435 episodes
Episode 382 Deep Dive: Quinton Anderson | Trust the System, Not the Agent – Zero Trust for the Agentic Enterprise
26/08/2026 | 49 mins.KB sits down with Quinton Anderson, founder of Aigentsphere, to challenge one of the most repeated lines in AI governance: that a human in the loop keeps you safe. His view is that asking people to approve task after task just trains them to say yes.
They get into why you should never trust an agent but can trust the system around it, why an agent can’t be fully tested before it goes live, and why the brakes are what let you go fast. A sharp look at what it actually takes to govern agents at scale.
About Quinton:
Quinton Anderson brings decades of experience in enterprise technology, risk management, and AI strategy. With a background spanning financial services, defense, and telecommunications, he founded Aigentsphere to solve the governance gap that emerges when organisations deploy AI agents at scale. He is passionate about building systems that make AI safe, accountable, and effective.
Keywords: agentic AI, AI governance, human in the loop, human oversight, zero trust for agents, sociotechnical systems, continuous compliance, board accountability, AI safety, enterprise AI, Quinton Anderson, Aigentsphere, KBKastEpisode 381 Deep Dive: Gijo Varghese | When a Cyber Attack Becomes a Public Safety Failure
19/08/2026 | 47 mins.Karissa Breen sits down with Gijo Varghese, Chief Security Officer at OT cyber security firm Secolve, to unpack an uncomfortable trade-off: the same connectivity and AI making power, water and transport smarter are also making them easier to break. Gijo explains how IT and OT convergence has widened the attack surface, why decades-old control systems were never built to touch the internet, and how a single IT intrusion can spill into the physical world. He walks through the incidents that prove it, from the 2015 Ukraine grid attack to Colonial Pipeline, where operators went to run the system by hand and found the people who knew how had all retired, to the Jaguar Land Rover breach that rippled through 5,000 suppliers and cost the UK economy billions. The throughline for boards and executives: a cyber incident stops being a security event the moment it becomes a public safety failure. Gijo makes the case for the kill switch, tested manual fallbacks, and treating resilience rather than compliance as the real measure of readiness.
About Gijo:
Gijo Varghese is a cyber security veteran, critical infrastructure defender, and the Chief Security Officer of Secolve. His passion in life is to protect the systems society depends on – power grids, transport networks, and biomedical health systems – keeping people, communities, and businesses safe from cyberattacks. With over 25 years of experience across IT and OT security, Gijo has spent his career at the frontline of Australia’s most essential industries, most recently leading cyber resilience at Endeavour Energy for six years, with prior roles at Transport for NSW, SA Health, CyberCX and Wipro Consulting.
Secolve is Australia’s leading OT cybersecurity firm, providing cyber advisory, offensive security, and training services to mines, factories, hospitals, transport networks, and energy ecosystems. As Secolve’s first CSO, Gijo leads the firm’s consultancy and professional services team, transforming complex OT cyber risks into practical action across executive, engineering, and operational teams.
Keywords: critical infrastructure security, OT security, IT/OT convergence, SCADA, ICS, cyber resilience, kill switch, Colonial Pipeline, Jaguar Land Rover, SOCI Act, CI45, incident response, operational technology, AI cybersecurity, public safety, board governance, cyber warfare, business continuityEpisode 380 Deep Dive: Mark Thomas | Owning a Policy PDF Doesn't Mean You Govern Your AI
12/08/2026 | 47 mins.In this episode, KB sits down with Mark Thomas, IT governance and risk veteran, ISACA Hall of Famer and president of Escoute Consulting, to pull apart a problem a lot of boards haven’t clocked yet – the gap between owning an AI policy and being able to prove it controls anything.
They get into the Air Canada chatbot case and what it says about accountability, why the honest board test is “would anyone notice if this was violated,” and how the risk changes once agents move from recommending to executing. Mark makes the case that human in the loop only counts when the human has the expertise, the authority and the time to say no. He also explains why only a small fraction of organisations have ever tested their ability to shut a system down, and why accountability never transfers to the vendor.
A practical, occasionally uncomfortable conversation for anyone putting AI into production.
——
About Mark:
Mark Thomas is a globally recognised expert in governance, risk management, and digital trust, with more than two decades of experience advising organisations operating in complex, regulated, and rapidly evolving environments. His work sits at a critical intersection where strategy, governance, and execution meet.
He works directly with boards and executive leadership to:
Strengthen oversight and accountability
Improve confidence in decision-making
Navigate emerging technologies and digital risk
Align governance with real-world execution
Mark is known for his ability to translate complex issues into clear, practical insight, helping leaders move from uncertainty to informed, defensible decisions.
Keywords: AI governance, AI risk, board accountability, agentic AI, human in the loop, kill switch, digital trust, AI policy, ISACA, Mark Thomas, Escoute Consulting, KBKast, enterprise AI, AI compliance, EU AI Act, shadow AI, Air Canada chatbotEpisode 379 Deep Dive: Sean Duca | Confidence Is Not Permission - Rethinking Authority in the Autonomous SOC
05/08/2026 | 42 mins.Most security vendors are shipping AI that treats capability as authority. Sean Duca thinks that’s the mistake customers are already paying for. Back on KBKast for a third time, now as co-founder and CEO of getsoteria.ai, Sean makes the case that confidence and permission are two separate gates, and that an autonomous SOC needs both before it touches anything.
He walks Karissa through governed autonomy: the machine acts on its own, but only inside a boundary it can’t set or cross. A bank teller and a self-driving car do the heavy lifting on the difference between a human in the loop, on the loop, and off it entirely. He gets specific about shadow mode, the 85% agreement bar his threat hunters have to keep clearing, and why his system fails closed and hands everything back to a person the moment it hits a wall.
About Sean:
Sean Duca has spent 25+ years in cybersecurity, most of it advising boards and security leaders across Asia Pacific. He’s now co-founder and CEO of getsoteria.ai, following senior roles as CTO for Customer Experience at Cisco (APJC), VP and Regional Chief Security Officer at Palo Alto Networks (APJ), and CTO for APAC at Intel Security. He’s a published author on cybersecurity and calls Singapore home.
Keywords: autonomous SOC, AI governance, governed autonomy, agentic AI security, confidence vs permission, human in the loop, AI access control, SOC automation, shadow mode, security operations, AI authority model, CISO, board risk, Sean Duca, getsoteria.ai, KBKastEpisode 378 Deep Dive: Harman Kaur | Automation Isn't Transformation - From Intent to Outcome in Autonomous IT
29/07/2026 | 39 mins.The old security math is broken. Teams used to get roughly 60 days between a vulnerability going public and attackers using it. Harman Kaur, Tanium’s CTO, explains why that number has flipped to negative, and what it means when the patch you need does not exist yet.
This conversation is about the difference between automation and transformation. Running the same broken process faster is not progress. Harman makes the case for rebuilding security from first principles: changing org charts, retiring tools people have relied on for years, and moving humans out of triage and into judgment.
She also gets specific about trust. In her view, trust now sits in the underlying data, because a confident AI acting on stale or incomplete data becomes dangerous at scale. Harman & KB get into the boardroom scramble around Mythos, why there is no single tool that solves it, and why the vendors closest to the data will be the ones left standing.
About Harman:
As Chief Technology Officer, Harman Kaur leads Tanium’s technology strategy, product management, AI and automation roadmap, and strategic technology partnerships.
Harman brings more than a decade of combined experience across the United States Air Force and Tanium. She continues to serve as a Cyber Officer in the U.S. Air Force. At Tanium, Harman has held senior roles across the customer organization, R&D, and most recently led the company’s AI and Autonomous Endpoint Management strategy as head of AI before stepping into the CTO role. Harman received an MBA from the University of Southern California and a BS in Information Systems from Hawaii Pacific University.
Keywords: cybersecurity, AI security, vulnerability management, patch management, endpoint security, autonomous endpoint management, Tanium, Harman Kaur, security automation, AI transformation, data quality, zero day, CISO, board risk, Mythos, security operations, KBKast
More Business podcasts
Trending Business podcasts
About KBKAST
Unlike every other security podcast, we don’t get stuck down in the technical weeds. Our remit is to speak with experts around the globe at the strategic level – how security technology can improve the experience and risk optimisation for every organisation.
The Voice of Cyber® - In Partnership with Vanta
Podcast websiteListen to KBKAST, Chanticleer and many other podcasts from around the world with the radio.net app

Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features


KBKAST
Scan code,
download the app,
start listening.
download the app,
start listening.
KBKAST: Podcasts in Family
























