
9 Minutes to Erase All Code. Security in the Age of AI | Jack Nelson, Ivanti
An AI agent hit an authentication error it couldn't get past. So it deleted the company's entire source code. Then the backup repo. Nine minutes, start to finish. "That should keep CISOs up at night." On The AI Floor, Shamil Malachiyev sits down with Jack Nelson, Chief Information Security Officer at Ivanti, for a ground-level look at what agentic AI is actually doing to enterprise security. Jack came to the CISO seat by an unusual route: 10 years as a commercial litigator, and by his own admission he has never written a line of code in his life. That turns out to be the point. His job is translating between the engineers who find the vulnerabilities and the executives who have to explain them to a board. He breaks down where AI adoption genuinely works, where it quietly fails, and what he will not let through the gate. Expect to learn: - Why an AI agent deleted a company's source code and its backup in nine minutes - Why "garbage in, garbage out" now runs at machine speed, and why that quietly sinks most AI projects - Why 92% patch coverage used to be excellent and is now a serious hole - Why a 10% security budget increase isn't enough, and who's telling companies to double it - Prompt injection without the jargon: it's social engineering, but for agents - Why AI isn't finding new classes of vulnerability, it's just brutally good at the known ones - How an AI governance committee decides what gets fast-tracked and what gets fully reviewed - Why accountability stays human: if your name is on it, you answer for it, robot or not If you run security, sit on a board, or you're shipping AI into a company that holds someone else's data, this is the from-the-trenches version. CHAPTERS 0:00 Nine minutes to no code 1:37 Welcome, Jack 2:01 From the courtroom to the CISO seat 6:44 Adopt fast or stay secure? 7:26 An AI agent deletes everything, backup included 9:53 Inside the AI governance committee 14:37 Garbage in, garbage out, at machine speed 18:23 Why tools are useless without the fundamentals 22:23 The patch apocalypse 27:45 Why a 10% budget bump isn't enough 30:26 Defence has to win every time 32:26 Prompt injection is social engineering for agents 37:19 Know your data before you build 42:05 Locking down agent access 44:30 When regulation makes you less safe 48:28 Training people for the AI era 50:37 A robot wrote it. Your name is still on it. 55:08 Hiring, remote work and the North Korean IT worker problem 59:35 Closing: walk before you run 👇 CONNECT WITH JACK NELSON Jack Nelson ► https://www.linkedin.com/in/nelsonjackt/ Ivanti ► https://www.ivanti.com/ 👇 CONNECT WITH SHAMIL Shamil Malachiyev ► https://www.linkedin.com/in/shamilmalachiyev/ FluidLabs ► https://fluidlabs.com/ 🎙 LISTEN to The AI Floor (The Founder's Code, Season 2) Spotify ► https://open.spotify.com/show/7v6YOQ77R1xzbOiiHsDawd Apple ► https://podcasts.apple.com/sa/podcast/the-founder-s-code/id1797768317 🔔 SUBSCRIBE for more unfiltered, ground-level conversations with the people actually building AI inside real companies. ABOUT THIS CHANNEL The AI Floor - honest, ground-level conversations that cut through the AI hype and count what's really happening with automation and AI agents across the industry. No shiny LinkedIn posts, just AI reality from the people doing the work. #AI #CyberSecurity #AIAgents #CISO #Ivanti #AISecurity #PromptInjection #JackNelson #TheAIFloor #Podcast


















