Measuring the Value of SecOps; BH Interviews with Fortra, Helmet, Above, & Keeper – Christopher Crowley, Josh Davies, Kaushik Shanadi, Tricia Howard, Darren Guccione – ESW #478
Interview with Christopher Crawley - The Value of SecOps
This week, we talk to Chris Crawley about his new book, The Value of Cybersecurity Operations. Chris has been training teams on security operations for years, but found that students often struggled to justify the importance of secops training and even the need for secops in general. This book was written to more broadly arm practitioners with the information they need to communicate why security operations are necessary to leadership.The book is available in several forms: eBook, hardcover, softcover, and an audiobook read by Chris himself!You can pick all versions up here: https://shop.montance.com/collections/all and Security Weekly listeners get 50% off with code sw-50!The Evolving Exploitation of Trust with Josh Davies, Security Strategist at Fortra
Fortra Intelligence and Research Experts (FIRE) is Fortra's emergent threat intelligence identity, created to unify research teams across multiple security disciplines and share intelligence with the wider threat intelligence community. FIRE co-ordinator and security strategist Josh Davies joins us to share insights from original FIRE research like Calphishing, Mirage2FA, RatPressto phishkit and heavily obfuscated campaigns that evade defences. While also digging into trends from big data analysis within phishing, fraud, social engineering and credential theft.Segment Resources:This segment is sponsored by Fortra. Access FIRE Research here: https://securityweekly.com/fortrabhWhy Agentic AI Security Requires a Defense-In-Depth Strategy with Kaushik Shanadi, CTO and Co-Founder of Helmet Security
Many organizations are approaching agentic AI security by stitching together individual controls, assuming that identity, network, endpoint, or application security alone is enough. Each address only one part of the problem. As AI agents become more autonomous, move across systems, and take actions on behalf of users, organizations need a true defense-in-depth strategy that combines every layer of the security stack. Kaushik can discuss how each security layer provides a different piece of the puzzle and how individually, none of the controls are sufficient. But together, they create the layered governance needed to securely deploy agentic AI.For more information about Helmet Security, please visit https://securityweekly.com/helmetbhAbove Security on Why Legacy Tools Don’t Cut It for Modern Insider Risk with Tricia Howard, Head of Marketing at Above Security
As organizations rush to adopt agentic AI, agents are often given broad access to critical business systems and sensitive data. Legacy insider risk management tools weren't built for this, and organizations have spent years on insider risk posturing and investments that leave security teams inundated with false positives while the real risk slips through undetected. In this segment, Tricia Howard draws on her decade in cybersecurity, including years watching user and entity behavior analytics (UEBA) overpromise and underdeliver, to unpack why understanding human – and now AI – intent is the missing piece.Segment Resources:- Blog Post: Redefining Insider Threat
- Blog Post: What I wanted UEBA to be, Years Ago
The Identity Crisis Your Security Team Didn't See Coming: Governing AI Agents with Darren Guccione, CEO and Co-Founder of Keeper Security
AI agents outnumber human identities in enterprise environments, and traditional security software was never built to govern them. 89% of cybersecurity decision-makers recently surveyed by Keeper Security said that AI adoption has made identity management harder.In this Black Hat USA conversation with Cyber Risk TV, Darren Guccione, CEO and Co-Founder of Keeper Security, shares a practical framework for extending identity governance to non-human identities and AI agents before the access gap becomes a breach.Segment Resources:To learn more about Keeper Security, visit: https://securityweekly.com/keeperbhChristopher Crowley has spent his career transforming how defenders detect and respond to advanced threats—most recently harnessing data science and artificial intelligence to make security operations smarter and more adaptive. As a Senior Instructor at the SANS Institute, he teaches SEC511: Cybersecurity Engineering – Advanced Threat Detection and Monitoring, SEC504: Hacker Tools, Techniques, and Incident Handling, and SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals. His mission: to equip defenders with the technical depth and analytical mindset to thrive in a world where AI reshapes both attacks and defense.
Montance® LLC is a trusted independent Information Security partner providing cybersecurity assessment, and framework development services enabling clients to create a new SOC, or improve existing security operations. We are committed to enhancing your SOC capabilities to execute its mission: to provide optimum security protection for digital assets.
Montance® LLC has provided services to organizations large and small in the financial, industrial, energy, medical, and defense industries. It is a one-person consulting firm providing a vehicle for direct and efficient engagement.
Josh Davies is a Principal Market Strategist at Fortra, where he helps shape the strategic direction of the company’s security portfolio and coordinates the activities of the Fortra Intelligence and Research Experts (FIRE) team. Drawing on a career that spans frontline security operations, incident response, threat hunting, solutions architecture, and product strategy, Josh combines practitioner experience with deep market intelligence to help organizations build effective, forward-looking security strategies. He regularly analyzes emerging threats, attacker techniques, and industry trends to inform both product innovation and customer security outcomes.
He is also the co-host of The Art of Security podcast, where he explores cybersecurity challenges, trends, and best practices with industry experts, helping security professionals navigate an increasingly complex threat landscape. Having worked directly with organizations ranging from mid-market businesses to large enterprises, Josh has helped architect security strategies that align technology, risk, and business objectives. Through his podcast, speaking engagements, and research, he is a strong advocate for intelligence-sharing, collaboration, and practical security approaches that enable organizations to stay ahead of an ever-evolving threat landscape.
Kaushik Shanadi is Co-Founder and CTO of Helmet Security, where he is building scalable, agent-native security protocols for the next generation of AI systems. A security engineer with deep experience across startups and enterprise environments, he has spent his career designing secure, high-performance infrastructure and solving complex cybersecurity challenges. Prior to founding Helmet, Kaushik served as Chief Architect at Conceal, where he led the development of advanced security technologies. He is based in the Washington, D.C. area and holds a B.S. degree from the University of Florida.
Tricia Howard is an artist gone rogue who ended up in cybersecurity. With a bachelor’s degree in theater arts and interests ranging from “Star Wars” to opera, she likes to bring a bit of pizzazz into the cyber realm. She is the Head of Marketing at Above Security, an AI-native agentic managed insider threat platform built to make insider risk proactive and operational through behavioral intelligence. She has over a decade of cybersecurity experience spanning threat research, content strategy, and technical storytelling, with a particular passion for making complex security topics accessible to both technical and non-technical audiences.
Darren Guccione is an entrepreneur, technologist and business leader. He is the CEO and Co-Founder of Keeper Security, the leading zero-trust and zero-knowledge identity security and Privileged Access Management (PAM) platform, used by more than 95,000 organizations globally. Guccione is a frequent keynote speaker and panelist at global technology and cybersecurity conferences and is regularly featured in national, trade and broadcast media as a cybersecurity subject matter expert. As a visionary entrepreneur, Guccione has co-founded other successful ventures and advised industry-leading companies. Guccione holds a master’s degree from the Kellstadt Graduate School of Business at DePaul University and a Bachelor of Science in Industrial and Mechanical Engineering from the University of Illinois at Urbana-Champaign.
