion: www.symphion.com

Jon: www.linkedin.com/in/jon-mclachlan

Sasha: www.linkedin.com/in/aliaksandr-sinkevich

YSecurity: www.ysecurity.io

🔒 Sponsored by YSecurity

Closing a big deal and getting hit with a vendor questionnaire, SOC 2 request, or pen test requirement? That's exactly what we handle.

YSecurity embeds a team of security engineers with backgrounds from Apple, Uber, Microsoft, Robinhood, and Brex directly into your company. No full-time hire, no bloated retainer. You set a monthly cap and we handle everything.

Book a free strategy call and we'll tell you exactly where you stand.

👉 Book your free call: 30 Min Meeting | YSecurity.io | Cal.com

👉 Learn more: YSecurity | On-Demand Cybersecurity Team for Startups — SOC 2 in 5 Months

View Details

The biggest AI mistake companies make isn't picking the wrong tool, it's not understanding the dependencies underneath it. Jacob and Stephen from Talbot West share how they map entire organizations to find the right AI entry point, why LLMs are overhyped, and what technologies are actually underrated right now.

Jacob: www.linkedin.com/in/jacobandra
Stephen: www.linkedin.com/in/stephenkarafiath
Talbot West: www.talbotwest.com
Jon: www.linkedin.com/in/jon-mclachlan
Sasha: www.linkedin.com/in/aliaksandr-sinkevich
YSecurity:www.ysecurity.io

🔒 Sponsored by YSecurity

Closing a big deal and getting hit with a vendor questionnaire, SOC 2 request, or pen test requirement? That's exactly what we handle.

YSecurity embeds a team of security engineers with backgrounds from Apple, Uber, Microsoft, Robinhood, and Brex directly into your company. No full-time hire, no bloated retainer. You set a monthly cap and we handle everything.

Book a free strategy call and we'll tell you exactly where you stand.

👉 Book your free call: 30 Min Meeting | YSecurity.io | Cal.com

👉 Learn more: YSecurity | On-Demand Cybersecurity Team for Startups — SOC 2 in 5 Months

View Details

You can have perfect infrastructure—and still be talking to the wrong person.

In this episode, Jasson Casey (Beyond Identity) breaks down why identity—not infrastructure—is the real security boundary, how passwords created today’s vulnerabilities, and what a future without “moving secrets” looks like. If you’re building or scaling a company, this is a shift you can’t ignore. Listen now.

Jasson: www.linkedin.com/in/jassoncasey
Beyond Identity: www.beyondidentity.com
Jon: www.linkedin.com/in/jon-mclachlan
Sasha: www.linkedin.com/in/aliaksandr-sinkevich
YSecurity: www.ysecurity.io

🔒 Sponsored by YSecurity

Closing a big deal and getting hit with a vendor questionnaire, SOC 2 request, or pen test requirement? That's exactly what we handle.

YSecurity embeds a team of security engineers with backgrounds from Apple, Uber, Microsoft, Robinhood, and Brex directly into your company. No full-time hire, no bloated retainer. You set a monthly cap and we handle everything.

Book a free strategy call and we'll tell you exactly where you stand.

👉 Book your free call: 30 Min Meeting | YSecurity.io | Cal.com

👉 Learn more: YSecurity | On-Demand Cybersecurity Team for Startups — SOC 2 in 5 Months

View Details

Is your security team drowning in noise while your developers struggle to keep up? Neatsun Ziv, CEO of Ox Security, explains why traditional "Shift Left" strategies have failed and how applying business context can help your team focus on the vulnerabilities that actually matter. Listen to the full episode to learn how to turn security into a competitive advantage.

Neatsun: https://www.linkedin.com/in/neatsun-ziv-ab7394/

Ox Security: www.ox.security/

Jon: www.linkedin.com/in/jon-mclachlan

Sasha: www.linkedin.com/in/aliaksandr-sinkevich

YSecurity: www.ysecurity.io

🔒 Sponsored by YSecurity

Closing a big deal and getting hit with a vendor questionnaire, SOC 2 request, or pen test requirement? That's exactly what we handle.

YSecurity embeds a team of security engineers with backgrounds from Apple, Uber, Microsoft, Robinhood, and Brex directly into your company. No full-time hire, no bloated retainer. You set a monthly cap and we handle everything.

Book a free strategy call and we'll tell you exactly where you stand.

👉 Book your free call: 30 Min Meeting | YSecurity.io | Cal.com

👉 Learn more: YSecurity | On-Demand Cybersecurity Team for Startups — SOC 2 in 5 Months

View Details

Most security decisions fail when the people doing the work don’t have the information they need. Garrett Smith, Founder and CEO of Reveal Technology and a Marine Corps Reserve Lieutenant Colonel, explains how bottom-up product design changes defense outcomes—and what business leaders can learn about building technology people actually adopt. Listen to learn how compliance, procurement, and mission pressure shape what ships and what stalls.

Garrett: https://www.linkedin.com/in/wgarrettsmith/

Reveal Technology: https://www.revealtech.ai

Jon: https://www.linkedin.com/in/jon-mclachlan

Sasha: https://www.linkedin.com/in/aliaksandr-sinkevich

YSecurity: https://www.ysecurity.io

🔒 Sponsored by YSecurity

Closing a big deal and getting hit with a vendor questionnaire, SOC 2 request, or pen test requirement? That's exactly what we handle.

YSecurity embeds a team of security engineers with backgrounds from Apple, Uber, Microsoft, Robinhood, and Brex directly into your company. No full-time hire, no bloated retainer. You set a monthly cap and we handle everything.

Book a free strategy call and we'll tell you exactly where you stand.

👉 Book your free call: 30 Min Meeting | YSecurity.io | Cal.com

👉 Learn more: YSecurity | On-Demand Cybersecurity Team for Startups — SOC 2 in 5 Months

View Details

AI agents can delete your production database and tell you everything is fine. Graham Neray, Co-Founder and CEO of Oso, breaks down why AI agents introduce a new level of risk for growing SaaS companies. If you’re adding AI to your product, moving upmarket, or selling into regulated industries, your authorization model is no longer a backend detail—it’s a growth dependency. Listen in to learn how automating least privilege protects your product, your customers, and your revenue.

Graham: https://www.linkedin.com/in/grahamneray/

Oso: https://www.osohq.com

Jon: https://www.linkedin.com/in/jon-mclachlan

Sasha: https://www.linkedin.com/in/aliaksandr-sinkevich

YSecurity: https://www.ysecurity.io

🔒 Sponsored by YSecurity

Closing a big deal and getting hit with a vendor questionnaire, SOC 2 request, or pen test requirement? That's exactly what we handle.

YSecurity embeds a team of security engineers with backgrounds from Apple, Uber, Microsoft, Robinhood, and Brex directly into your company. No full-time hire, no bloated retainer. You set a monthly cap and we handle everything.

Book a free strategy call and we'll tell you exactly where you stand.

👉 Book your free call: 30 Min Meeting | YSecurity.io | Cal.com

👉 Learn more: YSecurity | On-Demand Cybersecurity Team for Startups — SOC 2 in 5 Months

View Details

The perimeter will fail. What matters is whether your business turns one incident into a disaster. Andrew Rubin, Founder and CEO of Illumio, explains how breach containment reduces blast radius, why category timing is “luck,” and what leaders must do as AI speeds up attackers and defenders. Listen for a founder-level playbook on building security that scales with growth.

Andrew: https://www.linkedin.com/in/andrewsrubin

Illumio: https://www.illumio.com

Jon: https://www.linkedin.com/in/jon-mclachlan

Sasha: https://www.linkedin.com/in/aliaksandr-sinkevich

YSecurity: https://www.ysecurity.io

🔒 Sponsored by YSecurity

Closing a big deal and getting hit with a vendor questionnaire, SOC 2 request, or pen test requirement? That's exactly what we handle.

YSecurity embeds a team of security engineers with backgrounds from Apple, Uber, Microsoft, Robinhood, and Brex directly into your company. No full-time hire, no bloated retainer. You set a monthly cap and we handle everything.

Book a free strategy call and we'll tell you exactly where you stand.

👉 Book your free call: 30 Min Meeting | YSecurity.io | Cal.com

👉 Learn more: YSecurity | On-Demand Cybersecurity Team for Startups — SOC 2 in 5 Months

View Details

AI won’t save your startup. Unless it can ship changes safely. Venkat Thiruvengadam breaks down why the real value isn’t the model, it’s the orchestration: guardrails, permissions, context, and human-in-the-loop workflows that let agents do more than “read-only.” Tune in for a practical conversation on scaling DevOps, security, and compliance without slowing the business.

Venkat: www.linkedin.com/in/venkat-thiruvengadam

DuploCloud: www.duplocloud.com

Jon: www.linkedin.com/in/jon-mclachlan

Sasha: www.linkedin.com/in/aliaksandr-sinkevich

YSecurity: www.ysecurity.io

🔒 Sponsored by YSecurity

Closing a big deal and getting hit with a vendor questionnaire, SOC 2 request, or pen test requirement? That's exactly what we handle.

YSecurity embeds a team of security engineers with backgrounds from Apple, Uber, Microsoft, Robinhood, and Brex directly into your company. No full-time hire, no bloated retainer. You set a monthly cap and we handle everything.

Book a free strategy call and we'll tell you exactly where you stand.

👉 Book your free call: 30 Min Meeting | YSecurity.io | Cal.com

👉 Learn more: YSecurity | On-Demand Cybersecurity Team for Startups — SOC 2 in 5 Months

View Details

Trevor Hilligoss, Head of Security Research at SpyCloud and former FBI agent, joins the show to discuss why humans remain the biggest security risk facing organizations today. From reused credentials to commoditized cybercrime tools, Trevor breaks down how attackers actually gain access — and why focusing on real-world human behavior is more effective than worrying about sophisticated nation-state threats.

Trevor: www.linkedin.com/in/thilligoss/

SpyCloud: spycloud.com

Jon: www.linkedin.com/in/jon-mclachlan

Sasha: www.linkedin.com/in/aliaksandr-sinkevich

YSecurity: www.ysecurity.io

🔒 Sponsored by YSecurity

Closing a big deal and getting hit with a vendor questionnaire, SOC 2 request, or pen test requirement? That's exactly what we handle.

YSecurity embeds a team of security engineers with backgrounds from Apple, Uber, Microsoft, Robinhood, and Brex directly into your company. No full-time hire, no bloated retainer. You set a monthly cap and we handle everything.

Book a free strategy call and we'll tell you exactly where you stand.

👉 Book your free call: 30 Min Meeting | YSecurity.io | Cal.com

👉 Learn more: YSecurity | On-Demand Cybersecurity Team for Startups — SOC 2 in 5 Months

View Details

What if 90% of “secured” smart contracts were still exploitable? That’s the reality Olympix founder and CEO Channi Greenwall is seeing on-chain today. She breaks down why traditional audits are failing Web3 teams, why the attack surface is bigger than most founders realize, and how automated security is starting to close the gap.

You’ll learn:

  • Why Web3 security is closer to medical devices and aviation than typical SaaS risk
  • How one exploit can wipe out years of startup effort in seconds
  • The hidden overlap between Web2 and Web3 attack surfaces that founders underestimate
  • What it actually looks like to automate 60–80% of what human auditors do today

Listen to the full episode on your favorite platform.

Channi: www.linkedin.com/in/channi-greenwall
Olympix: www.olympix.security/
Jon: www.linkedin.com/in/jon-mclachlan
Sasha: www.linkedin.com/in/aliaksandr-sinkevich
YSecurity:www.ysecurity.io

🔒 Sponsored by YSecurity

Closing a big deal and getting hit with a vendor questionnaire, SOC 2 request, or pen test requirement? That's exactly what we handle.

YSecurity embeds a team of security engineers with backgrounds from Apple, Uber, Microsoft, Robinhood, and Brex directly into your company. No full-time hire, no bloated retainer. You set a monthly cap and we handle everything.

Book a free strategy call and we'll tell you exactly where you stand.

👉 Book your free call: 30 Min Meeting | YSecurity.io | Cal.com

👉 Learn more: YSecurity | On-Demand Cybersecurity Team for Startups — SOC 2 in 5 Months

View Details

Code ships faster than anyone can review it. Jack Cable, CEO and Co-Founder of Corridor, explains what actually gets missed when teams stop reviewing every pull request, why most security tools surface noise instead of risk, and how Corridor approaches secure-by-design when speed is non-negotiable.
Jack: https://www.linkedin.com/in/jackcable
Corridor: https://www.corridor.dev
Jon: https://www.linkedin.com/in/jon-mclachlan
Sasha: https://www.linkedin.com/in/aliaksandr-sinkevich
YSecurity: https://www.ysecurity.io

🔒 Sponsored by YSecurity

Closing a big deal and getting hit with a vendor questionnaire, SOC 2 request, or pen test requirement? That's exactly what we handle.

YSecurity embeds a team of security engineers with backgrounds from Apple, Uber, Microsoft, Robinhood, and Brex directly into your company. No full-time hire, no bloated retainer. You set a monthly cap and we handle everything.

Book a free strategy call and we'll tell you exactly where you stand.

👉 Book your free call: 30 Min Meeting | YSecurity.io | Cal.com

👉 Learn more: YSecurity | On-Demand Cybersecurity Team for Startups — SOC 2 in 5 Months

View Details

What if your first security hire wasn’t a person, but a simple, guided program that made sense to everyone in your company? In this conversation, Sidekick founder and CEO Phil Howie breaks down how SMBs can build a security and privacy practice from the ground up—long before they can afford a full internal team. We cover the reality of compliance vs real security, working with MSPs, the role of design in security tools, and how founders should think about AI, governance, and future regulation. If you’re a founder trying to grow in regulated markets, this one’s for you.

Phil: https://www.linkedin.com/in/philhowie

Sidekick: https://www.sidekick.co

Jon: https://www.linkedin.com/in/jon-mclachlan/

Sasha: https://www.linkedin.com/in/aliaksandr-sinkevich/

YSecurity: https://www.ysecurity.io/

🔒 Sponsored by YSecurity

Closing a big deal and getting hit with a vendor questionnaire, SOC 2 request, or pen test requirement? That's exactly what we handle.

YSecurity embeds a team of security engineers with backgrounds from Apple, Uber, Microsoft, Robinhood, and Brex directly into your company. No full-time hire, no bloated retainer. You set a monthly cap and we handle everything.

Book a free strategy call and we'll tell you exactly where you stand.

👉 Book your free call: 30 Min Meeting | YSecurity.io | Cal.com

👉 Learn more: YSecurity | On-Demand Cybersecurity Team for Startups — SOC 2 in 5 Months

View Details

Most companies still test security long after code is shipped. That delay creates blind spots.

In this episode, Rejah Rehim, Co-Founder & CEO of Beagle Security, explains how automated penetration testing gives teams a clearer picture of their real exposure—while keeping the process simple enough for developers to run themselves.

Rejah: https://www.linkedin.com/in/rejah/

Beagle Security: https://beaglesecurity.com/

Jon: https://www.linkedin.com/in/jon-mclachlan/

Sasha: https://www.linkedin.com/in/aliaksandr-sinkevich/

YSecurity: https://www.ysecurity.io/

🔒 Sponsored by YSecurity

Closing a big deal and getting hit with a vendor questionnaire, SOC 2 request, or pen test requirement? That's exactly what we handle.

YSecurity embeds a team of security engineers with backgrounds from Apple, Uber, Microsoft, Robinhood, and Brex directly into your company. No full-time hire, no bloated retainer. You set a monthly cap and we handle everything.

Book a free strategy call and we'll tell you exactly where you stand.

👉 Book your free call: 30 Min Meeting | YSecurity.io | Cal.com

👉 Learn more: YSecurity | On-Demand Cybersecurity Team for Startups — SOC 2 in 5 Months

View Details

AI agents can burn through budgets and trust in minutes. Eric Olden, Co-Founder and CEO of Strata Identity, breaks down the control plane founders need: policy-driven guardrails, intent/context/outcome audit, and lifecycle governance—so you can move from sandbox to production with confidence.

Eric: https://www.linkedin.com/in/boughtnotsold

Strata Identity: https://www.strata.io

Jon: https://www.linkedin.com/in/jon-mclachlan

Sasha: https://www.linkedin.com/in/aliaksandr-sinkevich

YSecurity: https://www.ysecurity.io

🔒 Sponsored by YSecurity

Closing a big deal and getting hit with a vendor questionnaire, SOC 2 request, or pen test requirement? That's exactly what we handle.

YSecurity embeds a team of security engineers with backgrounds from Apple, Uber, Microsoft, Robinhood, and Brex directly into your company. No full-time hire, no bloated retainer. You set a monthly cap and we handle everything.

Book a free strategy call and we'll tell you exactly where you stand.

👉 Book your free call: 30 Min Meeting | YSecurity.io | Cal.com

👉 Learn more: YSecurity | On-Demand Cybersecurity Team for Startups — SOC 2 in 5 Months

View Details

Most people think hackers exploit systems. The best hackers improve them. In this episode, Ted Harrington explains how to unlock your “inner hacker”—the mindset that turns obstacles into innovation. From breaking outdated rules to building smarter, safer companies, this conversation reframes what it means to lead with curiosity.

Ted: https://www.linkedin.com/in/securityted/
Ted’s website: https://www.tedharrington.com/
Jon: https://www.linkedin.com/in/jon-mclachlan
Sasha: https://www.linkedin.com/in/aliaksandr-sinkevich
YSecurity: https://www.ysecurity.io

🔒 Sponsored by YSecurity

Closing a big deal and getting hit with a vendor questionnaire, SOC 2 request, or pen test requirement? That's exactly what we handle.

YSecurity embeds a team of security engineers with backgrounds from Apple, Uber, Microsoft, Robinhood, and Brex directly into your company. No full-time hire, no bloated retainer. You set a monthly cap and we handle everything.

Book a free strategy call and we'll tell you exactly where you stand.

👉 Book your free call: 30 Min Meeting | YSecurity.io | Cal.com

👉 Learn more: YSecurity | On-Demand Cybersecurity Team for Startups — SOC 2 in 5 Months

View Details

Cutting support costs usually tanks experience—unless you redesign the system. Veronica Moturi shares how Brinks built an AI “first line,” kept humans for nuance, and improved accuracy by unifying data, verification, and troubleshooting. If you’re scaling support, this is your roadmap to trust, speed, and measurable unit economics. Veronica: www.linkedin.com/in/veronica-moturiBrinks Home: brinkshome.comJon: www.linkedin.com/in/jon-mclachlan 
Sasha: www.linkedin.com/in/aliaksandr-sinkevich YSecurity: www.ysecurity.io 🔒 Sponsored by YSecurity

Closing a big deal and getting hit with a vendor questionnaire, SOC 2 request, or pen test requirement? That's exactly what we handle.

YSecurity embeds a team of security engineers with backgrounds from Apple, Uber, Microsoft, Robinhood, and Brex directly into your company. No full-time hire, no bloated retainer. You set a monthly cap and we handle everything.

Book a free strategy call and we'll tell you exactly where you stand.

👉 Book your free call: 30 Min Meeting | YSecurity.io | Cal.com

👉 Learn more: YSecurity | On-Demand Cybersecurity Team for Startups — SOC 2 in 5 Months

View Details

Deepak Dutt, founder of Zighra, reveals how continuous behavioral authentication is changing the game—from stopping $200M fraud schemes to securing military operations.

Deepak: https://www.linkedin.com/in/deepakdutt/
Zighra: https://zighra.com/
Jon: https://www.linkedin.com/in/jon-mclachlan
Sasha: https://www.linkedin.com/in/aliaksandr-sinkevich
YSecurity: https://www.ysecurity.io

🔒 Sponsored by YSecurity

Closing a big deal and getting hit with a vendor questionnaire, SOC 2 request, or pen test requirement? That's exactly what we handle.

YSecurity embeds a team of security engineers with backgrounds from Apple, Uber, Microsoft, Robinhood, and Brex directly into your company. No full-time hire, no bloated retainer. You set a monthly cap and we handle everything.

Book a free strategy call and we'll tell you exactly where you stand.

👉 Book your free call: 30 Min Meeting | YSecurity.io | Cal.com

👉 Learn more: YSecurity | On-Demand Cybersecurity Team for Startups — SOC 2 in 5 Months

View Details

What if your first lines of code determined your startup’s ability to scale? Dirk Meister, founding engineer at Augment Code, walks us through the intentional security architecture decisions they made on day one—and why trust isn't something you can bolt on later.

Dirk Meister: https://www.linkedin.com/in/meisterdirk/

Augment Code: https://www.augmentcode.com/

Jon McLachlan: https://www.linkedin.com/in/jon-mclachlan/

Sasha Sinkevich: https://www.linkedin.com/in/aliaksandr-sinkevich/

YSecurity: https://www.ysecurity.io/

🔒 Sponsored by YSecurity

Closing a big deal and getting hit with a vendor questionnaire, SOC 2 request, or pen test requirement? That's exactly what we handle.

YSecurity embeds a team of security engineers with backgrounds from Apple, Uber, Microsoft, Robinhood, and Brex directly into your company. No full-time hire, no bloated retainer. You set a monthly cap and we handle everything.

Book a free strategy call and we'll tell you exactly where you stand.

👉 Book your free call: 30 Min Meeting | YSecurity.io | Cal.com

👉 Learn more: YSecurity | On-Demand Cybersecurity Team for Startups — SOC 2 in 5 Months

View Details

Michael Nov, Co-Founder and CEO of Prime Security, reveals how ignoring the design stage creates costly security gaps later. He shares hard-won lessons from building at OwnBackup and launching a startup during crisis.

Michael: https://www.linkedin.com/in/michael-nov
Prime Security: https://www.primesec.ai
Jon: https://www.linkedin.com/in/jon-mclachlan
Sasha: https://www.linkedin.com/in/aliaksandr-sinkevich
YSecurity: https://www.ysecurity.io

🔒 Sponsored by YSecurity

Closing a big deal and getting hit with a vendor questionnaire, SOC 2 request, or pen test requirement? That's exactly what we handle.

YSecurity embeds a team of security engineers with backgrounds from Apple, Uber, Microsoft, Robinhood, and Brex directly into your company. No full-time hire, no bloated retainer. You set a monthly cap and we handle everything.

Book a free strategy call and we'll tell you exactly where you stand.

👉 Book your free call: 30 Min Meeting | YSecurity.io | Cal.com

👉 Learn more: YSecurity | On-Demand Cybersecurity Team for Startups — SOC 2 in 5 Months

View Details

Contracts aren’t controls. Jonathan Mortensen, CEO of Confident Security, lays out a practical path to provably private AI—confidential compute, attestation, and encrypted weights—so you can swap your OpenAI-compatible endpoint, keep crown-jewel data out of vendor training, and still close enterprise deals. Listen to learn how founders can pass security reviews, avoid GPU sprawl, and turn privacy into a sales advantage.

Jonathan: https://www.linkedin.com/in/jonathanmortensen

Confident Security: https://www.confident.security

Jon: https://www.linkedin.com/in/jon-mclachlan

Sasha: https://www.linkedin.com/in/aliaksandr-sinkevich

YSecurity: https://www.ysecurity.io

🔒 Sponsored by YSecurity

Closing a big deal and getting hit with a vendor questionnaire, SOC 2 request, or pen test requirement? That's exactly what we handle.

YSecurity embeds a team of security engineers with backgrounds from Apple, Uber, Microsoft, Robinhood, and Brex directly into your company. No full-time hire, no bloated retainer. You set a monthly cap and we handle everything.

Book a free strategy call and we'll tell you exactly where you stand.

👉 Book your free call: 30 Min Meeting | YSecurity.io | Cal.com

👉 Learn more: YSecurity | On-Demand Cybersecurity Team for Startups — SOC 2 in 5 Months

View Details

AI isn’t just writing code—it’s joining the team. Scott Dietzen, Board Member at Augment Code, explains how Augment’s AI agents are changing the way enterprise software is built, secured, and scaled. These aren’t copilots for toy projects—they’re context-aware agents designed for real-world codebases and real production work.

Scott: https://www.linkedin.com/in/scottdietzen
Augment Code: https://www.augmentcode.com
Jon: https://www.linkedin.com/in/jon-mclachlan
Sasha: https://www.linkedin.com/in/aliaksandr-sinkevich
YSecurity: https://www.ysecurity.io

🔒 Sponsored by YSecurity

Closing a big deal and getting hit with a vendor questionnaire, SOC 2 request, or pen test requirement? That's exactly what we handle.

YSecurity embeds a team of security engineers with backgrounds from Apple, Uber, Microsoft, Robinhood, and Brex directly into your company. No full-time hire, no bloated retainer. You set a monthly cap and we handle everything.

Book a free strategy call and we'll tell you exactly where you stand.

👉 Book your free call: 30 Min Meeting | YSecurity.io | Cal.com

👉 Learn more: YSecurity | On-Demand Cybersecurity Team for Startups — SOC 2 in 5 Months

View Details

Free AI tools promise speed—but they can quietly kill enterprise deals. In this episode, Michael Moore, VP and Head of Legal at Glean, unpacks the legal, privacy, and trust pitfalls that most AI startups overlook. He explains how to design AI products that survive legal scrutiny, earn buyer trust, and actually close.Michael: www.linkedin.com/in/michaeltimmooreGlean: www.glean.com
Jon: www.linkedin.com/in/jon-mclachlan 
Sasha: www.linkedin.com/in/aliaksandr-sinkevich YSecurity: www.ysecurity.io 🔒 Sponsored by YSecurity

Closing a big deal and getting hit with a vendor questionnaire, SOC 2 request, or pen test requirement? That's exactly what we handle.

YSecurity embeds a team of security engineers with backgrounds from Apple, Uber, Microsoft, Robinhood, and Brex directly into your company. No full-time hire, no bloated retainer. You set a monthly cap and we handle everything.

Book a free strategy call and we'll tell you exactly where you stand.

👉 Book your free call: 30 Min Meeting | YSecurity.io | Cal.com

👉 Learn more: YSecurity | On-Demand Cybersecurity Team for Startups — SOC 2 in 5 Months

View Details

AI agents can do more than access your data—they can act. TraceForce.ai founders Xia Hua and Glenn Mulvaney reveal the next big security risk: autonomous agents that operate beyond permission boundaries. From startup execution to securing the agent economy, this special episode covers it all.

Xia: www.linkedin.com/in/xia-hua-ph-d
Glenn: www.linkedin.com/in/glennanthonymulvaney
TraceForce: www.traceforce.ai
Jon: www.linkedin.com/in/jon-mclachlan
Sasha: www.linkedin.com/in/aliaksandr-sinkevich
YSecurity: www.ysecurity.io

🔒 Sponsored by YSecurity

Closing a big deal and getting hit with a vendor questionnaire, SOC 2 request, or pen test requirement? That's exactly what we handle.

YSecurity embeds a team of security engineers with backgrounds from Apple, Uber, Microsoft, Robinhood, and Brex directly into your company. No full-time hire, no bloated retainer. You set a monthly cap and we handle everything.

Book a free strategy call and we'll tell you exactly where you stand.

👉 Book your free call: 30 Min Meeting | YSecurity.io | Cal.com

👉 Learn more: YSecurity | On-Demand Cybersecurity Team for Startups — SOC 2 in 5 Months

View Details

AI-generated fraud is now mainstream—and your team probably can’t tell the difference.
Ben Colman shares hard-earned insights on fighting deepfakes, building detection tech that actually works, and how to stay ahead in the AI arms race.

Ben: www.linkedin.com/in/benpcolman

Reality Defender: www.realitydefender.com

Jon: www.linkedin.com/in/jon-mclachlan
Sasha: www.linkedin.com/in/aliaksandr-sinkevich

YSecurity: www.ysecurity.io

View Details

Your data is moving—through APIs, AI agents, and services—and most businesses have no idea how. Abhi Sharma, CEO and Co-Founder of Relyance AI, joins us to explain how companies are getting AI governance wrong and what to fix. He reveals the 3 elements that define trust in AI—and why missing just one breaks everything.

Abhi:https://www.linkedin.com/in/abhisharmab/
Relyance AI:https://www.relyance.ai
Jon: www.linkedin.com/in/jon-mclachlan
Sasha: www.linkedin.com/in/aliaksandr-sinkevich
YSecurity: www.ysecurity.io

View Details

Most founders think you have to choose between security and usability. Riad Wahby disagrees—and built Cubist to prove it. In this episode, he breaks down how startups can achieve secure key management without sacrificing speed or flexibility.

Riad: www.linkedin.com/in/kwantam
Cubist: www.cubist.dev
Jon: www.linkedin.com/in/jon-mclachlan
Sasha: www.linkedin.com/in/aliaksandr-sinkevich
YSecurity: www.ysecurity.io

View Details

What if security wasn’t something developers had to think about at all? That’s the vision Travis McPeak—former Netflix and Databricks security leader—is building at Resourcely. In this episode, he breaks down why most security tools fail, how trust between security and engineering got broken, and what it really takes to fix cloud misconfigurations before they hit production. Travis also shares what compliance is getting wrong, why developer experience is non-negotiable, and what he learned going from big tech to startup CEO.

Travis: www.linkedin.com/in/travismcpeak
Resourcely: www.resourcely.io
Jon: www.linkedin.com/in/jon-mclachlan
Sasha: www.linkedin.com/in/aliaksandr-sinkevich
YSecurity: www.ysecurity.io

View Details

What if your security tools are actually slowing you down? Bright Security co-founder and CEO Gadi Bashvitz shares how their team went from AI fuzzing to reshaping the way developers tackle vulnerabilities—without drowning in false positives or compliance theater.

  • Why AppSec hasn’t kept up with how engineering works today
  • The 60x cost of fixing bugs in production
  • What dev-first security actually looks like in the real world
  • How Bright is helping teams fix the right issues—faster

Listen to learn how Bright Security is shifting security left—without slowing teams down.

Gadi: www.linkedin.com/in/bashvitz
Bright Security: www.brightsec.com
Jon: www.linkedin.com/in/jon-mclachlan
Sasha: www.linkedin.com/in/aliaksandr-sinkevich
YSecurity: www.ysecurity.io

View Details

AI is no longer just writing code or generating images—it’s shaping how we think.

In this episode, we sit down with AI researcher, professor, and investor Michal Pechoucek to explore how artificial intelligence is shifting from targeting systems to targeting human cognition. Michal outlines four emerging threats that are redefining AI security and explains why deepfakes, behavioral data, and black-box models are putting trust itself at risk.

We also discuss the growing gap between AI innovation and AI safety, how China is approaching behavioral data, and what this shift means for founders, defenders, and the future of digital trust.

Michal: www.linkedin.com/in/pechoucek
Evolution Equity: www.evolutionequity.com
Jon: www.linkedin.com/in/jon-mclachlan
Sasha: www.linkedin.com/in/aliaksandr-sinkevich
YSecurity: www.ysecurity.io

View Details

Everyone’s building AI. Few know how to deploy it safely. Yaron Singer, co-founder of Robust Intelligence (acquired by Cisco), reveals what’s really blocking AI from scaling—and why trust, not tech, is the biggest barrier. A must-listen for any founder navigating the AI wave.

Yaron Singer: www.linkedin.com/in/yaron-singer-76ab6317
Robust Intelligence: www.robustintelligence.com
Jon McLachlan: www.linkedin.com/in/jon-mclachlan
Sasha Sinkevich: www.linkedin.com/in/aliaksandr-sinkevich
YSecurity: www.ysecurity.io

View Details

What happens when a seasoned entrepreneur tackles one of the biggest security challenges for startups? Daniel Marashlian, Co-Founder and CTO of Drata, built a billion-dollar company by automating security audits. In this episode, he breaks down compliance headaches, AI’s role in security, and why automation is the future.

Daniel Marashlian: www.linkedin.com/in/danielzevDrata: www.drata.comJon McLachlan: www.linkedin.com/in/jon-mclachlan
Sasha Sinkevich: www.linkedin.com/in/aliaksandr-sinkevich
YSecurity: www.ysecurity.io

View Details

Too many startups fall into the “more tools = more security” trap. Instead of better protection, they end up with data silos, integration nightmares, and security teams buried in alerts—while real threats slip through the cracks.

Kabir Mathur, CEO of Lean, breaks down why adding more security tools might be your biggest mistake, the hidden costs of tool sprawl, and how to actually build a security stack that works.

Kabir Mathur: www.linkedin.com/in/mathurkabir
Leen: www.leen.dev
Jon McLachlan: www.linkedin.com/in/jon-mclachlan
Sasha Sinkevich: www.linkedin.com/in/aliaksandr-sinkevich
YSecurity: www.ysecurity.io

View Details

Imagine waking up to thousands of customers scammed—using your brand’s name. The website looked real. The emails were flawless. No one saw it coming. This is the new reality of AI-powered fraud. Cybercriminals don’t need weeks to set up a scam anymore—they need just 4 hours.

Rod Schultz, CEO of Bolster AI, exposes the rise of automated phishing, brand impersonation, and large-scale fraud, plus the strategies businesses need to stop attacks before they escalate.

Rod: www.linkedin.com/in/rodschultz
Bolster AI: www.bolster.ai
Jon: www.linkedin.com/in/jon-mclachlan
Sasha: www.linkedin.com/in/aliaksandr-sinkevich
YSecurity: www.ysecurity.io

View Details

What if the way you secure your company is all wrong? Taher Elgamal, the ‘Father of SSL,’ reveals why passwords are failing us, what smarter security looks like, and how businesses can thrive with it.
Taher: www.linkedin.com/in/taherelgamal
Evolution Equity: evolutionequity.com
Jon: www.linkedin.com/in/jon-mclachlan
Sasha: www.linkedin.com/in/aliaksandr-sinkevich
YSecurity: www.ysecurity.io

View Details

What does it take to stop a trillion-dollar criminal enterprise? Damon Fleury, Chief Product Officer of SpyCloud, dives into the murky world of cybercrime and the economy driving it. Fleury shares his journey from code and network stacks to facing off against an elaborate cybercrime ecosystem — one that’s as organized as a traditional business but designed purely to exploit and harm.
Damon: www.linkedin.com/in/damonfleury
SpyCloud: spycloud.com
Jon: www.linkedin.com/in/jon-mclachlan
Sasha: www.linkedin.com/in/aliaksandr-sinkevich
YSecurity: www.ysecurity.io

View Details

Neil Serebryany, Founder and CEO of CalypsoAI, shares his fascinating journey from the National Geospatial-Intelligence Agency to leading a cutting-edge AI security company. We dive into the evolving landscape of AI risks, data protection, and regulatory challenges while exploring the future of AI as it transforms industries and society. Learn how CalypsoAI is paving the way for secure AI adoption and what it means for the future of business and innovation.

Neil: www.linkedin.com/in/neil-serebryany
CalypsoAI: calypsoai.com
Jon: www.linkedin.com/in/jon-mclachlan
Sasha: www.linkedin.com/in/aliaksandr-sinkevich
YSecurity: www.ysecurity.io

View Details

In this episode of the Security Podcast of Silicon Valley, a YSecurity Production, Jon and Sasha sit down with Jacob Berry, Field CISO at Clumio, to explore the intricate balance between security and business growth. Jacob shares his journey from a "punk hacker" to leading security for a cutting-edge cloud data protection company. We delve into the evolving role of the CISO, the complexities of managing security for cloud-based services, and the importance of balancing confidentiality, integrity, and availability. Jacob also discusses the human side of security, from customer conversations to the challenges and opportunities in the fast-paced world of startups. Tune in to learn how Jacob navigates the intersection of technology, privacy, and business strategy.🔒 #CyberSecurity #WebSecurity #TechInnovation #YSecurityProduction #SiliconValleyTech #TechPodcast

View Details

In this episode of the Security Podcast of Silicon Valley, a YSecurity.io production, Hosts Jon McLahlan and Sasha Sinkevich sit down with Vijay Balasubramaniyan, the visionary Co-Founder and CEO of Pindrop Security. From his roots in voice technology at giants like Google and IBM to pioneering security innovations at Pindrop, Vijay shares his unique journey of merging voice and security. Discover how Pindrop is leading the charge against deepfake fraud, revolutionizing voice authentication, and even protecting democracy. Tune in for a deep dive into the future of voice and security, with insights from one of the industry's leading minds.

🎙️🔐 #Cybersecurity #VoiceTech #DeepfakeDetection #AI #Innovation

View Details

Join us in this episode of the Security Podcast in Silicon Valley, where host Jon McLachlan sits down with Kayne McGladrey, Field CISO at Hyperproof. Kayne shares his unique journey from theater to cybersecurity, offering insights into risk management, regulatory compliance, and the evolving landscape of cyber threats. Discover how his background in improv and theater has shaped his approach to cybersecurity, the importance of SEC 10-K disclosures, and practical advice for startups and security professionals. Don't miss this engaging and informative conversation!

Cybersecurity #CISO #RiskManagement #TheaterToTech #Hyperproof #SecurityLeadership #Podcast #Ysecurity 🎭🔒🖥️

View Details

In this episode of The Security Podcast of Silicon Valley, host Jon McLachlan sits down with Haseeb Awan, the visionary Founder and CEO of Efani Secure Mobile. Join us as Haseeb shares his inspiring journey from co-founding BitAccess to creating a bulletproof mobile service designed to protect against the rising threat of SIM swapping and digital identity theft. Haseeb opens up about his personal experiences with security breaches, the challenges he faced, and the innovative solutions Efani offers to ensure top-notch security for its users. Tune in for an engaging conversation filled with insights, resilience, and a commitment to making the digital world a safer place.

View Details

In this episode of the Security Podcast of Silicon Valley, a YSecurity production, hosts Jon McLachlan and Sasha Sinkevich dive into an engaging conversation with Simon Wijckmans, Founder and CEO of cside.dev. Simon shares his journey from working at Hydra, Vercel, and Cloudflare to founding cside.dev, a security startup focused on client-side security. He discusses the evolution of web security, the unique challenges of client-side attacks, and how cside.dev is pioneering solutions to make web security more accessible. Simon's insights into the dynamic landscape of cybersecurity and his passion for innovative solutions make this episode a must-listen. Join us as we explore the future of web security with one of the industry's brightest minds.

🔒 #CyberSecurity #ClientSideSecurity #WebSecurity #StartupJourney #TechInnovation #SeasideSecurity #YSecurityProduction #SiliconValleyTech #CyberThreats #TechPodcast #Infosec

View Details

In this episode of The Security Podcast of Silicon Valley, a YSecurity production, Host Jon McLachlan talks with Lorenzo Thione, a philanthropist, LGBTQ advocate, and investor. As the co-founder and chairman of StartOut, the only LGBTQ incubator, and managing director of Gaingels, Lorenzo shares his unique insights into the intersection of AI and security. They explore the ethical implications of advanced AI technologies, the importance of diversity in the tech industry, and how inclusive investment strategies can drive innovation. Tune in for a thought-provoking conversation on shaping a more equitable future in tech.

View Details

In this episode of the Security Podcast of Silicon Valley, a YSecurity production, Hosts Jon and Sasha dive deep with Suha Can, the Chief Information Security Officer at Grammarly, who oversees the security of over 30 million users and 70,000 enterprise teams worldwide. Suha shares his journey from discovering the internet in a small Turkish café to leading security at major tech giants like Amazon and Microsoft. We explore how he’s pioneering responsible AI at Grammarly, balancing product security with innovation, and preparing for the future of AI and cybersecurity. Tune in for an enlightening conversation on building trust, tackling zero-day exploits, and the evolving role of the CISO in today’s AI-driven world.

CyberSecurity #AI #DataPrivacy #CISO #Grammarly #TechLeadership #SecurityPodcast #Innovation #Trust #ArtificialIntelligence #SiliconValley 🎙️🔐

View Details

Join us on YSecurity Production as Jon McLachlan welcomes Tony Thai, the innovative Founder and CEO of HyperDraft. Discover how Tony’s journey from software engineering to a prominent law firm attorney inspired him to create groundbreaking legal tech solutions. In this episode, Tony shares insights into the intersection of cybersecurity and legal fields, the importance of client communication, and the impact of AI in legal services. Tune in for a deep dive into how HyperDraft transforms document generation and digital workflows, making legal services more efficient and secure.

View Details

Jon McLachlan welcomes Alan Braithwaite, Co-Founder and CTO of RunReveal, to share his journey from Cloudflare to co-founding RunReveal, discussing how his company is revolutionizing the security landscape by making threat detection faster and easier. Discover how RunReveal’s innovative approach to security data is changing the game, and hear Alan’s insights on the future of security tools. Tune in for an engaging conversation filled with industry insights and practical advice!

View Details

In this episode of the Security Podcast of Silicon Valley, hosts Jon McLachlan and Sasha Sinkevich welcome Vivek Ramachandran, the visionary Founder and CEO of SquareX. Vivek shares his inspiring journey into the cybersecurity field, sparked by his fascination with the power of individual hackers and their impact on massive websites. He discusses the evolution of the security landscape over the past 25 years, emphasizing the shift from lone warriors to collaborative team efforts against sophisticated cyber threats.

Vivek introduces SquareX’s innovative approach to web security, focusing on a browser-native solution to protect enterprise employees from online attacks. He elaborates on the challenges and breakthroughs in developing a seamless, effective browser extension that enhances security without compromising user experience. With insightful discussions on the importance of patience, community contributions, and the evolving role of AI in cybersecurity, this episode is a must-listen for entrepreneurs, security professionals, and anyone interested in the future of online protection. Tune in to hear Vivek’s vision for the future and his advice for aspiring entrepreneurs in the tech industry.

View Details

In this episode of The Security Podcast of Silicon Valley, host Jon McLachlan sits down with Dr. Georgianna Shea, the Chief Engineer at MITRE and Chief Technologist at the Foundation for Defense of Democracies. Dr. Shea shares her extensive experience in cybersecurity, from her work with the Department of Defense to her current role in influencing national security policy. Discover her insights on the importance of resilience in cybersecurity, the significance of Software Bill of Materials (SBOM), and how AI and quantum computing are shaping the future of cyber defense. Tune in for an inspiring conversation with one of the industry's leading experts.

View Details

Welcome to a new episode of the Security Podcast in Silicon Valley, a YSecurity production, where we delve into the ever-evolving landscape of cybersecurity, with Clea Ostendorf, Field CISO at Code42, as our distinguished guest. Clea's journey from an aspiring diplomat to a front-runner in cybersecurity offers profound insights into her unique approach that is reshaping the realm of data protection. Join us as our host Jon McLachlan, a seasoned expert in the field, engages Clea in a deep dive into how she merges traditional security methods with the pressing challenges of today’s digital world. Discover how Clea advocates for a collaborative security community and navigates the complex balance of work-life harmony in a demanding field. Tune in to uncover Clea’s strategies for fostering a culture of security that supports growth and innovation while protecting against insider threats. This episode is a must-listen for anyone interested in the intersections of technology, security, and corporate culture.

View Details

Host Jon McLachlan, welcomes Polina Morozov, a distinguished Security Recruiter from Grammarly (and formerly Robinhood) onto Security Podcast of Silicon Valley, a YSecurity.io production. As we peel back the layers of security and recruiting, Polina shares her remarkable journey from aspiring diplomat to a key player in tech hiring, highlighting the crucial role communication plays in connecting talent with opportunity. Discover how Grammarly's cutting-edge tools not only enhance written communication but also serve as a catalyst for Polina's career. Through candid conversations, this episode offers a unique lens on the challenges and triumphs of recruiting in the security tech world, emphasizing the importance of pushing boundaries, fostering trust, and the undeniable impact of cultural and global influences on business practices. Tune in for an engaging exploration of what it takes to secure top talent in the ever-evolving landscape of cybersecurity, or, land your next huge opportunity and accelerate your own career in cybersecurity.

View Details

Host Jon McLachlan sits down with Craig Goodwin, Co-Founder and CEO of Bleach Cyber. Craig shares his remarkable journey from military intelligence in the UK to leading cybersecurity roles at major corporations like Monster Worldwide, CDK Global, and Fujitsu, ultimately founding Bleach Cyber. Discover how Bleach Cyber aims to simplify cybersecurity for small businesses, making top-tier security accessible and manageable. Craig also dives into the human element of cybersecurity, the challenges of startup life, and the importance of resilience and simplicity in both business and life. Tune in for a compelling conversation filled with insights, practical advice, and Craig's vision for the future of cybersecurity.

🎙️🔐 #Cybersecurity #SmallBusiness #Startups #SimplifySecurity #Leadership #MilitaryToStartup #TechInnovation #YSecurity #SecurityPodcast

If you enjoy this episode, please like and subscribe.

For more insights, visit Bleach Cyber and YSecurity.

View Details

Host Jon McLachlan sits down with Benoit Chevallier-Mames, VP of Privacy Preserving Cloud and Machine Learning at Zama, as our first returning guest after , The Security Podcast in Silicon Valley, a YSecurity production. Dive into the transformative world of Fully Homomorphic Encryption (FHE), a technology that promises to revolutionize data privacy in AI applications. As an expert at RSA in SF in 2024, Benoit shares insights from his journey, from pioneering efforts at Apple to pushing the boundaries of privacy tech at Zama. Discover how Zama's cutting-edge advancements set the stage for a new era where data privacy and machine learning coexist seamlessly. Please tune in to learn about the practical applications of FHE in various industries and how it's shaping the future of secure data processing.

🔒💻 #SecurityPodcastSV #FHE #DataPrivacy #MachineLearning #AI #TechInnovation #YSecurity

View Details

🚀🔒 Dive into the intersection of AI and security with Augment Computing's leaders, Evan Driscoll, VP of Engineering(formerly Pure Storage, General Magic) and Dion Almaer, VP of Product(formerly Shopify, Google, Walmart.com, Mozilla), to uncover how Augment's groundbreaking SaaS platform is revolutionizing the developer experience with AI. This thrilling episode of The Security Podcast of Silicon Valley, brought to you by YSecurity, is hosted by Jon McLachlan and Sasha Sinkevich. 🌟👨‍💻

🤖💡 Uncover the fusion of cutting-edge AI and stringent security measures in Augment's robust SaaS platform, a game-changer in software development. What sets Augment apart in the competitive tech landscape? How does their security-first approach shape their platform's architecture and user experience? Explore these intriguing questions and more! 🛡️🧠 # AIInnovation # CyberSecurity # TechSavvy # FutureTech # YSecurityProductions # SaaSExcellence # SiliconValleyInsights

🔗 Learn more about AI's transformative power in software engineering at Augment Computing and on security at YSecurity.io.

🎧 Don't miss this enlightening conversation on how Augment is pioneering secure software solutions, exclusively on The Security Podcast of Silicon Valley. Stay updated with the latest episodes and expert insights on the convergence of AI and security by following and subscribing! 🌐🎤

We would love to hear from you! info@ysecurity.io for questions and comments on this show. If you enjoyed this show, please consider giving our podcast a five-star review, leaving a comment, and sharing with your friends and network.

TechTrends #SecureSoftware #AIandSecurity #PodcastForDevelopers #TechPodcasts

View Details

Don't miss this blend of technology, ambition, and forward-thinking only of The Security Podcast of Silicon Valley, a YSecurity.io production, as we dive into Avery Pennarun's journey, the Co-Founder and CEO of Tailscale, from starting his first company in college to selling it to IBM, taking a detour at Google, and eventually creating what's known as the anti-Google of cyber startups, Tailscale. Avery gives us a candid look at the evolution of a billion-dollar valuation company. Discover how Tailscale became the first security infrastructure product adopted bottom-up by individual engineers rather than imposed from the top down. Join us as we explore the fine line between security and connectivity and how Avery's vision for Tailscale's is reshaping the future of the Internet. #CyberSecurity #Tailscale #Networking #StartupJourney #ZeroTrust #Innovation 🔐💻🚀

🔗 Learn more about Tailscale: https://tailscale.com/ or connect with Avery Pennarun (Co-Founder and CEO)

🔗 Learn more about YSecurity: https://ysecurity.io or connect with Jon McLachlan (Co-Founder and Podcast Host)

If you feel this conversation is worth a 5 star review to please rate the show, subscribe, and spread the word! 📣

View Details

Dive into the heart of cybersecurity innovation with host Jon McLachlan and guest Michael Moore, the visionary Chief Privacy Officer at Lacework, and previously Pure Storage, on this episode of The Security Podcast of Silicon Valley, a YSecurity.io production. In this compelling episode, Michael shares his path from engineer to legal expert to cybersecurity trailblazer. Michael reveals his unique insights into the critical intersection of technology, privacy, and law, illuminating how these elements are essential in shaping the security landscape. Get this exclusive inside look at Lacework's advanced strategies for combating digital threats and safeguarding the digital future, straight from the expert leading the charge. This episode is an essential listen for anyone intrigued by the balance between cutting-edge cybersecurity measures and the imperative of safeguarding personal privacy in an increasingly vulnerable digital age.

Links referenced during the show:

Don't Let Your Company Reputation Be Held Ransom - By Michael Moore, Lea Kissner, Merritt Baer, 05 March, 2024

Product Privacy Done Right By Michael Moore, Lea Kissner, Alan Mulvaney, 04 March, 2024

View Details

Jon McLachlan hosts the visionary Jose Arrieta, the former CIO and Chief Data Officer at the US Department of Health and Human Services, in this enthralling episode of The Security Podcast of Silicon Valley, a YSecurity production. In this revealing conversation, Jose shares insights from his dynamic career spanning government, academia, and the intersection of cybersecurity and healthcare innovation. Discover how his unique approach to challenges and opportunities is shaping the future of secure solutions in critical sectors. From tackling potential nation-state cyber threats during the pandemic to reimagining the EHR space and advocating for data ownership, Jose's journey is a testament to the power of imagination, innovation, and going all in on the things that matter. Join us for a session packed with invaluable lessons on leadership, resilience, and the transformative potential of technology in our lives and society.

View Details

In this captivating episode of a YSecurity.io production, we delve into the mind of Steve Orrin, the Federal CTO at Intel, who provides valuable insights into various topics, including AI, Trusted Execution Environments, Cloud Computing, Team Building, Mergers and Acquisitions, and Entrepreneurship. Steve began his career as an entrepreneur, but after Intel acquired his company, he took his career to the next level and has been with Intel for over 18 years. As the Federal CTO at Intel, he leads Intel’s efforts in the DoD and Federal Government verticals. Throughout the interview, Steve shares personal anecdotes and life lessons, discussing how he transitioned from a background in biology to a successful career in technology and private industry.

View Details

In this enlightening episode of The Security Podcast of Silicon Valley, a YSecurity.io production with your host Jon McLachlan, we are honored to host Nick Sullivan, a trailblazer in the realm of cryptography and security. Formerly the Head of Cryptography at Cloudflare and now a pivotal figure in startup advisory and angel investing, Nick shares his journey from delving into pure mathematics at Waterloo to shaping the security landscape of the internet. He reflects on his early career, from researching cryptography to his impactful roles at Symantec, Apple, and eventually Cloudflare, where he spent over a decade innovating and advising on next-gen security protocols.

Nick offers an insider's view on the challenges and triumphs of developing Cloudflare's robust security infrastructure, emphasizing the importance of privacy, research, and the collective effort to safeguard the web. He discusses groundbreaking work on global data insights, the evolution of internet security practices, and his advisory role in nurturing startups toward solving today's most pressing security dilemmas.

Join us as Nick Sullivan imparts wisdom on the significance of curiosity, the power of collaboration, and the unyielding pursuit of building a better, more secure Internet. This episode is a must-listen for anyone passionate about the future of technology, privacy, and the endless possibilities that cryptography offers in securing our digital world.

View Details

Welcome to "The Founder's Guide to Compliance," a YSecurity.io production, hosted by Jon McLachlan and Sasha Sinkevich. We tear down the complexity surrounding compliance standards like SOC2, NIST, FIPS, PCI-DSS, HITRUST and the myriad facets of cybersecurity. Whether you're a startup founder knee-deep in the trenches or a seasoned executive navigating the ever-evolving landscape of digital security, this podcast is your no-BS zone for getting to the essence of what these standards mean for you and your business.

Jon, a Minnesota native and security enthusiast, brings his rich background from Apple and various startups to the table, sharing insights born from a life that embraces risk for greatness. With a passion for security that's as undeniable as his love for motorcycles, Jon's journey is about leading by example, turning challenges into stepping stones for success.

Sasha, starting his cybersecurity journey in Silicon Valley, has been shaped by the brilliant minds around him. His experience spans working with heavily regulated industries, creating security solutions for global financial institutions, and navigating the startup world from the ground up. Sasha's story is one of transformation, leveraging complex compliance requirements into simple, actionable strategies.

Together, Jon and Sasha aim to demystify compliance, making it accessible and understandable. They're here to show you how navigating these standards isn't just about ticking boxes but seizing opportunities to elevate your business.

"The Founder's Guide to Compliance" is empowers you with the knowledge and tools to not only meet but exceed the expectations of your customers and investors. Dive into a world where compliance becomes your competitive edge, enabling your startup to thrive in the digital age. Join Jon and Sasha as they guide you through the what, why, when, and how of compliance, turning potential hurdles into launchpads for success.

Welcome to the podcast where compliance meets clarity, and where your startup's security journey begins.

View Details

In this episode of The Security Podcast of Silicon Valley, host Jon McLachlan of YSecurity.io invites Feross Aboukhadijeh, Founder and CEO of Socket.dev, a supply-chain cybersecurity company, to share his compelling journey as he tackles some of the most pressing challenges in software development security. Feross, a Stanford graduate and former intern at Intel, Facebook, and Quora, shares his journey from developing PeerCDN, a pioneering peer-to-peer content network, to his current venture, Socket.dev. Discover how Socket.dev is addressing critical software supply chain vulnerabilities by utilizing innovative technologies, including heuristic analysis and the latest LLMs. This episode offers valuable insights into the evolving cybersecurity landscape and Feross's unique approach to tackling some of the most pressing challenges in software development security. Join us for a captivating discussion that's a must-listen for anyone interested in the future of cybersecurity.

View Details

In this episode of The Security Podcast of Silicon Valley, your host Jon McLachlan of YSecurity.io welcomes Aviv Grafi, founder and Innovator of Votiro, who shares his journey from the IDF's prestigious 8200 unit to revolutionizing cybersecurity. Aviv's passion for hacking and reverse engineering in his youth led to his success in both military and civilian sectors. He discusses the inception of Votiro, a company that stands out for its unique approach to document security, prioritizing the extraction of safe content over traditional threat detection methods. Aviv emphasizes the importance of proactive and enabling security solutions in the digital era, particularly in response to the new challenges posed by widespread digital transformation. Offering insights into the entrepreneurial mindset, Aviv highlights the balance between embracing the highs and lows of the journey and maintaining a positive, enabling approach to security. Join us for an episode filled with invaluable experiences and forward-thinking perspectives in cybersecurity.

View Details

In this compelling YSecurity.io podcast series, Ganesh Krishnan recounts his incredible 25+ year journey in security and shares why he Co-Founded Anzenna, a Cyber Security Engagement and Collaboration Platform.

Employees are key to maintaining overall security. Their actions can make a big difference. Cybersecurity teams handle monitoring and updating protocols, but employees must stay aware of trends and follow best practices. Prioritize cybersecurity by investing in security measures, providing training, and encouraging participation. When employees take responsibility for protecting data and systems, security becomes a collective effort. This is Anzenna.

View Details

Join us on a journey into the forefront of data security innovation in this captivating episode of a YSecurity.io production, featuring Elizabeth Nammour, Co-Founder and CEO of Teleskope. Elizabeth, or Lizzy as she's known, brings a wealth of experience and a deep passion for data security, honed during her time at Airbnb. There, she played a pivotal role in developing strategies to protect personally identifiable information (PII), ensuring compliance with GDPR, CCPA, and other critical data security regulations.

Teleskope stands as a testament to Lizzy's commitment to advancing data security, leveraging artificial intelligence to offer protection by default. Through her leadership, Teleskope is redefining how businesses secure their most sensitive information, offering innovative solutions that meet the evolving challenges of the digital age.

But this episode is more than a deep dive into the mechanics of data security. Lizzy shares personal stories that have shaped her journey, from her initial forays into the tech world to the founding of Teleskope. Her reflections offer invaluable insights for entrepreneurs and security professionals alike, highlighting how personal experiences and professional challenges can forge a path to innovation and success.

Listeners will be inspired by Lizzy's perspective on the intersection of technology, security, and entrepreneurship. Her stories illuminate the challenges and triumphs of building a startup focused on one of the most critical issues facing businesses today: data security.

Tune in to this YSecurity.io production for an engaging and enlightening conversation with Elizabeth Nammour. Whether you're an entrepreneur, a security enthusiast, or someone passionate about leveraging technology for a safer digital world, this episode promises a wealth of knowledge and inspiration, showcasing the power of AI in transforming data security and the journey of a visionary leader shaping the future of the industry.

View Details

Kevin Kane is the Co-Founder and CEO of Ambit, Inc. dba American Binary, a startup specializing in protecting businesses against current and next-generation cyber threats. With expertise in post-quantum cryptography and high-performance network infrastructure, catch a glimpse into the future of quantum computing and its devastating impact on RSA and EC public key cryptography, potentially halting secure communications across the Internet and globalization as we know it. In this episode, Kevin shares vulnerable moments and thoughtful insights on religion, philosophy, self-improvement, psychology, and how security plays a crucial role in today's interconnected and globalized world. Don't miss out on this insightful and engaging conversation.

View Details

Sergey Stelmakh engages the intriguing question of how to marry innovation (risk taking) with security (risk mitigation), how to build effective teams, and how his life led him down the path into security in engineering-driven companies, such as Head of Security Engineering at Yugabyte, Platform Security Architect at MuleSoft (acquired by Salesforce), Lead Security Architect at Symphony Communications, all from his roots as in mathematics as Assistant Professor at Belarusian State University.

View Details

Dominik Schürmann, the Co-Founder and CEO of heylogin, shares an incredible journey from childhood, and research, toward more usable security. How are usable security values different from "formal" or "provable" security? Why does it matter? How does that change where you spend your time and energy? And how can we integrate with human nature and our organic tendencies to build more secure software? These questions, and many more, guide Dominik to start heylogin, as he shares his outside-the-box vision for a better and more secure future.

View Details

Rod Schultz reflects on his childhood experiences and heroes, how he got into security, how that led him to Apple's DRM FairPlay team, Zoom's Head of Product Security and Privacy, and now DUST Identity's VP of Product.

View Details

David Carpe, Founder of Carpe Search Partners, shares deep insights on the professional value of networking (connecting with and offering service to the people around us) in the security community. We explore how to network effectively, offer a give, and how networking differs from charity, philanthropy, and everyday friends. Davides some profoundly personal views on the supposedly Great Silent Resignation, which may surprise you. We end with some gre. Youvice, you don't want to miss it.

View Details

Colin Bitterfield connects growth and security through standardization and proper documentation at People Data Labs. In this episode, he shares his strategies and tactics for building and maintaining a business-first security team that prioritizes people, so everyone wins.

View Details

Andrew Spangler, Head of Security and Compliance at Harness, shares some deep insight from his humble yet extensive experiences as a security professional. Join us for a light-hearted and profoundly human discussion on building trust, leading teams, interviewing strangers, overcoming security challenges, celebrating security victories, and career development in the security community.

View Details

David Gurle is a serial entrepreneur whose career has been a catalyst to positive change in secure collaboration and communication, from everywhere to Thomson Reuters, Skype, Microsoft, Perzo, and Symphony Communications. Today, he's the Founder and Executive Chairman of Hive, a distributed cloud computing and storage platform that disrupts the expensive, error-prone, and insecure centralized compute and storage paradigms. He shares personal stories of growing up in Beruit, Lebanon, amid a civil war, where he quickly learned the value of empathy and diversity.

View Details

Aman LaChapelle shares his fresh engineering mindset on security, privacy, AI, big data, compute infrastructure, and scaling. At Modular, he's rebuilding AI infrastructure for everyone, which means that data privacy is top of mind. We end with a lively exploration of what's missing from the ecosystem, and you won't believe what it is.

View Details

David M'Raihi is the Chief Product Security Officer at Rivian with broad expertise in cryptography and software security. Join us (guest David M'Raihi and host Jon McLachlan) as we explore what it takes to build a security team, break RSA, or just enjoy an intentional and deliberate life.

View Details

Michael Crandell, CEO at Bitwarden Inc., shares his inspirational vision and deep wisdom from his journey at Bitwarden. Bitwarden drives collaboration, increases security, and boosts productivity, with the power of open source + community, as the easiest way to secure all your passwords and sensitive information.

View Details

Sergej Dechand shares his security journey from usable security research to Co-Founding Code Intelligence, where he is CEO. Code Intelligence delivers open-source static analysis-guided fuzz testing that enables developers to simplify software security testing without modifying their code.

View Details

Benoit Chevallier-Mames shares a glimpse into his amazing career as a cryptographer, engineer, and leader at Apple and now Zama, where he's built software that has made a quiet yet serious impact on data security for billions of users. We explore the hard lessons learned at Apple and the technical grit behind Zama's approach to Machine Learning specific Fully Homomorphic Encryption (FHE) open-source SDK. Benoit gracefully closes with incredible words of wisdom.

View Details

Join me for a great conversation with Aaron Painter, the CEO of Nametag Inc, on the future of authentication and "Sign in with ID" as a more trusted alternative to passwords and device-based authentication.

View Details

Anders Eknert's journey that led him to Styra was peppered with insight and experience towards the best practices for authorization, answering the question, "What are you allowed to do?" Join us as he shows us how the wild-wild-west is slowly moving toward the history books. Email him at, anders@styra.com.

View Details

Sean Cassidy, Head of Security at Asana, shares stories and lessons learned through his journey in building outstanding security teams and impactful products.

View Details

Join a fantastic discussion with Will Butler on how he launched his career into red teaming by hacking airport security systems as a youngster and realizing his passion for security. We deep-dive into the different types of red teams, why penetration testing adds business value, and what goes into a successful attack. We explore the different kinds of creativity needed to find vulnerabilities, why diversity is essential, specifically on red teams, ethical/moral dilemmas penetration testers often face, and more.

View Details

Ben (he/him/they) is a software engineer specializing in computer security who has worked at startups, large tech companies, research labs, and intelligence agencies. In this episode, Ben shares how he got into security, his experiences along the way, the challenges he's faced, and how he sees the future of Threat Intelligence and Cyber Security.

View Details

Biff W. Clark, Managing Partner/ Cyber Security Consultant of Coefficient Technologies LLC, Biff has degrees from Midland University [BA in Business Management] and the Utica College [MS in Cyber Security, Cyber Operations]. He has 25 years sales and sales leadership experience with 15 years in selling and consulting with companies for information technology and cyber security solutions. Biff serves as Board Chair for The Hidden Genius Project, a non-profit Technology incubator for training and mentoring black male youth in technology, leadership, and entrepreneurship. He is an Advisor for Mindblown Labs, a financial wellness innovation lab and gamification studio focused on financial education, and a Venture Partner with Telescopic Ventures, a fund focused on frontier and emerging tech. Biff is a current member of the International Association of Police Chiefs and the Information Security Systems Association. (bwclark@coefficient.us)

View Details

An engaging discussion with Paul Nguyen, Co-Founder and Co-CEO of Permiso Security.

View Details

Founder and CEO Dan Sherry and Co-Founder COO Grace Chi join for an engaging discussion on Threat Intelligence, how Pulsedive makes hard data problems simple, and how community feedback is key to successful security.

View Details

Robert Rounsavall is the Co-Founder and President of Trapezoid Inc. a company that develops visibility and management tools around the security and operations of firmware. In this interview, we discuss his childhood experience that lead him into security, a bit of his military background, and compare startups and security to Ultramarathon running.

Robert Rounsavall has deep experience in security architecture and has spent time working in the large datacenter and cloud provider space. Robert has led incident response teams for both large enterprise and federal government organizations.

Robert also:

-holds a patent for a portable large-scale, remotely-deployable network security system (http://www.google.com/patents/US8931087). -is a contributing author in the Computer and Information Security Handbook ISBN: 978-0123743541 -is a contributor to the Open Data Center Alliance Provider Assurance Usage Model -was an early adopter of the CCSK (Certificate of Cloud Security Knowledge)

He also served 12 years in the military where he served as a Navy Crypto-Linguist Chief Petty Officer.

View Details

Michael Malone, Founder and CEO of SmallStep, joins for an in-depth and compelling discussion focused on Identity, Certificates, X.509, and Authentication.

Michael offers us the whole story of the humble beginnings of SmallStep. They were initially focused on Authorization but quickly pivoting to Authentication. Michael shares his philosophy around hiring, work ethics, and his pragmatic approach to building a business. He happily contributes one small step toward a more secure future.

View Details

Dylan Ayrey, Founder and CEO of Truffle Secure, joins for thought-provoking on how open-source projects, and Tuffle Hog in particular, are helping everyone build a more secure, resilient, transparent future.

How do you find secrets in a GitHub repo, including your Git history? Are you skeptical that open-source projects can be used to build a real company, or, secure software? What's the difference between Community and Open-Source? Why should engineers care about Open-Source projects, but especially engineers early in their careers? How do you make the case to build an Open-Source in a big company?

View Details

Fredrick Lee ("Flee"), the CSO of Gusto, joins for a thought-provoking, bold, and honest discussion on the importance of diversity when building engineering teams in general and security teams in particular.

Flee shares humble childhood stories growing up, attending a boarding school in the deep south where he helped teachers with the school's computers and discovered the hacker magazine 2600. He took inspiration from John Lee (aka, John Threat), the first Black Hacker Flee knew and one of the participants in the 90's "Great Hacker War." Flee learned a special appreciation for the purity of the challenging puzzles behind security problems, soaking in everything he could from a diverse community of outcasts, with computers acting as the great equalizer.

But also, what is it about diversity that produces resiliency in teams and products? Building diverse teams is the right thing to do socially, but is it also the correct thing to do technically? Absolutely, but why? Further, what roles do collaborations and open-source play in the security community? Finally, Flee describes some of the best days he's had as the CSO at Gusto, one of them going back to Gusto's internal response to George Floyd's murder.

View Details

Michael Brooks, CISO at Trava, joins for a thought-provoking discussion of cyber risk, ransomware attacks, business preparedness, and risk management.

The fundamental core issue behind all cybersecurity initiatives is data security. If we don't understand the value of our data, then what do we have? The question we might need to be asking ourselves: Can your business function without it? If not, then it's business-critical, and should be protected.

View Details

Join me for an interview with Prakash Darji, General Manager of Digital Experience Business Unit at Pure Storage, for a lively discussion on the future of storage and security.

Everything from Pure Storage's recent Portworx acquisition to recovering quickly from ransomware, take a sneak peek into the future of storage and security as Prakash sees it.

View Details

Join me for an interview with Leigh Honeywell. As founder and CEO of Tall Poppy, she's building tools and services to help companies protect their employees from online harassment and abuse.

Together, we share many vulnerable and authentic moments as we explore online harassment, abuse, and how Tall Poppy helps humans navigate difficult situations while still building a thriving business that makes the web better for all of us.

View Details

An interview with Wesley Belleman, Cyber Warfare Operator at the California Air National Guard and System Engineer at Palo Alto Networks, and his journey through Security Operations in the United Space Space Force.

In this episode, we dive into what a SOC is, how new technology changes our ability to respond to threats, and what the open problems are still open. We explore the cultural differences between civilian and military security operations and discuss various open-source projects such as Security Onion or MITRE Att&ck that can be used to build your own SOC. 

So what will the future of SOC's look like? Wes echo's Anton Chuvakin predictions that SOC's will be entirely automated, likely within our lifetimes, but not soon.

View Details

An interview with Daniel Feldman, Cloud Security Architect at HPE (formerly Scytale.io), as we discuss his journey through service authentication with the open standard SPIFFE and the implementation SPIRE.

In this episode, Daniel tells the story of how he came across this problem of authentication at Veritas Technologies, why he joined a small startup Scytale.io to continue focusing on his security journey, and touch on what it's like at Hewlett Packard Enterprise. We end on a forward-looking note on what the future of cloud security might look like, with many challenging and open cloud security problems out there.

Daniel is happy to meet others with similar interests and experiences, so in that spirit, he is open to connecting and sharing stories and ideas. He can be reached on LinkedIn or Twitter as d_feldman.

View Details

An interview with Andrew Gontarczyk, Chief Information Security Officer at Pure Storage, on the challenges of building a security team.

When is the right time for a company to build a security team? What types of Security Teams are there (Product Security, Infrastructure Security, DevSecOps, Red Team, Blue Team, Purple Teams), and what do they do? As a security leader, how do you influence the rest of a company towards a more secure posture? What are your favorite interview questions, and why? What role does diversity play in your team building? What's your leadership style? Even with a security team in place, what still keeps you up at night?

View Details

Join me for an interview with Anand Ganesh, Founding Software Architect at Hammerspace, to discuss how storageless data solves traditional B2B storage security problems.   What is storageless data? How does Hammerspace encrypt data at rest? How do disaster recovery, backup, and snapshot data protection mechanisms work in Hammerspace?  Why does data-as-a-service eliminate the need for fail-overs (passive-to-active transitions)? How do permissions work? How does intelligent data classification work in Hammerspace? How does Hammerspace help a customer recover from a ransomware attack? Do we have to trust our storage vendors such as AWS, Google, Azure, or even on-prem data centers? How do you securely delete data in a globally distributed system, like Hammerspace?