<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:media="http://search.yahoo.com/mrss/" xmlns:podcast="https://podcastindex.org/namespace/1.0">
  <channel>
    <atom:link href="https://feeds.simplecast.com/NKmLKfWM" rel="self" title="MP3 Audio" type="application/atom+xml"/>
    <atom:link href="https://simplecast.superfeedr.com" rel="hub" xmlns="http://www.w3.org/2005/Atom"/>
    <generator>https://simplecast.com</generator>
    <title>The Tabletop</title>
    <description>CISOs spend careers preparing for incidents they hope never happen. Here&apos;s what it looks like when one does.

Each episode of The Tabletop puts a security leader into a high-stakes, tabletop exercise—complete with evolving injects, tough tradeoffs, and no idea whether the incident they&apos;re navigating is ripped from the headlines or completely fictional. At the end, they have to guess.

Fast-paced and hosted by Vanta&apos;s Khush Kashyap, The Tabletop is a rare, front-row seat to how the best security minds in the world actually think, prioritize, and make critical decisions under pressure.

It’s part game, part masterclass—designed to entertain, educate, and showcase the real-world complexity of modern security leadership.</description>
    <copyright>2025 Vanta</copyright>
    <language>en</language>
    <pubDate>Wed, 2 Sep 2026 07:00:00 +0000</pubDate>
    <lastBuildDate>Wed, 2 Sep 2026 07:00:21 +0000</lastBuildDate>
    <image>
      <link>https://the-tabletop.simplecast.com</link>
      <title>The Tabletop</title>
      <url>https://image.simplecastcdn.com/images/9af9fba1-837c-4059-ab78-af95721786d7/6d1eb62a-0b05-4df6-8d87-d005b919bb52/3000x3000/vanta-thetabletop-cover.jpg?aid=rss_feed</url>
    </image>
    <link>https://the-tabletop.simplecast.com</link>
    <itunes:type>episodic</itunes:type>
    <itunes:summary>CISOs spend careers preparing for incidents they hope never happen. Here&apos;s what it looks like when one does.

Each episode of The Tabletop puts a security leader into a high-stakes, tabletop exercise—complete with evolving injects, tough tradeoffs, and no idea whether the incident they&apos;re navigating is ripped from the headlines or completely fictional. At the end, they have to guess.

Fast-paced and hosted by Vanta&apos;s Khush Kashyap, The Tabletop is a rare, front-row seat to how the best security minds in the world actually think, prioritize, and make critical decisions under pressure.

It’s part game, part masterclass—designed to entertain, educate, and showcase the real-world complexity of modern security leadership.</itunes:summary>
    <itunes:author>Vanta</itunes:author>
    <itunes:explicit>false</itunes:explicit>
    <itunes:image href="https://image.simplecastcdn.com/images/9af9fba1-837c-4059-ab78-af95721786d7/6d1eb62a-0b05-4df6-8d87-d005b919bb52/3000x3000/vanta-thetabletop-cover.jpg?aid=rss_feed"/>
    <itunes:new-feed-url>https://feeds.simplecast.com/NKmLKfWM</itunes:new-feed-url>
    <itunes:keywords>compliance,cybersecurity,risk management,saas,technology,trust</itunes:keywords>
    <itunes:owner>
      <itunes:name>Vanta</itunes:name>
      <itunes:email>meredith@caspianstudios.com</itunes:email>
    </itunes:owner>
    <itunes:category text="Business"/>
    <itunes:category text="Technology"/>
    <item>
      <guid isPermaLink="false">cf2e3d2e-8f93-4c56-b9af-cface2141c5a</guid>
      <title>Zlatko Unger has 35 minutes to stop AI from obeying poisoned emails (Live Tabletop Exercise)</title>
      <description><![CDATA[<p>You're the CISO at Larkfield Health, a 9,500-person health tech company. A little after 9:00 AM on a Tuesday, your Head of Detection forwards you a message from a security researcher you've never heard of. They say they've found a way to make Wingman—the AI assistant you rolled out company-wide six months ago—hand internal data to an outsider, and that a collection server that isn't theirs is already receiving it. Nothing in your own stack has made a sound. In this episode of The Tabletop, Zlatko Unger takes the hot seat and works the problem in real time.</p>
<p>Zlatko came up through security and compliance, with roles at First Data, Jiff (later acquired by Castlight Health), and Alation, and has spent years helping healthcare organizations navigate HIPAA compliance. He's now a CISO Expert at Wiz.</p>
<p>In this episode, host Khush Kashyap drops Zlatko into the following scenario: he's the CISO at Larkfield Health when a stranger's tip reveals that Wingman has been quietly exfiltrating data. The mechanism is a zero-click prompt injection—an ordinary-looking email, left unread for days, written not for a human but for the AI. When a finance employee asks Wingman a routine question, the assistant's own search finds the poisoned email, reads it as commands, and ships out figures, names, and file contents encoded into the URLs of images that load automatically. Because the traffic went to the vendor's own allow-listed domain, nothing flagged. Then it gets worse: the finance email wasn't the only one. Over nine days, six poisoned emails hit six different inboxes—payroll, employee records, privileged legal files—and because Wingman shipped what it read rather than whole files, there's no defensible list of what left and no way to rule out a seventh.</p>
<p>Zlatko works through activating the incident response plan when the only evidence is a stranger's email, whether to kill a tool the whole company depends on or keep it running behind new guardrails, who actually owns scoping what an AI can reach, and the HIPAA fork in the road when legal wants to write “low probability of compromise” and compliance says no one can sign it—all against a 60-day notification clock and a researcher about to demo the technique on a conference stage in 10 days. At the end, he renders his verdict: real incident or constructed fiction?</p>
<p>Quotes</p>
<p>“This might be a colossal event, or it might be a nothing burger. So the first thing to do is treat it as if it's a colossal event.”</p>
<p>“The educational piece is: don't give overarching permissions to an AI agent that sits outside of the DMZ.”</p>
<p>“One of the assumptions is that access permissions have been solved.”</p>
<p>“This is one of the things where the CISO needs to fall on the sword. Even if a junior analyst wrote it up, it still needs to be signed off, given the impact.”</p>
<p>“We're not in the clear, because somebody's gonna get creative—that prompt injection might come from a different threat vector than email.”</p>
<p>Time Stamps</p>
<p>[00:00] Welcome to The Tabletop: Meet Zlatko Unger, CISO Expert at Wiz</p>
<p>[00:54] The Rules: CISO at Larkfield Health, a 9,500-Person Health Tech Company</p>
<p>[01:23] The Scenario: A Stranger's Tip About Your Company-Wide AI Assistant</p>
<p>[02:06] First Gut Check: Colossal Event or Nothing Burger?</p>
<p>[04:11] Inject One: The Domain Gets Hits and a Finance Email That Wasn't What It Looked Like</p>
<p>[04:59] Zero-Click Exfiltration: How Wingman Shipped Data Out Through Images</p>
<p>[07:33] Would Security Awareness Training Have Stopped This?</p>
<p>[09:19] An Outsider Found It First: What That Tells You</p>
<p>[10:27] The Forced Choice: Kill Wingman Company-Wide or Keep It Running?</p>
<p>[11:48] Guardrails: Scoping Permissions While the Investigation Runs</p>
<p>[13:34] Inject Two: Six Inboxes and No Defensible List of What Left</p>
<p>[16:23] Who Owns Scoping What the AI Can Reach?</p>
<p>[18:45] Someone Chose Those Six: Who Are You Dealing With?</p>
<p>[20:06] The Twist: The Researcher Is Taking It to a Conference Stage</p>
<p>[21:51] Inject Three - Values Tradeoff: Patient Data, HIPAA, and "Low Probability"</p>
<p>[25:15] Whose Name Goes on the Risk Assessment?</p>
<p>[26:46] Three Weeks Later: The Technique Goes Public</p>
<p>[29:02] The Moment of Truth: Real Incident or Fiction?</p>
<p>[29:31] The Reveal: EchoLeak and the First Zero-Click Prompt Injection</p>
<p>[30:37] Off the Table: The AI Assumption Security Teams Should Drop</p>
<p>[32:20] Off the Table: The One Question to Ask Before Approving an AI Tool</p>
<p>Links</p>
<p>Connect with the guest and host on LinkedIn!</p>
<p><a href="https://www.linkedin.com/in/zlatkounger/" rel="noopener noreferrer">Zlatko Unger</a></p>
<p><a href="https://www.linkedin.com/in/khushbookashyap/" rel="noopener noreferrer">Khush Kashyap</a></p>
<p>Learn more about:</p>
<p><a href="https://www.wiz.io/" rel="noopener noreferrer">Wiz</a></p>
<p><a href="https://www.vanta.com/?utm_medium=podcasts&amp;utm_source=tabletop&amp;utm_campaign=fy27q2_podcast_tabletop-ciso-masterclass_global&amp;utm_content=rss-feed&amp;utm_term=episode-5" rel="noopener noreferrer">Vanta</a></p><br/> <p>Hosted by Simplecast, an AdsWizz company. See <a href="https://pcm.adswizz.com">pcm.adswizz.com</a> for information about our collection and use of personal data for advertising.</p>]]></description>
      <pubDate>Wed, 2 Sep 2026 07:00:00 +0000</pubDate>
      <author>meredith@caspianstudios.com (Zlatko Unger, Khush Kashyap)</author>
      <link>https://the-tabletop.simplecast.com/episodes/zlatko-unger-has-35-minutes-to-stop-ai-from-obeying-poisoned-emails-live-tabletop-exercise-LwTfft7x</link>
      <content:encoded><![CDATA[<p>You're the CISO at Larkfield Health, a 9,500-person health tech company. A little after 9:00 AM on a Tuesday, your Head of Detection forwards you a message from a security researcher you've never heard of. They say they've found a way to make Wingman—the AI assistant you rolled out company-wide six months ago—hand internal data to an outsider, and that a collection server that isn't theirs is already receiving it. Nothing in your own stack has made a sound. In this episode of The Tabletop, Zlatko Unger takes the hot seat and works the problem in real time.</p>
<p>Zlatko came up through security and compliance, with roles at First Data, Jiff (later acquired by Castlight Health), and Alation, and has spent years helping healthcare organizations navigate HIPAA compliance. He's now a CISO Expert at Wiz.</p>
<p>In this episode, host Khush Kashyap drops Zlatko into the following scenario: he's the CISO at Larkfield Health when a stranger's tip reveals that Wingman has been quietly exfiltrating data. The mechanism is a zero-click prompt injection—an ordinary-looking email, left unread for days, written not for a human but for the AI. When a finance employee asks Wingman a routine question, the assistant's own search finds the poisoned email, reads it as commands, and ships out figures, names, and file contents encoded into the URLs of images that load automatically. Because the traffic went to the vendor's own allow-listed domain, nothing flagged. Then it gets worse: the finance email wasn't the only one. Over nine days, six poisoned emails hit six different inboxes—payroll, employee records, privileged legal files—and because Wingman shipped what it read rather than whole files, there's no defensible list of what left and no way to rule out a seventh.</p>
<p>Zlatko works through activating the incident response plan when the only evidence is a stranger's email, whether to kill a tool the whole company depends on or keep it running behind new guardrails, who actually owns scoping what an AI can reach, and the HIPAA fork in the road when legal wants to write “low probability of compromise” and compliance says no one can sign it—all against a 60-day notification clock and a researcher about to demo the technique on a conference stage in 10 days. At the end, he renders his verdict: real incident or constructed fiction?</p>
<p>Quotes</p>
<p>“This might be a colossal event, or it might be a nothing burger. So the first thing to do is treat it as if it's a colossal event.”</p>
<p>“The educational piece is: don't give overarching permissions to an AI agent that sits outside of the DMZ.”</p>
<p>“One of the assumptions is that access permissions have been solved.”</p>
<p>“This is one of the things where the CISO needs to fall on the sword. Even if a junior analyst wrote it up, it still needs to be signed off, given the impact.”</p>
<p>“We're not in the clear, because somebody's gonna get creative—that prompt injection might come from a different threat vector than email.”</p>
<p>Time Stamps</p>
<p>[00:00] Welcome to The Tabletop: Meet Zlatko Unger, CISO Expert at Wiz</p>
<p>[00:54] The Rules: CISO at Larkfield Health, a 9,500-Person Health Tech Company</p>
<p>[01:23] The Scenario: A Stranger's Tip About Your Company-Wide AI Assistant</p>
<p>[02:06] First Gut Check: Colossal Event or Nothing Burger?</p>
<p>[04:11] Inject One: The Domain Gets Hits and a Finance Email That Wasn't What It Looked Like</p>
<p>[04:59] Zero-Click Exfiltration: How Wingman Shipped Data Out Through Images</p>
<p>[07:33] Would Security Awareness Training Have Stopped This?</p>
<p>[09:19] An Outsider Found It First: What That Tells You</p>
<p>[10:27] The Forced Choice: Kill Wingman Company-Wide or Keep It Running?</p>
<p>[11:48] Guardrails: Scoping Permissions While the Investigation Runs</p>
<p>[13:34] Inject Two: Six Inboxes and No Defensible List of What Left</p>
<p>[16:23] Who Owns Scoping What the AI Can Reach?</p>
<p>[18:45] Someone Chose Those Six: Who Are You Dealing With?</p>
<p>[20:06] The Twist: The Researcher Is Taking It to a Conference Stage</p>
<p>[21:51] Inject Three - Values Tradeoff: Patient Data, HIPAA, and "Low Probability"</p>
<p>[25:15] Whose Name Goes on the Risk Assessment?</p>
<p>[26:46] Three Weeks Later: The Technique Goes Public</p>
<p>[29:02] The Moment of Truth: Real Incident or Fiction?</p>
<p>[29:31] The Reveal: EchoLeak and the First Zero-Click Prompt Injection</p>
<p>[30:37] Off the Table: The AI Assumption Security Teams Should Drop</p>
<p>[32:20] Off the Table: The One Question to Ask Before Approving an AI Tool</p>
<p>Links</p>
<p>Connect with the guest and host on LinkedIn!</p>
<p><a href="https://www.linkedin.com/in/zlatkounger/" rel="noopener noreferrer">Zlatko Unger</a></p>
<p><a href="https://www.linkedin.com/in/khushbookashyap/" rel="noopener noreferrer">Khush Kashyap</a></p>
<p>Learn more about:</p>
<p><a href="https://www.wiz.io/" rel="noopener noreferrer">Wiz</a></p>
<p><a href="https://www.vanta.com/?utm_medium=podcasts&amp;utm_source=tabletop&amp;utm_campaign=fy27q2_podcast_tabletop-ciso-masterclass_global&amp;utm_content=rss-feed&amp;utm_term=episode-5" rel="noopener noreferrer">Vanta</a></p><br/> <p>Hosted by Simplecast, an AdsWizz company. See <a href="https://pcm.adswizz.com">pcm.adswizz.com</a> for information about our collection and use of personal data for advertising.</p>]]></content:encoded>
      <enclosure length="31428948" type="audio/mpeg" url="https://afp-922686-injected.calisto.simplecastaudio.com/d84c0e76-9762-4026-a72b-28f5db7658a7/episodes/5eafa46e-510c-4c75-897d-b4999cb373d4/audio/128/default.mp3?aid=rss_feed&amp;awCollectionId=d84c0e76-9762-4026-a72b-28f5db7658a7&amp;awEpisodeId=5eafa46e-510c-4c75-897d-b4999cb373d4&amp;feed=NKmLKfWM"/>
      <itunes:title>Zlatko Unger has 35 minutes to stop AI from obeying poisoned emails (Live Tabletop Exercise)</itunes:title>
      <itunes:author>Zlatko Unger, Khush Kashyap</itunes:author>
      <itunes:duration>00:32:44</itunes:duration>
      <itunes:summary>In this episode of The Tabletop, Zlatko Unger takes the hot seat, roleplaying as CISO at Larkfield Health, a fictional 9,500-person health tech company. A little after 9:00 AM on a Tuesday, his Head of Detection forwards him a message from a security researcher he&apos;s never heard of. They say they&apos;ve found a way to make Wingman—the AI assistant rolled out company-wide six months ago—hand internal data to an outsider, and that a collection server that isn&apos;t theirs is already receiving it. Nothing in his own stack has made a sound. </itunes:summary>
      <itunes:subtitle>In this episode of The Tabletop, Zlatko Unger takes the hot seat, roleplaying as CISO at Larkfield Health, a fictional 9,500-person health tech company. A little after 9:00 AM on a Tuesday, his Head of Detection forwards him a message from a security researcher he&apos;s never heard of. They say they&apos;ve found a way to make Wingman—the AI assistant rolled out company-wide six months ago—hand internal data to an outsider, and that a collection server that isn&apos;t theirs is already receiving it. Nothing in his own stack has made a sound. </itunes:subtitle>
      <itunes:keywords>technology, b2b, saas, ciso, cybersecurity, security, tech</itunes:keywords>
      <itunes:explicit>false</itunes:explicit>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>5</itunes:episode>
    </item>
    <item>
      <guid isPermaLink="false">560871da-fcea-408d-9236-7783470723df</guid>
      <title>Will Bengtson has 25 minutes to decide if his best engineer is a thief (Live Tabletop Exercise)</title>
      <description><![CDATA[<p>You're the CISO at Cendril, a 500-person AI-native company moving fast. Your principal engineer—a beloved early employee—is walking out the door for the last time on Friday. But at 5:12 PM Friday afternoon, your DLP fires: 14 gigabytes just left his laptop for a personal Dropbox. In this episode of The Tabletop, Will Bengtson takes the hot seat and works the problem in real time.</p>
<p>Will has spent his career at the intersection of security and engineering. He built and secured cloud infrastructure at Netflix and Capital One, led platform and security engineering at HashiCorp, and taught cybersecurity as a lecturer at UT El Paso. He's now CISO at C1 (ConductorOne), the AI-native identity platform.</p>
<p>In this episode, host Khush Kashyap drops Will into the following scenario: He's the CISO at Cendril when a departing star engineer, Jordan Reeves, transfers 14 GB to a personal Dropbox in the final 40 minutes of his last day. The files aren't random—architecture specs for Project Helix, a feature still six months from a stealth launch; internal QA test suites; and a customer segmentation model the data team built over 18 months. Jordan's access was still live, his laptop wasn't wiped, and HR didn't formally terminate his account until 5:30 PM, a full 18 minutes after the alert fired.</p>
<p>Then the picture sharpens. Six weeks later, a direct competitor—Ascendant AI—ships a feature that maps almost exactly to Project Helix, down to two edge-case decisions Cendril's engineers made in internal design reviews. A patent surfaces that predates Jordan's notice, muddying the water, and soon after, Jordan's LinkedIn lists him as a principal engineer at Ascendant. </p>
<p>Will walks through cutting access that SSO alone doesn't actually cut, the gap that lets offboarding lag behind risk, whether to go loud with a preservation demand or go quiet and image the laptop first, how to manage a furious VP of product and a CEO who says "I don't care if we win—I care that every engineer sees that we fight," and what the evidence really supports versus what everyone wants it to say. At the end, he renders his verdict: real incident or constructed fiction?</p>
<p><strong>Quotes</strong></p>
<p>“I don't know why people wait until the last day or the last two weeks to start taking the data if they're gonna take it all at once.”</p>
<p>“The biggest mistake is thinking that by cutting their single sign-on, that it cuts all access.”</p>
<p>“Why don't we put the energy into making the product better—and prove that Jordan wasn't the secret sauce that got us to where we are today?”</p>
<p>“Look, were these your best ideas? Can we do better? I'd hate for something like this to really poison the culture.”</p>
<p>“The scenarios where we think, ‘oh, this is gonna be a nothing burger,' have been the ones where customers are like, ‘What? How did you not tell us?'”</p>
<p><strong>Time Stamps</strong></p>
<p>[00:00] Welcome to The Tabletop: Meet Will Bengtson, CISO at C1</p>
<p>[00:47] The Rules: You Are Now the CISO at Cendril, a 500-Person AI-Native Company</p>
<p>[01:20] The Scenario: A Model Engineer's Last Day and a 5:12 PM DLP Alert</p>
<p>[02:00] First Gut Check: “This Sounds All Too Familiar”</p>
<p>[03:15] Inject One - The Full Log: 14 GB, Three Sensitive Folders, Access Still Live</p>
<p>[03:50] Your Next Hour: Cutting the Access That SSO Doesn't Actually Cut</p>
<p>[04:50] The 18-Minute Gap and the Case for Phased Offboarding</p>
<p>[07:00] Do You Contact Jordan? Relationships vs. Legal Exposure</p>
<p>[08:50] Go Loud or Go Quiet: A Preservation Demand vs. Imaging the Laptop</p>
<p>[10:15] Inject Two - Six Weeks Later: A Competitor Ships Your Stealth Feature</p>
<p>[11:00] The Patent Twist: Filed Before Jordan Ever Gave Notice</p>
<p>[13:30] What Evidence Do You Actually Have? Building the Civil Case</p>
<p>[14:50] Calming the VP of Product Down from Going Nuclear on LinkedIn</p>
<p>[15:50] Inject Three - Values Tradeoff: Jordan Resurfaces at Ascendant AI</p>
<p>[16:40] Three Legal Paths and Why He Chooses to Slow the Roll</p>
<p>[17:20] The CEO's Real Motive: “I Care That Every Engineer Sees That We Fight”</p>
<p>[18:50] Three Months Later: The Retrospective and the Culture Question</p>
<p>[20:45] The Moment of Truth: Real Incident or Fiction?</p>
<p>[21:30] Off the Table: The Biggest Mistake Companies Make Offboarding Trusted Employees</p>
<p>[22:25] Off the Table: Building a Security Culture That Trusts People and Still Protects What Matters</p>
<p>[23:50] Off the Table: The Strangest “Nothing Burger” That Blew Up</p>
<p><strong>Links</strong></p>
<p>Connect with the guest and host on LinkedIn!</p>
<p><a href="https://www.linkedin.com/in/william-bengtson/" rel="noopener noreferrer">Will Bengtson</a></p>
<p><a href="https://www.linkedin.com/in/khushbookashyap/" rel="noopener noreferrer">Khush Kashyap</a></p>
<p>Learn more about:</p>
<p><a href="https://www.c1.ai/" rel="noopener noreferrer">C1</a></p>
<p><a href="https://www.vanta.com?utm_medium=podcasts&utm_source=tabletop&utm_campaign=fy27q2_podcast_tabletop-ciso-masterclass_global&utm_content=rss-feed&utm_term=episode-4" rel="noopener noreferrer">Vanta</a></p><br/> <p>Hosted by Simplecast, an AdsWizz company. See <a href="https://pcm.adswizz.com">pcm.adswizz.com</a> for information about our collection and use of personal data for advertising.</p>]]></description>
      <pubDate>Wed, 19 Aug 2026 07:00:00 +0000</pubDate>
      <author>meredith@caspianstudios.com (Will Bengtson, Khush Kashyap)</author>
      <link>https://the-tabletop.simplecast.com/episodes/will-bengtson-has-25-minutes-to-decide-if-his-best-engineer-is-a-thief-live-tabletop-exercise-3ZGeJ2Ni</link>
      <content:encoded><![CDATA[<p>You're the CISO at Cendril, a 500-person AI-native company moving fast. Your principal engineer—a beloved early employee—is walking out the door for the last time on Friday. But at 5:12 PM Friday afternoon, your DLP fires: 14 gigabytes just left his laptop for a personal Dropbox. In this episode of The Tabletop, Will Bengtson takes the hot seat and works the problem in real time.</p>
<p>Will has spent his career at the intersection of security and engineering. He built and secured cloud infrastructure at Netflix and Capital One, led platform and security engineering at HashiCorp, and taught cybersecurity as a lecturer at UT El Paso. He's now CISO at C1 (ConductorOne), the AI-native identity platform.</p>
<p>In this episode, host Khush Kashyap drops Will into the following scenario: He's the CISO at Cendril when a departing star engineer, Jordan Reeves, transfers 14 GB to a personal Dropbox in the final 40 minutes of his last day. The files aren't random—architecture specs for Project Helix, a feature still six months from a stealth launch; internal QA test suites; and a customer segmentation model the data team built over 18 months. Jordan's access was still live, his laptop wasn't wiped, and HR didn't formally terminate his account until 5:30 PM, a full 18 minutes after the alert fired.</p>
<p>Then the picture sharpens. Six weeks later, a direct competitor—Ascendant AI—ships a feature that maps almost exactly to Project Helix, down to two edge-case decisions Cendril's engineers made in internal design reviews. A patent surfaces that predates Jordan's notice, muddying the water, and soon after, Jordan's LinkedIn lists him as a principal engineer at Ascendant. </p>
<p>Will walks through cutting access that SSO alone doesn't actually cut, the gap that lets offboarding lag behind risk, whether to go loud with a preservation demand or go quiet and image the laptop first, how to manage a furious VP of product and a CEO who says "I don't care if we win—I care that every engineer sees that we fight," and what the evidence really supports versus what everyone wants it to say. At the end, he renders his verdict: real incident or constructed fiction?</p>
<p><strong>Quotes</strong></p>
<p>“I don't know why people wait until the last day or the last two weeks to start taking the data if they're gonna take it all at once.”</p>
<p>“The biggest mistake is thinking that by cutting their single sign-on, that it cuts all access.”</p>
<p>“Why don't we put the energy into making the product better—and prove that Jordan wasn't the secret sauce that got us to where we are today?”</p>
<p>“Look, were these your best ideas? Can we do better? I'd hate for something like this to really poison the culture.”</p>
<p>“The scenarios where we think, ‘oh, this is gonna be a nothing burger,' have been the ones where customers are like, ‘What? How did you not tell us?'”</p>
<p><strong>Time Stamps</strong></p>
<p>[00:00] Welcome to The Tabletop: Meet Will Bengtson, CISO at C1</p>
<p>[00:47] The Rules: You Are Now the CISO at Cendril, a 500-Person AI-Native Company</p>
<p>[01:20] The Scenario: A Model Engineer's Last Day and a 5:12 PM DLP Alert</p>
<p>[02:00] First Gut Check: “This Sounds All Too Familiar”</p>
<p>[03:15] Inject One - The Full Log: 14 GB, Three Sensitive Folders, Access Still Live</p>
<p>[03:50] Your Next Hour: Cutting the Access That SSO Doesn't Actually Cut</p>
<p>[04:50] The 18-Minute Gap and the Case for Phased Offboarding</p>
<p>[07:00] Do You Contact Jordan? Relationships vs. Legal Exposure</p>
<p>[08:50] Go Loud or Go Quiet: A Preservation Demand vs. Imaging the Laptop</p>
<p>[10:15] Inject Two - Six Weeks Later: A Competitor Ships Your Stealth Feature</p>
<p>[11:00] The Patent Twist: Filed Before Jordan Ever Gave Notice</p>
<p>[13:30] What Evidence Do You Actually Have? Building the Civil Case</p>
<p>[14:50] Calming the VP of Product Down from Going Nuclear on LinkedIn</p>
<p>[15:50] Inject Three - Values Tradeoff: Jordan Resurfaces at Ascendant AI</p>
<p>[16:40] Three Legal Paths and Why He Chooses to Slow the Roll</p>
<p>[17:20] The CEO's Real Motive: “I Care That Every Engineer Sees That We Fight”</p>
<p>[18:50] Three Months Later: The Retrospective and the Culture Question</p>
<p>[20:45] The Moment of Truth: Real Incident or Fiction?</p>
<p>[21:30] Off the Table: The Biggest Mistake Companies Make Offboarding Trusted Employees</p>
<p>[22:25] Off the Table: Building a Security Culture That Trusts People and Still Protects What Matters</p>
<p>[23:50] Off the Table: The Strangest “Nothing Burger” That Blew Up</p>
<p><strong>Links</strong></p>
<p>Connect with the guest and host on LinkedIn!</p>
<p><a href="https://www.linkedin.com/in/william-bengtson/" rel="noopener noreferrer">Will Bengtson</a></p>
<p><a href="https://www.linkedin.com/in/khushbookashyap/" rel="noopener noreferrer">Khush Kashyap</a></p>
<p>Learn more about:</p>
<p><a href="https://www.c1.ai/" rel="noopener noreferrer">C1</a></p>
<p><a href="https://www.vanta.com?utm_medium=podcasts&utm_source=tabletop&utm_campaign=fy27q2_podcast_tabletop-ciso-masterclass_global&utm_content=rss-feed&utm_term=episode-4" rel="noopener noreferrer">Vanta</a></p><br/> <p>Hosted by Simplecast, an AdsWizz company. See <a href="https://pcm.adswizz.com">pcm.adswizz.com</a> for information about our collection and use of personal data for advertising.</p>]]></content:encoded>
      <enclosure length="24844053" type="audio/mpeg" url="https://afp-922686-injected.calisto.simplecastaudio.com/d84c0e76-9762-4026-a72b-28f5db7658a7/episodes/3d0f2226-6d85-49b9-b98c-87bb7c4d314b/audio/128/default.mp3?aid=rss_feed&amp;awCollectionId=d84c0e76-9762-4026-a72b-28f5db7658a7&amp;awEpisodeId=3d0f2226-6d85-49b9-b98c-87bb7c4d314b&amp;feed=NKmLKfWM"/>
      <itunes:title>Will Bengtson has 25 minutes to decide if his best engineer is a thief (Live Tabletop Exercise)</itunes:title>
      <itunes:author>Will Bengtson, Khush Kashyap</itunes:author>
      <itunes:duration>00:25:52</itunes:duration>
      <itunes:summary>In this episode, host Khush Kashyap drops Will Bengtson into the following scenario: He&apos;s the CISO at Cendril when a departing star engineer, Jordan Reeves, transfers 14 GB to a personal Dropbox in the final 40 minutes of his last day. The files aren&apos;t random—architecture specs for Project Helix, a feature still six months from a stealth launch; internal QA test suites; and a customer segmentation model the data team built over 18 months.</itunes:summary>
      <itunes:subtitle>In this episode, host Khush Kashyap drops Will Bengtson into the following scenario: He&apos;s the CISO at Cendril when a departing star engineer, Jordan Reeves, transfers 14 GB to a personal Dropbox in the final 40 minutes of his last day. The files aren&apos;t random—architecture specs for Project Helix, a feature still six months from a stealth launch; internal QA test suites; and a customer segmentation model the data team built over 18 months.</itunes:subtitle>
      <itunes:keywords>technology, data, b2b, breach, saas, compliance, analytics, cybersecurity, security, tech, business, hacker</itunes:keywords>
      <itunes:explicit>false</itunes:explicit>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>4</itunes:episode>
    </item>
    <item>
      <guid isPermaLink="false">4e0f19c0-f6c5-4bf8-a2d8-9cb72ab7ea9d</guid>
      <title>Sean Cassidy has 25 minutes to figure out who&apos;s really inside the power grid (Live Tabletop Exercise)</title>
      <description><![CDATA[<p>You’re a CISO at “It’s Electric,” and you get an interesting call. A local power plant operator just watched his computer mouse move on its own…should he be worried? In this episode of The Tabletop, Sean Cassidy takes the hot seat and works the problem in real time.</p>
<p>Sean is an engineer who became a security leader. He started as a software engineer building firewalls at Cisco, co-founded the security company DefenseStorm, led information security at Patreon, and spent nearly seven years building the security function at Asana. He recently landed at Plaid, a company sitting at the intersection of consumers, financial institutions, and increasingly AI agents making financial decisions on their own. </p>
<p>In this episode, host Khush Kashyap drops Sean into the following scenario: He is roleplaying the CISO at It’s Electric, a 10,000-employee utility serving customers across the country. Mid-morning on a Tuesday, a floor operator named Mike calls. His mouse started moving on its own, and by the time he grabbed the keyboard, someone had already been inside the plant’s control system and changed the configuration—changes that, left unchecked, could have cascaded into a wider power outage. </p>
<p>Mike caught it manually. Then the logs widen the picture: not one compromised workstation, but three. They all trace back to a remote-access tool tied to a third-party vendor service account that was installed four years ago, never deprovisioned even though the contract expired 18 months ago, and now logging in from an IP address outside the US. Then a name surfaces: a former employee terminated six months ago whose shared credential still works.</p>
<p>Sean walks through scoping an OT incident with EDR and laptop forensics, why general counsel is his very first call, holding two theories at once (external actor versus insider) rather than betting early, when to pull in law enforcement, what belongs in a public holding statement, and the NERC CIP compliance exposure sitting underneath it all. Along the way, he makes the case that the real failure happened long before the incident, in the vendor and employee offboarding that nobody owns. At the end, he renders his verdict: real incident or constructed fiction?</p>
<p><strong>Quotes</strong></p>
<p>“This is where my mind goes from, ‘It could just be a Mike problem,’ to, oh, no, this is a real security incident.”</p>
<p>“General counsel is always my partner in crime. Or not crime - partner in doing it right.”</p>
<p>“When you’re terminating a relationship, nothing breaks if you don’t do anything. You don’t notice.”</p>
<p>“Usually it’s no one’s job to make sure vendors are turned off.”</p>
<p>“IT playbooks are really good for common events. A mouse moving on its own? That’s not in the playbook.”</p>
<p><strong>Time Stamps</strong></p>
<p>[00:00] Welcome to The Tabletop: Meet Sean Cassidy, CISO at Plaid</p>
<p>[00:18] The Rules: CISO at It's Electric, a 10,000-Person Utility</p>
<p>[00:56] The Scenario: A Mouse Moves on Its Own at a Power Station</p>
<p>[01:18] Inject One - Technical Escalation: Not One Workstation, but Three</p>
<p>[03:13] Your Next 10 Minutes: Scoping the Incident and Paging Responders</p>
<p>[03:59] Why User Reports Take a Back Seat to Forensics</p>
<p>[06:09] The First Call: General Counsel Before the CEO</p>
<p>[06:59] Inject Two - Human and Reputational Pressure: A Dead Vendor Account and a Foreign IP</p>
<p>[08:11] Four Years Undiscovered: The Board Conversation You Should Have Had Sooner</p>
<p>[08:53] Nation-State or Not: How Much to Say Before Attribution</p>
<p>[10:05] The Compliance Clock: NERC CIP Supply Chain and Remote Access</p>
<p>[11:00] The Twist: Your General Counsel Is Unreachable</p>
<p>[12:04] Inject Three - Values Tradeoff: A Former Employee's Name Surfaces</p>
<p>[12:48] Telling the CEO: Outside Attack or Inside Job?</p>
<p>[14:02] Law Enforcement Timing: The Cost of Moving Too Early or Too Late</p>
<p>[16:02] What Goes in the Public Holding Statement</p>
<p>[17:23] Three Weeks Later: CISA, ISAC, and the NERC Reporting Threshold</p>
<p>[19:11] The Moment of Truth: Real Incident or Fiction?</p>
<p>[20:49] Off the Table: Why Vendor Access Never Gets Cleaned Up, the OT Playbook Gap, and the Database That Vanished</p>
<p><strong>Links</strong></p>
<p>Connect with the guest and host on LinkedIn!</p>
<ul>
 <li><a href="https://www.linkedin.com/in/seanacassidy" rel="noopener noreferrer">Sean Cassidy</a></li>
 <li><a href="https://www.linkedin.com/in/khushbookashyap/" rel="noopener noreferrer">Khush Kashyap</a></li>
</ul>
<p>Learn more about:</p>
<ul>
 <li><a href="https://plaid.com/" rel="noopener noreferrer">Plaid</a></li>
 <li><a href="https://www.vanta.com?utm_medium=podcasts&utm_source=tabletop&utm_campaign=fy27q2_podcast_tabletop-ciso-masterclass_global&utm_content=rss-feed&utm_term=episode-3" rel="noopener noreferrer">Vanta</a></li>
</ul><br/> <p>Hosted by Simplecast, an AdsWizz company. See <a href="https://pcm.adswizz.com">pcm.adswizz.com</a> for information about our collection and use of personal data for advertising.</p>]]></description>
      <pubDate>Wed, 5 Aug 2026 07:00:00 +0000</pubDate>
      <author>meredith@caspianstudios.com (Sean Cassidy, Khush Kashyap)</author>
      <link>https://the-tabletop.simplecast.com/episodes/sean-cassidy-has-25-minutes-to-figure-out-whos-really-inside-the-power-grid-live-tabletop-exercise-qs6NLX4V</link>
      <content:encoded><![CDATA[<p>You’re a CISO at “It’s Electric,” and you get an interesting call. A local power plant operator just watched his computer mouse move on its own…should he be worried? In this episode of The Tabletop, Sean Cassidy takes the hot seat and works the problem in real time.</p>
<p>Sean is an engineer who became a security leader. He started as a software engineer building firewalls at Cisco, co-founded the security company DefenseStorm, led information security at Patreon, and spent nearly seven years building the security function at Asana. He recently landed at Plaid, a company sitting at the intersection of consumers, financial institutions, and increasingly AI agents making financial decisions on their own. </p>
<p>In this episode, host Khush Kashyap drops Sean into the following scenario: He is roleplaying the CISO at It’s Electric, a 10,000-employee utility serving customers across the country. Mid-morning on a Tuesday, a floor operator named Mike calls. His mouse started moving on its own, and by the time he grabbed the keyboard, someone had already been inside the plant’s control system and changed the configuration—changes that, left unchecked, could have cascaded into a wider power outage. </p>
<p>Mike caught it manually. Then the logs widen the picture: not one compromised workstation, but three. They all trace back to a remote-access tool tied to a third-party vendor service account that was installed four years ago, never deprovisioned even though the contract expired 18 months ago, and now logging in from an IP address outside the US. Then a name surfaces: a former employee terminated six months ago whose shared credential still works.</p>
<p>Sean walks through scoping an OT incident with EDR and laptop forensics, why general counsel is his very first call, holding two theories at once (external actor versus insider) rather than betting early, when to pull in law enforcement, what belongs in a public holding statement, and the NERC CIP compliance exposure sitting underneath it all. Along the way, he makes the case that the real failure happened long before the incident, in the vendor and employee offboarding that nobody owns. At the end, he renders his verdict: real incident or constructed fiction?</p>
<p><strong>Quotes</strong></p>
<p>“This is where my mind goes from, ‘It could just be a Mike problem,’ to, oh, no, this is a real security incident.”</p>
<p>“General counsel is always my partner in crime. Or not crime - partner in doing it right.”</p>
<p>“When you’re terminating a relationship, nothing breaks if you don’t do anything. You don’t notice.”</p>
<p>“Usually it’s no one’s job to make sure vendors are turned off.”</p>
<p>“IT playbooks are really good for common events. A mouse moving on its own? That’s not in the playbook.”</p>
<p><strong>Time Stamps</strong></p>
<p>[00:00] Welcome to The Tabletop: Meet Sean Cassidy, CISO at Plaid</p>
<p>[00:18] The Rules: CISO at It's Electric, a 10,000-Person Utility</p>
<p>[00:56] The Scenario: A Mouse Moves on Its Own at a Power Station</p>
<p>[01:18] Inject One - Technical Escalation: Not One Workstation, but Three</p>
<p>[03:13] Your Next 10 Minutes: Scoping the Incident and Paging Responders</p>
<p>[03:59] Why User Reports Take a Back Seat to Forensics</p>
<p>[06:09] The First Call: General Counsel Before the CEO</p>
<p>[06:59] Inject Two - Human and Reputational Pressure: A Dead Vendor Account and a Foreign IP</p>
<p>[08:11] Four Years Undiscovered: The Board Conversation You Should Have Had Sooner</p>
<p>[08:53] Nation-State or Not: How Much to Say Before Attribution</p>
<p>[10:05] The Compliance Clock: NERC CIP Supply Chain and Remote Access</p>
<p>[11:00] The Twist: Your General Counsel Is Unreachable</p>
<p>[12:04] Inject Three - Values Tradeoff: A Former Employee's Name Surfaces</p>
<p>[12:48] Telling the CEO: Outside Attack or Inside Job?</p>
<p>[14:02] Law Enforcement Timing: The Cost of Moving Too Early or Too Late</p>
<p>[16:02] What Goes in the Public Holding Statement</p>
<p>[17:23] Three Weeks Later: CISA, ISAC, and the NERC Reporting Threshold</p>
<p>[19:11] The Moment of Truth: Real Incident or Fiction?</p>
<p>[20:49] Off the Table: Why Vendor Access Never Gets Cleaned Up, the OT Playbook Gap, and the Database That Vanished</p>
<p><strong>Links</strong></p>
<p>Connect with the guest and host on LinkedIn!</p>
<ul>
 <li><a href="https://www.linkedin.com/in/seanacassidy" rel="noopener noreferrer">Sean Cassidy</a></li>
 <li><a href="https://www.linkedin.com/in/khushbookashyap/" rel="noopener noreferrer">Khush Kashyap</a></li>
</ul>
<p>Learn more about:</p>
<ul>
 <li><a href="https://plaid.com/" rel="noopener noreferrer">Plaid</a></li>
 <li><a href="https://www.vanta.com?utm_medium=podcasts&utm_source=tabletop&utm_campaign=fy27q2_podcast_tabletop-ciso-masterclass_global&utm_content=rss-feed&utm_term=episode-3" rel="noopener noreferrer">Vanta</a></li>
</ul><br/> <p>Hosted by Simplecast, an AdsWizz company. See <a href="https://pcm.adswizz.com">pcm.adswizz.com</a> for information about our collection and use of personal data for advertising.</p>]]></content:encoded>
      <enclosure length="24500862" type="audio/mpeg" url="https://afp-922686-injected.calisto.simplecastaudio.com/d84c0e76-9762-4026-a72b-28f5db7658a7/episodes/c05458f0-69d3-4ba1-b924-c11d2160cccf/audio/128/default.mp3?aid=rss_feed&amp;awCollectionId=d84c0e76-9762-4026-a72b-28f5db7658a7&amp;awEpisodeId=c05458f0-69d3-4ba1-b924-c11d2160cccf&amp;feed=NKmLKfWM"/>
      <itunes:title>Sean Cassidy has 25 minutes to figure out who&apos;s really inside the power grid (Live Tabletop Exercise)</itunes:title>
      <itunes:author>Sean Cassidy, Khush Kashyap</itunes:author>
      <itunes:duration>00:25:31</itunes:duration>
      <itunes:summary>In this episode, host Khush Kashyap drops Plaid CISO Sean Cassidy into the following scenario: He is roleplaying the CISO at It’s Electric, a 10,000-employee utility serving customers across the country. Mid-morning on a Tuesday, a floor operator named Mike calls. His mouse started moving on its own, and by the time he grabbed the keyboard, someone had already been inside the plant’s control system and changed the configuration—changes that, left unchecked, could have cascaded into a wider power outage. 
</itunes:summary>
      <itunes:subtitle>In this episode, host Khush Kashyap drops Plaid CISO Sean Cassidy into the following scenario: He is roleplaying the CISO at It’s Electric, a 10,000-employee utility serving customers across the country. Mid-morning on a Tuesday, a floor operator named Mike calls. His mouse started moving on its own, and by the time he grabbed the keyboard, someone had already been inside the plant’s control system and changed the configuration—changes that, left unchecked, could have cascaded into a wider power outage. 
</itunes:subtitle>
      <itunes:keywords>technology, data, b2b, saas, compliance, threat, cybersecurity, security</itunes:keywords>
      <itunes:explicit>false</itunes:explicit>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>3</itunes:episode>
    </item>
    <item>
      <guid isPermaLink="false">bcbd78d0-a9b2-4c62-829c-d3aa9ad50d6e</guid>
      <title>Jason Chan has 26 minutes to shut down a hacker hidden in plain sight (Live Tabletop Exercise)</title>
      <description><![CDATA[<p>What do you do when an attacker doesn’t break into your network, but simply walks in by turning your own multi-factor authentication against you? In this episode of The Tabletop, Jason Chan takes the hot seat and works the problem in real time.</p>
<p>Jason spent over a decade building and leading Netflix’s information security team, an organization that became as well known for giving back to the security community as it was for protecting one of the world’s most-watched platforms: 30-plus open source releases, a long run of conference talks, and a genuine belief that a rising tide lifts all boats. Before Netflix, he ran security at VMware and cut his teeth in consulting. If anyone knows what a real incident looks like from the inside, it’s him.</p>
<p>In this episode, host Khush Kashyap drops Jason into the following scenario: He’s roleplaying the CISO at Clustrd, a 30,000-person tech company with a 107-person security team. Mid-afternoon on a Thursday, a marketing employee sends him a screenshot. Someone has posted in a company-wide Slack channel, 800 members strong, claiming they have access to Clustrd’s internal systems, with a shot of the admin dashboard as proof. The monitoring stack shows zero alerts. The access logs tell a different story: a contractor account, logged in through a legitimate remote-access tool, session still live. The way in wasn’t an exploit or malware, just an attacker spamming the contractor with MFA prompts until fatigue did the rest. Across escalating injects, the intruder moves laterally through a forgotten production script with hard-coded credentials and no owner, and Jason has to scope a breach he cannot fully see.</p>
<p>Jason walks through out-of-band communications when your own Slack is compromised, the cost-benefit of watching a live intruder versus cutting the session, the security archeology of tracing an unowned script, and the quiet regulatory risk of logs that were never retained. Along the way, he makes the case that the real work - the trust with engineering, the identity hygiene, the discipline not to overload users until they reflexively click approve - happens long before the incident does. At the end, he renders his verdict: real incident or constructed fiction?</p>
<p><strong>Quotes</strong></p>
<p>“The adversary used essentially legitimate, authorized access to do unauthorized things.”</p>
<p>“Sometimes our security controls get used against us.”</p>
<p>“Archeology is part of our jobs, figuring out what this thing does.”</p>
<p>“If you can limit the number of systems somebody can access, you’re going to almost by definition control the blast radius before anything happens.”</p>
<p><strong>Time Stamps</strong></p>
<p>[00:00] Welcome to The Tabletop: Meet Jason Chan and Today's Scenario</p>
<p>[01:01] The Rules: CISO at Clustrd, a 30,000-Person Company with a 107-Person Security Team</p>
<p>[01:31] Inject One: A Slack Post Claims Access to Clustrd's Internal Systems</p>
<p>[03:07] They Didn't Break In, They Walked In: MFA Fatigue and the Contractor Account</p>
<p>[07:56] The Attacker Wants You to Know: Going Public in Your Own Slack</p>
<p>[08:40] Forced Choice: Coordinating a Response When Slack Is Compromised</p>
<p>[08:40] Building a War Room You Can Actually Trust</p>
<p>[09:53] Inject Two: A Forgotten Production Script with Hard-Coded Credentials</p>
<p>[10:06] Two Fires at Once: A Live Session and an Unknown Blast Radius</p>
<p>[14:23] Inject Three: A Reporter Calls and the Clock Goes Public</p>
<p>[15:19] Scoping a Breach Without Evidence: Four Services You Can't Account For</p>
<p>[16:40] Accessed or Compromised? Why the Distinction Matters</p>
<p>[20:02] Two Weeks Later: The One Decision That Set Clustrd on This Path</p>
<p>[20:46] The Moment of Truth: Real Incident or Fiction?</p>
<p>[21:18] Off the Table: The Control Employees Treat as a Formality</p>
<p>[23:13] The Lesson the Industry Still Hasn't Absorbed</p>
<p>[25:28] Security for AI, AI for Security: What Jason Watches Now</p>
<p><strong>Links</strong></p>
<p>Connect with the guest and host on LinkedIn!</p>
<ul>
 <li><a href="https://www.linkedin.com/in/jasonbchan/" rel="noopener noreferrer">Jason Chan</a></li>
 <li><a href="https://www.linkedin.com/in/khushbookashyap/" rel="noopener noreferrer">Khush Kashyap</a></li>
</ul>
<p>Learn more about:</p>
<ul>
 <li><a href="https://www.vanta.com?utm_medium=podcasts&utm_source=tabletop&utm_campaign=fy27q2_podcast_tabletop-ciso-masterclass_global&utm_content=youtube&utm_term=episode-2" rel="noopener noreferrer">Vanta</a></li>
</ul><br/> <p>Hosted by Simplecast, an AdsWizz company. See <a href="https://pcm.adswizz.com">pcm.adswizz.com</a> for information about our collection and use of personal data for advertising.</p>]]></description>
      <pubDate>Wed, 22 Jul 2026 07:00:00 +0000</pubDate>
      <author>meredith@caspianstudios.com (Jason Chan, Khush Kashyap)</author>
      <link>https://the-tabletop.simplecast.com/episodes/jason-chan-has-26-minutes-to-shut-down-a-hacker-hidden-in-plain-sight-live-tabletop-exercise-jdzgXZDz</link>
      <content:encoded><![CDATA[<p>What do you do when an attacker doesn’t break into your network, but simply walks in by turning your own multi-factor authentication against you? In this episode of The Tabletop, Jason Chan takes the hot seat and works the problem in real time.</p>
<p>Jason spent over a decade building and leading Netflix’s information security team, an organization that became as well known for giving back to the security community as it was for protecting one of the world’s most-watched platforms: 30-plus open source releases, a long run of conference talks, and a genuine belief that a rising tide lifts all boats. Before Netflix, he ran security at VMware and cut his teeth in consulting. If anyone knows what a real incident looks like from the inside, it’s him.</p>
<p>In this episode, host Khush Kashyap drops Jason into the following scenario: He’s roleplaying the CISO at Clustrd, a 30,000-person tech company with a 107-person security team. Mid-afternoon on a Thursday, a marketing employee sends him a screenshot. Someone has posted in a company-wide Slack channel, 800 members strong, claiming they have access to Clustrd’s internal systems, with a shot of the admin dashboard as proof. The monitoring stack shows zero alerts. The access logs tell a different story: a contractor account, logged in through a legitimate remote-access tool, session still live. The way in wasn’t an exploit or malware, just an attacker spamming the contractor with MFA prompts until fatigue did the rest. Across escalating injects, the intruder moves laterally through a forgotten production script with hard-coded credentials and no owner, and Jason has to scope a breach he cannot fully see.</p>
<p>Jason walks through out-of-band communications when your own Slack is compromised, the cost-benefit of watching a live intruder versus cutting the session, the security archeology of tracing an unowned script, and the quiet regulatory risk of logs that were never retained. Along the way, he makes the case that the real work - the trust with engineering, the identity hygiene, the discipline not to overload users until they reflexively click approve - happens long before the incident does. At the end, he renders his verdict: real incident or constructed fiction?</p>
<p><strong>Quotes</strong></p>
<p>“The adversary used essentially legitimate, authorized access to do unauthorized things.”</p>
<p>“Sometimes our security controls get used against us.”</p>
<p>“Archeology is part of our jobs, figuring out what this thing does.”</p>
<p>“If you can limit the number of systems somebody can access, you’re going to almost by definition control the blast radius before anything happens.”</p>
<p><strong>Time Stamps</strong></p>
<p>[00:00] Welcome to The Tabletop: Meet Jason Chan and Today's Scenario</p>
<p>[01:01] The Rules: CISO at Clustrd, a 30,000-Person Company with a 107-Person Security Team</p>
<p>[01:31] Inject One: A Slack Post Claims Access to Clustrd's Internal Systems</p>
<p>[03:07] They Didn't Break In, They Walked In: MFA Fatigue and the Contractor Account</p>
<p>[07:56] The Attacker Wants You to Know: Going Public in Your Own Slack</p>
<p>[08:40] Forced Choice: Coordinating a Response When Slack Is Compromised</p>
<p>[08:40] Building a War Room You Can Actually Trust</p>
<p>[09:53] Inject Two: A Forgotten Production Script with Hard-Coded Credentials</p>
<p>[10:06] Two Fires at Once: A Live Session and an Unknown Blast Radius</p>
<p>[14:23] Inject Three: A Reporter Calls and the Clock Goes Public</p>
<p>[15:19] Scoping a Breach Without Evidence: Four Services You Can't Account For</p>
<p>[16:40] Accessed or Compromised? Why the Distinction Matters</p>
<p>[20:02] Two Weeks Later: The One Decision That Set Clustrd on This Path</p>
<p>[20:46] The Moment of Truth: Real Incident or Fiction?</p>
<p>[21:18] Off the Table: The Control Employees Treat as a Formality</p>
<p>[23:13] The Lesson the Industry Still Hasn't Absorbed</p>
<p>[25:28] Security for AI, AI for Security: What Jason Watches Now</p>
<p><strong>Links</strong></p>
<p>Connect with the guest and host on LinkedIn!</p>
<ul>
 <li><a href="https://www.linkedin.com/in/jasonbchan/" rel="noopener noreferrer">Jason Chan</a></li>
 <li><a href="https://www.linkedin.com/in/khushbookashyap/" rel="noopener noreferrer">Khush Kashyap</a></li>
</ul>
<p>Learn more about:</p>
<ul>
 <li><a href="https://www.vanta.com?utm_medium=podcasts&utm_source=tabletop&utm_campaign=fy27q2_podcast_tabletop-ciso-masterclass_global&utm_content=youtube&utm_term=episode-2" rel="noopener noreferrer">Vanta</a></li>
</ul><br/> <p>Hosted by Simplecast, an AdsWizz company. See <a href="https://pcm.adswizz.com">pcm.adswizz.com</a> for information about our collection and use of personal data for advertising.</p>]]></content:encoded>
      <enclosure length="24487060" type="audio/mpeg" url="https://afp-922686-injected.calisto.simplecastaudio.com/d84c0e76-9762-4026-a72b-28f5db7658a7/episodes/a55a6e8f-4e70-42f8-b06d-03e53d7b54d1/audio/128/default.mp3?aid=rss_feed&amp;awCollectionId=d84c0e76-9762-4026-a72b-28f5db7658a7&amp;awEpisodeId=a55a6e8f-4e70-42f8-b06d-03e53d7b54d1&amp;feed=NKmLKfWM"/>
      <itunes:title>Jason Chan has 26 minutes to shut down a hacker hidden in plain sight (Live Tabletop Exercise)</itunes:title>
      <itunes:author>Jason Chan, Khush Kashyap</itunes:author>
      <itunes:duration>00:25:30</itunes:duration>
      <itunes:summary>In this episode, host Khush Kashyap drops Jason Chan, former VP of Information Security at Netflix, into the following scenario: He’s roleplaying the CISO at Clustrd, a 30,000-person tech company with a 107-person security team. Mid-afternoon on a Thursday, a marketing employee sends him a screenshot. Someone has posted in a company-wide Slack channel, 800 members strong, claiming they have access to Clustrd’s internal systems, with a shot of the admin dashboard as proof. The monitoring stack shows zero alerts. The access logs tell a different story: a contractor account, logged in through a legitimate remote-access tool, session still live. The way in wasn’t an exploit or malware, just an attacker spamming the contractor with MFA prompts until fatigue did the rest. Across escalating injects, the intruder moves laterally through a forgotten production script with hard-coded credentials and no owner, and Jason has to scope a breach he cannot fully see.</itunes:summary>
      <itunes:subtitle>In this episode, host Khush Kashyap drops Jason Chan, former VP of Information Security at Netflix, into the following scenario: He’s roleplaying the CISO at Clustrd, a 30,000-person tech company with a 107-person security team. Mid-afternoon on a Thursday, a marketing employee sends him a screenshot. Someone has posted in a company-wide Slack channel, 800 members strong, claiming they have access to Clustrd’s internal systems, with a shot of the admin dashboard as proof. The monitoring stack shows zero alerts. The access logs tell a different story: a contractor account, logged in through a legitimate remote-access tool, session still live. The way in wasn’t an exploit or malware, just an attacker spamming the contractor with MFA prompts until fatigue did the rest. Across escalating injects, the intruder moves laterally through a forgotten production script with hard-coded credentials and no owner, and Jason has to scope a breach he cannot fully see.</itunes:subtitle>
      <itunes:keywords>netflix, technology, information technology, data, b2b, saas, analytics, cybersecurity, security</itunes:keywords>
      <itunes:explicit>false</itunes:explicit>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>2</itunes:episode>
    </item>
    <item>
      <guid isPermaLink="false">17f8f08d-ef3e-44ac-a5fe-f6e0f9fe0100</guid>
      <title>Alex Stamos has 23 minutes to stop an AI chatbot leaking data (Live Tabletop Exercise)</title>
      <description><![CDATA[<p>What does a security leader actually do when an AI chatbot starts confidently revealing customer data that was never supposed to see the light of day? In the debut episode of The Tabletop, Alex Stamos takes the hot seat and shows us in real time.</p>
<p>Alex has spent his career at the intersection of security and the hardest problems in tech—Chief Security Officer at Yahoo, Facebook, and SentinelOne, founder of the Stanford Internet Observatory, and now Chief Product Officer at Corridor, a startup focused on the security and safety of AI coding agents. If anyone knows what it looks like when AI ships faster than security can keep up, it’s him.</p>
<p>In this episode, host Khush Kashyap drops Alex into a fictional scenario: He’s roleplaying the CISO at Buzzmatrix, a fictional 400-person AI SaaS company with a lean security team and no in-house incident response. Late on a Friday, the VP of Marketing pushes a new AI chatbot live without security review. By Monday, customers are posting screenshots of the bot serving up order histories, account details, and support summaries—some real-looking, some hallucinated. Across a series of escalating injects, Alex has to decide what to take down, who to wake up, when to bring in legal, and what he owes customers.</p>
<p>Alex walks through engaging outside counsel, the GDPR clock, forensic vendor management, and the leverage a CISO actually holds over an uncooperative vendor. Along the way, he makes the case that the existential threat in most incidents isn’t the lawsuit, it’s the erosion of customer trust. At the end, he renders his verdict: real incident or constructed fiction?</p>
<p><strong>Quotes</strong></p>
<p>“CISOs are all L, no P in the P&L, right? We don’t make any money. We just lose it.”</p>
<p>“You can turn what was a small mistake into a huge scandal if you end up putting out a statement that you have to retract.”</p>
<p>“The litigation risk is almost never existential. What is existential is the trust of your customers.”</p>
<p>“If those models have access to all customer data, and then you tell them in a prompt—only give Sally Sally’s data—you’re toast, because they are not built to be able to do that access control.”</p>
<p><strong>Time Stamps</strong></p>
<p>[00:00]  “Our lawyers will destroy you guys in court”</p>
<p>[00:46]  Welcome to The Tabletop: Meet Alex Stamos and Today’s Scenario</p>
<p>[01:06]  Setup: CISO at BuzzMetrics, a 400-Person AI SaaS Company</p>
<p>[01:24]  The Friday Launch: Marketing Ships an AI Chatbot Without Review</p>
<p>[02:11]  Inject One: The Screenshots: Real and Hallucinated Customer Data</p>
<p>[03:57]  Pull It Down or Assess First? Triaging the Marketing Bot</p>
<p>[04:27]  Inject Two: The Conversation: Customers Claim the Data Is Theirs</p>
<p>[05:03]  Why You Don’t Post Before Legal Signs Off</p>
<p>[07:10]  Do You Owe a Response When the Data Is Fictional?</p>
<p>[07:48]  Inject Three: The Training Set: Real Tickets, No Scrub, No Consent</p>
<p>[08:14]  Now It’s a Real Breach: Outside Counsel, Regulators, and the GDPR Clock</p>
<p>[10:52]  When Does the Investigation Itself Become a Liability?</p>
<p>[11:47]  Forensics Inside the Vendor and the Hugging Face Nightmare</p>
<p>[12:51]  Vendor Leverage: “You guys are showing up in our write-up”</p>
<p>[14:55]  Over-Legalization: Why Lawyers Shouldn’t Drive Incident Decisions</p>
<p>[15:29]  Litigation Risk vs. the Existential Risk of Lost Trust</p>
<p>[16:43]  Root Cause: Launch Calendars, Data Controls, and a Culture Not Paranoid Enough</p>
<p>[20:03]  The Wake-Up Call: Staffing a Product Security Team After an Incident</p>
<p>[20:15]  The Moment of Truth: Real Incident or Fiction?</p>
<p>[21:16]  Off the Table: The One Question to Ask Before AI Touches Customer Data</p>
<p>[21:32]  The Privilege Differential and Why You Can’t Trust AI Access Control</p>
<p><strong>Links</strong></p>
<p>Connect with the guest and host on LinkedIn!</p>
<ul>
 <li><a href="https://www.linkedin.com/in/alexstamos/" rel="noopener noreferrer">Alex Stamos</a></li>
 <li><a href="https://www.linkedin.com/in/khushbookashyap/" rel="noopener noreferrer">Khush Kashyap</a></li>
</ul>
<p>Learn more about:</p>
<ul>
 <li><a href="https://www.corridor.dev/" rel="noopener noreferrer">Corridor</a></li>
 <li><a href="https://pit.stanford.edu/university-organizations/internet-observatory/" rel="noopener noreferrer">Stanford Internet Observatory</a></li>
 <li><a href="https://www.vanta.com/" rel="noopener noreferrer">Vanta</a></li>
</ul>
<p>The Tabletop is by Vanta, the leading Agentic Trust Platform helping security leaders manage compliance, reduce risk, and prove their programs work—before the incident, not after. Learn more about Vanta: <a href="https://bit.ly/4y2XTQo" target="_blank" rel="noopener noreferrer">https://bit.ly/4y2XTQo</a>.</p><br/> <p>Hosted by Simplecast, an AdsWizz company. See <a href="https://pcm.adswizz.com">pcm.adswizz.com</a> for information about our collection and use of personal data for advertising.</p>]]></description>
      <pubDate>Wed, 1 Jul 2026 07:00:00 +0000</pubDate>
      <author>meredith@caspianstudios.com (Alex Stamos, Khush Kashyap)</author>
      <link>https://the-tabletop.simplecast.com/episodes/the-hallucinating-bot-with-alex-stamos-cpo-at-corridor-5RzGcxGg</link>
      <content:encoded><![CDATA[<p>What does a security leader actually do when an AI chatbot starts confidently revealing customer data that was never supposed to see the light of day? In the debut episode of The Tabletop, Alex Stamos takes the hot seat and shows us in real time.</p>
<p>Alex has spent his career at the intersection of security and the hardest problems in tech—Chief Security Officer at Yahoo, Facebook, and SentinelOne, founder of the Stanford Internet Observatory, and now Chief Product Officer at Corridor, a startup focused on the security and safety of AI coding agents. If anyone knows what it looks like when AI ships faster than security can keep up, it’s him.</p>
<p>In this episode, host Khush Kashyap drops Alex into a fictional scenario: He’s roleplaying the CISO at Buzzmatrix, a fictional 400-person AI SaaS company with a lean security team and no in-house incident response. Late on a Friday, the VP of Marketing pushes a new AI chatbot live without security review. By Monday, customers are posting screenshots of the bot serving up order histories, account details, and support summaries—some real-looking, some hallucinated. Across a series of escalating injects, Alex has to decide what to take down, who to wake up, when to bring in legal, and what he owes customers.</p>
<p>Alex walks through engaging outside counsel, the GDPR clock, forensic vendor management, and the leverage a CISO actually holds over an uncooperative vendor. Along the way, he makes the case that the existential threat in most incidents isn’t the lawsuit, it’s the erosion of customer trust. At the end, he renders his verdict: real incident or constructed fiction?</p>
<p><strong>Quotes</strong></p>
<p>“CISOs are all L, no P in the P&L, right? We don’t make any money. We just lose it.”</p>
<p>“You can turn what was a small mistake into a huge scandal if you end up putting out a statement that you have to retract.”</p>
<p>“The litigation risk is almost never existential. What is existential is the trust of your customers.”</p>
<p>“If those models have access to all customer data, and then you tell them in a prompt—only give Sally Sally’s data—you’re toast, because they are not built to be able to do that access control.”</p>
<p><strong>Time Stamps</strong></p>
<p>[00:00]  “Our lawyers will destroy you guys in court”</p>
<p>[00:46]  Welcome to The Tabletop: Meet Alex Stamos and Today’s Scenario</p>
<p>[01:06]  Setup: CISO at BuzzMetrics, a 400-Person AI SaaS Company</p>
<p>[01:24]  The Friday Launch: Marketing Ships an AI Chatbot Without Review</p>
<p>[02:11]  Inject One: The Screenshots: Real and Hallucinated Customer Data</p>
<p>[03:57]  Pull It Down or Assess First? Triaging the Marketing Bot</p>
<p>[04:27]  Inject Two: The Conversation: Customers Claim the Data Is Theirs</p>
<p>[05:03]  Why You Don’t Post Before Legal Signs Off</p>
<p>[07:10]  Do You Owe a Response When the Data Is Fictional?</p>
<p>[07:48]  Inject Three: The Training Set: Real Tickets, No Scrub, No Consent</p>
<p>[08:14]  Now It’s a Real Breach: Outside Counsel, Regulators, and the GDPR Clock</p>
<p>[10:52]  When Does the Investigation Itself Become a Liability?</p>
<p>[11:47]  Forensics Inside the Vendor and the Hugging Face Nightmare</p>
<p>[12:51]  Vendor Leverage: “You guys are showing up in our write-up”</p>
<p>[14:55]  Over-Legalization: Why Lawyers Shouldn’t Drive Incident Decisions</p>
<p>[15:29]  Litigation Risk vs. the Existential Risk of Lost Trust</p>
<p>[16:43]  Root Cause: Launch Calendars, Data Controls, and a Culture Not Paranoid Enough</p>
<p>[20:03]  The Wake-Up Call: Staffing a Product Security Team After an Incident</p>
<p>[20:15]  The Moment of Truth: Real Incident or Fiction?</p>
<p>[21:16]  Off the Table: The One Question to Ask Before AI Touches Customer Data</p>
<p>[21:32]  The Privilege Differential and Why You Can’t Trust AI Access Control</p>
<p><strong>Links</strong></p>
<p>Connect with the guest and host on LinkedIn!</p>
<ul>
 <li><a href="https://www.linkedin.com/in/alexstamos/" rel="noopener noreferrer">Alex Stamos</a></li>
 <li><a href="https://www.linkedin.com/in/khushbookashyap/" rel="noopener noreferrer">Khush Kashyap</a></li>
</ul>
<p>Learn more about:</p>
<ul>
 <li><a href="https://www.corridor.dev/" rel="noopener noreferrer">Corridor</a></li>
 <li><a href="https://pit.stanford.edu/university-organizations/internet-observatory/" rel="noopener noreferrer">Stanford Internet Observatory</a></li>
 <li><a href="https://www.vanta.com/" rel="noopener noreferrer">Vanta</a></li>
</ul>
<p>The Tabletop is by Vanta, the leading Agentic Trust Platform helping security leaders manage compliance, reduce risk, and prove their programs work—before the incident, not after. Learn more about Vanta: <a href="https://bit.ly/4y2XTQo" target="_blank" rel="noopener noreferrer">https://bit.ly/4y2XTQo</a>.</p><br/> <p>Hosted by Simplecast, an AdsWizz company. See <a href="https://pcm.adswizz.com">pcm.adswizz.com</a> for information about our collection and use of personal data for advertising.</p>]]></content:encoded>
      <enclosure length="22570309" type="audio/mpeg" url="https://afp-922686-injected.calisto.simplecastaudio.com/d84c0e76-9762-4026-a72b-28f5db7658a7/episodes/98069a63-74bd-46b1-8f86-6446be8e8039/audio/128/default.mp3?aid=rss_feed&amp;awCollectionId=d84c0e76-9762-4026-a72b-28f5db7658a7&amp;awEpisodeId=98069a63-74bd-46b1-8f86-6446be8e8039&amp;feed=NKmLKfWM"/>
      <itunes:title>Alex Stamos has 23 minutes to stop an AI chatbot leaking data (Live Tabletop Exercise)</itunes:title>
      <itunes:author>Alex Stamos, Khush Kashyap</itunes:author>
      <itunes:duration>00:23:30</itunes:duration>
      <itunes:summary>In this episode, host Khush Kashyap drops Alex Stamos, Chief Product Officer at Corridor, into a fictional scenario: He’s roleplaying the CISO at Buzzmatrix, a fictional 400-person AI SaaS company with a lean security team and no in-house incident response. Late on a Friday, the VP of Marketing pushes a new AI chatbot live without security review. By Monday, customers are posting screenshots of the bot serving up order histories, account details, and support summaries—some real-looking, some hallucinated. Across a series of escalating injects, Alex has to decide what to take down, who to wake up, when to bring in legal, and what he owes customers.</itunes:summary>
      <itunes:subtitle>In this episode, host Khush Kashyap drops Alex Stamos, Chief Product Officer at Corridor, into a fictional scenario: He’s roleplaying the CISO at Buzzmatrix, a fictional 400-person AI SaaS company with a lean security team and no in-house incident response. Late on a Friday, the VP of Marketing pushes a new AI chatbot live without security review. By Monday, customers are posting screenshots of the bot serving up order histories, account details, and support summaries—some real-looking, some hallucinated. Across a series of escalating injects, Alex has to decide what to take down, who to wake up, when to bring in legal, and what he owes customers.</itunes:subtitle>
      <itunes:keywords>tabletop, technology, b2b, saas, ciso, cybersecurity, security</itunes:keywords>
      <itunes:explicit>false</itunes:explicit>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>1</itunes:episode>
    </item>
  </channel>
</rss>