More The Secure Disclosure episodes

Are Humans the Weakest Link in Security? w/ Sean Juroviesky thumbnail

Are Humans the Weakest Link in Security? w/ Sean Juroviesky

Published 25 Mar 2026

Duration: 00:26:23

Securing organizations requires aligning human-centric workflows and communication with embedded, frictionless security practices, addressing human error through behavior monitoring and training, managing shadow IT/AI via collaboration and inventory, balancing usability with targeted access controls, and fostering proactive security culture through education and storytelling rather than enforcement.

Episode Description

In this episode of the Secure Disclosure Podcast, we dive into the human side of security with Sean Juroviesky. From why people remain the biggest cha...

Overview

The text explores the challenges of integrating security with human behavior, emphasizing that individuals are inherently complex, prone to error, and often struggle to navigate organizational workflows and access requirements. It critiques traditional security approaches that prioritize tools like IAM systems over human-centric strategies, advocating for embedding security seamlessly into daily tasks to reduce friction and prevent shadow IT. Key risks include human error, such as phishing violations or misuse of permissions, which demand tailored solutions like enhanced training, targeted tools, and contextual monitoring for anomalies. The discussion also highlights the importance of balancing strict policies with usability, ensuring security measures are perceived as collaborative rather than adversarial, and fostering a culture where employees view security teams as partners rather than enforcers.

The text further addresses emerging risks from AI and unauthorized software, noting how rapid adoption of shadow applications and AI tools introduces compliance and liability issues. It underscores the need for proactive inventory management, legal agreements with third-party vendors, and targeted access controls to mitigate risks from over-permissioning AI assistants or unvetted tools. Strategies to address these challenges include continuous monitoring through endpoint detection systems, user education, and embedding security into AI workflows without stifling innovation. The discussion also emphasizes the dual potential of AI: while it can streamline tasks and boost efficiency, its riskssuch as autonomous actions by over-privileged AI agentsrequire strict, task-specific permissions and proactive frameworks. Collaboration across departments, including finance and legal teams, is presented as essential for aligning security with compliance goals and shared accountability.

Recent Episodes of The Secure Disclosure

14 Jul 2026 How to Stop Supply Chain Attacks Without Destroying Developer Productivity

"Cybersecurity threats, especially supply chain attacks on developers and open-source packages, demand balanced mitigation strategies, AI-driven security challenges, and early integration of security in development, with collaboration and adaptability key to addressing evolving risks."

1 Jul 2026 Solving the Supply Chain Security & Malware Crisis w/John Amaral

Escalating software supply chain threats target open-source ecosystems through credential exploitation, AI-fueled malware, and upstream compromises, with challenges in dependency management and outdated libraries driving AI-driven remediation strategies like automated patching and version pinning, though human oversight remains critical for validating fixes.

16 Jun 2026 Your Microphone Became a Keylogger w/ David vonThenen

Machine learning analyzes keystroke acoustic signatures to infer typed characters over remote platforms, highlighting high accuracy with known keyboards, privacy risks from surveillance, and challenges in noise and variability, while proposing defenses and noting AI's dual-use implications.

More The Secure Disclosure episodes