Measuring the Value of SecOps; BH Interviews with Fortra, Helmet, Above, & Keeper - Christopher Crowley, Josh Davies, Kaushik Shanadi, Tricia Howard, Darren Guccione - ESW #478

Measuring the Value of SecOps; BH Interviews with Fortra, Helmet, Above, & Keeper - Christopher Crowley, Josh Davies, Kaushik Shanadi, Tricia Howard, Darren Guccione - ESW #478

Author: Security Weekly Productions September 28, 2026 Duration: 1:37:49

Interview with Christopher Crawley - The Value of SecOps

This week, we talk to Chris Crawley about his new book, The Value of Cybersecurity Operations. Chris has been training teams on security operations for years, but found that students often struggled to justify the importance of secops training and even the need for secops in general. This book was written to more broadly arm practitioners with the information they need to communicate why security operations are necessary to leadership.

The book is available in several forms: eBook, hardcover, softcover, and an audiobook read by Chris himself!

You can pick all versions up here: https://shop.montance.com/collections/all and Security Weekly listeners get 50% off with code sw-50!

The Evolving Exploitation of Trust with Josh Davies, Security Strategist at Fortra

Fortra Intelligence and Research Experts (FIRE) is Fortra's emergent threat intelligence identity, created to unify research teams across multiple security disciplines and share intelligence with the wider threat intelligence community. FIRE co-ordinator and security strategist Josh Davies joins us to share insights from original FIRE research like Calphishing, Mirage2FA, RatPressto phishkit and heavily obfuscated campaigns that evade defences. While also digging into trends from big data analysis within phishing, fraud, social engineering and credential theft.

Segment Resources:

This segment is sponsored by Fortra. Access FIRE Research here: https://securityweekly.com/fortrabh

Why Agentic AI Security Requires a Defense-In-Depth Strategy with Kaushik Shanadi, CTO and Co-Founder of Helmet Security

Many organizations are approaching agentic AI security by stitching together individual controls, assuming that identity, network, endpoint, or application security alone is enough. Each address only one part of the problem. As AI agents become more autonomous, move across systems, and take actions on behalf of users, organizations need a true defense-in-depth strategy that combines every layer of the security stack. Kaushik can discuss how each security layer provides a different piece of the puzzle and how individually, none of the controls are sufficient. But together, they create the layered governance needed to securely deploy agentic AI.

For more information about Helmet Security, please visit https://securityweekly.com/helmetbh

Above Security on Why Legacy Tools Don't Cut It for Modern Insider Risk with Tricia Howard, Head of Marketing at Above Security

As organizations rush to adopt agentic AI, agents are often given broad access to critical business systems and sensitive data. Legacy insider risk management tools weren't built for this, and organizations have spent years on insider risk posturing and investments that leave security teams inundated with false positives while the real risk slips through undetected. In this segment, Tricia Howard draws on her decade in cybersecurity, including years watching user and entity behavior analytics (UEBA) overpromise and underdeliver, to unpack why understanding human – and now AI – intent is the missing piece.

Segment Resources:

To learn more about Above Security and insider risk management in the era of agentic AI, visit: https://securityweekly.com/abovebh

The Identity Crisis Your Security Team Didn't See Coming: Governing AI Agents with Darren Guccione, CEO and Co-Founder of Keeper Security

AI agents outnumber human identities in enterprise environments, and traditional security software was never built to govern them. 89% of cybersecurity decision-makers recently surveyed by Keeper Security said that AI adoption has made identity management harder.

In this Black Hat USA conversation with Cyber Risk TV, Darren Guccione, CEO and Co-Founder of Keeper Security, shares a practical framework for extending identity governance to non-human identities and AI agents before the access gap becomes a breach.

Segment Resources:

To learn more about Keeper Security, visit: https://securityweekly.com/keeperbh

Show Notes: https://securityweekly.com/esw-478


Hosted by Adrian Sanabria, Enterprise Security Weekly (Video) is a deep dive into the complex world of protecting large organizations. This isn't just a headline recap; it's a practical, analyst-level discussion for security professionals who need to understand the "why" behind the news. Each episode from Security Weekly Productions brings together a seasoned panel including co-hosts like Katie Teitler-Santullo, Ayman Elsawah, Jason Wood, Jackie McGuire, and Sean Metcalf to dissect emerging threats, architectural shifts, and the tools that promise to help. You'll hear candid evaluations as they put security vendors and their claims under the microscope, separating hype from genuine utility. The conversation revolves around actionable intelligence and strategic trends that empower defenders to build more resilient environments. Tuning into this podcast provides a consistent, informed perspective that cuts through the noise of the daily alert cycle, offering clarity and context that's often hard to find. It’s a video format that adds a layer of connection and detail to these technical discussions, making complex topics more accessible. If your work involves making critical decisions about enterprise security posture, this series serves as a vital resource for staying informed and ahead of the curve.
Author: Language: English Episodes: 50

Enterprise Security Weekly (Video)
Podcast Episodes