Podcasts about cissp

  • 349PODCASTS
  • 2,024EPISODES
  • 35mAVG DURATION
  • 5WEEKLY NEW EPISODES
  • Aug 25, 2026LATEST

POPULARITY

20192020202120222023202420252026

Categories



Best podcasts about cissp

Show all podcasts related to cissp

Latest podcast episodes about cissp

The Full Nerd
Episode 413: Ethical Hacker Talks Kernel Level Anti-Cheat, Wi-Fi Hacking & More

The Full Nerd

Play Episode Listen Later Aug 25, 2026 144:48


Join The Full Nerd gang as they offer level-headed takes about the latest PC building news. In this episode the gang is joined by special guest Mike Danseglio, CEH & CISSP, to discuss topics from DEFCON 2026, including the safety (or lack thereof) of anti-cheat software, how easily Wi-Fi can be hacked and what you can do about it, and much more. And of course we answer questions live! Timecodes: (00:00:00) - Intro (00:07:40) - DEFCON 2026 (00:39:14) - Anti-cheat debate (01:13:02) - Wi-Fi hacking (01:48:15) - Q&A Join the PC related discussions and ask us questions on Discord: https://discord.gg/UWhjwg778a Follow the crew on X and Bluesky: @AdamPMurray @BradChacos @MorphingBall Music by Our Ghosts: https://ourghosts.bandcamp.com/ Some links may contain affiliate links, which means if you buy something PCWorld may receive a small commission. ============= Read PCWorld! Website: http://www.pcworld.com Newsletter: http://www.pcworld.com/newsletters ============= Learn more about your ad choices. Visit megaphone.fm/adchoices

The Chris Voss Show
The Chris Voss Show Podcast – Artificial Intelligence Governance, Risk, and Compliance: Ensuring Trust, Security, and Ethics in AI-Based System by Dr. Kellep A. Charles AIGP CISSP

The Chris Voss Show

Play Episode Listen Later Aug 19, 2026 47:05


Artificial Intelligence Governance, Risk, and Compliance: Ensuring Trust, Security, and Ethics in AI-Based System by Dr. Kellep A. Charles AIGP CISSP https://www.amazon.com/Artificial-Intelligence-Governance-Risk-Compliance/dp/B0GYJD5D6X Kellepcharles.com Artificial Intelligence is rapidly changing many industries, but with its power comes responsibility. “AI Governance: Ensuring Trust, Security, and Ethics in AI-Based Systems” is your guide to navigating the challenges of responsible AI development and deployment. Written by cybersecurity expert Dr. Kellep A. Charles, this essential resource connects AI innovation with ethical practices. Whether you are a cybersecurity professional, data scientist, business leader, policymaker, or student, this book offers practical frameworks for managing AI risks, ensuring compliance, and creating trustworthy systems. Inside, you’ll find: Foundational AI concepts and the development of machine learning technologies Insights into agentic AI systems, including their benefits, risks, and governance needs Real-world applications of the NIST AI Risk Management Framework Strategies for managing the entire AI development lifecycle Practical threat modeling and security testing methods for AI systems Techniques for data governance, privacy protection, and reducing bias Current laws, standards, and regulations such as GDPR and the EU AI Act Step-by-step guidance for creating AI cybersecurity frameworks Protocols for incident response, monitoring, and maintaining deployed AI systems Tools, certifications, and organizational resources for AI security testing What makes this book unique? It includes real-world case studies, detailed checklists, sample governance policies, and templates for assessing AI impact. This book turns abstract AI ethics into concrete action plans. It addresses critical risks like model poisoning, adversarial attacks, data protection, and algorithmic fairness, providing practical strategies for mitigation. It is ideal for professionals seeking AIGP certification, organizations establishing AI governance programs, or anyone dedicated to responsible AI innovation. The book offers easy-to-understand explanations for non-technical readers while delivering the depth that practitioners need. Create AI systems that are powerful yet transparent, accountable, and aligned with human values. In a time when AI failures can have serious consequences, this book shows you how to ensure AI serves everyone safely and ethically. Learn to manage AI before it manages you.

CISSP Cyber Training Podcast - CISSP Training Program
CCT 365: Malicious QR Code Attacks and Digital Forensics Techniques Every CISSP Should Know [REPLAY]

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later Aug 10, 2026 25:05 Transcription Available


Send us Fan MailOne careless QR scan can quietly turn a “private” chat into a live wiretap. We start with a timely threat story: Russian APT-style actors abusing Signal's linked device flow by pushing phishing links that contain malicious QR codes, so messages can be mirrored to an attacker device in real time. If you use Signal, WhatsApp, or Telegram at work, this is the kind of simple, human-triggered failure mode worth building into your security awareness habits.Then we shift into CISSP Question Thursday with a rapid, practical run through CISSP Domain 7.1 style topics in digital forensics and incident response. We break down what comes first when handling digital evidence (forensic copy before analysis), how to examine a suspicious file without detonating it (static analysis), and what makes an incident report useful under pressure (a clear timeline of events and actions taken). We also cover insider threat artifacts, mobile device forensics tools like Cellebrite UFED, and why chain of custody is the backbone that keeps evidence credible from collection to court.Along the way, we talk about root cause analysis, anomaly-based detection for network traffic, and why clear writing beats big jargon when you're briefing executives, legal, or a board. If you want exam-ready thinking that also maps to real investigations, you'll get it here.Subscribe for weekly CISSP training, share this with a teammate who scans QR codes too fast, and leave a review with the topic you want next.Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

Hybrid Identity Protection Podcast
Inside a Veteran CISO's Playbook for Crisis and Communication with Philip Keibler, VP and CISO at Meijer

Hybrid Identity Protection Podcast

Play Episode Listen Later Aug 4, 2026 34:46


This episode features Philip Keibler, Vice President and CISO at Meijer, one of the nation's largest privately held retailers.With nearly three decades of security leadership, including CISO roles at Bass Pro Shops and Finish Line, Phil brings a rare long-view perspective on what the job actually requires day to day. He also talks about his feature in Semperis' upcoming documentary Midnight in the War Room, premiering at Black Hat on August 5.In this episode, Phil explains why CISOs who struggle to get budget usually have a storytelling problem, how he defines success in a role where stopping every attack is impossible, and what it takes to lead a team through an active incident. He also dives into why fundamentals are what actually address most of an organization's risk.This episode makes the case that the hardest parts of the CISO job are rarely technical, and that mastering the basics matters more than chasing the newest tool.Guest Bio Philip Keibler has spent nearly three decades at the intersection of technology, risk, and business building information security programs that work in the real world.As Vice President and Chief Information Security Officer at Meijer, Phil leads security for one of the nation's largest privately held retailers, overseeing the protection of supply chains, customer data, and critical operations across hundreds of locations in the Midwest.Phil's career spans industries where the stakes are high and the margin for error is low. Before joining Meijer in 2015, he served as CISO at Bass Pro Shops and previously held the CISO role at Finish Line. Earlier in his career he led security at Herff Jones, bringing security discipline to the manufacturing sector. He began his career at EDS and spent years consulting in the Aerospace sector where he got his start in security.What sets Phil apart is not just longevity, it is perspective. He has watched information security evolve from a reactive, audit-driven function into a proactive capability that enables business velocity. His approach centers on integrating security into how organizations operate, not as a checkbox, but as a competitive advantage that lets teams move fast while managing risk in practical ways.Beyond the day-to-day, Phil is a passionate contributor to the broader security community. He has served as a guest lecturer on cybersecurity and data privacy at the University of Chicago Law School, sits on the Institute for Cybersecurity Education and Research Advisory Board at Grand Valley State University, serves on the IT Advisory Committee at Kent County Technical Center, and is a board member the Meijer Credit Union. He is also featured in Midnight in the War Room, a Semperis documentary examining the human reality behind enterprise cyber defense.Phil has held his CISSP certification since 2009, attained his MBA from Davenport University, and a career's worth of operational experience across retail, aerospace, insurance, and manufacturing.Guest Quote “A successful CISO understands that it's not about prevention, it's about resilience, it's about recovery, and it's about identifying those things in your program that you can do incrementally better every single day. We're in the pursuit of perfection, but we understand we'll never get there.”Time stamps 02:46 Meet Philip Keibler: From Sysadmin to Security 04:35 Becoming a CISO 06:20 What CISOs Really Do 08:50 Defining Success and Resilience 10:41 Storytelling to the Board 13:29 Semperis' Midnight in the War Room 17:47 Team Care and Crisis Leadership 21:47 Advice for CISOs 24:24 The Case for Mastering the Fundamentals 31:02 Conclusion and Final ThoughtsSponsor The HIP Podcast is brought to you by Semperis, the leader in identity-driven cyber resilience for the hybrid enterprise. Trusted by the world's leading businesses, Semperis protects critical Active Directory and Entra ID environments from cyberattacks, ensuring rapid recovery and business continuity when every second counts. Visit semperis.com to learn more.Links Connect with Phil on LinkedInConnect with Sean on LinkedInDon't miss future episodesLearn more about SemperisHIP Conference 26 is coming to Nashville, September 8–10, 2026.Join us to explore this year's theme, Redefining Resilience, at the world's premier practitioner-led conference focused on securing hybrid identity environments.If you love the conversations on the HIP Podcast, this is where the community comes together in person. Learn more and register at https://www.hipconf.com/.

CISSP Cyber Training Podcast - CISSP Training Program
CCT 364: Third Party Risk Management - How One Vendor Breach Exposed 119,000 Users

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later Aug 3, 2026 46:08 Transcription Available


Send us Fan MailA breach can hit your headlines even when your own systems never get touched, and that's exactly why third-party risk management keeps showing up on the CISSP exam and in real incident reports. We walk through the Vimeo breach tied to its analytics vendor Anodot, where compromised vendor access and authentication tokens gave attackers a clean path to customer data. No video content or payment data was taken, but names, emails, and metadata exposure is still a trust and reputation problem that security teams have to own.From there, we zoom out to the bigger pattern behind modern supply chain security: attackers increasingly go after dependencies, CI/CD pipelines, shared developer tools, and widely used vendors because one compromise can cascade across hundreds of customers. We talk about how to reduce that exposure with a stronger TPRM program, including vendor risk tiering, continuous monitoring, SBOM thinking, and practical contractual controls like breach notification timelines, right to audit language, and clear subcontractor disclosure with flow-down requirements to address fourth-party risk.We also shift into CISSP Domain 1 rapid review mode: what the exam really wants when it asks about due diligence, evidence, and proportional risk decisions. You'll hear clean explanations of SOC 2 Type 1 vs SOC 2 Type 2, where ISO 27001 fits, why questionnaires like SIG are not proof, and which frameworks matter for third-party and supply chain risk management including NIST 800-161, ISO 27036, and NIST CSF 2.0. We close with practice scenarios that mirror common CISSP traps so you can spot them fast.Subscribe for more CISSP training, share this with a study partner, and leave a review so more security pros can find the show.Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

CISSP Cyber Training Podcast - CISSP Training Program
CCT 363: CISSP AI Governance: What Credit Union Examiners Are Really Asking

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later Jul 27, 2026 44:45 Transcription Available


Send us Fan MailOne bad AI decision can cost you more than money. It can cost you trust, trigger regulators overnight, and put your name on the hook when the board asks, “Who approved this?” We dig into AI governance through a CISSP lens, using real-world banking and credit union scenarios that show how fast things go sideways when AI tools slip outside your controls.We start with the uncomfortable reality behind modern AI adoption: vendors ship powerful models, teams connect third parties, and employees reach for whatever chatbot is quickest. From AI-powered lending platforms that promise speed and fairness, to shadow AI that starts with a simple copy paste of customer data, the common thread is the same. Policies are not protection unless you can detect, enforce, and prove what's happening with data, models, and vendors.Then we get practical. We walk through what examiners and auditors actually look for, why NIST AI RMF and existing third-party risk management rules are becoming the default playbook, and how to build evidence that holds up. Expect clear guidance on independent bias testing, explainability, contract language like right to audit and incident notification SLAs, and why model revalidation must be triggered by material change rather than an annual calendar cycle. We also tie the work back to CISSP domains and run practice questions designed to expose the “easy” answers that fail in real governance.If you're responsible for security, compliance, or risk, this is your roadmap for governing AI before it governs you. Subscribe, share with a teammate, and leave a review so more CISSP candidates and security leaders can find the show.Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

Coffee w/#The Freight Coach
1497. #TFCP - The AI Trojan Horse: Closing Logistics' Critical Data Voids!

Coffee w/#The Freight Coach

Play Episode Listen Later Jul 20, 2026 34:31


Are you blindly plugging AI tools into your freight operations without a second thought, or worse, letting shadow AI compromise your organization's most sensitive data? NMFTA's Director of Cybersecurity, Ben Wilkens, is back to give it to you straight about the wild west of AI in the transportation industry! We dive right into the critical differences between foundational AI models and everyday AI tools, the hidden risks of rapid large language model adoption, and why establishing a strict AI governance framework is now a matter of national security. The shift from zero to full AI integration has occurred almost overnight, and if you aren't actively protecting your digital footprint with proper guardrails, you're leaving your trucking company or brokerage vulnerable to bad actors and catastrophic data breaches.  We break down exactly how everyday professionals can utilize the NMFTA's free resources to build a secure tech infrastructure from the ground up, ensuring your data remains your ultimate currency.  Tune in for no-nonsense insights to protect your business, and don't forget to secure your spot at the upcoming NMFTA Cybersecurity Conference in Long Beach to stay ahead of the curve!  To access the 2026 NMFTA Cybersecurity AI Governance Framework, visit https://bit.ly/4wP09cq and complete the form.   About Ben Wilkens Ben Wilkens, CISSP, CCSP, CISM, is a Cybersecurity Principal Engineer at the National Motor Freight Traffic Association, Inc. (NMFTA)™. In his role at NMFTA, Ben spearheads research initiatives and leads teams dedicated to developing cutting-edge cybersecurity technologies, methodologies, and strategies to safeguard information systems and networks. He collaborates extensively with academic institutions, industry partners, and government agencies to advance cybersecurity practices and knowledge. Ben provides expert insights and recommendations to organizations, enhancing their security posture and helping them navigate the constantly evolving landscape of cyber threats. Before joining NMFTA, Ben was a key executive at a third-generation family-owned trucking and logistics company. There, he focused on the strategic integration of technology to improve operational efficiency while ensuring adherence to cybersecurity best practices. With a rare combination of CISSP, CCSP, and CISM certifications alongside an active Class A CDL, Ben brings a unique perspective to the intersection of cybersecurity and transportation. In addition to his extensive experience as an over-the-road driver, he has held roles in dispatch operations, driver management, and brokerage sales. Ben later transitioned to IT and operations support, where he honed his expertise in cybersecurity.  

CISSP Cyber Training Podcast - CISSP Training Program
CCT 362: Security Assessment Strategies & Abandoned Cloud Storage Risks (CISSP 6.1) - REPLAY

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later Jul 20, 2026 34:00 Transcription Available


Send us Fan MailThat forgotten cloud storage you stopped thinking about months ago can become a real attack path today. We start with a simple but dangerous scenario: abandoned AWS S3 buckets and other orphaned cloud storage that can be re-registered, repurposed, and used to serve malicious content to systems that still “trust” the old source. We walk through why this turns into a supply chain-style problem, what signals to look for, and the practical mitigations that matter most: proper decommissioning, continuous monitoring, tight access control, and disciplined cloud asset inventories.From there, we shift into CISSP Domain 6.1 and the real work of designing and validating assessment, test, and audit strategies. We explain how we approach building a security assessment and testing program from the ground up: clear objectives, tight scope, risk-based prioritisation, stakeholder alignment, and baselines grounded in frameworks like NIST CSF, ISO 27001, CIS Benchmarks, and NIST SP 800-53. The aim is simple: identify vulnerabilities, validate security controls, and turn findings into remediation that leadership can act on.We also break down core security testing methods you will see on the CISSP and in real organisations: vulnerability assessment, penetration testing (white box, black box, gray box), fuzz testing, SAST and DAST for application security, plus red team, blue team, and purple team collaboration. Finally, we demystify SOC 1 vs SOC 2 and Type 1 vs Type 2 reports, why they matter for third-party risk management, and how cyber resilience thinking (including the Cyber Resiliency Index) ties everything back to continuity and trust. If this helps, subscribe, share the show with a colleague studying CISSP, and leave a review with the topic you want next.Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

CISSP Cyber Training Podcast - CISSP Training Program
CCT 361: Bad Epoll - Root Access in 6 Instructions

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later Jul 13, 2026 32:20 Transcription Available


Send us Fan MailA six-instruction timing glitch in the Linux kernel can be the difference between “low-priv user” and full root control, and that is why we dig into the Bad EPoll vulnerability from a CISSP-ready, manager-first angle. We start by grounding what the Linux kernel EPoll subsystem does, why it is foundational to high-performance I/O, and why “just disable it” is not a real option when you're dealing with production Linux servers, desktops, cloud workloads, and Android devices.Then we unpack the security mechanics in clear terms: a use-after-free race condition, an impossibly thin race window, and the way memory corruption turns into privilege escalation. We also talk about what makes this case extra concerning, including the report that it can be triggered from inside Chrome's rendering sandbox. If you've ever relied on sandboxing, kernel boundaries, or “we run scanners” as your safety net, this story forces a more honest view of defense in depth.From there we connect the dots to CISSP Domain 8 software development security and real secure SDLC practice. We walk through where SAST, DAST, fuzzing, KASAN-style instrumentation, and AI-assisted code review help and where they fail, especially for concurrency bugs. The real takeaway is a layered detection strategy: automated testing plus manual secure code review for high-blast-radius code, support for external researchers through bug bounty programmes, and a patch management process that moves in days with verification and regression testing so incomplete fixes do not slip through.If this helps you think like a manager, subscribe, share the episode with a study buddy, and leave a review so more CISSP candidates can find it.Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

ITSPmagazine | Technology. Cybersecurity. Society
The Flood Made Everything Free. So Now We Pay for Proof. | Lens Four by Sean Martin | Read by TAPE9

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Jul 11, 2026 15:49


⬥EPISODE NOTES⬥ Tidal is about to stop paying royalties on any track it judges to be fully machine-made. Frame that as a music story and you miss the shift underneath it. By Deezer's own detection, roughly 75,000 AI-generated tracks now arrive every day, about 44% of everything uploaded, yet that same AI music is only 1 to 3 percent of what people actually play, and around 85% of those streams are flagged as fraudulent. The flood is not an audience. It is an attack on a shared payout. This edition follows one pattern across six industries: when the cost of generating something collapses toward zero, platforms stop paying for output and start paying for proof of human origin. Tidal cuts AI royalties. The Authors Guild sells a "Human Authored" badge for ten dollars a title. YouTube demonetizes "inauthentic" content. curl killed its bug bounty after a flood of AI slop, then reopened when the slop got good. And where no gatekeeper owns the payout, hiring, the open web, the scientific record, the flood just degrades the mechanism until no one trusts it. In this edition of Lens Four:

Redefining CyberSecurity
The Flood Made Everything Free. So Now We Pay for Proof. | Lens Four by Sean Martin | Read by TAPE9

Redefining CyberSecurity

Play Episode Listen Later Jul 11, 2026 15:49


⬥EPISODE NOTES⬥ Tidal is about to stop paying royalties on any track it judges to be fully machine-made. Frame that as a music story and you miss the shift underneath it. By Deezer's own detection, roughly 75,000 AI-generated tracks now arrive every day, about 44% of everything uploaded, yet that same AI music is only 1 to 3 percent of what people actually play, and around 85% of those streams are flagged as fraudulent. The flood is not an audience. It is an attack on a shared payout. This edition follows one pattern across six industries: when the cost of generating something collapses toward zero, platforms stop paying for output and start paying for proof of human origin. Tidal cuts AI royalties. The Authors Guild sells a "Human Authored" badge for ten dollars a title. YouTube demonetizes "inauthentic" content. curl killed its bug bounty after a flood of AI slop, then reopened when the slop got good. And where no gatekeeper owns the payout, hiring, the open web, the scientific record, the flood just degrades the mechanism until no one trusts it. In this edition of Lens Four:

All Things Internal Audit
Auditing the Auditors: Building Internal Audit at KPMG

All Things Internal Audit

Play Episode Listen Later Jul 7, 2026 21:07


The Institute of Internal Auditors Presents: All Things Internal Audit In this episode, Charles King sits down with Becky Mann to discuss what it takes to build and evolve an internal audit function inside a global firm. They share lessons from leading internal audit through disruption, how to structure teams around the business, and why auditors must move beyond rigid audit plans to deliver real value.  HOST: Charles King, CIA, CRMA, CISSP, CISA AI and Internal Audit Leader, KPMG  GUEST: Becky Mann, CIA Chief Audit Executive, KPMG   KEY POINTS: Introduction [00:00:00-00:00:44] Becky Mann's Internal Audit Background [00:00:44-00:02:06] Leading Internal Audit Through COVID-19 [00:02:06-00:03:18] KPMG's Internal Audit Function and Scope [00:03:18-00:05:35] Building Teams Around the Business [00:05:35-00:07:49] Learning to Pivot From the Audit Plan [00:07:49-00:09:21] Structuring Audit Portfolios [00:09:21-00:10:41] Rotations and Guest Auditor Programs [00:10:41-00:11:16] Onboarding Guest Auditors [00:11:16-00:13:55] Engaging the Board and Executive Stakeholders [00:13:55-00:16:36] Aligning Expectations and Avoiding Surprises [00:16:36-00:16:59] Why Internal Audit Still Matters [00:16:59-00:19:27] Choosing the Right Risk Response [00:19:27-00:20:31] Final Thoughts [00:20:31-00:20:54] IIA RELATED CONTENT:  Interested in this topic? Visit the links below for more resources: Global Internal Audit Standards Vision 2035 Communicating with the Board: Turning Audit Insights into Impact Three Lines Model   Visit The IIA's website or YouTube channel for related topics and more. Follow All Things Internal Audit: Apple Podcasts Spotify Libsyn Deezer

MSP Unplugged
Stop Getting Breached: Matt Lee Shares MSP Cybersecurity Strategies for Under $3M Shops

MSP Unplugged

Play Episode Listen Later Jul 6, 2026 40:21


CISSP Cyber Training Podcast - CISSP Training Program
CCT 360: SSA Whistleblower and the Thumb Drive: What CISSP Asset Security Tells Us About This Disaster

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later Jul 6, 2026 23:28 Transcription Available


Send us Fan MailImagine hearing a claim that the most sensitive identity data in the United States could be sitting on a personal thumb drive. That allegation is still unverified and under investigation, but it gives us a rare chance to see CISSP Domain 2 asset security in real time, with consequences that go far beyond a typical data breach.I walk through what's being reported about Social Security Administration data access and potential copying, then I put on the Domain 2 lens: data classification and handling requirements, who the true data owner is, what custodians should be enforcing, and how processors should be limited by scope, purpose, and time. We talk about why “high” impact data under FIPS 199 should automatically trigger stricter controls, and how failures in encryption, logging, and data loss prevention can let sensitive datasets slip outside organizational boundaries.We also dig into the part most teams get wrong: the data lifecycle. If you cannot execute secure disposal and verify it, you cannot “close Pandora's box.” Using NIST SP 800-88, we break down clear, purge, and destroy, connect it to real operational controls like removable media restrictions, and turn the whole story into practical exam guidance and CISO-level program lessons you can use with leadership.Subscribe for more CISSP-ready breakdowns, share this with someone studying Domain 2, and leave a review so more security pros can find the show. What is the first control you would fix in your own environment?Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

InfosecTrain
Crack CISSP in Your First Attempt in 2026

InfosecTrain

Play Episode Listen Later Jul 4, 2026 55:13


Thinking like a security leader is the absolute secret to conquering the CISSP exam. The primary reason candidates struggle with the test is that they answer questions from a purely technical perspective instead of adopting a managerial mindset. This session is designed to shift your perspective and build the exact strategy needed for success.Passing the exam on your first attempt requires a structured approach that respects the Computerized Adaptive Testing mechanics and the 2026 content updates.The 4-Phase Roadmap to Success1. Establish a Baseline: Weeks 1-2Take a full length diagnostic practice test before studying. Identify your weakest areas among the eight domains so you can allocate your study hours efficiently.2. Master Core Domains: Weeks 3-10Dive deep into high weight areas like Security and Risk Management. Pay close attention to modern topics integrated across the domains, including cloud native architectures, zero trust frameworks, and generative AI risk governance.3. Adopt the Managerial Mindset: Weeks 11-12Practice shifting your focus from fixing technical problems to selecting answers that protect the business mission, satisfy regulatory compliance, and mitigate systemic enterprise risk.4. Simulate Exam Dynamics: Weeks 13-14Take adaptive style mock exams. Because the testing algorithm adjusts question difficulty based on your answers and does not allow you to return to previous items, practice pacing yourself carefully through scenario based questions.Crucial 2026 Rule: Technical knowledge is the floor, but business leadership is the ceiling. Always choose the option that fixes the root process over the one that simply patches the immediate technical bug.To fast-track your journey and gain the comprehensive mentorship needed to conquer the eight domains, exploring structured training is your best next step.For an extensive deeper dive into the exact domain changes, exam mechanics, and preparation paths, check out this comprehensive 2026 CISSP Exam Strategy Video Guide⁠ which highlights how recent experience waiver updates and new governance models alter your study path.Watch Full Episode here: https://www.youtube.com/watch?v=3QpAPEmMOhc

HealthcareNOW Radio - Insights and Discussion on Healthcare, Healthcare Information Technology and More

S3E9: Shadow AI, Quantum Risk, and CISO Burnout - The Threats Healthcare Isn't Ready For Host: Frank Cutitta Guest: Dave Bailey, EMBA, CISSP, Vice President of Consulting Solutions & Strategy at Clearwater Security To stream our Station live 24/7 visit www.HealthcareNOWRadio.com or ask your Smart Device to “….Play Healthcare NOW Radio”. Find all of our network podcasts on your favorite podcast platforms and be sure to subscribe and like us. Learn more at www.healthcarenowradio.com/listen

CISSP Cyber Training Podcast - CISSP Training Program
CCT 359: ShinyHunters vs. Oracle — Supply Chain Risk Every CISSP Must Know

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later Jun 29, 2026 43:08 Transcription Available


Send us Fan MailA vendor gets breached and suddenly your perimeter does not matter, because the attacker does not need to “hack” you. They just reuse the access you already approved. That's the core lesson behind the Shiny Hunters campaign targeting Oracle PeopleSoft servers at colleges and universities, where compromised access led to large-scale theft of student data and a messy, high-impact supply chain incident.We walk through what supply chain security really means for modern cybersecurity and for the CISSP exam: it's not only the software you buy, but also hardware vendors, cloud service providers, managed service providers, open source libraries, and contractors with privileged access. I break down the four supply chain attack vectors you need to know cold: compromised credentials and OAuth tokens, malicious code injection in CI/CD pipelines, open source package attacks like typosquatting and maintainer compromise, and hardware tampering. Along the way, we map the ideas to CISSP Domains 1, 3, 5, and 8 so you can answer questions like a manager, not just a technician.Then we go deeper on two concepts that keep showing up in both real breaches and exam questions. First, SBOM (Software Bill of Materials), the “nutrition label” that tells you exactly what's inside your software so you can respond fast when a new CVE hits. Second, OAuth token governance, where long-lived or overly broad tokens can become silent master keys if you do not scope, expire, inventory, revoke, and monitor them properly. We finish with three practice questions and the reasoning behind the best answers and the common distractors.If this helps, subscribe so you do not miss the next training, share the episode with a CISSP study partner, and leave a review to help more security pros find the show.Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

The New CISO
CISO 3.0: The Playbook for Delivering Impact and Influence

The New CISO

Play Episode Listen Later Jun 25, 2026 58:06


What separates a CISO who survives from one who shapes the boardroom? In this episode, Steve Moore sits down with Walt Powell, Lead Field CISO at CDW and author of The CISO 3.0, to unpack the modern CISO playbook—why technical credentials alone no longer cut it, how to build personal eminence, and why most security leaders are still treated as second-class C-suite citizens.Walt traces his path from teaching networking before stateful firewalls existed, to writing CISSP exam questions for ISC2, to running CDW's Global Security Strategy Office. He explains what a field CISO does, why the role is harder than ex-CISOs realize, and how one bad meeting can tarnish a brand built over decades.He and Steve break down the four pillars Walt uses to measure his team—embedded advisory, eminence building, sales enablement, and voice of the customer—and how a karate-style “belt system” maps each consultant's competency. Walt explains why the same skills matrix from The CISO 3.0 works for any CISO trying to spot their own gaps.Walt argues a CISO who is not liked cannot succeed: you are the talent magnet, the culture builder, and the person proving in every board meeting that you belong in the seat. He shares the questions every candidate should ask before accepting the role—from D&O coverage to 10-K disclosure access—and why the 30-60-90 plan should be written before the second interview, not after the offer.The conversation closes with what Walt calls “strategic debt”—the identity and data governance work organizations skipped a decade ago that is now blocking AI adoption. Walt shares lessons from running OpenClaw on a Mac mini, why non-human identity tops every 2026 CISO worry list, and how Deep Research is reshaping senior architects.Key Topics• The modern field CISO role and the four pillars of impact• Why CISOs are still treated as second-class C-suite citizens• Building personal eminence through books, speaking, and writing• The CISO 3.0 skills matrix and self-assessment spider wheel• Two paths to the CISO seat: technical vs. MBA, and the gaps each leaves• Why likability is not optional for a successful CISO• Board readiness and proving you belong in the seat• Interview questions every CISO candidate must ask• Strategic debt: identity and data governance blocking AI adoption• OpenClaw, non-human identity, and the future of senior architectsGuest Bio:Walt Powell is the Lead Field CISO at CDW and a founding member of CDW's Global Security Strategy Office, where he leads a team of former CISOs advising security leaders in the field. A longtime executive coach and ISC2 exam development committee member, Walt is the author of The CISO 3.0: A Guide to Next-Generation Cybersecurity Leadership and Quantum Ready, his book on post-quantum cryptography. Connect with Walt on LinkedIn or at ciso30.com.GET A DEMO:

Becker’s Healthcare Podcast
Maria Sexton, MBA, CISSP, CRISC, CDPSE, Senior Vice President and Chief Information Officer at University Health System

Becker’s Healthcare Podcast

Play Episode Listen Later Jun 24, 2026 28:40 Transcription Available


In this episode, Maria Sexton, MBA, CISSP, CRISC, CDPSE, Senior Vice President and Chief Information Officer at University Health System, joins the podcast to discuss the growing need to expand patient access and deliver more seamless healthcare experiences. She shares insights on emerging developments shaping the industry and explains how rapid experimentation and innovation are helping organizations adapt, improve operations, and better meet the needs of patients and care teams.

Becker’s Healthcare Digital Health + Health IT
Maria Sexton, MBA, CISSP, CRISC, CDPSE, Senior Vice President and Chief Information Officer at University Health System

Becker’s Healthcare Digital Health + Health IT

Play Episode Listen Later Jun 23, 2026 28:40 Transcription Available


In this episode, Maria Sexton, MBA, CISSP, CRISC, CDPSE, Senior Vice President and Chief Information Officer at University Health System, joins the podcast to discuss the growing need to expand patient access and deliver more seamless healthcare experiences. She shares insights on emerging developments shaping the industry and explains how rapid experimentation and innovation are helping organizations adapt, improve operations, and better meet the needs of patients and care teams.

CISSP Cyber Training Podcast - CISSP Training Program
CCT 358: EDR Bypass Ransomware: The Gentle Killer Threat Every CISSP Must Know

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later Jun 22, 2026 43:02 Transcription Available


Send us Fan MailYour endpoint tool can be world class and still get taken out first. That's the unsettling reality behind a new wave of “EDR killer” capabilities being packaged inside ransomware-as-a-service platforms, where affiliates can plug in advanced evasion without building it themselves. When attackers can blind endpoint detection and response before the ransomware payload runs, the old comfort of “we have EDR, so we're covered” turns into a single point of failure.We unpack the reporting on a highly active ransomware operation and its toolset, then zoom in on the technical path that makes this work: BYOVD, bring your own vulnerable driver. With admin access, attackers load a legitimate but vulnerable signed driver, escalate into kernel mode, and terminate security processes from below the privilege stack. From there, we shift to what matters for real security programs: defence in depth, kernel integrity protections like HVCI and KMCI, strict driver allow and block policies, and aggressive driver hygiene to reduce attack surface.Then we put on the CISSP lens. We tie the scenario to Domain 7 security operations (EDR limits, incident response, monitoring), Domain 3 security architecture and engineering (layered controls, hardening), and Domain 1 security and risk management (risk = threat × vulnerability × impact, plus threat landscape shifts). The big takeaway is simple: your job isn't to find the fanciest tool, it's to build a program that still works when one control fails and to communicate that risk clearly to leadership.If this helps you think like a manager and study smarter, subscribe for weekly CISSP-focused breakdowns, share the episode with a teammate, and leave a review so more people can find the show.Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

ITSPmagazine | Technology. Cybersecurity. Society
Call It What It Is: When Ransomware Becomes Terrorism | An Interview with Cynthia Kaiser | Redefining CyberSecurity With Sean Martin — On Location at InfoSecurity Europe 2026

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Jun 19, 2026 16:18


A ransomware crew can run through your whole company between dinner and dessert. Sean Martin sat down with Cynthia Kaiser — twenty years at the FBI, now leading the Halcyon Ransomware Research Center — on the speed of the threat, the human cost the industry keeps abstracting away, and why a slice of ransomware deserves a harder name than “crime.”

ITSPmagazine | Technology. Cybersecurity. Society
A Crime Against Time | An Interview with Rik Ferguson | Redefining CyberSecurity With Sean Martin — On Location at InfoSecurity Europe 2026

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Jun 15, 2026 14:54


PODCAST EPISODE | Redefining CyberSecurity With Sean Martin — On Location at InfoSecurity Europe 2026 On Location With Sean Martin And Marco Ciappelli Adversaries are stealing encrypted data today that they cannot read yet, and storing it until a quantum computer can. Sean Martin sat down with Forescout's Rik Ferguson to talk about “harvest now, decrypt later,” why Q-Day is closer than the comfortable timelines suggest, and what the decisions you make this year have to do with secrets you thought were safe forever.

CISSP Cyber Training Podcast - CISSP Training Program
CCT 357: Is Your Encrypted Data Already Stolen? Quantum Risk & Supply Chain Attacks for CISSP

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later Jun 15, 2026 32:09 Transcription Available


Send us Fan MailSomeone is stealing encrypted data right now and they are not trying to read it today. They are saving it for later, betting that quantum computing will eventually break the encryption that protects it. I dig into the “Harvest Now, Decrypt Later” strategy, why it matters most for long-term confidentiality, and how security leaders can talk about it as a present-day risk instead of science fiction.From there, I get practical with post-quantum planning: what the NIST post-quantum cryptography standards signal, why quantum key distribution is still niche for most organisations, and the big architectural idea to remember for the CISSP and for real enterprise security programs: crypto agility. We walk through concrete steps like building a cryptographic inventory, mapping where RSA and elliptic curve crypto live, identifying data with 10 to 20 year secrecy needs, and pushing vendors for a clear PQC roadmap.Then we pivot into CISSP Domain 1 supply chain risk management (SCRM and CSCRM). I explain why supply chains are a prime target, how modern supply chain attacks can ride in through poisoned open source packages, and what SolarWinds showed the world about scale and impact. We close with the nuts and bolts that actually reduce third-party risk: lifecycle supplier management, meaningful assessments (on-site when it matters), document and policy review, audits, and minimum security requirements baked into contracts and SLAs.If you want more training, check out CISSP Cyber Training, subscribe for weekly updates, share this with a friend who owns risk, and leave a quick review so more CISSP candidates can find the show.Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

ITSPmagazine | Technology. Cybersecurity. Society
When the Threat Moves Daily and the Law Moves in Years | An Interview with James Morris | Redefining CyberSecurity With Sean Martin — On Location at InfoSecurity Europe 2026

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Jun 13, 2026 17:14


PODCAST EPISODE | Redefining CyberSecurity With Sean Martin — On Location at InfoSecurity Europe 2026 On Location With Sean Martin And Marco Ciappelli The UK's threats change by the day. Its laws change over years. Sean Martin sat down with James Morris — former Member of Parliament, now Director of the CSBR — to ask how a government writes cyber policy fast enough to matter, and why “resilience” has quietly stopped being a technical word.

CISSP Cyber Training Podcast - CISSP Training Program
CCT 356: Supply Chain Attacks Are Exploding in 2026 — Here's What the NCSC Wants You to Do

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later Jun 8, 2026 41:38 Transcription Available


Send us Fan MailYour software is only as trustworthy as the dependencies you quietly inherit and attackers know it. Today I break down the NCSC warning on software supply chain security and why open source package ecosystems have become a high-value target for real-world compromises that spread fast through CI/CD pipelines.I walk through the attack patterns that keep showing up in incidents: maintainer account compromise, expired domain takeover, typosquatting, and credential chaining. We connect each technique to the CISSP mindset so you can spot it in scenario questions and, more importantly, recognise it in your own environment. Along the way, I explain why Node.js, Python, and Rust projects are especially exposed, how automation can turn “latest version” convenience into an enterprise incident, and why developer environments often become an overlooked attack surface.Then we get practical with controls you can actually implement: pausing automatic dependency updates when compromise is suspected, adding human approval for critical packages, rotating credentials immediately, enforcing MFA on developer and registry accounts, and using private or trusted registries to mirror and vet dependencies. I also zoom out to show how to build supply chain security into the secure SDLC with software composition analysis (SCA), code signing, checksum verification, audit logging, continuous monitoring, and an SBOM so you can respond fast when a package turns toxic.If this helps you tighten your dependency management and level up your CISSP prep, subscribe, share this with a teammate, and leave a quick review so more security pros can find the show.Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

CISSP Cyber Training Podcast - CISSP Training Program
CCT 355: Zapier Breach Lessons For Cloud Security and Setting Up TPRM Program in 15 Minutes

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later Jun 4, 2026 24:26 Transcription Available


Send us Fan MailThe breach that takes down a company often does not kick in the front door. It walks in through a “simple” integration you set up months ago, powered by a token no one remembered to rotate. We start with a real-world Zapier-style scenario and unpack how researchers chained together a harmless-looking code block, an AWS Lambda environment, and a misconfigured IAM role to reach private repository files and ultimately an NPM token that could enable a supply chain attack.From there, we zoom out to the bigger cloud security problem: non-human identities. Service accounts, API keys, and OAuth tokens multiply fast, and they are frequently overprivileged, poorly tracked, and left active long after an integration is retired. We also talk about why SaaS-to-SaaS connections are so hard to secure, and why agentic AI makes visibility even more urgent. If you do not know what systems are connected, what data crosses those links, and who owns the risk, you are effectively trusting an invisible tunnel into your environment.To make this actionable, we lay out a four-phase third-party risk management (TPRM) framework you can apply immediately: build a vendor and integration inventory with tiering, run real due diligence (SOC 2 Type II, ISO 27001, data access scope, subprocessors and fourth parties), lock protections into contracts (DPA language, right to audit, breach notification expectations), then enforce ongoing monitoring and governance with quarterly token reviews, logging, and incident response playbooks. If you are studying for the CISSP, you will also see exactly how this maps to Domain 1, Domain 3, Domain 4, and Domain 5.Subscribe for more practical CISSP training, share this with a teammate who owns vendor approvals, and leave a review so more security pros can find it. What is the one integration you would audit first?Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

CISSP Cyber Training Podcast - CISSP Training Program
CCT 354: Data Security Controls and Compliance Requirements for the CISSP (Domain 2.3) - REPLAY

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later Jun 1, 2026 37:28 Transcription Available


Send us Fan MailYour firewall can be patched tomorrow, but what about the place your system hides its real secrets today? We start with a timely warning about a serious Fortinet FortiGate vulnerability and why perimeter devices are still a make-or-break control, then we pivot into the deeper layer most people ignore until it's too late: memory.We walk through CISSP Domain 3.4 by focusing on what memory protection is actually trying to achieve: confidentiality, integrity, and process isolation. From there, we unpack how modern operating systems enforce separation with paging, segmentation, and strict read, write, execute controls. You'll hear why Meltdown and Spectre were such a big deal, how speculative execution can leak passwords and encryption keys from privileged memory, and why patching decisions are never just “apply everything” but a risk-based vulnerability management call that depends on visibility into what you run.Next, we connect memory protection to virtualization security. We break down hypervisors, guest and host isolation, Type 1 versus Type 2 designs, and the threats that keep security teams up at night: VM escape, side-channel leakage through shared CPU resources, and the operational hazards of memory overcommitment. Then we bring in hardware roots of trust through TPMs: secure boot, measured boot, key storage for full disk encryption, TPM 2.0 types, and how HSM-style key management shows up in cloud environments. We close with practical best practices, from firmware and microcode updates to choosing encryption controls that fit your actual risk.If you're studying for the CISSP or building a real-world security strategy, subscribe, share this with a teammate, and leave a review so more security pros can find it.Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

CISSP Cyber Training Podcast - CISSP Training Program
CCT 353: AI Agent Governance Essentials - CISSP Practice Questions

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later May 28, 2026 28:26 Transcription Available


Send us Fan MailAI agents are landing in production faster than most security teams can track them, and the scariest part is how normal they can look. When an autonomous agent runs the same workflow 10,000 times, your SIEM and EDR may see “nothing to worry about” even while the agent quietly drifts outside its intended scope. That is the core AI governance problem we tackle, through the lens of CISSP thinking and real security leadership.We walk through what is driving the mess: board-level pressure, AI FOMO, and the dangerous habit of treating AI agents like old-school automation. Then we get concrete. We talk about why many enterprises still lack an inventory of AI agents, why traditional security tooling is tuned for human behaviour anomalies, and what it actually takes to be audit-ready. We cover practical governance frameworks like tiered autonomy, why observability is more than collecting output logs, and how to design decision-path tracing with execution records and decision logs you can act on.To make it actionable for exam prep and day-to-day work, I close with CISSP-style practice questions on the exact scenarios you will face: detection gaps, human approval bottlenecks, least privilege for agents, proving decisions during audits, and architecting platforms that balance operational efficiency with risk management. If you are serious about passing, I also share how my CISSP Sprint cohort is structured to force momentum, including booking your exam date early.Subscribe for weekly CISSP-focused training, share this with a teammate building AI workflows, and leave a review so more security pros can find the show. What part of AI agent governance is your biggest blind spot right now?Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

CISSP Cyber Training Podcast - CISSP Training Program
CCT 352: Data Security Controls and Compliance Requirements for the CISSP (Domain 2.3) - REPLAY

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later May 25, 2026 40:19 Transcription Available


Send us Fan MailYour security program can be airtight and still get wrecked by someone else's breach. We open with a Wired-style reality check: third-party app ecosystems and data brokers collecting location analytics at massive scale, then getting hacked or resold in ways your users never expected. If your organisation issues mobile devices, this is where security awareness, MDM controls, and clear “don't allow tracking unless required” guidance stops being a nice-to-have and starts becoming risk reduction.From there, we dig into CISSP Domain 2.3: provisioning resources securely, with the mindset of a senior security professional. We walk through information ownership versus asset ownership, why “IT owns the data” is often the wrong answer, and how classification (public, internal, confidential and beyond) drives least privilege and need-to-know access. We also cover the practical friction points: owners who don't realise they're owners, systems spread across teams, and the need to document decisions so risk acceptance is explicit instead of accidental.We then connect the dots across asset management, configuration management systems, and modern cloud operations. Expect talk on lifecycle tracking, secure disposal, rogue devices and shadow IT, plus the unique headaches of virtual sprawl, snapshots, tagging, data residency, and the cloud shared responsibility model. If you're studying for the CISSP exam or trying to run a cleaner security programme at work, you'll leave with a clearer map of what to inventory, who to hold accountable, and which controls keep resources from drifting into chaos.Subscribe for weekly CISSP-focused training, share this with a teammate who manages cloud or endpoints, and leave a review with the hardest “ownership” problem you've seen in the wild.Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

Going North Podcast
Ep. 1085 – From Cartoon Character to Podcast Powerhouse with Christine Blosdale

Going North Podcast

Play Episode Listen Later May 22, 2026 38:16


“I'm not a writer, but you don't have to be a writer to create a really wonderful book.” – Christine Blosdale Today's featured international bestselling bookcaster is award-winning media personality and sought-after expert authority coach, Christine Blosdale. Christine and I had a fun on a bun chat about her books, conquering her imposter syndrome, the power of a small start, and more!!Key Things You'll Learn:What sparked Christine's early love for recording and broadcastingHow she helps clients overcome their fear of writingWhy it's easier than you think to produce an audiobookThree major lessons learned from starting, growing, and running her podcastsChristine's Site: https://www.christineblosdale.com/Christine's Books: https://www.amazon.com/stores/author/B088C19Y6K/allbooksChristine's Podcasts: https://www.christineblosdale.com/mypodcastsThe opening track is titled, “Unknown From M.E. | Sonic Adventure 2 ~ City Pop Remix” by Iridium Beats. To listen to and download the full track, click the following link. https://www.patreon.com/posts/sonic-adventure-136084016 Please support today's podcast to keep this content coming! CashApp: $DomBrightmonDonate on PayPal: @DBrightmonBuy Me a Coffee: https://www.buymeacoffee.com/dombrightmonGet Going North T-Shirts, Stickers, and More: https://www.teepublic.com/stores/dom-brightmonThe Going North Advancement Compass: https://a.co/d/bA9awotYou May Also Like…699 – “From His Brothers Basement to Hall of Fame Podcaster” with Dave Jackson (@DaveJackson): https://www.goingnorthpodcast.com/ep-699-from-his-brothers-basement-to-hall-of-fame-podcaster-with-dave-jackson-davejackson/583 – “How to Be the Face of Your Business” with Tonya Eberhart (@brandfacestar): https://www.goingnorthpodcast.com/ep-583-how-to-be-the-face-of-your-business-with-tonya-eberhart-brandfacestar/488.5 – “Create, Innovate & Dominate” with Tracy Hazzard (@hazzdesign): https://www.goingnorthpodcast.com/ep-4885-create-innovate-dominate-with-tracy-hazzard-hazzdesign/681 – “Make Someone's Moment Through Podcasting” with Kelly Smith: https://www.goingnorthpodcast.com/ep-681-make-someones-moment-through-podcasting-with-kelly-smith/232 – “Podcast Power” with Heneka Watkis-Porter (@TheEntrepYou): https://www.goingnorthpodcast.com/232-podcast-power-with-heneka-watkis-porter-theentrepyou/400 – “How to Become a Multimillionaire, but Not Act Like It” with Tom Antion (@TomAntion): https://www.goingnorthpodcast.com/ep-400-how-to-become-a/#Host2Host Bonus Ep. - “Innuendo City” with Michelle Nedelec (@michellenedelec): https://www.goingnorthpodcast.com/host2host-bonus-ep-innuendo-city-with-michelle-nedelec-michellenedelec/333 – “How to Grow Your Social Media Influence” with Catherine Saykaly-Stevens (@CatherineNetWeb): https://www.goingnorthpodcast.com/ep-333-how-to-grow-your-social-media-influence-with-catherine-saykaly-stevens-catherinenetweb/86 - "Stepping Into the Spotlight" with Tsufit (@Tsufit): https://www.goingnorthpodcast.com/86-stepping-into-the-spotlight-with-tsufit-tsufit/384 – “Steal Your Skills From Corporate” with Katrina Roddy (@KRoddy65): https://www.goingnorthpodcast.com/ep-384-steal-your/277 – “Entrepreneurs Rocket Fuel” with Kimberly Hobscheid (@EntrepreneursR4): https://www.goingnorthpodcast.com/277-entrepreneurs-rocket-fuel-with-kimberly-hobscheid-entrepreneursr4/348 – “Bring Inner Greatness Out” with Dr. Mansur Hasib, CISSP, PMP, CPHIMS (@mhasib): https://www.goingnorthpodcast.com/ep-348-bring-inner-greatness-out-with-dr-mansur-hasib-cissp-pmp-cphims-mhasib/387 – “How to Demolish Imposter Syndrome & Create an Online Course” with Mark Kumar (@mark2kumar): https://www.goingnorthpodcast.com/ep-387-how-to/

CISSP Cyber Training Podcast - CISSP Training Program
CCT351: BitLocker Bypass Reality Check (YellowKey) and CISSP Practice Questions

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later May 21, 2026 24:28 Transcription Available


Send us Fan MailBitLocker feels like a safety net until you see how a single bypass can change the whole risk picture. Today we react to the Yellow Key vulnerability (noted in the news and referenced as CVE 2645585) and use it as a practical CISSP training moment: a public proof of concept is available, a vendor patch is not, and the attack hinges on physical access. That mix forces you to think clearly about what “high risk” actually means, why “critical” is not always the right label, and how real security teams respond when the perfect fix does not exist yet.We connect the story to CISSP domains you are actively tested on. Domain 3 shows up in the basics of data at rest encryption and the uncomfortable truth that encryption is only as strong as its implementation. Domain 7 shows up in zero-day vulnerability management, compensating controls, and the need to have patch deployment ready to move the moment Microsoft ships a fix. We also highlight why secure boot and firmware integrity checks matter, and why endpoint detection may not help when an attacker can silently read files with little to no logging signal.Then we shift into five exam-style questions designed to sharpen your decision-making: how to classify risk using likelihood and impact, how to spot absolute-language distractors, which CIA triad principle is actually failing when data is accessed without detection, and why data minimisation can reduce breach impact more than “adding another tool.” If you're studying for the CISSP exam and want practice that feels like real life, this is built for you.Subscribe for weekly CISSP practice, share this with a study partner, and leave a review so more candidates can find the show. What control would you tighten first if a BitLocker bypass hit your fleet tomorrow?Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

All Things Internal Audit
IT Controls Automation: Where Internal Audit Can Lead the Shift

All Things Internal Audit

Play Episode Listen Later May 20, 2026 20:35


The Institute of Internal Auditors Presents: All Things Internal Audit  In this episode, Mike Levy sits down with Reebu George to get practical about one of the most significant shifts underway in internal audit right now: the automation of IT controls. They talk through where this shift is happening, what use cases are proving their value, and how internal audit can lead the conversation rather than wait for the business to figure it out first.      HOST: Mike Levy, CIA, CRMA, CISSP CEO, Cherry Hill Advisory GUEST: Reebu George, CISSP, CISA, PMP Audit & Assurance Managing Director, IT Internal Audit Leader, Deloitte & Touche LLP   KEY POINTS: Introduction [00:00:02-00:00:47] The Shift Toward Continuous Auditing [00:00:47-00:02:26] How Automation Is Changing IT Controls [00:02:26-00:04:54] Building an Internal Audit Digital Strategy [00:05:39-00:07:09] Where Internal Audit Teams Should Start [00:07:09-00:09:33] Using AI and Automation in Audit Workflows [00:09:33-00:10:04] Earning a Seat at the Table [00:10:04-00:11:35] Developing Talent for Advisory Conversations [00:11:35-00:12:23] Rule-Based Controls and Automation Opportunities [00:12:23-00:13:45] Governance Risks in Automated Controls [00:13:45-00:15:39] Selling the Value of Automation [00:15:39-00:18:37] The Future of Continuous Assurance [00:18:37-00:19:49] Closing [00:19:52-00:20:23] IIA RELATED CONTENT:  Interested in this topic? Visit the links below for more resources: IT General Controls Certificate Program Knowledge Centers: Artificial Intelligence Global Internal Audit Standards Vision 2035   Visit The IIA's website or YouTube channel for related topics and more. Follow All Things Internal Audit: Apple Podcasts Spotify Libsyn Deezer  

CISSP Cyber Training Podcast - CISSP Training Program
CCT 350: Investigation Types Made Simple - CISSP Training (Replay)

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later May 18, 2026 44:49 Transcription Available


Send us Fan MailDefault passwords are the kind of problem everyone “knows” about and yet they still open doors for attackers every day. We start with a quick reality check on router security and why factory settings, legacy gear, and unmanaged IoT and OT devices can turn a simple misconfiguration into redirect attacks, man-in-the-middle exposure, DDoS headaches, or silent monitoring. If you're studying for the CISSP or defending a real network, you'll walk away with a clearer sense of what to fix first and how to roll changes out without creating change-management chaos.Then we shift into CISSP Domain 1.6: understanding requirements for investigation types. We break down administrative, criminal, civil, and regulatory investigations and why the burden of proof changes everything. We talk through why HR and legal need to be involved early, when law enforcement is (and is not) helpful, and how sloppy evidence handling can get key artifacts thrown out. We also cover e-discovery and legal holds, using the Electronic Discovery Reference Model (EDRM) to make the process easier to remember and apply.To close, we get practical about evidence: admissibility, chain of custody, and the forensics basics that protect data integrity, including media, memory, network, software, and embedded device analysis, plus the value of write blockers and disciplined documentation. If you want to pass the CISSP and operate like a calm, credible security professional during an incident, this is the mindset. Subscribe for weekly CISSP-focused training, share this with a teammate, and leave a review with the investigation topic you want us to tackle next.Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

CISSP Cyber Training Podcast - CISSP Training Program
CCT 349: FOXCONN Hack and Domain 7 CISSP Questions

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later May 14, 2026 28:20 Transcription Available


Send us Fan MailEight terabytes of stolen schematics is not just a scary number, it is a reminder that cyber risk becomes business risk fast. We start with the Wired report on the Foxconn ransomware attack and unpack what a claim like that could mean in the real world: intellectual property exposure, supply chain disruption, customer impact, and the uncomfortable truth that recovery is only one part of the story when data walks out the door.From there, we switch into CISSP Domain 7 Security Operations mode and work through practical exam-style questions with the “how would this hold up at work” mindset. We break down why live forensics imaging can be the right call during an insider threat investigation, using the order of volatility and the kinds of RAM artifacts that disappear the moment you shut a machine down. We also tackle a Patch Tuesday nightmare scenario where a CVSS 9.8 vulnerability is already being exploited but the change advisory board will not meet for ten days, and we explain why an emergency change process plus compensating controls is the mature security operations answer.We also cover a common privileged access failure where a domain admin uses an elevated account for email and browsing, and how least privilege plus a privileged access workstation (PAW) architecture can prevent a single phish from becoming domain compromise. Finally, we sharpen the fundamentals with an RTO/RPO recovery timeline question and a SIEM brute force threshold miss that illustrates false negatives and the need for better tuning and behavioural baselines.Subscribe for weekly CISSP training, share this with a study partner, and leave a review so more security pros can find the show. What topic do you want me to turn into practice questions next?Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

The Cybersecurity Defenders Podcast
Does the rise of AI mean human-led SOCs are obsolete? With Dr. Adeel Shaikh Muhammad [#322]

The Cybersecurity Defenders Podcast

Play Episode Listen Later May 13, 2026 25:18


Dr. Adeel Shaikh Muhammad, a cybersecurity strategist and global speaker with over 16 years of experience across information security, networks, and systems. Adeel brings a practical perspective on how organizations can adapt to evolving cyber threats and the growing role of AI in cybersecurity. Adeel, with an extraordinary portfolio of 40+ industry certifications, including CISSP, CISM, CISA, CCISO, PMP, CEH, ISO 27001 Lead Implementer & Auditor, and a robust suite of advanced Cisco, Microsoft, Fortinet, Barracuda, ITIL, PRINCE2, and AI-related credentials, he is a benchmark of technical mastery and visionary execution. His academic excellence includes a Master's in Cybersecurity and a current Doctorate in Business Administration (DBA) focused on the impact of AI in Security Operations Centers (SOCs) in the Gulf region.Adeel is the author of two acclaimed books—“AI-Driven Transformation of Security Operations Center (SOC)” and “AI and Us: The Ethical Choices”—bridging the critical intersection of AI innovation and ethical leadership.Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at limacharlie.io

CISSP Cyber Training Podcast - CISSP Training Program
CCT Vendor 04: The Practical Realities of Geopolitical Cyber Risk - Next Peak Interview

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later May 13, 2026 28:20 Transcription Available


Send us Fan MailNext Peak:   https://nextpeak.net/services/icr/A regional conflict can spike your cyber risk even if your offices never move and your headcount never changes. That is the uncomfortable reality behind geopolitical cyber risk, and it is why I brought on Helen Lee, Director of Intelligence Cyber Research at NextPeak, to break down how global flashpoints turn into real security problems for businesses of every size. If your security program only reacts to today's alerts, you are already behind the curve. We dig into what “geopolitical cyber risk” actually means, why awareness so often fails to become action, and how to bridge that gap with practical, decision ready outputs. Helen shares concrete examples that make the risk feel real: how hardware and supply chains can become national security issues, why router ecosystems can create broad exposure, and how second and third order effects in semiconductor production can introduce new vulnerabilities across your tech stack. We also talk about the World Economic Forum data showing that organisations expect geopolitical tensions to increase cyber risk while many are still adjusting their posture. From there, we get operational. We cover where this work fits in an existing security stack, how to “bake it in” at the governance, risk, and compliance layer, and why threat intelligence teams will be critical for monitoring geocyber indicators and handing off actionable guidance to the SOC and leadership. Helen walks through offerings like a geopolitical cyber risk index, assessments, advisory support, customised reporting, and future focused tabletop exercises that test readiness for plausible scenarios years ahead. If you are studying for the CISSP, this conversation ties directly to Security and Risk Management, third party risk, supply chain risk, and communicating risk to executives and boards. Subscribe for more practical CISSP focused conversations, share this with a security leader who owns vendor risk, and leave a review so more people can find the show. What is the biggest geopolitical risk you think your organisation is ignoring right now?Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

The Alien UFO Podcast
Reverse Engineering Crashed UFOs

The Alien UFO Podcast

Play Episode Listen Later May 12, 2026 10:59


This week I'm reading from Jon Majerowski's book 'Contact and Control: UFOs, DNA, and the Hidden War on Human Potential' THEY ARE NOT HIDING UFOs. THEY ARE HIDING WHAT CONTACT DOES TO YOU. Something is being managed. Not the craft, not the sightings, not the congressional hearings. Those are the distraction. What is being managed is the people who get too close. Experiencers are monitored, discredited, and studied without their knowledge or consent. The research never stopped. The public narrative just never changed. Jon Majerowski spent decades figuring out why. As a CISSP-certified cybersecurity expert trained to recognize patterns across complex systems, a Freemason with direct access to esoteric traditions most researchers never reach, and a lifelong UFO experiencer who has lived this from the inside, he came to the phenomenon from every angle at once. What he found was not a mystery. It was a machine. In Contact and Control, Majerowski maps the architecture of a control system that has been running for generations: Why UFO disclosure is controlled and what is deliberately kept back. The documented programs collecting DNA from experiencers without consent. How breakthrough technology gets suppressed and drip-fed through carefully selected frontmen. The thread of consciousness research running through military and intelligence channels. How ancient knowledge, Templar history, and occult tradition connect to all of it. This is not a book about lights in the sky. It is about who decided you were not allowed to know what those lights mean, and how they built the walls to make sure you never found out. For experiencers who were told they were crazy. For researchers who kept hitting the same walls. For anyone who has sensed the gap between the official story and lived reality. The control is real. So is the contact. This book maps both. Bio JON MAJEROWSKI is a husband, father, CISSP-certified information security professional, Freemason, and experiencer based in Maumee, Ohio. He hosts the UFOs on the Level podcast, where he conducts in-depth conversations with researchers, experiencers, insiders, and practitioners exploring UFOs, consciousness, and unexplained phenomena. As a member of several initiatory orders, Jon brings an insider perspective on esoteric traditions and mystery school knowledge to his investigation of the UFO phenomenon, or as he puts it, "The Phenomenon." His approach combines personal experience, decades of critical research, and a commitment to helping other experiencers feel less alone. Jon lives with his wife and daughters, balancing family life with consciousness exploration and disclosure activism. https://contactandcontrol.com/ https://www.amazon.com/dp/B0GTGPDMFM https://www.pastliveshypnosis.co.uk/ https://www.patreon.com/alienufopodcast https://simonbown.com/ My new book, Aspects of Alien Abduction https://www.amazon.com/dp/B0GRRPCT9Y Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Hybrid Identity Protection Podcast
Why Identity Security Needs Its Own Program with Angie Klein, IAM Business Technology Manager at Federated Insurance

Hybrid Identity Protection Podcast

Play Episode Listen Later May 12, 2026 38:05


This episode features Angie Klein, IAM Business Technology Manager at Federated Insurance.Angie brings over a decade of experience spanning systems development and identity security leadership, holding CISSP, CIDPRO, and CISM certifications and working hands-on with CyberArk, SailPoint IDN, and Active Directory in a regulated environment.In this episode, Angie dives into the organizational and cultural work that most identity programs skip. She shares why identity deserves its own program, how to apply OCM to bring resistant stakeholders on board, and why governance must come first. Angie's core argument is that if identity security creates too much friction, people will route around it, and that's where the real risk lives.This episode makes the case that the hardest part of identity security isn't the technology, it's getting people to trust it enough to stop working around it.Guest Bio As the IAM Business Technology Manager at Federated Insurance, Angie is dedicated to advancing our Identity and Access Management program and the industry as a whole. With over 10 years of experience and currently leading a team of Security Engineers and Identity and Access Analysts, Angie is passionate about IAM and love to see "ah ha" moments when colleagues understand that security is everyone's job.Angie bring over a decade of experience as a Systems Developer, providing extensive technical expertise in the Identity Security domain. I hold certifications, including CISSP, CIDPRO, and CISM. Additionally, she has experience working in the insurance industry and am skilled in CyberArk, Active Directory, SailPoint IDN, Analytical Skills, Project Management, and Public Speaking.Guest Quote "Identity security is ultimately about trust. People have to trust that you are doing the things that will help them do their job securely and not stop them from doing their job."Time stamps 01:45 Meet Angie Klein: Expert IAM Practitioner 01:22 Why Identity Needs Its Own Program 04:30 Why Identity Programs Stall 07:27 Organizational Change Management (OCM) Explained 12:51 OCM in Action 17:08 How to Gain Buy-In for an Identity Security Program 25:05 First Steps for Standing Up a Program 30:22 The Core Pillars of Identity Security 35:00 Conclusion and Final ThoughtsSponsor The HIP Podcast is brought to you by Semperis, the leader in identity-driven cyber resilience for the hybrid enterprise. Trusted by the world's leading businesses, Semperis protects critical Active Directory and Entra ID environments from cyberattacks, ensuring rapid recovery and business continuity when every second counts. Visit semperis.com to learn more.Links Connect with Angie on LinkedInConnect with Sean on LinkedInDon't miss future episodesLearn more about Semperis

The Alien UFO Podcast
UFO Contact & Control

The Alien UFO Podcast

Play Episode Listen Later May 11, 2026 60:43


This week I'm talking to Jon Majerowski about his book 'Contact and Control: UFOs, DNA, and the Hidden War on Human Potential' THEY ARE NOT HIDING UFOs. THEY ARE HIDING WHAT CONTACT DOES TO YOU. Something is being managed. Not the craft, not the sightings, not the congressional hearings. Those are the distraction. What is being managed is the people who get too close. Experiencers are monitored, discredited, and studied without their knowledge or consent. The research never stopped. The public narrative just never changed. Jon Majerowski spent decades figuring out why. As a CISSP-certified cybersecurity expert trained to recognize patterns across complex systems, a Freemason with direct access to esoteric traditions most researchers never reach, and a lifelong UFO experiencer who has lived this from the inside, he came to the phenomenon from every angle at once. What he found was not a mystery. It was a machine. In Contact and Control, Majerowski maps the architecture of a control system that has been running for generations: Why UFO disclosure is controlled and what is deliberately kept back. The documented programs collecting DNA from experiencers without consent. How breakthrough technology gets suppressed and drip-fed through carefully selected frontmen. The thread of consciousness research running through military and intelligence channels. How ancient knowledge, Templar history, and occult tradition connect to all of it. This is not a book about lights in the sky. It is about who decided you were not allowed to know what those lights mean, and how they built the walls to make sure you never found out. For experiencers who were told they were crazy. For researchers who kept hitting the same walls. For anyone who has sensed the gap between the official story and lived reality. The control is real. So is the contact. This book maps both. Bio JON MAJEROWSKI is a husband, father, CISSP-certified information security professional, Freemason, and experiencer based in Maumee, Ohio. He hosts the UFOs on the Level podcast, where he conducts in-depth conversations with researchers, experiencers, insiders, and practitioners exploring UFOs, consciousness, and unexplained phenomena. As a member of several initiatory orders, Jon brings an insider perspective on esoteric traditions and mystery school knowledge to his investigation of the UFO phenomenon, or as he puts it, "The Phenomenon." His approach combines personal experience, decades of critical research, and a commitment to helping other experiencers feel less alone. Jon lives with his wife and daughters, balancing family life with consciousness exploration and disclosure activism. https://contactandcontrol.com/ https://www.amazon.com/dp/B0GTGPDMFM https://www.pastliveshypnosis.co.uk/ https://www.patreon.com/alienufopodcast https://simonbown.com/ My new book, Aspects of Alien Abduction https://www.amazon.com/dp/B0GRRPCT9Y Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

CISSP Cyber Training Podcast - CISSP Training Program
CCT 348: ClaudeBleed - The Hidden Risk In AI Browser Extensions and CISSP Domain 3

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later May 11, 2026 34:00 Transcription Available


Send us Fan MailYour browser just became a security boundary you can't afford to ignore. We start with ClaudeBleed, a vulnerability in the Claude AI Chrome extension that shows how an AI browser agent can be hijacked by another malicious extension, even one with zero special permissions. When an agent can act “as you” inside a trusted environment, the risk jumps from theory to real outcomes like silent email sending, data loss through Google Drive, or code theft from private repos.We walk through the mechanics in plain language: the extension's communication model is too trusting, relying on origin assumptions instead of validating true execution context. That opens the door to script injection and environment-level manipulation, where the most sophisticated part of the attack is making bad actions look normal from the inside. We also talk about the vendor response, why partial patches can still leave uncomfortable gaps, and why “trust but verify” matters when AI tools move faster than enterprise controls.Then we pivot to CISSP Domain 3.9 design site and facility security controls, because reliability and security still live in wiring closets, server rooms, and restricted work areas. We cover practical facility security: locks and limited access, airflow and HVAC planning, avoiding storage-room chaos, why cameras must be monitored, how badge systems fail in real life, and how media and evidence storage ties into legal hold, forensics, encryption, and key management. We finish with environmental and resilience essentials including UPS vs generators, fire detection and suppression options, and power quality issues like sags, spikes, surges, and brownouts.Subscribe for weekly CISSP-ready lessons, share this with a teammate who lives in Chrome, and leave a review so more security pros can find the show.Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

CISSP Cyber Training Podcast - CISSP Training Program
AI Poisoning the Quiet Enterprise Threats and CISSP Questions (Domain 1)

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later May 7, 2026 28:05 Transcription Available


Send us Fan MailQuiet failures are the ones that scare me most, and enterprise AI creates a brand-new way for them to spread. If a chatbot becomes the “trusted employee” everyone relies on, a slow drip of bad documents, outdated procedures, or deliberately manipulated data can poison decisions for months without a single red flag. We break down what that looks like in real organizations, why it differs from the Hollywood version of a hack, and how the business impact shows up as confident misinformation rather than obvious outages.We also dig into the difference between data poisoning (deliberate manipulation) and data pollution (accidental garbage at scale), then connect it to retrieval augmented generation (RAG). RAG is powerful because it answers from your internal knowledge base, but that same knowledge base becomes the attack surface and the “source of truth” the model won't question. I share practical steps you can take right now: audit what your AI actually trusts, map the full AI contact surface across workflows and repositories, treat the AI pipeline like an untrusted vendor, and assign a named owner for accuracy and security.Then we shift into CISSP Domain 1 practice with exam-style questions that force real trade-offs: using annual loss expectancy (ALE) to recommend a risk treatment to the board, applying NIST RMF guidance even when controls are inherited through FedRAMP, handling an ethics dilemma under the ISC2 Code of Ethics, spotting the biggest BCP gap when RTO and RPO targets collide with backup frequency, and explaining why HIPAA compliance does not automatically equal GDPR compliance for EU citizen data.If you're studying for the CISSP or you're building security controls around AI and cloud systems, this one is built to sharpen both your judgement and your test readiness. Subscribe, share this with a friend who's deploying AI internally, and leave a quick review so more CISSP candidates can find the show.Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

CISSP Cyber Training Podcast - CISSP Training Program
CCT 346: CISSP Domain 7 - Testing Disaster Recovery Plans and Why BEC Still Works Despite MFA

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later May 4, 2026 26:53 Transcription Available


Send us Fan MailMFA feels like the finish line until you watch a company wire tens of millions of dollars to an attacker without a single password being stolen. We dig into why business email compromise (BEC) still works even in “secure” environments, because the real target is the decision point: trust, timing, urgency, and authority. When attackers can spoof executives or use deepfake voice and video, the authentication layer often never gets challenged in a meaningful way. We break down practical, real-world defenses that go beyond “more tools”: fixing payment and approval workflows, defining what counts as a high-risk transaction, forcing out-of-band verification using known contact details, adding mandatory pauses for unusual transfers, and training teams with realistic BEC scenarios during end-of-quarter and holiday pressure. The big takeaway is that blocked phishing emails are not the same thing as protected money movement, and leadership has to own that gap. Then we pivot into CISSP Domain 7 with a clear, test-focused walkthrough of disaster recovery plans. A DR plan on paper is not resilience, so we cover the five primary DR testing types: read-through checklist, walkthrough and tabletop, simulation, parallel, and full interruption. You will learn what each test proves, why most organizations stop at simulation, and how to build toward higher-confidence testing without taking reckless risks. If this helps you, subscribe for weekly CISSP-focused cyber training, share the episode with a teammate, and leave a review so more people can find the show.Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

CISSP Cyber Training Podcast - CISSP Training Program
CCT 345: Practice CISSP Questions - Domain 8.4 (Replay)

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later Apr 30, 2026 22:51 Transcription Available


Send us Fan MailA single compromised identity can turn your whole environment into a hallway of unlocked doors and cross-domain attacks are built to exploit exactly that. We start with a timely real-world breach theme and use it to explain how adversaries move between endpoints, cloud platforms, and third-party connections by abusing identity and privileged access, not just by running noisy malware. If your organization relies on a patchwork of identity tools, limited visibility, and “normal looking” logins, you may not see the threat until it has already jumped domains.From there, we pivot into CISSP Domain 8.4 thinking: how to evaluate acquired software without guessing. We break down what to look for in open source software (community activity, maintenance signals, orphaned project risk), what makes COTS software uniquely hard to assess (no source code visibility for deep vulnerability assessment), and what matters most for SaaS and managed services (encryption for data at rest and in transit, plus clear SLAs that define performance metrics and incident response expectations). We also cover why the shared responsibility model is non-negotiable for cloud security clarity, especially around account management and access control.We round it out with hands-on evaluation methods that map to both the exam and real security programs: threat modeling to uncover dependency risk, dependency scanning to catch vulnerable libraries, sandbox testing in a controlled environment, and periodic reassessments as threats evolve. If you're studying for the CISSP or building a safer vendor and software intake process, this one gives you a practical checklist mindset. Subscribe for more CISSP training, share this with a study partner, and leave a review with the software risk topic you want us to cover next.Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

CISSP Cyber Training Podcast - CISSP Training Program
CCT 344: Trigona RaaS - CISSP 3.7 Crypto - Board Translation Framework (Segment 3)

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later Apr 27, 2026 36:07 Transcription Available


Send us Fan MailRansomware actors are getting quieter, faster, and more custom and that should change how you study for the CISSP and how you defend your environment. We start with a quick personal update on a new CISSP Sprint: an eight-week live cohort built to give you structure, accountability, and weekly sessions so you can realistically target exam day without paying boot camp prices. Seats are limited, with an early bird option, because the whole point is real feedback and momentum. From there we dig into a timely threat story: Trigona ransomware and its use of a custom data exfiltration tool designed to evade common detection patterns. We break down what it means when attackers move away from popular utilities and how bandwidth saturation, connection rotation, and encrypted outbound traffic can slip past monitoring. If you're studying CISSP security operations and incident thinking, this is a clean example of how credential theft, endpoint interference, and network visibility all connect. Then we shift into CISSP Domain 3 cryptography and make the rules stick: symmetric versus asymmetric encryption, what key does what for confidentiality, and how digital signatures actually deliver integrity and non-repudiation. We also cover elliptic curve cryptography, key size advantages, and why quantum computing is forcing real post-quantum cryptography planning now, not later. Finally, we share a board briefing framework for CISOs and security leaders so you can translate technical risk into business impact, loss cases, and a clear ask the board can act on. Subscribe for weekly CISSP-focused cybersecurity training, share this with a study partner or a security leader, and leave a review so more people can find the show. What part do you want us to go deeper on next: crypto rules, ransomware tradecraft, or board communication?Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

Insight in Indian Country
"Lead with Curiosity."

Insight in Indian Country

Play Episode Listen Later Apr 25, 2026 10:43


Send us Fan MailCybersecurity isn't just an IT issue — it's a leadership issue. In this special session preview, REDW Principal and National Tribal Practice Leader Wes Benally sits down with REDW Principal John Graham, CISA, CISM, CISSP, CRISC, ahead of the NAFOA 44th Annual Spring Conference in Reno, Nevada.John offers Tribal leaders a new way to think about cyber risk — one rooted in stewardship, sovereignty, and sound decision-making. He shares how Tribal governments can build resilience before an incident strikes, what tends to go wrong when one does, and why data — from financial systems to recorded language — deserves to be protected like any other tribal asset.On April 28, 2026, John will join a panel of cybersecurity experts for What Could Go Wrong? Cybersecurity Essentials for Tribal Governments at NAFOA 2026. Don't miss it.Learn more about REDW at NAFOA 2026.Chapters00:00 - Introduction: John Graham and the NAFOA Panel01:04 - Reframing Cybersecurity as a Leadership Conversation02:53 - When Incidents Spiral: Leadership Disconnects During a Cyber Event06:06 - Stewardship, Sovereignty, and Tribal Data as an Asset08:26 - What John Hopes Leaders Take Away from NAFOAREDW Advisors and CPAs is proud to bring you the Insight in Indian Country Podcast, covering important advisory, accounting, and finance topics that impact Tribal Nations and business affairs. Thanks for listening!

@BEERISAC: CPS/ICS Security Podcast Playlist
Breaking Into OT Cybersecurity: Closing the Skills Gap and Protecting Critical Infrastructure

@BEERISAC: CPS/ICS Security Podcast Playlist

Play Episode Listen Later Apr 24, 2026 49:17


Podcast: PrOTect It All (LS 27 · TOP 10% what is this?)Episode: Breaking Into OT Cybersecurity: Closing the Skills Gap and Protecting Critical InfrastructurePub date: 2026-04-20Get Podcast Transcript →powered by Listen411 - fast audio-to-text and summarizationThe biggest challenge in OT cybersecurity isn't just technology - it's people. In this episode of Protect It All, host Aaron Crow sits down with Mike Holcomb to explore one of the most urgent issues facing the industry today: the growing skills gap in OT and ICS cybersecurity. Mike shares his journey from IT into operational technology security and breaks down why more professionals are needed to defend the systems that power energy, manufacturing, and critical infrastructure worldwide. This conversation goes beyond awareness - it's about practical pathways into the field and how the community is stepping up to make OT cybersecurity more accessible. You'll learn: Why OT cybersecurity is one of the most in-demand and underserved fields How to transition from IT to OT cybersecurity The biggest barriers newcomers face - and how to overcome them What foundational skills and controls matter most in ICS environments The role of community initiatives like BSides ICS in closing the gap Why training, mentorship, and collaboration are critical for the future Whether you're looking to break into cybersecurity, pivot your career, or build stronger teams, this episode delivers actionable guidance and inspiration from someone actively shaping the future of OT security. Tune in to learn how to build a career while helping protect the infrastructure the world depends on - only on Protect It All. Key Moments:  03:07 Getting started in cybersecurity 06:33 Early passion for cybersecurity 11:54 Hurricane Katrina aftermath discussion 15:50 Awareness and education on OT security 17:49 First experiences with GRID class 25:07 Early challenges in OT cybersecurity 29:17 Importance of effective communication 35:11 Global expansion of cybersecurity events 39:52 Building a foundation in OT cybersecurity 43:36 Excitement for new CompTIA exam 46:48 Expressing appreciation for community involvement About the guest:  Mike Holcomb is an independent consultant focused on OT/ICS cybersecurity and an educational content creator. Prior to supporting clients full-time through UtilSec, he was the Fellow of Cybersecurity and the OT/ICS Cybersecurity Global Lead for one of the world's largest engineering and construction companies, providing him with the opportunity to work in securing some of the world's largest OT/ICS environments, from power plants and commuter rail to manufacturing facilities and refineries. As part of his community efforts, Michael founded the BSidesICS/OT with multiple events planned globally in 2026. He has his master's degree in OT/ICS cybersecurity from the SANS Technology Institute. Additionally, he maintains cyber security and OT/ICS certifications such as the CISSP, GRID, GICSP, GCIP, GPEN, GCIH, ISA 62443, and more. He was awarded the SANS Difference Maker Award for Practitioner of the Year: ICS/OT Defender for 2025 and BEER-ISAC's Community Builder Award for 2026. He posts regularly on LinkedIn and YouTube to help others learn more about securing OT/ICS and critical infrastructure.  How to connect Mike:  Main Site: mikeholcomb.com LinkedIn: linkedin.com/in/mikeholcomb YouTube: youtube.com/@utilsec Instagram: instagram/_mikeholcomb/ Newsletter: utilsec.kit.com/95e31307f7 BSidesICS/OT: bsidesics.org Connect With Aaron Crow: Website: www.corvosec.com  LinkedIn: https://www.linkedin.com/in/aaronccrow Learn more about PrOTect IT All: Email: info@protectitall.co  Website: https://protectitall.co/  X: https://twitter.com/protectitall  YouTube: https://www.youtube.com/@PrOTectITAll  FaceBook:  https://facebook.com/protectitallpodcast   To be a guest or suggest a guest/episode, please email us at info@protectitall.co Please leave us a review on Apple/Spotify Podcasts: Apple   - https://podcasts.apple.com/us/podcast/protect-it-all/id1727211124 Spotify - https://open.spotify.com/show/1Vvi0euj3rE8xObK0yvYi4The podcast and artwork embedded on this page are from Aaron Crow, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.

UNSECURITY: Information Security Podcast
Unsecurity Episode 258: The CISSP Mentor Program with Brian Kelley

UNSECURITY: Information Security Podcast

Play Episode Listen Later Apr 20, 2026 30:49


In this episode of the Unsecurity Podcast, hosts Brad Nigh and Megan Larkins speak with Brian Kelley, information security consultant at FRSecure and one of the infamous CISSP Mentor Program's leads this year. Together, they talk about Brian's journey in information security and how it led him to helping support the FRSecure CISSP Mentor Program.Hear the trio discuss:Working in IT and finding interest in information securitySecurity focuses at MSPsPaying help forwardStudying tips and finding resourcesPicking your exam dateThe CISSP Mentor Program's format and evolutionWhile the program has already begun, you can still get all on-demand materials and join the rest of the live mentor sessions by signing up at https://learn.frsecure.com/courses/2026-cissp-mentor-program!Like, subscribe, and share with your network to stay informed about the latest in cyber and information security!We want to hear from you! Reach out at unsecurity@frsecure.com and follow us for more:LinkedIn: https://www.linkedin.com/company/frsecure/Instagram: https://www.instagram.com/frsecureofficial/Facebook: https://www.facebook.com/frsecure/BlueSky: https://bsky.app/profile/frsecure.bsky.socialAbout FRSecure:https://frsecure.com/FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can't do it alone. Whether you're wondering where to start or looking for a team of experts to collaborate with you, we are ready to serve.

Breaking Into Cybersecurity
Cybersecurity Career:Unlock your job path with Steve Regester | Breaking Into Cybersecurity

Breaking Into Cybersecurity

Play Episode Listen Later Apr 11, 2026 35:33


Dreaming of a high-demand, secure career that protects the digital world, but unsure where to start? This is your definitive guide to breaking into the thrilling field of cybersecurity, even with no prior experience! Industry expert Steve Regester reveals the exact roadmap you need to land your first cybersecurity job and build a resilient, rewarding future.In today's rapidly evolving digital landscape, the demand for skilled cybersecurity professionals is soaring. Cyber threats are more sophisticated than ever, making robust information security a critical concern for businesses worldwide. But how do you navigate this complex world and secure a lucrative role without an existing network or years of experience? Join us as Steve Regester, a seasoned veteran and renowned expert in the cybersecurity space, demystifies the entire process. He breaks down common barriers, offering actionable advice on everything from mastering foundational IT security skills to advanced strategies for career progression and how to get a cyber security job.This comprehensive guide is an invaluable resource for anyone aspiring to build a successful career in IT security. Whether you're a recent graduate looking for a clear career path, considering a significant career change into tech, or simply curious about the world of ethical hacking and digital defense, this video is your ultimate blueprint. Steve shares his invaluable insights on the diverse roles within cybersecurity, the most sought-after industry certifications like CompTIA Security+ or the highly respected CISSP, and crucial strategies for effective networking that will open doors.Discover how to craft a compelling cybersecurity resume, ace those challenging technical interviews, and position yourself as an indispensable asset in the global fight against cybercrime. Steve emphasizes practical tips and real-world scenarios, ensuring you understand not just 'what' to learn, but 'how' to apply it. We'll explore entry-level cybersecurity jobs, discuss potential cyber security salary expectations, and provide a clear framework for continuous learning in a field that constantly evolves. This isn't just about landing a job; it's about building a robust, future-proof cybersecurity career that truly matters. Empower yourself with the knowledge and confidence to make your cybersecurity career aspirations a reality. Don't miss out on these expert strategies from Steve Regester for breaking into cyber and securing your future in tech.Ready to embark on your cybersecurity journey? Like this video, subscribe to our channel for more expert insights into tech careers and information security, and hit the notification bell so you never miss an update on professional development! Share your questions and thoughts in the comments below – we love hearing from you!

The CyberWire
Lauren Van Wazer: You have to be your own North Star. [CISSP] [Career Notes]

The CyberWire

Play Episode Listen Later Jan 25, 2026 8:47


Please enjoy this encore of Career Notes. Lauren Van Wazer, Vice President, Global Public Policy and Regulatory Affairs for Akamai Technologies, shares her story as she followed her own North Star and landed where she is today. She describes her career path, highlighting how she went from working at AT&T to being able to work in the White House. She shares how she is a coach and a leader to the team she works with now, saying "my view is I've got their back, if they make a mistake, it's my mistake, and if they do well, they've done well." Lauren hopes she's made an impact in the world by making it a little bit better than before, and discusses how she doesn't let anyone stop her from her goals. Lauren shares her outlook on her experiences, calling attention to different roles in her life that made her journey all the better. We thank Lauren for sharing. Learn more about your ad choices. Visit megaphone.fm/adchoices