
Innovator Coffee
Innovator Coffee EP-43 2026 Blackhat: What's Crowded and What's New
Welcome to the Innovator Coffee, a podcast that bridges the gap between people and the world of AI and innovation. This is Wickey. Follow us to explore the top AI products, ecosystem insights, and the emerging trends. This episode of Innovator Coffee is a special Black Hat edition, bringing back first-hand observations from one of the world's largest security conferences in 2026. The host is joined by a CISO, a cybersecurity-focused VC, and two founders building AI security startups for a roundtable covering which areas at Black Hat felt most crowded this year, which capital flows reflect real demand versus hype, and the entirely new risks AI agents create that traditional tools simply can't see. Guest Introductions Victor Cheng: SVP, CIO, CISO and Platforms of Backstory His career started in IT before moving into payments, where handling PCI compliance in 2006 marked his entry into security and compliance. He has since spent nearly two decades in the field and is also active in venture capital, advising multiple startups. Sian Goldofsky: Founding Partner, SaaS Ventures Israel Founding partner of the Israeli arm of SaaS Ventures, a strategic investor that provides outsized value while taking minimal equity and control with cyber and AI focus with roughly 150 startups; about 40% of the U.S. fund is allocated to cybersecurity. Sian's own background is rooted in cybersecurity, with over a decade of professional experience in the space. Nadav Meiroviz: Co-founder & CEO, Conduct Nearly 15 years in cybersecurity, with military service in Israel's Unit 8200. Nadav co-founded Conduct with a childhood friend he's known since age seven, they went to the same classroom, the same university, and served in the same unit. Conduct is built to solve DLP (data loss prevention) and insider risk in the AI era. Mohan Kumar, Co-founder & CEO, Aira Security 15 years in security, Mohan co-founded his company with a friend of eight years; the two previously worked together at Box before his co-founder moved to AWS as a founding security engineer for Bedrock AgentCore, Amazon's platform for running AI agents in production. The company is a ten months old AI agent security startup, was part of the AWS*Nvidia*CrowdStrike accelerator. 8-Segment Timestamp Summary 1 00:04 – 00:40 The host frames the show and today's Black Hat theme, then introduces the four guests. 2 00:40 – 04:22 Guest introductions 3 04:22 – 06:20 First impressions of Black Hat this year: the intensity and aggressiveness of the shift toward agentic/AI topics exceeded expectations. 4 06:20 – 11:48 The most crowded spaces this year: AI SOC is saturated but still a necessary market; AI governance/posture-management vendors are everywhere; endpoint security is back in focus. 5 11:48 – 23:48 The Build vs. Buy debate and the "citizen developer" risk: AI coding agents let non-engineers build their own apps, fueling the "SaaS is dead" argument. Extends into DPA / sub-processor compliance risk. 6 23:48 – 33:27 New challenges from agentic workflows: short-lived agents are hard to audit or hold accountable; AI shows "ant-colony"-like survival behavior 7 33:27 – 41:03 How AI lowers the barrier to attacks: hyper-personalized phishing, malicious agents bypassing restrictions by hijacking a user's live session; the software supply chain trust-chain problem, the "outrun one bear" analogy, the dilemma between zero-day patching and a "30-day bake" policy, and security teams stuck in a reactive detect-and-respond loop. 8 41:03 – 48:00 Closing round: each guest shares a concrete action they're taking after Black Hat Thanks for Peter Qin helps with the editing Wickey Wang *IT Security Compliance Leader & University Faculty (AI security) *VC advisor and Angel Investor with cybersecurity and AI focus *GAI Security book co-author Questions, Suggestions, Feedback and Comments? You can find us in LinkedIn: https://www.linkedin.com/in/wickey-wang-cisa-six-sigma-green-belt-2aaa913/

