Connecting Cyber Risks to Board Outcomes & BHUSA interviews from Mimecast & Zscaler - BSW #462 @SecurityWeekly
Connecting Cyber Risks to Board Outcomes & BHUSA interviews from Mimecast & Zscaler - BSW #462  @SecurityWeekly
Uploaded August 2026 | Updated September 2026, 2 weeks ago
The threat landscape has become more interconnected, disruptive, and complex. Ransomware is now as much about extortion and data theft as it is about encryption. Supply chain events can create outages that ripple far beyond the initial target, and business interruption increasingly comes from third-party and cloud dependencies. How should CISOs prepare for these scenarios?

Dan Bowden, Global Business CISO at Marsh, joins Business Security Weekly to discuss how to connect cyber risk to the outcomes boards care about most: resilience, financial exposure, regulatory impact, and reputation. CISOs need to position cyber as an enterprise risk, not a technical risk, that can be measured, prioritized, and managed alongside other strategic risks. Dan will discuss the results of Marsh's Cyber Catalyst research and Global Cyber Claims Report.

Visit securityweekly.com/infosecworld2026 and save 30% on your ISW pass with code: ISW26-SWSAVINGS

The Agent Is the New Insider: Why Human Risk Doesn't Stop at People: Black Hat Interview with Leslie Nielson, CISO at Mimecast

AI agents now act with the same credentials and access as the humans who deployed them, but without the judgment or accountability that comes with actual employment. Mimecast CISO Leslie Nielsen argues that treating agentic AI as a brand new, standalone security category is the wrong instinct: agents are an extension of human risk, and the controls organizations already use to manage people are the right foundation for managing machines. In this conversation, Nielsen unpacks the growing gap between security leaders who expect AI driven attacks and those who feel prepared for them, and what that gap means for CISOs walking the floor at Black Hat.

Segment Resources:

Mimecast's new whitepaper Securing The Agentic Enterprise: assets.mimecast.com/api/public/content/securing-the-agentic-enterprise?v=ea66db05
Mimecast's landing page for thought leadership resources: workprotected.com
Mimecast's State of Human Risk Report: mimecast.com/resources/ebooks/state-of-human-risk
Mimecast's Threat Intelligence Hub: mimecast.com/threat-intelligence-hub

For more information about Mimecast please visit: securityweekly.com/mimecastbh

Ransomware Moves up the Org Chart: Managers Are Prime Targets: Black Hat Interview with Brett Stone-Gross, Sr. Director, Threat Intelligence at Zscaler

When a ransomware attack makes headlines, attention usually turns to the organization that was breached, the systems encrypted, data stolen, and disruption or ransom demand that followed. Less, if anything, is revealed about the employees compromised at the start of the attack, and what makes those individuals valuable targets.

New Zscaler ThreatLabz research examines this early stage of a real-world ransomware attack.
ThreatLabz identified victims of a campaign associated with a ransomware group known for gaining initial access, stealing large amounts of corporate data, and selectively encrypting critical systems. The findings show who those victims were and how their roles and authority could help an attacker move deeper into an organization.

This is part of ongoing ransomware research by ThreatLabz. The Zscaler ThreatLabz 2026 Ransomware Report, coming in the next two months, will include additional data on ransomware victims, the latest ransomware trends, targets, and tactics, and the risks enterprises should prepare for next.

This segment is sponsored by Zscaler. Visit securityweekly.com/zscalerbh to learn more about them!

Visit securityweekly.com/bsw for all the latest episodes!

Show Notes: securityweekly.com/bsw-462

00:00:00 Welcome to Business Security Weekly with Dan Bowden
00:02:23 Navigating CISO Struggles and Incident Response Preparedness
00:07:25 Translating Cyber Risk into Business Language and Culture
00:16:07 Understanding Cyber Catalyst and Global Cyber Claims Reports
00:24:05 Shifting Threats, Third-Party Risk, and Dan Bowden's Insights
00:34:48 Understanding the Risks of AI Agents and Shadow AI
00:38:18 Managing Non-Human Identities and Extending Security Controls
00:41:41 Implementing AI Governance and Mimecast's Security Solutions
00:50:22 Analyzing Ransomware's Target: Managers and Key Roles
00:54:33 Countering Evolving Ransomware Social Engineering Tactics
00:59:23 How AI is Shaping Ransomware Attacks and Future Threats
Connecting Cyber Risks to Board Outcomes & BHUSA interviews from Mimecast & Zscaler - BSW #462Randomness, Grey, Deepseek, Sonicwall, Spice, CaptiveCrunch, eBay, and Aaran Leyland  - SWN #604AI Agents Dont Respect Every BoundaryBorg, GitLost, ColdFusion, GodDamn, GhostApproval, OWA, Epaphroditus, Josh Marpet & More - SWN #597What If Ransomware Never Encrypts Anything?You Ruled Yourself Out Too SoonCyberRisk TV Live Coverage from Black Hat 2026 - Day 1Defense Gap in AI Security RaceVoting Works Like AuthenticationDont Overbuild Your AI WorkflowSecurity Teams Must Become EngineersAI Needs an Identity Too
Security Weekly - A CRA Resource |

Connecting Cyber Risks to Board Outcomes & BHUSA interviews from Mimecast & Zscaler - BSW #462

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER