Oct 15, 2025 · 30m · big-technology

Is the AI Boom About to Break Security? — With Grady Summers, CEO of Netwrix

Grady Summers · 19m spoken Alex Kantrowitz · 8m spoken
0:00 / 0:00
▶ Watch on YouTube →

gold bands on the timeline = statements, start to end. Hover to read, click to jump. CC turns on captions

Netwrix CEO Grady Summers joins Alex Kantrowitz to examine how generative AI is transforming enterprise software development and reshaping cybersecurity. Summers shares practical operational deployment strategies, analyzes emerging threat vectors like prompt injection and permission leakage, and explains why mastering core data governance fundamentals is essential in an AI-driven landscape.

How this conversation actually went

Every chapter scored 0–10 on four independent dynamics. Hover any point for the reasoning behind the score. Alex holds 29.6% of the talking time here. How this is scored →

Alex as informed peer 5.5 Guest teaching 5.3 Guest disagreement 0.9 Alex pushing back 1.7
05100:0010:0020:0030:000:14–2:16 · Alex as informed peer 5/10 AI Job Displacement vs. Economic Growth Alex opens with the macroeconomic debate on AI displacement, prompting Grady to outline Netwrix's aggressive adoption strategy. Kantrowitz aligns immediately with Summers's view that focusing solely on cost-cutting is short-sighted.2:17–5:20 · Alex as informed peer 6/10 Transitioning from Augmentation to Internal Automation Alex cites the Anthropic economic index tracking the transition from augmentation to automation. Grady educates the audience with concrete internal operational examples, including a custom deal desk GPT and customer service automation.5:20–8:49 · Alex as informed peer 6/10 Build vs. Buy Strategies and Addressing AI Project Failures Alex references an MIT study showing high enterprise failure rates in internal AI development to probe Netwrix's strategy. Grady explains why projects fail, describing how giving mediocre developers 'jetpacks' creates rapid architectural drift and 'crimes against technology.'8:52–12:03 · Alex as informed peer 6/10 Theory of Constraints: Shifting Development Bottlenecks Grady introduces the theory of constraints, explaining that speeding up coding shifts bottlenecks to product management and specifications. Kantrowitz asks a pointed clarifying question about whether AI lifts the floor for average developers or solely accelerates top talent.12:03–15:02 · Alex as informed peer 7/10 AI Market Trajectory, Economics, and Subsidies Kantrowitz challenges Summers on the economic sustainability of foundational model labs, asking whether relying on heavily VC-subsidized compute poses a long-term business risk. Grady concedes that enterprise users are currently benefiting from VC subsidies while making hay.15:02–17:30 · Alex as informed peer 7/10 The Expanding Attack Surface of Enterprise AI Alex frames how generative AI flips enterprise security from external perimeter defense to internal data leakage risks. Grady confirms this analysis and details novel prompt injection exploits using hidden text.17:31–20:30 · Alex as informed peer 5/10 Voice Cloning, AI Spoofing, and Social Engineering Alex discusses voice synthesis vulnerabilities based on his experience licensing his own voice. Grady shares how organizations run voice spoofing phishing drills and notes generational differences in detecting synthesized audio.20:31–25:04 · Alex as informed peer 5/10 Cybersecurity Fundamentals vs. Vendor Over-Complexity Alex questions why cybersecurity remains overwhelmingly complex despite basic core principles. Grady gives a candid critique of vendor conference gimmicks and strips security down to three fundamental rules: knowing assets, setting policy, and enforcing it.25:04–28:15 · Alex as informed peer 5/10 Data Governance: Uncovering Dormant and Accumulating Permissions Alex asks whether AI agents are actively exposing corporate secrets today. Grady explains how LLMs uncover dormant, accumulated legacy permissions that employees forgot they had, with Alex sharing a corroborating anecdote.28:16–29:49 · Alex as informed peer 3/10 Life Beyond Tech: Farming and Grounding Perspective The conversation closes with light personal banter about Summers's family farm and the therapeutic value for tech workers of getting away from screens to touch dirt.0:14–2:16 · Guest teaching 3/10 AI Job Displacement vs. Economic Growth Alex opens with the macroeconomic debate on AI displacement, prompting Grady to outline Netwrix's aggressive adoption strategy. Kantrowitz aligns immediately with Summers's view that focusing solely on cost-cutting is short-sighted.2:17–5:20 · Guest teaching 6/10 Transitioning from Augmentation to Internal Automation Alex cites the Anthropic economic index tracking the transition from augmentation to automation. Grady educates the audience with concrete internal operational examples, including a custom deal desk GPT and customer service automation.5:20–8:49 · Guest teaching 7/10 Build vs. Buy Strategies and Addressing AI Project Failures Alex references an MIT study showing high enterprise failure rates in internal AI development to probe Netwrix's strategy. Grady explains why projects fail, describing how giving mediocre developers 'jetpacks' creates rapid architectural drift and 'crimes against technology.'8:52–12:03 · Guest teaching 6/10 Theory of Constraints: Shifting Development Bottlenecks Grady introduces the theory of constraints, explaining that speeding up coding shifts bottlenecks to product management and specifications. Kantrowitz asks a pointed clarifying question about whether AI lifts the floor for average developers or solely accelerates top talent.12:03–15:02 · Guest teaching 4/10 AI Market Trajectory, Economics, and Subsidies Kantrowitz challenges Summers on the economic sustainability of foundational model labs, asking whether relying on heavily VC-subsidized compute poses a long-term business risk. Grady concedes that enterprise users are currently benefiting from VC subsidies while making hay.15:02–17:30 · Guest teaching 6/10 The Expanding Attack Surface of Enterprise AI Alex frames how generative AI flips enterprise security from external perimeter defense to internal data leakage risks. Grady confirms this analysis and details novel prompt injection exploits using hidden text.17:31–20:30 · Guest teaching 5/10 Voice Cloning, AI Spoofing, and Social Engineering Alex discusses voice synthesis vulnerabilities based on his experience licensing his own voice. Grady shares how organizations run voice spoofing phishing drills and notes generational differences in detecting synthesized audio.20:31–25:04 · Guest teaching 7/10 Cybersecurity Fundamentals vs. Vendor Over-Complexity Alex questions why cybersecurity remains overwhelmingly complex despite basic core principles. Grady gives a candid critique of vendor conference gimmicks and strips security down to three fundamental rules: knowing assets, setting policy, and enforcing it.25:04–28:15 · Guest teaching 7/10 Data Governance: Uncovering Dormant and Accumulating Permissions Alex asks whether AI agents are actively exposing corporate secrets today. Grady explains how LLMs uncover dormant, accumulated legacy permissions that employees forgot they had, with Alex sharing a corroborating anecdote.28:16–29:49 · Guest teaching 2/10 Life Beyond Tech: Farming and Grounding Perspective The conversation closes with light personal banter about Summers's family farm and the therapeutic value for tech workers of getting away from screens to touch dirt.0:14–2:16 · Guest disagreement 0/10 AI Job Displacement vs. Economic Growth Alex opens with the macroeconomic debate on AI displacement, prompting Grady to outline Netwrix's aggressive adoption strategy. Kantrowitz aligns immediately with Summers's view that focusing solely on cost-cutting is short-sighted.2:17–5:20 · Guest disagreement 1/10 Transitioning from Augmentation to Internal Automation Alex cites the Anthropic economic index tracking the transition from augmentation to automation. Grady educates the audience with concrete internal operational examples, including a custom deal desk GPT and customer service automation.5:20–8:49 · Guest disagreement 1/10 Build vs. Buy Strategies and Addressing AI Project Failures Alex references an MIT study showing high enterprise failure rates in internal AI development to probe Netwrix's strategy. Grady explains why projects fail, describing how giving mediocre developers 'jetpacks' creates rapid architectural drift and 'crimes against technology.'8:52–12:03 · Guest disagreement 1/10 Theory of Constraints: Shifting Development Bottlenecks Grady introduces the theory of constraints, explaining that speeding up coding shifts bottlenecks to product management and specifications. Kantrowitz asks a pointed clarifying question about whether AI lifts the floor for average developers or solely accelerates top talent.12:03–15:02 · Guest disagreement 1/10 AI Market Trajectory, Economics, and Subsidies Kantrowitz challenges Summers on the economic sustainability of foundational model labs, asking whether relying on heavily VC-subsidized compute poses a long-term business risk. Grady concedes that enterprise users are currently benefiting from VC subsidies while making hay.15:02–17:30 · Guest disagreement 1/10 The Expanding Attack Surface of Enterprise AI Alex frames how generative AI flips enterprise security from external perimeter defense to internal data leakage risks. Grady confirms this analysis and details novel prompt injection exploits using hidden text.17:31–20:30 · Guest disagreement 1/10 Voice Cloning, AI Spoofing, and Social Engineering Alex discusses voice synthesis vulnerabilities based on his experience licensing his own voice. Grady shares how organizations run voice spoofing phishing drills and notes generational differences in detecting synthesized audio.20:31–25:04 · Guest disagreement 2/10 Cybersecurity Fundamentals vs. Vendor Over-Complexity Alex questions why cybersecurity remains overwhelmingly complex despite basic core principles. Grady gives a candid critique of vendor conference gimmicks and strips security down to three fundamental rules: knowing assets, setting policy, and enforcing it.25:04–28:15 · Guest disagreement 1/10 Data Governance: Uncovering Dormant and Accumulating Permissions Alex asks whether AI agents are actively exposing corporate secrets today. Grady explains how LLMs uncover dormant, accumulated legacy permissions that employees forgot they had, with Alex sharing a corroborating anecdote.28:16–29:49 · Guest disagreement 0/10 Life Beyond Tech: Farming and Grounding Perspective The conversation closes with light personal banter about Summers's family farm and the therapeutic value for tech workers of getting away from screens to touch dirt.0:14–2:16 · Alex pushing back 1/10 AI Job Displacement vs. Economic Growth Alex opens with the macroeconomic debate on AI displacement, prompting Grady to outline Netwrix's aggressive adoption strategy. Kantrowitz aligns immediately with Summers's view that focusing solely on cost-cutting is short-sighted.2:17–5:20 · Alex pushing back 1/10 Transitioning from Augmentation to Internal Automation Alex cites the Anthropic economic index tracking the transition from augmentation to automation. Grady educates the audience with concrete internal operational examples, including a custom deal desk GPT and customer service automation.5:20–8:49 · Alex pushing back 2/10 Build vs. Buy Strategies and Addressing AI Project Failures Alex references an MIT study showing high enterprise failure rates in internal AI development to probe Netwrix's strategy. Grady explains why projects fail, describing how giving mediocre developers 'jetpacks' creates rapid architectural drift and 'crimes against technology.'8:52–12:03 · Alex pushing back 2/10 Theory of Constraints: Shifting Development Bottlenecks Grady introduces the theory of constraints, explaining that speeding up coding shifts bottlenecks to product management and specifications. Kantrowitz asks a pointed clarifying question about whether AI lifts the floor for average developers or solely accelerates top talent.12:03–15:02 · Alex pushing back 5/10 AI Market Trajectory, Economics, and Subsidies Kantrowitz challenges Summers on the economic sustainability of foundational model labs, asking whether relying on heavily VC-subsidized compute poses a long-term business risk. Grady concedes that enterprise users are currently benefiting from VC subsidies while making hay.15:02–17:30 · Alex pushing back 1/10 The Expanding Attack Surface of Enterprise AI Alex frames how generative AI flips enterprise security from external perimeter defense to internal data leakage risks. Grady confirms this analysis and details novel prompt injection exploits using hidden text.17:31–20:30 · Alex pushing back 1/10 Voice Cloning, AI Spoofing, and Social Engineering Alex discusses voice synthesis vulnerabilities based on his experience licensing his own voice. Grady shares how organizations run voice spoofing phishing drills and notes generational differences in detecting synthesized audio.20:31–25:04 · Alex pushing back 3/10 Cybersecurity Fundamentals vs. Vendor Over-Complexity Alex questions why cybersecurity remains overwhelmingly complex despite basic core principles. Grady gives a candid critique of vendor conference gimmicks and strips security down to three fundamental rules: knowing assets, setting policy, and enforcing it.25:04–28:15 · Alex pushing back 1/10 Data Governance: Uncovering Dormant and Accumulating Permissions Alex asks whether AI agents are actively exposing corporate secrets today. Grady explains how LLMs uncover dormant, accumulated legacy permissions that employees forgot they had, with Alex sharing a corroborating anecdote.28:16–29:49 · Alex pushing back 0/10 Life Beyond Tech: Farming and Grounding Perspective The conversation closes with light personal banter about Summers's family farm and the therapeutic value for tech workers of getting away from screens to touch dirt.

speaking balance: gold is Alex, purple is the guest (3 minute bins)

0:00 · Alex 39.6% · guest 60.4%0:00 · Alex 39.6% · guest 60.4%3:00 · Alex 16.6% · guest 83.4%3:00 · Alex 16.6% · guest 83.4%6:00 · Alex 2.5% · guest 97.5%6:00 · Alex 2.5% · guest 97.5%9:00 · Alex 16.2% · guest 83.8%9:00 · Alex 16.2% · guest 83.8%12:00 · Alex 35.5% · guest 64.5%12:00 · Alex 35.5% · guest 64.5%15:00 · Alex 63.1% · guest 36.9%15:00 · Alex 63.1% · guest 36.9%18:00 · Alex 48.1% · guest 51.9%18:00 · Alex 48.1% · guest 51.9%21:00 · Alex 14.5% · guest 85.5%21:00 · Alex 14.5% · guest 85.5%24:00 · Alex 24.4% · guest 75.6%24:00 · Alex 24.4% · guest 75.6%27:00 · Alex 37.1% · guest 62.9%27:00 · Alex 37.1% · guest 62.9%30:00 · Alex 27.4% · guest 72.6%30:00 · Alex 27.4% · guest 72.6%
Sharpest disagreement ▶ 6:37 Summers rejects checkbox AI outsourcing

Grady forcefully dismisses the approach of enterprise peers who simply pay vendors a 50% premium for out-of-the-box add-ons, insisting companies cannot 'checkbox your way to greatness.'

Hardest push from Alex ▶ 13:38 Kantrowitz challenges the commercial viability of AI model providers

Alex pushes past Grady's optimism to question the underlying financial vulnerability of relying on AI labs that burn massive VC capital and may drastically raise prices later.

Biggest teaching moment ▶ 25:28 Summers breaks down how AI surfaces dormant permissions

Grady educates the host on how modern enterprise LLMs create data breaches not by failing permissions, but by surfacing years of accumulated, forgotten access rights.

Alex holds their own ▶ 15:23 Kantrowitz articulates the inversion of cybersecurity attack surfaces

Alex delivers a comprehensive domain assessment detailing how enterprise AI shifts cybersecurity from external perimeter defense to internal insider threats and data sprawl.

the scores for every segment, with the reasoning behind each
ChapterTopicAlex as informed peerGuest teachingGuest disagreementAlex pushing backWhy
AI Job Displacement vs. Economic Growth 5301 Alex opens with the macroeconomic debate on AI displacement, prompting Grady to outline Netwrix's aggressive adoption strategy. Kantrowitz aligns immediately with Summers's view that focusing solely on cost-cutting is short-sighted.
Transitioning from Augmentation to Internal Automation 6611 Alex cites the Anthropic economic index tracking the transition from augmentation to automation. Grady educates the audience with concrete internal operational examples, including a custom deal desk GPT and customer service automation.
Build vs. Buy Strategies and Addressing AI Project Failures 6712 Alex references an MIT study showing high enterprise failure rates in internal AI development to probe Netwrix's strategy. Grady explains why projects fail, describing how giving mediocre developers 'jetpacks' creates rapid architectural drift and 'crimes against technology.'
Theory of Constraints: Shifting Development Bottlenecks 6612 Grady introduces the theory of constraints, explaining that speeding up coding shifts bottlenecks to product management and specifications. Kantrowitz asks a pointed clarifying question about whether AI lifts the floor for average developers or solely accelerates top talent.
AI Market Trajectory, Economics, and Subsidies 7415 Kantrowitz challenges Summers on the economic sustainability of foundational model labs, asking whether relying on heavily VC-subsidized compute poses a long-term business risk. Grady concedes that enterprise users are currently benefiting from VC subsidies while making hay.
The Expanding Attack Surface of Enterprise AI 7611 Alex frames how generative AI flips enterprise security from external perimeter defense to internal data leakage risks. Grady confirms this analysis and details novel prompt injection exploits using hidden text.
Voice Cloning, AI Spoofing, and Social Engineering 5511 Alex discusses voice synthesis vulnerabilities based on his experience licensing his own voice. Grady shares how organizations run voice spoofing phishing drills and notes generational differences in detecting synthesized audio.
Cybersecurity Fundamentals vs. Vendor Over-Complexity 5723 Alex questions why cybersecurity remains overwhelmingly complex despite basic core principles. Grady gives a candid critique of vendor conference gimmicks and strips security down to three fundamental rules: knowing assets, setting policy, and enforcing it.
Data Governance: Uncovering Dormant and Accumulating Permissions 5711 Alex asks whether AI agents are actively exposing corporate secrets today. Grady explains how LLMs uncover dormant, accumulated legacy permissions that employees forgot they had, with Alex sharing a corroborating anecdote.
Life Beyond Tech: Farming and Grounding Perspective 3200 The conversation closes with light personal banter about Summers's family farm and the therapeutic value for tech workers of getting away from screens to touch dirt.

Statements from this episode (14)

Prediction Not checkable as stated
Summers: Tech Industry's Unmet Demand Means AI Will Create Net Jobs
“As to whether it's going to create jobs or kill jobs, absolutely going to create jobs. There's so much unmet demand in our industry.”
Grady Summers Oct 15, 2025 ▶ 0:58
Assertion Not checkable as stated
Summers: Internal Analysis Shows 40% of Employee AI Usage Is Rewriting
“I recently wrote a script that analyzes like the sentiment, what people are doing with AI and the company. And it was about 35, 40% of the usage was just rewriting things.”
Grady Summers Oct 15, 2025 ▶ 3:05
Disclosure
Summers: Netwrix Automates Deal Desk to Hire More Engineers Next Year
“And the net net of that is we'll add more jobs next year. Cause I don't have to spend some, you know, the money to have somebody doing deal desk work. I could hire an engineer that's doing work to make customers happy.”
Grady Summers Oct 15, 2025 ▶ 5:09
Insight
Summers: Companies Must Build Core AI In-House Rather Than Relying on Vendors
“I don't think you can like checkbox your way to greatness and outsource your AI to, you know, Salesforce or Palo Alto. It's great. I love these companies, right? But we've got to build it in house.”
Grady Summers Oct 15, 2025 ▶ 6:42
Insight
Summers: AI tools enable 10x developer speedups
“What we're finding with AI is it lets everybody go so much faster. Like, I mean, I think when we started out, we're like, can we go 20% faster, maybe 30% faster. I think it's like 10 x faster that we can move.”
Grady Summers Oct 15, 2025 ▶ 7:07
Insight
Summers: AI Makes Mediocre Developers Build Off-Course 10x Faster
“The problem is even a mediocre developer goes 10 times faster. And I'd like to think, you know, hey, we all want eight players, but the fact is you have Mixed level of competency in an organization and you give them all a lightsaber or like this jet pack where…”
Grady Summers Oct 15, 2025 ▶ 7:22
Insight
Summers: AI Coding Speedups Expose Bottlenecks in Product Management and Marketing
“The constraint was always your developers writing code. And what that meant is you could get away with being a little bit sloppy and like product management, for example, maybe your specs were just sort of wishy-washy. Product marketing maybe could come in at …”
Grady Summers Oct 15, 2025 ▶ 9:08
Prediction Not checkable as stated
Summers: Companies Will Cut R&D Spend But Pay Top Developers Significantly More
“I think the future here is we're going to be paying good developers a heck of a lot more you know, we'll probably spend less on our R and D overall, but the good developers will make a ton more.”
Grady Summers Oct 15, 2025 ▶ 11:22
Disclosure
Summers: Top Individual Netwrix Developers Consume $4,000 in Monthly Anthropic Credits
“Some of our best developers might be using, you know, a thousand dollars in anthropic credits a month. And then we find somebody who's using like 4000 a month.”
Grady Summers Oct 15, 2025 ▶ 14:38
Assertion Supported
Summers: Attackers Use Hidden White Text to Exfiltrate Enterprise LLM Data
“And just in the last few weeks, we've seen these really innovative Attacks where somebody will open up you know, something that's got instructions to an LLM. So it's processed within an LLM, but you know, it's hidden. It's like white text on a white background…”
Grady Summers Oct 15, 2025 ▶ 16:47
Assertion Supported
Kantrowitz: Zoom and Klarna CEOs Are Using Video Avatars for Earnings Calls
“Even the CEOs of zoom and Klarna are doing earnings calls as video avatars.”
Alex Kantrowitz Oct 15, 2025 ▶ 18:33
Insight
Summers: Successful Cybersecurity Boils Down to Asset Tracking, Policy, and Enforcement
“You could be successful building a security program. Just three things. And I've been saying this for a long time. It's, do you know what you have? Because that could be computers. It could be servers. It could be cloud assets. It could be identities. It could…”
Grady Summers Oct 15, 2025 ▶ 22:18
Assertion Not checkable as stated
Summers: CISOs Fear Internal LLMs Will Uncover Existing Unintended Employee Access
“Almost every CISO I'm talking to now is, is concerned about Giving LLMs access to data for that reason. Not that the LLM is going to do something wrong, but it's going to let people search and find things way more powerfully and join information they didn't ev…”
Grady Summers Oct 15, 2025 ▶ 26:28
Insight
Summers: Enterprises Must Tolerate AI Rollout Mistakes Rather Than Blocking Chatbots
“The right reaction is, Hey, we're going to make a few mistakes along the way, but we got to let our people like get comfortable with this and use it in their daily workflows. And I feel like we're at that point with AI, we have to be careful. We don't want to …”
Grady Summers Oct 15, 2025 ▶ 27:01
Made with StarZero

Turn any episode into a week of clips.

This entire site, over 300 episodes transcribed, diarized, checked and made playable, runs on the StarZero media pipeline. Drop in your own episode and the podcast clipper finds the moments worth sharing, cuts them, captions them, and reframes them for every feed.