How the Threat Landscape Is Being Rewritten and What Organizations Need to Do Before It Gets Ahead of Them
Guest: Taylor Hersom, Founder and CEO at Eden Data
Host: Seth Earley, CEO at Earley Information Science
Published on: July 28, 2026
In this episode, Seth Earley speaks with Taylor Hersom, Founder and CEO of Eden Data, a cybersecurity and compliance firm he built and grew before its acquisition in 2025. They explore why security is still treated as a cost center when it should be treated as a sales motion and competitive differentiator, how AI has exponentially expanded the attack surface, why most organizations have adopted AI with almost no security program around it, and how the subscription model Taylor pioneered is now reshaping how professional services firms price and deliver work. Taylor shares candid and specific insights on AI governance standards, the limits of automated threat detection, and why information architecture is the foundation security professionals are finding missing everywhere they go.
Key Takeaways:
- Security is still treated as a cost center by most organizations when it should be viewed as a trust-building and sales motion that directly impacts revenue and brand reputation.
- Pre-revenue startups are now arriving with a million lines of AI-generated code - the attack surface has expanded exponentially and security programs have not kept pace.
- Most organizations have adopted AI across the enterprise without any AI-specific security program, controls around LLM access, or governance over what models are allowed to do.
- ISO 42001 and the NIST AI Risk Management Framework are the clearest starting points for organizations that want to de-risk their AI environment without reinventing the wheel.
- AI in security has shifted the human role from doing the work to supervising it - but final judgment on whether a threat is legitimate still requires a human and always will.
- Unorganized, incorrect, or inaccessible data creates systemic risk in AI environments - poor information architecture is what leads to the snowball effect of cascading security failures.
- The subscription model for security services - pricing for outcomes rather than hours - has proven durable across market conditions and is now becoming the industry expectation.
Insightful Quotes:
"We naturally leaned into AI from a technology standpoint, and there is almost no security around it to speak of. If you go ask the average company that's using AI across their enterprise, they probably don't have an AI-specific program where they have controls around their LLM and their processes and their access - and that is terrifying." - Taylor Hersom
"Rather than go the FUD route - fear, uncertainty, and doubt - you can look at security as a way to build your brand and make it a part of your identity, and be proactive in how you use this when educating customers about how you protect their data." - Taylor Hersom
"There's no AI without IA. Security requires information architecture - access controls, data organization, knowing what you have and where it lives. When you start losing control of your data, you start to create risks you don't even know about." - Seth Earley
Tune in to discover why cybersecurity in the AI era is no longer just a technical problem - and what organizations need to put in place before the threat landscape gets ahead of them.
Links
LinkedIn: https://www.linkedin.com/in/taylorhersom/
Website: https://www.edendata.com
Ways to Tune In:
Earley AI Podcast: https://www.earley.com/earley-ai-podcast-home Apple Podcast: https://podcasts.apple.com/podcast/id1586654770 Spotify: https://open.spotify.com/show/5nkcZvVYjHHj6wtBABqLbEiHeart Radio: https://www.iheart.com/podcast/269-earley-ai-podcast-87108370/ Stitcher: https://www.stitcher.com/show/earley-ai-podcast Amazon Music: https://music.amazon.com/podcasts/18524b67-09cf-433f-82db-07b6213ad3ba/earley-ai-podcast Buzzsprout: https://earleyai.buzzsprout.com/
Podcast Transcript: Cybersecurity, AI Risk, and Why Security Is a Sales Motion
Transcript introduction
This transcript captures a conversation between Seth Earley and Taylor Hersom about the rapidly shifting cybersecurity landscape in the AI era. They cover why security is still wrongly treated as a cost center, how AI has created an exponential expansion in attack surface that security programs have not kept pace with, what governance frameworks are most useful for organizations starting from scratch on AI security, the limits of automated threat detection and where human judgment remains essential, and how poor information architecture becomes a systemic security risk when AI is in the loop.
Transcript
Seth Earley: Good morning, good afternoon, good evening, depending upon your time zone. Welcome to the Earley AI Podcast. I'm your host, Seth Earley, and in each episode, we explore how artificial intelligence and data are reshaping business strategy and operations. Today, we are talking about cybersecurity in the AI era, a space that's been changing faster than most organizations can track. AI is creating more attack surface than ever before. The data organizations are collecting to train and fine-tune models has become a target in its own right. And the way companies are thinking about security is having to shift from fear-based to value-based and trust-based. Joining me today is Taylor Hersom, Founder and CEO at Eden Data, a cybersecurity and compliance firm he built and grew before its acquisition in 2025. Taylor started his career at Deloitte, went on to serve as Chief Security Officer, and has spent the last several years building a practice squarely at the intersection of security, compliance, and AI. Taylor, welcome to the show.
Taylor Hersom: Seth, thanks so much for having me. What an awesome intro. I'm honored to be here.
Seth Earley: Let's start with the biggest misconceptions that executives and technology leaders are most consistently getting wrong about cybersecurity today.
Taylor Hersom: The biggest misconception, far and above, is that security still gets looked at as a cost center - if I invest in this, I don't see an ROI, so therefore this is just costing me money. That mindset is limited, because in reality you have two main things when you invest in security. One, it de-risks you - it prevents you from ending up in the news for all the wrong reasons, which is brand reputation, legal reputation, all of those things. And then secondly, if you have two companies a customer is comparing, and one says look at all the ways we protect your data, and the other just says we store everything in Google Drive - there's a very different trust-building exercise happening between those two companies, and you're more likely to go with the company that makes you feel good about their cybersecurity.
Seth Earley: Security has historically been sold on fear - threat of breach, risk of ending up in the news. You're saying it's more effective to make the case for security investment as a value. Say more about that.
Taylor Hersom: Security has largely, historically been sold on FUD - fear, uncertainty, and doubt. It's hard to motivate someone by saying if you don't do this, something bad is going to happen. That gives people the inverse reaction that you would want. Humans do really well when we have some positivity, and so rather than go the FUD route, you can look at security as a way to build your brand and make it part of your identity - being proactive in how you educate customers about how you protect their data, their employees' data, your intellectual property.
A lot of what Eden Data did in the early days was focus on, instead of selling a customer a vCISO service where we build security controls and de-risk your environment, we said let's focus on a compliance standard you can achieve - like SOC 2 or ISO 27001 - and build a public security page that showcases all the ways you're investing in security. There are great tools now where you can upload your pen test report, your cyber insurance policy, your security policies, your most recent SOC 2 attestation report, and share that publicly with customers. That's a really positive way to build your brand and use it in your sales cycle.
Seth Earley: AI is enabling organizations to ship more code than ever before and creating more threat surface than ever before. What does that mean practically for how security teams need to operate?
Taylor Hersom: We already had this problem prior to AI with shadow IT, where anyone could go adopt a SaaS tool and upload data into it. AI has exacerbated that problem by expanding the attack surface exponentially. Early-stage startups used to have 100,000 to 200,000 lines of code. We now have pre-revenue startups coming in with a million lines of code. It's incredible on one side and terrifying on the other. It has fundamentally expanded the work effort and the need to understand your security governance.
It has also created an opportunity to leverage AI to reduce the workload. There are great companies leaning into more automated pen testing, compliance automation, and AI-powered threat response. CrowdStrike and Arctic Wolf are using AI to respond to threats faster. Those are real opportunities.
Seth Earley: Organizations are building AI on proprietary knowledge - training data, fine-tuning sets, IP, competitive differentiation. That has become a high-value target in its own right. How should organizations think about protecting those assets?
Taylor Hersom: It blows my mind every time I say this out loud, but we naturally leaned into AI from a technology standpoint and there is almost no security around it to speak of. If you go ask the average company using AI across their enterprise, they probably don't have an AI-specific program with controls around their LLMs, their processes, their access - and that is terrifying.
One easy place to start - very similar to how we used SOC 2 or ISO 27001 as a North Star for early-stage companies - is to adopt an established AI security standard immediately. My top two are ISO 42001 and the NIST AI Risk Management Framework. Either of those already have the things you should be doing to de-risk your company as it relates to LLMs in your environment. Let's not reinvent the wheel. That is going to be the easiest path forward to make a quick impact.
Seth Earley: Are there any gotchas or pitfalls organizations need to be aware of going down that path?
Taylor Hersom: Honestly, most of it is governance work, which is beautiful - it largely just takes a human to sit down, be strategic, and ask: where is my LLM pulling data, where are the references it's using, where did that answer come from? That just requires someone to sit down and document it. For ISO 42001, you can go buy the standard on the ISO website for about $150, and if you want to be audited against it, you work with a third-party auditor. The NIST AI RMF is an internal government document that gives guidance on managing AI security effectively - no cost other than the cost of implementing.
Seth Earley: Security has a technical side and a governance side - controls, policies, employee awareness. How does AI change both of those, and where are organizations falling short?
Taylor Hersom: A lot of what has happened is that it's really an expansion of existing controls. Prior to AI, people were getting breached because of the wrong access, the wrong monitoring, the wrong oversight. That's still happening with AI - I have a security policy that says I do all these things but I don't have a control that's actually doing those things.
The areas that are more specifically nefarious now are things like access to LLMs, governance over what LLMs are allowed to do, and then the legal ramifications - a healthcare company that plugged an LLM into their customer's PHI needs to ask: am I allowed to do that? Do I have legal coverage for that? Those are the new governance questions sitting on top of the existing fundamentals.
Seth Earley: There's a tendency to assume AI tools will handle security monitoring and threat detection automatically. Where does that assumption break down, and what still requires human judgment?
Taylor Hersom: Historically, humans were the complete factor - they decided whether an alert should be investigated, came to a conclusion, validated it. Now we have AI doing a lot of that. We went from doing the work to supervising the work. AI is evaluating logs, telling you this is a threat and this is not a threat, coming to conclusions before you even see it. But how is it coming to those conclusions? Is that accurate? And when it reaches a conclusion, there still needs to be human intervention to say, okay this is legitimate and I need to do something about it. AI, even though companies claim otherwise, is largely still at the stage of alerting in most security contexts - not actually addressing the threat.
The other concern is that LLMs can be largely right, but when they are wrong, they are really wrong. How do you catch those failures? How do you make sure the fail rate is not expanding because of the data set or the prompts? That requires ongoing human oversight - what decisions is the LLM allowed to make, and what are the consequences if it makes the wrong one?
Seth Earley: How is AI disrupting the consulting and services model, and what does a services firm need to do to adapt?
Taylor Hersom: I started experimenting with the subscription model back in 2020 on Upwork, before I founded Eden. Upwork would only let you set an hourly rate, but I started messaging in the comments section saying, my hourly rate is this, but here is what I can do for you on a monthly basis instead. People were already conditioned by SaaS - they could see the value of paying a fixed amount every month and knowing what they were getting. When I shifted those conversations from hourly to subscription, it worked. Eden became successful because that Upwork experimentation worked so well.
The subscription model I started with in 2021 is still being used at Riveron today. And now you're starting to see a global shift where nobody wants time and materials anymore. They want to pay for an output and set a dollar value on that output. For services firms still on a time and materials model, the path forward is getting constant customer feedback, ensuring what you offer actually adds value, and thinking about how to shift engagements from one-off projects to a cadence of connected work. The firms that figure out how to price for outcomes rather than hours are going to be the ones that survive the AI transition.
Seth Earley: There's no AI without IA - information architecture as a foundation. When you go into an organization, is poor information architecture a problem you keep running into?
Taylor Hersom: It is what leads to the snowball effect of the risks we were talking about. When you have an AI model leveraging data that is either not organized, incorrect, or that you aren't leveraging when you should be - that creates systemic problems with the LLM that then leads to systemic risk as it relates to cybersecurity. The most common thing we see is a library of data where everything is thrown in one room, and you don't even know about the other room because it's buried behind a pile of books. When you start losing control of your data, you start creating risks you don't even know about. That happens a lot.
And most leaders assume AI is going to solve that problem. It is not. The person who makes that assumption largely doesn't understand how an LLM works in the first place. This is a tool you need to know how to use before you start using it.
Seth Earley: Taylor, thank you so much for joining me today and sharing your perspective on how security is changing and evolving, and how that threat landscape is being rewritten. Thank you for your time.
Taylor Hersom: Thank you so much again, Seth. I love nerding out on these topics. This is a great time to be alive.
Seth Earley: And to our listeners, thanks for tuning in to the Earley AI Podcast. Be sure to subscribe for more conversations on how AI is shaping the business world. Taylor can be found on LinkedIn - link in the show notes. We will see you next time.
