
Free Daily Podcast Summary
by ITSPmagazine, Sean Martin, Marco Ciappelli
Founded in 2015, ITSPmagazine began as a vision for a publication positioned at the critical intersection of technology, cybersecurity, and society. What started as a written publication has evolved into a comprehensive repository for all their content—podcasts, articles, event coverage, interviews, videos, panels, and everything they create. This is where Sean Martin and Marco Ciappelli talk about cybersecurity, technology, society, music, storytelling, branding, conference coverage, and whatever else catches their attention. Over a decade of conversations exploring how these worlds collide, influence each other, and shape the human experience. This is where you'll find it all.
The most recent episodes — sign up to get AI-powered summaries of each one.
FedRAMP has changed before. What makes the Consolidated Rules for 2026 different is that the dates are on the calendar and the fence sitters have run out of runway. Jason Ford, Co-Founder and CEO of Steel Patriot Partners, has been inside the program since Rev 3 in 2013. Michael Parisi, Chief Growth Officer, comes at it from the business side. Together they map what changes and, more usefully, what it means for the decision in front of a provider right now. So what actually changes? The program consolidates into two paths, 20X and Rev 5. FedRAMP Ready moves to legacy status. Class A, B, and C pipelines open across a thirty to sixty day window, mandatory adoption arrives January 1, and new Rev 5 certifications close on June 11, 2027. Authorized becomes certified. Jason Ford also points out where the rules live: fedramp.gov, hosted in GitHub, which means they move with a commit. Reading them once is not tracking them. Why did FedRAMP need to change at all? Michael Parisi frames it as a supply problem. Agencies and primes have been working from a limited and aging set of technologies while better tools sat outside a process that was slow, rudimentary, and expensive. The action was warranted. His follow-up question gets less airtime: if the process moved faster, did responsibility move with it, and does the stakeholder now holding that due diligence know it yet? The engineering shift is real and it is the part most teams see coming. Jason Ford describes RMF thinking giving way to continuous DevSecOps, proving compliance in real time rather than at a point in time. Vulnerability remediation is where the compression bites. CISA's updated guidance drops severity score as the driver in favor of stepped prioritization, and windows that used to run 30, 60, and 90 days now land closer to three to twenty-one. What does this cost a business past the budget line? Time and capacity. 20X is faster than a Rev 5 process that once ran eighteen months, but faster is not instant. Retraining a couple hundred users inside a thousand-person organization is not a small endeavor, and if the transition eats half of the organization's capacity for a year, that is half as much capacity aimed at the business paying for it. Jason Ford is not arguing against the move. He is arguing that disruption belongs inside the decision. Then there is the internal work almost nobody has started. Mapping an existing Rev 5 ATO scope into a new certification level is not clear-cut, and past the mapping, marketing and sales both need re-education. Michael Parisi describes building a translation layer for customers: here is what we provided before, here is what it is now, and this change came from the program rather than from any reduction in assurance. Roughly half the time, Steel Patriot Partners tells organizations not to pursue certification at all. Michael Parisi treats that as one of the more valuable things the firm does. The opposite failure shows up just as often, with companies preparing to spend heavily on 20X because it sounds quicker and cheaper, when the agency or prime they are chasing expects a certification level. A lower bar only helps if the buyer accepts it. Where should a business start? With the business conversation. Michael Parisi notes the answer does not have to be yes or no today; it can be a maybe with defined trigger points. Jason Ford closes on posture: come with an open mind, and do not hand a multi-year commitment to a language model whose guardrails and training are not built for that call. Or, shorter: don't wait, and don't go it alone. Steel Patriot Partners built a three-question starting point for that first conversation at https://www.steelpatriotpartners.com/find-your-path. This is a Brand Story. A Brand Story is a ~35-40 minute in-depth conversation designed to tell the complete story of the guest, their company, and their vision. Learn more: https://www.studioc60.com/creation#full GUESTS Jason Ford, Co-Founder and Chief Executive Officer, Steel Patriot Partners On LinkedIn: https://www.linkedin.com/in/jason-ford-5ab206/ Michael Parisi, Chief Growth Officer, Steel Patriot Partners On LinkedIn: https://www.linkedin.com/in/michael-parisi-4009b2261/ RESOURCES Learn more about Steel Patriot Partners: <a href="https://www.
For companies in the defense industrial base, a compliance deadline is not paperwork. It is the difference between winning contracts and watching them stall. In this Brand Feature, Jason LaPointe, Chief Technology Officer at Exostar, and Michael Parisi, Chief Growth Officer at Steel Patriot Partners, walk through what it takes to get FedRAMP ready without cutting corners. Exostar was born out of a consortium that included Boeing and Lockheed Martin, and its FedRAMP-moderate posture lets smaller suppliers keep working on Department of War contracts. How does that work? Instead of moving every server and mailbox into a secure boundary, a supplier inherits roughly 80% of the controls from Exostar, which shrinks the scope of its own CMMC audit considerably. The clock was real. At the time, a November transition date loomed, after which many suppliers could no longer self-attest. That specific timeline has since been paused, but the pressure to prove readiness has not gone away. Exostar needed to show it was FedRAMP-moderate and ready for an audit, and working with Steel Patriot Partners, the team pulled a January target in by nearly three months, not by skipping steps, but by moving with confidence. Why build a new platform instead of retrofitting the old one? Jason LaPointe describes a platform first initiative: build the new compliant home, then migrate customers into it. Trying to modernize inside a live production environment would have been disruptive, so the team built alongside rather than on top, which freed them to re-architect and retool without breaking customers. Michael Parisi frames the engagement as embedding, not staff augmentation. Steel Patriot Partners plugged directly into the product team through daily standups and leadership calls, delivered infrastructure as code and deployment pipelines, and kept the work with US citizens, a requirement once controlled unclassified information is in play. What makes an audit go smoothly? Preparation that extends to how questions get answered. Jason LaPointe compares the audit to a deposition, where an unsolicited comment hands an assessor somewhere new to go. Michael Parisi, who spent years in the assessor's seat and ran the practice for a large C3PAO, explains why knowing the auditors and presenting information cleanly protects the outcome. The business math is unforgiving. Miss the audit window and millions in direct contracts can be exposed, while auditors book out six to eight months. Exostar cleared it with a clean, no POA&M result, and the business is now seeing tailwinds through initiatives like Golden Dome. The lesson Jason LaPointe offers other technology and security leaders is about temperament. Every part of the organization gets touched, from R&D to HR to finance, and the willingness to change quickly becomes the governor on success. Having a clear voice at the table for what good looks like, as Steel Patriot Partners provided, is what accelerates the decisions. This is a Brand Feature. A Brand Feature is a ~30 minute in-depth conversation designed to go deep on a company's story, solutions, and customer success. Learn more: https://www.studioc60.com/creation#feature GUESTS Jason LaPointe, Chief Technology Officer, Exostar Website: https://www.exostar.com/ LinkedIn: https://www.linkedin.com/in/jasonlapointe Michael Parisi, Chief Growth Officer, Steel Patriot Partners Website: https://www.steelpatriotpartners.com/ LinkedIn: https://www.linkedin.com/in/michael-parisi-4009b2261/ RESOURCES Learn more about Exostar: https://www.exostar.com/ Aerospace and Defense solutions from Exostar: https://www.exostar.com/industries/aerospace-defense/ Learn more about Steel Patriot Partners: https://www.steelpatriotpartners.com/ Find Your Path with Steel Patriot Partners: https://steelpatriotpartners.com/find-your-path/</a
PODCAST EPISODE | An Analog Brain In A Digital Age With Marco Ciappelli Fifteen years ago, Rose Ross brought a client an idea for an awards program built specifically for enterprise tech startups. The client passed. She built it herself — and the Tech Trailblazers have been running ever since, independent, judged by practitioners, and open for entries until 3 September. 📺 Watch | 🎙️ Listen | marcociappelli.com There are couches on the upper floor at ExCeL London where the glass opens onto the water, and every June I promise myself I will sit there and have one unhurried conversation with somebody worth an hour. Every June I walk past them carrying a bag of microphones. Rose Ross and I both did exactly that at Infosecurity Europe, so we recorded this weeks later and six thousand miles apart, and it worked out fine. Good ideas survive bad timing. Rose knows something about that. Fifteen years ago she brought a client an idea — an awards program for enterprise tech startups, the companies that had no category of their own. The client passed. She built it herself, gave it a better name than Global Innovation Awards, and asked Joe Baguley to judge. He said yes immediately. When someone like Joe says yes, she told me, you know you are onto something. Fifteen years later the Tech Trailblazers are still running, still independent, and now cover everything from storage and security to quantum and robotics, plus categories for the founders and the investors behind them. I have been around enough award programs to have opinions. Plenty of them are a night out: you put on the jacket, you eat the food, you take the photo, and by Monday the trophy is a doorstop. What Rose built works differently, and the difference is by design. Start with who does the scoring. Rose stays out of it completely, on the reasoning that nobody needs a PR person picking winners — she said it before I could. The judges are practitioners who know a category well enough to read a claim and tell whether it holds. Startups are scored against startups, apples with apples and pears with pears, so a young company is never dropped into a popularity contest against an incumbent. The criteria cover innovation, market readiness and leadership, and then each judge gets a free card: points awarded on instinct alone. I like that card more than I probably should. It concedes that expertise is partly something you feel and cannot fully write down, which is a rare concession in an industry that would prefer everything be a dashboard. Then the shortlists go in front of a thousand CIOs, CISOs and technology buyers around the world, and the promotion keeps going long after the announcement — a weekly roundup of what the alumni are doing, coverage where it can be earned, a podcast recording with Rose for every winner. Risk Ledger took the security category a couple of years back and has just closed a $24 million Series B. The award keeps working after the award. The best answer of the conversation came from a simple question. I asked what a win is actually worth. Rose moved through the exposure and the investor attention quickly, then spent the rest of it on the team. Not the founder. The engineers, the designers, the support people who put in eighteen months of long hours and rarely hear from anyone outside their own building that the work was good. That part, she said, is priceless. I grew up in a city built by workshops. The Florentine bottega was a collective — the master, the apprentices, the hands that ground the pigment and prepared the panels — and the good ones understood that the work belonged to the room. Recognition is old technology. Older than any category Rose runs. An award engineered so that it reaches past the founder and lands on everyone who built the thing is doing something more useful than handing out a doorstop. Near the end I asked whether technology today is money-driven or mission-driven. She declined to pick, which was the right call. Most people want both. She has never interviewed a founder who was in it purely for the exit. And without something worth caring about, you do not survive the years when the payoff is still a maybe. Entries close 3 September at techtrailblazers.com. Firestarters is free for the earliest-stage startups. Sean Martin is on the judging panel this year, so put your best in front of him. More conversations like this one, in your inbox: subscribe to the newsletter at marcociappelli.com. Who on your team should be hearing this week that the work was good? Let's keep thinking. — Marco Co-Founder ITSPmagazine & Studio C60 | Creative Director | Branding & Marketing Advisor
PODCAST EPISODE | An Analog Brain In A Digital Age With Marco Ciappelli Every organization has a policy on AI. Most of them are unwritten, unspoken, and enforced by silence. Priyanka Dave — behavioral scientist, dual PhD, and the person responsible for teaching an entire university system how to work with these tools — explains what actually happens inside a company that refuses to say the word out loud. 📺 Watch | 🎙️ Listen | marcociappelli.com This conversation sat in my queue for months. I recorded it back when the show still went by another name, filed it under soon, and then buried it under travel, deadlines, and the small avalanche of everything else. So: my apologies to Priyanka Dave, who deserved better timing. What I did before publishing was listen to the whole thing again, half expecting it to have gone stale — AI conversations have the shelf life of fresh milk — and it hadn't. Not one line. That is either a compliment to her or an indictment of the rest of us. Possibly both. Here is what has held up. Priyanka Dave is a behavioral scientist with two doctorates and the unglamorous job of teaching a large public institution how to actually use these tools. Her diagnosis is not about the technology. It is about what happens when nobody in charge will say anything about it. An organization that stays quiet on AI does not prevent its people from using AI. It only stops hearing about it. Employees keep working the way they were already working — with a chatbot open in the next tab — and they simply stop mentioning it. The tool doesn't go away. The conversation does. I cover cybersecurity for a living, so I recognized this immediately. It's shadow IT with a better vocabulary. And shadow IT was never a technology failure — it was a communication failure that grew teeth. The same thing is happening now, except the data walking out the door isn't on a USB stick. It's being pasted into a text box by someone who was never told where the line is, because nobody in the building was willing to draw one. The schools got there first, and got it wrong first. Ban it, some of them announced, and the students used it anyway — badly, secretly, without a shred of judgment about when the machine is confidently wrong. Prohibition didn't produce abstinence. It produced amateurs. It always does. So Priyanka's answer is education, and here I pushed, because education has a recursion problem. If the leader is supposed to model good AI use, who taught the leader? I asked her: who educates the educator? Her answer was refreshingly unromantic. Nobody, mostly. Budgets get cut, leadership development is the first line item to go, and the executives left standing are quietly teaching themselves at night so they don't look foolish in the morning. The people expected to be the role models are improvising just like everyone else — they're only better dressed while doing it. And this is where the real cost lands. She cited the research: people leave organizations that offer them nowhere to grow. Nobody wants to miss the train. If your company won't teach you the thing that everyone agrees is coming, you will go somewhere that will — and you will take your best years with you. The company that avoided the awkward conversation about AI doesn't just end up with a hidden problem. It ends up with a smaller team. Her three tips for leaders are almost embarrassingly simple, which is how you know they're good. Ask your people what excites them about AI. Then ask what scares them. Then use the thing yourself, out loud, where everyone can see you double-check its work. Which brings me to the word I've been chewing on since we hung up: sensemaking. Priyanka listed it among the capabilities leaders need. I called it common sense, and she let me get away with it. It means not pressing the easy button. It means remembering that the thing on the other side of the screen has no context, no stake, and no idea what it is saying — even when it sounds like it does. It is not your friend. It is not your enemy. It is something else, and we haven't named it yet. So the fear was never really about the machine, was it? It was about being the last person in the room who wasn't told how to use it. Priyanka's work and writing are linked below. Subscribe to the newsletter at marcociappelli.com. Let's keep thinking. — Marco Co-Founder ITSPmagazine & Studio C60 | Creative Director | Branding & Marketing Advisor | Personal Branding Coach | Journalist | Writer | Podcast: An Analog Brain In A Digital Age ⚠️ Beware: Pigs May Fly | 🌎 LAX🛸FLR 🌍 About Marco Marco Ciappelli is Co-Founder & CMO of ITSPmagazine, Co-Founder & Creative Director of
⬥EPISODE NOTES⬥ Tidal is about to stop paying royalties on any track it judges to be fully machine-made. Frame that as a music story and you miss the shift underneath it. By Deezer's own detection, roughly 75,000 AI-generated tracks now arrive every day, about 44% of everything uploaded, yet that same AI music is only 1 to 3 percent of what people actually play, and around 85% of those streams are flagged as fraudulent. The flood is not an audience. It is an attack on a shared payout. This edition follows one pattern across six industries: when the cost of generating something collapses toward zero, platforms stop paying for output and start paying for proof of human origin. Tidal cuts AI royalties. The Authors Guild sells a "Human Authored" badge for ten dollars a title. YouTube demonetizes "inauthentic" content. curl killed its bug bounty after a flood of AI slop, then reopened when the slop got good. And where no gatekeeper owns the payout, hiring, the open web, the scientific record, the flood just degrades the mechanism until no one trusts it. In this edition of Lens Four: 🔹 Tidal's July 15 policy ends royalty attribution and direct-to-fan sales for fully AI-generated tracks, a payout decision, not a content ban. 🔹 Deezer takes in about 75,000 AI tracks a day (44% of uploads), up from roughly 10,000 a day at the start of 2025, while human uploads barely moved. 🔹 The paradox that reframes the debate: AI music is 44% of uploads but 1 to 3 percent of listening, and about 85% of those streams are fraudulent. 🔹 The first US criminal AI streaming-fraud case: Michael Smith pleaded guilty after collecting more than 8 million dollars in royalties from hundreds of thousands of AI songs and roughly 1,000 bot accounts. 🔹 curl shut down its bug bounty under a flood of AI vulnerability reports, then reopened a month later because the AI reports got good enough to read. Cutting the money did not cut the volume. 🔹 The counter-case: recruiters see about 11,000 job applications submitted to LinkedIn every minute, up 45% in a year, with no single payout to switch off. 🔹 Provenance becomes a product: Suno (2 million subscribers, about 7 million songs a day) adds identity-verified voice cloning while the Authors Guild sells human certification. 🔹 The danger tier: roughly 20% of AI-recommended software packages do not exist (slopsquatting), and close to 10% of cancer papers show paper-mill signatures. 🔹 The language turned first: Merriam-Webster made "slop" its 2025 word of the year, and YouTube quietly renamed "repetitious" content to "inauthentic." 🔹 Human filters see it clearest: DJ Sam Young asks why we need fifty versions of the same thing, and producer Gregoire Gensollen says he will remember the human moments, not the tool. Fourth Lens: The three lenses meet at one move. Platforms re-price payouts around human origin, the market builds products that certify it, and the language teaches us to want it. That is not a defense of artists, it is a paywall around authenticity, sold as virtue, and it is arriving before audiences even asked for it. Reality has come at a premium, exactly as predicted in 2017. So the real question is not whether the real is worth more. It is this: when proof of human becomes a product, who is making the money, and who handed them the right to decide what counts as real? ▶ Read the full article and references ▶ Subscribe to Lens Four ▶ Redefining CyberSecurity Podcast ▶ Music Evolves Podcast ▶ ITSPmagazine ▶ Studio C60 Sean Martin, CISSP, is a cybersecurity market analyst, content strategist, and go-to-market advisor with more than 30 years of experience across engineering, product development, marketing, and media. He is co-founder of ITSPmagazine and Studio C60, host of the Redefining CyberSecurity Podcast and Music Evolves Podcast, and writes Lens Four at seanmartin.com. Keywords: AI-generated music, Tidal, De
⬥EPISODE NOTES⬥ Almost every booth at Infosecurity Europe 2026 had settled on the same four words. Outcomes. Resilience. Sovereignty. Human in the loop. The messaging had grown up, more tempered than RSAC, more honest in its European register. The tell was quieter — almost none of it could connect those words to a definition of success a buyer could actually verify. Strip away the polish and the show floor was a working argument about what the cybersecurity market is for, at the exact moment the clock that governs it collapsed to seconds. The go-to-market caught up to the language. The capability did not. This is the prove-it problem, and it is worth pulling apart clearly. In this edition of Lens Four: 🔹 Why the quiet vocabulary convergence mattered more than any single product launch — outcomes, resilience, sovereignty, and human in the loop became the words everyone said, and almost none could tie them to a definition of success a buyer could verify 🔹 The number that should reorganize every SOC — the jump from initial access to the next stage collapsing from 8 hours to 22 seconds, with ransomware finishing in under an hour, most often on a Wednesday night 🔹 How Qualys reframed measurement itself — a client environment of 62 million risk findings cut to under 1% that could actually be executed, because the dashboard was never the deliverable, remediation was 🔹 Why Corelight put the same test on the detection itself — a black box tells you little, so keep the data behind every alert in the open and let an analyst prove what it actually is, the way one proof of value surfaced unencrypted sensitive traffic in 30 minutes 🔹 How Sumo Logic showed the repeatable version — prove a fix once, then let an agent apply that proven fix across 599 identical machines under human oversight, and its move into the AWS European Sovereign Cloud put something concrete under the week's sovereignty talk 🔹 What the criminal economy revealed as the honest mirror — an underground market for AI attack tools that went from 38 posts to over 1,400 in two months, tiered and redundant, an AI call center for hire that sounds like SaaS 🔹 Why the board's only real question, are we okay, now lands on the CISO as personal liability, just as AI moves from experimentation to deployment inside the organization 🔹 How consolidation and absorption are sorting the floor — 40-plus tools in silos, "make us relevant" becoming an executive hire, and the 12-to-18-month reckoning where AI absorbs functions that fill today's expo hall 🔹 The tell underneath all of it — when every booth converges on the same three or four words, the words stop doing the one job language has at a trade show: helping a buyer tell two things apart Fourth Lens: The vocabulary moved faster than the products underneath it. The industry repositioned around outcomes without ever defining the outcome, and the bill comes due over the next 12 to 18 months, not because AI arrives, but because AI removes the last place to hide the question. Naming the outcome was the easy part. Proving it repeats, across environments and teams and budgets that share nothing but the problem, is the part the vocabulary skipped. When the story can no longer be rounded up, are we okay, and can you prove it twice? 🥁 🎶 A very big THANK YOU to our Infosecurity Europe 2026 Full Coverage Sponsors: Corelight · Qualys · Sumo Logic 👏 👏 👏 ▶ Full article and references ▶ Full Infosecurity Europe 2026 coverage ▶ Subscribe to Lens Four ▶ Redefining CyberSecurity Podcast ▶ Music Evolves Podcast ▶ ITSPmagazine ▶ Studio C60 Sean Martin is a cybersecurity market analyst, content strategist, and go-to-market advisor with more than 30 years of experience across engineering, product development, marketing, and media. He is co-founder of ITSPmagazine and <a href="h
ON LOCATION | Sean Martin & Marco Ciappelli — Infosecurity Europe 2026 Two conferences, two moods: at RSA the drumbeat was resilience; at InfoSec, it's sovereignty. Sean and I close the week with Forrester analyst Madelein van der Hout — beaming in from the Netherlands — on why Europe makes a framework out of everything, what AI deployment is doing to the boardroom, and the security jobs that don't exist yet. 📺 Watch | 🎤 Listen | ITSPmagazine.com There's a building across the Thames from the InfoSecurity press room — Millennium Mills, a derelict flour mill that looks precisely as haunted as it sounds. I kept glancing at it while Sean and I talked with Madelein van der Hout, who this year was a kind of friendly ghost herself: fully in the conversation, quick as ever, and across the North Sea in the Netherlands. She couldn't make it to London this year. FOMO, she told us, is real. Which turned out to be the point. Madelein is a senior analyst at Forrester — she reads this industry for a living — so the first thing we did was compare notes on what the week actually felt like. Sean kept hearing one word on the show floor: sovereignty. A few weeks earlier at RSA in San Francisco, the drumbeat had been resilience. Same industry, two continents, two moods. Madelein said it better than I could: RSA is where her blood pumps with enthusiasm for everything technology can do, good and bad, and InfoSec is where she comes to get grounded in reality. Flashy versus pragmatic. The far edge of the possible versus the guardrails. Europe, she said with affection, will make a framework out of anything — the cloud sovereignty package announced that week being the newest one. And under all the frameworks sits the thing no European conference can avoid: hybrid warfare, close enough to feel. AI is moving from experimentation to deployment inside real organizations, and the moment it does, it stops being a demo and becomes a liability that lands on a boardroom. That, Madelein argued, is what you're feeling here — the weight of being responsible for something you've only just let inside the walls. Her research points somewhere specific: security is drifting toward becoming a "trust and assurance" function, and with it come jobs that don't exist yet. Trust engineers. Agentic workflow assurance engineers. People whose whole task is to confirm that an AI agent did what the business actually intended, not just what it was told. Sean's read was sharp: almost nothing on the expo floor addresses any of that. They're architecting for now, Madelein agreed, not for what's coming. Which is the oldest story in technology — we shout about the future and keep building for the present. Near the end we argued about metaphors, which is the kind of thing I live for. I reached for Frankenstein: all these tools and agents and smart-city systems stitched together into something we then have to teach to move as one. Madelein offered a better image. Don't build a Frankenstein, she said — become a jellyfish. There's a species that works as a neural network, and when two of them are injured and collide, they don't compete. They merge and swim on as a single organism. More than synergy, Sean said. Exactly. We spend enormous energy bolting parts together and calling it integration. Madelein is describing fusion instead of assembly — one organism, not a monster made of seams. She's already made her peace with what all this means for her own work. This job will be automated, she said, maybe most of it, and she cannot wait to help reinvent what an analyst even is. That was the healthiest thing I heard all week. Not "will AI take my job," but "what is this job becoming." So I'm watching a ghost mill through the rain while a colleague beams in from another country, and the question under all the frameworks and the shiny new job titles is quieter than any of them. When everything can be orchestrated, what still has to be human? Let's keep thinking. The full conversation is part of our On Location coverage of Infosecurity Europe 2026 at ITSPmagazine.com. For more of my writing, subscribe to the newsletter at marcociappelli.com. — Marco (with my co-host, Sean Martin) Co-Founder ITSPmagazine & Studio C60 | Creative Director | Branding & Marketing Advisor | Personal Branding Coach | Journalist | Writer | Podcast: An Analog Brain In A Digital Age ⚠️ Beware: Pigs May Fly | 🌎 LAX🛸FLR 🌍 More from our Infosecurity Europe 2026 coverage:Infosecurity Europe 2026 event c
For most of the internet's life, proving identity has meant proving something you know or something you hold: a password, a code, a text message. Kevin Surace, CEO of TokenCore, argues that era is closing fast. As one of the people who helped invent the AI assistant at General Magic, he has a clear view of why the same technology now makes faces and voices simple to fake. Why isn't MFA enough? Because it protects a weak foundation. A decade-old paper mapped fifteen ways to defeat SMS codes, auth apps, and push approvals. Few attackers bothered with them until platforms like Salesforce and Microsoft made those methods mandatory. Now the attack has moved to where the door is. Surace walks through one of the common methods: an AI-written phishing email from a service you already trust, a PDF, and a pixel-perfect login page generated in moments. The credentials you enter relay to an attacker who is logging into the real site in real time. The push prompt asks if it is you, you approve, and the intruder is inside within minutes. The numbers back it up. Palo Alto Networks Unit 42 found that roughly ninety percent of successful intrusions over the past year involved hacked identity, almost all of them MFA or auth apps. The people compromised had privileged access, which means they had MFA in place. So what actually works? Surace makes the case for biometric-assured identity, a category Gartner projects growing into a twelve billion dollar market. TokenCore ties access to a fingerprint stored only on your device, the exact domain your account lives on, and physical proximity over a short-range wireless link. Look-alike domains never register, remote relays never get close enough, and the company never holds your biometric. The hardware comes as a ring, a portable, or a node about the size of an AirTag, and it is FIDO2 compatible, so it works with existing single sign-on. Most customers go passwordless once it is running. The reaction Surace hears most often from security leaders is that they can finally sleep at night. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUEST Kevin Surace, Chief Executive Officer, TokenCore LinkedIn: https://www.linkedin.com/in/ksurace/ RESOURCES Learn more about TokenCore: https://www.tokencore.com Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS Kevin Surace, TokenCore, Sean Martin, brand story, brand marketing, marketing podcast, brand spotlight, biometric assured identity, identity security, multi-factor authentication, MFA bypass, phishing resistant authentication, FIDO2, credential theft, passwordless, deepfake, AI security, account takeover, Unit 42, Gartner Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
Free AI-powered daily recaps. Key takeaways, quotes, and mentions — in a 5-minute read.
Get Free Summaries →Free forever for up to 3 podcasts. No credit card required.
Listeners also like.

Cyber Leaders
Explores cybersecurity trends and strategies through expert insights to help leaders navigate digital threats.

The Digital Executive
A daily tech podcast exploring emerging technologies through interviews with Silicon Valley CEOs, influencers, and celebrities.

Security Now (Audio)
A weekly deep dive into cybersecurity threats, hacking trends, and practical defense strategies for individuals and businesses.

TechSurge: Deep Tech Podcast
Explores emerging technologies, startup challenges, and investment trends through conversations with founders, investors, and tech leaders.

The AI XR Podcast.
Industry insiders interview top founders and executives on AI, spatial computing, VR/AR, and synthetic media.

Founder's Story
Real founders share raw stories of building, scaling, and leading companies, revealing the grit and purpose behind entrepreneurial success.

Accidental Tech Podcast
Three nerds discuss technology, Apple, programming, and related topics.

The Best SEO Podcast: Defining the Future of Search with LLM Visibility
Explores the evolution of SEO in the AI era, focusing on visibility in large language models and next-generation search strategies.

The Cloud Pod | Weekly AI & Cloud News on AWS, Azure & GCP
Covers weekly updates and AI innovations in cloud computing across AWS, Azure, and Google Cloud for tech professionals.

Lenny's Podcast: Product | Career | Growth
Conversations with top product and growth leaders offering practical strategies for building, launching, and scaling successful products.

Latent Space: The AI Engineer Podcast
Covers advances in AI engineering, including foundation models, code generation, and AI agents, through interviews with researchers and developers.

Primary Technology
Tech news covering consumer gadgets, AI, and major industry stories explained for a general audience.
Founded in 2015, ITSPmagazine began as a vision for a publication positioned at the critical intersection of technology, cybersecurity, and society. What started as a written publication has evolved into a comprehensive repository for all their content—podcasts, articles, event coverage, interviews, videos, panels, and everything they create. This is where Sean Martin and Marco Ciappelli talk about cybersecurity, technology, society, music, storytelling, branding, conference coverage, and whatever else catches their attention. Over a decade of conversations exploring how these worlds collide, influence each other, and shape the human experience. This is where you'll find it all.
AI-powered recaps with compact key takeaways, quotes, and insights.
Get key takeaways from The ITSPmagazine Podcast in a 5-minute read.
Stay current on your favorite podcasts without falling behind.
It's a free AI-powered email that summarizes new episodes of The ITSPmagazine Podcast as soon as they're published. You get the key takeaways, notable quotes, and links & mentions — all in a quick read.
When a new episode drops, our AI transcribes and analyzes it, then generates a personalized summary tailored to your interests and profession. It's delivered to your inbox every morning.
No. Podzilla is an independent service that summarizes publicly available podcast content. We're not affiliated with or endorsed by ITSPmagazine, Sean Martin, Marco Ciappelli.
Absolutely! The free plan covers up to 3 podcasts. Upgrade to Pro for 15, or Premium for 50. Browse our full catalog at /podcasts.
The ITSPmagazine Podcast publishes daily. Our AI generates a summary within hours of each new episode.
The ITSPmagazine Podcast covers topics including News, Technology, Culture, Society & Culture. Our AI identifies the specific themes in each episode and highlights what matters most to you.
Free forever for up to 3 podcasts. No credit card required.
Free forever for up to 3 podcasts. No credit card required.