Episode #
123
Ironbridge CISO Consulting's Jim Almerico on the end of AI euphoria and the flaws emerging
The euphoria around AI is over, and the flaws are showing up at a speed nobody imagined a year ago. Jim Almerico (https://www.linkedin.com/in/jalmerico), CISO at Ironbridge CISO Consulting, tells Eli that organizations deploying AI without understanding how it operates are repeating the mistakes of the early internet and IoT eras.
Jim shares lessons from securing PsiQuantum under a 90-day CMMC deadline for a $31 million DARPA contract, why identity access management is the foundation for governing AI agents, and how quantum computing is approaching its tipping point.
Topics discussed:
- Why AI security mirrors early internet and IoT security failures
- Governing autonomous AI agents through identity access management
- Completing CMMC certification in 90 days for a DARPA contract
- How open defender communication would strengthen collective security
- Preparing encryption and certificates for post-quantum readiness
- Securing MCP and API connections against unintended data exposure
- Why blind trust in AI is the biggest organizational risk
Key Takeaways:
- Require model cards and data flow documentation before deploying AI so security teams know exactly how a system operates before they protect it.
- Clean up identity access management for knowledge workers first, because AI agents will inherit every unresolved permission in the system.
- Build AI governance around containment controls, not checklists, since the organizations behind the most advanced AI could not contain their own products.
- Demand open communication between defender teams, treating shared intelligence as the biggest force multiplier in security.
- Start quantum readiness now by inventorying encryption and certificates, even though the quantum tipping point may be years away.
- Audit MCP and API connections for unintended data exposure before integrating AI tools across organizational boundaries.
- Approach AI adoption with the understanding that both benefits and harm are real, and resist blind trust in any tool your team cannot fully explain.
Listen to More Episodes: YouTube • Apple • Spotify • Website