
Hosted by KBI.Media · EN

Most security vendors are shipping AI that treats capability as authority. Sean Duca thinks that’s the mistake customers are already paying for. Back on KBKast for a third time, now as co-founder and CEO of getsoteria.ai, Sean makes the case that confidence and permission are two separate gates, and that an autonomous SOC needs both before it touches anything. He walks Karissa through governed autonomy: the machine acts on its own, but only inside a boundary it can’t set or cross. A bank teller and a self-driving car do the heavy lifting on the difference between a human in the loop, on the loop, and off it entirely. He gets specific about shadow mode, the 85% agreement bar his threat hunters have to keep clearing, and why his system fails closed and hands everything back to a person the moment it hits a wall. About Sean: Sean Duca has spent 25+ years in cybersecurity, most of it advising boards and security leaders across Asia Pacific. He’s now co-founder and CEO of getsoteria.ai, following senior roles as CTO for Customer Experience at Cisco (APJC), VP and Regional Chief Security Officer at Palo Alto Networks (APJ), and CTO for APAC at Intel Security. He’s a published author on cybersecurity and calls Singapore home. Keywords: autonomous SOC, AI governance, governed autonomy, agentic AI security, confidence vs permission, human in the loop, AI access control, SOC automation, shadow mode, security operations, AI authority model, CISO, board risk, Sean Duca, getsoteria.ai, KBKast

The old security math is broken. Teams used to get roughly 60 days between a vulnerability going public and attackers using it. Harman Kaur, Tanium’s CTO, explains why that number has flipped to negative, and what it means when the patch you need does not exist yet. This conversation is about the difference between automation and transformation. Running the same broken process faster is not progress. Harman makes the case for rebuilding security from first principles: changing org charts, retiring tools people have relied on for years, and moving humans out of triage and into judgment. She also gets specific about trust. In her view, trust now sits in the underlying data, because a confident AI acting on stale or incomplete data becomes dangerous at scale. Harman & KB get into the boardroom scramble around Mythos, why there is no single tool that solves it, and why the vendors closest to the data will be the ones left standing. About Harman: As Chief Technology Officer, Harman Kaur leads Tanium’s technology strategy, product management, AI and automation roadmap, and strategic technology partnerships. Harman brings more than a decade of combined experience across the United States Air Force and Tanium. She continues to serve as a Cyber Officer in the U.S. Air Force. At Tanium, Harman has held senior roles across the customer organization, R&D, and most recently led the company’s AI and Autonomous Endpoint Management strategy as head of AI before stepping into the CTO role. Harman received an MBA from the University of Southern California and a BS in Information Systems from Hawaii Pacific University. Keywords: cybersecurity, AI security, vulnerability management, patch management, endpoint security, autonomous endpoint management, Tanium, Harman Kaur, security automation, AI transformation, data quality, zero day, CISO, board risk, Mythos, security operations, KBKast

Bradon Rogers, Chief Customer Officer at Island, the company that created the enterprise browser category in 2020, joins KB to unpack why the industry spent two decades bolting security around the browser instead of building it in. They dig into whether organisations are solving complexity or just relocating it, why VPNs and VDI survived so long when everybody hated them, and Bradon’s blunt read on SASE: legacy on-prem architecture shoved into the cloud. He explains why SSL inspection leaves blind spots the laws of physics won’t let you close, what zero trust misses after access is granted, and how data boundaries keep company information out of personal AI tenants without turning security into the say no police. Bradon closes with his prediction for the next two years: non-human identities, agents working without human hands on the wheel, and agentic engineers who won’t just be developers but lawyers and doctors shepherding agents through their work. About Bradon: Bradon Rogers is the Chief Customer Officer at Island, where he directs the technical aspects of all customer interactions, leveraging his vast experience in cybersecurity, enterprise software, and cloud technology. Bradon’s career in cybersecurity spans over 25 years, during which he has played an executive leadership role for some of the largest firms in the industry. Keywords: enterprise browser, browser security, Island, zero trust, VPN replacement, VDI, SASE, SSL inspection, DLP, shadow AI, data boundary, agentic AI, AI agents, non-human identity, CISO, cybersecurity podcast

KB is on the ground at SAP Sapphire 2026 in Orlando, where AI has moved beyond experimentation and into the center of enterprise decision making. In this KB On The Go episode, Maura Hameroff (CMO, Cloud ERP Private and RISE with SAP) makes the case that modernizing your core is a business transformation decision rather than a technical upgrade, and that companies still running on legacy systems carry more operational and security risk than most realize. Then Ted Way, PhD (VP & Chief Product Officer, Business AI Product Engineering, SAP) walks through what responsible enterprise AI actually takes: a governance layer, real business process knowledge, and data you can trust. As he puts it, AI first without security first is just a faster way to a data breach. A grounded look at what it takes to move from AI pilots to AI at scale without cutting corners that come back to bite you.

In this episode, Anna Wheeler, CEO of SSAW LLC, joins KB as she explains why so many cyber teams are stuck in event-driven strategy while calling it the real thing, why the doers can’t climb out of it because their KPIs won’t let them, and why visionary CEOs keep getting ousted when the board can’t see what they see. Along the way: the CEOs quietly burning more AI tokens than anyone else in their company, vendors winning unicorn exits on marketing rather than technology, adversaries stealing encrypted data as a long game, and what happens when boards start making decisions on synthetic confidence. Her closing advice for leaders: get very comfortable with being uncomfortable, and go looking for the sources you’d normally avoid. About Anna: Anna Wheeler is a cybersecurity strategist and former Army Blackhawk crew chief who has spent the last two decades helping government and industry modernize how they secure missions, data, and critical infrastructure. She has led federal modernization and cyber campaigns across DHS and the wider national security community, shaping multi‑billion‑dollar technology portfolios and advancing cloud, Zero Trust, and AI‑driven approaches to resilience. As CEO of SSAW LLC and a trusted advisor to C‑suites, boards, and policymakers, Anna is known for turning buzzword-heavy innovation into pragmatic, mission‑aligned change. She serves on multiple advisory boards, mentors rising cyber leaders, and speaks frequently on moving from “FOMO to focus” in cybersecurity innovation. Keywords: AI strategy, CISO, board of directors, CEO, cybersecurity leadership, event-driven strategy, strategic thinking, synthetic confidence, AI bias, go-to-market, vendor marketing, Symantec, SBOM, harvest now decrypt later, cybersecurity podcast

Recorded at Cisco Live 2026 in Las Vegas, where 20,000 operators, engineers and executives gathered at Mandalay Bay to shape the future of networking, AI and cybersecurity. KB sits down with two Cisco leaders confronting the problems AI is creating and the infrastructure built to outlast them. Tom Gillis, SVP and GM of Cisco’s Infrastructure and Security Group, explains why the gap between a vulnerability being disclosed and exploited has collapsed from months to hours, and how Live Protect shields critical flaws between patches with no reboot and no downtime. Then Ramana Kompella, Head of Cisco Research and Cisco Fellow, makes the case for quantum networking over ever bigger quantum computers, unpacks the new Universal Quantum Switch, and explains why “harvest now, decrypt later” makes quantum safe infrastructure a today decision, not a 2029 one. Key topics: AI accelerated exploitation, vulnerability shielding and Live Protect, continuous infrastructure updates and digital twins, quantum networking, the Universal Quantum Switch, post quantum cryptography and CNSA 2.0, and the harvest now decrypt later threat.

John leads customer success, presales, and professional services across APAC at Workato and serves as Field CTO for the region. With more than twenty-five years of experience, including roles at Oracle and TIBCO and as co-founder of Rubicon Red, he focuses on helping enterprises unlock real, lasting value from AI and integration. In this episode of KBKast, John joins KB to unpack why 42% of AI initiatives were abandoned in 2025, up from 17% the year before, and why the answer isn’t the technology. It’s trust. John explains why AI is a bigger deal than cloud ever was: what used to be storage and processing is now decision and action inside core enterprise systems. He takes aim at “governance theater,” the steering committees and policy documents that create a feeling of control while nobody can actually see what an agent is doing. And he lands the warning every security leader needs to hear: you got away with over-provisioning access for humans, because humans never went looking. Agents will. Also covered: the tokenomics panic, 700% month-on-month cost blowouts, why AI shouldn’t re-map a purchase order every single time, who owns the agent when things go wrong, and why a central control plane is the only way to govern agents at scale. Keywords: AI agents, agentic AI, AI governance, governance theater, enterprise AI, AI security, control plane, observability, MCP, tokenomics, AI cost management, AI strategy, CISO, agent permissions, Workato, shadow AI, AI ROI, autonomous agents

KB grabs the mic backstage at SPHERE 2026 by Atmos for two conversations that sit on either end of the same problem: how leaders should be thinking about risk in an unstable world, and what it actually looks like when a sector has been living that instability for years. First up, KB sits down with Chris Krebs, former Director of the U.S. Cybersecurity and Infrastructure Security Agency (CISA). They get into the CISA cuts making headlines, why old assumptions baked into risk registers no longer hold, and the five cracks Chris sees forming in the foundation of modern risk management. He also breaks down why boards need to push vendors harder on third-party risk, and why cyber has become the opening move in every modern conflict. Then Tom Huth, Specialist in Energy Market Cyber Incident Coordination at AEMO, and Ryan McLaren, co-founder and COO of Retrospect Labs, bring it back to ground level. They unpack why the energy sector’s tight-knit supply chain has made it a genuine leader in cyber resilience, the difference between a tabletop exercise and a full functional simulation, and the trust problem nobody’s fully solved: how do you verify who’s really on the other end of the phone when your systems go down? A grounded look at what it takes to build real muscle memory before the bad day arrives.

KB is on the ground at SAP Sapphire in Orlando, where AI has officially moved beyond experimentation and into the core of enterprise decision making. In two conversations, Marielle Ehrmann (Chief Security, Compliance and Risk Officer, SAP) unpacks why AI governance has entered the boardroom as an accelerator rather than a brake, what separates responsible AI from AI theater, and why the biggest risk usually isn’t the model itself but the humans around it. Then Martin Merz (President Sovereign Cloud, SAP) explains why sovereign cloud has surged back into the conversation, the four dimensions SAP uses to define it, and why Australia’s pragmatic regulatory approach puts it among the top countries he works with globally. A grounded look at trust, governance and what it actually takes to innovate at enterprise scale. Keywords: AI governance, sovereign cloud, enterprise AI risk, digital sovereignty, responsible AI

Mark Jones is Co Founder of MosaicalAI and has spent more than 25 years working across cybersecurity, technology risk, governance and resilience in complex environments where decisions need to be defensible and the cost of getting it wrong is high. His work sits at the intersection of security, business leadership and change. He helps organisations understand risk, build capability in their people, create practical operating models, and move with confidence when technology is changing faster than traditional governance can keep up. Today, Mark’s work is focused on AI. At MosaicalAI, he helps Australian organisations rebuild how teams work for the agentic era. His view is that every team runs on three things: people, technology and data, but most teams are still operating on a model built before AI. MosaicalAI maps how a team works today, builds the agentic version beside it, then rebuilds it with them. Mark’s approach is AI native and cybersecurity driven. He does not start with tools or generic productivity use cases. He starts with the team, the workflow, the data, the controls, the risks and the decisions that matter. The goal is practical AI capability that the organisation owns, understands and can govern. Cybersecurity is MosaicalAI’s first proof point because it is where AI adoption gets real quickly. Cyber teams already understand risk, evidence, accountability, control and resilience. When they use AI to improve triage, reporting, exposure management, control mapping, evidence gathering and decision support, they are better placed to guide safe AI adoption across the broader business. Mark believes AI cannot simply be bolted onto an organisation. It needs ownership, guardrails, evidence, accountability, resilience and control from day one. He is a Certified Information Security Manager and Certified Information Systems Security Professional, combining practical executive experience with globally recognised security credentials.