Menu
Sign In Search Podcasts Libraries Charts People & Topics Add Podcast API Blog Pricing

David Spark

πŸ‘€ Speaker
1577 total appearances

Appearances Over Time

Podcast Appearances

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

So I'm going to start with you, Andy.

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

If least privilege breaks agentic workflows, and we're talking about agentic workflows versus actual humans as identities.

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

What does appropriate access governance even look like?

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

And how do you enforce policy against behavior you can't predict in advance?

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

I mean, because agents don't have predictable behaviors, do they?

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

Well, more than agents, I would say.

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

So, Danny, part of the core philosophy of ThreatLocker is this default-deny approach.

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

And by default, you limit privileges, yes, or just limit a lot of things beyond just privileges.

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

So, well then, how then does...

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

the least privileged behavior or the way you monitor it if you're dealing with agents that are moving at a much faster speed than humans.

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

How does this change?

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

I mean, how does speed come into the equation, I guess, is my question.

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

And also the agent itself, you should also throw in there, the agent itself doesn't have a conscience.

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

So it's not stopping itself or regulating itself.

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

What about this AI security challenge?

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

Quote, we just deployed more attack service in 12 months than we built in the previous decade, end quote.

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

After seeing a surfeit of MCP servers with no authentication and a bevy of malicious skills in the LLM marketplaces in just a month, Caleb Sema of White Rabbit has a simple diagnosis, repeating the cloud mistake.

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

But this makes me wonder if this is a mistake or this is just a pattern.

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

New technology deploys, businesses wait to see if it sticks.

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

Once it does, startups scramble to build solutions.