ISACA Podcast: Recent Episodes

ISACA Podcast

The ISACA Podcast gives you insight into the latest regulations, trends and threats experienced by information systems auditors and governance and security professionals. Whether you are beginning your career or have decades of experience, the ISACA Podcast can help you be better equipped to address industry challenges and embrace opportunities.

View Details

Containers run much of the software we depend on, and many are shipped with security problems that no one noticed. Traditional container scanning tools can miss important vulnerabilities, insecure configurations, embedded secrets, and risky Dockerfile patterns before they reach production.

In this episode, ISACA’s Adedayo Ojo, Principal, Emerging Technologies and Professional Practices, Research Development, speaks with Advait Patel, Senior Site Reliability Engineer at Broadcom, Docker Captain, and Google Developer Expert in Google Cloud, about why traditional container scanning misses so much and what it takes to identify the issues that matter most.

Advait shares lessons from running containers at scale on a large cloud platform and explains how he built DockSec, an open-source tool that uses AI to identify insecure Dockerfile patterns, embedded secrets, and misconfigurations that signature-based scanners tend to overlook. The conversation offers practical guidance that developers and security teams can apply immediately, along with an honest look at where AI can strengthen container security—and where it cannot.

Related Resources & Stay Connected

Explore DockSec on GitHub: Review the open-source DockSec project, explore its features, and learn how it uses AI to identify insecure Dockerfile patterns, embedded secrets, and container misconfigurations.
https://github.com/OWASP/DockSec

Learn More About DockSec from OWASP: Discover more about the DockSec project, its approach to container security, and how it helps developers identify risks that traditional signature-based scanners may miss.
https://owasp.org/DockSec/

Connect with Advait Patel on LinkedIn: Follow Advait for insights on container security, cloud infrastructure, site reliability engineering, Docker, and AI-powered security.
https://www.linkedin.com/in/advaitpatel93/

Explore Advait Patel’s GitHub: View Advait’s open-source projects, technical work, and contributions to cloud and container security.
https://github.com/advaitpatel

Explore More ISACA Podcast Episodes: Dive deeper into cybersecurity, governance, risk, privacy, and emerging technology insights.
https://www.isaca.org/resources/news-and-trends/isaca-podcast-library

Subscribe to ISACA on YouTube: Stay ahead with expert interviews, industry analysis, and cybersecurity leadership insights.
https://www.youtube.com/@IsacaHq

Don’t forget to like, comment, and subscribe for more conversations shaping the future of IT, cybersecurity, governance, risk, and emerging technology.

View Details

As threats have evolved, so too has the approach to modern identity security. A privilege-centric approach must be adopted to address this evolution. Identity management for all accounts within an organization must mature to meet the demands of the cloud, nonhuman identities (NHIs), agentic AI, and modern attack vectors. Your strategy must now manage and mitigate not only traditional privileged access (root and administrator accounts), but also attacks targeting modern identities with paths to privileged access.

These paths to privilege remain one of the most valuable targets for cybercriminals because many organizations continue to defend their environments with fragmented or siloed security strategies and solutions. Security gaps and risks exist across endpoints, cloud environments, SaaS applications, third-party access, and now agentic AI and NHIs, making today's threat landscape more complex than ever.

In this episode, ISACA's Donnie Carpenter, Principal, Information Security and Professional Practices Research Development, speaks with Christopher Hills, Chief Security Strategist at BeyondTrust, about the evolution of identity security and why organizations must rethink how they protect privileged access in today's rapidly changing technology landscape.

Related Resources & Stay ConnectedLearn more about BeyondTrust: Discover how BeyondTrust helps organizations protect identities, manage privileged access, and reduce cyber risk across cloud, endpoint, SaaS, and hybrid environments.
BeyondTrust

Additional Resources from BeyondTrust:

  • Shadow AI Governance: How to Detect Shadow AI Governance
  • Microsoft Vulnerability Report: Microsoft Vulnerability Report

Explore More ISACA Podcast Episodes: Dive deeper into cybersecurity, governance, risk, and emerging technology insights.
ISACA Podcast Library

Subscribe to ISACA on YouTube: Stay ahead with expert interviews, industry analysis, and cybersecurity leadership insights.
ISACA YouTube Channel

Don't forget to like, comment, and subscribe for more conversations shaping the future of IT, cybersecurity, governance, and risk.

View Details

FedRAMP 20x is redefining what federal compliance looks like. Designed to modernize the authorization process, this bold initiative is moving cybersecurity governance toward automation while reducing the lengthy timelines and documentation burdens that have traditionally defined FedRAMP.

Join host Safia Kazi as she speaks with Jake Bernardes, CISO at Anecdotes, about what FedRAMP 20x is, why it matters, and how this transformation will reshape governance, risk, and compliance (GRC) automation. Together, they explore what organizations can expect as federal compliance evolves and what the changes mean for enterprise customers navigating the future of cybersecurity governance.

Related Resources & Stay Connected

Learn more about Anecdotes: Discover how Anecdotes is helping organizations transform governance, risk, and compliance with AI-powered automation, continuous monitoring, and audit-grade data that enables faster, smarter, and more scalable GRC programs. https://www.anecdotes.ai/

Explore More ISACA Podcast Episodes: Dive deeper into cybersecurity, governance, risk, and emerging tech insights. https://www.isaca.org/resources/news-and-trends/isaca-podcast-library

Subscribe to ISACA on YouTube: Stay ahead with expert interviews, industry analysis, and cybersecurity leadership insights. https://www.youtube.com/@IsacaHq

Don’t forget to like, comment, and subscribe for more conversations shaping the future of IT and cybersecurity.

View Details

Technology is transforming how organizations operate — and IT audit and assurance must evolve alongside it. In this episode, Paul Phillips sits down with Mary Carmichael, contributor to the newly updated IT Audit and Assurance Framework (ITAF 5), to discuss how audit professionals can adapt to today’s increasingly complex digital enterprise.

Together, they explore the major shifts shaping modern audit, including AI governance, digital ecosystems, automation, evolving risk landscapes, cloud environments, and the growing need for stronger data literacy within audit teams. Mary also shares practical guidance on how organizations can begin modernizing their audit approach without overhauling everything overnight.

Key discussion topics include:

  • The evolution from traditional control testing to outcome-based assurance
  • Why audit teams need stronger technology and data capabilities
  • AI governance, automation, and digital risk considerations
  • Building practical audit modernization strategies
  • How ITAF 5 supports governance, credibility, and audit relevance in modern enterprises

Whether you're an auditor, governance professional, cybersecurity leader, or risk practitioner, this conversation provides valuable insight into the future of audit and assurance in a technology-driven world.

Related Resources & Stay Connected

Download ITAF 5: https://www.isaca.org/resources/itaf-is-a-framework

Explore More ISACA Podcast Episodes: Dive deeper into cybersecurity, governance, risk, and emerging tech insights. https://www.isaca.org/resources/news-and-trends/isaca-podcast-library

▶️Subscribe to ISACA on YouTube: Stay ahead with expert interviews, industry analysis, and cybersecurity leadership insights. https://www.youtube.com/@IsacaHq

🔔 Don’t forget to like, comment, and subscribe for more conversations shaping the future of IT audit, governance, risk, and cybersecurity.

ITAudit #ITAF5 #AuditAndAssurance #Cybersecurity #Governance #RiskManagement #AI #ISACA #DigitalTransformation #InternalAudit

View Details

In today’s evolving cybersecurity landscape, strong leadership is the foundation of an effective security posture. Yet many agencies struggle when a “compliance mentality” takes hold, where meeting minimum requirements overshadows proactive risk management.

In this ISACA Podcast episode, Lisa Cook, ISACA's Principal Research Analyst, sits down with Patrick Bevill, Chief Information Security Officer (CISO) at the Federal Retirement Thrift Investment Board, to explore how agency leaders can establish a strong tone at the top and foster a culture that prioritizes security resilience over check-the-box compliance.​

Related Resources & Stay Connected

Learn more about Williams Adley: Discover how Williams Adley helps organizations navigate audit, assurance, cybersecurity, risk, and advisory services with a focus on integrity and innovation. https://www.williamsadley.com/

Explore More ISACA Podcast Episodes: Dive deeper into cybersecurity, governance, risk, and emerging tech insights. https://www.isaca.org/resources/news-and-trends/isaca-podcast-library

Subscribe to ISACA on YouTube: Stay ahead with expert interviews, industry analysis, and cybersecurity leadership insights. https://www.youtube.com/@IsacaHq

Don’t forget to like, comment, and subscribe for more conversations shaping the future of IT and cybersecurity.

View Details

Compliance does not have to be a stressful, last-minute scramble. In this episode, we explore how AI-driven control and automation transforms identity security from a costly headache into an audit-ready powerhouse. We break down the steps to simplify your regulatory processes, reduce operational costs, and enhance security by effectively managing human and non-human identities.

You will learn why gaining centralized visibility is your crucial first step, how to instantly spot and remediate risky orphan accounts, and the secret to running seamless, automated access certifications. Join our identity security experts as they share practical strategies to strengthen your defenses without draining your IT resources. Expect actionable tips that will help you build a sustainable, AI-powered compliance process tailored to your organization.

Related Resources & Stay Connected

  • Learn more about SailPoint:
    Explore how SailPoint is helping organizations modernize identity security, strengthen governance, and simplify compliance in an AI-driven world.
    https://www.sailpoint.com/
  • Explore More ISACA Podcast Episodes:
    Dive deeper into cybersecurity, governance, risk, and emerging tech insights.
    https://www.isaca.org/resources/news-and-trends/isaca-podcast-library
  • Subscribe to ISACA on YouTube:
    Stay ahead with expert interviews, industry analysis, and cybersecurity leadership insights.
    https://www.youtube.com/@IsacaHq

Don’t forget to like, comment, and subscribe for more conversations shaping the future of IT and cybersecurity.

View Details

Women in cybersecurity leaders share their stories and career advice in this SheLeadsTech fireside chat celebrating International Women’s Day.

In celebration of International Women’s Day and Women’s History Month, ISACA’s SheLeadsTech initiative brings together three inspiring leaders in cybersecurity for a special fireside conversation.

Join Debbie Lew and Jo Stewart-Rattray, both ISACA Hall of Fame inductees and recipients of the Eugene Frank Founders Award, as they sit down with Gail Coury, who will be inducted into the ISACA Hall of Fame in 2026.

In this warm and engaging discussion, they reflect on their journeys into cybersecurity, the evolving role of women in technology, and the power of mentorship, leadership, and community in shaping the future of the profession.

In this episode, they discuss:
• Their personal paths into cybersecurity and IT
• How opportunities for women in tech have evolved over time
• Lessons learned from leadership and service within the ISACA community
• Advice for the next generation of women entering the field

The conversation wraps up with a fun rapid-fire round that offers a glimpse into the personalities behind these accomplished careers.

Whether you're an experienced professional or just beginning your journey in technology, this fireside chat offers inspiration, insight, and encouragement from women helping shape the future of cybersecurity.

🔗 Learn more about ISACA’s SheLeadsTech initiative:
https://www.isaca.org/membership/sheleadstech

🎧 Explore more ISACA Podcasts:
https://www.isaca.org/resources/news-and-trends/isaca-podcast-library

📺 Subscribe to ISACA on YouTube:
https://www.youtube.com/@IsacaHq

WomenInCybersecurity

SheLeadsTech

WomenInTech

View Details

On this episode of the ISACA Podcast, host Chris McGowan is joined by Amit Patel, Senior Vice President at Consulting Solutions, to explore one of the most underestimated threats in cybersecurity: the human element. From accidental errors to insider breaches, they discuss why employee behavior is at the heart of most security incidents—and what organizations can do about it. Amit shares insights on how ongoing training, strong policies, and AI-powered tools like behavior analytics can help bridge the gap between tech and human responsibility. Whether you're a cybersecurity leader or simply navigating today’s digital landscape, this episode offers practical strategies to strengthen your organization’s human-centric security posture.

📚 Related Resources & Stay Connected📖 Read the full article:
Humans Are IT Security’s Weakest Link
https://www.isaca.org/resources/news-and-trends/industry-news/2024/humans-are-it-securitys-weakest-link

🎙 Explore More ISACA Podcast Episodes:
Dive deeper into cybersecurity, governance, risk, and emerging tech insights.
https://www.isaca.org/resources/news-and-trends/isaca-podcast-library

▶️ Subscribe to ISACA on YouTube:
Stay ahead with expert interviews, industry analysis, and cybersecurity leadership insights.
https://www.youtube.com/@IsacaHq

🔔 Don’t forget to like, comment, and subscribe for more conversations shaping the future of IT and cybersecurity.

View Details

You’re listening to Secure Your Privates™ brought to you by ISACA Podcasts - where security meets privacy, risk meets reality, and governance finally makes sense. We’re here to cut through the noise and get real about what’s actually happening in cyber. The no-BS podcast on security and privacy. We talk about what’s broken, what’s working, and what nobody’s telling you in between.

View Details

In this ISACA Podcast episode, host Safia Kazi, Principal Research Analyst – Privacy, is joined by Dirk Schrader, VP of Security Research at Netwrix, to discuss how generative AI is revealing long-standing gaps in enterprise data security and governance.

This episode builds on insights from a recent ISACA webinar that explored how generative AI is exposing weaknesses in enterprise data security and governance. The discussion examines why many organizations lack visibility into where sensitive data resides and who can access it, particularly across hybrid and cloud environments. The conversation also addresses emerging risks introduced by AI tools, including non-human access and overexposed data. Listeners will gain practical, governance-focused guidance on how DSPM helps organizations assess risk, support compliance, and prepare data responsibly for AI initiatives.

Related Resources:

  • Watch the ISACA Webinar from the ISACA Virtual Summit 2025: “Securing Data in the Age of AI with DSPM”
    https://www.isaca.org/training-and-events/online-training/virtual-summits/ai-governance-strategies
  • Learn more from Netwrix:
    https://netwrix.com/en/resources/
  • Explore more ISACA Podcasts:
    https://www.isaca.org/resources/news-and-trends/isaca-podcast-library
  • ISACA on YouTube:
    https://www.youtube.com/@IsacaHq

View Details

Lauren Hasson is the Founder of DevelopHer, an award-winning career development platform. In this podcast, she'll share a bit about her background and give a sneak peek at her upcoming CPE-eligible event.

View Details

In this episode, ISACA's Lisa Cook engages with Yakir Golan, Executive Officer (CEO) and Co-Founder of Kovrr, to explore the critical role of Cyberrisk Quantification (CRQ) in enhancing organizational financial resilience. They discuss how CRQ solutions provide objective assessments of an organization's cybersecurity posture, enabling leaders to make informed decisions that align risk mitigation strategies with business objectives. The conversation also highlights the importance of translating cyberrisk exposure into monetary terms to facilitate high-level discussions and protect shareholder confidence.

Listen & Subscribe Catch this episode—and more—on the ISACA Podcast Library: https://www.isaca.org/resources/news-and-trends/isaca-podcast-library

or on your favorite podcast platform.

View Details

Ransomware remains one of the most formidable cybersecurity threats facing organizations worldwide.

In this episode of the ISACA Podcast, host Chris McGowan speaks with Netwrix endpoint protection expert Jeremy Moskowitz, who explains how ransomware infiltrates and cripples desktop environments. He explains cybercriminals' tactics to exploit social engineering and system misconfigurations to gain unauthorized access, offering actionable insights on the most effective prevention and mitigation strategies.

Additionally, Jeremy delivers practical advice that security teams can use to resist ransomware. He shares tips on safeguarding locally stored data, implementing robust backup solutions, enforcing strict access controls and system patching, and educating staff on common red flags associated with ransomware.

Listen & Subscribe to ISACA Podcast

Catch this episode—and more—on the ISACA Podcast Library
or on your favorite podcast platform.

Connect & Learn More about Netwrix

  • Netwrix Data Loss Prevention Solution: Learn more
  • Follow Netwrix on LinkedIn: Netwrix Corporation: Posts | LinkedIn
  • Additional Resources Provided by Netwrix:
    • CISA’s Ransomware Guidance
    • SANS Institute White Papers on Ransomware
    • NIST SP 800-61 Rev. 2 – Incident Handling Guide
    • Krebs on Security – Ransomware Articles

View Details

Cybersecurity and the role of internal audit, an urgent call to action: The forces driving business growth and efficiency contribute to a broad attack surface for cyber assaults. How is the end user protected with good service while not being compromised?

  • First Line includes internet, cloud, mobile, and social technologies, now mainstream, are platforms inherently oriented for sharing. Outsourcing, contracting, and remote workforces are shifting operational control.
  • Second line includes information and technology risk management leaders who establish governance and oversight, monitor security operations, and take-action as needed, often under the direction of the chief information security officer (CISO)
  • Third line of cyber defense—independent review of security measures and performance by the internal audit function. Internal audit should play an integral role in assessing and identifying opportunities to strengthen enterprise security. At the same time, internal audit has a duty to inform the audit committee and board of directors that the controls for which they are responsible are in place and functioning correctly, a growing concern across boardrooms as directors face potential legal and financial liabilities.

View Details

The prevalence of ransomware and the security concerns associated with AI have made the role of cybersecurity professionals vital for enterprise success. The complex security landscape can make cybersecurity jobs stressful, but enterprises can take steps to retain cybersecurity talent and ensure enterprise assets are protected. In this podcast, Justin Rende, founder and CEO at Rhymetec, shares insight on the top concerns for cybersecurity professionals, the most in-demand skills, and the impact of AI on cybersecurity.

View Details

Given the dynamic nature of cyberthreats and the ever-expanding digital ecosystem, authentication is more critical than ever. In this episode, ISACA director of professional practices and innovation discusses a new content piece titled, "Examining Authentication in the Deepfake Era" with author Dr. Chase Cunningham. Their conversation of the paper explores the evolution, current state, and future trajectory of authentication technologies.

View Details

Emerging healthcare technologies have the potential to revolutionize healthcare and accessibility-related concerns, but these advancements are not without risk. To maximize the value and minimize the harms associated with emerging health technologies, it is critical to address ethical, privacy, and societal concerns to ensure that these technologies help rather than hurt humanity.

In this ISACA Podcast, join Safia Kazi and Collin Bedder as they explore the applications and risks associated with emerging healthcare technologies.

View Details

SAP systems are treated differently than many other enterprise applications from a cybersecurity perspective. Most SAP security teams are siloed and left to meet security objectives on their own. Since SAP is so integral to organizations, it is unusual for SAP security objectives to not be on the radar of an existing 24/7 cybersecurity team executing response actions for Linux or Microsoft environments. SAP teams must be integrated w

SAP systems are treated differently than many other enterprise applications from a cybersecurity perspective. Most SAP security teams are siloed and left to meet security objectives on their own. Since SAP is so integral to organizations, it is unusual for SAP security objectives to not be on the radar of an existing 24/7 cybersecurity team executing response actions for Linux or Microsoft environments. SAP teams must be integrated with other cybersecurity groups within an organization to empower them with a security approach that unifies the entire enterprise landscape.

A chief information security officer (CISO) has many priorities, but when it comes to SAP environments, CISOs must fully understand how SAP applies to the IT enterprise and organizational environment to help them achieve all security goals. In addition, CISOs need to know their SAP team members personally so they can integrate them rather than contain them in silos. Finally, SAP must be secured to the same degree as other enterprise applications. When there is a Linux, Microsoft, or even a hybrid cloud incident, cybersecurity teams have a detailed plan of action upon which they are ready to act. SAP requires high-level consideration, or critical elements of the business will be vulnerable to malicious cyber actors—with no apparent response.

View Details

Many people are pondering whether generative artificial intelligence (AI) tool ChatGPT is a friend or a foe.

In this ISACA podcast episode, Camelot Secure Director of Solutions Engineering Zachary Folks discusses not only his view of how ChatGPT can be considered an evolution of the encyclopedia, but importantly how it is aiding cybersecurity professionals and the overall goal of enterprise security, as well as how cybercriminals who want to exploit it can leverage it as well. He believes the world is entering a time when AI is fighting AI, and security professionals must focus on feeding ChatGPT technology more relevant data faster than the adversary. Folk also addresses how AI is affecting social engineering and his predictions for upcoming AI developments.

View Details

Welcome to Episode 4 of "The Cyber Standard Podcast"!

Join host Ameet Jugnauth, Vice President of the London Chapter of ISACA, as he delves into the world of cybersecurity standardization. In this episode, titled "Becoming a License Body," Ameet is joined by esteemed guests Bryan Lillie, Strategic Technical Lead at the UK Cyber Security Council, and Peter Leitch, Co-Founder and Managing Partner at ANSEC. Together, they explore the intricacies of licensed bodies in shaping the cyber profession. Don't miss this insightful conversation!

Explore Further:

Delve deeper into the subject with additional resources provided in the episode description.

https://www.isaca.org/about-us/newsroom/press-releases/2023/uk-cyber-security-council-partners-with-isaca-for-audit-and-assurance-pilot-scheme

View Details

Welcome to Episode 3 of "The Cyber Standard Podcast"!

Join host Ameet Jugnauth, Vice President of the London Chapter of ISACA, as he delves into the essential aspects of applying for and assessing candidates in the cybersecurity field. In this episode, titled "How to Apply," Ameet is joined by distinguished guests Ethan Duffell, representing the UK Cyber Security Council, and Allan Broadman, Director of CyberAdvisor London. Together, they shed light on the launch of specializations and the significance of professional standards in the cybersecurity sector. Don't miss this insightful conversation!

Explore Further:

Delve deeper into the subject with additional resources provided in the episode description.

https://www.isaca.org/about-us/newsroom/press-releases/2023/uk-cyber-security-council-partners-with-isaca-for-audit-and-assurance-pilot-scheme

View Details

Traditional security questionnaires just aren't cutting it anymore.

Tune into this ISACA Podcast episode, Chris McGowan chats with VISO TRUST CEO and Co-founder, Paul Valente as they delve into the evolving landscape of Third-Party Risk Management (TPRM), exposing the limitations of current methods and exploring how emerging AI trends are shaping a more secure future and driving more effective third-party risk management programs.

To learn more about VISO Trust please go to https://visotrust.com/

View Details

Are you curious about how to maximize the strategic value and impact of your bug bounty program?

In this episode, you can learn how Adobe continuously develops and improves its bounty program to engage security researchers and hackers globally and improve its security posture from an adversary perspective.

In this ISACA Podcast, Chris McGown, ISACA's Information Security Professional Practices Principal, chats with Alex Stan, Product Security Engineer and member of the Product Security Incident Response Team (PSIRT), discusses the value of bug bounty programs and shares how you can develop a metrics-driven approach to enhance the internal security testing and detection capabilities of your organization.

Explore Further: Delve deeper into the subject with additional resources

https://blog.developer.adobe.com/adobe-announces-researcher-hall-of-fame-initiative-for-security-researchers-5e677286dbd6

https://blog.developer.adobe.com/researcher-q-a-aem-solution-architect-by-day-adobe-bug-bounty-hunter-by-night-aed39a4750e4

https://blog.developer.adobe.com/attention-security-researchers-level-up-your-skills-and-join-our-private-bug-bounty-program-2da9d5979d8b

https://blog.developer.adobe.com/adobe-recap-2023-ambassador-world-cup-final-four-df701e1a1b12

View Details

Tune in to the inaugural episode of "The Cyber Standard Podcast," “The Vision!”

Join host Ameet Jugnauth as he interviews Robin Lyons, ISACA Principal, IT Audit Professional Practices, and Annmarie Dann, Director of Professional Standards at the UK Cyber Security Council, in a compelling discussion about the standardization of specialisms in cybersecurity. Explore the Council's and ISACA's visions for the future, the significance of the Audit & Assurance specialism, and the collaborative efforts between the two organizations. Don't miss this insightful conversation that sets the stage for the podcast's journey into the world of cybersecurity standardization.

Explore Further: Delve deeper into the subject with additional resources provided in the episode description.

https://www.isaca.org/about-us/newsroom/press-releases/2023/uk-cyber-security-council-partners-with-isaca-for-audit-and-assurance-pilot-scheme

View Details

Getting dressed is a routine example of everyday life packed with choices. Should I wear pants or shorts? Do I need a sweater? Shoes or sandals? While we often make these choices subconsciously, even actions that don’t appear as choices include several microscopic risk-based calculations.

These judgments are executed based on some estimate of risk, and as known in the cybersecurity industry, what is believed to be safe today may no longer be safe tomorrow (or possibly even within the hour). Given this unique challenge, how do you establish a process that allows you to identify, analyze, prioritize, and treat security risks that are constantly evolving and where the threat is persistently adapting?

In this podcast, ISACA's Lisa Cook discusses with Adobe's Matt Carroll, Senior Manager of Technology Governance, Risk, and Compliance the risk methodology and practices his team has developed at Adobe that have helped the company rapidly measure security risk in a constantly changing landscape.

View Details

ISACA recently marked the 25th anniversary of Steve Ross’ ISACA Journal Information Security Matters column. Over the last quarter century, technology, security, and the workforce have evolved, while certain challenges remain the same.

In this ISACA Podcast episode, Safia Kazi speaks to Steve about how he started writing for the Journal, societal shifts in security perceptions, and how writing skills are invaluable for anyone in the security industry.

View Details

Organizations can no longer rely on legacy vulnerability management solutions to protect against even basic attacks. Instead, vulnerability management is just one small component in a unified continuous threat exposure management (CTEM) approach to securing an enterprise from malicious intruders and ransomware. In addition to vulnerability management, security around misconfigurations, patching, identity, software, external attack surfaces, and more must be included.

In this ISACA Podcast, Nanitor Chief Strategist Derek Melber explains that an organization can prevent breaches and ransomware by taking an asset-centric prioritized-security approach that includes all of these security areas.

For more ISACA Podcasts, visit www.isaca.org/podcasts

To learn more about Nanitor, please visit https://nanitor.com/

To view the Nanitor article, please click https://nanitor.com/resources/blog/cybersecurity/exploring-continuous-threat-exposure-management-ctem/

View Details

Software-as-a-Service (SaaS) providers continue to face increasing customer demand to attain security compliance certifications that demonstrate commitment to security, privacy, confidentiality, and more. Pursuing every national and international certification individually results in a repetitive cycle of ongoing walkthroughs, interviews, testing, and evidence requests (i.e., audits).

A central CCF can be considered a one-stop shop response to the complex alphabet soup of compliance standards on the market today.

In this ISACA Podcast episode, ISACA's Chris McGowan listens in as Zach Folk, Director of Solutions Engineering explains why having a central CCF can help various product engineering teams meet their security compliance needs and understand the level of effort required for each compliance certification.

View Details

In this ISACA Podcast episode, we’ll delve into how leveraging Agile concepts can mitigate common challenges neurodiverse auditors face in the workplace. Neurodivergent auditors can bring a fresh and dynamic energy to projects if given appropriate accommodation.

Join us as ISACA's Robin Lyons chats with Program External Audit IT Program Manager Amanda Tucker as they explore small changes that can significantly impact not only neurodiverse individuals on your team but the entire team itself.

View Details

With the increasing demand for audits and risk assessments, artifact requests will not be going away anytime soon. However, the burden these activities bring to the organization can be drastically reduced when audit and risk work together.

In this ISACA Podcast episode, Paul Phillips, Director of Event Content Development at ISACA, hosts Staff Governance, Risk, and Compliance Analyst Benjamin Bartz. Ben takes a deeper dive and elaborates on some of the must-haves for this partnership to live to its full potential.

View Details

Effective IT issue management is crucial for organizations to mitigate financial loss, reputational damage, and operational disruptions. Issue management tools streamline the process by tracking and resolving issues, while risk rating helps prioritize responses based on their impact and likelihood.

In this ISACA Podcast episode, ISACA's GRC Professional Practices Principal, Lisa Cook chats with IT Risk Manager, Eric Peck about why acknowledging and addressing high-risk issues with a structured approach empowers organizations to protect themselves and ensure compliance in today's complex regulatory landscape.

View Details

Software-as-a-Service (SaaS) providers continue to face increasing customer demand to attain security compliance certifications that demonstrate commitment to security, privacy, confidentiality, and more. Pursuing every national and international certification individually results in a repetitive cycle of ongoing walkthroughs, interviews, testing, and evidence requests (i.e., audits).

A central CCF can be considered a one-stop shop response to the complex alphabet soup of compliance standards on the market today.

In this ISACA Podcast episode, ISACA's Lisa Cook listens in as James Huang, Global Cloud Compliance Senior Manager, explains why having a central CCF can help various product engineering teams meet their security compliance needs and understand the level of effort required for each compliance certification.

View Details

Understanding product security risk starts before a single code line is written. Teams can discover threats to the architecture of a system early in the development life cycle with Threat Modeling. While it’s not a new concept, how do we transform traditional ways of Threat Modeling to meet the complexities of modern software development at scale?

In this ISACA Podcast episode, Chris McGowan chats with Lauren Strope, Manager of Application Security at Adobe. Lauren offers her expertise on strategies for scaling your program and provides unique perspectives on the future of Threat Modeling.

Learn more about Adobe at www.adobe.com

For more ISACA Podcasts, please visit https://www.isaca.org/resources/news-and-trends/isaca-podcast-library

View Details

Security risks introduced by vendors have become a top-of-mind concern for executives today, driven by recent supply chain incidents that have exposed organizations to operational and reputational risks.

A robust vendor security program is now a must, as it helps ensure compliance and proactively identifies and mitigates these risks throughout the vendor lifecycle. However, many vendor security teams today face an ever-growing backlog of security reviews, creating increased urgency and pressure for teams to maintain quality assessments. These reviews are often perceived as time-consuming in the procurement process, calling for a balance between meeting business demands and conducting thorough assessments to identify and isolate potential risks.

In this ISACA Podcast, Adobe's Manager of Vendor Security Nidhi Bandi shares about recent enhancements Adobe has made to calculate risk in the vendor space better and provides guidance on how you can stand up a strong vendor security program that balances procurement needs at your organization.

Learn more about Adobe at https://www.adobe.com/

Listen to more ISACA Podcasts at https://www.isaca.org/resources/news-and-trends/isaca-podcast-library

View Details

If we want people to bring their most creative, innovative selves to work, we need to cultivate a culture where inspiration is given, encouraged, and fostered.

In this ISACA Podcast, Kristi Hedges, executive coach, and leadership development consultant, speaker, and author, gives a sneak peek of her upcoming member-exclusive 'Cultivating Inspired Leaders, a CPE-eligible event. At the event, Kristi Hedges will provide a roadmap for building an inspired mindset for leaders, teams, and individuals.

Register for this ISACA event at https://www.isaca.org/membership/member-exclusive-speaker-series

View Details

Neurodiversity within cybersecurity offers many benefits but requires organizations and hiring managers to re-evaluate hiring practices and job descriptions typically structured for neurotypical applicants.

Join ISACA's Director of Professional Practices and Innovation as he hosts a conversation with a company helping to remove barriers and maximize the value neurodiverse talent brings to cybersecurity.

For more ISACA Podcast, go to https://www.isaca.org/resources/news-and-trends/isaca-podcast-library

View Details

Agile Scrum is a lightweight framework that promises to significantly improve internal audits by creating a mindset that generates stakeholder value through adaptive solutions for complex auditing problems. This mindset is needed as organizations face unprecedented changes and pressures in today's business landscape. Internal audits must keep leaders informed and aware of potential risks.

Such a mindset addresses some of the often-experienced auditing challenges such as a lack of senior management support, insufficient audit preparation time, difficult auditees and lack of time needed to write audit results.

Featuring special guest Thomas Bell and hosted by ISACA's Robin Lyons.

View Details

Chronic workplace stress can lead to burnout, which poses a significant risk to the mental health of busy professionals, such as auditors. But how can these professionals protect themselves from burnout? And how can their employers help them do so? If you are interested in learning the answers to these questions, then watch as ISACA’s Robin Lyons and Dr. Elena Klevsky, Assistant Professor of Accounting at the University of Tampa, discuss strategies for avoiding burnout.

Inspired by the Sustainable Model of Human Energy proposed by Ryan Quinn, Gretchen Spreitzer and Chak Fu Lam, these strategies focus on managing your personal energy by increasing resources, decreasing job demands, practicing skills and tasks, and monitoring energy.

Properly implementing these strategies has the potential to help busy professionals ensure that they have sufficient resources to meet their job demands, and, therefore, increase the likelihood that they feel energized instead of exhausted.

View Details

While users of technology are becoming more educated in how to avoid cyberattacks such as phishing, a distracted user might be more prone to missing signs of social engineering. This project explored whether users immersed in augmented reality applications were more inclined to fall for an on-screen text message that prompted familiarity (such as a friend calling in) or urgency (such as a warning to update software or be subject to an automatic device re-boot within a certain timeframe).

Featuring special guest Sarah Katz and hosted by ISACA's Collin Beder.

View Details

A comprehensive information security awareness program must be in place to ensure that employees are aware of and educated about the threats they may encounter at the workplace. The workforce needs to be prepared to know how to respond to these threats. It all starts with a risk assessment to identity the most critical of risks that need to be mitigated through preparedness. Making security a part of the organization’s culture reduces these risks to an acceptable level.

Featuring special guest Chris Madeksho and hosted by ISACA's Lisa Cook.

View Details

This podcast speaks about how an Information Systems (IS) Auditor can prepare for the Interruptions, Disruptions and the Emergence events that happen to the business and to technology.

Describing the features of Interruptions, Disruptions and Emergence events and distinguishing the differences between them, special guest Anantha Sayana outlines how the IS Auditor can prepare, react, and contribute to all the three.

Hosted by ISACA's Hollee Mangrum-Willis.

View Details

On this podcast, ISACA's Hollee Mangrum-Willis and special guest Cindy Baxter discuss the disparities between American communities and access to electronic health records. From there, they examine how key data insights from the ISACA community can help us all be healthier.

View Details

ISACA Digital Trust Advisory Council Members Anne Toth and Michelle Finneran Dennedy will discuss privacy concerns and priorities around emerging tech and the most critical considerations for ensuring strong digital trust. Hosted by ISACA's Safia Kazi. 

View Details

Scott Gould is the author of 'The Shape of Engagement: The Simple Process Behind how Engagement Works.' In this podcast, Scott gives a sneak peak at his upcoming member-exclusive, CPE-eligible event. Scott will discuss the essential frameworks for understanding and operationalizing engagement and building enduring connections with your networks and communities.

View Details

In security, aligning with product teams has never been more important, especially when outmaneuvering adversaries. To foster a truly productive and action-oriented cybersecurity culture, security teams must begin addressing their product engineering counterparts as customers they serve rather than entities they govern.

In this podcast, ISACA’s Chris McGowan listens in as Adobe’s Manager of Adversary Intelligence Gurpartap “GP” Sandhu provides unique insight into how he’s bringing intrapreneurship to life in product security through a key project that delivers actionable data that product teams can use to enhance their security posture more rapidly.

They’ll also discuss how his team is harnessing strong adversary focus using the power of data and share advice on how you can stay ahead of adversaries by better predicting their next move in the ever-changing threat landscape. Tune into this ISACA Podcast to learn more!

Check out more from Adobe, https://www.adobe.com/trust.html

For more ISACA podcasts, www.isaca.org/podcasts

View Details

We, as a society, have always lived by certain norms that are driven by our communities. These norms are enforced by rules and regulations, societal influence and public interactions. But is the same true for artificial intelligence (AI)?

In this podcast we discuss and explore the answers to some of the key questions related to the rapid adoption of AI, such as: What are the risks associated with AI and the impact of its increasing adaption within almost every industry? And, what role should we as IT Auditors should play in this fast changing technological landscape?

Hosted by ISACA's Hollee Mangrum-Willis and featuring special guest Jai Sisodia.

View Details

Organizations today struggle with vulnerability management. More specifically, remediating vulnerabilities in a timely manner poses a challenge. With vulnerability remediation backlogs growing at an alarming rate, what can organizations do to meet their established remediation timelines and to protect the organization from cybersecurity threats. Cybersecurity leader Ray Payano will discuss the exponential increase in published vulnerabilities, the lack of resources in cybersecurity to perform remediation and balancing remediation with reduced maintenance windows. These challenges contribute to organizations struggling with remediation backlogs. Ray will explain how calculating vulnerability risk can help organizations prioritize their vulnerabilities based on risk level to help determine the order in which vulnerabilities are addressed.

Hosted by ISACA's Chris McGowan.

View Details

Guests Jack Freund and Natalie Jorion discuss the need for additional data for quantitative risk analyses and methods to derive that data when it does not exist. They cover how this was done in the past and their updated method for interpolation of such data from record losses and other firmographic data. They end with a discussion of the role of model validation and how it can enable reliable risk management decision making.

Hosted by ISACA's Safia Kazi.

View Details

Are you wondering about the ever-changing landscape of IT compliance and risk management? Look no further. Hyperproof, a leading SaaS compliance operations provider, conducts an annual survey of over 1,000 IT risk, compliance, and security professionals to uncover their top challenges. Tune in to this exclusive episode to hear about the top five most important statistics uncovered from the survey and get an overview of how your industry peers are managing IT risk and compliance programs within their organizations.

We’ll cover:

● The top five findings from the survey

● How your peers are planning to handle compliance, audit management, and risk management in the midst of this year’s volatile economy

● What companies are doing differently in response to recent and highly publicized security breaches to avoid security lapses and compliance violations

Download Hyperproof’s 2023 IT Compliance and Risk Benchmark Report https://hyperproof.io/it-compliance-benchmarks/

View Details

The world of business has changed dramatically over the past few years. Our digital world is more connected than ever, leaving security and technology teams stretched even thinner. Privacy and data regulations are increasing on a state and national level, threat actors are learning and evolving, and cybersecurity has finally become a boardroom priority! Now that you have leadership’s attention- what will you do? If your answer is “risk management as usual”, that may be holding you back.

Traditional risk management approaches make a lot of promises, but most of them are myths. Do any of these sound familiar?

● You can make better-informed decisions by using a single platform.

● You can use automation to achieve continuous compliance.

● You can implement risk management by creating a risk register.

● You can use qualitative attributes to measure and assess risk.

In this episode, we’ll assess risk management myths and discuss how to establish scalable, quantifiable, and always-on risk management for the future.

Hosted by Lisa Cook and featuring special guest Megan Maneval.

View Details

Cyber threats are now a “clear and present danger” to most organizations, companies and governments of the world. A good cyber defense involves many, intricate layers. You can never have enough layers, just like you can never remove all the risk. In order for organizations to reduce as much risk as possible, in a rapidly shifting threat landscape, they must constantly make improvements. The threat groups are making rapid improvements and increasing their expertise at a steady rate. They are investing  in R&D and Zero-Day exploits. To offer a good defense, we must make progress at the same rate as the threat groups or we may fall behind, increasing risks and allowing the cyber world to become like the “wild-wild west.”

View Details

Conducting adequate preparation including risk assessments, assessing resource requirements and ensuring ongoing communication to harness both the benefits and to address the potential challenges faced when conducting hybrid or fully virtual audits.

View Details

This podcast is a practical discussion with two IT Internal Auditors, Frans Geldenhuys and Gustav Silvo, that have automated IT General Controls across their highly diversified and decentralized group. They will share some of the pitfalls they have experienced in their automation roll out and advise on how to avoid or manage these pitfalls with host, Robin Lyons.

Check out Frans and Gustav’s full ISACA Industry News article, “Seven Things to Know Before Automating IT General Control Audits,” http://www.isaca.org/automating-it-general-control-audits

For more ISACA Podcasts, https://www.isaca.org/podcasts

View Details

Organizational culture is crucial because it shapes behaviors and attitudes in the workplace, and this can have a profound impact on operations and overall success. However, it is sometimes difficult for CISOs and other infosec managers to fully understand their culture, because they are inside it constantly. This article shows how infosec managers can assess the organizational culture, by using a culture model to examine the behaviors, relationships, attitudes, values, and environment that the culture sustains.  It also discusses possible ways to lead a culture change initiative.

View Details

What are the primary risks associated with the adoption of emerging technologies, particularly during periods of high market volatility and changing governance requirements? We talk with Samuel Zaruba Smith, PhD(c) about his learnings from working in government regulated industries and emerging technology. We deep dive into the problems of business strategy, security, policy, social engineering ethics, and audits within a business environment of emerging technology systems such as Artificial Intelligence and Web3 decentralized technologies. Given the current business landscape of early 2023, changing market conditions and rapidly evolving governance concerns need to be top of the mind for all organizational leaders. Samuel provides insightful recommendations for improving your organizational structure and technology governance to create a more productive, inclusive, and ethical workplace. 

View Details

Get to know Chief Membership and Marketing Officer Julia Kanouse as she sits down with childhood best friend and ISACA VP Amanda Raible. The duo discuss everything from leadership to motherhood while competing in Mario Kart! Tune in!

View Details

There are literally thousands of VPN services on the market. Some are undeniably benign, but others offer a slate of features that are friendly to cyber criminals. Keeping your network safe from hackers requires you to understand the VPN market, and make decisions based on your company’s appetite for risk. Fortunately, by analyzing IP address data associated with these devices, security professionals can get access to a wealth of VPN contextual data that helps them distinguish between perfectly legitimate providers and those that turn a blind eye toward crime. In today’s world, it is vital for security professionals to know how to leverage IP address data and its contextual insights to protect enterprise networks.

View Details

Today, the pace of change across industries is quicker than ever before. Economic, political, and social unrest and a global climate crisis have placed unprecedented disruption and pressures on organizations looking to navigate a rapidly changing environment.

Firms are being out-innovated and entire industries are being disrupted in a matter of months or years, as opposed to decades. Shifting regulations, data as an asset, dynamic customer behavior and employee expectations of continued flexibility in a more virtual workplace add to the challenge.

Technology risk and compliance needs to adjust to this new reality. The strategy and value of an organization’s technology risk management are becoming essential to build and secure stakeholder trust. That means moving closer to the point where the risk events occur and using preventative, detective, and automated controls as much as possible.

In this podcast, Beth McKenney, a Principal in the KPMG Technology Risk service network, offers a game plan for companies to meet these today’s challenges with an eye on building stakeholder trust. That means having a proactive, rather than a reactive, approach to risk management.

View Details

In a world where adversaries are constantly adapting to improve tactics, techniques, and procedures (TTPs), it is crucial to understand the unique traits and goals of various types of adversaries that actively seek to cause harm to an organization. The personification of these threats will ultimately help measure resilience against specific threat actors, identify investment and hardening opportunities, and improve trust with customers.

In this podcast, Daniel Ventura, Manager of Product Security Incident Response Team (PSIRT), shares insight into Adobe’s approach to adversary personification as well as provides guidance on how you can better measure the security resilience of your products. He’ll also talk about Adobe’s bug bounty program which helps his team identify new trends in adversary interest and defend against real incident response events.

View Details

For the average person, life moves quickly. But for business leaders and anyone involved in any aspect of IT, the pace at which technology is changing is overwhelming. Technology can help businesses and individuals do more with less and increase profit margins. However, technological advances carry tremendous risk and increase the criticality of risk management. No longer can business and personal use of technology be viewed in siloes. ISACAs Director of Professional Practices and Innovation, Jon Brandt, is joined by Ryan Cloutier as they discuss some of the latest headlines and impact to intellectual property.

View Details

If you thought ISACA was only about certification and education, get ready to listen to this podcast and see how ISACA advocates for the IT Audit and Risk Management professions! Join Cindy Baxter, author of the Audit in Practice column in the ISACA Journal, as she interviews two members of the ISACA New England Board of Directors who attended ISACA’s Hill Day in Washington DC.  Hear how they met with their government representatives and with ISACA’s help, discussed legislation that supports our profession!  It’s an opportunity to think about the impacts you can have in your own back yard and with civic leaders!

View Details

SaaS is eating the world even more than we think. Companies are dealing with SaaS sprawl: hundreds of apps distributed across different owners that store sensitive data and which are used to orchestrate critical business workflows. Security-minded teams are turning to external compliance frameworks to help protect their customers and data. However, traditional identity governance controls have fallen short of delivering real security outcomes in this digital-first world. They’re missing a critical piece: automation. In this episode, ConductorOne’s CEO and Co-Founder, Alex Bovee joins this episode to discuss why we need to change the way we think about compliance and risk and what a security-led governance program could look like.

Learn more about ConductorOne at https://www.linkedin.com/company/conductorone/ or https://www.conductorone.com/blog/automating-compliance-controls-least-privilege-access/

View Details

A review of the events of 2022 shows that 2023 will not be the year of dire new cyber attacks waged by hoodie-wearing cyber criminals or office-bound nation-state APTs. Instead, 2023 will be when multiple regulatory bodies express their mounting frustration with public and private companies' collective inability to reduce the volume and impact of prior cyber attacks.  

Tune into this ISACA Episode as Hyperproof’s Field CISO, Kayne McGladrey, speaks with ISACA’s Jeff Champion on how 2023 will be the year of risk.  

Learn more about Hyperproof at:  

https://twitter.com/Hyperproof 

https://www.linkedin.com/company/hyperproof/ 

https://www.instagram.com/hyperproof/ 

Additional Hyperproof Resources:  

https://hyperproof.io/resource/the-ultimate-guide-to-enterprise-risk-management/ 

https://www.isaca.org/resources/news-and-trends/isaca-now-blog/2022/three-key-predictions-for-2023-the-year-of-risk 

https://hyperproof.io/resource/risk-management-software-buyer-guide/ 

https://hyperproof.io/case-studies/pythian-uses-hyperproof-to-get-time-back-and-improve-its-risk-management-maturity/ 

View Details

We live in the age of continuous compromise. This podcast dives into why so many organizations continue to be breached even after spending money on cybersecurity point solutions. Many organizations gravitate towards silver bullet solutions without understanding the threat and impact. During this podcast, we will discuss why a a holistic and collaborative approach is absolutely critical to create cyber-resilience. 

For more information check out www.isaca.org/improving-cyberresilience-in-an-age-of-continuous-attacks 

View Details

A strong audit and assurance function is critical to achieving digital trust in an organization. This conversation spotlights audit's role in digital trust and outlines key priorities. It also shares new ISACA resources for auditors.

For more information, go to https://isaca.org/digital-trust

View Details

ISACA's Chris Dimitriadis and the US GAO's Nick Marinos discuss the current state of critical infrastructure security, escalating threats and how to better prepare.

For more information check out www.isaca.org/heightened-threats

View Details

Paul Philips and Lisa Young will discuss how risk scenarios help decision-makers understand how certain events can impact organizational strategy and objectives. Good risk scenario building is a skill and can take some time to truly master. Paul and Lisa will provide actionable advice on building the best possible scenarios to help your organization better manage risk

For more information check out https://www.isaca.org/resources/it-risk

View Details

Compliance with the world’s ever-increasing list of privacy laws can be a tricky undertaking for any organization, but by taking a few simple steps, you can begin to mature your privacy program from a series of check-box exercises into an intelligent compliance program that can help organizations to build consumer trust and protect brand reputation.

Join this conversation with OneTrust DPO Linda Thielova and ISACA's Paul Phillips to learn how to operationalize privacy compliance within your organization and get practical tips on how to mature your privacy compliance program.

View Details

Career coach Caitlin McGaw will share her top tips for young professionals and career changes on how to launch a successful career in IT audit--from acing your first interview and landing your first job to career resources to help your career continue to grow and thrive.

To learn more, check out www.caitlinmcgaw.com 

View Details

Learn more at isaca.org/digital-trust 

View Details

Privacy Mining will increase because of billions of IoT devices being connected every day. Combined with advanced psychologic research, this can be a very powerful tool for manipulating people's behavior. A Fake reality also poses a big threat to our future of privacy. Software, such as Deep Fakes, has the ability to use someone's facial structure and create fake videos featuring digitally created characters with an uncanny resemblance of real people, such as celebrities.

This technology is so advanced, that our minds aren't sophisticated enough to comprehend the difference between real and fake data created by it, which leads to the next point. We are entering a trust crisis.

Trust is the foundation for innovation and technological advance. If people don't trust autonomous cars - they won't use them; if people don't certain websites - they won't read their news; Without trust, we cannot move forward, which is why we need to raise awareness about the dark future of privacy.

View Details

Why do individuals, organizations, institutions, nations, or responsible agents work hard to preserve their personal and enterprise data, personnel information, trade secrets, intellectual properties, technical know-how, or national data, yet easily trade on the individual and enterprise data and national data of others?

To understand and answer the question appropriately, one must examine the underlying of the Information Privacy Realities Contradiction Theory (IPRCT), which is integral to (1) our natural unity of opposites, (2) our material dialectic mechanism or struggle of choosing from the opposites, and (3) the role of our self-interest in time and circumstance. Therefore, understanding the intricacies of the IPRCT would be instrumental to the proper and timely introduction of privacy requirements early in our system development lifecycle and in the development and enactment of information privacy policies, directives, guidance, and regulations around the world.

In this ISACA Podcast episode, Safia Kazi host Dr. Patrick Offor, Chief Warrant Officer Five Retired (CW5(R)); Associate Faculty, to discuss his recently released ISACA Journal article.

To read Dr. Offor’s full article, please visit https://www.isaca.org/resources/isaca-journal/issues/2022/volume-6/the-information-privacy-contradiction.

To listen to more ISACA podcasts, please visit www.isaca.org/podcasts.

View Details

On National IT Professionals Day, ISACA's Kevin Keh explains how IT professionals can advance digital trust in their organizations and in their industries.Learn more at isaca.org/digital-trust

View Details

Numerous laws and regulations have been passed to protect sensitive information, both at the federal and state level, creating a patchwork of requirements for companies to comply with.  

However, with limited resources for cybersecurity investment, this uncoordinated approach has clouded objectives and led to decision paralysis within firms. Could cybersecurity implementation benefit from a Sarbanes-Oxley Act (SOX) type approach? 

This approach would create a risk-based, internal control model focused on cybersecurity that includes enforcement capabilities and requires third-party oversight and executive accountability.

To read Should Cybersecurity Be Subject to a SOX-Type Regulation? Please visit: www.isaca.org/should-cybersecurity-be-subject-to-a-sox-type-regulation

To listen to more ISACA podcasts, please visit: www.isaca.org/podcasts

View Details

Guy Pearce joins ISACA’s Lisa Villanueva for a conversation about the traps of Data Governance and management. Guy breaks down Lore vs. Data, reasons for not using information for decision-making and why data is a shared benefit for the organization. Stay tuned until the close to hear Guy’s advice on how to use metaphor when communicating technical concepts to executive leadership.

To read Guy's full article, visit: 

To listen to more ISACA podcasts, please visit: www.isaca.org/podcasts

View Details

ISACA’s Jeff Champion welcomes Steven Ross to the ISACA podcast. Steven asks what the effect of Convergence on the Control Community and concludes that everything is connected to every role, and it is becoming risky to have employees siloed within their own practice. He also remarks on how he once wrote an ISACA Journal article about companies creating a role for Chief Security Officer and now that is becoming a reality within the industry. Tune in now!

To read Steven’s full-length article, visit: www.isaca.org/convergence-where-next

To listen to more ISACA podcasts, visit: www.isaca.org/podcasts

View Details

The Impact of SOX on the Industry 20 Years Ago and Today. Opponents of Sarbanes Oxley, (SOX) contend the law is too costly for companies to operationalize given the small benefit that SOX regulation provide. Proponents say that a world without SOX is a world in chaos. 

This article discusses how SOX measures up 20 years after the law was enacted.

To read Cindy's ISACA Journal article, Do Data Go to Waste, please visit: www.isaca.org/do-data-go-to-waste

To listen to more ISACA Podcasts, please visit www.isaca.org/podcasts.

View Details

As uncertainty persists due to the COVID-19 pandemic, the war in Ukraine, international cyberthreats, inflation, and a looming recession, it is clear that the world has entered a new era of risk. These factors have created the perfect storm for rising fraud. In the past year, unauthorized digital account openings increased by 21%, while smartphone-related cyberattacks soared by 71%, reflecting a changing threat landscape impacting enterprises and consumers alike.

According to one global survey, nearly half of all respondents experienced fraud in the past 24 months, 3 compromising financial resources, personal data, and peace of mind with frightening rapidity. Recent research we have completed also reflects that “60% of Consumers Don't Believe Companies Do Enough to Protect Their Data as Demand for Security Grows".

Listen to the CEO of GBG Americas, Christina Luttrell, as she explains that, as a result, identity verification is a priority for organizations and government agencies that view it as a strategic differentiator that allows them to enhance the customer experience while improving their defensive posture at a critical time in this ISACA podcast episode.

To read the ISACA Journal article, Protecting Your Enterprise and Deterring Fraud in a New Risk Era, please visit: https://www.isaca.org/protecting-your-enterprise.

To listen to more ISACA Podcasts, please visit www.isaca.org/podcasts.

View Details

Richard Hollis, Director of Rick Crew, is serious about asking the tough questions.

ISACA’s Jon Brandt welcomes him to the ISACA podcast to have a conversation that challenges the status quo: Does the Cyber Security Industry work? After decades of experience in the security industry, Richard asks, “have I affected any change?” Richard points out that if we buy a toaster at the store and it doesn’t work, we return it, but as security professionals, we don’t hold products to the same standards. Why is this? Jon and Richard go back and forth on FUD, vendors, false positives, and where accountability lies in the industry.

Join Richard and Jon in the conversation to think about how we can affect the positive change that we want to see in our industry in the future!

To read Richard's full report, please visit www.isaca.org/the-circle-of-failure.

To listen to more ISACA podcasts, visit www.isaca.org/podcasts.

View Details

The world's largest software companies leverage modern-day Red Teams to protect against real-world attacks. Many companies focus on vulnerability management, compliance, and patching to secure themselves, but this is only a tiny part of the big picture. An improved security posture is achieved by leveraging the Red Team to pressure test the attack surface and discover the impact that can be made by actively exploiting the soft spots of the company.

In this podcast, Justin Tiplitsky, Director of the Red Team at Adobe, talks about how his team uses adversary intel to perform continuous testing on the parts of the company that attackers are the most interested in targeting. This continuous testing leads to the relentless identification of the most opportunistic areas to attack, more closely emulating the never-ending threat from real adversaries. Testing is followed up by storytelling and data to influence change within the company.

To learn more about Adobe, please visit: www.adobe.com

To listen to more ISACA Podcasts, please visit: www.isaca.org/podcasts

View Details

In an era of rampant ransomware and other malicious cyberattacks, it’s mandatory to double down on cybersecurity analysis and strategy to ensure an optimal security posture and the protection of critical assets and data.

Today, two models can help security professionals harden network resources and protect against modern-day threats and attacks: the cyber kill chain (CKC)and the MITRE ATT&CK framework.

Tim Liu, long-term security technologist, co-founder, and CTO, will provide an overview of these two frameworks and the limitations or benefits of each approach. 

To read Taking Security Strategy to the Next Level, please visit www.isaca.org/taking-security-strategy-to-the-next-level.

To listen to more ISACA podcasts, please visit www.isaca.org/podcasts.

View Details

As you plan and execute your audit, do you take time to invest in the stakeholder relationship? This can be an often-overlooked element but essential in an effective audit.

Tune into this ISACA Podcast as Steve Jackson, IT Audit Manager at Airbnb, chats with ISACA’s Robin Lyons about ways to gain auditee buy-in and have a successful and effective audit.

To read Steve’s full-length article, “Auditee Buy-In—A Key Component of Effective Audits,” visit www.isaca.org/auditee-buy-in

To watch the ISACA Video Podcast of this episode, visit, https://youtu.be/nWFcXC24ueA. 

For more ISACA Podcasts, please visit: www.isaca.org/podcasts or visit ISACA YouTube Channel at https://www.youtube.com/c/IsacaHq.

View Details

In this ISACA Podcast episode, ESET’s Chief Security Evangelist, Tony Anscombe, joins ISACA’s Principal, Emerging Technology Professional Practices, Collin Beder to discuss ESET’s recently released T2 2022 Threat Report.

As a global leader in cybersecurity, ESET’s T2 2022 Threat Report summarizes the most notable trends that have shaped the threat landscape for the past four months. This report dives into CloudMensis, the previously unknown macOS malware discovered by ESET researchers.

To read the full ESET report: https://www.welivesecurity.com/wpcontent/uploads/2022/10/eset_threat_report_t22022.pdf.

For more information, check out ESET’s award-winning blog: WeLiveSecurity. Make sure to follow ESET Research on Twitter for the latest news from ESET Research.

To listen to more ISACA Podcasts, please visit www.isaca.org/podcasts.

View Details

Data are the lifelines of a digital economy. They drive innovation, enabling cutting-edge research and next-generation technologies, including artificial intelligence (AI), robotics, and the Internet of things (IoT). But these opportunities introduce new sources of risk that must be managed appropriately. Canadians are raising important questions such as, “How will personal data be used?” and “What controls are in place to safeguard privacy and security?”

To encourage innovation within the digital economy while managing this risk, the Government of Canada has established the need for digital trust between citizens and organizations as an enabler by implementing a Digital Charter. As the Canadian government cites, “Trust is the foundation on which our digital and data-driven Canadian economy will be built.” This digital trust is defined by the “confidence that users have in the ability of people, technology, and processes to create a secure digital world.

Tune into this ISACA Podcast as the Acting Director of Internal Assurance at the Office of Enterprise Risk & Assurance of the University of British Columbia (UBC), Mary Carmichael, join’s ISACA’s Safia Kazi to explore topics including what is the Digital Charter and how it supports digital trust; what are critical elements of the Digital Charter (e.g., AI Ethics, Privacy, Principles for the Digital Economy); what are the implications for organizations and the public.

To read Mary’s full-length article, visit https://www.isaca.org/enabling-digital-trust-with-canadas-digital-charter.

View Details

It is all about the system's downtime.

In this ISACA Podcast episode, Risk Masters International's Steven Ross tells ISACA's Collin Beder that organizations should start focusing on hours of unavailable systems and data when measuring the cost of a cyber-attack. Steven also discusses the causes and targets of system downtime and why he thinks the IT world is currently living in a dangerous time.

To read Steven's full-length article, visit www.isaca.org/its-about-down-time.

To listen to more ISACA Podcasts, visit www.isaca.org/podcasts.

View Details

We are subjected to phishing scams almost every day, and even the most seasoned professional must examine an email to ensure the links included are safe.

Brown University and Federal Reserve Bank of Cleveland's Allen Dziwa says people are the weakest link and that customized messaging using regional language for targeted attacks is becoming more prevalent. Allen breaks down the many types of attacks (phishing, spear phishing, smishing, vishing, whaling) with ISACA's Kevin Keh. Tune in now to learn how to be vigilant when facing potential attacks from scammers.

To read Allen’s full article, please visit: www.isaca.org/how-social-engineering-bypasses-technical-controls

To listen to more ISACA Podcasts, please visit: www.isaca.org/podcasts

View Details

Ryan Cloutier's child came home from school one day and told him that he had figured out the staff Wi-Fi password. Frustrated that the security wasn't better for a school network, Ryan decided to do something about it. Since then, his career has been focused on serving K12, local government, and socio-economically disadvantaged communities with his company Security Studio.

ISACA's Jeff Champion asks him about ways to overcome technical language barriers when completing risk assessments and Ryan discusses key issues with risk assessments and a path forward to resolving them. Tune in to start thinking about more interesting ways to approach risk assessments!

To read Ryan's full-length article, visit: www.isaca.org/what-makes-risk-assessments-so-unpleasant

To listen to more ISACA Podcasts, visit: www.isaca.org/podcasts

View Details

Executive Director of Cybersecurity Gatebreakers Foundation, Naomi Buckwalter, joins ISACA’s Jon Brandt to discuss burnout.

There are many factors at play when discussing burnout: company culture, work-from-home flexibility, unrealistic expectations from supervisors, and industry pressure, but Naomi gives you multiple action plans for combatting workplace burnout and creating healthy boundaries with your colleagues. Tune into this ISACA Podcast now!

To learn more about Naomi, please visit: https://www.linkedin.com/in/naomi-buckwalter/

To listen to more ISACA podcasts, please visit: www.isaca.org/podcasts

View Details

In this ISACA podcast episode, IT Risk Director and Senior Vice President Mike Powers and IT Segment Risk Manager Julie Ebersbach discuss using the qualitative risk assessment as part of an organization's enterprise risk framework, focusing on using data to inform subjective judgments. 

The value and accuracy of a qualitative risk assessment, based on subject matter expert judgment, can be improved with focused data. Tune in now to hear Mike and Julie chat with ISACA's Jeff Champion about how quantifiable data increases the qualitative risk assessment's reliability, accuracy, and credibility.

To read ISACA Journal article, Quantifying the Qualitative Technology Risk Assessment, please visit: www.isaca.org/quantifying-the-qualitative-technology-risk-assessment

To listen to more ISACA Podcasts, please visit www.isaca.org/podcasts.

View Details

In today’s dynamic world of distributed computing and cloud-scale systems, traditional security data platforms and tools such as SIEM typically fall short of actually delivering the intelligence needed to better adapt to the rapidly changing threat landscape. This is primarily due to a lack of core data lifecycle management, analytics, and integration capabilities. In addition to closing these functional gaps, security organizations could benefit by making AI/ML-driven advanced analytics a core component of their security intelligence capabilities. While there is admittedly a lot of hype around the concept of a “security data lake” in the industry, most approaches to date have not really delivered the type of usable intelligence needed to be as nimble as we must be in today’s cybersecurity world.

To address these issues, Adobe is taking a holistic approach to data and analytics that aims to enable efficiencies and scale for its Security organization. We have embarked on a journey to build an integrated and holistic security data and analytics platform as a foundational building block in its security organization. Join Krishna Patil, Principal Architect, Security, from Adobe as he discusses with ISACA's Collin Beder the approach we have taken to provide insights you can use to help tackle the problem of not just gathering the right data but making it more actionable to your security teams. Tune into this ISACA Podcast now!

To learn more about Adobe, please visit: www.adobe.com

To listen to more ISACA Podcasts, please visit: www.isaca.org/podcasts

View Details

There is no denying the passion that ecfirst's CEO, Ali Pabrai has for cybersecurity. In this ISACA Podcast, Ali tells ISACA's Hollee Mangrum-Willis that after all his years in the industry, he is still more excited than a two-year-old at the entrance to Disneyland.

Listen in as Ali discusses his origin story as a first-generation American working for Fermi National Accelerator Laboratory, creating a startup soon after the new millennium and how he has balanced all his career accomplishments while raising a neurodivergent child. Tune in now to hear about why Ali thinks we should compare the human body to cybersecurity and much more!

To learn more about Ali, please visit: https://www.linkedin.com/in/pabrai/

To learn more about OneInTech, please visit: www.oneintech.org

To listen to more ISACA Podcasts, please visit: www.isaca.org/podcasts

View Details

Cybersecurity incidents like ransomware can potentially bring operations to a standstill. Recent regulatory changes by the FTC and proposed changes by the SEC show that both agencies are drafting cybersecurity rules similar to ERM concepts. This would include board oversight of cybersecurity and the responsibility of senior management to implement cybersecurity policies and procedures and provide training for information security staff that is sufficient for them to address relevant security risks. In addition, this could mean that your organization may be required to report incidents and disclose cybersecurity policies and procedures.

Tune in to this ISACA Podcast episode to listen in as Cyber Defense Labs’ Manager of Cybersecurity Advisory Services Tom Schneider tells ISACA’s Jeff Champion that any threat to this essential information is an enterprise risk that needs to be managed by the enterprise through teamwork, with leadership from both the board and senior management. Tom also gives insights into managing cybersecurity risk as an enterprise risk.

To read Managing Cybersecurity Risk as Enterprise Risk, please visit: www.isaca.org/managing-cybersecurity-risk-as-enterprise-risk.

To listen to more ISACA Podcasts, please visit: www.isaca.org/podcasts.

View Details

University of Florida's Ivy Munoko is passionate about AI and has plenty to share regarding implementation and usage, but ISACA's Collin Beder asks, "is it ethical"? 

Ivy breaks down the ethical considerations for AI and the four types of intelligence (Mechanical, Analytical, Intuitive, Empathetic), and she shares her take on why she thinks AI won't be replacing our jobs for a very long time to come

To read Ivy's article, please visit www.isaca.org/implementing-ai-capabilities-and-risk.

To listen to more ISACA Podcasts, please visit www.isaca.org/podcasts. 

View Details

What’s The Risk LLC’s Cindy Baxter sits down with ISACA’s Robin Lyons to discuss auditing culture, which can be one of the most interesting areas to audit. We all have things we want out of our work environment like remote work, flexible hours or as Cindy comments: “I’d love to take my dog to work with me!”, but she and Robin question what is really important to workplace culture, and does it start with a “tone at the top”? Cindy gives advice on auditing approaches and key assessments when auditing as culture can be a critical part of an organization, making or breaking its effectiveness.

To read Cindy’s full length article, please visit: www.isaca.org/auditing-culture 

To listen to more ISACA Podcasts, please visit: www.isaca.org/podcasts 

View Details

What’s The Risk LLC’s Cindy Baxter sits down with ISACA’s Robin Lyons to discuss auditing culture, which can be one of the most interesting areas to audit. We all have things we want out of our work environment like remote work, flexible hours or as Cindy comments: “I’d love to take my dog to work with me!”, but she and Robin question what is really important to workplace culture, and does it start with a “tone at the top”? Cindy gives advice on auditing approaches and key assessments when auditing as culture can be a critical part of an organization, making or breaking its effectiveness.

To read Cindy’s full length article, please visit: www.isaca.org/auditing-culture 

To listen to more ISACA Podcasts, please visit: www.isaca.org/podcasts 

View Details

This episode of the ISACA Podcast is all about incident reporting. Lesotho Postbank's Relebohile Kobeli talks to ISACA's Collin Beder about mitigating risk, minimizing losses from events, and good communication. As Relebohile says: "as we carry out our daily tasks at work, we should always be proactive... and recognize abnormal behavior". Tune in now!

To read Relebohile's full article, please visit: www.isaca.org/how-enterprises-can-leverage-incident-reporting 

To listen to more ISACA Podcasts, please visit: www.isaca.org/podcasts 

View Details

This episode of the ISACA Podcast is all about incident reporting. Lesotho Postbank's Relebohile Kobeli talks to ISACA's Collin Beder about mitigating risk, minimizing losses from events, and good communication. As Relebohile says: "as we carry out our daily tasks at work, we should always be proactive... and recognize abnormal behavior". Tune in now!

To read Relebohile's full article, please visit: www.isaca.org/how-enterprises-can-leverage-incident-reporting 

To listen to more ISACA Podcasts, please visit: www.isaca.org/podcasts 

View Details

Netflix's Lisa Young started as a bank teller that learned tech by fixing and servicing ATMs, which transitioned to her joining the network ops field and leading her to "help organizations understand what could keep them from meeting their strategy, objectives or mission". After rough telecom layoffs, she re-educated herself with ISACA certifications and started leading a chapter, which included the honor of hosting an ISACA conference and she has developed content with ISACA's Paul Phillips. In this episode she sits down with Paul to discuss their shared work on ISACA-related projects, cyber careers and why you should be curious and ask how things work. Lisa loves the idea of continuous learning and asks, "what is a good next step for you?"

To listen to more ISACA Podcasts, go to isaca.org/podcasts

Be sure to like, comment, and subscribe for more ISACA Productions content.

View Details

Netflix's Lisa Young started as a bank teller that learned tech by fixing and servicing ATMs, which transitioned to her joining the network ops field and leading her to "help organizations understand what could keep them from meeting their strategy, objectives or mission". After rough telecom layoffs, she re-educated herself with ISACA certifications and started leading a chapter, which included the honor of hosting an ISACA conference and she has developed content with ISACA's Paul Phillips. In this episode she sits down with Paul to discuss their shared work on ISACA-related projects, cyber careers and why you should be curious and ask how things work. Lisa loves the idea of continuous learning and asks, "what is a good next step for you?"

To listen to more ISACA Podcasts, go to isaca.org/podcasts

Be sure to like, comment, and subscribe for more ISACA Productions content.

View Details

Some industry watchers estimate that by 2025 the collective data of humanity will reach 175 Zettabytes. ISACA's Jon Brandt invites Dr. Chase Cunningham (aka Dr. Zero Trust) to discuss how to defend the ever-growing amount data, problem-solving for business units and compliance. Chase also questions the idea of “never compromise” and “perfect defense” when defending data. Tune in now!

To Learn more about Dr. Zero Trust, visit: www.zerotrustedge.com/dr-zero-trust

To listen to more ISACA Podcasts, visit: www.isaca.org/podcasts 

View Details

Some industry watchers estimate that by 2025 the collective data of humanity will reach 175 Zettabytes. ISACA's Jon Brandt invites Dr. Chase Cunningham (aka Dr. Zero Trust) to discuss how to defend the ever-growing amount data, problem-solving for business units and compliance. Chase also questions the idea of “never compromise” and “perfect defense” when defending data. Tune in now!

To Learn more about Dr. Zero Trust, visit: www.zerotrustedge.com/dr-zero-trust

To listen to more ISACA Podcasts, visit: www.isaca.org/podcasts 

View Details

Parte I: https://isacapodcast.podbean.com/e/foco-de-la-industria-arnulfo-espinosa-dominguez/

El vicepresidente del Capítulo Monterrey de ISACA y Director de Auditoría y Fraude de TI de uno de los Grupos Financieros más grandes de México, Arnulfo Espinosa Domínguez, se une a Jocelyn Alcantar de ISACA para compartir muchas cosas que ha aprendido durante sus 20 años de experiencia profesional en la industria. Habiéndose dado cuenta del valor de la información a una edad temprana, Arnulfo ha forjado su camino dentro de la comunidad de TI. Es un formador acreditado para múltiples certificaciones, asesor independiente y presidente de varios comités de Ciberseguridad, Riesgo y Auditoría, y es reconocido mundialmente por un apodo que sus compañeros le han dado, "El AudiTHOR".

Como voluntario de ISACA desde hace mucho tiempo y orador de conferencias, Arnulfo ha sido premiado en numerosas ocasiones por sus destacados logros. En 2019, se le otorgó el "Premio al Líder de Capítulo Sobresaliente" (Outstanding Chapter Leader Award) de ISACA, en 2020, recibió el "Premio John Kuyers al Mejor Orador" (John Kuyers Award for Best), y recibió el mayor logro, el "Premio Salón de la Fama de ISACA" (ISACA Hall of Fame Award) en 2021. 

¡Únase a la escucha de este episodio mientras Arnulfo ofrece sus mejores consejos y prácticas para convertirse en un orador excepcional, consejos sobre cómo los profesionales emergentes pueden entrar en la industria, y cómo su alter ego, AudiTHOR, alimenta su pasión por la auditoría!

Para leer más sobre Arnulfo, visite www.isaca.org/resources/news-and-trends/isaca-now-blog/2020/iamisaca-from-rock-star-to-speak-star

Para escuchar más Podcasts de ISACA, visite www.isaca.org/podcasts

View Details

Parte I: https://isacapodcast.podbean.com/e/foco-de-la-industria-arnulfo-espinosa-dominguez/

El vicepresidente del Capítulo Monterrey de ISACA y Director de Auditoría y Fraude de TI de uno de los Grupos Financieros más grandes de México, Arnulfo Espinosa Domínguez, se une a Jocelyn Alcantar de ISACA para compartir muchas cosas que ha aprendido durante sus 20 años de experiencia profesional en la industria. Habiéndose dado cuenta del valor de la información a una edad temprana, Arnulfo ha forjado su camino dentro de la comunidad de TI. Es un formador acreditado para múltiples certificaciones, asesor independiente y presidente de varios comités de Ciberseguridad, Riesgo y Auditoría, y es reconocido mundialmente por un apodo que sus compañeros le han dado, "El AudiTHOR".

Como voluntario de ISACA desde hace mucho tiempo y orador de conferencias, Arnulfo ha sido premiado en numerosas ocasiones por sus destacados logros. En 2019, se le otorgó el "Premio al Líder de Capítulo Sobresaliente" (Outstanding Chapter Leader Award) de ISACA, en 2020, recibió el "Premio John Kuyers al Mejor Orador" (John Kuyers Award for Best), y recibió el mayor logro, el "Premio Salón de la Fama de ISACA" (ISACA Hall of Fame Award) en 2021. 

¡Únase a la escucha de este episodio mientras Arnulfo ofrece sus mejores consejos y prácticas para convertirse en un orador excepcional, consejos sobre cómo los profesionales emergentes pueden entrar en la industria, y cómo su alter ego, AudiTHOR, alimenta su pasión por la auditoría!

Para leer más sobre Arnulfo, visite www.isaca.org/resources/news-and-trends/isaca-now-blog/2020/iamisaca-from-rock-star-to-speak-star

Para escuchar más Podcasts de ISACA, visite www.isaca.org/podcasts

View Details

Many organizations prioritize goals such as gains and profits, which often require rich data sets, but fail to consider the eventual impact of their data handling methodologies on foundational social justice issues. ISACA's Collin Beder talks to Josh Scarpino about his recently released article Evaluating Ethical Challenges in AI and ML. Josh discusses issues such as ethical behavior, systemic issues and how to create trusted systems. Collin also asks what is the future for humans in regards to AI. Tune in now!

To read Evaluating Ethical Challenges in AI and ML, visit: www.isaca.org/evaluating-ethical-challenges-in-ai-and-ml

To listen to more ISACA Podcasts, visit: www.isaca.org/podcasts 

View Details

Many organizations prioritize goals such as gains and profits, which often require rich data sets, but fail to consider the eventual impact of their data handling methodologies on foundational social justice issues. ISACA's Collin Beder talks to Josh Scarpino about his recently released article Evaluating Ethical Challenges in AI and ML. Josh discusses issues such as ethical behavior, systemic issues and how to create trusted systems. Collin also asks what is the future for humans in regards to AI. Tune in now!

To read Evaluating Ethical Challenges in AI and ML, visit: www.isaca.org/evaluating-ethical-challenges-in-ai-and-ml

To listen to more ISACA Podcasts, visit: www.isaca.org/podcasts 

View Details

Parte II: https://isacapodcast.podbean.com/e/foco-de-la-industria-arnulfo-espinosa-dominguez-parte-ii/

El vicepresidente del Capítulo Monterrey de ISACA y Director de Auditoría y Fraude de TI de uno de los Grupos Financieros más grandes de México, Arnulfo Espinosa Domínguez, se une a Jocelyn Alcantar de ISACA para compartir muchas cosas que ha aprendido durante sus 20 años de experiencia profesional en la industria. Habiéndose dado cuenta del valor de la información a una edad temprana, Arnulfo ha forjado su camino dentro de la comunidad de TI. Es un formador acreditado para múltiples certificaciones, asesor independiente y presidente de varios comités de Ciberseguridad, Riesgo y Auditoría, y es reconocido mundialmente por un apodo que sus compañeros le han dado, "El AudiTHOR".

Como voluntario de ISACA desde hace mucho tiempo y orador de conferencias, Arnulfo ha sido premiado en numerosas ocasiones por sus destacados logros. En 2019, se le otorgó el "Premio al Líder de Capítulo Sobresaliente" (Outstanding Chapter Leader Award) de ISACA, en 2020, recibió el "Premio John Kuyers al Mejor Orador" (John Kuyers Award for Best), y recibió el mayor logro, el "Premio Salón de la Fama de ISACA" (ISACA Hall of Fame Award) en 2021. 

¡Únase a la escucha de este episodio mientras Arnulfo ofrece sus mejores consejos y prácticas para convertirse en un orador excepcional, consejos sobre cómo los profesionales emergentes pueden entrar en la industria, y cómo su alter ego, AudiTHOR, alimenta su pasión por la auditoría!

Para leer más sobre Arnulfo, visite www.isaca.org/resources/news-and-trends/isaca-now-blog/2020/iamisaca-from-rock-star-to-speak-star

Para escuchar más Podcasts de ISACA, visite www.isaca.org/podcasts

View Details

Parte II: https://isacapodcast.podbean.com/e/foco-de-la-industria-arnulfo-espinosa-dominguez-parte-ii/

El vicepresidente del Capítulo Monterrey de ISACA y Director de Auditoría y Fraude de TI de uno de los Grupos Financieros más grandes de México, Arnulfo Espinosa Domínguez, se une a Jocelyn Alcantar de ISACA para compartir muchas cosas que ha aprendido durante sus 20 años de experiencia profesional en la industria. Habiéndose dado cuenta del valor de la información a una edad temprana, Arnulfo ha forjado su camino dentro de la comunidad de TI. Es un formador acreditado para múltiples certificaciones, asesor independiente y presidente de varios comités de Ciberseguridad, Riesgo y Auditoría, y es reconocido mundialmente por un apodo que sus compañeros le han dado, "El AudiTHOR".

Como voluntario de ISACA desde hace mucho tiempo y orador de conferencias, Arnulfo ha sido premiado en numerosas ocasiones por sus destacados logros. En 2019, se le otorgó el "Premio al Líder de Capítulo Sobresaliente" (Outstanding Chapter Leader Award) de ISACA, en 2020, recibió el "Premio John Kuyers al Mejor Orador" (John Kuyers Award for Best), y recibió el mayor logro, el "Premio Salón de la Fama de ISACA" (ISACA Hall of Fame Award) en 2021. 

¡Únase a la escucha de este episodio mientras Arnulfo ofrece sus mejores consejos y prácticas para convertirse en un orador excepcional, consejos sobre cómo los profesionales emergentes pueden entrar en la industria, y cómo su alter ego, AudiTHOR, alimenta su pasión por la auditoría!

Para leer más sobre Arnulfo, visite www.isaca.org/resources/news-and-trends/isaca-now-blog/2020/iamisaca-from-rock-star-to-speak-star

Para escuchar más Podcasts de ISACA, visite www.isaca.org/podcasts

View Details

The stakes are too high for organizations not to comply with data privacy regulations,” Bassel Kablawi states in his article, "Why (and How to) Dispose of Digital Data." As the Information Security and Data Privacy Consultant for System Solutions, Bassel Kablawi has the knowledge and experience to determine that the value of data disposal can help an organization protect personal data from being exposed and why the final step in the Data Lifecycle could be considered the most crucial.

Bassel takes us on a deep dive into digital data with ISACA's Safia Kazi on the five stages of data disposal in this ISACA podcast episode. He explains why it is essential to understand that destruction should be performed based on an organization’s retention policy and the five main disposal methods of data, which include date anonymization, data deletion, data crypto shredding (for encrypted data), data degaussing, and data destruction.

Tune in to hear Bassel explain why data destruction is critical to developing digital trust with customers and stakeholders and could save an organization’s reputation.

To read Bassel's article, please visit: www.isaca.org/resources/news-and-trends/industry-news/2022/why-and-how-to-dispose-of-digital-data

To listen to more ISACA Podcasts, please visit: www.isaca.org/podcasts

View Details

The stakes are too high for organizations not to comply with data privacy regulations,” Bassel Kablawi states in his article, "Why (and How to) Dispose of Digital Data." As the Information Security and Data Privacy Consultant for System Solutions, Bassel Kablawi has the knowledge and experience to determine that the value of data disposal can help an organization protect personal data from being exposed and why the final step in the Data Lifecycle could be considered the most crucial.

Bassel takes us on a deep dive into digital data with ISACA's Safia Kazi on the five stages of data disposal in this ISACA podcast episode. He explains why it is essential to understand that destruction should be performed based on an organization’s retention policy and the five main disposal methods of data, which include date anonymization, data deletion, data crypto shredding (for encrypted data), data degaussing, and data destruction.

Tune in to hear Bassel explain why data destruction is critical to developing digital trust with customers and stakeholders and could save an organization’s reputation.

To read Bassel's article, please visit: www.isaca.org/resources/news-and-trends/industry-news/2022/why-and-how-to-dispose-of-digital-data

To listen to more ISACA Podcasts, please visit: www.isaca.org/podcasts

View Details

Link to Part I: https://isacapodcast.podbean.com/e/industry-spotlight-johann-dettweiler-part-1/

In this ISACA podcast episode, we connect with TalaTek Director of Operations Johann Dettweiler to discuss his almost two decades of experience across multiple industry fields, his involvement in FEDRAMP compliance, and why the next generation should focus on adding certifications to their resumes.

Johann tells ISACA's Keith Karlsson that it was his work ethic and guidance of a trusted mentor that provided an opportunity in the IT security field. In less than 12 months, he racked up multiple impressive certifications such as CISSP, CCSP, and CEH that rapidly advanced his career and, as he explains it, allows him to be “the person that everyone hates because I tell you what is wrong with your system.”

Johann’s strong background in research and his constant quest for knowledge about this evolving industry, he is more than willing to provide listeners with his efficiency hacks to stay productive, motivational career advice, and why the next-generation cyber professionals may have an advantage over him. Tune in now to meet Senior Security Information Security Consultant Johann Dettweiler.

To learn more about Johann, visit https://talatek.com/project/johann-dettweiler/

To listen to other ISACA Podcast episodes, visit www.isaca.org/podcast

View Details

Link to Part I: https://isacapodcast.podbean.com/e/industry-spotlight-johann-dettweiler-part-1/

In this ISACA podcast episode, we connect with TalaTek Director of Operations Johann Dettweiler to discuss his almost two decades of experience across multiple industry fields, his involvement in FEDRAMP compliance, and why the next generation should focus on adding certifications to their resumes.

Johann tells ISACA's Keith Karlsson that it was his work ethic and guidance of a trusted mentor that provided an opportunity in the IT security field. In less than 12 months, he racked up multiple impressive certifications such as CISSP, CCSP, and CEH that rapidly advanced his career and, as he explains it, allows him to be “the person that everyone hates because I tell you what is wrong with your system.”

Johann’s strong background in research and his constant quest for knowledge about this evolving industry, he is more than willing to provide listeners with his efficiency hacks to stay productive, motivational career advice, and why the next-generation cyber professionals may have an advantage over him. Tune in now to meet Senior Security Information Security Consultant Johann Dettweiler.

To learn more about Johann, visit https://talatek.com/project/johann-dettweiler/

To listen to other ISACA Podcast episodes, visit www.isaca.org/podcast

View Details

Link to Part II: https://isacapodcast.podbean.com/e/industry-spotlight-johann-dettweiler-part-ii/

In this ISACA podcast episode, we connect with TalaTek Director of Operations Johann Dettweiler to discuss his almost two decades of experience across multiple industry fields, his involvement in FEDRAMP compliance, and why the next generation should focus on adding certifications to their resumes.

Johann tells ISACA's Keith Karlsson that it was his work ethic and guidance of a trusted mentor that provided an opportunity in the IT security field. In less than 12 months, he racked up multiple impressive certifications such as CISSP, CCSP, and CEH that rapidly advanced his career and, as he explains it, allows him to be “the person that everyone hates because I tell you what is wrong with your system.”

Johann’s strong background in research and his constant quest for knowledge about this evolving industry, he is more than willing to provide listeners with his efficiency hacks to stay productive, motivational career advice, and why the next-generation cyber professionals may have an advantage over him. Tune in now to meet Senior Security Information Security Consultant Johann Dettweiler.

To learn more about Johann, visit https://talatek.com/project/johann-dettweiler/

To listen to other ISACA Podcast episodes, visit www.isaca.org/podcast

View Details

Link to Part II: https://isacapodcast.podbean.com/e/industry-spotlight-johann-dettweiler-part-ii/

In this ISACA podcast episode, we connect with TalaTek Director of Operations Johann Dettweiler to discuss his almost two decades of experience across multiple industry fields, his involvement in FEDRAMP compliance, and why the next generation should focus on adding certifications to their resumes.

Johann tells ISACA's Keith Karlsson that it was his work ethic and guidance of a trusted mentor that provided an opportunity in the IT security field. In less than 12 months, he racked up multiple impressive certifications such as CISSP, CCSP, and CEH that rapidly advanced his career and, as he explains it, allows him to be “the person that everyone hates because I tell you what is wrong with your system.”

Johann’s strong background in research and his constant quest for knowledge about this evolving industry, he is more than willing to provide listeners with his efficiency hacks to stay productive, motivational career advice, and why the next-generation cyber professionals may have an advantage over him. Tune in now to meet Senior Security Information Security Consultant Johann Dettweiler.

To learn more about Johann, visit https://talatek.com/project/johann-dettweiler/

To listen to other ISACA Podcast episodes, visit www.isaca.org/podcast

View Details

Cloud is ubiquitous now. From small enterprises to large companies, all are moving a part of their technology operations to cloud. Initial reluctance is now nowhere to be seen. There is more confidence among the user for the use of cloud technology. Join ISACA’s Jeff Champion as he talks with Risk and Control Specialist, Upesh Parekh about cloud deployment models, the various risks involved with cloud storage, and what to know when using cloud technology for an organization.

Read Achieving Effective Cloud Risk Management at: www.isaca.org/achieving-effective-cloud-risk-management

Listen to more ISACA Podcasts at: www.isaca.org/podcasts

View Details

Link to Part I: https://www.podbean.com/media/share/pb-agrfe-12a9555

Author, editor, speaker, and educator, Dr. Blake Curtis is joined by Red Cross’s Senior Internal Auditor Niki Gomes to talk about everything from growing up in a small town to completing his master’s degree in 10 weeks and publishing his 600-page dissertation in this ISACA Industry Spotlight episode.

In a meaningful conversation, Blake discusses how surviving a near-death experience transformed and motivated him to expand his understanding of what it means to be a human. He was inspired to supercharge his learning, career journey, and personal growth. Making the decision to become intentional in every interaction and giving 100% of his effort in every initiative, he blazed his path to success.

At the 2022 ISACA North America Conference, Blake presented his findings from his ground-breaking and internationally known dissertation, "The Next Generation Cybersecurity Auditor.” His research discovered a technical competency gap in Big Four IT Auditors and SMEs and debunked the 10,000-hour rule and "years of experience" fallacy. His study proved that task-based experience is more objective than time-based experience. Blake is also the author of "How to Complete Your Master's Degree in One Semester," which has assisted over 150 students to complete their master’s degrees in record-setting times.

Along his journey, he has earned over 30 IT certifications and gained additional impressive certificates for engineering, advising, managing, and leadership. Blake has an abundance of experience to share with ISACA’s audience.  Tune in now to be inspired, uplifted, and enlightened by his techniques, advice, and wisdom that can help boost your career!

Below you can find materials and resources that Blake would like to share with our audience.

Links:

How to regulate a profession pg. 261 and 265 of Creating the Next Generation Cybersecurity Auditor: Examining the Relationship between It Auditors’ Competency, Audit Quality, & Data Breaches - ProQuest

Debunking Years of Experience:

https://www.linkedin.com/posts/reginaldblakecurtis_science-hiring-experience-activity-6951573321901621248-cygl?utm_source=linkedin_share&utm_medium=member_desktop_web

Videos

Equitable Hiring YouTube Series link: https://www.youtube.com/watch?v=IsnoCNIA2WU&list=PLfr4LANhCPrCXIc6V_h_k2dyKwPP7wJJa

Tools

Inoreader: Inoreader - Take back control of your newsfeed

Anki Notecards (Spaced Repetition): About - AnkiWeb

Notion

Books

Art of Conversation – Judy Apps

Verbal Judo – George Thompson

The Science of Self-Learning – Peter Hollins

Finish What Your Start – Peter Hollins

The Power of Discipline – Daniel Walter

View Details

Author, editor, speaker, and educator, Dr. Blake Curtis is joined by Red Cross’s Senior Internal Auditor Niki Gomes to talk about everything from growing up in a small town to completing his master’s degree in 10 weeks and publishing his 600-page dissertation in this ISACA Industry Spotlight episode.

In a meaningful conversation, Blake discusses how surviving a near-death experience transformed and motivated him to expand his understanding of what it means to be a human. He was inspired to supercharge his learning, career journey, and personal growth. Making the decision to become intentional in every interaction and giving 100% of his effort in every initiative, he blazed his path to success.

At the 2022 ISACA North America Conference, Blake presented his findings from his ground-breaking and internationally known dissertation, "The Next Generation Cybersecurity Auditor.” His research discovered a technical competency gap in Big Four IT Auditors and SMEs and debunked the 10,000-hour rule and "years of experience" fallacy. His study proved that task-based experience is more objective than time-based experience. Blake is also the author of "How to Complete Your Master's Degree in One Semester," which has assisted over 150 students to complete their master’s degrees in record-setting times.

Along his journey, he has earned over 30 IT certifications and gained additional impressive certificates for engineering, advising, managing, and leadership. Blake has an abundance of experience to share with ISACA’s audience.  Tune in now to be inspired, uplifted, and enlightened by his techniques, advice, and wisdom that can help boost your career!

Below you can find materials and resources that Blake would like to share with our audience.

Links:

How to regulate a profession pg. 261 and 265 of Creating the Next Generation Cybersecurity Auditor: Examining the Relationship between It Auditors’ Competency, Audit Quality, & Data Breaches - ProQuest

Debunking Years of Experience:

https://www.linkedin.com/posts/reginaldblakecurtis_science-hiring-experience-activity-6951573321901621248-cygl?utm_source=linkedin_share&utm_medium=member_desktop_web

Videos

Equitable Hiring YouTube Series link: https://www.youtube.com/watch?v=IsnoCNIA2WU&list=PLfr4LANhCPrCXIc6V_h_k2dyKwPP7wJJa

Tools

Inoreader: Inoreader - Take back control of your newsfeed

Anki Notecards (Spaced Repetition): About - AnkiWeb

Notion

Books

Art of Conversation – Judy Apps

Verbal Judo – George Thompson

The Science of Self-Learning – Peter Hollins

Finish What Your Start – Peter Hollins

The Power of Discipline – Daniel Walter

View Details

Link to Part I: https://isacapodcast.podbean.com/e/industry-spotlight-arnulfo-espinosa-dominguez-part-i/

Vice President of the ISACA Monterrey Chapter and IT Audit & Fraud Director of one of the largest Financial Groups in México, Arnulfo Espinosa Dominguez, joins ISACA’s Jocelyn Alcantar to share some of the many things he has learned over his 20 years of professional experience in the industry. Having realized the value of information at an early age, Arnulfo has forged his path within the IT community. He is an accredited trainer for multiple certifications, an independent advisor and chairman for various Cybersecurity, Risk, and Audit committees, and is globally recognized by a nickname his peers have given him, "The AudiTHOR.”

As a long-time ISACA volunteer and conference speaker, Arnulfo has been awarded on numerous occasions for his outstanding achievements. In 2019, he was given the ISACA “Outstanding Chapter Leader Award,” in 2020, he received the “John Kuyers Award for Best Speaker”, and he received the highest achievement, the “ISACA Hall of Fame Award” in 2021.  

Tune into this episode as Arnulfo offers his best tips and practices for becoming an exceptional keynote speaker, advice on how the up-and-coming professionals can get into the industry, and how his alter ego, AudiTHOR, fuels his passion for auditing!

To read more about Arnulfo, visit www.isaca.org/resources/news-and-trends/isaca-now-blog/2020/iamisaca-from-rock-star-to-speak-star.

To listen to more ISACA Podcasts, visit www.isaca.org/podcasts.

View Details

Arnulfo Espinosa Dominguez tells ISACA's Jocelyn Alcantar that his first idea for a career as a child was to be a doctor, but soon realized the responsibility that comes with the profession. Soon after that, Arnulfo was working with a family member's computer--they had lost important documents and he realized the value of information. Fast forward to today and Arnulfo is an Electronic and Communications Engineer for ARES Alliance with the responsibility of technology. As a long-time ISACA volunteer, Arnulfo has been a part of the chapter in Monterrey, Mexico as a member and president. In 2020, he received the ISACA John Kuyers Award “For his ability to present complex concepts to audiences in simple manner and for sharing his passion and knowledge by speaking at ISACA events.” In addition to receiving this award, Arnulfo was the 2022 ISACA Conference Latin America emcee. Tune in to hear his keynote speaking tips, advice on how up and coming professionals can get into the industry and learn about his alter ego that fuels his passion for auditing!

To read more about Arnulfo, visit: www.isaca.org/resources/news-and-trends/isaca-now-blog/2020/iamisaca-from-rock-star-to-speak-star

To listen to more ISACA Podcasts, visit: www.isaca.org/podcasts

View Details

ISACAs Director of Professional Practices and Innovation Jon Brand hosts Doug Levin, co-founder and National Director of K12 Security Information eXchange (K121 SIX), a national non-profit dedicated solely to helping schools protect themselves from emerging cybersecurity threats. Levin's work includes development and implementation of the nations initial and subsequent technology plans and well as creation of K-12 Cyber Incident Map, the most comprehensive database of publicly-disclosed K-12 cybersecurity incidents. Throughout this episode they discuss the often unique challenges for the underrepresented sector of U.S. critical infrastructure and current initiatives to bolster K-12 cybersecurity and privacy.

For more information, check out https://www.k12six.org/

Be sure to like, comment and subscribe for more ISACA Productions content

View Details

Cybersecurity leader, author, and host of the CISO Stories podcast, Todd Fitzgerald sits down with ISACA’s Chelsey Byrd to discuss his extensive career journey in security, his best-selling book, CISO COMPASS, and how a make-believe FBI club connects directly to his career passions today.

As one of ISACA’s top-rated speakers, Todd gives tips and techniques for the best way to prepare for a speaking event, how to engage the audience, and some entertaining moments and behind-the-scenes accounts from conferences!

Named the Chicago CISO of the Year and ranked Top 50 IS Executive in 2016 and 2017, Todd offers listeners his best career advice, ways to stay aware of current business trends, and much more.

Listen now to this episode of ISACA’s Industry Spotlight.

To listen to CISO Stories, visit https://securityweekly.com/category-shows/the-ciso-stories-podcast/.

To listen to more ISACA Podcasts, visit www.isaca.org/podcasts.

View Details

A strong audit and assurance function is critical to achieving digital trust in an organization. This conversation spotlights audit's role in digital trust and outlines key priorities. It also shares new ISACA resources for auditors.

For more information, go to https://isaca.org/digital-trust

View Details

We usually think about the most efficient way to do things while working in production environments. Still, often employees forget about an insecure environment once the work has been completed and they have moved on to another project.

“We don’t always need to audit things; sometimes you can gauge risk by having a conversation with stakeholders…on how they manage databases,” says Adam Kohnke, Cybersecurity Architect for Charter Next Generation.

Adam joins ISACA’s Jon Brandt in this episode to discuss his recently released ISACA Journal article, “Managing Security Across Disparate Database Technologies.” Adam breaks down best practices for User Access Management, Encryption, and Logging. He comments on the best ways to start the conversation about security beyond what management considers vital for IT.

Tune in now for the full episode!

To read the full article, visit www.isaca.org/managing-security-across-disparate-database-technologies.

To listen to more ISACA podcasts, visit: www.isaca.org/podcasts 

View Details

AI is a part of our everyday life. What's The Risk LLC's Cindy Baxter gives ISACA's Kevin Keh examples of modern media like the movies Free Guy, Ron’s Gone Wrong and The Matrix, and how they relate to AI-related risk factors, and they ask the questions, what is true? what is the data we are looking at? AI is about data accuracy and reputational risk, and Cindy discusses how to manage frameworks, create meaningful check points and intended outcomes six months or 2 years later that are spot on for what an organization intended. Cindy strongly believes that you always get a better outcome with diversity, because people from diverse backgrounds and life experiences create different ways to learn and produce innovative ideas and avoid rework.

To read Cindy's full article, visit: www.isaca.org/implementing-emerging-technologies

To listen to more ISACA podcasts, visit: www.isaca.org/podcasts

View Details

ISACA's risk expert Paul Phillips and Richard Hollis, CEO of Risk Factory and an ISACA Conference Europe speaker, examine top cyber risks impacting the supply chain, steps organizations need to take to manage supply chain risk, and important steps to take in the contract process.

Be sure to like, comment, and subscribe for more ISACA Productions content.

View Details

On this episode of Industry Spotlight, ISACA's outgoing Board Chair, Greg Touhill, introduces the 2022-23 Board Chair, Pam Nigro. They trade stories from their careers, Pam's thoughts on the future of ISACA, how Game of Thrones relates to Cybersecurity, and Greg shares his favorite moments from his tenure.

To read Pam's welcome letter, go to: www.isaca.org/letter-from-the-incoming-board-chair

To listen to more ISACA Podcasts, go to: www.isaca.org/podcasts 

View Details

In this episode, ISACA’s Jon Brandt chats with Thomas Lenzenhofer, Business Development Manager at Cisco, about his new ISACA article titled, “The Impact of People on Today’s Information Security Landscape.”

With over 20 years of industry experience, Thomas has a wealth of knowledge to share with ISACA listeners. The security of an organization is a serious matter, and Thomas gives a vivid scenario from his recent ISACA Journal article about how an attack on a country's health care system could be massively disruptive to the daily functions of staff computer systems, possibly causing employees not to receive payroll. Thomas also gives examples of how to properly train staff to avoid an event like this and says that security is a business enabler from the top-down. Tune in now!

To read Thomas' ISACA article, visit: www.isaca.org/impact-of-people-on-information-security-landscape

To listen to more ISACA podcasts, visit: www.isaca.org/podcasts

View Details

Executive Director for GRC for Intelligent Ecosystem (GRCIE) Jenai Marinkovic joins ISACA Director of Professional Practices and Innovation Jon Brandt to address key findings in ISACA's 2022 State of Cybersecurity report and talk about GRCIE program. In this two-part program, they delve into program creation, services offered, student selection and how ISACA research continues to shape their work. 

For more information about GRCIE, visit https://www.grcie.org/

Be sure to like, comment, and subscribe for more ISACA Productions content

View Details

Executive Director for GRC for Intelligent Ecosystem (GRCIE) Jenai Marinkovic joins ISACA Director of Professional Practices and Innovation Jon Brandt to address key findings in ISACA's 2022 State of Cybersecurity report and talk about GRCIE program. In this two-part program, they delve into program creation, services offered, student selection and how ISACA research continues to shape their work. 

For more information about GRCIE, visit https://www.grcie.org/

Be sure to like, comment, and subscribe for more ISACA Productions content

View Details

Application testing is a critical component of a software development lifecycle. A complete testing battery for any application includes not only functionality and usability testing but security and reliability testing as well. However, helping ensure that security testing in particular produces results that focus on actionable items – with accurate relative priorities – has been a persistent challenge. Are actionable items from testing actually going to move the needle in terms of product quality and resilience – especially in how they manage evolving threats? While the “OWASP Top 10” and “CWE/SANS Top 25” are still important, they represent merely a reasonable beginning to a security testing strategy. How do you go beyond those lists and become truly more “adversary-aware” in testing?  In addition, how do you make sure that these testing efforts genuinely help your development teams “shift left” in their thinking and implementation of better security controls in your applications? These are challenges Adobe set out to solve by not just making our testing efforts more extensive or frequent – but smarter, and with as tight of alignment as possible to the software development lifecycle and even closer in modeling real-world adversary threats.

We invite you to join Shannon Lietz, VP, Adobe Security, as she speaks with ISACA's IT Audit Professional Practices Principal, Robin Lyons for a discussion of these issues and others that we must address as an industry to make us genuinely more “DevSecOps”-minded in our approach to application security testing. Robin and Shannon will discuss Adobe’s overall strategy around our application testing efforts and how smarter testing is fundamental to achieving a true “shift left” approach around application security. They will also talk about how this effort is really going to help us deliver the safer digital experiences users are demanding.

For more information go to https://trust.adobe.com

Be sure to like, comment, and subscribe for more ISACA Productions content.

View Details

One of ISACA’s most popular Journal columnists joins us to discuss his most recent release, “Cyber Decisions Only Executives Can Make.” Steven Ross chats with ISACA’s Safia Kazi about cyber recovery plans that organizations have in place and that only when an attack disrupts normal business operations do those organizations realize they should have prepared and planned for operation continuity without the system and data they rely on. As Executive Principal for Risk Master International and fifty plus years of industry experience, Steven shares his insights into cyber recovery plans, categorizing cyberattacks, paying ransom to cyber criminals, and offers his advice on what organizations should do if they find themselves in the middle of a critical cyber decision.

To read the full ISACA Journal article, click here: https://www.isaca.org/resources/isaca-journal/issues/2022/volume-4/cyber-decisions-only-executives-can-make

Be sure to like, comment, and subscribe for more ISACA Productions content.

View Details

ESET, a global leader in cybersecurity, has released its T1 2022 Threat Report, which summarizes the most notable trends that shaped the threat landscape from January to April 2022. Join ISACA’s Research Advisor, Brian Fletcher, as he breaks down the ESET T1 2022 Threat Report with Chief Security Evangelist for ESET, Tony Anscombe.

For more information, check out ESET’s award-winning blog: WeLiveSecurity. Make sure to follow ESET Research on Twitter for the latest news from ESET Research.

Be sure to like, comment, and subscribe for more ISACA Productions content.

View Details

Join ISACA's Lisa Villanueva as she talks with Guy Pearce about his recently released ISACA white paper "Real-World Data Resilience". Guy has a deep knowledge of the movement of data and says "it’s about change and nothing is stable." Lisa asks Guy about AI model implications, Data Drift and cloud adoption. If you want to dive deeper, you can read the entire white paper and learn about data and resilience in its modern context at: https://www.isaca.org/

To listen to more ISACA podcasts, visit: www.isaca.org/podcasts

Be sure to like, comment, and subscribe for more ISACA Productions content.

View Details

BRM Advisory's Jo Stewart-Rattray believes Privacy is a team sport and that every organization needs to be responsible for collecting information and ask if collecting data is necessary. She tells ISACA's Safia Kazi about a Venn diagram approach between security and privacy and why she believes that the main role of a CSO needs to be educating and communicating this to the organization. Jo says that the issue of Data Privacy is not going away and that it will be in the spotlight forever.

To read Jo's full article, follow this link www.isaca.org/where-privacy-meets-security

Be sure to like, comment, and subscribe for more ISACA Productions content.

View Details

On 9 August 2022, Dorie Clark will be the featured speaker at the Member Exclusive Speaker Series.

In this talk based on her book Stand Out: How to Find Your Breakthrough Idea and Build a Following Around It, Dorie Clark explains how to build a following around your ideas. Join Megan Moritz and Dorie Clark as they start the discussion about advancing your business or your cause and inspiring others to listen and take action.

Register for the Member Exclusive Speaker Series at isaca.org/training-and-events

Be sure to like, comment, and subscribe for more ISACA Productions content.

View Details

Jan Anisimowicz is an experienced senior IT manager with over 23 years of experience in GRC, data analysis, broad business, and technical perspective in telco, banking, pharma, and insurance. As the COO and EVP at C&F, he is consistently solving business problems by leveraging his all-around experience in creating and developing IT products and IT service offerings for businesses.

In this ISACA Industry Spotlight episode, Jan Anisimowicz chats with ISACA's Megan Moritz on what he believes the most pressing current business continuity issue is in this always-changing industry. With the recent pandemic, Jan also discusses his active participation in the digital transformation technology for vaccine manufacturers, the key component to the development and delivery of the vaccine. He also explains why he wants to travel to Mars, how some friends convinced him to run 9 marathons, and his dream to build a 14th-century-style restaurant with archival computers and gaming devices!

To learn more about Jan, visit: linkedin.com/in/anisimowicz

To listen to more ISACA Podcasts, visit: isaca.org/podcasts

View Details

Climate resiliency and green innovations are of worldwide interest today, but what is the best way to use skills and expertise that will make a difference?  Cindy Baxter from What's the Risk, LLC talks with Frank O'Brian, leader of the East Boston Climate Coalition to hear about the Coalition's approach, the challenges they've faced, and what they do to overcome obstacles.  This discussion takes us into everyone's backyard to understand how IS audit and risk professionals can contribute to climate resiliency in an impactful way. Please join us to imagine the role you can play in environmental resiliency and justice!

To read Cindy's full ISACA Journal article - follow this link --> www.isaca.org/resilience-and-regulation

Be sure to like, comment, and subscribe for more ISACA Productions content!

View Details

With the growing emphasis on consent for collecting and processing data, some enterprises have turned to tricking data subjects into giving their consent by using privacy dark patterns. Privacy dark patterns can manifest in numerous ways, from confusing user interface design to manipulative language. In this episode Jonathan Brandt, ISACA's Director of Professional Practices and Innovation, is joined by ISACA's Privacy Professional Practices Principal, Safia Kazi, who defines and provides examples of privacy dark patterns, their consequences, and how to avoid them. Jon and Safia also discuss how privacy dark patterns affect digital trust, which can ultimately hurt an enterprise's reputation and customers.

To read the full article, Fostering Trust by Eliminating Dark Patterns click the link: https://www.isaca.org/fostering-trust-by-eliminating-dark-patterns.

Be sure to like, comment, and subscribe for more ISACA Productions content!

View Details

In 2019, Mark Thomas was on the road 40 weeks in 18 US states and 13 countries. In 2020, he pivoted to a workstyle of 1 location, 1 state and 1 country. He tells ISACA's Jessica Barnett that he was actually prepared for a pandemic-type of event that stopped travel in his business plan. Mark and Jessica dive deep into his career journey and their shared history of developing ISACA training content. He also was the CIO of a telecommunications startup that was all remote pre-pandemic. Mark is an accredited ISACA trainer and shares his advice on what credential you should get and how to grow your career. Tune in now to hear Mark's exciting story!

Visit markthomasonline.com for more information on Mark.

Visit isaca.org/podcasts for my ISACA podcasts.

Be sure to like, comment, and subscribe for more ISACA Productions content!

View Details

In the early days of the Covid-19 pandemic, all organizations pivoted to remote work. Now that we are years into working remotely, University of West Florida's Jerry Burch asks if the choices we made in 2020 are still the best ones. He explains to ISACA's Brian Fletcher what the concept of "satisficing" is and why we might want to explore other options before picking a solution for employees’ remote work.

While we have all adjusted to the shift that came in March 2020, Jerry argues that it could happen again and now is the time to consider all options for your cybersecurity team. He also discusses Rational choice theory as it relates to cybersecurity and fighting cybercrime. Tune in now!

To read Cybersecurity In A Covid-19 World: Insights On How Decisions Are Made, Please visit: www.isaca.org/cybersecurity-in-a-covid-world

To listen to more ISACA Podcasts, please visit: isaca.org/podcasts

View Details

Caitlin McGaw answered an ad in the newspaper in 1997 for a position with an Executive Search Firm and she was instantly hooked. She tells ISACA's Hollee Mangrum-Willis that for the past 25 years, she has been passionate about the idea of corporate match-making in the IT Audit space. Hollee asks Caitlin about process improvement within the ISACA community and the examples of candidates using transferable skills to pivot to different positions within the industry. Caitlin discusses the growth mindset and coachability of a candidate during the hiring process and how that translates to performance on the job. Caitlin also explains why she thinks more candidates should pursue careers in IT Audit.

To learn more about Caitlin, visit: www.linkedin.com/in/caitlinmcgaw and www.caitlinmcgaw.com

To listen to more ISACA podcasts, visit: isaca.org/podcasts

View Details

One of Ed McCabe's first childhood memories was taking apart his grandparent's heirloom grandfather clock to find out why it wasn't working. His grandparents were not happy to find it in pieces, but he did get it working again and says that experience was the beginning of a life-long interest in IT, beginning his quest to always ask "why, how and what is technology supposed to do and what is it not, supposed to do?". ISACA's Angie Coleman talks to Ed about his career in the US Navy, private sector and founding his own company The Rubicon Advisory Group. Ed discusses how his organization has supported clients through the most challenging moments during the pandemic, how he learned to find balance for his life while sustaining his passion for education and technology, and what his advice is to ISACA members when preparing for a certification test.

For more information on Ed, visit: www.therubiconadvisorygroup.com

To listen to more ISACA Podcasts, visit: www.isaca.org/podcasts

Be sure to like, comment, and subscribe for more ISACA Productions content!

View Details

"The thing that you plan for is not the thing that is going to happen" says Risk Masters' Executive Principal Steven Ross. Steven talks to ISACA's Safia Kazi about how to prepare for a cybersecurity Event and how to recover. Steven discusses the types of attacks to watch out for, Business Continuity Planning and how to recover from a cybersecurity event. Listen in as Steven shares some ways you can use your imagination to prepare for "the thing that is going to happen".

To read Steven's full article, visit: https://www.isaca.org/resources/isaca-journal/issues/2022/volume-3/cyber-business-recovery

To listen to more ISACA Podcasts, visit: https://www.isaca.org/podcasts

View Details

Everyone starts somewhere and for Niki Gomes, it was at the front desk of a hotel where she worked her way up to hospitality management, before pivoting to accounting and finally to the American Red Cross, where she is currently Senior Internal Auditor. Niki tells ISACA's Melissa Swartz about her passion for people, technology and how the pandemic changed her work life to better connect with her family.

Dive deep into this Industry Spotlight episode as Niki discusses why young Black and Latina women are under-represented in the industry and her plan to remedy that divide, mentoring and what her advice is for the next generation. Tune in now to hear all of Niki's inspiring story!

For more information, check out out https://www.redcross.org/

Be sure to like, comment, and subscribe for more ISACA Production content.

View Details

Paul Philips and Lisa Young will discuss how risk scenarios help decision-makers understand how certain events can impact organizational strategy and objectives. Good risk scenario building is a skill and can take some time to truly master. Paul and Lisa will provide actionable advice on building the best possible scenarios to help your organization better manage risk.

For more information check out https://www.isaca.org/resources/it-risk

View Details

Data now includes, consumer's social media, news, view and even browser searches. From 2010-2020, the amount of data created, captured, and copied in the world increased from 1.2 trillion GB to 59 trillion GB and the amount created in the next 5 years is projected to double. With that massive amount of data being collected, there is a growing sense of distrust with consumers when it comes to privacy. 

RGP's Janis Parthun and Lynn Rohland join ISACA's Safia Kazi for a discussion about data privacy. Janis and Lynn discuss trends from their clients, challenges that AI is introducing and the effect that the pandemic has had on the industry.

Visit ISACA.org/podcasts for more ISACA Podcasts!

Be sure to like, comment, and subscribe for more ISACA content!

View Details

"Cybersecurity is only as good as an organization's weakest link" - Ali Pabrai

Join ISACA's Senior Manager, CMMI Professional Practice, Kileen Harrison as she talks with ecfirst's Chief Executive Officer, Ali Pabrai about his recently released articles, “What Cyberprofessionals Should Know About CUI”, and “US DoD Launches Comprehensive CMMC 2.0 Cybersecurity Framework”. Ali explains the three levels of CCMC 2.0 and goes further in depth on CUI classification.

By the end of this episode, you'll have all the CMMC and CUI "Rocket Fuel" that you need to understand this latest certification.

To read Ali's full articles - https://www.isaca.org/resources/news-and-trends/newsletters/atisaca/2022/volume-8/what-cyberprofessionals-should-know-about-cui

https://www.isaca.org/resources/news-and-trends/industry-news/2022/us-dod-launches-comprehensive-cmmc-2-cybersecurity-framework

Be sure to like, comment, and subscribe for more ISACA content.

View Details

Cyber continues to influence not just business but global conflict too.

In this episode, ISACA’s CyberPro, Jon Brandt chats with Founder and CEO of Anchor Systems, Fred Carr about the current threat landscape, challenges, and misalignment between public and private sectors, and impacts on national and global security. They also dive into the role non-combatants now play on the battlefield and talk about recent US efforts to thwart ransomware.

For more information, check out - https://www.isaca.org/training-and-events/cybersecurity

Be sure to like, comment, and subscribe for more ISACA Production content.

View Details

People are considered the weakest link in any organization’s cybersecurity defenses. Hence, in most cases, the primary targets of cyber-attackers are the employees of the organization. In addition, people are easier to compromise and exploit unlike finding a single software to breach an organization or enterprise business. While a lot of efforts go into improving the existing security infrastructure, ignorance of human resources would leave a significant gap in the defense strategy.

Join ISACA’s Research Advisor, Brian Fletcher, as he is joined by Dr. Yasmin Razack, author of “A Security Awareness Program for PCI DSS Compliance: Implementation and Legal and Ethical Issues to Be Considered”. In this episode, they will be addressing the challenges in implementing a security awareness program to fill this gap and the legal/ethical issues that needs to be considered during implementation. As per the Payment Card Industry – Data Security Standard (PCI-DSS) requirement 12.6, a Security Awareness Program is mandatory to be held at least once a year and for new hires. However, it is not an easy task and cannot be a one-time activity. But if implemented effectively, awareness programs can be the human firewall of the organization. It will make the organization compliant to regulations like PCI-DSS thereby protecting it from fines due to non-compliance, defamation, costs of data breaches and will help improve customer trust and loyalty.

To read Dr. Razack’s full article click here - www.isaca.org/pci-dss-compliance

Be sure to like, comment, and subscribe for more ISACA Production content!

View Details

Making a difference within the cyber industry is of paramount importance to Jo Stewart-Rattray. She is incredibly passionate about encouraging, teaching, and mentoring more women into tech and security fields. In this episode of Industry Spotlight, Robyn Franko, Manager of Event Operations and Services at ISACA, chats with Jo about her background and career path, hobbies, and some interesting challenges the industry faces.

Jo has over 25 years of experience in the IT field, some of which were spent as CIO in the Utilities and as Group CIO in the Tourism space, and with significant experience in the Information Security arena, including as CISO in the healthcare sector. She underpins her information technology and security background with her qualifications in education and management. She specializes in consulting in risk and technology issues with a particular emphasis on governance and security in both the commercial and operational areas of businesses. Jo provides strategic advice to organizations across a number of industry sectors, including banking and finance, utilities, manufacturing, tertiary education, retail, healthcare, and government. 

She has chaired several of ISACA’s international committees, including the Board Audit & Risk Committee, Leadership Development, and Professional Influence & Advocacy.  She served as an Elected Director on ISACA’s International Board of Directors for seven years and was the founder of its global women’s leadership initiative, SheLeadsTech. Because of her involvement with ISACA and the SheLeadsTech program and her rural background Jo was selected from a large number of candidates to be one of only two non-government delegates and was invited to join the official Australian Government delegation to the 62nd Session of the United Nations Commission on the Status of Women (CSW62) held in New York in March 2018.  She returned to the UN in 2019 and again spoke at two UN events this year. She has spoken on Capitol Hill during a Day of Advocacy designed to bring tech leaders together in one place to discuss issues related to women in technology and then to meet with congressional representatives and Senator’s offices.

View Details

It's hard to believe the quarter century mark has almost arrived!  Have you thought about what you would like your work world to be in 2025?  Have you dreamed of more flexibility or better access to information so you can get work done faster? ISACA’s IT Professional Practices Lead, Kevin Keh, sits down with Cindy Baxter, Director of What's the Risk, LLC to talk about her recently released article “The Transformative Power of Mobility”. Cindy spoke with three professionals from three different industries and asked them how the promise of mobility could change their work lives.  Hear about the work her interviewees do and the aspirations they have for themselves and their professions.  Can IS risk and audit professionals make their mobility dreams come true?  Tune in to the conversation and see what you think!

To Read Cindy’s full ISACA Journal Article click here - www.isaca.org/power-of-mobility

Please like, comment, and subscribe to the ISACA Media channels to keep up to date with all of ISACA’s new content.

View Details

"For me, it's all about working with people... at the end of the day, you want to work in a place where you can trust other individuals, you can get to know other individuals, and being personable with one another makes an organization great to work for," Raven David tells ISACA.

In this Industry Spotlight episode, we meet Raven David, Cyber Risk and Governance Manager for The University of New South Wales (UNSW).

Fascinated with technology at an early age, the native Australian recalls that he spent part of his childhood disassembling computers and putting them back together to understand better how they worked. This passion led him on a fantastic life journey and set him on a path to dominate the industry as a risk management, governance, compliance, assurance, and emerging technologies expert.

Raven talks about his less traditional educational and career track. While working full-time, he managed a full-time class schedule simultaneously, to a career that allowed him to establish and manage a cyber risk and compliance team within a corporation of 5,000+ employees.

Listen as Raven recaps the success of his cybersecurity awareness program, gives thoughtful advice to the next generation of young professionals, and discusses his current self-educating project, 3D printed chess set with Arduino-powered actuators and a Python chess engine. 

As an active contributor to ISACA and the ISACA Sydney Chapter, Raven recently volunteered, mentored, and led the 2021 Oceania Conference Taskforce and is currently a CRISC Certification Working Group.

In this ISACA Industry Spotlight episode, get to know the next-gen cybersecurity leader, Raven David.

Connect with Raven David on LinkedIn: https://www.linkedin.com/in/ravendavid/ 

Press play now, and don’t forget to subscribe!

View Details

Is Privacy a commodity? This episode explores the future direction of privacy and the demise of privacy in the digital age. Could privacy become something that people cannot afford, creating a two-tier system of internet users — those who can afford privacy and those who cannot?

Join Safia Kazi, ISACA's Privacy Professional Practice Advisor, as she speaks with Steven Ross, Executive Principal of Risk Masters International, about his recently released ISACA article "Privacy for Sale.” Listen in as they chat about what privacy could be worth, and if this is a decision we must make soon?

To read Steve’s full ISACA Journal article, please check out www.isaca.org/privacy-for-sale

We would love to hear from you, please leave your comments below. If you enjoyed this episode, please click the like and subscribe buttons for more from ISACA!

View Details

Join ISACA’s Performance Based Training Engineer, Collin Beder as he speaks with Tom Schneider, Senior Associate of Proactive Advisory for Cyber Defense Labs as they discuss Tom’s recently released article “Ensuring that Cybersecurity is Everyone’s Job”.  Employees expect to focus on the responsibilities that are communicated to them, for example in their job descriptions. If cybersecurity and privacy responsibilities are not documented in job descriptions, then it is likely that staff will assume that cybersecurity is not a primary responsibility for them because management did not consider it significant enough to include. Collin and Tom will delve into these topics and why keeping cybersecurity on everyone’s mind will be better in the long run.

To read Tom’s  full article, please check out https://www.isaca.org/resources/isaca-journal/issues/2022/volume-2/ensuring-that-cybersecurity-is-everyones-job

We would love to hear from you, please leave your comments below. If you enjoyed this episode, please click the like and subscribe buttons for more from ISACA!

View Details

ISACA’s Jon Brandt welcomes Dr. Chase Cunningham aka Dr. Zero Trust to the ISACA CyberPros podcast. You may know Chase from his own podcast, Dr. Zero Trust, or book series, Cynja. Chase dives deep into Zero Trust and Jon gets Chase's opinions on how legislation relates to ZT, and thoughts on attack trends, including how to outsmart bad actors.

Listen now and don’t forget to subscribe and write in the comments!

For more information check out https://www.isaca.org/credentialing/cybersecurity

Interested in hearing more from DrZeroTrust - check out his podcast at:

https://anchor.fm/chase-cunningham8

View Details

Tune in as ISACA’s Kevin Keh talks with the Chief Security Evangelist of ESET, Tony Anscombe about the latest released report from ESET.

ESET, a global leader in cybersecurity, has released its T3 2021 Threat Report, which summarizes the most notable trends that shaped the threat landscape from September to December 2021.

For more information, check out ESET’s award-winning blog: WeLiveSecurity. Make sure to follow ESET Research on Twitter for the latest news from ESET Research.

To read the full Report, please check out https://www.welivesecurity.com/2022/02/09/eset-threat-report-t32021/

We would love to hear from you, please leave your comments below. If you enjoyed this episode, please click the like and subscribe buttons for more from ISACA!

View Details

Today's Page to Podcast features ISACA's Kevin Keh and Donald Tse, the Head of Cyber & Technology Risk at Mox Bank and author of "Cybersecurity and the Technology Risk in Virtual Banking", as they dive into the virtual banking scene in fintech. This will compare the differences between a digital-only virtual bank and a brick-and-mortar traditional bank and therefore the underlying challenges and risks they face. As a founding member of Mox Bank, Donald will also share his experience in building digital trust with customers and regulators in this whole new cloud-native bank.

To read Donald's full article, please check out https://www.isaca.org/resources/isaca-journal/issues/2022/volume-1/cybersecurity-and-technology-risk-in-virtual-banking

We would love to hear from you, please leave your comments below. If you enjoyed this episode, please click the like and subscribe buttons for more from ISACA!

View Details

Working from alternate work sites using unsecure networks may be here to stay, but there is much to learn from 2020 that can help improve cybersecurity capabilities for remote staff. Listen in with ISACA's Deputy Director of One in Tech, Hollee Mangrum-Willis as she talks with Tom Conkle, CEO of Optic Cyber Solutions, and Kelly Hood, EVP of Optic Cyber Solutions. They will discuss various technical solutions such as using VPNs, enabling MFA, encrypting mobile devices and laptops, and leveraging services such as a CASB, and how, ultimately, training and awareness are the most effective at protecting organizational data.

To read the full article, be sure to check out https://www.isaca.org/resources/news-and-trends/industry-news/2021/lessons-learned-from-a-year-of-remote-work.

We would love to hear from you, please leave your comments below. If you enjoyed this episode, please click the like and subscribe buttons for more from ISACA!

View Details

Listen in as ISACA’s Director of Professional Practices & Innovation, Jon Brandt, is joined by Muneeb Imran Shaikh, author of "Pakistan’s Cybersecurity Policy in 2021: A Review". They will dig deeper into the report and discuss the policy changes that Pakistan and other Central Asian countries will see moving forward.

To read the full report, be sure to check out https://www.isaca.org/resources/news-and-trends/newsletters/atisaca/2021/volume-39/pakistan-cybersecurity-policy-in-2021-a-review.

We would love to hear from you, please leave your comments below. If you enjoyed this episode, please click the like and subscribe buttons for more from ISACA!

View Details

Both XDR and Zero Trust are useful security concepts, but they are sadly overhyped. Listen in as ISACA's Research Advisor, Brian Fletcher and Trend Micro's Bill Malik look into the realities behind ZDR and Zero Trust, how ransomware works, and how the both XDR and Zero Trust can help organizations minimize their vulnerabilities

Interested in reading Bill's full ISACA Blog? Click the link and download a copy today! https://www.isaca.org/resources/news-and-trends/industry-news/2021/using-zero-trust-and-xdr-to-stop-ransomware.

We would love to hear from you, please leave your comments below. If you enjoyed this episode, please click the like and subscribe buttons for more from ISACA!

View Details

Mark Thomas (Founder, Escoute) and Caren Shiozaki (EVP & CIO, TMST, Inc.) join ISACA's Lisa Villanueva for a conversation about Environment, Social, Governance or ESG. Mark and Caren dive deep into why your organization will want to know about ESG. Mark & Caren agree “the ESG Train” has already left the station. Organizations need to jump on board now!  Click play now to learn about ESG!

For more information, don't forget to check out https://www.isaca.org/resources/insights-and-expertise/white-papers#sort=relevancy&layout=card and https://youtube.com/playlist?list=PLHaB3gI5mcQa0zjjXSyC3ZBlKmsct9H4g 

View Details

The Sarbanes-Oxley (SOX) Act was passed by the United States Congress in 2002. 20 years later, ISACA's IT Audit Professional Practice Lead, Robin Lyons chats with Cindy Baxter, Director at What’s the Risk, LLC on all things SOX. Cindy goes in-depth on the scandals that caused SOX to be enacted, legislation's effect on corporate behavior, how SOX has affected the audit profession, and what trends she sees in the regulatory landscape in 2022 and beyond!

Interested in reading Cindy’s full ISACA Journal article? Click the link and download a copy today! https://www.isaca.org/resources/isaca-journal/issues/2022/volume-1/the-impact-of-sox-on-the-industry-20-years-ago-and-today

We would love to hear from you, please leave your comments below. If you enjoyed this episode, please click the subscribe button for more from ISACA!

View Details

Listen in as Safia Kazi, ISACA's Privacy Professional Practice Advisor, as she speaks with Steve Ross, Executive Principal of Risk Masters International, about his article "Privacy in the Dark (Data)".

Organizations have a lot of “dark data”; information that they have collected, filed and forgotten.  Some of it concerns people, so there is a privacy concern about how that data is secured.  Both enterprising cyberattackers and litigants using eDiscovery tools have incentive to search through this dark data to see what they might make use of.  The potential for misuse calls for greater attention to the security of this data.

For more information, don't forget to check out https://www.isaca.org/resources/isaca-journal/issues/2022/volume-1/privacy-in-the-dark-data

View Details

ISACA's CyberPro Jon Brant breaks down industry news stories so far in the new year: Log4j, Cyber Insurance, Augmented Reality/Virtual Reality, Metaverse, Deep Fakes, and even the legal discussion around vehicle car data. Tune in now to hear Jon's hot takes on all this and more. Happy listening!

For more information, don't forget to check out https://www.isaca.org/resources/news-and-trends/isaca-podcast-library.

View Details

What are the main risks that most enterprises need to consider when it comes to social media? If you don’t know, you and your organization are in danger of serious reputational risk! Watch as ISACA’s IT Governance Job Practice Lead, Lisa Villanueva discusses the risks of social media with Robert Findlay, Global Head of IT Audit at Glanbia. Social media is one of the easiest platforms to hack and it isn’t just from external threat actors. Oftentimes, the hack is coming from inside the organization from current and recently released employees. And remember, it doesn’t matter who hacks into your social platform, it is your enterprise that gets the blame and negative press. Robert and Lisa also discuss the current state of security on social media platforms and how organizations can benefit by bringing in auditors to show how to control the management of social media and avoid these pitfalls.

Don't forget to check out https://www.isaca.org/resources/isaca... for more information!

View Details

Blake Curtis is a global business risk and security engineer for Deloitte Global and a research scientist completing his Ph.D. in cybersecurity and risk management. Today he breaks down frameworks, governance, and governmental controls from the board level to the code level. ISACA's Lisa Villanueva then asks him about years of experience vs. years of exposure as he gives his solution for the industry skills gap. In addition, he gives us some history on ISACA and CISA. Press play now to get into it with Blake!

A note from the author: Blake Curtis

Blake is asking for listeners' assistance in completing his research by taking a quick survey. He is collecting responses from IT auditors; however, we also collect survey responses from IT professionals and cybersecurity practitioners. To learn more please read below.

Your Choice: Anonymity or Engagement 

The participants' responses will remain anonymous. As a result, no one will be able to identify them or their answers. Additionally, no one will know whether they participated in the study unless they received a certificate of completion and decide to share it via social media or other media sources.

However, we strongly encourage each participant to share their certificate on LinkedIn and share the survey with other candidates. Their contributions will inform the scientific body of research and potentially influence equitable hiring decisions in the Governance, Risk, and Compliance (GRC), Cyber, and Audit professions.

Get CPE Credit! 

Participants will have the option to receive a certificate of completion at the end of the survey. They may be able to use this certificate to receive Continuing Professional Development (CPD) or Continuing Professional Education (CPE) units.

Take this survey/assessment, earn CPE credit and help Blake with this market research! https://cyberauditor.questionpro.com

To reach the full article, please check out https://www.isaca.org/resources/isaca-journal/issues/2021/volume-6/how-to-construct-a-governance-system-from-the-board-level-to-the-code-level

View Details

ISACA’s Cyber Pro, Jon Brandt, invites information security guru, Naomi Buckwalter, Director of Information Security and IT to the podcast to discuss hot and heavy topics within Cybersecurity and the IT industry. Listen in as they hash out the current and future trends. 

View Details

While our development teams have been busy running full speed ahead using the latest and greatest technology to build amazing products, security teams haven’t always been known to keep the same pace – and we have reached a point of “developer revolt.” Security teams are still too often viewed as producers of “design constraints” by development teams versus “reliable partners” in helping them build better software. The path to changing this is getting security more tightly integrated into the DevOps pipeline – and working to make security even more of everyone’s responsibility. In this podcast Shannon Lietz, Adobe’s VP of Vulnerability Labs, will discuss some of the opportunities for security teams to become trusted partners, providing a roadmap for how DevSecOps needs to evolve to reach necessary maturity, and discuss some of the efforts that can help the broader security industry get better at this essential security muscle.

View Details

Join Kevin Keh, IT Professional Practices Lead - Research Development for ISACA, and guest, Ramses Gallego, International Chief Technology Officer for CyberRes in the latest session of our LinkedIn Live series on Emerging Technology as they discuss four of the most prominent forms of ultra-emerging technologies including Quantum Computing, Nanotechnology, Internet of Behavior (IoB) and XR/VR. For each technology, they’ll dive deep into what the technology is, why it’s considered emerging, and ultimately, why it’s something your organization should keep an eye on as it continues to evolve. Happy viewing!

View Details

ISACA’s Director, Channel Business Development, Chris DeMale is joined by ServiceNow’s Director of Product Marketing, Karl Klaessig in this follow up interview that takes a deeper look into his presentation during ISACA’s Virtual Summit session, Security Operations Challenges in 2021. The presentation discussed how opportunistic and tenacious cybercriminals can be. Klaessig takes explores how dissecting attackers' behavior and automating responses can better defend your attack surface.

View Details

This ISACA TV interview is a discussion about information security concerns (and challenges), evolution, and the future. Topics covered include mobile computing devices, the Internet of Things (IoT), artificial intelligence (AI), cyber threat intelligence (CTI), software tools, and malware. Threats, risk, safeguards, and countermeasures will be reviewed along with some new ideas and approaches. Tune in as ISACA’s Information Security Professional Practices Lead, Jon Brandt chat with Larry Wlosinski, Senior Consultant at Coalfire Federal about his recently release article, Cyberthreat intelligence as a Proactive Extension to Incident Response.

View Details

Enterprises use machine learning to validate who they are doing business with and to find new opportunities. ISACA's IT Professional Practices Lead Kevin Keh discusses secure machine learning with Protegrity's Chief Security Strategist Ulf Mattsson. Ulf explains Trusted Execution Environment (TEE), synthetic data, and encryption keys. All these technologies can be sometimes misunderstood, but they are changing the digital landscape, so listen in now!

Link: https://www.isaca.org/resources/isaca-journal/issues/2021/volume-6/how-innovative-enterprises-win-with-secure-machine-learning

View Details

Jon Brandt (Information Security Professional Practices Lead at ISACA) and Renju Varghese (Fellow and Chief Architect at HCL Technologies) break down the State Of Cybersecurity 2021 —Part II report. Threat actors did not take advantage of clients more during the pandemic, but there have been higher instances of attacks or attempts of attacks during the past 18 months. This has brought attention to organization’s boards and executives to show Cybersecurity in a more serious light than it was pre-pandemic. Tune in now to hear what Renju says you can expect in 2022!

ISACA's State of Cybersecurity 2021 – Part II report:

https://www.isaca.org/why-isaca/about-us/newsroom/press-releases/2021/new-isaca-study-finds-cybersecurity-workforce-minimally-impacted-by-pandemic-but-still-grappling

View Details

Listen in as ISACA’s Information Security Professional Practices Lead, Jon Brandt grabs the podcast microphone and takes over November’s Cyber Pros to discuss CISA’s Directive Breakdown.   

View Details

Why is the cloud still considered an emerging technology in 2021? Why is the cloud both an enabler and catalyst for all other technologies? How has the cloud changed our organizational eco-systems? What is the future of cloud services?  Join ISACA’s Chief Futurist, Dustin Brewer as he and  Julia Hermann— Head of Security Architecture and Cyber Defense at Giesecke + Devrient answer these questions and more regarding our oldest emerging technology, the cloud!

View Details

In honor of Cybersecurity month, ISACA’s Director of Communications, Kristen Kessinger, and Information Security Practices Lead, Jon Brandt, discuss the findings of this year’s ISACA State of Cybersecurity research study and what they may mean for you as both members and leaders of your IT organization.

View Details

Join ISACA’s CEO David Samuelson as he discusses ISACA’s Global Strategy with ISACA’s Chief Global Strategy officer Chris Dimitriadis. Chris shares his career path to ISACA, industry trends, advice to the next generation and how ISACA will continue to innovate in the future!

View Details

What is digital body language and why does it matter? Join ISACA's Director of Global Volunteer Engagement Megan Moritz as she speaks with Erica Dhawan, author of Digital Body Language: How to Build Trust and Connection, No Matter the Distance. Megan and Erica discuss our modern digital environments and how we can prioritize thoughtfulness over hastiness, building trust from behind a computer screen and how collective conversations are now possible in the digital world. 

On November 30th, ISACA’s membership experience team will be hosting a first-ever ISACA Speaker Series. A complementary, member-exclusive, CPE-eligible event. This is the premier event in a series of experiences centered around ideas on leadership, including leading an organization, others, and yourself. In our first interactive member-only session, Speaker Erica Dhawan, will combine cutting-edge research with engaging storytelling to decode the new signals and cues of leading and communicating that have replaced traditional body language.

Register Now: 30 November Speaker Series Webinar: https://store.isaca.org/s/lt-event?id=a334w000004VJBQAA4 Book:  Digital Body Language: How to Build Trust and Connection No Matter the Distance:  https://us.macmillan.com/books/9781250246523

View Details

Join ISACA’s Director of Communications, Kristen Kessinger as she interviews ISACA’s Information Security Professional Practices Lead, Jon Brandt about what is currently happening in the cybersecurity workforce. Listen in as Jon explains how the demand for cybersecurity resources is large, but the workforce pipeline is not keeping pace and how that makes hiring difficult for organizations. Jon and Kristen also discuss the “Great Resignation”, how the pandemic has helped make job hunters more selective, and if the NIST/NICE frameworks are still valued. Take a listen and enjoy!

View Details

Listen in as ISACA Conference Europe Keynote speaker, Vinh Giang's discusses how he became the successful entrepreneur, magician and keynote speaker that he is today. Vinh’s life story is unique. The child of Vietnamese refugees, Vinh experienced bullying, shyness, and other situational hardships, he realized he wanted to leave school to pursue his passion of magic. He has since become a successful entrepreneur and keynote speaker. Vinh discusses what we as professionals can do to expand our communications skills by taking risks and overcoming our fears. Vinh will also explain what you can look forward to in his upcoming ISACA Conference Europe keynote speech. ISACA Conference Europe is 20-22 October 2021. Click Here to Register Now!

interested in learning more about Vinh Giang, check out his website and social media links below: 

Vinh Giang Website

YouTube

Instagram

Keynote Speaker

View Details

One of the cornerstones of managing the unknown is defining it and measuring it. Anything that could cause harm to an organization needs to be tracked and managed. As more and more transactions occur entirely on digital platforms or are at least facilitated digitally, the ability of cybersecurity issues to trigger a breakdown in the delivery of products and services is a top concern of executives and boards. Cyber risk quantification (CRQ; sometimes called cyber risk economics) has been a solution to which many have turned in order to better understand their specific cyber risk exposure and to rationalize their options to manage it. This roundtable discussion lead by ISACA's Paul Phillips provides an overview of what exactly cyber risk quantification is and some of the important foundational elements of cyber risk measurement methodologies. Paul talks to Jack Jones (Chief Risk Scientist, RiskLens and Chairman, FAIR Institute), Tony Martin-Vegue  (Senior Security Risk Engineer, Netflix), and Evan Wheeler (Vice President of Risk Management, NDVR)

View Details

Digital transformation has heightened due to the pandemic. We went from, “we can’t work from home” to “we can only work from home moving forward”. Because of this change, our cyber risk increases and organizations need to take new action when it comes to risk. Join ISACA’s Risk IT Risk Professional Practices Lead, Paul Philips as he talks with Dr. Jack Freund—Head of Cyber Risk Methodology at VisibleRisk—about how to effectively communicate Cyber Risk to a Board of Directors. Organizations need to understand the financial ramifications of all aspects of cyber risk. Along with risk quantification, organizations need to work with and inform the BOD about the risk appetite for certain projects, how much risk tolerance the organization can afford to deal with and more.

View Details

Cybersecurity Maturity Model Certification or CMMC is a new security program being released by the US DoD. If you are a DoD contractor, your livelihood could be at stake as contract requirements and contractors will need to be certified or a contract won’t be awarded. Listen in as TelaTek's Director of Operations, Johann Dettweiler breaks down these new requirements published in his latest journal article with ISACA's CMMI Professional Practice Lead, Kileen Harrison. Johann discusses the importance of all organizations —big or small—going through the different levels of security in the CMMC guidelines, starting at Level 1 and working their way up. What is the most important thing an organization needs to get started? The ability to read, familiarize and understand the different levels of CMMC otherwise, they won’t know how to implement it in their organization and will have to hire a third party. These CMMC requirements are here to stay and will only continue to get more stringent the more hacks and attacks keep increasing.

View Details

What is security as a service and when is it needed?  Tune in as ISACA’s Cyber Pros explain how the increase in hacks and attacks are forcing companies to take cyber security more seriously. The bad news is, there is a lack of cyber security professionals in the field and those who do have the necessary skillset to manage a company’s security are becoming more and more costly. Academia is trying to help get the security workforce up to speed quickly, but they are failing. Until we see an influx of new and skilled cyber security professionals, security as a service is an option that can save your company both time and money and help assure that your company’s data and information is safe and secure.

For more information, check out ISACA’s State of Cybersecurity 2021.

View Details

Everyone needs a resilient operating model, and the pandemic has been the reality check showing how necessary it is to have a plan. Was your small-business or corporation prepared for the shift to remote work in early 2020? If not, you probably realized that business continuity is more than having the right systems and applications in place. The most important factor is people! Although both large and small enterprises have accommodated and adapted, the smaller organizations with fewer resources and time have faced equal or greater hurdles when it comes to this type of planning.

Join ISACA’s IT Professional Practices Lead, Kevin Keh, as he interviews Cindy Baxter, Director, What’s the Risk, LLC and discusses the importance of having a business continuity and resilience plan for your business. Cindy discusses consistently updating your crisis team and notification systems, the importance of allowing an auditor to fully understand your business, accepting critical feedback throughout the entire audit process vs. waiting for the final report and more! Cindy also mentions how small business owners and employees shouldn’t get defensive or take the findings personally. Remember, the value comes not in the result, but in the adoption of the results and recommendations.

For more information on this topic, click here to download ISACA’s IT Business Continuity/Disaster Recover Audit Program.

View Details

Organizations are increasingly concerned about data security in several scenarios, including collecting and retaining sensitive personal information; processing personal information in external cloud environments, and information sharing. Commonly implemented solutions do not provide strong protection from data theft and privacy disclosures.

Privacy and risk management professionals are particularly concerned about the privacy and security of data analytics that are shared externally. Compliance of privacy regulations such as the US State of California Consumer Privacy Act (CCPA), the EU General Data Protection Regulation (GDPR) and other emerging regulations around the world require techniques for secure processing of sensitive data.

Listen in as ISACA’s Safia Kazi interviews Chief Security Strategist and data protection expert, Ulf Mattsson on the latest on privacy-preserving techniques.

View Details

Why should you listen to ISACA’s CyberPros?  Find out as Dustin Brewer and Frank Downs explain how they got started in the cybersecurity field and grew their knowledge and experience to become the cyber professionals they are today. Dustin and Frank discuss their traditional and non-traditional paths to learning, their experience working in the US government and the importance of earning a certification and continuing your education. Want to know how to get started in Cybersecurity? Start here by listening to this podcast.

View Details

Join ISACA's Dustin Brewer as he tells you what you need to know about IoT now – why is it still considered an emerging tech? What are the biggest cybersecurity threats, and what opportunities will the Internet of Things bring in the next five years? Listen in to find out!

View Details

ESET has released its T1 2021 Threat Report, summarizing key statistics from ESET detection systems and highlighting notable examples of ESET’s cybersecurity research. The featured theme of the report recounts ESET’s analysis of a vulnerability chain that allows an attacker to take over any reachable Exchange server. The attack has become a global crisis, and this research identifies more than 10 different threat actors or groups that likely leveraged this vulnerability chain.  

Join ISACA’s Information Security Professional Practices Lead, Jon Brandt, and ESET’s Chief Security Evangelist, Tony Anscombe, as they examine the findings of the ESET TI 2021 Threat Report. Dive deep into areas such as the rapid growth of “infostealers,” including the data they collect and how it is monetized; the increasing number of cryptocurrency threats; and recent vulnerabilities and potential exploitation of exchange servers and the resulting impact on organizations.

View Details

Every day, the risk of cyber and ransomware attacks regularly increases in frequency and danger. But despite the proof in numbers, many organizations still don’t recognize the need to fortify their fortress and improve the strength of their Cybersecurity practices. This is because the leadership of many organizations don’t understand cybersecurity or even want to understand it. That is —until it is too late.

In this episode, ISACA’s Cyber Pros, Dustin Brewer and Frank Downs explain the importance of cybersecurity and provide real world examples of why it pays to be proactive, not reactive when it comes to your company’s security. In the end, it will not only save your company a ton of time and money, but may even save your company!  

Interested in learning more on this topic Check out ISACA’s State of Cybersecurity 2021 report at https://www.isaca.org/go/state-of-cybersecurity-2021 .

View Details

Finding a balance between a pleasant user experience and stringent security requirements can be a challenge. User authentication has become increasingly complex over the years, blending usernames and passwords with second factor authentication, like One Time Passwords (OTP). In many cases users need to re-authenticate many times a day depending on the applications or devices they use. For many users extremely long and complex passwords blend across work and personal accounts which reduce security and increase frustration and confusion. Is it even possible to balance heightened security and enhance the overall user experience? Adobe believes this is possible. We want to share our Zero-Trust framework for achieving this balance, through “ZEN.” The Zero-Trust Enterprise Network (or ZEN) project from Adobe is an initiative based upon numerous best practices and principles from various digital workspaces.

View Details

Listen in as ISACA Journal columnist, Steven Ross, CISA, CDPSE, AFBCI, CISSP, MBCP, delves deeper into his latest article, “Advanced Security for Secret Information.” As a follow up to his two previously published journals, “Keeping Secrets,” and “Secrets and Privacy,” Ross continues to make the case that the protection of secret information is becoming a significant issue in cybersecurity.

All companies —no matter how small— need some form of a security program to protect their secret information. However, the security that is currently in place to protect those secrets are oftentimes insufficient. Steven discusses the use of encryption and extended monitoring to keep the “bad guys” at bay from stealing your important information.

View Details

David Samuelson is back and continuing his discussion of ISACA’s Digital transformation. This time David interviews members of ISACA’s IT team — CTO, Simona Rollinson; Sr. Director, Application Development, Sean Ways; and Sr. Director of Enterprise Project Management, Amy Witkowski. Listen in as they discuss ISACA’s new, customer-centric CMS and how we have and will rely on technology through the pandemic and beyond. The team also explains how ISACA has recruited the right talent to staff up for the programs of the future through the power of  “people, process, and technology”.

View Details

Join ISACA’s CEO David Samuelson as he discusses the positive potential of technology with ISACA’s Chief Product Officer, Nader Qaimari. Listen in as Nader explains how ISACA’s newest certifications (Emerging Technology  and Information Technology) were built with performance based testing and gamification to help beginners and young professionals get started in the IT field. Providing this new learning will help hiring managers who are struggling to find the right candidates due to these missing skills gaps. David and Nader also discuss ISACA’s new unified learning platforms that are scalable and supports the needs of our global members. 

View Details

Is your home printer or fax machine an IOT device? You bet it is! Dubbed ‘Faxploit’, research has shown how cyber criminals can infiltrate any home or corporate network by exploiting wireless printers and fax machines. A fax numbers is all it takes to launch this type of attack.

Listen in as Cyber Pros, Dustin Brewer and Frank Downs discuss the need for these home devices, how—they too—are at risk of being hacked and their best suggestions on how to mitigate this vulnerability.

So fill your paper tray, test your fax connection and press play …it’s time for a Cyber Pros breakdown!

View Details

The computer chip shortage resulting from the COVID-19 pandemic may sound like a mere supply chain issue, but the ramifications of it have also been felt in the cybersecurity sector. In this episode of the ISACA® Podcast, sponsored by ESET, security experts Dustin Brewer and Frank Downs explore the impact of the ongoing computer chip shortage and discuss what makes it a concern from both a security and a business operations perspective.

View Details

Volunteering to participate in medical research is a commendable act of service, but to do so can understandably raise questions about subject privacy. In this episode of the ISACA® Podcast, ISACA® Journal columnist Cindy Baxter discusses how patient privacy has changed in the digital age and explores ways that auditors can conduct better audits of privacy programs within research organizations.

View Details

To survive—and thrive—after a digital transformation, organizations must establish a robust resilience program. In this episode of the ISACA® Podcast, sponsored by ServiceNow, Risk Solutions Specialist Brandon Reese explains how to navigate the path to resilience by continuously monitoring compliance, creating cross-functional workflows and embedding risk awareness throughout the entire enterprise. To access the ServiceNow webinar on which this podcast is based, visit the Future of Data Protection, Privacy and IT Risk Management page of the ISACA website.

View Details

Cryptocurrency has helped make blockchain technology mainstream, lauded by the general public for its decentralizing capabilities and in the cybersecurity space due to its integrity and self auditing. In this episode of the ISACA® Podcast, sponsored by ESET, security experts Dustin Brewer and Frank Downs discuss how and why cryptocurrency has been so widely adopted and predict where they think it will go next.

View Details

It is no secret that there has long been a gap in the cybersecurity workforce. But enterprises can take a step toward filling it by looking to nontraditional candidates, according to Adobe’s Director of Application Security, David Lenoe. In this episode of the ISACA® Podcast, sponsored by Adobe, Lenoe discusses how enterprises can diversify the talent and hiring pool for security, including best practices and tips for attracting great candidates, and gives advice to professionals that may not have traditional security experience but are hoping to break into the field.

View Details

Remote access tools can be an IT blessing, allowing tech support to quickly and remotely troubleshoot computer problems while reducing the need for lengthy conversations with confused employees. But just as remote access can be used for good, malicious cyberactors can leverage it to cause financial or even biological harm. In this episode of the ISACA® Podcast, security experts Dustin Brewer and Frank Downs explore different ways remote access tools can be exploited and how it can be avoided.

View Details

The COVID-19 pandemic has prompted massive changes within the modern workforce, providing risk assurance and audit professionals a unique opportunity to assess how they approach the risk framework. In this podcast, ISACA® Journal columnist Cindy Baxter discusses how technology shapes behavior, what tips information systems professionals can use for success and what risk will look like post-pandemic.

View Details

With today’s advanced cloud capabilities, cybersecurity is an obvious priority at many organizations. But that can leave physical security diminished or outright neglected. In this episode of the podcast, security experts Dustin Brewer and Frank Downs discuss what makes it so important to secure physical assets and how enterprises can do so effectively.

View Details

IT enterprises with strong ethical frameworks are successful not only in making a greater, more positive impact on society, but in terms of financial and reputational status as well. To achieve this, however, organizations must be able to involve everyone from entry-level staff to executive leadership, all while anticipating scenarios that could occur in the future. In this episode of the ISACA® Podcast, ISACA® Journal columnist Ian Cooke explains the risk zones of the Ethical Operating System, the impact of bias upon ethics, the role of automated technology within an ethical context and more.

View Details

APTS are typically driven by experienced cyberactors, significant funding and a target that possesses extremely sensitive data. The depth of these threats means that virtually no enterprise is immune, even those which have implemented highly sophisticated cybersecurity measures. In this podcast, ISACA® security experts Dustin Brewer and Frank Downs discuss how to identify APTs, what makes them unique and how any organization can fall victim to such a threat.

View Details

Increasing pressure on many organizations to meet compliance requirements has resulted in a push to adopt a zero trust approach. But for implementation to be successful, enterprises must obtain a thorough understanding of the nuances of the framework. In this episode of the ISACA® Podcast, sponsored by Vanguard Integrity Professionals, Brian Marshall and Milt Rosberg from Vanguard Integrity Professionals discuss why it is important to “trust nobody and verify everybody” from a security perspective, how to get stakeholder buy-in, what makes internal threats particularly dangerous and more.

View Details

Since its conception, microcomputing has made waves in the open source community, providing an accessible and relatively user-friendly way for technology owners to create their own amateur smart devices before mass-manufactured ones hit the market. Rather than investing in an expensive, highly controlled computer setup, microcomputing offered users a low-cost, highly customizable method of achieving wireless access. In this podcast, ISACA® security experts Dustin Brewer and Frank Downs discuss how microcomputing has evolved and the many ways it can be used.

View Details

The dust of the COVID-19 pandemic has begun to settle and professionals around the globe are now more comfortable with the realities of remote work. Yet even increased familiarity with working from home still leaves room for security threats to arise. In this podcast, Edward Morse and Vasant Raval, authors of the ISACA® Journal, vol. 5 article “Working From Home—Reassessing Risk and Opportunities,” discuss how enterprises can evaluate the risk of remote software and devices, describe the most effective ways to secure home technology and consider what parts of working from home are here to stay even beyond the pandemic.

View Details

Phishing emails and dangerous links are among the most pervasive threats to cybersecurity, capable of targeting everyone from seemingly impenetrable government organizations to college students’ university email accounts. The COVID-19 pandemic has only worsened the malware problem, as malicious hackers attempt to impersonate health authorities to steal personal information through social engineering. In this podcast, ISACA security experts Dustin Brewer and Frank Downs discuss malware: what it is, what forms it can take and how it spreads.

View Details

Once a technological marvel, the idea of a wireless connection to the Internet has become so engrained in the digital world that it is hard to fathom a time when that was not the case. But just because Wi-Fi has gone mainstream does not mean it is static. In this episode of the Cyber Pros Exchange series, security experts Dustin Brewer and Frank Downs consider the history of Wi-Fi, how it reached its position today and why it’s so important that it be secured properly.

View Details

The wave of remote working arrangements implemented as a response to the COVID-19 pandemic has introduced new and often unpredictable IT vulnerabilities. This has made it all the more important to identify Key Risk Indicators, or KRIs, as a method of providing a warning before risk can develop any further. In this episode of the ISACA Podcast, sponsored by Galvanize, Greg Slayton discusses ways that the pandemic has stretched technology’s limits and how organizations can use KRIs to restore proper risk management.

View Details

Putting effective privacy measures into practice can be a difficult task for organizations that lack a comprehensive, well-documented privacy strategy. Without one, enterprises may be exposing customer data to vulnerabilities, and could find themselves at risk of noncompliance with privacy regulations. In this episode of the podcast, Tim Clements, a featured speaker at EuroCACS 2020, explains why every organization should be creating and implementing a privacy strategy, what is at risk if one does not exist and how to get started with creating one. Clements will host the EuroCACS session “Privacy Strategy and Roadmap—Do You Have One, and Is It Aligned With Your Business Strategy?” with Clara Kromann from Pandora on 28 October 2020.

View Details

Once considered a privilege, remote work has become a necessity resulting from the public health risk posed by COVID-19. Telecommunication technologies such as video conferencing are core tools in the adoption of remote work, but virtual communication lacks the depth of in-person professional connections. In this episode of the ISACA Podcast, Vasant Raval and Edward Morse discuss how to make working from home productive, secure and personally fulfilling.

View Details

At its core, blockchain functions to maintain the integrity of data and systems. But how does it compare to other databases and when should it be used? In this episode of the ISACA podcast, cybersecurity experts Dustin Brewer and Frank Downs define blockchain, explain how it relates to cryptocurrency and the cloud, and discuss applications where it may prove useful.

View Details

Most organizations would agree that privacy by design is fundamental to growing a successful business and building customer trust. Yet putting this ideal into practice can often prove challenging. In this episode of the podcast, ISACA Journal columnist Steven Ross elaborates on his article “Privacy by Implementation and Execution” and explores some of the obstacles of implementing privacy by design.

View Details

When it comes to the ever-expanding field that is cybersecurity, passionate practitioners should adopt the attitude that there is always more to learn. Yet it is true that the very foundation of one’s education can impact what direction a career takes. In this episode of the ISACA podcast, Dustin Brewer and Frank Downs explore the value of cybersecurity degrees compared to certificates, and discuss how each accreditation can take participants in a different direction professionally.

View Details

The thought of taking a risk can dredge up feelings of discomfort or even outright fear for many. This reluctance has only been amplified by the uncertainty stemming from the COVID-19 pandemic. In this podcast, the Governance, Risk and Control (GRC) Conference 2020 keynote speaker Caspar Berry discusses the importance of taking risks and how not taking a risk may be costlier than taking a risk and failing.

View Details

Cybersecurity frameworks can be a valuable tool for organizations, helping them implement best practices and establish documentation for complex processes. But with so many different cybersecurity frameworks to choose from, selecting the right one can be challenging. In this episode of the ISACA podcast, Frank Downs and Dustin Brewer discuss what constitutes a framework, why there seem to be so many out there and how to determine what framework will best fit your enterprise.

View Details

As the role of technology has expanded, so has the amount of personal data that are being shared. While people want to protect their privacy, there is often a tradeoff between being able to use a service and not sharing data about yourself. In this podcast, Frank Downs and Dustin Brewer discuss the information we share and how to decide if we want to keep it private.

View Details

This podcast contains subject matter and references that some listeners may find objectionable. ISACA believes that the context of the subject matter makes it appropriate and necessary for the privacy discussion within this episode.

With the growing number of privacy regulations around the world and the growing emphasis on privacy, organizations must protect their customers’ privacy. But what happens when a privacy violation occurs in one country but affects someone in a different country, both of which are governed by different privacy laws? In this podcast, Steven Ross discusses some of the challenges associated with enforcing privacy regulations and what privacy expectations consumers should have. Share your feedback on the ISACA Podcast: https://www.research.net/r/9GR6F2D

View Details

Many organizations found themselves unprepared for the workplace and business disruptions caused by COVID-19. But it is possible for organizations to act now to protect their information systems. In this podcast, Steven Ross shares some strategies for remote work and explains how organizations can prepare for crises, such as a pandemic. Share your feedback on the ISACA Podcast: https://www.research.net/r/9GR6F2D

View Details

As a result of the COVID-19 pandemic, many organizations are now trying to manage having an entirely remote workforce. While remote work can allow people to stay safe while doing their jobs, there are some cybersecurity concerns associated with remote work. In this podcast, Frank Downs and Dustin Brewer address the benefits and challenges of working from home, how organizations can evaluate and improve their security posture, and the importance of cybermaturity. Share your feedback on the ISACA Podcast: https://www.research.net/r/9GR6F2D

View Details

A recent survey found that 90 percent of CISOs would take a pay cut if it meant better work/life balance. There are many reasons for CISO burnout, and a broader cultural shift is needed to combat the excessive pressure put on CISOs. In this podcast episode, Dustin Brewer and Frank Downs discuss the reasons for CISO burnout, why it is a problem and how it can be addressed. Share your thoughts on the podcast here: https://www.research.net/r/9GR6F2D

Links Dustin mentions:

  • Dark Reading: https://www.darkreading.com/risk/90--of-cisos-would-cut-pay-for-better-work-life-balance/d/d-id/1336995
  • Maslach Burnout Inventory: https://www.mindgarden.com/117-maslach-burnout-inventory
  • Free Mind Tools Burnout Self-Test: https://www.mindtools.com/pages/article/newTCS_08.htm

View Details

Complacency, refusal to deviate from a plan and freezing in stressful situations are harmful in a corporate environment and can be deadly in an extreme adventuring context. Alison Levine, the first American women's Everest expedition team captain, shares how lessons she learned on Everest can apply in a business context. Share your thoughts on the ISACA Podcast: https://www.research.net/r/9GR6F2D

View Details

Inventor Guglielmo Marconi, a key contributor to wireless telegraphy, did not want to engage with anyone who criticized his wireless telegraph technology, and he believed it to be completely secure. But in 1903, magician Nevil Maskelyn hacked a wireless telegraph communication. And while the communication methods and technology has changed since then, there are several lessons cybersecurity professionals can learn from Marconi and Maskelyn. Share your thoughts on the ISACA Podcast here: https://www.research.net/r/9GR6F2D

View Details

Red team exercises can help enterprises find and address their weaknesses. Unfortunately, the cybersecurity skills gap extends to red teams and blue teams. In this podcast, Frank Downs and Dustin Brewer discuss why red teaming, in conjunction with blue teaming, is a valuable tool for cybersecurity, and they also discuss some of the causes of and solutions to the skills gap. Provide your feedback on the ISACA Podcast here: https://www.research.net/r/9GR6F2D

View Details

The technology landscape of the 2020s is sure to include some sweeping changes. What impact might the rise of more digital natives to leadership roles within their organizations have on how organizations explore and deploy technology? On this episode of the ISACA Podcast's 50th Anniversary Series, guest Alicja Foksinska offers her perspective.

View Details

Understanding an organization’s culture is essential when building a cybersecurity program. But how can security professionals learn about the culture, and how should that drive security programs? In this podcast, we discuss how to build a strong cybersecurity culture, how to leverage the organization’s culture when developing security initiatives and strategies to overcome impediments to a cyberculture.

View Details

Complex interdependencies in the supply chain and elsewhere can make assessing risk difficult, particularly when it comes to protecting critical infrastructure. In this episode of the ISACA Podcast, guest Charlie Harry provides his perspective on how governments and organizations can overcome these challenges. 

View Details

To tackle the complex challenges of the cyberlandscape, strong leaders are needed. But what makes someone a leader, and what should be expected of leaders? In this podcast, Matt Doan discusses how to be a leader, why more cyberleaders are necessary and why it’s beneficial to think of cybersecurity in an ecosystem context. Share your thoughts on the podcast here https://www.research.net/r/9GR6F2D

View Details

An unsophisticated attack on industrial control systems can halt the operations of manufacturing plants, resulting in lost revenue and reputational harm. But a few simple steps can help organizations prevent attacks from happening and recover quickly when they do occur. In this podcast, we discuss the steps organizations can take to secure their operations. Share your opinions about the ISACA Podcast here: https://www.research.net/r/9GR6F2D

View Details

Many organizations are intimidated by the dark web or don't think they have the needed expertise to counter security threats that originate there. In this episode of the ISACA Podcast, recorded from the Infosecurity-ISACA North America Expo and Conference, conference presenter Alex Holden makes the case for why organizations need to prioritize understanding the dark web, and explains how they can go about doing it.

View Details

Computer-assisted audit tools can help auditors improve testing and more efficiently deal with the barrage of data being created these days. Infosecurity-ISACA North America Expo and Conference presenter Rochelle Vargas discusses why she considers these tools to be game-changers for auditors.

View Details

Learning and certification have been at the heart of ISACA's 50-year history, but many of the ways in which technology professionals have pursued industry expertise have changed with the times. Guest Allan Boardman provides his perspective on what has changed and what has stayed constant for learners in ISACA's professional community.

View Details

The use of VPNs is often touted as a strong security measure, but what happens when the VPN service you use is compromised? In this podcast, Dustin Brewer and Frank Downs discuss the recent NordVPN hack, the importance of pen testing and auditing, and lessons learned from the incident. Share your opinions about the ISACA Podcast here: https://www.research.net/r/9GR6F2D

View Details

The misconceptions about why women are underrepresented in the tech workforce are numerous – some cling to the notion that girls and women aren't as interested or proficient in tech fields, despite plenty of evidence to the contrary. In this SheLeadsTech Series episode of the ISACA Podcast, guest Beverly Allen addresses some of the misconceptions about the gender gap in technology fields such as cybersecurity.

View Details

Every organizations uses suppliers, and these suppliers (while adding value) also can pose a risk. In this podcast, Mark Thomas discusses some of the main challenges organizations face when managing their vendor and supplier risk, how to use COBIT to govern and manage this risk, and how organizations not using COBIT can put the tips presented in this podcast into practice. Share your opinions about the ISACA Podcast here: https://www.research.net/r/9GR6F2D

View Details

Digital transformation can give organizations a competitive edge and improve their operations. The COBIT framework can be used as a powerful tool for digital transformation efforts. In this podcast, we discuss how to use COBIT to guide your organization’s digital transformation efforts.

View Details

From its proud but humble origins as a small group of auditors in the Los Angeles area, ISACA has evolved over the past 50 years into a thriving global association of business technology professionals. A spirit of volunteerism has been the catalyst, as explored in this episode of the ISACA Podcast with guest Michael Cangemi.

View Details

Organizations that want to have a competitive edge must leverage the power of emerging technology, but this technology adds complexity to IT auditing. What can auditors do to address this complexity, and what is the role of business leaders when it comes to IT audit? This podcast, in partnership with Protiviti, discusses the results of the 2019 Global IT Audit Benchmarking Study and provides insights on the top challenges IT audit professionals face, how to address these challenges and the skills IT auditors must have.

View Details

Environmental sustainability principles support a healthy ecosystem that sustains life. Much of the language used in environmental sustainability is also used in the digital ecosystem. In this podcast, we discuss how environmental sustainability principles can be applied in a digital transformation context to protect a valuable resource of modern times: information. To provide feedback on the ISACA Podcast, please visit https://www.research.net/r/9GR6F2D.

View Details

ISACA recently surveyed nearly 4,000 professionals in the tech workforce to find out what motivates them, what factors influence retention most and how perceptions about the workplace vary between women and men. In this SheLeadsTech Series episode of the ISACA Podcast, we delve into several of the survey findings.

View Details

Popular culture depictions of cybersecurity, while entertaining, are often inaccurate, which could be dissuading people from exploring careers in cyber. In this podcast, we discuss some common misconceptions of cyber in pop culture, how that affects the cyberworkforce and how cyberprofessionals can draw people into cybersecurity careers.

View Details

The need for mobile security solutions has exploded in the 2000s, but many of organizations' traditional security considerations are insufficient when it comes to accounting for the proliferation of mobile devices. In this 50th Anniversary Series episode of the ISACA Podcast with guest Eric Green, we find out why it is so hard for individuals and their organizations to get it right on mobile security, and what can be done to break down those barriers.

View Details

Many of our institutions were created before the internet and major shifts on the technology landscape introduced unforeseen risks, threats and opportunities. In this Off-stage and Off-script edition of the ISACA Podcast, Infosecurity-ISACA North America Expo and Conference keynote speaker Jamie Bartlett provides his perspective on how to course correct.

View Details

Enthusiasm for cybersecurity helps professionals stay motivated, and finding a network of like-minded professionals can be invigorating. Conferences can help cybersecurity professionals learn more and stay excited about cyber, but the amount of information gained from them can be overwhelming. In this Cyber Pros Exchange podcast, we discuss how you can make the most of a conference experience.

View Details

Data centers no longer look the same as they did years ago. More and more is being outsourced, and the involvement of third parties can create risk for organizations. In this podcast, we discuss the implications of an outsourced data center and what organizations can do to keep their data safe.

View Details

Disruptive Technology, Then and Now by ISACA Podcast

View Details

As automation has taken hold, more and more jobs that people used to perform are now taken care of by machines. That means humans have more opportunities to innovate and pursue purpose-driven careers that are meaningful to them on a personal level. In this Offstage and Offscript edition of the ISACA Podcast, EuroCACS/CSX 2019 keynote speaker Jon Duschinsky discusses why people and organizations should be enthused about the new professional landscape.

View Details

Medical devices that are connected to the Internet can empower patients and help healthcare providers better monitor their patients’ health. But these connected devices also pose a great security risk as they collect personal health information. In this podcast, we discuss the risk and benefits of connected medical devices, the regulatory landscape surrounding Internet of Medical Things devices, and how to securely configure them.

View Details

The kitchen has become a testing ground for Internet-connected devices. While these devices can make cooking easier and more enjoyable, they present a security risk. In this podcast, we discuss the risk of IoT-connected devices and how you can leverage their benefits while remaining secure.

View Details

As a high school student, Kyla Guru already has started her own cybersecurity education program and helped launch a conference for high school girls interested in technology. In this SheLeadsTech Series edition of the ISACA Podcast, Guru talks about how she became so engaged, so quickly, in cybersecurity and championing girls and women in technology.

View Details

The Certified Information Systems Auditor (CISA) certification is ISACA's flagship certification and has played a major role in the organization's growth and global cachet over ISACA's 50-year history. In this 50th Anniversary Series edition of the ISACA Podcast, guest Thomas Phelps discusses how the CISA has remained relevant amid a dynamic and fast-changing technology landscape.

View Details

The role of IT auditors has changed as technology has changed. In this podcast, we discuss the role of IT audit and how IT audit can help strengthen information security and cybersecurity measures.

View Details

Many organizations view risk management as an unpleasant process that has to be done to meet regulatory requirements. But what if risk management were leveraged to add value to organizations and strengthen their security measures? In this podcast, we discuss how to use risk management to improve performance and add value.

View Details

A ransomware attack leveraging an unpatched vulnerability affected several government services for the city of Baltimore (Maryland, USA). In this podcast, we discuss how this ransomware attack occurred, the services it affected and lessons learned from this attack.

View Details

From mobile payments to the use of artificial intelligence to the introduction of new security risks, technology has had a profound impact on how the financial sector operates. In this 50th Anniversary Series episode of the ISACA Podcast, Ashley Holmes analyzes the past, present and future state of fintech. Holmes notes that banks and others in the financial services sector have to manage a balancing act in embracing innovation and automation while not alienating customers that still expect a certain level of human-to-human service and accessibility.

View Details

In an era of data overload, dealing with unstructured data poses distinct challenges to organizations. In this Off Stage and Off Script Series edition of the ISACA Podcast, North America CACS 2019 conference presenter George Khalil provides his perspective on which pitfalls should be avoided when it comes to managing unstructured data.

View Details

Most organizations know how to respond to malicious outsiders who may try to steal sensitive data. But what about the insider threat? In this podcast, we discuss ways to protect against the insider threat, and we use the example of a distillery to show the steps you can take to protect your data.

View Details

While organizations increasingly understand the value of gender diversity in leadership roles, they don't always know how to make it a reality. In this episode of the ISACA Podcast's SheLeadsTech Series, Kellie McElhaney provides guidance on steps organizations can take to create meaningful inclusion in their leadership ranks.