POPULARITY
Categories
What a company is trying to reach is rarely a certificate. Michael Parisi, Chief Growth Officer at Steel Patriot Partners, treats the destination as the opening question rather than the closing one, and the firm orders its own priorities to match. Business owners first, engineers second, compliance and security people third. What does a secure and compliant business actually look like? It looks like whatever lets that business do what it set out to do. For one company it means entering a regulated industry it has never served. For another it means proving to itself and to an auditor that it is secure enough to work with a partner that will not move without evidence. The framework follows the objective. Before a framework gets named or a control gets selected, someone has to decide whether the trip is worth taking. Michael Parisi puts more than half of that work in the category of psychology, and describes the most fulfilling part as helping someone understand where they actually stand. He comes at it from several sides of the same decision, having spent about fifteen years with the Big Four, five and a half with a cybersecurity standards organization and certification body, and two in a similar role at an audit and attestation firm. How does a company know which route it is on? Steel Patriot Partners narrowed it to five positions and put three questions in front of them under the name Find Your Path. Growth has tapped out and a new industry looks like the way to keep going. Money is already committed to a direction someone else recommended. The decision is settled and the work needs a specialist. The open question is which partners and auditors to trust. Or the team needs sustained support rather than a project with an end date. What makes the answer usable is that the firm has nothing riding on it. Steel Patriot Partners stays agnostic relative to tools, software, and auditors, which keeps the opening question plain. Who do you like, and what do you already have? Personality and culture then carry weight alongside capability. Knowing the route also means knowing where it narrows, so Michael Parisi and CEO Jason Ford both press on what a client has not considered, then on what to watch out for. Sometimes the useful answer points somewhere else entirely. Find Your Path is not a robot, an LLM, or an AI tool, and the point is to give an organization enough value to lower its guard and talk directly. One of Michael Parisi's favorite outcomes is confirming that a company may not need to do the thing it walked in asking about, and when the work sits outside what Steel Patriot Partners handles, the firm connects them with someone who does. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUEST Michael Parisi, Chief Growth Officer, Steel Patriot Partners LinkedIn: https://www.linkedin.com/in/michael-parisi-4009b2261/ RESOURCES Steel Patriot Partners: https://www.steelpatriotpartners.com Find Your Path, three questions to start: https://www.steelpatriotpartners.com/find-your-path Steel Patriot Partners Insights: https://resources.steelpatriotpartners.com Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS michael parisi, steel patriot partners, sean martin, brand story, brand marketing, marketing podcast, brand spotlight, black hat usa 2026, find your path, secure and compliant business, business enablement, cybersecurity strategy, grc, governance risk and compliance, agnostic advisory, audit readiness, fedramp, cmmc, entering a regulated market, vendor and partner selection
Steel Patriot Partners lists its priorities in an order much of the cybersecurity industry reverses. Business owners first, engineers second, security and compliance people third. Michael Parisi, Chief Growth Officer, says the sequence is deliberate and shapes how the firm opens a client conversation. The order tracks the path the founders took. Jason Ford, Co-Founder and CEO, started in the late 1990s as a government contractor at the FBI, met FISMA and SAS 70 early, and built a platform for the Treasury that sold savings bonds online before PCI was a standard. He started his first company in 2004, took it through FedRAMP in 2013, and was acquired in 2017 holding 35 to 36 authorizations to operate across multiple agencies. What changes when an advisor is free to answer directly? Parisi spent about 15 years in the Big Four across PwC and Deloitte before joining Steel Patriot Partners. Auditors hold independence, which means watching a decision head the wrong way without steering it. In an advisory seat, he says, telling an organization that its preferred direction falls apart as a business decision becomes part of the work. How does a company find out where it actually stands? Ford says compliance is one outcome among many, sitting alongside operational maturity, better visibility, and integrating AI into DevSecOps. The common gap is not knowing where you sit on your own maturity journey. That finding cuts both ways, and some organizations learn they are further along than they assumed. Buying more tools rarely closes the gap. Ford argues the work is holistic and that each organization is unique, so what fits one may fit another poorly. AI does not settle it either, since a model fed your own assumptions will hand them back. The name follows the same logic. Steel is Pittsburgh, Patriot is Boston, and Partners is the operating model, since Steel Patriot Partners advises, deploys and operates environments alongside the client. Parisi closes by asking anyone weighing a path to verify it as a business decision rather than as an information security purchase or a price comparison. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUESTS Jason Ford, Co-Founder and CEO, Steel Patriot Partners LinkedIn: https://www.linkedin.com/in/jason-ford-5ab206/ Michael Parisi, Chief Growth Officer, Steel Patriot Partners LinkedIn: https://www.linkedin.com/in/michael-parisi-4009b2261/ RESOURCES Steel Patriot Partners: https://www.steelpatriotpartners.com/ Find Your Path, the qualifier that helps you locate your starting point: https://www.steelpatriotpartners.com/find-your-path ROI Workshop: https://www.steelpatriotpartners.com/roi-workshop ITSPmagazine event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS jason ford, michael parisi, steel patriot partners, marco ciappelli, brand story, brand marketing, marketing podcast, brand spotlight, cybersecurity compliance, grc, fedramp, fisma, cmmc, maturity assessment, cybersecurity advisory, business risk, compliance strategy, security consulting, ai in devsecops, trusted advisor
The former senior minister unveils the robust Cabinet debates over three defining institutions published in a new book. Synopsis: Conversations and interviews that give you something to think about. Each Wednesday, In Your Opinion speaks to thinkers, leaders, and the people shaping our lives and the issues of the day. Governing Singapore today is a tough task, made more difficult by frequent comparisons with the immediate post-independence decades - a period dominated by the towering figure of founding Prime Minister Lee Kuan Yew. Yet was Lee more open to persuasion than we realise? Was governing Singapore far more complex, nuanced and more akin to a team sport? What enabled the Singapore Cabinet to have vociferous debates on policy including the Elected Presidency, the Group Representation Constituency and the Non-Constituency Member of Parliament? And after recent developments and the power of hindsight, would one of their chief architects say they’re due for a refresh? These are the subjects of the book Creating Three Unique Singapore Laws: An Inside Story by S. Jayakumar, launched on Aug 12. In an exclusive hour-long podcast with The Straits Times opinion editor Lin Suling, he opens up on Cabinet deliberations and sheds light on a milieu in Singapore’s history after the 1981 Anson by-election, which sparked the creation of three powerful institutions that have become indelible parts of Singapore’s political system. Highlights (click/tap above): 1:44 Are recent resignations of minority Members of Parliament a setback for the GRC system? Is the GRC system due for a review? 12:58 Has public understanding on the limits of the Elected Presidency improved? 21:21 Was the NCMP scheme created to secure the ruling People’s Action Party’s dominance in Parliament? 29:26 Do PAP backbenchers pull their punches in Parliament? What was it like being J B Jeyaretnam’s “sparring partner”? 31:36 Was Lee Kuan Yew actually more open to persuasion than Singaporeans realise? 33:10 What allowed Lee’s Cabinet to have such vociferous debates? Does S Jayakumar worry about political correctness dampening discussions? What does it take to recruit capable Cabinet Ministers? 40:45 Why did a proposal on constitutional design go through DEFCO - the defence council overseeing national security? 44:00 Are any of Singapore's constitutional institutions due for a refresh? 46:59 How did S Jayakumar balance heavy ministerial portfolios with constituency duties in Bedok and family life? Creating Three Unique Singapore Laws: An Inside Story is published by Straits Times Press and available for $38.90 (excluding GST) at major bookstores and online at https://www.stbooks.sg/ Read ST’s Opinion section: https://str.sg/w7sH Follow Lin Suling on LinkedIn: https://str.sg/hiLQ Host: Lin Suling (linsuling@sph.com.sg) Produced and edited by: Teo Tong Kai Executive producers: Danson Cheong and Lynda Hong Follow In Your Opinion Podcast here and get notified for new episode drops: Channel: https://str.sg/w7Qt Apple Podcasts: https://str.sg/wukb Spotify: https://str.sg/w7sV YouTube: https://str.sg/GjMT Feedback to: podcast@sph.com.sg --- Follow more ST podcast channels: All-in-one ST Podcasts channel: https://str.sg/wvz7 Get more updates: http://str.sg/stpodcasts --- Get The Straits Times app, which has a dedicated podcast player section: The App Store: https://str.sg/icyB Google Play: https://str.sg/icyX --- #inyouropinionSee omnystudio.com/listener for privacy information.
Après 5 ans à se côtoyer, on n’a jamais vu la blonde de Dave Morgan et on commence à croire que c’est une poupée! On tente de soutenir la candidature de Youppi! comme meilleure mascotte de la LNH, selon USA Today. On a jasé de l’objet que tout le monde a dans la vie… sauf Julibou! Dans notre 7 chanceux, on en a miaulé une bonne shot pour faire gagner notre certificat-cadeau de 100 $ chez Animo Etc. Dans son Wake Up Quiz, Ben K7 nous a offert ses traditionnelles devinettes et, une fois de plus, le tout a dérapé! On a jasé de la programmation du Vans Warped Tour avec Nick d’Evenko. Dans sa Grosse Nouvelle, Étienne Phénix nous a parlé, une fois de plus, de Justin Trudeau, qui nous coûte cher en surveillance de la part de la GRC.
Recorded on location at Black Hat USA 2026 in Las Vegas at the end of day two, Karthik Kannan, Founder and CEO at Anvilogic, walks through a seven year build that reached its original shape this year. The plan from the start was a full security operations platform covering data, the detection engineering process, triage and investigation, and case management. In the shorthand of the category, SIEM and SOAR combined. It arrived in phases. Detection engineering came first, implemented on top of Splunk for most customers, then the data platform expanded into data lakes including Snowflake, Databricks, and Microsoft Azure. Triage and investigation followed over the last two years. In the last year Anvilogic rolled out agents that carry out the work of specific personas, and this year the company launched Blueprints, an orchestrator agent that brings the discrete agents together to run a whole workflow with humans in the loop. What separates a security graph from a frontier model? It knows the environment. Karthik Kannan describes the enterprise security graph as Anvilogic's own model running inside the network, learning the micro environment, with frontier LLMs called on to fill gaps in the macro environment. His argument is that platforms operating as LLM wrappers miss the last mile, because AI on its own reaches 60, 70, or 80 percent of the way if you are lucky. How does a team keep control when agents run the workflow? Through gates, permissions, and a record of what happened. Workflows can be described in plain English, with human gates inserted as often as the team wants. Access controls sit at the persona, organization, and object levels, and activity is audited and logged, which matters to the GRC teams Anvilogic works with. Screens dedicated to what the company calls a maturity score show which feeds are coming in, what kinds of detections exist, and what coverage looks like against the MITRE ATT&CK framework, in a form available to executives and CISOs. Karthik Kannan also points to version 8.0, introduced the week before the event, which includes an Anvilogic MCP Server for connecting to third party tools. Customers are already building their own Blueprint workflows during proofs of concept, including a large life sciences customer Anvilogic expects to feature in a public case study. Karthik Kannan is careful about the claim being made here. This is not a proclamation of an autonomous SOC. It is automation that makes life in a SOC easier and more efficient, adopted at a crawl, walk, run pace, with every step visible along the way. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Karthik Kannan, Founder and CEO at Anvilogic On LinkedIn: https://www.linkedin.com/in/karthikkannan001/ RESOURCES Black Hat USA 2026 event coverage from ITSPmagazine: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Learn more about Anvilogic: https://www.anvilogic.com Anvilogic 8.0, from onboarding to investigation: https://www.anvilogic.com/learn/anvilogic-8-0-automate-the-soc Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS karthik kannan, anvilogic, sean martin, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, agentic secops, ai soc platform, enterprise security graph, detection engineering, triage and investigation, blueprints orchestrator agent, mcp server, mitre att&ck coverage, human in the loop automation, siem and soar, security operations, grc audit logs Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
ממשל ארגוני הוא דבר "חי" שדורש עדכון חדשות לבקרים במיוחד כיום שנכנסה האינטליגנציה המלאכותית לסביבות העסקיות והתפעוליות. ממשל ארגוני דורש הבנה עמוקה בתהליכים, אנשים והטכנולוגיות בארגון, עברו הימים שמנכ"ל ודריקטוריון מכירים ומבינים "בערך", האחריות האישית של ההנהלה הבכירה והדרקטוריון הולכת וגדלה וניתן לראות זאת בברור בחוק הסיבר שעבר בקריאה ראשונה בכנסת. כול זה הופך את התפקיד של הסיסו לצומת מרכזית ודורש ידע וכלים שלא נדרשו בעבר. נחשון פינקו מארח את שירלי סידי מנהלת חטיבת הייעוץ לסייבר וגי.אר.סי באשנב (לשעבר אמן סיבר וענן) מקבוצת אמן. המשמעות של גי.אר.סי לארגון מה תחומי הידע שהסיסו נדרש כיום להחזיק איך מתמודדים ארגונית עם האינטליגנציה המלאכותית ועוד Organizational governance is a “living discipline” that requires constant updates, especially today as AI enters business and operational environments. Effective governance demands a deep understanding of processes, people, and technologies within the organization. The days when CEOs and boards had only a “rough” understanding are over — senior leadership and boards now carry growing personal responsibility, clearly reflected in the new Cyber Law that passed its first reading in the Knesset. All of this turns the CISO role into a central crossroads, requiring new skills and knowledge, never needed before. Nachshon Pincu hosts Shirly Sidi, Director of the Cyber Consulting and GRC Division at Eshnav (formerly Aman Cyber & Cloud) of the Aman Group. The significance of GRC for the organization The knowledge domains modern CISOs must master How organizations should address the rise of AI And more ועוד
Automation and AI have flooded the sales and marketing side of the market, and Michael Parisi, Chief Growth Officer at Steel Patriot Partners, says the security leaders on the receiving end were already past capacity. The pitch tends to lead with the product rather than the problem. So many CISOs have stopped taking direct sales calls and started asking a different question: what VAR do you work with, and who can I buy you through? That routing puts weight back on partners who know where a program has been and how to move it forward. Parisi describes a partner meeting during the week with RegScale and Wiz, with Steel Patriot Partners in the services role, and the recognition that the company is moving toward systems integration with engineering at the center. Software providers can supply the product. Aligning and configuring it against a specific set of business expectations is a different job. What happens when that job has no owner? Tools get bought and the return never shows up. Parisi sees organizations spending on best of breed and failing to recognize ROI because the tools are not being used or configured against the business objective. The correction is engineering work rather than another purchase. One client was told by its board to cut a significant portion of the IT and information security budget. Steel Patriot Partners looked for overlap, found three tools accomplishing the same business outcome, met the number, and exceeded it on cost savings. Parisi attributes the underlying problem to years of deferred maintenance on the stack, from teams with the appetite to buy tools and without the time to configure them. He expects the consolidation the cloud market saw a decade ago to reach cybersecurity tooling and GRC, and puts a number on it: 48 main GRC providers today, roughly five within five years. Good enough, configured appropriately, beats best of breed sitting idle. For CISOs building the next budget cycle, Parisi recommends bringing the sourcing closer in. Go to your anchor partners, ask what they are running next year and what worked this year, and skip the attempt to talk to everybody. Steel Patriot Partners co-founder Jason Ford has a line that fits alongside it. Have an open mind. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUEST Michael Parisi, Chief Growth Officer, Steel Patriot Partners LinkedIn: https://www.linkedin.com/in/michael-parisi-4009b2261/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Steel Patriot Partners: https://www.steelpatriotpartners.com Steel Patriot Partners at Black Hat USA 2026: https://www.steelpatriotpartners.com/events/black-hat-usa-2026 Steel Patriot Partners Insights: https://resources.steelpatriotpartners.com Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS michael parisi, steel patriot partners, sean martin, brand story, brand marketing, marketing podcast, brand spotlight, black hat usa 2026, ciso budget, channel partners, var, systems integrator, grc consolidation, security tool sprawl, licensing costs, roi, configuration, compliance, cybersecurity engineering, regscale, wiz Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
Summary Today Marc is chattin' with Richa Kaul, founder and CEO of an AI-based compliance automation platform. The conversation centered on how AI is reshaping enterprise governance, risk, and compliance (GRC), especially by helping organizations handle growing complexity without simply adding more headcount. The discussion quickly focused on how compliance teams can use automation and AI to streamline vendor risk, regulatory requirements, and other time-consuming workflows. Richa explained that his approach starts by separating what truly requires human judgment from what can be automated. A major theme was the mismatch between the speed of modern risk and the pace at which organizations can hire. Richa argued that risk is increasing faster than teams can scale, making it unrealistic to solve GRC challenges by just expanding staff. Instead, she framed the real question as what work should remain with humans and what work can be handled by AI or automation. She emphasized that teams are bogged down by urgent audit prep, repetitive tasks, and reactive “fire drills,” which prevents them from focusing on strategic risk reduction. The chat then moved into visibility and granularity in risk management, particularly around privacy. Richa noted that many CISOs and GRC leaders lack sufficient visibility into their organization's risks, especially because privacy is cross-functional and touches employees, users, operations, and regulatory obligations. She said this lack of clarity makes it difficult for leaders to confidently communicate risk to boards or determine where to invest time and resources. In her view, the biggest issue is not just managing risk, but being able to see it clearly enough to act on it. Another key topic was AI governance. Richa pointed out that many companies are paying attention to AI policy at the top level, but are not doing enough to train employees at the operational level, where mistakes are most likely to happen. She described the “last mile” of AI governance as especially vulnerable, since employees may unknowingly expose proprietary information by entering sensitive data into tools like GPT. According to Richa, human behavior is often the weakest link, and effective governance requires education and training throughout the organization, not just policy statements from leadership. Their chat also touched on industry-specific risk, with healthcare highlighted as a major area of concern. Richa said healthcare compliance appears underinvested compared with financial services, even though both are highly regulated and handle highly sensitive data. She closed by offering a practical starting point for companies facing generative AI challenges: map your most important data, follow it from input to output, identify the systems it touches, and secure each step of the journey. His overall message was optimistic — that even though the risk landscape feels overwhelming, organizations have tools, platforms, and partners that can help them manage it more effectively. Key Points AI can reduce compliance burden by automating repetitive GRC tasks. Organizations can't hire fast enough to keep up with rising risk and regulatory complexity. Many leaders lack clear visibility into privacy and cross-functional risk. AI governance fails most often at the employee level, not just the policy level. Healthcare compliance is highly exposed and may be underinvested relative to its risk. Key Quotes “Risk right now is increasing at a speed and at a rate that teams cannot possibly hire to mitigate.” “It is not the question of, should teams get smaller. I think it’s a question of what work should humans be doing and what work can I do instead.” “A lot of CISOs tell me that they don’t have the visibility, or at least the granularity of visibility into their risks that they would like.” “Humans are the weakest link.” “Don’t you need to boil the ocean, but let’s look at what is your highest risk data.” About Our Guest Richa Kaul is a technology executive and Head of Product Engineering: Strategy, AI Builder, and Cloud & AI Enterprise Transformation, with 20+ years of experience leading cloud, data, and AI initiatives across Fortune 500 organizations. She has managed portfolios as large as $2B in revenue and $300M in operating budgets, while building global teams of 100+ and advising CxOs on enterprise AI and financial strategy. Richa is known for driving GenAI adoption, modernizing data platforms, advancing AI governance, and delivering scalable, cost-effective transformation across banking, capital markets, asset management, and wealth management. Follow Our Guest LinkedIn About Our Host National co-chair of the Cyber Center for Excellence, Marc Schein, CIC,CLCS is also a Risk Management Consultant at Marsh McLennan Agency. He assists clients by customizing comprehensive commercial insurance programs that minimize the burden of financial loss through cost effective transfer of risk. By conducting a Total Cost of Risk (TCoR) assessment, he can determine any gaps in coverage. As part of an effective risk management insurance team, Marc collaborates with senior risk consultants, certified insurance counselors, and expert underwriters to examine the adequacy of existing client programs and develop customized solutions to transfer risk, improve coverage and minimize premiums. Follow Our Host Website | LinkedIn
Innovation comes in many areas and compliance professionals need to not only be ready for it but embrace it. Join Tom Fox, the Voice of Compliance as he visits with top innovative minds, thinkers and creators in the award-winning Innovation in Compliance podcast. In this episode, host Tom Fox visits with s Diego Panama, new CEO of LogicGate. They discuss his career from Microsoft product management to scaling Live Ramp to an IPO, building go-to-market at Olo, and joining LogicGate through a planned CEO transition with co-founder Matt Kunkel. Panama describes his focus on scaling operations while preserving a customer-first, values-driven culture, and sharpening the company's positioning as the leading AI GRC platform for enterprise. The discussion highlights AI's role in moving GRC from check-the-box defense to real-time, strategic enablement, including holistic risk visibility across silos, third-party risk blind spots, and always-on monitoring. Panama explains LogicGate's workflow agents and the path toward orchestrated, autonomous GRC with humans setting risk appetite, emphasizes data access, quality, and governance, and outlines product UX evolution from no-code to prompt-driven configuration. He notes boards' increased attention to GRC due to AI risks and encourages students and practitioners to stay curious and aligned to business outcomes. Key Highlights · Why LogicGate and GRC · AI Makes GRC Strategic · Holistic Risk and Third Parties · Workflow Agents Explained · Data Access and Governance · Big Tech Lessons on Focus · Staying Current in Tech Resources LogicGate Diego Panama on LinkedIn Innovation in Compliance was recently honored as the Number 4 podcast in Risk Management by 1,000,000 Podcasts
History shows that nations often enter new conflicts relying on old, familiar tactics. It's only after those tactics fail that they adapt to something new. Today, thousands of defense contractors and companies are making the exact same mistake with Cybersecurity Maturity Model Certification (CMMC). By applying outdated, static compliance tools to a modern, dynamic regulatory landscape, organizations face mounting delays, incomplete visibility, and soaring costs. In this week's episode of Feds At The Edge, we sit down with leading experts from GDIT, Axonius Federal, Red River and ComplAi, who have successfully navigated these pitfalls to streamline the journey to certification. They highlight why traditional governance, risk, and compliance (GRC) tools built for commercial frameworks fail under CMMC standards, why continuous monitoring must replace periodic rule-checking, and how essential a complete data inventory is for long-term success.
Eric Evans and Charlie Clayton from Hanabyte join Ingram Micro's AWS Partner Spotlight to discuss how regulated organizations can move fast in the cloud without sacrificing security or compliance. They break down Hanabyte's "cradle to grave" approach — from mock audits and knowledge transfer to blurring the line between compliance and engineering — and how their Ingram Micro partnership helps clients navigate NIST, CMMC, FedRAMP, and HIPAA requirements.Key Takeaways
Eric Evans and Charlie Clayton from Hanabyte join Ingram Micro's AWS Partner Spotlight to discuss how regulated organizations can move fast in the cloud without sacrificing security or compliance. They break down Hanabyte's "cradle to grave" approach — from mock audits and knowledge transfer to blurring the line between compliance and engineering — and how their Ingram Micro partnership helps clients navigate NIST, CMMC, FedRAMP, and HIPAA requirements.Key Takeaways
All links and images can be found on CISO Series This week's episode is hosted by me, David Spark, producer of CISO Series and Mike Johnson, CISO, Rivian. Joining us is our sponsored guest, Khush Kashyap, senior director of GRC at Vanta. In this episode: Running up the token meter Some risks resist a price tag Resilience isn't a vacation policy Compliance is the wrong finish line A huge thanks to our sponsor, Vanta Still stuck on the quarterly audit treadmill? Meet Calm-pliance. Vanta combines compliance, risk, and proof on one Agentic Trust Platform—and continuously monitors your controls, keeping you audit-ready all year round. Find your Calm-pliance here.
This playlist is 91% vinyl friendly. Near perfect. Philips, The Tina Century Bluetooth Turntable room.. A £350-£400 retro look to blend in with your wood panelling room, it reminds me of a car grill from the 1960s. Built-in speakers with deep (how low can you go) bass and crystal-clear highs. Any track marked * has been given either a tiny or a slightly larger 41 Rooms tweak/edit/chop and the occasional tune might sound a bit dodgy, quality-wise. On top of that, the switch between different decades and production values never helps in the mix here. Lyric of Playlist 154 Tim Hardin’s lyric and song title. 00.00 (Intro) THE FLAMINGOS – Stars (Edit) – Unreleased demo – 1983. Episode #1 for info. 00.41 NEW ORDER – Dreams Never End (John Peel session: 16.2.81) – The Peel Sessions 12″ EP – Strange Fruit – 1987 Diary for Jan 16, ’81 says ‘Karl W round. NEW ORDER JOHN PEEL…‘ Those caps signal something special and the journey had begun at Heaven, London a week earlier. Two good mates called Karl were there, though I hadn’t realised the one at my house listening to the first broadcast of the session was a Carl. 03.45 THE TEARDROP EXPLODES – Second Head – Kilimanjaro, LP – Mercury – 1980 Listening to this album now it’s got a bit of a bubbly and bouncy feel. Judging by a set list suggested for the Manchester Poly night’ that followed ours/mine it doesn’t look like Second Head made into our night here. Packed with Kilimanjaro tracks though. 06.55 TOM PETTY and THE HEARTBREAKERS – I Need To Know – 7″ – Shelter – 1978 Still with a fair amount of ‘rock’ in my world at this point in time, for some reason I thought I’d had a 12″ of this but that would have been a bit daft. At just 2mins 22 plus, a fiery new wave feel that could have made it as an Elvis Costello tune. 09.17 FORMAL SPPEEDWEAR – Who Needs Spain Ball – Punch Card, LP – Melodic – 2026 “Who Needs Spain Ball?”. ‘On the surface, the single functions as a highly accessible, synth-forward New Wave track featuring the record's biggest, most infectious pop chorus. However, the title and the song’s inner mechanics are intentionally surreal, designed to “pull the rug” out from under the listener‘. – Apologies, I forgot the source. An early Talking Heads vibe going on? They’re pulling the rug even more with their merch – with the band’s name the only lettering… album t-shirts! 12.28 BIG JOANIE – It’s You – Sistahs, LP – The Daydream Library Series – 2018 So post punk! 14.48 EGOSLAVIA – Twist Face – Self-titled, (mini) LP – 9 1/2 x 16″ Records – 1982 Not that many will have debated it but I’ve always pronounced this band as ‘Egoslayvia’ and it’s only just dawned on me it was likely ‘Egoslahvia’. Better late… and a band I was introduced to by a US guy who dropped in on John Peel’s radio show somewhere in the ’80s. Very unusual for Peely to have anyone else in the studio with him but his guest was picking tracks from three or so US bands that Peely had never heard of, something that irritated the latter, slightly. 20.08 BIFFER BONKER – 4 Prong, Fucked Up, 2 Potato Thing – Biffer Bonker Is…Unabashed, download album only – ? – 2026 Anyone with a decades long history of Bedford, UK’s musical landscape stretching back to punk bands of the mid to late 70s will have knowledge of Biffer in a former life or three fronting a wealth of different bands but his present world view is available here, with something from the man for me currently getting waylaid by various postal services. ‘No god is required… ‘ Ain’t that the truth and if there isn’t a lyric sheet involved somewhere I might be requesting one :), as he’ll be back here at some point. He’s also the man who introduced me to Click Click via an early demo tape of theirs somewhere around 1984. 23.17 BROKEN SPINDLES – To Die, For Death – Fulfilled / Complete, LP – Saddle Creek – 2004 Content with having spun Induction on an earlier show, and as it turns out, rightly guessing on the album’s diversity I hadn’t been rushing to grab the physical vinyl… but here we are! One Joel Peterson, from Omaha, Nebraska. 25.35 TARWATER – 20 Miles Up – Silur, LP – Kitty-Yo – 1986 From the US to Germany and there’s a far wider breadth to this duos ‘catalogue’ than the two tracks now spun on 41 Rooms would suggest. 29.35 RIPPLE – I Don’t Know What It Is But It Sure Is Funky – 7″ – GRC – 1973 I don’t know about I Don’t Know… but with no UK release it’s unlikely our mainstream radio of the time spun this, though maybe a DJ or two down the Pilgrims or in the Anglers (Inn) Lair across the road could have. I have strong memories of hearing Willie Henderson’s Dance Master at the latter. 32.53 MARY KENT – Lost Generation – 7″ – CBS – 1969 It’s a slower, darker take than the version the song’s writer, Jim(my) Webb put out himself a year later and though Mary’s intro needed red carding for the show her version has some gravitas and feels ‘worthier’ now than it may have done to the UK’s record buyers back in 1969… what with the Vietnam war being… yep, somewhere else. The intro brings to my mind Common Sense’s Resurrection ’95. 36.57 LADY BLACKBIRD vs CROOKED MAN – Whatever His Name (Pt 1) * – Crooked Spirituals Remixes, 12″ – Foundation – 2025 She’s rightly got her soul audience but I much prefer her vocals set against some electronic goings on, as with the already 41 Rooms’ spun Athletes Of God and some remixing bods, including here, Crooked Man. They seem to give her vocals more of an edge for me. 42.18 ROBERTO RODRIGUEZ (feat. MAX C) – About This Love (Crazy P Remix) (Dub) * – 12″ – Compost Black Label – 2009 The vocals are incidental but the track just keeps building, dropping, shifting. A head-nod-a-thon of slight unease. 45.42 CLICK CLICK – Stay Out Of The Water – 12″ b-side – Rorschach Testing – 1985 Great times in the summer and autumn of ’85. Our RT label is off and running with a party at Winkles (Bedford), a P(roduction) and D(istribution) deal with Rough Trade, 500 copies of the initial yellow and blue sleeved 12″ pressing head straight to the US off the back of A-side (Sweet Stuff) getting CC Single Of The Week in Sounds and with spins on John Peel’s radio show there are one-off gigs in London, Brighton and Northampton and rehearsals are sounding great. Gig poster for 28.11.84. Part of a Rorschach Testing ad, The Catalogue #29, Aug ’85. 49.24 SIMPLE MINDS – Premonition (John Peel session: 7.1.80) – Silver Box, 5CD – Virgin – 2004 Having already seen them on the OGWT (live from Hurrah’s New York) and live at the Marquee the previous month I must have heard this session but for whatever reason I definitely didn’t record it. A ropey photo below of mine from London’s Hammersmith Palais, 26.8.80. 54.28 THE FALL – Dktr. Faustus * – Bend Sinister, LP – Beggars Banquet – 1986 It’s about time Mark E Smith (RIP) and his gang made it back here… so they have. 00.01.00 ECHO and THE BUNNYMEN – I Bagsy Yours (John Peel session: 22.8.79) – The Peel Sessions 12″ EP – 1988 This show’s third Peel session track of the era and the song renamed Monkeys in time to nestle next to the track Crocodiles months later on their debut album. I’m with ‘Bagsy’, though. Even us southerners used the term back then, though it might be best to not remember how it was being used here. 01.02.47 THE MOVE – I Can Hear The Grass Grow – 7″ – Deram – 1967 ‘An early, proto-psychedelic freakbeat masterpiece‘ in some modern day circles but a fab bit of wild pop back then. As the years rolled on though, the ‘weedier’ (sadly) Roy Wood’s guitar interjections have sounded. 01.05.52 PETULA CLARK – The Other Man’s Grass (Is Always Greener) – 7″ – Pye – 1967 Husband and wife writers, Tony Hatch and Jackie Trent (or in this particular case, Jackie Trent and Tony Hatch :)), with their key and tempo changing swirler giving ‘Our Pet’ her last Top 20 hit. So idiosyncratic it never got covered by anyone else or maybe offered as an exclusive to Petula? Either way, I bet Trent (no mean singer herself) forwarded a guide vocal version and I’d have been interested in hearing that. And it’s taken me a week to realise I’ve placed two songs next to each with ‘Grass’ in the title. Very unintentional but spooky and true. 01.08.49 BROOKE COMBE – Tears Won’t Lie * – 7″ – Fontana – 2026 I reckon Northern soul’s younger followers will dance and some older purists will very likely pick at the production but Combe and co-writer, James Skelly have nailed it, and if this song had been recorded in the mid 1960s – and maybe on the label this 7″ now pays homage to (with say Kiki Dee?) – there’d be an even bigger price tag on it than this barely out of the 2026 pressing plant £18 7′ already commands. Also, all involved in the Combe camp will have been as meticulous on the look for the dancers in the video as was MT Jones for his I Don’t Understand. Paying homage can be tough stuff. 01.11.19 TERRY CALLIER – Ordinary Joe – 7″ – Cadet – 1972 Terry and producer, Charles Stepney with a ‘skipping along the road’ feel. An even more expensive buy than the above… and I have neither. 01.15.17 CHAIRMEN OF THE BOARD – Give Me Just A Little More Time – 7″ – Invictus – 1970 INV 501. Did Invictus kick off their UK releases with a homage to Tamla Motown’s UK singles catalogue. Five years earlier the latter had also started with (TMG) 501, via The Supremes’ Stop In The Name Of Love. 01.17.57 JACKIE WILSON – I Get The Sweetest Feeling – 7″ – Brunswick – 1968 1968 for Jackie but the mid ’70s for me. Putnoe, Bedford… sunshine… Gill H… 01.20.49 THE CONTROLLERS – Somebody’s Gotta Win, Somebody’s Gotta Loose (7″ version) – 7″ – Juana – 1977 I didn’t knowingly hear this til maybe twenty years ago. With the amount of music that bypasses us, is it possible I’ve never heard the greatest song I could ever hear? 01.24.42 UMBRA MOON – Don’t Let Me Down – Download only – 2024 This Australian girl is seemingly taking longer to break out than I would have imagined but though stylistically aside of my normal listening, this is a gem. 01.28.02 SHAWN PHILLIPS – Solitude – 7″ b-side – Columbia – 1965 With my copy bought for this side alone, there are few artists I’ve come across who have been both super jaunty and deeper than deep in the songwriting department and 41 Rooms can be with Shawn in both moods. 01.30.48 JOHN and BEVERLEY MARTYN – Primrose Hill – 7″ – Warner Brothers – 1970 In 1970 approximately 1% of the American population had a passport, so aside thinking (at best) Primrose Hill maybe had some Civil War battle reference for them they were going to struggle to warm to this London landmark being referenced, even though somebody at Warners US – as opposed to their UK counterpoints – thought this Carole King-like tune had legs as a single. Sadly, they were wrong, with the promo 7″ likely more common than the stock copy. 01.33.40 TIM HARDIN – You Upset The Grace Of Living When You Lie – 7″ promo only – Verve Forecast – 1967 Yep, lyric and title of show 154 goes to… though at 1min 45 it’s nearly over by the time he’s got through singing the line. A ragged, slightly altered take of the song was part of Hardin’s performance at Woodstock but his set only got to make it to an official release of the festival in 2019. 01.35.22 JOSE FELICIANO – Dirty Work – For My Love… Mother Music, LP – RCA – 1974 It’s likely I’d be outnumbered with my thinking here but Jose’s passion makes Steely Dan’s own recorded version, sung by their then main vocalist, David Palmer, sound lack lustre. 01.38.08 VANGELIS – He-O – Earth, LP – Vertigo – 1973 Back in Vangelis’ big years I only got around to wanting his 1976 single, Pulstar but then hearing the Beatfanatics Balearic Boogie Remix of Let It Happen in 2007 led me backwards to this album and it’s the vocals (of one Robert Fitoussi) on both tracks that seem to make the difference for me. 01.42.05 STEVIE WONDER – Pastime Paradise * – Songs In The Key Of Life, 2LP – Tamla Motown – 1976 I bought the album at the time but my youthful ignorance didn’t fully take in the scale of Stevie’s accomplishment and looking now at the full tracklisting there were only six tracks I regularly played, with Pastime Paradise being one of them. The American buyers who took Songs… to No 1 in the Billboard album charts will have delved deeper. 01.45.21 KOICHI OZAKI – Petal Of The Cherry Blossom * – Novo Tempo / Koichi Ozaki: Novo Tempo Meets Eurasian Suite Vol. 2, 12″ – Eurasian Suite – 2004 If I could dip into the whole of the soul/(acid)jazz/beats etc etc world of the Japanese from the ’90s onwards there’d be a basket full of great tunes I’ve yet to hear. So little time… 01.51.22 KEITH JARRETT (TRIO) – Dancing – Changeless, LP – ECM Records – 1989 ‘Original material which is deeply subversive (though also respectfully aware) of the whole tradition of jazz as a system of improvisation on ‘the changes’… On Changeless, there are no chord progressions at all; the trio improvises each section in a single key, somewhat in the manner of an Indian raga‘. – The Penguin Guide to Jazz. ‘These pieces – not written, rehearsed, thought out, sketched, or arranged – ‘came up’ in the middle of four distinctly different concerts. Process is swifter and more accurate than thought.‘ – Keith Jarrett’s album liner notes (edited). Show 155 arrives Sept 6. Dec x The post Post Punk Plus Podcast Playlist 154 – Original upload 2.8.26 appeared first on 41Rooms.
FedRAMP has changed before. What makes the Consolidated Rules for 2026 different is that the dates are on the calendar and the fence sitters have run out of runway. Jason Ford, Co-Founder and CEO of Steel Patriot Partners, has been inside the program since Rev 3 in 2013. Michael Parisi, Chief Growth Officer, comes at it from the business side. Together they map what changes and, more usefully, what it means for the decision in front of a provider right now. So what actually changes? The program consolidates into two paths, 20X and Rev 5. FedRAMP Ready moves to legacy status. Class A, B, and C pipelines open across a thirty to sixty day window, mandatory adoption arrives January 1, and new Rev 5 certifications close on June 11, 2027. Authorized becomes certified. Jason Ford also points out where the rules live: fedramp.gov, hosted in GitHub, which means they move with a commit. Reading them once is not tracking them. Why did FedRAMP need to change at all? Michael Parisi frames it as a supply problem. Agencies and primes have been working from a limited and aging set of technologies while better tools sat outside a process that was slow, rudimentary, and expensive. The action was warranted. His follow-up question gets less airtime: if the process moved faster, did responsibility move with it, and does the stakeholder now holding that due diligence know it yet? The engineering shift is real and it is the part most teams see coming. Jason Ford describes RMF thinking giving way to continuous DevSecOps, proving compliance in real time rather than at a point in time. Vulnerability remediation is where the compression bites. CISA's updated guidance drops severity score as the driver in favor of stepped prioritization, and windows that used to run 30, 60, and 90 days now land closer to three to twenty-one. What does this cost a business past the budget line? Time and capacity. 20X is faster than a Rev 5 process that once ran eighteen months, but faster is not instant. Retraining a couple hundred users inside a thousand-person organization is not a small endeavor, and if the transition eats half of the organization's capacity for a year, that is half as much capacity aimed at the business paying for it. Jason Ford is not arguing against the move. He is arguing that disruption belongs inside the decision. Then there is the internal work almost nobody has started. Mapping an existing Rev 5 ATO scope into a new certification level is not clear-cut, and past the mapping, marketing and sales both need re-education. Michael Parisi describes building a translation layer for customers: here is what we provided before, here is what it is now, and this change came from the program rather than from any reduction in assurance. Roughly half the time, Steel Patriot Partners tells organizations not to pursue certification at all. Michael Parisi treats that as one of the more valuable things the firm does. The opposite failure shows up just as often, with companies preparing to spend heavily on 20X because it sounds quicker and cheaper, when the agency or prime they are chasing expects a certification level. A lower bar only helps if the buyer accepts it. Where should a business start? With the business conversation. Michael Parisi notes the answer does not have to be yes or no today; it can be a maybe with defined trigger points. Jason Ford closes on posture: come with an open mind, and do not hand a multi-year commitment to a language model whose guardrails and training are not built for that call. Or, shorter: don't wait, and don't go it alone. Steel Patriot Partners built a three-question starting point for that first conversation at https://www.steelpatriotpartners.com/find-your-path. This is a Brand Story. A Brand Story is a ~35-40 minute in-depth conversation designed to tell the complete story of the guest, their company, and their vision. Learn more: https://www.studioc60.com/creation#full GUESTS Jason Ford, Co-Founder and Chief Executive Officer, Steel Patriot Partners On LinkedIn: https://www.linkedin.com/in/jason-ford-5ab206/ Michael Parisi, Chief Growth Officer, Steel Patriot Partners On LinkedIn: https://www.linkedin.com/in/michael-parisi-4009b2261/ RESOURCES Learn more about Steel Patriot Partners: https://www.steelpatriotpartners.com/ FedRAMP's Consolidated Rules for 2026: What It Means for Cloud Providers: https://resources.steelpatriotpartners.com/fedramps-consolidated-rules-for-2026 Find Your Path, a three-question starting point for ISO, CMMC, and FedRAMP decisions: https://www.steelpatriotpartners.com/find-your-path Complimentary ROI Workshop: https://www.steelpatriotpartners.com/roi-workshop Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS jason ford, michael parisi, steel patriot partners, sean martin, brand story, brand marketing, marketing podcast, fedramp, fedramp consolidated rules for 2026, fedramp 20x, rev 5, fedramp certification classes, cloud service provider compliance, federal compliance, cisa vulnerability remediation, continuous monitoring, devsecops, ato, 3pao, govramp, cmmc, grc, federal marketplace, compliance roi Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
What happens when an unconstrained OpenAI model goes rogue and hacks into Hugging Face, breaching real-world security boundaries? This episode unpacks a watershed moment for AI safety that has everyone in cybersecurity talking. OpenAI's unconstrained internal testing AI got loose, attacked Hugging Face. We hear from OpenAI, Hugging Face and Andrew Ng. GRC went off the air Friday. Was GRC hacked? What happened? The Linux kernel project repairs 442 CVEs in a single batch. LG's PC monitors cause PC adware installation. France bans all social media access below age 15. WordPress' recent CRITICAL vulnerability claims victims. Amazing details about "Rocky" from Andy Weir. The new AI exploit ranking benchmark that caused the breakout Show Notes - https://www.grc.com/sn/SN-1089-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: adaptivesecurity.com XBOW.com cohesity.com/Resilience threatlocker.com/twit
What happens when an unconstrained OpenAI model goes rogue and hacks into Hugging Face, breaching real-world security boundaries? This episode unpacks a watershed moment for AI safety that has everyone in cybersecurity talking. OpenAI's unconstrained internal testing AI got loose, attacked Hugging Face. We hear from OpenAI, Hugging Face and Andrew Ng. GRC went off the air Friday. Was GRC hacked? What happened? The Linux kernel project repairs 442 CVEs in a single batch. LG's PC monitors cause PC adware installation. France bans all social media access below age 15. WordPress' recent CRITICAL vulnerability claims victims. Amazing details about "Rocky" from Andy Weir. The new AI exploit ranking benchmark that caused the breakout Show Notes - https://www.grc.com/sn/SN-1089-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: adaptivesecurity.com XBOW.com cohesity.com/Resilience threatlocker.com/twit
What happens when an unconstrained OpenAI model goes rogue and hacks into Hugging Face, breaching real-world security boundaries? This episode unpacks a watershed moment for AI safety that has everyone in cybersecurity talking. OpenAI's unconstrained internal testing AI got loose, attacked Hugging Face. We hear from OpenAI, Hugging Face and Andrew Ng. GRC went off the air Friday. Was GRC hacked? What happened? The Linux kernel project repairs 442 CVEs in a single batch. LG's PC monitors cause PC adware installation. France bans all social media access below age 15. WordPress' recent CRITICAL vulnerability claims victims. Amazing details about "Rocky" from Andy Weir. The new AI exploit ranking benchmark that caused the breakout Show Notes - https://www.grc.com/sn/SN-1089-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: adaptivesecurity.com XBOW.com cohesity.com/Resilience threatlocker.com/twit
What happens when an unconstrained OpenAI model goes rogue and hacks into Hugging Face, breaching real-world security boundaries? This episode unpacks a watershed moment for AI safety that has everyone in cybersecurity talking. OpenAI's unconstrained internal testing AI got loose, attacked Hugging Face. We hear from OpenAI, Hugging Face and Andrew Ng. GRC went off the air Friday. Was GRC hacked? What happened? The Linux kernel project repairs 442 CVEs in a single batch. LG's PC monitors cause PC adware installation. France bans all social media access below age 15. WordPress' recent CRITICAL vulnerability claims victims. Amazing details about "Rocky" from Andy Weir. The new AI exploit ranking benchmark that caused the breakout Show Notes - https://www.grc.com/sn/SN-1089-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: adaptivesecurity.com XBOW.com cohesity.com/Resilience threatlocker.com/twit
What happens when an unconstrained OpenAI model goes rogue and hacks into Hugging Face, breaching real-world security boundaries? This episode unpacks a watershed moment for AI safety that has everyone in cybersecurity talking. OpenAI's unconstrained internal testing AI got loose, attacked Hugging Face. We hear from OpenAI, Hugging Face and Andrew Ng. GRC went off the air Friday. Was GRC hacked? What happened? The Linux kernel project repairs 442 CVEs in a single batch. LG's PC monitors cause PC adware installation. France bans all social media access below age 15. WordPress' recent CRITICAL vulnerability claims victims. Amazing details about "Rocky" from Andy Weir. The new AI exploit ranking benchmark that caused the breakout Show Notes - https://www.grc.com/sn/SN-1089-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: adaptivesecurity.com XBOW.com cohesity.com/Resilience threatlocker.com/twit
What happens when an unconstrained OpenAI model goes rogue and hacks into Hugging Face, breaching real-world security boundaries? This episode unpacks a watershed moment for AI safety that has everyone in cybersecurity talking. OpenAI's unconstrained internal testing AI got loose, attacked Hugging Face. We hear from OpenAI, Hugging Face and Andrew Ng. GRC went off the air Friday. Was GRC hacked? What happened? The Linux kernel project repairs 442 CVEs in a single batch. LG's PC monitors cause PC adware installation. France bans all social media access below age 15. WordPress' recent CRITICAL vulnerability claims victims. Amazing details about "Rocky" from Andy Weir. The new AI exploit ranking benchmark that caused the breakout Show Notes - https://www.grc.com/sn/SN-1089-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: adaptivesecurity.com XBOW.com cohesity.com/Resilience threatlocker.com/twit
What happens when an unconstrained OpenAI model goes rogue and hacks into Hugging Face, breaching real-world security boundaries? This episode unpacks a watershed moment for AI safety that has everyone in cybersecurity talking. OpenAI's unconstrained internal testing AI got loose, attacked Hugging Face. We hear from OpenAI, Hugging Face and Andrew Ng. GRC went off the air Friday. Was GRC hacked? What happened? The Linux kernel project repairs 442 CVEs in a single batch. LG's PC monitors cause PC adware installation. France bans all social media access below age 15. WordPress' recent CRITICAL vulnerability claims victims. Amazing details about "Rocky" from Andy Weir. The new AI exploit ranking benchmark that caused the breakout Show Notes - https://www.grc.com/sn/SN-1089-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: adaptivesecurity.com XBOW.com cohesity.com/Resilience threatlocker.com/twit
What happens when an unconstrained OpenAI model goes rogue and hacks into Hugging Face, breaching real-world security boundaries? This episode unpacks a watershed moment for AI safety that has everyone in cybersecurity talking. OpenAI's unconstrained internal testing AI got loose, attacked Hugging Face. We hear from OpenAI, Hugging Face and Andrew Ng. GRC went off the air Friday. Was GRC hacked? What happened? The Linux kernel project repairs 442 CVEs in a single batch. LG's PC monitors cause PC adware installation. France bans all social media access below age 15. WordPress' recent CRITICAL vulnerability claims victims. Amazing details about "Rocky" from Andy Weir. The new AI exploit ranking benchmark that caused the breakout Show Notes - https://www.grc.com/sn/SN-1089-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: adaptivesecurity.com XBOW.com cohesity.com/Resilience threatlocker.com/twit
Send us Fan MailIn this episode of The Route to Networking, Till Heinimann is joined by Michael Masal, Account Executive at Archer Integrated Risk Management. Having built a career spanning IT support, telecommunications, network engineering, cybersecurity and GRC before moving into technology sales, Michael shares how his technical background has shaped his customer-first approach to sales.Michael reflects on his career journey, from earning his first opportunity through persistence and continuous learning to making the transition from engineering into sales. He discusses the realities of working in a target-driven environment, why understanding technology gives him a unique perspective with customers, and how solving problems, rather than simply selling products, has become the foundation of his success.Throughout the conversation, Michael explores the importance of building trust, becoming a trusted advisor and developing the qualities that matter most in technology sales, including resilience, research and active listening. He also shares his thoughts on standing out in an increasingly competitive market, the growing role of AI, and why genuine relationships remain one of the biggest differentiators in the industry.The episode closes with a quick-fire round covering career development, resilience, continuous learning and the advice Michael would give to anyone looking to build a successful career in technology and sales.
In this episode, Ryan Williams Sr. interviews Brian Albertson, a GRC architect and president of the ISACA Atlanta chapter, exploring his journey in cybersecurity, the importance of community and mentorship, and the future of AI and cybersecurity. Brian's LinkedIn: https://www.linkedin.com/in/brianalbertson/ Preorder Brian's upcoming book series: The Hive: A Fable of Fear, Governance, and Transformation – Volume 1 - https://www.routledge.com/The-Hive-A-Fable-of-Fear-Governance-and-Transformation-Volume-1/Albertson/p/book/9781041240860 The Hive: A Fable of Fear, Governance, and Transformation – Volume 2 - https://www.routledge.com/The-Hive-A-Fable-of-Fear-Governance-and-Transformation-Volume-2/Albertson/p/book/9781041366966 Please LISTEN
We built what we are calling the Digital Village SDK which helps corporate web and app designers, parents and educators stay compliant with GRC laws, and create a safer on and offline experience for kids.FIND HER HERE:X and LinkedIn : LisaManns6AuthentiKid everywhere elsehttps:://www.authentikid.comOUR FIRST EPISODE 6/14/2024:https://youtu.be/aUufP8urOgk
Cloud ERP is reshaping how organizations manage risk. In this episode with EY, we explore why security, governance, and AI must be built into ERP transformation from day one, not added later.=====As organizations accelerate their move to cloud ERP, managing risk is becoming less about reacting to issues and more about designing secure, resilient processes from the start. In this episode, EY's Natalie Freedline and Dan Crawley discuss how cloud transformations are reshaping risk management, from understanding the shared responsibility model to embedding security, governance, and automated controls early in every implementation. The conversation explores why successful ERP transformations depend as much on people, processes, and clear ownership as they do on technology. The speakers explain how organizations can strengthen governance, prepare teams for change, and build trusted data foundations that support long-term business resilience. Download Episode TranscriptUseful Links: SAP Cloud ERPSAP-EY Allience5 common compliance myths when moving to S/4HANAThe role of governance in Continuous Controls Monitoring enablementDisclaimer: The views reflected in this video are the views of the author and do not necessarily reflect the views of the global EY organization or its member firms.Follow Us on Social Media!SAP S/4HANA Cloud ERP: LinkedIn=====Guest 1: Dan Crawley, SAP Security and Identity Architect at EYDan Crawley is an SAP Security and Identity Architect with more than 15 years of experience providing strategic leadership and delivering scalable, maintainable solutions in application security and identity management within the SAP ERP space. Having delivered complex implementations and enterprise transformations across many different industries, he enjoys the challenges of learning new technologies and implementing them to provide more compliant and efficient solutions. Guest 2: Natalie Freedline - Principal, Technology Consulting, Ernst & Young LLP | EY - GlobalNatalie has more than 18 years of Technology consulting experience serving Industrial Products and Consumer Products clients undergoing transformations. Starting her career in audit, Natalie has a wide range of experience assisting clients with SAP and Oracle process and controls enablement/optimization, application security, business transformation, governance, risk and compliance (GRC) technology enablement and enterprise risk management (including IT risk). Natalie has delivered strategic programs for SAP S/4 HANA transformations and specializes in quantifying the business case to drive efficiencies and lower the cost of compliance through analytics and monitoring, security and GRC technologies.In addition to helping clients deploy risk and compliance programs, Natalie holds a leadership role managing the Risk Technology team focused on SAP of over 100 resources to streamline growth, collaboration, knowledge sharing and improve the quality of engagement delivery.Host 1: Richard Howells, SAPRichard Howells has been working in the Supply Chain Management and Manufacturing space for over 30 years. He is responsible for driving the thought leadership and awareness of SAP's ERP, Finance, and Supply Chain solutions and is an active writer, podcaster, and thought leader on the topics of supply chain, Industry 4.0, digitization, and sustainability.Follow Richard Howell on LinkedIn and XHost 2: Oyku Ilgar, SAPOyku Ilgar is a marketer and thought leader specializing in SAP's digital supply chain and ERP solutions since 2017. As a marketer, blogger, and podcaster, she creates engaging content that highlights innovative SAP technologies and explores key topics including business trends, AI, Industry 4.0, and sustainability.Follow Oyku Ilgar on LinkedIn and SAP Community
All links and images can be found on CISO Series This week's episode is hosted by David Spark, producer of CISO Series, and Andy Ellis, principal of Duha. Joining them is Tim Callahan, CIO/CISO, AFLAC. In this episode: Week one is the wrong time to overreach Nobody has the AI playbook Vulnerability management wasn't built for this clock Stop blaming the human, fix the system A huge thanks to our sponsor, Vanta No, it's not your imagination. Risk and regulations ARE ramping up—and customers now expect proof of security just to do business. That's why Vanta is a game-changer. Vanta automates your compliance process and brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Companies like Ramp and Writer spend 82% less time on audits with Vanta. That's not just faster compliance—it's more time for growth. Get started at Vanta.com/CISO.
Link to the episode This week's Department of Know is hosted by Rich Stroffolino, with guests Davi Ottenheimer, principal, Flying Penguin, and Chris Ray, field CTO, GigaOm. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. Huge thanks to our sponsor, Vanta Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines.
Interpol's fraud sweep goes global China flags Claude Code Old GitHub accounts, new tricks Get the show notes here: https://cisoseries.com/cybersecurity-news-interpols-global-fraud-sweep-chinas-claude-code-flag-old-github-account-tricks/ Thanks to our episode sponsor, Vanta Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines.
Mexico's first cyber test gets tested Snoops break into Roundcube mailservers Cash App owner pays up over lax security Get the show notes here: https://cisoseries.com/cybersecurity-news-mexicos-big-cyber-test-roundcube-mailserver-snooped-on-cash-app-found-lax/ Thanks to our episode sponsor, Vanta Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines.
The UK's Cyber Pledge and Cyber Shield Millions exposed in Japanese telco attack China looking to curb overseas model access Get the show notes here: Thanks to our episode sponsor, Vanta Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines.
Suspected China-Nexus hackers use fake Indian tax filing utility to deploy DcRAT Prompt injection attacks trick AI Agents into making crypto payments France to stop certifying products without quantum-safe encryption Get the show notes here: https://cisoseries.com/cybersecurity-news-india-tax-rat-prompt-injection-crypto-scam-france-pushes-quantum-safe/ Thanks to our episode sponsor, Vanta Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines.
JadePuffer ransomware used AI agent to automate entire attack AdaptHealth suffers cyberattack UK's National Cyber Action Plan launch delayed by political leadership crisis Get the show notes here: https://cisoseries.com/cybersecurity-news-first-ai-ransomware-adapthealth-suffers-cyberattack-uk-cyber-plan-delayed/ Thanks to our episode sponsor, Vanta Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines.
Stop chasing certifications without direction. If you're trying to break into cybersecurity or grow into a leadership role, this is the real career map. In this video, I walk you through the 5 most in-demand cybersecurity career paths - from hacker to identity, cloud, GRC, and CISO. I've worked in all of them over the last 20 years, and I'm giving you the no-BS truth on what each role really looks like, what hiring managers want in 2025, and what it actually takes to succeed.What we'll cover in this video: what penetration testing really is (Hint: it's not just hacking), why IAM (Identity & Access Management) is exploding in demand, the real-world impact (and pressure) of cloud security leadership, how GRC & privacy are fast tracks to C-suite for legal/finance folks, what it actually takes to become a successful CISO, and the truth nobody tells you: It's not where you start—it's how you grow.This isn't another generic “top 5 jobs” list. This is real experience, real insights, and a real roadmap for building a cybersecurity career that actually leads to leadership.Looking to go from chaos and unpredictability to resilience in the world of AI? Start here with The Predictability Factor newsletter at The Monica Talks Cyber (https://www.monicatalkscyber.com).
The risks keeping CFOs up at night aren't new. But the way they connect, accelerate, and amplify each other is. In the final episode of their three-part GRC series, Embark's Adam Olsen and Managing Director Allison Bradshaw break down the risk landscape organizations are navigating right now, and what it actually takes to get ahead of it.In this episode:AI governance frameworks: how to build tiered oversight proportional to risk, from chatbots to credit decisions, without slowing down adoptionThe "black box" problem: why explainability and transparency are now regulatory expectations, not just best practicesCybersecurity as enterprise risk: how to reframe board conversations around cyber exposure and what ransomware preparedness actually requiresIdentity, access, and the human element: why phishing remains the most common attack vector and what effective security culture looks like beyond annual trainingData privacy in a fragmented regulatory environment: GDPR, CCPA, and the state-by-state patchwork, plus why privacy and cybersecurity programs are stronger when built togetherThird-party and vendor risk: how to apply a risk-based approach across a complex vendor ecosystem, including fourth-party exposure and ESG considerations in the supply chainThe regulatory change problem: AI regulation, SEC cyber disclosure rules, ESG reporting requirements, and how to build compliance capabilities that don't start from scratch every timeWhy integrated risk management isn't optional: how AI, cyber, privacy, and regulatory risks connect in ways siloed functions will always missTo connect with Allison or learn more about how Embark approaches GRC, visit embarkwithus.com.
In Episode 107 of the Cybersecurity Readiness Podcast Series, Dr. Dave Chatterjee is joined by Richa Kaul, Founder and Chief Executive Officer of Complyance and a former public sector technology policy leader, to address one of the most consequential misunderstandings in enterprise security governance: the assumption that compliance equals security.Opening with two recent and high-profile incidents — the May 2025 ransomware attack on Marks & Spencer, which halted online operations for weeks and generated estimated losses exceeding £300 million, and a concurrent third-party support provider compromise that exposed customer data across multiple platforms including Discord — Dr. Chatterjee establishes the episode's central premise: organizations that invest heavily in GRC platforms, generate dashboards full of green indicators, and maintain formal compliance certifications can still be catastrophically breached. The gap between compliance and security is not theoretical. It is structural and where attackers operate.Kaul explains the root cause with precision. Traditional GRC tools were built to centralize data and automate workflow notifications — functions that reduce administrative burden but do not reduce risk. The result is a compliance theater dynamic in which organizations check boxes, pass periodic audits, and receive certifications that say little about their actual security posture. The Complyance platform is built on a different philosophy: compliance with standards should be a byproduct of genuinely good security practices, not the objective in its own right.The episode explores the architecture of intelligent GRC: continuous monitoring across all integrated sources of truth, agentic AI that automates evidence collection and remediation guidance, tiered third-party risk programs that apply scrutiny proportional to vendor criticality, and risk quantification frameworks that translate security signals into board-level governance decisions. Kaul is equally precise about what GRC platforms cannot do: they cannot substitute for operational security teams, and no platform — however sophisticated — can protect an organization whose leadership has not committed to genuine risk reduction as the governing objective.Analyzed through Dr. Chatterjee's Commitment–Preparedness–Discipline (CPD) framework, the conversation reframes GRC from a compliance function into a governance discipline. The episode's central message is neither technical nor vendor-specific: the organizations that will withstand the next breach are not those with the most compliance certifications — they are those that have claimed ownership of the problem, built the continuous processes to address it, and institutionalized the discipline to keep those processes operating after the audit is over.To access and download the entire podcast summary with discussion highlights - https://www.dchatte.com/episode-107-compliant-but-exposed-rethinking-grc-for-real-security/Connect with Host Dr. Dave ChatterjeeLinkedIn: https://www.linkedin.com/in/dchatte/ Website: https://dchatte.com/Books PublishedThe DeepFake ConspiracyCybersecurity Readiness: A Holistic and High-Performance ApproachArticles & Cases PublishedChatterjee, D. (2026). Root: Automating the Remediation Gap, Ivey Publishing, Jan 7, 2026.Ramasastry, C. and Chatterjee, D. (2025). Trusona: Recruiting For The Hacker Mindset, Ivey Publishing, Oct 3, 2025.Chatterjee, D. and Leslie, A. (2024). “Ignorance is not bliss: A human-centered whole-of-enterprise approach to cybersecurity preparedness,” Business Horizons, Accepted on Oct 29, 2024.Isik, O., Chatterjee, D., and Lourenco, D.A. (2024). “Getting Cybersecurity Right,” California Management Review — Insights, Accepted for Publication, July 8, 2024. Chatterjee, D. (2023). “Mission critical – How American Cancer Society successfully and securely migrated to the cloud amid the pandemic,” I by IMD, March 13, 2023.Chatterjee, D. (2022). “Preventing security breaches must start at the top,” I by IMD, September 28, 2022, Institute for Management Development, Lausanne, SwitzerlandChatterjee, D. (2022). “Making Cybersecurity Readiness Mainstream,” Executive Blog Post, NETSPI, March 1, 2022Benz, M. and Chatterjee, D. (2020). “Calculated Risk? A Cybersecurity Evaluation Tool for SMEs,” Business Horizons, available online from May 4, 2020Chatterjee, D. (2019). “Should Executives Go To Jail Over Cyber Attacks,” Journal of Organizational Computing and Electronic Commerce, Vol 29, Issue 1, pp. 1-3.Abraham, C., Chatterjee, D., and Sims, R. (2019). “Muddling through cybersecurity: Insights from the U.S. healthcare industry,” Business Horizons, July 2019.
This episode features Jim Bowie, VP and CISO at Tampa General Hospital, joined by co-host Courtney Guss, Director of Crisis Management at Semperis.Jim began his career in EMS and law enforcement before moving into cybersecurity, giving him a grounded understanding of how operational continuity and human outcomes intersect during a crisis. At Tampa General, he leads teams spanning network security, operations, IAM, and GRC, and has built a training culture centered on adversarial simulation, monthly range of exercises, and regular DR drills.In this episode, Jim argues that rehearsal is the highest-leverage move for resource-constrained security teams and explains why an outage is an outage regardless of cause. He covers why identity is consistently the weak point in every simulation and why the relationships you build before an incident are the ones that matter most.If your organization is still treating recovery as an afterthought, this episode will change how you think about it.Guest BiosJim Bowie Jim Bowie is the Vice President and Chief Information Security Officer (CISO) at Tampa General Hospital (TGH). Jim is an accomplished leader with decades of cybersecurity experience and leadership in threat hunting, incident response, threat intelligence, and security operations. He is a strategist with demonstrated ability to bridge between security, infrastructure, and business needs and has experience leading multiple areas in information technology, including cloud infrastructure and security, with exceptional results in employee engagement and productivity.Courtney Guss Courtney Guss is the Director of Crisis Management at Semperis, with over 20 years of experience spanning cybersecurity, risk management, and crisis response. She specializes in helping organizations navigate high-impact incidents—from ransomware attacks to regulatory reporting—by orchestrating clear, business-aligned response strategies. Courtney is passionate about transforming crisis chaos into operational clarity.Guest Quote "You absolutely need a technology component to your program. But at the end of the day, that tech is surfaced to a person in the chair. And if that person's not up to speed, there's no amount of tech that's going to help them and help you get through a crisis."Time stamps 01:45 Meet Jim Bowie: Veteran Cybersecurity Leader 02:38 Healthcare Crisis Management Challenges 04:18 Training Beats Budget 06:46 Clinician Buy-In 07:00 Community Ripple Effects 10:23 Mutual Aid Agreements 12:45 Hurricane Drills as Cyber Drills 14:39 Adversarial Practice Culture 17:30 Making Training Time Non-Negotiable 20:14 Recovery Focus and Identity 26:35 Conclusion and Final ThoughtsSponsor The HIP Podcast is brought to you by Semperis, the leader in identity-driven cyber resilience for the hybrid enterprise. Trusted by the world's leading businesses, Semperis protects critical Active Directory and Entra ID environments from cyberattacks, ensuring rapid recovery and business continuity when every second counts. Visit semperis.com to learn more.LinksConnect with Jim on LinkedInConnect with Courtney on LinkedInConnect with Sean on LinkedInDon't miss future episodesLearn more about Semperis
Podcast: PrOTect It All (LS 27 · TOP 10% what is this?)Episode: Cybersecurity vs Resilience: What Business Leaders Need to Know About Managing RiskPub date: 2026-06-15Get Podcast Transcript →powered by Listen411 - fast audio-to-text and summarization Cybersecurity isn't the goal. Business resilience is. In this episode of Protect It All, host Aaron Crow sits down with Lee Ward to explore why organizations need to move beyond compliance checklists and start focusing on what really matters: the ability to withstand, recover from, and adapt to disruption. Drawing on more than two decades of experience spanning the UK civil service, logistics, supply chain operations, and governance, risk, and compliance (GRC), Lee shares practical insights on helping boards and executives understand cyber risk in business terms. Together, Aaron and Lee discuss the realities of risk acceptance, operational technology challenges, patching constraints, and why resilience not perfection should be the ultimate objective of any cybersecurity program. You'll learn: Why resilience is a better business objective than security alone How to communicate cyber risk to boards and executive leadership The difference between compliance and meaningful risk reduction Practical approaches to OT security, patching, and operational constraints Why risk acceptance is a critical leadership responsibility How logistics and supply chain organizations approach resilience planning Whether you're a security leader, executive, risk manager, or OT practitioner, this episode provides practical guidance for building organizations that can continue operating when disruptions inevitably occur. Tune in to learn why resilience not just security is becoming the defining metric of successful organizations. Key Moments: 03:59 Understanding Cyber Risks for Leaders 07:16 Discussing non-cyber risks to services 11:12 Understanding business impact of cyber risk 15:45 Evaluating Cybersecurity Risks 19:37 Understanding installation complexities 21:15 Global risks affecting business resilience 24:27 Discussing regulation impacts on business 29:30 People's drive to make good choices 31:27 Industrial control systems demo at DEFCON 34:43 Limitations of technical security 38:06 The future of AI and education About the guest : Lee Ward is a Governance, Risk Management, and Compliance (GRC) leader with more than 20 years of experience spanning the UK civil service, logistics, supply chain operations, and cybersecurity. Specializing in business resilience, risk governance, and operational technology security, Lee helps organizations translate complex cyber risks into meaningful business decisions. He is passionate about moving beyond compliance-driven security programs and helping leaders build resilient organizations that can adapt, recover, and thrive in an increasingly uncertain world. How to connect Lee: https://www.linkedin.com/in/lee-ward-882a54244/ Learn more about PrOTect IT All: Email: info@protectitall.co Website: https://protectitallpod.com/ep110 X: https://twitter.com/protectitall YouTube: https://www.youtube.com/@PrOTectITAll FaceBook: https://facebook.com/protectitallpodcast To be a guest or suggest a guest/episode, please email us at info@protectitall.co Please leave us a review on Apple/Spotify Podcasts: Apple - https://podcasts.apple.com/us/podcast/protect-it-all/id1727211124 Spotify - https://open.spotify.com/show/1Vvi0euj3rE8xObK0yvYi4 The podcast and artwork embedded on this page are from Aaron Crow, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.
Today, we're diving deep into the world of quantum computing and its far-reaching implications for cybersecurity, risk, and digital resilience. Join Frank La Vigne and Candace Gillhoolley as they sit down with Chris Basener, a leading GRC advisor specializing in post-quantum cryptography. Together, they unravel the challenges organizations face in preparing for the inevitable arrival of quantum computers powerful enough to threaten today's encryption, discuss the realities and misconceptions surrounding post-quantum cryptography, and explore practical strategies for building long-term digital resilience.We'll explore the urgent need for cryptographic agility, the complexities of migrating to new standards, and why every organization—from banks to manufacturers—must start planning now, despite the uncertainty around when quantum threats will fully materialize. Plus, Chris Basener shares insights on talent shortages, project management for quantum readiness, and how companies can move from awareness to action. If you're curious about the intersection of quantum technology, cybersecurity, and strategic risk management, you won't want to miss this conversation!LinksChris' LinkedIn profile - https://www.linkedin.com/in/chris-basener/Time Stamps00:00 Quantum computing and cryptography risks04:04 Understanding Mosca's Theorem Basics08:02 Quantum computing in finance12:10 Concerns about quantum cryptography adoption15:58 Importance of Strategic Planning19:30 Challenges of Early Adoption23:01 Building cyber resilience with agility26:55 Challenges in Manufacturing Security28:31 Importance of national security31:49 Future risks of data security35:30 Discussing hybrid algorithm security41:15 Discussing cybersecurity frameworks43:11 Securing funding through governance48:47 Creating a post-quantum cryptography course50:04 Post quantum cryptography course53:42 Connecting on LinkedIn for courses
Chinese cybercrime group sets record pace Cisco warns of critical Unified CM flaw with PoC exploit code Hackers spied on a stock exchange executive's Outlook mailbox for five months Get the show notes here: https://cisoseries.com/cybersecurity-news-chinese-cybercrime-group-cisco-cm-flaw-cisa-faces-changes/ Huge thanks to our episode sponsor, Vanta Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta [rhymes with Santa] Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines.
This week's Department of Know is hosted by Rich Stroffolino, with guests Robb Dunewood, host, Daily Tech News Show, and David Cross, CISO, Atlassian. Get the show notes here. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines.
Law enforcement cracks down on illegal streamers The European Commission releases digital sovereignty plan The startup costs for US cyber force Get the show notes here: https://cisoseries.com/cybersecurity-news-illegal-streamers-eu-digital-sovereignty-cost-of-a-cyber-force/ Huge thanks to our episode sponsor, Vanta Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta [rhymes with Santa] Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines.
Russia claims officials' surveillance Project Glasswing access expands CISA flags two-year-old Oracle flaw Get the show notes here: https://cisoseries.com/cybersecurity-news-russia-claims-officials-surveillance-project-glasswing-expands-cisa-flags-two-year-old-oracle-flaw/ Huge thanks to our episode sponsor, Vanta Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta [rhymes with Santa] Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines.
Meta AI hands over Instagram account access Dutch police dismantle huge botnet RedHat packages get backdoored Get the show notes here: https://cisoseries.com/meta-ai-hands-over-instagram-access-dutch-police-dismantle-botnet-redhat-packages-backdoored/ Huge thanks to our episode sponsor, Vanta Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta [rhymes with Santa] Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines.
Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks ChatGPT share links used to host fake outage pages to deliver malware Federal audit reveals NIST's NVD problems Get the show notes here: https://cisoseries.com/cybersecurity-news-globalprotect-vpn-exploited-chatgpt-share-links-exploits-feds-criticize-nist/ Huge thanks to our episode sponsor, Vanta Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta [rhymes with Santa] Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines.
Send us Fan MailIn this episode of the B2B Go-To-Market Leaders Podcast, Vijay Damojipurapu sits down with PV Bóccasam, advisor to private equity firms and veteran operator across enterprise software, venture-backed startups, and category-defining companies, to explore a radically different way of thinking about go-to-market.PV argues that go-to-market is not about sales motions, pipeline generation, or even positioning frameworks—it's about one thing: reducing buyer anxiety and lowering the perceived risk of change.Drawing from decades of experience building and scaling enterprise software companies across identity governance, GRC, enterprise risk management, and private equity-backed transformations, PV shares how the best GTM leaders think less about “selling” and more about helping customers justify, adopt, and communicate measurable value internally.They dive into:Why GTM should focus on reducing customer risk, not maximizing seller activity.The difference between customer convictions and customer incentives—and why both matter.Why measurable proof is the only reliable way to break buyer inertia.How enterprise software companies should rethink value delivery in the AI era.Why AI should reduce operational uncertainty—not create more chaos.The evolution from product-led to sales-led to partner-led GTM motions.Why “platform” messaging fails for most enterprise SaaS companies.How modern AI-native SaaS products are becoming systems of orchestration, not systems of record.The importance of helping customers retell your value proposition internally.Why enterprise GTM leaders must become the clearest thinkers during periods of uncertainty.How private equity firms should approach AI adoption through organizational redesign, not just cost-cutting.And why long-term impact matters more than short-term velocity in building a career and a company.PV's central insight is simple but powerful:Customers don't buy software—they buy reduced uncertainty, measurable outcomes, and confidence in the future state.This episode is a deep philosophical and operational masterclass on enterprise go-to-market strategy, AI adoption, organizational design, and what it truly means to build trust at scale.Connect with Vijay Damojipurapu on LinkedInConnect with PV Boccasam on LinkedInBrought to you by: stratyve.com
All links and images can be found on CISO Series This week's CISO Series Podcast features David Spark, producer of CISO Series, and Andy Ellis, principal of Duha. Joining us is our sponsored guest, Jadee Hanson, CISO, Vanta. In this episode: The compliance receipt nobody reads Who signs off on the AI that wrote the code The agent that wouldn't stop The questionnaire that should not exist A huge thanks to our sponsor, Vanta Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.
Most GRC functions were built a decade ago in response to SOX or a single risk event. The world has changed. The function often hasn't. In this episode, Embark's Adam Olsen is joined by Managing Director Allison Bradshaw to break down what it actually takes to modernize governance, risk, and compliance for the environment organizations are operating in today.In this episode:Why siloed GRC functions create blind spots, audit fatigue, and hidden costs that far exceed what shows up on a budget lineWhat an integrated GRC model looks like in practice: common risk taxonomy, shared technology, and coordinated activities across all three lines of defenseHow to make the business case for modernization, including the 20 to 30 percent cost reduction organizations typically see when duplication is eliminatedTechnology enablement beyond the platform: continuous controls monitoring, workflow automation, and real-time integration with your ERP and source systemsHow modern GRC transforms SOX from a seasonal sprint into a year-round process, with a real-world example of an $800K compliance budget getting restructuredWhere AI fits into GRC today: risk identification, anomaly detection, and compliance monitoring, plus the governance frameworks organizations need to manage AI as a risk in its own rightWhat a risk-intelligent culture actually looks like, and why most GRC transformations fail on culture long before they fail on technologyHow to start without boiling the ocean: practical guidance on sequencing a GRC modernization roadmapTo connect with Allison or learn more about Embark's GRC maturity assessment, visit embarkwithus.com.
What if your engineering calculations secretly sabotaged your nation's best efforts? This week, we reveal how a newly uncovered 21-year-old NSA rootkit quietly corrupted scientific research in hostile states and why it changes everything you think you know about cyberwarfare. Bitwarden's CLI hit with a supply-chain attack. Commercial routers in Iran fail shortly before the war. Meta logging all employee activity to train replacement AI. GRC's DNS Benchmark Release 5. Two miscellaneous AI thoughts. A bunch of terrific listener feedback. Unraveling the diabolical history of "fast16.sys" Show Notes - https://www.grc.com/sn/SN-1076-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: doppel.com threatlocker.com/twit material.security cyberhoot.com/securitynow guardsquare.com