Search a title or topic

Over 20 million podcasts, powered by 

Player FM logo
Artwork

Content provided by Dave Lewis, 1Password and Dave Lewis. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Dave Lewis, 1Password and Dave Lewis or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.
Player FM - Podcast App
Go offline with the Player FM app!

Chasing Entropy Podcast 020: Trey Ford on Research, Risk, and the Rise of Agentic AI

31:02
 
Share
 

Manage episode 505327342 series 3662462
Content provided by Dave Lewis, 1Password and Dave Lewis. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Dave Lewis, 1Password and Dave Lewis or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.

In the 20th episode of the Chasing Entropy Podcast, Dave Lewis sits down with Trey Ford, Chief Strategy & Trust Officer at Bugcrowd and former General Manager of Black Hat, to explore the realities of modern cybersecurity leadership.

From the pitfalls of annual penetration tests to the messy realities of vulnerability disclosure, Trey shares lessons from decades in the field. He explains why risk should be owned at the board level (not by the CISO alone), why disclosure remains the internet’s immune system, and what the rise of agentic AI means for governance and resilience.

The conversation also dives into leadership growth: shifting from arguing to win, to arguing to understand, and how CISOs can transform into true business partners rather than gatekeepers.

Key Takeaways

  • Continuous resilience matters. Annual pen tests don’t reflect reality—continuous measurement does.
  • Risk ownership belongs with the business. CISOs shouldn’t carry it alone.
  • Disclosure is essential. Research-first venues like Black Hat make it safer.
  • Agentic AI raises new risks. Guardrails, explainability, and governance must be designed in.
  • CISO success = trust. Build partnerships across the executive team, not walls.

Memorable Quotes

  • “If it’s accessible, it’s worth securing, scope is a convenience, not a defense.”
  • “It’s not CISO vs. world; it’s the business deciding risk together.”
  • “In the cloud you can ‘accidentally it all the way’, agentic AI just gives that accident agency.”

Listen to Episode 20 now wherever you get your podcasts!

  continue reading

21 episodes

Artwork
iconShare
 
Manage episode 505327342 series 3662462
Content provided by Dave Lewis, 1Password and Dave Lewis. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Dave Lewis, 1Password and Dave Lewis or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.

In the 20th episode of the Chasing Entropy Podcast, Dave Lewis sits down with Trey Ford, Chief Strategy & Trust Officer at Bugcrowd and former General Manager of Black Hat, to explore the realities of modern cybersecurity leadership.

From the pitfalls of annual penetration tests to the messy realities of vulnerability disclosure, Trey shares lessons from decades in the field. He explains why risk should be owned at the board level (not by the CISO alone), why disclosure remains the internet’s immune system, and what the rise of agentic AI means for governance and resilience.

The conversation also dives into leadership growth: shifting from arguing to win, to arguing to understand, and how CISOs can transform into true business partners rather than gatekeepers.

Key Takeaways

  • Continuous resilience matters. Annual pen tests don’t reflect reality—continuous measurement does.
  • Risk ownership belongs with the business. CISOs shouldn’t carry it alone.
  • Disclosure is essential. Research-first venues like Black Hat make it safer.
  • Agentic AI raises new risks. Guardrails, explainability, and governance must be designed in.
  • CISO success = trust. Build partnerships across the executive team, not walls.

Memorable Quotes

  • “If it’s accessible, it’s worth securing, scope is a convenience, not a defense.”
  • “It’s not CISO vs. world; it’s the business deciding risk together.”
  • “In the cloud you can ‘accidentally it all the way’, agentic AI just gives that accident agency.”

Listen to Episode 20 now wherever you get your podcasts!

  continue reading

21 episodes

All episodes

×
 
Loading …

Welcome to Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Copyright 2025 | Privacy Policy | Terms of Service | | Copyright
Listen to this show while you explore
Play