Podlipodcast player Webplayer

The Security Strategist

The Security Strategist

The Cybersecurity Blind Spot Leaders Are Missing, and Why It’s About to Get Worse

The Security Strategist · May 13, 2026 · 41:27

0:0041:27

Listen in the Podli app 🎧

Follow your favourite podcasts, listen offline and in the car with CarPlay and Android Auto, and always pick up where you left off. Free to try.

Podcast: The Security Strategist

Guest: Garrett Hamilton, CEO, Reach Security, and Jay Wilson, CIO & CISO, Insurity

Host: Shubhangi Dua, Podcast Producer and B2B Tech Journalist, EM360Tech

There’s a growing disconnect at the core of enterprise cybersecurity, and most enterprise leadership teams don’t recognise it yet. With budgets increasing, tools improving more than ever, and AI quickly being integrated into both offensive and defensive strategies.

On paper, this should be a golden era for cyber resilience. However, many enterprises feel more exposed, not less. The issue isn’t a lack of innovation, rather it’s something harder to see—and far more dangerous.

In this episode of The Security Strategist podcast, host Shubhangi Dua, Podcast Producer and B2B Tech Journalist at EM360Tech, sits down with Garrett Hamilton, CEO of Reach Security, and Reach customer, Jay Wilson, CIO & CISO at Insurity.

They unpack why enterprises are still getting breached despite record security spend—and how configuration drift, AI-driven threats, and operational blind spots are quietly reshaping the future of cyber defence.

They address the key issues enterprises are playing with in the industry today – whether what enterprises configured yesterday is still protecting them now. The reality is that it isn't safeguarding them.

“The surface area of the problem is just continuing to increase,” says Wilson. “But security teams aren’t growing at the same rate.” This mismatch is creating a new kind of exposure—one that doesn’t show up in dashboards.

Also Read: Ten Hidden Cybersecurity Misconfigurations

What Cybersecurity Enterprise Strategies are Missing?

For years, cybersecurity strategies have focused on accumulation – collecting tools, more telemetry, and more layers of defence. For instance, respondents, on average, were dealing with 35 tools at a time. But as environments grow, they become harder to manage. The issue pertains to control, not to the visibility of risk.

“You had one product expert acting as five or six experts in one,” Hamilton explains. “That approach never scaled well.”

Today, this issue is worse. Teams inherit complex tools they can’t fully optimise or continuously validate. Over time, small changes—like exceptions, updates, and integrations—start to add up. No single change breaks the system, but together, they alter it.

Also Read: Configuration Lifecycle Management (CLM) That Reduces Complexity And Risk

Is Drift the Quiet Failure AI is Accelerating?

This shift is what insiders are increasingly referring to as configuration drift. It’s becoming one of the most overlooked risks in cybersecurity. It’s not dramatic or invisible, but it’s constant.

“If it isn’t broken, don’t touch it—that used to work,” Isurity CISO says. “Not so much anymore.”

In a pre-AI world, misconfigurations could linger for months before being exploited. Now, that time frame has shrunk. “The adversary can find it faster than that three-month or six-month window,” Hamilton warns.

The new reality is that enterprises are no longer just defending against external threats. They are now racing to keep up with changes within their own environments. AI too is making the problem worse. For example, rapid “vibe coding” can quickly create solutions, but those solutions tend to fail without ongoing maintenance.

“It worked for two or three months,” the Reach CEO notes, alluding to customer experience pertinent to vibe coding. “Then I returned to it—and it wasn’t working as expected.”

Drift isn’t a bug but a byproduct of speed.

Where AI Offers Real Value

For the past decade, cybersecurity investments have focused heavily on detection and response. However, that model is starting to show its weaknesses. There are too man

Episodes: The Security Strategist

PodliGet the free Podli app
↓ App