A CISO's Guide to Securing Agentic AI: Governance, Shadow AI and Zero-Trust Agents — feat. Peter Holcomb (Optimo IT)
PETER HOLCOMB — Peter Holcomb — Optimo IT
When your app's "brain" is a non-deterministic LLM and your agents can roam autonomously, who owns security — and can you even secure the beehive? Alex Belotsky sits down with Pete…
Show notes
When your app's "brain" is a non-deterministic LLM and your agents can roam autonomously, who owns security — and can you even secure the beehive? Alex Belotsky sits down with Peter Holcomb, founder and CEO of Optimo IT, for a classically-trained CISO's field guide to deploying AI in regulated enterprises. Peter walks through starting with an AI governance and maturity assessment before writing a line of code, the crawl-walk-run path from Microsoft Copilot to custom agents, and why messy, unclassified data (across OneDrive, S3, Azure blobs) is the real blocker — solved with a data enclave and the medallion (bronze/silver/gold) framework. The conversation digs into the concrete new attack surface: model risk across Anthropic, OpenAI, Gemini and open-source models, prompt injection, vector-database and API risks, and the rise of "shadow AI" — including autonomous tools like OpenClaw/Clawbot pulling unvetted third-party skills and triggering infostealer infections. Peter argues human-in-the-loop is still the best available brake, sketches a "unified agentic mesh" pulling together DSPM, DLP, SOAR (Tines, Torq, BlinkOps) and CNAPP tooling (Wiz, Aqua, Orca), and makes the case for zero-t