Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

The Truth About Insider Threats: AI, Paranoia & Hybrid Work | MSP Series

Every organization thinks insider threat is someone else's problem — until it isn't. Join host Alex Courson as she sits down with two leading experts who have spent their careers on the front lines of insider risk: Shawnee Delaney (former CIA-trained DIA case officer and CEO of Vaillance Group) and Peter Hadjigeorgiou (Field CISO at Teramind). Whether you run a business, work in IT, or manage people in a remote, hybrid, or in-office environment, this conversation is for you. We dive deep into AI in the workplace, workplace paranoia, and how organizations need to evolve to drive real change.

Hot Take: Over-permissioned agents will be the next big breach.

The next big breach won't be a hacker. It'll be an over-permissioned agent. Someone approved an agent action at some point, for a reason that made sense at the time. But access persisted long after a task was performed. Stale permissions without human intervention could turn into exposure. Listen to perspectives from people who see this problem from different roles.

DORA Compliance: Inside a Fireblocks Pooled Audit

An internal auditor from Boerse Stuttgart Digital explains how a Fireblocks-hosted pooled audit helped meet DORA's third-party ICT requirements. Instead of every customer auditing Fireblocks one by one, the pooled audit community joined forces on a single common audit: shared scope, shared evidence, shared result. In this conversation, the pooled audit coordinator walks through how the community set the scope, why a pooled audit covers customer-specific requirements that a standard SOC 2 might miss, and how Fireblocks supported the process with subject matter experts, documentation, and on-site coordination.

The Difference Between Hype and Documented Risk

How do security leaders separate legitimate AI security concerns from fear, uncertainty, and doubt? In this clip, Rik Ferguson explains why today's warnings about autonomous threats are different from past predictions. The evidence is already being documented, tested, and observed across the cybersecurity industry, making this a present challenge rather than a future possibility.

What Can Nico Hülkenberg Teach Cybersecurity Pros?

InfoSec conference speakers should give cybersecurity professionals a clear reason to invest their time in attending. The decision to book Formula 1 driver Nico Hülkenberg for InfoSec Europe raises an interesting question about whether celebrity keynote speakers deliver more value than experienced industry practitioners.

Is "Assume Breach" No Longer Enough?

For more than a decade, security strategies have been shaped by the principle of "assume breach." But what if the next evolution of cybersecurity requires a different assumption? In this clip, Rik Ferguson discusses why organizations should begin building and testing security architectures based on the expectation that attackers will increasingly be autonomous and non-human, and why defenses must evolve accordingly.

What's Wrong With the Current State of Cyber Conferences

Cybersecurity conferences lose their value when the same vendor-led conversations keep repeating themselves. Community events such as BSides, Hack Glasgow and SteelCon offer a different model, where sponsors build credibility by supporting the community rather than throwing sales material at attendees.