AI Security Brief
Trailer
Recent Episodes
Can you trust AI with critical infrastructure?
In traditional IT, isolating a compromised endpoint can stop an attack. In operational technology (OT) environments, that same action could disrupt control of a pipeline, cause a rupture, or trigger environmental damage. That’s why adopting AI in critical infrastructure requires a fundamentally different security approach. Drawing on more than 25 years of experience across energy, pipelines, aerospace, and defense, Jason Cradit, CTO and CISO at Everline, explains how security leaders can move beyond blanket restrictions and establish practical AI governance and guardrails.
Is a closed or an open AI model more trustworthy?
There's no silver bullet when it comes to AI security strategy, and treating one model, tool, or vendor as the answer can limit an organization’s ability to adapt. Morgan Adamski, who leads PwC’s Cyber, Data & Technology Risk practice, joins us to tackle two pressing questions: How should organizations choose between closed frontier models and open-weight alternatives? And how can they build a multi-model architecture flexible enough to keep pace as AI technology rapidly evolves? Drawing on her work with boards, CISOs, and security teams, Morgan cuts through the “paralysis by analysis” surrounding these questions and offers security leaders a practical path forward.
What does hospital downtime teach us about building AI-native organizations?
Is your organization truly AI native, or did you just bolt AI onto existing infrastructure? Your answer could be an indicator to how much risk you’re carrying without realizing it. Zach Evans, Chief Technology Officer at Xsolis, has a simple test for telling the difference: strip out the AI and see if your process still works. If it does, you may be exposing your organization to security blind spots and workflows that quietly erode organizational knowledge and skills. Zach joins Johnny Hand and Dustin Childs to unpack what it actually takes to build an AI-native organization, and why the stakes of getting agentic AI wrong can be unforgiving for every organization, not just those in healthcare.
What do AI-driven ‘bank heist’ attacks mean for defenders?
Attackers aren't just using AI to steal data; they're using it to fight back while you investigate them in real time. And once an adversary is inside, why would they ever want to leave? That's the unsettling reality Tom Kellermann, VP of AI Security and Threat Research at TrendAI, lays out in this episode. And the numbers prove it. According to a 2026 TrendAI survey of 46 financial-sector CISOs, more than 60% of respondents experienced counter-incident response, where adversaries actively disrupt live investigations. In addition, nearly 90% of these leaders reported more AI-enabled attacks year over year. Tom joins Johnny Hand and Dustin Childs to explain why the threats that hit banks first tend to hit everyone else next, and what defenders can do about it.
Is AI security actually a physical problem?
While AI might seem abstract, something that lives in "the cloud" is concrete. The AI applications we use every day run on GPUs in physical buildings, and Mark Houpt secures them. As Chief Information Security Officer at DataBank, he's watched those data centers go from anonymous warehouses to national security targets almost overnight. Mark joins hosts Johnny Hand and Dustin Childs to make the case that the AI era is, at its core, a physical security problem, and why the security fundamentals you already know still work, even when applied to threats that didn't exist two years ago.



