
Hosted by Wil Klu · EN

AI is making penetration testers faster, but it still cannot replace the judgment needed to prove real business risk.Wil hosts Nat Shere, Product Security Manager at Skillable and a penetration tester with more than 10 years of experience, for a practical look at AI penetration testing. They break down where AI helps, where automated pentesting falls short, and why finding more vulnerabilities does not matter unless a tester can prove exploitability and impact. This episode is for CISOs, security leaders, buyers, and cybersecurity professionals trying to separate useful AI tools from expensive scanner theater.Key takeaways:• Learn how AI automates repetitive testing and supports deeper exploit research• Compare AI pentesting tools with vulnerability scanners and manual pen tests• Judge reports by evidence, repeatable steps, and business impact• Understand the privacy risks of sending customer data to public AI models• See why hallucinations, scope, and creative testing still need an expert• Explore how AI may reshape entry-level cybersecurity career pathsFollow The Keyboard Samurai and leave a review for more plain-English conversations about cyber, technology, and business.Find Nat: https://www.linkedin.com/in/nathaniel-shere/

AI can help cybersecurity teams move faster, but speed creates new questions about control, accountability, and whether humans can keep up.Wil Klusovsky, host of The Keyboard Samurai, talks with Carl Stern, VP of Information Security at Age of Learning and a cybersecurity leader with more than 25 years of experience. They discuss building cybersecurity programs in the age of AI, securing agentic AI, using automation for threat intelligence and GRC, and protecting the next generation of cyber talent. The conversation then moves beyond today’s tools into AI governance, artificial general intelligence, regulation, and the future role of human judgment.• Strengthen cybersecurity fundamentals as AI accelerates attacks• Secure AI agents through identity and access controls• Apply AI to threat intelligence, third-party risk, and compliance work• Examine how automation changes entry-level cybersecurity careers• Separate LLM capabilities from the risks of AGI• Consider why thoughtful AI regulation is moving too slowlyFollow The Keyboard Samurai for more conversations about cybersecurity, technology, business, and leadership. Leave a review and share the episode with someone thinking seriously about AI risk.Find Carl: https://www.linkedin.com/in/carlstern/

Buying a company means inheriting its cyber risk, technical debt, and every forgotten system still humming in the corner.Wil Klu, host of The Keyboard Samurai, sits down with Orville Williams, VP of Cybersecurity and Risk at Trilon Group, to explain what cybersecurity looks like during mergers and acquisitions. Drawing on his work across 14 partner firms, Orville shares how teams uncover legacy hardware, licensing gaps, shadow IT, unknown VPNs, and phishing risk while moving acquired companies toward a common security baseline. This episode is for executives, deal teams, CISOs, CIOs, and IT leaders responsible for cybersecurity due diligence or post-merger integration.You’ll hear how to:• Bring security into the M&A process earlier• Price hidden integration and remediation costs• Set a 30-to-60-day cybersecurity integration plan• Improve asset visibility and find unknown systems• Deploy practical controls such as MFA, EDR, and email security• Protect employees from phishing, impersonation, and payment fraudFollow The Keyboard Samurai for more business-first cybersecurity conversations, and share this episode with someone responsible for the next acquisition.Find Orville: https://www.linkedin.com/in/orville-williams-510986230/

Ransomware response gets a lot harder when panic, money, law enforcement, insurance, and attackers all collide.Wil hosts Kurtis Minder, author of Cyber Recon, longtime cyber operator, former CEO, and ransomware negotiator, for a grounded conversation on cyber espionage, dark web intelligence, ransomware negotiation, and personal cyber hygiene. Kurtis explains what human-led threat intelligence looks like, why negotiation is partly psychology, and how victims can make better decisions under pressure. This episode is for cyber leaders, business executives, founders, and anyone who wants to understand how cyber risk works in the real world.Key takeaways:• Learn how cyber espionage supports threat intelligence• Understand what happens during ransomware negotiation• See why response requires calm leadership, not just technical skill• Explore how attackers use supply chains and personal data• Improve your thinking around cyber hygiene and riskFind Kurtis: www.kurtisminder.comhttps://www.cyberreconbook.com/https://www.linkedin.com/in/kurtisminder/Follow The Keyboard Samurai for more conversations on cyber, tech, business, and leadership. Leave a review and share this episode with someone responsible for cyber risk or business resilience.

AI agents need governance before they get access to your business.In this episode of The Keyboard Samurai, host Wil Klu talks with Christophe Foulon about agentic AI governance, AI identity management, data governance, and the business risks created when AI agents can act inside real systems. Christophe brings 20+ years in tech and IT, with experience across Microsoft 365, Purview, cloud modernization, regulated industries, and hybrid environments.Key takeaways:• Start AI governance with intent, access, and ownership• Treat AI agents as non-human identities with real risk• Threat model agents before they touch sensitive systems• Use clearer context to reduce token spend and bad outputs• Build the business case for specialized AI tools• Connect AI productivity to security, compliance, and business outcomesFollow The Keyboard Samurai for more conversations on cyber, AI, leadership, and the business side of technology.Find Christophe on Linkedin: https://www.linkedin.com/in/christophefoulon/

AI adoption is no longer just an innovation project. It’s a business, security, and workforce transformation problem all at once.In this episode, Wil Klu sits down with Matt Sharp, CSO at Xactly and co-author of The CISO Evolution, to talk about how companies should approach AI adoption when the rules are still being written. They cover AI governance, cybersecurity risk, design partnerships, learning curves, small language models, token costs, and the growing pressure to turn AI experiments into real business outcomes.Key takeaways:• Why AI adoption requires agility, not fixed best practices• How CISOs can help secure fast-moving AI bets• Why teams need hands-on AI learning, even without production use• How token costs and prompt quality may change workforce value• Why private equity and investors are pushing AI toward measurable outcomes• How design partnerships can help security teams keep paceFollow The Keyboard Samurai for more conversations on cyber, AI, leadership, and the business side of technology.Find Matt: https://www.linkedin.com/in/ciso-mba/https://www.cisoevolution.com/His book: https://www.amazon.com/CISO-Evolution...Co authored with Rock Lambros who was also on KBS: https://open.spotify.com/episode/1hC2q4dwvLqfJ65SHqqWdr?si=3GtedE4sRy6BCXteD2Bf-A

Threat actors don’t always "break in" anymore. They log in with real credentials.Wil hosts Randall Jackson, CISO at Income Research and Management, for a clear conversation on modern cyber attacks, identity compromise, AI-powered phishing, MFA fatigue, vulnerability prioritization, and the real pressure CISOs face. Randall brings 30+ years in IT and cyber, with experience across MSPs, MSSPs, and financial services. This episode is for business leaders, CISOs, IT leaders, and anyone trying to understand how cybersecurity works in the real world now.Topics covered:• Why identity compromise changed the attack model• How AI makes phishing cleaner and harder to spot• Why once-a-year security training is not enough• How FIDO keys, MFA, PAM, and zero trust reduce risk• How CISOs prioritize vulnerabilities through business context• When outsourcing, managed security, or fractional CISO help makes senseFollow The Keyboard Samurai for more practical conversations on cyber, tech, leadership, and business risk.Find Randall: https://www.linkedin.com/in/randall-jackson-41ciso/

Cyber insurance is not a checkbox. It is risk transfer, and the details matter.Host Wil Klu talks with Will Brooks of U.Kon, formerly FifthWall, about how cyber insurance really works, why many businesses are underinsured, and how leaders should connect cybersecurity risk to financial impact. This episode is for business owners, CFOs, CISOs, CIOs, MSPs, and advisors who need to understand cyber policies without getting buried in insurance jargon.Key takeaways:• Why cyber insurance got more serious after COVID and ransomware growth• How to think about policy limits based on actual business loss• Why CISOs often understand the risk, but CFOs need the dollars• What MSPs and consultants can say without trying to sell insurance• Why add-on cyber coverage may not be enough• How comprehensive cyber insurance covers more than one type of incidentFollow The Keyboard Samurai for more plain-English conversations on cybersecurity, business risk, and technology leadership.Find Will: https://www.linkedin.com/in/wi1bo/

Manufacturing cybersecurity is not about buying every tool. It is about knowing what can hurt the business, what matters first, and how to fund the right work.In this episode of The Keyboard Samurai, host Wil Klu talks with Craig Duckworth, Director at Barry-Wehmiller Design Group, continuing conversation from from @industrialcybersecurityinsider podcast about OT cybersecurity, industrial risk, cyber insurance, business impact analysis, and security budgeting. Craig brings real-world industrial cybersecurity experience from systems integration, risk mitigation, and manufacturing environments where old assets, new connectivity, and limited budgets collide. This conversation is for manufacturing leaders, CIOs, CISOs, IT teams, OT teams, and executives who need a clearer way to protect production.Key topics covered:→ Turning OT cyber risk into business impact→ Prioritizing security spend when budget is limited→ Protecting legacy manufacturing systems→ Explaining cyber risk to leadership and boards→ Understanding cyber insurance limits→ Building a practical security roadmap→ Knowing when to use outside partnersFollow The Keyboard Samurai for more conversations on cyber, technology, leadership, and the business side of security.Wil: https://www.linkedin.com/in/wilklu/viLogics: https://www.linkedin.com/company/vilogicswww.vilogics.comCraig: https://www.linkedin.com/in/craigaduckworth/BW Design Group: https://www.linkedin.com/company/barry-wehmiller-design-group/http://www.bwdesigngroup.com/

Cars are collecting business data, and most security programs are pretending they are still just transportation.Wil Klu hosts Merry Marwig, VP of Global Communications and Advocacy at Privacy4Cars, to unpack why corporate cars, rentals, fleet vehicles, and personal vehicles used for work need to be treated like endpoints. They talk through the data stored in modern vehicles, why infotainment systems create real privacy and security risk, and how CISOs can build vehicle data deletion into policies, vendor contracts, and lifecycle processes.In this episode:• Why cars are overlooked endpoints in cybersecurity programs• What sensitive data can remain inside infotainment systems• How fleet vehicles can expose corporate and employee data• Why NIST 800-88 and certificates of deletion matter• What CISOs should require from automotive vendors• How vehicle privacy affects companies and consumersFollow The Keyboard Samurai for more plain-English conversations on cyber risk, leadership, and the business side of technology.Find Merry: https://www.linkedin.com/in/marwig/