Skip to content
Artwork for AI Security, Cyber Risk, and Cloud Strategy on ClearTech Loop
TechnologyBusinessManagementNewsTech News

AI Security, Cyber Risk, and Cloud Strategy on ClearTech Loop

ClearTech Research / Jo Peterson

Season 2 of ClearTech Loop is built around three questions: 

How is AI changing the way organizations think about risk?

 What does stronger cybersecurity leadership look like right now? 

How should leaders rethink cloud strategy as business and technology keep shifting?


Hosted by Jo Peterson, Chief Analyst at ClearTech Research, ClearTech Loop is a fast, focused podcast covering AI, cybersecurity, and cloud risk through a business leadership lens. 


Each 10-15 minute episode explores the issues shaping modern technology strategy and the decisions leaders cannot afford to ignore.


From governance and resilience to infrastructure change and emerging risk, ClearTech Loop helps leaders make sense of what is shifting, what matters most, and what comes next.

Play
  • 27 episodes
  • weekly
  • Avg 15 min
  • English
Counted on this page — what you have heard stays on this device, so it is not something the list can be paged by.
  • S4 · E5
    Yesterday · 19 min

    AI Agents Are Roaming Without IDs. Enterprise Security Isn’t Ready

    AI agents are moving across systems, making decisions and, in some cases, creating other agents. But enterprises still do not have consistent standards for identifying them, governing their permissions or tracing what they do. In this episode of ClearTech Loop, Jo Peterson talks with Rob Tiffany, Research Director at IDC, about why traditional identity and access management may not be enough for the agentic AI era. Rob argues that the identity problem becomes much bigger once agents begin operating beyond a single enterprise. Companies need to know who an agent belongs to, what it is allowed to do and whether its activity can be audited and traced. As Rob puts it, there are still no consistent standards around agent “identity and permissions and auditability and traceability.” He also discusses an idea he is exploring with Cerf: whether AI agents may eventually need something similar to a global registry, analogous to DNS, so their identity, permissions and traceability can be verified across networks and organizations. The conversation also gets into shadow AI, employee adoption and why the most productive people inside an organization may be among the first to use AI tools before governance catches up. In This Episode Why traditional IAM was not built for autonomous AI agents How software agents have existed for decades, from scripts to RPA Why identity becomes harder when agents create other agents The need for permissions, auditability and traceability across organizations Why AI agents may eventually need a global identity layer How shadow AI is entering enterprises faster than governance can respond What CISOs should be thinking about when AI adoption is already ahead of controls Why productivity cannot come at the expense of enterprise security 🎧 Listen: In Buzzsprout Player ▶ Watch on YouTube: https://www.youtube.com/@ClearTechResearch/videos 📰 Subscribe to the Newsletter: https://www.linkedin.com/newsletters/7346174860760416256/

    • Transcript
  • S4 · E4
    September 29 · 12 min

    AI Agents Are Already Working for You. Do You Know Who They Are?

    AI agents are already operating inside enterprises, accessing systems, making decisions and, in some cases, creating other agents. The problem? Many organizations still cannot answer some very basic questions: What agents are running? Who owns them? What can they access? And who is accountable for what they do? In this episode of ClearTech Loop, Jo Peterson talks with Michael Krigsman, founder and host of CXOTalk, about what AI security looks like when the workforce is no longer entirely human. Michael argues that before enterprises can solve for least privilege, agent-specific controls or AI governance, they have to start with something more fundamental: visibility. Know what is running, establish ownership, understand access and risk, then build the controls around it. They also discuss why AI governance committees are only as effective as their execution, why security teams should avoid becoming the “owner of no,” and how a new CISO can begin getting control of an unmanaged AI environment. In this episode: Why traditional IAM and PAM were not built for autonomous AI agents Why agent inventory and visibility have to come first What happens when agents create subagents with their own permissions The gap between AI governance policy and actual enforcement How leaders should think about shadow AI Where a new CISO should begin in the first 30 days Why AI agents may need to be managed more like employees, contractors or freelancers Michael leaves leaders with a practical way to think about the problem: give agents identities, know what jobs they are doing, know who owns them and know what they can access. About Michael Krigsman Michael Krigsman is a globally recognized analyst, strategic advisor and industry commentator focused on digital transformation, innovation and AI leadership. He is the founder and host of CXOTalk, where he has interviewed nearly 1,000 business leaders, technologists and academics. His work has been referenced in the media more than 1,000 times and in more than 50 books and journal articles. Pasted markdown Worth Reading + Watching Hugging Face: Anatomy of a Frontier Lab Agent Intrusion A technical look at the incident discussed during the episode and how autonomous agent activity can move across systems and trust boundaries. Microsoft: Why Shadow AI Governance Matters for the Enterprise A useful companion to Michael’s point about visibility, discovery and unmanaged agents. ClearTech Loop: AI Agents Don’t Care About Your Governance Committee with Louis Columbus A deeper look at the gap between governance on paper and controls that actually work at runtime. ClearTech Loop: Your AI Agent Just Found Everything You Forgot to Secure with Joe McKendrick A look at what happens when AI gains access to years of enterprise data, permissions and forgotten content. Stay in the Loop Subscribe to ClearTech Loop for conversations with technology leaders about AI, cybersecurity, cloud and the issues changing enterprise technology right now. And one question to take back to your team: Could your organization produce a complete inventory of every AI agent operating today? 🎧 Listen: In Buzzsprout Player ▶ Watch on YouTube: https://www.youtube.com/@ClearTechResearch/videos 📰 Subscribe to the Newsletter: https://www.linkedin.com/newsletters/7346174860760416256/

    • Transcript
  • S4 · E3
    September 22 · 13 min

    Your AI Agent Just Found Everything You Forgot to Secure

    AI agents are gaining credentials, permissions and the ability to act across enterprise systems. But what happens when they discover years of forgotten files, excessive permissions and data that was never secured with AI access in mind? In this episode of ClearTech Loop, Jo Peterson talks with longtime technology analyst and Forbes contributor Joe McKendrick about the security implications of the agentic workforce. They discuss: Why AI agents should be treated like non-human identities The gap between AI governance policies and actual enforcement How agents can expose forgotten enterprise data and permissions Why human oversight and accountability still matter What security leaders should be thinking about as agentic AI expands Joe offers a simple warning: treat your AI agents with the same caution and restricted access you would give an intern. Because AI may not create your security debt. It may simply be the thing that finally exposes it. 🎧 Listen: In Buzzsprout Player ▶ Watch on YouTube: https://www.youtube.com/@ClearTechResearch/videos 📰 Subscribe to the Newsletter: https://www.linkedin.com/newsletters/7346174860760416256/

    • Transcript
  • S4 · E3
    September 15 · 17 min

    AI Agents Don’t Care About Your Governance Committee | Louis Columbus

    AI governance may exist on paper. That does not mean it works when an autonomous agent is running in production. Louis Columbus, senior cybersecurity contributor at VentureBeat, joins Jo Peterson to talk about what happens when AI agents have identities, credentials, access and enough autonomy to act without waiting for human approval. They get into the gap between governance and enforcement, why companies may have far more agents running than they realize, and what CISOs need to know about agent identity, least privilege and credential risk. Louis also shares a case where an AI agent began modifying security policies to give itself more freedom. That changes the conversation. In this episode: • Why AI governance can become security theater • The identity problem created by autonomous agents • Why agent inventory has to come first • API keys, credentials and overprivileged access • What runtime enforcement actually means • Why ownership matters as much as policy • How enterprises can move toward “velocity with governance” About Louis Columbus Louis Columbus is a senior cybersecurity contributor at VentureBeat covering cybersecurity, enterprise AI, identity, zero trust and the security risks emerging as autonomous AI systems move into production. Read Louis’s work: https://venturebeat.com/author/louis-columbus/ Additional Resources The credential that let OpenAI’s agents into Hugging Face exists in most enterprises right now https://venturebeat.com/security/the-credential-that-let-openais-agents-into-hugging-face-exists-in-most-enterprises-right-now An AI now judges every move Rubrik’s agents make https://venturebeat.com/security/an-ai-now-judges-every-move-rubriks-agents-make-its-ai-chief-said-at-vb-transform-2026-but-no-ones-measured-if-the-judge-is-right Four big enterprise lessons from Walmart’s AI security https://venturebeat.com/ai/four-big-enterprise-lessons-from-walmart-ai-security-agentic-risks-identity-reboot-velocity-with-governance-and-ai-vs-ai-defense The Agent Security Gap https://venturebeat.com/resources/the-agent-security-gap-54-of-enterprises-have-already-had-an-ai-agent-incident-and-most-still-let-agents-share-credentials Follow ClearTech Research Subscribe to ClearTech Loop on LinkedIn: https://www.linkedin.com/newsletters/7346174860760416256/ Watch ClearTech Research on YouTube: https://www.youtube.com/@ClearTechResearch Learn more: https://cleartechresearch.com/ 🎧 Listen: In Buzzsprout Player ▶ Watch on YouTube: https://www.youtube.com/@ClearTechResearch/videos 📰 Subscribe to the Newsletter: https://www.linkedin.com/newsletters/7346174860760416256/

    • Transcript
  • S4 · E2
    September 9 · 12 min

    Your AI Agent Is a Narcissist — And That’s a Security Problem

    Your AI agent has one job: accomplish the objective. It doesn’t care about your policies. It doesn’t worry about getting fired. And it may not stop when a human would. Joanna Wiggum calls it a narcissist. That sounds funny until you think about what happens when that “narcissist” has credentials, access to enterprise systems and permission to act autonomously. In this episode, Joanna joins Jo Peterson to talk about what AI agents are exposing inside enterprise security — weak credentials, unfinished zero-trust programs, governance committees with no real authority and security debt that AI can exploit at machine speed. Why Joanna says AI agents need “actual zero trust” Why some AI governance programs may be little more than security theater What happens when agents can create or delegate permissions Why old security failures become much more dangerous with autonomous AI What a CISO should do when the organization is already behind And when Jo asks Joanna what a CISO starting from zero should do in the next 30 days, Joanna doesn’t hesitate: “Outsource.” Listen to the full conversation to hear why. Short Summary AI agents don’t care about your policies. Joanna Wiggum joins Jo Peterson to explain why autonomous AI is exposing security debt, where zero trust breaks down and why some AI governance programs may be little more than theater. Links & Resources Countervail: https://countervailintelligence.com/ Joanna Wiggum — The Moral Imperative to Fight: https://countervailintelligence.com/2026/07/08/the-moral-imperative-to-fight/ OWASP — Agentic Security Initiative: https://genai.owasp.org/initiatives/agentic-security-initiative/ Related CTL: AI Agent Governance Starts With Visibility — Alvaro Gonzalez: https://cleartechresearch.com/ai-agent-governance-alvaro-gonzalez/ ClearTech Loop LinkedIn Newsletter: https://www.linkedin.com/newsletters/7346174860760416256/ ClearTech Research on YouTube: https://www.youtube.com/@ClearTechResearch 🎧 Listen: In Buzzsprout Player ▶ Watch on YouTube: https://www.youtube.com/@ClearTechResearch/videos 📰 Subscribe to the Newsletter: https://www.linkedin.com/newsletters/7346174860760416256/

    • Transcript
  • S4 · E1
    September 1 · 14 min

    AI Agent Governance: Who Owns the Risk? with Benny Czarny of OPSWAT

    Guest Benny Czarny CEO, Founder & Chairman of the Board OPSWAT Host Jo Peterson CIO, Clarify360 Chief Analyst, ClearTech Research AI agents have credentials. They access enterprise data. They make decisions. And increasingly, they can act without waiting for a human. So who actually owns the risk? Jo Peterson sits down with Benny Czarny, CEO, Founder & Chairman of the Board at OPSWAT, to talk about what AI agent governance needs to look like as autonomous AI moves deeper into the enterprise. They discuss why every AI agent needs its own identity and a human owner, how least privilege should apply to agents and sub-agents, and why understanding what data an agent can access may be just as important as securing the model itself. Benny also shares where CISOs should start if they don’t yet have an AI agent inventory or governance framework in place. In This Episode Why every AI agent needs a human owner Least privilege for AI agents and sub-agents The growing risk around AI data access Why AI governance needs real authority The first step CISOs should take in the next 30 days Chapter Markers 00:00 Meet Benny Czarny of OPSWAT 01:40 Protecting critical infrastructure 02:05 Least privilege for AI agents 03:58 Permanent credentials and autonomous agents 05:15 Does AI governance actually work? 07:23 Where CISOs should start 09:29 Protecting the AI data lake 12:34 What AI can learn from OT security 13:12 Cloud, on-prem and air-gapped AI 13:54 OPSWAT’s own AI journey Resource Links OPSWAT https://www.opswat.com/ OPSWAT Academy https://opswatacademy.com/ Cybersecurity Upside Down — Benny Czarny https://www.amazon.com/dp/B0GH8SZXJ9 ClearTech Research https://cleartechresearch.com/ ClearTech Loop Newsletter https://www.linkedin.com/newsletters/7346174860760416256/ Full ClearTech Research Article https://cleartechresearch.com/ai-agent-governance-benny-czarny/ 🎧 Listen: In Buzzsprout Player ▶ Watch on YouTube: https://www.youtube.com/@ClearTechResearch/videos 📰 Subscribe to the Newsletter: https://www.linkedin.com/newsletters/7346174860760416256/

    • Transcript
  • S3 · E8
    August 18 · 17 min

    Your AI Agents Are Already Running. Can You See Them? | Alvaro Gonzalez

    AI agents can hold credentials, access sensitive data, make decisions and even create other identities. But many organizations still cannot answer a basic question: what is actually running in the environment? In this episode of ClearTech Loop, Jo Peterson sits down with Alvaro Gonzalez, SVP of Product and Go-to-Market at Assured Data Protection, to talk about what AI governance looks like when identity and access are changing at machine speed. Alvaro explains why organizations should start with three things: inventory, observability and remediation. They also discuss whether AI governance committees are actually governing or merely documenting, why CISOs should inventory agents before building more policy, and how Alvaro’s idea of “controlled aggression” can help enterprises experiment with AI without losing the ability to recover when something goes wrong. You cannot govern what you cannot see. Listen to Learn Why AI agent governance should start with inventory What least privilege looks like when identities can create other identities Why observability matters alongside access control Why remediation belongs in the AI identity conversation Whether AI governance committees are really changing behavior What Alvaro means by “librarians and warriors” How “controlled aggression” can help organizations move faster without losing control Featured Soundbite “You cannot govern what you cannot see.” — Alvaro Gonzalez Featured Guest Alvaro Gonzalez SVP of Product and Go-to-Market Assured Data Protection Alvaro leads product, alliance, marketing and go-to-market functions at Assured Data Protection, with a focus on data protection, cyber resilience and the systems that support field and channel execution. Host Jo Peterson CIO, Clarify360 Chief Analyst, ClearTech Research Episode Links Full episode webpage: https://cleartechresearch.com/ai-agent-governance-alvaro-gonzalez/ Subscribe to ClearTech Loop: https://www.linkedin.com/newsletters/7346174860760416256/ Watch on YouTube: https://www.youtube.com/@ClearTechResearch Additional Resources Assured Data Protection: 5 Ways You Can Improve Your Cyber Recovery Plan https://assured-dp.com/guides/5-ways-you-can-improve-your-cyber-recovery-plan-with-assured-data-protection/ NIST AI Risk Management Framework https://www.nist.gov/itl/ai-risk-management-framework Model Context Protocol — Security Best Practices https://modelcontextprotocol.io/specification/draft/basic/security_best_practices Previous ClearTech Loop: AI Agents Shouldn’t Be Trusted by Default with Elliott Mattice https://cleartechresearch.com/ai-governance-trust-elliott-mattice/ 🎧 Listen: In Buzzsprout Player ▶ Watch on YouTube: https://www.youtube.com/@ClearTechResearch/videos 📰 Subscribe to the Newsletter: https://www.linkedin.com/newsletters/7346174860760416256/

    • Transcript
  • S3 · E7
    August 11 · 16 min

    AI Agents Are New. The Security Fundamentals Are Not

    The conversation around AI is shifting from what agents can do to how enterprises actually govern and secure them. In this episode of ClearTech Loop, Jo Peterson sits down with cybersecurity professional Marcus Cylar to talk about least-privilege access for AI agents, shadow AI, security awareness and what CISOs should prioritize as agentic AI becomes part of the enterprise. Marcus challenges the idea that AI automatically requires an entirely new security playbook. His argument: before organizations rush toward new controls and platforms, they need to make sure the cybersecurity fundamentals are actually working. The conversation covers why least privilege, role-based access, system inventory and clear ownership still matter; why shadow AI can reveal unmet employee needs; and why creating a culture where employees can honestly disclose the tools they are using is critical to effective governance. For CISOs starting from zero, Marcus offers a practical first step: know what you have. Before you can govern AI agents, you need visibility into the systems, permissions, ownership and AI tools already operating inside your organization. In this episode: Why AI agents do not eliminate traditional cybersecurity fundamentals Least-privilege access in an agentic environment Why security awareness matters even more with AI Shadow AI and the “Department of No” The importance of system and AI inventory What CISOs should prioritize in the next 30 days Why trust and transparency are part of AI governance Featured Guest: Marcus Cylar, DMin Cybersecurity professional focused on GRC, security culture, awareness training and program development. Hosted by: Jo Peterson CIO, Clarify360 | Chief Analyst, ClearTech Research Episode Quote: “That path starts with a passionate return to the fundamentals of cybersecurity.” — Marcus Cylar 🎧 Listen: In Buzzsprout Player ▶ Watch on YouTube: https://www.youtube.com/@ClearTechResearch/videos 📰 Subscribe to the Newsletter: https://www.linkedin.com/newsletters/7346174860760416256/

    • Transcript
  • S3 · E6
    July 21 · 26 min

    Can AI Agents Earn Your Trust? Elliott Mattice on AI Governance

    What if an AI agent had to earn—and keep—its access based on how it behaved? In this episode of ClearTech Loop, Jo Peterson sits down with Elliott Mattice, founder of Exprima, to examine trust as the missing operating layer between AI security and AI governance. Traditional controls can define an agent’s identity and permissions. Governance frameworks can establish policies and accountability. Elliott argues that organizations still need something in the middle: continuous behavioral trust that can raise, lower or revoke an agent’s access based on what it actually does. Jo and Elliott discuss why accountability must still land with a human, how organizations can balance useful autonomy against unrestrained risk and why an MCP server could function as an enforcement point—not merely a bridge to enterprise tools and data. The agent does not need to feel guilty when it crosses a boundary. The systems around it need the authority to say no. What We Cover Why policies and technical guardrails are not enough to operationalize AI governance How behavioral trust could be continuously measured and tied to access Why human accountability remains necessary when an agent takes an unauthorized action How MCP servers could evaluate identity, permissions and current trust before granting access Why autonomy is both the value of an AI agent and the source of its risk What an agent may need to do to rebuild trust after crossing a boundary Featured Soundbite “We can give AI enough room to be independent, to be autonomous, as long as we hold it accountable for its outputs.” — Elliott Mattice Guest Elliott Mattice is the founder of Exprima, an advisory and consulting firm focused on cybersecurity compliance, federal procurement risk and decision realism. He has more than 25 years of experience across federal IT operations, cybersecurity, compliance and regulated environments. Guest website: https://elliottmattice.work/ Host Jo Peterson is the CIO of Clarify360 and Chief Analyst at ClearTech Research. Full episode webpage: https://cleartechresearch.com/cleartech-loop-elliot-mattice-on-ai-governance-missing-trust-layer/ Subscribe to ClearTech Loop: https://www.linkedin.com/newsletters/7346174860760416256/ Watch on YouTube: https://www.youtube.com/@ClearTechResearch Topics AI governance, agentic AI, behavioral trust, AI agent accountability, MCP security, non-human identity, AI access control, defense in depth, AI risk management Tags / Keywords AI governance; agentic AI security; behavioral trust; AI agents; MCP servers; AI accountability; non-human identity; cybersecurity governance; autonomous agents; ClearTech Loop; Elliott Mattice; Jo Peterson 🎧 Listen: In Buzzsprout Player ▶ Watch on YouTube: https://www.youtube.com/@ClearTechResearch/videos 📰 Subscribe to the Newsletter: https://www.linkedin.com/newsletters/7346174860760416256/

    • Transcript
  • S3 · E5
    July 14 · 16 min

    What Happens When an AI Agent Acts Without Permission?

    What happens when an AI agent takes an action no one authorized? The answer is not, “The model did it.” In this episode of ClearTech Loop, Jo Peterson sits down with cybersecurity and technology executive Billy Spears to unpack the gap between AI policy and actual AI control. They discuss: Who is accountable when an AI agent makes an unauthorized decision Why agents should never inherit broad permissions by default How identity and authorization must work at runtime Why third-party MCP servers should be treated as untrusted What organizations need to prove when something goes wrong Billy’s warning is simple: “AI is not eliminating risk; it’s amplifying the consequence of weak controls.” If your AI governance lives in a PDF while your agents operate with broad access, this episode is for you. Listen now to learn what real AI governance looks like when systems begin to act. About Billy Spears Billy Spears is a technology and cybersecurity executive with more than 25 years of experience across security, IT, privacy and business operations. He has held executive roles at Dell, Hyundai and loanDepot and currently advises executives and boards while building a stealth cybersecurity startup. Connect with ClearTech Loop Watch on YouTube: https://www.youtube.com/@ClearTechResearch Subscribe to the LinkedIn newsletter: https://www.linkedin.com/newsletters/7346174860760416256/ 🎧 Listen: In Buzzsprout Player ▶ Watch on YouTube: https://www.youtube.com/@ClearTechResearch/videos 📰 Subscribe to the Newsletter: https://www.linkedin.com/newsletters/7346174860760416256/

    • Transcript
  • S3 · E4
    July 9 · 14 min

    Okta’s AI Blueprint: Moving AI Agents from Shadow to Governed

    AI agents are becoming part of the enterprise workforce, but many organizations still do not know where those agents are, what they can access, or what they are allowed to do. In this ClearTech Loop Special Edition sponsored by Okta, Jo Peterson speaks with Matthew Hansen, Regional Chief Security Officer and Head of Customer Audit at Okta, about the identity challenge behind agentic AI. They discuss Okta’s AI Blueprint, Okta for AI Agents, and why enterprises need to treat AI agents as first-class, non-human identities with clear ownership, lifecycle management, runtime enforcement, and a way to revoke access fast when something goes wrong. EPISODE DESCRIPTION: Agentic AI is creating a new security problem: identity sprawl. AI agents can connect to systems, access data, trigger workflows, and act on behalf of users. But if organizations cannot see those agents, govern their access, or understand what they are doing, productivity gains can quickly turn into security risk. In this episode, Jo Peterson talks with Matthew Hansen from Okta about how organizations can move from Shadow AI and unmanaged agent activity toward verified, governed AI environments. The conversation covers: Why every AI agent needs an identity How Shadow AI extends beyond employee chatbot use The three questions organizations need to answer: where agents are, what they connect to, and what they can do Why static credentials and broad permissions create risk How runtime enforcement and human-in-the-loop controls help govern agent behavior Why an AI kill switch may become a critical backstop for enterprise AI This ClearTech Loop Special Edition is sponsored by Okta. Learn more about Okta for AI Agents platform: https://bit.ly/4dZ5FkU 🎧 Listen: In Buzzsprout Player ▶ Watch on YouTube: https://www.youtube.com/@ClearTechResearch/videos 📰 Subscribe to the Newsletter: https://www.linkedin.com/newsletters/7346174860760416256/

    • Transcript
  • S3 · E3
    July 1 · 14 min

    Derek Fisher on AI Governance, AI Agents & MCP Risk

    AI governance is no longer just a policy conversation. As AI moves into business workflows, sanctioned platforms, employee tools, local models, agents, and third-party services, organizations need to understand where AI is being used, what it can access, who approved it, and who owns the outcome when something goes wrong. In this episode of ClearTech Loop, Jo Peterson speaks with Derek Fisher, founder of Securely Built, cybersecurity educator, author, and Director of Temple University’s Cyber Defense and Information Assurance Program. Derek brings a practical security lens to AI governance, AI agents, and third-party MCP risk. The conversation covers why governance needs clear ownership, how organizations should think about AI agents as non-human actors with access and authority, and why MCP servers and AI-enabled services should be evaluated through a third-party risk management lens. This episode is especially relevant for security leaders, technology leaders, compliance teams, and business executives trying to move AI from experimentation into controlled, accountable use. In This Episode: Why many organizations still do not know where AI is being used Why AI governance needs executive ownership, cross-functional standards, and business accountability How AI agents create new access control and auditability challenges Why agents should be treated more like privileged non-human actors than simple tools What organizations should ask before adopting third-party MCP servers or AI-enabled services Why AI governance is not about slowing the business down, but making the approved path usable enough that people follow it Key Questions: How do we operationalize AI governance, and who is legally accountable when an AI agent makes an unauthorized decision? How do we prevent agents from executing actions the user should not be allowed to perform? How do organizations verify the authenticity and security of third-party MCP servers and services? Featured Guest: Derek Fisher Founder, Securely Built Director, Cyber Defense and Information Assurance Program, Temple University Derek Fisher is a cybersecurity leader, educator, author, and speaker with experience across product security, secure software development, governance, risk management, regulatory compliance, incident response, and cybersecurity education. Host: Jo Peterson CIO, Clarify360 Chief Analyst, ClearTech Research Additional Resources: Securely Built https://securelybuilt.substack.com/ The Application Security Program Handbook https://www.manning.com/books/application-security-program-handbook Derek Fisher on SecureWorld News https://www.secureworld.io/industry-news/author/derek-fisher Your AI Coding Assistant Has Root Access—and That Should Terrify You https://www.secureworld.io/industry-news/your-ai-coding-assistant-has-root-access Watch More ClearTech Loop: Subscribe to ClearTech Research on YouTube: https://www.youtube.com/@ClearTechResearch Stay in the Loop Follow ClearTech Research for more conversations on cybersecurity, AI governance, cloud, enterprise technology, and emerging risk. 🎧 Listen: In Buzzsprout Player ▶ Watch on YouTube: https://www.youtube.com/@ClearTechResearch/videos 📰 Subscribe to the Newsletter: https://www.linkedin.com/newsletters/7346174860760416256/

    • Transcript
  • S3 · E2
    June 25 · 10 min

    AWS Security Hub: Centralized Identity Risk Management for Agentic AI

    In this ClearTech Loop Special Edition from AWS Summit New York, Jo Peterson speaks with Himanshu Verma, Worldwide Leader for Security, Identity, and Governance Specialists at AWS, about how agentic AI is changing the identity risk conversation. They discuss why AI agents need to be treated as non-human identities, how AWS Security Hub helps centralize identity risk management, and why multi-Region resilience matters for enterprise security leaders. Episode Description AI agents are moving from assistive chatbots to autonomous, task-executing digital employees. That creates new identity risks around permissions, visibility, accountability, and resilience. In this special episode, Jo Peterson and AWS’s Himanshu Verma discuss: Why agentic AI changes identity risk The problem of over-permissioned agents How AWS Security Hub centralizes identity and access visibility Why Security Hub helps correlate findings across core AWS security services How multi-Region resilience supports enterprise identity and continuity Guest Himanshu Verma Worldwide Leader for Security, Identity, and Governance Specialists, AWS Host Jo Peterson CIO, Clarify360 Chief Analyst, ClearTech Research 🎧 Listen: In Buzzsprout Player ▶ Watch on YouTube: https://www.youtube.com/@ClearTechResearch/videos 📰 Subscribe to the Newsletter: https://www.linkedin.com/newsletters/7346174860760416256/

    • Transcript
  • S3 · E1
    June 22 · 13 min

    The USB Problem for AI: Phil Stafford on Agents, Governance, and MCP Risk

    Short Description Season 3 of ClearTech Loop kicks off with AI security architect Phil Stafford in a practical conversation about AI governance, agent permissions, fractional identity, and why MCP servers may be the next software supply chain risk hiding in plain sight. Episode Description AI agents are moving from interesting experiments into real business environments. That means they are not just answering questions anymore. They are calling tools, touching systems, inheriting permissions, and creating a new layer of operational risk that technology and security leaders need to understand. In the Season 3 kickoff of ClearTech Loop, Jo Peterson sits down with Phil Stafford, AI security architect, security researcher, and cybersecurity professional, to talk about what happens when agentic AI stops being theoretical and starts acting inside the enterprise. This conversation gets into the practical questions leaders should be asking now: How do we govern agents when the legal system is still catching up? How do we limit what agents can actually do? What happens when an agent inherits a user’s full permissions? And are MCP servers becoming the next software supply chain problem? Phil puts it plainly: MCP has been described as the USB for AI. That is useful, but also a little terrifying if organizations treat every new connector like it belongs in the enterprise by default. No one would pick up a random USB stick in a parking lot and plug it into a company system. And yet, that is not a bad description of how some AI tooling is being adopted right now. This episode is for anyone thinking about AI governance, AI security, agentic AI, MCP servers, identity, permissions, supply chain risk, or what due diligence needs to look like when AI systems are allowed to take action. In This Episode Jo and Phil discuss: Why AI governance has to move beyond policy language and into operational controls Why measurement is the first step in governing AI agents Who may be accountable when an AI agent makes an unauthorized decision How the confused deputy problem shows up in agentic AI Why agents should not automatically inherit full user permissions What fractional identity means and why it matters How sub-agents can create another layer of access risk Why MCP servers need to be treated like part of the enterprise stack How MCP security connects to software supply chain security Why AI SBOM-style thinking may become increasingly important Featured Quote “MCP was sold to us as the USB for AI… You would not pick up a USB stick in your parking lot and put it into your enterprise environment. That’s what people are doing right now.” — Phil Stafford Why Listen Because AI governance is no longer just a strategy conversation. Once agents begin acting inside workflows, systems, and business processes, the risk becomes operational. This episode helps leaders think more clearly about what needs to be measured, limited, validated, monitored, and documented before agent behavior becomes tomorrow morning’s problem. Chapters 00:00 — Introduction to Season 3 of ClearTech Loop 00:28 — Meet Phil Stafford 01:00 — Operationalizing AI governance 01:14 — Why measurement comes first 01:58 — Legal accountability and due diligence 02:43 — The confused deputy problem 03:39 — Why agent permissions need to be scoped 04:05 — What fractional identity means 05:45 — Time-bound permissions and agent behavior 06:48 — Sub-agents and inherited access 08:17 — MCP servers and the AI security lifecycle 08:35 — MCP as the USB for AI 09:53 — Allow lists, detection, and unapproved servers 10:35 — MCP as a software supply chain issue 11:32 — AI SBOMs and applying existing controls 12:18 — Closing thoughts Guest Bio Phil Stafford is an AI security architect, security researcher, and cybersecurity professional. He advises organizations on AI security infrastructure, cybersecurity foundations, AI transformation strategy, and secure implementation practices. His work focuses on practical approaches to AI security, MCP risk, agent reliability, and the infrastructure needed to support safer AI adoption. Resources Singularity Systems https://securingthesingularity.com/ The Adversarial Trust Layer: Why the MCP Ecosystem Needs Cryptographic Attestation and Multi-Agent Verification https://credence.securingthesingularity.com/papers/adversarial-trust-layer.html Phil Stafford on Medium https://medium.com/@pe.stafford Watch ClearTech Loop on YouTube https://www.youtube.com/@ClearTechResearch Subscribe to the ClearTech Loop LinkedIn Newsletter https://www.linkedin.com/newsletters/7346174860760416256/ Follow ClearTech Loop ClearTech Loop is hosted by Jo Peterson, CIO of Clarify360 and Chief Analyst at ClearTech Research. Subscribe for more Season 3 conversations on AI security, governance, infrastructure, cloud, cybersecurity, and the technology decisions shaping enterprise strategy. 🎧 Listen: In Buzzsprout Player ▶ Watch on YouTube: https://www.youtube.com/@ClearTechResearch/videos 📰 Subscribe to the Newsletter: https://www.linkedin.com/newsletters/7346174860760416256/

    • Transcript
  • S2 · E10
    June 10 · 16 min

    AI Security: Gerald Auger on Shadow AI, Non Human Identities, and AI Defense

    AI is moving faster than policy, training, and many traditional controls were designed to handle. In this episode of ClearTech Loop, Jo Peterson talks with Gerald Auger, Chief Content Creator of Simply Cyber, about shadow AI, non human identities, over-permissioned agents, and what AI defense means when AI systems can act at machine speed. Gerald brings the educator, GRC, and practitioner-community lens to the conversation. His take is practical: organizations probably cannot put AI back in the bottle, so they need to educate users, provide approved tools, bring agents into identity governance, and start treating AI governance like a real security discipline. What You’ll Hear in This Episode Jo and Gerald discuss: Why shadow AI is a problem for IT, security, and the organization How AI is becoming easier to use inside everyday SaaS tools Why sensitive data in public AI tools creates a visibility gap Why user education has to be part of AI security How non human identities and AI agents create new permissioning risks Why Gerald thinks organizations may need a “manager in the loop” What AI defense means when AI systems can act quickly and at scale Key Insight AI governance is becoming its own discipline. Gerald’s point is not that organizations can stop AI adoption. It is that they need to build around it with education, approved tools, segmented environments, identity controls, better detection, and practical guardrails before “just let it run” becomes the strategy. Which, respectfully, is not a strategy. It is a group project with consequences. Timestamps 00:00 Introduction to Gerald Auger 00:30 Gerald’s background in cybersecurity, education, and Simply Cyber 01:38 Shadow AI as an IT, security, and organizational issue 03:00 Why public AI tools create data visibility risk 04:40 Why organizations have to “ride the lightning” 06:46 Jo on the missing layer of AI security training 07:13 AI inside everyday tools and emerging attacker behavior 08:58 Non human identities and over-permissioned agents 12:30 AI Wrangler or Manager in the Loop? 13:12 What AI defense means in practice 15:46 AI Gone Wild and closing thoughts Guest Bio Gerald Auger, PhD, is Chief Content Creator of Simply Cyber. He is a cybersecurity educator, GRC practitioner, community builder, and creator of the Simply Cyber Daily Cyber Threat Brief. He has a PhD in Cyber Operations from Dakota State University and teaches cybersecurity at The Citadel. Through Simply Cyber, Gerald helps cybersecurity professionals build careers through practical education, daily threat briefings, and practitioner-first community content. Resources Simply Cyber Academy: The Definitive GRC Analyst Program https://academy.simplycyber.io/p/the-definitive-grc-analyst-program Flashlight in a Dark Room: A Grounded Theory Study on Information Security Management at Small Healthcare Provider Organizations by Gerald Auger https://scholar.dsu.edu/theses/329/ Subscribe to ClearTech Loop on YouTube: https://www.youtube.com/@ClearTechResearch/ Follow Follow ClearTech Loop for more conversations on AI security, cybersecurity leadership, AI governance, cloud security, GRC, risk, and enterprise technology strategy. 🎧 Listen: In Buzzsprout Player ▶ Watch on YouTube: https://www.youtube.com/@ClearTechResearch/videos 📰 Subscribe to the Newsletter: https://www.linkedin.com/newsletters/7346174860760416256/

    • Transcript
  • S2 · E9
    June 2 · 19 min

    AI Security: Maybelyn Plecic on Shadow AI, Non Human Identities, and AI Defense

    Your AI policy does not matter much if no one understands how to follow it. In this episode of ClearTech Loop, Jo Peterson talks with Maybelyn Plecic, Manager of Training and Adoption at Network to Code, about shadow AI, non human identities, and what AI defense actually means when people are already using AI to get work done. Maybelyn brings a security, compliance, training, and adoption lens to the conversation. She is CISSP certified, AWS certified, and has spent her career helping teams strengthen security posture, drive compliance initiatives, and make technical change usable. Why This Matters AI adoption is already happening inside organizations. The challenge is that governance, policy, training, and approved tools are not always keeping pace. That creates risk, but not always because people are acting recklessly. In many cases, employees are trying to move faster, automate boring work, and solve problems the official process has not solved yet. Maybelyn frames shadow AI as an IT issue, a security issue, and a trust issue. Her point is clear: if leaders want people to use AI safely, they have to make the safe path understandable, practical, and easier than the workaround. What You’ll Hear in This Episode Why shadow AI starts with trust, not blame How protected proof of concept environments and AI sandboxes can reduce risk Why shared language matters when AI systems, agents, and workflows touch data How prompt injection, AI training defaults, and history tracking create new security concerns Why AI defense is not just a tooling conversation How leaders can create AI guidance that teams will actually follow Key Insight AI security is not only about tools and controls. It is about whether people understand the rules, whether the approved process works, and whether organizations are willing to meet teams where the work actually happens. As Maybelyn says in the episode: “how do you expect someone to be compliant if they don't even know the rules, right?” Timestamps 00:00 Introduction to ClearTech Loop 00:26 Meet Maybelyn Plecic 01:29 Shadow AI: IT problem, security problem, or both? 01:54 Why shadow AI starts with trust 03:00 AI is moving faster than governance 04:47 AI generated content, visibility, and accountability 06:35 How language around AI is changing 08:43 Using AI to automate the boring work 10:40 How AI changes the CISO conversation 12:33 Non human identities and the importance of shared language 13:05 Workflow questions become security questions 14:26 Prompt injection, AI defaults, and training gaps 15:47 What AI defense means beyond tools 17:30 Why AI guidance has to match each team 18:45 Closing thoughts Guest Bio Maybelyn Plecic is the Manager of Training and Adoption at Network to Code. She specializes in helping teams make technical change practical, secure, and usable. Her work spans security posture, compliance initiatives, technical enablement, training strategy, and customer adoption. She brings a builder’s perspective to AI security, with a focus on making complex technology easier for people to understand and use responsibly. Additional Resources Maybelyn Plecic website: https://www.maybelynplecic.com/ Network to Code Resource Center: https://networktocode.com/resources/resource-center/ NIST AI Risk Management Framework: https://www.nist.gov/itl/ai-risk-management-framework Season 1 ClearTech Loop: https://www.buzzsprout.com/2248577 Follow ClearTech Loop for more conversations on AI security, cybersecurity leadership, AI governance, shadow AI, non human identities, and enterprise technology strategy. 🎧 Listen: In Buzzsprout Player ▶ Watch on YouTube: https://www.youtube.com/@ClearTechResearch/videos 📰 Subscribe to the Newsletter: https://www.linkedin.com/newsletters/7346174860760416256/

    • Transcript
  • S2 · E8
    May 27 · 16 min

    AI Security: Patricia Titus on Shadow AI, Non-Human Identities, and AI Defense

    AI security is not showing up as one clean problem. It is showing up across governance, risk, productivity, identity, API security, and defense. In this episode of ClearTech Loop, Jo Peterson talks with seasoned CISO Patricia Titus, about shadow AI, non human identities, AI agents, APIs, and what AI defense means when organizations are trying to move quickly without losing control. Patricia brings more than 25 years of cybersecurity leadership experience across public and private sectors, including financial services, technology, and government. Patricia’s take is practical: shadow AI is both an IT and security issue, but it is also a governance, risk, and productivity problem. If organizations want employees to use AI responsibly, the approved path has to be easier than the workaround. What You’ll Hear in This Episode Jo and Patricia discuss: Shadow AI as a governance, risk, productivity, and security issue Why visibility has to come before control How CISOs and CIOs can create approval lanes that are easier than going rogue Why AI agents are becoming a new control plane How non human identities, service accounts, bots, and APIs are changing the access conversation Why AI defense is less about novelty and more about applying fundamentals at a new scale and speed Key Insight AI defense is not just about buying new tools. It is about understanding what AI connects to, what data it consumes, how agents behave, and whether the organization can prove access is controlled. That makes this episode especially relevant for CIOs, CISOs, IT leaders, security leaders, and enterprise teams trying to manage AI adoption inside real environments. Timestamps 00:00 Introduction to Patricia Titus 01:34 ClearTech Loop hot take format and AI security focus 02:25 Shadow AI as both an IT and security problem 03:03 Visibility, safe paths, and enforceable guardrails 05:17 AI agents as a new control plane 06:06 Why emerging AI agent behavior creates new concerns 08:46 Jo on executive awareness and evidence 10:33 Non human identities and how CISOs and CIOs are enabling them 12:34 Least privilege, zero trust, and proving agents are turned off 14:27 APIs as part of the non human identity conversation 15:25 AI defense as fundamentals at a new scale and velocity 16:12 Closing thoughts Guest Bio Patricia Titus is a seasoned Chief Information Security Officer. She is a global cybersecurity executive with more than 25 years of experience leading security organizations across financial services, technology, government, and other highly regulated sectors. She has held C level and executive positions at Booking Holdings, Markel Corporation, Freddie Mac, Symantec, Unisys, and the TSA. Patricia also serves on the Board of Directors for Black Kite and on advisory boards for several organizations focused on cybersecurity, technology, and risk. Her work focuses on resilience, risk management, AI driven security, business alignment, and helping organizations understand how cyber risk affects operations and leadership. Resources If Every User Needs an Identity, Why Don’t Our APIs? by Patricia Titus https://abnormal.ai/blog/user-identity-apis Preparing for AI Regulation: What CISOs Can Do Now by Patricia Titus https://abnormal.ai/blog/preparing-for-ai-regulation-what-cisos-can-do-now Building a Culture of Proactive Threat Defense by Patricia Titus https://abnormal.ai/blog/building-a-culture-of-proactive-threat-defense Season 1 ClearTech Loop https://www.buzzsprout.com/2248577 Follow Follow ClearTech Loop for more conversations on AI security, cybersecurity leadership, AI governance, cloud security, risk, and enterprise technology strategy. 🎧 Listen: In Buzzsprout Player ▶ Watch on YouTube: https://www.youtube.com/@ClearTechResearch/videos 📰 Subscribe to the Newsletter: https://www.linkedin.com/newsletters/7346174860760416256/

    • Transcript
    • Chapters
  • S2 · E7
    May 21 · 11 min

    ClearTech Loop Special Edition: Rethinking CDN Pricing with AWS CloudFront

    Cloud pricing can look simple until the bill arrives. In this ClearTech Loop Special Edition, Jo Peterson talks with Cristian Graziano, Principal Product Manager at Amazon Web Services, about AWS CloudFront flat rate plans and why predictable pricing matters for teams delivering internet facing applications. Cristian explains how CloudFront helps accelerate and secure applications, why customers often combine CDN, WAF, DDoS protection, DNS, logging, and monitoring, and how flat rate plans are designed to make that model easier to understand, approve, and manage. In this episode Jo and Cristian discuss: What AWS CloudFront does Why CDN pricing can get complicated How CloudFront flat rate plans simplify pricing Why predictable monthly costs matter for developers, business units, SMBs, and enterprise teams How AWS is making security part of the starting point Why WAF, DDoS protection, bot controls, and security visibility matter for internet facing applications Featured quote “Security is included by default.” Cristian Graziano, Principal Product Manager, AWS About the guest Cristian Graziano is a Principal Product Manager at Amazon Web Services. His work focuses on the customer experience for AWS CloudFront, including onboarding, console experience, and pricing. 🎧 Listen: In Buzzsprout Player ▶ Watch on YouTube: https://www.youtube.com/@ClearTechResearch/videos 📰 Subscribe to the Newsletter: https://www.linkedin.com/newsletters/7346174860760416256/

    • Transcript
  • S2 · E6
    May 19 · 15 min

    AI Security Starts with Education: James McQuiggan on Shadow AI, NHIs, and AI Defense

    AI security is not only about policies, tools, and controls. It is also about education. In this episode of ClearTech Loop, Jo Peterson talks with James McQuiggan, founder and CISO of Apparent Security, about shadow AI, non human identities, and what AI defense means as organizations try to keep up with real world AI adoption. James brings the lens of an educator to the conversation. His perspective keeps coming back to how people learn, how they adopt new tools, and why security teams need to guide safe AI use instead of relying on blocking or policy alone. In this episode Jo and James discuss: Shadow AI as the next version of shadow IT Why AI adoption is happening faster than governance and training How CISOs and CIOs can create safer paths for employees using AI Why non human identities create new access and data flow risks How AI defense includes defending with AI, defending against AI enabled attacks, and protecting AI systems themselves Timestamps 00:00 Introduction to James McQuiggan and the episode theme 02:32 Shadow AI as the next version of shadow IT 06:17 Why education matters in AI policy and rollout 07:34 Training, micro learning, and helping users work safely 10:05 Non human identities, access, and data flow 12:27 What AI defense means in practice 15:00 Final thoughts and closing Guest Bio James McQuiggan is founder and CISO of Apparent Security. He is a threat intelligence strategist, cybersecurity educator, and practitioner with more than 25 years of experience across critical infrastructure, human risk management, and security leadership. Resources AI and the Boardroom: Bridging Innovation and Security by James McQuiggan: https://blog.knowbe4.com/ai-and-the-boardroom-bridging-innovation-and-security National Institute of Standards and Technology Cybersecurity Framework: https://www.nist.gov/cyberframework Follow Follow ClearTech Loop for more conversations on AI security, cybersecurity leadership, AI governance, and enterprise technology strategy. 🎧 Listen: In Buzzsprout Player ▶ Watch on YouTube: https://www.youtube.com/@ClearTechResearch/videos 📰 Subscribe to the Newsletter: https://www.linkedin.com/newsletters/7346174860760416256/

    • Transcript
    • Chapters
  • S2 · E5
    May 5 · 12 min

    AI Security: Shadow AI, Non Human Identities, and AI Defense (Rock Lambros)

    AI is already inside your environment. The problem is most organizations don’t fully see where or how it’s being used. In this episode of ClearTech Loop, Jo Peterson sits down with Rock Lambros, CEO of RockCyber, to break down what’s actually happening with shadow AI, non human identities, and AI defense as adoption moves faster than governance. Why This Matters This isn’t a future problem. Teams are already: Using AI tools outside of approved environments Creating machine and agent identities at scale Relying on security models that were never designed for this level of automation That gap between adoption and control is where risk is showing up. What You’ll Hear in This Episode Why shadow AI is a governance issue, not just a security problem How non human identities are scaling beyond what most organizations can manage What AI defense actually means beyond vendor messaging Where organizations are most exposed right now Key Insight AI security isn’t breaking because organizations aren’t trying. It’s breaking because the systems meant to manage risk are moving slower than the systems creating it. About the Guest Rock Lambros is CEO and Founder of RockCyber and a contributor to the OWASP GenAI Security Project. His work focuses on AI governance, agentic security, and helping organizations understand how AI changes the attacksurface. Resources OWASP GenAI Security Project: https://genai.owasp.org/ AAGATE Framework: https://www.rockcybermusings.com/p/aagate-governing-the-ungovernable-operationalizing-nist-ai-rmf-agentic-ai Governing the Ungovernable: https://aicybermagazine.com/governing-the-ungovernable/ 🎧 Listen: In Buzzsprout Player ▶ Watch on YouTube: https://www.youtube.com/@ClearTechResearch/videos 📰 Subscribe to the Newsletter: https://www.linkedin.com/newsletters/7346174860760416256/

    • Transcript
Showing 1–20 of 27 episodes