Episode

The Rise of CTEM - Why AI Demands a New Approach to Security

Podcast
Razorwire Cyber Security & InfoSec Insights
Published
Apr 8, 2026
Duration seconds
3434
Processing state
not_requested
Canonical source
https://razorwire.captivate.fm/episode/the-rise-of-ctem-why-ai-demands-a-new-approach-to-security
Audio
https://op3.dev/e/episodes.captivate.fm/episode/48ddd11e-30e6-47a2-8fbf-11507b29b6f1.mp3
JSON
/v1/public/podcasts/razorwire-cyber-security-infosec-insights-5584923/episodes/the-rise-of-ctem-why-ai-demands-a-new-approach-to-security
Markdown
/podcast/razorwire-cyber-security-infosec-insights-5584923/the-rise-of-ctem-why-ai-demands-a-new-approach-to-security.md

Actions

  • POST https://stenobird.com/v1/public/podcasts/razorwire-cyber-security-infosec-insights-5584923/episodes/the-rise-of-ctem-why-ai-demands-a-new-approach-to-security/transcription-requests
    Idempotently request low-priority transcript generation for this episode.
  • GET https://stenobird.com/podcast/razorwire-cyber-security-infosec-insights-5584923/the-rise-of-ctem-why-ai-demands-a-new-approach-to-security.md
    Read the agent-friendly Markdown representation of this episode resource.

Summary

What happens when your organisation adopts AI faster than your security strategy can keep up? Welcome to Razorwire, the podcast where we share our take on the world of cybersecurity with direct, practical advice for professionals and business owners alike. I'm Jim, and in this episode, I'm joined by Martin Voelk, penetration tester and AI red teamer, and Jonathan Care, lead analyst covering the intersection of AI, cybersecurity and identity. We started out planning to talk about the rise of CTEM (Continuous Threat Exposure Management) and why traditional pentesting and vulnerability scanning can't keep up anymore. But the conversation quickly went further than that, into the real security risks of AI agents, prompt injection, vibe coding and the speed at which organisations are adopting AI without thinking about what happens when it goes wrong. Martin shares examples from his red teaming work of how AI agents can be tricked into exfiltrating data and executing malicious code, Jonathan makes the case for why identity needs to become a first class attack surface in any CTEM programme; and all three of us end up genuinely concerned about what happens when CISOs are expected to govern technology that's moving faster than anyone can keep up with. This one ended up not going quite as planned, and it's all the better for it. Three key talking points: Why traditional security testing can't keep up with AI and agent-driven attacks: Annual pentests and periodic vulnerability scans were built for a world where things changed slowly. Martin and Jonathan explain why that model is no longer suitable when new AI vulnerabilities are emerging daily, most of them without a CVE number attached, and why CTEM as a continuous programme rather than a one-off exercise is becoming essential. H…