Pular para o conteúdo
PodcastsNotíciasThe ITSPmagazine Podcast

The ITSPmagazine Podcast

ITSPmagazine, Sean Martin, Marco Ciappelli
The ITSPmagazine Podcast
Último episódio

2159 episódios

  • The ITSPmagazine Podcast

    Coding Is a Fraction of the Work. Harness Secures Everything After It. | A Brand Briefing at Black Hat USA 2026 with Rahul Sood, General Manager, Application Security at Harness | Hosted by Sean Martin

    15/08/2026 | 16min
    Rahul Sood has run the application security business at Harness for almost a year. He describes application security as one of the core pillars of the company, part of a vision of building a DevSecOps platform. A year ago Harness publicly announced that security accounted for a quarter of its revenue. Sood says the figure is now considerably higher.

    The company did not start there. Founder Jyoti Bansal thought about Harness for a decade before founding it, Sood says, after seeing the problem inside one of the largest banks. Harness launched as a DevOps platform, then merged with an API security company Bansal had also funded. The result is a platform that treats security as part of the developer workflow rather than a bolt-on, and covers it from code all the way to runtime.

    What changes when security lives inside the developer workflow? Developers stop leaving their own tools to chase findings. Harness aggregates results across scanners, deduplicates them, and puts remediation, assignment, and exemption requests in one place. Security teams get the other half of the picture through a policy engine that shows which policies fire on every build, which ones break a build, and where a developer asked for an exception, with a full audit trail behind it.

    Where is the bottleneck now that AI writes the code? It moved downstream. Sood says nearly every development team is generating more code with AI, while the volume actually reaching users has not risen at the same rate. By his estimate coding is 20 to 30 percent of the software development life cycle, and the remaining 70 to 80 percent happens after the code is written.

    That includes agents. Harness has extended the platform to support the Agent DLC, with native capabilities for AI evaluation and prompt testing alongside security coverage for agents from code to runtime. Sood points to two differences. The span from code to runtime covers agents while they are built and while they run, and skill scanning and prompt scanning were added to the same scanner already looking for code vulnerabilities rather than shipped as another tool to buy.

    The operational payoff shows up in release cadence. Sood describes a tier one US bank that maintained 150 separate policies and convened a team to confirm each one had been met before it could launch its banking app. Automating that review removed the meeting, and the bank now runs multiple launches within weeks. With 80 to 90 percent of software now assembled from third-party packages, libraries, and open source components, the same policy engine can block any build that pulls in a package which is end of life or malicious.

    This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing

    GUEST

    Rahul Sood, General Manager, Application Security at Harness

    On LinkedIn: https://www.linkedin.com/in/rssoods/

    RESOURCES

    Black Hat USA 2026 event coverage from ITSPmagazine: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas

    Harness: https://www.harness.io/

    Harness customer case studies: https://www.harness.io/customers

    Securing the Agent DLC, by Rahul Sood: https://www.harness.io/blog/securing-the-agent-dlc

    Harness AI Security: https://www.harness.io/products/ai-security

    Harness Application Security Testing: https://www.harness.io/products/application-security-testing

    Are you interested in telling your story?

    ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full

    ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight

    ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight

    ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings

    KEYWORDS

    rahul sood, harness, sean martin, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, application security, devsecops, agent dlc, ai security, api security, policy engine, software supply chain, open source risk, prompt scanning, skill scanning, code to runtime, developer experience, release velocity

    Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
  • The ITSPmagazine Podcast

    Compliance Moves at the Speed of DevOps When Paperwork Writes Itself | A Brand Briefing at Black Hat USA 2026 with Travis Howerton, Co-Founder and CEO at RegScale | Hosted by Sean Martin

    14/08/2026 | 13min
    Why does compliance paperwork fall behind the systems it describes? Because the systems change faster than the documents. Travis Howerton points to cloud native technologies that spin up and down on demand, which makes describing infrastructure in paperwork something that goes out of date instantly. Add new regulation for third party risk, supply chain, zero trust, and privacy, and an approach that was already expensive and frustrating stops being fit for purpose.

    RegScale answers that with compliance as code. The company went to NIST and helped write the standard that became OSCAL, the Open Security Controls Assessment Language, then built the capability for machines to attest to their own state using it. Paperwork starts writing itself, and CISOs get risk and compliance outcomes as a byproduct of operational excellence rather than as a separate project.

    Is automating the evidence trail a shortcut? Travis Howerton argues the opposite. It prevents corner cutting, because the alternative is what he calls compliance theater. An old general he worked for described that as a mother-in-law visit, where you clean the house to a ridiculous standard, everybody goes through the dance, and the moment the visit ends the kids destroy the house again.

    Where should a security team start automating? Start with what hurts. He tells people to think like a surgeon, who opens by asking the patient what is wrong, then work backwards from the pain. There is no easy button, and the honest starting point is the truth about how fast teams will need to react.

    That pain usually maps to one of three business drivers. Cut cost, or shift the share of budget going to checklist compliance toward tools that buy down risk. Get real-time assurance. Or earn the reps and certs needed to sell into a market, whether that is FedRAMP for government work or PCI for card data. Compressing those timelines by 70 to 80 percent lets a company get to market faster and grow revenue.

    The results Travis Howerton cites are specific. One large government agency is touting over $100 million in labor savings, and a Department of War customer with a 52-week end-to-end cycle has compressed it by 36 weeks using RegScale technology alongside other integrated tools. Having tripled, doubled, and doubled again over the last three years, RegScale stays focused on the largest and most complex organizations, with international markets and the energy sector on the horizon.

    This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing

    GUEST

    Travis Howerton, Co-Founder and CEO at RegScale

    LinkedIn: https://www.linkedin.com/in/travishowerton/

    RESOURCES

    Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas

    RegScale: https://regscale.com

    OSCAL, the Open Security Controls Assessment Language: https://pages.nist.gov/OSCAL/

    Are you interested in telling your story?

    ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full

    ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight

    ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight

    ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings

    KEYWORDS

    travis howerton, regscale, sean martin, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, compliance as code, continuous controls monitoring, oscal, grc engineering, fedramp, fisma, authority to operate, ai agents, risk management, cybersecurity compliance

    Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
  • The ITSPmagazine Podcast

    Post-Quantum Readiness Starts With the Infrastructure You Buy Today | A Brand Briefing at Black Hat USA 2026 with Larry Lunetta, Vice President, Portfolio Technical Marketing at HPE | Hosted by Sean Martin

    14/08/2026 | 16min
    Post-quantum cryptography was in conversation after conversation at Black Hat USA 2026, yet Larry Lunetta of HPE walked part of the show floor and counted a single reference to quantum. Where the topic shows up, and where it does not, says something about who is expected to solve it.

    Why does a problem described in 1994 matter now? Larry Lunetta points to Peter Shor, who asked what would happen to RSA if a different kind of computing technology existed. What changed since then is the trajectory. Five years ago cryptographically relevant quantum computing looked like a 10 to 15 year phenomenon. Larry Lunetta now puts it as soon as three years out, with the original algorithm improved, qubit hardware advancing, and classical supercomputing pulling the timeline in alongside it.

    The exposure starts before any of that arrives. Larry Lunetta describes harvest now, decrypt later, where an attacker collects RSA-encrypted data today and waits for the machine that can open it. Data that carries no consequence when it leaks this year can be read later, which puts long-lived information like identity records and medical data at the front of the queue rather than in a later phase.

    HPE puts a three part journey in front of customers. Cryptographically aware asks which data is most sensitive, where it lives, and whether it is protected sufficiently. Cryptographically planning reaches into the refresh cycle, so that new network, server, and storage purchases already implement PQC-relevant algorithms. Cryptographically nimble accounts for the fact that no cryptographically relevant quantum computer exists to test against yet, which makes the ability to change algorithms and firmware quickly part of the design.

    Who owns the conversation inside the business? Larry Lunetta puts the CISO at the center of gravity, with CIOs becoming aware and boards engaged where GDPR governs customer and private information. His advice for security leaders is to broaden the conversation toward infrastructure and operations, and to make encryption and PQC readiness a question asked during procurement rather than after it.

    This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing

    GUEST

    Larry Lunetta, Vice President, Portfolio Technical Marketing at HPE

    On LinkedIn: https://www.linkedin.com/in/larryathpe/

    RESOURCES

    Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas

    HPE: https://www.hpe.com

    Post-Quantum Cryptography overview: https://www.hpe.com/us/en/what-is/post-quantum-cryptography.html

    HPE technology leadership in quantum: https://www.hpe.com/us/en/about/technology-leadership-quantum.html

    Are you interested in telling your story?

    ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full

    ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight

    ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight

    ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings

    KEYWORDS

    larry lunetta, hpe, sean martin, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, post-quantum cryptography, pqc, quantum computing, harvest now decrypt later, rsa encryption, cryptographic agility, ciso, crypto agility, nist post-quantum standards, it infrastructure security, encryption, data protection

    Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
  • The ITSPmagazine Podcast

    Agents Get Zero Trust, and the Network Becomes the Sensor | A Brand Briefing at Black Hat USA 2026 with David Hughes, SVP and GM of SASE and Security for Networking at HPE | Hosted by Sean Martin

    14/08/2026 | 15min
    Most people know HPE for servers, compute, and storage. David Hughes leads a pillar that gets less attention. He runs the SSE and security business inside HPE Networking, which he says accounts for about a third of the company now that HPE has merged with Juniper, and which organizes into four pillars: campus and branch, data center switching, routing infrastructure, and security.

    Recorded on location at Black Hat USA 2026, the conversation opens on a balancing act Hughes hears constantly. Customers want to push hard on AI adoption while staying protected and avoiding undue risk. The same tension runs between teams. Networking answers for performance and user experience. Security answers for protecting those users and the company's data. HPE's answer is to embed security thinking into the network itself, making it a sensor and an enforcement point for the security team.

    What happens when users are no longer only people? The identity question moves to devices, workloads, and agents. Hughes frames it as human and non-human identity, and his position is to take the ZTNA architecture that works for people and adapt it, starting with IoT devices, then workloads, then agents. Put an agent in a sandbox and it sees only the subset of resources it is supposed to reach.

    How do networking and security teams work from the same picture? Through shared visibility and agentic technology across the management layer. HPE is putting agentic technology into how it manages storage, compute, networks, and security products, then meshing those agents together so a wifi complaint that turns out to be a firewall policy change gets to root cause faster, with automatic remediation as the goal.

    Hughes also covers post-quantum cryptography, where HPE is moving across all product lines to introduce quantum resistant and quantum safe capabilities in hardware and software, with some launched this year and more coming through the following quarters. The deadline arrives earlier than most calendars suggest, because data harvested today can be decrypted later.

    Rounding it out: HPE Threat Labs, announced earlier in the year with Mounir Hahad's team from Juniper at its core, and AI focused capabilities on the next generation firewalls covering observability, role based governance over which services employees can use, and session level inspection of prompts and responses. Hughes closes with a direct invitation to CISOs who know HPE for compute and networking and have yet to meet the security team.

    This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing

    GUEST

    David Hughes, SVP and GM of SASE and Security for Networking at HPE

    On LinkedIn: https://www.linkedin.com/in/david-hughes-42751636/

    RESOURCES

    Black Hat USA 2026 event coverage from ITSPmagazine: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas

    HPE: https://www.hpe.com/

    HPE Threat Labs: https://www.hpe.com/us/en/hpe-labs/threat-labs.html

    Are you interested in telling your story?

    ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full

    ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight

    ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight

    ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings

    KEYWORDS

    david hughes, hpe, sean martin, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, zero trust, ztna, non-human identity, agentic ai, ai security, post-quantum cryptography, network security, sase, sse, hpe threat labs, self-driving network, firewall governance, juniper, iot security, cross domain troubleshooting

    Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
  • The ITSPmagazine Podcast

    AI Agents Act at Machine Speed. Menlo Security Governs What They Actually Do. | A Brand Briefing at Black Hat USA 2026 with Eric Avigdor, Vice President of Product of Menlo Security | Hosted by Sean Martin

    14/08/2026 | 15min
    Recorded on location at Black Hat USA 2026, Eric Avigdor of Menlo Security describes an adoption pattern he hears in customer conversation after customer conversation. AI makes teams measurably more productive. The guardrails that keep company data inside the business arrive later, if they arrive at all.

    Eric Avigdor leads product for AI security and data security at Menlo Security, and he splits the problem into two categories that get very different levels of attention. One is how people use AI in the browser, including what data gets pasted into an assistant and how much of that usage anyone knows about. The other is autonomous agents built to run business processes, where the question is how to keep them productive without letting their goals get hijacked.

    The category Eric Avigdor says compliance teams skip past is the agent that holds sensitive data and internet access at the same time. Read a poisoned web page, take the hidden instruction, and the goal changes. What is the difference between an agent running analysis on an internal database and an agent doing financial analysis at a bank with customer records and web access? One of them can be told to send the data somewhere else.

    So who owns AI governance? In most companies, nobody does, at least not with authority. Responsibility lands with the endpoint team, the network team, or the browser team, and each one works its own angle. An endpoint team tracks agent traffic on the endpoint and then loses the trail when the agent moves data cloud to cloud. A cloud team has the reverse blind spot.

    Menlo Agent Runtime Security, or MARS, is built around what an agent actually does rather than what it intends to do. Agent traffic is proxied through the Menlo Security cloud browser, where data masking, indirect prompt injection prevention, and web-based and file-based threat prevention are applied before an incident becomes cleanup work. Browser and web traffic today, MCP traffic next.

    For regulated organizations, that architecture produces something auditors can use. Logging, dashboarding, and a visual record of what an agent attempted in the real world. Europe has the AI Act. The US has not landed comparable rules yet, and Eric Avigdor says that gap concerns him enough that he is talking with people working to close it.

    GUEST

    Eric Avigdor, Vice President of Product, Menlo Security | On LinkedIn: https://www.linkedin.com/in/eric-avigdor-0b561118/

    RESOURCES

    Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas

    Menlo Security: https://www.menlosecurity.com/

    Menlo AI Agent Security: https://www.menlosecurity.com/product/ai-agent-security

    Menlo AI Adaptive DLP: https://www.menlosecurity.com/product/ai-adaptive-dlp

    Are you interested in telling your story?

    ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full

    ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight

    ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight

    ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings

    KEYWORDS

    eric avigdor, menlo security, sean martin, brand story, brand marketing, marketing podcast, brand spotlight, black hat usa 2026, mars, menlo agent runtime security, ai agent security, prompt injection, indirect prompt injection, data exfiltration, ai governance, browser security, agentic ai, autonomous agents, shadow ai, data loss prevention, eu ai act, ai compliance, coding agents, mcp security

    Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
Mais podcasts de Notícias
Sobre The ITSPmagazine Podcast
Founded in 2015, ITSPmagazine began as a vision for a publication positioned at the critical intersection of technology, cybersecurity, and society. What started as a written publication has evolved into a comprehensive repository for all their content—podcasts, articles, event coverage, interviews, videos, panels, and everything they create. This is where Sean Martin and Marco Ciappelli talk about cybersecurity, technology, society, music, storytelling, branding, conference coverage, and whatever else catches their attention. Over a decade of conversations exploring how these worlds collide, influence each other, and shape the human experience. This is where you'll find it all.
Site de podcast

Ouça The ITSPmagazine Podcast, Petit Journal e muitos outros podcasts de todo o mundo com o aplicativo o radio.net

Obtenha o aplicativo gratuito radio.net

  • Guardar rádios e podcasts favoritos
  • Transmissão via Wi-Fi ou Bluetooth
  • Carplay & Android Audo compatìvel
  • E ainda mais funções
Aplicações
Social
v8.14.3 | © 2007-2026 radio.de GmbH
Generated: 8/18/2026 - 2:50:02 PM