DiscoverThe InfoSec Control Room
The InfoSec Control Room
Claim Ownership

The InfoSec Control Room

Author: Taher Amine ELHOUARI

Subscribed: 0Played: 0
Share

Description

The InfoSec Control Room is a podcast by Taher Amine ELHOUARI about cybersecurity, governance, risk, compliance, resilience, and CISO-level decision-making.

This show goes beyond buzzwords, checklists, and surface-level security advice. Each episode explores the gap between what organizations believe they have in place and what actually works when incidents happen, audits begin, regulators ask questions, or leadership needs to make risk-based decisions.

Hosted from the perspective of a CISO/DSSI, cybersecurity governance practitioner, auditor, advisor, speaker, and community builder, The InfoSec Control Room covers practical topics across information security, GRC, CISO leadership, ISO standards, cyber resilience, privacy, incident response, CSIRT operations, security awareness, regulatory expectations, and lessons from the field.

The core idea is simple: most organizations do not have a security problem. They have a governance problem that manifests as security.

This podcast is for CISOs, security leaders, GRC professionals, auditors, consultants, executives, aspiring cybersecurity leaders, and practitioners who want clearer thinking, stronger controls, and governance that actually works.

No noise. No checkbox compliance. No fake maturity.

Just practical conversations on how security is governed, controlled, measured, and improved.

https://www.TaherAmine.org/

34 Episodes
Reverse
Taher Amine ELHOUARI explores why outsourcing a service does not outsource the associated risk, covering supplier dependency, shared responsibility, third-party access, contracts, incident handling, concentration risk, offboarding, and the internal capability needed to govern providers effectively.
Taher Amine ELHOUARI explores cyber resilience beyond prevention, examining how organizations can keep critical services functioning, manage dependencies, recover effectively, adapt during disruption, and improve after failures and incidents.
Taher Amine ELHOUARI explores why ISO/IEC 27001 certification should be the result of a functioning ISMS rather than the end goal, and examines risk ownership, internal audit, corrective action, management review, control implementation, and continuous improvement beyond audit day.
Taher Amine ELHOUARI explores why cybersecurity dashboards often overwhelm boards with activity instead of helping them make decisions, and explains how executive reporting should connect cyber risk, uncertainty, business impact, priorities, and required leadership action.
In EP009 of The InfoSec Control Room, I look beyond the simple statement, “We have a CSIRT,” and ask the question that actually matters: what can that team really do when something serious happens?A CSIRT can exist on the organization chart, have assigned staff, procedures, tooling, and even a dedicated mailbox, while still being poorly prepared for a real incident. Readiness comes from much more practical things: knowing exactly what the team is responsible for, who it serves, how people reach it, what happens outside business hours, what access responders already have, how cases are handed over, how other departments work with the team, and where outside help is needed.This episode looks at the difference between a CSIRT that exists and one that can actually function under pressure. I discuss service boundaries, availability, access to systems and logs, case management, practical exercises, relationships with legal and business teams, communication during uncertain situations, team skills, external support, incident closure, lessons learned, and the danger of depending too heavily on a few individuals who hold everything together.I also explore why a CSIRT should not simply process incidents and move on. A strong response team notices patterns, exposes recurring weaknesses, feeds lessons back into the organization, and helps improve the environment that keeps producing those incidents.One of the main ideas from EP009 is simple: a CSIRT is not ready because management created one. It is ready when people know how to use it, when the team knows what it owns, when it can reach the right systems and people, and when it can work effectively under pressure.If you work in CSIRT, SOC, DFIR, SecOps, cybersecurity leadership, IT operations, GRC, risk, audit, business continuity, or incident management, this episode is designed to challenge the difference between having a team and having a real response capability.
loading
Comments