Craig Thomas

speaker
382 appearances 2 recordings 1 series first heard Jun 2026 last heard 8 Jul

Craig Thomas’s voice in public audio — every appearance, attributed to the second.

Trend

recordings per month · last 12 months
1 · Jul OctJan 26AprJulnow

Recordings per month over the last 12 months — 2 in all, peaking in Jul 2026 with 1.

Appearances

newest first · ▶ plays the moment
There are solutions, and we're starting to see those solutions for how a CISO can gain this access and enable the business, but it has to shift from gate controls to runtime controls.
Yeah, so those network identity layers we talked a little bit about already, but they see who and where, but they aren't really seeing what.
The application layer does see inputs and outputs, but no kind of intermediate behavior, what tools were called, what memory was accessed, what reasoning steps were taken.
And so shifting that to kernel level visibility, it actually sees those system calls, the file IO, the process behavior,
what the model is actually doing versus just what model is called on the host and not just what it's saying at that API boundary.
And if you're only watching certain layers, you're only watching that front door aspect.
And so as you dive in the kernel layer, you get the aggregate of all these things.
And you need all those things at runtime to truly see and shift and protect in real time the whole picture.
And then, like we talked about, that enables you to leverage AI within your environments to get the most from the AI that you're investing in for both internal processes as well as customers.
Yeah, yeah, great question.
You've got to shift from these broad controls to being more scalpel-like, right?
So session-level containment talks about terminating or sandboxing just a single agent's execution without taking down the model, the infrastructure, or adjacent sessions, right?
So you have to continue to enable the business while blocking that individual attacker or rogue AI agent from there.
So look at it like killing a single process without rebooting the whole server.
But in order to do that, you need the instrumentation to identify the right process.
In practice, you revoke the session token or you freeze pending tool calls in that execution context.
You also need to preserve the session artifacts for forensics so you can see what has happened, but you allow those other sessions to continue.
So I always like to, from an analogy perspective, you know,
If you have a compromised account in an enterprise SaaS environment like Salesforce, if a single user session gets hijacked, you don't shut down for everyone.
You kill that session.
Showing 61–80 of 382 · page 4 of 20 ← Previous Next →