Podcast Episode
Patch Now, Govern Faster: SharePoint Fire Drills, Vendor Blast Radius & the AI Agent Gap

About this episode
Patch now, govern faster. This week Shawn Valle and Garrett Gross break down three stories every security leader needs on their radar: the SharePoint zero-days under active attack (and CISA's 72-hour patch mandate), the Craneware breach that put 2,000 hospitals in the blast radius of a single vendor, and Gartner's warning that AI agents are hitting production 8x faster than governance can keep up — with $234B at risk.Cybersecurity Growth is a show for aspiring and existing cybersecurity leaders, hosted by Shawn Valle and Garrett Gross.⏱️ CHAPTERS 0:00 Cold open + welcome 2:30 A word from Cybersecurity Growth 3:30 SharePoint zero-days: CISA says patch in 3 days 11:00 Craneware breach: one vendor, 2,000 hospitals of blast radius 18:30 Gartner: AI agents outpacing governance 8-to-1, $234B at risk 26:00 Rapid takeaways you can use Monday morning🔗 STORIES WE COVEREDCISA urges immediate SharePoint patching: https://www.securityweek.com/cisa-urges-immediate-patching-of-exploited-sharepoint-vulnerabilities/CISA SharePoint hardening alert: https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-urges-sharepoint-hardening-after-new-exploitationsCraneware breach (TechCrunch): https://techcrunch.com/2026/07/20/hackers-stole-significant-amount-of-data-from-tech-firm-relied-on-by-thousands-of-us-hospitals-and-pharmacies/Gartner: agentic AI puts $234B at risk (CIO): https://www.cio.com/article/4192242/agentic-ai-puts-234b-in-enterprise-saas-spending-at-risk-gartner-says.htmlGartner on tiered AI agent governance: https://www.gartner.com/en/newsroom/press-releases/2026-05-26-gartner-says-applying-uniform-governance-across-ai-agents-will-lead-to-enterprise-ai-agent-failure
🎓 LEVEL UP YOUR LEADERSHIP The Cybersecurity Growth platform is live — self-paced courses like "The First 100 Days of a CISO," program-building templates, and a community of global cyber leaders. Courses count toward CPEs (CISSP and more). Free trials at https://CybersecurityGrowth.com📬 CONNECTSubscribe on YouTube + hit the bellListen on your favorite podcast appShorts on TikTokLive every other week on Twitch + YouTube
New episodes every 2 weeks. Thanks for growing with us.#Cybersecurity #CISO #Leadership #AISecurity #SharePoint #ThirdPartyRisk #AIGovernance #CyberLeadershipSHOW NOTES Patch Now, Govern FasterSharePoint under fire (3:30). Four SharePoint CVEs are being actively exploited, including an unauthenticated RCE, and CISA gave federal agencies just 3 days to patch. Attackers are chaining bugs to steal IIS machine keys and persist — meaning patching alone won't evict them; key rotation is required. We debate the real leadership call: emergency weekend change window vs. normal change control, and whether on-prem SharePoint should exist in your environment at all in 2026.The vendor blast radius problem (11:00). Craneware — billing software behind ~2,000 US hospitals and ~10,000 clinics and pharmacies — confirmed attackers exfiltrated a significant volume of data. Same week, Hugging Face disclosed a malicious-dataset attack that stole credentials off its infrastructure. Two supply-chain intrusions in one news cycle is a pattern. We dig into what a real vendor-breach playbook looks like, and how much disclosure — and how fast — you should demand from critical vendors.The AI agent governance gap (18:30). Gartner says AI agents are entering production 7–8x faster than orgs are building governance, with $234B in enterprise software spend at risk by 2030 and 40%+ of agentic AI projects predicted to be canceled by 2027. Their contrarian take: uniform governance across all agents guarantees failure — tier it by autonomy and risk. The real question is organizational, not technical: who owns agent identity and authorization at your company?Monday-morning takeaways (26:00). Ask your team: do we run on-prem SharePoint anywhere, and which critical vendors have breach-notification SLAs in their contracts? Then start an AI agent inventory — even a spreadsheet of what agents exist, what they can touch, and who approved them puts you ahead of most orgs.Hosted by Shawn Valle (Founder & Chief Strategist, Cybersecurity Growth) and Garrett Gross. Learn more at https://CybersecurityGrowth.com