Skip to content
Artwork for Security You Should Know
TechnologyNewsTech News

Security You Should Know

CISO Series

What if you could get a no-nonsense look at security solutions in just 15 minutes? Security You Should Know, the latest podcast from the CISO Series, does just that.

Hosted by Rich Stroffolino, each episode brings together one security vendor and two security leaders to break down a real-world problem and the solution trying to fix it. Expect straight answers on:

How to explain the issue to your CEO
What the solution actually does (and doesn't do)
How the pricing model works

Then, our security leaders ask the tough questions to see what sets this vendor apart.

Subscribe now and and stay ahead of the latest security solutions. Visit CISOseries.com for more details.

Security You Should Know: Connecting security solutions with security leaders.

Play
  • 21 episodes
  • fortnightly
  • Avg 19 min
  • English
Counted on this page — what you have heard stays on this device, so it is not something the list can be paged by.
  • Monday · 18 min

    Cloaking the Network from Discovery with AppGate

    In this episode, Leo Taddeo, CEO and President at AppGate, explains how the company's zero trust network access platform cloaks internet-facing infrastructure from discovery, uses direct-routed architecture instead of cloud-routed hairpinning to avoid the latency tax, and layers in continuous, context-aware policy checks that go beyond device posture and MFA. Joining him are Ross Young, co-host of CISO Tradecraft, and Derek Fisher, Director of the Cyber Defense and Information Assurance Program at Temple University. Want to know: Why does securing remote access remain one of the top attack vectors year after year? How does AppGate's direct-routed architecture avoid the latency and throughput limits of cloud-routed competitors? What happens to a user's access when the circumstances that justified it change, like a closed service ticket? How does cloaking network infrastructure stop an adversary's reconnaissance before it starts? What's the fallback when a controller hosted in a customer's own data center goes down? How does AppGate defend against credential replay and man-in-the-middle attacks that bypass MFA entirely? What does AppGate's per-user licensing model mean for organizations managing multiple devices and enclaves? Check out the episode for the answers you need. Huge thanks to our sponsor, AppGate AppGate secures and protects an organization's most valuable assets with its high performance Zero Trust Network Access (ZTNA) solution. AppGate ZTNA is the only direct-routed Zero Trust solution built for peak performance, superior protection and seamless interoperability. AppGate safeguards enterprises and government agencies worldwide. Learn more at appgate.com.

  • August 17 · 18 min

    Securing the AI Control Plane with Speakeasy

    In this episode, Sagar Batchu, CEO of Speakeasy, explains how the Speakeasy AI control plane lets organizations adopt AI everywhere and still prove it's governed — putting every agent, tool, and MCP server behind a single security layer that authenticates each action, enforces policy, and inspects every session for prompt injection and data exfiltration. Pressure-testing the approach are George Finney, CISO at The University of Texas System, and Nick Espinosa, host of The Deep Dive Radio Show. Want to know: Why is knowing what your AI agent can access still an unsolved problem, and how much of it traces back to the identity and data governance we never fixed for humans? Should an AI agent ever be allowed to take an action no individual can fully understand, even when it's statistically more effective than the human alternative? Where's the line between legitimate governance and surveillance, and how do you assure employees you're not building a panopticon? Are there decisions and departments that should stay permanently in human hands, off-limits to agents entirely? When an agent acts through a company's API and something goes wrong, who's actually responsible: the employee, the company, the model developer, the API provider, or the governance platform? Could a control plane have flagged the week's biggest AI incident before it escalated? Is adopting this really as simple as switching on enterprise settings and plugging in an API, whether you're an SMB or the Fortune 1? What is "cognitive surrender," and why does Speakeasy's CEO think it's the one quality companies most need to protect? Check out the episode for the answers you need. A huge thanks to our sponsor, Speakeasy. Speakeasy is the enterprise AI control plane. It governs every AI agent, tool, and MCP server from one place. Every connection is authenticated, every policy enforced, and every agentic action inspected and logged. So organizations can scale AI adoption with visibility and control. Copy for below Banner: AI usage is outgrowing your enterprise controls. Speakeasy is the AI control plane that governs every agent, assistant, and MCP server from one layer. Each connection is authenticated, each policy enforced, and every action recorded. So you stay in control as AI adoption scales."

  • August 4 · 18 min

    Proving Resilience with Gambit Security

    In this episode, Curtis Simpson, CSO at Gambit Security, explains how Gambit moves organizations past that guesswork by continuously mapping a company's minimally viable business capabilities and validating whether the infrastructure, backups, and recovery processes behind them can actually deliver within the timeframes the business requires. Joining him to pressure-test the approach are Howard Holton, former CEO of GigaOm, and Adam Palmer, CISO at First Hawaiian Bank. Want to know: Why do so many disaster recovery plans hold up on paper but fail the moment they're actually needed? What's the real difference between having something backed up and proving you can recover it? What is a "minimally viable company," and how much of mapping it is automated versus built on human input? What happens when your infrastructure fails today, versus what Gambit's roadmap has planned for tomorrow? What should actually land in front of your CEO or board to demonstrate recovery confidence? Is there an organization too small, or too mature, to get value from this kind of resilience assessment? Why does decades-old infrastructure like the mainframe often cause the longest, most damaging outages? Why is now the moment for security to finally move from a "trust but trust" model to "trust but verify" on recoverability? Check out the episode for the answers you need. Huge thanks to our sponsor, Gambit Security Gambit is the AI-native cyber resilience platform for enterprises that can't afford downtime. It continuously maps your live environment, backups, security tools, and infrastructure-as-code, then validates whether your entire stack can actually recover from disruption. Gambit gives security and infrastructure leaders proof of recoverability on demand, so the business keeps running. Balens maps, controls, and proves your recoverability across every layer of your stack - against infrastructure failures, human and AI errors, and cyber threats. One live view of your cloud, IaC, and backups that updates as your environment evolves. Agentless deployment in 15 minutes. Learn more at gambit.security

  • July 27 · 17 min

    Closing the Configuration Gap with CoreView

    In this episode, Andrea Sivieri, Chief Product and Technology Officer at CoreView, explains how CoreView secures that overlooked layer, the configuration, permissions, and structure of a Microsoft 365 tenant rather than just the data flowing through it. Joining him are Davi Ottenheimer, principal at Flying Penguin, and Will Gregorian, CISO at Galileo Medical. Want to know: Why does Microsoft's own admin console give you roughly a thousand ways to configure a single setting? What's the actual difference between securing your Microsoft 365 data and securing your Microsoft 365 configuration? How does a "virtual tenant" stop one compromised admin account from exposing your entire company? How do you stay ahead of a vendor that can change its APIs or shut off access without warning? How do you catch a change to your tenant that you had no way of seeing in the first place? How far back can you rewind a tenant's configuration history, and why does that number matter? What does managing a 2.7 million-user tenant reveal about resilience that a small business never has to think about? Check out the episode for the answers you need. A huge thanks to our sponsor, CoreView

  • July 20 · 18 min

    Securing the Open Source Supply Chain with ActiveState

    In this episode, Abby Kearns, CEO of ActiveState, explains how her company closes that gap by rebuilding open-source packages from verified sources before they ever reach a developer's pipeline, rather than scanning for problems after the fact. Joining her are Doug Mayer, vp and CISO at WCG, and Howard Holton, former CEO at GigaOM. Want to know: Why is AI increasing exploitability on both the attacker side and the developer side of the open source supply chain? How does a package catalog replace your package manager without slowing developers down or pushing them around the process? What does ActiveState do differently than upstream scanning tools like JFrog Artifactory or Sonatype Nexus? What happens when a developer needs a package that isn't in the catalog yet? How is ActiveState thinking about shadow AI and SBOM coverage beyond language libraries? What upcoming regulatory deadlines, like the EU Cyber Resilience Act, should security teams have on their radar? What happens to open source security when AI produces more CVEs and patches than the maintainers behind these projects can process? Huge thanks to our sponsor, ActiveState ActiveState gives security and engineering teams a single governed source for open source software. With 79 million components built from source, continuously remediated, and delivered directly into the tools teams already use, ActiveState eliminates the CVE backlog and the developer toil that comes with it. Companies see a 60 to 99% reduction in CVEs and reclaim up to 30% of developer time. Curate a private, vetted repository of open source components from the ActiveState Library that developers use safely without scouring the internet. A Curated Catalog provides your security team total control over what enters their environments while giving engineering teams a fast, secure way to build, onboard, and start new projects.

  • June 15 · 23 min

    Elevating the SOC with Prophet Security

    In this episode, Grant Oviatt, vp of product and co-founder at Prophet Security, explains how his platform deploys AI agents to investigate and respond to alerts the way a skilled analyst would, using REST API integrations across existing security tools rather than absorbing all your data into another SIEM. Joining him are Will Gregorian, CISO at Galileo Medical, and Howard Holton, CEO at GigaOm. Want to know: Why are AI-powered SOC tools adding to analyst frustration rather than reducing it? When an AI agent makes a bad call on an investigation, who actually owns that failure? How does Prophet Security's audit trail let you trace every query, piece of evidence, and reasoning step an agent used? Why is Prophet Security using frontier models rather than training its own, and how does security-specific context change the outcome? What does giving an AI agent remediation authority look like in practice, and where does Prophet Security draw the line? How long does it realistically take to go from contract to running Prophet Security against live alerts? Check out the episode for the answers you need. Huge thanks to our episode sponser, Prophet Security Prophet AI is an Agentic AI SOC Platform that investigates and responds with context, shows its reasoning, and elevates every part of your SOC. Prophet AI SOC Analyst investigates and responds to alerts in minutes; Threat Hunter streamlines threat hunts with a natural language interface; and Detection Advisor provides insights on detection quality and coverage.

  • June 8 · 20 min

    Securing AI Agents with CompFly AI

    In this episode, Venkat Siva, co-founder and CEO at CompFly AI, explains how his platform gives security, engineering, and business teams a control plane for autonomous AI agents across their full lifecycle. CompFly discovers agents, assigns each one a verifiable distributed identity, runs adversarial and safety simulations before launch, enforces deterministic policies at runtime through a gateway, and produces immutable audit logs for compliance teams after the fact. Joining him are Mike Lockhart, CISO at EagleView, and Gary Chan, System VP and CISO at SSM Health. Huge thank you to our sponsor, CompFly AI CompFly is the control plane for the agentic enterprise. We make autonomous AI agents governable at scale discovering them, evaluating their risk, and enforcing real-time guardrails before execution. Enterprises deploy CompFly to move agents from sandbox to production with the evidence trail their boards/management require.

  • June 1 · 22 min

    Automating Offensive Security with XBOW

    In this episode, Nico Waisman, CISO at XBOW, explains how XBOW uses autonomous AI agents to run continuous, incremental penetration testing without triggering false-positive avalanches or taking down production systems. Joining him are Jacob Combs, CISO at Tandem Diabetes Care, and Davi Ottenheimer, president at Flying Penguin. Want to know: Why can't traditional pen tests keep up with modern attack surfaces? How XBOW's attack credit model maps to the way security teams already size testing effort? What stops an autonomous pen testing agent from causing real damage in production? How incremental testing works when a new pull request changes the application? Where XBOW is headed on prompt injection and LLM-specific vulnerabilities? How you audit what the AI actually did during an assessment? What novel vulnerability chains are emerging as AI reasoning models get more capable? Check out the episode for the answers you need. Huge thanks to our sponsor, XBOW

  • May 18 · 17 min

    Rethinking Tabletops with Reflex Security

    In this episode, Cassio Goldschmidt, co-founder and CTO at Reflex Security, explains how Reflex replaces static, script-driven tabletops with adaptive AI-driven simulations that fight back, measure real human behavior under pressure, and surface the gaps that scripted exercises never reach. Joining him are Nick Espinosa, host of the nationally syndicated Deep Dive Radio Show, and Jay Wilson, CISO and CIO at Insurity. Want to know: Why do traditional tabletops train teams to know the plan rather than execute under pressure? What's the difference between a team that panics and a team that chokes, and why does it matter? How does Reflex use AI agents to adapt the simulation based on what the team actually does? Can you run separate tabletops for technical, legal, and executive audiences without multiplying the workload? Is there a risk that security leaders optimize for the AI's score rather than genuine preparedness? How does an AI agent joining a video conference change the way a tabletop runs? How hard should training be relative to the real thing? Check out the episode for the answers you need. Huge thanks to our sponsor, Reflex Security Most tabletop exercises are static, predictable, and easy to pass. Reflex Security built the first tabletop that fights back, throwing teams into dynamic simulations against intelligent AI adversaries that adapt to your every move. With Reflex, your team can move from checkbox exercises to real crisis readiness.

  • May 11 · 16 min

    Securing Mobile Apps with Guardsquare

    In this episode, Ryan Lloyd, Chief Product Officer at Guardsquare, explains how the platform combines code obfuscation, runtime integrity checks, and real-time threat monitoring to secure mobile apps at the binary level, integrated directly into the CI/CD pipeline. Joining him are TC Niedzialkowski, Head of IT & Security at Opendoor, and Montez Fitzpatrick, CISO at Navvis. Want to know: Why does organizational apathy around mobile app security persist even as mobile becomes the primary customer channel? What's the difference between app integrity and code integrity, and why does it matter for defending against repackaging attacks? How does obfuscation function as a real security control rather than just security through obscurity? How does Guardsquare fit into the CI/CD pipeline, and what does the actual build overhead look like for development teams? What API and webhook capabilities exist for routing threat monitoring data into your existing security stack? How does Guardsquare's mobile app attestation model bind server-side APIs to verified legitimate app instances — and why does that matter for stopping bots and credential theft? Huge thanks to our sponsor, Guardsquare Guardsquare delivers mobile app security without compromise, providing advanced protections for both Android and iOS apps. From app security testing to code hardening to real-time visibility into the threat landscape, Guardsquare solutions provide enhanced mobile application security from early in the development process through publication. Learn more about how to protect your app at Guardsquare.com.

  • May 4 · 19 min

    Verifying Identities with Trusona

    In this episode, Ori Eisen, founder and CEO at Trusona, makes a case for getting out of the AI detection arms race entirely. He argues that trying to catch AI-generated fakes with AI detection is the antivirus playbook, and we know how that ends. Trusona instead anchors verification to authoritative sources, DMV records and physical-world signals, things AI can mimic on screen but can't actually own. No pre-registered devices required. And it works in both directions: attackers calling your help desk, and attackers calling your employees while pretending to be IT. Joining him are Eduardo Ortiz, VP and Global Head of Cybersecurity at Techtronic Industries, and Mandy Huth, SVP and CISO at Ultra Clean Technology. Want to know: Why do MFA and SSO still leave gaps attackers walk right through? How Trusona verifies identity with no pre-registered devices or tokens? Why building AI detection on top of AI fakes is a losing strategy? How is a false rejection rate of zero achievable without locking out real employees? What deployment actually looks like, and how fast you can be live? Which departments beyond IT need identity verification, and where do you start? How to measure the business value of this beyond just counting blocked account takeovers? Why is a solid help desk protocol still not enough on its own? Huge thanks to our sponsor, Trusona GenAI supercharges identity impersonation and social engineering attacks – rendering legacy identity verification methods obsolete, especially in high-risk workflows like IT Help Desk password/MFA resets, vendor payment changes, remote employee hiring, or customer account access. Trusona ATO Protect empowers your team to thwart these attacks across business units and channels. GenAI supercharges identity impersonation and social engineering. It's rapidly eroding traditional authentication, especially in high-risk workflows like help desk password or MFA resets, vendor payment changes, remote employee hiring, and customer account access. Trusona's ATO Protect addresses deepfakes and social engineering directly—without adding friction or relying on legacy MFA.

  • March 16 · 17 min

    Transitioning to Quantum-Safe Encryption with enQase

    All links and images can be found on CISO Series. In this episode, Raj Patil, CTO at enQase, explains how enQase's full-stack platform helps enterprises implement quantum-safe security through a structured, integrated approach. This covers everything from cryptographic asset discovery and governance to out-of-band key generation for network appliances, without requiring organizations to rip and replace existing infrastructure. Joining him are Ross Young, co-host at CISO Tradecraft, and Adam Palmer, CISO at First Hawaiian Bank. Want to know: Why is the post-quantum cryptography transition harder than simply implementing new standards? What three factors should frame every CEO conversation about quantum risk? Where should a highly regulated enterprise start, and what can reasonably wait three to five years? Why should we be planning for "harvest now, decrypt later" attacks right now? How do you build and track a cryptographic bill of materials across hundreds of applications and devices? Why is crypto agility more important than picking the perfect algorithm? Huge thanks to our sponsor, enQase The enQase Platform empowers enterprises, defense organizations, cloud providers, and critical infrastructure operators to seamlessly adopt quantum-safe technologies while achieving crypto agility across their ecosystems. By combining quantum-grade hardware with software-defined control and interoperability, enQase ensures alignment with NIST standards, delivers unmatched flexibility and compliance readiness, and reduces risk across data, network, and compute layers, all while maintaining business continuity and operational resilience in an evolving cryptographic landscape. Learn more at enqase.com.

  • February 9 · 21 min

    Operationalizing Threat Intelligence with Recorded Future

    All links and images can be found on CISO Series. In this episode, Jamie Zajac, Chief Product Officer at Recorded Future, explains how autonomous threat operations can close this gap by automatically deploying intelligence across security controls at machine speed. Joining him are Dan Holden, CISO at Commerce, and Arvin Bansal, CISO at C&S Wholesale Grocers. Want to know: Why do organizations still struggle to operationalize threat intelligence despite massive investments? How does threat intelligence translate into board-level metrics that demonstrate business impact? What do autonomous threat operations mean and how do they differ from traditional threat intelligence? How can intelligence drive faster incident response and more efficient SOC operations? Why third-party risk intelligence matters more than vendor questionnaire scores? How AI is changing the threat landscape and what defenders should prioritize? What does the future of threat intelligence look like in two years? How to use intelligence for policy decisions and budget building, not just tactical blocking? A huge thanks to our sponsor, Recorded Future Recorded Future is the world's largest threat intelligence company, serving 1,900+ organizations across 80 countries. Its Intelligence Graph® contains 200+ billion nodes of threat data, combining AI analytics with autonomous capabilities to transform manual threat intelligence into automated Intelligence Operations across security ecosystems. Recorded Future was acquired by Mastercard (NYSE: MA) in 2024. Learn more at https://pages.recordedfutureext.com/

  • February 2 · 21 min

    Getting Visibility into AI Usage with Harmonic Security

    All links and images can be found on CISO Series. In this episode, Alastair Paterson, CEO and co-founder at Harmonic Security, explains how Harmonic Protect addresses these challenges by securing workforce AI adoption through browser-based visibility, endpoint agents, and MCP gateways. Joining him are Ross Young, co-host at CISO Tradecraft, and Johna Till Johnson, CEO and founder at Nemertes. Want to know: Why are enterprises still struggling with AI governance despite years of motivation to solve it? How does Harmonic keep pace with 50,000+ AI products when the landscape changes monthly? What's the difference between visibility, coaching, and blocking in AI governance? How do you implement AI controls without creating thousands of new alerts for security teams? Where does Harmonic fit in the multi-step process of setting policy, monitoring compliance, and enforcement? How can CISOs measure the ROI of AI governance tools and benchmark against industry peers? What's Harmonic's strategy with secure AI browsers? Why should AI browsers be blocked by default in the enterprise? What should CISOs prioritize for AI security in 2026? Huge thanks to our sponsor, Harmonic Security As every employee adopts AI in their work, organizations need control and visibility. Harmonic Security delivers AI Governance and Control, the intelligent control layer that secures and enables the AI-First workforce. By understanding user intent and data context in real time, Harmonic gives security leaders all they need to help their companies innovate at pace. Learn more at www.harmonic.security.

  • January 26 · 21 min

    Unifying Detection and Response with Athena Security

    In this episode, Peter Worth, founder, president, and CEO at Athena Security, explains how their security operations platform addresses these challenges through unified detection and response. Joining him are Jason Taule, CISO at Luminous Health, and Will Gregorian, head of security at Galileo Medical. Want to know: Why are security teams still struggling with alert fatigue despite decades of awareness? How does security product fragmentation create blind spots in enterprise defense? What's the difference between indicators of compromise and indicators of attack? How do AI anomaly detection systems avoid declaring malicious activity "normal"? What strategies prevent model drift and adversarial poisoning in AI-based threat detection? Why does each client need their own behavioral baseline model? How do open source foundations impact enterprise security platform reliability? Why are CISOs increasingly held personally accountable for security incidents? Huge thanks to our episode sponsor, Athena Security Group Athena Security Group delivers a best in class, AI enabled, Cyber Defense solution (SIEM, EDR, XDR & MDR) on top of Wazuh's award winning open-source SIEM/EDR platform, synthesizing and consolidating cyber security alert management and response across the entire security operations landscape, facilitating intelligent and efficient cybersecurity decision making and response for the modern enterprise, table stakes in the age of AI.

  • January 12 · 17 min

    Bridging the Cloud Security Gap with Trend Micro

    In this episode, Franz Fiorim, field CTO at Trend Micro, explains how Trend Vision One consolidates multiple cloud security tools across AWS, GCP, Azure, Oracle Cloud, and Alibaba Cloud to streamline management, automate controls, and reduce integration overhead. Joining him are Nick Espinosa, host of the Deep Dive Radio Show, and Jason Shockey, CSO at Cenlar FSB. Want to know: Why do organizations still struggle with cloud visibility despite years of cloud adoption? How does Trend Micro reconcile security visibility with privacy laws across different jurisdictions? What security frameworks does Trend Micro use to measure and define acceptable risk? How does cyber risk quantification tie technical security metrics to business impact analysis? What questions help determine the financial impact of potential security incidents? How long does implementation take for fully cloud versus hybrid environments? What safeguards prevent overdependence on a single security vendor? Where does Trend Micro draw the line between automated decision-making and human oversight? How does Trend Micro protect AI infrastructure and prevent sensitive data exposure in prompts? Huge thanks to our sponsor, Trend Micro Cloud risk never sleeps. That's why there's Trend Vision One™ Cloud Security. Gain comprehensive visibility and control over your multi-cloud and hybrid environments. Streamline compliance, manage risks proactively, and enhance operational efficiency with real-time risk assessments, automated vulnerability management, and centralized dashboards. Ensure robust protection and peace of mind for your cloud assets with the trusted leader in CNAPP.

  • January 5 · 16 min

    Stopping Lateral Movement with Zero Networks

    All links and images can be found on CISO Series. In this episode, Benny Lakunishok, co-founder and CEO at Zero Networks, explains how their automated approach to microsegmentation addresses these challenges by putting a network bubble around every asset, from clients and servers to OT devices and cloud resources, without requiring agents or breaking existing environments. Joining him are Shaun Marion, vp and CSO at Xcel Energy, and Doug Mayer, vp and CSO at WCG. Want to know: Why does complexity make lateral movement such a persistent problem despite years of awareness? How can microsegmentation be deployed at scale without becoming a massive science project? How does Zero Networks handle MFA and privileged access management across all asset types? What happens if there's already a threat living in your environment during the learning phase? How to segment OT environments that use different protocols beyond standard IT systems? Can automated learning really create accurate policies without extensive human intervention? How does network segmentation fit into AI capabilities and hybrid cloud strategies? What's the real-world experience of customers who've deployed automated microsegmentation? Huge thanks to our sponsor, Zero Networks Zero Networks enables organizations to dynamically microsegment 90%+ of their networks in 90 days. The result? A self-defending, resilient network where defenders act with confidence, auditors gain clear assurance, and business operations continue uninterrupted. Step into the Era of the Defender with Zero – get a demo HERE.

  • Dec 1, 2025 · 19 min

    Verifying Identity with Incode Technologies

    All links and images can be found on CISO Series. Traditional identity systems authenticate credentials and devices, but they can't verify who's actually behind them. Attackers use AI-generated IDs and deepfake videos to pass background checks, then clone voices to reset MFAs at the help desk. Identity has become the primary attack surface, and existing IAM platforms still trust the human layer far too easily. In this episode, Fernanda Sottil, Senior Director of Strategy at Incode Technologies, explains how their solution adds a real-world identity layer that integrates seamlessly with existing IAM systems. Joining her are Nick Espinosa, host of the Deep Dive radio show and Bozidar Spirovski, CISO at Blue Dot. Questions answered on the show: How does Incode comply with GDPR when training AI models on employee facial data? What happens when legitimate users get blocked, especially job candidates? How does Incode maintain accuracy across 4,600 document types in 200 countries? Can organizations see error rates and override the system when needed? How quickly can Incode patch new attack vectors as adversarial threats evolve? Huge thanks to our sponsor, Incode Technologies Incode Workforce helps enterprises stop deepfakes, prevent fraud, and secure every identity moment. By matching an ID to a selfie with AI-powered biometrics, Incode confirms the real person behind each IAM interaction, safeguarding onboarding, access, and recovery with frictionless verification that ensures workforce security and trust at scale.

  • Nov 17, 2025 · 15 min

    Securing Application Delivery with Island

    All links and images can be found on CISO Series. Modern application security has become a tangled mess of VPNs, proxies, DLP, CASBs, and remote browser tools—all creating friction for users and security teams alike. The root issue? Browsers were built for consumers, not enterprise security, forcing organizations to pile on complexity that undermines both protection and performance. In this episode, Braden Rogers, chief customer officer at Island, explains how their enterprise browser platform rethinks application delivery by building security services natively into the browsing experience. Joining him are Nick Ryan, former CISO, and Janet Heins, CISO at ChenMed. Want to know: How do you explain this approach to your CEO in plain English? What's the real architecture difference between enterprise browsers and traditional VDI? How do you deploy a new browser to 20,000 users without change management chaos? What happens to your existing security stack when you add an enterprise browser? Can users access personal apps while keeping corporate data protected? What's the offline experience when cloud services fail? How does this handle the surge of AI tools in your organization? What's the difference between browser enforcement and a full enterprise browser? How do you apply different security controls without overwhelming users? What does vendor support actually look like from pilot to production? Huge thanks to our episode sponsor, Island What if you no longer had to bolt agents, proxies, and gateways onto browsers? Island, the Enterprise Browser, embeds core security, IT, and productivity into the workspace. Intelligent boundaries keep data where it belongs. Orgs have full visibility into all work. And users enjoy a fast, smooth, and productive experience. Learn more at Island.io

Showing 1–20 of 21 episodes