More The Secure Disclosure episodes

Are Humans the Weakest Link in Security? w/ Sean Juroviesky thumbnail

Are Humans the Weakest Link in Security? w/ Sean Juroviesky

Published 25 Mar 2026

Duration: 00:26:23

Securing organizations requires aligning human-centric workflows and communication with embedded, frictionless security practices, addressing human error through behavior monitoring and training, managing shadow IT/AI via collaboration and inventory, balancing usability with targeted access controls, and fostering proactive security culture through education and storytelling rather than enforcement.

Episode Description

In this episode of the Secure Disclosure Podcast, we dive into the human side of security with Sean Juroviesky. From why people remain the biggest cha...

Overview

The text explores the challenges of integrating security with human behavior, emphasizing that individuals are inherently complex, prone to error, and often struggle to navigate organizational workflows and access requirements. It critiques traditional security approaches that prioritize tools like IAM systems over human-centric strategies, advocating for embedding security seamlessly into daily tasks to reduce friction and prevent shadow IT. Key risks include human error, such as phishing violations or misuse of permissions, which demand tailored solutions like enhanced training, targeted tools, and contextual monitoring for anomalies. The discussion also highlights the importance of balancing strict policies with usability, ensuring security measures are perceived as collaborative rather than adversarial, and fostering a culture where employees view security teams as partners rather than enforcers.

The text further addresses emerging risks from AI and unauthorized software, noting how rapid adoption of shadow applications and AI tools introduces compliance and liability issues. It underscores the need for proactive inventory management, legal agreements with third-party vendors, and targeted access controls to mitigate risks from over-permissioning AI assistants or unvetted tools. Strategies to address these challenges include continuous monitoring through endpoint detection systems, user education, and embedding security into AI workflows without stifling innovation. The discussion also emphasizes the dual potential of AI: while it can streamline tasks and boost efficiency, its riskssuch as autonomous actions by over-privileged AI agentsrequire strict, task-specific permissions and proactive frameworks. Collaboration across departments, including finance and legal teams, is presented as essential for aligning security with compliance goals and shared accountability.

Recent Episodes of The Secure Disclosure

17 Mar 2026 AI Agents Must Have Identity & Access Control w/ Johannes Keienburg

Autonomous AI agents, with transformative productivity potential, pose significant security, accountability, and governance challenges requiring dynamic access controls, human oversight, and industry-wide standards to ensure safe and regulated integration.

16 Mar 2026 The Creator of Curl on Why AI Is Breaking Bug Bounties w/ Daniel Stenberg

The Curl project's evolution from a 1996 currency tool to a prominent open-source library highlights community-driven growth, open-source maintenance challenges, AI's impact on security reporting, sustainability issues, and tensions between innovation and unresolved technical risks.

9 Mar 2026 LLMs Will Never Be Fully Secure w/ Brooks McMillin

Security oversights in AI/MCP server development, mirroring historical flaws like SQL injection, include unsafe practices such as `eval` usage and weak authorization, risking remote code execution and data leaks, while stressing the need for layered defenses against AI-amplified exploits in untested ecosystems.

More The Secure Disclosure episodes