Cybersecurity News & Analysis by Cyber Sidekicks - Your Weekly Update’ · Christina Richmond | Rory Duncan - Cybersecurity Experts | Richmond Advisory Group

The Paradigm Shift of Agency: with Zenity's Chris Hughes

·40 min·2 clips
Chris Hughes says the real paradigm shift is “the introduction of autonomy or agency of the agents.”
1. Cyber Sidekicks frames this episode around Chris Hughes, VP of Security Strategy at Zenity, and the coming RSAC trip. 2. Chris Hughes matters here because he writes, hosts the Resilient Cyber podcast, and works on Zenity’s security strategy. 3. The core question is how agentic AI changes cybersecurity when software can now take actions, not just return answers. 4. Hughes says AI has a double edge: it can redesign security workflows while also introducing new risk across GRC, AppSec, SecOps, and pen testing. 5. He compares today’s AI search problem with earlier trusted sources such as encyclopedias and reputable books. 6. Hughes argues that source verification still matters because LLMs can be hallucinated, misleading, or untrustworthy. 7. Christina describes agentic AI as a browser-and-identity problem, because agents can get permissions that traditional systems did not expect. 8. Hughes says the key difference is autonomy, since agents can take actions in the browser, in enterprise systems, and in coding contexts. 9. He ties that autonomy to hijacking, misdirection, and misuse of tools that now have broad permissions. 10. He says identity and access management becomes harder when organizations may have tens to hundreds of agents per human user. 11. Hughes also connects agentic coding to software supply chain security, including open source dependencies and “phantom dependencies.” 12. He notes that AI coding tools have been trained on large bodies of open source software, which helps explain why vulnerabilities reappear downstream. 13. On AppSec, he says the industry has already moved from CVSS-only thinking toward EPSS, KEV, and reachability analysis. 14. He adds that the surge in pull requests from AI tools is stretching review capacity and increasing the pace security teams must handle. 15. Hughes says organizations are now trying to push security checks into IDEs and developer workflows to keep up with that volume. 16. He says “probabilistic security” is valid because AI-native SAST and LLM-as-a-judge systems already operate with nondeterministic outputs. 17. He argues that many businesses have always accepted risk implicitly, but the current shift makes that acceptance more explicit. 18. The interview style is conversational, technical, and improvisational, with Christina and Rory pressing Hughes on policy, guardrails, and critical infrastructure. 19. Listeners interested in AI security, AppSec, and enterprise risk would get the most from it. 20. Listeners wanting a light RSAC preview without deep technical discussion may skip it.

As heard by us

RSA prep turns into a practical case for machine-speed AI security.

Cyber Sidekicks uses its RSA prep episode to ask a timely question: what happens when AI tools, agentic coding, and AppSec have to keep pace with machine speed?

Read the full review in PlayNext →

Why you'd press play

You want the AI-security debate before RSA takes over the room.

Read the full recommendation in PlayNext →
Listen to the show on