The Watchtower

Convenience: The Common Thread Behind Human and Agentic Risk

Episode Summary

If Convenience Wins, We Lose.

Episode Notes

If Convenience Wins, We Lose.

Evan Gordenker led more than 160 insider investigations at Unit 42, including work on DPRK IT-worker operations, before taking over insider threat and data security at Airwallex.

Evan joins Ash Hunt to showcase how intent is often the wrong place to start. Whether the risk comes from an employee, an AI agent, or an adversary using legitimate credentials, the real question is what trusted access allows them to do.

Evan explains why convenience sits at the center of human and agentic risk, how AI agents expose the limits of access models built for people, why security teams need finer-grained control over credentials and permissions, and why the DPRK IT-worker playbook keeps working without changing much at all.
 

Connect

Evan Gordenker on LinkedIn

Airwallex

 

Chapters

0:00 The insider threat you're worried about isn't a person
1:19 How Evan fell into cybersecurity via the Tokyo Olympics
4:20 What the industry gets wrong about who the insider actually is
5:25 Why the 'secret police' framing kills your program
8:00 Intent doesn't matter — controls do
9:30 What a real, messy insider investigation actually looks like
12:30 One sentence in an incident report can end a career
15:01 Would you classify an AI agent as an insider?
16:33 The one-password experiment — how agents test every credential
19:39 4 years into agentic systems. Still built for humans only.
23:54 If security runs insider risk alone, you're toast
28:35 The DPRK IT-worker threat — and why it hasn't had to evolve
32:54 How Fortune 500s started frustrating North Korean operators
36:48 The one through-line: convenience
42:50 Why InfoSec has never mattered more than right now