Bridging the gap between Zero Trust theory and practice. Unpacking the hurdles of continuous verification and least privilege in complex access environments.
Cybersecurity teams have faced major shifts before—from advanced persistent threats to ransomware. Now, Frontier AI is accelerating vulnerability discovery and creating new challenges for defenders. In this episode of Let's Talk Security, Forescout CEO Barry Mainz sits down with cybersecurity evangelist and former practitioner Karsten Abata to discuss the concept of the "Control Gap"—the time between identifying a risk and having the controls in place to effectively contain it.
Your WAF is doing its job. It's blocking SQLi, XSS, and the usual suspects. But here's the problem: it wasn't built for APIs, and it definitely wasn't built for AI agents. APIs now power nearly every digital experience. And AI agents — the automated systems that access your APIs at machine speed, at machine scale — are the fastest-growing source of that traffic.
Earlier this year, a bill arrived from one of 1Password’s AI vendors for 5x the value of the original contract. The initial agreement came in below a certain threshold, so it never reached the right approvers for review. By the time it did, we had a much clearer understanding of how quickly AI costs can add up.
You deployed Zscaler, passed the audit, and got leadership's sign-off. The project closed, and the dashboard has been green ever since. That moment is usually right about when the real risk starts to take shape.
Every Patch Tuesday starts the same way: New patches become available, and administrators begin answering the question, Is this patch safe to deploy? That answer rarely comes from a single place. Most administrators read the vendor's knowledge base article, look for known issues, monitor community discussions, and wait for early deployment feedback before rolling the patch out across the organization.
If your organization runs anything on the public internet, a mandate that changes how often you renew TLS certificates is already in effect. In March 2026, the maximum validity of public TLS certificates dropped from 398 days to 200. What fewer teams have worked out is that the first certificates issued under the 200-day cap start expiring at the end of September. That makes this autumn the first real test of whether your renewal workflows are ready for what the next three years will ask of them.