Episode Details
Back to Episodes
From ISDN to AI - Two Veterans on How Defence in Depth Has Changed
Description
Defence in depth has evolved every time the technology landscape has shifted. The internet, virtualisation, cloud, SaaS. AI is the next shift, and the old model isn't keeping up.
Welcome to Razorwire, the podcast where we share our take on the world of cybersecurity with direct, practical advice for professionals and business owners alike. I'm Jim and in this episode, I'm joined once again by Martin Voelk, co-founder of SpartanX and an ethical hacker with nearly 26 years in cybersecurity.
Every major technology shift has forced security teams to rethink how they protect their organisations. The internet moved data outside the building. Virtualisation and cloud meant infrastructure was no longer yours to control. Each time, defence in depth had to evolve. AI is the latest shift, and it may be the one that breaks the model entirely.
We trace the journey from on-prem data centres and ISDN routers through to a world where AI agents act autonomously, supply chains are built on unverified code and the offensive side of AI is outpacing the defensive side at a rate security teams can't match. They get into why every AI agent needs its own identity, why shadow AI is a problem most organisations haven't begun to address and why the only realistic answer to AI-powered attacks is AI-powered defence.
Three key talking points:
Defence in depth has always evolved, but this time it's different:
Every previous technology shift gave security teams time to catch up. AI isn't offering that. The pace of change is faster than most organisations can respond to, and the defensive tooling hasn't kept pace with what the offensive side can already do.
AI agents need to be treated like people:
Every AI agent needs its own identity, authentication and authorisation policies. Without that, a compromised agent can act under a human user's name with no way to tell the difference. The legal and forensic implications are enormous and largely unsolved.
The offensive side is winning:
AI is finding vulnerabilities faster than teams can fix them. Alert volumes are overwhelming SOCs, attackers are using AI-generated noise to mask real attacks and human in the loop is becoming unworkable at scale. The only realistic counter is defensive AI, but it isn't mature yet.
Defence in depth has survived every technology shift so far. AI is testing it in ways we haven't seen before. If you're responsible for securing an organisation that's adopting AI, this is the conversation to listen to.
On why security teams are always one step behind:
"We don't have the ability to figure out what's going on until it's already happened. We don't have that technology yet."
James Rees
Listen to this episode on your favourite podcasting platform: https://razorwire.captivate.fm/listen
In this episode, we covered the following topics:
- The Evolution of Defence in Depth
- From ISDN and on-prem data centres to cloud and SaaS, we trace how defence in depth has evolved with every major technology shift.
- Why AI Is Different
- Previous shifts gave security teams time to adapt. We discuss why AI isn't offering that luxury.
- Supply Chain Risk and Unverified Code
- Open source code from GitHub, AI skills downloaded from the web, integrations nobody has reviewed. Discover why the modern supply chain is built on foundations most organisations haven't verified.
- Third Party Risk Management Is Broken
- AI fills in vendor questionnaires and AI revie