DiscoverHybrid Identity Protection Podcast
Hybrid Identity Protection Podcast
Claim Ownership

Hybrid Identity Protection Podcast

Author: Semperis

Subscribed: 15Played: 199
Share

Description

The HIP Podcast is the premier podcast for cybersecurity pros charged with defending hybrid identity environments. Hosted by 15-time Microsoft MVP and Active Directory security expert, Sean Deuby.
Presented by Semperis: the pioneers of identity-driven cyber resilience for the hybrid enterprise.
104 Episodes
Reverse
Recorded live at Black Hat 2026, this episode features Sarah Gosler, Managing Director and Head of Cyber Resiliency and Human Defense at Wells Fargo. Sarah explains why humans are the largest attack surface and how—when AI has industrialized social engineering and cybersecurity is an "everybody problem"—the role of the CISO has shifted to encompass both the technical and the operational. Sarah makes the case that the more automated attacks get, the more the human side of defense matters.Before Wells Fargo, Sarah was Global Head of Cyber Human Defense and Readiness Products at BNY Mellon, where she built the firm's first commercial cyber product and earned two patents for a dynamic wargaming system. A former chief marketing officer, she brings a user-experience lens to cyber defense and is a featured cast member in Semperis’ new documentary Midnight in the War Room.Guest Bio Sarah Gosler is a senior cybersecurity executive focused on cyber resiliency and the human dimension of institutional risk. Her work is grounded in a simple premise: systems break — what matters is whether the organization holds.As Managing Director and Head of Cyber Resiliency & Human Defense at Wells Fargo, Sarah leads initiatives that strengthen how the firm prepares for and responds to cyber incidents. She integrates advanced wargaming, human defense strategy, and behavioral science to enhance institutional coordination, executive decision-making, and organizational performance under stress.Previously, at the Bank of New York, she built and scaled the firm’s global Cyber Human Defense program and pioneered its first commercial cyber readiness product, earning two patents in cyber wargaming and advancing industry approaches to social engineering resilience.Sarah is a frequent keynote speaker, media contributor, and published author of white papers on the psychological and organizational dimensions of cyber risk. She is widely recognized for bridging technical resilience with executive leadership and dynamics — shaping how financial institutions address cyber as both a technological and human challenge.With more than two decades at the intersection of finance, technology, and organizational performance, Sarah continues to influence the global conversation on institutional resilience, crisis leadership, and the evolving human front line of cyber defense.Guest Quote “I'm such a big advocate of making sure people don't say that humans are the weakest link. Humans represent the largest attack surface of any company. And so, if you think about it, if that's the biggest attack surface, but you're calling it the weakest link, you're really setting yourself up to fail.”Time stamps 00:30 Meet Sarah Gosler 03:46 Why Weakest Link Is the Wrong Framing 06:18 A Marketing Approach to Cybersecurity 07:30 The Cyber Villains Series 10:02 Cyber Is an Everybody Problem 14:36 Deepfakes on the Rise 15:32 Safe Words as a Cyber Defense 16:41 Sarah's Video Game Creation at BNY Mellon 20:09 The Industrialization of Social Engineering 23:21 Conclusion and Final ThoughtsSponsor The HIP Podcast is brought to you by Semperis, the leader in identity-driven cyber resilience for the hybrid enterprise. Trusted by the world’s leading businesses, Semperis protects critical Active Directory and Entra ID environments from cyberattacks, ensuring rapid recovery and business continuity when every second counts. Visit semperis.com to learn more.Links Connect with Sarah on LinkedInConnect with Sean on LinkedInDon't miss future episodesLearn more about SemperisMidnight in the War Room tells the story of cyber defenders on the front lines. See this pioneering documentary at an upcoming screening near you: https://www.semperis.com/midnight-in-the-war-room/events/
This episode features Wylie Shanks, a cybersecurity consultant who leads an OT cybersecurity program for a large North American energy company's business unit.Wylie has spent more than twenty-five years working with critical infrastructure organizations, designing, defending, and recovering environments that span enterprise IT through industrial control systems. In this conversation, he walks Sean Deuby through the Purdue model level by level, then explains what changed when Windows servers, domain controllers, and vendor-managed accounts moved into environments built to run for decades without interruption. Wylie and Sean cover why safety and availability outrank everything else on the plant floor, why MFA and patch cycles that work in IT can be unworkable in OT, how forest architectures set up twenty years ago constrain organizations today, and how new resilience mandates in the US and Canada are pushing operators to prove they can run disconnected for 90 days. This episode makes the case that OT security is less about importing IT controls than about translating between two groups of experts who have never had to speak the same language. Guest Bio Wylie Shanks is a cybersecurity consultant who currently leads an OT cybersecurity program for a large North American energy company's business unit. With over twenty-five years of experience working with critical infrastructure organizations, he designs, defends, and recovers environments spanning enterprise IT to industrial control systems. His expertise spans security architecture, incident response, privileged access management, and cyber risk management, translating complex challenges into practical, auditable solutions. Wylie holds numerous certifications, including GIAC Security Expert (GSE), ISSAP, GIAC Response in Industrial Defense (GRID), and GIAC Cyber Incident Leader (GCIL). Guest Quote "Safety, of course, is critical. That's one of the differences between, say, an IT and an OT environment is in OT, there can be lives at stake. The environment can be impacted. You have different concerns about reliability and safety." Time stamps 02:40 Meet Wylie Shanks: 25 Years in Critical Infrastructure 04:59 Defining the OT Environment 05:51 Walking Through the Purdue Model 08:45 Explaining OT with a Thermostat 12:11 Ranking Safety, Reliability, and Integrity 13:39 Revisiting Stuxnet 15:21 Why MFA Breaks on the Plant Floor 18:36 Finding Windows and Active Directory in OT 21:29 Applying PAM and Least Privilege 27:14 Comparing AD Forest Architectures 31:19 Earning Trust with Plant Operators 35:41 Meeting New Resilience Mandates 40:49 Mapping the Threat Vectors 44:49 Facing AI-Assisted Attacks 47:41 Learning from Colonial Pipeline 53:15 Making Resilience Measurable 56:42 Conclusion and Final Thoughts Sponsor The HIP Podcast is brought to you by Semperis, the leader in identity-driven cyber resilience for the hybrid enterprise. Trusted by the world's leading businesses, Semperis protects critical Active Directory and Entra ID environments from cyberattacks, ensuring rapid recovery and business continuity when every second counts. Visit semperis.com to learn more. Links Connect with Wylie on LinkedIn Connect with Sean on LinkedIn Don't miss future episodes Learn more about Semperis
This episode features Marc Jason Grens, President of Chaintrax. Marc has led Chaintrax for twelve years, growing it from a compliance and anti-money-laundering firm in cash-to-crypto services into a licensed blockchain forensics practice after entering the ransomware payment business in 2017. He has since advised on more than 4,000 incidents. In this episode, Marc explains why ransomware victims decide to pay, why that payment can violate US sanctions law if it isn't vetted first, and why tracking the money afterward is how law enforcement works to recover it. This episode makes the case that paying a ransom is only the beginning of a compliance and recovery process, not the end of one. Guest Bio Marc Grens is the President of Chaintrax,  which has been providing cutting-edge financial, technological, and consulting services for the payments and incident response industry for the last 12 years. He is a serial entrepreneur with more than 15 years of experience in the investment industry. Prior to Chaintrax, Marc held senior positions at Charles Schwab, HighTower Advisors, and Alpha Strategies. He received his M.B.A. from the Kellstadt Graduate School of Business at DePaul University in 2010, and a B.A. from Illinois State University. Marc is an active angel investor and serves on multiple advisory boards of companies in the Chicago tech community. Sponsor The HIP Podcast is brought to you by Semperis, the leader in identity-driven cyber resilience for the hybrid enterprise. Trusted by the world’s leading businesses, Semperis protects critical Active Directory and Entra ID environments from cyberattacks, ensuring rapid recovery and business continuity when every second counts. Visit semperis.com to learn more. Links Connect with Marc on LinkedIn Connect with Sean on LinkedIn Connect with Jeff on LinkedIn Don't miss future episodes Learn more about Semperis HIP Conference 26 is coming to Nashville, September 8–10, 2026. Join us to explore this year's theme, Redefining Resilience, at the world's premier practitioner-led conference focused on securing hybrid identity environments. If you love the conversations on the HIP Podcast, this is where the community comes together in person. Learn more and register at https://www.hipconf.com/.
This episode features Chris Steinke, Director of Product Strategy at Semperis.Chris has spent more than 20 years across cybersecurity, digital identity, infrastructure, and operations, including leadership roles at American Express and Early Warning Services (Zelle) and early work at MightyID, where he helped bring one of the industry's first dedicated identity resilience platforms to market.In this episode, Chris explains why moving identity to the cloud creates a single point of failure, why backup and recovery alone aren't enough, and why the next frontier is making trust portable, so applications aren't locked to a single identity provider.This episode reframes identity resilience as a continuity problem: not just recovering after an outage but keeping the business running through one.Guest Bio Chris Steinke is Director of Product Strategy at Semperis and a technology executive with more than 20 years of experience in cybersecurity, digital identity, infrastructure, and operations. Throughout his career, including leadership roles at American Express and Early Warning Services (Zelle), he has helped organizations build resilient digital ecosystems and defend against large-scale identity threats. As an early pioneer at MightyID, Chris helped bring one of the industry's first dedicated identity resilience platforms to market.Today, his work focuses on the future of digital trust, including identity resilience, multi-IdP architectures, and trust portability - the next evolution in ensuring business continuity in an identity-centric world.Guest Quote “We spent years making identities portable, and that's what we did really at the start. We were worried about the identities. So, the next challenge is how do we make trust portable?”Time stamps 02:11 Meet Chris Steinke: 20+ year Technology Executive 03:10 Why Identity Resilience Matters 08:43 Hidden Risks in Cloud Identity 15:52 Multi-IdP Failover Playbooks 23:06 Applications Are the Hard Part 31:46 The IRON Framework 37:35 Conclusion and Final ThoughtsSponsor The HIP Podcast is brought to you by Semperis, the leader in identity-driven cyber resilience for the hybrid enterprise. Trusted by the world’s leading businesses, Semperis protects critical Active Directory and Entra ID environments from cyberattacks, ensuring rapid recovery and business continuity when every second counts. Visit semperis.com to learn more.LinksConnect with Chris on LinkedInConnect with Sean on LinkedInDon't miss future episodesLearn more about SemperisHIP Conference 26 is coming to Nashville, September 8–10, 2026.Join us to explore this year's theme, Redefining Resilience, at the world's premier practitioner-led conference focused on securing hybrid identity environments.If you love the conversations on the HIP Podcast, this is where the community comes together in person. Learn more and register at https://www.hipconf.com/.
This episode features Philip Keibler, Vice President and CISO at Meijer, one of the nation's largest privately held retailers.With nearly three decades of security leadership, including CISO roles at Bass Pro Shops and Finish Line, Phil brings a rare long-view perspective on what the job actually requires day to day. He also talks about his feature in Semperis' upcoming documentary Midnight in the War Room, premiering at Black Hat on August 5.In this episode, Phil explains why CISOs who struggle to get budget usually have a storytelling problem, how he defines success in a role where stopping every attack is impossible, and what it takes to lead a team through an active incident. He also dives into why fundamentals are what actually address most of an organization's risk.This episode makes the case that the hardest parts of the CISO job are rarely technical, and that mastering the basics matters more than chasing the newest tool.Guest Bio Philip Keibler has spent nearly three decades at the intersection of technology, risk, and business building information security programs that work in the real world.As Vice President and Chief Information Security Officer at Meijer, Phil leads security for one of the nation's largest privately held retailers, overseeing the protection of supply chains, customer data, and critical operations across hundreds of locations in the Midwest.Phil's career spans industries where the stakes are high and the margin for error is low. Before joining Meijer in 2015, he served as CISO at Bass Pro Shops and previously held the CISO role at Finish Line. Earlier in his career he led security at Herff Jones, bringing security discipline to the manufacturing sector. He began his career at EDS and spent years consulting in the Aerospace sector where he got his start in security.What sets Phil apart is not just longevity, it is perspective. He has watched information security evolve from a reactive, audit-driven function into a proactive capability that enables business velocity. His approach centers on integrating security into how organizations operate, not as a checkbox, but as a competitive advantage that lets teams move fast while managing risk in practical ways.Beyond the day-to-day, Phil is a passionate contributor to the broader security community. He has served as a guest lecturer on cybersecurity and data privacy at the University of Chicago Law School, sits on the Institute for Cybersecurity Education and Research Advisory Board at Grand Valley State University, serves on the IT Advisory Committee at Kent County Technical Center, and is a board member the Meijer Credit Union. He is also featured in Midnight in the War Room, a Semperis documentary examining the human reality behind enterprise cyber defense.Phil has held his CISSP certification since 2009, attained his MBA from Davenport University, and a career's worth of operational experience across retail, aerospace, insurance, and manufacturing.Guest Quote “A successful CISO understands that it's not about prevention, it's about resilience, it's about recovery, and it's about identifying those things in your program that you can do incrementally better every single day. We're in the pursuit of perfection, but we understand we'll never get there.”Time stamps 02:46 Meet Philip Keibler: From Sysadmin to Security 04:35 Becoming a CISO 06:20 What CISOs Really Do 08:50 Defining Success and Resilience 10:41 Storytelling to the Board 13:29 Semperis' Midnight in the War Room 17:47 Team Care and Crisis Leadership 21:47 Advice for CISOs 24:24 The Case for Mastering the Fundamentals 31:02 Conclusion and Final ThoughtsSponsor The HIP Podcast is brought to you by Semperis, the leader in identity-driven cyber resilience for the hybrid enterprise. Trusted by the world’s leading businesses, Semperis protects critical Active Directory and Entra ID environments from cyberattacks, ensuring rapid recovery and business continuity when every second counts. Visit semperis.com to learn more.Links Connect with Phil on LinkedInConnect with Sean on LinkedInDon't miss future episodesLearn more about SemperisHIP Conference 26 is coming to Nashville, September 8–10, 2026.Join us to explore this year's theme, Redefining Resilience, at the world's premier practitioner-led conference focused on securing hybrid identity environments.If you love the conversations on the HIP Podcast, this is where the community comes together in person. Learn more and register at https://www.hipconf.com/.
loading
Comments