#405 - RSM 2026 Attack Vectors Report

#405 - RSM 2026 Attack Vectors Report

Jeff and Jim sit down with David Llorens, principal at RSM, to break down the RSM 2026 Attack Vectors Report. Drawing from real-world offensive security engagements, David explains why identity continues to be the primary attack surface, how AI chatbots are creating new vulnerabilities through prompt injection, and what separates organizations that get breached from those that don't. The conversation covers MFA gaps, the explosion of non-human identities, why PAM is the top investment priority for 2026, and how CISOs can align security spending with business objectives. Plus, the episode wraps up with soccer stories and some quality trash talk.


Connect with David: https://www.linkedin.com/in/david-llorens-009a3310/

Review RSM’s 2026 Attack Vectors Report: https://rsmus.com/insights/services/risk-fraud-cybersecurity/rsm-attack-vector-report.html


Connect with us on LinkedIn:

Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/

Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/

Visit the show on the web at http://idacpodcast.com

TIMESTAMPS0:00 - Intro and Jim's big personal news4:51 - Main topic intro: RSM 2026 Attack Vectors Report5:55 - David's origin story and how he got into cybersecurity9:53 - What a principal is at RSM and David's current role11:16 - What the Attack Vectors Report is and how it is created14:40 - Why identity security is a dominant theme in this year's report17:19 - What separates organizations that get breached from those that don't18:18 - MFA as the first line of defense18:45 - Privileged access management as a growing priority19:40 - Detecting lateral movement through identity anomalies21:00 - Credential rotation as an advanced defensive technique22:26 - Non-human identities and service account risks24:37 - Middle market challenges and budget constraints25:17 - Is it the size of the budget or how you spend it?28:29 - Using internal audit and cross-department collaboration for security wins30:15 - Cybersecurity as a business enabler, not a deterrent32:45 - Non-human identities and agentic AI creating new attack surfaces35:51 - Prompt injection attacks and AI chatbot vulnerabilities39:42 - Actionable recommendations for practitioners42:41 - MFA implementation gaps and session hijacking45:02 - The case for FIDO2 and layered conditional access46:35 - Is identity security a board-level issue?49:47 - Three things CISOs should focus on through 202650:52 - PAM as the top investment priority51:28 - Removing unnecessary privileges from users56:11 - Redefining what privilege means in your organization57:43 - Social media accounts as privileged access58:42 - Credentials stored in SharePoint and OneDrive59:38 - Wrap up and where to find the report59:58 - Lighter topic: David's soccer background and playing semi-pro1:05:06 - Best trash talk stories1:07:03 - Jim's trash talk philosophy: scoreboard1:08:00 - Jeff's basketball trash talk and calling his shots1:10:00 - Final thoughts and sign off

KEYWORDSIDAC, Identity at the Center, Jeff Steadman, Jim McDonald, David Llorens, RSM, attack vectors report, offensive security, penetration testing, identity security, MFA, multifactor authentication, privileged access management, PAM, non-human identities, service accounts, agentic AI, AI security, prompt injection, lateral movement, credential rotation, FIDO2, conditional access, session hijacking, middle market, CISO, board-level security, certificate-based authentication, active directory, configuration management, shadow AI

Det här avsnittet är hämtat från ett öppet RSS-flöde och publiceras inte av Podme. Det kan innehålla reklam.

Avsnitt(443)

#443 - Ghosts in the Machine with John Huyette and Omer Arshed

#443 - Ghosts in the Machine with John Huyette and Omer Arshed

Jeff and Jim are joined by John Huyette, AI Risk Leader at RSM, and Omer Arshed, North American Digital Identity Leader at RSM, to explore how identity controls can help organizations manage the growi...

24 Aug 1h 13min

#442 - Identiverse 2026 - Identity After Dark with Bravura Security

#442 - Identiverse 2026 - Identity After Dark with Bravura Security

Recorded live at Identiverse 2026 in Las Vegas on June 17, Jeff and Jim are joined by Bart Allan, General Manager at Bravura Security, for a live recording with a studio audience. In a late-night talk...

19 Aug 1h 29min

#441 - Identiverse 2026 - Sachini Siriwardene and Ian Glazer

#441 - Identiverse 2026 - Sachini Siriwardene and Ian Glazer

Live from Identiverse 2026 in Las Vegas, Jeff and Jim sit down with Sachini Siriwardene, winner of this year's Kim Cameron Award, along with Ian Glazer of the Digital Identity Advancement Foundation (...

17 Aug 37min

#440 - Identiverse 2026 - Mike Kiser

#440 - Identiverse 2026 - Mike Kiser

Recorded live at Identiverse 2026, Jeff and Jim sit down with returning guest Mike Kiser, Director of Strategy and Standards at SailPoint, for a wide-ranging conversation that spans two of the standar...

10 Aug 52min

#439 - Sponsor Spotlight - Tuebora

#439 - Sponsor Spotlight - Tuebora

This Sponsor Spotlight episode, made possible with support from Tuebora, features Jim McDonald in conversation with Sanjay Nadimpalli, CEO and founder of Tuebora. Sanjay shares his path into identity ...

5 Aug 54min

#438 - Identiverse 2026 - Sean O'Dell

#438 - Identiverse 2026 - Sean O'Dell

Recorded live at Identiverse 2026 in Las Vegas, Jeff sits down with Decoded co-host Sean O'Dell for a wide-ranging state of the union on continuous identity, shared signals, and the identity questions...

3 Aug 39min

#437 - Identiverse 2026 - Pam Dingle

#437 - Identiverse 2026 - Pam Dingle

Live from the IDAC booth at Identiverse 2026, Jeff and Jim sit down with Pam Dingle, Director of Identity Standards at Microsoft, to unpack agentic identity. Pam breaks down assistive versus autonomou...

27 Juli 55min

#436 - Sponsor Spotlight - P0 Security

#436 - Sponsor Spotlight - P0 Security

In this Sponsor Spotlight episode, Jeff Steadman flies solo and welcomes Greg Danyi, co-founder and CTO of P0 Security, to the show. Greg walks through P0's approach to runtime access control, coverin...

22 Juli 46min

Populärt inom Teknik

uppgang-och-fall
market-makers
rss-elektrikerpodden
skogsforum-podcast
natets-morka-sida
rss-laddstationen-med-elbilen-i-sverige
rss-technokratin
 och-bilen-gar-bra
elbilsveckan
rss-en-ai-till-kaffet
bli-saker-podden
klocksnack-tillsammans-med-nymans-ur-1851
rss-veckans-ai
bilar-med-sladd
hej-bruksbil
rss-uppgang-och-fall
rss-kack-tech-podcast
garagehang
rss-fabriken-2
prova-programmering-av-distansakademin