Santosh Subramanian

Secured by Design - IAM & Cybersecurity Podcast

Great security solution are designed from the ground up.. Secured by Design is a podcast where Santosh shares practical insights, frameworks, and perspectives on identity security and other aspects of cybersecurity. Each episode breaks down complex concepts into actionable ideas for professionals protecting digital identities, designing secure systems, and leading security initiatives.  Because true security is built  and not bolted on...

Author

Santosh Subramanian

Category

Technology

Podcast website

www.buzzsprout.com

Latest episode

May 10, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Mastering AI Security: Top 10 Risks and Mitigations for LLMs 10.05.2026

Summary This episode explores the top 10 security risks associated with deploying large language models (LLMs) and AI systems. It provides practical insights and mitigation strategies to help organizations secure their AI implementations effectively. Keywords AI security, LLM risks, prompt injection, data leakage, supply chain security, poisoning, output handling, system prompt leakage, misinforma...

Securing Autonomous AI: The OWASP Top 10 Risks Explored 04.05.2026

Summary This episode explores the security risks associated with AI agents, focusing on the OWASP top 10 vulnerabilities and practical mitigation strategies. Learn how autonomous systems can be secured to prevent catastrophic failures and protect organizational assets. Key  topics AI agent security risks OWASP top 10 for agent applications Mitigation strategies for autonomous systems Chapters 00:0...

How Vercel's Supply Chain Attack Unfolded 22.04.2026

Summary This episode dissects the recent Vercel breach, a supply chain attack involving third-party AI tools, OAuth vulnerabilities, and insider risks. It highlights practical steps organizations can take to enhance cybersecurity and prevent similar incidents. Key  topics Supply chain attack involving third-party AI tools OAuth vulnerabilities and permissions management Best practices for environm...

The Mythos Inflection: AI and the Future of Cyber Defense 19.04.2026

Summary This episode explores the groundbreaking capabilities of Anthropic's Mythos AI model, its implications for cybersecurity, and how defenders can adapt to this new threat landscape. We discuss the model's ability to autonomously identify and exploit vulnerabilities, the strategic responses from industry leaders, and the importance of critical evaluation amidst hype. Key Topics Myth...

Why Identity Is The Hidden Keystone in Effective GRC Programs 10.04.2026

Summary This episode explores the critical relationship between identity and access management (IDAM) and holistic Governance, Risk, and Compliance (GRC) programs. Hosted by Santosh, it delves into how integrated identity management enhances security, compliance, and organizational resilience in the digital age. Key Topics The connection between identity and GRC The evolution of IDAM and its role...

How SCA, SAST, and DAST Protect Modern Apps (Application Security) 03.04.2026

Summary This episode explores the core tools in application security - SCA, SAST, and DAST and how they form a comprehensive, shift-left security strategy to protect modern applications from vulnerabilities throughout the development lifecycle. Key Topics Shift-left security strategy SCA (Software Composition Analysis) SAST (Static Application Security Testing) DAST (Dynamic Application Security T...

How LiteLLM Became a Weapon in a Supply Chain Attack 29.03.2026

Summary This episode explores the recent security breach involving Lite LLM, a popular open-source Python library, and discusses the implications for cybersecurity in AI development. Learn how a trusted tool was exploited, the attack's mechanics, and essential security lessons for organizations. Key Topics Supply chain attack on Lite LLM Multi-stage compromise via CI/CD pipeline Malicious pac...

How ITDR Can Prevent the Next Major Data Breach 24.03.2026

Summary This episode explores the critical importance of Identity Threat Detection and Response (ITDR) in modern cybersecurity. Hosted by Santosh, it covers how identity infrastructure is the most targeted layer in enterprises, the rise of identity-based attacks, and practical strategies to enhance security posture. Key Topics The rise of identity-based attacks and their impact The three pillars o...

How Nation-States Target Critical Infrastructure: The Stryker Case Study 19.03.2026

Summary This episode explores the March 2026 cyber attack on Stryker Corporation, a leading medical technology company, highlighting the attack's mechanics, motives, and lessons for organizations worldwide. Learn how nation-state actors target critical infrastructure and how to defend against such destructive threats. Key Topics The timeline and impact of the Stryker cyber attack The role of...

The Day the Internet Broke: Cloudflare's Outage Explained 10.12.2025

Summary In this episode of 'Secured by Design', we discuss the root cause for significant Cloudflare outage that occurred on November 18, 2025, which disrupted major internet services and highlighted the fragility of digital infrastructure. The conversation delves into the causes of the outage, its financial impact on businesses, and the lessons learned regarding cybersecurity and infras...

Unlocking the Future of Customer Identity Management 03.12.2025

Summary In this episode of 'Secured by Design', we delve into Customer Identity and Access Management (CIAM), exploring its significance in enhancing customer experiences while ensuring security and privacy. The discussion highlights the digital experience gap, the differences between CIAM and traditional IAM, and the core concepts that underpin effective CIAM systems. We emphasizes the...

The Invisible Workforce: Understanding Non-Human Identities 26.11.2025

Summary In this episode of Secured by Design, we discuss the growing prevalence of non-human identities (NHIs) in organisations, which outnumber human identities significantly. We highlight the security risks associated with NHIs, including their lack of oversight and the potential for exploitation by attackers. The conversation emphasises the need for organisations to adopt a modern playbook for...

From Passwords to Passkeys: The Future of Authentication 19.11.2025

Summary In this episode of 'Secured by Design', we discusses the critical shift from traditional passwords to passkeys in the realm of cybersecurity. We also highlight the alarming statistics surrounding password breaches and the vulnerabilities they present. The conversation delves into the mechanics of passkeys, their advantages over passwords, and the growing adoption of this technolo...

Modern Identity Governance and Administration 12.11.2025

Summary  In this episode of Secured by Design, we delve into the complexities of modern identity governance and administration (IGA). We discuss the challenges organizations face in managing access for a multitude of identities and applications, and how IGA solutions can streamline this process.  To explain how a modern IGA solution does this, we follow the journey of an employee, James, from onbo...

What Does "Secured by Design" Really Mean? 07.11.2025

Summary In this (First) episode of Secured by Design, we explore the critical role of identity in cybersecurity. We emphasise that identity should be the foundation of security, rather than an afterthought. Through real-world examples, we illustrate the risks associated with poor identity management and the benefits of adopting an identity-first approach. The conversation also highlights the cultu...

Listen to the Secured by Design - IAM & Cybersecurity Podcast podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.