Episode 321 Deep Dive: Graeme Neilson | How the Security Industry Ignores the Halting Problem
KBKAST9 Juli 2025

Episode 321 Deep Dive: Graeme Neilson | How the Security Industry Ignores the Halting Problem

In this episode, we sit down with Graeme Neilson, Founder and Chief Research Officer at Siege, as he unpacks why the security industry often ignores the halting problem—a foundational concept in computer science that explains why software will always contain bugs and vulnerabilities. Graeme challenges the efficacy of awareness training programs, arguing that fundamental flaws in protocols like email and the complexity of software itself, not user behaviour, are the real culprits behind persistent cyber risks. The discussion explores the ongoing frustrations around password management and multifactor authentication, the dangers of concentrating credentials in cloud-based password managers, and the risks introduced by abstracted and AI-generated code. Graeme also emphasises that the true security challenge lies in managing identity—both human and machine—as digital systems become more pervasive and embedded in our daily lives, advocating for a move towards treating cybersecurity issues more like safety concerns in other industries.

Graeme was born in Scotland, learnt cracking, reverse engineering and security from the Internet. Emigrated to NZ in early 2000’s and was one of the founders of Aura Information Security (pen testing company and RedShield (web defence company). He has presented original offensive security research at many international conferences including Blackhat, H2HC, Troopers, Ruxcon and Kiwicon. Now he is head of research for Siege Ltd, an NZ based company specialising in testing denial of service and bot mitigations.

Det här avsnittet är hämtat från ett öppet RSS-flöde och publiceras inte av Podme. Det kan innehålla reklam.

Avsnitt(436)

Episode 383 Deep Dive: Sarah Sloan | It Still Runs, But Can You Defend It? The End-of-Life Tech Reckoning

Episode 383 Deep Dive: Sarah Sloan | It Still Runs, But Can You Defend It? The End-of-Life Tech Reckoning

The tech running hospitals, power grids and government services often still works. Sarah Sloan, Cisco’s Head of Cybersecurity Policy for APAC, joins KB to explain why that’s the problem, not the reass...

3 Sep 38min

Episode 382 Deep Dive: Quinton Anderson | Trust the System, Not the Agent – Zero Trust for the Agentic Enterprise

Episode 382 Deep Dive: Quinton Anderson | Trust the System, Not the Agent – Zero Trust for the Agentic Enterprise

KB sits down with Quinton Anderson, founder of Aigentsphere, to challenge one of the most repeated lines in AI governance: that a human in the loop keeps you safe. His view is that asking people to ap...

26 Aug 49min

Episode 381 Deep Dive: Gijo Varghese | When a Cyber Attack Becomes a Public Safety Failure

Episode 381 Deep Dive: Gijo Varghese | When a Cyber Attack Becomes a Public Safety Failure

Karissa Breen sits down with Gijo Varghese, Chief Security Officer at OT cyber security firm Secolve, to unpack an uncomfortable trade-off: the same connectivity and AI making power, water and transpo...

19 Aug 47min

Episode 380 Deep Dive: Mark Thomas | Owning a Policy PDF Doesn't Mean You Govern Your AI

Episode 380 Deep Dive: Mark Thomas | Owning a Policy PDF Doesn't Mean You Govern Your AI

In this episode, KB sits down with Mark Thomas, IT governance and risk veteran, ISACA Hall of Famer and president of Escoute Consulting, to pull apart a problem a lot of boards haven’t clocked yet – t...

12 Aug 47min

Episode 379 Deep Dive: Sean Duca | Confidence Is Not Permission - Rethinking Authority in the Autonomous SOC

Episode 379 Deep Dive: Sean Duca | Confidence Is Not Permission - Rethinking Authority in the Autonomous SOC

Most security vendors are shipping AI that treats capability as authority. Sean Duca thinks that’s the mistake customers are already paying for. Back on KBKast for a third time, now as co-founder and ...

5 Aug 42min

Episode 378 Deep Dive: Harman Kaur | Automation Isn't Transformation - From Intent to Outcome in Autonomous IT

Episode 378 Deep Dive: Harman Kaur | Automation Isn't Transformation - From Intent to Outcome in Autonomous IT

The old security math is broken. Teams used to get roughly 60 days between a vulnerability going public and attackers using it. Harman Kaur, Tanium’s CTO, explains why that number has flipped to negat...

29 Juli 39min

Episode 377 Deep Dive: Bradon Rogers | The Forgotten Workspace - Why Nobody Ever Secured the Browser

Episode 377 Deep Dive: Bradon Rogers | The Forgotten Workspace - Why Nobody Ever Secured the Browser

Bradon Rogers, Chief Customer Officer at Island, the company that created the enterprise browser category in 2020, joins KB to unpack why the industry spent two decades bolting security around the bro...

22 Juli 39min

From SAP Sapphire - KB On The Go | Legacy Risk and the AI Trust Gap

From SAP Sapphire - KB On The Go | Legacy Risk and the AI Trust Gap

KB is on the ground at SAP Sapphire 2026 in Orlando, where AI has moved beyond experimentation and into the center of enterprise decision making. In this KB On The Go episode, Maura Hameroff (CMO, Clo...

17 Juli 33min

Populärt inom Business & ekonomi

framgangspodden
rss-jossan-nina
varvet
svd-tech-brief
badfluence
uppgang-och-fall
rss-borsens-finest
avanzapodden
rss-inga-dumma-fragor-om-pengar
24fragor
rss-kort-lang-analyspodden-fran-di
bathina-en-podcast
tabberaset
rikatillsammans-om-privatekonomi-rikedom-i-livet
kvalitetsaktiepodden
lastbilspodden
rss-hos-psykologen
rss-sparpodden-2
rss-dagen-med-di
kapitalet-en-podd-om-ekonomi