
The TPRM Podcast
Real conversations about security, risk, and the trade-offs behind modern business. Hosted by Nate Lee, CISO and founder of Cloudsec.ai.
Episodes
Reading the feed…

Real conversations about security, risk, and the trade-offs behind modern business. Hosted by Nate Lee, CISO and founder of Cloudsec.ai.
Reading the feed…
AI isn't just changing how we write software. It's changing how organizations capture knowledge, how security teams operate, and how expertise itself is created, shared, and retained. But what happens when your experience becomes part of the AI systems you build? In this episode of the TPRM Podcast: Threats, Pitfalls & Risk Myths, Nate Lee sits down with Joe Sullivan, Chief Trust Officer at Corridor and former Chief Security Officer at Facebook, Uber, and Cloudflare, to explore one of the biggest shifts facing cybersecurity and every knowledge-based profession. Together they discuss how AI is
Most conversations about AI focus on one question: **Will AI replace jobs?** Alex Stamos thinks that's only part of the story. In this episode of the TPRM Podcast, Threats, Pitfalls & Risk Myths, Nate Lee sits down with Alex Stamos, Chief Product Officer at Corridor, former Chief Security Officer at Facebook, former CISO of Yahoo, and founding director of the Stanford Internet Observatory. The conversation explores how AI is fundamentally changing software development, cybersecurity, and the future of work. As autonomous coding agents become more capable, organizations are entering a world whe
Most conversations about AI and cybersecurity focus on a simple question: Will AI help defenders, or will it help attackers? But that may be the wrong question entirely. In this episode of the TPRM Podcast, Threats, Pitfalls & Risk Myths, Nate Lee sits down with Trey Ford, Chief Strategy & Trust Officer at Bugcrowd, former General Manager of Black Hat, former CISO of Deepwatch, and former security leader at Salesforce and Heroku. The conversation explores what Trey calls the "Bugpocalypse" and why AI is fundamentally changing the economics of vulnerability discovery. As AI dramatically lowers
Most security teams still treat patching as the front line of defense. But what happens when attackers move faster than your remediation cycle, vulnerabilities are discovered at machine speed, and security teams are still optimizing around outdated assumptions? In this episode of the TPRM Podcast, Threats, Pitfalls & Risk Myths, Nate Lee sits down with Jerry Perullo, former CISO of Intercontinental Exchange, where he spent more than two decades securing critical infrastructure, including the New York Stock Exchange. Jerry is now Founder & CTO of Adversarial, Professor at Georgia Tech, and co-h
In this episode of the TPRM Podcast, Threats, Pitfalls & Risk Myths, Nate Lee sits down with Ayoub Fandi, GRC Engineering Lead at GitLab and creator of the GRC Engineer podcast and newsletter. As AI reshapes how security teams operate, many GRC programs are still built around audits, frameworks, and compliance driven workflows. Ayoub explains why this model is quickly losing relevance and why simply automating existing processes often leads to solving the wrong problems faster. The conversation explores how security teams need to rethink their operating models in an AI driven world. Nate and A
In this episode of the TPRM Podcast, Threats, Pitfalls & Risk Myths, Nate Lee sits down with Michael Coates, Founding Partner at Seven Hill Ventures and former CISO of Twitter, Mozilla, and CoinList. As AI continues to accelerate both attack speed and capability, the gap between attackers and defenders is rapidly shrinking. Michael explains how automated attacks are compressing response times to the point where human driven security models are no longer viable, and why organizations must begin removing humans from critical decision loops. The conversation explores how security teams need to re
In this episode of the TPRM Podcast, Threats, Pitfalls & Risk Myths, Nate Lee sits down with Conor Sherman, CISO in Residence at Sysdig and host of the Zero Signal Podcast. As AI rapidly reshapes the cybersecurity landscape, both attackers and defenders are beginning to automate their operations in ways that were not possible just a few years ago. Conor explains how threat actors are already using AI driven techniques to accelerate attacks and why traditional security operating models are starting to struggle to keep up. The conversation explores how defenders should rethink security strategy
In this episode of the TPRM Podcast, Threats, Pitfalls & Risk Myths, Nate Lee sits down with Jacob DePriest, Chief Information Security Officer at 1Password. As AI adoption accelerates across enterprises, security leaders are facing a new tension. Move too fast, and you increase exposure. Move too slow and teams find their own tools, bypassing controls entirely. Jacob shares how security teams should think about enabling innovation without sacrificing visibility. The conversation explores agent security, auditability challenges, identity and authorization concerns, and why traditional controls
In this episode of the TPRM Podcast, Threats, Pitfalls & Risk Myths, Nate Lee talks with Jake Bernardes, Chief Information Security Officer at Anecdotes and former CISO at Whistic, known for his candid, data-first approach to GRC and third-party risk. Jake brings deep experience across GRC, TPRM, and security leadership, and is an outspoken voice on why traditional compliance frameworks like SOC 2 have become procurement shortcuts rather than meaningful security signals. He shares a pragmatic view on what is broken in modern GRC and what it will take to fix it. They explore what agentic GRC ac
In this episode of the TPRM Podcast — Threats, Pitfalls & Risk Myths — Nate Lee talks with Ross Young, a former CISO and longtime security leader known for his pragmatic, outcome-driven approach to cybersecurity. Ross brings experience from the intelligence community, including over a decade in government service, as well as senior security leadership roles at Capital One and Caterpillar Financial. He’s also the co-host of the CISO Tradecraft podcast and the author of Cybersecurity’s Dirty Secret: Why Most Budgets Go to Waste. They explore why so much security spending fails to meaningfully re
In this episode of the TPRM Podcast, Threats, Pitfalls & Risk Myths, host Nate Lee sits down with Bob Lord, one of the most influential voices in modern cybersecurity. Bob has led security programs at Twitter, Red Hat, Yahoo, Rapid7, and the Democratic National Committee, and later helped shape the Secure by Design initiative for the U.S. government during his time at CISA. Today, he works with policymakers and industry leaders through the Institute for Security and Technology. In this conversation, Bob introduces the concept of Hack Lore, the outdated and misleading security advice that sound
In this episode of the TPRM Podcast — Threats, Pitfalls & Risk Myths — host Nate Lee sits down with Mike Johnson, who led security as CISO at Lyft, Fastly, and now, Rivian, to explore what modern security really looks like at AI speed. Mike has had a front-row seat to the evolution of security — from the early days of SaaS and hyperscale cloud platforms to today’s world of AI-driven attacks, software supply chain risk, and software-defined vehicles. He brings a pragmatic, experience-backed perspective on what actually works when security has to scale fast. They discuss: • Why security question
In this episode of the TPRM Podcast — Threats, Pitfalls & Risk Myths — host Nate Lee sits down with Jason Chan, former VP of Information Security at Netflix, to explore how engineering-led security, paved roads, and guardrails—not gates—reshaped modern cloud security. Jason spent nearly a decade building one of the most influential security programs in tech. His work on paved roads, automation, least privilege, and engineering-aligned controls helped define how today’s high-velocity organizations approach risk, resilience, and scale. They discuss: • What the paved road was originally intended
In this episode of the TPRM Podcast — Threats, Pitfalls & Risk Myths — host Nate Lee sits down with Rinki Sethi, Chief Security and Strategy Officer at Upwind Security, to explore how the runtime era is reshaping the future of cybersecurity. Rinki brings over two decades of experience including being CISO at companies such as Twitter, Rubrik and Bill.com, as well as her work as a board member at multiple companies and co-founder of Lockstep Ventures. Her perspective offers a rare view into where security is headed as data volume explodes and AI-driven systems gain real decision power. They dis
In this episode of the TPRM Podcast — Threats, Pitfalls & Risk Myths — host Nate Lee talks with Aaron Stanley, VP of Security at dbt Labs and former Head of Cybersecurity at Twilio, about what it really takes to scale security without slowing down your teams or your business. Aaron shares his approach to building security programs that keep up with growth — balancing innovation, risk management, and developer velocity. Together, they unpack what “secure by design” actually means in a fast-moving SaaS environment. They discuss: - How to align security goals with business outcomes - The trade-of
In this episode of the TPRM Podcast — Threats, Pitfalls & Risk Myths — host Nate Lee sits down with Alex Rice, Co-Founder and CTO of HackerOne and former Head of Product Security at Facebook, to talk about how transparency can transform the way organizations think about security and trust. Alex shares his journey building the world’s leading vulnerability disclosure platform and why openness, accountability, and community are the future of effective security. They explore: - Why transparency drives better security outcomes - Lessons learned from years of hacker–company collaboration - How to m
In this episode of the TPRM Podcast — Threats, Pitfalls & Risk Myths — host Nate Lee sits down with Andrew Becherer, CISO at Sublime Security, former Datadog CISO and beard afficianado to unpack one of the industry’s biggest misconceptions: the belief that compliance equals security. Andrew shares candid lessons from years leading security programs at high-growth SaaS companies—how to cut through noise, align with business objectives, and build a culture of trust that actually works in practice. They discuss: - The real difference between security and compliance - How to communicate risk in la
In this first episode of the TPRM Podcast — Threats, Pitfalls & Risk Myths — host Nate Lee sits down with Jadee Hanson, CISO at Vanta, to discuss how modern security teams can move beyond point-in-time audits and checkbox compliance. Together, they explore what it really takes to build continuous trust in today’s fast-moving SaaS world — where shared responsibility, vendor transparency, and scalable security programs are no longer optional. Jadee shares her perspective on: - The limits of traditional security questionnaires - Why continuous monitoring builds better partnerships - How security