Join us tomorrow for "Hacking Pentesting in the Age of Agentic AI"

Join us TOMORROW, Friday [05-29-26], for "Hacking Pentesting in the Age of Agentic AI"

Join us Friday, May 29th, 2026, for “Hacking Pentesting in the Age of Agentic AI: An hour of critical thinking about who's really in charge when the machines do the testing.”

It all begins at 1 PM ET/10 AM PT tomorrow, with guests Eric Sheridan, CTO, Sprocket Security, and Will Gregorian, CISO, Galileo Medical. We'll have fun conversation and games, plus at the end of the hour we'll do our meetup in breakout rooms.

Thanks to our Super Cyber Friday sponsor, Sprocket Security

Defense in Depth
What Does the Next Generation of Cloud Security Look Like?

Detection was originally built for humans who were writing the code.

We know human-paced security controls can't be applied to autonomous AI agents. So what needs to change with CNAPP and cloud security? 

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by David Spark, the producer of CISO Series, and Steve Zalewski. Joining us is our sponsored guest, Dan Benjamin, vp product - data, identity, and AI security, Palo Alto Networks.

Listen to the full episode here.

The detection ceiling

Detection-first security wasn't designed for a world where a third of code is AI-generated. "The real question isn't whether CNAPP vendors can adapt. It's whether detection-first survives when the attack surface is generated code running at machine speed. Coverage gap isn't a tooling problem. It's a design problem. You can't inspect your way to safety when a third of code is AI-generated," said Bil Harmer, CISO at Supabase. Daniel Spangenberg located where the process actually breaks: "The bottleneck was never finding the misconfiguration. It was the human loop after the finding." Add agents and the loop inverts. By the time a human reviews, the agent has made twenty more changes. What's needed isn't an AI module bolted onto CNAPP. It's a shift, he argued, from periodic evaluation against state to deterministic evaluation at the point of change. 

A category gap, not a feature gap

The governance problem with AI agents isn't a tooling shortfall. It's that the right tool category doesn't exist yet. Andrew Wilder, CSO at Vetcor, explained, "The permission model for AI agents doesn't exist yet. We have autonomous systems browsing, querying, writing, and executing cloud ops and we're governing them with tools designed for humans doing those things manually. This isn't a CNAPP gap. It's a category gap." Jason Elrod, CISO at MultiCare Health System, pushed the problem further: "We're shifting from human-executed decisions to system-driven decisions at machine speed. Coverage and detection matter, but the real (and growing) gap is accountability. Who owns the decision when it's made by an agent?"

Resilience by design

If defense can't match AI's speed reactively, it has to be built in before anything runs. Erik Bloch of Illumio thinks of it as a network architecture problem. Assume an agent gets in, then ask how you limit what it can reach. "Building resilient networks, like we will with code, will reshape defense and place more on upfront design, vs. today's reactive measures." Debra Anderson didn't mince words about the stakes. "Security will need to shift from static posture management to real-time, risk-adaptive control systems." If a third of code is AI-generated, she said, security has to operate at machine speed, or become irrelevant.

An insider threat with no face

Agents are a threat category for which security has no playbook yet. "CNAPP was built for human-scale threats. An agent without an owner is an insider threat with no face at machine speed. We have methodologies that we apply to humans every day. But we simply haven't built all of the defensive responses for agents yet," said Dutch Schwartz of Nisos. And the scale goes beyond permissions. Aniketh Maddipati of AgentMint added that even with the right model in place, you still can't answer what the agent did. Detection assumes you can inspect fast enough, but with agent workflows, the action is already done before detection fires. The missing piece, he said, is "evidence that's generated at execution time — not reconstructed after the fact from logs the operator controls."

Please listen to the full episode on your favorite podcast app, or over on our blog, where you can read the full transcript. If you’re not already subscribed to the Defense in Depth podcast, please go ahead and subscribe now.

Huge thanks to our sponsor, Palo Alto Networks

Subscribe to Defense in Depth podcast

Please subscribe via Apple Podcasts, Spotify, YouTube Music, Amazon Music, Pocket Casts, RSS, or just type "Defense in Depth" into your favorite podcast app.

May AMA: "I'm a security professional who has dealt with ransomware. Ask me anything about incident response and business continuity."

Our monthly AMA on r/cybersecurity on Reddit is underway! Ransomware continues to be one of the most disruptive threats facing organizations today, but what does it actually look like when you're in the middle of it?

This month we've brought together security professionals who have navigated ransomware incidents firsthand, from initial response to recovery to keeping the business running under pressure. They're here all week to share what they've learned.

Please ask questions for our participants here.

This month's participants are:

  • Gary Hayslip, (u/Shaynei), former vp, senior security advisor, Halcyon

  • Peter Clay, (u/cpthuah36), CISO, Aireon

  • Trey Blalock, (u/Trey-Blalock-AMA), former CISO, researcher & keynote speaker, Verification Labs

  • Adam Marre, (u/amarre_sec), CISO, svp, Arctic Wolf

Thanks to all of our participants for contributing!

Cybersecurity Headlines - Department of Know

Our LIVE stream of The Department of Know happens every Friday at 4 PM ET / 1 PM PT with CISO Series producer Richard Stroffolino, and a panel of security pros. Each week, we bring you the cybersecurity stories that actually matter, and the conversations you’ve been having at work all week long.

Friday’s episode will feature Bruce Schneier, chief of security architecture, Inrupt and Chris Ray, field CTO, GigaOm. Join us on YouTube and catch up on what shaped the week in security.

Thanks to our Cybersecurity Headlines sponsor, Guardsquare

Share for a chance to WIN A FREE GIFT!

Help us get the word out! Share next week’s Super Cyber Friday registration link on LinkedIn, tag me (David Spark) and CISO Series, and you'll be entered for a chance to win an item from our prize store. We'll randomly pick one winner from everyone who shares.

Participate! Add our live shows to your calendar

Learn more about all of the fun ways you can participate, and add our events to your calendar.

Cyber chatter from around the web...
Jump in on these conversations

  • "Linus Torvalds says AI-powered bug hunters have made Linux security mailing list 'almost entirely unmanageable'" (More here)

  • "'The Worst Leak That I've Witnessed': U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub — Gizmodo" (More here)

  • "Microsoft is pulling the plug on SMS codes, wants you to switch to passkeys." (More here)

Coming up on Super Cyber Friday:

  • [05-29-26] - “Hacking Pentesting in the Age of Agentic AI”

  • [06-05-26] - “Hacking Agentic Access”

Register for and add all of these events to your calendar on our Events Page.

Cybersecurity Headlines - Daily News Shorts

Subscribe to the CISO Series YouTube channel, for daily shorts videos from CISO Series reporter, Rich Stroffolino. You can find all of the stories he’s covered, plus new content every weekday, at the Cybersecurity Headlines Shorts YouTube playlist.

Thank you for supporting CISO Series and all our programming

We don’t just say we appreciate your feedback; we incorporate it into our programming. Learn more about all of the fun ways you can participate.

We love all kinds of support: listening, watching, contributions, What's Worse?! scenarios, telling your friends, sharing on social media, and most of all we love our sponsors!

Everything is available at cisoseries.com.

Interested in sponsorship, contact me, David Spark.