This episode explores the evolving landscape of cyber resiliency in 2026, emphasizing the importance of operational continuity, AI-driven security tools, and human expertise in cybersecurity. Our VP of Sales and Partnerships, Ron Vaz, and Founder/CISO of B & B Cyber Solutions LLC, Peter Bagley, share insights on strategic risk management, AI integration, and talent development to stay resilient against cyber threats.
Key Takeaways
- Shift from unhackable to prepared at all times
- AI’s impact on cybersecurity strategies
- Balancing security tools with human expertise
- Importance of training and talent in cybersecurity
- Managing false positives and trust in AI systems
Transcript
Kchristaihne Castillo (00:51.992)
Hey everyone! Welcome back to Sold Out Chat. I’m K, the Marketing Coordinator here at Above Promotions. Today, we are continuing our deep dive into the pillar of modern leadership, “Building Cyber Resiliency”. As we move further into 2026, the question isn’t about just stopping a breach, it’s about how your business survives and thrives during one. So, to help us unpack this, we have two fantastic guests.
First, we’ll hear from our very own VP of Sales and Partnerships, Ron Vaz. With over a decade of expertise in strategic planning and growth, Ron is the architect behind our high-level B2B relationships. Interestingly, he’s also the acclaimed owner and lead photographer at Broadway Photography, giving him a unique visual perspective on the business world. Hi, Ron!
Ron Vaz (01:49.144)
Hey, K. It’s great to be here today.
Ron Vaz (01:53.93)
And we’re honored to have Peter Bagley, a retired army information system analyst with 40 plus years of IT experience. Peter is a security professional at St. Pete College and the founder of BNB Cyber Solutions. He holds a master’s in information system management and more industry credentials than we have time to list today. From CISSP to CCISO. How you doing today, Peter?
Peter Bagley (02:21.434)
about you?
Ron Vaz (02:26.224)
doing great, really interested in getting here, a bit of your knowledge on the topics today.
Ron Vaz (02:34.758)
All right, so let’s jump right in. All right, here we go. In the past, the goal was to be unhackable. Today, with the speed of AI, how has AI shifted the strategy from just stopping attacks to ensure businesses can maintain operations during an ongoing threat?
Peter Bagley (02:35.049)
I’ll give it my best shot.
Peter Bagley (02:57.83)
It thinks it changes a lot, think more than anything due to the nature of the speed and everything’s moving so quickly. it’s kind of a shift from unhackable to being prepared at all times to be hacked. Kind of like the defense in depth flipped into zero trust. and that kind of helps us always be on a ready to hopefully in case something happens, we’ve already put a lot of controls in place security wise to kind of offset that.
But you still got to have things out there like detection and response in real time. You want to maybe have that if you can. Hopefully most organizations already have that. Automated containment using some form of AI if you’re going to use AI. And then lastly, business continuity under the active attack role, which goes back to using like the minor attack model that will also give you a chance to be prepared in case something happens, as well as if something does.
It’ll give you some steps to react and hopefully mitigate whatever situation is.
Ron Vaz (04:04.034)
It’s got the point where it’s not if you’re going to get hacked, it’s when you’re going to get hacked and how you respond to it at that point.
Peter Bagley (04:11.941)
Exactly. Yeah. Because it’s going to happen. Won’t work out. Unfortunately.
Ron Vaz (04:21.254)
yeah, no matter how big or small you are, it’s gonna come for you.
Peter Bagley (04:27.599)
Exactly, exactly.
Ron Vaz (04:30.544)
Cyber security is often viewed as a cost center. Is there a balance that executives can see with security professionals, that AI-driven security tools? With this mix, can there be competitive advantages or just another line item on the budget?
Peter Bagley (04:49.938)
I think it could be both depending on the organization and how they’re utilizing one which they already have. That’s one thing that lot of organizations even as of today, if they bought and I’ll call them toys, some new toys as in systems, software within the last four to five years, it’s already AI integrated into it. Problem is though, are they fully utilizing the toys they have?
And that’s where they kind of come into a situation where it could be a cost issue because then you’re out there one duplicating which already have instead of trying to find out, does this allow us, whatever this is to move forward and do the things we want to do? If not, then you look at alternatives, but AI can reduce the manual labor part of it to where you won’t have to kind of have so many people touching the keys. But at the same time, you have to maintain the human touch because
AI is, again, I call it a tool. And because it is a tool, you have people that need to know how to use the tool and fully utilize the capability of the tool. So that really comes down to the cost aspect of things. Because in a lot of cases, a lot of these companies already have some of the capabilities they’re looking for to kind of offset that cost. They just need to do training, get their people trained up on what those capabilities are, because there goes another aspect of it. Yes, there’s a cost.
But the cost of training someone compared to buying a new product is a lot less than you would do if you’re going to buy a brand new product.
Ron Vaz (06:24.566)
I think from a lot of organizations that I’ve spoken to and that I’ve either worked with or worked alongside of, the issue a lot of times comes down to the fact that a lot of them, like you said, they have the tools, they’re not using it to its ultimate capabilities. And they’re looking at it to say, okay, it costs too much money for this extra add-on within the same tool. But at the end of the day,
Peter Bagley (06:44.72)
Mm-hmm.
Ron Vaz (06:51.066)
that one tool that you may spend an extra five, $10,000 on, if that is the loophole, if that’s the hole that in your security system that somebody hacks into, that can cost you millions or cost your entire business right there.
Ron Vaz (07:10.31)
So we’re seeing a literal arms race between malicious AI. OK. You know what saying? The loophole that they choose not to fill, that could be the hole that the malicious bad actors are getting into. And that can save them between $5,000 and $5,000.
Peter Bagley (07:13.164)
I think I missed that last part of what you were saying there, Ron.
Peter Bagley (07:34.444)
Yeah, I think.
Ron Vaz (07:40.836)
Yeah, so it can cost them a lot more money in the long run.
Peter Bagley (07:41.39)
Yeah, I can agree with you relating to the loophole factor. Yeah, the loophole, but see that goes back to from the very beginning, the basics of we’ll say asset management is knowing what assets you have. And if you don’t know what you have, one, it’s hard to protect them. And then two, you don’t know exactly what you need to protect. So you gotta make sure you cover your bases first and knowing what all your assets are that you’re working with.
Ron Vaz (07:59.622)
Absolutely.
Ron Vaz (08:06.82)
And we’re seeing a little arms race between malicious AI and defensive AI.
Peter Bagley (08:10.611)
Once you got that, much, much easier to kind of work from that point on. And if companies step back and do an honest risk assessment and look at what they have, and then they do a business impact analysis and kind of plan out what their priorities are and what capabilities are needed to maintain productivity, then that helps a lot. That allows them to now step back from a quantitative analysis standpoint and make sure that they can quantify cost.
for whatever this thing they’re trying to get that they may not already have. And if they do, then basically they a lot of dollars, can now recycle those dollars to something else.
Kchristaihne Castillo (08:50.636)
I definitely agree with that point here. So we are seeing a literal arms race between malicious AI and defensive AI. At the strategic level, how should the company decide when to adopt a new AI security tool without falling into the trap of shiny object syndrome or overcomplicating their tech stack?
Peter Bagley (09:14.348)
Yeah, everyone likes the new toy shiny out you got I agree 100 % with you on that and that’s sometimes a downfall From the strategic standpoint because you’re looking at the long-range aspect of how is this going to help you? You want to look at you know what you’re working with and you know your mission assignment whatever your mission is relating to your organization You want to make sure you’re tracking where you’re going in that mission statement
and still fulfilling it with these things that you’re looking at. So, you you ask yourself, does it solve a real and defined risk issue for me right now if I were to get this new capability? Hopefully, maybe, maybe not. Going back to analyzing and assessing what you have. Integration capability, does it fit into the existing ecosystem that I’m using as far as this new shiny object that I’m trying to get? Because it may look nice, but it’s kind of like, you you go out here and you buy a
a souped up Ford F-150 and your garage is just big enough for a Fiat, a little small vehicle, like a Mini Cooper, you got a problem there. That big truck’s never gonna fit inside that garage. So that’s the same type of scenario you’re looking at as relating to does this capability fit into how we operate, our ecosystem of things. And it may not, and it may be one of the best things on the market, but…
You need to find maybe some alternatives to kind of help you still get to where you’re trying to get to. And lastly, think operational maturity is another big part of it as well, because the people are what drive the process. So you also have to look strategically as in, okay, if I get these new capabilities, going back to what I was saying earlier, do I have the right skill, tool set of people that can maintain it and manage it and grow it? And if I don’t, then that’s another cost factor you got to add, because if you want
That’s me, as we call such a matter expert, your problem had to pay for. And if that’s not in the budget, along with the new shiny object you got, then that could be a problem. And lastly, I always say training, because one of the things I’ve always been involved with relating to the procurement side of the house, whenever you buy something new, you want to make sure you have training that comes with it for the people who are utilizing it or for people who may be utilizing in their future. That helps offset costs as well.
Peter Bagley (11:39.049)
Cause it’s easier to send two or three people to school compared to trying to create a brand new product and teaching brand new group of people how to use.
Ron Vaz (11:49.043)
Yeah, having the right people and with the right knowledge is very cost effective.
Peter Bagley (11:55.246)
yeah? Definitely.
Ron Vaz (11:58.527)
And speaking of that, as we handle for more decision-making power to automated AI systems, such as automatically blocking users or shutting down servers, what strategic risk do false positive pose? And what is the potential impact on the trust of customers and partnerships?
Peter Bagley (12:19.813)
Well, you know, you’re as we know, as individuals, our name is really all we have. Your name is your brand. Your name is how you trust it. And that’s a huge part for any company or corporation is your name. or you start looking at things like false positives. That means that something’s coming up that should not be looked at as good. And it isn’t, but due to the technology of what you’re using, the knowledge of the people who are programming it.
it may not be hitting that sweet spot. And that’s one of the things a lot of people kind of miss when they look at some of these tools, because you want to hand things over short. You got business disruptions that could take place, because again, you got a tool that’s not functioning properly, it wasn’t initially set up right. You got revenue loss that could take place as far as downtime, block transactions that could take place in case you’re having these false positives, because it’s saying that things are working when they’re really not.
and then, you know, your trust, like I said, rose up your trust as far as the companies you work with, because they rely on you for their own productivity needs and, whatever they’re working with. So it’s a lot of pieces and, know, down the road, particularly, you gotta look at it from the aspect of, you want to keep a human in the loop because as I said earlier, AI is a tool. Every tool needs someone to manage it and maintain it.
and use it properly. So going back to again, you gotta have that high impact knowledge person tied into that high impact tool. If you’re relying on it that much that you’re trusting it to kind of manage most of the things in your company. lastly, tuning, continuous tuning. It’s just like when you use biometrics for the very first time. And I know all you guys maybe have, know, using your thumbprint, your face recognition on your phone. When we first did it,
You had to go through that process like four or five different times for that biometric program to capture all of your specific details that relate to you to put into your system so you can now just show your face and open your phone. It’s exactly the same thing. There’s a sweet spot between false positives and false negatives, and they kind of cross. That’s the spot you’re trying to ultimately get to, but they do not come out the box that way. And that comes from tuning and basically maintaining
Peter Bagley (14:46.241)
the tool to get it where you ultimately want it to be. This is never going be perfect, but you get pretty close, I think.
Ron Vaz (14:53.087)
Yeah. You had mentioned making sure you have a subject matter, subject matter experts in place. And I think that’s where a lot of companies from what I’ve seen lately, they’re laying off everybody. But then when something happens, they’re calling back these same people to try to consult for them. And they’re trying to pay them less. then they realize these people, some of these people are really smart and they were like, you know what? You’re going to pay me $20,000 an hour to consult for you.
Peter Bagley (15:01.069)
Mm-hmm.
Peter Bagley (15:13.442)
Yeah.
Ron Vaz (15:22.131)
because somebody hacks you, but you could have just, you’ve been paying this person $70,000 and you could have just saved this, saved yourself thousands of dollars if you’re just knowing that keeping the right people in the right place at the right time. But they want to cut everybody out and they think AI is going to handle it.
Peter Bagley (15:22.222)
Mm-hmm. It’s true.
Peter Bagley (15:31.939)
to it.
Peter Bagley (15:37.987)
And that comes back to that. Yeah. no, it’s not. But that goes back to that strategic thing we just talked about a little bit earlier. You’re looking down the road at what you’re trying to do and what you have and can you accomplish it going forward? Well, you know, the human body is the biggest asset we have for any company. We’re either maintaining it, producing it, servicing it, whatever it may be, it’s the human. You can put as many computer and
Ron Vaz (15:49.119)
Mm-hmm.
Peter Bagley (16:07.17)
AI systems in place, but someone has to be able to tell it what to do. And that’s where the human touch comes in. So yeah, it’s very important because when I’m back to your point, you know, the people you had in house that you decided to let go, actually, for example, like, was it? think I heard the metals letting like 5,000 people go today. And Zuckerberg’s going to go ahead and try to integrate more AI. But you know, it’s nature to be right. We chose this profession.
Ron Vaz (16:28.037)
again.
Peter Bagley (16:36.513)
and we understand the ebb and flow of our profession. But at the same time, when you go to hire back that person, maybe somebody else already picked them up. So you might be too little too late going back to your point. Now you’re gonna play two to three times more for that same knowledge base that you let go of. So you gotta really consider the big picture rather than just going back to your previous question, the shiny new toy.
Ron Vaz (16:47.889)
yeah.
Ron Vaz (16:57.865)
I know.
Ron Vaz (17:02.303)
I know that’s what I would do. And I’ve been in that place where I’ve been let go from a corp company and they want to call me back to help them out. I’m like, you know what? It’s going to cost you a little more this time.
Peter Bagley (17:16.492)
It’s true. It’s true.
Kchristaihne Castillo (17:20.718)
we talk about here at above promotions, like you can never remove that human element in what you’re doing. Because definitely AI don’t know how to do empathy. So how are they going to deal with a certain problem, a certain breach that they have to convey to their users if they don’t have that human element? So it’s very important that we still have that.
Peter Bagley (17:45.096)
No, very true. And that goes also Kchristaihne about the trust factor because people trust again, the name is what they’re trusting because that’s your brand and the people behind it are trusted because of that brand. And the minute you disrupt that due to lack of preparation in the military, we call it, know, piss poor performance. And that’s because you didn’t prepare. So you got to prepare for these things because they’re going to come regardless if you them or not.
Ron Vaz (17:45.433)
absolutely.
Ron Vaz (18:18.687)
Speaking along those lines, resiliency isn’t just about software. It’s about people, what we’ve been discussing. As AI changes the nature of work, how should leadership rethink the talent strategy to ensure that their teams have the AI literacy needed to spot high-level synthetic threats, such as deepfake CFOs or AI-generated fraud?
Peter Bagley (18:43.256)
huh.
Yeah, that’s that’s a very big question and that’s one that no one’s really solved yet. Honestly as far as I know Because it evolves daily. There’s always some new form of defect being created There’s always some form of a ransom attack. I mean you can now you know as you have software as a service well, there’s a RAS ransomware as a service you can go buy it and Use that to attack somebody else. So, you know
Ron Vaz (19:09.823)
Mm-hmm. yeah.
Peter Bagley (19:14.779)
that piece is gonna be hard for leadership to capture. Again, you just have to kind of look at what is your mission and what do you need to secure as much as you can, having the right controls in place. And again, I always go back to training and probably because the teacher in me, I’ve been teaching for almost 40 plus years in different capacities, but if you don’t train your people right, they can’t help reduce.
what you imagine could take place. And it’s not to the fault of their own. You can’t blame someone for something they don’t know about. And then you got to teach the C level, the C suite, as you say, the executives about the importance of these different things that are taking place. Why you’re training people, your finance team, they have to understand all the dynamics of what’s going on too, because now you’re talking budget issues. And of course people are hacking into systems. They have money.
because money is what helps me going after. So it’s education. You really gotta take care of your people and let them know what’s going on. And then the other thing, embedding security awareness into your day-to-day operation. In the audit and assessment world, or readiness mode if you were to say, that’s one of the biggest things. Security should be looked at first, rather than in the middle of a project being created, or at the end.
It’s a little too late by that time because you probably miss a lot of things that could have helped earlier in the process. So if you’re integrating security into your overall ecosystem of how you operate, then you’re educating your people, which is a big piece of it. And, you know, as far as the things like, you know, the deep fakes and all those things you talked about, they’re not going anywhere. They’re only increasing. Unfortunately, AI, as we’ve been talking about, is going to help leverage that to move even faster. So really.
Training and educating your people is the only thing you can do. It’s just like a phishing attack. If you don’t do phishing attacks to your own outlook, exchange, mail capability, then how do your people know what to look for when something really comes down? That’s a process that has to take place today, regardless. And all these other things we’re talking about, they eventually will fall into that same line. And actually they already are. We’re just kind of behind the power curve a little bit as far as catching up with them.
Kchristaihne Castillo (21:37.102)
I definitely agree with training your people, educating them as always. With change being the only constant thing in the world, we definitely should keep on training, keep on learning these things. Especially right now in the digital world, everything is so quick. So,
Peter Bagley (21:46.244)
Yes.
Peter Bagley (21:51.066)
I did. Yes.
Peter Bagley (21:55.662)
And that’s the problem. mean, with a snap of a finger, you’re worldwide.
Kchristaihne Castillo (22:00.722)
Exactly, Actually, me right now, I’m actually located in the Philippines. So everything should be lined up. You have to have that unified communication across your company. So what should those entering the field expect to see and know considering the rise in AI tools and vulnerabilities? Like many people are concerned that
Peter Bagley (22:06.201)
Well, see, here we are.
Peter Bagley (22:13.367)
Yes. I agree.
Kchristaihne Castillo (22:27.008)
A degree in cybersecurity may not be helpful for those entering the field.
Peter Bagley (22:33.769)
so the playing fields changed, I guess the best way to put it. The way we used to play the game of going to traditional ed, as in your degree, go to college, get out, get a job. Those days don’t really look the same. Nowadays you want people to have more hands-on skills, more certifications. I’m even, I have kids that come down to high school that have CompTIA A plus, network plus and security plus, for example.
That’s coming out of high school, no degree. And they can walk into a $60,000 a year job just with that alone and hands-on experience. So that’s how it’s evolved. And as you look at incorporating AI into this, you need people that can understand, first of all, the basics. What makes a computer work? What is a network? Because like you said, you’re in the Philippines right now. If we weren’t on a good network backbone, we couldn’t talk at all.
And I tell people you can have as many cloud instances as you want. If your network’s down, you can’t get to it. It’s unavailable. Some of those basic things people need to know about, as well as basic security things that can kind of help not only just at work, but also at home, keeping themselves mentally in tune to the things that are going on around them. And as far as some of that knowledge, you want to have AI-assisted tools. But like I said, you want to, again, have
understanding how they’re gonna be used. And then you also look at critical thinking as far as the analyst goes. AI still needs some type of human judgment. It can go in and produce a whole lot of things. You can bring in a SIM tool, have AI pull all of your algorithms down, your threat feeds, and give you a single pane of glass to look at. But some human has to look at that, because it’s just gonna provide you the data.
So that’s where you want to make sure you have your people in place that can help you out with that. And hands-on experience is really where it’s at now. But the key is you don’t have to a lot of money to get hands-on experience nowadays. There’s so many free courses out there. There’s so many free tools. can go out and you can get a free one-year instance of Google Cloud, Azure for Microsoft, as well as AWS for a year for free. And you can build your own instance of it.
Peter Bagley (24:58.545)
and build your own network in the cloud. And that doesn’t cost you anything. and by the way, you can take the courses that each one of those companies offer on how to get certified in those areas. They’re also showing you hands-on capabilities. And then you also go out and get virtual boxing. You got a couple of laptops hanging around the house, connect them up together, and you can build a full-blown network right in your house that gives you a lab somewhere to test. And one of the things, because I do a lot of career coaching,
is that people, they’re afraid that, okay, I don’t know it. Well, that’s not always true. You know a lot more than you give yourself credit for because of how we had to maneuver things today, but you just haven’t figured out how to put that on paper. So if you have a lab at home and a company says, okay, do you know how to use Splunk, which is a SIM tool, for example, and you took a class from Splunk for free and you’re using all their products for free, then
Yeah, you know how to use Blunk. Now, are you an expert? No, he didn’t ask you that. He asked you, you know how to use it? Because every company knows whatever you come in the door with, it’s not going to be everything they need you to do. But you have a strong base in place, which saves them a whole lot of time.
Kchristaihne Castillo (26:17.086)
agree with that one. With everything like being available right now on the internet unlike before that we have to go to libraries, it’s very easy to learn these new things.
Peter Bagley (26:25.651)
Mm-hmm.
Yeah, yeah. I mean, even LinkedIn learning out there, it’s free. If you get a account on LinkedIn, and if you’re military, they give you one year free of LinkedIn learning. Doesn’t cost you anything at all. You just gotta sign up. And they have tons and tons of classes out there for any subject you can think of, from Python all the way down to being developed operations as far as security goes, as far as DevSecOps. So yeah, a lot of things are out there.
Kchristaihne Castillo (26:56.878)
Mm-hmm, that’s right. So if you were sitting in a board meeting today, what is the one non-negotiable AI security pillar every company must have in place in 2026 to ensure they remain viable and resilient in an increasingly automated world?
Peter Bagley (27:15.955)
Yeah, that’s a good question because we have so many different tools that are out there. I think one of the biggest things is. You want to be able to have not just a plan on paper of how you’re going to do things you want to. Kind of sketch things out a little bit and have a living capability in place that you can kind of grow and build and along that process, the whole organization is going to have to learn and grow as well because.
There are no static environments anymore. Everything is very dynamic. It evolves in a matter of hours or a day. And you’re constantly trying to catch up and real estate, you never will catch up. But what you end up doing is trying to make sure you are operating to the full capability of what you have and the people you have working with you. The AI powered detection and response tools are awesome. They can help you out a lot because that saves a lot of man hours.
from a security analyst going out and try to cover in that information. And if it can reproduce to where that analyst is now evaluated much quicker, you just save a whole lot of time trying to find out where the threat came from. So that’s a plus. Automated playbooks also help if you have something like that in place because they then can kind of do some of the manual aspects of things quicker. Once you program a playbook, but by the way, someone has to be smarter to program a playbook.
We’ll start there too. But once that’s done, it’s gonna run constantly, just like vulnerability scans. You can use a tool like Nessus. As long as you set up vulnerability scans on a schedule, process of how often you want them to scan, what devices and capabilities you want to scan, it’ll produce it for you. So there’s a lot of good stuff out there, you know, because in the end, we’re all trying to get a better picture of, when something does happen, what do we do? Or how quickly can we get back up?
how much is gonna affect productivity as a whole. So when you’re at your things like recovery objectives, as far as time and the point of the objectives for recovery, point objective, how quickly can we get there? Well, AI and those students can help you get there faster, but the manual aspects is gonna take place somewhere in there. So I think the biggest thing is having an organization that’s communicating, one.
Peter Bagley (29:39.899)
open to understand the way that technology is moving and how swiftly it’s moving. And the C-suite, which is of course your executive level group, they’re the ones that control the checkbook, but the people on the ground are the ones who bang the keys to keep the car running. And if there’s no continuity between the two of them, you’re dead on arrival. It’s not going to work. Your company’s not going to progress because you have to be able to listen to the people on the ground what they need. And at the same time,
In our business, we call it trust but verify. You trust them, but you want to verify if something you really need or not. So you have to spend that big money that you may not already have budgeted because it’s something you have to have like today. So there’s a lot of factors you’re to, but again, communication is the biggest piece as far as we’re going to see and having organizations open enough to be nimble and agile to move with it.
Kchristaihne Castillo (30:37.036)
definitely agree with that one Peter. I also like to add something that I always take to heart as the marketing coordinator here at Above Promotions. Whenever we take a new technology, a new tool that we wanted to use in the company or with the client, we always ensure that we review that privacy policy. So you never go wrong with reviewing everything.
even a regular review even you’ve been using it for years you have to make sure that you always do that review and another one is making sure that you have this crisis management in place like you always have to be ready if you will be attacked by a breach or something like that so yeah those are the two things that i always make sure that’s in place
Peter Bagley (31:11.801)
I agree.
Peter Bagley (31:32.14)
Those are very smart things to look at as well as a lot of companies don’t realize you need to have a PR person because the C-suite or the CEO, CFO, CIO, any of those CIOs, they may not be able to talk to the public about things that take place as in ransomware or various incidents that may take place. It could be a disaster recovery situation. Now we’re here in Florida, we had two hurricanes back to back. Who would have thought that was gonna happen? But that’s reality.
And it also wiped out some companies that had on-premise capabilities. They weren’t all in the cloud. So how do you address your stakeholders that you work with, the companies that are trusting you, as we just talked about earlier? And that’s why it’s always good to have someone in that realm that can speak just enough to keep everybody satisfied and show you’re making progress in resolving the issue, but not too much that puts your name and your business brand on the line.
Ron Vaz (32:31.772)
That’s why they need to keep Above Promotions on their speed dial.
Peter Bagley (32:38.379)
There you go. Great segue.
Ron Vaz (32:42.95)
Yeah
Kchristaihne Castillo (32:43.212)
That’s right, that’s right. That was what I was about to say.
Peter Bagley (32:47.563)
And we didn’t practice that.
Kchristaihne Castillo (32:49.614)
So thank you so much. Thank you so much Ron and Peter for your incredible insights today. It’s clear that resiliency is a blend of technical hardening and human strategy. So to recap, we discussed the shift toward operational continuity, the business value of security as a trust signal.
Ron Vaz (32:53.724)
See, everything just flows properly.
Peter Bagley (33:00.702)
hahaha
Kchristaihne Castillo (33:18.4)
and why AI literacy is the new baseline for talent. So if you’re looking to audit your own AI governance, visit abovepromotions.com or connect with Ron Vaz and Peter Bagley on LinkedIn. So check out our other episodes on Spotify and YouTube. Thanks for tuning in to Sold Out Chat and stay strategic, stay resilient and keep winning.
Peter Bagley (33:44.596)
Thanks a lot.
Conclusion
In conclusion, as we advance toward 2026, the question of cyber resiliency becomes ever more critical. Organizations must not only focus on preventing breaches but also prepare to thrive in the face of them. By adopting a proactive approach, leveraging AI effectively, and maintaining human oversight, businesses can build a robust cyber resiliency strategy that protects their operations and builds trust with customers.
While you can’t truly “predict” a human, you can resolve the technical and strategic friction that makes their behavior seem erratic. At Above Promotions, we specialize in identifying the hidden variables that cause these disconnects.
Whether through a comprehensive MarTech Audit in our Innovation Lab to smooth out the digital journey, or deep behavioral analysis in our Strategic Insights Center to understand the “why” behind the data, we help you move from reactive guessing to highly informed anticipation. We help you find the holes in your strategy and turn the mystery of “unpredictable behavior” into a clear, scalable, and intentional path toward growth.
Ready to build a robust cyber resilience strategy?
- Watch the full episode on YouTube here
- Book a Consultation with our Innovation Lab to audit your brand alignment and stay ahead of the curve.
Check out some of our favorite items the team uses to make our recordings work:
– USB to HDMI adapters https://amzn.to/4aFkoQv
– Tripod https://amzn.to/4kImvHO
– Carpet Cord Covers https://amzn.to/4kImvHO
– Reusable Cable Ties https://amzn.to/3MCzsGu
– Wireless Lapel Mic https://amzn.to/4rVD4lV
– Background Paper https://amzn.to/4u2R2Dz
– EcoFlow Portable Power Station https://amzn.to/49jApeN
– HD Web camera https://amzn.to/3REptD1



