Podcasts about Information security

  • 1,096PODCASTS
  • 3,752EPISODES
  • 38mAVG DURATION
  • 5WEEKLY NEW EPISODES
  • Jul 20, 2026LATEST
Information security

POPULARITY

20192020202120222023202420252026

Categories



Best podcasts about Information security

Show all podcasts related to information security

Latest podcast episodes about Information security

The Shared Security Show
Surveillance Pricing: When Your Data Sets the Price

The Shared Security Show

Play Episode Listen Later Jul 20, 2026 22:05


This week on Shared Security, Tom and Scott dig into surveillance pricing: the use of personal data, behavioral profiles, shopping history, location signals, income assumptions, household information, and AI-driven targeting to decide what price or discount different people see for the same product.The conversation connects New Jersey's proposed grocery surveillance-pricing ban, Consumer Reports-style loophole concerns, loyalty-card data, and a creepy Papa John's / Instacart / streaming-ad example into one listener-friendly question: when does ordinary dynamic pricing become personalized price discrimination based on what companies think they know about your life?** Links mentioned on the show **EPIC — New Jersey Legislature Passes Grocery Surveillance Pricing Ban https://epic.org/new-jersey-legislature-passes-grocery-surveillance-pricing-ban/Schneier on Security — Papa Johns Surveillance-Based Advertising https://www.schneier.com/blog/archives/2026/07/papa-johns-surveillance-based-advertising.htmlEFF — California's Bill to Ban Surveillance Pricing https://www.eff.org/deeplinks/2026/06/californias-bill-ban-surveillance-pricingScott's Digital Legacy Project https://securityperspectives.com/digital-legacy-tools/** Watch this episode on YouTube **[YOUTUBE URL]** Become a Shared Security Supporter **Get exclusive access to bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today by going to our YouTube channel's membership section: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/join** Thank you to our sponsors! **SLNTVisit https://slnt.com to check out SLNT's amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code "sharedsecurity".** Subscribe and follow the podcast **Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcastFollow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.socialFollow us on Mastodon: https://infosec.exchange/@sharedsecurityJoin us on Reddit: https://www.reddit.com/r/SharedSecurityShow/Visit our website: https://sharedsecurity.netSubscribe on your favorite podcast app: https://sharedsecurity.net/subscribeSign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribeLeave us a rating and review: https://ratethispodcast.com/sharedsecurityContact us: https://sharedsecurity.net/contact

ILTA
#0198: (JIT) ILTA Just-In-Time: Vibe Coding – Built by AI, Owned by You, Reviewed by Nobody

ILTA

Play Episode Listen Later Jul 8, 2026 12:17


Legal professionals are increasingly using AI to build internal automations, workflow tools, and client-facing applications, often without the involvement of the IT or security departments. This episode examines what happens when "vibe coding" meets the legal environment: client data handled by code nobody fully understands, third-party dependencies nobody vetted, and compliance obligations nobody mapped.  Listeners will leave with practical tips for enabling AI-assisted code development without abandoning their duty of care. Moderator: @Jack Recinto - Director of Applications, Ice Miller LLP Speaker: @Ken Fishkin - Associate Director of Information Security, Lowenstein Sandler LLP Recorded on 07-08-2026.

Cracking Cyber Security Podcast from TEISS
teissTalk: How AI is forcing a redesign of security itself

Cracking Cyber Security Podcast from TEISS

Play Episode Listen Later Jul 2, 2026 46:02


Why only 5% of organisations have full visibility into AI tool usage - what a credible approach to access controls and runtime behavioural monitoring looks likeMoving beyond policy intent to architecture that governs AI workloads, autonomous agents and machine-driven workflowsMoving from fragmented controls to unified, policy-driven security architectures that deliver consistent enforcement across hybrid and multi-cloud environmentsJonathan Craven, Host, teissTalkhttps://www.linkedin.com/in/jonathanbcraven/Satyam R., Director of Information Security & DevOps, BAMKOhttps://www.linkedin.com/in/hackersatyamrastogi/Paul Barbosa, V P & General Manager, Cloud Security & SASE, Check Point Softwarehttps://www.linkedin.com/in/paulbarbosa/

The ISO Show
#254 Driving ISO Implementation – Meet the Consultant: Emma Coxhill

The ISO Show

Play Episode Listen Later Jul 1, 2026 25:43


The path towards becoming an ISO consultant is often a meandering one. It's not often a career that many aspire to, yet despite that, there are still thousands of ISO professionals worldwide. We're continuing with our mini-series where we introduce members of our team, to explore how they fell into the world of ISO and discuss the common challenges they face while helping clients achieve ISO certification.   In this episode we introduce Emma Coxhill, an isologist® at Blackmores, to share their recent journey into the world of ISO consultancy and how they've found their first year working with other organisations to help them achieve ISO certification. You'll learn ·      What is Emma's role at Blackmores? ·      What does Emma enjoy outside of consultancy? ·      What did Emma do before becoming an ISO consultant? ·      How has Emma found her first year as an ISO consultant? ·      What Standards has Emma worked with so far? ·      Has there been any unexpected elements to her role? ·      What is the biggest challenge Emma has had during a project so far and how did she overcome it? ·      What is Emma's biggest achievement?   Resources ·      Isologyhub ·      TISAX Webinar   In this episode, we talk about: [00:30] Episode Summary – We introduce Emma Coxhill, an Isologist® here at Blackmores, to discuss her recent entry into the world of ISO consultancy, including how she's found working on the other side to help other organisations achieve ISO certification. [03:30] What is Emma's role at Blackmores? Her role primarily involves supporting clients in two key areas: maintaining and continually improving their existing ISO management systems and helping them establish and implement new standards. Emma specialises in information security management systems (ISMS), but is branching out to other Standards as she takes on more clients. [04:30] What does Emma do in her free time? Emma is a big fan of the outdoors, enjoying long walks and exploring in general. It makes sense then that she also enjoys gardening. While it is a lot of work, she finds the result rewarding. Emma is also a big fan of movies, excluding horror films! She enjoys making the trip to see films on the big screen when she has the chance. Lastly, Emma is also a qualified life coach. This involves guiding people to get where they want to be in life, with the crucial distinction that it's not about telling people what to do, but rather providing the right questions and tools to help them achieve their goals quicker. These skills have evidently translated well into her role as an ISO consultant, as auditing is very similar in the fact that it's about giving people a different perspective. [06:55] What was Emma's previous role? Emma previously worked in admi and retail roles, with her last job being a sales admin at a company for 13 years. She first started at that company as a sales admin, moved onto business systems and around 2019 the request for them to earn ISO 27001 certification came in. Back then ISO 27001 was a 'nice to have' and not a 'need to have' like it is today. Emma jumped at the chance to join the team working on the ISO 27001 Implementation, taking part in the research, training and implementation tasks. The company managed to navigate their certification, even through the turbulence of COVID, and Emma was the one maintaining that ISMS for the following years. During that time she also implemented TISAX, an Information Security Standard specific to the automotive industry, which you can learn more about on one of our previous webinars hosted by Emma. Sadly, Emma was made redundant in 2025, but was fortunate to join the Blackmores team shortly after. [10:10] How has Emma found her first year as an ISO consultant? It's been challenging for Emma to adjust to being on the other side of the fence, helping others to achieve certification rather than being the one to implement a system firsthand. Thankfully there was plenty of opportunity to learn during her first year with Blackmores, including expanding her repertoire of Standards and being able to learn from other experienced consultants in the team. She's really enjoying working with a variety of clients, getting to learn about different industries and how different each company is in their operations. Emma is aware that she's just scratching the surface within her first year, and is eager to learn more. [12:20] What Standards has Emma worked with so far? ISO 27001 is the main one as it's the one that Emma learned to implement from scratch at her pervious job. Since joining the Blackmores Team she's also gained experience working with ISO 9001 (Quality Management), ISO 27701 (PII Management), ISO 17100 (Translation), ISO 42001 (AI Management) and TISAX. ISO 27001 remains her favourite out of all of them, and she's keen to learn more from Blackmores own Information Security guru, Steve Mason. [14:15] Has there been any unexpected elements to her role? One of the more unexpected aspects has been helping clients navigate various acquisitions. When she joined, Blackmores had an unusual amount of clients currently in the middle of this process. Dealing with ISO management in these situations can get tricky as you're having to marry up different styles of management as two companies merge. Emma's role was in helping them to navigate that transition. She was surprised as she expected to be dealing with companies that were business as usual for years, but ISO Management is at the heart of managing these types of changes. So, it was interesting to learn how involved an ISO consultant can get into the inner workings of a business to help ease the burden for all parties involved. [17:20] What is the biggest challenge Emma has had during a project so far and how did she overcome it? Emma is still relatively fresh to implementation projects, but has found the process to be quite straight forward with the both the Blackmores 7 step methodology and support from other team members. What has been a challenge was the promotion she was tasked with for TISAX. It was a new service offering for Blackmores due to her expertise, and she was involved in recording a podcast and hosting a webinar. Both activities she'd not had any prior experience with. She doesn't think of herself as a big presenter, so it seemed like a dauting task. Emma did a lot of practice and went our of her comfort zone to do the webinar, which was positively received by the audience. The experience certainly boosted her confidence in that area, and though it was a bit stressful at the time due to nerves, she felt like it was a good learning opportunity. [19:45] What is Emma's biggest achievement? Emma has various moments throughout her life, with an early one being the fact that she passed her driving test first time at the age of 17. Later in 2005, she went solo travelling for 5 months around Australia, New Zealand and Fiji. She did end up having to work for a bit of that trip to make up some additional funds, but that was a necessary evil. Other than that, she was amazed at all the different people she met during her travels and was so pleased that she was able to complete the trip. Lastly, she's proud to have joined the Blackmores team in 2025. She's recently helped her first client achieve certification from scratch, which felt like a reward in of itself to know they'd passed their ISO assessment.  If you'd like any assistance with implementing ISO standards, get in touch with us, we'd be happy to help! We'd love to hear your views and comments about the ISO Show, here's how: ●     Share the ISO Show on Twitter or Linkedin ●     Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one. Subscribe to keep up-to-date with our latest episodes: Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List

Situational Awareness Tactics
Need-to-Know Since 400 BC: What the Spartan Scytale Teaches Modern Operators About Information Security, Compartmentalization, and Trusting

Situational Awareness Tactics

Play Episode Listen Later Jun 24, 2026 6:44 Transcription Available


The Spartans did not just build an encryption device when they developed the scytale, they built an entire operational security philosophy around the idea that information in the wrong hands is a weapon turned against you, and the discipline with which they controlled, transmitted, and protected military communications during the Peloponnesian War is a masterclass in the kind of need-to-know compartmentalization that defines modern high-threat operational environments. This episode breaks down how the scytale worked, why its simplicity was also its greatest operational strength, and what the Spartan crypto-state model reveals about the timeless relationship between information control, command integrity, and battlefield survival. Whether you are thinking about modern OPSEC, secure communications protocols, or the foundational principles behind keeping critical information out of enemy hands, the Spartans figured it out first and this episode shows you exactly how they did it.

Maschinenraum - Der Maschinenbau-Podcast
#341 Cybersecurity im Maschinenbau - was hat es mit der EU-Richtline NIS 2 auf sich. Interview mit Sascha Hesse

Maschinenraum - Der Maschinenbau-Podcast

Play Episode Listen Later Jun 22, 2026 68:44


In diesem Podcast-Gespräch diskutiere ich mit Sascha Hesse die Herausforderungen und Anforderungen der NIS 2-Richtlinie in der Cybersecurity für Unternehmen, insbesondere im Maschinenbau. Es werden praktische Schritte, gesetzliche Hintergründe und die Bedeutung einer Sicherheitskultur in Unternehmen beleuchtet. Die NIS-2-Richtlinie (Network and Information Security) ist eine EU-weite Cybersicherheitsrichtlinie. Ihr Ziel ist es, Unternehmen und kritische Infrastrukturen besser vor Cyberangriffen und IT-Ausfällen zu schützen sowie ein einheitliches Sicherheitsniveau in der gesamten Europäischen Union zu etablieren. Nur stellt sich dann die großen Fragen: wen Betrifft die Richtline überhaupt? wie muss ich mich verhalten und welche Schritte muss ich einleiten, wenn mein Unternehmen betroffen ist? kann ich das selbst machen, oder brauche ich externe Dienstleister? mit welchen Kosten muss hier gerechnet werden? All diese und noch weitere sehr spannende Punkte werden wir in dem Gespräch beleuchten und etwas Licht ist Dunkel der EU-Richtlinen bringen.   weiterführende Links: AGOR AG: https://agor-ag.com/ Gesellschaft für Cyberethik: https://agora-future.de/  

The ISO Show
#252 Wavenet's On-going Commitment to Best Practice – Successfully Maintaining Seven ISO Standards

The ISO Show

Play Episode Listen Later Jun 17, 2026 33:02


Anyone that has undergone the ambitious task of Implementing an ISO Standard will know how much work goes into creating and maintaining a single ISO certification. Now imagine juggling seven ISO certifications! There's a key difference between those that simply collect badges and those that see the value each ISO certification can bring, as every Standard has their own requirements and guidance to tackle specific areas of quality, risk and sustainability. When implemented well, they create a solid well-rounded framework that can drive unparalleled continual improvement. In this episode Ian is joined by Damian Edwards, Head of Standards at Wavenet, to dive into how they manage the mammoth task of maintaining seven ISO Standards, the challenges with managing multiple ISO certifications and what benefits they've brought to the business since implementation.   You'll learn ·      Who is Damian Edwards? ·      Who are Wavenet? ·      How did Damian manage integrating management systems during Wavenet's acquisition of Daisy Corporate Services? ·      What is Damian's role at Wavenet? ·      How do Wavenet manage their ISO certifications? ·      How has ISO Support helped you over the past year? ·      What has Damian learned while managing ISO Standards? ·      What are the benefits of ISO certification? ·      Damain's top tip for anyone considering ISO Implementation   Resources ·      Wavenet ·      Wavenet Certifications ·      Blackmores – ISO Support Service ·      Isologyhub   In this episode, we talk about: [00:30] Episode Summary – We welcome Damian Edwards back onto the podcast to discuss how he maintains Wavenet's seven ISO certifications, and the explore the benefits gained from an integrated ISO Management System.   [03:05] Who is Damian Edwards? Damian is the Head of Standards at Wavenet, and has featured on the ISO Show before! One lesser known fact about Damian, is that he a 'Dance dad', supporting his daughter through all of her lessons and competitions. He's very proud of her latest achievement of qualifying for the World Championship for Irish dancing in her age group. [05:05] Who are Wavenet? Wavenet is an IT provider, providing IT network communications, security and resilience services. They are UK based with 1,600 employees based in their Solihull head office. Wavenet were formed in 2000, but have grown through acquisition, one of which was Damians previous company, Daisy Corporate Services. When Daisy was acquired, both businesses were of a similar size, so the process looked more like a merger in practice. A large part of that was uniting the ISO Standards managed by both businesses, so Damian had his hands full with ISO integration, amending audit schedules and managing extension to scope audits. [06:30] How did Damian manage integrating management systems during Wavenet's acquisition of Daisy Corporate Services? One of the biggest challenges was the extension to scope that needed to happen due to the increase in sites. Thankfully, as Wavenet were used to acquisitions, they had dedicated acquisition project managers that assist with managing the integration. At the start, there are some teething problems as both businesses will still be using their respective processes for a while. However, once system that helped was a system called 'ServiceNow', which is where issue tickets could be logged, monitored and actioned in one centralised system. [08:15] What is Damian's role at Wavenet? Damian is the Head of Standards, which includes both ISO Standards and ESG related regulatory compliance. ISO certifications are more often than not a prerequisite or a condition of a bid over a contract, without them, Wavenet wouldn't win any business. They also create a foundation of trust for Wavenet's clients in the realms of Information Security, quality and environmental management. Wavenet are currently certified to the following Standards: ·      ISO 9001 Quality Management ·      ISO 20000-1 Service Management ·      ISO 27001 Information Security Management ·      ISO 22301 Business Continuity Management ·      ISO 45001 Health & Safety Management ·      ISO 14001 Environmental Management ·      ISO 50001 Energy Management In addition to maintaining all of these certifications, Damian also strives to utilise them to drive continual improvement within the business.   [10:30] How do Wavenet manage their ISO certifications? Damian is directly responsible for five of those ISO Standards, however there are some where he doesn't have the expertise to fully manage the requirements. ISO 27001 and ISO 45001 for example require skilled people at the helm, so Wavenet have dedicated managers to handle those areas. One of Damians key responsibilities is juggling all of the audits to make sure each element is covered, and he's put a lot of work into integrating those audits where possible to get the most out of their time and resources. Though, it's important to note that you can't integrate everything, as each standard will have some unique requirements. Areas that you can integrate however include elements such as: ·      Context ·      Audit Programme ·      Corrective Actions When you do have a lot of Standards, some elements can get watered down if you try to integrate everything. Policy for example, if you have five Standards and decide to integrate all related policies into a single document, it will become long and unruly, which will lead to people unwilling to read it. So, you have to take care to ensure focus on certain elements to make those more accessible for the staff that need it. Another aspect that needed additional consideration was Wavenet's risk profile, with their amount of sites and services, it's very varied. Too much for a single person to be aware of all the risks, which is where Damian's subject area experts can provide additional insight to fill the gaps. Damian is also keen to combine external audits where possible to both reduce cost and possible duplication of effort, as many Standard do share common subject areas, this can be done across multiple Standards. Certification Bodies are usually quite happy to work with you on this! Damians key take away is, that there isn't one solution that fits every business when managing this many Standards. It was a very trial and error process, especially with the ever changing landscape of a business, but Standards are also designed with flexibility in mind, so with the right people in place it's certainly manageable. [16:05] How has Blackmores' ISO Support helped? Blackmores has assisted Wavenet with their ISO 45001, ISO 50001 and ISO 41001 (Facilities Management) implementation. ISO 41001 was later dropped as it was no longer applicable for the business. Standards can be quite hard to apply to your own business when looking at them at face value, the requirements sound generic because they're designed to apply to every type of business. This is where Blackmores experience as a consultancy can help with interpretation and practicalities of how a Standard will apply to your way of working. Blackmores will also assist with internal audits, which help identify non-conformities that may have been missed if it were not for a fresh pair of eyes. As Damian states: "I would rather have them identified before an external audit" as this gives you a chance to resolve issues or put an action plan in place before it gets to that stage. Damain also reminds everyone to not be afraid of your auditor, internal or external. They are not maliciously looking for problems, they simply help to highlight issues which can be resolved sp you can improve as a business. No Management System is perfect, the important thing is that you can recognise when something needs addressing, and how you go about doing so. [19:30] What has Damian learned while managing ISO Standards? Damian has learned to not think of ISO as a tick box exercise, it's a tool to help businesses improve. He has also learned that you don't need to reinvent the wheel when Implementing a Management System. You likely already have much of what's required in place, but not monitored or organised regularly. For example, aspects such as 'Management Review' may already be happening in existing meetings with top management, you simply need to ensure these are minuted, cover what needs to be discussed in regards to the Management System, and make note of any gaps that need to be addressed. Businesses like Wavenet that have been in operation for 26 years know what they're doing, and are likely already following best practice. You don't need to restructure your business to meet an ISO Standard, but rather integrate the Standard requirements with how you already operate. If done correctly, it should become a simple part of your day-today tasks. Damian jokingly states: "What's my role? I sometimes say it's to do as little as possible", as the more a business is aligned with a Standard, the less you will have to do to upkeep that. [22:55] What benefits have Wavenet experienced as a result of their ISO certifications? As mentioned earlier, a lot of won business is due to ISO certification. Certain certifications are simply a tender or client requirement. Standards such as ISO 50001 tackle their energy consumption. It's focus on reducing that will inevitably lead to reduced business costs. Since implementing the Standard, Wavenet now have monthly meetings to monitor energy use, which gives them a good basis to make informed decisions on where energy use is concerned. Damian has found that over time, good practice has been so embedded that people are using it in their everyday behaviors without even realising it. He's heard people in their resolutions team use terminology like 'root cause' without knowing where it came from. He's seen team making use of skill matrix's when evaluating the competence of certain teams such as engineering for client visits. So, people within the business are using ISO terminology and techniques to ensure best practice without being explicitly asked to. It simply works as a method to drive the business effectively when implemented correctly. [26:15] Damian's top tip for aspiring ISO implementors: Apart from approaching a consultancy like Blackmores to help if it's your first time going through the process, it's got to be leadership commitment. Top management need to be actively promoting ISO within the business, and they should be involved with the process. You need everyone's buy-in to make a system work, and that is made much easier if it's driven from the top down. Another tip is that a Management System should be a team effort. It shouldn't just be the responsibility of one person, you need input from everyone in the business to ensure you've covered all angles and risks that could affect your business. Lastly, look at what you already have in place and try and integrate the Standard into that. Don't make more work for yourself if you don't have to, you likely already have the bones in place. [28:20] Damian's book recommendation: The Thursday Murder Book Club – by Richard Osmond [29:10] Damian's favourite quote? "Hard work beats talent when talent doesn't beat work hard." And: "You miss 100% of the shots you don't take" To learn more about Wavenet, check out their website and keep up-to-date with their latest news via their LinkedIn page. If you'd like any assistance with your ISO Implementation or need any additional ISO Support, contact us, we'd be happy to help. We'd love to hear your views and comments about the ISO Show, here's how: ●     Share the ISO Show on Twitter or Linkedin ●     Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one. Subscribe to keep up-to-date with our latest episodes: Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List

No Password Required
No Password Required Podcast Episode 73 - Mudita Khurana

No Password Required

Play Episode Listen Later Jun 9, 2026 28:13


Show Summary:    Mudita Khurana — Tech Lead at Airbnb and the person who always says, “I got this” No Password Required Season 7: Episode 6 - Mudita Khurana   Mudita Khurana is a Tech Lead for Automated Tooling and Vulnerability Management at Airbnb, where she focuses on building modular, scalable security systems in an era of rapidly evolving AI threats. Before Airbnb, she spent nearly a decade in security roles across Accenture, Meta, and PwC, making bold career pivots along the way, including turning down a PwC return offer to join Facebook's product security team. In this episode, Mudita shares her journey from a family of doctors in India to Carnegie Mellon and into the heart of Big Tech security. She discusses what it means to thrive as a non-traditional engineer in a deeply technical field, why she stepped back from management to get closer to the work, and how she thinks about building security tooling that won't be obsolete in three months. Jack Clabby and co-host Kayley Melton, recording live from Tampa B-Sides at the University of South Florida, talk with Mudita about imposter syndrome, AI's curveballs for security teams, leadership without a leadership title, and the importance of community in staying on top of a field that never stops moving. She also reflects on what great mentorship looks like early in a career and why clarity, ownership, and consistency are the leadership qualities she keeps coming back to. In the Lifestyle Polygraph, Mudita firmly plants her flag in the Harry Potter universe as Hermione, explains why Deadpool doesn't qualify as a superhero, debates gym vs. nature as a reset strategy, and reveals her dream remote work base: a high-altitude Buddhist mountain town in the Himalayas.   Follow Mudita on LinkedIn: https://www.linkedin.com/in/muditakhurana/     In this episode: Mudita shares her unconventional path into cybersecurity, highlighting the importance of mentorship and curiosity (0:25 - 1:37) The significance of mentorship, especially Vandana Verma, in her career development (2:26 - 4:00) Transition from management to technical IC roles and why staying close to technical work matters (9:29 - 10:23) The influence of her education at Carnegie Mellon and how it broadened her problem-solving skills (6:23 - 7:41) Navigating imposter syndrome and embracing challenges as growth opportunities (3:26 - 5:29) How AI is changing cybersecurity strategies—building modular, layered systems for agility (15:31 - 16:26) The importance of community, trust, and consensus in cybersecurity decision-making (17:06 - 17:47) Mudita's favorite places for remote work and balancing planning with spontaneity in travel (23:01 - 24:13) Her personal approach to wellness, exercise, and resets during busy days (21:32 - 22:36) Her unique perspective on superhero characters, favorite places, and cultural roots (18:54 - 19:36, 25:19 - 26:21) Timestamp Highlights: (00:25) Mudita's 10-year journey into cybersecurity starting from India (02:26) Mentorship's critical role in her growth and her admiration for Vandana Verma (09:29) Transition from management back to technical roles and why staying close to the work matters (15:31) How AI fosters layered, modular security systems for faster adaptation (17:06) The importance of community and trusted information sources in security (21:32) Reset routines—gym versus nature hikes—and staying grounded during busy days (25:19) Leh, Ladakh: Mudita's ideal remote work location nestled in Himalayan beauty Resources & Links: Vandana Verma - Influential mentor in cybersecurity ThreatLocker - Supporter of this podcast Cyber Florida – The Mother Ship

The Amp Hour Electronics Podcast
#725 – The Secret Life of Circuits with lcamtuf / Michał Zalewski

The Amp Hour Electronics Podcast

Play Episode Listen Later Jun 4, 2026 59:56


Welcome Michał Zalewski, AKA lcamtuf! The lcamtuf Substack is where Michał is writing most these days Chris first found and geeked out about the CNC guide on the lcamtuf original site (discussed many times here) Michał is interested in the craft of teaching electronics He recently published The Secret Life of Circuits with No Starch Press Use the code AMPHOUR26 for 30% off The Secret Life of Circuits valid from June 1st through June 30th It was announced on his blog here Deriving fomulas from basic trigonometry sometimes bugs people who think electronics should only work with calculus Software geeks follow the site, often getting lots of attention on Hacker News Row hammer DRAM There were no Information Security degrees in the early days, so the field was made up of folks with backgrounds in math and EEs Fuzzing for security SMBC cartoon for blming humans Books American Fuzzy Lop The Tangled Web P0f v3 Silence on the Wire Security stuff (including books on the subject) ages over time, as opposed to electronics On the subjects of Calculators (and Michał’s collection) Calculators are a footnote in the history of computing, but still intriguing Dead ends in calculators CRT displays on calculators Nixie tubes Discrete moving into logic gates into processors Mechanical calculators are rare and get a high price online Working with transistors The Secret Life of Circuits start with FET based transistors vs BJT BJTs are often right after diode chapter because of the multiple junctions in an NPN, but that doesn’t make it easier to understand Projects A recent project involved making a clock out of current meters  Woodworking and AI example Want to see all lcamtuf articles in one place? Sokoban Sir box-a-lot

Cyber Risk Management Podcast
EP 211: What Sea-Tac's Ransomware Revealed

Cyber Risk Management Podcast

Play Episode Listen Later Jun 2, 2026 47:05


In August 2024, a ransomware attack shut down baggage systems, flight displays, and Wi-Fi at Sea-Tac Airport. What did it reveal about how executives think about cyber investment? And why is “how much more security do we need?” the wrong question to ask after a major incident? Let's find out with our guest Stephanie Warren, Assistant Director of Information Security at the Port of Seattle, who lived through that attack and came out the other side with hard-won lessons about executive decision-making under pressure. Your hosts are Kip Boyle, CISO with Cyber Risk Opportunities, and Jake Bernstein, Partner with K&L Gates. LinkedIn profile – https://www.linkedin.com/in/stephanie-warren-0746343/

No Password Required
No Password Required Podcast Episode 72 - Madeline Sedgwick

No Password Required

Play Episode Listen Later May 25, 2026 50:44


Madeline Sedgwick — Cyber Threat Analyst at Palo Alto Networks and a DUUUUVALLL lifer No Password Required Season 7: Episode 5 – Madeline Sedgwick   Madeline Sedgwick is a  Cyber threat Researcher and Threat Analyst at Palo Alto Networks Unit 42, specializing in nation-state cyber activity, covert infrastructure, and cyber intelligence analysis. Before entering the private sector, she spent six years in the U.S. Navy as an intelligence specialist, helping support some of the earliest cyber operations under United States Cyber Command. In this episode, Madeline shares her journey from joining the Navy to becoming one of the first certified cyber targeteers supporting offensive cyber operations. She discusses the realities of tracking covert threat actor infrastructure, why defenders must understand adversary behavior beyond alerts and signatures, and how intelligence analysis helps uncover the bigger picture behind cyber campaigns. 
Jack Clabby and co-host Sarina Gandy talk with Madeline about fusion analysis, cyber warfare, leadership, and the challenges of translating highly technical investigations into actionable insights for government and industry leaders. She also reflects on the importance of humility in leadership, mentoring, and learning to navigate high-pressure situations with confidence and curiosity. 
In the Lifestyle Polygraph, Madeline debates cybersecurity in the Star Wars universe, explains her Weird Al Yankovic Dragon Con costume, reflects on her time playing bass in a metal band, and proudly shares why Jacksonville, Florida, will always be home.   Follow Madeline on Linked in: https://www.linkedin.com/in/mesedgwick/ Chapters:  02:10 Intro-Madeline Sedgwick  09:00 The Role of Cybersecurity in National Security 12:08 Understanding Covert Networks and Threat Intelligence 14:52 Fusion Analysis in Cybersecurity 18:04 The Importance of Distinguishing Threats 20:52 Challenges in Cybersecurity Response 23:58 Briefing Decision Makers on Cyber Threats 27:52 Understanding Adversary Intent and Risk Communication 30:12 Leadership Lessons from the Navy 34:33 The Importance of Mentorship in Career Development 37:30 The Lifestyle Polygraph: A Fun Twist on Cybersecurity 41:04 Embracing Creativity and Personal Expression 45:50 Pride in Roots: The Jacksonville Connection

The Mindful Business Security Show
Common Pitfalls in AI Projects

The Mindful Business Security Show

Play Episode Listen Later May 21, 2026 59:48


The Mindful Business Security Show is a call-in radio style podcast for small business leaders. Join our hosts as they take questions from business leaders like you!   On this episode, Accidental CISO is joined by guest host Brent Hinks. Brent has spent the last decade helping customers implement AI solutions. Join them as they discuss the challenges and pitfalls of implementing AI in organizations. They explore common reasons for project failures, the importance of stakeholder buy-in, trust, governance, and best practices for successful AI projects.   Are you struggling with how to deal with Cybersecurity, Information Security, or Risk Management in your organization? Be a caller on a future episode of the show! Visit our podcast page for more information about upcoming episodes. You can sign up to be a caller and guarantee yourself a Q&A session on the show!   Show Merch: https://shop.mindfulsmbshow.com/ Website: https://www.focivity.com/podcast Twitter: @mindfulsmbshow Hosted by: @AccidentalCISO Produced by: @Focivity Theme music by Michael Kobrin.

Breakfast with Refilwe Moloto
Cyber sense, making sense of scams: Alleged ANC data breach raises questions about cyber security and public data exposure

Breakfast with Refilwe Moloto

Play Episode Listen Later May 15, 2026 8:08 Transcription Available


This week’s Cyber Sense feature focuses on claims made in a recent TikTok video by Boikokobetso Makhetloane, also known online as Mr Fingerz, in which he alleges that a database linked to the ANC may have been compromised and data exposed online. Lester Kiewit speaks to Mr Fingerz about how cyber breaches are identified, what it means when data surfaces on the dark web, and the broader risks posed to organisations and individuals when sensitive information is potentially leaked. The discussion explores cyber leak attribution, verification challenges, and organisational response to suspected breaches. Good Morning Cape Town with Lester Kiewit is a podcast of the CapeTalk breakfast show. This programme is your authentic Cape Town wake-up call. Good Morning Cape Town with Lester Kiewit is informative, enlightening and accessible. The team’s ability to spot & share relevant and unusual stories make the programme inclusive and thought-provoking. Don’t miss the popular World View feature at 7:45am daily. Listen out for #LesterInYourLounge which is an outside broadcast – from the home of a listener in a different part of Cape Town - on the first Wednesday of every month. This show introduces you to interesting Capetonians as well as their favourite communities, habits, local personalities and neighbourhood news. Thank you for listening to a podcast from Good Morning Cape Town with Lester Kiewit. Listen live on Primedia+ weekdays between 06:00 and 09:00 (SA Time) to Good Morning CapeTalk with Lester Kiewit broadcast on CapeTalk https://buff.ly/NnFM3Nk For more from the show go to https://buff.ly/xGkqLbT or find all the catch-up podcasts here https://buff.ly/f9Eeb7i Subscribe to the CapeTalk Daily and Weekly Newsletters https://buff.ly/sbvVZD5 Follow us on social media CapeTalk on Facebook: https://www.facebook.com/CapeTalk CapeTalk on TikTok: https://www.tiktok.com/@capetalk CapeTalk on Instagram: https://www.instagram.com/ CapeTalk on X: https://x.com/CapeTalk CapeTalk on YouTube: https://www.youtube.com/@CapeTalkSee omnystudio.com/listener for privacy information.

The Aubrey Masango Show
Crime-time: South Africa ranks top in the continent in suffering from cyberattacks

The Aubrey Masango Show

Play Episode Listen Later May 14, 2026 46:21 Transcription Available


Aubrey Masango speaks to Chad Thomas, Crime Expert at IRS Forensic Investigations on South Africa being ranked top in the continent in the number of cyberattacks on companies and institutions. They also explore some of the reasons why there's been an increased number of cyberattacks in the country over the years. Tags: 702, The Aubrey Masango Show, Aubrey Masango, Crime Time, Cyber-Crime, Cyber Security, Hacking, Data Breaches, Technology, Artificial Intelligence, Deep Fakes, Phishing, POPIA, Information Security, Encryption The Aubrey Masango Show is presented by late night radio broadcaster Aubrey Masango. Aubrey hosts in-depth interviews on controversial political issues and chats to experts offering life advice and guidance in areas of psychology, personal finance and more. All Aubrey’s interviews are podcasted for you to catch-up and listen. Thank you for listening to this podcast from The Aubrey Masango Show. Listen live on weekdays between 20:00 and 24:00 (SA Time) to The Aubrey Masango Show broadcast on 702 https://buff.ly/gk3y0Kj and on CapeTalk between 20:00 and 21:00 (SA Time) https://buff.ly/NnFM3Nk Find out more about the show here https://buff.ly/lzyKCv0 and get all the catch-up podcasts https://buff.ly/rT6znsn Subscribe to the 702 and CapeTalk Daily and Weekly Newsletters https://buff.ly/v5mfet Follow us on social media: 702 on Facebook: https://www.facebook.com/TalkRadio702 702 on TikTok: https://www.tiktok.com/@talkradio702 702 on Instagram: https://www.instagram.com/talkradio702/ 702 on X: https://x.com/Radio702 702 on YouTube: https://www.youtube.com/@radio702 CapeTalk on Facebook: https://www.facebook.com/CapeTalk CapeTalk on TikTok: https://www.tiktok.com/@capetalk CapeTalk on Instagram: https://www.instagram.com/ CapeTalk on X: https://x.com/CapeTalk CapeTalk on YouTube: https://www.youtube.com/@CapeTalk567See omnystudio.com/listener for privacy information.

The Cybersecurity Defenders Podcast
How AI adoption in enterprise infrastructure has expanded the attack surface with Katherine McNamara from Cisco / Defender Fridays [#318]

The Cybersecurity Defenders Podcast

Play Episode Listen Later May 4, 2026 36:15


Today on Defender Fridays, Katherine McNamara, Cybersecurity Technical Solutions Architect at Cisco, joins us to discuss how AI and ML adoption in enterprise infrastructure has expanded the attack surface for AI-driven systems.She'll walk through the security challenges unique to generative AI and ML-based architectures, and cover the four critical components: Model, Data, Application, and System, that organizations need to secure to maintain integrity.Katherine works for Cisco as a Cybersecurity Systems Engineer by day and by night, she's labbing and trying new things with the resources she has available. Katherine loves technology and getting her hands into the CLI or trying something new. She holds a Bachelors of Science and Masters of Information Security and Assurance from Western Governors University as well as several industry certifications. Register for Live SessionsJoin us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.Register here: https://limacharlie.io/defender-fridaysSubscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!Sponsored by LimaCharlieThis episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.Why LimaCharlie?Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.Try the Agentic SecOps Workspace free: https://limacharlie.ioLearn more: https://docs.limacharlie.io/Follow LimaCharlieSign up for free: https://limacharlie.io/LinkedIn: / limacharlieio X: https://x.com/limacharlieioCommunity Discourse: https://community.limacharlie.com/Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie

ILTA
#0178: (WIS) SheSecures: Voices from Women in Legal Security - Sherri Vollick

ILTA

Play Episode Listen Later May 2, 2026 16:11


SheSecures is an ILTA Women in Security podcast series dedicated to amplifying the experiences, expertise, and leadership of women shaping the future of legal security. Each episode is designed to be approachable and useful, with real takeaways you can apply in your own role. This month's episode is with Sherri Vollick.  Sherri is a strategic and accomplished cyber and risk leader with deep expertise in security operations, governance, risk and compliance, secure application development, and cloud security. Sherri currently serves as Director of Information Security & Compliance at Saul Ewing LLP and is an active mentor and contributor within the broader information security community.

Segurança Legal
#416 – Saber sem conhecer

Segurança Legal

Play Episode Listen Later Apr 30, 2026 43:03


Neste episódio comentamos sobre os desafios e as soluções técnicas para a aferição de idade na internet, um tema que ganhou forte destaque com as novas regras do ECA Digital. Você irá descobrir como funcionam os protocolos de conhecimento zero, também conhecidos como Zero-Knowledge Protocol ou ZKP, e de que forma eles permitem comprovar a maioridade de um usuário sem expor dados pessoais sensíveis. Você entenderá a diferença entre ferramentas invasivas, como a biometria facial, e métodos técnicos que respeitam a privacidade e a proteção de dados, utilizando criptografia aplicada e padrões internacionais de segurança da informação. Além disso, você vai aprender sobre os impactos práticos da regulamentação da ANPD no controle de acesso a conteúdos restritos e como evitar o rastreamento excessivo por grandes empresas de tecnologia. O debate também aborda táticas de engenharia social, destacando uma série educativa sobre phishing baseada na psicologia da fraude, que é um conhecimento essencial para evitar golpes online e vazamento de dados. Ao longo da discussão, você verá que é possível equilibrar a proteção no ambiente digital com a garantia da intimidade, sem adotar modelos de vigilância em massa durante a autenticação de sistemas. Para não perder nenhuma discussão sobre tecnologia, direito e sociedade, assine o podcast na sua plataforma de áudio favorita e siga nossos perfis no YouTube, Mastodon, Blue Sky, Instagram e TikTok. Aproveite para avaliar o programa e compartilhar o conteúdo com outras pessoas interessadas no assunto. Você também pode apoiar o projeto acessando a plataforma de financiamento coletivo indicada no áudio ou enviando suas dúvidas e sugestões diretamente para o nosso e-mail oficial. Esta descrição foi realizada a partir do áudio do podcast com o uso de IA, com revisão humana  Visite nossa campanha de financiamento coletivo e nos apoie!  Conheça o Blog da BrownPipe Consultoria e se inscreva no nosso mailing ShowNotes The Psychology of Fraud, Persuasion and Scam Techniques LEI Nº 15.211, DE 17 DE SETEMBRO DE 2025 – Dispõe sobre a proteção de crianças e adolescentes em ambientes digitais (Estatuto Digital da Criança e do Adolescente) DECRETO Nº 12.880, DE 18 DE MARÇO DE 2026 – Regulamenta a Lei nº 15.211, de 17 de setembro de 2025, que dispõe sobre a proteção de crianças e adolescentes em ambientes digitais, e institui a Política Nacional de Promoção e Proteção dos Direitos da Criança e do Adolescente no Ambiente Digital. Mecanismos confiáveis de aferição de idade – ORIENTAÇÕES PRELIMINARES Radar tecnológico – Mecanismos de aferição de idade

The Cybersecurity Readiness Podcast Series
The Clock Is Ticking: Navigating Quantum Risk and the Path to Crypto Agility

The Cybersecurity Readiness Podcast Series

Play Episode Listen Later Apr 29, 2026 40:53


In Episode 103 of the Cybersecurity Readiness Podcast Series, Dr. Dave Chatterjee is joined by Peterson Gutierrez—Vice President of Information Security at Barracuda Networks and a 28-year cybersecurity veteran with experience spanning private industry, the Big Four, and New York City Cyber Command—to examine one of the most consequential and underestimated challenges facing security leaders today: the quantum computing threat and what it truly means to become cryptographically agile.Opening with a vivid scenario—a healthcare organization whose encrypted data is exfiltrated today and decrypted after a quantum breakthrough years from now—Dr. Chatterjee introduces the concept of Q Day risk: the danger is not a dramatic breach tomorrow, but decisions made today that leave organizations exposed later. The episode moves beyond the industry's fixation on which post-quantum algorithm to adopt, making the case that algorithm selection is the wrong problem to solve. The right goal is crypto agility: the organizational discipline to abstract encryption from code and adapt continuously as the cryptographic landscape evolves.Framed through Dr. Chatterjee's Commitment–Preparedness–Discipline (CPD) lens, the conversation delivers a clear and actionable message: crypto agility is not a technical upgrade—it is a leadership, architecture, and governance challenge that requires executive ownership, modular system design, proactive vendor engagement, and continuous organizational discipline before Q Day makes inaction catastrophic.To access and download the entire podcast summary with discussion highlights - https://www.dchatte.com/episode-103-the-clock-is-ticking-navigating-quantum-risk-and-the-path-to-crypto-agility/Connect with Host Dr. Dave ChatterjeeLinkedIn: https://www.linkedin.com/in/dchatte/ Website: https://dchatte.com/Books PublishedThe DeepFake ConspiracyCybersecurity Readiness: A Holistic and High-Performance ApproachArticles & Cases PublishedChatterjee, D. (2026). Root: Automating the Remediation Gap, Ivey Publishing, Jan 7, 2026.Ramasastry, C. and Chatterjee, D. (2025). Trusona: Recruiting For The Hacker Mindset, Ivey Publishing, Oct 3, 2025.Chatterjee, D. and Leslie, A. (2024). “Ignorance is not bliss: A human-centered whole-of-enterprise approach to cybersecurity preparedness,” Business Horizons, Accepted on Oct 29, 2024.Isik, O., Chatterjee, D., and Lourenco, D.A. (2024). “Getting Cybersecurity Right,” California Management Review — Insights, Accepted for Publication, July 8, 2024. Chatterjee, D. (2023). “Mission critical – How American Cancer Society successfully and securely migrated to the cloud amid the pandemic,” I by IMD, March 13, 2023.Chatterjee, D. (2022). “Preventing security breaches must start at the top,” I by IMD, September 28, 2022, Institute for Management Development, Lausanne, SwitzerlandChatterjee, D. (2022). “Making Cybersecurity Readiness Mainstream,” Executive Blog Post, NETSPI, March 1, 2022Benz, M. and Chatterjee, D. (2020). “Calculated Risk? A Cybersecurity Evaluation Tool for SMEs,” Business Horizons, available online from May 4, 2020Chatterjee, D. (2019). “Should Executives Go To Jail Over Cyber Attacks,” Journal of Organizational Computing and Electronic Commerce, Vol 29, Issue 1, pp. 1-3.Abraham, C., Chatterjee, D., and Sims, R. (2019). “Muddling through cybersecurity: Insights from the U.S. healthcare industry,” Business Horizons, July 2019.

The Cybersecurity Defenders Podcast
Real examples of AI-powered code scanning with Jeff McJunkin from Rogue Valley Information Security / Defender Fridays [#315]

The Cybersecurity Defenders Podcast

Play Episode Listen Later Apr 27, 2026 32:41


Jeff McJunkin, Founder of Rogue Valley Information Security, joins Defender Fridays to talk AI-powered code scanning for vulnerabilities. Jeff walks through real examples including using AI to find privilege escalation bugs in the Linux kernel.Jeff McJunkin is the founder of Rogue Valley Information Security, a consulting firm specializing in penetration testing and red team engagements. Jeff found the offensive side of cyber security very alluring during one the first penetration tests of his career. Feeling the challenge of host defenses like AV and centralized logging, and, at the time, knowing nothing about AV evasion or avoiding events that are likely to cause alerts, it was all very exciting. The challenge of successfully accomplishing the goal of that pen test, using essentially only native tools, was addictive for Jeff. He was hooked. Since those first penetration tests, Jeff has gone on to become an expert in the field, doing assessments for Fortune 100 companies, architecting two major versions of Core NetWars Experience, and contributing a vast amount of material to SANS Penetration Testing.Register for Live SessionsJoin us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.Register here: https://limacharlie.io/defender-fridaysSubscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!Sponsored by LimaCharlieThis episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.Why LimaCharlie?Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.Try the Agentic SecOps Workspace free: https://limacharlie.ioLearn more: https://docs.limacharlie.io/Follow LimaCharlieSign up for free: https://limacharlie.io/LinkedIn: / limacharlieio X: https://x.com/limacharlieioCommunity Discourse: https://community.limacharlie.com/Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie

No Password Required
No Password Required Breakout Room with Fagan Afandiyev

No Password Required

Play Episode Listen Later Apr 21, 2026 20:28


Fagan Afandiyev — Elite Cybersecurity Competitor and Legendary Whitehatter No Password Required: Breakout Room: Episode 1 — Fagan Afandiyev Fagan Afandiyev is a cybersecurity student at the University of South Florida and a member of the CyberHerd competition team, known for his strategic mindset and passion for solving complex challenges. From competing in international robotics competitions to discovering cybersecurity through hands-on platforms, Fagan has built his skills through curiosity, persistence, and a love for problem solving. Fagan shares how competitions, community, and continuous learning shaped his journey into cybersecurity. He walks through his growth within USF's cyber community, and how that led to a penetration testing internship at Microsoft. He also offers insight into the mindset needed to succeed in cybersecurity, encouraging others to embrace challenges, learn through failure, and find enjoyment in the process. Follow Fagan on Linked in here: https://www.linkedin.com/in/fagan-afandi/ Presented by ThreatLocker Chapters:  00:00 Introduction to Cybersecurity Passion 3:02   Journey to Cyber Herd and University Life 06:12 Internship at Microsoft and Career Aspirations 08:59 Hackathon Experience and Community Engagement 12:39 Behind the Scenes of Cyber Competitions 14:30  Overcoming Challenges in Cyber Competitions 18:00 Gratitude and Mentorship in Cybersecurity  

Conversations with Valerie
Why you are stuck in your career | Adewale Adeife

Conversations with Valerie

Play Episode Listen Later Apr 10, 2026 41:37


In this conversation, I sit down with Adewale Adeife an Information Security manager to unpack a powerful shift in thinking about work, growth, and long-term success. We talk about the difference between a job and a career, and why many people stay stuck because they keep moving too quickly instead of building something that compounds over time. He introduces the idea of treating your career like a stock rather than something you keep trading for short-term gain. If you've ever felt like you're working hard but not really growing, or you're constantly starting over, this conversation is for you.Connect with Adewale:Instagram- https://www.instagram.com/adewale.adeife?LinkedIn- https://www.linkedin.com/in/adewaleadeife?Subscribe for more honest, faith-rooted conversations.

The Cybersecurity Defenders Podcast
Why cyber analysts are crucial in protecting public infrastructure with Michael Hamilton from PISCES International [#308]

The Cybersecurity Defenders Podcast

Play Episode Listen Later Apr 8, 2026 45:14


Michael Hamilton, Chief Technology Officer at PISCES International, joins us to discuss the benefits of providing real world experience to students while they protect existing public infrastructure. The resilient future of local government security rests in our ability to adapt to changing threats and adopt new technologies, including AI.Learn more at https://pisces-intl.org/30 years in Information Security as a practitioner, entrepreneur, consultant, and in executive management. Direct experience in retail, manufacturing, government, defense, academic, semiconductor, energy, law enforcement, transportation, publishing and financial sectors - from Fortune 1 to small nonprofits. Formerly: Policy Advisor to Washington State, Chief Information Security Officer for the City of Seattle, and Managing Consultant for VeriSign Global Security Consulting. Former Vice-Chair of the DHS State, Local, Tribal and Territorial Government Coordinating Council.Currently: Field CISO, Lumifi CyberSupport our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at limacharlie.io

The ISO Show
#247 How do ISO 27001 Information Security and ISO 42001 AI Management compare?

The ISO Show

Play Episode Listen Later Apr 1, 2026 23:31


Information is increasingly becoming the number one priority for businesses. With so many of us reliant on tech to stay in operation, there is an inevitable increase in data breaches and incidents year-on-year. The addition of new AI driven technology has added a new layer of complexity to the information security landscape, regarding both the new risks using the technology brings as well as falling prey to more complex AI led scams.   Thankfully ISO Standards are here to help, with ISO 27001 tackling general information security and ISO 42001 for effective AI Management. But how do these two compare, and is there merit in implementing both? In this episode, Ian Battersby is joined by Bas Von Hertom, Cyber Security Specialist at TUV Nord, to discuss what ISO 27001 and ISO 42001 are, the main differences between the Standards and how they can complement each other when integrated.   You'll learn ·      Who is Bas Von Hertom? ·      Who are TUV Nord? ·      What are ISO 27001 and ISO 42001? ·      How does ISO 42001 support regulatory frameworks such as the EU AI Act? ·      How do ISO 27001 and ISO 42001 differ in managing information security risks? ·      Other key differences between ISO 27001 and ISO 42001 ·      How much more work is involved for Implementing ISO 42001 if you already have ISO 27001 in place? ·      Can ISO 27001 and ISO 42001 be integrated? ·      What organisations should be implementing both Standards? ·      How are Certification Bodies quoting for ISO 27001 and ISO 42001? ·      Bas's advice to leadership teams looking to build a case for full certification   Resources ·      TUV Nord ·      Isologyhub   In this episode, we talk about: [02:05] Episode Summary – Ian is joined by Bas Von Hertom, Cyber Security Specialist at TUV Nord, to explore the differences between ISO 27001 and ISO 42001 and the benefits of integrating both Standards. [02:30] Who is Bas Von Hertom? Bas is the Cyber Security Specialist at TUV Nord. He is a lead auditor for Standards including ISO 27001, ISO 42001, TISAX and standards specifically for industrial automation. Bas had once stated around 5 years ago that he would never pursue a career in auditing, but once he came into contact with TUV Nord he decided to give it a go. Before joining TUV, he was a very hands-on systems administrator and many of those skills transferred well into auditing. [04:45] Who are TUV Nord? TUV Nord are a UKAS accredited Certification Body. They also offer services for testing and inspection. TUV have worked with a large range of sectors, from manufacturing and energy to IT, healthcare and even space. [06:25] What are ISO 27001 and ISO 42001? ISO 27001 is the Standard for Information Security Management, with compliant management systems being called an ISMS. It provides structure for identifying, assessing, and managing risks related to the information security while also ensuring availability and resilience on the information security. ISO 42001 AI Management is a much more recent Standard, being published in December of 2024. It focuses on ethical and effective AI management, with a system that applies to relevant products in addition to the wider business. [07:30] How does ISO 42001 support regulatory frameworks such as the EU AI Act? The EU AI Act sets out legal obligations that organisations offering AI products must comply with, however it only defines the rules rather than providing any implementation guidance. This is where ISO 42001 can fill the gaps, by providing a framework that will meet these regulatory requirements. [08:45] How do ISO 27001 and ISO 42001 differ in managing information security risks? Both Standards take a risk-based approach to their subject matter, but the nature of the risks that each address are what differ. ISO 27001 focuses on risks that relate to the protection of information assets based on confidentiality, integrity and availability of information. It's also ensures that business objectives are clearly defined and aligned with business strategy. ISO 42001 on the other hand deals with a broader and more complex set of risks, because it also looks at ethical considerations. This can includes the monitoring and measurement of ethical risks such as AI bias and discrimination. It also looks at societal, legal and reputational risks as one of ISO 42001's key values is creating trust within the AI space. [10:10] Other key differences between ISO 27001 and ISO 42001: Besides their subject matter, another key difference is the way objectives are framed and evaluated. In ISO 42001 these objectives have to be aligned with the Annexes within the Standard, which is something not commonly done when implementing ISO 27001. ISO 42001 also requires an 'AI Impact Assessment', which again, aligns with the systems objectives as the results of the AI Impact Assessment will describe the way bias, ethical and societal considerations impact other requirements within ISO 42001. [11:00] How much more work is involved for Implementing ISO 42001 if you already have ISO 27001 in place? If you already have ISO 27001 in place, you have a strong foundation for ISO 42001. ISO 27001 puts the fundamental base in place, with a governance structure, risk assessment processes, internal audits, corrective actions and methods for continual improvement. There's a lot of overlap where the high-level requirements are concerned. However, ISO 42001 also looks at AI products and services, which differs from ISO 27001.   ISO 42001 may also require additional training for those involved with the management systems and the AI products and services. [12:15] Can ISO 27001 and ISO 42001 be integrated? Yes, and in fact, Bas highly encourages it! If you intend to implement both Standards, it's much more efficient to do so as an integrated management system. They both utilise the Annex SL format, a high-level structure that's shared with most ISO Standards, so they're designed to be integrated. This also saves on duplication of effort where documentation is concerned and also potentially on cost if you require additional support with implementation. [13:30] What organisations should be implementing both Standards? Both ISO 27001 and ISO 42001 can apply to any business. Most businesses are now utilising AI in some form, and ISO 42001 can apply to those using it just as much as it does to those developing their own AI tools or selling related services. However, sectors where ISO 42001 will likely become fundamental include the financial sector, where AI tools for fraud detection are becoming popular. There's also a growing need for it within the medical field as AI is increasingly used for research and development. [14:30] How are Certification Bodies quoting for ISO 27001 and ISO 42001? There are a number of variables that Certification Bodies use to work out certification costs, these include size of the organisation and business complexity. This can be tricky to calculate for ISO 42001 as you need to consider the amount of AI systems used before you can provide a quote. The full requirements for this are described in ISO 42006, which is a guidance Standard. Most certification bodies will offer a discount for the combined certification to both Standards. An integrated approach is certainly something that Bas recommends, in addition to ensuring that you keep the same auditor or audit team throughout the implementation. By having one team for both systems, you can complete combined internal audits to save on time and resources.   [16:20] Bas's advice to leadership teams looking to build a case for full certification: First of all, don't wait, just make a start. A lot of businesses make the mistake of waiting until it's a common requirement within their market, which can leave you lagging behind the curve. Instead, strive to be one of the early adopters as that will give you a strategic advantage in the market. This is especially the case if you already have ISO 27001 in place. You already have the foundational knowledge to implement ISO 42001, so just make a start on looking at risks relevant to ISO 42001. Many businesses opt to implement certain Standard due to the demands of their clients, and ISO 42001 is likely to be added to that list. So it's better to get a head start! Bas also recommends finding sources of guidance on ISO 42001 implementation. Whether that's sourcing training or an external party to advise, it's good to have other sources of knowledge of you're not familiar with the Standard or ISO implementation as a whole. [21:30] Bas's favourite quote: We don't rise to the level of our expectation, but we fall to the level of the systems that we use. If you'd like to find out more TUV Nord or are looking for ISO 27001 and ISO 42001 certification, check out their website. We'd love to hear your views and comments about the ISO Show, here's how: ●     Share the ISO Show on Twitter or Linkedin ●     Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one. Subscribe to keep up-to-date with our latest episodes: Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List

AI in Action Podcast
Cybersecurity Series E17: 'Cyber Strategies and Leadership' with CIE's Jane Corr

AI in Action Podcast

Play Episode Listen Later Mar 23, 2026 15:24


Today's guest is Jane Corr, Head of Cyber Security at CIE (Córas Iompair Éireann). Founded in 1945, CIE is Ireland's state-owned public transport group, providing rail and bus services nationwide through its operating companies Iarnród Éireann, Dublin Bus and Bus Éireann. Headquartered in Dublin, the group plays a central role in connecting communities, supporting economic activity and delivering sustainable mobility, carrying hundreds of millions of passenger journeys across Ireland each year.Jane is an accomplished Information Security and IT leader with a proven track record of building high-performing teams and delivering results. Known for her “can-do” attitude and strong customer focus, Jane brings a structured approach to solving complex challenges. Her expertise spans information security, technology risk, programme delivery, IT operations and data centre management within large organisations. She is also highly experienced in presenting to Boards and executive leadership.In the episode, Jane discusses:0:00 Her journey from Infrastructure leader to cybersecurity2:55 Why cyber leaders must communicate concisely and confidently5:36 Her broad CSO role including AI, regulation, talent and influence7:14 Advice to start with strategy, align people, roadmap and governance8:55 The need to embed cyber as accessible service, balance risk and compliance11:52 How cyber is maturing toward measurable, compliance-driven continuous improvementTo find out more about all the great work happening at CIE (Córas Iompair Éireann), check out the website www.cie.ie.

HLTH Matters
Why Healthcare Needs Cyber Resilience, Not Just Cybersecurity

HLTH Matters

Play Episode Listen Later Mar 12, 2026 23:45


In this episode of the Cybersecurity at ViVE series on The Beat Podcast, host Sandy Vance sits down with Chad Alessi, Managing Director of Cybersecurity at CTG, for a wide-ranging conversation about what it really takes to protect healthcare organizations in today's threat landscape. With a background spanning chemical engineering, the U.S. Marines, energy sector Operational Technology security, and IT consulting, Chad brings a unique cross-industry perspective to healthcare cybersecurity. From the difference between cybersecurity and cyber resilience to the rise of AI-powered attacks, this episode is packed with practical insights for healthcare leaders who want to stay ahead of what is coming. In this episode, they talk about how: Cyber resilience focuses on operational continuity when an attack happens, not just prevention Breaches resolved within 200 days can save organizations over $1 million Bad actors often sit idle inside networks for months, collecting data before launching an attack Baseline requirements are identity-first security, including multi-factor authentication (MFA) and privileged access management Human-only Security Operations Center (SOC) models are too slow to keep up with today's automated, AI-powered attacks CTG uses Microsoft's Unified Security Operations (SecOps) platform to eliminate tool sprawl and improve response time Zero-trust architecture is expanding from department-level to enterprise-wide in healthcare New HIPAA regulations now require provable network segmentation for legacy medical devices AI-assisted security operations will continue to grow in the next few years A Little About Chad: As CTG's Managing Director of Cybersecurity, Chad Alessi leverages decades of experience in technology, cybersecurity, and operational strategy across enterprise and mid-market sectors to meet the evolving cybersecurity needs of clients in the U.S. During his time in IT consulting, Chad was instrumental in driving IT transformation in the company's regulated pipeline and gas processing business units. He holds a BS in Chemical Engineering, an MBA from the University of Alabama, an MS in Information Systems with a concentration in Information Security from Syracuse University, and post-graduate certifications in leadership, full stack development, cybersecurity, and cloud computing. Chad is known for his strong work ethic, integrity, resourcefulness, and service-based leadership, which he attributes to his time in the U.S. Marine Corps.

Leaders In Payments
Special Series: The Trust Advantage with David Edwards, SVP Information Security at Payroc | Episode 472

Leaders In Payments

Play Episode Listen Later Mar 5, 2026 37:48 Transcription Available


What does it actually take to secure a payments company in an era of sophisticated, well-funded cybercriminals? In this first episode of The Trust Advantage Series, brought to you by Payroc, host Greg Myers sits down with David Edwards, Payroc's Senior Vice President of Information Security, for a candid and eye-opening conversation about modern cybersecurity in the payments industry.With 30 years in technology — spanning private banking, retail, and payments — David brings hard-won perspective to the questions keeping payments executives up at night. Sparked by a real-world ransomware attack on a payments company, this episode cuts through the compliance checkbox mentality to explore what genuine, operational security actually looks like.David and Greg cover a wide range of critical topics: why passing audits doesn't equal being secure, how AI has radically changed the phishing threat landscape, the three pillars of identity and vulnerability management, and why resilience — not prevention — is the new gold standard. David also breaks down Payroc's layered approach to ransomware defense, how the company integrates acquired platforms without creating security gaps, and the right questions ISVs, ISOs, banks, and merchants should be asking their payment partners.Whether you're a developer, a risk officer, or a business owner processing transactions, this episode delivers a masterclass in why security isn't just an IT issue — it's everyone's job.

RSA Conference
Cyber at the Top: Beyond Confidentiality: The New Priorities in Information Security

RSA Conference

Play Episode Listen Later Mar 5, 2026 24:53


For years, information security was largely centered on protecting confidentiality. But as our world becomes more digital and increasingly dependent on always-available, trustworthy systems, integrity and availability are taking on equal importance. In this episode of Cyber at the Top, Dr. Hugh Thompson is joined by Bjørn Watne, Global CISO of INTERPOL, to explore how this shift is changing the way security leaders think about risk. Together, they discuss why disruption is becoming a defining threat, how emerging technologies are reshaping security priorities, and what it means to balance all three pillars of information security. The conversation offers a thoughtful look at how CISOs can reframe security as a driver of resilience, reliability, and organizational trust.

The ISO Show
#245 What's The Difference Between TISAX and ISO 27001?

The ISO Show

Play Episode Listen Later Mar 4, 2026 23:39


For those in the automotive industry, namely suppliers working with European OEM's, you're likely familiar with TISAX but not necessarily with the Standard that many of its requirements originate from. ISO 27001 is the leading Information Management Standard, and its Annex A forms the basis of TISAX, however there are many differences between the two. For Automotive suppliers looking to create a more holistic Information Security Management System, it can be beneficial to implement elements of both even if you don't intend to certify to both. In this episode, Ian Battersby is joined by Emma Coxhill, isologist at Blackmores, to explore the differences between TISAX and ISO 27001, how existing ISO 27001 compliant management systems can be leveraged for TISAX compliance and the benefits of implementing both Standards for automotive suppliers. You'll learn ·      How does TISAX differ from ISO 27001? ·      How does the recertification / annual surveillance for TISAX and ISO 27001 differ? ·      Can a company have TISAX without ISO 27001 and vice versa? ·      How can an existing ISO 27001 certification be leveraged for TISAX? ·      What are the additional benefits of implementing both TISAX & ISO 27001? ·      What is a reasonable timeframe for implementing TISAX? ·      The key role of Internal Audits ·      How can Blackmores support companies in implementing TISAX? Resources ·      Register for our TISAX webinar here ·      ENX ·      Isologyhub   In this episode, we talk about: [02:05] Episode Summary – Emma Coxhill joins Ian to dive into the key differences between ISO 27001v Information Security and TISAX, including the benefits of implementing both and how each can be leveraged to assist in the implementation of the other.   [03:10] What is TISAX? TISAX was developed for the automotive industry by the German Association of the Automotive Industry, VDA, and it's managed by the ENX Association. It's based on the ISO 27001 Annex A controls, and was created for the automotive industry because they were looking to standardise the framework for assessing and sharing information security results between manufacturers and their suppliers. [04:20] How does TISAX differ from ISO 27001? ISO 27001 is a general Information Security management Standard, it can be applied to any business, whereas TISAX is only applicable to the automotive industry. ISO 27001 includes a framework of requirements that everyone must implement, whereas TISAX has a more customisable element. With TISAX you can select an applicable level and relevant subject areas for your operations. The last main difference is the fact that ISO 27001 certification ends in a certificate which can be shared and displayed wherever you want. TISAX in comparison has Labels, which are only available through the ENX portal where you have control over who can access them. [05:15] How does the recertification / annual surveillance for TISAX and ISO 27001 differ? The good news is that TISAX is a bit more forgiving than ISO when it comes to a recertification cycle. TISAX does not require an annual Surveillance like ISO 27001, instead once you've earned a Label it remains valid for 3 years. ISO 27001 in comparison requires an annual Surveillance for each year until the 3rd when you have your Recertification Audit. If you have a significant change to scope part way through your 3 years of TISAX, you will need to have a chat with your auditor to see if extra work is required. This will depend on your level, with higher levels likely to require some additional work and for you to adjust your scope within the ENX portal. Overall, a TISAX label is less of a burden than traditional Management System Standards like ISO 27001. However, TISAX is a lot more strict and will require more upfront preparation ahead of earning your Label. [07:30] Are Internal Audits required for TISAX? They are, but the amount and frequency are a lot more flexible than ISO 27001. You can do as many as you like, but at a bare minimum we recommend you conduct internal audits 6 months ahead of your TISAX label expiring to ensure you're ready for re-certification. You can of course carry on with annual internal audits to make sure you're on track. This can be handy if specific clients ask for further evidence of you following processes in accordance with TISAX requirements.   [08:35] Can a company have TISAX without ISO 27001 and vice versa? You can! Both are independent Standards, however they do compliment each other. Organisations that hold both have a competitive advantage, as ISO 27001 applies to all industries and is more widely recognised. However, if you only operate in the automotive space, TISAX may be sufficient. If you supply to multiple sectors, it's worth considering implementing both TISAX and ISO 27001. [09:25] How can an existing ISO 27001 certification be leveraged for TISAX? If you already hold an existing ISO 27001 certification, than you're already 80% of the way there to TISAX compliance. As TISAX is based off of ISO 27001's Annex A controls, a lot of the requirements cross over, so you will already have most of the foundations in place to cover TISAX. It will just be the more automotive specific requirements that will require some additional work. These requirements include considerations for: ·      Data Protection ·      Prototype protection ·      Assets ·      3rd Party Suppliers The amount of additional work will also depend on the TISAX Level you're aiming for, with Level 3 being the most demanding for these specific requirements. [10:55] What are the additional benefits of implementing both TISAX & ISO 27001? Benefits include: Robust Information Security – Having both TISAX and ISO 27001 forms a strong and versatile information security infrastructure that will cover all of your operations. Easy Integration – These two Standards complement each other, and can easily be integrated. If you already have ISO 27001 in place, you have already completed a majority of the framework and will be familiar with what's required to earn and keep both your ISO certificate and TISAX Label. Customer Trust and Long-Term Resilience – TISAX is desired, if not an outright requirement for European based OEM's to work with suppliers. They require this because TISAX is a trusted Standard, a Label displays your commitment to information security within the automotive industry. It also helps to put you in a better position to both safeguard data as well as respond in the event of a data / security incident. Wider market access – If you supply to more than just the automotive industry, than having ISO 27001 in place will grant you access to the wider market that will recognise that Standard over TISAX. [12:05] What is a reasonable timeframe for implementing TISAX? This will depend on a number of factors including the type of organisation, the number of sites, resources available etc. The key thing to note is that this is note a 2 week project, it will take a number of months to get everything in place for your external assessment. A good measure of if you're ready is if you can score at least more than 2.71 on your self-assessment, and have completed a few internal audits to double check. If you already have ISO 27001 in place, than you're looking at between 3 – 6 months. If you do not have ISO 27001 in place than you're looking at 6 months minimum. For Level 2, you will need proof that ,you have everything in place, it's all been communicated and the relevant individuals have been trained. Level 3 requires everything to be in place and operating for a certain amount of time, typically around 3 months is ideal to start building a library of evidence ahead of your external assessment. Emma's top tip: Be honest in your self-assessment. It's there to be a benchmark, and you need to reflect on the reality of your position if you're to accurately assess what Level you are ready to be assessed against. [14:20] Core elements for success: As with any Standard, ISO or otherwise, TISAX will require leadership commitment in order to be successful. The requirements of TISAX need to come from the top down, just like with ISO 27001. The Leadership ultimately drive TISAX's success, by ensuring the relevant resources are in place, and involved individuals have the necessary time to implement and maintain the Label. For those within the Automotive Sector, TISAX is becoming an absolute requirement. It's being pushed as a tender requirement, so you may lose out on business if you opt to not earn a Label. [16:35] The key role of Internal Audits: As mentioned earlier, Internal Audits are a key part of the process for both TISAX and ISO 27001. It acts as a business health check to ensure you're on the right path. They can help identify areas which may be non-conforming or simply highlight opportunities for improvement. For TISAX, there is not outright requirement for 3rd party audits ahead of your assessment, however we would recommend them as a fresh pair of eyes can reveal things you may have overlooked. An external auditor will also be more unbias and can provide an honest review and feedback as to what TISAX Level you are ready for.   [18:25] How can Blackmores support you with TISAX Implementation?: We can provide as little or as much support as needed. This can include a fully guided implementation where we assist you through each step. This can apply to both TISAX and ISO 27001 if you wish to certify to both Standards. Other options include: ·      Assisting with your TISAX self-assessment (aka a Gap Analysis) ·      Conducting a Maturity Assessment ·      Conducting internal audits ·      On-site support during your TISAX assessment audit We are happy to provide whatever level of support you need. Blackmores do not provide a tick-box exercise, we pride ourselves on ensuring an implemented system works for you. [21:10] Upcoming TISAX Webinar – Join us on the 18th March 2026 at 2pm for a webinar where we'll dive into TISAX further and provide practical guidance on how to complete the VDA Self-Assessment. Attendees will also get access to some freebies. So don't delay, register your place here today. We'd love to hear your views and comments about the ISO Show, here's how: ●     Share the ISO Show on Twitter or Linkedin ●     Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one. Subscribe to keep up-to-date with our latest episodes: Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List

Cracking Cyber Security Podcast from TEISS
teissTalk: Building a trusted security model for Generative and Agentic AI

Cracking Cyber Security Podcast from TEISS

Play Episode Listen Later Feb 26, 2026 44:16


Transferable lessons - how overlooking fundamental security and data trust leads to Generative and Agentic AI failuresSteps for embedding security checkpoints and governance directly into your AI pipelineStrategies to scale AI safely - avoiding costly retrofits - and positioning security as a key competitive advantageThom Langford, Host, teissTalkhttps://www.linkedin.com/in/thomlangford/Tim Roberts, Managing Director, AlixPartnershttps://www.linkedin.com/in/thrrobertsSatyam Rastogi, Director of Information Security & DevOps, BAMKOhttps://www.linkedin.com/in/hackersatyamrastogi/Deryck Mitchelson, Head of Global CISO Team & C-Suite Advisor, Check Pointhttps://www.linkedin.com/in/deryckmitchelson

Accenture InfoSec Beat
InfoSec Beat: Careers in Information Security – Client Data Protection

Accenture InfoSec Beat

Play Episode Listen Later Feb 20, 2026 27:33


This episode of the InfoSec Beat podcast focuses on careers in information security. Accenture CISO Kris Burkhardt talks with Dan Cosceari, the delivery lead for the Accenture Client Data Protection program, which helps internal teams treat client data properly and manage information security risk. Dan sees client data protection through customers' eyes. This customer-first mindset started in his restaurant days in New York City, and it drives how Dan protects client data today. Hear how he puts this into practice, advocates across the organization, and stays ahead of technology and regulatory changes.

No Password Required
No Password Required Podcast Episode 69 - Sue Serna

No Password Required

Play Episode Listen Later Feb 16, 2026 44:39


Sue Serna - Social Media Security and Governance Leader and Lover of All BeaglesNo Password Required Season 7: Episode 2 - Sue SernaSue Serna is the CEO and Founder of Serna Social and the former head of global social media at Cargill. She brings more than two decades of experience at the intersection of storytelling, strategy, and security.In this episode, she shares her journey from business reporter to leading her own consultancy serving companies around the world on social media strategy.Jack Clabby of Carlton Fields, P.A, joined by guest co-host Rex Wilson of Cyber Florida, welcomes Sue for a candid discussion about the realities of enterprise social media. From managing more than 150 Facebook pages for a single company, to navigating internal politics, agency relationships, and regulatory pressure, Sue explains why social media is far from “free” and why most organizations still under-resource it.Sue dives deep into the gap between social media teams and cybersecurity departments. She outlines how personal account compromises can escalate into enterprise-level incidents, why governance frameworks matter, and how large organizations can regain control of sprawling digital footprints. Drawing from real-world examples, she argues that social media must be treated like finance or HR, a core business function requiring structure, ownership, and accountability.The episode wraps with the Lifestyle Polygraph, where Sue reveals her love of Apollo-era space history, debates iconic Philadelphia traditions, and imagines what magical talent her beagle would bring to Hogwarts.Follow Sue at SernaSocial.com or connect with her on LinkedIn: https://www.linkedin.com/in/sueserna/ Chapters: 00:00 Introduction and First Impressions   02:45 The Evolving Role of Social Media in Corporations   04:58 Transitioning from Journalism to Social Media  11:11 Building Social Media from Scratch   13:00 Becoming a CEO and Founder   16:28 The Importance of Networking   16:54 Bridging the Gap Between Social Media and Cybersecurity  20:51 Real-World Social Media Security Incidents  28:35 Navigating Internal Conflicts in Social Media  30:32 The Lifestyle Polygraph Begins   31:17 Nerd Things That Expose Sue: Space and Harry Potter!  35:16 Sue's Love For Beagles  37:50 Wreckless Intern or Overconfident Executive?  40:42 Hogwarts and Magical Beagles 

The Builders Club Startup Founders Podcast
How Data security is evolving with AI | Arshad Ahmad, ZS - Director of Information Security

The Builders Club Startup Founders Podcast

Play Episode Listen Later Feb 10, 2026 58:58


In this episode of The Builders Club Podcast, Sohail Khan sits down with Arshad Ahmad, Director of Information Security at ZS, to decode one of the most critical challenges of our time: protecting data in the age of Artificial Intelligence.The rapid rise of GenAI has created a paradox for modern enterprises. While AI offers unprecedented productivity, it also opens new doors for sophisticated cyber threats. Arshad breaks down how security leaders are shifting from a "defensive" posture to an "adaptive" one, ensuring that innovation doesn't come at the cost of integrity.Key Insights from Arshad Ahmad:1. AI as a Double-Edged Sword: How AI-driven automation is revolutionizing threat detection while simultaneously enabling hackers to launch more complex, personalized attacks.2. The Privacy Paradox: Strategies for organizations to leverage Large Language Models (LLMs) and internal data without leaking proprietary secrets into the public domain.3. The "Human Firewall" in a Tech-First World: Why technical controls are only half the battle and why building a security-first culture is more important than ever.4. The Evolving CISO Role: How security leadership has shifted from being "the department of No" to a strategic business partner that enables safe growth.Whether you are a cybersecurity professional, a tech leader, or an entrepreneur navigating the digital landscape, this conversation offers a masterclass in staying resilient in an AI-powered world.#CyberSecurity #AI #DataSecurity #InformationSecurity #TheBuildersClub #CISO #TechLeadership #GenAI

Cracking Cyber Security Podcast from TEISS
teissTalk: Silent Swipers - unmasking info-stealers in today's threat landscape

Cracking Cyber Security Podcast from TEISS

Play Episode Listen Later Jan 29, 2026 44:57


Understanding the anatomy, infrastructure and automation of modern information-stealing malwareTracking delivery methods, evasion technique and high-value data targetsBuilding effective, multi-layered defences against the prevalent info-stealer familiesThom Langford, Host, teissTalkhttps://www.linkedin.com/in/thomlangford/Jim Walter, Senior Threat Researcher, SentinelOneBrett Taylor, SE Director UK&I, SentinelOnehttps://www.linkedin.com/in/effectiveleaderandmentor/Satyam Rastogi, Director of Information Security & DevOps, BAMKOhttps://www.linkedin.com/in/hackersatyamrastogi/

No Password Required
No Password Required Podcast Episode 68 — Rob Hughes

No Password Required

Play Episode Listen Later Jan 20, 2026 44:51


Rob Hughes — CISO at RSA and Champion of a Passwordless FutureNo Password Required Season 7:  Episode 1 - Rob HughesRob Hughes, the CISO at RSA, has more than 25 years of experience leading security and cloud infrastructure teams. In this episode, he reflects on his unconventional career path, from co-founding the original Geek.com and serving as its Chief Technologist during the early days of the internet, to leading security and systems design at Philips Home Monitoring.Jack Clabby of Carlton Fields, P.A. and Kayley Melton welcome Rob for a wide-ranging conversation on identity, leadership, and the realities of modern cybersecurity. Rob currently leads RSA's Security and Risk Office, overseeing cybersecurity, information security governance, and risk across both RSA's products and corporate environment.Rob explains his dream for a passwordless future. He unpacks why passwords remain one of the largest sources of cyber risk, how real-world incidents and password-spraying attacks have accelerated change, and why phishing-resistant technologies like passkeys may finally be reaching a tipping point.  The episode wraps with the Lifestyle Polygraph, where Rob lightens the conversation with stories about gaming with his kids, underrated horror films, and classic cars.Follow Rob on LinkedIn: https://www.linkedin.com/in/robert-hughes-816067a4/Chapters: 00:00 Introduction to No Password Required01:43 Meet Rob Hughes, CISO at RSA02:05 The Role of a CISO in a Security Company05:09 Transitioning to the CISO Role08:00 The Early Days of Geek.com12:14 Launching a Startup During the Dot Com Boom14:30 The Push for a Passwordless Future18:21 Tipping Point for Passwordless Adoption20:20 Ongoing Learning in Cybersecurity26:09 Managing Stress in High-Pressure Environments33:46 The Lifestyle Polygraph Begins34:15 Career Insights in Cybersecurity36:08 Dream Cars and Personal Preferences39:58 Underrated Horror Films41:19 Creating a Cybersecurity Monster

The Gate 15 Podcast Channel
The Gate 15 Interview EP 66: Chris Camacho: Cyber Risk, Building Communities, Nirvana, and Peruvian Chicken

The Gate 15 Podcast Channel

Play Episode Listen Later Jan 19, 2026 39:24


In this episode of The Gate 15 Interview, Andy Jabbour speaks with Chris Camacho. Chris is Abstract Security's Co-Founder and Chief Operating Officer (COO). In this role, Chris is responsible for the go-to-market strategy, company vision, growth, collaboration, and client engagement. He is a leader, innovator and community builder. Before co-founding Abstract Security, Chris served as both Chief Strategy Officer and Chief Revenue Officer at Flashpoint and was responsible for helping grow the company to an acquisition by Audax PE and supporting three acquisitions to Flashpoint's portfolio, which helped the company be an industry market leader in the information security market. Before his time at vendors like Abstract Security and Flashpoint, Chris was the Senior Vice President of Information Security at Bank of America, where he oversaw the Threat Management Program. An entrepreneur, Chris also served as CEO for NinjaJobs, a career-matching community for elite cybersecurity talent. As he continues to build trust and relationships throughout the cybersecurity community, he's now building C2 Corner, a space for security leaders to share stories, connect through experience, and build what's next together. Chris on LinkedIn.In the podcast Chris and Andy discuss:Chris's background and the road from financial services to becoming a vendor.Chris shares some threat perspective from deepfakes to the complexities of geopolitics and polarization.Chris talks about managing ever-increasing amounts of data and how Abstract Security is helping organizations to reduce risk.We discuss the idea of AI SOCs helping to enhance security operations.The importance of community building: from trust groups and ISACs to C2 Corner to in-person meet-ups!Chris shares some career advice, andWe play 3 Questions! and talk Chris's favorite meats, reading books (and writing books?), and the glory of the 90s.Selected links:Abstract Security. “Security teams should stop adversaries—not manage security data. Abstract's streaming-first platform simplifies the entire security data pipeline, from ingestion to detection to storage. By eliminating noise and delays, we help your team move faster, stay focused, and outpace attackers in real time.”Introducing C2 Corner: By Practitioners, For the IndustryApplied Security Data Strategy: A Leader's Guide: a practical toolkit designed to help organizations of all sizes

Cybercrime Magazine Podcast
CISO Confidential. Measuring Human Risk. Adam Keown, Eastman & Kendra Cooley, Doppel.

Cybercrime Magazine Podcast

Play Episode Listen Later Jan 13, 2026 13:47


Adam Keown is the CISO at Eastman. In this episode, he joins host Scott Schober and Kendra Cooley, Senior Director of Information Security and IT at Doppel, to discuss humans and the evolving cyber threat landscape, including what tailored, environment-specific training looks like, ideal resilience programs, and more. This episode of CISO Confidential is brought to you by Doppel. Learn more about our sponsor at https://doppel.com.

Grow Your Credit Union
The Five Dollar Fake CEO

Grow Your Credit Union

Play Episode Listen Later Jan 6, 2026 32:33


Read the shownotes and full transcript on our site: growyourcreditunion.com Deepfake technology has become so accessible that threat actors need only 10 to 30 seconds of audio and a $5 monthly subscription to convincingly impersonate executives, bypass authentication, and trick employees into catastrophic decisions. Credit unions face record ransomware attacks while most lack AI governance policies to address emerging threats. In this episode of Grow Your Credit Union, host Joshua Barclay welcomes sponsored guest Brian Hinze, President & CEO at NCU-ISAO, along with co-host Oto Ricardo, Director of Information Security and Cyber Risk at Advia Credit Union, to explore: Why ransomware attacks hit record levels despite preparedness efforts How credit unions approach AI governance policies What deepfake threats mean for credit union security How NCU-ISAO supports credit unions through community and collaboration   A huge thanks to our sponsor, NCU-ISAO Cybersecurity threats are evolving faster than ever, and credit unions are increasingly in the crosshairs. NCU-ISAO is the only organization fully dedicated to protecting credit unions through real-time threat intelligence, actionable alerts, expert-led analysis, and a community of security-minded professionals. Strengthen your defenses with collaboration. Learn more at NCUISAO.org/GYCU.

The CyberWire
Michael Scott: A team of humble intellects. [Information security] [Career Notes]

The CyberWire

Play Episode Listen Later Jan 4, 2026 9:37


Please enjoy this encore of Career Notes. Chief Information Security Officer at Immuta, Michael Scott shares his story from working at a forgotten internet service provider to leading the security fight for major food chain restaurants. Michael explains how the different roles at various companies he has worked with paved his way to where he is now at Immuta. He works with a group of colleagues and he leads in a different style, describing that "It really is just a collection of a lot of, we call humble intellects" working with him. Michael attributes adversity to being a cornerstone of existence in the security community, and explains how that helps him keep up the fight. We thank Michael for sharing his story with us. Learn more about your ad choices. Visit megaphone.fm/adchoices

Career Notes
Michael Scott: A team of humble intellects. [Information security]

Career Notes

Play Episode Listen Later Jan 4, 2026 9:37


Please enjoy this encore of Career Notes. Chief Information Security Officer at Immuta, Michael Scott shares his story from working at a forgotten internet service provider to leading the security fight for major food chain restaurants. Michael explains how the different roles at various companies he has worked with paved his way to where he is now at Immuta. He works with a group of colleagues and he leads in a different style, describing that "It really is just a collection of a lot of, we call humble intellects" working with him. Michael attributes adversity to being a cornerstone of existence in the security community, and explains how that helps him keep up the fight. We thank Michael for sharing his story with us. Learn more about your ad choices. Visit megaphone.fm/adchoices

Assurance in Action
Cybersecurity Demystified: UK Govt initiatives to strengthen cyber resilience in the UK

Assurance in Action

Play Episode Listen Later Dec 18, 2025 24:35 Transcription Available


In the third episode of our ‘Cyber Security De-mystified Podcast Series', Steve Ramsden, President Information Security at Intertek meets with guest speaker Irfan Hemani -Deputy Director for UK Cyber Security & Resilience Policy at Department for Science, Innovation and Technology –  DSIT to talk about UK Govt initiatives aiming to strengthen cyber resilience and what this means for UK organisations.Speakers:Steven Ramsden:  President of Information Security at IntertekIrfan Hemani : Deputy Director for UK Cyber Security & Resilience Policy,  DSITFollow us on- Intertek's Assurance In Action || Twitter || LinkedIn.

Destination Linux
446: Ubuntu From The BIOS & The Quest for an Open Source Mac

Destination Linux

Play Episode Listen Later Dec 16, 2025 70:08


This week on Destination Linux, we are joined by a special guest host: Craig Rowland, the CEO of Sandfly Security! We're diving deep into the reality of modern security—specifically when third-party code knocks over your castle. From malicious VSCode extensions to the "React2Shell" vulnerability, we discuss why "Open Source" doesn't automatically mean "Safe" and how to protect your supply chain. Then, is it possible to have the macOS experience without the Apple ecosystem? Ryan explores ravynOS, a daring new project with "macOS vibes and a BSD soul." It's attempting to bring the Aqua interface—and eventually Mac app compatibility—to the open-source world. Plus, Jill brings us massive news from Canonical and AMI. You might soon be installing Ubuntu directly from your motherboard's BIOS without ever needing a USB drive. We break down how this partnership changes the game for hardware. Finally, we read an incredible listener story. Show Notes: 00:00:00 Intro 00:02:39 Extended Intro: Open Source or Bust 00:03:08 Community Feedback: A Pentester's Origin Story 00:10:03 Guest Host: Sandfly Security & Agentless Protection 00:15:53 Security Deep Dive: Supply Chain Attacks, Malicious VSCode Extensions & React2Shell 00:44:31 ravynOS: The Open Source Mac Killer? 00:56:05 News: Canonical + AMI: Installing Ubuntu from the BIOS 01:08:07 Outro 01:09:33 Post-Show Shenanigans Support the Show: Sponsored by Sandfly Security: destinationlinux.net/sandfly - Get 50% off the Home Edition with code DESTINATION50 Special Guest: Craig Rowland.

Money Matters
Holiday Scams And Safe Shopping

Money Matters

Play Episode Listen Later Dec 3, 2025 22:51 Transcription Available


We break down the most common holiday scams and show how small choices—slowing down, going direct, and verifying—protect your money and your identity. Russell Barger, VP of Information Security, shares simple rules that stop most attacks at home and at work.• seasonal lures through fake deals, social posts and tracking links• warning signs: urgency, odd senders, spoofed domains, impersonal tone• safer shopping by navigating directly to trusted sites• workplace risks from HR and payroll phishing during year end• how to verify without clicking and use second channels• what to do after a risky click and quick password resets• saving cards on big retailers versus small shops• gift card scams: tampering checks and “boss” requests• social engineering spikes and holistic message evaluation• two golden rules: don't click and were you expecting thisSubscribe to the Money Matters PodcastHave an idea for a show or a question for Kim? Send us a text messageSupport the showWelcome to Money Matters, the podcast that focuses on how to use the money you have, make the money you need and save the money you want – brought to you by Neighbors Federal Credit Union. The information, opinions, and recommendations presented in this Podcast are for general information only and any reliance on the information provided in this Podcast is done at your own risk. This Podcast should not be considered professional advice.

Security Unfiltered
Unlocking Data Protection: Vishnu Varma on Cybersecurity Challenges

Security Unfiltered

Play Episode Listen Later Dec 1, 2025 53:55 Transcription Available


Send us a textIn this episode, Joe sits down with Vishnu Varma to explore the evolving landscape of cybersecurity and data management. Vishnu shares his journey from India to the US, detailing his experiences at Cisco and the rise of cloud security. They delve into the challenges of managing vast amounts of data in the age of AI, discussing how BonFi AI is innovating in data security. Tune in to learn about the importance of context in data protection and the future of cybersecurity in a rapidly changing digital world.00:00:19 Introduction to Vishnu's Journey00:00:30 Entering the US and Cisco00:02:18 Cloud Security and AI00:02:48 Data Governance and Challenges00:08:47 The Expansiveness of Cloud00:11:00 AI's Appetite for Data00:12:11 Data Security in the JNI Era00:14:29 The Importance of Context00:16:13 Data Used by Enterprises00:22:24 Conclusion and Future Trendshttps://www.bonfy.ai/Bonfy.aiBonfy ACS is a next-gen DLP platform built for the AI era. Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.Support the showFollow the Podcast on Social Media! Tesla Referral Code: https://ts.la/joseph675128 YouTube: https://www.youtube.com/@securityunfilteredpodcast Instagram: https://www.instagram.com/secunfpodcast/Twitter: https://twitter.com/SecUnfPodcast Affiliates➡️ OffGrid Faraday Bags: https://offgrid.co/?ref=gabzvajh➡️ OffGrid Coupon Code: JOE➡️ Unplugged Phone: https://unplugged.com/Unplugged's UP Phone - The performance you expect, with the privacy you deserve. Meet the alternative. Use Code UNFILTERED at checkout*See terms and conditions at affiliated webpages. Offers are subject to change. These are affiliated/paid promotions.

Cyber Crime Junkies
This New Rule Can DESTROY Your Sales Overnight: CMMC's Wide Reach

Cyber Crime Junkies

Play Episode Listen Later Nov 10, 2025 39:41 Transcription Available


CMMC 2.0 explained in plain English — what it means for small businesses, defense contractors, and vendors across the DoD supply chain. Learn about Level 1 vs Level 2, self-attestation risks, C3PAO shortages, compliance deadlines, and how to stay audit-ready before 2025.Don't miss out on crucial information about the CMMC 2025 deadline. The Cybersecurity Maturity Model Certification is a vital requirement for businesses dealing with the Department of Defense. If you miss the deadline, you risk losing contracts and facing severe penalties. In this video, we'll explore the consequences of missing the CMMC 2025 deadline and provide valuable insights on how to prepare and stay compliant. Stay ahead of the game and ensure your business is CMMC-ready. Find out what happens if you missed the deadline and learn how to avoid costly mistakes. Tune in now and take the first step towards CMMC compliance. CHAPTERS00:00 – The 4 Letters That Can End Your Business00:15 – CMMC 2.0: Why November 10, 2025 Changes Everything01:35 – Meet the Expert: Frontline View from a CMMC Assessor02:59 – What Is CMMC (In Plain English)?04:20 – FCI vs CUI: The Data That Decides Your Level07:05 – Are You Level 1 or Level 2? How the Flow-Down Really Work10:05 – Why the DoD Stopped “Trusting” Small Contractors11:40 – Supply-Chain Breaches: How Third Parties Take You Down13:00 – Level 1: The 17 “Basic” Controls Everyone Ignores17:00 – The Dangerous Game of Fudging Your Self-Attestation21:15 – Level 2: 110 Controls, SSPs, and the Reality of NIST 800-17123:40 – C3PAO Bottleneck: Why Waiting Means Losing Contracts26:30 – POA&M and the 180-Day “Grace” Trap32:05 – Surprise: Printers, MSPs, and “Non-Defense” Vendors in the Blast Radius35:15 – CMMC Is Not Going Away (And Other Hard Truths)37:05 – Countdown to FallSend us a textGrowth without Interruption. Get peace of mind. Stay Competitive-Get NetGain. Contact NetGain today at 844-777-6278 or reach out online at www.NETGAINIT.com Support the show

The Social-Engineer Podcast
Ep. 325 - Security Awareness Series - A Crystal Ball for Mitigating Threats With Chris and Carter

The Social-Engineer Podcast

Play Episode Listen Later Oct 20, 2025 32:02


Today on the Social-Engineer Podcast: The Security Awareness Series, Chris is joined by Carter Zupancich. Chris and Carter explore the evolving landscape of social engineering threats, focusing on the rise of vishing attacks and the role of AI in enhancing these tactics. Their discussion underscores the importance of empowering employees as a human firewall and the need for continuous education and testing to strengthen organizational security. [Oct 20, 2025]   00:00 - Intro 00:31 - Carter Zupancich Intro -          Website: https://carterzupancich.com/ 01:30 - Intro Links: -          Social-Engineer.com - http://www.social-engineer.com/ -          Managed Voice Phishing - https://www.social-engineer.com/services/vishing-service/ -          Managed Email Phishing - https://www.social-engineer.com/services/se-phishing-service/ -          Adversarial Simulations - https://www.social-engineer.com/services/social-engineering-penetration-test/ -          Social-Engineer channel on SLACK - https://social-engineering-hq.slack.com/ssb -          CLUTCH - http://www.pro-rock.com/ -          innocentlivesfoundation.org - http://www.innocentlivesfoundation.org/                                                03:35 - Tools, Tactics and Procedures 05:19 - Tech Advances 08:16 - The Classics 10:01 - The Need for Testing 12:16 - Callback Phishing 17:26 - Setting Expectations 21:56 - Approved Language 23:56 - Verify! 25:16 - Empowerment 26:17 - And Now a Horrible Story 28:47 - Investing In Employees 31:19 - Wrap Up & Outro -          www.social-engineer.com -          www.innocentlivesfoundation.org

Cybersecurity Where You Are
Episode 156: How CIS Uses CIS Products and Services

Cybersecurity Where You Are

Play Episode Listen Later Oct 8, 2025 37:02


In episode 156 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager are joined by Stephanie Gass, Sr. Director of Information Security at Center for Internet Security® (CIS®), and Angelo Marcotullio, Chief Information Officer at CIS. Together, they explore how CIS practices what it preaches by using CIS products and services internally, which includes implementation of the CIS Critical Security Controls® (CIS Controls®) and CIS Benchmarks®, automation, and alignment to compliance frameworks. Their discussion highlights how CIS builds a strong cybersecurity foundation while adapting to evolving threats and regulatory requirements.The conversation dives into practical applications, cultural alignment, and the importance of repeatable processes for scaling security across new products and services. It also touches on the role of privacy regulations, cyber risk quantification, and the community-driven approach that underpins CIS best practices. Here are some highlights from our episode:01:12. Why CIS “drinks its own champagne” when it comes to cybersecurity02:56. Three ways the CIS Controls help modern enterprises defend against threat actors04:02. The importance of pulling together security lessons learned in a way that's translatable10:03. Our use of the CIS Controls to align to SOC 2, ISO 27001, and other frameworks12:01. How governance, risk, and compliance (GRC) engineering works with automation to help build repeatable processes22:43. The role of collaboration and communication in building a cybersecurity program27:17. Privacy regulations as a catalyst for security innovation30:24. The CIS Community Defense Model and evidence-based practices32:40. How CIS leverages lessons learned to improve our security best practicesResourcesEpisode 146: What Security Looks Like for a Security CompanyImplementation Guide for Small and Medium-Sized Enterprises CIS Controls IG1How to Construct a Sustainable GRC Program in 8 StepsMapping and Compliance with the CIS ControlsCIS Completes SOC 2 Type II Audit Using CIS Best PracticesEpisode 74: The Nexus of Cybersecurity & Privacy LegislationCIS Community Defense Model 2.0Episode 121: The Economics of Cybersecurity Decision-MakingEpisode 77: Data's Value to Decision-Making in CybersecurityCIS CommunitiesIf you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.

AWS for Software Companies Podcast
Ep154: Presenting Security to the Board of Directors with CISOs from Gusto and MongoDBs

AWS for Software Companies Podcast

Play Episode Listen Later Oct 6, 2025 31:28


Experienced CISOs from MongoDB and Gusto reveal proven frameworks for translating complex cybersecurity metrics into board-friendly presentations that drive decision-making.Topics Include:Security leaders discuss challenges of presenting technical cybersecurity topics to boardsMongoDB CISO presents three times in six months, Gusto director five timesThree-angle metrics framework: environmental threats, prevention quality, and detection/response speed capabilitiesBoard members switch contexts frequently, requiring extensive education and simplified heat mapsRepeatable presentation models help board members follow consistent data across meetingsAudit committees get different depth than general board updates on programsNew technologies like AI require educating boards on risks versus opportunitiesFoundational security principles like zero trust remain constant regardless of technologySecurity buzzwords need translation appendices since board members forget technical definitionsFinancial services background helps translate cyber risks into dollar amounts boards understandThird-party penetration testing provides independent validation but requires vendor rotation strategiesLimited 30-minute board time means trusting security leaders' vendor diligence decisionsFirst-time CISOs should educate on threat landscape then tailor strategy to companyBalance discussing shiny new technologies with essential foundational security blocking and tacklingAI implementation spans customer features, infrastructure security, and augmenting security capabilities internallyParticipants:Sean Josephson - Sr. Director of Information Security, GustoJulien Soriano – Sr. Vice President, CISO, MongoDBGee Rittenhouse - Vice President, Security Services, Amazon Web ServicesFurther Links:Gusto: Website – LinkedInMongoDB: Website – LinkedIn – AWS MarketplaceSee how Amazon Web Services gives you the freedom to migrate, innovate, and scale your software company at https://aws.amazon.com/isv/

The New CISO
Are You Relying on the Right Tools?

The New CISO

Play Episode Listen Later Sep 11, 2025 44:19


In this episode of The New CISO, host Steve Moore speaks with Dr. Timo Wandhöfer, Group CISO and Head of Information Security & Business Continuity Management at Klöckner & Co, about the evolving responsibilities of modern CISOs and why influencing—not just convincing—stakeholders is essential for success.From his early career as a researcher in computer science to leading global security and resiliency efforts in the steel industry, Timo shares how critical thinking, skepticism, and cross-functional collaboration shaped his leadership style. He reflects on the dangers of overconfidence in detection, the risks of over-relying on tools, and the lessons learned from merging information security with business continuity. Timo also explores how AI can both accelerate remediation and introduce new risks, and why resilience planning and transparent communication are at the core of effective leadership.Key Topics Covered:The evolving role of the CISO: from protection to resilience and adaptabilityHow research skills translate into critical thinking and cross-functional collaborationWhy overconfidence and lack of visibility remain major pitfalls in security programsThe importance of transparency, maturity, and asset inventory for strong defensesResiliency planning: ransomware recovery, crisis management, and operating modelsInsider threat investigations and the role of HR, Legal, and IT in responseThe shift from convincing to influencing stakeholders through dialogueThe promise and risks of AI and automation in remediation and decision-makingWhy today's CISO must be a communicator, storyteller, and business leaderTimo's journey highlights how resilience, adaptability, and influence define the “new CISO.” His insights provide a roadmap for leaders who want to strengthen security programs, build trust with stakeholders, and guide their organizations with both technical and business acumen.

The Rachel Maddow Show
War plans group chat scandal fits pattern of Trump's embarrassing weakness on information security

The Rachel Maddow Show

Play Episode Listen Later Mar 26, 2025 44:20


Rachel Maddow looks at Donald Trump's ridiculously poor track record of mishandling sensitive information, with the scandal of several of his top officials thoughtlessly discussing military plans in an insecure group text raising questions of criminality on top of the widespread outrage over the sheer sloppiness of their actions.