Tech Talks Daily podcast

Security Posture at Machine Speed With Barracuda

0:00
23:14
Manda indietro di 15 secondi
Manda avanti di 15 secondi

What happens when attackers can discover and exploit a weakness faster than your organization can patch it?

Recorded at Barracuda TechSummit 2026 in Alpbach, Austria, this conversation features Arve Kjoelen, CISO at Barracuda. Arve is responsible for protecting Barracuda's systems, environment, and code, which makes him the person answering the familiar question of who checks the checker.

Our conversation begins with the collapse in response time. Security teams once had hours or days to investigate suspicious activity. Arve explains why they may now have minutes or seconds, while vulnerabilities can move from disclosure to exploitation within days. Traditional weekly scans and handoffs to patching teams struggle when attackers operate at machine speed.

Arve offers a useful framework for understanding security posture through threats, exposures, assets, and controls. Technology changes constantly, but these categories give leaders a way to assess risk without chasing every new term. He also explains why reducing attack surface can begin with basic questions. Does a system need to be accessible from the internet? Does a web server also need remote management exposed? Does a midsize business benefit from spreading its workloads across every major cloud provider?

We examine the difficult balance surrounding AI adoption. Blocking every new tool can prevent employees from benefiting from useful technology, but allowing unrestricted adoption creates new exposure. Arve argues for deliberate choices and guidance that reduce risk without stopping progress.

The conversation also addresses AI-guided remediation. Barracuda uses AI internally to identify vulnerabilities, but Arve is cautious about fully automated fixes. An AI system may identify a problem and suggest a solution, while a human remains responsible for judging whether the proposed action could damage a production environment. Faster decisions are valuable only when organizations understand the consequences.

Arve also considers how entry-level technology roles may change as AI performs more coding and analysis. His view is that people will need to understand how to work with AI, evaluate its output, and carry an idea from design through secure implementation. The role changes, but the demand for human judgment remains.

We finish with model sovereignty, data trust, and provider dependency. If a security capability relies on one AI model, leaders need to know whether they can move to an alternative if access, performance, pricing, or policy changes. Arve also explains why Barracuda is preparing to support both open and closed models while the market develops.
Where should your organization use AI to accelerate defense, and which security decisions should remain firmly under human control? Listen to the full conversation and share your thoughts with me.

Altri episodi di "Tech Talks Daily"