Cybersecurity Where You Are (audio)
Center for Internet Security

Último episódio
205 episódios
- In episode 205 of Cybersecurity Where You Are, Tony Sager speaks with Phyllis Lee, VP of SBP Content Development at the Center for Internet Security®(CIS®), and Steve Lipner, Executive Director of SAFECode. Together, they discuss how an updated document from CIS and SAFECode gives concrete guidance on what artificial intelligence (AI) means for your Secure by Design process.
Here are some highlights from our episode:
02:17. A refresher on making Secure by Design digestible for end organizations
02:57. Distillation and prescriptive guidance: The value provided by CIS
06:53. An overview of Butler Lampson's "Gold Standard of Security"
07:03. How a shift in approach to Secure by Design led to the founding of SAFECode
09:42. The importance of verification requirements for what developers have done
12:54. A product of CIS pragmatism: Prioritization relative to the development environment
20:06. Artifacts as evidence of secure software development at work
30:15. How the updated document provides guidance around AI
30:45. What AI creates instead of new classes of vulnerabilities
Resources
CIS Critical Security Controls® (CIS Controls®)
Secure by Design
Secure by Design v1.1 A Guide to Assessing Software Security Practices
Turning Secure Software Development into a Measurable Practice
CIS and SAFECode Release Secure by Design v1.1: A Guide to Assessing Software Security Practices
Episode 164: Secure by Design in Software Development
CIS Critical Security Control 16: Application Software Security
Guide to Implementation Groups (IG): CIS Critical Security Controls v8.1
Episode 200: Alan Paller's Vision and Our Next Chapter
From Prompts to Protocols: The Security Blueprint for Enterprise AI
Mythos AI: What Actually Matters for Cybersecurity Leaders
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org. - In episode 204 of Cybersecurity Where You Are, Sean Atkinson speaks with Ryan Winmill, Chief Security Officer and Vice President of FIFA World Cup Boston, and John Cohen, Executive Director of the Office of Strategic Programs and Initiatives at the Center for Internet Security® (CIS®). Together, they discuss how FIFA World Cup 2026 (FWC26) — secured through an unprecedented tripartite governance framework, $625 million in U.S. Congressional funding, and real-time intelligence that stopped a swatting attempt at the finals — set a new standard for proactive event security worldwide.
Here are some highlights from our episode:
01:18. The "unprecedented" governance framework created for FWC26
03:53. The role of CIS as a force multiplier for FIFA, host regions, and other partners
11:00. Why you can't trust the person with an ego in large-scale event security planning
13:23. How the threat environment evolved over the previous three World Cup tournaments
17:23. A new bar for proactive event security going forward
18:43. How CIS provided quality control that helped to mitigate swatting calls during FWC26
21:55. Unique approaches used by host regions to better understand the World Cup fanbase
23:15. How counterfeit FIFA volunteer uniforms triggered a cross-city credentialing response
26:46. Recommendations for future large-scale event host cities
30:19. Ryan's recommendation to future host cities: "Call CIS before you get started"
Resources
Special Event Risk Analysis & Advisory Services
Episode 196: Securing FIFA World Cup 2026 Collaboratively
Inside the Security Operation Behind the 2026 FIFA World Cup
3 Lessons for Securing Large-Scale Events: Inside FIFA World Cup 2026
Securing FIFA World Cup 2026 With a Collective Defense Approach
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org. - In episode 203 of Cybersecurity Where You Are, Sean Atkinson speaks with Pavlina Pavlova, Founder of Critical Cyber. Together, they discuss how Pavlina started Critical Cyber to go beyond the data and give voice to the human impact of cyber attacks, from ransomware hitting hospitals to cyber tactics targeting civilians in active conflict zones.
Here are some highlights from our episode:
00:44. How Pavlina's work covering the impact of cyber attacks on Ukrainian critical infrastructure led to Critical Cyber
03:13. How Critical Cyber works with cyber attack victims, responders, and other audiences
04:08. Countering the tendency, even among cybersecurity experts, to sanitize cyber attacks' human impact
08:57. The use of storytelling with those impacted by cyber attacks to drive policy changes
15:02. Why cyber attacks in some sectors are underreported
19:01. Critical Cyber's mission of combining testimony, research, and expert collaboration
24:51. Where Critical Cyber is and where it's looking to go
Resources
Critical Cyber
Cybersecurity for Critical Infrastructure
Episode 202: Delineating AI Security and Cybersecurity
Recent Water Utility Attacks Offer a Blueprint for Resilience
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org. - In episode 202 of Cybersecurity Where You Are, Sean Atkinson and Ed Skoudis sit down with Rob T. Lee, Chief of Research & Chief AI Officer at the SANS Institute. Together, they explore how the implications of multiple 2026 sandbox escapes of artificial intelligence (AI) models are starting to delineate AI security and cybersecurity.
Here are some highlights from our episode:
02:00. The historical context of one AI model's 2026 sandbox escape
03:26. The impact of ethics, guardrails, and misconfigurations in an AI containment breach
06:08. Why context matters when talk of AI models "going rogue" surfaces
11:49. How history helps us to delineate AI security and cybersecurity
13:47. A new skill and mindset to match our refined AI risk understanding
15:43. Rules and cybersecurity implementation as a possible way forward
19:04. The double-edged sword of restricting access to open-weight models
23:25. Recommendations for keeping up with what's changing in the AI security space
25:51. Rob's advice: To learn how to defend a thing, try learning how to build it first
28:23. AI governance and seeing through the "slop" to informed conversation
29:54. The use of AI to learn more about and discuss AI security for years to come
Resources
OpenAI says its AI technology acted on its own in an ‘unprecedented’ hack of another company
Pacing model development in an era of cyber-critical capabilities
Black Hat USA 2026 | The 'Breaking' News: The OpenAI–Hugging Face Incident
Episode 193: AI Security and Responsibility in EO 14409
The AI Daily Brief — Daily AI News & Analysis
AI Playbooks for SLTT Cybersecurity Leaders
SANS Cybersecurity Summits
SANS NewsBites
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org. - In episode 201 of Cybersecurity Where You Are, Sean Atkinson and Ed Skoudis sit down with William Wright, Chief Executive Officer of Closed Door Security. Together, they reflect on the evolution of penetration testing, including the impact on pentesting from artificial intelligence (AI).
Here are some highlights from our episode:
01:03. How things have changed since William's and Ed's first pentests
09:02. Community: A defining element of Capture The Flag (CTF) events
14:47. Industry concerns over the "death" of CTFs and "cheating" by artificial intelligence (AI)
17:00. Opportunities to take CTFs to the next level in the age of AI
20:18. Pentesting vs. vulnerability scanning: Why terminology matters
25:43. The advent of autonomous AI tools and what they could mean for vulnerability scanning
29:07. Why continuous improvement in cybersecurity doesn't always require AI
Resources
Closed Door Security
Episode 189: The Present and Future of AI-enabled Pentesting
SANS Cyber Ranges
Top External Network Risks And How to Fix Them
Penetration Testing
Vulnerability Assessments
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
Mais podcasts de Negócios
Podcasts em tendência em Negócios
Sobre Cybersecurity Where You Are (audio)
Welcome to audio version of “Cybersecurity Where You Are,” the podcast of the Center for Internet Security® (CIS®). Cybersecurity affects us all, so join us on Wednesdays as Sean Atkinson, CISO at CIS; Tony Sager, SVP & Chief Evangelist at CIS; and Ed Skoudis, President of the SANS Technology Institute discuss trends and threats, explore security best practices, and interview experts in the industry. Together, we’ll clarify these issues, Creating Confidence in the Connected World®. Subscribe to the video version of our podcast here: https://fast.wistia.net/embed/channel/0l9fss300m?wchannelid=0l9fss300m.
Site de podcastOuça Cybersecurity Where You Are (audio), Jota Jota Podcast e muitos outros podcasts de todo o mundo com o aplicativo o radio.net

Obtenha o aplicativo gratuito radio.net
- Guardar rádios e podcasts favoritos
- Transmissão via Wi-Fi ou Bluetooth
- Carplay & Android Audo compatìvel
- E ainda mais funções
Obtenha o aplicativo gratuito radio.net
- Guardar rádios e podcasts favoritos
- Transmissão via Wi-Fi ou Bluetooth
- Carplay & Android Audo compatìvel
- E ainda mais funções


Cybersecurity Where You Are (audio)
Leia o código,
baixe o aplicativo,
ouça.
baixe o aplicativo,
ouça.
Cybersecurity Where You Are (audio): Podcast do grupo































