{"type":"rich","version":"1.0","provider_name":"Transistor","provider_url":"https://transistor.fm","author_name":"Signed","title":"How Do You Know Your Security Tools Are Actually Working?","html":"<iframe width=\"100%\" height=\"180\" frameborder=\"no\" scrolling=\"no\" seamless src=\"https://share.transistor.fm/e/cf47db9a\"></iframe>","width":"100%","height":180,"duration":7569,"description":"Your website is no longer read only by people.\nTony Lauro opens this episode with a client whose sequential order numbers let a competitor read their daily volume through a public API. No breach. No alert. Just a number counting up in plain sight.\nThe same blind spot shows up when a product drop gets sniped by bots in seconds, or when the large language models you're exposing to customers and employees get probed before anyone notices.\nTony has spent 13 years inside Akamai's bot management and API security practice, watching exactly this shift happen. He walks through what replaced the old human-or-machine test, and it comes down to one thing: who decided your defaults, and whether anyone at your company ever checked.\n\nFind the Risk You're Already Dealing With\nOur security team still argues about whether traffic is a real person or a bot. Is that even the right question to be asking anymore? → Jump to [1:00]\nSome of our \"customers\" completing checkouts or filling out forms might actually be AI agents acting on a real person's behalf. Can our bot rules even tell the difference? → Jump to [3:54]\nWe know some of the activity on our platform isn't clean, but cracking down on it would hurt our numbers. How do we actually think through that tradeoff? → Jump to [26:38]\nOur security team and our marketing team have never once talked about brand risk together. Should they be in the same room? → Jump to [29:03]\nOur provider pushes our blocking rules out to the edge before traffic even reaches us. What judgment calls are they making on our behalf without us knowing? → Jump to [36:57]\nWe know AI is a risk somehow, but nobody's mapped out where it's actually hitting us. Where would we even start? → Jump to [45:01]\nWe just turned on an internal AI tool or chatbot, and I don't know what it's actually watching for. What should it be catching? → Jump to [50:57]\nA security vendor ran a proof of value on us and found something scary in our environment. Is that actually proof their...","thumbnail_url":"https://img.transistorcdn.com/d8NGarPLhvklmJcOQEYdHcKCmSM85HfY2AEspyWoL-M/rs:fill:0:0:1/w:400/h:400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS82NzJl/MzE1NTFmNzgzMjVk/NTdhOTc4ZGU2YWYx/Zjc5Ny5wbmc.webp","thumbnail_width":300,"thumbnail_height":300}