Discover
Cybersecurity Where You Are (video)
Cybersecurity Where You Are (video)
Author: Center for Internet Security
Subscribed: 57Played: 1,973Subscribe
Share
© 2026
Description
Welcome to video version of “Cybersecurity Where You Are,” the podcast of the Center for Internet Security® (CIS®). Cybersecurity affects us all, so join us on Wednesdays as Sean Atkinson, CISO at CIS; Tony Sager, SVP & Chief Evangelist at CIS; and Ed Skoudis, President of the SANS Technology Institute discuss trends and threats, explore security best practices, and interview experts in the industry. Together, we’ll clarify these issues, Creating Confidence in the Connected World®. Subscribe to the audio version of our podcast here: https://fast.wistia.net/embed/channel/wbyhaw35xf?wchannelid=wbyhaw35xf.
207 Episodes
Reverse
In episode 207 of Cybersecurity Where You Are, Sean Atkinson makes the case for treating artificial intelligence (AI) not as software but as an ongoing trust relationship. He highlights the value of integrating best practices from regulations like the EU AI Act, walks through the three stages of an AI governance lifecycle, and explains how AI risk management fits into organizational governance, change management, and other business processes.Here are some highlights from our episode:01:16. The trust component of AI governance02:02. A need to align to regulatory best practices and bring them into AI risk management03:47. Advice: Contextualize, don't generalize, your risks associated with AI use04:40. Common questions that lead to AI governance as a requirement06:59. Grounding an agile AI governance process on foundational principles07:46. How the "fortress" approach overlooks the relationship element of AI security09:51. A direct invitation: Listener feedback on AI governance thinking11:44. Evaluating trust and relationship in machine learning and generative AI14:04. The role of human oversight in realizing AI as a method that gets to a solution quicker14:53. AI governance boards: A potential solution to elevating AI literacy internally16:00. AI governance lifecycle: Three phases from current business processes to value generation18:55. Overview of the future of AI security23:16. The need for foundational security controls and AI-specific controls25:00. AI governance assessment: Why it needs to happen across the organization26:28. How AI governance ties into organizational governance29:49. Ethics and responsible AI practice29:57. Change management considerations with AI deployment30:35. A concluding call to action to get stronger togetherResourcesCIS Critical Security Controls®Episode 198: AI Privacy from a Risk-Based PerspectiveEpisode 122: DeepSeek AI Security and Utility ConsiderationsEpisode 120: How Contextual Awareness Drives AI GovernanceAI Playbooks for SLTT Cybersecurity LeadersCIS Controls v8.1.2 AI Security Guidance WorkbookGuide to Implementation Groups (IG): CIS Critical Security Controls v8.1Mapping and Compliance with the CIS ControlsIf you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing [email protected].
In episode 206 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager speak with Julie Morris, Founder and Head of Thought Leadership at Persona Media, about why trust and influence have become survival skills for today's CISOs. Julie breaks down three types of organizational power, explains why the "good guys" resist the language of influence, and offers a practical starting point for anyone who's ever felt like PowerShell was the only power they understood.Here are some highlights from our episode:02:13. From old to new: A shift in how trust and influence factor into organizational structures04:24. The three kinds of power in an organization: hard, soft, and network09:59. Wise advice: Build your personal and professional network first11:07. How influence multiplies confidence with network power12:03. Inertia, fear, and status quo: overcoming the emotional reactions that oppose change18:12. How Sean uses the power of "slow down," not "no," to support AI transformation20:49. Why good thought leadership starts with empathy and self awareness24:32. Building organizational processes that "trigger" a change in CISOs' trust and influence26:30. Hugging Face as an example of how triggering moments become lessons27:42. What Tony Soprano has to do with measuring trust and influence30:47. Reality check: Every information gap gets filled one way or another32:15. The power of community and shared ideas in figuring out thought leadership together36:09: Advice: Be in the "river" of your network to go where you want to go37:34. How understanding of shared values helps to overcome imposter's syndromeResourcesCIS Critical Security Controls®Episode 183: The Role of CISO in Supporting Risk TranslationEpisode 187: The Role of a CISO as a Strategic StorytellerEpisode 192: How Leaders Balance Expertise and CommunicationEpisode 199: Translating Cyber Risk into Business DecisionsThe Myth of Mythos: What It Means For Information SecurityEpisode 202: Delineating AI Security and CybersecurityIf you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing [email protected].
In episode 205 of Cybersecurity Where You Are, Tony Sager speaks with Phyllis Lee, VP of SBP Content Development at the Center for Internet Security®(CIS®), and Steve Lipner, Executive Director of SAFECode. Together, they discuss how an updated document from CIS and SAFECode gives concrete guidance on what artificial intelligence (AI) means for your Secure by Design process.Here are some highlights from our episode:02:17. A refresher on making Secure by Design digestible for end organizations02:57. Distillation and prescriptive guidance: The value provided by CIS06:53. An overview of Butler Lampson's "Gold Standard of Security"07:03. How a shift in approach to Secure by Design led to the founding of SAFECode09:42. The importance of verification requirements for what developers have done12:54. A product of CIS pragmatism: Prioritization relative to the development environment20:06. Artifacts as evidence of secure software development at work30:15. How the updated document provides guidance around AI30:45. What AI creates instead of new classes of vulnerabilitiesResourcesCIS Critical Security Controls® (CIS Controls®)Secure by DesignSecure by Design v1.1 A Guide to Assessing Software Security PracticesTurning Secure Software Development into a Measurable PracticeCIS and SAFECode Release Secure by Design v1.1: A Guide to Assessing Software Security PracticesEpisode 164: Secure by Design in Software DevelopmentCIS Critical Security Control 16: Application Software SecurityGuide to Implementation Groups (IG): CIS Critical Security Controls v8.1Episode 200: Alan Paller's Vision and Our Next ChapterFrom Prompts to Protocols: The Security Blueprint for Enterprise AIMythos AI: What Actually Matters for Cybersecurity LeadersIf you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing [email protected].
In episode 204 of Cybersecurity Where You Are, Sean Atkinson speaks with Ryan Winmill, Chief Security Officer and Vice President of FIFA World Cup Boston, and John Cohen, Executive Director of the Office of Strategic Programs and Initiatives at the Center for Internet Security® (CIS®). Together, they discuss how FIFA World Cup 2026 (FWC26) — secured through an unprecedented tripartite governance framework, $625 million in U.S. Congressional funding, and real-time intelligence that stopped a swatting attempt at the finals — set a new standard for proactive event security worldwide.Here are some highlights from our episode:01:18. The "unprecedented" governance framework created for FWC2603:53. The role of CIS as a force multiplier for FIFA, host regions, and other partners11:00. Why you can't trust the person with an ego in large-scale event security planning13:23. How the threat environment evolved over the previous three World Cup tournaments17:23. A new bar for proactive event security going forward18:43. How CIS provided quality control that helped to mitigate swatting calls during FWC2621:55. Unique approaches used by host regions to better understand the World Cup fanbase23:15. How counterfeit FIFA volunteer uniforms triggered a cross-city credentialing response26:46. Recommendations for future large-scale event host cities30:19. Ryan's recommendation to future host cities: "Call CIS before you get started"ResourcesSpecial Event Risk Analysis & Advisory ServicesEpisode 196: Securing FIFA World Cup 2026 CollaborativelyInside the Security Operation Behind the 2026 FIFA World Cup3 Lessons for Securing Large-Scale Events: Inside FIFA World Cup 2026Securing FIFA World Cup 2026 With a Collective Defense ApproachIf you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing [email protected].
In episode 203 of Cybersecurity Where You Are, Sean Atkinson speaks with Pavlina Pavlova, Founder of Critical Cyber. Together, they discuss how Pavlina started Critical Cyber to go beyond the data and give voice to the human impact of cyber attacks, from ransomware hitting hospitals to cyber tactics targeting civilians in active conflict zones.Here are some highlights from our episode:00:44. How Pavlina's work covering the impact of cyber attacks on Ukrainian critical infrastructure led to Critical Cyber03:13. How Critical Cyber works with cyber attack victims, responders, and other audiences04:08. Countering the tendency, even among cybersecurity experts, to sanitize cyber attacks' human impact08:57. The use of storytelling with those impacted by cyber attacks to drive policy changes15:02. Why cyber attacks in some sectors are underreported19:01. Critical Cyber's mission of combining testimony, research, and expert collaboration24:51. Where Critical Cyber is and where it's looking to goResourcesCritical CyberCybersecurity for Critical InfrastructureEpisode 202: Delineating AI Security and CybersecurityRecent Water Utility Attacks Offer a Blueprint for ResilienceIf you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing [email protected].






