David Bombal

#566: Stop buying AI security tools until you watch this

Mar 25, 2026
Danny Jenkins, a cybersecurity practitioner at ThreatLocker focused on application control and zero trust, cuts through AI hype. He warns against treating AI as a cure and talks about agentic AI risks, treating agents like users, mixing AI with rule-based controls, and pragmatic steps like default-deny app control, closing open ports, and restricting cloud app access.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

AI Is Not The Security Silver Bullet

  • AI is not a magic cure for cybersecurity problems and won't replace fundamental controls.
  • Danny Jenkins shows that despite AI availability, cybercrime has increased, proving controls matter more than hype.
INSIGHT

AI Can Explain Code But Not Intent

  • AI can analyze code and speed SOC work but cannot determine software intent reliably.
  • Jenkins uses the backup vs exfiltration example: identical function but different intent, which AI cannot discern.
ADVICE

Restrict Agentic AI To Need‑To‑Know Access

  • Treat agentic AIs like users: grant only necessary access and impose strict boundaries.
  • Limit where agents can send data, what internet endpoints they reach, and constrain their permissions on devices.
Get the Snipd Podcast app to discover more snips from this episode
Get the app