Podcasts about Information security

  • 1,099PODCASTS
  • 3,761EPISODES
  • 38mAVG DURATION
  • 5WEEKLY NEW EPISODES
  • Aug 5, 2026LATEST
Information security

POPULARITY

20192020202120222023202420252026

Categories



Best podcasts about Information security

Show all podcasts related to information security

Latest podcast episodes about Information security

The ISO Show
#256 BedX – Supporting Businesses Looking To Tender For Universal Bedfordshire and Beyond

The ISO Show

Play Episode Listen Later Aug 5, 2026 45:06


There has been a lot of buzz around the upcoming Universal Project currently in development in Bedfordshire. It's estimated to generate around £50 billion in economic benefit, along with the creation of 20,000 jobs during its construction, and a further 8,000 jobs once it's operational. It's undoubtedly brought a lot of eyes towards the smallest county in the UK, and with it a lot of opportunity for local businesses to get involved with not only the main theme park itself, but the surrounding projects that aim to make Bedford and beyond a thriving tourist destination. For those wondering how to get involved, there is a dedicated group looking to share knowledge and tools to get you tender ready. In this episode, we are joined by Lorna Leonard, Managing Director of LBS, and Kirsty Maynard, Commercial Director of THSP, who are instrumental in running BedX, a group dedicated to sharing knowledge and tools to help businesses get tender ready for Universal and beyond. Listen to our roundtable discussion as we dive into why BedX was created, its main drivers, how it can support local businesses and how you can get involved. You'll learn ·      Who are Kirsty and Lorna? ·      What is BedX? ·      What were the main drivers behind the creation of BedX? ·      What are the group's main aims? ·      What are Kirsty and Lorna's roles within the group? ·      How can businesses get involved with and benefit from BedX? ·      What can businesses be doing now to get tender ready for Universal?     Resources ·      Bedfordshire Chamber of Commerce - BedX ·      BedX Webinars ·      Tender Diagnostic ·      Kirsty Maynard LinkedIn ·      Lorna Leonard LinkedIn   In this episode, we talk about: [02:25] Episode Summary – Stephanie Churchman and Carly Mowbray are joined by Lorna Leonard (LBSv) and Kirsty Maynard (THSP) to discuss the creation of BedX, and how it aims to support businesses with tender preparation ahead of the Universal and related projects currently underway in Bedfordshire.   [01:25] Who are Kirsty and Lorna?: Kirsty is the commercial director at THSP. THSP work with businesses across health and safety, HR and compliance, helping organizations make sure they've got the right systems, processes and people in place to operate safely, professionally and compliantly. THSP have been in operation since 1992 and support any type of organisation, from construction to food brands, global luxury retailers, major transport organizations, and complex international businesses operating in highly controlled environments. Lorna is the managing director of LBS. LBS is a business solutions company supporting sophisticated start-ups and growing corporations with outsourced finance department services, direction and solutions. She set-up the business 14 years ago, and has worked with organisations of all sizes, from blue chip companies to micro businesses of only 1 or 2 people. Regular listeners may recall Lorna from a previous episode, she also shares many insightful posts on LinkedIn and is certainly worth a follow! [07:05] What is BedX? It's A business-led working group powered by the Bedfordshire Chamber of Commerce. It was created to help Bedfordshire businesses understand, prepare for and win work from the major investments coming into the region, in particular, the universal destinations and experiences, the Luton Airport expansion and other on-going linked projects. BedX's role is to connect, inform and prepare, but they don't lobby, they don't represent the developers and they don't do politics. They are simply there to help local businesses get ready. [07:45] What were the main drivers behind the creation of BedX? The Universal park is certainly the banner piece for the group. It's what all the big numbers are attached to, including 5 billion pounds worth of inward economic investment, 20,000 jobs created and the five years' worth of construction. However, that is just one part of the upcoming development going on in Bedfordshire. The big project is seeing more funding going into the area to support transport networks and other venues as investors seek to make Bedfordshire a place worth staying for more than just the Universal Park. Other projects include the expansion of the Wixams Train Station, construction at the Luton Hoo, the new Luton Town Football Club and a new Data Centre at Quest Pit. BedX was created in response to all of these projects, not just Universal. It's to help local businesses navigate these opportunities, as this small county has rarely seen such a seismic shift in the amount of investment going into the area. Even though the deadline for Universal Park is 5 years away, supply chains are looking for support now, which is why it's better to start preparing sooner rather than later. [10:20] Making Bedfordshire a play to stay: It's also not just about the venues, to prepare for the influx of tourists there will be more investment in housing and transport and related routes such as the work currently going on at the Black Cat roundabout. Kirsty states that the Bedford County Council have a scrutiny committee, which is currently labelled as the Universal Scrutiny Committee, and are in discussion about a viable tourist strategy for Bedfordshire. So, there is no doubt that there will be many more small projects going ahead within a very short timeframe to get the area ready. [12:00] How LBS's expertise is instrumental within BedX: Businesses that want to get involved may not know how to get working capital or access potential available funding, which is where Lorna's and LBS's expertise comes in to support BedX's aims. With tenders as highly valued as this, it can throw businesses through a loop if they're not prepared. Lorna shares a story where she explains that she used to work for a company that made point of purchase display equipment, this company had a US subsidiary called Anshauser-Busch, who own Budweiser. That subsidiary put through an order directly through to their factory, requesting a huge order be manufactured and delivered within 180 days. The cost of which was upwards of $2.7 million, which was due to suppliers 150 days prior to Lorna's company at the time being paid. It was their first time working with that subsidiary, so there was no guarantee on payment. The lessons they learned ended up shaping how the company operated going forward. All this to say, if you're bidding for high value contracts, you need to think about the opportunity from every perspective. [14:40] Be realistic about what you bid for: Kirsty states she is really passionate about ensuring businesses are trying to grow responsibly, so that they understand those terms in the bid and that they're realistic about the size of contract that they should be bidding for. If you're looking for more guidance in this area, Katie from Bids and Tender Support provided a webinar on this topic for BedX. It's available to view on-demand on BedX's website. [16:25] Lorna's role within BedX: Lorna reminds us that a lot of the Tier 1 contractors started out as 1 or 2 person businesses. She states that, honestly, 90% of the companies that BedX help will not be in direct contact with one of those Tier 1 contractors. However, supply chains are just that, a chain, there are many opportunities to get involved further down the line. Lorna feels as if that's a large part of her role, keeping businesses focused on the opportunities they can access within that supply chain. She is also keen to help all the local businesses understand how this is going to affect them, because whether they get involved in the various projects being built or not, the whole area is going to be affected regardless. She points out an example where they needed to source a large number of electricians, and it turns out that Bedfordshire simply doesn't have enough! So BedX is helping to make the wider community aware of training opportunities like this that can open doors for local businesses. [18:45] Other considerations for businesses operating in Bedfordshire: Lorna points out a few other concerns that people had about the on-going development in the area, including the possibility of local contractors putting prices up due to all the other projects. Timeframes may also be affected by both on-going work and the fact that more businesses will be getting involved in the area's development. [19:15] What are the group's main aims?: BedX's main aim is to be an opportunity exchange, they sit in the middle as a conduit between the opportunities and the Bedfordshire businesses and help to inform, educate and prepare to be a part of it. They are there to support preparation local businesses are able to access emerging supply chains as that waterfall flows down into tier 2 and 3 and even into 4 and 5 over the course of the project. If you're not sure which of those tiers you'd likely sit in, BedX have a helpful household checklist to find out. [20:20] Getting ISO Ready for Universal: Kirsty mentions that she's seen a lot of recent Pre-Qualification Questionnaires (PQQ's) request that bidding companies are certified to ISO 27001 Information Security. Many will be familiar with the requests for ISO 9001 (Quality Management), ISO 14001 (Environmental Management) and ISO 45001 (Occupational Health & Safety), but ISO 27001 seems to be a more recent pre-requisite. This is particularly the case for any Government contracts, with them stating either Cyber Essentials or ISO 27001 must be in place for any bidding businesses. Carly points out that ISO 27001 in many cases is just the first step, as you can strengthen this with supporting Standards such as ISO 27701 (Privacy Information Management) and ISO 27017 & ISO 27018 (Cloud Security), which can give you an advantage over your competitors. If you've not got any Standards in place, or are just starting out on your implementation journey, you can get in contact with Blackmores as we'd be happy to guide you towards successful certification. [25:00] Kirsty's role within BedX: Kirsty's role is focused on coordination, though all BedX organisers are volunteers, they still want to ensure that actions are followed up and completed. Kirsty has a project planning background and brings those skills to the group. She also plays a key part in tender and procurement readiness, as she has years of experience with PQQ's from her work within the construction industry. She knows what good looks like when bidding for work, and ensures that knowledge is being passed on to those looking to bid for Universal and other Bedfordshire development projects. A trait that many of the BedX team hold, Kirsty and Lorna especially, is the motivation to help people, and this group allows them to do so at scale. [27:45] How can businesses get involved with BedX?: You don't need to be a member of the Bedfordshire Chamber of Commerce to get involved. Currently BedX's main focus is on knowledge sharing, so their main output in webinars. They also have a tender diagnostic tool available, this is an online tool which takes just a few minutes to complete and will give you an idea of where you're already compliant and where there's work to be done. They have also had 1 in-person event, that being their official launch in April of 2026, which was attended by members from the Bedfordshire business community and representatives from Universal, Sizewell C and Luton Rising. They expect to run more in-person events in future, so keep an eye on their LinkedIn for news on these! Lorna hints at an upcoming event planned for September 2026

The Catalyst by Softchoice
The Token Burn Episode: What Happens When Your Software Bill Has No Ceiling

The Catalyst by Softchoice

Play Episode Listen Later Jul 29, 2026 27:59 Transcription Available


Your AI bill just stopped behaving like a software bill. For twenty years, IT leaders got very good at counting seats: buy a hundred, pay for a hundred. Then AI swapped the seat for a meter, and the number stopped holding still.This episode follows the burn from three vantage points: a financial analyst rationing a $250-a-month token budget he tore through in two days; the tech executive who watched enterprise AI bills climb 7x, 10x, 20x; and the IT leader at a 300-person company who refused to solve it with a usage dashboard. Along the way: Meta's leaked internal token leaderboard, Uber blowing its entire annual AI budget by April, and the uncomfortable question of who profits when everyone's told to use more.In this episode:Why token-based pricing breaks the budgeting playbook IT has relied on for two decadesWhat happens to the people using the tool when the meter starts running — and why rationing has a hidden costWhy measuring usage is the wrong scoreboard, and who benefits when you keep score anywayThe mid-market move that beats policing: measure centrally, push the judgment to managers, and get clear on what you're optimizing forFeaturing Brian Elliott, CEO of Work Forward; Daryl Dore, Senior Director of IT & Information Security at Higher Logic; and Benjamin, a financial analyst who spoke with us on condition of anonymity.Support our sponsor:This episode is brought to you by Sophos MDR. Running Microsoft security tools and drowning in alerts? Sophos MDR's 24/7 experts investigate and stop the real threats. >>> Learn more at: https://www.sophos.com/en-us/solutions/use-cases/microsoft#ITLeadership  #AICostManagement  #SaaSManagement  #FinOps  #EnterpriseAI  #TokenBurn  #ITAMShow Notes & ResourcesReferenced in this episodeMeta's internal AI token leaderboard (Fortune) — 85,000 employees ranked by token consumption; shut down days after it leaked.Uber burns its 2026 AI budget in four months (Forbes; TechCrunch) — adoption jumps 32% to 84% in a month; spend later capped.Jensen Huang on token consumption as a productivity signal (Tom's Hardware).Gartner: worldwide AI spending forecast to grow 47% in 2026 (Gartner).Zylo 2026 SaaS Management Index — the scale of wasted SaaS spend (Zylo).Brian Elliott's newsletter, Work Forward.Guest: Daryl Dore — Higher Logic.This episode's sponsor: Sophos MDR, in partnership with Softchoice — 24/7 managed detection and response for Microsoft environments. https://www.sophos.com/en-us/solutions/use-cases/microsoft The Catalyst by Softchoice is the podcast dedicated to exploring the intersection of humans and technology. 

UAB Green and Told
The Victory You'll Never See - Heather McCalley '11

UAB Green and Told

Play Episode Listen Later Jul 27, 2026 21:10


Heather McCalleyMS, College of Arts and Sciences, 2011CERT, College of Arts and Sciences, 2011More InformationYellowhammer News - UAB forensics team DarkTower leaves criminals with nowhere to hideDarkTower - homepageLinkedIn - Heather McCalleyLinkedIn - International Women's Day post (Gary Warner)

The Mindful Business Security Show
Special Episode - AI Implementation Playbook Part 1: The Why of AI

The Mindful Business Security Show

Play Episode Listen Later Jul 23, 2026 58:38


The Mindful Business Security Show is a call-in radio style podcast for small business leaders. Join our hosts as they take questions from business leaders like you!   On this episode, Accidental CISO is joined by guest host Mike Simmons. Mike is a consultant, leadership coach, speaker, and podcaster. He combines systems thinking with a people focused approach to help his clients achieve results through clear communication.   You can find Mike's videos about business and leadership on his YouTube channel, and you can contact him via his website, Find My Catalyst.   In this episode Mike referred to some tools that can help business leaders analyze problems and communicate more effectively. Videos offering more details about each can be found on YouTube. Collaborative Problem Solving Framework How to Simplify Problem Solving - 1 tool 6 steps What is Communication? How Leaders Make Decisions Faster: Four Simple Frameworks   Are you struggling with how to deal with Cybersecurity, Information Security, or Risk Management in your organization? Be a caller on a future episode of the show! Visit our podcast page for more information about upcoming episodes. You can sign up to be a caller and guarantee yourself a Q&A session on the show!   Show Merch: https://shop.mindfulsmbshow.com/ Website: https://www.focivity.com/podcast Twitter: @mindfulsmbshow Hosted by: @AccidentalCISO Produced by: @Focivity Theme music by Michael Kobrin.

The ISO Show
#255 AI Due Diligence - Information Security Checks Before You Integrate AI

The ISO Show

Play Episode Listen Later Jul 22, 2026 19:59


AI can be fantastic for relieving a lot of administrative burdens, allowing individuals to focus on more complex tasks that need a human touch. However, many are all too quick to install and integrate, which can lead to crucial vetting processes being skipped. So many applications have also integrated various AI features, and while you may have vetted the software before these were available, those new AI features still need scrutiny before widespread use within the business. In this episode, we dive into why there is a need for a more cautious approach to implementing AI and share some tips on basic Information Security checks you can do to ensure an AI application or integration is safe to use.   You'll learn ·      The link between AI and increasing data breaches ·      Recent incidents as a result of AI misuse or error ·      Key considerations for the implementation of AI technology ·      11 Information Security checks for AI tools     Resources ·      Isologyhub ·      ISO 42001 Webinar ·      IAF Accreditation Check   In this episode, we talk about: [02:25] Episode Summary – Stephanie Churchman explains the need for caution when exploring the implementation of AI tools, and provides guidance on some information security checks you can perform to ensure your data stays safe. [02:45] The link between AI and increasing data breaches: Data breaches tripled since the wide adoption of AI in early 2024 and studies are saying there is a clear link between these two events. Here in the UK alone, 32% of businesses experienced a cyber-attack or data breach in 2023, compared to 43% of businesses in 2025, with us already steadily on track to surpass that in 2026. Does this mean people shouldn't use AI at all? No, of course not, but we do need far more caution before you simply start using a tool. [03:35] Recent incidents as a result of AI misuse or error: ChatGPT copycat – There was a ChatGPT clone available as a web extension that was downloaded by some 1.5 million users. It functioned just like ChatGPT, answered queries and provided links to legit sources. But, in the background, it was scrapping passwords and gathering information that was to be sold off without users knowledge. Sage Copilot - The popular accounting software had to temporarily suspend Sage Copilot after a data-isolation flaw occurred. This incident caused an issue where users who prompted the AI to list recent invoices ended up with incorrectly surfaced financial records belonging to unrelated businesses. This was a major security issue, especially for an application thousands of businesses rely on to track their financial records. Google Gemini – Google Gemini was found to have been abused by bad actors for data reconnaissance. One particular group were building profiles on major cybersecurity and defense companies and were looking to gather specific technical job roles and salary information. Google's threat intelligence team characterized this activity as a blurring of boundaries between professional research and malicious reconnaissance. Their soft touch approach allowed the bad actors to craft tailored phishing personas and to further identify potential soft targets to compromise. [06:30] Key considerations for the implementation of AI technology: Any software or technology you plan on introducing into the business that will interact with your and your customers data should be subject to clear vetting procedures, with clear rules for use to follow. Before integrating an AI tool, ask yourself, is the tool you want to use: a)    Relevant b)    Safe c)    Ethical Ethical may sound strange, and will depend on what you're using an AI for. Take CV sorting for example, many studies have shown that AI's can have an inherited bias based on their training data. This has also now evolved into AI based recruitment tools preferring AI generated CV's over human written ones. From a safety standpoint, think about the data you are feeding into those recruitment tools, that's personally identifiable information, full names, phone numbers, emails and possibly even addresses. A full profile for an individual. Is that system your using closed, do you know if you consented to having any input data used for further training? Don't just assume that inputted data won't be used beyond your control. If that recruitment AI tool gets hacked, who do you think is liable for the breach? Is it the AI tool developer or the business that input the data? You think the answer would be clear, but the legality of all this is still being debated. [09:10] 11 Information Security checks for AI tools: #1: Have an AI Policy and AI Integration approval process in place - Many businesses will already have an AI policy in place, most are very generic, so we recommend looking at the guidance provided by ISO 42001 to see what good looks like for an AI policy. You should also create a clear approval process that any AI tools must pass BEFORE people start using them. This should be clearly communicated to the wider team, and there should be a method to manage these checks such as a ticketing system to kick off the process. #2: Understand where your data actually goes - Find out whether inputs are used to train the vendor's models. These inputs can include prompts, uploaded files or even customer data depending on what the tool is. You also need to find out how long that data is retained, and whether it's stored in a specific jurisdiction. You can look for answers to these in a DPA (Data Processing Agreement), don't rely on the basic marketing blurb they state on the website. If those answers aren't provided, contact the tools support or basic enquiries to find out. #3: Check for a SOC 2, ISO 27001, or equivalent certification – This is an easy check for vendor's security posture. Absence of certification shouldn't automatically disqualify a vendor or tool, but it should prompt more due diligence, not less. Even with a certification in place, you also need to double check that it's valid. ISO 27001 for example will need to be certified by a UKAS accredited certification body for those in the UK. For overseas, you will have your own ISO accreditation bodies, which can be verified on the IAF website. #4: Map out third-party and subprocessor risk - Most AI tools sit on top of other infrastructure like cloud hosting, underlying foundation models and additional analytics tools. You should ask for a subprocessor list to fully understand who else touches the data. #5: Test for prompt injection and data leakage - If the tool interacts with external content such as emails, documents or web pages, it can potentially be manipulated by malicious instructions hidden in that content. Businesses should ask vendors how they mitigate this and ideally test it themselves. #6: Clarify access controls and permission scoping - This is especially the case for AI agents or tools with system integrations. You need to establish if the tool operates with the same permissions as the user, or whether it has broader access. Overprivileged AI agents may operate independently with no human oversight. 'Human in the loop' has become a common phrase within cyber security for a reason, you always need a point of human oversight to ensure the AI is doing what it's supposed be doing and is doing so safely. #7: Ask about model update and versioning transparency - You need to ensure that the vendor won't just silently swap out the underlying model for its AI tools, as this can introduce sudden behaviour changes in the tool itself. Transparency is a key component of emerging AI security frameworks and regulations such as ISO 42001 and the EU AI Act. If a vendor isn't willing to tell you when they're making major changes to their tools, then it's not a vendor you want to entertain. #8: Evaluate the output reliability and hallucination risk in context - For security-adjacent or compliance-adjacent AI tools, factually wrong outputs are a risk. AI can have a tendency to 'hallucinate' data or outcomes and then present them as fact. So, ask the vendor what guardrails exist and whether their tools' outputs are auditable / traceable. They should know what data was used to train their models, or where their models are pulling data from. If they don't or can't control what data is being used, then it's not a tool you can 100% trust. #9: Review incident response and breach notification commitments - If the vendor is breached, do you how quickly you would be notified, and what their recovery process looks like? If you hold ISO 27001 and ISO 22301, or simply have a business continuity plan in place then you will already have similar procedures in place for peace of mind for your own customers, so why should you settle for any less? And just like your clients would expect, breach notifications and expected recovery times should be contractually defined, not just assumed. #10: Consider the supply-chain risk of the vendor itself - This tech is still relatively new, and so newer AI vendors may have smaller security teams and less mature processes than what you may be used to with more established providers.  However, startup pace doesn't mean you have to tolerate the start-up risk. Consider all of the previously mentioned steps, if they don't have a lot of that in place, then they may not be mature enough yet for you to go ahead with. This doesn't mean you have to automatically disqualify them, if they have a clear plan of action for growth, which shows a clear focus on increased security and transparency within a reasonable timeframe, then it's still worth considering. #11: AI tool monitoring and Kill switch – In addition to this initial vetting procedure, you should also have a process in place to continuously monitor these AI tools too. Many AI tools aren't static, they'll update and become better or possibly introduce issues as they will inevitably face the risk of bugs and other technical problems as they roll out updates. If a tool is consistently encountering issues, continuous monitoring allows this to be flagged up as a security issue. Which is where you'll also need a kill switch in place if an AI tool is behaving unsafely. It's important that you know how to isolate it and remove it from your systems. AI tools are more ingrained that your typical software, often designed to work in tandem with existing apps rather than as a standalone system. This will mean that some tools will have access to possibly sensitive data, something that needs to be protected if the AI tool experiences issues that could lead to that data being compromised. The relevant staff, likely your IT team, need to have a clear process for what to do in those scenarios. If you'd like any assistance with implementing ISO standards, get in touch with us, we'd be happy to help! We'd love to hear your views and comments about the ISO Show, here's how: ●     Share the ISO Show on Twitter or Linkedin ●     Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one. Subscribe to keep up-to-date with our latest episodes: Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List

No Password Required
No Password Required Podcast Episode 75 - Philipp Leo

No Password Required

Play Episode Listen Later Jul 20, 2026 43:01


Philipp Leo — Swiss cyber expert, diplomat, and military officer, always two steps ahead of the storm No Password Required Season 7: Episode 7 - Philipp Leo Philipp Leo co-founded Leo & Muhly Cyber Advisory, a strategic advisory firm specializing in cyber risk, resilience, and geopolitics. Now consulting with governments and private firms in Switzerland and abroad, Philipp has served as a UN observer on the Korean DMZ, trained the next generation of Swiss Armed Forces cyber specialists, and taught at the University of Glasgow. He is also part of Europol's network of experts in data protection and cybercrime and has published stateside in MIT Sloan Management Review. In this episode, Philipp shares his journey from a Swiss bank he couldn't wait to leave to the Korean border, and eventually to the boardrooms of executives who still think cyber risk is someone else's problem. He breaks down the three most dangerous misconceptions executives have about cyber risk, why the CISO is too often a poster child rather than a decision-maker, and the challenges to cyber insurance in Europe. Cyber attorney Jack Clabby and co-host Kayley Jerrell talk with Philipp about his live crisis simulation that nobody can win, how to train cyber warriors, and how nation-state cyber conflict is looking more and more like the age of Caribbean pirates. In the Lifestyle Polygraph, Philipp reveals his favorite book, his eye-opening, go-to celebratory drink, and the weight of his luxury umbrella. He also shares his favorite escape when the complexity of modern life gets to be too much and introduces us to a Zurich commuting tradition that involves swimming home through a river.   In this episode: Philipp's journey from a Swiss bank he couldn't wait to leave to the Korean DMZ and eventually the boardrooms of Fortune 500 executives (00:27 - 02:22) The three most dangerous misconceptions executives have about cyber risk and why cyber risk is a corporate problem, not a technology problem (04:19 - 05:30) How Philipp's live crisis simulation works, why nobody can win it, and why that's exactly the point (05:49 - 08:47) Why cyber crisis teams have improved dramatically but leadership boards remain the weakest link (06:30 - 08:47) The CISO poster child problem: why most CISOs have the accountability without the authority (09:54 - 11:00) Why cyber insurance in Europe has largely failed to deliver and what happens when attackers find your policy before you do (11:17 - 13:44) The OFAC twist: what happens mid-exercise when a Swiss bank decides to pay and then learns the attackers are on the sanctions list (18:38 - 19:31) Training Swiss Armed Forces cyber specialists and why the first lesson is that the other side plays by no rules (19:47 - 21:37) Whether nation states can ever beat the cyber threat and why the east side of Vienna tells you everything you need to know (21:54 - 23:25) Why nation-state cyber conflict has become remarkably similar to the age of Caribbean pirates (23:46 - 24:23) The Lifestyle Polygraph: Endurance, Campari Red Bull, a three-ounce umbrella, a cabin in the Alps, and swimming home through a Zurich river (00:04 - 12:03)   Timestamp Highlights: (00:27) From Swiss banker to UN observer on the Korean DMZ (04:19) The three misconceptions executives have about cyber risk (05:49) The crisis simulation nobody can win and why that's the whole point (09:54) Why the CISO is too often a poster child without real power (11:17) Why cyber insurance in Europe has largely failed (18:38) The OFAC twist that stopped a Swiss bank mid-exercise (19:47) Training Swiss cyber warriors to understand the other side plays by no rules (21:54) Nation states vs. cyber threats: are defenders always outpaced? (23:46) How nation-state cyber conflict mirrors the age of Caribbean pirates (07:25) Always prepared: the three-ounce umbrella that nobody sees   Resources & Links: Leo & Muhly Cyber Advisory  Philipp Leo on LinkedIn ThreatLocker — Presenting sponsor DerScanner — Supporter of this podcast Cyber Florida — The Mother Ship  

The Shared Security Show
Surveillance Pricing: When Your Data Sets the Price

The Shared Security Show

Play Episode Listen Later Jul 20, 2026 22:05


This week on Shared Security, Tom and Scott dig into surveillance pricing: the use of personal data, behavioral profiles, shopping history, location signals, income assumptions, household information, and AI-driven targeting to decide what price or discount different people see for the same product.The conversation connects New Jersey's proposed grocery surveillance-pricing ban, Consumer Reports-style loophole concerns, loyalty-card data, and a creepy Papa John's / Instacart / streaming-ad example into one listener-friendly question: when does ordinary dynamic pricing become personalized price discrimination based on what companies think they know about your life?** Links mentioned on the show **EPIC — New Jersey Legislature Passes Grocery Surveillance Pricing Ban https://epic.org/new-jersey-legislature-passes-grocery-surveillance-pricing-ban/Schneier on Security — Papa Johns Surveillance-Based Advertising https://www.schneier.com/blog/archives/2026/07/papa-johns-surveillance-based-advertising.htmlEFF — California's Bill to Ban Surveillance Pricing https://www.eff.org/deeplinks/2026/06/californias-bill-ban-surveillance-pricingScott's Digital Legacy Project https://securityperspectives.com/digital-legacy-tools/** Watch this episode on YouTube **[YOUTUBE URL]** Become a Shared Security Supporter **Get exclusive access to bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today by going to our YouTube channel's membership section: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/join** Thank you to our sponsors! **SLNTVisit https://slnt.com to check out SLNT's amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code "sharedsecurity".** Subscribe and follow the podcast **Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcastFollow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.socialFollow us on Mastodon: https://infosec.exchange/@sharedsecurityJoin us on Reddit: https://www.reddit.com/r/SharedSecurityShow/Visit our website: https://sharedsecurity.netSubscribe on your favorite podcast app: https://sharedsecurity.net/subscribeSign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribeLeave us a rating and review: https://ratethispodcast.com/sharedsecurityContact us: https://sharedsecurity.net/contact

Cloud Do You Do?
A day at the breach: How to fix data sprawl and shadow sharing

Cloud Do You Do?

Play Episode Listen Later Jul 17, 2026 27:26


Who still has access to your company files? What happens to the sensitive files your team shares once a project is over? In this episode of the Cloud Do You Do podcast, Revolgy's Ashley talks with Matt Dubreuil from our partner, DoControl, about the hidden risks of data sprawl and shadow sharing in Google Workspace. Google Workspace makes file sharing incredibly easy. People just create a link and drop it in a chat to get work done. The problem is that access stays open long after a vendor contract ends or an employee leaves, leaving private company data sitting in personal emails and forgotten folders. Matt explains why built-in security tools make it hard to clean up this historical mess, and why putting strict blocks on file sharing doesn't actually solve the problem. In this episode: Shadow sharing: How everyday file sharing creates massive compliance and security blind spots over time. The limits of native tools: Why standard Google Workspace settings make it difficult to see what is currently exposed and fix it in bulk. A smarter way to fix it: Why sending a quick Slack message to ask a user about a risky file share works much better than just blocking them. Free data risk assessment: Find out exactly how many open links and former employees still have access to your workspace with a fast, non-disruptive scan that makes audits easier. Reach out directly to Ashley at ash@revolgy.com to get your free scan set up. Links & Resources Listen to DoControl's podcast, The Breach Seat Matt's podcast recommendation: How I Built This (specifically the episode with Jensen Huang of NVIDIA) Check out DoControl.io We are Revolgy - a global cloud partner. Our cloud engineers and architects provide professional and managed services for your projects on GCP and AWS. In a nutshell, we help to make life digital-native companies, SMBs and corporates in the cloud easier. Check our website revolgy.com for more information.Make sure to follow Revolgy on Spotify, Linkedin, and X.Thanks a lot for listening, and see you next time!

ILTA
#0198: (JIT) ILTA Just-In-Time: Vibe Coding – Built by AI, Owned by You, Reviewed by Nobody

ILTA

Play Episode Listen Later Jul 8, 2026 12:17


Legal professionals are increasingly using AI to build internal automations, workflow tools, and client-facing applications, often without the involvement of the IT or security departments. This episode examines what happens when "vibe coding" meets the legal environment: client data handled by code nobody fully understands, third-party dependencies nobody vetted, and compliance obligations nobody mapped.  Listeners will leave with practical tips for enabling AI-assisted code development without abandoning their duty of care. Moderator: @Jack Recinto - Director of Applications, Ice Miller LLP Speaker: @Ken Fishkin - Associate Director of Information Security, Lowenstein Sandler LLP Recorded on 07-08-2026.

No Password Required
No Password Required Breakout Room with Rob Whetstine

No Password Required

Play Episode Listen Later Jul 6, 2026 57:16


In this episode: Why Rob always asks for the team nobody wants and what the turnaround process actually looks like (00:31 - 02:10) From sleeping in his car at 18 to Fortune 500 executive, and the kindness from strangers he still carries with him today (02:10 - 04:32) What a successful team turnaround actually looks like, including eight leaders in ten years and what changed (04:32 - 07:00) Servant leadership, why career leaders almost always fail, and the power of coming in with a partial idea instead of a completed thought (07:00 - 09:33) The truth about the cybersecurity job shortage and why open jobs almost never mean what you think they mean (09:33 - 11:37) Why communication skills matter more than technical ability and what happens when a technical score of 10 meets a communication score of two (11:37 - 13:22) Cyber is a marathon, not a race, and why passion got Rob a job at Disney over people with far more experience (13:22 - 15:27) Neurodiversity in the workplace, getting diagnosed with autism at 40, and why really smart doesn't get jobs anymore (15:27 - 17:51) The colleague who told Rob everyone thought he was a jerk, the boss who explained why, and the apology tour that followed (17:51 - 21:31) Getting laid off from Disney, becoming a ghost on the internet, and accidentally building the BowtieSecurityGuy brand (21:31 - 25:47) Tying self-worth to career, crying before job interviews, and the four words his wife said that changed everything (25:47 - 27:40) The 3am LinkedIn message from India that made Rob realize he was in this for life (27:40 - 29:40) Zero expectations, zero conditions, and why Rob messaged Rex about a hat with absolutely nothing to gain (29:40 - 31:40) Immersion therapy, D&D every Monday, and why a bad public speaker is more memorable than a good one (34:03 - 37:16) Rejection sensitivity dysphoria, masking, and why setting the tone in a room changes everything (37:16 - 39:23) The 3,000 manual LinkedIn messages, the algorithm daddy slap, and pricing yourself where you want to be (39:23 - 40:43) Zero expectations as a life philosophy and why people don't quit jobs, they quit bosses (40:43 - 42:27) Learning to walk three times, leg braces, and why cutting through grass almost brought Rob to tears (42:27 - 44:40) What Rob tells job seekers who have been at it for two years: you are ten nos away from your dream job (44:40 - 47:09) The cybersecurity salary reality check and why 3,500 to 4,500 people graduate with cyber degrees every single month (47:09 - 48:50) Rob's thank you to the people who know who they are, his battle buddies, and why vulnerability is a strength (48:50 - 51:28) Fail with style, the Walt Disney Haunted Mansion story, and why Rob never took no for an answer at Disney (51:28 - 56:39)   Timestamp Highlights: (00:31) Give me the team nobody wants (02:10) Homelessness at 18 and the kindness that stayed with him (07:00) Servant leadership and the power of a partial idea (09:33) The real reason there are so many open cybersecurity jobs that never get filled (11:37) Stop applying. Start connecting. (13:22) How passion got Rob hired at Disney over NSA agents (17:51) Getting diagnosed with autism at 40 (21:31) Getting laid off from Disney and accidentally building a brand (27:40) The 3am message that changed everything (34:03) D&D, immersion therapy, and why bad public speakers are more memorable (42:27) Learning to walk three times and why Rob doesn't take anything for granted (51:28) Walt Disney, the Haunted Mansion, and failing with style   Resources & Links: BowtieSecurityGuy — Rob's brand across all platforms ThreatLocker — Presenter of No Password Required Breakout Room Cyber Florida — The Mother Ship  

Cracking Cyber Security Podcast from TEISS
teissTalk: How AI is forcing a redesign of security itself

Cracking Cyber Security Podcast from TEISS

Play Episode Listen Later Jul 2, 2026 46:02


Why only 5% of organisations have full visibility into AI tool usage - what a credible approach to access controls and runtime behavioural monitoring looks likeMoving beyond policy intent to architecture that governs AI workloads, autonomous agents and machine-driven workflowsMoving from fragmented controls to unified, policy-driven security architectures that deliver consistent enforcement across hybrid and multi-cloud environmentsJonathan Craven, Host, teissTalkhttps://www.linkedin.com/in/jonathanbcraven/Satyam R., Director of Information Security & DevOps, BAMKOhttps://www.linkedin.com/in/hackersatyamrastogi/Paul Barbosa, V P & General Manager, Cloud Security & SASE, Check Point Softwarehttps://www.linkedin.com/in/paulbarbosa/

The ISO Show
#254 Driving ISO Implementation – Meet the Consultant: Emma Coxhill

The ISO Show

Play Episode Listen Later Jul 1, 2026 25:43


The path towards becoming an ISO consultant is often a meandering one. It's not often a career that many aspire to, yet despite that, there are still thousands of ISO professionals worldwide. We're continuing with our mini-series where we introduce members of our team, to explore how they fell into the world of ISO and discuss the common challenges they face while helping clients achieve ISO certification.   In this episode we introduce Emma Coxhill, an isologist® at Blackmores, to share their recent journey into the world of ISO consultancy and how they've found their first year working with other organisations to help them achieve ISO certification. You'll learn ·      What is Emma's role at Blackmores? ·      What does Emma enjoy outside of consultancy? ·      What did Emma do before becoming an ISO consultant? ·      How has Emma found her first year as an ISO consultant? ·      What Standards has Emma worked with so far? ·      Has there been any unexpected elements to her role? ·      What is the biggest challenge Emma has had during a project so far and how did she overcome it? ·      What is Emma's biggest achievement?   Resources ·      Isologyhub ·      TISAX Webinar   In this episode, we talk about: [00:30] Episode Summary – We introduce Emma Coxhill, an Isologist® here at Blackmores, to discuss her recent entry into the world of ISO consultancy, including how she's found working on the other side to help other organisations achieve ISO certification. [03:30] What is Emma's role at Blackmores? Her role primarily involves supporting clients in two key areas: maintaining and continually improving their existing ISO management systems and helping them establish and implement new standards. Emma specialises in information security management systems (ISMS), but is branching out to other Standards as she takes on more clients. [04:30] What does Emma do in her free time? Emma is a big fan of the outdoors, enjoying long walks and exploring in general. It makes sense then that she also enjoys gardening. While it is a lot of work, she finds the result rewarding. Emma is also a big fan of movies, excluding horror films! She enjoys making the trip to see films on the big screen when she has the chance. Lastly, Emma is also a qualified life coach. This involves guiding people to get where they want to be in life, with the crucial distinction that it's not about telling people what to do, but rather providing the right questions and tools to help them achieve their goals quicker. These skills have evidently translated well into her role as an ISO consultant, as auditing is very similar in the fact that it's about giving people a different perspective. [06:55] What was Emma's previous role? Emma previously worked in admi and retail roles, with her last job being a sales admin at a company for 13 years. She first started at that company as a sales admin, moved onto business systems and around 2019 the request for them to earn ISO 27001 certification came in. Back then ISO 27001 was a 'nice to have' and not a 'need to have' like it is today. Emma jumped at the chance to join the team working on the ISO 27001 Implementation, taking part in the research, training and implementation tasks. The company managed to navigate their certification, even through the turbulence of COVID, and Emma was the one maintaining that ISMS for the following years. During that time she also implemented TISAX, an Information Security Standard specific to the automotive industry, which you can learn more about on one of our previous webinars hosted by Emma. Sadly, Emma was made redundant in 2025, but was fortunate to join the Blackmores team shortly after. [10:10] How has Emma found her first year as an ISO consultant? It's been challenging for Emma to adjust to being on the other side of the fence, helping others to achieve certification rather than being the one to implement a system firsthand. Thankfully there was plenty of opportunity to learn during her first year with Blackmores, including expanding her repertoire of Standards and being able to learn from other experienced consultants in the team. She's really enjoying working with a variety of clients, getting to learn about different industries and how different each company is in their operations. Emma is aware that she's just scratching the surface within her first year, and is eager to learn more. [12:20] What Standards has Emma worked with so far? ISO 27001 is the main one as it's the one that Emma learned to implement from scratch at her pervious job. Since joining the Blackmores Team she's also gained experience working with ISO 9001 (Quality Management), ISO 27701 (PII Management), ISO 17100 (Translation), ISO 42001 (AI Management) and TISAX. ISO 27001 remains her favourite out of all of them, and she's keen to learn more from Blackmores own Information Security guru, Steve Mason. [14:15] Has there been any unexpected elements to her role? One of the more unexpected aspects has been helping clients navigate various acquisitions. When she joined, Blackmores had an unusual amount of clients currently in the middle of this process. Dealing with ISO management in these situations can get tricky as you're having to marry up different styles of management as two companies merge. Emma's role was in helping them to navigate that transition. She was surprised as she expected to be dealing with companies that were business as usual for years, but ISO Management is at the heart of managing these types of changes. So, it was interesting to learn how involved an ISO consultant can get into the inner workings of a business to help ease the burden for all parties involved. [17:20] What is the biggest challenge Emma has had during a project so far and how did she overcome it? Emma is still relatively fresh to implementation projects, but has found the process to be quite straight forward with the both the Blackmores 7 step methodology and support from other team members. What has been a challenge was the promotion she was tasked with for TISAX. It was a new service offering for Blackmores due to her expertise, and she was involved in recording a podcast and hosting a webinar. Both activities she'd not had any prior experience with. She doesn't think of herself as a big presenter, so it seemed like a dauting task. Emma did a lot of practice and went our of her comfort zone to do the webinar, which was positively received by the audience. The experience certainly boosted her confidence in that area, and though it was a bit stressful at the time due to nerves, she felt like it was a good learning opportunity. [19:45] What is Emma's biggest achievement? Emma has various moments throughout her life, with an early one being the fact that she passed her driving test first time at the age of 17. Later in 2005, she went solo travelling for 5 months around Australia, New Zealand and Fiji. She did end up having to work for a bit of that trip to make up some additional funds, but that was a necessary evil. Other than that, she was amazed at all the different people she met during her travels and was so pleased that she was able to complete the trip. Lastly, she's proud to have joined the Blackmores team in 2025. She's recently helped her first client achieve certification from scratch, which felt like a reward in of itself to know they'd passed their ISO assessment.  If you'd like any assistance with implementing ISO standards, get in touch with us, we'd be happy to help! We'd love to hear your views and comments about the ISO Show, here's how: ●     Share the ISO Show on Twitter or Linkedin ●     Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one. Subscribe to keep up-to-date with our latest episodes: Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List

The Mindful Business Security Show
Experimenting and learning about AI safely in small businesses

The Mindful Business Security Show

Play Episode Listen Later Jun 25, 2026 58:51


The Mindful Business Security Show is a call-in radio style podcast for small business leaders. Join our hosts as they take questions from business leaders like you!   On this episode, Accidental CISO is joined by guest host Zack Korman. Zack is a business and cybersecurity leader with a background in law, finance, and tech startups. His love for building with AI has led him to launch his current startup, Embroidery, where he and his team are building an AI driven threat detection tool for AI agents. Join them as they discuss how organizations can learn about AI and experiment with it safely to build institutional knowledge.   You can find Zack and his hot takes on X: @ZackKorman   Are you struggling with how to deal with Cybersecurity, Information Security, or Risk Management in your organization? Be a caller on a future episode of the show! Visit our podcast page for more information about upcoming episodes. You can sign up to be a caller and guarantee yourself a Q&A session on the show!   Show Merch: https://shop.mindfulsmbshow.com/ Website: https://www.focivity.com/podcast Twitter: @mindfulsmbshow Hosted by: @AccidentalCISO Produced by: @Focivity Theme music by Michael Kobrin.

Situational Awareness Tactics
Need-to-Know Since 400 BC: What the Spartan Scytale Teaches Modern Operators About Information Security, Compartmentalization, and Trusting

Situational Awareness Tactics

Play Episode Listen Later Jun 24, 2026 6:44 Transcription Available


The Spartans did not just build an encryption device when they developed the scytale, they built an entire operational security philosophy around the idea that information in the wrong hands is a weapon turned against you, and the discipline with which they controlled, transmitted, and protected military communications during the Peloponnesian War is a masterclass in the kind of need-to-know compartmentalization that defines modern high-threat operational environments. This episode breaks down how the scytale worked, why its simplicity was also its greatest operational strength, and what the Spartan crypto-state model reveals about the timeless relationship between information control, command integrity, and battlefield survival. Whether you are thinking about modern OPSEC, secure communications protocols, or the foundational principles behind keeping critical information out of enemy hands, the Spartans figured it out first and this episode shows you exactly how they did it.

Maschinenraum - Der Maschinenbau-Podcast
#341 Cybersecurity im Maschinenbau - was hat es mit der EU-Richtline NIS 2 auf sich. Interview mit Sascha Hesse

Maschinenraum - Der Maschinenbau-Podcast

Play Episode Listen Later Jun 22, 2026 68:44


In diesem Podcast-Gespräch diskutiere ich mit Sascha Hesse die Herausforderungen und Anforderungen der NIS 2-Richtlinie in der Cybersecurity für Unternehmen, insbesondere im Maschinenbau. Es werden praktische Schritte, gesetzliche Hintergründe und die Bedeutung einer Sicherheitskultur in Unternehmen beleuchtet. Die NIS-2-Richtlinie (Network and Information Security) ist eine EU-weite Cybersicherheitsrichtlinie. Ihr Ziel ist es, Unternehmen und kritische Infrastrukturen besser vor Cyberangriffen und IT-Ausfällen zu schützen sowie ein einheitliches Sicherheitsniveau in der gesamten Europäischen Union zu etablieren. Nur stellt sich dann die großen Fragen: wen Betrifft die Richtline überhaupt? wie muss ich mich verhalten und welche Schritte muss ich einleiten, wenn mein Unternehmen betroffen ist? kann ich das selbst machen, oder brauche ich externe Dienstleister? mit welchen Kosten muss hier gerechnet werden? All diese und noch weitere sehr spannende Punkte werden wir in dem Gespräch beleuchten und etwas Licht ist Dunkel der EU-Richtlinen bringen.   weiterführende Links: AGOR AG: https://agor-ag.com/ Gesellschaft für Cyberethik: https://agora-future.de/  

The ISO Show
#252 Wavenet's On-going Commitment to Best Practice – Successfully Maintaining Seven ISO Standards

The ISO Show

Play Episode Listen Later Jun 17, 2026 33:02


Anyone that has undergone the ambitious task of Implementing an ISO Standard will know how much work goes into creating and maintaining a single ISO certification. Now imagine juggling seven ISO certifications! There's a key difference between those that simply collect badges and those that see the value each ISO certification can bring, as every Standard has their own requirements and guidance to tackle specific areas of quality, risk and sustainability. When implemented well, they create a solid well-rounded framework that can drive unparalleled continual improvement. In this episode Ian is joined by Damian Edwards, Head of Standards at Wavenet, to dive into how they manage the mammoth task of maintaining seven ISO Standards, the challenges with managing multiple ISO certifications and what benefits they've brought to the business since implementation.   You'll learn ·      Who is Damian Edwards? ·      Who are Wavenet? ·      How did Damian manage integrating management systems during Wavenet's acquisition of Daisy Corporate Services? ·      What is Damian's role at Wavenet? ·      How do Wavenet manage their ISO certifications? ·      How has ISO Support helped you over the past year? ·      What has Damian learned while managing ISO Standards? ·      What are the benefits of ISO certification? ·      Damain's top tip for anyone considering ISO Implementation   Resources ·      Wavenet ·      Wavenet Certifications ·      Blackmores – ISO Support Service ·      Isologyhub   In this episode, we talk about: [00:30] Episode Summary – We welcome Damian Edwards back onto the podcast to discuss how he maintains Wavenet's seven ISO certifications, and the explore the benefits gained from an integrated ISO Management System.   [03:05] Who is Damian Edwards? Damian is the Head of Standards at Wavenet, and has featured on the ISO Show before! One lesser known fact about Damian, is that he a 'Dance dad', supporting his daughter through all of her lessons and competitions. He's very proud of her latest achievement of qualifying for the World Championship for Irish dancing in her age group. [05:05] Who are Wavenet? Wavenet is an IT provider, providing IT network communications, security and resilience services. They are UK based with 1,600 employees based in their Solihull head office. Wavenet were formed in 2000, but have grown through acquisition, one of which was Damians previous company, Daisy Corporate Services. When Daisy was acquired, both businesses were of a similar size, so the process looked more like a merger in practice. A large part of that was uniting the ISO Standards managed by both businesses, so Damian had his hands full with ISO integration, amending audit schedules and managing extension to scope audits. [06:30] How did Damian manage integrating management systems during Wavenet's acquisition of Daisy Corporate Services? One of the biggest challenges was the extension to scope that needed to happen due to the increase in sites. Thankfully, as Wavenet were used to acquisitions, they had dedicated acquisition project managers that assist with managing the integration. At the start, there are some teething problems as both businesses will still be using their respective processes for a while. However, once system that helped was a system called 'ServiceNow', which is where issue tickets could be logged, monitored and actioned in one centralised system. [08:15] What is Damian's role at Wavenet? Damian is the Head of Standards, which includes both ISO Standards and ESG related regulatory compliance. ISO certifications are more often than not a prerequisite or a condition of a bid over a contract, without them, Wavenet wouldn't win any business. They also create a foundation of trust for Wavenet's clients in the realms of Information Security, quality and environmental management. Wavenet are currently certified to the following Standards: ·      ISO 9001 Quality Management ·      ISO 20000-1 Service Management ·      ISO 27001 Information Security Management ·      ISO 22301 Business Continuity Management ·      ISO 45001 Health & Safety Management ·      ISO 14001 Environmental Management ·      ISO 50001 Energy Management In addition to maintaining all of these certifications, Damian also strives to utilise them to drive continual improvement within the business.   [10:30] How do Wavenet manage their ISO certifications? Damian is directly responsible for five of those ISO Standards, however there are some where he doesn't have the expertise to fully manage the requirements. ISO 27001 and ISO 45001 for example require skilled people at the helm, so Wavenet have dedicated managers to handle those areas. One of Damians key responsibilities is juggling all of the audits to make sure each element is covered, and he's put a lot of work into integrating those audits where possible to get the most out of their time and resources. Though, it's important to note that you can't integrate everything, as each standard will have some unique requirements. Areas that you can integrate however include elements such as: ·      Context ·      Audit Programme ·      Corrective Actions When you do have a lot of Standards, some elements can get watered down if you try to integrate everything. Policy for example, if you have five Standards and decide to integrate all related policies into a single document, it will become long and unruly, which will lead to people unwilling to read it. So, you have to take care to ensure focus on certain elements to make those more accessible for the staff that need it. Another aspect that needed additional consideration was Wavenet's risk profile, with their amount of sites and services, it's very varied. Too much for a single person to be aware of all the risks, which is where Damian's subject area experts can provide additional insight to fill the gaps. Damian is also keen to combine external audits where possible to both reduce cost and possible duplication of effort, as many Standard do share common subject areas, this can be done across multiple Standards. Certification Bodies are usually quite happy to work with you on this! Damians key take away is, that there isn't one solution that fits every business when managing this many Standards. It was a very trial and error process, especially with the ever changing landscape of a business, but Standards are also designed with flexibility in mind, so with the right people in place it's certainly manageable. [16:05] How has Blackmores' ISO Support helped? Blackmores has assisted Wavenet with their ISO 45001, ISO 50001 and ISO 41001 (Facilities Management) implementation. ISO 41001 was later dropped as it was no longer applicable for the business. Standards can be quite hard to apply to your own business when looking at them at face value, the requirements sound generic because they're designed to apply to every type of business. This is where Blackmores experience as a consultancy can help with interpretation and practicalities of how a Standard will apply to your way of working. Blackmores will also assist with internal audits, which help identify non-conformities that may have been missed if it were not for a fresh pair of eyes. As Damian states: "I would rather have them identified before an external audit" as this gives you a chance to resolve issues or put an action plan in place before it gets to that stage. Damain also reminds everyone to not be afraid of your auditor, internal or external. They are not maliciously looking for problems, they simply help to highlight issues which can be resolved sp you can improve as a business. No Management System is perfect, the important thing is that you can recognise when something needs addressing, and how you go about doing so. [19:30] What has Damian learned while managing ISO Standards? Damian has learned to not think of ISO as a tick box exercise, it's a tool to help businesses improve. He has also learned that you don't need to reinvent the wheel when Implementing a Management System. You likely already have much of what's required in place, but not monitored or organised regularly. For example, aspects such as 'Management Review' may already be happening in existing meetings with top management, you simply need to ensure these are minuted, cover what needs to be discussed in regards to the Management System, and make note of any gaps that need to be addressed. Businesses like Wavenet that have been in operation for 26 years know what they're doing, and are likely already following best practice. You don't need to restructure your business to meet an ISO Standard, but rather integrate the Standard requirements with how you already operate. If done correctly, it should become a simple part of your day-today tasks. Damian jokingly states: "What's my role? I sometimes say it's to do as little as possible", as the more a business is aligned with a Standard, the less you will have to do to upkeep that. [22:55] What benefits have Wavenet experienced as a result of their ISO certifications? As mentioned earlier, a lot of won business is due to ISO certification. Certain certifications are simply a tender or client requirement. Standards such as ISO 50001 tackle their energy consumption. It's focus on reducing that will inevitably lead to reduced business costs. Since implementing the Standard, Wavenet now have monthly meetings to monitor energy use, which gives them a good basis to make informed decisions on where energy use is concerned. Damian has found that over time, good practice has been so embedded that people are using it in their everyday behaviors without even realising it. He's heard people in their resolutions team use terminology like 'root cause' without knowing where it came from. He's seen team making use of skill matrix's when evaluating the competence of certain teams such as engineering for client visits. So, people within the business are using ISO terminology and techniques to ensure best practice without being explicitly asked to. It simply works as a method to drive the business effectively when implemented correctly. [26:15] Damian's top tip for aspiring ISO implementors: Apart from approaching a consultancy like Blackmores to help if it's your first time going through the process, it's got to be leadership commitment. Top management need to be actively promoting ISO within the business, and they should be involved with the process. You need everyone's buy-in to make a system work, and that is made much easier if it's driven from the top down. Another tip is that a Management System should be a team effort. It shouldn't just be the responsibility of one person, you need input from everyone in the business to ensure you've covered all angles and risks that could affect your business. Lastly, look at what you already have in place and try and integrate the Standard into that. Don't make more work for yourself if you don't have to, you likely already have the bones in place. [28:20] Damian's book recommendation: The Thursday Murder Book Club – by Richard Osmond [29:10] Damian's favourite quote? "Hard work beats talent when talent doesn't beat work hard." And: "You miss 100% of the shots you don't take" To learn more about Wavenet, check out their website and keep up-to-date with their latest news via their LinkedIn page. If you'd like any assistance with your ISO Implementation or need any additional ISO Support, contact us, we'd be happy to help. We'd love to hear your views and comments about the ISO Show, here's how: ●     Share the ISO Show on Twitter or Linkedin ●     Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one. Subscribe to keep up-to-date with our latest episodes: Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List

No Password Required
No Password Required Podcast Episode 73 - Mudita Khurana

No Password Required

Play Episode Listen Later Jun 9, 2026 28:13


Show Summary:    Mudita Khurana — Tech Lead at Airbnb and the person who always says, “I got this” No Password Required Season 7: Episode 6 - Mudita Khurana   Mudita Khurana is a Tech Lead for Automated Tooling and Vulnerability Management at Airbnb, where she focuses on building modular, scalable security systems in an era of rapidly evolving AI threats. Before Airbnb, she spent nearly a decade in security roles across Accenture, Meta, and PwC, making bold career pivots along the way, including turning down a PwC return offer to join Facebook's product security team. In this episode, Mudita shares her journey from a family of doctors in India to Carnegie Mellon and into the heart of Big Tech security. She discusses what it means to thrive as a non-traditional engineer in a deeply technical field, why she stepped back from management to get closer to the work, and how she thinks about building security tooling that won't be obsolete in three months. Jack Clabby and co-host Kayley Melton, recording live from Tampa B-Sides at the University of South Florida, talk with Mudita about imposter syndrome, AI's curveballs for security teams, leadership without a leadership title, and the importance of community in staying on top of a field that never stops moving. She also reflects on what great mentorship looks like early in a career and why clarity, ownership, and consistency are the leadership qualities she keeps coming back to. In the Lifestyle Polygraph, Mudita firmly plants her flag in the Harry Potter universe as Hermione, explains why Deadpool doesn't qualify as a superhero, debates gym vs. nature as a reset strategy, and reveals her dream remote work base: a high-altitude Buddhist mountain town in the Himalayas.   Follow Mudita on LinkedIn: https://www.linkedin.com/in/muditakhurana/     In this episode: Mudita shares her unconventional path into cybersecurity, highlighting the importance of mentorship and curiosity (0:25 - 1:37) The significance of mentorship, especially Vandana Verma, in her career development (2:26 - 4:00) Transition from management to technical IC roles and why staying close to technical work matters (9:29 - 10:23) The influence of her education at Carnegie Mellon and how it broadened her problem-solving skills (6:23 - 7:41) Navigating imposter syndrome and embracing challenges as growth opportunities (3:26 - 5:29) How AI is changing cybersecurity strategies—building modular, layered systems for agility (15:31 - 16:26) The importance of community, trust, and consensus in cybersecurity decision-making (17:06 - 17:47) Mudita's favorite places for remote work and balancing planning with spontaneity in travel (23:01 - 24:13) Her personal approach to wellness, exercise, and resets during busy days (21:32 - 22:36) Her unique perspective on superhero characters, favorite places, and cultural roots (18:54 - 19:36, 25:19 - 26:21) Timestamp Highlights: (00:25) Mudita's 10-year journey into cybersecurity starting from India (02:26) Mentorship's critical role in her growth and her admiration for Vandana Verma (09:29) Transition from management back to technical roles and why staying close to the work matters (15:31) How AI fosters layered, modular security systems for faster adaptation (17:06) The importance of community and trusted information sources in security (21:32) Reset routines—gym versus nature hikes—and staying grounded during busy days (25:19) Leh, Ladakh: Mudita's ideal remote work location nestled in Himalayan beauty Resources & Links: Vandana Verma - Influential mentor in cybersecurity ThreatLocker - Supporter of this podcast Cyber Florida – The Mother Ship

The Amp Hour Electronics Podcast
#725 – The Secret Life of Circuits with lcamtuf / Michał Zalewski

The Amp Hour Electronics Podcast

Play Episode Listen Later Jun 4, 2026 59:56


Welcome Michał Zalewski, AKA lcamtuf! The lcamtuf Substack is where Michał is writing most these days Chris first found and geeked out about the CNC guide on the lcamtuf original site (discussed many times here) Michał is interested in the craft of teaching electronics He recently published The Secret Life of Circuits with No Starch Press Use the code AMPHOUR26 for 30% off The Secret Life of Circuits valid from June 1st through June 30th It was announced on his blog here Deriving fomulas from basic trigonometry sometimes bugs people who think electronics should only work with calculus Software geeks follow the site, often getting lots of attention on Hacker News Row hammer DRAM There were no Information Security degrees in the early days, so the field was made up of folks with backgrounds in math and EEs Fuzzing for security SMBC cartoon for blming humans Books American Fuzzy Lop The Tangled Web P0f v3 Silence on the Wire Security stuff (including books on the subject) ages over time, as opposed to electronics On the subjects of Calculators (and Michał’s collection) Calculators are a footnote in the history of computing, but still intriguing Dead ends in calculators CRT displays on calculators Nixie tubes Discrete moving into logic gates into processors Mechanical calculators are rare and get a high price online Working with transistors The Secret Life of Circuits start with FET based transistors vs BJT BJTs are often right after diode chapter because of the multiple junctions in an NPN, but that doesn’t make it easier to understand Projects A recent project involved making a clock out of current meters  Woodworking and AI example Want to see all lcamtuf articles in one place? Sokoban Sir box-a-lot

Cyber Risk Management Podcast
EP 211: What Sea-Tac's Ransomware Revealed

Cyber Risk Management Podcast

Play Episode Listen Later Jun 2, 2026 47:05


In August 2024, a ransomware attack shut down baggage systems, flight displays, and Wi-Fi at Sea-Tac Airport. What did it reveal about how executives think about cyber investment? And why is “how much more security do we need?” the wrong question to ask after a major incident? Let's find out with our guest Stephanie Warren, Assistant Director of Information Security at the Port of Seattle, who lived through that attack and came out the other side with hard-won lessons about executive decision-making under pressure. Your hosts are Kip Boyle, CISO with Cyber Risk Opportunities, and Jake Bernstein, Partner with K&L Gates. LinkedIn profile – https://www.linkedin.com/in/stephanie-warren-0746343/

No Password Required
No Password Required Podcast Episode 72 - Madeline Sedgwick

No Password Required

Play Episode Listen Later May 25, 2026 50:44


Madeline Sedgwick — Cyber Threat Analyst at Palo Alto Networks and a DUUUUVALLL lifer No Password Required Season 7: Episode 5 – Madeline Sedgwick   Madeline Sedgwick is a  Cyber threat Researcher and Threat Analyst at Palo Alto Networks Unit 42, specializing in nation-state cyber activity, covert infrastructure, and cyber intelligence analysis. Before entering the private sector, she spent six years in the U.S. Navy as an intelligence specialist, helping support some of the earliest cyber operations under United States Cyber Command. In this episode, Madeline shares her journey from joining the Navy to becoming one of the first certified cyber targeteers supporting offensive cyber operations. She discusses the realities of tracking covert threat actor infrastructure, why defenders must understand adversary behavior beyond alerts and signatures, and how intelligence analysis helps uncover the bigger picture behind cyber campaigns. 
Jack Clabby and co-host Sarina Gandy talk with Madeline about fusion analysis, cyber warfare, leadership, and the challenges of translating highly technical investigations into actionable insights for government and industry leaders. She also reflects on the importance of humility in leadership, mentoring, and learning to navigate high-pressure situations with confidence and curiosity. 
In the Lifestyle Polygraph, Madeline debates cybersecurity in the Star Wars universe, explains her Weird Al Yankovic Dragon Con costume, reflects on her time playing bass in a metal band, and proudly shares why Jacksonville, Florida, will always be home.   Follow Madeline on Linked in: https://www.linkedin.com/in/mesedgwick/ Chapters:  02:10 Intro-Madeline Sedgwick  09:00 The Role of Cybersecurity in National Security 12:08 Understanding Covert Networks and Threat Intelligence 14:52 Fusion Analysis in Cybersecurity 18:04 The Importance of Distinguishing Threats 20:52 Challenges in Cybersecurity Response 23:58 Briefing Decision Makers on Cyber Threats 27:52 Understanding Adversary Intent and Risk Communication 30:12 Leadership Lessons from the Navy 34:33 The Importance of Mentorship in Career Development 37:30 The Lifestyle Polygraph: A Fun Twist on Cybersecurity 41:04 Embracing Creativity and Personal Expression 45:50 Pride in Roots: The Jacksonville Connection

The Aubrey Masango Show
Crime-time: South Africa ranks top in the continent in suffering from cyberattacks

The Aubrey Masango Show

Play Episode Listen Later May 14, 2026 46:21 Transcription Available


Aubrey Masango speaks to Chad Thomas, Crime Expert at IRS Forensic Investigations on South Africa being ranked top in the continent in the number of cyberattacks on companies and institutions. They also explore some of the reasons why there's been an increased number of cyberattacks in the country over the years. Tags: 702, The Aubrey Masango Show, Aubrey Masango, Crime Time, Cyber-Crime, Cyber Security, Hacking, Data Breaches, Technology, Artificial Intelligence, Deep Fakes, Phishing, POPIA, Information Security, Encryption The Aubrey Masango Show is presented by late night radio broadcaster Aubrey Masango. Aubrey hosts in-depth interviews on controversial political issues and chats to experts offering life advice and guidance in areas of psychology, personal finance and more. All Aubrey’s interviews are podcasted for you to catch-up and listen. Thank you for listening to this podcast from The Aubrey Masango Show. Listen live on weekdays between 20:00 and 24:00 (SA Time) to The Aubrey Masango Show broadcast on 702 https://buff.ly/gk3y0Kj and on CapeTalk between 20:00 and 21:00 (SA Time) https://buff.ly/NnFM3Nk Find out more about the show here https://buff.ly/lzyKCv0 and get all the catch-up podcasts https://buff.ly/rT6znsn Subscribe to the 702 and CapeTalk Daily and Weekly Newsletters https://buff.ly/v5mfet Follow us on social media: 702 on Facebook: https://www.facebook.com/TalkRadio702 702 on TikTok: https://www.tiktok.com/@talkradio702 702 on Instagram: https://www.instagram.com/talkradio702/ 702 on X: https://x.com/Radio702 702 on YouTube: https://www.youtube.com/@radio702 CapeTalk on Facebook: https://www.facebook.com/CapeTalk CapeTalk on TikTok: https://www.tiktok.com/@capetalk CapeTalk on Instagram: https://www.instagram.com/ CapeTalk on X: https://x.com/CapeTalk CapeTalk on YouTube: https://www.youtube.com/@CapeTalk567See omnystudio.com/listener for privacy information.

The Cybersecurity Defenders Podcast
How AI adoption in enterprise infrastructure has expanded the attack surface with Katherine McNamara from Cisco / Defender Fridays [#318]

The Cybersecurity Defenders Podcast

Play Episode Listen Later May 4, 2026 36:15


Today on Defender Fridays, Katherine McNamara, Cybersecurity Technical Solutions Architect at Cisco, joins us to discuss how AI and ML adoption in enterprise infrastructure has expanded the attack surface for AI-driven systems.She'll walk through the security challenges unique to generative AI and ML-based architectures, and cover the four critical components: Model, Data, Application, and System, that organizations need to secure to maintain integrity.Katherine works for Cisco as a Cybersecurity Systems Engineer by day and by night, she's labbing and trying new things with the resources she has available. Katherine loves technology and getting her hands into the CLI or trying something new. She holds a Bachelors of Science and Masters of Information Security and Assurance from Western Governors University as well as several industry certifications. Register for Live SessionsJoin us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.Register here: https://limacharlie.io/defender-fridaysSubscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!Sponsored by LimaCharlieThis episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.Why LimaCharlie?Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.Try the Agentic SecOps Workspace free: https://limacharlie.ioLearn more: https://docs.limacharlie.io/Follow LimaCharlieSign up for free: https://limacharlie.io/LinkedIn: / limacharlieio X: https://x.com/limacharlieioCommunity Discourse: https://community.limacharlie.com/Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie

ILTA
#0178: (WIS) SheSecures: Voices from Women in Legal Security - Sherri Vollick

ILTA

Play Episode Listen Later May 2, 2026 16:11


SheSecures is an ILTA Women in Security podcast series dedicated to amplifying the experiences, expertise, and leadership of women shaping the future of legal security. Each episode is designed to be approachable and useful, with real takeaways you can apply in your own role. This month's episode is with Sherri Vollick.  Sherri is a strategic and accomplished cyber and risk leader with deep expertise in security operations, governance, risk and compliance, secure application development, and cloud security. Sherri currently serves as Director of Information Security & Compliance at Saul Ewing LLP and is an active mentor and contributor within the broader information security community.

Segurança Legal
#416 – Saber sem conhecer

Segurança Legal

Play Episode Listen Later Apr 30, 2026 43:03


Neste episódio comentamos sobre os desafios e as soluções técnicas para a aferição de idade na internet, um tema que ganhou forte destaque com as novas regras do ECA Digital. Você irá descobrir como funcionam os protocolos de conhecimento zero, também conhecidos como Zero-Knowledge Protocol ou ZKP, e de que forma eles permitem comprovar a maioridade de um usuário sem expor dados pessoais sensíveis. Você entenderá a diferença entre ferramentas invasivas, como a biometria facial, e métodos técnicos que respeitam a privacidade e a proteção de dados, utilizando criptografia aplicada e padrões internacionais de segurança da informação. Além disso, você vai aprender sobre os impactos práticos da regulamentação da ANPD no controle de acesso a conteúdos restritos e como evitar o rastreamento excessivo por grandes empresas de tecnologia. O debate também aborda táticas de engenharia social, destacando uma série educativa sobre phishing baseada na psicologia da fraude, que é um conhecimento essencial para evitar golpes online e vazamento de dados. Ao longo da discussão, você verá que é possível equilibrar a proteção no ambiente digital com a garantia da intimidade, sem adotar modelos de vigilância em massa durante a autenticação de sistemas. Para não perder nenhuma discussão sobre tecnologia, direito e sociedade, assine o podcast na sua plataforma de áudio favorita e siga nossos perfis no YouTube, Mastodon, Blue Sky, Instagram e TikTok. Aproveite para avaliar o programa e compartilhar o conteúdo com outras pessoas interessadas no assunto. Você também pode apoiar o projeto acessando a plataforma de financiamento coletivo indicada no áudio ou enviando suas dúvidas e sugestões diretamente para o nosso e-mail oficial. Esta descrição foi realizada a partir do áudio do podcast com o uso de IA, com revisão humana  Visite nossa campanha de financiamento coletivo e nos apoie!  Conheça o Blog da BrownPipe Consultoria e se inscreva no nosso mailing ShowNotes The Psychology of Fraud, Persuasion and Scam Techniques LEI Nº 15.211, DE 17 DE SETEMBRO DE 2025 – Dispõe sobre a proteção de crianças e adolescentes em ambientes digitais (Estatuto Digital da Criança e do Adolescente) DECRETO Nº 12.880, DE 18 DE MARÇO DE 2026 – Regulamenta a Lei nº 15.211, de 17 de setembro de 2025, que dispõe sobre a proteção de crianças e adolescentes em ambientes digitais, e institui a Política Nacional de Promoção e Proteção dos Direitos da Criança e do Adolescente no Ambiente Digital. Mecanismos confiáveis de aferição de idade – ORIENTAÇÕES PRELIMINARES Radar tecnológico – Mecanismos de aferição de idade

The Cybersecurity Readiness Podcast Series
The Clock Is Ticking: Navigating Quantum Risk and the Path to Crypto Agility

The Cybersecurity Readiness Podcast Series

Play Episode Listen Later Apr 29, 2026 40:53


In Episode 103 of the Cybersecurity Readiness Podcast Series, Dr. Dave Chatterjee is joined by Peterson Gutierrez—Vice President of Information Security at Barracuda Networks and a 28-year cybersecurity veteran with experience spanning private industry, the Big Four, and New York City Cyber Command—to examine one of the most consequential and underestimated challenges facing security leaders today: the quantum computing threat and what it truly means to become cryptographically agile.Opening with a vivid scenario—a healthcare organization whose encrypted data is exfiltrated today and decrypted after a quantum breakthrough years from now—Dr. Chatterjee introduces the concept of Q Day risk: the danger is not a dramatic breach tomorrow, but decisions made today that leave organizations exposed later. The episode moves beyond the industry's fixation on which post-quantum algorithm to adopt, making the case that algorithm selection is the wrong problem to solve. The right goal is crypto agility: the organizational discipline to abstract encryption from code and adapt continuously as the cryptographic landscape evolves.Framed through Dr. Chatterjee's Commitment–Preparedness–Discipline (CPD) lens, the conversation delivers a clear and actionable message: crypto agility is not a technical upgrade—it is a leadership, architecture, and governance challenge that requires executive ownership, modular system design, proactive vendor engagement, and continuous organizational discipline before Q Day makes inaction catastrophic.To access and download the entire podcast summary with discussion highlights - https://www.dchatte.com/episode-103-the-clock-is-ticking-navigating-quantum-risk-and-the-path-to-crypto-agility/Connect with Host Dr. Dave ChatterjeeLinkedIn: https://www.linkedin.com/in/dchatte/ Website: https://dchatte.com/Books PublishedThe DeepFake ConspiracyCybersecurity Readiness: A Holistic and High-Performance ApproachArticles & Cases PublishedChatterjee, D. (2026). Root: Automating the Remediation Gap, Ivey Publishing, Jan 7, 2026.Ramasastry, C. and Chatterjee, D. (2025). Trusona: Recruiting For The Hacker Mindset, Ivey Publishing, Oct 3, 2025.Chatterjee, D. and Leslie, A. (2024). “Ignorance is not bliss: A human-centered whole-of-enterprise approach to cybersecurity preparedness,” Business Horizons, Accepted on Oct 29, 2024.Isik, O., Chatterjee, D., and Lourenco, D.A. (2024). “Getting Cybersecurity Right,” California Management Review — Insights, Accepted for Publication, July 8, 2024. Chatterjee, D. (2023). “Mission critical – How American Cancer Society successfully and securely migrated to the cloud amid the pandemic,” I by IMD, March 13, 2023.Chatterjee, D. (2022). “Preventing security breaches must start at the top,” I by IMD, September 28, 2022, Institute for Management Development, Lausanne, SwitzerlandChatterjee, D. (2022). “Making Cybersecurity Readiness Mainstream,” Executive Blog Post, NETSPI, March 1, 2022Benz, M. and Chatterjee, D. (2020). “Calculated Risk? A Cybersecurity Evaluation Tool for SMEs,” Business Horizons, available online from May 4, 2020Chatterjee, D. (2019). “Should Executives Go To Jail Over Cyber Attacks,” Journal of Organizational Computing and Electronic Commerce, Vol 29, Issue 1, pp. 1-3.Abraham, C., Chatterjee, D., and Sims, R. (2019). “Muddling through cybersecurity: Insights from the U.S. healthcare industry,” Business Horizons, July 2019.

The Cybersecurity Defenders Podcast
Real examples of AI-powered code scanning with Jeff McJunkin from Rogue Valley Information Security / Defender Fridays [#315]

The Cybersecurity Defenders Podcast

Play Episode Listen Later Apr 27, 2026 32:41


Jeff McJunkin, Founder of Rogue Valley Information Security, joins Defender Fridays to talk AI-powered code scanning for vulnerabilities. Jeff walks through real examples including using AI to find privilege escalation bugs in the Linux kernel.Jeff McJunkin is the founder of Rogue Valley Information Security, a consulting firm specializing in penetration testing and red team engagements. Jeff found the offensive side of cyber security very alluring during one the first penetration tests of his career. Feeling the challenge of host defenses like AV and centralized logging, and, at the time, knowing nothing about AV evasion or avoiding events that are likely to cause alerts, it was all very exciting. The challenge of successfully accomplishing the goal of that pen test, using essentially only native tools, was addictive for Jeff. He was hooked. Since those first penetration tests, Jeff has gone on to become an expert in the field, doing assessments for Fortune 100 companies, architecting two major versions of Core NetWars Experience, and contributing a vast amount of material to SANS Penetration Testing.Register for Live SessionsJoin us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.Register here: https://limacharlie.io/defender-fridaysSubscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!Sponsored by LimaCharlieThis episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.Why LimaCharlie?Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.Try the Agentic SecOps Workspace free: https://limacharlie.ioLearn more: https://docs.limacharlie.io/Follow LimaCharlieSign up for free: https://limacharlie.io/LinkedIn: / limacharlieio X: https://x.com/limacharlieioCommunity Discourse: https://community.limacharlie.com/Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie

No Password Required
No Password Required Breakout Room with Fagan Afandiyev

No Password Required

Play Episode Listen Later Apr 21, 2026 20:28


Fagan Afandiyev — Elite Cybersecurity Competitor and Legendary Whitehatter No Password Required: Breakout Room: Episode 1 — Fagan Afandiyev Fagan Afandiyev is a cybersecurity student at the University of South Florida and a member of the CyberHerd competition team, known for his strategic mindset and passion for solving complex challenges. From competing in international robotics competitions to discovering cybersecurity through hands-on platforms, Fagan has built his skills through curiosity, persistence, and a love for problem solving. Fagan shares how competitions, community, and continuous learning shaped his journey into cybersecurity. He walks through his growth within USF's cyber community, and how that led to a penetration testing internship at Microsoft. He also offers insight into the mindset needed to succeed in cybersecurity, encouraging others to embrace challenges, learn through failure, and find enjoyment in the process. Follow Fagan on Linked in here: https://www.linkedin.com/in/fagan-afandi/ Presented by ThreatLocker Chapters:  00:00 Introduction to Cybersecurity Passion 3:02   Journey to Cyber Herd and University Life 06:12 Internship at Microsoft and Career Aspirations 08:59 Hackathon Experience and Community Engagement 12:39 Behind the Scenes of Cyber Competitions 14:30  Overcoming Challenges in Cyber Competitions 18:00 Gratitude and Mentorship in Cybersecurity  

Conversations with Valerie
Why you are stuck in your career | Adewale Adeife

Conversations with Valerie

Play Episode Listen Later Apr 10, 2026 41:37


In this conversation, I sit down with Adewale Adeife an Information Security manager to unpack a powerful shift in thinking about work, growth, and long-term success. We talk about the difference between a job and a career, and why many people stay stuck because they keep moving too quickly instead of building something that compounds over time. He introduces the idea of treating your career like a stock rather than something you keep trading for short-term gain. If you've ever felt like you're working hard but not really growing, or you're constantly starting over, this conversation is for you.Connect with Adewale:Instagram- https://www.instagram.com/adewale.adeife?LinkedIn- https://www.linkedin.com/in/adewaleadeife?Subscribe for more honest, faith-rooted conversations.

The Cybersecurity Defenders Podcast
Why cyber analysts are crucial in protecting public infrastructure with Michael Hamilton from PISCES International [#308]

The Cybersecurity Defenders Podcast

Play Episode Listen Later Apr 8, 2026 45:14


Michael Hamilton, Chief Technology Officer at PISCES International, joins us to discuss the benefits of providing real world experience to students while they protect existing public infrastructure. The resilient future of local government security rests in our ability to adapt to changing threats and adopt new technologies, including AI.Learn more at https://pisces-intl.org/30 years in Information Security as a practitioner, entrepreneur, consultant, and in executive management. Direct experience in retail, manufacturing, government, defense, academic, semiconductor, energy, law enforcement, transportation, publishing and financial sectors - from Fortune 1 to small nonprofits. Formerly: Policy Advisor to Washington State, Chief Information Security Officer for the City of Seattle, and Managing Consultant for VeriSign Global Security Consulting. Former Vice-Chair of the DHS State, Local, Tribal and Territorial Government Coordinating Council.Currently: Field CISO, Lumifi CyberSupport our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at limacharlie.io

The ISO Show
#247 How do ISO 27001 Information Security and ISO 42001 AI Management compare?

The ISO Show

Play Episode Listen Later Apr 1, 2026 23:31


Information is increasingly becoming the number one priority for businesses. With so many of us reliant on tech to stay in operation, there is an inevitable increase in data breaches and incidents year-on-year. The addition of new AI driven technology has added a new layer of complexity to the information security landscape, regarding both the new risks using the technology brings as well as falling prey to more complex AI led scams.   Thankfully ISO Standards are here to help, with ISO 27001 tackling general information security and ISO 42001 for effective AI Management. But how do these two compare, and is there merit in implementing both? In this episode, Ian Battersby is joined by Bas Von Hertom, Cyber Security Specialist at TUV Nord, to discuss what ISO 27001 and ISO 42001 are, the main differences between the Standards and how they can complement each other when integrated.   You'll learn ·      Who is Bas Von Hertom? ·      Who are TUV Nord? ·      What are ISO 27001 and ISO 42001? ·      How does ISO 42001 support regulatory frameworks such as the EU AI Act? ·      How do ISO 27001 and ISO 42001 differ in managing information security risks? ·      Other key differences between ISO 27001 and ISO 42001 ·      How much more work is involved for Implementing ISO 42001 if you already have ISO 27001 in place? ·      Can ISO 27001 and ISO 42001 be integrated? ·      What organisations should be implementing both Standards? ·      How are Certification Bodies quoting for ISO 27001 and ISO 42001? ·      Bas's advice to leadership teams looking to build a case for full certification   Resources ·      TUV Nord ·      Isologyhub   In this episode, we talk about: [02:05] Episode Summary – Ian is joined by Bas Von Hertom, Cyber Security Specialist at TUV Nord, to explore the differences between ISO 27001 and ISO 42001 and the benefits of integrating both Standards. [02:30] Who is Bas Von Hertom? Bas is the Cyber Security Specialist at TUV Nord. He is a lead auditor for Standards including ISO 27001, ISO 42001, TISAX and standards specifically for industrial automation. Bas had once stated around 5 years ago that he would never pursue a career in auditing, but once he came into contact with TUV Nord he decided to give it a go. Before joining TUV, he was a very hands-on systems administrator and many of those skills transferred well into auditing. [04:45] Who are TUV Nord? TUV Nord are a UKAS accredited Certification Body. They also offer services for testing and inspection. TUV have worked with a large range of sectors, from manufacturing and energy to IT, healthcare and even space. [06:25] What are ISO 27001 and ISO 42001? ISO 27001 is the Standard for Information Security Management, with compliant management systems being called an ISMS. It provides structure for identifying, assessing, and managing risks related to the information security while also ensuring availability and resilience on the information security. ISO 42001 AI Management is a much more recent Standard, being published in December of 2024. It focuses on ethical and effective AI management, with a system that applies to relevant products in addition to the wider business. [07:30] How does ISO 42001 support regulatory frameworks such as the EU AI Act? The EU AI Act sets out legal obligations that organisations offering AI products must comply with, however it only defines the rules rather than providing any implementation guidance. This is where ISO 42001 can fill the gaps, by providing a framework that will meet these regulatory requirements. [08:45] How do ISO 27001 and ISO 42001 differ in managing information security risks? Both Standards take a risk-based approach to their subject matter, but the nature of the risks that each address are what differ. ISO 27001 focuses on risks that relate to the protection of information assets based on confidentiality, integrity and availability of information. It's also ensures that business objectives are clearly defined and aligned with business strategy. ISO 42001 on the other hand deals with a broader and more complex set of risks, because it also looks at ethical considerations. This can includes the monitoring and measurement of ethical risks such as AI bias and discrimination. It also looks at societal, legal and reputational risks as one of ISO 42001's key values is creating trust within the AI space. [10:10] Other key differences between ISO 27001 and ISO 42001: Besides their subject matter, another key difference is the way objectives are framed and evaluated. In ISO 42001 these objectives have to be aligned with the Annexes within the Standard, which is something not commonly done when implementing ISO 27001. ISO 42001 also requires an 'AI Impact Assessment', which again, aligns with the systems objectives as the results of the AI Impact Assessment will describe the way bias, ethical and societal considerations impact other requirements within ISO 42001. [11:00] How much more work is involved for Implementing ISO 42001 if you already have ISO 27001 in place? If you already have ISO 27001 in place, you have a strong foundation for ISO 42001. ISO 27001 puts the fundamental base in place, with a governance structure, risk assessment processes, internal audits, corrective actions and methods for continual improvement. There's a lot of overlap where the high-level requirements are concerned. However, ISO 42001 also looks at AI products and services, which differs from ISO 27001.   ISO 42001 may also require additional training for those involved with the management systems and the AI products and services. [12:15] Can ISO 27001 and ISO 42001 be integrated? Yes, and in fact, Bas highly encourages it! If you intend to implement both Standards, it's much more efficient to do so as an integrated management system. They both utilise the Annex SL format, a high-level structure that's shared with most ISO Standards, so they're designed to be integrated. This also saves on duplication of effort where documentation is concerned and also potentially on cost if you require additional support with implementation. [13:30] What organisations should be implementing both Standards? Both ISO 27001 and ISO 42001 can apply to any business. Most businesses are now utilising AI in some form, and ISO 42001 can apply to those using it just as much as it does to those developing their own AI tools or selling related services. However, sectors where ISO 42001 will likely become fundamental include the financial sector, where AI tools for fraud detection are becoming popular. There's also a growing need for it within the medical field as AI is increasingly used for research and development. [14:30] How are Certification Bodies quoting for ISO 27001 and ISO 42001? There are a number of variables that Certification Bodies use to work out certification costs, these include size of the organisation and business complexity. This can be tricky to calculate for ISO 42001 as you need to consider the amount of AI systems used before you can provide a quote. The full requirements for this are described in ISO 42006, which is a guidance Standard. Most certification bodies will offer a discount for the combined certification to both Standards. An integrated approach is certainly something that Bas recommends, in addition to ensuring that you keep the same auditor or audit team throughout the implementation. By having one team for both systems, you can complete combined internal audits to save on time and resources.   [16:20] Bas's advice to leadership teams looking to build a case for full certification: First of all, don't wait, just make a start. A lot of businesses make the mistake of waiting until it's a common requirement within their market, which can leave you lagging behind the curve. Instead, strive to be one of the early adopters as that will give you a strategic advantage in the market. This is especially the case if you already have ISO 27001 in place. You already have the foundational knowledge to implement ISO 42001, so just make a start on looking at risks relevant to ISO 42001. Many businesses opt to implement certain Standard due to the demands of their clients, and ISO 42001 is likely to be added to that list. So it's better to get a head start! Bas also recommends finding sources of guidance on ISO 42001 implementation. Whether that's sourcing training or an external party to advise, it's good to have other sources of knowledge of you're not familiar with the Standard or ISO implementation as a whole. [21:30] Bas's favourite quote: We don't rise to the level of our expectation, but we fall to the level of the systems that we use. If you'd like to find out more TUV Nord or are looking for ISO 27001 and ISO 42001 certification, check out their website. We'd love to hear your views and comments about the ISO Show, here's how: ●     Share the ISO Show on Twitter or Linkedin ●     Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one. Subscribe to keep up-to-date with our latest episodes: Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List

AI in Action Podcast
Cybersecurity Series E17: 'Cyber Strategies and Leadership' with CIE's Jane Corr

AI in Action Podcast

Play Episode Listen Later Mar 23, 2026 15:24


Today's guest is Jane Corr, Head of Cyber Security at CIE (Córas Iompair Éireann). Founded in 1945, CIE is Ireland's state-owned public transport group, providing rail and bus services nationwide through its operating companies Iarnród Éireann, Dublin Bus and Bus Éireann. Headquartered in Dublin, the group plays a central role in connecting communities, supporting economic activity and delivering sustainable mobility, carrying hundreds of millions of passenger journeys across Ireland each year.Jane is an accomplished Information Security and IT leader with a proven track record of building high-performing teams and delivering results. Known for her “can-do” attitude and strong customer focus, Jane brings a structured approach to solving complex challenges. Her expertise spans information security, technology risk, programme delivery, IT operations and data centre management within large organisations. She is also highly experienced in presenting to Boards and executive leadership.In the episode, Jane discusses:0:00 Her journey from Infrastructure leader to cybersecurity2:55 Why cyber leaders must communicate concisely and confidently5:36 Her broad CSO role including AI, regulation, talent and influence7:14 Advice to start with strategy, align people, roadmap and governance8:55 The need to embed cyber as accessible service, balance risk and compliance11:52 How cyber is maturing toward measurable, compliance-driven continuous improvementTo find out more about all the great work happening at CIE (Córas Iompair Éireann), check out the website www.cie.ie.

HLTH Matters
Why Healthcare Needs Cyber Resilience, Not Just Cybersecurity

HLTH Matters

Play Episode Listen Later Mar 12, 2026 23:45


In this episode of the Cybersecurity at ViVE series on The Beat Podcast, host Sandy Vance sits down with Chad Alessi, Managing Director of Cybersecurity at CTG, for a wide-ranging conversation about what it really takes to protect healthcare organizations in today's threat landscape. With a background spanning chemical engineering, the U.S. Marines, energy sector Operational Technology security, and IT consulting, Chad brings a unique cross-industry perspective to healthcare cybersecurity. From the difference between cybersecurity and cyber resilience to the rise of AI-powered attacks, this episode is packed with practical insights for healthcare leaders who want to stay ahead of what is coming. In this episode, they talk about how: Cyber resilience focuses on operational continuity when an attack happens, not just prevention Breaches resolved within 200 days can save organizations over $1 million Bad actors often sit idle inside networks for months, collecting data before launching an attack Baseline requirements are identity-first security, including multi-factor authentication (MFA) and privileged access management Human-only Security Operations Center (SOC) models are too slow to keep up with today's automated, AI-powered attacks CTG uses Microsoft's Unified Security Operations (SecOps) platform to eliminate tool sprawl and improve response time Zero-trust architecture is expanding from department-level to enterprise-wide in healthcare New HIPAA regulations now require provable network segmentation for legacy medical devices AI-assisted security operations will continue to grow in the next few years A Little About Chad: As CTG's Managing Director of Cybersecurity, Chad Alessi leverages decades of experience in technology, cybersecurity, and operational strategy across enterprise and mid-market sectors to meet the evolving cybersecurity needs of clients in the U.S. During his time in IT consulting, Chad was instrumental in driving IT transformation in the company's regulated pipeline and gas processing business units. He holds a BS in Chemical Engineering, an MBA from the University of Alabama, an MS in Information Systems with a concentration in Information Security from Syracuse University, and post-graduate certifications in leadership, full stack development, cybersecurity, and cloud computing. Chad is known for his strong work ethic, integrity, resourcefulness, and service-based leadership, which he attributes to his time in the U.S. Marine Corps.

Leaders In Payments
Special Series: The Trust Advantage with David Edwards, SVP Information Security at Payroc | Episode 472

Leaders In Payments

Play Episode Listen Later Mar 5, 2026 37:48 Transcription Available


What does it actually take to secure a payments company in an era of sophisticated, well-funded cybercriminals? In this first episode of The Trust Advantage Series, brought to you by Payroc, host Greg Myers sits down with David Edwards, Payroc's Senior Vice President of Information Security, for a candid and eye-opening conversation about modern cybersecurity in the payments industry.With 30 years in technology — spanning private banking, retail, and payments — David brings hard-won perspective to the questions keeping payments executives up at night. Sparked by a real-world ransomware attack on a payments company, this episode cuts through the compliance checkbox mentality to explore what genuine, operational security actually looks like.David and Greg cover a wide range of critical topics: why passing audits doesn't equal being secure, how AI has radically changed the phishing threat landscape, the three pillars of identity and vulnerability management, and why resilience — not prevention — is the new gold standard. David also breaks down Payroc's layered approach to ransomware defense, how the company integrates acquired platforms without creating security gaps, and the right questions ISVs, ISOs, banks, and merchants should be asking their payment partners.Whether you're a developer, a risk officer, or a business owner processing transactions, this episode delivers a masterclass in why security isn't just an IT issue — it's everyone's job.

RSA Conference
Cyber at the Top: Beyond Confidentiality: The New Priorities in Information Security

RSA Conference

Play Episode Listen Later Mar 5, 2026 24:53


For years, information security was largely centered on protecting confidentiality. But as our world becomes more digital and increasingly dependent on always-available, trustworthy systems, integrity and availability are taking on equal importance. In this episode of Cyber at the Top, Dr. Hugh Thompson is joined by Bjørn Watne, Global CISO of INTERPOL, to explore how this shift is changing the way security leaders think about risk. Together, they discuss why disruption is becoming a defining threat, how emerging technologies are reshaping security priorities, and what it means to balance all three pillars of information security. The conversation offers a thoughtful look at how CISOs can reframe security as a driver of resilience, reliability, and organizational trust.

The ISO Show
#245 What's The Difference Between TISAX and ISO 27001?

The ISO Show

Play Episode Listen Later Mar 4, 2026 23:39


For those in the automotive industry, namely suppliers working with European OEM's, you're likely familiar with TISAX but not necessarily with the Standard that many of its requirements originate from. ISO 27001 is the leading Information Management Standard, and its Annex A forms the basis of TISAX, however there are many differences between the two. For Automotive suppliers looking to create a more holistic Information Security Management System, it can be beneficial to implement elements of both even if you don't intend to certify to both. In this episode, Ian Battersby is joined by Emma Coxhill, isologist at Blackmores, to explore the differences between TISAX and ISO 27001, how existing ISO 27001 compliant management systems can be leveraged for TISAX compliance and the benefits of implementing both Standards for automotive suppliers. You'll learn ·      How does TISAX differ from ISO 27001? ·      How does the recertification / annual surveillance for TISAX and ISO 27001 differ? ·      Can a company have TISAX without ISO 27001 and vice versa? ·      How can an existing ISO 27001 certification be leveraged for TISAX? ·      What are the additional benefits of implementing both TISAX & ISO 27001? ·      What is a reasonable timeframe for implementing TISAX? ·      The key role of Internal Audits ·      How can Blackmores support companies in implementing TISAX? Resources ·      Register for our TISAX webinar here ·      ENX ·      Isologyhub   In this episode, we talk about: [02:05] Episode Summary – Emma Coxhill joins Ian to dive into the key differences between ISO 27001v Information Security and TISAX, including the benefits of implementing both and how each can be leveraged to assist in the implementation of the other.   [03:10] What is TISAX? TISAX was developed for the automotive industry by the German Association of the Automotive Industry, VDA, and it's managed by the ENX Association. It's based on the ISO 27001 Annex A controls, and was created for the automotive industry because they were looking to standardise the framework for assessing and sharing information security results between manufacturers and their suppliers. [04:20] How does TISAX differ from ISO 27001? ISO 27001 is a general Information Security management Standard, it can be applied to any business, whereas TISAX is only applicable to the automotive industry. ISO 27001 includes a framework of requirements that everyone must implement, whereas TISAX has a more customisable element. With TISAX you can select an applicable level and relevant subject areas for your operations. The last main difference is the fact that ISO 27001 certification ends in a certificate which can be shared and displayed wherever you want. TISAX in comparison has Labels, which are only available through the ENX portal where you have control over who can access them. [05:15] How does the recertification / annual surveillance for TISAX and ISO 27001 differ? The good news is that TISAX is a bit more forgiving than ISO when it comes to a recertification cycle. TISAX does not require an annual Surveillance like ISO 27001, instead once you've earned a Label it remains valid for 3 years. ISO 27001 in comparison requires an annual Surveillance for each year until the 3rd when you have your Recertification Audit. If you have a significant change to scope part way through your 3 years of TISAX, you will need to have a chat with your auditor to see if extra work is required. This will depend on your level, with higher levels likely to require some additional work and for you to adjust your scope within the ENX portal. Overall, a TISAX label is less of a burden than traditional Management System Standards like ISO 27001. However, TISAX is a lot more strict and will require more upfront preparation ahead of earning your Label. [07:30] Are Internal Audits required for TISAX? They are, but the amount and frequency are a lot more flexible than ISO 27001. You can do as many as you like, but at a bare minimum we recommend you conduct internal audits 6 months ahead of your TISAX label expiring to ensure you're ready for re-certification. You can of course carry on with annual internal audits to make sure you're on track. This can be handy if specific clients ask for further evidence of you following processes in accordance with TISAX requirements.   [08:35] Can a company have TISAX without ISO 27001 and vice versa? You can! Both are independent Standards, however they do compliment each other. Organisations that hold both have a competitive advantage, as ISO 27001 applies to all industries and is more widely recognised. However, if you only operate in the automotive space, TISAX may be sufficient. If you supply to multiple sectors, it's worth considering implementing both TISAX and ISO 27001. [09:25] How can an existing ISO 27001 certification be leveraged for TISAX? If you already hold an existing ISO 27001 certification, than you're already 80% of the way there to TISAX compliance. As TISAX is based off of ISO 27001's Annex A controls, a lot of the requirements cross over, so you will already have most of the foundations in place to cover TISAX. It will just be the more automotive specific requirements that will require some additional work. These requirements include considerations for: ·      Data Protection ·      Prototype protection ·      Assets ·      3rd Party Suppliers The amount of additional work will also depend on the TISAX Level you're aiming for, with Level 3 being the most demanding for these specific requirements. [10:55] What are the additional benefits of implementing both TISAX & ISO 27001? Benefits include: Robust Information Security – Having both TISAX and ISO 27001 forms a strong and versatile information security infrastructure that will cover all of your operations. Easy Integration – These two Standards complement each other, and can easily be integrated. If you already have ISO 27001 in place, you have already completed a majority of the framework and will be familiar with what's required to earn and keep both your ISO certificate and TISAX Label. Customer Trust and Long-Term Resilience – TISAX is desired, if not an outright requirement for European based OEM's to work with suppliers. They require this because TISAX is a trusted Standard, a Label displays your commitment to information security within the automotive industry. It also helps to put you in a better position to both safeguard data as well as respond in the event of a data / security incident. Wider market access – If you supply to more than just the automotive industry, than having ISO 27001 in place will grant you access to the wider market that will recognise that Standard over TISAX. [12:05] What is a reasonable timeframe for implementing TISAX? This will depend on a number of factors including the type of organisation, the number of sites, resources available etc. The key thing to note is that this is note a 2 week project, it will take a number of months to get everything in place for your external assessment. A good measure of if you're ready is if you can score at least more than 2.71 on your self-assessment, and have completed a few internal audits to double check. If you already have ISO 27001 in place, than you're looking at between 3 – 6 months. If you do not have ISO 27001 in place than you're looking at 6 months minimum. For Level 2, you will need proof that ,you have everything in place, it's all been communicated and the relevant individuals have been trained. Level 3 requires everything to be in place and operating for a certain amount of time, typically around 3 months is ideal to start building a library of evidence ahead of your external assessment. Emma's top tip: Be honest in your self-assessment. It's there to be a benchmark, and you need to reflect on the reality of your position if you're to accurately assess what Level you are ready to be assessed against. [14:20] Core elements for success: As with any Standard, ISO or otherwise, TISAX will require leadership commitment in order to be successful. The requirements of TISAX need to come from the top down, just like with ISO 27001. The Leadership ultimately drive TISAX's success, by ensuring the relevant resources are in place, and involved individuals have the necessary time to implement and maintain the Label. For those within the Automotive Sector, TISAX is becoming an absolute requirement. It's being pushed as a tender requirement, so you may lose out on business if you opt to not earn a Label. [16:35] The key role of Internal Audits: As mentioned earlier, Internal Audits are a key part of the process for both TISAX and ISO 27001. It acts as a business health check to ensure you're on the right path. They can help identify areas which may be non-conforming or simply highlight opportunities for improvement. For TISAX, there is not outright requirement for 3rd party audits ahead of your assessment, however we would recommend them as a fresh pair of eyes can reveal things you may have overlooked. An external auditor will also be more unbias and can provide an honest review and feedback as to what TISAX Level you are ready for.   [18:25] How can Blackmores support you with TISAX Implementation?: We can provide as little or as much support as needed. This can include a fully guided implementation where we assist you through each step. This can apply to both TISAX and ISO 27001 if you wish to certify to both Standards. Other options include: ·      Assisting with your TISAX self-assessment (aka a Gap Analysis) ·      Conducting a Maturity Assessment ·      Conducting internal audits ·      On-site support during your TISAX assessment audit We are happy to provide whatever level of support you need. Blackmores do not provide a tick-box exercise, we pride ourselves on ensuring an implemented system works for you. [21:10] Upcoming TISAX Webinar – Join us on the 18th March 2026 at 2pm for a webinar where we'll dive into TISAX further and provide practical guidance on how to complete the VDA Self-Assessment. Attendees will also get access to some freebies. So don't delay, register your place here today. We'd love to hear your views and comments about the ISO Show, here's how: ●     Share the ISO Show on Twitter or Linkedin ●     Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one. Subscribe to keep up-to-date with our latest episodes: Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List

Cracking Cyber Security Podcast from TEISS
teissTalk: Building a trusted security model for Generative and Agentic AI

Cracking Cyber Security Podcast from TEISS

Play Episode Listen Later Feb 26, 2026 44:16


Transferable lessons - how overlooking fundamental security and data trust leads to Generative and Agentic AI failuresSteps for embedding security checkpoints and governance directly into your AI pipelineStrategies to scale AI safely - avoiding costly retrofits - and positioning security as a key competitive advantageThom Langford, Host, teissTalkhttps://www.linkedin.com/in/thomlangford/Tim Roberts, Managing Director, AlixPartnershttps://www.linkedin.com/in/thrrobertsSatyam Rastogi, Director of Information Security & DevOps, BAMKOhttps://www.linkedin.com/in/hackersatyamrastogi/Deryck Mitchelson, Head of Global CISO Team & C-Suite Advisor, Check Pointhttps://www.linkedin.com/in/deryckmitchelson

Accenture InfoSec Beat
InfoSec Beat: Careers in Information Security – Client Data Protection

Accenture InfoSec Beat

Play Episode Listen Later Feb 20, 2026 27:33


This episode of the InfoSec Beat podcast focuses on careers in information security. Accenture CISO Kris Burkhardt talks with Dan Cosceari, the delivery lead for the Accenture Client Data Protection program, which helps internal teams treat client data properly and manage information security risk. Dan sees client data protection through customers' eyes. This customer-first mindset started in his restaurant days in New York City, and it drives how Dan protects client data today. Hear how he puts this into practice, advocates across the organization, and stays ahead of technology and regulatory changes.

No Password Required
No Password Required Podcast Episode 69 - Sue Serna

No Password Required

Play Episode Listen Later Feb 16, 2026 44:39


Sue Serna - Social Media Security and Governance Leader and Lover of All BeaglesNo Password Required Season 7: Episode 2 - Sue SernaSue Serna is the CEO and Founder of Serna Social and the former head of global social media at Cargill. She brings more than two decades of experience at the intersection of storytelling, strategy, and security.In this episode, she shares her journey from business reporter to leading her own consultancy serving companies around the world on social media strategy.Jack Clabby of Carlton Fields, P.A, joined by guest co-host Rex Wilson of Cyber Florida, welcomes Sue for a candid discussion about the realities of enterprise social media. From managing more than 150 Facebook pages for a single company, to navigating internal politics, agency relationships, and regulatory pressure, Sue explains why social media is far from “free” and why most organizations still under-resource it.Sue dives deep into the gap between social media teams and cybersecurity departments. She outlines how personal account compromises can escalate into enterprise-level incidents, why governance frameworks matter, and how large organizations can regain control of sprawling digital footprints. Drawing from real-world examples, she argues that social media must be treated like finance or HR, a core business function requiring structure, ownership, and accountability.The episode wraps with the Lifestyle Polygraph, where Sue reveals her love of Apollo-era space history, debates iconic Philadelphia traditions, and imagines what magical talent her beagle would bring to Hogwarts.Follow Sue at SernaSocial.com or connect with her on LinkedIn: https://www.linkedin.com/in/sueserna/ Chapters: 00:00 Introduction and First Impressions   02:45 The Evolving Role of Social Media in Corporations   04:58 Transitioning from Journalism to Social Media  11:11 Building Social Media from Scratch   13:00 Becoming a CEO and Founder   16:28 The Importance of Networking   16:54 Bridging the Gap Between Social Media and Cybersecurity  20:51 Real-World Social Media Security Incidents  28:35 Navigating Internal Conflicts in Social Media  30:32 The Lifestyle Polygraph Begins   31:17 Nerd Things That Expose Sue: Space and Harry Potter!  35:16 Sue's Love For Beagles  37:50 Wreckless Intern or Overconfident Executive?  40:42 Hogwarts and Magical Beagles 

Cracking Cyber Security Podcast from TEISS
teissTalk: Silent Swipers - unmasking info-stealers in today's threat landscape

Cracking Cyber Security Podcast from TEISS

Play Episode Listen Later Jan 29, 2026 44:57


Understanding the anatomy, infrastructure and automation of modern information-stealing malwareTracking delivery methods, evasion technique and high-value data targetsBuilding effective, multi-layered defences against the prevalent info-stealer familiesThom Langford, Host, teissTalkhttps://www.linkedin.com/in/thomlangford/Jim Walter, Senior Threat Researcher, SentinelOneBrett Taylor, SE Director UK&I, SentinelOnehttps://www.linkedin.com/in/effectiveleaderandmentor/Satyam Rastogi, Director of Information Security & DevOps, BAMKOhttps://www.linkedin.com/in/hackersatyamrastogi/

No Password Required
No Password Required Podcast Episode 68 — Rob Hughes

No Password Required

Play Episode Listen Later Jan 20, 2026 44:51


Rob Hughes — CISO at RSA and Champion of a Passwordless FutureNo Password Required Season 7:  Episode 1 - Rob HughesRob Hughes, the CISO at RSA, has more than 25 years of experience leading security and cloud infrastructure teams. In this episode, he reflects on his unconventional career path, from co-founding the original Geek.com and serving as its Chief Technologist during the early days of the internet, to leading security and systems design at Philips Home Monitoring.Jack Clabby of Carlton Fields, P.A. and Kayley Melton welcome Rob for a wide-ranging conversation on identity, leadership, and the realities of modern cybersecurity. Rob currently leads RSA's Security and Risk Office, overseeing cybersecurity, information security governance, and risk across both RSA's products and corporate environment.Rob explains his dream for a passwordless future. He unpacks why passwords remain one of the largest sources of cyber risk, how real-world incidents and password-spraying attacks have accelerated change, and why phishing-resistant technologies like passkeys may finally be reaching a tipping point.  The episode wraps with the Lifestyle Polygraph, where Rob lightens the conversation with stories about gaming with his kids, underrated horror films, and classic cars.Follow Rob on LinkedIn: https://www.linkedin.com/in/robert-hughes-816067a4/Chapters: 00:00 Introduction to No Password Required01:43 Meet Rob Hughes, CISO at RSA02:05 The Role of a CISO in a Security Company05:09 Transitioning to the CISO Role08:00 The Early Days of Geek.com12:14 Launching a Startup During the Dot Com Boom14:30 The Push for a Passwordless Future18:21 Tipping Point for Passwordless Adoption20:20 Ongoing Learning in Cybersecurity26:09 Managing Stress in High-Pressure Environments33:46 The Lifestyle Polygraph Begins34:15 Career Insights in Cybersecurity36:08 Dream Cars and Personal Preferences39:58 Underrated Horror Films41:19 Creating a Cybersecurity Monster

The Gate 15 Podcast Channel
The Gate 15 Interview EP 66: Chris Camacho: Cyber Risk, Building Communities, Nirvana, and Peruvian Chicken

The Gate 15 Podcast Channel

Play Episode Listen Later Jan 19, 2026 39:24


In this episode of The Gate 15 Interview, Andy Jabbour speaks with Chris Camacho. Chris is Abstract Security's Co-Founder and Chief Operating Officer (COO). In this role, Chris is responsible for the go-to-market strategy, company vision, growth, collaboration, and client engagement. He is a leader, innovator and community builder. Before co-founding Abstract Security, Chris served as both Chief Strategy Officer and Chief Revenue Officer at Flashpoint and was responsible for helping grow the company to an acquisition by Audax PE and supporting three acquisitions to Flashpoint's portfolio, which helped the company be an industry market leader in the information security market. Before his time at vendors like Abstract Security and Flashpoint, Chris was the Senior Vice President of Information Security at Bank of America, where he oversaw the Threat Management Program. An entrepreneur, Chris also served as CEO for NinjaJobs, a career-matching community for elite cybersecurity talent. As he continues to build trust and relationships throughout the cybersecurity community, he's now building C2 Corner, a space for security leaders to share stories, connect through experience, and build what's next together. Chris on LinkedIn.In the podcast Chris and Andy discuss:Chris's background and the road from financial services to becoming a vendor.Chris shares some threat perspective from deepfakes to the complexities of geopolitics and polarization.Chris talks about managing ever-increasing amounts of data and how Abstract Security is helping organizations to reduce risk.We discuss the idea of AI SOCs helping to enhance security operations.The importance of community building: from trust groups and ISACs to C2 Corner to in-person meet-ups!Chris shares some career advice, andWe play 3 Questions! and talk Chris's favorite meats, reading books (and writing books?), and the glory of the 90s.Selected links:Abstract Security. “Security teams should stop adversaries—not manage security data. Abstract's streaming-first platform simplifies the entire security data pipeline, from ingestion to detection to storage. By eliminating noise and delays, we help your team move faster, stay focused, and outpace attackers in real time.”Introducing C2 Corner: By Practitioners, For the IndustryApplied Security Data Strategy: A Leader's Guide: a practical toolkit designed to help organizations of all sizes

Cybercrime Magazine Podcast
CISO Confidential. Measuring Human Risk. Adam Keown, Eastman & Kendra Cooley, Doppel.

Cybercrime Magazine Podcast

Play Episode Listen Later Jan 13, 2026 13:47


Adam Keown is the CISO at Eastman. In this episode, he joins host Scott Schober and Kendra Cooley, Senior Director of Information Security and IT at Doppel, to discuss humans and the evolving cyber threat landscape, including what tailored, environment-specific training looks like, ideal resilience programs, and more. This episode of CISO Confidential is brought to you by Doppel. Learn more about our sponsor at https://doppel.com.

Grow Your Credit Union
The Five Dollar Fake CEO

Grow Your Credit Union

Play Episode Listen Later Jan 6, 2026 32:33


Read the shownotes and full transcript on our site: growyourcreditunion.com Deepfake technology has become so accessible that threat actors need only 10 to 30 seconds of audio and a $5 monthly subscription to convincingly impersonate executives, bypass authentication, and trick employees into catastrophic decisions. Credit unions face record ransomware attacks while most lack AI governance policies to address emerging threats. In this episode of Grow Your Credit Union, host Joshua Barclay welcomes sponsored guest Brian Hinze, President & CEO at NCU-ISAO, along with co-host Oto Ricardo, Director of Information Security and Cyber Risk at Advia Credit Union, to explore: Why ransomware attacks hit record levels despite preparedness efforts How credit unions approach AI governance policies What deepfake threats mean for credit union security How NCU-ISAO supports credit unions through community and collaboration   A huge thanks to our sponsor, NCU-ISAO Cybersecurity threats are evolving faster than ever, and credit unions are increasingly in the crosshairs. NCU-ISAO is the only organization fully dedicated to protecting credit unions through real-time threat intelligence, actionable alerts, expert-led analysis, and a community of security-minded professionals. Strengthen your defenses with collaboration. Learn more at NCUISAO.org/GYCU.

The CyberWire
Michael Scott: A team of humble intellects. [Information security] [Career Notes]

The CyberWire

Play Episode Listen Later Jan 4, 2026 9:37


Please enjoy this encore of Career Notes. Chief Information Security Officer at Immuta, Michael Scott shares his story from working at a forgotten internet service provider to leading the security fight for major food chain restaurants. Michael explains how the different roles at various companies he has worked with paved his way to where he is now at Immuta. He works with a group of colleagues and he leads in a different style, describing that "It really is just a collection of a lot of, we call humble intellects" working with him. Michael attributes adversity to being a cornerstone of existence in the security community, and explains how that helps him keep up the fight. We thank Michael for sharing his story with us. Learn more about your ad choices. Visit megaphone.fm/adchoices

Career Notes
Michael Scott: A team of humble intellects. [Information security]

Career Notes

Play Episode Listen Later Jan 4, 2026 9:37


Please enjoy this encore of Career Notes. Chief Information Security Officer at Immuta, Michael Scott shares his story from working at a forgotten internet service provider to leading the security fight for major food chain restaurants. Michael explains how the different roles at various companies he has worked with paved his way to where he is now at Immuta. He works with a group of colleagues and he leads in a different style, describing that "It really is just a collection of a lot of, we call humble intellects" working with him. Michael attributes adversity to being a cornerstone of existence in the security community, and explains how that helps him keep up the fight. We thank Michael for sharing his story with us. Learn more about your ad choices. Visit megaphone.fm/adchoices

Assurance in Action
Cybersecurity Demystified: UK Govt initiatives to strengthen cyber resilience in the UK

Assurance in Action

Play Episode Listen Later Dec 18, 2025 24:35 Transcription Available


In the third episode of our ‘Cyber Security De-mystified Podcast Series', Steve Ramsden, President Information Security at Intertek meets with guest speaker Irfan Hemani -Deputy Director for UK Cyber Security & Resilience Policy at Department for Science, Innovation and Technology –  DSIT to talk about UK Govt initiatives aiming to strengthen cyber resilience and what this means for UK organisations.Speakers:Steven Ramsden:  President of Information Security at IntertekIrfan Hemani : Deputy Director for UK Cyber Security & Resilience Policy,  DSITFollow us on- Intertek's Assurance In Action || Twitter || LinkedIn.

Destination Linux
446: Ubuntu From The BIOS & The Quest for an Open Source Mac

Destination Linux

Play Episode Listen Later Dec 16, 2025 70:08


This week on Destination Linux, we are joined by a special guest host: Craig Rowland, the CEO of Sandfly Security! We're diving deep into the reality of modern security—specifically when third-party code knocks over your castle. From malicious VSCode extensions to the "React2Shell" vulnerability, we discuss why "Open Source" doesn't automatically mean "Safe" and how to protect your supply chain. Then, is it possible to have the macOS experience without the Apple ecosystem? Ryan explores ravynOS, a daring new project with "macOS vibes and a BSD soul." It's attempting to bring the Aqua interface—and eventually Mac app compatibility—to the open-source world. Plus, Jill brings us massive news from Canonical and AMI. You might soon be installing Ubuntu directly from your motherboard's BIOS without ever needing a USB drive. We break down how this partnership changes the game for hardware. Finally, we read an incredible listener story. Show Notes: 00:00:00 Intro 00:02:39 Extended Intro: Open Source or Bust 00:03:08 Community Feedback: A Pentester's Origin Story 00:10:03 Guest Host: Sandfly Security & Agentless Protection 00:15:53 Security Deep Dive: Supply Chain Attacks, Malicious VSCode Extensions & React2Shell 00:44:31 ravynOS: The Open Source Mac Killer? 00:56:05 News: Canonical + AMI: Installing Ubuntu from the BIOS 01:08:07 Outro 01:09:33 Post-Show Shenanigans Support the Show: Sponsored by Sandfly Security: destinationlinux.net/sandfly - Get 50% off the Home Edition with code DESTINATION50 Special Guest: Craig Rowland.

Security Unfiltered
Unlocking Data Protection: Vishnu Varma on Cybersecurity Challenges

Security Unfiltered

Play Episode Listen Later Dec 1, 2025 53:55 Transcription Available


Send us a textIn this episode, Joe sits down with Vishnu Varma to explore the evolving landscape of cybersecurity and data management. Vishnu shares his journey from India to the US, detailing his experiences at Cisco and the rise of cloud security. They delve into the challenges of managing vast amounts of data in the age of AI, discussing how BonFi AI is innovating in data security. Tune in to learn about the importance of context in data protection and the future of cybersecurity in a rapidly changing digital world.00:00:19 Introduction to Vishnu's Journey00:00:30 Entering the US and Cisco00:02:18 Cloud Security and AI00:02:48 Data Governance and Challenges00:08:47 The Expansiveness of Cloud00:11:00 AI's Appetite for Data00:12:11 Data Security in the JNI Era00:14:29 The Importance of Context00:16:13 Data Used by Enterprises00:22:24 Conclusion and Future Trendshttps://www.bonfy.ai/Bonfy.aiBonfy ACS is a next-gen DLP platform built for the AI era. Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.Support the showFollow the Podcast on Social Media! Tesla Referral Code: https://ts.la/joseph675128 YouTube: https://www.youtube.com/@securityunfilteredpodcast Instagram: https://www.instagram.com/secunfpodcast/Twitter: https://twitter.com/SecUnfPodcast Affiliates➡️ OffGrid Faraday Bags: https://offgrid.co/?ref=gabzvajh➡️ OffGrid Coupon Code: JOE➡️ Unplugged Phone: https://unplugged.com/Unplugged's UP Phone - The performance you expect, with the privacy you deserve. Meet the alternative. Use Code UNFILTERED at checkout*See terms and conditions at affiliated webpages. Offers are subject to change. These are affiliated/paid promotions.

The Social-Engineer Podcast
Ep. 325 - Security Awareness Series - A Crystal Ball for Mitigating Threats With Chris and Carter

The Social-Engineer Podcast

Play Episode Listen Later Oct 20, 2025 32:02


Today on the Social-Engineer Podcast: The Security Awareness Series, Chris is joined by Carter Zupancich. Chris and Carter explore the evolving landscape of social engineering threats, focusing on the rise of vishing attacks and the role of AI in enhancing these tactics. Their discussion underscores the importance of empowering employees as a human firewall and the need for continuous education and testing to strengthen organizational security. [Oct 20, 2025]   00:00 - Intro 00:31 - Carter Zupancich Intro -          Website: https://carterzupancich.com/ 01:30 - Intro Links: -          Social-Engineer.com - http://www.social-engineer.com/ -          Managed Voice Phishing - https://www.social-engineer.com/services/vishing-service/ -          Managed Email Phishing - https://www.social-engineer.com/services/se-phishing-service/ -          Adversarial Simulations - https://www.social-engineer.com/services/social-engineering-penetration-test/ -          Social-Engineer channel on SLACK - https://social-engineering-hq.slack.com/ssb -          CLUTCH - http://www.pro-rock.com/ -          innocentlivesfoundation.org - http://www.innocentlivesfoundation.org/                                                03:35 - Tools, Tactics and Procedures 05:19 - Tech Advances 08:16 - The Classics 10:01 - The Need for Testing 12:16 - Callback Phishing 17:26 - Setting Expectations 21:56 - Approved Language 23:56 - Verify! 25:16 - Empowerment 26:17 - And Now a Horrible Story 28:47 - Investing In Employees 31:19 - Wrap Up & Outro -          www.social-engineer.com -          www.innocentlivesfoundation.org

The Rachel Maddow Show
War plans group chat scandal fits pattern of Trump's embarrassing weakness on information security

The Rachel Maddow Show

Play Episode Listen Later Mar 26, 2025 44:20


Rachel Maddow looks at Donald Trump's ridiculously poor track record of mishandling sensitive information, with the scandal of several of his top officials thoughtlessly discussing military plans in an insecure group text raising questions of criminality on top of the widespread outrage over the sheer sloppiness of their actions.