
Episode 19: Cloudflare Outage, AI-Powered Attacks & The Rise of GRC Engineering | Distilled Security Podcast
Get every episode summarized
Each time Distilled Security Podcast publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
About this episode
In this episode, we break down a major Cloudflare outage, explore how a nation-state used AI agents to automate a cyberattack, and discuss the growing risks around MCP integrations. We also highlight why GRC Engineering is becoming essential to modern security programs and wrap up with key regulatory updates, including CMMC changes affecting thousands of contractors.
Topics covered:
• Cloudflare outage impact and root cause
• Nation-state attack using AI agents to automate intrusion steps
• MCP (Model Context Protocol): power, risks, and examples
• Why GRC Engineering is the future of compliance and automation
• Updates on GDPR, ISO 27701, California AB 5866, and SEC rules
• CMMC assessor shortages and what organizations must prepare for
Spirit of the Episode
• Knob Creek 21-Year Limited Release, rich caramel notes, heavy char, smooth for 100 proof
Timestamps
- 0:02—Cloudflare Outage Stories & Global Impact
- 3:07—Root Cause, Not a Cyberattack & Third-Party Risk Reality
- 10:38 - China Uses Anthropic’s Claude + MCP for Automated Cyberattacks
- 14:17 - Full AI Attack Lifecycle Explained
- 27:18 - MCP: The API for AI & Its Security Risks
- 44:05 - Bourbon Break: Knob Creek 21-Year Review
- 50:02 - GRC Engineering Deep Dive: Automation & Controls-as-Code
- 1:24:13 - Regulatory Roundup: GDPR, ISO 27701, California AB 566, SEC SP
- 1:44:27 - CMMC 2.0 Crisis: Auditor Shortages & DoD Contract Impact
- 2:11:20 - Closing Thoughts & Episode Wrap-Up
Hosts
- Justin Leapline – @justinleapline
- Joe Wynn – @wynnjoe
- Rick Yocum – @rickyocum
Guest
- Matthew J. Schiavone - @Sikitch
Connect with Us
- Website: distilledsecuritypodcast.com
- X: @DisSecPod
- Email: [email protected]
Get every episode summarized
Each time Distilled Security Podcast publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from Distilled Security Podcast

Episode 24: 2 Years, 24 Episodes & The State of Security in the Age of AI
Distilled Security Podcast

Episode 23: Nobody read the report
Distilled Security Podcast

Episode 22: Is AI Good for Security, CIRCIA Starts the Clock, and the M&A Proble...
Distilled Security Podcast

Episode 21: AI Notetakers Are Illegal, GRC Tools Are Lying, and ISO 42001 Change...
Distilled Security Podcast