More The Secure Disclosure episodes

Are Humans the Weakest Link in Security? w/ Sean Juroviesky thumbnail

Are Humans the Weakest Link in Security? w/ Sean Juroviesky

Published 25 Mar 2026

Duration: 00:26:23

Securing organizations requires aligning human-centric workflows and communication with embedded, frictionless security practices, addressing human error through behavior monitoring and training, managing shadow IT/AI via collaboration and inventory, balancing usability with targeted access controls, and fostering proactive security culture through education and storytelling rather than enforcement.

Episode Description

In this episode of the Secure Disclosure Podcast, we dive into the human side of security with Sean Juroviesky. From why people remain the biggest cha...

Overview

The text explores the challenges of integrating security with human behavior, emphasizing that individuals are inherently complex, prone to error, and often struggle to navigate organizational workflows and access requirements. It critiques traditional security approaches that prioritize tools like IAM systems over human-centric strategies, advocating for embedding security seamlessly into daily tasks to reduce friction and prevent shadow IT. Key risks include human error, such as phishing violations or misuse of permissions, which demand tailored solutions like enhanced training, targeted tools, and contextual monitoring for anomalies. The discussion also highlights the importance of balancing strict policies with usability, ensuring security measures are perceived as collaborative rather than adversarial, and fostering a culture where employees view security teams as partners rather than enforcers.

The text further addresses emerging risks from AI and unauthorized software, noting how rapid adoption of shadow applications and AI tools introduces compliance and liability issues. It underscores the need for proactive inventory management, legal agreements with third-party vendors, and targeted access controls to mitigate risks from over-permissioning AI assistants or unvetted tools. Strategies to address these challenges include continuous monitoring through endpoint detection systems, user education, and embedding security into AI workflows without stifling innovation. The discussion also emphasizes the dual potential of AI: while it can streamline tasks and boost efficiency, its riskssuch as autonomous actions by over-privileged AI agentsrequire strict, task-specific permissions and proactive frameworks. Collaboration across departments, including finance and legal teams, is presented as essential for aligning security with compliance goals and shared accountability.

Recent Episodes of The Secure Disclosure

6 May 2026 AI Panic is Driving Shadow IT w/ Noora Ahmed-Moshe

AI's impact on employment and cybersecurity risks, driven by shadow AI, phishing, and emerging threats like prompt injection, require balancing workforce skills, security measures, and organizational trust.

29 Apr 2026 When AI Agents Change their Intent w/ Frank Vukovits

AI agents, autonomous non-human entities operating in enterprise systems without human oversight, pose security and governance challenges requiring updated access control frameworks, real-time monitoring, and intent-based governance to address risks like unauthorized access and shadow AI, paralleling historical tech challenges like Y2K.

22 Apr 2026 OWASP Top 10, Vibe Coding, and What Developers Miss w/ Tanya Janca

Gaps in cybersecurity education, persistent vulnerabilities like SQL injection, OWASP data limitations, evolving supply chain risks, high training costs, AI's contextual challenges, and the need for secure-by-design principles and collaboration highlight systemic challenges in addressing evolving cyber threats.

15 Apr 2026 The Future of Hacking is Agentic w/ Jason Haddix

Recommended: Security Testing will change, and might change quicker than this episode suggests. Keep Security Top of Mind during Development.

AI transforms security with automated penetration testing and threat detection, but requires human oversight to mitigate risks like prompt injection, ensure ethical use, and balance AI efficiency with creative problem-solving in an evolving threat landscape.

More The Secure Disclosure episodes