Derek Banks
Bio
Derek is a BHIS Security Consultant, Penetration Tester, and Red Teamer with advanced degrees, industry certifications, and broad experience across forensics, incident response, monitoring, and offensive security, who enjoys learning from colleagues, helping clients improve their security, and spending his free time with family, fitness, and playing bass guitar.Appears in 50 Episodes
OpenAI / Hugging Face Breach Walkthrough | Episode 65
🔒 Want to run AI without sending your data to the cloud? AI Security Ops co-host Bronwen Aker is teaching Keeping Things Local: Build Private LLMs for Your Team. ✔️ Bu...
Agentic Terminology | Episode 64
In this episode of BHIS Presents: AI Security Ops, the team tackles one of the biggest sources of confusion in modern AI: What’s the difference between prompts, skills...
AI News Stories | Episode 63
In this episode of BHIS Presents: AI Security Ops, the team follows a single trend that is changing the economics of cyberattacks: The machine-speed attacker is no lon...
Are Foreign Open Weight Models a Security Risk? | Episode 61
In this episode of AI Security Ops, the team tackles one of the most common questions security teams are asking about open-weight AI models: Are foreign open-weight mo...
Hey Skippy! | Episode 60
This episode takes a break from the usual AI security news roundup for a show-and-tell discussion centered on "Skippy," an AI-powered personal assistant built to autom...
Agentic Security: The Maturity Model — From Wild West to Locked Down | Episode 58
In this episode of BHIS Presents: AI Security Ops, the team tackles one of the most urgent — and misunderstood — problems in modern security: How do you actually secur...
Introducing Fusion AI Pentest | Episode 57
In this episode of BHIS Presents: AI Security Ops, the team introduces a new approach to offensive security: Fusion AI Pentesting. https://www.blackhillsinfosec.com/fu...
Open Weight Models and Open Source Harnesses | Episode 56
In this episode of BHIS Presents: AI Security Ops, the team looks at what it actually means to own your AI stack. Open-weight models and open-source harnesses are no l...
AI Cost Saving Tips | Episode 55
In this episode of BHIS Presents: AI Security Ops, the team digs into a problem every AI-enabled SOC eventually hits: The demo looked great — until the inference bill ...
Is It the Model or the Harness? | Episode 54
In this episode of BHIS Presents: AI Security Ops, the team tackles a foundational question in modern AI security: Is the real risk in the model… or in the harness aro...
AI News | Episode 53
In this episode of BHIS Presents: AI Security Ops, the team breaks down a packed week in AI security — from the first AI-built zero day in the wild to model supply cha...
Agent Pentest Benchmarking | Episode 52
In this episode of BHIS Presents: AI Security Ops, the team breaks down a new benchmarking framework designed to evaluate AI pentesting agents against real-world offen...
AI and Bug Bounties | Episode 51
In this episode of BHIS Presents: AI Security Ops, the team breaks down a growing problem in cybersecurity: AI-generated bug bounty “slop” overwhelming the system. Wha...
Claude Mythos | Episode 49
In this episode of BHIS Presents: AI Security Ops, the team breaks down Claude Mythos Preview — Anthropic’s unreleased frontier model that may represent a turning poin...
LiteLLM Supply Chain Compromise | Episode 47
In this episode of BHIS Presents: AI Security Ops, the team breaks down the LiteLLM supply chain compromise–a real-world attack that shows how AI systems are being bre...
Model Ablation | Episode 46
In this episode of BHIS Presents: AI Security Ops, the team breaks down model ablation — a powerful interpretability technique that’s quickly becoming a serious concer...
Embedding Space Attacks | Episode 45
In this episode of BHIS Presents: AI Security Ops, the team explores embedding space attacks — a lesser-known but increasingly important threat in modern AI systems — ...
Indirect Prompt Injection | Episode 44
In this episode of BHIS Presents: AI Security Ops, the team breaks down indirect prompt injection — the #1 risk in the OWASP Top 10 for LLM Applications — and why it r...