- CISO Series Newsletter
- Posts
- There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First
CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

In our hurry to embrace LLMs and agents, we seem to be repeating all the same mistakes we made when we rushed to the cloud. While there is no lack of startups looking to fill this security void, threat actors aren't waiting for the next procurement cycle to take advantage. So how can we keep infrastructure secure in this interim?
This week's episode is hosted by David Spark, producer of CISO Series and Andy Ellis, principal of Duha. Joining is our sponsored guest, Danny Jenkins, CEO, ThreatLocker.
Listen to the full episode here.
Permission creep at machine speed
Authorization tells you what was allowed. It says nothing about whether it should have happened. That gap has always existed with human employees, noted Apurv Garg. People accumulate permissions over years because nobody really tracks what their job requires. It's different with AI. Agents inherit all of it and act on all of it, immediately and without hesitation. A human exfiltrating data tends to move slowly. An agent can inflict the same damage in seconds, with no conscience to steer it away from edge cases. The problem isn't that agents are inherently more dangerous than humans. It's that they expose the governance work organizations were never doing in the first place.
The pattern we keep calling a mistake
Businesses adopt new technology fast and security plays catch-up. But as Caleb Sima of White Rabbit pointed out, attackers don't wait for procurement cycles. This happened with the internet, with e-commerce, with cloud, and it is happening again with AI. Calling it a mistake misreads how businesses operate. Companies move when the technology is good enough, and it's good enough now. The security leaders who got out ahead of cloud became the first CISOs. The ones who kept saying no just became bottlenecks.
Stop authenticating the human
Multi-factor authentication addressed the single-password problem without solving the social engineering problem. Someone can still be tricked into handing over credentials and approving a push notification on cue. Even engineers, who are supposed to be the skeptical ones, get phished. The smarter frame is to stop thinking about authenticating a person and start thinking about a person paired with a set of known devices. Once a device has to authenticate before the human does, phished credentials stop working on their own. You might get the password and the code, but you can't get the machine certificate. Phishing someone and stealing their laptop at the same time is a much harder ask.
Vibe coded out of existence
Plain English is now a programming language. LLMs have lowered the barrier enough that business analysts are writing functional tools without calling a developer, noted CISO Tradecraft's Ross Young. Even CISOs are getting in on the action. Most of them aren't dismantling their vendor stacks. They're filling gaps that vendors have ignored, or quietly replacing tools that were only ever pretending to do something. The products most at risk are the ones that don't really build anything. They pull data from other sources and put a dashboard on top of it. That's a weekend project now. The vendors with years of edge-case experience and real-world feedback baked into their products aren't going anywhere.
Listen to the full episode on our blog or your favorite podcast app, where you can read the entire transcript. If you haven't subscribed to the CISO Series Podcast via your favorite podcast app, please do so now.
Thanks to Cary Johnson of Phishbusters for providing our "What's Worse" scenario.
Thanks to our podcast sponsor, ThreatLocker
Subscribe to CISO Series Podcast
Please subscribe via Apple Podcasts, Spotify, YouTube Music, Amazon Music, Pocket Casts, RSS, or just type "CISO Series Podcast" into your favorite podcast app.
Security You Should Know
Securing AI Agents with CompFly AI
In this episode, Venkat Siva, co-founder and CEO at CompFly AI, explains how his platform gives security, engineering, and business teams a control plane for autonomous AI agents across their full lifecycle.
CompFly discovers agents, assigns each one a verifiable distributed identity, runs adversarial and safety simulations before launch, enforces deterministic policies at runtime through a gateway, and produces immutable audit logs for compliance teams after the fact.
Joining him are Mike Lockhart, CISO at EagleView, and Gary Chan, System VP and CISO at SSM Health.
Want to know:
Why is safely deploying AI agents still an open question for so many organizations?
How do you govern an agent that can stitch normal permissions into abnormal outcomes?
How does CompFly plug into a stack that already includes Bedrock, Copilot Studio, LangChain, and custom harnesses?
What happens when an agent action gets blocked, and what does the audit trail look like?
How do you validate that the policies CompFly recommends are the right ones for your agents?
Where do the boundaries sit when agents have code execution capabilities of their own?
Who watches the watcher, and how does CompFly itself stay trustworthy?
Check out the episode for the answers you need.
Thanks to our podcast sponsor, CompFly AI
Subscribe to Security You Should Know
Please subscribe via Apple Podcasts, Spotify, Amazon Music, Pocket Casts, RSS, or just type "Security You Should Know" into your favorite podcast app.
What I love about cybersecurity…
“I love winning. I love it when we manage to stop something, stop a hack, or really, really annoy somebody on a server who's trying to take over a system. I just love winning.“ - Danny Jenkins, CEO, ThreatLocker
Listen to the full episode of "There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First"
Has Cybersecurity Become a Cult?
"Discipline questions itself. It goes, 'I see I'm doing this. Why am I doing this?' And that refines the discipline. We're doing it dogmatically. We're doing it because we're told to do it because the framework says so." - Joshua Copeland, director of security, Crescendo
Listen to the full episode of "Has Cybersecurity Become a Cult?"
CISO Series Newsletter - Twice every week
Cybersecurity Headlines Newsletter - Every weekday
Security You Should Know Newsletter - Weekly
Every Host Has to Learn Their Listeners Matter More Than Them
Dave Bittner, podcast host at The CyberWire, and David Spark had a discussion about what separates great cybersecurity content from the forgettable: respecting the listener's time, asking the questions the audience actually has, and caring enough about the craft to do it right.
Watch here.
Thanks to our sponsor, ThreatLocker
Cybersecurity Headlines - Department of Know
Our LIVE stream of The Department of Know happens every Friday at 4 PM ET / 1 PM PT with CISO Series producer Richard Stroffolino, and a panel of security pros. Each week, we bring you the cybersecurity stories that actually matter, and the conversations you’ve been having at work all week long.
Friday’s episode will feature Brett Conlon, CISO, American Century Investments, and Jason Thomas, senior director, technology security, governance, and risk, Cystic Fibrosis Foundation. Join us on YouTube and catch up on what shaped the week in security.
Thanks to our Cybersecurity Headlines sponsor, Doppel
Super Cyber Friday
Join us Friday for “Hacking the Analyst Firms”
Join us on Friday, June 12, 2026, for Super Cyber Friday: “Hacking the Analyst Firms: An hour of critical thinking about how vendor rankings get made and who they're really for.”
It all kicks off at 1 PM ET / 10 AM PT, when David Spark will be joined by Chris Ray, field CTO, GigaOm, and Fernando Montenegro, vice president and practice lead, cybersecurity, Futurum Group, for an hour of insightful conversation and engaging games. And stick around for our always-popular meetup, hosted right inside the event platform.
Help us get the word out! Share next week’s Super Cyber Friday registration link on LinkedIn, tag me (David Spark) and CISO Series, and you'll be entered for a chance to win an item from our prize store. We'll randomly pick one winner from everyone who shares.
Participate! Add our live shows to your calendar
Learn more about all of the fun ways you can participate, and add our events to your calendar.
Google Calendar, iCalendar, Outlook, or export an .ics file
Cybersecurity Headlines - Daily News Shorts
Subscribe to the CISO Series YouTube channel, for daily shorts videos from CISO Series reporter, Rich Stroffolino. You can find all of the stories he’s covered, plus new content every weekday, at the Cybersecurity Headlines Shorts YouTube playlist.
Thank you for supporting CISO Series and all our programming
We don’t just say we appreciate your feedback; we incorporate it into our programming. Learn more about all of the fun ways you can participate.
We love all kinds of support: listening, watching, contributions, What's Worse?! scenarios, telling your friends, sharing on social media, and most of all we love our sponsors!
Everything is available at cisoseries.com.
Interested in sponsorship, contact me, David Spark.





