Formerly known as Wikibon

CyberSHIFT Podcast

with Krista Case

About the podcast

“Navigating the disruption reshaping cybersecurity and resilience.”

CyberSHIFT is an analyst-led podcast from theCUBE exploring how cybersecurity, resilience, and enterprise operations are being redefined by unprecedented, AI-driven disruption. The security discipline is undergoing a fundamental shift, moving away from prevention as the primary goal toward business continuity and the ability to operate through inevitable disruption. Each episode examines how decision-making changes under pressure and what the next generation of operating models looks like, grounded by insight from the practitioners and leaders navigating these changes in real time. Hosted by Principal Analyst Krista Case, CyberSHIFT unpacks conversations that will shape cybersecurity and resilience for years to come.

episodes

The New Measure of Cyber Recovery: Can the Business Get Back to Work?

A cyberattack is more likely to interrupt today’s enterprise than the natural disasters business continuity programs were originally built around. Enterprises still need to prepare for fires, floods, earthquakes, power failures and other physical events. But they are more likely to experience a cyber incident that disrupts business operations by affecting employee productivity, taking applications or customer-facing services offline, or corrupting or exposing data. AI adds urgency. Attackers are using AI to accelerate the attack lifecycle, while enterprises are embedding AI into applications, workflows and business processes. Defenders have less time to make informed decisions, and AI-enabled processes create new dependencies across enterprise systems. As agents take actions across those systems, the consequences of a compromised identity, application or agent can extend well beyond the initial point of failure. The need for resilience came through at Black Hat 2026, a conference historically centered on security threats, vulnerabilities and defenses. Conversations

Black Hat 2026: Governing AI Agents From Access to Action

Enterprise AI is moving from answering questions to taking action. Agents can access data, invoke tools, call APIs and execute tasks across business processes. They can act on behalf of employees, interact with other agents and operate at a speed and scale that conventional human-centric security models were not built to handle. This requires a different governance model. Enterprises need to know which agents exist, who is responsible for them, what identities and privileges they use, what data and tools they can access and what they do with that access. An agent can be properly authenticated and authorized to access a resource and still take a risky action. Security teams therefore need to answer two questions: What is the agent allowed to do? And is what the agent is doing appropriate for the task and business process? Conversations across Black Hat 2026 showed an industry working through both questions. Identity,

What Black Hat 2026 Revealed About the Future of Security Operations

What Black Hat 2026 Revealed About the Future of Security Operations Cybersecurity has always been a race against time. Black Hat 2026 made it clear that AI is putting new pressure on the clock. The industry’s answer to growing risk has long included more visibility, more detection and more specialized tools. Those investments generated valuable information, but they also created a coordination problem: someone still has to assemble the context, figure out what happened, determine what matters, decide what to do, get that decision to the right person or system and verify the outcome. Simply put, there is more telemetry and findings than humans can reasonably make sense of. Closing that gap will require a new operating model that uses AI to pull that context together, speed up investigation and move routine work toward action, while relying on human expertise for judgment, business impact, and consequential decisions. AI Is Changing

Microsoft Just Described What AI-Native Cybersecurity Looks Like

The cybersecurity industry has spent the past two years adding AI to existing products. Copilots summarize alerts, assistants answer questions, and agents automate individual tasks. While these capabilities have improved analyst productivity, they have done little to change the underlying operating model of security. Microsoft’s introduction of Project Perception suggests the industry is beginning to move beyond that phase. The announcement is significant for the architectural direction it represents. Microsoft is describing a security platform designed to continuously perceive risk, reason across shared context, coordinate specialized agents, and translate intelligence into action. Whether Project Perception becomes the blueprint for the industry remains to be seen. What matters is that one of the industry’s largest platform vendors is acknowledging that AI requires more than another assistant layered onto existing workflows, and that security operations are entering a new architectural phase. More Data Hasn’t Solved Security’s Real Problem For more than a

AI-Native Security Needs Enterprise Context

Walk through the expo floor at Black Hat this year, and every security vendor will present an AI story. Some vendors are positioning agentic AI as a new SOC operating layer that can investigate alerts, hunt threats, prioritize risk, and execute response across the security stack. Others are emphasizing autonomous defense, controlled autonomy, natural-language security operations, or AI-driven exposure management. The message is consistent: security teams need to make decisions and act at machine speed without scaling headcount at the same rate. This is true. But simply adding AI to an existing security product doesn’t make it AI native any more than adding cloud connectivity turned every on-premises application into SaaS. AI may change the interface, but it doesn’t necessarily change the operating model. The critical question is whether it changes how decisions are made across the security environment, because security’s biggest challenge is no longer generating intelligence. It’s creating

Why Cybersecurity’s Tool Problem Is Really an Operating Model Problem

Most security teams are running twenty, forty, sometimes eighty different tools, and that didn’t happen by accident. Every purchase solved a legitimate problem. New attack surfaces required new visibility. Cloud computing required different controls than the data center. Compliance added reporting requirements. Detection and response became specialized. Over time, security architectures evolved into a collection of best-of-breed products, each optimized for its own domain. The problem is that the enterprise is becoming an interconnected system where decisions increasingly depend on context shared across applications, data, people, and now AI. Security architectures evolved one product at a time, but the enterprise no longer operates one product at a time. Today, each security product has its own telemetry, policy engine, workflows, and view of risk. None understands enough about the enterprise to make decisions independently. Analysts supply the missing context by connecting technical signals to business priorities, critical applications, identities, and operational

AI Trust Starts with Data Utility: Capital One’s Case for Secure, Usable Data in the Agentic Era

The conventional security playbook, which is to restrict access to protect sensitive data, is a limiting factor for enterprise AI. AI systems need high-fidelity data to produce real business value, so organizations that over-protect data are degrading its utility and ultimately limiting AI outcomes before a single model is trained. This emerging requirement to balance data protection with data accessibility was a central topic of theCUBE Research’s interview with Vince Goveas, director of product management at Capital One Software. Goveas argues that data protection must shift from perimeter defense to a data-centric model where sensitive data is “self-protecting” as it moves through pipelines and into AI systems, preserving usability without expanding exposure. Capital One Software’s approach is enterprise tokenization, delivered through Capital One Databolt. The product case is grounded in a direct comparison. In research conducted with PwC, Capital One tested tokenization, masking, and clear text across AI use cases.

From Perimeter to Authority: How AI Is Forcing a Rethink of Enterprise Data Security

Artificial intelligence is accelerating enterprise transformation, opening new opportunities for productivity, automation, and business growth. It is also lowering barriers to attack, changing the economics of cyber offense. According to Darktrace’s 2026 State of AI Cybersecurity report, 92% of security leaders say AI threats are forcing them to upgrade their defenses. Nearly half report feeling inadequately prepared. Those numbers reflect the concrete shift in attack economics: capabilities that once required highly skilled experts and weeks of manual effort are now fast, automated, and widely accessible. AI allows adversaries to rapidly exploit applications and databases, compressing the window between vulnerability discovery and active exploitation in ways that traditional enterprise security architectures were not designed to handle. Oracle’s response to this challenge is organized around three principles: Secure at Source, Secure at Speed, and Secure through Resilience. Secure at Source embeds security controls at the data layer so that policy enforcement travels

Why Data Primacy May Define Enterprise AI

For decades, applications have served as the center of gravity for enterprise technology. Business logic, workflows, data models, permissions, and semantics have largely been embedded within individual applications. Organizations purchased ERP systems, CRM platforms, supply chain applications, and industry-specific software, then spent years building integrations between them. At its Accelerate 2026 conference, EverPure highlighted that AI is beginning to expose the limits of that model. The company’s thesis centers on data primacy: the idea that the quality, context, provenance, and relationships within enterprise data will increasingly determine AI outcomes more than model capability or compute. As AI becomes embedded in business operations, that assertion carries implications well beyond AI performance. Organizations will not simply need to recover applications and infrastructure after disruption. They will need to preserve and recover the semantic understanding that allows AI systems to reason, decide, and act. The Context Problem EverPure’s leadership returned repeatedly to the

Identity Is Becoming the Control Plane for AI Agents

Vendors are positioning for a world where AI agents operate across the enterprise, making decisions, accessing systems, and executing workflows with minimal human involvement. Orchestration layers, policy-driven architectures, and agentic control planes are taking shape. Yet most organizations have not answered a more basic question: Where are my agents? That question surfaced repeatedly in recent discussions with Okta around its Okta for AI Agents offering and expanding Identity Security Posture Management (ISPM) strategy. Enterprises are moving quickly to adopt AI, but most still lack visibility into what agents exist in their environments, who created them, and what those agents can access. This explains why identity is emerging as one of the foundational control layers of the AI era. Before enterprises can govern AI agents, they must first find them. The Scale of the Problem Is Not Theoretical The urgency becomes clear when you look at the numbers. Research cited by

What Microsoft Build 2026 Means for AI Agent Security and Governance

For years, applications were defined artifacts. You could assess them, test them, and make a reasonable determination that they were safe to deploy. That model does not apply to the AI-driven applications that organizations are building. Models update continuously. Agents interact with external systems at runtime. Decisions depend on context and retrieved information that didn’t exist when the code was written. At Build 2026, Microsoft’s security announcements reflect that the development lifecycle has broken open. Securing code, securing agents, securing models: the perimeter of the application no longer contains the risk. Microsoft Is Betting on the System, Not the Model The headline capability is MDASH, the Microsoft Security multi-model agentic scanning harness, now in expanded preview. It orchestrates more than 100 specialized AI agents across a configurable panel of models to discover, validate, and prove exploitability across codebases. The system recently reached a CyberGym benchmark score of 96.55%, jumping roughly

Why Is Snowflake Talking About Ransomware at an AI Conference?

At Snowflake Summit 2026, the company announced new ransomware and data exfiltration protection capabilities as part of its Horizon Catalog security portfolio. On the surface, the pairing seems off. Ransomware is a mature security problem. AI agents are a new technology challenge. Most vendors discuss them in separate conversations, under separate budgets, with separate teams. Snowflake is making a case that ransomware, data exfiltration, agent governance, and AI security are variations of the same underlying problem: controlling how data moves through an increasingly autonomous enterprise. Security Is Moving Up the Stack For most of the past two decades, enterprise security was built around infrastructure. Firewalls protected networks. Endpoint tools protected devices. Identity platforms controlled who could access systems and applications. Even modern zero-trust architectures remain largely focused on verifying users and limiting access to resources. Cloud computing shifted some of that focus toward data: where it lives, who can reach

Palo Alto Networks’ Idira Signals a Major Shift in Identity Security Strategy

CyberArk rebrand reflects the convergence of identity, privilege, and machine identity security as enterprises adapt to AI-driven environments Palo Alto Networks’ rebrand of CyberArk to Idira at IMPACT 2026 reflects a market shift underway. AI-driven environments expose the limitations of traditional identity governance and privileged access models that were built for relatively static workforce environments centered on human users, persistent accounts, and periodic access reviews. Modern enterprises now operate across distributed infrastructure where machine and autonomous identities continuously inherit and exercise privilege across cloud services, applications, APIs, orchestration frameworks, and interconnected AI workflows. As theCUBE Research recently explored in “How AI Stacks Are Rewriting the Rules of Business,” enterprise architectures are evolving into ecosystems of models, agents, orchestration layers, and autonomous processes. Those environments increasingly require organizations to govern not only who has access, but also how authority, decision-making, and actions are delegated across interconnected systems. As a result, identity

Verizon’s 2026 DBIR and the Gap Between Risk and Response

Verizon’s 2026 Data Breach Investigations Report (DBIR) arrives alongside industry discussion about Anthropic’s Mythos and the broader implications of AI-accelerated vulnerability discovery. Much of that conversation has focused on whether frontier AI models will dramatically expand offensive cyber capabilities. The bigger threat, however, is the burden this will place on IT and security teams that are already struggling to keep pace with the volume of risk they can see today. This concept is reinforced by DBIR data. Vulnerability exploitation became the leading initial access vector in this year’s report, appearing in 31% of breaches analyzed. Organizations faced 50% more critical vulnerabilities requiring remediation as compared to the previous reporting period, and median remediation timelines increased from 32 days to 43 days. These numbers reinforce the criticality of patching discipline and exposure management, but they do not tell the whole story. The broader report reflects escalating enterprise risk resulting from an

Anthropic Mythos and the Growing Gap Between Risk and Response

AI is accelerating vulnerability discovery, but the real challenge is how organizations prioritize and act on risk at scale. Anthropic’s Claude Mythos Preview is getting a lot of attention, and it should. Early results suggest it can surface high-severity vulnerabilities across widely used systems and open source software at machine speed and scale, including issues in widely deployed open source libraries and core infrastructure components. While that is meaningful, it reflects an evolution of something that security teams already deal with, and it does not capture the more important issue at hand. Security teams are not struggling because they cannot find issues. They are already dealing with more findings than they can realistically address, and backlogs are the norm. What they need is a better way to manage and prioritize them at scale. Those conditions become harder to manage as AI accelerates vulnerability discovery. The pressure builds faster, and it

AI Data Protection Gap: Why Enterprise AI Data Is at Risk

AI data is quickly becoming the most valuable asset in the enterprise – and the least protected.

While nearly three-quarters of organizations have moved beyond experimentation into operational AI, protection of AI-generated data is lagging badly. In fact, nearly 70% of organizations haven’t even backed up half of their AI data. At the same time, that data is under active attack – from data poisoning and model theft to prompt injection and exfiltration.

This is the emerging gap in that AI adoption is accelerating, but the systems designed to protect it were built for a different era.

From Youtube

Book A Briefing

Fill out the form , and our team will be in touch shortly.
Skip to content