The TPRM PodcastThreats, Pitfalls & Risk Myths
Listen onYouTubeSpotifyApple PodcastsiHeartRadio
EP 20October 6, 2026Premieres Tuesday, October 6

Why Security “Best Practices” Are Broken

Sean Cassidy

CISO, Plaid; Former Head of Security, Asana

Sean Cassidy

What if some of the things we call “security best practices” aren't actually reducing risk?

In this episode of the TPRM Podcast: Threats, Pitfalls & Risk Myths, Nate Lee sits down with Sean Cassidy, Chief Information Security Officer at Plaid, to challenge some of the assumptions security teams have built their programs around.

They dig into third-party risk management, phishing, AI, security automation, threat modeling, and what happens when security processes create more friction than protection.

Sean makes the case for a different approach: understand the actual risk, explain why a control matters, prepare for vendors to get breached, and use AI where it can genuinely make security teams better.

They also get into where AI is already working inside security teams, why AI may be particularly good at repetitive judgment calls, the idea of an automated “security factory,” and the emerging possibility of persistent autonomous AI threat actors.

The conversation covers

  • Why Sean hates the phrase “security best practice”
  • Why more TPRM rigor doesn't necessarily mean less risk
  • What security teams should prepare for when a vendor gets breached
  • Why users shouldn't be your primary defense against phishing
  • How Plaid is using AI for security workflows
  • Why AI could finally help understaffed security teams scale
  • Where AI security reviews still fall short
  • Why threat modeling and security charters matter
  • The coming problem of autonomous AI threat actors

About the guest

Sean Cassidy is Chief Information Security Officer at Plaid, and previously served as Head of Security at Asana. His career spans software engineering, security entrepreneurship, and security leadership, including roles at Cisco and Limelight Networks.

He co-founded DefenseStorm, where he served as CTO and helped build an early cloud-based security platform for banks and credit unions. His work there eventually led him from the vendor side of cybersecurity into security leadership and CISO roles.

At Plaid, Sean focuses on building security programs around actual risk rather than process for process's sake. He is also exploring how AI and automation can help security teams scale, from phishing triage and vendor risk analysis to application security and the emerging challenge of autonomous AI threat actors.