Home About Black Hat Contact Essays Fireside Chats My Take News Alerts Q&A Reels RSAC Videocasts ☰
 

Q & A

 

NEW TECH Q&A: Why Data Bill of Materials (DBOM) is surfacing as a crucial tool to secure AI

By Byron V. Acohido

Enterprises hustling to embed AI across their operations came to an uncomfortable realization in 2025: they lost track of the data powering those systems.

Related: The case for SBOM

Few paused to map where sensitive data lived or how it moved. That oversight is now surfacing in audits, breach incidents, and regulatory pressure.

According to field research from Bedrock Security, most IT and security leaders still lack foundational visibility into the datasets fueling training and inference.

“You can’t govern retroactively,” says Bruno Kurtic, co-founder and CEO of Bedrock Data. “You need controls before the model runs, not after.”

Last Watchdog caught up with Kurtic to understand what this shift means in practical terms. Here’s an edited version of that conversation.

SHARED INTEL Q&A: This is how ‘edge AI’ is forcing a rethink of trust, security and resilience

By Byron V. Acohido

A seismic shift in digital systems is underway — and most people are missing it.

Related: Edge AI at the chip layer

While generative AI demos and LLM hype steal the spotlight, enterprise infrastructure is being quietly re-architected, not from the cloud down, but from the silicon up.

As AI use cases move from experimentation to deployment, a new layer of compute is taking shape. Behind the scenes, semiconductor companies like Infineon are already adapting embedded systems and edge architectures to handle persistent inference workloads — AI that must run in real time, in the field, at the device level.

NEW TECH Q&A: Start-up Identient debuts reimagined AI copilots trained on experts’ insights

By Byron V. Acohido

Cybersecurity has always been a moving target. But AI has shifted the center of gravity.

Related: The workflow cadences of Gen AI

Over just the past two years, we’ve watched decision cycles compress, incentive structures change beneath us, and the mechanisms for validating expertise start to break down in real time.

Threat actors are already using AI to scale speed and improvisation. Defensive teams are retooling under pressure. Meanwhile, the advisory layer — analysts, consultants, research channels — has struggled to keep up with risks evolving faster than their traditional frameworks allow.

At Last Watchdog, we’ve noted how even well-established decision models begin to falter once AI-driven ambiguity and tempo are introduced. That’s why I took interest in a new approach from Seattle-based Identient. Led by founder and CEO, Steve Tout, the company is launching what it calls the first marketplace for “verified digital twins”: AI counterparts trained only on authenticated expert material and constrained by provenance and governance.

SHARED INTEL Q&A: API gaps expose AI fault lines — an urgent call for hygiene, active monitoring

By Byron V. Acohido

The race to deploy GenAI far and wide has intensified enterprises’ reliance on APIs — most of which remain poorly understood and underprotected.

Related: Mistaking AI pattern matching for wisdom

This reality is highlighted in a just-released Salt Security survey of 250 security and IT leaders which found nearly half (48%) reporting API security concerns slowing down their organizations’ AI adoption.

It tracks. Generative AI relies on connecting models to internal data and functions — often through complex webs of APIs. But most companies still don’t have full visibility into their APIs, let alone control over how they behave in real time. Shadow APIs, zombie APIs, weak governance — these gaps are translating into AI blockers.

The recent OneLogin breach is a case in point. Attackers used a compromised API key to access internal apps and customer data — and the intrusion went undetected for weeks. Traditional tools like WAFs, gateways, and static scans missed it. They weren’t built to track today’s fast-changing API traffic or catch business logic abuse in production.

Shared Intel Q&A: Viewing CMMC as a blueprint for readiness across the defense supply chain

By Byron V. Acohido

Small and mid-sized contractors play a vital role in the U.S. defense industrial base — but too often, they remain the weakest link in the cybersecurity chain.

Related: Pentagon enforcing CMMC

RADICL’s  2025 DIB Cybersecurity Maturity Report reveals that 85% of these contractors still fall short of basic regulatory standards. And just 3% meet the threshold of “Advanced” maturity.

This is no longer a theoretical problem. With the Cybersecurity Maturity Model Certification (CMMC) 2.0 framework expected to become enforceable as early as November 2025, thousands of SMBs in the defense supply chain face a major inflection point. They’ll either demonstrate compliance — or risk being locked out of federal contracts.

To unpack what this means, Last Watchdog sat down with Chris Petersen, co-founder and CEO of RADICL, the threat-informed Cybersecurity-as-a-service (CSaaS) company behind the annual maturity study. Petersen explains why many firms are still dangerously exposed — and how the smartest ones are rethinking CMMC as a blueprint for long-term resilience.

Critical insights Q&A: Anomali’s AI-native approach helps defenders cut noise, mitigate swiftly

By Byron V. Acohido

The cybersecurity world is deep into an AI pivot.

Related: The case for AI-native SOCs

The headlines fixate on doomsday threats and autonomous cyber weapons. But the real revolution may be happening at a quieter layer: inside the SOC.

Security operations teams are under intense pressure. According to IBM’s 2024 Cost of a Data Breach report, organizations are now storing log and telemetry data across an average of 13 different environments — from cloud services to on-prem tools to third-party SaaS platforms. Meanwhile, the average time to identify and contain a breach remains stuck at 277 days.

Legacy SIEMs (security information and event management systems) were never built for this sprawl. Licensing models penalize data volume, siloed tools create blind spots, and even the best-run SOCs struggle with alert fatigue and staffing gaps. What if the answer isn’t more humans, but smarter automation?

Critical insights Q&A: AcceleTrex pilots a trust-first, privacy-led model to reinforce business outcomes

By Byron V. Acohido

I’ve been writing about data trust and privacy engineering for more than a decade.

Related: Preserving privacy can be profitable

In 2015, I sat down with Cisco’s privacy lead, Michelle Dennedy, who argued that privacy must be grounded in authorized, fair processing — and warned that treating data as cheap exhaust ultimately costs you in breaches, fines, and lost credibility.

But Dennedy didn’t stop at theory. She’s gone on to build and lead — pioneering privacy engineering in practice. She founded PrivacyCode / PrivacyCode.ai, a startup focused on governance, accountability, and AI-aware privacy systems, and later assumed the role of Chief Data Strategy Officer at Abaxx Technologies, where she continues to push the boundaries of trust infrastructure.