Running Claude Code or Claude in Chrome? Here’s the audit matrix for every blind spot your security stack misses
VentureBeat

Running Claude Code or Claude in Chrome? Here’s the audit matrix for every blind spot your security stack misses

Kayne McGladrey, an IEEE senior member who advises enterprises on identity risk, described the same dynamic independently in an interview with VentureBeat. Enterprises are cloning human permission sets onto agentic systems, McGladrey said. The agent does whatever it needs to do to get its job done, and sometimes that means using far more permissions than a human would.
AI agents are running hospital records and factory inspections. Enterprise IAM was never built for them.
VentureBeat

AI agents are running hospital records and factory inspections. Enterprise IAM was never built for them.

Kayne McGladrey, an IEEE senior member, told VentureBeat that organizations are defaulting to cloning human user profiles for agents, and permission sprawl starts on day one. Carter Rees, VP of AI at Reputation, identified the structural reason. "A significant vulnerability in enterprise AI is broken access control, where the flat authorization plane of an LLM fails to respect user permissions," Rees told VentureBeat.
An AI agent rewrote a Fortune 50 security policy. Here’s how to govern AI agents before one does the same.
VentureBeat

An AI agent rewrote a Fortune 50 security policy. Here’s how to govern AI agents before one does the same.

McGladrey's practitioner experience confirms the gap. The Cloud Security Alliance published an NIST AI RMF Agentic Profile in April 2026, proposing autonomy-tier classification and runtime behavioral metrics. But SOC 2, ISO 27001, and PCI DSS have not operationalized agent identities. The compliance frameworks McGladrey works with inside enterprises were written for humans. Agent identities do not appear in any control catalog he has encountered. The gap is a lagging indicator; the risk is not.
How to create an effective business continuity plan
CIO

How to create an effective business continuity plan

The list of possible impact scenarios is extensive. Instead of trying to identify them all, McGladrey advises identifying the most likely and most representative types of incidents and then focusing on how such incidents could impact the business. From there, leaders must determine what impacts would be intolerable based on the organization’s risk tolerance.
Meta’s AI training with keystrokes: Progress or privacy issue
TechTarget

Meta’s AI training with keystrokes: Progress or privacy issue

"This is something that can be done because we don't have a federal privacy act in the United States, whereas in other countries, this would be completely unacceptable as well as considered to be culturally unacceptable," McGladrey said.
Episode 85 : Will AI Agency Reduce or Reinforce Global Inequality?”
Tallinn University Student Podcast

Episode 85 : Will AI Agency Reduce or Reinforce Global Inequality?”

So it was Tom Cruise waving his hands around to use a computer, but it showed a world where people got arrested for crimes they hadn't committed yet based on data that could be flawed or biased. And it turns out that movie was a warning.
AI Could Transform Rural Healthcare, But Who Will Benefit The Most? Experts Comment
TechRound

AI Could Transform Rural Healthcare, But Who Will Benefit The Most? Experts Comment

Kayne McGladrey raises another concern: the transfer of risk. AI vendors may provide the tools, but providers often carry the legal and financial consequences when things go wrong. In already stretched rural systems, that imbalance could have serious implications. There is also the issue of data. Many AI models are trained on urban populations, which may not reflect the realities of rural patients. That increases the risk of misdiagnosis or ineffective recommendations, particularly in communities with different health profiles.
Claude Code, Copilot and Codex all got hacked. Every attacker went for the credential, not the model.
VentureBeat

Claude Code, Copilot and Codex all got hacked. Every attacker went for the credential, not the model.

Kayne McGladrey, an IEEE Senior Member who advises enterprises on identity risk, made the same diagnosis in an exclusive interview with VentureBeat. "It uses far more permissions than it should have, more than a human would, because of the speed of scale and intent."
Guide: DORA Compliance Evidence for Agentic AI
Teleport

Guide: DORA Compliance Evidence for Agentic AI

DORA compliance requires both proper documentation and comprehensive data generation. The gap between policy and practice can be bridged by rigorous, automated evidence collection alongside documented ICT risk management frameworks. But as agentic AI continues to redefine modern operations, the definition of sufficient evidence must similarly modernize. Organizations that adopt JIT access, unified logging, and agent-specific telemetry today will not only survive the next NCA audit, but will also achieve longstanding operational resilience.
State Fights Millions Of Daily Cyber Attacks — But Experts Say Weak Spots Remain
Michigan Information & Research Service

State Fights Millions Of Daily Cyber Attacks — But Experts Say Weak Spots Remain

"You can reduce risk," said cybersecurity expert Kayne McGladrey. "But nobody out there can be perfect. It's an unattainable goal." McGladrey said he tends to think of cybersecurity in terms of risk; sometimes the risk is increased, and some things decrease risk.
EU AI Act Compliance: Requirements, Risks, and What to Document
Teleport

EU AI Act Compliance: Requirements, Risks, and What to Document

This guide is for compliance officers, technical leads, CISOs, and their legal advisors preparing for increased regulatory scrutiny. Organizations must prepare for potential reviews of their risk management systems, data governance, and cybersecurity measures. Failure to provide adequate documentation may result in significant administrative fines, making the preparation of sufficient evidence a top priority for legal and technical teams alike.
Microsoft patched a Copilot Studio prompt injection. The data exfiltrated anyway
VentureBeat

Microsoft patched a Copilot Studio prompt injection. The data exfiltrated anyway

McGladrey cut to the governance failure. “If crime was a technology problem, we would have solved crime a fairly long time ago,” he told VentureBeat. “Cybersecurity risk as a standalone category is a complete fiction.”
Episode 42: Stop Thinking Servers, Start Thinking Systems
Zero Trust Journey

Episode 42: Stop Thinking Servers, Start Thinking Systems

We move past the buzzwords to discuss the gritty reality of ripping out legacy "flat" networks and replacing them with Zero Trust architectures that actually improve performance while reducing liability. Kayne breaks down why the private sector continues to struggle with risk and how the rise of Agentic AI is changing the identity landscape in 2026.
Ep08 – Cyber Risk Is a Myth. Are You Framing Risk in Business Terms? with Kayne McGladrey
MYGRCPOV

Ep08 – Cyber Risk Is a Myth. Are You Framing Risk in Business Terms? with Kayne McGladrey

In this episode of MY GRC POV, Monica sits down with Kayne McGladrey to challenge a common leadership trap. Teams talk cyber. Executives hear noise. Budgets stall. Decisions slow. Kayne breaks down how to translate security and compliance risk into business outcomes leaders act on. Revenue impact. Cost exposure. Operational uptime. Customer trust.
How AI Agents Impact SOC 2 Trust Services Criteria
Teleport

How AI Agents Impact SOC 2 Trust Services Criteria

Integrating AI into production environments expands the scope of SOC 2 to cover models, training data, and automated decision-making systems. This shift affects every Trust Services Criterion. It also expands “evidentiary requirements,” requiring auditable records for production execution in addition to the AI decisions and automation workflows that triggered those executions.
Closing the Skills Gap the Smart Way
Root To CISO Podcast

Closing the Skills Gap the Smart Way

In this episode of Root to CISO Byte Size, Kayne McGladrey shares practical insights on how cybersecurity professionals can align technical skills with business priorities to strengthen their impact. From conducting meaningful skills gap analyses to communicating security in revenue-focused terms, Kayne explains how CISOs can protect budget, support growth, and position security as a strategic enabler. He also offers grounded advice for early-career professionals on building the right skills, engaging with the community, and making informed career decisions in today’s evolving market.
What CISOs need to know about the OpenClaw security nightmare
CSO Online

What CISOs need to know about the OpenClaw security nightmare

“If this was easy, Microsoft would have written this,” says IEEE’s McGladrey. “But there aren’t a lot of options out there. I think that’s the real thing we’re working against here.”
Top 50 Global Thought Leaders and Influencers on Cybersecurity 2026
Thinkers360

Top 50 Global Thought Leaders and Influencers on Cybersecurity 2026

#1 Kayne McGladrey, CISSP
The Cybersecurity Debt We Pretend Isn’t There
Adopting Zero Trust Podcast

The Cybersecurity Debt We Pretend Isn’t There

"As organizations push return-to-office (RTO) mandates and chase efficiency, many security teams are quietly accumulating debt they don’t know how to unwind. In this episode, we are joined by Lea Cure Thorpe and Kayne McGladrey to unpack the less-discussed consequences of recent security decisions: RTO exposure, endpoint blind spots, tooling overload, analyst burnout, and the slow erosion of junior talent (thanks AI)."
How shopping chatbots might transform retail
FT

How shopping chatbots might transform retail

One problem is that agentic AI reads all the text that it encounters and retains the data it absorbs, McGladrey adds. Embedded text, contained in website code but not visible to the human user, can trick agents into purchasing unwanted products while clones of legitimate retail websites can extract customer payment credentials.

Understand the stories that matter.

Every week, I break down the most important updates in cybersecurity and AI law and policy. Human-written, deeply analyzed.

I don’t spam! Read the privacy policy for more info.