POPULARITY
Podcast: PrOTect It All (LS 27 · TOP 10% what is this?)Episode: AI for OT Cybersecurity: Real-World Strategies to Protect Critical InfrastructurePub date: 2026-07-06Get Podcast Transcript →powered by Listen411 - fast audio-to-text and summarizationAI is changing OT cybersecurity - but success still depends on understanding your operations. In this episode of Protect It All, host Aaron Crow welcomes Vivek Ponnada for a practical conversation about how artificial intelligence is transforming the way organizations defend critical infrastructure. With decades of experience in industrial automation and OT security, Vivek shares firsthand insights into the realities of protecting legacy control systems while preparing for a future increasingly shaped by AI, automation, and digital transformation. Together, Aaron and Vivek discuss how organizations can use AI to improve visibility, accelerate threat detection, prioritize vulnerabilities, and strengthen operational resilience, without losing sight of the fundamentals that keep industrial environments safe. Key Learning: How AI is transforming OT cybersecurity and industrial operations Practical AI use cases for protecting critical infrastructure Why legacy systems remain one of the biggest OT security challenges How AI can improve vulnerability management and incident response The role of digital twins in strengthening cyber resilience Why trust, collaboration, and operational knowledge remain essential in OT security Whether you're responsible for manufacturing, utilities, energy, water, or other critical infrastructure, this episode provides practical insights into balancing innovation with operational reliability. Tune in to discover how AI can strengthen OT cybersecurity while helping organizations protect the systems that keep the world running. Key Moments: 06:43 AI and cloud adoption in OT 13:27 Controller logic changes and safety steps 21:24 Discussing Digital Twins for Security Use 26:51 Managing vulnerabilities at scale 32:41 Understanding Power Plant Limitations 37:17 Keeping up with plant changes 41:43 Automating infrastructure and maintenance 49:08 Rising importance of cybersecurity investment 52:16 Early days in cybersecurity and OT 01:00:03 Ransomware impacts on industries 01:01:53 Using GPUs for security and OT About the guest : Vivek Ponnada is an Operational Technology (OT) Security practitioner with global experience and currently serves as the SVP of Growth & Strategy at Frenos, the world's first Simulated OT Pentesting Platform. Having started his career in Industrial Control Systems (ICS) as a Technician, Vivek became a Controls Engineer and commissioned Gas Turbines in Europe, Middle-East, Africa and South-East Asia. Post MBA, Vivek held multiple roles in Sales, Marketing & Business Development and Services covering ICS and OT Security solutions for Critical Infrastructure industries (Power, Oil & Gas etc.) at GE, XenonCyber Dynamics and Nozomi Networks. He was a co-lead for the Top 20 Secure PLC Coding Practices Project and regularly speaks at Information Security Conferences. Vivek has a C.Eng. from IEI, MBA from McCombs (UT Austin) and holds the ISA/IEC 62443 Cybersecurity Expert & GICSP certifications. He is a member of the ISA, ISACA, Public Safety Canada ICS Security Symposium Advisory Committee and is a CS2AI Fellow. How to connect Vivek: Frenos: https://frenos.io LinkedIn: https://www.linkedin.com/in/1ot/ Frenos YouTube: https://www.youtube.com/@Frenos_Security Learn more about PrOTect IT All: Email: info@protectitall.co Website: http://protectitallpod.com/ep113 X: https://twitter.com/protectitall YouTube: https://www.youtube.com/@PrOTectITAll FaceBook: https://facebook.com/protectitallpodcast To be a guest or suggest a guest/episode, please email us at info@protectitall.co Please leave us a review on Apple/Spotify Podcasts: Apple - https://podcasts.apple.com/us/podcast/protect-it-all/id1727211124 Spotify - https://open.spotify.com/show/1Vvi0euj3rE8xObK0yvYi4The podcast and artwork embedded on this page are from Aaron Crow | Operational Technology & Cybersecurity Host, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.
Welcome to RIMScast. Your host is Justin Smulison, Business Content Manager at RIMS, the Risk and Insurance Management Society. In this episode, Justin interviews RIMS Vice President of Content & Publications, Morgan O'Rourke, and RIMS Risk Management Magazine Managing Editor, Hilary Tuttle, on the Q2 digital edition online now. The discussion starts with Hilary's Hurricane prediction and the risks associated with storms. They discussed the risks of applying AI in the risk industry, and how using it for the simple tasks means your remaining tasks are the hard ones. To get the best results, be polite to your AI! Justin asks about Red Teaming, its purpose, and how it operates. Human behavior is an important consideration in risk management. Listen for pointers on what to do as a risk manager for the rest of 2026, and some things to avoid. Key Takeaways: [:01] About RIMS and RIMScast. [:16] About this episode of RIMScast. This is our mid-year risk review, and we will be rejoined by Morgan O'Rourke and Hilary Tuttle. They are here to discuss the major trends shaping the risk landscape; what's happened so far in 2026, and what we can look forward to. But first… [:47] RIMS Virtual Workshops. The next RIMS-CRMP Exam Prep with PARIMA will be held virtually on July 21st and 22nd. Registration links are in this episode's notes. [:58] We have a summertime webinar. On July 16th, Zurich will present "Too Hot to Ignore: Heat-Related Injuries and Workers' Compensation." Register at RIMS.org/webinars and via the link in this episode's show notes. [1:13] Also on the webinars page, you will see a two-part series hosted by the RIMS Membership Department. The "Classroom to Career" webinar series highlights how RIMS equips students with the knowledge, skills, and connections needed to thrive in risk management careers. [1:29] Participants will gain insights into industry trends, career pathways, and practical tools that help them confidently step into the evolving world of risk management after graduation. These sessions will be hosted on September 1st and 9th. [1:42] These sessions are member exclusives and are complimentary for RIMS members, of course. So, if you are interested in becoming a member, this would be the time. Visit RIMS.org/membership. [1:52] You can enroll now in the RIMS CRO Certificate Program in Advanced Enterprise Risk Management hosted by the famous James Lam. Beginning July 15th, workshops will be held bi-weekly from 11:00 a.m. to 3:00 p.m. Eastern Time. The registration link is in the show notes. [2:16] The RIMS ERM Conference 2026 will be held on November 19th and 20th in Columbus, Ohio. Registration will open in July. Be on the lookout for the call for nominations for the RIMS ERM Global Award of Distinction. Visit RIMS.org/ERM2026 in July for that announcement. [2:37] RIMS is back on YouTube. Our handle is @RIMSOfficialChannel. We've got plenty of videos there, including RIMScast, RIMScast Canada video podcasts, and other informative and entertaining content from RIMS. Subscribe to the channel today! [2:55] On with the Show! We are in the middle of the year, and that means that it's time for our mid-year risk review with two of my favorite people, Morgan O'Rourke, RIMS Vice President of Content & Publications, and Hilary Tuttle, Managing Editor of RIMS Risk Management Magazine. [3:14] Morgan and Hilary are joining us today to discuss some of the highlights of the Q2 Edition of RIMS Risk Management Magazine, which is available now. [3:21] We're going to talk about hurricane preparedness, reputation, red-teaming, AI, and other emerging trends that risk professionals should be aware of, avoiding, and embracing. We're going to have a lot of fun! Let's get to it! [3:35] Interview! Morgan O'Rourke and Hilary Tuttle, Welcome Back to RIMScast! [3:42] Justin mentions that the Publications Department is a team of five. After nine years, Justin is still the second-newest person. [4:29] Morgan says Risk Management Magazine has articles going up every week. Every quarter, they have a digital issue, reminiscent of a physical magazine, with pages and a table of contents. When this episode is released, the Q2 digital issue was published a week ago. [4:54] RIMS Risk Management Magazine has occasional special issues, on ERM and the Special RISKWORLD Awards Issue. Hilary says the Editor's Picks are articles you may have missed on the website. Morgan says it's sometimes new stuff, or archival stuff that's still relevant. [5:30] Morgan says they try to publish in a frequency and format that everybody can appreciate. Morgan and Hilary miss the physical print magazine. Justin thinks they've maintained the essence of the print magazine. Morgan says that's what the digital magazines are meant to do. [6:22] Morgan says print is not necessarily the way that everybody consumes things nowadays, so you've got to be where everybody's attention is, and that's what we're trying to do. [6:40] The Marquee article in the Q2 digital edition is Hilary's coverage of the 2026 hurricane season outlook. Hilary is well-versed in hurricane preparedness and seasonal outlooks. Hilary says this year, a lot of the forecasts are calling for a below-average season. [7:26] This year, Hilary focused on factors that will make the season different. She focused on macroeconomic volatility, geopolitical instability, and U.S. Federal budget cuts as some of the biggest complications this year that are making a fragile and challenging recovery landscape. [8:03] Hilary says we talk about increased prices in disaster materials, preparation materials, supply problems, and a Federal support system characterized by defunding or dysfunction, and what that means for risk managers tasked with hurricane preparation or recovery. [8:43] Hilary says, looking beyond the forecast, it's important to assess how your resilience strategy is going to hold up in practice. Even a single landfall is going to be more expensive, potentially. The cost may be higher than ever. Response materials are 40% more expensive. [9:28] Justin says we had a risk engineer from Global Risk Consultants on the show recently, talking about the physical preparations, 48 hours, 36 hours, and 24 hours before an impact. [9:56] Hilary says, between materials shortages and price increases, the supply chain is potentially going to be a huge problem for disaster preparation and responses. Getting things is difficult with the Strait of Hormuz closed. People are seeing it across industries and materials. [10:22] Some response materials are also going to be more expensive because of the increased cost of oil. Hilary found that interesting when reporting the piece. Generator fuel is drastically more expensive than it has been. [10:43] It's a best practice to have 72 hours' worth per generator on site, if you're in a high-risk area. [11:55] Materials that require petrochemical input include plywood and structural lumber. Boarding your windows is going to be more expensive, if you can get it. Transport costs are going to be drastically higher. [11:11] Heavy-duty plastic sheeting is a petrochemical-related product. Some products also use by-products of the crude oil production: polymers, petroleum derivatives, and plastics, like rubber seals. All of those will be more expensive as crude oil fluctuates. [11:40] Morgan says you have to prepare for increased costs. You may be underinsured for the costs of materials you may have insured for in the beginning. Be aware of increased costs and do what you can to prepare, whether by increasing coverage or buying more in bulk. [12:10] If you're going to face increased costs, the more you do beforehand to offset those costs is probably for the better. Hilary says she put together 10 detailed and useful tips. One thing that she bumped up the list is to revisit your insurance values and policy limits. [12:40] Hilary thinks the risk of underinsurance is worth underscoring this year. It is going to be drastically more expensive to rebuild. Make sure you have the coverage you need to cover those expenses and the expenses of potentially needing to relocate when things are closed. [12:56] Car parts are drastically more expensive, so if you operate fleets, it's worth noting that those metals are delayed and pricier because of tariffs and supply chain problems. [13:11] Hilary says it's also worth noting that we had Tropical Storm Arthur last week. It never reached hurricane strength, but it still managed to do four to six billion dollars in damage, according to initial estimates from AccuWeather. [13:27] Tropical Storm Arthur hit the Gulf Coast and did a lot of damage in terms of business interruption, delayed flights, and extended power outages. In terms of business continuity, it doesn't need to be a hurricane to do a tremendous amount of damage. [13:47] AccuWeather says the hurricane classification system is solely based on wind speed. Wind does not do as much damage as water. Storm surge, inland flooding, and water damage are not reflected in hurricane classification. We shouldn't just be concerned about hurricanes. [14:21] The peril and the need for preparation are just as dramatic for other storms. [14:28] Morgan notes that the storm season started on June 1st, and we had a billion-dollar potential damage storm within a week or so. Hilary says it's one of the earliest we've seen. [14:46] Morgan says they're usually more in the fall. In some years, we've seen tropical storms before the season. Storms are not necessarily confined to the Atlantic Coast. There are Pacific storms to take into account. [15:18] Morgan learned about Pacific storms from Hilary. In between Hilary's article drafts, there were three Pacific hurricanes that formed, so she had to update the story. The Super El Niño is the climate pattern that creates these storms in the Eastern Pacific. [15:47] With the Super El Niño, you get more activity in the Eastern Pacific and less in the Atlantic because of warmer waters in the Pacific and more Trade Winds in the Atlantic that act to break up storm formation. [16:05] Parts of Central America, Mexico, and the West Coast are going to be at increased risk. Hawaii, as well. Morgan says one of the more impactful storms on the Pacific was named Hilary in 2023. Hilary was a billion-dollar storm that killed three people. [17:21] A Quick Break! There are so many other wonderful RIMS events coming up in 2026. The Annual Florida RIMS Educational Conference will be held from July 28th through August 1st at the lovely Ritz-Carlton in Naples, Florida. A link to the event is in this episode's show notes. [17:40] Register now for the Second Annual RIMS Texas Regional Conference, which will be held from August 10th through 12th at the Grand Hyatt on the San Antonio River Walk. [17:51] The 11th Annual Chicagoland Risk Forum will return to the Old Post Office on Thursday, September 24th, 2026. Visit ChicagolandRiskForum.org for more information. [18:01] The RIMS Western Regional Conference will be held from October 4th through the 7th in Seattle, Washington. The agenda is live, and registration is open. Visit RIMSWesternRegional.com and the link in this episode's show notes for more information. [18:18] Save the dates October 18th through the 21st. We will be in Quebec City to celebrate the 50th Live RIMS Canada Conference. Booth sales are open, and sponsorship opportunities are still available. Advance registration is open now. [18:35] Visit RIMSCanadaConference.ca for more information. Also, remember to check out RIMS.org/Canada for our spinoff show, RIMScast Canada, hosted by National Conference Committee Chair, Aaron Lukoni. [18:50] The RIMS ERM Conference 2026 will be held on November 19th and 20th in Columbus, Ohio. Registration opens in July. [19:01] Be on the lookout for an announcement about submissions for the RIMS Global ERM Award of Distinction. Visit RIMS.org/ERM2026. [19:12] Let's Return to Our Interview with RIMS Risk Management Magazine's Hilary Tuttle and Morgan O'Rourke! [19:31] Justin says artificial intelligence is on people's minds. It's evolved into a data governance and operational risk challenge. [19:52] Morgan's first reaction concerning AI is, "What else can we say about this?" There is a little bit of burnout about AI. Hilary says we get so many articles. Morgan says there does need to be attention paid. What are your AI use policies? Are your employees introducing risk with AI? [20:42] Morgan says there was a cybersecurity survey cited in the issue. The biggest risks they are seeing are misinformation and disinformation. IT people don't consider themselves or their companies prepared to identify those risks across the board. Justin quotes that ISACA poll. [21:45] Hilary says you're seeing a lot of shadowy AI use; a lot of unlicensed and unsanctioned use. If your company allows you to use Copilot, but you're using ChatGPT and Gemini, that's unsanctioned use. [22:15] Morgan says dropping an entire report in that might be proprietary information, to distill that into a public environment; not just opening the program, but what you're putting into it, may be stuff that no one would want out. [22:31] Hilary says a recent study showed that 90% of organizations have employees who regularly use personal AI tools at work. Forty percent of companies have bought official subscriptions to AI services because they get different privacy protections than free versions. [22:51] Fifty percent of companies are running on shadow AI. They're either letting employees foot the bill by using personal subscriptions or using a free mode, and that's a disaster. One of the things a lot of organizations aren't thinking about is the cost of subscriptions and tokens. [23:10] A lot of companies that are starting to adopt AI at a large scale and are footing that bill are running into astoundingly large bills for these services and not factoring in that it is not free computing power. It is not a free tool. [23:28] Now that some of these companies are going IPO, if tools are free, they're not going to stay free. Morgan says, it's one of those things that, although it's not necessarily something you want to hear for the fifteenth time, it doesn't mean you shouldn't be doing something about it. [24:03] Hilary adds that hidden costs are a big thing people aren't thinking about. People are thinking about governance, which is incredibly important. The market for that is also booming. People have an interest in making you afraid of it, as well as selling it to you in the first place. [24:22] Hilary says, the governance market is going from $200+ million two years ago to an estimated three or four billion dollars by 2037. It's a huge industry to make you dependent on AI and to charge you to govern it or make it safer. [24:43] Hillary says we're seeing studies that companies have made huge investments in AI, and are not seeing an ROI. A recent study showed that 5% of organizations have had transformative ROIs. The other 95% said there is zero measurable impact on Profit & Loss, if not a net negative. [25:10] Hilary says one CEO said that unless it's for coding specifically, we're not going to get monetary value whatsoever out of AI. A lot of companies that have fired people are starting to reverse course really quickly. [25:24] Hilary says companies that make AI are walking back a lot of their claims about how transformative it's going to be. They had said there would be a job apocalypse because widespread job automation would be so easy. They're walking that claim back. [25:47] The COO of Uber said that gains in productivity were absolutely nothing compared to the increased AI-related expenses they are experiencing. They're walking back a lot of their investment. [25:58] The former Chief of AI at Microsoft said that employees default to automating tasks that they dislike, rather than ones that create value. Morgan says it speaks to being practical about what you're going to get out of it, as opposed to it being a magic button to press. [26:28] Morgan says that in the early going of anything, there's a spike of promise and then reality kicks in. AI is not going to be tossed aside. Hilary says there's a hype bubble around AI, that AI is for everything, and that AI would replace everyone. Companies are laying off. [26:59] Hilary says last year, 125,000 tech workers lost their jobs. In 2026 through June, already 120,000 tech workers have lost jobs. We are seeing an overinflated promise of what AI is going to be. People are slowly beginning to realize AI is to augment employees, not replace them. [27:25] Morgan says there's a push for "the human in the loop." People have come to recognize that we can't leave people out of this, if only to check the accuracy of results. You can't replace workers because there's stuff that the AI can't do. [27:42] Morgan says AI is always going to tell you what you want to hear. It's going to give you stuff that's already out there. It's not giving you new information; it's just distilling it differently. [27:55] Hilary says there's an important core competency people need to be developing now. Taking a quick look at a thing and saying it makes sense is not an adequate amount of oversight to provide for things you're using AI for, particularly as you start using it more and more. [28:14] AI is structured to give you things it thinks you want, or to predict what you would do. The results may seem well-written, but you must pay attention to what's in it and whether it makes sense. [28:33] Hilary says some people submit stories to RIMS Risk Management Magazine that simply restate things; they don't explore ideas. With AI, don't just look to approve it; look to assess it and analyze what it is doing before you put it forward. [29:14] Hilary says, to be very clear, RIMS Risk Management Magazine does not accept articles that are written by AI. When it comes to articles about AI, they've seen just about everything. [30:11] Morgan says he would probably be interested in practical use cases that are not promotional, if somebody found some success using AI, that fellow risk professionals could benefit from, as well, and not something so proprietary that it only works for their company. [30:26] Morgan says it should be something like where AI might be able to help risk managers in general. A lot of people are using AI for different things. It's not about the only best practice, but helping the magazine establish a list of best practices for AI in the risk process. [30:50] Hilary says it's also helpful to get articles that have practical guidance on what people are using that is useful in terms of governance. How are they crafting effective policies? [31:01] How are they working to train their workforce on best practices so they're using AI responsibly and getting the most out of it? How are they exploring the ideas of customization, if that is something their company is doing in-house? Practical articles. [31:17] Hilary says she is seeing a lot of articles on legal exposure and how that is shaping up since all of the case law is so nascent. What are the exposures? What are the liabilities other organizations are learning in real time that you can start guarding against? [31:35] Morgan says there are a lot of cases working through without a lot of precedent. Some of these cases will become precedents. Four years ago, everyone was talking about basic, general risks. Now we are talking about specific risks of real applications. [32:04] Hilary says there is interest in the costs of AI. That's underexplored and would be interesting to read about. Are companies seeing that it's having impacts they haven't anticipated? Every prompt you give to ChatGPT, even 'thank you," is a payment to OpenAI. [32:54] Hilary says a study showed that 80% of people are saying "please" and "thank you" to the AI because they don't want to make it angry; 18% are doing it because they say it's just the right thing to do. Hilary puts "thank you" at the end of a prompt, so it's not an extra prompt. [33:22] Hilary says, some AI platforms perform better when you talk to them politely. ChatGPT will give you more coherent, nicer, and polished answers if your input is polite. Morgan refers to the Terminator movies. Hilary says, You want to be polite, but you don't want to be empowering. [34:02] Hilary says, in a video from the American Psychological Association, a professor from Michigan State talked about the underappreciated problem with AI, that if you automate the easy parts of your job, then 100% of your job is the hard parts, a guaranteed ticket to burnout. [34:39] You've made the easy wins and the low-level stuff that your brain needs to recover, a part of your job that you don't get to do. You don't get those bits. Everything is complicated, difficult, and exhausting. That's not how the brain is designed to function. [35:00] Morgan says, We don't want AI to do the fun or easy stuff. Hilary says, Think of a call center. If it's a simple thing, like "What time do you open?", or "Do I have a warranty?", AI can close them easily. That leaves you with a furious customer yelling at you for 20 minutes. [35:25] If that's all you do, all day, every day, what is your life going to be like? Then you start putting things on hold because you need a second. If your goal was efficiency, you're not making it more efficient; you're adding more buffer time because you can't handle that all the time. [35:59] Another Quick Break! The Spencer Educational Foundation's Funding Their Future Gala 2026 will be held on September 17th in New York City at the Waldorf Astoria. This year, Spencer will honor Sierra Signorelli of Zurich and our recent guest, Marya Propis of RT Specialty. [36:19] A link to the Gala is in this episode's show notes. [36:21] We have reached the deadline for the Spencer Educational Foundation's Risk Manager on Campus submissions. Grant awardees, colleges, and universities are typically notified in September. [36:37] General Grants are open, and the application deadline is July 30th. Internship Grant applications open on August 15th and close on October 15th. [36:48] Links to each of these grants are in this episode's show notes. Visit SpencerEd.org for more information. [36:56] Let's Conclude Our Interview with Morgan O'Rourke and Hilary Tuttle of RIMS Sisk Management Magazine! [37:09] Morgan and Hilary have released the Q2 Digital Issue of RIMS Risk Management Magazine. There's an article about red teaming. Morgan says Red teaming is conducting a crisis simulation. You have a team that is the adversary, challenging your assumptions and plans. [38:04] Hilary says they are immersive exercises that involve some form of offense and defense. It's basically wargaming. [39:10] The feature on reputation red teaming suggests that organizations need to prepare for the first 48 hours. In a crisis, it's the first 48 hours of the crisis as much as the crisis itself. [39:40] Morgan says social media is going to amplify the impact of a crisis immediately. Consider the knee-jerk reactions you see online to anything that's happening. If your company loses control of the narrative, people are telling a story that isn't your story and isn't accurate. [39:55] Morgan says there was a story that Jeff Bezos had said that we should be using water for AI purposes rather than human consumption because AI will solve more problems. But Jeff Bezos never said that. Social media amplifies something before people question its validity. [40:37] Morgan says we're in an environment where "crazy," more often than not, sounds possible. Hilary says social media is a force multiplier for a lot, particularly when there are zero content moderation controls, leading to misinformation, disinformation, and hate speech. [41:04] Morgan points out that even with moderation, something can be put up and seen before it's moderated. The Bezos story is on Snopes that it's not true, but how many people follow up a story like that after they see the headline? They might not know where they saw it. [41:34] The point of throwing these reputation red teaming exercises together is to acknowledge the fact that not only do you need a plan, but the plan has to be in place to be able to move quickly. [41:44] When it comes to a crisis that happens within your organization, one of the biggest parts of it is the reputation elements. People run with it, "Not only is this a bad thing an organization did, or a questionable thing, but they're terrible for it and irredeemable." [42:04] If you can't put out a statement in the first 12 hours after something happens, because you weren't ready for it, that means you entirely miss out on any opportunity to correct that misinformation and be a part of the narrative that actually steers the conversation. [42:30] Morgan speaks about attention spans. People see a headline and then move on to the next headline. Your first impression may be their only impression. Act quickly. Have the people in place and the plans in place. The exercise is for people to poke holes in your plan. [42:59] Justin says it's a good article, and the author, Ted Skinner, gives you actionable takeaways. Morgan likes the article but had not heard of red teaming. [44:05] Hilary says red teaming is very common in cybersecurity. This is the first time they have run across it in other applications. [44:48] Justin brings up human behavior. It's in the Q2 issue. It permeates every risk. You can't just let AI do your job for you; you have to put a human perspective and input into it. Human behavior impacts employee misconduct. There was an article on it in the RIMS Weekend Read. [45:17] Employee misconduct is on the minds of risk professionals and executives. [45:27] Morgan says culture is a good stopgap measure to have. A risk manager can't be everywhere at once. If your organization has a risk-aware culture, it can stand in for you when you're not around. If everyone's aware of risk, you don't have to be the only person watching. [46:02] Hilary says culture is your sunscreen. It's your everyday, it's your automatic. It's the thing that you need to do to prevent the majority of photoaging and skin cancer. Some of the more subject-specific areas are your serums to spot treat your hyperpigmentation and redness. [46:21] It depends on what your specific skin is like. Are you focusing on wrinkles? Are you adding antioxidants? The sunscreen is the thing you need every day, as it covers the vast majority of problems. [47:05] Morgan says the human element is always necessary to interweave into all of this because it's one of the things you can control. You can't control geopolitical events or storms, but you can control whether or not you put the sunscreen on. [47:25] You can control whether or not you have plans in place for any disaster. That's what allows you to sleep at night. You can do something in an environment where it feels like nothing can be done. That can get overwhelming. [47:42] Hilary says part of overcoming that overwhelm is the empowerment that comes with educating yourself and doing the work. You can't control geopolitical risk. What does that mean for your organization? What does that mean for your cost of materials? [48:06] It takes time, and it's not glamorous to look up how much asphalt we use in a year. The stuff that keeps all the gravel together in asphalt is a by-product of oil production, and drastically increases in price. What does it mean if your supply chain is going to be drastically delayed? [48:33] Those are the ways you can empower yourself and make a difference within your organization with some of these big, ephemeral risks. You need to think, What does this mean for us? [48:49] Hilary says one of the things we evaluate with our goals and the single most common edit note that I give on submitted articles, is "So, what? Yes, that is a risk. What does it mean for you? What do you do about it? What consequence does this have for your organization?" [49:20] Those questions are the distinctions between an article I read and an article I publish. Those are the distinctions between a risk manager who is informed and a risk manager who is empowered. [49:55] Justin asks, based on the Q2 issue of RIMS Risk Management Magazine, and on what they heard and saw at RISKWORLD 2026, what actions should risk managers take before the end of 2026? [50:12] Morgan says it depends on where you come from and understanding where risks exist, for you, and breaking it down to the things you can control, looking at where all these big-picture things intersect your business. [50:33] That comes down to strengthening your fundamental risk management practices to make sure you don't lose sight of the basics. [50:47] There is some talk of the property insurance market softening. That may give you more funds to invest in training or in infrastructure improvements. At least, reassess your policy's terms and conditions and see if you might take advantage of pricing. [51:12] Those are the fundamentals of risk management. In a time when everything is crazy, when it's a polycrisis environment, those are the things you're going to have to do; otherwise, it will get too crazy to look at all the big stuff. [51:34] Hilary agrees. Focus on localized impacts, whether it's the impact of the supply chain disruption on your business, or a storm, or inflation, and also, work on your skill set, learning to have a critical eye when it comes to how and if you're using AI, and what it's being used for. [52:00] Hilary says there's a 56% wage premium for workers with AI skills, according to PWC. A lot of self-improvement and educational things are critical to doing your job well now, but they also set you up to be more prepared career-wise. [52:16] Hillary touches on thinking about what some of these impacts do to your workforce. AI is a tremendously stressful and confusing one for your workforce, so redirecting some money into training programs is a great option. You'll have a better workforce, and they'll feel better. [52:41] Studies show that the more training you offer, the less resistance you get when it comes to tool integration, and the better outcomes. [52:51] When it comes to storm season, you're dealing with a standing inflation, but so are your workers. If they can't afford plywood to board up their houses, that's also a problem. If they are displaced, you have a displaced workforce, and that means business interruption. [53:07] What can you do to assist? Is that ordering things in bulk, so you have some purchasing power to help them obtain supplies? Is that providing emergency kits so they are prepared at home, and you have a more prepared workforce that comes back to work sooner? [53:28] Think small when the big stuff is a little too big. [53:41] Morgan says, the other side of the coin is to avoid getting distracted by headlines that maybe don't have as much relevance. Educate yourself to know what technology works for you. If you just take things on faith, that may not be fit for purpose for you. [54:14] Hilary says a wait-and-see approach with a lot of emerging technology is proven to be the best course of action, and Hilary recommends it. Focus on augmenting employees, not replacing them. [54:36] According to Gartner, 50% of AI layoffs are going to be reversed by 2027. A lot of people who acted fast and cut people because they overestimated the impact of AI are going to be hiring those people back, and probably for more money, not to mention retraining costs. [55:02] Some people are calling it a layoff boomerang. It's coming back. Those who were not overly hasty are the ones who will fare better in the long run. That's an important lesson to keep in mind when it comes to making some of these decisions, going forward. [55:28] Morgan says, nobody would have said we're going to have a war that's going to dominate all the headlines. Hilary says, if you told me there was going to be a war, Iran wouldn't have been my first guess. [55:42] Morgan says, We're starting storm season. We're anticipating it being a mellow storm season. It doesn't mean it will be. It's the nature of the game that there are a lot of unanticipated things. [55:57] Hilary says a dry hurricane season comes with increased dryness, which means increased wildfire risk. It's always something. It's either flooding or it's burning. Which you prefer is largely subjective. [56:24] Morgan says it's one of those years where it's tough to predict anything, because every day it's something new, which is what keeps risk management interesting. Hilary agrees. Morgan says he's still interested. [56:49] Justin says, It's been great to have you rejoin us. It's always fun! These are some of my favorite episodes to produce. Everyone, go to RMMagazine.com. RIMS members get access to the "turn the page" edition, but anyone can view a lot of the articles online. [57:11] The Awards issue is also at RMMagazine.com and RIMS.org/Awards. There's a listing of the folks who won, as well as links to the issue itself, where you can read more about those individuals. Learn editorial guidelines for contributing articles at RMMagazine.com/Contribute. [57:39] Hilary says There are also our Topics pages, if you want any subject-specific coverage. It's a great way to navigate within the website. Natural disaster things don't vary that wildly, year to year, when it comes to preparation best practices. [57:58] In submitting article pitches, keep in mind that Hilary will ask, "So what?" If you're submitting something, ask yourself that. So what? Why should somebody care to read this? [58:29] Justin says, Look at her Hurricane Outlook, and the Red Teaming article for good examples of what we're looking for. The Hurricane Outlook is far more in-depth than what we're expecting from the typical outside contributor, but it should give you a good starting point. [58:46] I'd like to congratulate you on another wonderful quarterly edition of RIMS Risk Management Magazine. I look forward to seeing you at upcoming RIMS events, and thank you so much for joining us. [59:00] Special thanks again to Morgan O'Rourke and Hilary Tuttle for joining us here on RIMScast again. The Q2 Edition of RIMS Risk Management Magazine is now available on RMMagazine.com. [59:12] If you want to contribute, check out RMMagazine.com/Contribute for the editorial guidelines. You can reach out to Morgan O'Rourke and Hilary Tuttle. And our Editor, Jennifer Post there, as well. [59:23] We're certainly going to have them back for our Year in Review episode of RIMScast, but if and when major news happens, or I run out of guests, they just may come back and rejoin us here on RIMScast. [59:36] Plug Time! You can sponsor a RIMScast episode for this, our weekly show, or a dedicated episode. Links to sponsored episodes are in the show notes. [1:00:04] RIMScast has a global audience of risk and insurance professionals, legal professionals, students, business leaders, C-Suite executives, and more. Let's collaborate and help you reach them! Contact pd@rims.org for more information. [1:00:22] Become a RIMS member and get access to the tools, thought leadership, and network you need to succeed. Visit RIMS.org/membership or email membershipdept@RIMS.org for more information. [1:00:40] Risk Knowledge is the RIMS searchable content library that provides relevant information for today's risk professionals. Materials include RIMS executive reports, survey findings, contributed articles, industry research, benchmarking data, and more. [1:00:56] For the best reporting on the profession of risk management, read Risk Management Magazine at RMMagazine.com. It is written and published by the best minds in risk management. [1:01:10] Justin Smulison is the Business Content Manager at RIMS. Please remember to subscribe to RIMScast on your favorite podcasting app. You can email us at Content@RIMS.org. [1:01:22] Practice good risk management, stay safe, and thank you again for your continued support! Links: RIMS Risk Management Magazine | Contribute | Q2 2026 Issue Now Available RIMScast on YouTube! RIMS-CRO Certificate Program in Advanced Enterprise Risk Management | July – Sept. 2026 Cohort | Led by James Lam | Register Now! 2026 Florida RIMS Educational Conference | July 28‒Aug. 1 | Register Now RIMS Texas Regional Conference 2026 | Aug. 10‒12 in San Antonio | Register Now! Spencer Educational Foundation's 2026 Funding Their Future Gala | Sept. 17, 2026 ChicagoLand Risk Forum | Sept. 24, 2026 RIMS Western Regional Conference — Oct. 4‒7, 2026 | Seattle, WA | Register Today and Submit an Educational Session! RIMS Canada Conference — Oct. 18‒21, 2026 | Quebec City | www.rimscanadaconference.ca | Advance Registration Open | Sponsorship Opportunities Available RIMS ERM Conference 2026 | November 19‒20 in Columbus, Ohio | Registration Opens in July! | www.rims.org/ERM2026 Spencer Educational Foundation — Scholarships and Grants | Open Calls and Timelines. RIMS Now RIMS-Certified Risk Management Professional (RIMS-CRMP) | Insights Video Series Featuring Joe Milan! RIMS, the Foundation for Risk Management The Strategic and Enterprise Risk Center RIMS Diversity Equity Inclusion Council RIMS-CRMP Stories RIMScast Canada — Episodes Now Live RISK PAC | RIMS Advocacy Upcoming RIMS-CRMP Prep Virtual Workshops: RIMS-CRMP Exam Prep with PARIMA July 21‒22, 2026 Full RIMS-CRMP Prep Course Schedule See the full calendar of RIMS Virtual Workshops Upcoming RIMS Webinars: RIMS.org/Webinars "Too Hot To Ignore: Heat-Related Injuries and Workers' Compensation" | July 16 | Presented by Zurich RIMS Student Series: "Classroom to Career Part 1" | Sept 1 RIMS Student Series: "Classroom to Career Part 2" | Sept 9 Related RIMScast Episodes: "Emerging Risks and AMRAE's RMIS Panorama 2026 with François Beaume" "Strategy and Change with Ward Ching and Aaron Olson" "RIMS Risk Manager of the Year Jeff Bray" "Board Reporting and ERM in 2026 with Trisha Sqrow and Suzanne Christensen" "Risk Outlook '26 with Morgan O'Rourke and Hilary Tuttle" (Jan 2026) Sponsored RIMScast Episodes: "48 Hours From a Storm: What to Do Before A Hurricane Strikes" | Sponsored by Global Risk Consultants, a TÜV SÜD Company (New!) "AI-Scale, Risk Ready: Engineering Controls for the New Data Center Boom" | Sponsored by Global Risk Consultants, a TÜV SÜD Company "Facing Into Risk: Navigating the New Risk Landscape" (New!) | Sponsored by AXA XL "Secondary Perils, Major Risks: The New Face of Weather-Related Challenges" | Sponsored by AXA XL "The ART of Risk: Rethinking Risk Through Insight, Design, and Innovation" | Sponsored by Alliant "Mastering ERM: Leveraging Internal and External Risk Factors" | Sponsored by Diligent "Cyberrisk: Preparing Beyond 2025" | Sponsored by Alliant "The New Reality of Risk Engineering: From Code Compliance to Resilience" | Sponsored by AXA XL "Change Management: AI's Role in Loss Control and Property Insurance" | Sponsored by Global Risk Consultants, a TÜV SÜD Company "Demystifying Multinational Fronting Insurance Programs" | Sponsored by Zurich "Understanding Third-Party Litigation Funding" | Sponsored by Zurich "What Risk Managers Can Learn From School Shootings" | Sponsored by Merrill Herzog "Simplifying the Challenges of OSHA Recordkeeping" | Sponsored by Medcor "How Insurance Builds Resilience Against An Active Assailant Attack" | Sponsored by Merrill Herzog "Third-Party and Cyber Risk Management Tips" | Sponsored by Alliant RIMS Publications, Content, and Links: RIMS Membership — Whether you are a new member or need to transition, be a part of the global risk management community! RIMS Virtual Workshops On-Demand Webinars RIMS-Certified Risk Management Professional (RIMS-CRMP) RISK PAC | RIMS Advocacy RIMS Strategic & Enterprise Risk Center RIMS-CRMP Stories — Featuring RIMS President Manny Padilla! RIMS Events, Education, and Services: RIMS Risk Maturity Model® Sponsor RIMScast: Contact sales@rims.org or pd@rims.org for more information. Want to Learn More? Keep up with the podcast on RIMS.org, and listen on Spotify and Apple Podcasts. Have a question or suggestion? Email: Content@rims.org. Join the Conversation! Follow @RIMSorg on Facebook, Twitter, and LinkedIn. About our guest: Morgan O'Rourke | Vice President, RIMS Content & Publications Hilary Tuttle | Managing Editor, Risk Management Magazine Production and engineering provided by Podfly.
The future of cybersecurity, risk, audit, and governance is rapidly evolving - and AI Governance is emerging as one of the most in-demand disciplines for professionals looking to stay ahead. In this elite episode of InfosecTrain TechTalks: Real World Decoded, host Krish sits down with Chris DeMale, Vice President at ISACA, to explore how artificial intelligence is rewriting the professional landscape and opening massive new avenues for risk, privacy, and compliance experts.The "course titled" AI Governance and Risk Management Training acts as the perfect structural transition for veterans aiming to upscale their credentials. As enterprises accelerate their deployment of machine learning systems, the demand for trusted advisors who can independently audit and secure these models has skyrocketed. We dive deep into the widening AI skills gap, look at the emergence of specialized ISACA AI credentials, and map out the exact career roadmap needed to remain indispensable in an automated world.
The CISM exam doesn't test what you know - it tests how you think as a security leader. For cybersecurity professionals moving up the corporate ladder, earning ISACA's Certified Information Security Manager (CISM) designation is the ultimate validation of your strategic authority. In this definitive preparation masterclass, InfosecTrain maps out the exact blueprint, chronological study timeline, and mental frameworks required to conquer the exam on your very first try.The "course titled" CISM Certification Training is built specifically to transition your brain from tactical troubleshooting to high-level enterprise risk governance. We break down how to stop answering questions like a technical engineer and start evaluating multi-domain corporate dilemmas from a business-first perspective. Learn how to accurately prioritize resources, interpret complex situational prompts, and decode ISACA's specific exam architecture under real test conditions.
¿En qué momento quedó definitivamente regulada la cadena de bloques (Blockchain) como un nuevo servicio de confianza apoyado en criptografía? ¿Podemos disociar atestaciones de atributos del concepto de identidad digital? ¿Dónde está el sano equilibrio entre el rol del Estado y una completa soberanía individual apoyada en la descentralización?Ignacio Alamillo Domingo es Doctor en Derecho por la Universidad de Murcia, Licenciado en Derecho por la UNED, auditor de Sistemas de Información certificado, Director de Seguridad de la Información certificado e Ingeniero Certificado en Soluciones de Protección de Datos, por ISACA, así como SMP Master por SMI.En la actualidad es Abogado del Ilustre Colegio de Reus, Asesor de Logalty y Director General de Astrea La Infopista Jurídica SL. Asimismo, colabora con el Grupo de Investigación iDerTec de la Universidad de Murcia. También es miembro del ETSI TC ESI, que normaliza los servicios de confianza, miembro de UNE CTN71/SC307, de CEN-CLC/JTC 19 y de ISO TC 307, relativos a Blockchain. Dispone de más de 100 publicaciones y ha impartido más de 400 ponencias en identidad digital, servicios de confianza y materias relacionadas.Referencias:* Nacho Alamillo Domingo en LinkedIn* Astrea* Adrian Doerk: digital identity, digital wallets and data protection (Masters of Privacy, junio de 2024)* Jamie Smith: AI Agents, digital identity, wallets and personal data (Masters of Privacy, diciembre de 2024)* Iain Henderson: MyTerms as the missing universal opt-in signal (After The Magic repost)* Reglamento eIDAS 2.0* Identidad Digital Europea* European Decentralisation Institute* Identity Commons and Internet Identity Workshop (IIW)* Fundación OpenID* Internet, claves legales para la empresa (Civitas-Aranzadi, 2002) - Ignacio Alamillo, Sergio Maldonado, Fernando Ramos, otros This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.mastersofprivacy.com/subscribe
CISM is not about technical perfection - it's about making the right management decision. For security professionals transitioning into leadership, ISACA's Certified Information Security Manager (CISM) credential remains the benchmark for enterprise governance. In this study session, InfosecTrain walks you through 10 high-impact practice questions designed to reframe your perspective from a hands-on engineer to a strategic business leader.The "course titled" CISM Certification Training demands that candidates balance security protocols with organizational objectives. We break down the core architecture of tricky, scenario-based exam prompts across vital domains like Information Security Governance and Information Risk Management. Learn how to look past the most "technically secure" option to consistently identify the answer that delivers the highest business value.
Most candidates fail these questions not because they're hard, but because they think like technicians instead of auditors. In the 2026 enterprise landscape, passing the Certified Information Systems Auditor (CISA) exam requires an immediate shift away from tactical, day-to-day engineering fixes toward corporate governance and independent assurance. In this high-level study session, InfosecTrain deconstructs 10 highly complex, scenario-based practice questions that frequently trip up candidates.The "course titled" CISA Certification Training focuses heavily on testing your evaluation skills across ISACA's core framework. We pull back the curtain on the actual logic used to craft these multiple-choice items, showing you how to balance technical controls against business risks. Learn how to systematically eliminate distractors, read between the lines of tricky compliance prompts, and consistently identify the absolute best administrative answer on your first attempt.
At the 2026 Middle Tennessee ISACA conference I had the chance to sit down for short chats with a few information security pros: India James, whospoke on the importance of security and digital trust at the conference; Ken Smith, Director of Sales Engineering Enterprise for the Great Lakes at Arctic Wolf; and Jonathan Weaver, Partner at ProNsight's Risk and Compliance Consulting Practice.
Ransomware has evolved from basic digital extortion into a sophisticated, AI-powered threat that's faster,smarter, and more devastating than ever before. In this session, we'll explore how threat actors are weaponizing artificial intelligence to supercharge their operations—from automated reconnaissance and hyper-realistic phishing to malware that adapts in real-time to evade detection. We'll also examine how AI-driven ransomware exploits supply chain vulnerabilities to create cascading disruptions across entire industries.More importantly, we'll discuss practical strategies for fighting back: leveraging AI-powered behavior alanalytics and autonomous response tools, implementing zero-trust architecture,and building true organizational resilience through tested backup and recovery procedures. Whether you're in security operations, incident response, or infrastructure protection, this session will equip you with actionable insights to shift from a prevention-only mindset to one focused on preparedness and rapid recovery in today's evolving threat landscape. About the speaker: Gary Hayslip is an experienced Global Security Executive with a proven track record of delivering innovative security programs that protect billion-dollar enterprises at every touchpoint. He is intensely focused on driving continuous improvement to maximize the efficiency of security programs while minimizing costs. As an insightful thought leader, he possesses strong business acumen and a commitment to organizational mission, values, and goals. He has demonstrated the ability to collaborate with all levels of an organization to champion new ideas, gain buy-in, and build consensus. Hayslip brings extensive experience in information technology, security leadership, physical security, and risk management to his role as the Senior Security Advisor | CISO in Residence for Halcyon.ai. His previous executive positions include multiple roles as Chief Information Security Officer, Chief Information Officer, Deputy Director of IT, and Chief Privacy Officer for the U.S. Navy (Active Duty), the U.S. Navy (Federal Government employee), the City of San Diego, California, Webroot Software, and SoftBank Investments (Vision Fund & Vision Fund II).Hayslip is a proven cybersecurity expert with excellent communication and public speaking skills. He is skilled at explaining complex security and risk concepts to audiences with different levels of knowledge. Hayslip has earned a reputation as a highly effective communicator, author, and keynote speaker. He co-authored the "CISO Desk Reference Guide: A Practical Guide for CISOs – Volumes 1 & 2," "The Executive Primer: An Executive's Guide to Security Programs," "Developing Your Cybersecurity Career Path," and the "The Essential Guide to Cybersecurity for SMBs." He recently coauthored andpublished "Mastering Third Party Risk," a guide aimed specifically for security practitioners to help them manage the risk exposure to organizations from vendors and supply chains. These books are among the top resources for helping CISOs improve their leadership and business skills. Hayslip currently serves as an independent director on several boards and advises various other security and technology firms. He is an active member of the cybersecurity community and belongs to professional organizations such asISC2, NACD, ISACA, and Infragard. Hayslip holds several professional certifications, including CISSP, CISA, and CRISC, and has earned a BS in Information Systems Management from the University of Maryland,University College, and an MBA from San Diego State University.
CISM isn't just a certification it's a leadership upgrade. While many certifications focus on the "how" of security, the Certified Information Security Manager (CISM) focuses on the "why" from a business perspective. In this episode of InfosecTrain Tech Talks, we map out the complete journey to becoming a management-level security professional in 2026.The "course titled" CISM Certification Training continues to be one of the most valuable credentials for those aiming for the CISO track, focusing heavily on governance, risk, and program development rather than just technical execution. We break down the four essential domains and provide a realistic time commitment and study strategy to help you pass on your first attempt.
ISACA has stepped into a defining role in the CMMC ecosystem, taking over as the CMMC Assessor and Instructor Certification Organization -- the CAICO -- for the U.S. Department of War's Cybersecurity Maturity Model Certification program. Recorded live at RSAC Conference 2026, this conversation with Todd Gagnon, the Director of the CAICO at ISACA, gets right to the heart of what that means for cybersecurity professionals, defense contractors, and anyone thinking about where their career intersects with the defense industrial base. The CMMC program exists to solve a persistent problem: too many companies doing business with the federal government had failed to properly implement required cybersecurity controls. Built around NIST 800-171's 110 security requirements, CMMC demands third-party, independent verification -- and that means a large, trained, credentialed assessor workforce. ISACA's role is to build and certify exactly that. Todd Gagnon walks through the two foundational credentials at the center of this effort: the CMMC Certified Professional (CCP) as the entry point, and the CMMC Certified Assessor (CCA) as the operational core. With roughly 800 credentialed professionals in the current ecosystem against a need measured in thousands, the stakes and the urgency are clear. What makes this conversation practically useful is the range of people it speaks to. Gagnon lays out who should be thinking about a CCP -- including professionals early in their careers and organizations that want internal staff who truly understand the CMMC framework, not just outside consultants. He explains the C3PAO model, how subcontractor compliance flows through the ecosystem, and why NIST 800-171 is a strong cybersecurity foundation regardless of whether an organization ever touches a government contract. The certification pathway is open to non-ISACA members, the CCP is designed to be accessible, and the knowledge transfers well beyond the federal contracting context. ISACA is also moving ahead of the curve: with NIST having released Revision 3 of 800-171, ISACA is already developing training content for the transition -- targeting late 2025 delivery so that a wave of Revision 3-ready professionals will be in place when the Department of War makes the regulatory shift. Todd Gagnon closes with a candid ask for patience as the April 1st transition from Cyber AB to ISACA takes effect, along with a clear statement of intent: the credentials issued under ISACA's watch should stand for something. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUEST Todd Gagnon, Director, CMMC Assessor & Instructor Certification Organization (CAICO) at ISACA LinkedIn: https://www.linkedin.com/in/todd-gagnon-90b8a6264/ RESOURCES ISACA CMMC Certification Hub: https://www.isaca.org/cmmc ISACA Official Website: https://www.isaca.org KEYWORDS Todd Gagnon, ISACA, Sean Martin, Marco Ciappelli, CMMC, Cybersecurity Maturity Model Certification, CAICO, CCP, CCA, NIST 800-171, Defense Industrial Base, cybersecurity certification, DoD compliance, government contractors, brand spotlight, brand story, brand marketing, marketing podcast, RSAC Conference 2026 Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
This episode features Krista Arndt, Associate CISO at St. Luke's University Health Network.With a career spanning healthcare, finance, crypto, and the Department of Defense, Krista brings a uniquely nontraditional path into cybersecurity, one shaped by mission-driven leadership, authenticity, and a commitment to mentorship.In this episode, Krista explains why identity sits at the center of nearly every major cyber incident and shares lessons from real-world response work. She also draws a striking parallel between incident response and her life as a national drag racing competitor, where staying calm under pressure and building in fail-safes can mean the difference between disaster and resilience.This episode is a powerful look at what it means to lead in cybersecurity.Guest Bio Krista Arndt is the Associate CISO SLUHN. As the Associate CISO, Krista is responsible for managing the security program's day-to-day operational effectiveness. In her previous roles, Krista assisted with developing and leading security programs in crypto, finance, and the Department of Defense. Krista earned her Bachelor's Degree in Biology from Felician College in NJ where she was a scholarship athlete, serving as the women's basketball team captain. She also holds her CISM and CRISC certifications and NHRA competition driver's license.Krista is an active member of ISACA, serves as InfraGard Philadelphia Chapter's Healthcare Sector Chief, serves on Neumann University's Business Advisory Council and is Marketing Committee chair for Women in Cybersecurity-Delaware Valley Affiliate. Krista is also a published author, detailing her journey to embracing her unique authenticity in her book, “Permission to be Real; How to Lead, Influence, and Thrive Without Fitting the Mold". Through this service and her writing, Krista's mission is to give back to her community by providing mentorship and support for aspiring cybersecurity professionals, especially for women who wish to enter the field. When off the clock, Krista takes her affinity for overcoming challenges to the garage and the race track, where she enjoys building and improving her own race car, competing as a driver in national drag racing events with her family, and using her racing as a forum to advocate for neurodiversity awareness and inclusion.Guest Quote “In the incidents that I've been involved in, major or not, I'll tell you—identity is at the crux of that... They're trying to get unfettered access… How do they get unfettered access? Through an identity that isn't secured correctly.”Time stamps 00:45 Meet Krista Arndt: Veteran CSO 06:17 Writing Permission to Be Real 10:43 Speaking the Business Language: Why Security Translation Matters 12:49 Lessons from Real-World Incidents 15:43 AI Agents and the Next Wave of Identity Risk 16:55 What Drag Racing Teaches About Incident Response 23:28 Surviving the CISO Seat 26:44 Conclusion and Final ThoughtsSponsor The HIP Podcast is brought to you by Semperis, the leader in identity-driven cyber resilience for the hybrid enterprise. Trusted by the world's leading businesses, Semperis protects critical Active Directory and Entra ID environments from cyberattacks, ensuring rapid recovery and business continuity when every second counts. Visit semperis.com to learn more.LinksConnect with Krista on LinkedInCheck out Krista's book: Permission to be RealLearn more about St. Luke's University Health NetworkConnect with Sean on LinkedInDon't miss future episodesLearn more about Semperis
Please enjoy this encore of Word Notes. An IT governance framework developed by ISACA. CyberWire Glossary link: https://thecyberwire.com/glossary/cobit Audio reference link: isacappc. “How Do You Explain Cobit to Your Dad – or Your CEO?” YouTube, YouTube, 24 Aug. 2016, https://www.youtube.com/watch?v=EYATVkddIyw.
Please enjoy this encore of Word Notes. An IT governance framework developed by ISACA. CyberWire Glossary link: https://thecyberwire.com/glossary/cobit Audio reference link: isacappc. “How Do You Explain Cobit to Your Dad – or Your CEO?” YouTube, YouTube, 24 Aug. 2016, https://www.youtube.com/watch?v=EYATVkddIyw. Learn more about your ad choices. Visit megaphone.fm/adchoices
In this ISACA Podcast episode, host Safia Kazi, Principal Research Analyst – Privacy, is joined by Dirk Schrader, VP of Security Research at Netwrix, to discuss how generative AI is revealing long-standing gaps in enterprise data security and governance. This episode builds on insights from a recent ISACA webinar that explored how generative AI is exposing weaknesses in enterprise data security and governance. The discussion examines why many organizations lack visibility into where sensitive data resides and who can access it, particularly across hybrid and cloud environments. The conversation also addresses emerging risks introduced by AI tools, including non-human access and overexposed data. Listeners will gain practical, governance-focused guidance on how DSPM helps organizations assess risk, support compliance, and prepare data responsibly for AI initiatives. Related Resources: Watch the ISACA Webinar from the ISACA Virtual Summit 2025: “Securing Data in the Age of AI with DSPM” https://www.isaca.org/training-and-events/online-training/virtual-summits/ai-governance-strategies Learn more from Netwrix: https://netwrix.com/en/resources/ Explore more ISACA Podcasts: https://www.isaca.org/resources/news-and-trends/isaca-podcast-library ISACA on YouTube: https://www.youtube.com/@IsacaHq
Traditional IT security is predictable, but AI is not. In an era where AI learns, evolves, and operates on data-centric logic, the standard playbooks for network and infrastructure security are no longer enough. Enter ISACA's Advanced in Artificial Intelligence Security Management (AISM), a framework designed to bridge the gap between traditional security and the unique risks of the AI era.In this episode, we explore the shift from application logic to data-centric AI security. We dive into the complexities of "Poisoning" attacks, prompt injections, and the critical importance of human-in-the-loop governance. Whether you're a CISSP, CISM, or an aspiring AI security leader, this is your guide to mastering the integration of AI into your enterprise strategy.
In today's episode, host Jim Love discusses the discovery of the 'Glass Worm,' a self-spreading malware hidden in Visual Studio Code extensions downloaded over 35,000 times. The worm, hiding its malicious JavaScript in invisible unicode characters, steals developer credentials and drains crypto wallets. He also covers the security flaws in AI-powered IDEs like Cursor and Windsurf, leaving 1.8 million developers vulnerable. Lastly, a new survey from ISACA reveals that AI-driven attacks are now the top cybersecurity concern for 2026, overtaking ransomware and insider threats. Love advises how developers and security teams can mitigate these threats. 00:00 Introduction and Shoutout 01:10 Cybersecurity Headlines 01:46 Glass Worm Malware in Visual Studio Code 04:06 AI-Powered IDEs with Security Flaws 06:00 AI-Driven Cybersecurity Threats 07:50 Conclusion and Contact Information
Artificial intelligence is the topic the entire accounting industry can't get enough of, with it likely to impact every aspect of the profession. On this insightful episode of the Accountants Daily Insider, ISACA director of event content development, Paul Phillips, joins all the way from the US to share professional expertise and advice about how ISACA is revolutionising the audit profession alongside AI. More Australian auditors can now pursue the world's first and only audit-specific artificial intelligence certification, with ISACA expanding eligibility for its ISACA Advanced in AI Audit (AAIA) certification to include CPAs and FCPAs from CPA Australia. Built on ISACA's trusted expertise in IT audit and the rigorous standards behind these renowned credentials, AAIA validates expertise in conducting AI-focused audits, addressing AI integration challenges and enhancing audit processes through AI-driven insights. The credential covers the key domains of AI governance and risk, AI operations, and AI auditing tools and techniques. Phillips shares this and more in the latest episode of The Accountants Daily Insider. Tune in!
#SecurityConfidential #DarkRhiinoSecurityMaman Ibrahim is a cybersecurity and digital risk leader with over 20 years of experience helping organizations transform cybersecurity from a compliance task into a strategic advantage. As Principal Partner at EugeneZonda and Founder of Ginkgo Resilience, he has led secure digital transformations across industries like pharma, manufacturing, and business services, saving companies over £150 million through risk management and third-party oversight. A contributor to initiatives like the OWASP Top 10 Agentic AI Risks and the World Economic Forum's Cyber Resilience Compass, Maman is deeply involved in global cybersecurity organizations, including ISACA, CIISec, and the UK Cyber Security Council. Known for his facilitation-first approach, he helps executives align leadership and strategy to build cultures of cyber resilience. 00:00 Introduction to Cybersecurity and Mamon Ibrahim02:38 Maman's Journey11:29 Transforming Cybersecurity: Compliance to Strategic Advantage16:12 Understanding Risks in Cybersecurity18:46 Making Cybersecurity a Competitive Advantage22:07 The Role of the CISO in Modern Organizations27:12 The Importance of Asset Protection in Organizations29:10 Navigating Third-Party Risks in Cybersecurity32:48 The Role of Procurement in Cyber Resilience38:41 Understanding Agentic AI Risks47:48 Knowledge Sharing and Mentorship in Cybersecurity-----------------------------------------------------------------To learn more about Maman visit https://www.linkedin.com/in/mamane/To learn more about Dark Rhiino Security visit https://www.darkrhiinosecurity.com-----------------------------------------------------------------
#SecurityConfidential #DarkRhiinoSecurityMaman Ibrahim is a cybersecurity and digital risk leader with over 20 years of experience helping organizations transform cybersecurity from a compliance task into a strategic advantage. As Principal Partner at EugeneZonda and Founder of Ginkgo Resilience, he has led secure digital transformations across industries like pharma, manufacturing, and business services, saving companies over £150 million through risk management and third-party oversight. A contributor to initiatives like the OWASP Top 10 Agentic AI Risks and the World Economic Forum's Cyber Resilience Compass, Maman is deeply involved in global cybersecurity organizations, including ISACA, CIISec, and the UK Cyber Security Council. Known for his facilitation-first approach, he helps executives align leadership and strategy to build cultures of cyber resilience. 00:00 Introduction to Cybersecurity and Mamon Ibrahim02:38 Maman's Journey11:29 Transforming Cybersecurity: Compliance to Strategic Advantage16:12 Understanding Risks in Cybersecurity18:46 Making Cybersecurity a Competitive Advantage22:07 The Role of the CISO in Modern Organizations27:12 The Importance of Asset Protection in Organizations29:10 Navigating Third-Party Risks in Cybersecurity32:48 The Role of Procurement in Cyber Resilience38:41 Understanding Agentic AI Risks47:48 Knowledge Sharing and Mentorship in Cybersecurity----------------------------------------------------------------To learn more about Maman visit https://www.linkedin.com/in/mamane/To learn more about Dark Rhiino Security visit https://www.darkrhiinosecurity.com
Special Virtual Episodes with ISACA Leaders: State of Cyber (Part 1) - Maintaining readiness in a complex threat environmentSpeakers:Jamie Norton - ISACA Board Member Chirag Joshi - Sydney Chapter Board Member Abby Zhang - Auckland Chapter Board Member Jason Wood - Auckland Chapter former PresidentBharat Bajaj - ISACA Melbourne Board DirectorFor the full series visit: https://mysecuritymarketplace.com/security-amp-risk-professional-insight-series-2025/#mysecuritytv #isaca #cybersecurity OVERVIEWAccording to ISACA research, almost half of companies exclude cybersecurity teams when developing, onboarding, and implementing AI solutions.Only around a quarter (26%) of cybersecurity professionals or teams in Oceania are involved in developing policy governing the use of AI technology in their enterprise, and nearly half (45%) report no involvement in the development, onboarding, or implementation of AI solutions, according to the recently released 2024 State of Cybersecurity survey report from global IT professional association ISACA.Key Report Findings Security teams in Oceania noted they are primarily using AI for: Automating threat detection/response (36% vs 28% globally); Endpoint security (33% vs 27% globally); Automating routine security tasks (22% vs 24% globally); and Fraud detection (6% vs 13% globally).Additional AI resources to help cybersecurity and other digital trust professionalso EU AI Act white papero Examining Authentication in the Deepfake EraSYNOPSISISACA's 2024 State of Cybersecurity report reveals that stress levels are on the rise for cybersecurity professionals, largely due to an increasingly challenging threat landscape. The annual ISACA research also identifies key skills gaps in cybersecurity, how artificial intelligence is impacting the field, the role of risk assessments and cyber insurance in enterprises' security programs, and more.The demand for cybersecurity talent has been consistently high, yet efforts to increase supply are not reflected in the global ISACA IS/IT-community workforce. The current cybersecurity practitioners are aging, and the efforts to increase staffing with younger professionals are making little progress. Left unchecked, this situation will create business continuity issues in the future. Shrinking budgets and employee compensation carry the potential to adversely affect cybersecurity readiness much sooner than the aging workforce, when the Big Stay passes. Declines in vacant positions across all reporting categories may lead some enterprises to believe that the pendulum of power will swing back to employers, but the increasingly complex threat environment is greatly increasing stress in cybersecurity teams; therefore, the concern is not if, but when, employees will reach their tipping point to vacate current positions.
Welcome to the Indo-Pacific State of Cyber Series with ISACA and sponsored by Vanta. This session focuses on The State of Privacy - A Challenging Landscape: Lack of training or poor training tops reasons for privacy failuresSpeakersSafia Kazi - ISACA Global - Report Author Jo Stewart-Rattray - ISACA Oceania Ambassador Privacy professionals are under growing pressure as they face budget cuts, resource challenges and changes in regulations. According to ISACA's State of Privacy 2025 survey report, almost half (48 percent) expect a budget decrease in the next year and 73 percent indicate expert-level privacy professionals are the most difficult to hire, adding to the stress of keeping data safe and meeting compliance requirements. The new research from ISACA, the leading global professional association helping individuals advance their careers in digital trust fields, reflects insights from more than 1,600 privacy professionals worldwide.The study found that 63 percent of privacy professionals say their role is more stressful now than it was five years ago, with 34 percent indicating it is significantly more stressful. They cite the main causes of this stress as the rapid evolution of technology (63 percent), compliance challenges (61 percent) and resource shortages (59 percent). To find out more visit https://mysecuritymarketplace.com/security-amp-risk-professional-insight-series-2025/To find out more on Vanta visit https://mysecuritymarketplace.com/vanta#isaca #mysecuritytv #privacy
Welcome to the Indo-Pacific State of Cyber Series with ISACA and sponsored by Vanta. We present the third session with the State of Trust – Critical to the success of every businessSpeakersJamie Norton - ISACA Board Member Jason Wood - Auckland Chapter former President Reshma Devi - Melbourne Chapter Board Member Evan Rowse – Vanta A copy of the VANTA report is available here https://mysecuritymarketplace.com/vantaA copy of the ISACA report - State of Digital Trust 2024 is available here https://www.isaca.org/resources/reports/state-of-digital-trust-2024Trust is critical to the success of every business. But building, scaling and demonstrating trust is getting harder for Australian organisations. To meet customer expectations, security leaders and their teams must address complex threats, a growing compliance burden, and increasing risk from their third-party vendor footprint. The rapid adoption of AI technologies only adds to the challenge, requiring more oversight and governance.Vanta's second annual State of Trust Report uncovers key trends across these areas of security, compliance and the future of trust. Based on a survey of 2,500 IT and business leaders (with 500 of the respondents from Australia), our research found that more than half (58%) of Australian organisations say that security risks for their business have never been higher.More than 5,800 digital trust professionals shared their insights for ISACA's State of Digital Trust research and give their perspectives on:The top benefits of digital trustThe consequences of a lack of digital trustBiggest digital trust obstaclesAccountability for digital trustBudgetsMeasurementSPONSOR: Vanta's trust management platform takes the manual work out of your security and compliance process and replaces it with continuous automation—whether you're pursuing your first framework or managing a complex program.For more on the Security & Risk Professional Insight Series visit https://mysecuritymarketplace.com/security-amp-risk-professional-insight-series-2025/For more on IPRAAC – visit Indo-Pacific Robotics, Autonomy, AI and Cyber Conference 7-9 October 2025 – Perth, Western Australia - https://indopacificroboticsconference...For more information on our sponsor – VANTA – visit https://mysecuritymarketplace.com/vanta#vanta #isaca #digitaltrust #mysecuritytv
A recent poll by cybersecurity industry body ISACA found that 95% of organizations still lack a quantum computing roadmap, despite the technology's potential to break existing internet encryption. The poll, which surveyed over 2,600 professionals, revealed that 62 percent are worried about quantum computing breaking encryption, but only 5 percent consider it a high priority. You can listen to all of the Quantum Minute episodes at QuantumMinute.com. The Quantum Minute is brought to you by Applied Quantum, a leading consultancy and solutions provider specializing in quantum computing, quantum cryptography, quantum communication, and quantum AI. Learn more at https://AppliedQuantum.com.
The powerful and emerging world of quantum computing is on its way. Quantum computing is a technology that is set to redefine privacy, trust, and artificial intelligence. What does quantum computing really mean, how will it change the digital trust landscape, what will happen when organizations gain quantum capabilities, and how existing standards and laws can help us govern. Quantum computing is still in its early stages, but it promises to open new possibilities, bring new challenges, and create risks we need to understand today. To help us navigate this complex but exciting topic, host Punit Bhatia speaks with cybersecurity expert Ramsés Gallego about the exciting and challenging world of quantum computing. With over 25 years of experience in cybersecurity and technology governance, Ramsés brings not just knowledge, but incredible energy to the discussion — "quantum energy," as we like to say. Will it change the way we define and manage digital trust? KEY CONVERSION POINT 00:02:20 How would you define digital trust 00:05:03 Demystify what is Quantum 00:10:52 How Quantum change the AI game? 00:15:44 What will happen if you acquire Quantum Computing 00:19:17 How are we seeing digital trust dimension with Quantum Computing? 00:28:10 How would an organization or a corporate govern this? 00:33:20 Get in touch with Ramses ABOUT GUEST With an MBA and Law education, Ramsés Gallego is a +25 year security professional with deep expertise in the Risk Management and Governance areas. Ramsés is now Chief Technologist Cybersecurity with DXC, where he defines the vision and mission, purpose and promise of the division. He has recently been Strategist & Evangelist for the office of the CTO with Symantec and holds the following professional accreditations: CISM, CGEIT, CISSP, SCPM, CCSK, ITIL and COBIT Foundations. An internationally recognized public speaker, has visited +25 different countries in the past 12 months and has been awarded 'Best Speaker' in four continents. He is also a Six Sigma Black Belt professional and is proud of being Past International VP for ISACA's Board of Directors, actual President of the Barcelona Chapter, Ambassador of the association and honored to be inducted into the ISACA Hall of Fame. Ramsés is also Executive Vice President of the Quantum World Association and has had the US flag flown on his honor at The Capitol, in Washington DC, USA. With already 22 Marathons -and other crazy adventures- on his legs he lives in Barcelona, Spain, with his wonderful wife and his two loved kids. ABOUT HOST Punit Bhatia is one of the leading privacy experts who works independently and has worked with professionals in over 30 countries. Punit works with business and privacy leaders to create an organization culture with high privacy awareness and compliance as a business priority. Selectively, Punit is open to mentor and coach professionals. Punit is the author of books “Be Ready for GDPR'' which was rated as the best GDPR Book, “AI & Privacy – How to Find Balance”, “Intro To GDPR”, and “Be an Effective DPO”. Punit is a global speaker who has spoken at over 30 global events. Punit is the creator and host of the FIT4PRIVACY Podcast. This podcast has been featured amongst top GDPR and privacy podcasts. As a person, Punit is an avid thinker and believes in thinking, believing, and acting in line with one's value to have joy in life. He has developed the philosophy named ‘ABC for joy of life' which passionately shares. Punit is based out of Belgium, the heart of Europe. RESOURCES Websites www.fit4privacy.com, www.punitbhatia.com, https://www.linkedin.com/in/ramsesgallego/ Podcast https://www.fit4privacy.com/podcast Blog https://www.fit4privacy.com/blog YouTube http://youtube.com/fit4privacy
In this episode, ISACA's Lisa Cook engages with Yakir Golan, Executive Officer (CEO) and Co-Founder of Kovrr, to explore the critical role of Cyberrisk Quantification (CRQ) in enhancing organizational financial resilience. They discuss how CRQ solutions provide objective assessments of an organization's cybersecurity posture, enabling leaders to make informed decisions that align risk mitigation strategies with business objectives. The conversation also highlights the importance of translating cyberrisk exposure into monetary terms to facilitate high-level discussions and protect shareholder confidence. Listen & Subscribe Catch this episode—and more—on the ISACA Podcast Library: https://www.isaca.org/resources/news-and-trends/isaca-podcast-library or on your favorite podcast platform.
An expert from ISACA shares her insights into medtech's Voluntary Improvement Program (VIP), a collaboration among participants, ISACA, MDIC, and US FDA formed to enhance patient safety and product quality in medical device manufacturing. Listen to learn more about attaining measurable improvements with the VIP.
In this unfiltered episode of Unspoken Security, host A. J. Nash explores the looming threat quantum computing poses to our digital infrastructure with experts Robert Clyde, Managing Director of Clyde Consulting and Chair of crypto-security firm CryptoQuanti, and Jamie Norton, a Board Director at ISACA with extensive cybersecurity credentials. They cut through the technical jargon to explain how quantum computing fundamentally differs from classical computing and why its exponential processing power threatens to break current encryption standards."While current quantum computers operate at around 150 qubits, once they reach sufficient power, everything from banking transactions to secure communications could be compromised instantly," warns Robert during the discussion of "Q Day" — the moment when quantum computers become powerful enough to defeat public-key cryptography underpinning internet security.Despite the alarming scenario, the experts offer practical guidance on preparing for this threat. They outline how organizations should begin implementing post-quantum cryptography solutions developed by NIST, emphasizing that proactive preparation, not panic, is the critical response security professionals should adopt today. Listen to the full episode to understand the quantum threat and learn the concrete steps your organization should take now before Q Day arrives.Send us a textSupport the show
At RSAC 2025, the most urgent signals weren't necessarily the loudest. As ISACA board member and cybersecurity veteran Rob Clyde joins Sean Martin and Marco Ciappelli for a post-conference recap, it's clear that conversations about the future of the profession—and its people—mattered just as much as discussions on AI and cryptography.More Than a Job: Why Community MattersRob Clyde shares his long-standing involvement with ISACA and reflects on the powerful role that professional associations play in cybersecurity careers. It's not just about certifications—though Clyde notes that employers often value them more than degrees—it's also about community, mentorship, and mutual support. When asked how many people landed a job because of someone in their local ISACA chapter, half the room raised their hands. That kind of connection is difficult to overstate.Clyde urges cybersecurity professionals to look beyond their company roles and invest in something that gives back—whether through volunteering, speaking, or simply showing up. “It's your career,” he says. “Take back control.”Facing Burnout and Legal Risk Head-OnThe group also addresses a growing issue: burnout. ISACA's latest research shows 66% of cybersecurity professionals are feeling more burned out than last year. For CISOs in particular, that pressure is compounded by personal liability—as in the case of former SolarWinds CISO Tim Brown being sued by the SEC. Clyde warns that such actions have a chilling effect, discouraging internal risk discussions and openness.To counteract that, he emphasizes the need for continuous learning and peer support as a defense, not only against burnout, but also isolation and fear.The Silent Threat of QuantumWhile AI dominated RSAC's headlines, Clyde raises a quieter but equally pressing concern: quantum computing. ISACA chose to focus its latest poll on this topic, revealing a significant gap between awareness and action. Despite widespread recognition that a breakthrough could “break the internet,” only 5% of respondents are taking proactive steps. Clyde sees this as a wake-up call. “The algorithms exist. Q Day is coming. We just don't know when.”From mental health to quantum readiness, this conversation makes it clear: cybersecurity isn't just a technology issue—it's a people issue. Listen to the full episode to hear what else we're missing.Learn more about ISACA: https://itspm.ag/isaca-96808⸻Guest: Rob Clyde, Board Director, Chair, Past Chair of the Board Directors at ISACA | https://www.linkedin.com/in/robclyde/ResourcesLearn more and catch more stories from ISACA: https://www.itspmagazine.com/directory/isacaStay tuned for an upcoming ITSPmagazine Webinar with ISACA: https://www.itspmagazine.com/webinarsISACA Quantum Pulse Poll 2025 and related resources: https://www.isaca.org/quantum-pulse-pollISACA State of Cybersecurity 2024 survey report: https://www.isaca.org/resources/reports/state-of-cybersecurity-2024Learn more and catch more stories from RSA Conference 2025 coverage: https://www.itspmagazine.com/rsac25______________________Keywords:sean martin, marco ciappelli, rob clyde, rsac2025, burnout, quantum, cryptography, certification, isaca, cybersecurity, brand story, brand marketing, marketing podcast, brand story podcast______________________Catch all of our event coverage: https://www.itspmagazine.com/technology-and-cybersecurity-conference-coverageWant to tell your Brand Story Briefing as part of our event coverage? Learn More
The cybersecurity workforce shortage isn't a new problem—but according to Jamie Norton, Board Director at ISACA, it's one that's getting worse. In this on-location conversation during RSAC Conference 2025, Norton shares how ISACA is not only acknowledging this persistent gap but actively building pathways to close it, especially for early-career professionals.While many know ISACA for its certifications and events, Norton emphasizes that the organization's mission goes much deeper—supporting digital trust through education, community, and career development. One key area of focus: helping individuals navigate every phase of their professional journey, from new graduates to seasoned leaders. That includes new offerings like the Certified Cyber Operations Analyst (CCOA) credential, designed specifically to meet the growing demand for technical, hands-on skills in security operations roles.What's driving this shift? Norton points to employer demand for candidates who can walk into SOC and technical analyst roles with practical experience. The CCOA was created based on feedback from ISACA's 185,000+ global members and a wide network of hiring organizations, all highlighting the same pain point: early-stage roles are difficult to fill, not because people aren't interested, but because too many can't prove their skills in ways hiring managers understand.ISACA's response is both strategic and community-driven. Certification development is rooted in large-scale data analysis and enhanced by input from members around the world, ensuring each program reflects real-world needs. At the same time, ISACA recognizes that certifications alone don't create confidence. Community and mentorship matter—especially for those struggling with imposter syndrome or breaking into the field from non-traditional backgrounds.Looking ahead, ISACA is investing in career journey tools, AI-focused certifications, and guidance for post-quantum readiness—all while continuing to support members through local chapters and global programs.For those hiring, job-seeking, or guiding others into the field, this episode offers a grounded, forward-looking view into how one organization is equipping the cybersecurity workforce for the work that matters now—and what's coming next.Learn more about ISACA: https://itspm.ag/isaca-96808Note: This story contains promotional content. Learn more.Guest: Jamie Norton, Director Board of Directors, ISACA | https://www.linkedin.com/in/jamienorton/ResourcesLearn more and catch more stories from ISACA: https://www.itspmagazine.com/directory/isacaLearn more and catch more stories from RSA Conference 2025 coverage: https://www.itspmagazine.com/rsac25______________________Keywords:jamie norton, sean martin, marco ciappelli, cybersecurity, certifications, workforce, skills, governance, community, careers, brand story, brand marketing, marketing podcast, brand story podcast______________________Catch all of our event coverage: https://www.itspmagazine.com/technology-and-cybersecurity-conference-coverageWant to tell your Brand Story Briefing as part of our event coverage? Learn More
As anticipation builds for the RSAC Conference 2025, ISACA leaders Mary Carmichael and Dooshima Dabo'Adzuana join Sean Martin and Marco Ciappelli to preview what the global technology and cybersecurity association has in store for attendees this year. With a focus on expanding community, AI governance, and professional development, their conversation reveals how ISACA is showing up with both timely insights and tangible resources.Mary Carmichael, President of ISACA's Vancouver Chapter and a CPA focused on cybersecurity risk and governance, highlights the session she's co-presenting with Dooshima Dabo'Adzuana: Third-Party AI: What Are You Really Buying? Their talk will explore the increasing complexity of evaluating AI solutions procured from vendors—especially those embedding large language models. Topics include due diligence during procurement, monitoring post-deployment, and assessing whether vendor practices align with internal risk and privacy requirements.Dooshima Dabo'Adzuana, a researcher at Boise State University and leader from ISACA's Abuja Chapter, shares how ISACA members across regions are grappling with similar questions: What does AI mean for my organization? What risks do third-party integrations introduce? She emphasizes the importance of frameworks and educational tools—resources that ISACA is making readily available at their booth (South Expo #2268) and through new certification tracks in AI audit and security.Alongside the AI focus, visitors to the booth can explore results from ISACA's Quantum Pulse Poll and access guidance on encryption readiness for a post-quantum future. The booth will also feature a selfie station and serve as a meeting point for the diverse ISACA community, with members from over 220 chapters worldwide.The conversation rounds out with a critical discussion on cybersecurity career development. Both Mary and Dooshima share personal stories of transitioning into the field—Mary from accounting, Dooshima from insurance—and call for broader recognition of transferable skills. They point to global tools, such as career pathway frameworks supported by ISACA and the UK Cyber Security Council, as essential for addressing the persistent workforce gap.This episode offers a preview of how ISACA is connecting global conversations on AI, quantum, and professional development—making RSAC Conference 2025 not just a tech showcase, but a community gathering rooted in learning and action.Stop by booth 2268 in the South Expo to explore how ISACA are equipping professionals with practical tools for AI governance, quantum readiness, and cybersecurity career growth—and how your organization can benefit from a stronger, more connected community.Learn more about ISACA: https://itspm.ag/isaca-96808Guests:Mary Carmichael, President of ISACA's Vancouver Chapter | https://www.linkedin.com/in/carmichaelmary/Dooshima Dabo'Adzuana, a researcher at Boise State University and leader from ISACA's Abuja Chapter | https://www.linkedin.com/in/dooshima-dabo-adzuana/ResourcesMary and Dooshima's session at RSA Conference: https://path.rsaconference.com/flow/rsac/us25/FullAgenda/page/catalog/session/1737642290064001tqyqLearn more about ISACA's AI resources: https://www.isaca.org/resources/artificial-intelligenceLearn more about ISACA's credentials: https://www.isaca.org/credentialingLearn more and catch more stories from ISACA: https://www.itspmagazine.com/directory/isacaLearn more and catch more stories from RSA Conference 2025 coverage: https://www.itspmagazine.com/rsa-conference-usa-2025-rsac-san-francisco-usa-cybersecurity-event-infosec-conference-coverage______________________Keywords: ai, quantum, cybersecurity, risk, governance, audit, certification, encryption, rsa, rsac, third-party, compliance, career, skills, education, community, brand story, brand marketing, marketing podcast, brand story podcast______________________Catch all of our event coverage: https://www.itspmagazine.com/technology-and-cybersecurity-conference-coverageWant to tell your Brand Story Briefing as part of our event coverage? Learn More
Our feature guest this week is Nipun Mahajan, EVP at ISACA Denver. News from and a lot more! Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends. Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com This week's news: Join the Colorado = Security Slack channel Boulder, Colorado Named New Host of Sundance Film Festival Beginning in 2027 Popular grocery chain plans expansion into the Denver-metro area Denver sporting goods maker expands more than threefold Denver-based Angi Inc. completes spin-off, becomes independent Ball Corp. offloads product line to new joint venture Denver cryptocurrency company is being bought by a major industry player Five Critical Insights from the State of Trust Summit What does Google's $32B acquisition of cloud security startup Wiz mean for security operations? | Red Canary Upcoming Events: Check out the full calendar ISSA Denver - Insider Threats: A Hacker's Perspective - 4/9 CSA Colorado - Securing the Cloud - Attack Vectors - 4/15 Denver OWASP - The Attacker's Distributed Supercomputer: Your Browser - 4/16 ISACA Denver - Annual General Meeting - 4/17 Let's Talk Software Security - Can't We Just Automate Application Security? - 4/17 ISSA Pikes Peak - Chapter Meeting - 4/23 View our events page for a full list of upcoming events * Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here. * Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0
A critical vulnerability could let attackers hijack and potentially disable vulnerable servers. Europol warns of a “shadow alliance” between state-backed threat actors and cybercriminals. Sekoia examines ClearFake. A critical PHP vulnerability is under active exploitation. A sophisticated scareware phishing campaign has shifted its focus to macOS users. Phishing as a service attacks are on the rise. A new jailbreak technique bypasses security controls in popular LLMs. Microsoft has uncovered StilachiRAT. CISA confirms active exploitation of a critical Fortinet vulnerability. On our CertByte segment, Chris Hare is joined by Troy McMillan to break down a question targeting the ISACA® Certified Information Security Manager® (CISM®) exam. AI coding assistants get all judgy. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CertByte Segment Welcome to CertByte! On this bi-weekly segment hosted by Chris Hare, a content developer and project management specialist at N2K, we share practice questions from N2K's suite of industry-leading certification resources. This week, Chris is joined by Troy McMillan to break down a question targeting the ISACA® Certified Information Security Manager® (CISM®) exam. Today's question comes from N2K's ISACA® Certified Information Security Manager® (CISM®) Practice Test. The CISM exam helps to affirm your ability to assess risks, implement effective governance, proactively respond to incidents and is the preferred credential for IT managers, according to ISACA.To learn more about this and other related topics under this objective, please refer to the following resource: CISM Review Manual, 15th Edition, 1.0, Information Security Governance, Introduction. Have a question that you'd like to see covered? Email us at certbyte@n2k.com. If you're studying for a certification exam, check out N2K's full exam prep library of certification practice tests, practice labs, and training courses by visiting our website at n2k.com/certify. Please note: The questions and answers provided here, and on our site, are not actual current or prior questions and answers from these certification publishers or providers. Additional source: https://www.isaca.org/credentialing/cism#1 Selected Reading Critical AMI MegaRAC bug can let attackers hijack, brick servers (bleepingcomputer) Europol Warns of “Shadow Alliance” Between States and Criminals (Infosecurity Magazine) ClearFake's New Widespread Variant: Increased Web3 Exploitation for Malware Delivery (Sekoia.io Blog) PHP RCE Vulnerability Actively Exploited in Wild to Attack Windows-based Systems (cybersecuritynews) Scareware Combined With Phishing in Attacks Targeting macOS Users (securityweek) Sneaky 2FA Joins Tycoon 2FA and EvilProxy in 2025 Phishing Surge (Infosecurity Magazine) New Jailbreak Technique Bypasses DeepSeek, Copilot, and ChatGPT to Generate Chrome Malware (gbhackers) Microsoft Warns of New StilachiRAT Malware (SecurityWeek) Fortinet Vulnerability Exploited in Ransomware Attack, CISA Warns (Infosecurity Magazine) AI coding assistant Cursor reportedly tells a 'vibe coder' to write his own damn code (TechCrunch) Share your feedback. We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. Want to hear your company in the show? You too can reach the most influential leaders and operators in the industry. Here's our media kit. Contact us at cyberwire@n2k.com to request more info. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
Niel Harper is a Certified Director and ISACA Board Vice Chair. He is also the Chief Information Security Officer and Data Protection Officer at Doodle. Niel is based in Germany. He has more than 20 years of experience in IT risk management, cybersecurity, privacy, Internet governance and policy, and digital transformation. Safia Kazi is the Privacy Professional Practices Principal at ISACA. She has worked at ISACA for just over a decade, initially working on ISACA's periodicals and now serving as the Privacy Professional Practices Principal. She is based in Chicago. In 2021, she was a recipient of the AM&P Network's Emerging Leader award, which recognizes innovative association publishing professionals under the age of 35. In this episode… ISACA's State of Privacy 2025 survey reveals that privacy professionals are facing significant hurdles, including staffing shortages, budget cuts, and increasing demands for technical privacy expertise. Many organizations are shifting privacy responsibilities to legal and security teams, without additional resources or training. At the same time, AI adoption is increasing, introducing new complexities and risks. With privacy budgets under strain and teams expected to do more with less, how can businesses sustain effective privacy programs while navigating new challenges? According to ISACA's State of Privacy 2025 survey, one of the most pressing concerns for privacy teams is the growing demand for technical privacy expertise. Privacy by design also remains a challenge, with limited resources making it difficult for teams to embed privacy into product development from the outset. AI also plays a growing role in privacy operations, helping automate processes while raising concerns about data security, bias, and third-party risks. Despite these findings from ISACA's survey, businesses can make privacy sustainable by fostering a culture of privacy awareness from the top down, ensuring leadership understands the value of privacy beyond compliance. In this episode of She Said Privacy/He Said Security, Jodi and Justin Daniels speak with Niel Harper, Certified Director and Board Vice Chair at ISACA and CISO and DPO at Doodle, and Safia Kazi, Privacy Professional Practices Principal at ISACA, about the findings from ISACA's State of Privacy 2025 survey. Safia explains how privacy professionals can adapt to changes by continuously learning and staying informed on emerging risks, while Niel highlights the need for board-level privacy advocacy. They also explore how organizations are adapting to staffing shortages and budget constraints, the impact of AI on privacy operations, and how organizations can effectively navigate emerging risks.
Discusses data privacy compliance and environmental, social, and governance (ESG) reporting. Our guest today is Katrina Destrée who is a globally experienced privacy and sustainability professional. Katrina's work in privacy and sustainability focuses on privacy programs, ESG reporting, awareness and training, and strategic communications. Additional resources: International Association of Privacy Professionals (IAPP): https://iapp.org/ ISACA: https://www.isaca.org/ Global Enabling Sustainability Initiative (GeSI): https://www.gesi.org/ Agréa Privacy & ESG: https://agreaprivacyesg.com/ CITI Program's “GDPR for Research and Higher Ed” course: https://about.citiprogram.org/course/gdpr-for-research-and-higher-ed/ CITI Program's “Big Data and Data Science Research Ethics” course: https://about.citiprogram.org/course/big-data-and-data-science-research-ethics/ CITI Program's “Essentials of Responsible AI” course: https://about.citiprogram.org/course/essentials-of-responsible-ai/
¡APRENDE SecTY Podcast! EP4.48 ¿Cuál es el mejor marco de referencia para tu negocio? Cuando quieres poner en orden la ciberseguridad en tu negocio a veces necesitas una base de controles que te guíen, pero ¿cuál es el mejor marco de referencia para tu negocio? Pues te lo cuento en este episodio presentado por Aeronet. Te explico los pasos que necesitas para hacer tu análisis de impacto de tu negocio Este episodio es presentado por AeroNet. Empresa de tecnología 100% puertorriqueña, líder en soluciones de conectividad para negocios y residencias en Puerto Rico. Go Faster, Go Save. AeroNet Wireless - Reliable High Speed Internet (aeronetpr.com) ¡Escucha el video sobre este tema en el canal de YOUTUBE de Aprende SecTY y suscríbete! https://www.youtube.com/@aprendesecty/?sub_confirmation=1 Recuerda: Síguenos en Facebook, Instagram, X y LinkedIN como: @SecTYCS Envíame tus preguntas o recomendaciones a: aprende@sectycs.com Video recomendado: ¿Qué Cambió en el Cybersecurity Framework del NIST?:https://youtu.be/dpvZTUzgDIA #ciberseguridad #SecurityAwareness #InformtaionTechnology #ITSecurity #Empoderamiento #Confianza #NIST #COBIT #ISACA #CIS #PCI #ISO27001 #marcosdereferencia #cybersecurityframework
Given the dynamic nature of cyberthreats and the ever-expanding digital ecosystem, authentication is more critical than ever. In this episode, ISACA director of professional practices and innovation discusses a new content piece titled, "Examining Authentication in the Deepfake Era" with author Dr. Chase Cunningham. Their conversation of the paper explores the evolution, current state, and future trajectory of authentication technologies.
Send Bidemi a Text Message!In this episode, host Bidemi Ologunde spoke with Jorge (George) Flores. Jorge has been a cyber security professional for more than a decade and a half. In the most recent years of his career, George has transitioned into Governance, Risk, and Compliance (GRC) in the field of healthcare, specializing in HIPAA and HITRUST audit. He has obtained the CISSP, HCISPP, ITIL, and CEH certifications, and currently holds a Master's Degree in Computer Science from FIU. George is an active member of South Florida ISSA as well as ISACA. He recently created an educational youtube channel "GRCguy" to help with security awareness and education. George is a proponent of "work/life balance" and encourages young cyber security professionals to ensure they prioritize what matters most first, which is all aspects of health.Support the show
¡APRENDE SecTY Podcast! EP4.44 Ciberdefensa en la Era Trump: ¿Mano Dura contra los Ciberataques? Has pensado en cual seria la estrategia de ciberdefensa bajo el liderazgo de Donald Trump. ¡Interesante! Acompáñame junto con Aeronet para escuchar si la ciberseguridad es o será una prioridad bajo su mandato. Este episodio es presentado por AeroNet. Empresa de tecnología 100% puertorriqueña, líder en soluciones de conectividad para negocios y residencias en Puerto Rico. Go Faster, Go Save. AeroNet Wireless - Reliable High Speed Internet (aeronetpr.com) Taller de Ciberseguridad: Conoce la información y adminístrala de manera segura REGISTRATE AQUÍ: https://bit.ly/talleronlineciberseguridad ¡Escucha el video sobre este tema en el canal de YOUTUBE de Aprende SecTY y suscríbete! https://www.youtube.com/@aprendesecty/?sub_confirmation=1 Recuerda: Síguenos en Facebook, Instagram, X y LinkedIN como: @SecTYCS Envíame tus preguntas o recomendaciones a: aprende@sectycs.com Deja tu reseña en iTunes/Apple Podcast y compártelo con personas que necesiten mejorar la seguridad en su negocio y en su vida. Puedes escucharnos también por medio de: iTunes/Apple Podcast, Spotify, YouTube Music, Amazon Music y iHeartRadio.
¡APRENDE SecTY Podcast! EP4.43: Cómo los Ciudadanos Pueden Contribuir a la Seguridad Electoral ¡Las elecciones, tu voto! ¿sabías que tú también eres una pieza clave en la protección de nuestras elecciones? Como, pues escucha el episodio especial de hoy presentado por Aeronet. Este episodio es presentado por AeroNet. Empresa de tecnología 100% puertorriqueña, líder en soluciones de conectividad para negocios y residencias en Puerto Rico. Go Faster, Go Save. AeroNet Wireless - Reliable High Speed Internet (aeronetpr.com) Taller de Ciberseguridad: Conoce la información y adminístrala de manera segura REGISTRATE AQUÍ: https://bit.ly/talleronlineciberseguridad ¡Escucha el video sobre este tema en el canal de YOUTUBE de Aprende SecTY y suscríbete! https://www.youtube.com/@aprendesecty/?sub_confirmation=1 Recuerda: Síguenos en Facebook, Instagram, X y LinkedIN como: @SecTYCS Envíame tus preguntas o recomendaciones a: aprende@sectycs.com Deja tu reseña en iTunes/Apple Podcast y compártelo con personas que necesiten mejorar la seguridad en su negocio y en su vida. Puedes escucharnos también por medio de: iTunes/Apple Podcast, Spotify, YouTube Music, Amazon Music y iHeartRadio.
Today's guest is Tony Clarke, SVP of IT Digital Operations at ICON. Founded in 1990, ICON's mission has been to help their clients to accelerate the development of drugs and devices that save lives and improve quality of life. They are a global provider of consulting, and outsourced development and commercialization services to pharmaceutical, biotechnology, medical device and government and public health organizations. ICON has been recognized as one of the world's leading Contract Research Organizations through various high-profile industry awards. Tony is a senior information security leader with broad range of experience in cybersecurity and information security who has experience across a number of industries including banking/finance, insurance, utilities, telecommunications, government, semi-state bodies, EU and United Nations agencies. He is a keen contributor to the cybersecurity community who has spoken at several cybersecurity conferences and is a regular contributor to OWASP, ISACA and academic events. In this episode, Tony talks about: His diverse background in electronics, IT and cybersecurity, His role managing IT operations, support and enhancements, Focus on impactful technology while managing compliance in trials, Developing language models to simplify information navigation and access, Striving for efficiency by simplifying processes and reducing hurdles, Focus on iterative development and proof of concept for initiatives, Diversity in teams to enhance creativity and problem-solving, Excitement for AI agents enhancing efficiencies and automating outcomes
¡APRENDE SecTY Podcast! EP4.42: Como reportar un cibercrimen Los ataques cibernéticos están a la orden del día, y cualquier de nosotros puede ser víctima. ¿Sabes qué hacer si eres atacado? ¿Cómo puedes proteger tu reputación y minimizar el daño? Hoy te hablo de como reportar un cibercrimen junto con Aeronet. Este episodio es presentado por AeroNet. Empresa de tecnología 100% puertorriqueña, líder en soluciones de conectividad para negocios y residencias en Puerto Rico. Go Faster, Go Save. AeroNet Wireless - Reliable High Speed Internet (aeronetpr.com) ***Regístrate HOY al Curso Corto de la Universidad de PR Recinto de Humacao: Ciberseguridad para Todos: Protege tu Información Personal àCiberseguridad para Todos: Protege tu Información Personal – DECEP En Línea | UPR Humacao Cybersecurity Awareness Month: Home - National Cybersecurity Alliance (staysafeonline.org) Como reportar un cibercrimen: Internet Crime Complaint Center (IC3) del FBI: Federal Bureau of Investigation FTC: Federal Trade Commission: IdentityTheft.gov o ReportFraud.ftc.gov Report Hacked Account · Report your hacked account to the respective platform's support team. Find direct links to popular platforms here. Report Phishing · Anti-Phishing Working Group · AARP Fraud Watch Network · FTC Report Identity Theft · Theft IdentityTheft.gov · Identity Theft Resource Center · ADT: What to Do if Your Identity Is Stolen guide Report Ransomware · CISA · FBI Field Offices · U.S. Secret Service Field Offices Report Credit Card Fraud · FTC Report Social Security Fraud · If you believe someone is using your social security number for employment purposes or to fraudulently receive Social Security benefits, contact the Social Security Administration's fraud hotline at 1-800-269-0271. Request a copy of your social security statement to verify its accuracy. o Social Security Administration: Report Fraud, Waste or Abuse Report tax fraud · IRS – Report Tax Fraud · Treasury Inspector General for Tax Administration (TIGTA) – Report a crime · Report tax-related phishing messages or calls to the IRS: phishing@irs.gov Report Business Email Compromise · Internet Crime Complaint Center Report Online Stalking If you believe you are being stalked or are a victim of stalkerware, call, chat or text the National Domestic Violence Hotline: · Visit thehotline.org · Text “Start” to 88788 · Call +1 (800) 799-7233 Report Cyberbullying Report cyberbullying to the platform where the bullying occurred, or to your child's school. Report to local law enforcement if there have been threats of violence, stalking, or hate crimes. · Report Cyberbullying ¡Escucha el video sobre este tema en el canal de YOUTUBE de Aprende SecTY y suscríbete! https://www.youtube.com/@aprendesecty/?sub_confirmation=1 Recuerda: Síguenos en Facebook, Instagram, X y LinkedIN como: @SecTYCS Envíame tus preguntas o recomendaciones a: aprende@sectycs.com Deja tu reseña en iTunes/Apple Podcast y compártelo con personas que necesiten mejorar la seguridad en su negocio y en su vida. Puedes escucharnos también por medio de: iTunes/Apple Podcast, Spotify, YouTube Music, Amazon Music y iHeartRadio.
¡APRENDE SecTY Podcast! EP4.41: Cómo usar la inteligencia artificial (IA) de manera segura Sabemos que la IA está transformando todo, desde cómo trabajamos hasta cómo protegemos nuestras empresas, ¡pero también puede convertirse en un arma de doble filo si no la usamos con seguridad! Quedate conmigo y Aeronet para contarte como usarla de manera segura. Este episodio es presentado por AeroNet. Empresa de tecnología 100% puertorriqueña, líder en soluciones de conectividad para negocios y residencias en Puerto Rico. Go Faster, Go Save. AeroNet Wireless - Reliable High Speed Internet (aeronetpr.com) ***Regístrate HOY al Curso Corto de la Universidad de PR Recinto de Humacao: Ciberseguridad para Todos: Protege tu Información Personal àCiberseguridad para Todos: Protege tu Información Personal – DECEP En Línea | UPR Humacao Cybersecurity Awareness Month: Home - National Cybersecurity Alliance (staysafeonline.org) ¡Escucha el video sobre este tema en el canal de YOUTUBE de Aprende SecTY y suscríbete! https://www.youtube.com/@aprendesecty/?sub_confirmation=1 Recuerda: Síguenos en Facebook, Instagram, X y LinkedIN como: @SecTYCS Envíame tus preguntas o recomendaciones a: aprende@sectycs.com Deja tu reseña en iTunes/Apple Podcast y compártelo con personas que necesiten mejorar la seguridad en su negocio y en su vida. Puedes escucharnos también por medio de: iTunes/Apple Podcast, Spotify, YouTube Music, Amazon Music y iHeartRadio.
¡APRENDE SecTY Podcast! EP4.40: ¿Es fácil activar el MFA? Como activar el MFA para que no te hackeen la cuenta Todavía muchos se preguntan que es el MFA y si es fácil activarlo. Hoy te cuento como activarlo y otros detalles interesantes en este episodio del Cybersecurity Awareness Month presentado por Secty y Aeronet. Este episodio es presentado por AeroNet. Empresa de tecnología 100% puertorriqueña, líder en soluciones de conectividad para negocios y residencias en Puerto Rico. Go Faster, Go Save. AeroNet Wireless - Reliable High Speed Internet (aeronetpr.com) ***Regístrate HOY al Curso Corto de la Universidad de PR Recinto de Humacao: Ciberseguridad para Todos: Protege tu Información Personal àCiberseguridad para Todos: Protege tu Información Personal – DECEP En Línea | UPR Humacao Cybersecurity Awareness Month: Home - National Cybersecurity Alliance (staysafeonline.org) ¡Escucha el video sobre este tema en el canal de YOUTUBE de Aprende SecTY y suscríbete! https://www.youtube.com/@aprendesecty/?sub_confirmation=1 Recuerda: Síguenos en Facebook, Instagram, X y LinkedIN como: @SecTYCS Envíame tus preguntas o recomendaciones a: aprende@sectycs.com Deja tu reseña en iTunes/Apple Podcast y compártelo con personas que necesiten mejorar la seguridad en su negocio y en su vida. Puedes escucharnos también por medio de: iTunes/Apple Podcast, Spotify, YouTube Music, Amazon Music y iHeartRadio.
¡APRENDE SecTY Podcast! EP4.39 La Ciberseguridad No es Suficiente: Desafíos Críticos que Enfrentamos en 2024 ¿Está tu negocio preparado para lo que se avecina en este mundo digital?, te cuento sobre los desafíos críticos de ciberseguridad que enfrentamos en este año y lo que viene. Así que quédate conmigo en este episodio presentado por Aeronet. Este episodio es presentado por AeroNet. Empresa de tecnología 100% puertorriqueña, líder en soluciones de conectividad para negocios y residencias en Puerto Rico. Go Faster, Go Save. AeroNet Wireless - Reliable High Speed Internet (aeronetpr.com) ***Regístrate HOY al Curso Corto de la Universidad de PR Recinto de Humacao: Ciberseguridad para Todos: Protege tu Información Personal àCiberseguridad para Todos: Protege tu Información Personal – DECEP En Línea | UPR Humacao Cybersecurity Awareness Month: Home - National Cybersecurity Alliance (staysafeonline.org) ¡Escucha el video sobre este tema en el canal de YOUTUBE de Aprende SecTY y suscríbete! https://www.youtube.com/@aprendesecty/?sub_confirmation=1 Recuerda: Síguenos en Facebook, Instagram, X y LinkedIN como: @SecTYCS Envíame tus preguntas o recomendaciones a: aprende@sectycs.com Deja tu reseña en iTunes/Apple Podcast y compártelo con personas que necesiten mejorar la seguridad en su negocio y en su vida. Puedes escucharnos también por medio de: iTunes/Apple Podcast, Spotify, YouTube Music, Amazon Music y iHeartRadio.
¡APRENDE SecTY Podcast! EP4.38: Ciberacoso: Protege tu Entorno Familiar y Laboral El ciberacoso. ¿Sabías que puede afectar tanto a adolescentes como a empresas? Descubre cómo identificarlo, prevenirlo y proteger a tus seres queridos y tu negocio del acoso digital. Así que no te despegues en este episodio presentado por Aeronet. Este episodio es presentado por AeroNet. Empresa de tecnología 100% puertorriqueña, líder en soluciones de conectividad para negocios y residencias en Puerto Rico. Go Faster, Go Save. AeroNet Wireless - Reliable High Speed Internet (aeronetpr.com) Noticia relacionada: Noticentro por Wapa | Brian Luis Valentín Ramos, dueño de múltiples páginas de redes sociales dedicadas a publicar fotos de pornografía infantil, fotos íntimas... | Instagram ***Regístrate HOY al Curso Corto de la Universidad de PR Recinto de Humacao: Ciberseguridad para Todos: Protege tu Información Personal àCiberseguridad para Todos: Protege tu Información Personal – DECEP En Línea | UPR Humacao ¡Escucha el video sobre este tema en el canal de YOUTUBE de Aprende SecTY y suscríbete! https://www.youtube.com/@aprendesecty/?sub_confirmation=1 Recuerda: Síguenos en Facebook, Instagram, X y LinkedIN como: @SecTYCS Envíame tus preguntas o recomendaciones a: aprende@sectycs.com Deja tu reseña en iTunes/Apple Podcast y compártelo con personas que necesiten mejorar la seguridad en su negocio y en su vida. Puedes escucharnos también por medio de: iTunes/Apple Podcast, Spotify, YouTube Music, Amazon Music y iHeartRadio.
¡APRENDE SecTY Podcast! EP4.37: Ciberseguridad para Líderes: Evita Riesgos y Gana Más Contratos La ciberseguridad no es solo un tema técnico, es una responsabilidad que empieza con los lideres, o sea contigo. ¡Evita los riesgos y gana más contratos! De eso y muchos más estaré hablando en este episodio de hoy presentado por Aeronet. Este episodio es presentado por AeroNet. Empresa de tecnología 100% puertorriqueña, líder en soluciones de conectividad para negocios y residencias en Puerto Rico. Go Faster, Go Save. AeroNet Wireless - Reliable High Speed Internet (aeronetpr.com) Episodios relacionados: EP4.31 Cómo Aumentar tus Ganancias Implementando Estrategias de Seguridad Cibernética Efectivas: https://aprendesecty.libsyn.com/ep431-cmo-aumentar-tus-ganancias-implementando-estrategias-de-seguridad-ciberntica-efectivas ***Regístrate HOY al Curso Corto de la Universidad de PR Recinto de Humacao: Ciberseguridad para Todos: Protege tu Información Personal àCiberseguridad para Todos: Protege tu Información Personal – DECEP En Línea | UPR Humacao ¡Escucha el video sobre este tema en el canal de YOUTUBE de Aprende SecTY y suscríbete! https://www.youtube.com/@aprendesecty/?sub_confirmation=1 Recuerda: Síguenos en Facebook, Instagram, X y LinkedIN como: @SecTYCS Envíame tus preguntas o recomendaciones a: aprende@sectycs.com Deja tu reseña en iTunes/Apple Podcast y compártelo con personas que necesiten mejorar la seguridad en su negocio y en su vida. Puedes escucharnos también por medio de: iTunes/Apple Podcast, Spotify, YouTube Music, Amazon Music y iHeartRadio.
¡APRENDE SecTY Podcast! EP4.36 Evita una catástrofe con la capacitación de seguridad ¿Ha pasado por algún buen susto de un ataque cibernético? ¿Y no sabes cómo llegaste ahí? ¡Pues te lo voy a decir! La falta de capacitación de seguridad… ¡Que como! Te doy detalles de riesgos, beneficios y consejos de capacitar en seguridad al personal. Acompáñame junto con Aeronet en este episodio. Este episodio es presentado por AeroNet. Empresa de tecnología 100% puertorriqueña, líder en soluciones de conectividad para negocios y residencias en Puerto Rico. Go Faster, Go Save. AeroNet Wireless - Reliable High Speed Internet (aeronetpr.com) Episodios relacionados: EP3.42 Mira, pero no toques-es un pescaito: https://aprendesecty.libsyn.com/ep342-mira-pero-no-toques-es-un-pescaito ***Regístrate HOY al Curso Corto de la Universidad de PR Recinto de Humacao: Ciberseguridad para Todos: Protege tu Información Personal àCiberseguridad para Todos: Protege tu Información Personal – DECEP En Línea | UPR Humacao ¡Escucha el video sobre este tema en el canal de YOUTUBE de Aprende SecTY y suscríbete! https://www.youtube.com/@aprendesecty/?sub_confirmation=1 Recuerda: Síguenos en Facebook, Instagram, X y LinkedIN como: @SecTYCS Envíame tus preguntas o recomendaciones a: aprende@sectycs.com Deja tu reseña en iTunes/Apple Podcast y compártelo con personas que necesiten mejorar la seguridad en su negocio y en su vida. Puedes escucharnos también por medio de: iTunes/Apple Podcast, Spotify, YouTube Music, Amazon Music y iHeartRadio.
¡APRENDE SecTY Podcast! EP4.35 Prepárate para las auditorias de sistemas y conoce los controles claves para cumplir ¿Cuántos ya comenzaron a recibir las peticiones de auditores para cumplir con algunas regulaciones que le aplican a tu negocio? Hoy te digo cuales son esos controles claves para cumplir con una auditoría de IT y algunos consejitos más. Así que quédate conmigo y Aeronet en este próximo episodio. REGISTRO! Taller de Ciberseguridad: Conoce tu información y adminístrala de manera segura en colaboración con Provider Connection y Angeles Rivera. Aprende SecTY - Capacitación Integral en Ciberseguridad para empleados. FECHA: 4 de septiembre 2024 a las 6:00PM por ZOOM. Episodios relacionados: Ep 2: Regulaciones que aplican a tu negocio: https://aprendesecty.libsyn.com/ep-2-regulaciones-que-aplican-a-tu-negocio Ep 11: Aprende a pasar una auditoria de sistemas y sácale la lengua al auditor: https://aprendesecty.libsyn.com/ep-11-aprende-a-pasar-una-auditoria-de-sistemas-y-scale-la-lengua-al-auditor Este episodio es presentado por AeroNet. Empresa de tecnología 100% puertorriqueña, líder en soluciones de conectividad para negocios y residencias en Puerto Rico. Go Faster, Go Save. AeroNet Wireless - Reliable High Speed Internet (aeronetpr.com) ¡Escucha el video sobre este tema en el canal de YOUTUBE de Aprende SecTY y suscríbete! https://www.youtube.com/@aprendesecty/?sub_confirmation=1 Recuerda: Síguenos en Facebook, Instagram, X y LinkedIN como: @SecTYCS Envíame tus preguntas o recomendaciones a: aprende@sectycs.com Deja tu reseña en iTunes/Apple Podcast y compártelo con personas que necesiten mejorar la seguridad en su negocio y en su vida. Puedes escucharnos también por medio de: iTunes/Apple Podcast, Spotify, YouTube Music, Amazon Music y iHeartRadio.