Cybersecurity Where You Are (audio)
Center for Internet Security

Último episódio
202 episódios
- In episode 202 of Cybersecurity Where You Are, Sean Atkinson and Ed Skoudis sit down with Rob T. Lee, Chief of Research & Chief AI Officer at the SANS Institute. Together, they explore how the implications of multiple 2026 sandbox escapes of artificial intelligence (AI) models are starting to delineate AI security and cybersecurity.
Here are some highlights from our episode:
02:00. The historical context of one AI model's 2026 sandbox escape
03:26. The impact of ethics, guardrails, and misconfigurations in an AI containment breach
06:08. Why context matters when talk of AI models "going rogue" surfaces
11:49. How history helps us to delineate AI security and cybersecurity
13:47. A new skill and mindset to match our refined AI risk understanding
15:43. Rules and cybersecurity implementation as a possible way forward
19:04. The double-edged sword of restricting access to open-weight models
23:25. Recommendations for keeping up with what's changing in the AI security space
25:51. Rob's advice: To learn how to defend a thing, try learning how to build it first
28:23. AI governance and seeing through the "slop" to informed conversation
29:54. The use of AI to learn more about and discuss AI security for years to come
Resources
OpenAI says its AI technology acted on its own in an ‘unprecedented’ hack of another company
Pacing model development in an era of cyber-critical capabilities
Black Hat USA 2026 | The 'Breaking' News: The OpenAI–Hugging Face Incident
Episode 193: AI Security and Responsibility in EO 14409
The AI Daily Brief — Daily AI News & Analysis
AI Playbooks for SLTT Cybersecurity Leaders
SANS Cybersecurity Summits
SANS NewsBites
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org. - In episode 201 of Cybersecurity Where You Are, Sean Atkinson and Ed Skoudis sit down with William Wright, Chief Executive Officer of Closed Door Security. Together, they reflect on the evolution of penetration testing, including the impact on pentesting from artificial intelligence (AI).
Here are some highlights from our episode:
01:03. How things have changed since William's and Ed's first pentests
09:02. Community: A defining element of Capture The Flag (CTF) events
14:47. Industry concerns over the "death" of CTFs and "cheating" by artificial intelligence (AI)
17:00. Opportunities to take CTFs to the next level in the age of AI
20:18. Pentesting vs. vulnerability scanning: Why terminology matters
25:43. The advent of autonomous AI tools and what they could mean for vulnerability scanning
29:07. Why continuous improvement in cybersecurity doesn't always require AI
Resources
Closed Door Security
Episode 189: The Present and Future of AI-enabled Pentesting
SANS Cyber Ranges
Top External Network Risks And How to Fix Them
Penetration Testing
Vulnerability Assessments
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org. - In episode 200 of Cybersecurity Where You Are, Sean Atkinson, Tony Sager, and Ed Skoudis sit down with Frank Reeder, Co-Founder and Founding Chair of the Center for Internet Security® (CIS®). Together, they reflect on how Alan Paller's vision continues to drive CIS forward. In the spirit of that vision, this milestone episode also marks a new chapter for the podcast: Ed Skoudis joins as co-host of Cybersecurity Where You Are.
Here are some highlights from our episode:
01:09. The two complementary missions of CIS
02:55. Three defining moments that have shaped CIS into the organization it is today
08:10. The story of naming CIS
10:31. How CIS and SANS advance Alan Paller's vision of bringing people together
13:50. Personal anecdotes of Alan Paller as a connector of people
15:45. "What would Alan do?" A question that continues to guide CIS and SANS
22:00. How CIS security best practices are emblematic of helping others
27:12. CIS's "secret sauce" as a trusted, neutral platform for cybersecurity collaboration
29:53. How CIS can continue to embody Alan Paller's philosophy into the future
37:47. A special announcement: Ed Skoudis as a new co-host on the podcast
Resources
CIS Benchmarks® List
CIS Critical Security Controls®
Multi-State Information Sharing and Analysis Center®
Episode 114: 3 Board Chairs Reflect on 25 Years of Community
Alan Paller Laureate Program
SANS Difference Makers Awards
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org. - In episode 199 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager sit down with Chris Painter, Chair of the Risk Committee and Board Member at the Center for Internet Security® (CIS®). Together, they discuss how chief information security officers (CISOs) can support the work of translating cyber risk into business decisions by Boards.
Here are some highlights from our episode:
00:50. Introductions to Chris
01:36. The single biggest translation error Chris has seen CISOs make
07:38. Cyber risk quantification: An opportunity to go beyond translation for Boards
09:25. How ransomware changed Boards' understanding of cyber risks' business impact
10:45. The value of tabletop exercises (TTX) and other simulations in creating shared language
13:26. Recommendations on how to make the most of a TTX
18:37. Risk modeling and how artificial intelligence (AI) complicates probability estimations
21:51. "Pressure" (2026) as an illustration of making good, not 100% accurate, estimations
22:58. How growing public awareness of cyber is reshaping CISOs' conversations with Boards
25:55. The importance of walking Boards through risk mitigation steps with AI as an example
29:31. A recommendation for how CISOs can learn what directors care about
30:15. From "wizardry" to familiarity: An ongoing generational shift around cyber
Resources
Episode 183: The Role of CISO in Supporting Risk Translation
Episode 187: The Role of a CISO as a Strategic Storyteller
Episode 192: How Leaders Balance Expertise and Communication
How Risk Quantification Tests Your Reasonable Cyber Defense
CIS RAM (Risk Assessment Method)
Leveraging Generative Artificial Intelligence for Tabletop Exercise Development
CIS Controls v8.1 Incident Response Policy Template
You Have a Cybersecurity Incident. Now What?
Prompt Injections: The Inherent Threat to Generative AI
"Pressure" | Official Website | 29 May 2026
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org. - In episode 198 of Cybersecurity Where You Are, Sean Atkinson discusses artificial intelligence (AI) and privacy from a risk-based cybersecurity perspective. Together, he explores how organizations and individuals can assess AI risk, apply governance frameworks, evaluate third-party AI services, and balance innovation with due diligence.
Here are some highlights from our episode:
00:41. Framing the conversation around AI, privacy, and risk-based controls
02:22. Due diligence and ethical considerations around AI products and services
03:14. Data minimization and transparency as foundations for AI privacy
04:46. Privacy impact assessments as a way to understand AI data collection and use
05:42. AI governance and the tension between implementation velocity and risk management
10:08. The use of existing data flows and controls in AI assessments
11:57. Algorithmic transparency and the challenge of understanding AI decision making
13:47. Standards, frameworks, and data sovereignty in AI privacy governance
15:12. Encryption, anonymization, tokenization, and federated learning as privacy safeguards
16:40. The need to shift stakeholder input left in AI development and deployment lifecycles
19:13. Building literacy around security, data management, privacy, and AI risk
23:40. The value of cross-functional and written assessment criteria for AI risk
26:21. A call to action for keeping pace with AI privacy and and innovation risk
Resources
CIS Controls v8.1.2 AI Security Guidance Workbook
Episode 105: Context in Cyber Risk Quantification
Service Provider Management Policy Template for CIS Control 15
EU AI Act: first regulation on artificial intelligence
AI Risk Management Framework
IAPP AI Governance Center
Episode 120: How Contextual Awareness Drives AI Governance
Secure by Design v1.1 A Guide to Assessing Software Security Practices
Reasonable Cybersecurity
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
Mais podcasts de Negócios
Podcasts em tendência em Negócios
Sobre Cybersecurity Where You Are (audio)
Welcome to audio version of “Cybersecurity Where You Are,” the podcast of the Center for Internet Security® (CIS®). Cybersecurity affects us all, so join us on Wednesdays as Sean Atkinson, CISO at CIS; Tony Sager, SVP & Chief Evangelist at CIS; and Ed Skoudis, President of the SANS Technology Institute discuss trends and threats, explore security best practices, and interview experts in the industry. Together, we’ll clarify these issues, Creating Confidence in the Connected World®. Subscribe to the video version of our podcast here: https://fast.wistia.net/embed/channel/0l9fss300m?wchannelid=0l9fss300m.
Site de podcastOuça Cybersecurity Where You Are (audio), The Diary Of A CEO with Steven Bartlett e muitos outros podcasts de todo o mundo com o aplicativo o radio.net

Obtenha o aplicativo gratuito radio.net
- Guardar rádios e podcasts favoritos
- Transmissão via Wi-Fi ou Bluetooth
- Carplay & Android Audo compatìvel
- E ainda mais funções
Obtenha o aplicativo gratuito radio.net
- Guardar rádios e podcasts favoritos
- Transmissão via Wi-Fi ou Bluetooth
- Carplay & Android Audo compatìvel
- E ainda mais funções


Cybersecurity Where You Are (audio)
Leia o código,
baixe o aplicativo,
ouça.
baixe o aplicativo,
ouça.
Cybersecurity Where You Are (audio): Podcast do grupo





























