Resilient Cyber podcast

The First OWASP Top 10 Backed by Real Incident Data

14/09/2026
0:00
25:50
Reculer de 15 secondes
Avancer de 15 secondes

Rock Lambros, Co-Lead of the 2026 OWASP Top 10 for LLM Applications, on why prompt injection would have fallen out of the top 10 based on incident data alone, and why the community kept it at number one anyway.

In this episode I sit down with Rock Lambros, longtime security leader, former CISO, core team member of the OWASP GenAI Security Project, and Co-Lead of the 2026 OWASP Top 10 for LLM Applications, to dig into the new list and the harder questions underneath it. We get into the letter from the project leads that opens the document, why the LLM and Agentic lists are converging, what a year of messy incident data actually told the working group, and why Rock argues that agency is not authorization.

In this episode:

  • Why the LLM Top 10 and the Agentic Top 10 are merging in practice
  • The opening letter, and why the industry was slow to admit the model was never the thing to secure
  • Who benefits from a model-centric framing of AI security
  • Prompt injection ranked number one by practitioners and out of the top 10 by the incident data
  • Why incidents get reported by outcome rather than by initial vector
  • Misinformation, the widest gap between the vote and the data
  • Hidden Context Exposure, soft guardrails, and why instructions and data share one context window
  • Context rot and why context window management matters for agents doing critical work
  • Using AI to govern AI, and the dual-layer approach in the Agentic Control Standard
  • Agency versus authorization, and why OAuth is what we have rather than the answer
  • How to get involved in the OWASP GenAI Security Project

Chapters:
 0:00 Intro and Rock's background
 1:17 What the agentic work changed about the LLM Top 10
 3:59 The opening letter and "It Was Never the Model"
 8:48 Incident data and the prompt injection ranking
 11:23 Misinformation and the limits of the data
 14:24 Hidden Context Exposure and soft guardrails
 17:18 The context window and context rot
 19:57 Using AI to govern AI
 22:49 Excessive agency, and agency versus authorization
 27:09 How to get involved with OWASP

Connect with Rock:
LinkedIn: https://www.linkedin.com/in/rocklambros
OWASP GenAI Security Project: https://genai.owasp.org
Get involved: https://genai.owasp.org/contributing
OWASP Top 10 for LLM Applications 2026: https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/

Read my piece on the new list, It Was Never the Model: https://www.resilientcyber.io/p/it-was-never-the-model

Resilient Cyber: https://www.resilientcyber.io

D'autres épisodes de "Resilient Cyber"