437 episodes
- When Mythos hit in April, the security world split between panic and hype. Sumedh Thakar, President and CEO of Qualys, joins KB to make the calmer case that Mythos accelerated an old threat rather than inventing one. They get into why zero-day vulnerabilities now need zero-day remediation, the misread that Mythos runs on your own code while your vendors use it too, the board conversation it reopened, tokenomics and budget pressure, and how much a CISO should really hand to the machines.
About Sumedh:
As a cybersecurity visionary, Sumedh is passionate about making the world’s digital journey safer. His education and early experiences as a coder led him to Qualys, where he rose from engineer to president and CEO. He joined Qualys in 2003, shortly after the company’s founding and in an era when organizations started using the cloud but didn’t know what to call it. His contributions and leadership helped propel Qualys to its current success in cybersecurity.
Sumedh became president and CEO in 2021. In 2019, he was named president, and prior to that, he was chief product officer, driving the company’s vision of making enterprise security more efficient and disrupting the VM space with integrated capabilities like patch management and cybersecurity asset management. A “product fanatic and engineer at heart,” Sumedh was instrumental in dramatically expanding the original Qualys platform’s scope, integrations, and automations. He also scaled the company’s engineering talent internationally with a global 24×7 follow-the-sun product team. He is a co-inventor of five U.S. patents for cybersecurity technology in Qualys offerings.
Previously, Sumedh was an engineer at Intacct, an early cloud-based financial and accounting software provider. He also worked at Northwest Airlines developing complex algorithms for its yield and revenue management reservation system. He has a bachelor’s degree in computer engineering with distinction from Savitribai Phule Pune University.
Keywords: Mythos, AI security, cybersecurity, zero-day, autonomous remediation, vulnerability management, CISO strategy, board reporting, Qualys, Sumedh Thakar, patch management, true risk, exposure management, AI attacks, first-party code Episode 383 Deep Dive: Sarah Sloan | It Still Runs, But Can You Defend It? The End-of-Life Tech Reckoning
03/09/2026 | 38 mins.The tech running hospitals, power grids and government services often still works. Sarah Sloan, Cisco’s Head of Cybersecurity Policy for APAC, joins KB to explain why that’s the problem, not the reassurance it sounds like.
Drawing on a new ASPI report Cisco funded, “Past its use-by-date,” they get into why so much end-of-life tech is still in place (usually budgets and skills, not negligence), how AI and quantum turned a slow-burn risk into an urgent one, and why most organisations still can’t see the ageing gear in their own environment. Plus the upside: why moving early beats being forced by an incident.
About Sarah:
Sarah Sloan is Head of Cybersecurity Policy APAC, Cisco where she leads public sector engagement on cybersecurity policy matters across the region. With over 15 years’ experience across government, industry, and consulting — including more than a decade focused on cyber and technology — Sarah has held senior roles in the Australian Government and leading global technology firms, driving policy development, public-private sector partnerships, and national cybersecurity priorities. She holds a Bachelor of Laws (Hons) and Bachelor of Asia-Pacific Studies from the Australian National University (ANU), and postgraduate qualifications in legal practice, international law, and Japanese studies. Sarah is also Chair of the Australian Industry Information Association’s (AIIA) National Security and Cyber Resilience Policy Advisory Network.
Keywords: end-of-life technology, legacy systems, critical infrastructure, cybersecurity governance, ASPI, Cisco, Legacy Five, board risk, post-quantum cryptography, AI cyber threats, SOCI Act, technology lifecycle, cost of downtime, CISO, digital resilienceEpisode 382 Deep Dive: Quinton Anderson | Trust the System, Not the Agent – Zero Trust for the Agentic Enterprise
26/08/2026 | 49 mins.KB sits down with Quinton Anderson, founder of Aigentsphere, to challenge one of the most repeated lines in AI governance: that a human in the loop keeps you safe. His view is that asking people to approve task after task just trains them to say yes.
They get into why you should never trust an agent but can trust the system around it, why an agent can’t be fully tested before it goes live, and why the brakes are what let you go fast. A sharp look at what it actually takes to govern agents at scale.
About Quinton:
Quinton Anderson brings decades of experience in enterprise technology, risk management, and AI strategy. With a background spanning financial services, defense, and telecommunications, he founded Aigentsphere to solve the governance gap that emerges when organisations deploy AI agents at scale. He is passionate about building systems that make AI safe, accountable, and effective.
Keywords: agentic AI, AI governance, human in the loop, human oversight, zero trust for agents, sociotechnical systems, continuous compliance, board accountability, AI safety, enterprise AI, Quinton Anderson, Aigentsphere, KBKastEpisode 381 Deep Dive: Gijo Varghese | When a Cyber Attack Becomes a Public Safety Failure
19/08/2026 | 47 mins.Karissa Breen sits down with Gijo Varghese, Chief Security Officer at OT cyber security firm Secolve, to unpack an uncomfortable trade-off: the same connectivity and AI making power, water and transport smarter are also making them easier to break. Gijo explains how IT and OT convergence has widened the attack surface, why decades-old control systems were never built to touch the internet, and how a single IT intrusion can spill into the physical world. He walks through the incidents that prove it, from the 2015 Ukraine grid attack to Colonial Pipeline, where operators went to run the system by hand and found the people who knew how had all retired, to the Jaguar Land Rover breach that rippled through 5,000 suppliers and cost the UK economy billions. The throughline for boards and executives: a cyber incident stops being a security event the moment it becomes a public safety failure. Gijo makes the case for the kill switch, tested manual fallbacks, and treating resilience rather than compliance as the real measure of readiness.
About Gijo:
Gijo Varghese is a cyber security veteran, critical infrastructure defender, and the Chief Security Officer of Secolve. His passion in life is to protect the systems society depends on – power grids, transport networks, and biomedical health systems – keeping people, communities, and businesses safe from cyberattacks. With over 25 years of experience across IT and OT security, Gijo has spent his career at the frontline of Australia’s most essential industries, most recently leading cyber resilience at Endeavour Energy for six years, with prior roles at Transport for NSW, SA Health, CyberCX and Wipro Consulting.
Secolve is Australia’s leading OT cybersecurity firm, providing cyber advisory, offensive security, and training services to mines, factories, hospitals, transport networks, and energy ecosystems. As Secolve’s first CSO, Gijo leads the firm’s consultancy and professional services team, transforming complex OT cyber risks into practical action across executive, engineering, and operational teams.
Keywords: critical infrastructure security, OT security, IT/OT convergence, SCADA, ICS, cyber resilience, kill switch, Colonial Pipeline, Jaguar Land Rover, SOCI Act, CI45, incident response, operational technology, AI cybersecurity, public safety, board governance, cyber warfare, business continuityEpisode 380 Deep Dive: Mark Thomas | Owning a Policy PDF Doesn't Mean You Govern Your AI
12/08/2026 | 47 mins.In this episode, KB sits down with Mark Thomas, IT governance and risk veteran, ISACA Hall of Famer and president of Escoute Consulting, to pull apart a problem a lot of boards haven’t clocked yet – the gap between owning an AI policy and being able to prove it controls anything.
They get into the Air Canada chatbot case and what it says about accountability, why the honest board test is “would anyone notice if this was violated,” and how the risk changes once agents move from recommending to executing. Mark makes the case that human in the loop only counts when the human has the expertise, the authority and the time to say no. He also explains why only a small fraction of organisations have ever tested their ability to shut a system down, and why accountability never transfers to the vendor.
A practical, occasionally uncomfortable conversation for anyone putting AI into production.
——
About Mark:
Mark Thomas is a globally recognised expert in governance, risk management, and digital trust, with more than two decades of experience advising organisations operating in complex, regulated, and rapidly evolving environments. His work sits at a critical intersection where strategy, governance, and execution meet.
He works directly with boards and executive leadership to:
Strengthen oversight and accountability
Improve confidence in decision-making
Navigate emerging technologies and digital risk
Align governance with real-world execution
Mark is known for his ability to translate complex issues into clear, practical insight, helping leaders move from uncertainty to informed, defensible decisions.
Keywords: AI governance, AI risk, board accountability, agentic AI, human in the loop, kill switch, digital trust, AI policy, ISACA, Mark Thomas, Escoute Consulting, KBKast, enterprise AI, AI compliance, EU AI Act, shadow AI, Air Canada chatbot
More Business podcasts
Trending Business podcasts
About KBKAST
Unlike every other security podcast, we don’t get stuck down in the technical weeds. Our remit is to speak with experts around the globe at the strategic level – how security technology can improve the experience and risk optimisation for every organisation.
The Voice of Cyber® - In Partnership with Vanta
Podcast websiteListen to KBKAST, Chanticleer and many other podcasts from around the world with the radio.net app

Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features


KBKAST
Scan code,
download the app,
start listening.
download the app,
start listening.
KBKAST: Podcasts in Family























