惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
L
LINUX DO - 最新话题
罗磊的独立博客
IT之家
IT之家
阮一峰的网络日志
阮一峰的网络日志
WordPress大学
WordPress大学
Security Archives - TechRepublic
Security Archives - TechRepublic
H
Hacker News: Front Page
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
The Hacker News
The Hacker News
Recent Commits to openclaw:main
Recent Commits to openclaw:main
大猫的无限游戏
大猫的无限游戏
PCI Perspectives
PCI Perspectives
Hugging Face - Blog
Hugging Face - Blog
博客园 - 【当耐特】
Application and Cybersecurity Blog
Application and Cybersecurity Blog
P
Proofpoint News Feed
NISL@THU
NISL@THU
小众软件
小众软件
S
Security Affairs
腾讯CDC
人人都是产品经理
人人都是产品经理
C
Check Point Blog
The GitHub Blog
The GitHub Blog
有赞技术团队
有赞技术团队
Forbes - Security
Forbes - Security
Project Zero
Project Zero
G
Google Developers Blog
博客园 - 三生石上(FineUI控件)
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
博客园_首页
Jina AI
Jina AI
The Cloudflare Blog
C
Cisco Blogs
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
L
Lohrmann on Cybersecurity
Y
Y Combinator Blog
W
WeLiveSecurity
V
Visual Studio Blog
Scott Helme
Scott Helme
N
News | PayPal Newsroom
I
Intezer
C
CXSECURITY Database RSS Feed - CXSecurity.com
Attack and Defense Labs
Attack and Defense Labs
Spread Privacy
Spread Privacy
Webroot Blog
Webroot Blog
T
Threatpost
雷峰网
雷峰网
MongoDB | Blog
MongoDB | Blog
N
News and Events Feed by Topic

Blog on 1Password Blog

Why secure-by-design is an incentives problem, with Bob Lord | 1Password NIST and AI agents: 1Password’s approach to agent identity | 1Password Go beyond device health with External Checks in 1Password Device Trust | 1Password Natoma and 1Password help enterprises scale AI securely with governed agent access | 1Password New integrations between 1Password SaaS Manager and EPM | 1Password A first step toward post-quantum security | 1Password RSA 2026: Leading the way to secure agentic AI | 1Password How 1Password is Building a Culture of AI Fluency Through AI Champions | 1Password 1Password vs. Keeper Security: A comparison | 1Password 1Password vs. LastPass: Which is right for you? | 1Password Secure MCP credentials with 1Password and Runlayer | 1Password The next layer of AI security | 1Password Building the next chapter of Go-to-Market in EMEA | 1Password Automating SOC workflows with 1Password Enterprise Password Manager | 1Password Automated Provisioning hosted by 1Password: A Simpler, Smarter Way to Manage Access | 1Password Introducing 1Password® Unified Access: Identity Security for Humans and Their AI Agents | 1Password Next-generation automated provisioning, without compromising zero-knowledge security | 1Password Bitwarden vs. 1Password: Which password manager is right for you? | 1Password Password Manager for Families, Enterprise & Business | 1Password | 1Password How to wrangle SaaS contract renewals | 1Password Stop trusting consumer browsers with work credentials | 1Password IAM stops at sign-in. Your credentials do not. | 1Password Your digital pit crew: a 10-minute pre-race security checklist | 1Password 1Password Device Trust is coming to EMEA | 1Password The identity transformation: Analyst and CIO insights | 1Password Why now is the moment to join 1Password Go-To-Market | 1Password Identity and Accountability in the Age of AI Agents | 1Password How 1Password secures agent architectures | 1Password 1Password becomes the first global partner to transact through Express Private Offers in AWS Marketplace | 1Password Start Learning on 1Password Academy | 1Password Expanding Programmatic Access to 1Password | 1Password Zero knowledge vs. a malicious server: A look at ETH Zurich’s research | 1Password Agents are making filesystems cool again | 1Password Black History Month employee spotlight: Joseph Ojelade | 1Password 1Password's new benchmark teaches AI agents how not to get scammed | 1Password Streamlining SaaS onboarding and offboarding | 1Password 3 common SaaS Management challenges and how to avoid them | 1Password How 1Password Is Evolving Its Partner Ecosystem | 1Password How to build secure agent swarms that power production-grade autonomous systems | 1Password From magic to malware: How OpenClaw's agent skills become an attack surface | 1Password Solving the unsanctioned SaaS problem | 1Password 1Password and 60 Day Hustle: cybersecurity for small businesses | 1Password Security advisory for AI-assisted browsing interactions with the 1Password browser extension | 1Password It’s incredible. It’s terrifying. It’s OpenClaw. | 1Password Managing the risks of social logins | 1Password What’s the first security tool your small business should buy? | 1Password As AI Supercharges Phishing Scams, 1Password Introduces Built-In Protection | 1Password How to interview with confidence at 1Password | 1Password Five tips for successful SaaS Management | 1Password SaaS Manager | 1Password Why SaaS License Waste Is a Cost and Security Problem | 1Password AI is changing the IDE. With 1Password, security keeps up | 1Password How IT teams can get a handle on shadow IT | 1Password Bringing secure, just-in-time secrets to Cursor with 1Password | 1Password Now available via QBS Software: 1Password Enterprise Password Manager – MSP Edition | 1Password The role of credentials in the AI espionage campaign reported by Anthropic | 1Password The hidden offboarding step draining your budget | 1Password AWS and 1Password: Innovation in AI and beyond | 1Password Simplifying credential security on OpenAI Atlas | 1Password From Social Work to Social Impact: Growing at 1Password | 1Password Improving in-page notifications in the 1Password browser extension | 1Password Password Manager for Families, Enterprise & Business | 1Password | 1Password Now available via Renaissance: 1Password Enterprise Password Manager – MSP Edition | 1Password Behind the wheel at Oracle Red Bull Racing | 1Password Securing MCP servers with 1Password: Stop credential exposure in your agent configurations | 1Password What’s new in 1Password Enterprise Password Manager - Q4, 2025 | 1Password Belonging as a catalyst for high performance | 1Password Password habits are worsening, but leaders see a path to passwordless | 1Password A simpler, faster way to unlock 1Password | 1Password Oracle Red Bull Racing Episode 4, CIO Matt Cadieux | 1Password 70% of IT and security pros say SSO is falling short | 1Password 1Password's Phishing Survey: Avoid Holiday Phishing Scams | 1Password Securing the Win | 1Password SaaS optimization: How to maximize value and reduce costs | 1Password The enterprise AI crisis: Unsanctioned tools and unenforced policies | 1Password An Identity Security taxonomy for Agentic AI | 1Password Introducing new .env file support in 1Password environments | 1Password Speed and security: Mark Hazelton on protecting Oracle Red Bull Racing’s most valuable asset – its data | 1Password 1Password for Good: Giving back during cybersecurity awareness month | 1Password Utah Mammoth and Utah Jazz score with identity security | 1Password Oracle Red Bull Racing CEO and Team Principal | 1Password Three signs you need a SaaS Management Platform | 1Password Closing the credential risk gap for AI agents using a browser | 1Password Microsoft and Dropbox password managers are sunsetting: What it means and what to do next | 1Password From hackathon nerves to internship wins: Kavya’s journey at 1Password | 1Password 1Password now available in Comet, the AI-powered browser by Perplexity | 1Password 1Password announces new integration with Zscaler | 1Password Breaking the mold: Why more women should consider a career in sales | 1Password What security leaders need to know about mergers and acquisitions | 1Password Clickjacking: What it means for 1Password users | 1Password AI and security at Black Hat: 5 key takeaways from a security expert panel | 1Password Blog | 1Password Do any CISOs feel lucky? | 1Password How to lead with confidence in the AI era: a conversation with Nancy Wang, VP, Engineering | 1Password New Device Trust Check makes browser extension enforcement easier | 1Password Purpose, performance, and trust: Inside the culture powering 1Password’s next chapter | 1Password Now available on Pax8 Marketplace: 1Password Enterprise Password Manager - MSP Edition | 1Password The security principles guiding 1Password’s approach to AI | 1Password Choosing the right SaaS management platform for your business | 1Password Simplify access reviews with 1Password SaaS Manager | 1Password How great usability tripled Duke University's password manager adoption | 1Password
The Chasing Entropy Podcast Season One is in the Books | 1Password
info@1password.com (Dave Lewis) · 2025-12-15 · via Blog on 1Password Blog

Twenty-seven episodes. Dozens of CISOs and security leaders. Hours of honest conversation about what actually keeps them up at night.

When I launched the show, the goal was simple. Strip out the fluff and talk about how security really works inside organizations that ship software, handle sensitive data, and carry real operational risk—just practitioners comparing scars.

This season covered three big threads that kept looping back into each other. The changing reality of the CISO role. The rise of agentic AI systems. The grind of day-to-day security work in complex environments. All of it shaped by people who actually own the outcomes.

The CISO job is no longer “just security”

Across episodes with sitting CISOs, former CISOs, and advisors, one theme kept repeating. The role has outgrown the narrow idea of “head of security.”

Guests talked about shaping product strategy, influencing M&A decisions, and acting as a translator between engineering, legal, and the board. Security decisions now touch revenue targets, customer churn, and brand risk. That shift sounds good in theory. In practice, it means CISOs end up accountable for many things they do not fully control.

Several guests described the alignment problem. They own risk, but budgets roll up through other executives. They see threats, but business incentives still reward speed over resilience. They are measured on incident outcomes, yet they do not directly manage the teams that ship code or choose vendors.

We heard candid stories about burnout and turnover. One CISO walked us through the exact timeline of an incident, followed by a board meeting, followed by pressure to “simplify the story” for investors. Another unpacked why they walked away from a role that looked perfect on paper. All of them stressed the same point. Governance on slides and governance in reality are two different things.

A few concrete patterns emerged:

  • The healthiest programs treat security as a design constraint early, not as an after-the-fact control.

  • CISOs who succeed long term invest in political capital, not only technical depth.

  • Boards that receive concise, quantified risk narratives tend to fund security in a more predictable way.

None of that is theoretical. It came from leaders who already lived through breaches, regulatory investigations, and restructuring.

Agentic AI forced everyone to redraw the map

If the CISO role was the structural thread of the season, agentic AI was the disruptive one.

I talked with researchers, builders, and defenders about AI systems that can plan, act, and adapt with far less human hand-holding. Not just models that classify or summarize, but agents that chain actions, call tools, integrate with SaaS, and touch production systems.

The mood was not hype. It was curiosity mixed with concern.

On the risk side, the questions got sharper:

  • How do you test agents that can call arbitrary APIs on your behalf.

  • What is the blast radius when an agent interprets a prompt in an unexpected way.

  • Where do you log intent, not just output, so you can reconstruct what happened.

Several episodes dug into evaluation, not just capability. One guest explained their approach to “red teaming the planner” instead of only the model. Another guest from a large enterprise shared how they introduced guardrails that look a lot like familiar security patterns. Least privilege for tools. Strict boundaries between environments. Strong human review on high-impact actions.

We also spent time on governance. Who owns agent risk? Is it the CISO, the CIO, or the data team? That debate is still unresolved inside many companies. The one clear signal. Wherever AI agents can pivot from data to action, security teams will get pulled in, whether they were consulted or not.

The grind of modern security work

Between strategy and AI, the season also stayed close to the operational reality. The stuff that never makes keynotes.

We broke down identity incidents where the root cause was a single overprivileged service account that no one wanted to touch. We walked through SaaS sprawl and what happens when finance signs a contract and security hears about it six months later. We heard from teams still dealing with old VPN concentrators, fragile OT networks, brittle backups, and half-documented cloud resources.

Several guests talked frankly about tooling fatigue. Too many dashboards. Too little integration. Alerts without context. One recurring message. Visibility without ownership is noise.

We heard practical tactics that worked:

  • Building small, cross-functional “fix teams” for specific classes of risk, such as exposed secrets or misconfigured identity providers.

  • Tying security metrics to business metrics, for example, mapping control adoption to sales cycle friction or support ticket volume.

  • Using tabletop exercises as a way to expose process gaps, not as compliance theater.

These were not abstract frameworks. They were things people tested on real incidents with real stakes.

What we learned by listening

After twenty-seven episodes, some lessons cut across every topic.

First, security teams thrive when they are allowed to be specific. “Reduce risk” is meaningless. “Cut the mean time to revoke access for departing employees from three days to four hours” is actionable. The same applies to vendor review, detection tuning, or AI rollouts. Precision beats broad ambition.

Second, language matters. Many guests described how small shifts in wording changed the outcome of conversations. Talking about “protecting revenue” instead of “blocking threats.” Presenting one or two sharp options, not a buffet of scenarios. Explaining uncertainty without drifting into drama.

Third, community still matters more than tools. People came on the Chasing Entropy Podcast to say the quiet parts out loud. To admit where they guessed. To share how often “best practice” collided with reality. That level of honesty is worth more than another product announcement.

Where the Chasing Entropy Podcast goes next

Season one proved there is room for unvarnished security conversations. The numbers are useful, but the direct feedback from listeners stood out more. Messages from CISOs who replayed episodes for their leadership teams. Notes from practitioners who used an anecdote from the show to justify a change in process. Comments from people new to the field who appreciated hearing that even seasoned leaders fight the same battles.

Season two will dig deeper into a few areas our guests only had time to touch on. Security for AI. Agentic AI in production, not pilots. Identity is the real control plane. The economics of security work, from budget structures to talent models. We will keep the format simple. Bring in people who do the work. Ask them pointed questions. Respect their time and yours.

If you listened to one episode or all twenty-seven, thank you. Your attention is a scarce resource. If you shared the show with a colleague, argued with a guest in your head, or scribbled notes, you are part of the experiment.

Entropy does not stop. Systems age. Threats adapt. Organizations change their minds. The goal of this podcast is not to deliver a final answer. It is to track how security practice evolves, one honest conversation at a time.

Season one is a wrap! See you in 2026!

Podcast: https://podcasts.apple.com/ca/podcast/chasing-entropy-podcast-by-1password/id1811491680 

YouTube: https://www.youtube.com/@ChasingEntropyPodcast