Podcasts about cissp

  • 352PODCASTS
  • 2,039EPISODES
  • 35mAVG DURATION
  • 5WEEKLY NEW EPISODES
  • Sep 14, 2026LATEST

POPULARITY

20192020202120222023202420252026

Categories



Best podcasts about cissp

Show all podcasts related to cissp

Latest podcast episodes about cissp

CISSP Cyber Training Podcast - CISSP Training Program
CCT 370: CISSP Cryptography, FIPS Validation, and Post-Quantum (Domain 3)

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later Sep 14, 2026 38:32 Transcription Available


Send us Fan MailA compliance deadline can change your security posture without changing a single bit of your encryption. We start with a simple sticker-on-the-windshield analogy that maps directly to what's happening with FIPS 140 validations: your VPN can keep encrypting, your database can keep protecting data, and yet an assessor can still mark you down because “working” is not the same as “validated.”We walk through the practical CISSP Domain 3 lesson behind the noise: the difference between an algorithm claim (we use AES-256), a configuration claim (we run in FIPS mode), and an evidence claim (we hold an active FIPS 140 validation on the CMVP list). With FIPS 140-2 certificates moving to historical status and FIPS 140-3 testing queues stretching beyond 500 days, the manager move is not wishful thinking. It's documenting the gap, treating it as risk, and getting formal risk acceptance with executive sign-off plus a real remediation plan, especially if you're facing CMMC or customer security assessments.From there we connect the dots across cryptographic life cycle management, cryptographic agility, and the real places crypto fails: key management and implementation. We cover HSM storage, rotation, dual control versus split knowledge, PKI revocation choices (CRL, OCSP, OCSP stapling), common cryptanalysis categories, and why side-channel and fault-injection attacks hit modules rather than “the math.” We then get clear on quantum risk, harvest now decrypt later, and what NIST's post-quantum standards (ML-KEM, ML-DSA, SLH-DSA) mean for your migration plan starting with a cryptographic inventory.Subscribe for more CISSP exam-ready training, share this with a teammate who owns compliance evidence, and leave a review if it helped. What would fail first in your environment: the crypto itself, or the proof you can show an auditor?Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

CISSP Cyber Training Podcast - CISSP Training Program
CCT 369: Security Models Demystified - CISSP Domain 3.2 (Replay of CCT 278)

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later Sep 7, 2026 31:46 Transcription Available


ITSPmagazine | Technology. Cybersecurity. Society
Marketing Volume Held Steady. Scrutiny Went Up. | Lens Four by Sean Martin | Read by TAPE9

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Sep 2, 2026 22:08


⬥EPISODE NOTES⬥ For a full year, agentic AI was the pitch. This year the conversation shifted to whether it holds up once it is actually running in production, against real work. Vendors came armed with customer-sourced numbers rather than concept demos — hours returned per analyst per week, percentages of alerts dispositioned without human review, agreement rates measured against human analyst judgment. Buyers arrived having spent the months since the previous major conference testing products and weighing what they were told against what they saw. Not one of the four questions that dominated the show is exciting, and not one of them is actually an AI question. Naming an owner before something ships is governance. Showing your work is audit. Knowing where your components came from is supply chain hygiene. Configuring a tool to reach the outcome it was bought for is the oldest plain, unrewarded work there is. AI did not create those problems — it made them impossible to keep deferring. Marketing volume held steady. Scrutiny went up. In this edition of Lens Four:

Dark Rhino Security Podcast
S20 E03 Are Phishing Tests Actually Helping?

Dark Rhino Security Podcast

Play Episode Listen Later Sep 2, 2026 45:25


Craig Taylor is a seasoned cybersecurity expert and entrepreneur with nearly 30 years of experience managing risk across industries—from Fortune 500 corporations to SMBs. As the Co-Founder and CEO of CyberHoot, he has pioneered a positive reinforcement approach to cybersecurity education, helping businesses eliminate risky behaviors and build a positive cybersecurity culture. With a background in psychology and extensive experience leading security programs at Chase Paymentech, Vistaprint, and DXC Technology, Craig specializes in incident response, governance, and compliance. A CISSP-certified professional since 2001, he is a recognized thought leader, public speaker, and advocate for making cybersecurity training engaging, fun, and effective.00:00 Introduction02:00 Our Guest02:42 Human Behavior in Cybersecurity08:32 Understanding Learning Taxonomy in Cybersecurity Training10:18 Non-Deception Based Phishing Simulations20:02 The Evolving Threat Landscape with AI31:02 The Psychology of Behavior Change38:00 The Human Element in Cybersecurity43:49 More about Craig

HLTH Matters
How AI Is Changing the Ransomware Threat in Healthcare

HLTH Matters

Play Episode Listen Later Sep 2, 2026 24:03


Ransomware remains one of the biggest cybersecurity threats facing healthcare, but the threat landscape is changing rapidly. Attackers are becoming more targeted, ransomware-as-a-service is making sophisticated tools more accessible, and artificial intelligence is giving cybercriminals new ways to identify vulnerabilities and craft convincing attacks. In this episode of The Beat's Cybersecurity at ViVE series, Sandy Vance speaks with Dave Bailey, VP of Consulting Solutions & Strategy at Clearwater, about the evolving ransomware threat and what healthcare organizations can do to stay ahead of it. Dave explains why smaller healthcare organizations and specialty practices are increasingly attractive targets, how attackers are using AI to improve social engineering and phishing, and why traditional cybersecurity approaches may not be fast enough for the threats ahead. The conversation also explores why healthcare organizations need to understand their AI risk, establish guardrails, inventory their AI use cases, and prepare defenses that can respond at machine speed. Dave shares practical advice for organizations beginning their AI journey, while emphasizing that cybersecurity can no longer be something organizations assess once a year. It has to become a continuously monitored, evolving process. In this episode, they talk about: Why healthcare continues to be one of the most attractive targets for ransomware How ransomware attacks have shifted toward smaller healthcare organizations and specialty practices Why dental practices and specialty providers can be particularly appealing targets How ransomware-as-a-service has created a more scalable business model for cybercriminals Why cybercriminals increasingly operate like businesses How attackers decide which healthcare organizations to target Why post-COVID healthcare's rapid shift to telehealth changed the threat landscape How AI is making phishing and social engineering attacks more sophisticated Why AI creates new governance and risk-management challenges for healthcare organizations Why healthcare organizations need defenses that can operate at machine speed How frontier AI models could help attackers discover previously unknown software vulnerabilities Why patching needs to become faster as AI-powered attacks evolve Why healthcare organizations need to challenge vendors about their cybersecurity roadmaps How organizations can begin building an AI governance strategy Why organizations should inventory their AI use cases before trying to govern them How healthcare organizations can use a tiered approach to AI risk Why workforce training and communication are essential to responsible AI adoption Why cybersecurity risk assessment can no longer be a once-a-year exercise Why scalability and continuous monitoring will become increasingly important A Little About Dave: Dave Bailey is Vice President of Consulting Solutions & Strategy at Clearwater, where he leads the development and delivery of enterprise-level cybersecurity and risk management services for healthcare organizations nationwide. With more than 24 years of cybersecurity experience, including 14 years focused on healthcare, Dave is a trusted advisor to executive teams navigating complex regulatory, operational, and cyber risk challenges. A recognized authority in cyber risk management and NIST Cybersecurity Framework assessment and implementation, Dave brings a strategic, business-aligned approach to security transformation. He previously served 13 years as a Communications and Information Officer in the United States Air Force, with leadership assignments spanning the Pentagon, domestic bases, and overseas operations. Dave holds an Executive MBA from Quantic School of Business and Technology and is a CISSP, blending executive perspective with deep technical expertise.

Redefining CyberSecurity
Marketing Volume Held Steady. Scrutiny Went Up. | Lens Four by Sean Martin | Read by TAPE9

Redefining CyberSecurity

Play Episode Listen Later Sep 2, 2026 22:08


⬥EPISODE NOTES⬥ For a full year, agentic AI was the pitch. This year the conversation shifted to whether it holds up once it is actually running in production, against real work. Vendors came armed with customer-sourced numbers rather than concept demos — hours returned per analyst per week, percentages of alerts dispositioned without human review, agreement rates measured against human analyst judgment. Buyers arrived having spent the months since the previous major conference testing products and weighing what they were told against what they saw. Not one of the four questions that dominated the show is exciting, and not one of them is actually an AI question. Naming an owner before something ships is governance. Showing your work is audit. Knowing where your components came from is supply chain hygiene. Configuring a tool to reach the outcome it was bought for is the oldest plain, unrewarded work there is. AI did not create those problems — it made them impossible to keep deferring. Marketing volume held steady. Scrutiny went up. In this edition of Lens Four:

Princeton
CyberPrinceton Podcast - Policy, Legislation, and Regulations - 004

Princeton

Play Episode Listen Later Sep 1, 2026 66:59


I'm wrapping up my analysis of The Declaration of Independence as a project initiation document, and I'll begin to examine the U.S. Constitution as a foundational governance artifact. The next couple of episodes will focus on translating regulatory documents into security and systems specifications—and ultimately used to engineer proprietary automated-compliance processing and security supervision systems.Join me as I take deep dives into the processes required to engineer policy driven high consequence operations across critical infrastructure and OT, national security and intelligence, cybersecurity and data privacy, finance, securities and trade, workforce and customer engagement, healthcare and higher education, and more. Princeton Brooke, CISSP

CISSP Cyber Training Podcast - CISSP Training Program
CCT 368: CISSP Asset Security and Data Classification (Domain 2)

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later Aug 31, 2026 42:56 Transcription Available


Send us Fan MailNine million images. No password. No encryption. And the defence was basically: “It wasn't public because you had to know the URL.” That single line opens up one of the most important CISSP Domain 2 conversations you can have: security through obscurity is not access control, and a hidden address is not a key. We take this real data exposure and translate it into the kind of manager-level reasoning the CISSP exam demands, not memorised trivia.We then zoom out into Asset Security fundamentals: identification and inventory, data classification based on impact, and the roles that make controls enforceable. We break down data owner versus custodian, plus controller and processor language you will see in privacy frameworks like GDPR. The core takeaway is simple and painful: without a named owner, nothing downstream is mandatory, so encryption, authentication, retention jobs, and evidence-producing logging keep losing to deadlines.Finally, we turn the incident into practice questions and “spot the trap” exam thinking: accountability does not transfer when you outsource, absent controls are not weak controls, and impact is not likelihood. We also hit retention and destruction across the data lifecycle, including NIST SP 800-88 clearing, purging, and destruction, and where degaussing and crypto erase really belong.Subscribe for more CISSP exam prep with real-world security stories, share this with a study partner, and leave a review if it helps you think more clearly under exam pressure.Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

Princeton
CyberPrinceton Podcast - Policy, Legislation, and Regulations - 003

Princeton

Play Episode Listen Later Aug 31, 2026 58:17


CyberPrinceton Podcast: Policy, Legislation, and RegulationsEpisode: 003Title: Chief Sovereign Security Scientist (CSCI) — Deconstructing the Declaration of Independence: Baseline Controls & System Intent Series: Policy, Legislation, and Regulations Host: Princeton Brooke, CISSP, PenTest+ CySA+ | Chief Security Scientist & Systems Engineer at Corporate CybersecurityEpisode OverviewWe are going live today for Episode 003.Building on my pre-engineering and scoping work in Episode 002, today I conclude my deep-dive analysis of the Declaration of Independence as a foundational enterprise specification for analyzing and authoring policy that addresses: enterprise governance, regulations, cybersecurity and privacy, critical infrastructure, national security and international relations. I also begin to assess the documents for their contribution in identifying the need for policy that shapes international relations, war powers, trade, commerce, labor relations, finance and accounting.Drawing from concepts in Sovereign Enterprise Security, I examine how the grievances, sovereign declarations, and foundational assertions of 1776 translate directly into technical system requirements. Using the Sovereign Enterprise Framework (SEFF) and SovSecOps, we will discuss and eventually demonstrate how to turn core legal intent into machine-readable Policy-as-Code (PaC), root trust boundaries, and automated regulatory processing logic—setting the stage for my architectural analysis of the U.S. Constitution in future episodes.__What I'm covering today and in the next couple of episodes:Declaration as System PID: Finalizing the Declaration of Independence as a formal Project Initiation Document and root security requirement baseline.Grievance Translation:Converting 18th-century operational failure modes (colonial grievances) into modern Zero Trust controls, access barriers, and threat models.Sovereign Root of Trust:Establishing identity, data sovereignty, and independent governance primitives before building the constitutional architecture.__Who Should Tune In:Systems & Enterprise Architects(Policy-as-Code & root system requirements)Cybersecurity & Defense Leaders (Zero Trust boundaries & sovereign security)GRC & Compliance Officers (Traceability & automated requirement engineering)Policy Researchers, Consultants & C-Suite Strategists(Computational law & institutional continuity)Bring your questions and edge cases to the live chat for interactive Q&A.

Princeton
CyberPrinceton Podcast - Policy, Legislation, and Regulations - 002

Princeton

Play Episode Listen Later Aug 29, 2026 135:23


Episode 002: Exploring Sovereign Enterprise Security concepts through the application of policy analysis techniques to the United States Charters of Freedom documents: The Declaration of Independence, The Constitution of the United States, and the Bill of Rights. Podcast: CyberPrinceton PodcastSeries: Policy, Legislation, and RegulationsHost: Princeton Brooke, CISSP, PenTest+ CySA+ | Chief Security Scientist & Systems Engineer at Corporate CybersecurityBuilding on Episode 001's reading of the Charters of Freedom, Episode 002 shifts to the critical pre-execution phase of enterprise design. Drawing from Princeton Brooke's book series, Sovereign Enterprise Security, this session serves as a live R&D exercise applying the Sovereign Enterprise Framework (SEFF) and SovSecOps to the initial pre-engineering, stakeholder consultation, and scoping phases of governance architecture.Assuming the role of Chief Sovereign Security Scientist (CSCI) for the 1776 Continental Congress, Princeton Brooke explores how a lead architect conducts feasibility studies, gathers high-level stakeholder requirements from historical founders, defines system boundaries, and structures the project charter before technical buildout.Engineering & Systems Pre-Design: Feasibility analysis, structural dependencies, and initial architecture mapping.Management Consulting & Stakeholder Alignment: Facilitating consensus among diverse factions (the Framers) and aligning intent with deliverables.Project Management & Scope Definition: Establishing charters, boundaries, constraints, and phase gates.Defense & International Relations: Scoping critical infrastructure protection, statecraft parameters, and sovereign security postures.Policy & Political Science: Translating governance philosophy and legislative intent into structured organizational requirements.Business Strategy, Finance & Logistics: Setting resource limits, modeling trade/supply constraints, and defining continuity parameters.Analyze pre-engineering responsibilities during enterprise initiation and discovery.Execute stakeholder discovery to capture requirements from competing historical leaders.Define scope, constraints, and baseline charters for multi-generational sovereign entities using SEFF and SovSecOps methodologies.Methodology: Enterprise Architecture Discovery & Factional AlignmentCore Topics: Consulting key founders (Hancock, Jefferson, Adams, Franklin) to extract core governance rules; reconciling central vs. state power; capturing non-negotiable requirements like root foreign independence, economic self-determination, and civil liberty guarantees.Methodology: Pre-Engineering Assessment & Scope Boundary DefinitionCore Topics: Framing the Declaration of Independence as the formal Project Initiation Document (PID); setting federal vs. state authority limits; evaluating physical, financial, logistical, and geopolitical constraints facing the 1776 build.Methodology: Systems Engineering Planning & Governance DesignCore Topics: Translating colonial grievances into structured engineering requirements for the Constitution and Bill of Rights; designing blueprints for checks and balances and immutable rights; drafting the SovSecOps lifecycle roadmap.Project Initiation Charter (1776 Edition): A structured scope document detailing stakeholder requirements, system boundaries, and project constraints.Pre-Engineering Architecture Matrix: A SEFF planning tool mapping stakeholder intent directly into functional requirement specifications across defense, finance, policy, and infrastructure.

The Raving Patients Podcast
Your Vendors Have the Keys: The Cyber Risk Dental Practices Ignore

The Raving Patients Podcast

Play Episode Listen Later Aug 28, 2026 37:34


The biggest cybersecurity threat to your dental practice may not be a hacker trying to break through your firewall. It could be a vendor you already trust. In this episode of the Raving Patients Podcast, Dr. Len Tau sits down with Anthony Jurjevic, CISSP, founder and CEO of Techspedient, to uncover the cybersecurity risks many dental practices do not realize are already inside their networks. With more than 25 years in healthcare IT and cybersecurity, including over 15 years focused on dental technology, Anthony explains why vendor access, outdated credentials, shared passwords, and poorly managed remote access tools can leave practices vulnerable. Anthony explains how practice management companies, imaging vendors, billing services, patient communication platforms, phone systems, and other vendors may have ongoing access to a practice's network. The problem is not necessarily that these vendors are unsafe. It is that many practices do not know who still has access, how that access is being monitored, or what happens if a vendor's credentials are compromised. The conversation also tackles one of the biggest misconceptions in dental cybersecurity: being in the cloud does not automatically mean your practice is backed up or secure. Anthony shares how attackers can compromise a workstation, use saved credentials to access cloud-based patient information, and quietly steal data without encrypting an entire network. He explains why modern ransomware attacks increasingly focus on data theft and extortion, making traditional backups only one piece of a much larger security strategy. Dr. Len and Anthony also discuss HIPAA compliance, what happens after a ransomware attack, the importance of cyber insurance and forensic investigations, and the practical steps dentists can take right now to identify vulnerabilities. From auditing vendor access and removing former employees to testing backups, enabling multi-factor authentication, and conducting third-party cybersecurity assessments, this episode gives practice owners a practical look at protecting both their patients and their businesses. What You'll Learn Why trusted vendors can become one of your biggest cybersecurity vulnerabilities How unattended remote access can expose your dental practice Why being "in the cloud" does not automatically make your data safe How modern ransomware has shifted from encrypting data to stealing it Why backups cannot protect you once patient data has already been stolen What "HIPAA compliant" software really means for a dental practice What to do immediately after discovering a possible ransomware attack Why individual user accounts are safer than shared passwords How to audit vendor access, administrative permissions, and former employee accounts Why multi-factor authentication should be enabled wherever possible How penetration testing can reveal weaknesses before an attacker finds them — Key Takeaways 02:13 Your Vendors Have the Keys: The Cyber Risk Dental Practices Ignore 03:45 Meet Anthony Jurjevic 05:35 The Hidden Risk of Vendor Access 09:55 Why the Cloud Is Not a Backup 13:12 Ransomware, Data Theft, and Cyber Threats 17:57 What HIPAA Compliance Really Means 19:42 What Happens After a Ransomware Attack 24:54 Simple Ways to Protect Your Practice 26:20 The Danger of Shared Credentials 30:06 Testing Your Practice's Cybersecurity 32:15 Lightning Round 35:55 Connect With Anthony — Connect With Anthony Email: ajurjevic@techspedient.com Phone: 732-275-2708 Company: Techspedient - https://www.techspedient.com/ Anthony is also offering Raving Patients listeners a free simulated phishing attack for their practice. There is no obligation or sales pressure, and practices receive the reports so they can see where their vulnerabilities may be and address them with their IT provider. — Learn proven dental marketing strategies and online reputation management techniques at DrLenTau.com.   This podcast is sponsored by Dental Intelligence. Learn more here.   This podcast is sponsored by CallRail, call tracking & lead conversion software for dentists. Find out more here.   Raving Patients Podcast is your go-to place for the latest and best dental marketing strategies that will help you skyrocket your practice. Follow us for more!  

Princeton
CyberPrinceton Podcast - Policy, Legislation, and Regulations - 001

Princeton

Play Episode Listen Later Aug 27, 2026 143:57


Join Princeton Brooke in the kickoff to the CyberPrinceton Podcast series called “Policy, Legislation, and Regulations”.Episode one includes:​ Reading of the United States Charters of Freedom:​ Declaration of Independence ​ United States Constitution ​ Bill of Rights​ Ideas for the Podcast seriesPrinceton Brooke is an award winning cyber security researcher and author of the Sovereign Enterprise Security book series. He holds a Master of Science in Cyber Security Engineering from the University of Southern California, and several industry and professional certifications including CISSP, CySA+, and PenTest+. Princeton brings over 35 years of experience in software development, security, and systems engineering for high consequence and regulatory operations. Mr. Princeton Brooke is the Chief Security Scientist and Systems Engineer at Corporate Cybersecurity.

The Full Nerd
Episode 413: Ethical Hacker Talks Kernel Level Anti-Cheat, Wi-Fi Hacking & More

The Full Nerd

Play Episode Listen Later Aug 25, 2026 144:48


Join The Full Nerd gang as they offer level-headed takes about the latest PC building news. In this episode the gang is joined by special guest Mike Danseglio, CEH & CISSP, to discuss topics from DEFCON 2026, including the safety (or lack thereof) of anti-cheat software, how easily Wi-Fi can be hacked and what you can do about it, and much more. And of course we answer questions live! Timecodes: (00:00:00) - Intro (00:07:40) - DEFCON 2026 (00:39:14) - Anti-cheat debate (01:13:02) - Wi-Fi hacking (01:48:15) - Q&A Join the PC related discussions and ask us questions on Discord: https://discord.gg/UWhjwg778a Follow the crew on X and Bluesky: @AdamPMurray @BradChacos @MorphingBall Music by Our Ghosts: https://ourghosts.bandcamp.com/ Some links may contain affiliate links, which means if you buy something PCWorld may receive a small commission. ============= Read PCWorld! Website: http://www.pcworld.com Newsletter: http://www.pcworld.com/newsletters ============= Learn more about your ad choices. Visit megaphone.fm/adchoices

CISSP Cyber Training Podcast - CISSP Training Program
CCT 367: Threat Modeling and the AI Agent That Breached Hugging Face (CISSP Domain 1.10)

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later Aug 24, 2026 42:52 Transcription Available


Send us Fan MailA rogue AI agent didn't “hack the future” so much as exploit the oldest security problems in the book: weak boundaries, over-trusted inputs, exposed endpoints, and credentials lying around. We walk through the Hugging Face intrusion story like a CISO briefing a board, step by step, translating a fast-moving AI-red-team narrative into the kind of clear threat modeling logic you need for ISC2 CISSP Domain 1.10 and for real risk decisions. From there, we shift into training mode and get concrete about threat modeling concepts and methodologies. We define threat modeling the way the exam cares about it: proactive, iterative, and designed to produce security requirements and prioritised countermeasures that feed your SDLC and risk register. We break down the three starting perspectives (asset-centric, attack-centric, and system-centric), then anchor STRIDE to data flow diagrams and trust boundaries so you can identify what security property is actually being violated, not just recite acronyms. We also cover the difference between identifying and ranking threats so you don't fall into the classic traps: DREAD ranks threats you already found, while PASTA starts with business objectives and risk appetite and is built for risk-centric outputs leaders can fund. We talk attack trees, why MITRE ATT&CK is an input rather than a methodology, and why your threat actor catalog must include authorized non-human identities and vendor integrations that can operate outside intended scope. If this helps, subscribe, share it with a study buddy, and leave a quick review so more CISSP candidates can find it.Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

The Chris Voss Show
The Chris Voss Show Podcast – Artificial Intelligence Governance, Risk, and Compliance: Ensuring Trust, Security, and Ethics in AI-Based System by Dr. Kellep A. Charles AIGP CISSP

The Chris Voss Show

Play Episode Listen Later Aug 19, 2026 47:05


Artificial Intelligence Governance, Risk, and Compliance: Ensuring Trust, Security, and Ethics in AI-Based System by Dr. Kellep A. Charles AIGP CISSP https://www.amazon.com/Artificial-Intelligence-Governance-Risk-Compliance/dp/B0GYJD5D6X Kellepcharles.com Artificial Intelligence is rapidly changing many industries, but with its power comes responsibility. “AI Governance: Ensuring Trust, Security, and Ethics in AI-Based Systems” is your guide to navigating the challenges of responsible AI development and deployment. Written by cybersecurity expert Dr. Kellep A. Charles, this essential resource connects AI innovation with ethical practices. Whether you are a cybersecurity professional, data scientist, business leader, policymaker, or student, this book offers practical frameworks for managing AI risks, ensuring compliance, and creating trustworthy systems. Inside, you’ll find: Foundational AI concepts and the development of machine learning technologies Insights into agentic AI systems, including their benefits, risks, and governance needs Real-world applications of the NIST AI Risk Management Framework Strategies for managing the entire AI development lifecycle Practical threat modeling and security testing methods for AI systems Techniques for data governance, privacy protection, and reducing bias Current laws, standards, and regulations such as GDPR and the EU AI Act Step-by-step guidance for creating AI cybersecurity frameworks Protocols for incident response, monitoring, and maintaining deployed AI systems Tools, certifications, and organizational resources for AI security testing What makes this book unique? It includes real-world case studies, detailed checklists, sample governance policies, and templates for assessing AI impact. This book turns abstract AI ethics into concrete action plans. It addresses critical risks like model poisoning, adversarial attacks, data protection, and algorithmic fairness, providing practical strategies for mitigation. It is ideal for professionals seeking AIGP certification, organizations establishing AI governance programs, or anyone dedicated to responsible AI innovation. The book offers easy-to-understand explanations for non-technical readers while delivering the depth that practitioners need. Create AI systems that are powerful yet transparent, accountable, and aligned with human values. In a time when AI failures can have serious consequences, this book shows you how to ensure AI serves everyone safely and ethically. Learn to manage AI before it manages you.

CISSP Cyber Training Podcast - CISSP Training Program
CCT 366: Software Supply Chain Security Explained — CISSP Domain 8 (ChainDrop Case Study)

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later Aug 17, 2026 33:04 Transcription Available


Send us Fan MailA supply chain attack that leaves your Git history spotless should change how you think about “secure code.” We walk through ChainDrop, a worm discovered in the NPM ecosystem that poisoned 444 packages while evading the places defenders usually look. The unnerving twist is that it can trigger without a classic npm install and can hide in the space between your repository and the package archive your CI/CD pipeline actually pulls, which is exactly why code review alone can't be your finish line.From there, we tie the real-world scenario directly to CISSP Domain 8 Software Development Security and the secure SDLC. I lay out a clear, exam-friendly framework for assessing third-party and acquired software risk: Software Composition Analysis (SCA), Software Bill of Materials (SBOM), vendor and publisher risk assessment, and runtime plus pipeline controls. We talk about why SCA is necessary but incomplete, how a living SBOM enables fast exposure checks when a new campaign hits, and why Executive Order 14028 is pushing SBOM adoption into “expected” territory for many organisations.We also get practical about CI/CD pipeline security: dependency pinning, trusted publishing workflows, signed commits, OIDC, and package signing and verification approaches like Sigstore and Cosign. Finally, we run through scenario-based practice questions that highlight common CISSP traps and the manager mindset the exam rewards. If you want more episodes like this, subscribe, share it with a developer or security lead, and leave a quick review so more CISSP candidates can find the show.Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

supply chains case study executive orders domain git sca ci cd npm cissp cosign sdlc sbom software supply chain security materials sbom sigstore oidc
CISSP Cyber Training Podcast - CISSP Training Program
CCT 365: Malicious QR Code Attacks and Digital Forensics Techniques Every CISSP Should Know [REPLAY]

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later Aug 10, 2026 25:05 Transcription Available


Send us Fan MailOne careless QR scan can quietly turn a “private” chat into a live wiretap. We start with a timely threat story: Russian APT-style actors abusing Signal's linked device flow by pushing phishing links that contain malicious QR codes, so messages can be mirrored to an attacker device in real time. If you use Signal, WhatsApp, or Telegram at work, this is the kind of simple, human-triggered failure mode worth building into your security awareness habits.Then we shift into CISSP Question Thursday with a rapid, practical run through CISSP Domain 7.1 style topics in digital forensics and incident response. We break down what comes first when handling digital evidence (forensic copy before analysis), how to examine a suspicious file without detonating it (static analysis), and what makes an incident report useful under pressure (a clear timeline of events and actions taken). We also cover insider threat artifacts, mobile device forensics tools like Cellebrite UFED, and why chain of custody is the backbone that keeps evidence credible from collection to court.Along the way, we talk about root cause analysis, anomaly-based detection for network traffic, and why clear writing beats big jargon when you're briefing executives, legal, or a board. If you want exam-ready thinking that also maps to real investigations, you'll get it here.Subscribe for weekly CISSP training, share this with a teammate who scans QR codes too fast, and leave a review with the topic you want next.Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

Hybrid Identity Protection Podcast
Inside a Veteran CISO's Playbook for Crisis and Communication with Philip Keibler, VP and CISO at Meijer

Hybrid Identity Protection Podcast

Play Episode Listen Later Aug 4, 2026 34:46


This episode features Philip Keibler, Vice President and CISO at Meijer, one of the nation's largest privately held retailers.With nearly three decades of security leadership, including CISO roles at Bass Pro Shops and Finish Line, Phil brings a rare long-view perspective on what the job actually requires day to day. He also talks about his feature in Semperis' upcoming documentary Midnight in the War Room, premiering at Black Hat on August 5.In this episode, Phil explains why CISOs who struggle to get budget usually have a storytelling problem, how he defines success in a role where stopping every attack is impossible, and what it takes to lead a team through an active incident. He also dives into why fundamentals are what actually address most of an organization's risk.This episode makes the case that the hardest parts of the CISO job are rarely technical, and that mastering the basics matters more than chasing the newest tool.Guest Bio Philip Keibler has spent nearly three decades at the intersection of technology, risk, and business building information security programs that work in the real world.As Vice President and Chief Information Security Officer at Meijer, Phil leads security for one of the nation's largest privately held retailers, overseeing the protection of supply chains, customer data, and critical operations across hundreds of locations in the Midwest.Phil's career spans industries where the stakes are high and the margin for error is low. Before joining Meijer in 2015, he served as CISO at Bass Pro Shops and previously held the CISO role at Finish Line. Earlier in his career he led security at Herff Jones, bringing security discipline to the manufacturing sector. He began his career at EDS and spent years consulting in the Aerospace sector where he got his start in security.What sets Phil apart is not just longevity, it is perspective. He has watched information security evolve from a reactive, audit-driven function into a proactive capability that enables business velocity. His approach centers on integrating security into how organizations operate, not as a checkbox, but as a competitive advantage that lets teams move fast while managing risk in practical ways.Beyond the day-to-day, Phil is a passionate contributor to the broader security community. He has served as a guest lecturer on cybersecurity and data privacy at the University of Chicago Law School, sits on the Institute for Cybersecurity Education and Research Advisory Board at Grand Valley State University, serves on the IT Advisory Committee at Kent County Technical Center, and is a board member the Meijer Credit Union. He is also featured in Midnight in the War Room, a Semperis documentary examining the human reality behind enterprise cyber defense.Phil has held his CISSP certification since 2009, attained his MBA from Davenport University, and a career's worth of operational experience across retail, aerospace, insurance, and manufacturing.Guest Quote “A successful CISO understands that it's not about prevention, it's about resilience, it's about recovery, and it's about identifying those things in your program that you can do incrementally better every single day. We're in the pursuit of perfection, but we understand we'll never get there.”Time stamps 02:46 Meet Philip Keibler: From Sysadmin to Security 04:35 Becoming a CISO 06:20 What CISOs Really Do 08:50 Defining Success and Resilience 10:41 Storytelling to the Board 13:29 Semperis' Midnight in the War Room 17:47 Team Care and Crisis Leadership 21:47 Advice for CISOs 24:24 The Case for Mastering the Fundamentals 31:02 Conclusion and Final ThoughtsSponsor The HIP Podcast is brought to you by Semperis, the leader in identity-driven cyber resilience for the hybrid enterprise. Trusted by the world's leading businesses, Semperis protects critical Active Directory and Entra ID environments from cyberattacks, ensuring rapid recovery and business continuity when every second counts. Visit semperis.com to learn more.Links Connect with Phil on LinkedInConnect with Sean on LinkedInDon't miss future episodesLearn more about SemperisHIP Conference 26 is coming to Nashville, September 8–10, 2026.Join us to explore this year's theme, Redefining Resilience, at the world's premier practitioner-led conference focused on securing hybrid identity environments.If you love the conversations on the HIP Podcast, this is where the community comes together in person. Learn more and register at https://www.hipconf.com/.

CISSP Cyber Training Podcast - CISSP Training Program
CCT 364: Third Party Risk Management - How One Vendor Breach Exposed 119,000 Users

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later Aug 3, 2026 46:08 Transcription Available


Send us Fan MailA breach can hit your headlines even when your own systems never get touched, and that's exactly why third-party risk management keeps showing up on the CISSP exam and in real incident reports. We walk through the Vimeo breach tied to its analytics vendor Anodot, where compromised vendor access and authentication tokens gave attackers a clean path to customer data. No video content or payment data was taken, but names, emails, and metadata exposure is still a trust and reputation problem that security teams have to own.From there, we zoom out to the bigger pattern behind modern supply chain security: attackers increasingly go after dependencies, CI/CD pipelines, shared developer tools, and widely used vendors because one compromise can cascade across hundreds of customers. We talk about how to reduce that exposure with a stronger TPRM program, including vendor risk tiering, continuous monitoring, SBOM thinking, and practical contractual controls like breach notification timelines, right to audit language, and clear subcontractor disclosure with flow-down requirements to address fourth-party risk.We also shift into CISSP Domain 1 rapid review mode: what the exam really wants when it asks about due diligence, evidence, and proportional risk decisions. You'll hear clean explanations of SOC 2 Type 1 vs SOC 2 Type 2, where ISO 27001 fits, why questionnaires like SIG are not proof, and which frameworks matter for third-party and supply chain risk management including NIST 800-161, ISO 27036, and NIST CSF 2.0. We close with practice scenarios that mirror common CISSP traps so you can spot them fast.Subscribe for more CISSP training, share this with a study partner, and leave a review so more security pros can find the show.Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

CISSP Cyber Training Podcast - CISSP Training Program
CCT 363: CISSP AI Governance: What Credit Union Examiners Are Really Asking

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later Jul 27, 2026 44:45 Transcription Available


Send us Fan MailOne bad AI decision can cost you more than money. It can cost you trust, trigger regulators overnight, and put your name on the hook when the board asks, “Who approved this?” We dig into AI governance through a CISSP lens, using real-world banking and credit union scenarios that show how fast things go sideways when AI tools slip outside your controls.We start with the uncomfortable reality behind modern AI adoption: vendors ship powerful models, teams connect third parties, and employees reach for whatever chatbot is quickest. From AI-powered lending platforms that promise speed and fairness, to shadow AI that starts with a simple copy paste of customer data, the common thread is the same. Policies are not protection unless you can detect, enforce, and prove what's happening with data, models, and vendors.Then we get practical. We walk through what examiners and auditors actually look for, why NIST AI RMF and existing third-party risk management rules are becoming the default playbook, and how to build evidence that holds up. Expect clear guidance on independent bias testing, explainability, contract language like right to audit and incident notification SLAs, and why model revalidation must be triggered by material change rather than an annual calendar cycle. We also tie the work back to CISSP domains and run practice questions designed to expose the “easy” answers that fail in real governance.If you're responsible for security, compliance, or risk, this is your roadmap for governing AI before it governs you. Subscribe, share with a teammate, and leave a review so more CISSP candidates and security leaders can find the show.Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

Coffee w/#The Freight Coach
1497. #TFCP - The AI Trojan Horse: Closing Logistics' Critical Data Voids!

Coffee w/#The Freight Coach

Play Episode Listen Later Jul 20, 2026 34:31


Are you blindly plugging AI tools into your freight operations without a second thought, or worse, letting shadow AI compromise your organization's most sensitive data? NMFTA's Director of Cybersecurity, Ben Wilkens, is back to give it to you straight about the wild west of AI in the transportation industry! We dive right into the critical differences between foundational AI models and everyday AI tools, the hidden risks of rapid large language model adoption, and why establishing a strict AI governance framework is now a matter of national security. The shift from zero to full AI integration has occurred almost overnight, and if you aren't actively protecting your digital footprint with proper guardrails, you're leaving your trucking company or brokerage vulnerable to bad actors and catastrophic data breaches.  We break down exactly how everyday professionals can utilize the NMFTA's free resources to build a secure tech infrastructure from the ground up, ensuring your data remains your ultimate currency.  Tune in for no-nonsense insights to protect your business, and don't forget to secure your spot at the upcoming NMFTA Cybersecurity Conference in Long Beach to stay ahead of the curve!  To access the 2026 NMFTA Cybersecurity AI Governance Framework, visit https://bit.ly/4wP09cq and complete the form.   About Ben Wilkens Ben Wilkens, CISSP, CCSP, CISM, is a Cybersecurity Principal Engineer at the National Motor Freight Traffic Association, Inc. (NMFTA)™. In his role at NMFTA, Ben spearheads research initiatives and leads teams dedicated to developing cutting-edge cybersecurity technologies, methodologies, and strategies to safeguard information systems and networks. He collaborates extensively with academic institutions, industry partners, and government agencies to advance cybersecurity practices and knowledge. Ben provides expert insights and recommendations to organizations, enhancing their security posture and helping them navigate the constantly evolving landscape of cyber threats. Before joining NMFTA, Ben was a key executive at a third-generation family-owned trucking and logistics company. There, he focused on the strategic integration of technology to improve operational efficiency while ensuring adherence to cybersecurity best practices. With a rare combination of CISSP, CCSP, and CISM certifications alongside an active Class A CDL, Ben brings a unique perspective to the intersection of cybersecurity and transportation. In addition to his extensive experience as an over-the-road driver, he has held roles in dispatch operations, driver management, and brokerage sales. Ben later transitioned to IT and operations support, where he honed his expertise in cybersecurity.  

CISSP Cyber Training Podcast - CISSP Training Program
CCT 362: Security Assessment Strategies & Abandoned Cloud Storage Risks (CISSP 6.1) - REPLAY

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later Jul 20, 2026 34:00 Transcription Available


Send us Fan MailThat forgotten cloud storage you stopped thinking about months ago can become a real attack path today. We start with a simple but dangerous scenario: abandoned AWS S3 buckets and other orphaned cloud storage that can be re-registered, repurposed, and used to serve malicious content to systems that still “trust” the old source. We walk through why this turns into a supply chain-style problem, what signals to look for, and the practical mitigations that matter most: proper decommissioning, continuous monitoring, tight access control, and disciplined cloud asset inventories.From there, we shift into CISSP Domain 6.1 and the real work of designing and validating assessment, test, and audit strategies. We explain how we approach building a security assessment and testing program from the ground up: clear objectives, tight scope, risk-based prioritisation, stakeholder alignment, and baselines grounded in frameworks like NIST CSF, ISO 27001, CIS Benchmarks, and NIST SP 800-53. The aim is simple: identify vulnerabilities, validate security controls, and turn findings into remediation that leadership can act on.We also break down core security testing methods you will see on the CISSP and in real organisations: vulnerability assessment, penetration testing (white box, black box, gray box), fuzz testing, SAST and DAST for application security, plus red team, blue team, and purple team collaboration. Finally, we demystify SOC 1 vs SOC 2 and Type 1 vs Type 2 reports, why they matter for third-party risk management, and how cyber resilience thinking (including the Cyber Resiliency Index) ties everything back to continuity and trust. If this helps, subscribe, share the show with a colleague studying CISSP, and leave a review with the topic you want next.Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

CISSP Cyber Training Podcast - CISSP Training Program
CCT 361: Bad Epoll - Root Access in 6 Instructions

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later Jul 13, 2026 32:20 Transcription Available


Send us Fan MailA six-instruction timing glitch in the Linux kernel can be the difference between “low-priv user” and full root control, and that is why we dig into the Bad EPoll vulnerability from a CISSP-ready, manager-first angle. We start by grounding what the Linux kernel EPoll subsystem does, why it is foundational to high-performance I/O, and why “just disable it” is not a real option when you're dealing with production Linux servers, desktops, cloud workloads, and Android devices.Then we unpack the security mechanics in clear terms: a use-after-free race condition, an impossibly thin race window, and the way memory corruption turns into privilege escalation. We also talk about what makes this case extra concerning, including the report that it can be triggered from inside Chrome's rendering sandbox. If you've ever relied on sandboxing, kernel boundaries, or “we run scanners” as your safety net, this story forces a more honest view of defense in depth.From there we connect the dots to CISSP Domain 8 software development security and real secure SDLC practice. We walk through where SAST, DAST, fuzzing, KASAN-style instrumentation, and AI-assisted code review help and where they fail, especially for concurrency bugs. The real takeaway is a layered detection strategy: automated testing plus manual secure code review for high-blast-radius code, support for external researchers through bug bounty programmes, and a patch management process that moves in days with verification and regression testing so incomplete fixes do not slip through.If this helps you think like a manager, subscribe, share the episode with a study buddy, and leave a review so more CISSP candidates can find it.Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

ITSPmagazine | Technology. Cybersecurity. Society
The Flood Made Everything Free. So Now We Pay for Proof. | Lens Four by Sean Martin | Read by TAPE9

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Jul 11, 2026 15:49


⬥EPISODE NOTES⬥ Tidal is about to stop paying royalties on any track it judges to be fully machine-made. Frame that as a music story and you miss the shift underneath it. By Deezer's own detection, roughly 75,000 AI-generated tracks now arrive every day, about 44% of everything uploaded, yet that same AI music is only 1 to 3 percent of what people actually play, and around 85% of those streams are flagged as fraudulent. The flood is not an audience. It is an attack on a shared payout. This edition follows one pattern across six industries: when the cost of generating something collapses toward zero, platforms stop paying for output and start paying for proof of human origin. Tidal cuts AI royalties. The Authors Guild sells a "Human Authored" badge for ten dollars a title. YouTube demonetizes "inauthentic" content. curl killed its bug bounty after a flood of AI slop, then reopened when the slop got good. And where no gatekeeper owns the payout, hiring, the open web, the scientific record, the flood just degrades the mechanism until no one trusts it. In this edition of Lens Four:

Redefining CyberSecurity
The Flood Made Everything Free. So Now We Pay for Proof. | Lens Four by Sean Martin | Read by TAPE9

Redefining CyberSecurity

Play Episode Listen Later Jul 11, 2026 15:49


⬥EPISODE NOTES⬥ Tidal is about to stop paying royalties on any track it judges to be fully machine-made. Frame that as a music story and you miss the shift underneath it. By Deezer's own detection, roughly 75,000 AI-generated tracks now arrive every day, about 44% of everything uploaded, yet that same AI music is only 1 to 3 percent of what people actually play, and around 85% of those streams are flagged as fraudulent. The flood is not an audience. It is an attack on a shared payout. This edition follows one pattern across six industries: when the cost of generating something collapses toward zero, platforms stop paying for output and start paying for proof of human origin. Tidal cuts AI royalties. The Authors Guild sells a "Human Authored" badge for ten dollars a title. YouTube demonetizes "inauthentic" content. curl killed its bug bounty after a flood of AI slop, then reopened when the slop got good. And where no gatekeeper owns the payout, hiring, the open web, the scientific record, the flood just degrades the mechanism until no one trusts it. In this edition of Lens Four:

All Things Internal Audit
Auditing the Auditors: Building Internal Audit at KPMG

All Things Internal Audit

Play Episode Listen Later Jul 7, 2026 21:07


The Institute of Internal Auditors Presents: All Things Internal Audit In this episode, Charles King sits down with Becky Mann to discuss what it takes to build and evolve an internal audit function inside a global firm. They share lessons from leading internal audit through disruption, how to structure teams around the business, and why auditors must move beyond rigid audit plans to deliver real value.  HOST: Charles King, CIA, CRMA, CISSP, CISA AI and Internal Audit Leader, KPMG  GUEST: Becky Mann, CIA Chief Audit Executive, KPMG   KEY POINTS: Introduction [00:00:00-00:00:44] Becky Mann's Internal Audit Background [00:00:44-00:02:06] Leading Internal Audit Through COVID-19 [00:02:06-00:03:18] KPMG's Internal Audit Function and Scope [00:03:18-00:05:35] Building Teams Around the Business [00:05:35-00:07:49] Learning to Pivot From the Audit Plan [00:07:49-00:09:21] Structuring Audit Portfolios [00:09:21-00:10:41] Rotations and Guest Auditor Programs [00:10:41-00:11:16] Onboarding Guest Auditors [00:11:16-00:13:55] Engaging the Board and Executive Stakeholders [00:13:55-00:16:36] Aligning Expectations and Avoiding Surprises [00:16:36-00:16:59] Why Internal Audit Still Matters [00:16:59-00:19:27] Choosing the Right Risk Response [00:19:27-00:20:31] Final Thoughts [00:20:31-00:20:54] IIA RELATED CONTENT:  Interested in this topic? Visit the links below for more resources: Global Internal Audit Standards Vision 2035 Communicating with the Board: Turning Audit Insights into Impact Three Lines Model   Visit The IIA's website or YouTube channel for related topics and more. Follow All Things Internal Audit: Apple Podcasts Spotify Libsyn Deezer

MSP Unplugged
Stop Getting Breached: Matt Lee Shares MSP Cybersecurity Strategies for Under $3M Shops

MSP Unplugged

Play Episode Listen Later Jul 6, 2026 40:21


CISSP Cyber Training Podcast - CISSP Training Program
CCT 360: SSA Whistleblower and the Thumb Drive: What CISSP Asset Security Tells Us About This Disaster

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later Jul 6, 2026 23:28 Transcription Available


Send us Fan MailImagine hearing a claim that the most sensitive identity data in the United States could be sitting on a personal thumb drive. That allegation is still unverified and under investigation, but it gives us a rare chance to see CISSP Domain 2 asset security in real time, with consequences that go far beyond a typical data breach.I walk through what's being reported about Social Security Administration data access and potential copying, then I put on the Domain 2 lens: data classification and handling requirements, who the true data owner is, what custodians should be enforcing, and how processors should be limited by scope, purpose, and time. We talk about why “high” impact data under FIPS 199 should automatically trigger stricter controls, and how failures in encryption, logging, and data loss prevention can let sensitive datasets slip outside organizational boundaries.We also dig into the part most teams get wrong: the data lifecycle. If you cannot execute secure disposal and verify it, you cannot “close Pandora's box.” Using NIST SP 800-88, we break down clear, purge, and destroy, connect it to real operational controls like removable media restrictions, and turn the whole story into practical exam guidance and CISO-level program lessons you can use with leadership.Subscribe for more CISSP-ready breakdowns, share this with someone studying Domain 2, and leave a review so more security pros can find the show. What is the first control you would fix in your own environment?Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

HealthcareNOW Radio - Insights and Discussion on Healthcare, Healthcare Information Technology and More

S3E9: Shadow AI, Quantum Risk, and CISO Burnout - The Threats Healthcare Isn't Ready For Host: Frank Cutitta Guest: Dave Bailey, EMBA, CISSP, Vice President of Consulting Solutions & Strategy at Clearwater Security To stream our Station live 24/7 visit www.HealthcareNOWRadio.com or ask your Smart Device to “….Play Healthcare NOW Radio”. Find all of our network podcasts on your favorite podcast platforms and be sure to subscribe and like us. Learn more at www.healthcarenowradio.com/listen

CISSP Cyber Training Podcast - CISSP Training Program
CCT 359: ShinyHunters vs. Oracle — Supply Chain Risk Every CISSP Must Know

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later Jun 29, 2026 43:08 Transcription Available


Send us Fan MailA vendor gets breached and suddenly your perimeter does not matter, because the attacker does not need to “hack” you. They just reuse the access you already approved. That's the core lesson behind the Shiny Hunters campaign targeting Oracle PeopleSoft servers at colleges and universities, where compromised access led to large-scale theft of student data and a messy, high-impact supply chain incident.We walk through what supply chain security really means for modern cybersecurity and for the CISSP exam: it's not only the software you buy, but also hardware vendors, cloud service providers, managed service providers, open source libraries, and contractors with privileged access. I break down the four supply chain attack vectors you need to know cold: compromised credentials and OAuth tokens, malicious code injection in CI/CD pipelines, open source package attacks like typosquatting and maintainer compromise, and hardware tampering. Along the way, we map the ideas to CISSP Domains 1, 3, 5, and 8 so you can answer questions like a manager, not just a technician.Then we go deeper on two concepts that keep showing up in both real breaches and exam questions. First, SBOM (Software Bill of Materials), the “nutrition label” that tells you exactly what's inside your software so you can respond fast when a new CVE hits. Second, OAuth token governance, where long-lived or overly broad tokens can become silent master keys if you do not scope, expire, inventory, revoke, and monitor them properly. We finish with three practice questions and the reasoning behind the best answers and the common distractors.If this helps, subscribe so you do not miss the next training, share the episode with a CISSP study partner, and leave a review to help more security pros find the show.Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

The New CISO
CISO 3.0: The Playbook for Delivering Impact and Influence

The New CISO

Play Episode Listen Later Jun 25, 2026 58:06


What separates a CISO who survives from one who shapes the boardroom? In this episode, Steve Moore sits down with Walt Powell, Lead Field CISO at CDW and author of The CISO 3.0, to unpack the modern CISO playbook—why technical credentials alone no longer cut it, how to build personal eminence, and why most security leaders are still treated as second-class C-suite citizens.Walt traces his path from teaching networking before stateful firewalls existed, to writing CISSP exam questions for ISC2, to running CDW's Global Security Strategy Office. He explains what a field CISO does, why the role is harder than ex-CISOs realize, and how one bad meeting can tarnish a brand built over decades.He and Steve break down the four pillars Walt uses to measure his team—embedded advisory, eminence building, sales enablement, and voice of the customer—and how a karate-style “belt system” maps each consultant's competency. Walt explains why the same skills matrix from The CISO 3.0 works for any CISO trying to spot their own gaps.Walt argues a CISO who is not liked cannot succeed: you are the talent magnet, the culture builder, and the person proving in every board meeting that you belong in the seat. He shares the questions every candidate should ask before accepting the role—from D&O coverage to 10-K disclosure access—and why the 30-60-90 plan should be written before the second interview, not after the offer.The conversation closes with what Walt calls “strategic debt”—the identity and data governance work organizations skipped a decade ago that is now blocking AI adoption. Walt shares lessons from running OpenClaw on a Mac mini, why non-human identity tops every 2026 CISO worry list, and how Deep Research is reshaping senior architects.Key Topics• The modern field CISO role and the four pillars of impact• Why CISOs are still treated as second-class C-suite citizens• Building personal eminence through books, speaking, and writing• The CISO 3.0 skills matrix and self-assessment spider wheel• Two paths to the CISO seat: technical vs. MBA, and the gaps each leaves• Why likability is not optional for a successful CISO• Board readiness and proving you belong in the seat• Interview questions every CISO candidate must ask• Strategic debt: identity and data governance blocking AI adoption• OpenClaw, non-human identity, and the future of senior architectsGuest Bio:Walt Powell is the Lead Field CISO at CDW and a founding member of CDW's Global Security Strategy Office, where he leads a team of former CISOs advising security leaders in the field. A longtime executive coach and ISC2 exam development committee member, Walt is the author of The CISO 3.0: A Guide to Next-Generation Cybersecurity Leadership and Quantum Ready, his book on post-quantum cryptography. Connect with Walt on LinkedIn or at ciso30.com.GET A DEMO:

Becker’s Healthcare Podcast
Maria Sexton, MBA, CISSP, CRISC, CDPSE, Senior Vice President and Chief Information Officer at University Health System

Becker’s Healthcare Podcast

Play Episode Listen Later Jun 24, 2026 28:40 Transcription Available


In this episode, Maria Sexton, MBA, CISSP, CRISC, CDPSE, Senior Vice President and Chief Information Officer at University Health System, joins the podcast to discuss the growing need to expand patient access and deliver more seamless healthcare experiences. She shares insights on emerging developments shaping the industry and explains how rapid experimentation and innovation are helping organizations adapt, improve operations, and better meet the needs of patients and care teams.

Becker’s Healthcare Digital Health + Health IT
Maria Sexton, MBA, CISSP, CRISC, CDPSE, Senior Vice President and Chief Information Officer at University Health System

Becker’s Healthcare Digital Health + Health IT

Play Episode Listen Later Jun 23, 2026 28:40 Transcription Available


In this episode, Maria Sexton, MBA, CISSP, CRISC, CDPSE, Senior Vice President and Chief Information Officer at University Health System, joins the podcast to discuss the growing need to expand patient access and deliver more seamless healthcare experiences. She shares insights on emerging developments shaping the industry and explains how rapid experimentation and innovation are helping organizations adapt, improve operations, and better meet the needs of patients and care teams.

CISSP Cyber Training Podcast - CISSP Training Program
CCT 358: EDR Bypass Ransomware: The Gentle Killer Threat Every CISSP Must Know

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later Jun 22, 2026 43:02 Transcription Available


Send us Fan MailYour endpoint tool can be world class and still get taken out first. That's the unsettling reality behind a new wave of “EDR killer” capabilities being packaged inside ransomware-as-a-service platforms, where affiliates can plug in advanced evasion without building it themselves. When attackers can blind endpoint detection and response before the ransomware payload runs, the old comfort of “we have EDR, so we're covered” turns into a single point of failure.We unpack the reporting on a highly active ransomware operation and its toolset, then zoom in on the technical path that makes this work: BYOVD, bring your own vulnerable driver. With admin access, attackers load a legitimate but vulnerable signed driver, escalate into kernel mode, and terminate security processes from below the privilege stack. From there, we shift to what matters for real security programs: defence in depth, kernel integrity protections like HVCI and KMCI, strict driver allow and block policies, and aggressive driver hygiene to reduce attack surface.Then we put on the CISSP lens. We tie the scenario to Domain 7 security operations (EDR limits, incident response, monitoring), Domain 3 security architecture and engineering (layered controls, hardening), and Domain 1 security and risk management (risk = threat × vulnerability × impact, plus threat landscape shifts). The big takeaway is simple: your job isn't to find the fanciest tool, it's to build a program that still works when one control fails and to communicate that risk clearly to leadership.If this helps you think like a manager and study smarter, subscribe for weekly CISSP-focused breakdowns, share the episode with a teammate, and leave a review so more people can find the show.Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

ITSPmagazine | Technology. Cybersecurity. Society
Call It What It Is: When Ransomware Becomes Terrorism | An Interview with Cynthia Kaiser | Redefining CyberSecurity With Sean Martin — On Location at InfoSecurity Europe 2026

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Jun 19, 2026 16:18


A ransomware crew can run through your whole company between dinner and dessert. Sean Martin sat down with Cynthia Kaiser — twenty years at the FBI, now leading the Halcyon Ransomware Research Center — on the speed of the threat, the human cost the industry keeps abstracting away, and why a slice of ransomware deserves a harder name than “crime.”

ITSPmagazine | Technology. Cybersecurity. Society
A Crime Against Time | An Interview with Rik Ferguson | Redefining CyberSecurity With Sean Martin — On Location at InfoSecurity Europe 2026

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Jun 15, 2026 14:54


PODCAST EPISODE | Redefining CyberSecurity With Sean Martin — On Location at InfoSecurity Europe 2026 On Location With Sean Martin And Marco Ciappelli Adversaries are stealing encrypted data today that they cannot read yet, and storing it until a quantum computer can. Sean Martin sat down with Forescout's Rik Ferguson to talk about “harvest now, decrypt later,” why Q-Day is closer than the comfortable timelines suggest, and what the decisions you make this year have to do with secrets you thought were safe forever.

CISSP Cyber Training Podcast - CISSP Training Program
CCT 357: Is Your Encrypted Data Already Stolen? Quantum Risk & Supply Chain Attacks for CISSP

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later Jun 15, 2026 32:09 Transcription Available


Send us Fan MailSomeone is stealing encrypted data right now and they are not trying to read it today. They are saving it for later, betting that quantum computing will eventually break the encryption that protects it. I dig into the “Harvest Now, Decrypt Later” strategy, why it matters most for long-term confidentiality, and how security leaders can talk about it as a present-day risk instead of science fiction.From there, I get practical with post-quantum planning: what the NIST post-quantum cryptography standards signal, why quantum key distribution is still niche for most organisations, and the big architectural idea to remember for the CISSP and for real enterprise security programs: crypto agility. We walk through concrete steps like building a cryptographic inventory, mapping where RSA and elliptic curve crypto live, identifying data with 10 to 20 year secrecy needs, and pushing vendors for a clear PQC roadmap.Then we pivot into CISSP Domain 1 supply chain risk management (SCRM and CSCRM). I explain why supply chains are a prime target, how modern supply chain attacks can ride in through poisoned open source packages, and what SolarWinds showed the world about scale and impact. We close with the nuts and bolts that actually reduce third-party risk: lifecycle supplier management, meaningful assessments (on-site when it matters), document and policy review, audits, and minimum security requirements baked into contracts and SLAs.If you want more training, check out CISSP Cyber Training, subscribe for weekly updates, share this with a friend who owns risk, and leave a quick review so more CISSP candidates can find the show.Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

ITSPmagazine | Technology. Cybersecurity. Society
When the Threat Moves Daily and the Law Moves in Years | An Interview with James Morris | Redefining CyberSecurity With Sean Martin — On Location at InfoSecurity Europe 2026

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Jun 13, 2026 17:14


PODCAST EPISODE | Redefining CyberSecurity With Sean Martin — On Location at InfoSecurity Europe 2026 On Location With Sean Martin And Marco Ciappelli The UK's threats change by the day. Its laws change over years. Sean Martin sat down with James Morris — former Member of Parliament, now Director of the CSBR — to ask how a government writes cyber policy fast enough to matter, and why “resilience” has quietly stopped being a technical word.

CISSP Cyber Training Podcast - CISSP Training Program
CCT 356: Supply Chain Attacks Are Exploding in 2026 — Here's What the NCSC Wants You to Do

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later Jun 8, 2026 41:38 Transcription Available


Send us Fan MailYour software is only as trustworthy as the dependencies you quietly inherit and attackers know it. Today I break down the NCSC warning on software supply chain security and why open source package ecosystems have become a high-value target for real-world compromises that spread fast through CI/CD pipelines.I walk through the attack patterns that keep showing up in incidents: maintainer account compromise, expired domain takeover, typosquatting, and credential chaining. We connect each technique to the CISSP mindset so you can spot it in scenario questions and, more importantly, recognise it in your own environment. Along the way, I explain why Node.js, Python, and Rust projects are especially exposed, how automation can turn “latest version” convenience into an enterprise incident, and why developer environments often become an overlooked attack surface.Then we get practical with controls you can actually implement: pausing automatic dependency updates when compromise is suspected, adding human approval for critical packages, rotating credentials immediately, enforcing MFA on developer and registry accounts, and using private or trusted registries to mirror and vet dependencies. I also zoom out to show how to build supply chain security into the secure SDLC with software composition analysis (SCA), code signing, checksum verification, audit logging, continuous monitoring, and an SBOM so you can respond fast when a package turns toxic.If this helps you tighten your dependency management and level up your CISSP prep, subscribe, share this with a teammate, and leave a quick review so more security pros can find the show.Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

CISSP Cyber Training Podcast - CISSP Training Program
CCT 355: Zapier Breach Lessons For Cloud Security and Setting Up TPRM Program in 15 Minutes

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later Jun 4, 2026 24:26 Transcription Available


Send us Fan MailThe breach that takes down a company often does not kick in the front door. It walks in through a “simple” integration you set up months ago, powered by a token no one remembered to rotate. We start with a real-world Zapier-style scenario and unpack how researchers chained together a harmless-looking code block, an AWS Lambda environment, and a misconfigured IAM role to reach private repository files and ultimately an NPM token that could enable a supply chain attack.From there, we zoom out to the bigger cloud security problem: non-human identities. Service accounts, API keys, and OAuth tokens multiply fast, and they are frequently overprivileged, poorly tracked, and left active long after an integration is retired. We also talk about why SaaS-to-SaaS connections are so hard to secure, and why agentic AI makes visibility even more urgent. If you do not know what systems are connected, what data crosses those links, and who owns the risk, you are effectively trusting an invisible tunnel into your environment.To make this actionable, we lay out a four-phase third-party risk management (TPRM) framework you can apply immediately: build a vendor and integration inventory with tiering, run real due diligence (SOC 2 Type II, ISO 27001, data access scope, subprocessors and fourth parties), lock protections into contracts (DPA language, right to audit, breach notification expectations), then enforce ongoing monitoring and governance with quarterly token reviews, logging, and incident response playbooks. If you are studying for the CISSP, you will also see exactly how this maps to Domain 1, Domain 3, Domain 4, and Domain 5.Subscribe for more practical CISSP training, share this with a teammate who owns vendor approvals, and leave a review so more security pros can find it. What is the one integration you would audit first?Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

CISSP Cyber Training Podcast - CISSP Training Program
CCT 354: Data Security Controls and Compliance Requirements for the CISSP (Domain 2.3) - REPLAY

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later Jun 1, 2026 37:28 Transcription Available


Send us Fan MailYour firewall can be patched tomorrow, but what about the place your system hides its real secrets today? We start with a timely warning about a serious Fortinet FortiGate vulnerability and why perimeter devices are still a make-or-break control, then we pivot into the deeper layer most people ignore until it's too late: memory.We walk through CISSP Domain 3.4 by focusing on what memory protection is actually trying to achieve: confidentiality, integrity, and process isolation. From there, we unpack how modern operating systems enforce separation with paging, segmentation, and strict read, write, execute controls. You'll hear why Meltdown and Spectre were such a big deal, how speculative execution can leak passwords and encryption keys from privileged memory, and why patching decisions are never just “apply everything” but a risk-based vulnerability management call that depends on visibility into what you run.Next, we connect memory protection to virtualization security. We break down hypervisors, guest and host isolation, Type 1 versus Type 2 designs, and the threats that keep security teams up at night: VM escape, side-channel leakage through shared CPU resources, and the operational hazards of memory overcommitment. Then we bring in hardware roots of trust through TPMs: secure boot, measured boot, key storage for full disk encryption, TPM 2.0 types, and how HSM-style key management shows up in cloud environments. We close with practical best practices, from firmware and microcode updates to choosing encryption controls that fit your actual risk.If you're studying for the CISSP or building a real-world security strategy, subscribe, share this with a teammate, and leave a review so more security pros can find it.Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

CISSP Cyber Training Podcast - CISSP Training Program
CCT 353: AI Agent Governance Essentials - CISSP Practice Questions

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later May 28, 2026 28:26 Transcription Available


Send us Fan MailAI agents are landing in production faster than most security teams can track them, and the scariest part is how normal they can look. When an autonomous agent runs the same workflow 10,000 times, your SIEM and EDR may see “nothing to worry about” even while the agent quietly drifts outside its intended scope. That is the core AI governance problem we tackle, through the lens of CISSP thinking and real security leadership.We walk through what is driving the mess: board-level pressure, AI FOMO, and the dangerous habit of treating AI agents like old-school automation. Then we get concrete. We talk about why many enterprises still lack an inventory of AI agents, why traditional security tooling is tuned for human behaviour anomalies, and what it actually takes to be audit-ready. We cover practical governance frameworks like tiered autonomy, why observability is more than collecting output logs, and how to design decision-path tracing with execution records and decision logs you can act on.To make it actionable for exam prep and day-to-day work, I close with CISSP-style practice questions on the exact scenarios you will face: detection gaps, human approval bottlenecks, least privilege for agents, proving decisions during audits, and architecting platforms that balance operational efficiency with risk management. If you are serious about passing, I also share how my CISSP Sprint cohort is structured to force momentum, including booking your exam date early.Subscribe for weekly CISSP-focused training, share this with a teammate building AI workflows, and leave a review so more security pros can find the show. What part of AI agent governance is your biggest blind spot right now?Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

Going North Podcast
Ep. 1085 – From Cartoon Character to Podcast Powerhouse with Christine Blosdale

Going North Podcast

Play Episode Listen Later May 22, 2026 38:16


“I'm not a writer, but you don't have to be a writer to create a really wonderful book.” – Christine Blosdale Today's featured international bestselling bookcaster is award-winning media personality and sought-after expert authority coach, Christine Blosdale. Christine and I had a fun on a bun chat about her books, conquering her imposter syndrome, the power of a small start, and more!!Key Things You'll Learn:What sparked Christine's early love for recording and broadcastingHow she helps clients overcome their fear of writingWhy it's easier than you think to produce an audiobookThree major lessons learned from starting, growing, and running her podcastsChristine's Site: https://www.christineblosdale.com/Christine's Books: https://www.amazon.com/stores/author/B088C19Y6K/allbooksChristine's Podcasts: https://www.christineblosdale.com/mypodcastsThe opening track is titled, “Unknown From M.E. | Sonic Adventure 2 ~ City Pop Remix” by Iridium Beats. To listen to and download the full track, click the following link. https://www.patreon.com/posts/sonic-adventure-136084016 Please support today's podcast to keep this content coming! CashApp: $DomBrightmonDonate on PayPal: @DBrightmonBuy Me a Coffee: https://www.buymeacoffee.com/dombrightmonGet Going North T-Shirts, Stickers, and More: https://www.teepublic.com/stores/dom-brightmonThe Going North Advancement Compass: https://a.co/d/bA9awotYou May Also Like…699 – “From His Brothers Basement to Hall of Fame Podcaster” with Dave Jackson (@DaveJackson): https://www.goingnorthpodcast.com/ep-699-from-his-brothers-basement-to-hall-of-fame-podcaster-with-dave-jackson-davejackson/583 – “How to Be the Face of Your Business” with Tonya Eberhart (@brandfacestar): https://www.goingnorthpodcast.com/ep-583-how-to-be-the-face-of-your-business-with-tonya-eberhart-brandfacestar/488.5 – “Create, Innovate & Dominate” with Tracy Hazzard (@hazzdesign): https://www.goingnorthpodcast.com/ep-4885-create-innovate-dominate-with-tracy-hazzard-hazzdesign/681 – “Make Someone's Moment Through Podcasting” with Kelly Smith: https://www.goingnorthpodcast.com/ep-681-make-someones-moment-through-podcasting-with-kelly-smith/232 – “Podcast Power” with Heneka Watkis-Porter (@TheEntrepYou): https://www.goingnorthpodcast.com/232-podcast-power-with-heneka-watkis-porter-theentrepyou/400 – “How to Become a Multimillionaire, but Not Act Like It” with Tom Antion (@TomAntion): https://www.goingnorthpodcast.com/ep-400-how-to-become-a/#Host2Host Bonus Ep. - “Innuendo City” with Michelle Nedelec (@michellenedelec): https://www.goingnorthpodcast.com/host2host-bonus-ep-innuendo-city-with-michelle-nedelec-michellenedelec/333 – “How to Grow Your Social Media Influence” with Catherine Saykaly-Stevens (@CatherineNetWeb): https://www.goingnorthpodcast.com/ep-333-how-to-grow-your-social-media-influence-with-catherine-saykaly-stevens-catherinenetweb/86 - "Stepping Into the Spotlight" with Tsufit (@Tsufit): https://www.goingnorthpodcast.com/86-stepping-into-the-spotlight-with-tsufit-tsufit/384 – “Steal Your Skills From Corporate” with Katrina Roddy (@KRoddy65): https://www.goingnorthpodcast.com/ep-384-steal-your/277 – “Entrepreneurs Rocket Fuel” with Kimberly Hobscheid (@EntrepreneursR4): https://www.goingnorthpodcast.com/277-entrepreneurs-rocket-fuel-with-kimberly-hobscheid-entrepreneursr4/348 – “Bring Inner Greatness Out” with Dr. Mansur Hasib, CISSP, PMP, CPHIMS (@mhasib): https://www.goingnorthpodcast.com/ep-348-bring-inner-greatness-out-with-dr-mansur-hasib-cissp-pmp-cphims-mhasib/387 – “How to Demolish Imposter Syndrome & Create an Online Course” with Mark Kumar (@mark2kumar): https://www.goingnorthpodcast.com/ep-387-how-to/

All Things Internal Audit
IT Controls Automation: Where Internal Audit Can Lead the Shift

All Things Internal Audit

Play Episode Listen Later May 20, 2026 20:35


The Institute of Internal Auditors Presents: All Things Internal Audit  In this episode, Mike Levy sits down with Reebu George to get practical about one of the most significant shifts underway in internal audit right now: the automation of IT controls. They talk through where this shift is happening, what use cases are proving their value, and how internal audit can lead the conversation rather than wait for the business to figure it out first.      HOST: Mike Levy, CIA, CRMA, CISSP CEO, Cherry Hill Advisory GUEST: Reebu George, CISSP, CISA, PMP Audit & Assurance Managing Director, IT Internal Audit Leader, Deloitte & Touche LLP   KEY POINTS: Introduction [00:00:02-00:00:47] The Shift Toward Continuous Auditing [00:00:47-00:02:26] How Automation Is Changing IT Controls [00:02:26-00:04:54] Building an Internal Audit Digital Strategy [00:05:39-00:07:09] Where Internal Audit Teams Should Start [00:07:09-00:09:33] Using AI and Automation in Audit Workflows [00:09:33-00:10:04] Earning a Seat at the Table [00:10:04-00:11:35] Developing Talent for Advisory Conversations [00:11:35-00:12:23] Rule-Based Controls and Automation Opportunities [00:12:23-00:13:45] Governance Risks in Automated Controls [00:13:45-00:15:39] Selling the Value of Automation [00:15:39-00:18:37] The Future of Continuous Assurance [00:18:37-00:19:49] Closing [00:19:52-00:20:23] IIA RELATED CONTENT:  Interested in this topic? Visit the links below for more resources: IT General Controls Certificate Program Knowledge Centers: Artificial Intelligence Global Internal Audit Standards Vision 2035   Visit The IIA's website or YouTube channel for related topics and more. Follow All Things Internal Audit: Apple Podcasts Spotify Libsyn Deezer  

The Cybersecurity Defenders Podcast
Does the rise of AI mean human-led SOCs are obsolete? With Dr. Adeel Shaikh Muhammad [#322]

The Cybersecurity Defenders Podcast

Play Episode Listen Later May 13, 2026 25:18


Dr. Adeel Shaikh Muhammad, a cybersecurity strategist and global speaker with over 16 years of experience across information security, networks, and systems. Adeel brings a practical perspective on how organizations can adapt to evolving cyber threats and the growing role of AI in cybersecurity. Adeel, with an extraordinary portfolio of 40+ industry certifications, including CISSP, CISM, CISA, CCISO, PMP, CEH, ISO 27001 Lead Implementer & Auditor, and a robust suite of advanced Cisco, Microsoft, Fortinet, Barracuda, ITIL, PRINCE2, and AI-related credentials, he is a benchmark of technical mastery and visionary execution. His academic excellence includes a Master's in Cybersecurity and a current Doctorate in Business Administration (DBA) focused on the impact of AI in Security Operations Centers (SOCs) in the Gulf region.Adeel is the author of two acclaimed books—“AI-Driven Transformation of Security Operations Center (SOC)” and “AI and Us: The Ethical Choices”—bridging the critical intersection of AI innovation and ethical leadership.Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at limacharlie.io

The Alien UFO Podcast
Reverse Engineering Crashed UFOs

The Alien UFO Podcast

Play Episode Listen Later May 12, 2026 10:59


This week I'm reading from Jon Majerowski's book 'Contact and Control: UFOs, DNA, and the Hidden War on Human Potential' THEY ARE NOT HIDING UFOs. THEY ARE HIDING WHAT CONTACT DOES TO YOU. Something is being managed. Not the craft, not the sightings, not the congressional hearings. Those are the distraction. What is being managed is the people who get too close. Experiencers are monitored, discredited, and studied without their knowledge or consent. The research never stopped. The public narrative just never changed. Jon Majerowski spent decades figuring out why. As a CISSP-certified cybersecurity expert trained to recognize patterns across complex systems, a Freemason with direct access to esoteric traditions most researchers never reach, and a lifelong UFO experiencer who has lived this from the inside, he came to the phenomenon from every angle at once. What he found was not a mystery. It was a machine. In Contact and Control, Majerowski maps the architecture of a control system that has been running for generations: Why UFO disclosure is controlled and what is deliberately kept back. The documented programs collecting DNA from experiencers without consent. How breakthrough technology gets suppressed and drip-fed through carefully selected frontmen. The thread of consciousness research running through military and intelligence channels. How ancient knowledge, Templar history, and occult tradition connect to all of it. This is not a book about lights in the sky. It is about who decided you were not allowed to know what those lights mean, and how they built the walls to make sure you never found out. For experiencers who were told they were crazy. For researchers who kept hitting the same walls. For anyone who has sensed the gap between the official story and lived reality. The control is real. So is the contact. This book maps both. Bio JON MAJEROWSKI is a husband, father, CISSP-certified information security professional, Freemason, and experiencer based in Maumee, Ohio. He hosts the UFOs on the Level podcast, where he conducts in-depth conversations with researchers, experiencers, insiders, and practitioners exploring UFOs, consciousness, and unexplained phenomena. As a member of several initiatory orders, Jon brings an insider perspective on esoteric traditions and mystery school knowledge to his investigation of the UFO phenomenon, or as he puts it, "The Phenomenon." His approach combines personal experience, decades of critical research, and a commitment to helping other experiencers feel less alone. Jon lives with his wife and daughters, balancing family life with consciousness exploration and disclosure activism. https://contactandcontrol.com/ https://www.amazon.com/dp/B0GTGPDMFM https://www.pastliveshypnosis.co.uk/ https://www.patreon.com/alienufopodcast https://simonbown.com/ My new book, Aspects of Alien Abduction https://www.amazon.com/dp/B0GRRPCT9Y Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Hybrid Identity Protection Podcast
Why Identity Security Needs Its Own Program with Angie Klein, IAM Business Technology Manager at Federated Insurance

Hybrid Identity Protection Podcast

Play Episode Listen Later May 12, 2026 38:05


This episode features Angie Klein, IAM Business Technology Manager at Federated Insurance.Angie brings over a decade of experience spanning systems development and identity security leadership, holding CISSP, CIDPRO, and CISM certifications and working hands-on with CyberArk, SailPoint IDN, and Active Directory in a regulated environment.In this episode, Angie dives into the organizational and cultural work that most identity programs skip. She shares why identity deserves its own program, how to apply OCM to bring resistant stakeholders on board, and why governance must come first. Angie's core argument is that if identity security creates too much friction, people will route around it, and that's where the real risk lives.This episode makes the case that the hardest part of identity security isn't the technology, it's getting people to trust it enough to stop working around it.Guest Bio As the IAM Business Technology Manager at Federated Insurance, Angie is dedicated to advancing our Identity and Access Management program and the industry as a whole. With over 10 years of experience and currently leading a team of Security Engineers and Identity and Access Analysts, Angie is passionate about IAM and love to see "ah ha" moments when colleagues understand that security is everyone's job.Angie bring over a decade of experience as a Systems Developer, providing extensive technical expertise in the Identity Security domain. I hold certifications, including CISSP, CIDPRO, and CISM. Additionally, she has experience working in the insurance industry and am skilled in CyberArk, Active Directory, SailPoint IDN, Analytical Skills, Project Management, and Public Speaking.Guest Quote "Identity security is ultimately about trust. People have to trust that you are doing the things that will help them do their job securely and not stop them from doing their job."Time stamps 01:45 Meet Angie Klein: Expert IAM Practitioner 01:22 Why Identity Needs Its Own Program 04:30 Why Identity Programs Stall 07:27 Organizational Change Management (OCM) Explained 12:51 OCM in Action 17:08 How to Gain Buy-In for an Identity Security Program 25:05 First Steps for Standing Up a Program 30:22 The Core Pillars of Identity Security 35:00 Conclusion and Final ThoughtsSponsor The HIP Podcast is brought to you by Semperis, the leader in identity-driven cyber resilience for the hybrid enterprise. Trusted by the world's leading businesses, Semperis protects critical Active Directory and Entra ID environments from cyberattacks, ensuring rapid recovery and business continuity when every second counts. Visit semperis.com to learn more.Links Connect with Angie on LinkedInConnect with Sean on LinkedInDon't miss future episodesLearn more about Semperis

The Alien UFO Podcast
UFO Contact & Control

The Alien UFO Podcast

Play Episode Listen Later May 11, 2026 60:43


This week I'm talking to Jon Majerowski about his book 'Contact and Control: UFOs, DNA, and the Hidden War on Human Potential' THEY ARE NOT HIDING UFOs. THEY ARE HIDING WHAT CONTACT DOES TO YOU. Something is being managed. Not the craft, not the sightings, not the congressional hearings. Those are the distraction. What is being managed is the people who get too close. Experiencers are monitored, discredited, and studied without their knowledge or consent. The research never stopped. The public narrative just never changed. Jon Majerowski spent decades figuring out why. As a CISSP-certified cybersecurity expert trained to recognize patterns across complex systems, a Freemason with direct access to esoteric traditions most researchers never reach, and a lifelong UFO experiencer who has lived this from the inside, he came to the phenomenon from every angle at once. What he found was not a mystery. It was a machine. In Contact and Control, Majerowski maps the architecture of a control system that has been running for generations: Why UFO disclosure is controlled and what is deliberately kept back. The documented programs collecting DNA from experiencers without consent. How breakthrough technology gets suppressed and drip-fed through carefully selected frontmen. The thread of consciousness research running through military and intelligence channels. How ancient knowledge, Templar history, and occult tradition connect to all of it. This is not a book about lights in the sky. It is about who decided you were not allowed to know what those lights mean, and how they built the walls to make sure you never found out. For experiencers who were told they were crazy. For researchers who kept hitting the same walls. For anyone who has sensed the gap between the official story and lived reality. The control is real. So is the contact. This book maps both. Bio JON MAJEROWSKI is a husband, father, CISSP-certified information security professional, Freemason, and experiencer based in Maumee, Ohio. He hosts the UFOs on the Level podcast, where he conducts in-depth conversations with researchers, experiencers, insiders, and practitioners exploring UFOs, consciousness, and unexplained phenomena. As a member of several initiatory orders, Jon brings an insider perspective on esoteric traditions and mystery school knowledge to his investigation of the UFO phenomenon, or as he puts it, "The Phenomenon." His approach combines personal experience, decades of critical research, and a commitment to helping other experiencers feel less alone. Jon lives with his wife and daughters, balancing family life with consciousness exploration and disclosure activism. https://contactandcontrol.com/ https://www.amazon.com/dp/B0GTGPDMFM https://www.pastliveshypnosis.co.uk/ https://www.patreon.com/alienufopodcast https://simonbown.com/ My new book, Aspects of Alien Abduction https://www.amazon.com/dp/B0GRRPCT9Y Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

UNSECURITY: Information Security Podcast
Unsecurity Episode 258: The CISSP Mentor Program with Brian Kelley

UNSECURITY: Information Security Podcast

Play Episode Listen Later Apr 20, 2026 30:49


In this episode of the Unsecurity Podcast, hosts Brad Nigh and Megan Larkins speak with Brian Kelley, information security consultant at FRSecure and one of the infamous CISSP Mentor Program's leads this year. Together, they talk about Brian's journey in information security and how it led him to helping support the FRSecure CISSP Mentor Program.Hear the trio discuss:Working in IT and finding interest in information securitySecurity focuses at MSPsPaying help forwardStudying tips and finding resourcesPicking your exam dateThe CISSP Mentor Program's format and evolutionWhile the program has already begun, you can still get all on-demand materials and join the rest of the live mentor sessions by signing up at https://learn.frsecure.com/courses/2026-cissp-mentor-program!Like, subscribe, and share with your network to stay informed about the latest in cyber and information security!We want to hear from you! Reach out at unsecurity@frsecure.com and follow us for more:LinkedIn: https://www.linkedin.com/company/frsecure/Instagram: https://www.instagram.com/frsecureofficial/Facebook: https://www.facebook.com/frsecure/BlueSky: https://bsky.app/profile/frsecure.bsky.socialAbout FRSecure:https://frsecure.com/FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can't do it alone. Whether you're wondering where to start or looking for a team of experts to collaborate with you, we are ready to serve.

Breaking Into Cybersecurity
Cybersecurity Career:Unlock your job path with Steve Regester | Breaking Into Cybersecurity

Breaking Into Cybersecurity

Play Episode Listen Later Apr 11, 2026 35:33


Dreaming of a high-demand, secure career that protects the digital world, but unsure where to start? This is your definitive guide to breaking into the thrilling field of cybersecurity, even with no prior experience! Industry expert Steve Regester reveals the exact roadmap you need to land your first cybersecurity job and build a resilient, rewarding future.In today's rapidly evolving digital landscape, the demand for skilled cybersecurity professionals is soaring. Cyber threats are more sophisticated than ever, making robust information security a critical concern for businesses worldwide. But how do you navigate this complex world and secure a lucrative role without an existing network or years of experience? Join us as Steve Regester, a seasoned veteran and renowned expert in the cybersecurity space, demystifies the entire process. He breaks down common barriers, offering actionable advice on everything from mastering foundational IT security skills to advanced strategies for career progression and how to get a cyber security job.This comprehensive guide is an invaluable resource for anyone aspiring to build a successful career in IT security. Whether you're a recent graduate looking for a clear career path, considering a significant career change into tech, or simply curious about the world of ethical hacking and digital defense, this video is your ultimate blueprint. Steve shares his invaluable insights on the diverse roles within cybersecurity, the most sought-after industry certifications like CompTIA Security+ or the highly respected CISSP, and crucial strategies for effective networking that will open doors.Discover how to craft a compelling cybersecurity resume, ace those challenging technical interviews, and position yourself as an indispensable asset in the global fight against cybercrime. Steve emphasizes practical tips and real-world scenarios, ensuring you understand not just 'what' to learn, but 'how' to apply it. We'll explore entry-level cybersecurity jobs, discuss potential cyber security salary expectations, and provide a clear framework for continuous learning in a field that constantly evolves. This isn't just about landing a job; it's about building a robust, future-proof cybersecurity career that truly matters. Empower yourself with the knowledge and confidence to make your cybersecurity career aspirations a reality. Don't miss out on these expert strategies from Steve Regester for breaking into cyber and securing your future in tech.Ready to embark on your cybersecurity journey? Like this video, subscribe to our channel for more expert insights into tech careers and information security, and hit the notification bell so you never miss an update on professional development! Share your questions and thoughts in the comments below – we love hearing from you!