POPULARITY
Categories
MONEY FM 89.3 - Prime Time with Howie Lim, Bernard Lim & Finance Presenter JP Ong
Jalan Besar is home to residents from all walks of life, from young families and working adults to seniors who have lived in the neighbourhood for decades. As communities become more diverse and fast-paced, creating meaningful opportunities for different generations to connect has become increasingly important. Through initiatives such as family carnivals, volunteer programmes and the Horizons @ Jalan Besar masterplan, the GRC is finding new ways to bring residents together. So how do you build a neighbourhood where people of all ages don't just live alongside one another, but genuinely connect? On The Agenda, Hongbin Jeong speaks with Shawn Loh, MP for Jalan Besar GRC, to find out more.See omnystudio.com/listener for privacy information.
We built what we are calling the Digital Village SDK which helps corporate web and app designers, parents and educators stay compliant with GRC laws, and create a safer on and offline experience for kids.FIND HER HERE:X and LinkedIn : LisaManns6AuthentiKid everywhere elsehttps:://www.authentikid.comOUR FIRST EPISODE 6/14/2024:https://youtu.be/aUufP8urOgk
All links and images can be found on CISO Series This week's episode is hosted by David Spark, producer of CISO Series, and Andy Ellis, principal of Duha. Joining them is Tim Callahan, CIO/CISO, AFLAC. In this episode: Week one is the wrong time to overreach Nobody has the AI playbook Vulnerability management wasn't built for this clock Stop blaming the human, fix the system A huge thanks to our sponsor, Vanta No, it's not your imagination. Risk and regulations ARE ramping up—and customers now expect proof of security just to do business. That's why Vanta is a game-changer. Vanta automates your compliance process and brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Companies like Ramp and Writer spend 82% less time on audits with Vanta. That's not just faster compliance—it's more time for growth. Get started at Vanta.com/CISO.
AI is transforming cybersecurity, but who is securing the AI? Organizations urgently need leaders to manage AI security, governance, and risk. In this episode of TechTalks, InfosecTrain breaks down why the ISACA Advanced in AI Security Management (AAISM) credential is fast becoming essential for modern security leaders.
Interpol's fraud sweep goes global China flags Claude Code Old GitHub accounts, new tricks Get the show notes here: https://cisoseries.com/cybersecurity-news-interpols-global-fraud-sweep-chinas-claude-code-flag-old-github-account-tricks/ Thanks to our episode sponsor, Vanta Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines.
Link to the episode This week's Department of Know is hosted by Rich Stroffolino, with guests Davi Ottenheimer, principal, Flying Penguin, and Chris Ray, field CTO, GigaOm. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. Huge thanks to our sponsor, Vanta Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines.
Mexico's first cyber test gets tested Snoops break into Roundcube mailservers Cash App owner pays up over lax security Get the show notes here: https://cisoseries.com/cybersecurity-news-mexicos-big-cyber-test-roundcube-mailserver-snooped-on-cash-app-found-lax/ Thanks to our episode sponsor, Vanta Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines.
The UK's Cyber Pledge and Cyber Shield Millions exposed in Japanese telco attack China looking to curb overseas model access Get the show notes here: Thanks to our episode sponsor, Vanta Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines.
AI Governance Is No Longer Optional for CISOs. As artificial intelligence becomes deeply embedded in business operations, automated decision-making, and enterprise risk management, today's security leaders face a new challenge - not just securing data, but governing algorithmic models responsibly. In this episode of InfosecTrain TechTalks: Real World Decoded, host Payal Pawar sits down with Gaurav Sinha, a leading AI Governance and Cybersecurity Consultant, to explore how security executives can move beyond compliance checklists and build operational frameworks using global standards.The "course titled" ISO 42001 Lead Implementer Training serves as an indispensable blueprint for teams trying to draw clear boundaries between traditional IT security and algorithmic risk. While legacy frameworks excel at data confidentiality, they struggle with the fluid, non-deterministic behaviors unique to machine learning pipelines. We map out how to build dedicated AI risk registers, align controls with standard information security management systems, and translate technical AI vulnerabilities into business risk narratives that ensure courtroom and boardroom readiness.
Suspected China-Nexus hackers use fake Indian tax filing utility to deploy DcRAT Prompt injection attacks trick AI Agents into making crypto payments France to stop certifying products without quantum-safe encryption Get the show notes here: https://cisoseries.com/cybersecurity-news-india-tax-rat-prompt-injection-crypto-scam-france-pushes-quantum-safe/ Thanks to our episode sponsor, Vanta Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines.
JadePuffer ransomware used AI agent to automate entire attack AdaptHealth suffers cyberattack UK's National Cyber Action Plan launch delayed by political leadership crisis Get the show notes here: https://cisoseries.com/cybersecurity-news-first-ai-ransomware-adapthealth-suffers-cyberattack-uk-cyber-plan-delayed/ Thanks to our episode sponsor, Vanta Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines.
AI success isn't just about innovation - it's about governance, accountability, and trust. As enterprises rapidly transition from testing machine learning models to deploying them across live production environments, unstructured experimentation must give way to a rigorous framework. In this foundational masterclass, InfosecTrain provides a step-by-step strategic roadmap for constructing an enterprise-grade Artificial Intelligence Management System (AIMS).The "course titled" ISO/IEC 42001:2023 Lead Auditor Training is an essential asset for professionals who want to lead these governance architectures. We pull back the curtain on how to systematically translate abstract ethical standards into concrete operational baselines. Learn how to navigate the core clauses of the international standard, establish solid accountability lines across data science teams, and build a scalable compliance program that protects your enterprise from model risk while accelerating business growth.
Stop chasing certifications without direction. If you're trying to break into cybersecurity or grow into a leadership role, this is the real career map. In this video, I walk you through the 5 most in-demand cybersecurity career paths - from hacker to identity, cloud, GRC, and CISO. I've worked in all of them over the last 20 years, and I'm giving you the no-BS truth on what each role really looks like, what hiring managers want in 2025, and what it actually takes to succeed.What we'll cover in this video: what penetration testing really is (Hint: it's not just hacking), why IAM (Identity & Access Management) is exploding in demand, the real-world impact (and pressure) of cloud security leadership, how GRC & privacy are fast tracks to C-suite for legal/finance folks, what it actually takes to become a successful CISO, and the truth nobody tells you: It's not where you start—it's how you grow.This isn't another generic “top 5 jobs” list. This is real experience, real insights, and a real roadmap for building a cybersecurity career that actually leads to leadership.Looking to go from chaos and unpredictability to resilience in the world of AI? Start here with The Predictability Factor newsletter at The Monica Talks Cyber (https://www.monicatalkscyber.com).
The risks keeping CFOs up at night aren't new. But the way they connect, accelerate, and amplify each other is. In the final episode of their three-part GRC series, Embark's Adam Olsen and Managing Director Allison Bradshaw break down the risk landscape organizations are navigating right now, and what it actually takes to get ahead of it.In this episode:AI governance frameworks: how to build tiered oversight proportional to risk, from chatbots to credit decisions, without slowing down adoptionThe "black box" problem: why explainability and transparency are now regulatory expectations, not just best practicesCybersecurity as enterprise risk: how to reframe board conversations around cyber exposure and what ransomware preparedness actually requiresIdentity, access, and the human element: why phishing remains the most common attack vector and what effective security culture looks like beyond annual trainingData privacy in a fragmented regulatory environment: GDPR, CCPA, and the state-by-state patchwork, plus why privacy and cybersecurity programs are stronger when built togetherThird-party and vendor risk: how to apply a risk-based approach across a complex vendor ecosystem, including fourth-party exposure and ESG considerations in the supply chainThe regulatory change problem: AI regulation, SEC cyber disclosure rules, ESG reporting requirements, and how to build compliance capabilities that don't start from scratch every timeWhy integrated risk management isn't optional: how AI, cyber, privacy, and regulatory risks connect in ways siloed functions will always missTo connect with Allison or learn more about how Embark approaches GRC, visit embarkwithus.com.
Checking compliance boxes isn't enough - real AI risk management starts where compliance ends. As enterprises rapidly scale artificial intelligence across production pipelines, traditional IT risk management models are hitting their absolute limits. In this forward-looking masterclass episode, InfosecTrain contrasts conventional risk frameworks against the unpredictable, non-deterministic realities of machine learning systems.The "course titled" AI Governance and Risk Management Training serves as an indispensable roadmap for modern defenders facing this evolution. We step away from static software asset checklists to analyze live threat vectors like data poisoning, model degradation, and complex prompt injections. Discover how to build a resilient, multi-layered risk program from scratch, map out accountability boundaries, and align your enterprise defense directly with practical frameworks like the NIST AI Risk Management Framework (RMF).
In Episode 107 of the Cybersecurity Readiness Podcast Series, Dr. Dave Chatterjee is joined by Richa Kaul, Founder and Chief Executive Officer of Complyance and a former public sector technology policy leader, to address one of the most consequential misunderstandings in enterprise security governance: the assumption that compliance equals security.Opening with two recent and high-profile incidents — the May 2025 ransomware attack on Marks & Spencer, which halted online operations for weeks and generated estimated losses exceeding £300 million, and a concurrent third-party support provider compromise that exposed customer data across multiple platforms including Discord — Dr. Chatterjee establishes the episode's central premise: organizations that invest heavily in GRC platforms, generate dashboards full of green indicators, and maintain formal compliance certifications can still be catastrophically breached. The gap between compliance and security is not theoretical. It is structural and where attackers operate.Kaul explains the root cause with precision. Traditional GRC tools were built to centralize data and automate workflow notifications — functions that reduce administrative burden but do not reduce risk. The result is a compliance theater dynamic in which organizations check boxes, pass periodic audits, and receive certifications that say little about their actual security posture. The Complyance platform is built on a different philosophy: compliance with standards should be a byproduct of genuinely good security practices, not the objective in its own right.The episode explores the architecture of intelligent GRC: continuous monitoring across all integrated sources of truth, agentic AI that automates evidence collection and remediation guidance, tiered third-party risk programs that apply scrutiny proportional to vendor criticality, and risk quantification frameworks that translate security signals into board-level governance decisions. Kaul is equally precise about what GRC platforms cannot do: they cannot substitute for operational security teams, and no platform — however sophisticated — can protect an organization whose leadership has not committed to genuine risk reduction as the governing objective.Analyzed through Dr. Chatterjee's Commitment–Preparedness–Discipline (CPD) framework, the conversation reframes GRC from a compliance function into a governance discipline. The episode's central message is neither technical nor vendor-specific: the organizations that will withstand the next breach are not those with the most compliance certifications — they are those that have claimed ownership of the problem, built the continuous processes to address it, and institutionalized the discipline to keep those processes operating after the audit is over.To access and download the entire podcast summary with discussion highlights - https://www.dchatte.com/episode-107-compliant-but-exposed-rethinking-grc-for-real-security/Connect with Host Dr. Dave ChatterjeeLinkedIn: https://www.linkedin.com/in/dchatte/ Website: https://dchatte.com/Books PublishedThe DeepFake ConspiracyCybersecurity Readiness: A Holistic and High-Performance ApproachArticles & Cases PublishedChatterjee, D. (2026). Root: Automating the Remediation Gap, Ivey Publishing, Jan 7, 2026.Ramasastry, C. and Chatterjee, D. (2025). Trusona: Recruiting For The Hacker Mindset, Ivey Publishing, Oct 3, 2025.Chatterjee, D. and Leslie, A. (2024). “Ignorance is not bliss: A human-centered whole-of-enterprise approach to cybersecurity preparedness,” Business Horizons, Accepted on Oct 29, 2024.Isik, O., Chatterjee, D., and Lourenco, D.A. (2024). “Getting Cybersecurity Right,” California Management Review — Insights, Accepted for Publication, July 8, 2024. Chatterjee, D. (2023). “Mission critical – How American Cancer Society successfully and securely migrated to the cloud amid the pandemic,” I by IMD, March 13, 2023.Chatterjee, D. (2022). “Preventing security breaches must start at the top,” I by IMD, September 28, 2022, Institute for Management Development, Lausanne, SwitzerlandChatterjee, D. (2022). “Making Cybersecurity Readiness Mainstream,” Executive Blog Post, NETSPI, March 1, 2022Benz, M. and Chatterjee, D. (2020). “Calculated Risk? A Cybersecurity Evaluation Tool for SMEs,” Business Horizons, available online from May 4, 2020Chatterjee, D. (2019). “Should Executives Go To Jail Over Cyber Attacks,” Journal of Organizational Computing and Electronic Commerce, Vol 29, Issue 1, pp. 1-3.Abraham, C., Chatterjee, D., and Sims, R. (2019). “Muddling through cybersecurity: Insights from the U.S. healthcare industry,” Business Horizons, July 2019.
This episode features Jim Bowie, VP and CISO at Tampa General Hospital, joined by co-host Courtney Guss, Director of Crisis Management at Semperis.Jim began his career in EMS and law enforcement before moving into cybersecurity, giving him a grounded understanding of how operational continuity and human outcomes intersect during a crisis. At Tampa General, he leads teams spanning network security, operations, IAM, and GRC, and has built a training culture centered on adversarial simulation, monthly range of exercises, and regular DR drills.In this episode, Jim argues that rehearsal is the highest-leverage move for resource-constrained security teams and explains why an outage is an outage regardless of cause. He covers why identity is consistently the weak point in every simulation and why the relationships you build before an incident are the ones that matter most.If your organization is still treating recovery as an afterthought, this episode will change how you think about it.Guest BiosJim Bowie Jim Bowie is the Vice President and Chief Information Security Officer (CISO) at Tampa General Hospital (TGH). Jim is an accomplished leader with decades of cybersecurity experience and leadership in threat hunting, incident response, threat intelligence, and security operations. He is a strategist with demonstrated ability to bridge between security, infrastructure, and business needs and has experience leading multiple areas in information technology, including cloud infrastructure and security, with exceptional results in employee engagement and productivity.Courtney Guss Courtney Guss is the Director of Crisis Management at Semperis, with over 20 years of experience spanning cybersecurity, risk management, and crisis response. She specializes in helping organizations navigate high-impact incidents—from ransomware attacks to regulatory reporting—by orchestrating clear, business-aligned response strategies. Courtney is passionate about transforming crisis chaos into operational clarity.Guest Quote "You absolutely need a technology component to your program. But at the end of the day, that tech is surfaced to a person in the chair. And if that person's not up to speed, there's no amount of tech that's going to help them and help you get through a crisis."Time stamps 01:45 Meet Jim Bowie: Veteran Cybersecurity Leader 02:38 Healthcare Crisis Management Challenges 04:18 Training Beats Budget 06:46 Clinician Buy-In 07:00 Community Ripple Effects 10:23 Mutual Aid Agreements 12:45 Hurricane Drills as Cyber Drills 14:39 Adversarial Practice Culture 17:30 Making Training Time Non-Negotiable 20:14 Recovery Focus and Identity 26:35 Conclusion and Final ThoughtsSponsor The HIP Podcast is brought to you by Semperis, the leader in identity-driven cyber resilience for the hybrid enterprise. Trusted by the world's leading businesses, Semperis protects critical Active Directory and Entra ID environments from cyberattacks, ensuring rapid recovery and business continuity when every second counts. Visit semperis.com to learn more.LinksConnect with Jim on LinkedInConnect with Courtney on LinkedInConnect with Sean on LinkedInDon't miss future episodesLearn more about Semperis
Podcast: PrOTect It All (LS 27 · TOP 10% what is this?)Episode: Cybersecurity vs Resilience: What Business Leaders Need to Know About Managing RiskPub date: 2026-06-15Get Podcast Transcript →powered by Listen411 - fast audio-to-text and summarization Cybersecurity isn't the goal. Business resilience is. In this episode of Protect It All, host Aaron Crow sits down with Lee Ward to explore why organizations need to move beyond compliance checklists and start focusing on what really matters: the ability to withstand, recover from, and adapt to disruption. Drawing on more than two decades of experience spanning the UK civil service, logistics, supply chain operations, and governance, risk, and compliance (GRC), Lee shares practical insights on helping boards and executives understand cyber risk in business terms. Together, Aaron and Lee discuss the realities of risk acceptance, operational technology challenges, patching constraints, and why resilience not perfection should be the ultimate objective of any cybersecurity program. You'll learn: Why resilience is a better business objective than security alone How to communicate cyber risk to boards and executive leadership The difference between compliance and meaningful risk reduction Practical approaches to OT security, patching, and operational constraints Why risk acceptance is a critical leadership responsibility How logistics and supply chain organizations approach resilience planning Whether you're a security leader, executive, risk manager, or OT practitioner, this episode provides practical guidance for building organizations that can continue operating when disruptions inevitably occur. Tune in to learn why resilience not just security is becoming the defining metric of successful organizations. Key Moments: 03:59 Understanding Cyber Risks for Leaders 07:16 Discussing non-cyber risks to services 11:12 Understanding business impact of cyber risk 15:45 Evaluating Cybersecurity Risks 19:37 Understanding installation complexities 21:15 Global risks affecting business resilience 24:27 Discussing regulation impacts on business 29:30 People's drive to make good choices 31:27 Industrial control systems demo at DEFCON 34:43 Limitations of technical security 38:06 The future of AI and education About the guest : Lee Ward is a Governance, Risk Management, and Compliance (GRC) leader with more than 20 years of experience spanning the UK civil service, logistics, supply chain operations, and cybersecurity. Specializing in business resilience, risk governance, and operational technology security, Lee helps organizations translate complex cyber risks into meaningful business decisions. He is passionate about moving beyond compliance-driven security programs and helping leaders build resilient organizations that can adapt, recover, and thrive in an increasingly uncertain world. How to connect Lee: https://www.linkedin.com/in/lee-ward-882a54244/ Learn more about PrOTect IT All: Email: info@protectitall.co Website: https://protectitallpod.com/ep110 X: https://twitter.com/protectitall YouTube: https://www.youtube.com/@PrOTectITAll FaceBook: https://facebook.com/protectitallpodcast To be a guest or suggest a guest/episode, please email us at info@protectitall.co Please leave us a review on Apple/Spotify Podcasts: Apple - https://podcasts.apple.com/us/podcast/protect-it-all/id1727211124 Spotify - https://open.spotify.com/show/1Vvi0euj3rE8xObK0yvYi4 The podcast and artwork embedded on this page are from Aaron Crow, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.
Send us Fan MailWhat if I told you that one weak password, one phishing email, or one hacked server could disrupt an entire business, hospital, bank, or government system?In today's digital world, cyber threats are everywhere.And standing between those threats and our digital lives are professionals known as Cybersecurity Specialists. In this episode of The Kapeel Gupta Career PodShow, we explore one of the fastest-growing, highest-demand, and future-proof careers in technology.If you enjoy:
Today, we're diving deep into the world of quantum computing and its far-reaching implications for cybersecurity, risk, and digital resilience. Join Frank La Vigne and Candace Gillhoolley as they sit down with Chris Basener, a leading GRC advisor specializing in post-quantum cryptography. Together, they unravel the challenges organizations face in preparing for the inevitable arrival of quantum computers powerful enough to threaten today's encryption, discuss the realities and misconceptions surrounding post-quantum cryptography, and explore practical strategies for building long-term digital resilience.We'll explore the urgent need for cryptographic agility, the complexities of migrating to new standards, and why every organization—from banks to manufacturers—must start planning now, despite the uncertainty around when quantum threats will fully materialize. Plus, Chris Basener shares insights on talent shortages, project management for quantum readiness, and how companies can move from awareness to action. If you're curious about the intersection of quantum technology, cybersecurity, and strategic risk management, you won't want to miss this conversation!LinksChris' LinkedIn profile - https://www.linkedin.com/in/chris-basener/Time Stamps00:00 Quantum computing and cryptography risks04:04 Understanding Mosca's Theorem Basics08:02 Quantum computing in finance12:10 Concerns about quantum cryptography adoption15:58 Importance of Strategic Planning19:30 Challenges of Early Adoption23:01 Building cyber resilience with agility26:55 Challenges in Manufacturing Security28:31 Importance of national security31:49 Future risks of data security35:30 Discussing hybrid algorithm security41:15 Discussing cybersecurity frameworks43:11 Securing funding through governance48:47 Creating a post-quantum cryptography course50:04 Post quantum cryptography course53:42 Connecting on LinkedIn for courses
Chinese cybercrime group sets record pace Cisco warns of critical Unified CM flaw with PoC exploit code Hackers spied on a stock exchange executive's Outlook mailbox for five months Get the show notes here: https://cisoseries.com/cybersecurity-news-chinese-cybercrime-group-cisco-cm-flaw-cisa-faces-changes/ Huge thanks to our episode sponsor, Vanta Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta [rhymes with Santa] Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines.
This week's Department of Know is hosted by Rich Stroffolino, with guests Robb Dunewood, host, Daily Tech News Show, and David Cross, CISO, Atlassian. Get the show notes here. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines.
Law enforcement cracks down on illegal streamers The European Commission releases digital sovereignty plan The startup costs for US cyber force Get the show notes here: https://cisoseries.com/cybersecurity-news-illegal-streamers-eu-digital-sovereignty-cost-of-a-cyber-force/ Huge thanks to our episode sponsor, Vanta Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta [rhymes with Santa] Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines.
Russia claims officials' surveillance Project Glasswing access expands CISA flags two-year-old Oracle flaw Get the show notes here: https://cisoseries.com/cybersecurity-news-russia-claims-officials-surveillance-project-glasswing-expands-cisa-flags-two-year-old-oracle-flaw/ Huge thanks to our episode sponsor, Vanta Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta [rhymes with Santa] Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines.
Meta AI hands over Instagram account access Dutch police dismantle huge botnet RedHat packages get backdoored Get the show notes here: https://cisoseries.com/meta-ai-hands-over-instagram-access-dutch-police-dismantle-botnet-redhat-packages-backdoored/ Huge thanks to our episode sponsor, Vanta Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta [rhymes with Santa] Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines.
Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks ChatGPT share links used to host fake outage pages to deliver malware Federal audit reveals NIST's NVD problems Get the show notes here: https://cisoseries.com/cybersecurity-news-globalprotect-vpn-exploited-chatgpt-share-links-exploits-feds-criticize-nist/ Huge thanks to our episode sponsor, Vanta Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta [rhymes with Santa] Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines.
Send us Fan MailIn this episode of the B2B Go-To-Market Leaders Podcast, Vijay Damojipurapu sits down with PV Bóccasam, advisor to private equity firms and veteran operator across enterprise software, venture-backed startups, and category-defining companies, to explore a radically different way of thinking about go-to-market.PV argues that go-to-market is not about sales motions, pipeline generation, or even positioning frameworks—it's about one thing: reducing buyer anxiety and lowering the perceived risk of change.Drawing from decades of experience building and scaling enterprise software companies across identity governance, GRC, enterprise risk management, and private equity-backed transformations, PV shares how the best GTM leaders think less about “selling” and more about helping customers justify, adopt, and communicate measurable value internally.They dive into:Why GTM should focus on reducing customer risk, not maximizing seller activity.The difference between customer convictions and customer incentives—and why both matter.Why measurable proof is the only reliable way to break buyer inertia.How enterprise software companies should rethink value delivery in the AI era.Why AI should reduce operational uncertainty—not create more chaos.The evolution from product-led to sales-led to partner-led GTM motions.Why “platform” messaging fails for most enterprise SaaS companies.How modern AI-native SaaS products are becoming systems of orchestration, not systems of record.The importance of helping customers retell your value proposition internally.Why enterprise GTM leaders must become the clearest thinkers during periods of uncertainty.How private equity firms should approach AI adoption through organizational redesign, not just cost-cutting.And why long-term impact matters more than short-term velocity in building a career and a company.PV's central insight is simple but powerful:Customers don't buy software—they buy reduced uncertainty, measurable outcomes, and confidence in the future state.This episode is a deep philosophical and operational masterclass on enterprise go-to-market strategy, AI adoption, organizational design, and what it truly means to build trust at scale.Connect with Vijay Damojipurapu on LinkedInConnect with PV Boccasam on LinkedInBrought to you by: stratyve.com
Innovation spans many areas, and compliance professionals need not only to be ready for it but also to embrace it. Join Tom Fox, the Voice of Compliance, as he visits with top innovative minds, thinkers, and creators in the award-winning Innovation in Compliance podcast. In this episode, host Tom visits with Noor Aziz, a Saudi Arabia–based governance, risk, and compliance professional with extensive ISO lead auditor credentials, internal audit and controls experience, and a growing focus on AI governance. Noor argues that effective compliance must be practical and business-friendly—clear ownership, escalation, accountability, and evidence—so it still functions under operational pressure rather than becoming bypassed. She emphasizes leadership commitment, culture shaped by observed behavior, and integrated GRC to reduce silos that create duplication, inconsistent reporting, and “governance fatigue.” On AI, she frames governance as a board-level issue because adoption is outpacing accountability, creating future scrutiny around oversight, traceability, and defensibility; she notes, “capability without governance eventually creates instability.” She recommends change management, micro-learning, and ongoing communications, and concludes that governance is organizational infrastructure, not administrative overhead. Key highlights: Integrating Controls, Audit, and Risk Breaking Down GRC Silos Why AI Governance Is Board Level Culture When Nobody's Watching Training That Actually Works: Microlearning and Ongoing Comms Why Frameworks Fail in Execution Maturing Governance for Business Value Resources: Connect with Noor Aziz on LinkedIn Innovation in Compliance was recently ranked Number 4 in Risk Management by 1,000,000 Podcasts.
All links and images can be found on CISO Series This week's CISO Series Podcast features David Spark, producer of CISO Series, and Andy Ellis, principal of Duha. Joining us is our sponsored guest, Jadee Hanson, CISO, Vanta. In this episode: The compliance receipt nobody reads Who signs off on the AI that wrote the code The agent that wouldn't stop The questionnaire that should not exist A huge thanks to our sponsor, Vanta Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.
In this episode, we sat down with Richa Gual, CEO of Complyance, the AI-first enterprise GRC platform that recently raised a $20M Series A led by GV (Google Ventures), to dig into how legacy GRC is finally being disrupted and what role AI agents play in that transformation.We discussed why GRC has lived in the dark ages for so long, stuck in static documents, snapshot-in-time assessments, system sampling, and self-attestations while the rest of IT moved to cloud, APIs, and automation. We unpacked the credibility crisis caused by commoditized compliance and rubber-stamp audits, the limits of the first wave of GRC automation, and what genuinely changes when agentic AI takes on evidence review, vendor risk, policy drafting, and customer trust workflows end-to-end.Richa shared Complyance's perspective on building agentic AI for the most sensitive data an organization holds, why explainability and isolation matter more in GRC than almost anywhere else, and how customers like Dropbox, CVS Health, and Major League Soccer are using AI agents to cut manual GRC work by 70% without lowering the assurance bar. We closed on what the next five years look like for the GRC workforce and whether the field can finally restore credibility to the phrase “compliance equals security.”
In this episode, Chris Johnson sits down with Eric Shoemaker of Genius GRC to unpack one of the most misunderstood shifts in the MSP space: the move from tool-driven cybersecurity to standards-aligned governance, risk, and compliance programs.Eric explains why Genius GRC isn't a software platform and why that distinction matters. Together, they explore how early automation wins (like continuous access reconciliations) impressed auditors but didn't replace the need for real governance, documented reviews, and independent judgment. As the market matures, the conversation turns to a growing risk: MSPs and SMBs stacking new security tools while core systems remain misconfigured and under-governed.Chris and Eric tackle the myth of “do-it-yourself” GRC, the dangers of vibe-based compliance, and why tools only amplify expertise; they don't replace it. They also dig into the critical separation between IT operations and security leadership, making the case for advisory or independent CISO models that reduce conflicts of interest and improve risk outcomes.The discussion closes with practical, budget-conscious fundamentals, such as DNS filtering, CIS IG1, and free or low-cost controls that actually move the needle, plus hard truths about negligence versus resourcing failures and why resilience must be budgeted from day one.If you're an MSP, consultant, or business leader navigating cybersecurity maturity, this episode is a grounded, no-hype look at what actually reduces risk.
Welcome to RIMScast. Your host is Justin Smulison, Business Content Manager at RIMS, the Risk and Insurance Management Society. In this episode, Justin interviews Jennifer McNelly, CEO of the American Society of Safety Professionals, about her wide-ranging safety career, the ASSP publishing the first U.S.-Based standard on risk assessment and management, the ASSP's Standards-Based User Groups, and how safety practices are not about worker behavior but overall organization system safety improvement. Jennifer shares her excitement about National Safety Month and the upcoming Safety Conference + Expo 2026, from June 15th through 17th in Anaheim, California. Listen for inspiration on closing the safety gap in your organization. Key Takeaways: [:01] About RIMS and RIMScast. [:16] About this episode of RIMScast. We are releasing this episode ahead of National Safety Month in June, and our special guest is Jennifer McNelly, the CEO of the American Society of Safety Professionals, but first… [:43] RIMS Virtual Workshops. The next RIMS-CRMP Exam Prep will be held on June 9th and 10th. The next RIMS-CRMP-FED Exam Prep with AFERM will be held on June 16th and 17th. Links to registration are in this episode's notes. [:58] Webinars. On May 21st, GRC returns to present "Is Your Fire Protection Strategy Outdated? Emerging Risks Are Changing the Rules." [1:10] On May 28th, Zurich returns with "From Underwriting To Risk Management: What To Expect From The Growing Demand For Data Center Construction." Register for webinars at RIMS.org/Webinars or through the links in this episode's show notes. [1:25] Folks, RIMS is back on YouTube. Our handle is @RIMSOfficialChannel. We've got plenty of videos there, including RIMScast, RIMScast Canada video podcasts, and other informative and entertaining content from RIMS. Subscribe to the channel today! [1:43] If you plan to submit a session for the RIMS Canada Conference 2026, today, the air date May 19th, is your last day to do so. Visit RIMS Canada to submit your session. We hope to see you in Quebec City, October 18th through the 21st. [2:02] On with the Show! June is approaching, and that means National Safety Month. That is also observed in several parts of the world. Who better to speak about safety than Jennifer McNelly, the CEO of The American Society of Safety Professionals (ASSP)? [2:20] Jennifer is an accomplished executive with more than 35 years of leadership experience in associations, government, and industry. She has been the Society's CEO since 2018, leading the global organization of more than 36,000 occupational, safety, and health professionals. [2:36] Jennifer has some new risk management standards to discuss, under the safety umbrella. I also thought we would benefit from hearing her philosophies on safety and how the ASSP encourages its members to embed safety into their organization's culture. Let's get to it! [2:55] Interview! ASSP CEO, Jennifer McNelly, Welcome to RIMScast! [3:29] Jennifer McNelly and Gary LaBranche, CEO of RIMS, run into each other often at ASAE. They have talked about connecting. Jennifer is excited to be here on RIMScast to talk about collaboration, partnership, and keeping everybody safe at work. [4:04] Jennifer asks every safety professional she connects with, "Tell me your story." She says she is an amalgamation of many stories that have led her to be the CEO of ASSP. She started in the political world. She says you've got to build strong partnerships to move things forward. [4:26] That is the foundation of the mindset Jennifer brings to the ASSP. After politics, she spent time in the U.D. Department of Labor in the capacity of public-private partnerships. That's how you move things forward. [4:41] This was followed by a deep commitment to the people in this nation who make things through leadership at the Manufacturing Institute and Global Stages. All of Jennifer's career has been at the intersection of people and the world of work, and making the world a better place. [4:58] Jennifer says now she gets to do that with unbelievable honor for those who get up and run the world's economy every day, ensuring they get to go home as they were and better than when they walked in the door. [5:11] Jennifer says that's about economic contribution, keeping everybody safe, and the commitment and heart of every safety professional. Safety brought her in the door, with a very unique lens of how we need to work together to send everybody home. [5:32] Jennifer has been with ASSP for eight years, moving into her ninth year. She brings energy, passion, and connection to what ASSP is doing. She likes to think of herself as the catalyst for impact, to make workers' safety, health, and well-being an inherent right for everybody. [6:11] Jennifer says everyone's got a safety story. Often, the thing that hits the headline is the "Somebody did …" and there was a whole set of events. [6:23] Hence, today's conversation, anchored in the importance of risk identification, risk management, and integration into thinking every day by everyone. [6:33] It's not just one thing that starts it. It can be the mindset of someone who's had a bad morning and lost childcare for their family. It can be about a system in process. It can be about a bad piece of equipment. It can be a bunch of other things, but what we hear is the headline. [6:53] Jennifer says our goal is to unpack the story and get to the root cause and improve it, for everyone. [7:00] Jennifer says the ASSP has over 35,000 members globally. A lot of the membership is in the industrial space. They have partners in insurance, and those who service as well as those who produce. ASSP calls this the Safety Ecosystem. [7:26] Justin says RIMS sees that Enterprise Risk Management is leading the way for the future of the profession. Justin asks how Jennifer sees safety risk integrating more deeply into ERM frameworks. [7:42] Jennifer said in 2019, early in her career at ASSP, her pitch to the Board of Directors was for moving safety professionals and workers from basic compliance to a complete integration of human capital, total worker health, and principles like prevention through design. [8:10] Risk Enterprise Systems are critical to that objective. ASSP just released a new standard, "ANSI/ASSP Z310.1 Risk Management — Guidelines for Assessing and Managing Risk." [8:34] It's about management systems, operating in an organizational context, and creating and documenting a comprehensive approach. It's about stakeholder engagement, culture, and inclusivity. [8:49] It also has an important mindset: Change always happens. Therefore, it's about dynamic operations, not static operations; about how you use clear and available information to lead forward, and consider culture and human factors, always with continuous improvement. [9:11] Jennifer says we can't move forward without all those factors integrated into Enterprise Risk. [9:18] The ASSP's Z310.1 Committee is comprised of 28 organizations. ASSP plays an important role in the marketplace. Its logo is a shield, and its members are guardians of workplace safety. Every one of them is a workplace superhero. [10:05] Jennifer loves all superheroes because she loves the potential of hope that each one of us has that power. [10:12] One of the things that is unique about ASSP's market position is its global-based standards. It brings companies together around the table to flesh it out. It's not a single company. [10:34] Jennifer says injuries, serious incidents, and fatalities happen in an environment that's complex, dynamic, and always changing. By bringing together those who are doing the work, we gain consensus. [10:49] Justin says there is a link to the press release in this episode's show notes. The press release mentions how ANSI/ASSP Z310.0 builds off the ISO 31000 standard. There's a lot of value in it for RIMS members. Please check out the link in this episode's show notes. [11:17] Justin notes that ANSI comes with a lot of heft. The RIMS-CRMP is ANSI-accredited. RIMS is the only globally recognized risk management program through ANSI. [11:37] Jennifer says that early in her career, she sat on ANSI's 17024 PCAC, the group that approved those kinds of standards. She is a firm believer in business driving business outcomes. They know what works. [11:54] The workers doing the work and the business conducting the business know what works. Jennifer talks about cross connections and says we should be talking and doing more together. Each of us has a critical role. [12:42] A Quick Break! There are so many other wonderful RIMS events coming up in 2026. The 2026 Florida RIMS Educational Conference will be held from July 28th through August 1st at the lovely Ritz-Carlton in Naples, Florida. A link to the event is in this episode's show notes. [13:04] Register now for the Second Annual RIMS Texas Regional Conference, to be held from August 10th through 12th at the Grand Hyatt on the San Antonio River Walk. Advance rates are available through June 5th. [13:18] The 11th Annual Chicagoland Risk Forum will return to the Old Post Office on Thursday, September 24th, 2026, in Chicago. Visit ChicagolandRiskForum.org for more information. [13:31] The RIMS Western Regional Conference will be held from October 4th through the 7th in Seattle, Washington. Registration is open, and you can also submit a session. Visit RIMSWesternRegional.com and the link in this episode's show notes for more information. [13:49] Save the dates October 18th through the 21st. We will be in Quebec City to celebrate the 50th Live RIMS Canada Conference. Booth sales are already open. The call for educational sessions has been extended to May 19th, the air date of this episode. [14:06] Submit your session today. Early-bird registration will open in June. [14:12] Visit RIMSCanadaConference.ca for more information. Also, remember to check out RIMS.org/Canada for our spinoff show, RIMScast Canada, hosted by National Conference Committee Chair, Aaron Lukoni. [14:27] The RIMS ERM Conference 2026 will be held on November 18th and 19th in Columbus, Ohio. Details will follow on RIMS.org. [14:37] Let's Return to our Interview with ASSP CEO Jennifer McNelly! [14:44] Jennifer says standards bring consensus together, but members are asking how to use the standards and what to do with them. [15:03] Members want the playbook because they are busy, underresourced, and over-expected. They have a stressful work environment. The ASSP launched Standards-Based User Groups in January of this year. [15:20] The ASSP's partners collaboratively spend close to $7 million a year investing in keeping the standards updated. How do you move the standards to market? What do you do with them? There are hundreds of thousands of companies around the world that use the standards. [15:38] To somebody who is just starting that journey, it's a challenge. The ASSP's Standards-Based User Groups dig into the company's maturity, the maturity of the safety professional, and help them move one step further. [15:59] The point of Standards-Based User Groups (SBUGs) is to make the standards accessible. Jennifer says there are a couple of unique angles to the approach they are taking. [16:29] The ASSP's Standards-Based User Groups approach starts where serious incidents and fatalities happen, fall from heights and energy controls, two things where there is a lot of technical expertise in lock-out, tag-out, and fall prevention standards. [16:51] Jennifer says there is a disruption happening in business and in safety, the impact and influence of Big Data, AI, and analytics. The third SBUG is AI and Safety. Through technology partners, by integrating the Standards, it will level up what people have access to. [17:23] The ASSP's traditional routes are through the safety professionals. By putting Standards-Based User Groups in the hands of the reporting systems they have to use every day, that is scaling in a way that has never been done before. [18:06] The focus of the Standards-Based User Groups is scaling great knowledge in a framework denied by the industry. [18:16] Justin says it becomes a strategic risk management function. Jennifer says it is built into enterprise systems to drive action and make better decisions. [18:30] Another Quick Break! The Spencer Educational Foundation's Risk Manager on Campus application period is now open, and it will close on June 30th. Grant awardees, colleges, and universities are typically notified in September. [18:51] The Course Development Grant application deadline for Interval Number 2 will be on June 15th, 2026. Award notifications will be sent out in late July. [19:06] General Grant applications will open on May 1st, 2026, and the application deadline is July 30th. Internship Grant applications open on August 15th and close on October 15th. [19:18] Links to each of these grants are in this episode's show notes. Visit SpencerEd.org for more information. [19:27] Let's Conclude Our Interview with the American Society of Safety Professionals CEO Jennifer McNelly! [19:47] Justin points out that June is National Safety Month. Jennifer thinks every day is National Safety Day! National Safety Month puts a consistent spotlight on safety. She believes safety professionals need more celebration. [20:34] Jennifer loves to tell their stories. She is grateful to any safety professional and to anybody in the ecosystem listening today. Thank you for everything that you do. [20:48] June is coming, and we are not done. Jennifer often talks about the gap. She uses the roots of ASSP and the Triangle Shirtwaist Factory Fire as a real example that the gap is always going to exist. [21:12] Jennifer speaks of the Triangle Shirtwaist Factory Fire. It is the roots of the ASSP. There remains a building on the corner of NYU where about 149 individuals perished jumping out of windows because the doors were locked. It is the foundation and grounding of safety in the U.S. [21:36] Jennifer repeats that it is a real example of the gap. A couple of years ago, the ASSP Board of Directors went to the dedication of the building. Every year, Taps is played, and the ladder goes up, and it stops at the sixth floor. [21:49] You see the bunting and the gap between where we are today and where they were then. Someone next to Jennifer said, "But it needs to go higher!" That's the point. There is always a gap because business is dynamic and ever-changing. [22:06] Our responsibility as safety professionals and associations is to fill the gap and get ahead of it. With serious incidents and fatalities, the data has been flat for 10 years. Let's do something different. [22:23] Let's think about the principles of prevention through design and crack the C-Suite decision-making. Jennifer talks about safety as good governance. How safety succeeds is about the economic decision-making process. [22:44] Jennifer says it's got to be built into business in every way, shape, and form. Safety is never a moment or a one-and-done. It is a part of every part of business decision-making. [23:07] NIOSH does tremendous research on the future of work and how dynamic it is. Every year, Jennifer calls senior executives and talks through critical things. She does that because research says one thing and the ASSP membership says another. There's a gap. [23:28] Often, in that gap, Jennifer hears the term "research to practice." That leads back to the Standards-Based User Groups. What does the research say, what does the data say, and how do you scale it? [23:42] There are several forces at play when looking at what's shaping the world of work. There's workforce instability; a fluidity that never existed before. It's one of the biggest emerging risks Jennifer sees. [24:02] Next is the fact that safety is not a metric. Then there's the pace of change and technology, and the influence of leadership. Jennifer believes that leadership happens in every role and function. How do we empower individual and corporate leadership? [25:15] If a company is doing minimal compliance with the law, data tells us that's not enough. Jennifer said a volunteer was excited to tell her they had removed cell phones from a site. But cell phones can be used to photograph risks you hadn't seen. [25:54] First, understand what problem you are trying to solve. Is it technology looking for a problem, or a problem looking for a solution that the technology enables? That's the approach ASSP is taking. [26:13] If we continue to have individuals die every year, falling from heights, how do we solve that through technology, because somewhere in that complex system, things are not where they need to be. That's a statement of forward motion. [26:39] Jennifer says she thinks there is a huge opportunity, but it needs to be ethically used, transparent, and clear what problem we are trying to solve. AI in safety isn't new. ASSP worked with MakUSafe AI for three years as they started studying technology advancements in safety. [27:04] Jennifer says wearables have been around "forever." They're a good practice. Someone has seen the problem and identified the solution, and our challenge is replication, application, and scale. ASSP is striving toward that and how technology can enable it. [27:24] Jennifer says guardrails are something we hear from membership all the time. Jennifer wants it to be done in a way that integrates it seamlessly, not a new shiny penny. Jennifer is very careful to make sure changes are made at every level. This isn't a blame-the-worker approach. [27:53] This isn't Big Brother is watching somebody in the workplace. This is about empowerment in an era of action. How does information become a learning opportunity to understand A + B + C + D? [28:18] Jennifer says when she thinks of behaviors and actions, she thinks of the C-Suite decision-making. [28:26] What does the Board of Directors governing an enterprise know and understand about the human capital management and decision-making on the capital investment side of safety in the workplace? [28:39] Justin notes registration is open for Safety 2026, held from June 15th through 17th in Anaheim. It's the 65th Annual Conference and Expo. Jennifer calls it a Safety Revival! For Safety members, coming together to learn, connect, and grow gives a unique sense of belonging. [29:19] Jennifer calls it a battery-filling, energizing, impact like no other. It's a great opportunity to see what is on the leading edge and solve problems. The Expo is not a sales pitch. Everybody on that floor has to have a reason and something to share with safety professionals. [29:45] Jennifer describes the 200 classes. There are over 700 program applicants each year. There's too much content and not enough time. There's top-notch technical content and the opportunity to connect with someone that you know you can call and get an answer from. [30:20] Jennifer's favorite thing is to run around, hear stories, and take selfies. It truly is a welcoming and impactful event. [30:32] Jennifer says she's the reason people stop the second they walk in the door. She reminds them why they're there. Last year, she wore an ASSP pickleball outfit to show it's about not just being together but also having fun. Sometimes we forget that connection and fun. [31:14] People are going to learn, but have a great time while you're doing it! Jennifer says she will see everybody onstage! Anaheim will be the place to be! [31:29] The link to the 65th Annual Conference and Expo for Safety 2026 is in this episode's show notes. Justin says it has been such a pleasure to connect with you, finally, and get the word out for National Safety Month. We're priming for National Safety Month. [32:07] Special thanks to ASSP CEO Jennifer McNelly for joining us here on RIMScast! There are lots of links in this episode's show notes. Visit ASSP.org for more information, as well as the Safety 2026 Conference at Safety.ASSP.org. [32:27] Also in this episode's show notes are the links to RIMS coverage of Worker Safety and prior coverage of National Safety Month. A lot of this information is evergreen, so I hope you'll check it out. [32:39] Plug Time! You can sponsor a RIMScast episode for this, our weekly show, or a dedicated episode. Links to sponsored episodes are in the show notes. [33:08] RIMScast has a global audience of risk and insurance professionals, legal professionals, students, business leaders, C-Suite executives, and more. Let's collaborate and help you reach them! Contact pd@rims.org for more information. [33:25] Become a RIMS member and get access to the tools, thought leadership, and network you need to succeed. Visit RIMS.org/membership or email membershipdept@RIMS.org for more information. [33:43] Risk Knowledge is the RIMS searchable content library that provides relevant information for today's risk professionals. Materials include RIMS executive reports, survey findings, contributed articles, industry research, benchmarking data, and more. [34:00] For the best reporting on the profession of risk management, read Risk Management Magazine at RMMagazine.com. It is written and published by the best minds in risk management. [34:14] Justin Smulison is the Business Content Manager at RIMS. Please remember to subscribe to RIMScast on your favorite podcasting app. You can email us at Content@RIMS.org. [34:26] Practice good risk management, stay safe, and thank you again for your continued support! Links: RIMS Canada Conference — Oct. 18‒21, 2026 | Quebec City | rimscanadaconference.ca | Submit Your Session by May 19! RIMScast on YouTube! Spencer Educational Foundation — Scholarships and Grants | Open Calls and Timelines. RIMS-CRO Certificate Program In Advanced Enterprise Risk Management | July‒Sept. 2026 Cohort | Led by James Lam 2026 Florida RIMS Educational Conference | July 28‒Aug. 1 | Register Now RIMS Texas Regional Conference 2026 | Aug. 10‒12 in San Antonio | Register Now! ChicagoLand Risk Forum | Sept. 24, 2026 RIMS Western Regional Conference — Oct. 4‒7, 2026 | Seattle, WA | Register Today and Submit an Educational Session! RIMS Risk Management Magazine | Contribute RIMS Now RIMS-Certified Risk Management Professional (RIMS-CRMP) | Insights Video Series Featuring Joe Milan! The Strategic and Enterprise Risk Center RIMS Diversity Equity Inclusion Council RIMS-CRMP Stories RIMScast Canada – Episodes Now Live RISK PAC | RIMS Advocacy www.assp.org | safety.assp.org | June 15‒17 "ASSP Publishes First U.S.-Based Standard on Risk Assessment and Management" Jennifer McNelly — ASSP Bio Upcoming RIMS-CRMP Prep Virtual Workshops: RIMS-CRMP Exam Prep | June 9‒10 RIMS-CRMP-FED Exam Prep with AFERM | June 16‒17, 2026 Full RIMS-CRMP Prep Course Schedule See the full calendar of RIMS Virtual Workshops Upcoming RIMS Webinars: "Is Your Fire Protection Strategy Outdated? Emerging Risks Are Changing the Rules" | May 21 | Presented by Global Risk Consultants "From Underwriting To Risk Management: What To Expect From The Growing Demand For Data Center Construction" | May 28 | Presented by Zurich RIMS.org/Webinars Related RIMScast Episodes: "RIMS Risk Manager of the Year Jeff Bray" "Risk Leadership on the Construction Frontlines with Cynthia Garcia" "Rubber Meets Risk: Lessons from John Baldwin of Discount Tire" "Company Safety and RIMS Chapter Leadership with Tamieka Weeks" "Security Risks with William Sako" "Safety and Preparedness in 2024 with National Safety Council CEO Lorraine Martin" "Opioid Awareness and Workers Comp Risks with Raji Chadarevian of the NCCI" Sponsored RIMScast Episodes: "AI-Scale, Risk Ready: Engineering Controls for the New Data Center Boom" (New!) | Sponsored by Global Risk Consultants, a TÜV SÜD Company "Facing Into Risk: Navigating the New Risk Landscape" (New!) | Sponsored by AXA XL "Secondary Perils, Major Risks: The New Face of Weather-Related Challenges" | Sponsored by AXA XL "The ART of Risk: Rethinking Risk Through Insight, Design, and Innovation" | Sponsored by Alliant "Mastering ERM: Leveraging Internal and External Risk Factors" | Sponsored by Diligent "Cyberrisk: Preparing Beyond 2025" | Sponsored by Alliant "The New Reality of Risk Engineering: From Code Compliance to Resilience" | Sponsored by AXA XL "Change Management: AI's Role in Loss Control and Property Insurance" | Sponsored by Global Risk Consultants, a TÜV SÜD Company "Demystifying Multinational Fronting Insurance Programs" | Sponsored by Zurich "Understanding Third-Party Litigation Funding" | Sponsored by Zurich "What Risk Managers Can Learn From School Shootings" | Sponsored by Merrill Herzog "Simplifying the Challenges of OSHA Recordkeeping" | Sponsored by Medcor "How Insurance Builds Resilience Against An Active Assailant Attack" | Sponsored by Merrill Herzog "Third-Party and Cyber Risk Management Tips" | Sponsored by Alliant RIMS Publications, Content, and Links: RIMS Membership — Whether you are a new member or need to transition, be a part of the global risk management community! RIMS Virtual Workshops On-Demand Webinars RIMS-Certified Risk Management Professional (RIMS-CRMP) RISK PAC | RIMS Advocacy RIMS Strategic & Enterprise Risk Center RIMS-CRMP Stories — Featuring RIMS President Manny Padilla! RIMS Events, Education, and Services: RIMS Risk Maturity Model® Sponsor RIMScast: Contact sales@rims.org or pd@rims.org for more information. Want to Learn More? Keep up with the podcast on RIMS.org, and listen on Spotify and Apple Podcasts. Have a question or suggestion? Email: Content@rims.org. Join the Conversation! Follow @RIMSorg on Facebook, Twitter, and LinkedIn. About our guest: Jennifer McNelly, CEO, American Society of Safety Professionals More from ASSP: Standards-Based User Groups (SBUGs) News release: ASSP Announces Strategic Framework to Drive Safety Beyond Compliance; Avetta Collaboration Provides First Industry Proof Point Webpage: Standards-Based User Groups AI white paper News release: ASSP Releases White Paper on AI and the Evolving Role of EHS Professionals White paper: AI and the Evolving Role of EHS Professionals.pdf 2026 Corporate Listening Tour report News release: ASSP Report Identifies Five Critical Themes Shaping the Future of Workplace Environmental Health and Safety Webpage (with 2026 report): ASSP Corporate Listening Tour Production and engineering provided by Podfly.
Climate mandates, GRC strategy, and a bike metaphor that'll change how you think about controls. In this episode, Alyssa Zucker speaks with sustainability expert Mark Mellen on California's SB 253 soft launch—and why companies treating this year as a free pass will be blindsided in 2027. Then 25-year GRC veteran Graeme Fleming explains why governance-first programs help organizations move faster. Chapters 00:00—Intro: California, GRC, and what's at stake 01:45—Mark Mellen: California SB 253 and the soft launch 07:00—SB 261, climate risk, and the commercial case 10:00—Global mandates: CSRD, ISSB, and the fragmented web 11:30—The ESG controller and data governance 17:00—Quantifying sustainability value 20:00—Graeme Fleming: Putting the G back in GRC 22:00—AI, the EU AI Act, and GRC's strategic role 23:00—The bike brake framework Subscribe for new episodes!
Link to the episode This week's Department of Know is hosted by Rich Stroffolino, with guests Jonathan Waldrop, CISO, Acoustic, and Jason Elrod, CISO, MultiCare Health System. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. Huge thanks to our sponsor, Vanta Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.
PAN-OS RCE exploit under active use enabling root access and espionage Polish intelligence says hackers attacked water treatment control systems Ivanti warns of new EPMM flaw exploited in zero-day attacks Get the show notes here: https://cisoseries.com/cybersecurity-news-pan-os-rce-exploit-poland-water-hacks-ivanti-epmm-flaw/ Thanks to our episode sponsor, Vanta Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.
Most internal audit functions are still operating like it's 2010. In the first episode of Embark's new GRC series, Adam Olsen is joined by Allison Bradshaw, Principal and head of Embark's GRC and Internal Audit Services practice, to make the case for a fundamentally different model. The conversation covers what modern IA looks like, how to build the right delivery structure, and how CFOs can measure real return on investment.In this episode:Why compliance-checkbox IA is leaving significant value on the table, and what a risk-based, consultative function looks like insteadCo-sourcing vs. outsourcing: a practical framework for deciding which model fits your organization's size, complexity, and risk profileHow data analytics and AI are shifting IA from sampling transactions to testing entire populations in near-real timeThe emerging demand for IT audit, cybersecurity, and AI governance capabilities, and why most teams can't hire for all of itA framework for measuring IA ROI: prevented costs, recovered value, process improvements, and stakeholder confidenceA real-world co-sourced engagement example where a single year yielded over $1.6M in identified losses and fraud
Most GRC functions were built a decade ago in response to SOX or a single risk event. The world has changed. The function often hasn't. In this episode, Embark's Adam Olsen is joined by Managing Director Allison Bradshaw to break down what it actually takes to modernize governance, risk, and compliance for the environment organizations are operating in today.In this episode:Why siloed GRC functions create blind spots, audit fatigue, and hidden costs that far exceed what shows up on a budget lineWhat an integrated GRC model looks like in practice: common risk taxonomy, shared technology, and coordinated activities across all three lines of defenseHow to make the business case for modernization, including the 20 to 30 percent cost reduction organizations typically see when duplication is eliminatedTechnology enablement beyond the platform: continuous controls monitoring, workflow automation, and real-time integration with your ERP and source systemsHow modern GRC transforms SOX from a seasonal sprint into a year-round process, with a real-world example of an $800K compliance budget getting restructuredWhere AI fits into GRC today: risk identification, anomaly detection, and compliance monitoring, plus the governance frameworks organizations need to manage AI as a risk in its own rightWhat a risk-intelligent culture actually looks like, and why most GRC transformations fail on culture long before they fail on technologyHow to start without boiling the ocean: practical guidance on sequencing a GRC modernization roadmapTo connect with Allison or learn more about Embark's GRC maturity assessment, visit embarkwithus.com.
Google Chrome installs 4GB AI model on devices Daemon Tools disk app backdoored in supply-chain attack Crypto's 'decentralised finance' sector hit by investor exodus Get the show notes here: Thanks to our episode sponsor, Vanta Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.
Video game platform hit by supply chain attack Bleeding Llama could expose your data US gets more early LLM access Get the show notes here: https://cisoseries.com/cybersecurity-news-video-game-supply-chain-attack-bleeding-llama-us-gets-early-llm-access/ Thanks to our episode sponsor, Vanta Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.
Instructure discloses breach amid leak threats DigiCert revokes certificates Silver Fox targets Indian and Russian orgs Get the show notes here: https://cisoseries.com/cybersecurity-news-instructure-discloses-breach-digicert-revokes-certificates-silver-fox-targets-indian-and-russian-orgs/ Thanks to our episode sponsor, Vanta Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.
Telegram Mini Apps deliver Android malware CISA orders Federal agencies to patch cPanel bug by Sunday British cyber agency warns of looming 'patch wave' due to speedy AI flaw discovery Get the show notes here: https://cisoseries.com/cybersecurity-news-telegram-mini-apps-malware-cpanel-is-sorry-patch-wave-warning/ Thanks to our episode sponsor, Vanta Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.
This week on the Community Trust Bank Coaches Corner: Tonight we have on GRC New Head Football Coach Dane Damron. Coach Damron takes over this year for GRC and looks to improve on their winning ways!! Join us for an action-packed episode! Your home for passionate sports talk—from Friday night lights to the hardwood to the diamond! We shine a spotlight on local high school athlete's sports scene. If it matters to you it matters to us!! Four voices. Four communities. All sports. Hosts - Sean Kiper, Wes Crouch, Adam Muncy, and Daron Stephens. Follow and Like us on the following Social Media Platforms. Support the show Follow us on Facebook Follow us on X Subscribe on Youtube Visit us on the Web
What if your engineering calculations secretly sabotaged your nation's best efforts? This week, we reveal how a newly uncovered 21-year-old NSA rootkit quietly corrupted scientific research in hostile states and why it changes everything you think you know about cyberwarfare. Bitwarden's CLI hit with a supply-chain attack. Commercial routers in Iran fail shortly before the war. Meta logging all employee activity to train replacement AI. GRC's DNS Benchmark Release 5. Two miscellaneous AI thoughts. A bunch of terrific listener feedback. Unraveling the diabolical history of "fast16.sys" Show Notes - https://www.grc.com/sn/SN-1076-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: doppel.com threatlocker.com/twit material.security cyberhoot.com/securitynow guardsquare.com
What if your engineering calculations secretly sabotaged your nation's best efforts? This week, we reveal how a newly uncovered 21-year-old NSA rootkit quietly corrupted scientific research in hostile states and why it changes everything you think you know about cyberwarfare. Bitwarden's CLI hit with a supply-chain attack. Commercial routers in Iran fail shortly before the war. Meta logging all employee activity to train replacement AI. GRC's DNS Benchmark Release 5. Two miscellaneous AI thoughts. A bunch of terrific listener feedback. Unraveling the diabolical history of "fast16.sys" Show Notes - https://www.grc.com/sn/SN-1076-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: doppel.com threatlocker.com/twit material.security cyberhoot.com/securitynow guardsquare.com
What if your engineering calculations secretly sabotaged your nation's best efforts? This week, we reveal how a newly uncovered 21-year-old NSA rootkit quietly corrupted scientific research in hostile states and why it changes everything you think you know about cyberwarfare. Bitwarden's CLI hit with a supply-chain attack. Commercial routers in Iran fail shortly before the war. Meta logging all employee activity to train replacement AI. GRC's DNS Benchmark Release 5. Two miscellaneous AI thoughts. A bunch of terrific listener feedback. Unraveling the diabolical history of "fast16.sys" Show Notes - https://www.grc.com/sn/SN-1076-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: doppel.com threatlocker.com/twit material.security cyberhoot.com/securitynow guardsquare.com
What if your engineering calculations secretly sabotaged your nation's best efforts? This week, we reveal how a newly uncovered 21-year-old NSA rootkit quietly corrupted scientific research in hostile states and why it changes everything you think you know about cyberwarfare. Bitwarden's CLI hit with a supply-chain attack. Commercial routers in Iran fail shortly before the war. Meta logging all employee activity to train replacement AI. GRC's DNS Benchmark Release 5. Two miscellaneous AI thoughts. A bunch of terrific listener feedback. Unraveling the diabolical history of "fast16.sys" Show Notes - https://www.grc.com/sn/SN-1076-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: doppel.com threatlocker.com/twit material.security cyberhoot.com/securitynow guardsquare.com
What if your engineering calculations secretly sabotaged your nation's best efforts? This week, we reveal how a newly uncovered 21-year-old NSA rootkit quietly corrupted scientific research in hostile states and why it changes everything you think you know about cyberwarfare. Bitwarden's CLI hit with a supply-chain attack. Commercial routers in Iran fail shortly before the war. Meta logging all employee activity to train replacement AI. GRC's DNS Benchmark Release 5. Two miscellaneous AI thoughts. A bunch of terrific listener feedback. Unraveling the diabolical history of "fast16.sys" Show Notes - https://www.grc.com/sn/SN-1076-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: doppel.com threatlocker.com/twit material.security cyberhoot.com/securitynow guardsquare.com
What if your engineering calculations secretly sabotaged your nation's best efforts? This week, we reveal how a newly uncovered 21-year-old NSA rootkit quietly corrupted scientific research in hostile states and why it changes everything you think you know about cyberwarfare. Bitwarden's CLI hit with a supply-chain attack. Commercial routers in Iran fail shortly before the war. Meta logging all employee activity to train replacement AI. GRC's DNS Benchmark Release 5. Two miscellaneous AI thoughts. A bunch of terrific listener feedback. Unraveling the diabolical history of "fast16.sys" Show Notes - https://www.grc.com/sn/SN-1076-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: doppel.com threatlocker.com/twit material.security cyberhoot.com/securitynow guardsquare.com
RSAC Conference 2026 is in the books, and the post-event read is familiar. More vendors, more AI-driven marketing, more noise, and a buyer-side audience that increasingly cannot tell who to trust. Michael Parisi, Chief Growth Officer at Steel Patriot Partners, joins ITSPmagazine for a quick post-event catch-up on what he walked away with, and what is quietly shifting underneath all that volume. The headline takeaway is what Michael Parisi calls the "fog of more." Marketing has done its job too well. CISOs and business leaders facing real decisions cannot tell competing solutions apart, do not know where to start, and are not sure their current stack is even the right one. Too much information has become its own information problem. What is shifting, according to Michael Parisi, is where the meaningful conversations actually happen. Closed-door, hallway, and dinner conversations have always existed at RSAC Conference, but more people are now openly recognizing that this is where the real industry decisions get made. That recognition is changing how teams plan to engage with future conferences and industry events. For Steel Patriot Partners, which describes itself as business owners first, engineers second, and security and compliance practitioners third, that is exactly the conversation they want to be in. This is a Brand Highlight. A Brand Highlight is a ~5 minute introductory conversation designed to put a spotlight on the guest and their company. Learn more: https://www.studioc60.com/creation#highlight GUEST Michael Parisi, Chief Growth Officer, Steel Patriot Partners | https://www.linkedin.com/in/michael-parisi-4009b2261/ RESOURCES Learn more about Steel Patriot Partners: https://www.steelpatriotpartners.com Steel Patriot Partners Assistance Center: https://www.steelpatriotpartners.com View all of our RSAC Conference 2026 coverage: https://www.itspmagazine.com/rsac26 Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS Michael Parisi, Steel Patriot Partners, Marco Ciappelli, Sean Martin, brand story, brand marketing, marketing podcast, brand highlight, RSAC Conference 2026, RSAC, cybersecurity compliance, fog of more, vendor noise, CISO, GRC, cybersecurity advisory, FedRAMP, CMMC, HITRUST, AI security marketing, hallway conversations, post RSAC Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
Meta quietly ditches encryption for Instagram chats while TikTok also backpedals on privacy, shaking up assumptions about how much big tech really values your secrets. Meanwhile, Steve Gibson reveals why CISA's free government security scans are an absolute must for businesses—plus what he learned when GRC took the plunge. The Security Now "Caption That Photo" contest. A mega social media company says "no" to strong encryption. WhatsApp to give parents more control, Consumer bandwidth proxying is becoming a big deal. Meta buys the Moltbook duo. The EU gives up and settles upon the status quo. When a ransomware negotiation is not what it seems. CISA compels federal agencies to submit their logs. Is that a VPN in your pocket or something more malicious. Be careful what you download, thinking it's AI. A super-clever and super-simple A/V scanner bypass. Will AI write code for me? Another listener discovers the Joy of AI. Steve's CISA Internet scanning experience Show Notes - https://www.grc.com/sn/SN-1070-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: joindeleteme.com/twit promo code TWIT material.security canary.tools/twit - use code: TWIT adaptivesecurity.com meter.com/securitynow