AI Security Brief

AI Security Brief

AI Security Brief unpacks how AI is reshaping cybersecurity, from emerging attack techniques to zero-day research and real-world adversary activity. Powered by TrendAI threat intel and featuring conversations with international law enforcement, AI policy leaders, and security leaders, each episode delivers one insight worth bringing back to your team. Hosted by AI security practitioners Johnny Hand and Dustin Childs.

Trailer

Recent Episodes

Ep 11 | 9.10.26

Is a closed or an open AI model more trustworthy?

There's no silver bullet when it comes to AI security strategy, and treating one model, tool, or vendor as the answer can limit an organization’s ability to adapt. Morgan Adamski, who leads PwC’s Cyber, Data & Technology Risk practice, joins us to tackle two pressing questions: How should organizations choose between closed frontier models and open-weight alternatives? And how can they build a multi-model architecture flexible enough to keep pace as AI technology rapidly evolves? Drawing on her work with boards, CISOs, and security teams, Morgan cuts through the “paralysis by analysis” surrounding these questions and offers security leaders a practical path forward.

TranscriptTranscript
Ep 10 | 8.27.26

What does hospital downtime teach us about building AI-native organizations?

Is your organization truly AI native, or did you just bolt AI onto existing infrastructure? Your answer could be an indicator to how much risk you’re carrying without realizing it. Zach Evans, Chief Technology Officer at Xsolis, has a simple test for telling the difference: strip out the AI and see if your process still works. If it does, you may be exposing your organization to security blind spots and workflows that quietly erode organizational knowledge and skills. Zach joins Johnny Hand and Dustin Childs to unpack what it actually takes to build an AI-native organization, and why the stakes of getting agentic AI wrong can be unforgiving for every organization, not just those in healthcare.

TranscriptTranscript
Ep 9 | 8.13.26

What do AI-driven ‘bank heist’ attacks mean for defenders?

Attackers aren't just using AI to steal data; they're using it to fight back while you investigate them in real time. And once an adversary is inside, why would they ever want to leave? That's the unsettling reality Tom Kellermann, VP of AI Security and Threat Research at TrendAI, lays out in this episode. And the numbers prove it. According to a 2026 TrendAI survey of 46 financial-sector CISOs, more than 60% of respondents experienced counter-incident response, where adversaries actively disrupt live investigations. In addition, nearly 90% of these leaders reported more AI-enabled attacks year over year. Tom joins Johnny Hand and Dustin Childs to explain why the threats that hit banks first tend to hit everyone else next, and what defenders can do about it.

TranscriptTranscript
Ep 8 | 7.30.26

Is AI security actually a physical problem?

While AI might seem abstract, something that lives in "the cloud" is concrete. The AI applications we use every day run on GPUs in physical buildings, and Mark Houpt secures them. As Chief Information Security Officer at DataBank, he's watched those data centers go from anonymous warehouses to national security targets almost overnight. Mark joins hosts Johnny Hand and Dustin Childs to make the case that the AI era is, at its core, a physical security problem, and why the security fundamentals you already know still work, even when applied to threats that didn't exist two years ago.

TranscriptTranscript
Ep 7 | 7.16.26

Who governs your AI agents?

Your team spent a decade maturing privileged access management. Then AI agents arrived and they don’t log in like humans. Now your biggest insider threat is an AI agent that lacks the access it needs, and then it goes to get it. In this episode Sundari Parekh, VP of AI Security and Cyber Risk Advisory for TrendAI™, addresses a hard truth: PAM was never fully solved, and non-human identity and agentic AI are amplifying the gap. Her fix: stop building a separate AI team, upend your identity thinking, and shift from gatekeeping AI adoption to safely enabling it.

TranscriptTranscript
Load More
AI Security Brief
Host(s)
Dustin Childs
Johnny Hand
Dustin C. Childs is a part of TrendAI™ Zero Day Initiative™ (ZDI), which is the world's largest vendor-agnostic bug bounty program. Dustin began his infosec journey in the late 1990s at the Air Force Information Warfare Center. Following his time working for the government, Mr. Childs worked in the Microsoft Trustworthy Computing group, where he served as a case manager in the Microsoft Security Response Center (MSRC) with a focus on addressing vulnerabilities in the Windows operating system and in Microsoft's developer tools. In his current role, Mr. Childs gathers and analyzes threat intelligence from various TrendAI and open-source resources to understand and communicate risk to enterprises. He also creates, implements, and oversees internal and external communications programs that promote the work of the TrendAI™ ZDI and its researchers. He has spoken at multiple conferences including Black Hat USA, ThotCon, BlueHat, B-Sides, and multiple ISSA events.
Johnny Hand is a seasoned cybersecurity leader with over 20 years of experience translating intricate technical concepts into business-critical operations. He is the global CISO at TrendAI™, where he spearheads the integration of artificial intelligence for enhanced security and operational efficiency. His background in securing critical infrastructure includes leading information security and technology operations for an international academic institution and overseeing communication and defensive cyber operations for specialized units within the U.S. Navy. His focus remains on building resilient security strategies that adapt to the evolving technology landscape.
Schedule: Biweekly
Creator: TrendAI
TrendAI