Resilient Cyber
Hosted by Chris Hughes
Supply chain, vulnerability management and AI agent security, from a practitioner who writes the books on them.
- Level
- Practitioner, assumes you work in or study security
- Status
- Active, last episode
- Who's behind it
- Independent, Chris Hughes sourceCompanion to the host's Resilient Cyber newsletter.
- Last verified
- Transcripts for some episodes
Listed underAppSecGRC and privacyCISO and leadership
Editorial take
The best weekly interview show for software supply chain and vulnerability management, now tilted hard toward AI agent security. Chris Hughes co-wrote Software Transparency and Effective Vulnerability Management, and his questions show it: he pushes guests on data, not slogans. Episodes run about 30 to 45 minutes, with a mix of practitioners, researchers, founders and investors. For a student, it is a fast way to learn the vocabulary of modern AppSec (SBOM, VEX, CVE prioritization, secure-by-design) from the people defining it. The limitation: many guests run startups in the space, so some episodes lean on one company's view of the problem, and the 2026 run is almost entirely AI.
Last hand-checked 2026-09-30.
Listen if you …
- work in AppSec, product security or vulnerability management and want the current debates
- are a student who wants to hear how supply chain and SBOM concepts play out in real programs
- follow AI agent security and want interviews rather than vendor webinars
Skip if you …
- you want breach stories or news, this is a topical interview show
- you are tired of AI, most 2026 episodes are about it
Start with these 3 episodes
- 01
Switching to Cyber - Navigating Cybersecurity Careers
· 33 min · Beginner
Helen Patton and Josiah Dykstra on moving into security mid-career; the most direct episode for career switchers.
- 02
Resilient Cyber w/ Patrick Garrity - 2025 VulnMgt Research Roundup
· 39 min · Practitioner
Hughes on home turf: a data-led review of a year of exploitation trends with VulnCheck's researcher.
- 03
S6E21: Christoph Kern - Dissecting Secure-by-Design
· 46 min · Practitioner
Google's Christoph Kern on secure-by-design engineering; durable thinking that will not date with the news cycle.
About the show
Resilient Cyber is Chris Hughes's interview podcast, the audio companion to his Resilient Cyber newsletter. Hughes is a US Air Force veteran, co-founder of Aquia and the co-author of two Wiley books on software supply chain security and vulnerability management.
The show started in February 2021 with public sector and DoD software modernization guests, ran in numbered seasons through mid-2024, and has since moved to standalone weekly interviews. Recurring subjects are software supply chain security, CVE and NVD data, AppSec tooling, GRC engineering, cyber investing, and, since 2025, AI agents.
Notable guests
- Phil Venables
- Tanya Janca
- Kelly Shortridge
- Allan Friedman
- Andy Ellis
- Jim Manico
- Dan Lorenc
- Christoph Kern
Pairs with
If Resilient Cyber works for you, these likely will too.
Absolute AppSec
Ken Johnson · Seth Law
Two working AppSec practitioners arguing about what actually helps developers ship safer code.
Listen if you run or work on an application security program and want peers' honest opinions.
panelweekly60m+Application Security Weekly
Mike Shema · John Kinsella · Kalyani Pawar
An hour a week on finding and fixing software flaws, from secure design to LLM-written code.
Listen if you build or secure software and want one reliable AppSec interview a week.
mixedweekly60m+AI Security Podcast
Ashish Rajan · Caleb Sima
Two former CISOs separate real AI security risk from vendor noise, for the people who have to sign off on it.
Listen if you are a CISO or security architect being asked to approve AI agents and copilots.
mixedbiweekly30–60mCloud Security Podcast
Ashish Rajan
Practitioners from Netflix, Block, and Adobe explain how they actually run cloud security, now with a heavy AI tilt.
Listen if you are a cloud or platform engineer moving into security.
interviewbiweekly30–60m