POPULARITY
Qualys returns to Black Hat USA 2026 with an AI Risk Operations Center built around three principles customers have been asking for over the last three years. May Mitchell, Chief Marketing Officer at Qualys, walks through them in order. Detect vulnerabilities at AI speed. Prioritize what surfaces, because not every finding calls for action in the same hour and the sequence follows the workflows a team already runs. Eliminate it through autonomous remediation, then confirm the fix worked. Mitchell also notes that Qualys has been a Black Hat sponsor for over 23 years. What are security teams asking for at AI speed? They want detection to keep pace with disclosure. Mitchell points to InstaScan, the innovation Qualys launched during Black Hat week, which provides continuous scanning and detection. The meetings on the floor have been with customers from across the regions, not only the US. How has the AI conversation shifted since RSAC Conference? It has narrowed to implementation. Mitchell says the messaging moved from AI to agents to autonomous, and that this year the questions are targeted. How do I implement it. How do I get it into the workflows. How do I have governance. The economics of AI sits alongside those questions, with more asked about ROI, since budgets are not rising across the board. That pushes organizations to evaluate their technology stack, consolidate, and look for a single platform that gives complete visibility and gives security leaders something they can take to a board or a CFO. Customization depends on the size of the organization, and larger heterogeneous environments are where Qualys partners come in with risk assessment services, planning, integration, and ongoing management. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST May Mitchell, Chief Marketing Officer at Qualys On LinkedIn: https://www.linkedin.com/in/maymitchell/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Qualys: https://www.qualys.com/ InstaScan announcement: https://www.qualys.com/company/newsroom/news-releases/usa/qualys-launches-instascan-to-detect-vulnerabilities-within-minutes-of-disclosure Agent Insta and scanless detection: https://blog.qualys.com/product-tech/2026/08/03/instascan-agent-insta-scanless-detection ROCon Americas 2026 in Austin: https://www.qualys.com/rocon/2026/americas Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS May Mitchell, Qualys, Marco Ciappelli, brand briefing, brand story, brand marketing, marketing podcast, Black Hat USA 2026, risk operations center, InstaScan, AI speed detection, autonomous remediation, vulnerability management, prioritization, security governance, economics of AI, platform consolidation, cyber risk management, CISO, ROCon Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
Today's guest is Kammil Mahajan, Co-Founder and CEO at Sector8. Businesses across the globe are confronted with the need to integrate AI into their operations, whether they explicitly choose to or not. However, the challenge extends beyond just implementation; it's about understanding the actions AI systems can autonomously undertake. Kammil's company Sector8 is at the forefront of addressing these concerns, as he explores the essence of AI security and how Sector8 is paving the way for future enterprises.Topics include:0:00 His startup lessons from action to failure and resilience2:12 How Sector8 secures AI adoption through governance and cybersecurity4:02 Why Agentic AI expands risks through autonomous actions and access6:48 How Prompt injection evolves into AI-driven actions and risks8:33 Securing AI starts with visibility, access control and guardrails10:13 Sector8's role in enabling secure AI adoption with real-time controls13:26 How AI security is shifting towards agentic governance and real-time controls14:40 Partnering with Enterprise Ireland to scale globally 16:12 How entrepreneurship requires resilience, discipline and staying focused
In this episode of the Mic On Podcast, Seun Okinbaloye sits with veteran politician, diplomat, and former Minister of State for Defence, Senator Musiliu Obanikoro, who shares his views on governance, security, and the 2027 elections.Obanikoro reflects on his political journey, discusses lessons learned from President Bola Tinubu, and defends the administration's economic reforms, arguing that difficult decisions were necessary for long-term stability. He also advocates a tough approach to tackling insecurity, including the possible use of mercenaries in the fight against terrorism.Looking ahead to 2027, Obanikoro expresses confidence in President Tinubu's re-election prospects, weighs in on Lagos politics, and insists the APC remains well-positioned to retain power at both the state and national levels.Guest:Senator Musiliu Obanikoro (Former Senator/Former Minister of State for Defence)
TOPIC: Security Challenges, Governance, Political Strategy and the Road to 2027On this edition of Oluwakayode and The Guru, the duo unpack some of the most pressing issues shaping Nigeria's political and governance landscape, with a particular focus on security, public confidence, and the emerging calculations ahead of the 2027 general elections.The conversation examines recent security developments across the country, the government's response to ongoing challenges, and the impact these issues continue to have on communities, businesses, and national development. Drawing from historical precedents and current realities, Oluwakayode and The Guru explore whether Nigeria is learning the right lessons from past experiences.Attention also turns to the political manoeuvring already taking shape ahead of 2027, as alliances, ambitions, and strategic positioning begin to emerge across the country's political spectrum. The duo discuss the issues likely to dominate future campaigns and what citizens should be paying attention to as political conversations intensify.Blending historical context, political analysis, and practical insight, the discussion offers listeners a deeper understanding of the forces shaping Nigeria's present and influencing its future.
Key Takeaways Overview: Companies are drowning in AI tools, most of which "do not talk to each other." Today, Microsoft announced Microsoft 365 E7: The Frontier Suite, officially launching May 1st for $99. The suite brings together Microsoft 365 E5, M365 Copilot Wave 3, and Agent 365. Manage agents: IDC projects 1.3 billion AI agents by 2028, creating major governance, access control, and data management challenges that Agent 365 addresses by giving teams a single place to track, secure, and manage them all. Big idea: Work IQ, which will be explored at AI Agent & Copilot Summit, signals that Copilot has gone mainstream, with 160% YoY growth and large-scale enterprise deployments. "This isn't experimentation anymore. This is enterprise AI going mainstream." Visit Cloud Wars for more.
In this episode, we take a focused look at Startup-Scale Landing Zones. We've previously discussed Enterprise-scale Landing Zones and how the default model from the Cloud Adoption Framework is the usual approach for new deployments. SSLZ is an opinionated approach that is better suited to smaller environments. We talk about the pros, cons, differences, and how to get started.(00:00) - Intro and catching up.(04:51) - Show content starts.Show links- Startup-Scale Landing Zone (GitHub)- Nice intro page for SSLZ- Give us feedback!
In this episode, we're not diving deep into a single feature of Azure - instead, we'll talk and share our insights on how to build a career working with Microsoft security. What should you know? What's relevant? What's less relevant? What are the core skills you should have? (00:00) - Intro and catching up.(04:51) - Show content starts.Show links- No links this week :)- Give us feedback!
In this episode, we take a look at the transition from "vibe-coding" to shipping verifiable, production-grade AI applications. This is the critical shift from relying on "gut feel" and prompt tinkering to implementing rigorous audit trails, versioning, and security controls. We discuss why many AI pilots fail due to a lack of explainability, the specific risks of privilege expansion and data leakage in agentic workflows, and also outline how to use Microsoft Foundry/Azure AI Studio to operationalize your models like true regulated software. (00:00) - Intro and catching up.(05:30) - Show content starts.Show links- RedAmon (GitHub) for automated agentic offensive security- Give us feedback!
In this week's episode, we look at recent Microsoft Tech updates. By popular request, we're expanding our scope beyond Azure to include Microsoft 365, Power Platform, and related Microsoft platforms and capabilities. What's new? What's interesting? What's retiring? (00:00) - Intro and catching up.(03:30) - Show content starts.Show links- Preview: Virtual Network Routing Appliance- Claude and Codex on Agent HQ (Github Copilot)- Disabling NTLM by default- What's new in Microsoft Sentinel- Give us feedback!
In der aktuellen Folge von Breach FM sprechen Robert und Max über neue Erkenntnisse zu Salt Typhoon und dessen Aktivitäten in europäischen Telekommunikationsnetzen – mit besonderem Blick auf Norwegen und die geopolitischen Implikationen langfristiger Spionagekampagnen. Wir diskutieren den kritischen Bericht des US Cyber Safety Review Board zur Sicherheitskultur bei Microsoft und fragen, was „Security Governance“ bei einem der wichtigsten Tech-Konzerne der Welt wirklich bedeutet.Außerdem schauen wir auf Dänemarks ungewöhnlich offene Rekrutierungsoffensive für offensive Cyber-Operationen und ordnen ein, was das über aktuelle Bedrohungslagen und staatliche Cyberstrategien verrät. Mit dabei ist auch eine schwere Schwachstelle in Azure Front Door und warum „Patch your stuff“ weiterhin keine Floskel ist. Zum Abschluss geht es um gezielte Phishing-Kampagnen gegen Signal-Nutzer, die besonders Journalisten, Politiker und Militärs ins Visier nehmen – und warum hier weniger Technik als vielmehr Social Engineering das eigentliche Risiko ist.Norwegian intelligence discloses country hit by Salt Typhoon campaignhttps://therecord.media/norawy-intelligence-discloses-salt-typhoon-attacks Denmark's military intelligence service has launched a campaign to recruit cybersecurity specialists for offensive cyber operationshttps://www.fe-ddis.dk/da/nyheder/2026/fe-soger-landets-skarpeste-hoveder-til-hackerakademi/Gemeinsamer Sicherheitshinweis (BfV und BSI) - Phishing über Messengerdienstehttps://www.bsi.bund.de/SharedDocs/Cybersicherheitswarnungen/DE/2026/202602_BfV_BSI.htmlCSRB Slams Microsoft for ‘Inadequate' Security Culture, Calls for Overhaulhttps://www.meritalk.com/articles/csrb-slams-microsoft-for-inadequate-security-culture-calls-for-overhaulCVE-2026-24300https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-24300The Technological Republic (Buch von Alex Karp)https://www.m-vg.de/finanzbuchverlag/shop/article/25367-the-technological-republic/Careless Peoplehttps://www.thalia.de/shop/home/artikeldetails/A1074309386
In this episode, we take a look at the Unified Tenant Configuration Management APIs, or UTCM. This is a set of capabilities that allow you to monitor and extract tenant configuration for automated and code-based monitoring and management. We discuss why you would use these, how they work, and also try them out by building tooling around the APIs. (00:00) - Intro and catching up.(03:13) - Show content starts.Show links- UTCM APIs- Jussi's vibe-coded tooling on GitHub- Give us feedback!
In this episode, we take a look at Windows Backup for Organizations. What's the capability, and why should you use it? What's required, and anything that's missing from it? We discuss backups in general, also, and provide insights on what you should back up. (00:00) - Intro and catching up.(03:30) - Show content starts.Show links- Windows Backup for Organizations- LEGO Arcade Machine (40805)- Give us feedback!
In this episode, we dissect the newly refreshed Well-Architected Framework guidance on building AI workloads. What is AI, actually? The guidance is organized into sections, and we walk through each one, sharing our insights and thoughts. (00:00) - Intro and catching up.(04:26) - Show content starts.Show links- Google Gemini- AI Workload guidance in Well-Architected Framework- Reference architectures- Give us feedback!
Rob Hughes — CISO at RSA and Champion of a Passwordless FutureNo Password Required Season 7: Episode 1 - Rob HughesRob Hughes, the CISO at RSA, has more than 25 years of experience leading security and cloud infrastructure teams. In this episode, he reflects on his unconventional career path, from co-founding the original Geek.com and serving as its Chief Technologist during the early days of the internet, to leading security and systems design at Philips Home Monitoring.Jack Clabby of Carlton Fields, P.A. and Kayley Melton welcome Rob for a wide-ranging conversation on identity, leadership, and the realities of modern cybersecurity. Rob currently leads RSA's Security and Risk Office, overseeing cybersecurity, information security governance, and risk across both RSA's products and corporate environment.Rob explains his dream for a passwordless future. He unpacks why passwords remain one of the largest sources of cyber risk, how real-world incidents and password-spraying attacks have accelerated change, and why phishing-resistant technologies like passkeys may finally be reaching a tipping point. The episode wraps with the Lifestyle Polygraph, where Rob lightens the conversation with stories about gaming with his kids, underrated horror films, and classic cars.Follow Rob on LinkedIn: https://www.linkedin.com/in/robert-hughes-816067a4/Chapters: 00:00 Introduction to No Password Required01:43 Meet Rob Hughes, CISO at RSA02:05 The Role of a CISO in a Security Company05:09 Transitioning to the CISO Role08:00 The Early Days of Geek.com12:14 Launching a Startup During the Dot Com Boom14:30 The Push for a Passwordless Future18:21 Tipping Point for Passwordless Adoption20:20 Ongoing Learning in Cybersecurity26:09 Managing Stress in High-Pressure Environments33:46 The Lifestyle Polygraph Begins34:15 Career Insights in Cybersecurity36:08 Dream Cars and Personal Preferences39:58 Underrated Horror Films41:19 Creating a Cybersecurity Monster
In this episode of Absolute AppSec, Nathan Hunstad, Director of Security at Vanta, discusses the intersection of security policy, governance, and technical defense. Drawing on his unique background in political science and the Minnesota state legislature, Hunstad argues that policy acts as the essential "conductor" for an organization's security tools. A major theme of the conversation is the challenge of compliance for startups, with the group advising founders to prioritize business survival and basic security hygiene—like password managers and IAM—before pursuing intensive certifications like SOC 2. The discussion also explores how AI is accelerating both development velocity and the ability to automate tedious security questionnaires. Furthermore, Hunstad contrasts the security posture of modern, cloud-native startups against legacy enterprises, noting that older organizations often struggle with "dark corners" of un-inventoried, vulnerable legacy tech. The episode concludes with a critique of outdated authentication standards, specifically advocating for the removal of mandatory password rotation in favor of NIST-aligned, phishing-resistant MFA.
professorjrod@gmail.comIn this episode of Technology Tap: CompTIA Study Guide, we delve into the critical role of security governance in building secure organizations. Learn how governance frameworks—comprising policies, standards, procedures, and playbooks—transform strategic intent into consistent, auditable actions that both teams and auditors rely on. Whether you're preparing for your CompTIA exam or aiming to develop essential IT skills, understanding these governance principles is key to effective tech exam prep and technology education. Join us as we break down complex concepts in an easy-to-understand way, helping you succeed in your IT certification journey and beyond.We start with clear definitions that make exam questions and real-world decisions easier. Policies set high-level rules and expectations. Standards add measurable technical requirements like encryption strength and logging baselines. Procedures translate both into step-by-step action, and playbooks coordinate who does what, in what order, using which tools. Along the way, we compare external frameworks such as ISO 27001, NIST 800, PCI DSS, and FIPS with internal standards that tailor controls to your environment.Privacy law isn't a side quest; it shapes everything. We demystify GDPR, CCPA, FERPA, HIPAA, and COPPA, and clarify roles that exams love to test: the data owner who sets classification and usage, the data controller who defines purpose and lawful basis, the data processor who acts for the controller, and the data custodian who protects and maintains data without deciding how it's used. You'll learn practical cues to spot each role fast and avoid common pitfalls.Finally, we dig into change management as a risk control function. Its goal is to minimize risk while implementing changes, with impact analysis, approvals, testing, and rollback plans. Automation and orchestration can speed response and reduce error, but only when guided by policy and enforced by standards. Expect memorable exam tips, grounded examples, and a framework you can use right away on the job.If this helped sharpen your Security+ prep or your day-to-day practice, subscribe, share the show with a colleague, and leave a quick review. Your feedback helps more learners tap into technology with confidence.Support the showArt By Sarah/DesmondMusic by Joakim KarudLittle chacha ProductionsJuan Rodriguez can be reached atTikTok @ProfessorJrodProfessorJRod@gmail.com@Prof_JRodInstagram ProfessorJRod
In this week's episode, we look at recent Microsoft Tech updates. By popular request, we're expanding the scope beyond just Azure to include Microsoft 365, Power Platform, and similar Microsoft platforms and capabilities. What's new? What's interesting? What's retiring? (00:00) - Intro and catching up.(04:45) - Show content starts.Show links- Update: Retirement date for default outbound access has been extended- GA: Tenant-owned Domain Impersonation for Teams messaging- Preview: Tenant-to-tenant migration with orchestrator for Microsoft 365- Preview: Dynamic Threat Detection Agent- Get started with azureblobcontainer-to-azureblobcontainer migration in Azure Storage- Give us feedback!
In this episode, we take a look at the brand new Microsoft Security Dashboard for AI. We initially spotted this during Microsoft Ignite 2025, and have been eagerly waiting for it to become available. And here it is! We talk about the what, how, and why of this new capability.(00:00) - Intro and catching up.(02:40) - Show content starts.Show links- Microsoft Security Dashboard for AI- Fitness tests that Jussi is working on - part 1, part 2 (in Finnish)- Give us feedback!
In this episode, we take a look at Azure networking topologies from the ground up. What options do we have for building enterprise-scale architectures, and when should we choose one over another? We discuss our own experiences, and also the stuff we seemingly do not know enough about.(00:00) - Intro and catching up.(03:59) - Show content starts.Show links- Define an Azure network topology - Traditional Azure networking topology (Hub and Spoke) - Virtual WAN network topology (Managed)- Give us feedback!
In this episode, we dive deeper into Azure Trusted Signing, and how it can help with signing your binaries. Why should you care? What are the tools today and in the future, and how to get this done right?(00:00) - Intro and catching up.(03:01) - Show content starts.Show links- Signtool - Introduction to code signing - Trusted Signing- Give us feedback!
In this episode, we take a look at three interesting - and free - tools to help you manage and secure Azure and Entra ID. We take each tool for a spin and reflect on the findings and usage.(00:00) - Intro and catching up.(03:15) - Show content starts.Show links‑ ScEntra‑ azqr - Azure Quick Review‑ EntraExporter- Give us feedback!
In an era of relentless data breaches and cyber threats, cloud security governance stands as the ultimate framework balancing accessibility with ironclad protection for your cloud assets. This episode breaks down its core components, from risk assessment and advanced tech like encryption/MFA to policy enforcement, incident response, and ongoing monitoring. Explore how it aligns cloud usage with business goals, ensures compliance, and collaborates with providers while empowering teams through training.
In this week's episode, we look at recent Microsoft Tech updates. By popular request, we're expanding the scope beyond just Azure to include Microsoft 365, Power Platform, and similar Microsoft platforms and capabilities. What's new? What's interesting? What's retiring?(00:00) - Intro and catching up.(04:25) - Show content starts.Show links- Agent 365 tooling servers - Mistral 3 available in Microsoft Foundry - Microsoft 365 Copilot Business - Entra ID support for RDP Connections- Ignite 2025 Next Steps- Foundry Control Plane: Where Developers Build, Operate, and Govern Every Agent Feedback - Give us feedback!
In this episode, we unpack what's new with Microsoft Defender for Cloud. During Ignite 2025, Microsoft announced that the public preview of MDC would be available shortly, and it has arrived now. We'll take a look at what changed, what didn't, and why you should care.(00:00) - Intro and catching up.(03:52) - Show content starts.Show links- Defender for Cloud Preview- Give us feedback!
In this episode, we take a look at the new Microsoft Zero Trust Assessment tool. We reflect on Zero Trust in general, its application in the Microsoft security landscape, and what this exciting tool will offer you.(00:00) - Intro and catching up.(05:00) - Show content starts.Show links- Microsoft Zero Trust Assessment tool- Demo of Microsoft Zero Trust Assessment (Merill Fernando)- Give us feedback!
Microsoft Ignite 2025 is here! We reflect on the hero announcements and what they mean for the future. Some exciting announcements were made during the first keynote, and we already had a chance to try a few of them out.(00:00) - Intro and catching up.(03:35) - Show content starts.Show links- ESPC'25 in Dublin- Microsoft Agent 365- Security Copilot announcement- Azure Copilot- Microsoft Foundry, and more here- Defender for Cloud- Give us feedback!
Send us a textThe fastest way to lose trust is to let AI adoption outrun your governance. We open with a blunt look at AI sprawl and shadow AI—how unsanctioned tools slip past weak policies, create data exposure, and strain legacy controls—then lay out a practical path for teams that don't have a big‑tech budget: continuous discovery via proxies or CASB‑like tools, real‑time monitoring through a trusted partner, and risk assessments that focus on business impact, not buzzwords. The goal isn't to slow innovation; it's to make it safe and repeatable.From there, we bring CISSP Domain 1.3 to life with five scenario‑based questions that mirror real leadership decisions. You'll hear why federated governance outperforms heavy central mandates in multinationals, how defining risk appetite is the first step before any framework, and which metrics actually prove value to a board. We draw a clear line between due care (policies, accountability, legal alignment) and due diligence (testing, verification, audits), and we show why insurance can transfer residual risk but can never replace sound governance.We also get specific about executive communication. A new CEO wants alignment, accountability, and outcomes—not weekly patch timelines. Learn how to map security objectives to corporate strategy, prioritize by business risk, and present measurable progress that earns budget and buy‑in. If you're preparing for the CISSP or leading a program under pressure, these principles help you think like a strategist and act with confidence.Want more? Explore the free resources and growing library at CISSP Cyber Training, and grab the 360 free CISSP practice questions. If this episode helps you think clearer about governance and AI, subscribe, share it with a teammate, and leave a quick review to help others find the show.Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a textCheck us out at: https://www.cisspcybertraining.com/Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkoutGet access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouvSecurity governance represents one of the most misunderstood yet critical components of any cybersecurity program. As we explore Domain 1.3 of the CISSP exam, we unpack how proper governance creates accountability and structure that protects both your organization and your career.We begin with a startling real-world example: the "Red November" campaign, where Chinese state-sponsored hackers exploited vulnerable internet-facing appliances and VPNs across defense, aerospace, and government sectors for a full year. This sophisticated operation highlights why casual approaches to security governance leave organizations exposed to devastating attacks.Security governance isn't merely a theoretical concept – it's a practical framework that defines who's responsible for what across your security landscape. We break down the crucial roles every organization must establish: from Senior Managers who hold ultimate responsibility, to Data Owners who classify information, to Data Custodians who implement protections, and the often-overlooked role of Auditors who verify everything works as intended. Understanding these distinctions protects security professionals from becoming scapegoats when incidents occur.The real value emerges when we examine how security control frameworks like NIST CSF, ISO 27001, and CRI provide structured approaches to managing risk. These aren't one-size-fits-all solutions, but rather customizable blueprints that help you systematically identify, implement, and monitor security measures appropriate to your specific needs. Framework mapping allows you to align multiple requirements efficiently, making compliance less burdensome and more effective.Finally, we demystify the concepts of due care and due diligence – the practical actions that demonstrate you've taken reasonable steps to protect your organization. These aren't just legal defenses; they're the fundamental building blocks of a mature security program that aligns with business objectives while meaningfully reducing risk.Whether you're preparing for the CISSP exam or building a more robust security program, this episode provides the practical knowledge you need to implement effective security governance that executives will support and auditors will approve.Support the showGain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Host Chris Hackett explores the realities of risk and compliance with three industry experts. Joakim Sjunnesson, Group Information Security Risk Manager at ASSA ABLOY, Adrien LeClerqc, Internal Audit and Risk Manager at Spotify, and Somaia El-Gamal, Assistant Manager of Security Governance at Boubyan Digital Factory share insights into how businesses can manage risk, strengthen governance, and navigate compliance challenges. This discussion highlights the importance of security, audit, and compliance frameworks in building resilience and supporting sustainable business growth.
RSAC Conference 2025 has been full on, with cybersecurity experts from all over the world descending on San Francisco to share trends, data, and announcements.This year, ITPro has been providing both remote and on the ground coverage from the event, across talks covering topics such as AI security and threat actor methodology.In this episode, Jane speaks to Rory about some of his RSAC coverage and key takeaways from the event.Read more:RSAC Conference 2025 was a sobering reminder of the challenges facing cybersecurity professionalsRSAC Conference Day One: Vibe Is 'All In' on AI for Security“Governance is an irreplaceable role”: Microsoft Security VP on why diversity and sector expertise will keep security workers relevant in the age of agentic AIRSAC Conference day two: A focus on what attackers are doing"There needs to be an order of magnitude more effort"": AI security experts call for focused evaluation of frontier models and agentic systemsCyber defenders need to remember their adversaries are human, says Trellix research headRSAC Conference day three: using AI to do more with less and facing new attack techniques"China has almost doubled their aggression in cyber': Kevin Mandia and Nicole Perlroth warn organizations aren't waking up to growing APT threats
This episode of the InfoSec Beat podcast focused on careers in information security features a conversation between Accenture CISO Kris Burkhardt and Paul Kunas, who led our Governance, Risk, and Compliance (GRC) function for almost 10 years. Paul's career journey involved security roles at Accenture and other companies and ultimately a return to Accenture to formalize GRC for Information Security. The work spanned developing global strategies and building many programs to arrive at one common view of risk today. Activities center on various analyses to secure technology, updating strategies, validating approaches, instilling a common view and vision, and responding to new challenges.
Episode 65 features Marina Segal, a friend, former colleague, and now co-founder and CEO of her VC-backed start-up, Tamnoon (www.tamnoon.io). I first met and worked with Marina Segal at Dome9 and, subsequently, Check Point Software. Marina is a shrewd and highly experienced executive with a strong background in Security Governance, Risk, and Compliance. In this age of AI, automation, and BOTs, she and her team have created an interesting value proposition with a human touch. I hope you enjoy the discussion. *PLEASW NOTE*Correction* Midway through the broadcast I refer to CNAPP as a 'horizontal vertical' solution and I meant to say CSPM, not CNAPP. My bad. Thanks!
In this episode, I talk to Brian Wilson whose departure from the Navy was prompted by an offer that was just too good to pass up. Known throughout the Corps for his kindness, humbleness, intelligence, and hid dedication to the mission, we all thought Brian would stay until forced out. His first stint out of the Navy lasted 14 years, allowing him to combine many of the roles and skills he developed while on active duty. Just recently, Brian moved to the Institute for Security Governance in Monterey, CA. Brian is on LinkedIn. --- Support this podcast: https://podcasters.spotify.com/pod/show/tom-welsh/support
Guest: Nitin Raina, Global CISO, Thoughtworks [@thoughtworks]On LinkedIn | https://www.linkedin.com/in/nnraina/____________________________Host: Sean Martin, Co-Founder at ITSPmagazine [@ITSPmagazine] and Host of Redefining CyberSecurity Podcast [@RedefiningCyber]On ITSPmagazine | https://www.itspmagazine.com/sean-martinView This Show's Sponsors___________________________Episode NotesIn this episode of the Redefining Cybersecurity Podcast, host Sean Martin connects with Nitin Raina, the global Chief Information Security Officer (CISO) for ThoughtWorks. The discussion centers around Nitin's innovative approaches to transforming and elevating cybersecurity, drawing from his rich experience and strategic mindset. Nitin shares his journey in cybersecurity, emphasizing the evolution of the security program under his leadership. He discusses the significance of adapting a business-centric approach to cybersecurity, breaking away from conventional, technology-focused strategies. This includes the development and successful implementation of a business security maturity model designed to align with the organization's diverse, global operations.A notable aspect of Nitin's strategy is the emphasis on leadership activation and the importance of governance in driving cybersecurity initiatives. By fostering a culture of security ownership across all levels of leadership and the broader organization, Nitin underscores the transformational shift in how cybersecurity is perceived and managed within ThoughtWorks. He highlights the collaborative efforts with different departments, such as IT operations and legal compliance, to ensure a cohesive approach to protecting the organization's 'crown jewels.' Through anecdotes and examples, Nitin illustrates the impact of these strategies on enhancing security awareness, decision-making, and operational effectiveness across the company.The conversation also touches on the technical side, discussing the role of developers within the cybersecurity landscape and the utilization of contemporary technologies and frameworks to bolster the security posture. The episode concludes with insights into the future of cybersecurity, advocating for a more integrated and business-aligned approach. Nitin's reflections on the journey and achievements of his company's cybersecurity initiatives provide valuable lessons for organizations aiming to redefine their security strategies in a rapidly evolving digital world.Key Questions AddressedHow did Nitin Raina's leadership and strategies transform the cybersecurity posture at his company?What role does leadership activation play in redefining cybersecurity across an organization?How can cybersecurity be aligned with business strategies to foster growth and innovation?___________________________Watch this and other videos on ITSPmagazine's YouTube ChannelRedefining CyberSecurity Podcast with Sean Martin, CISSP playlist:
In this episode of What That Means, Camille gets into product security governance with Vernetta Dorsey Windsong, Director of Product Security Governance at Intel. They talk about how product security and governance practices work together, how to get started with product security governance, the challenges of implementing new practices, automation within a secure development lifecycle, the effects of AI on processes, preventing governance creep, and more. Learn more about the secure development lifecycle in Vernetta and Camille's previous conversation: https://cybersecurityinside.libsyn.com/49-what-than-means-with-camille-secure-development-lifecycle-sdl The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.
Although our paths did not cross too many times while serving in the Navy JAG Corps, Ian Wexler and I had many common career experiences, including career challenges and duty stations. Ian's last assignment on active duty was as Director, Institute for International Legal Studies in Newport, RI. Following his retirement this past fall, Ian became Director, Institute for Security Governance in Monterey, CA. DISCLAIMER: THE OPINIONS EXPRESSED BY IAN WEXLER IN THIS PODCAST ARE HIS PERSONAL VIEWS AND NOT THOSE OF THE INSTITUTE FOR SECURITY GOVERNANCE, THE DEFENSE SECURITY COOPERATION UNIVERSITY, THE DEFENSE SECURITY AGENCY, OR THE DEPARTMENT OF DEFENSE. Ian's biography can be found HERE while his LinkedIn profile can be accessed HERE. --- Support this podcast: https://podcasters.spotify.com/pod/show/tom-welsh/support