View Details
In episode 199 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager sit down with Chris Painter, Chair of the Risk Committee and Board Member at the Center for Internet Security® (CIS®). Together, they discuss how chief information security officers (CISOs) can support the work of translating cyber risk into business decisions by Boards.
Here are some highlights from our episode:
- 00:50. Introductions to Chris
- 01:36. The single biggest translation error Chris has seen CISOs make
- 07:38. Cyber risk quantification: An opportunity to go beyond translation for Boards
- 09:25. How ransomware changed Boards' understanding of cyber risks' business impact
- 10:45. The value of tabletop exercises (TTX) and other simulations in creating shared language
- 13:26. Recommendations on how to make the most of a TTX
- 18:37. Risk modeling and how artificial intelligence (AI) complicates probability estimations
- 21:51. "Pressure" (2026) as an illustration of making good, not 100% accurate, estimations
- 22:58. How growing public awareness of cyber is reshaping CISOs' conversations with Boards
- 25:55. The importance of walking Boards through risk mitigation steps with AI as an example
- 29:31. A recommendation for how CISOs can learn what directors care about
- 30:15. From "wizardry" to familiarity: An ongoing generational shift around cyber
Resources
- Episode 183: The Role of CISO in Supporting Risk Translation
- Episode 187: The Role of a CISO as a Strategic Storyteller
- Episode 192: How Leaders Balance Expertise and Communication
- How Risk Quantification Tests Your Reasonable Cyber Defense
- CIS RAM (Risk Assessment Method)
- Leveraging Generative Artificial Intelligence for Tabletop Exercise Development
- CIS Controls v8.1 Incident Response Policy Template
- You Have a Cybersecurity Incident. Now What?
- Prompt Injections: The Inherent Threat to Generative AI
- "Pressure" | Official Website | 29 May 2026
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 198 of Cybersecurity Where You Are, Sean Atkinson discusses artificial intelligence (AI) and privacy from a risk-based cybersecurity perspective. Together, he explores how organizations and individuals can assess AI risk, apply governance frameworks, evaluate third-party AI services, and balance innovation with due diligence.
Here are some highlights from our episode:
- 00:41. Framing the conversation around AI, privacy, and risk-based controls
- 02:22. Due diligence and ethical considerations around AI products and services
- 03:14. Data minimization and transparency as foundations for AI privacy
- 04:46. Privacy impact assessments as a way to understand AI data collection and use
- 05:42. AI governance and the tension between implementation velocity and risk management
- 10:08. The use of existing data flows and controls in AI assessments
- 11:57. Algorithmic transparency and the challenge of understanding AI decision making
- 13:47. Standards, frameworks, and data sovereignty in AI privacy governance
- 15:12. Encryption, anonymization, tokenization, and federated learning as privacy safeguards
- 16:40. The need to shift stakeholder input left in AI development and deployment lifecycles
- 19:13. Building literacy around security, data management, privacy, and AI risk
- 23:40. The value of cross-functional and written assessment criteria for AI risk
- 26:21. A call to action for keeping pace with AI privacy and and innovation risk
Resources
- CIS Controls v8.1.2 AI Security Guidance Workbook
- Episode 105: Context in Cyber Risk Quantification
- Service Provider Management Policy Template for CIS Control 15
- EU AI Act: first regulation on artificial intelligence
- AI Risk Management Framework
- IAPP AI Governance Center
- Episode 120: How Contextual Awareness Drives AI Governance
- Secure by Design v1.1 A Guide to Assessing Software Security Practices
- Reasonable Cybersecurity
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 197 of Cybersecurity Where You Are, Sean Atkinson sits down with Ben Wilcox, Chief Technology Officer and Chief Information Security Officer at ProArch; and Ed Skoudis, President of SANS Technology Institute. Together, they discuss artificial intelligence (AI), operational technology (OT) data, and how understanding creates the foundation for AI-ready OT data.
Here are some highlights from our episode:
- 00:54. Introductions to Ben and Ed
- 02:16. How we understand and integrate AI into OT environments
- 04:30. How OT diverges from information technology (IT) in data responsibilities
- 05:23. Opportunities for AI to assist OT
- 06:33. The importance of meeting OT systems where they are
- 08:10. A passive and incremental approach that respects the operations machines are doing
- 12:29. Efficiency gains, public safety improvements, and other benefits of AI-ready OT data
- 17:47. What lifecycle management, asset hierarchies, and governance look like for OT data
- 22:14. The promise of AI to help to make OT environments understandable
- 23:19. A team sport: How IT and OT can work together to understand assets and data
- 28:38. The need for translation in IT-OT communication
- 29:01. Recommendations for how to make OT data AI ready
Resources
- CIS Critical Security Controls®
- CIS Controls version 8.1 ICS Workbook
- Artificial Intelligence and Large Language Models Companion Guide
- CIS Controls v8.1 Enterprise Asset Management Policy Template
- CIS Controls v8.1 Software Asset Management Policy Template
- CIS Controls v8.1 Data Management Policy Template
- CIS Controls v8.1 Account & Credential Management Policy Template
- Establishing Essential Cyber Hygiene
- ProArch
- Cybersecurity for Critical Infrastructure
- Episode 77: Data's Value to Decision-Making in Cybersecurity
- Episode 183: The Role of CISO in Supporting Risk Translation
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 196 of Cybersecurity Where You Are, Sean Atkinson sits down with Sasha Larkin, Director of Intelligence and C4 Operations for FIFA World Cup 2026, and John Cohen, Executive Director of the Office of Strategic Programs and Initiatives at the Center for Internet Security® (CIS®). Together, they discuss how CIS, FIFA, and FIFA World Cup 2026 host cities started collaborating in 2025 on cybersecurity, public safety, intelligence, and information-sharing efforts supporting the largest sporting event in the world.
Here are some highlights from our episode:
- 00:40. Introductions to Sasha and John
- 02:07. Overview of one of the most complex public safety efforts assembled for a sporting event
- 05:52. Consistency: A standard for preventing and deterring threats at FIFA World Cup 2026
- 10:30. The impact of relationships in shaping FIFA's security ops and information sharing
- 11:53. Effective communication: The key to cross-functional collaboration in support of the tournament
- 18:07. The importance of information that guides operations
- 20:35. Education as a way to inform stakeholders and deploy resources
- 26:19. A deliberate effort to look at unanticipated threats and plan for them
- 29:14. Examples of messaging synchronization in support of FIFA World Cup 2026
- 32:37. An all-hands-on-deck support campaign from CIS
- 33:29. Parting thoughts around large-scale event support in the future
Resources
- An Examination of Generative AI and Physical Threat Planning
- An Examination of AI-Enabled Threats to Event and Stadium Security
- Multidimensional Threats
- 5 Major Emerging Risks to Large-Scale Events
- Illicit Sports Betting and Match Integrity Risks to Large-Scale Events
- Deepfakes and Synthetic Media: The Emerging Threat to Large-Scale Public Gatherings
- Growing Risks to Digital Ticketing Platforms for Large-Scale Events
- Unmanned Aircraft Systems (UAS): Evolving Risks to Large-Scale Public Gatherings
- Unmanned Aircraft Systems (UAS): Evolving Risks to Large-Scale Public Gatherings Cyber Risks Companion Guide
- 5 Steps to Help Secure Your City before a Large-Scale Event
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 195 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager sit down with Ed Skoudis, President of SANS Technology Institute, and Marcus Sachs, Senior Vice President and Chief Engineer at the Center for Internet Security® (CIS®). Together, they discuss Enigma machines, their history, and their security lessons for today.
Here are some highlights from our episode:
- 00:56. Introductions to Ed and Marc
- 01:32. What Enigma machines are and why cybersecurity folks still care about them today
- 06:10. Enigma machines as a symbol for how we can use hacking for noble purposes
- 07:18. How the human mind and the need for ease of use can undermine security
- 15:59. The importance of testing when designing and maintaining a security system
- 20:45. Why "security through obscurity" isn't actually true
- 22:58. Curiosity, logic, and a wide range of knowledge: Essential traits for getting hired in cybersecurity today
- 30:57. The impact of culture in shaping security policy and priorities
- 35:09. Why artificial intelligence (AI) is the Enigma machine of 2026
- 36:11. How to learn more about Enigma machines
Resources
- Episode 189: The Present and Future of AI-enabled Pentesting
- A Short Guide for Spotting Phishing Attempts
- Penetration Testing
- Vulnerability Assessments
- Episode 192: How Leaders Balance Expertise and Communication
- Episode 193: AI Security and Responsibility in EO 14409
- The Myth of Mythos: What It Means For Information Security
- National Cryptologic Museum
- Enigma Replica: The Enigma touch
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 194 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager sit down with Ed Skoudis, President of SANS Technology Institute. Together, they conduct a mid-year review of 2026 cybersecurity predictions from seven Center for Internet Security® (CIS®) experts, as shared on the CIS website.
Here are some highlights from our episode:
- 01:50. Ongoing conversations about improving defense with artificial intelligence (AI)
- 05:19. A trap to avoid: Automating things with AI because we can regardless of utility
- 06:54. Ed's prediction about a near-term transition for AI-enabled vulnerability discovery
- 09:27. How AI agents change the economics around conducting a penetration test
- 11:26. Adversary emulation: A blurry proposition when threat actors use AI to look like anybody
- 14:02. Ed's prediction about threat actors shifting APT profiles within a single attack campaign
- 17:00. The need to systematically rethink cyber defense to support state and local cybersecurity
- 23:34. How adversaries are pivoting to the "authorization sprawl" in light of zero trust efforts
- 29:20. Industry-specific threat intelligence as a way to keep organizations informed
- 32:10. Why a policy isn't the same as security control for operational technology (OT)
- 33:55. Social expectations and public policy objectives around holistic OT security
- 39:52. Compliance as a floor, not a ceiling, that results as a byproduct of continuous security
- 43:43. The need for oversight and confidence in technology as distinct from the "Fog of More"
Resources
- Episode 169: 2026 Cybersecurity Predictions from CIS — Pt 1
- Episode 174: 2026 Cybersecurity Predictions from CIS — Pt 2
- Episode 179: 2026 Cybersecurity Predictions from CIS — Pt 3
- The Myth of Mythos: What It Means For Information Security
- Episode 189: The Present and Future of AI-enabled Pentesting
- Authorization Sprawl: The Vulnerability Reshaping Modern Attacks
- Episode 188: DBIR 2026 Insights and Collaboration with CIS
- Mapping and Compliance with the CIS Controls
- Mapping and Compliance with the CIS Benchmarks
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 193 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager sit down with Rob T. Lee, Chief of Research & Chief AI Officer at the SANS Institute, and Brian Calkin, Chief Technology and Innovation Officer at the Center for Internet Security® (CIS®). Together, they discuss AI security and the responsibility of the U.S. government in creating confidence around it, as represented in Executive Order (EO) 14409, "Promoting Advanced Artificial Intelligence Innovation and Security."
Here are some highlights from our episode:
- 00:50. Introductions to Rob and Brian
- 02:32. How to conceptualize confidence around something as complex as AI security
- 04:32. The U.S. government's responsibility to set AI security guardrails as clear expectations
- 08:12. The use of "voluntary" participation to create confidence in the context of EO 14409
- 14:38. How Mythos AI and similar developments affect assessment of frontier AI models
- 17:11. Airport security as an analogy for understanding AI security and privacy concerns
- 18:41. Why cybersecurity is a hard sell until an incident occurs
- 20:50. How AI is quickly becoming critical infrastructure
- 22:53. Furbies as reference for a flexible, iterative benchmarking process for AI security
- 25:50. The need for technical folks to translate AI risks into something understandable
- 28:21. Balancing encouragement of AI innovation with mindfulness of risk
- 31:24. The basics as a foundation for building shared responsibility around AI security
Resources
- Promoting Advanced Artificial Intelligence Innovation and Security
- The Myth of Mythos: What It Means For Information Security
- Episode 190: Separating Mythos AI Fact from Fiction
- The “AI Vulnerability Storm”: Building a “Mythos-ready” Security Program
- Anthropic says it has taken its latest AI models offline to comply with new export controls
- Establishing Essential Cyber Hygiene
- Episode 187: The Role of a CISO as a Strategic Storyteller
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 192 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager sit down with Marcus Sachs, Senior Vice President and Chief Engineer at the Center for Internet Security® (CIS®). Together, they discuss how leaders, including those in cybersecurity, balance their technical expertise with mastery of communication strategies.
Here are some highlights from our episode:
- 00:51. Introductions to Marcus
- 02:04. How Marcus found value in using analogies to communicate complex topics
- 08:40. Coordination with non-technical folks as a sign of leadership maturity
- 14:03. The wisdom in knowing what to say and what not to say when managing up
- 17:31. The need to balance technical skills with team resourcing in a way that's imitable
- 21:07. The challenge of leaders learning by proximity in hybrid and remote environments
- 24:16. "Classic" engineering vs. "new" engineering
- 25:13. Lessons from Boards in applying discipline, rigor, and order to software engineering
- 28:23. The value in leaders continuously learning how businesses work
Resources
- Episode 183: The Role of CISO in Supporting Risk Translation
- Episode 187: The Role of a CISO as a Strategic Storyteller
- Episode 99: How Cyber-Informed Engineering Builds Resilience
- 7 CIS Experts' 2026 Cybersecurity Predictions
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 191 of Cybersecurity Where You Are, Sean Atkinson sits down with Sasha Elvenaes, Sr. Multidimensional Threat Analyst at the Center for Internet Security® (CIS®), and Rian Davis, Multidimensional Threat Analyst at CIS. Together, they discuss how threat actors are misusing generative artificial intelligence (GenAI) to plan physical threats.
Here are some highlights from our episode:
- 00:40. Introductions to Sasha, Rian, and their research on GenAI misuse
- 01:56. The impact of GenAI on lowering the barrier for operationalizing physical threat activity
- 03:37. Exploitation of GenAI model design to circumvent models' guardrails
- 05:58. The misuse of session persistence to streamline physical threat research
- 07:57. GenAI misuse: A call for critical infrastructure operators to think about security differently
- 11:52. Factors that make large-scale events a target of physical threat activity
- 14:33. The use of GenAI as a strategy for organizations to see what threat actors could see
- 15:37. Ongoing question: How can drones help mitigate risks while protecting public safety?
- 17:13. Extrapolation as a reinforcement of GenAI session persistence
- 20:15. The new reality: Look at what information AI can provide to threat actors
- 25:01. Traditional methods vs. GenAI conversations for threat planning
- 27:58. Continuous vulnerability assessments, communication, and other recommendations
Resources
- An Examination of Generative AI and Physical Threat Planning
- An Examination of AI-Enabled Threats to Event and Stadium Security
- Multidimensional Threats
- Man who exploded Cybertruck in Las Vegas used ChatGPT in planning, police say
- Episode 190: Separating Mythos AI Fact from Fiction
- Episode 185: AI Prompt Injection from a Risk Perspective
- 5 Steps to Help Secure Your City before a Large-Scale Event
- Unmanned Aircraft Systems (UAS): Evolving Risks to Large-Scale Public Gatherings
- 8 Security Essentials for Managing Your Online Presence
- Vulnerability Assessments
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 190 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager sit down with Brian Calkin, Chief Technology and Innovation Officer at the Center for Internet Security® (CIS®). Together, they separate fact from fiction around artificial intelligence (AI) capabilities like Mythos AI and other AI-driven vulnerability discovery tools.
Here are some highlights from our episode:
- 00:50. Greetings to Brian and setting the stage for questions from a CIS webinar
- 03:05. The lack of a unified formula or standard for vulnerability prioritization
- 03:55. The opportunity for defenders to interrupt vulnerabilities chained together
- 05:47. An invitation to better understand your enterprise amid the "slopdemic"
- 06:33. How AI guardrails tie back into security best practices
- 10:15. How a fundamental practice we can refine is the best counter to chained attacks
- 12:25. The value of the CIS Community Defense Model and a teaser for Version 3
- 14:50. Mythos AI vs. Static Application Security Testing (SAST) in terms of practice and time
- 19:08. Visibility, governance, and prioritization: Three elements of a "prepared" environment
- 24:32. "One to one" cyber defense as a losing battle
- 27:25. The importance of knowing your dependencies with open-source software
- 33:15. Threat actor economics and the ongoing debate around responsibility in cybersecurity
Resources
- Mythos AI: What Actually Matters for Cybersecurity Leaders
- Secure by Design
- CIS Critical Security Controls®
- CIS Community Defense Model 2.0
- Episode 185: AI Prompt Injection from a Risk Perspective
- Living off the Land: Threats Looming From Within
- Turn Intel Into Action: CIS Controls and the 2026 Verizon DBIR
- Implementation Guide for Small- and Medium-Sized Enterprises CIS Controls IG1
- Information Technology and Information Security Governance
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 189 of Cybersecurity Where You Are, Sean Atkinson sits down with Ed Skoudis, President of SANS Technology Institute. Together, they discuss the present and future of pentesting enabled by artificial intelligence (AI).
Here are some highlights from our episode:
- 00:39. Introductions to Ed
- 01:49. The promise of AI-enabled pentesting in creating more secure infrastructure
- 04:52. AI-enabled and AI-centric workflows in the realm of penetration testing
- 08:03. Wranglers, matadors, and centaurs, oh my! Metaphors for AI-enabled pentesters
- 13:00. How AI can assist with reporting, enumeration, and scanning as part of a pentest
- 14:57. AI-enabled source-assisted pentesting and the types of vulnerabilities it finds
- 19:50. A learning opportunity for the broader cybersecurity community
- 23:44. How AI and human analysts could split the workload in a future penetration test
- 25:54. AI-enabled pentesting vs. AI pentester in a box
- 29:51. Why "human in the loop" might be too passive a phrase
- 30:37. The use of AI for source code development
Resources
- Mythos AI: What Actually Matters for Cybersecurity Leaders
- Secure by Design
- SEC543: AI-Assisted Source Code Analysis and Exploitation for Penetration Testers
- Episode 108: Gaming and Competition in Cybersecurity
- Episode 59: Probing the Modern Role of the Pentest
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 188 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager sit down with Philippe "Phil" Langlois, Data Breach Investigations Report (DBIR) Author at Verizon; and Charity Otwell, Director of the CIS Critical Security Controls® (CIS Controls®) at the Center for Internet Security® (CIS®). Together, they discuss some of the top insights of the 2026 DBIR and how CIS contributed to the publication.
Here are some highlights from our episode:
- 00:50. Introductions to Phil and Charity
- 02:46. Vulnerability exploitation as the most common attack vector
- 05:25. The role of artificial intelligence (AI) in threat actors' natural system thinking
- 07:03. The need for clear governance and responsibility around vulnerability management
- 08:58. Insight into the types of techniques threat actors research using frontier AI models
- 13:43. A trending drop in ransomware payouts and organizations willing to pay attackers
- 14:59. Why a healthy dose of distrust goes a long way in assessing attackers' claims of victims
- 16:24. How two ransomware groups stand out above the norm
- 17:49. The ongoing risk surrounding vendor, supplier, and other third party exposure
- 22:34. The need for governance in managing data issues involving the use of AI
- 27:14. Three ways in which CIS contributed to the 2026 DBIR
- 34:02. How the 2026 DBIR informs the CIS Controls and parting actionable steps
Resources
- 2026 Data Breach Investigations Report
- CIS Critical Security Controls®
- Episode 87: Marking 11 Years as a Verizon DBIR Contributor
- Mythos AI: What Actually Matters for Cybersecurity Leaders
- Applying the CIS Controls to Real‑World AI Environments
- CIS Community Defense Model 2.0
- The Conti Leaks: A Case of Cybercrime’s Commercialization
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 187 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager discuss how the role of a CISO functions as a strategic storyteller of cyber risk while keeping the bigger picture in mind.
Here are some highlights from our episode:
- 00:51. Framing the conversation around CISOs' efforts to communicate with the business
- 02:01. Translation: A nuanced practice of simplifying the story while still telling the truth
- 02:41. The need for a CISO to bridge their organization's respective "culture gap(s)"
- 04:13. Collaborative and dictatorial: Two different ways CISOs talk to a business
- 06:07. The work of translation in motivating and informing action around perceived risk
- 07:03. Security sampling: A story from Tony that reminds CISOs of the bigger picture
- 09:55. Fewer wizards and more mechanics: What the cybersecurity industry needs today
- 12:20. Two factors to consider: Politicking and the need to provide an accessible narrative
- 15:49. Rapport and tradecraft as two critical tools supporting the role of a CISO
- 18:09. Technical competence as a prerequisite for confidence in risk conversations
- 19:20. The false sense of security from relying on comparative data with competitors
- 22:14. The CISO as a strategic storyteller who helps the business make decisions
- 27:03. The need for machinery to constantly rediscover and recreate trust
- 30:15. A call to action for Boards: Build vernacular in cybersecurity risk space
- 35:03. CISO as a strategic storyteller vs. CISO as an enforcer
Resources
- CIS Critical Security Controls®
- CIS Community Defense Model 2.0
- Episode 183: The Role of CISO in Supporting Risk Translation
- Episode 166: Foundations of Actuarial Science in Cyber Risk
- Episode 121: The Economics of Cybersecurity Decision-Making
- NICE Workforce Framework for Cybersecurity (NICE Framework)
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 186 of Cybersecurity Where You Are, Tony Sager sits down with Tony Krzyzewski, a CIS Critical Security Controls® (CIS Controls®) Ambassador for the Center for Internet Security® (CIS®). Together, they discuss how strong cyber defense starts with the fundamentals of IT operations.
Here are some highlights from our episode:
- 00:45. Introductions to Tony Krzyzewski and his background
- 02:19. Tony Krzyzewski's first interaction with the CIS Controls
- 03:47. IT operations: The foundation that makes strong cyber defense possible
- 06:20. How an increasingly connected world makes the CIS Controls essential to cybersecurity
- 09:56. The need for operations people to realize they're part of the cybersecurity solution
- 13:11. The use of Implementation Groups to reduce overload on IT and security teams
- 16:52. How the CIS Controls differ from "umbrella frameworks" like NIST CSF and ISO 27001
- 18:25. CIS Controls mappings and how they help to simplify a surplus of good guidance
- 20:35. How the CIS Controls support improvement programs and Board-level conversations
- 25:38. Tony Krzyzewski's work in creating the CIS Controls Ambassador program
- 27:02. Why a deep view of what's happening at CIS supports Tony Krzyzewski's efforts
- 30:11. Growing international promotion of the CIS Controls and "doing the basics well"
Resources
- CIS Critical Security Controls®
- CIS Controls Ambassador Spotlight: Tony Krzyzewski
- Episode 160: Championing SME Security with the CIS Controls
- Episode 168: Institutionalizing Good Cybersecurity Ideas
- Episode 172: Helping CISOs as a CIS Controls Ambassador
- Episode 181: Supply and Demand of Cybersecurity Ecosystems
- Guide to Implementation Groups (IG): CIS Critical Security Controls v8.1
- Reasonable Cybersecurity
- Mappings to Security Frameworks
- Translations
- Policy Templates
- Securing the AI Ecosystem Begins at the Model Layer
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 185 of Cybersecurity Where You Are, Sean Atkinson sits down with Brian Calkin, Chief Technology and Innovation Officer at the Center for Internet Security® (CIS®); Theodore "TJ" Sayers, Senior Director of Threat Intelligence at CIS; and Kyle Leonard, Cyber Threat Intelligence Analyst at CIS. Together, they use a risk perspective to discuss artificial intelligence (AI) prompt injection and how to defend against it.
Here are some highlights from our episode:
- 00:49. A definition of AI prompt injection for businesses and executives
- 02:16. Brian on his role of guiding AI implementation at CIS
- 03:12. Understanding the urgency surrounding AI prompt injection as a security risk
- 05:32. Signals and trends indicative of threat actors attempting to weaponize prompt injection
- 07:10. How AI prompt injection differs from traditional input validation vulnerabilities
- 11:13. Early indicators that cyber threat intelligence (CTI) teams can monitor
- 15:00. The need to treat AI as a new identity in any enterprise implementation strategy
- 17:10. Understanding the difference: AI safety vs. AI security
- 20:36. Foundational, practical AI security that extends across all sectors
- 24:55. How CIS manages risk and supports the opportunity around the use of AI
- 28:25. The long-term promise of AI-driven vulnerability discovery grounded in fundamentals
- 34:48. Recommendations for piercing through the marketing hype surrounding AI
Resources
- Prompt Injections: The Inherent Threat to Generative AI
- New CIS Report Warns Prompt Injection Attacks Pose Growing Risk to Generative AI
- Episode 182: Striking a Balance on an AI Adoption Journey
- Episode 120: How Contextual Awareness Drives AI Governance
- Mythos AI: What Actually Matters for Cybersecurity Leaders
- Applying the CIS Controls to Real‑World AI Environments
- An Examination of Generative AI and Physical Threat Planning
- AI Playbooks for SLTT Cybersecurity Leaders
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 184 of Cybersecurity Where You Are, Sean Atkinson sits down with Brock Boggs, Director of Technology at Cityscape Schools and Multi-State Information Sharing and Analysis Center® (MS-ISAC®) member. Together, they discuss how Brock approaches cybersecurity policy development as a journey at his school.
Here are some highlights from our episode:
- 01:21. Brock's first attempt at drafting an IT security policy manual
- 04:17. Fact or fiction? How the best "written" security program doesn't always translate
- 06:35. A starting policy landscape of creating baselines for cybersecurity, ticketing, and more
- 08:40. How Brock learned about a roadmap for his school at ISAC Annual Meeting 2023
- 11:07. Lean and to the point: The second draft of Brock's IT security policy manual
- 12:37. The use of Center for Internet Security® (CIS®) policy templates to write procedures
- 19:34. How Brock used regular updates about his policy manual to secure stakeholder buy-in
- 28:42. Openness, willingness to fail, and adaptability as strengths of the community
- 31:49. Approaching cybersecurity policy development as an ever-changing journey
Resources
- CIS Critical Security Controls®
- Policy Templates
- Formalizing K-12 Cybersecurity Policies in Less Time
- Episode 163: K-12 Cybersecurity Made Practical
- Episode 176: A Cybersecurity Journey of Incremental Wins
- Guide to Implementation Groups (IG): CIS Critical Security Controls v8.1
- CIS SecureSuite® Membership
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 183 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager discuss how the role of CISO supports risk translation across all levels of an organization.
Here are some highlights from our episode:
- 01:52. Describing the role of CISO in a single sentence
- 03:43. The importance of storytelling in risk translation for an organization
- 07:56. The need for CISOs to meet members of an organization where they are
- 10:47. Why the function of translating risk matters more than sharing it
- 14:41. The misnomer of "soft skills" and why they're a crucial part of professional life
- 15:50. Tony's experience with cultivating "soft skills" and working with trusted truth tellers
- 21:01. The importance of contextualization when framing risk to a Board of Directors
- 24:20. How teaching and communicating differ
- 25:05. Humility and empathy: Crucial skills in understanding another person's world
- 26:34. How communication and public speaking can help to advance a mission
- 29:08. The use of teaching to build mastery and writing to understand what we teach
- 32:35. Public speaking tip: Don't let the first time you hear your words aloud be onstage
- 36:10. Tony's "superpower" of geeky sincerity
Resources
- Episode 88: The Evolution of the Role of a CISO
- Episode 121: The Economics of Cybersecurity Decision-Making
- Episode 166: Foundations of Actuarial Science in Cyber Risk
- CIS Community Defense Model 2.0
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 182 of Cybersecurity Where You Are, Sean Atkinson sits down with Brian Calkin, Chief Technology and Innovation Officer at the Center for Internet Security® (CIS®). Together, they discuss how organizations can strike a balance on their journeys of artificial intelligence (AI) adoption.
Here are some highlights from our episode:
- 00:39. Introductions to Brian
- 01:06. The risk of overbuilding governance when introducing an AI strategy
- 02:36. Unknowns, data concerns, and other commonalities between AI and cloud adoption
- 04:27. The utility of AI frameworks: General purpose recommendations as a starting point
- 06:58. The importance of leading employees in getting the tools they need to be successful
- 10:42. Listening as a key method for strategic leaders to remove roadblocks to AI adoption
- 13:47. Final say as a means to make a strategic business decision and adapt as necessary
- 17:35. AI as artificial intelligence and the role of humans as sources of actual intelligence
- 19:56. Being a good Googler: An analogy for asking the right questions with AI prompting
- 23:46. The increasing volume and velocity of cyber attacks leveraging AI
- 24:00. The need to enhance defenders' skillsets using AI
- 27:08. An invitation to play with AI capability and see what it can do for you
Resources
- Episode 120: How Contextual Awareness Drives AI Governance
- AI Playbooks for SLTT Cybersecurity Leaders
- Episode 95: AI Augmentation and Its Impact on Cyber Defense
- OWASP Top 10 for Large Language Model Applications
- An Examination of Generative AI and Physical Threat Planning
- Prompt Injections: The Inherent Threat to Generative AI
- Disrupting the first reported AI-orchestrated cyber espionage campaign
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 181 of Cybersecurity Where You Are, Tony Sager sits down with Vilius Benetis, Director of NRD Cyber Security. Together, they discuss how Vilius applies his expertise as a CIS Critical Security Controls® (CIS Controls®) Ambassador to help to cultivate supply and demand for growing cybersecurity ecosystems around the world.
Here are some highlights from our episode:
- 01:11. Introductions to Vilius and recollections of how he met Tony for the first time
- 02:06. The CIS Controls as a reasonable, logical approach that avoids generic language
- 04:11. How the CIS Controls shaped Vilius' cybersecurity conversations with the World Bank
- 05:26. A clear connection between knowing what you have and recovering from an incident
- 07:55. A strategic look at how to build cybersecurity programs that will grow and evolve
- 12:18. How the CIS Controls help to clarify reasonable cybersecurity and avoid victim blaming
- 18:07. An encouraging sign: Governments enabling businesses, not competing with them
- 21:13. Transportation: A lens for understanding how security culture and expectations change
- 28:11. A brief look at how to make progress on operationalizing security
- 31:54. The supply and demand forces that help to create cybersecurity ecosystems
- 38:13. An opportunity for helping organizations to simplify governance
- 42:02. Parting thoughts and thanks
Resources
- CIS Critical Security Controls®
- CIS Controls Ambassador Spotlight: Vilius Benetis
- Episode 160: Championing SME Security with the CIS Controls
- Episode 168: Institutionalizing Good Cybersecurity Ideas
- Episode 172: Helping CISOs as a CIS Controls Ambassador
- Reasonable Cybersecurity
- Guide to Implementation Groups (IG): CIS Critical Security Controls v8.1
- The Cost of Cyber Defense: CIS Controls IG1
- CIS Community Defense Model 2.0
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 180 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager sit down with Stephen Thomas, SVP of Sales and Business Services at the Center for Internet Security® (CIS®), and Nick Rust, Director of Distribution at CIS. Together, they discuss how CIS supports secure by design by integrating it into operational practices.
Here are some highlights from our episode:
- 00:48. Introductions to Stephen and Nick
- 02:20. The need to connect development and operational environments
- 07:31. How CIS security best practices make cybersecurity standard and repeatable
- 09:19. Navigating the complexity the cloud adds to secure by design
- 11:44. The importance of removing guesswork for operating partners and development teams
- 14:21. How CIS provides the professional infrastructure for collective action in cybersecurity
- 16:00. Good configuration management: The bedrock of every successful security program
- 17:29. The use of a common language to communicate security across an organization
- 23:59. Shared responsibility, not shared accountability, in the cloud
- 27:21. A look back at how CIS did secure by design using a projectized approach
- 32:21. Conveying confidence around cybersecurity and compliance in the connected world
- 36:16. Parting pieces of advice for organizations just getting started
Resources
- Secure by Design
- Secure by Design: A Guide to Assessing Software Security Practices
- Episode 164: Secure by Design in Software Development
- CIS SecureSuite® Membership
- CIS SecureSuite® Product Vendor Members
- CIS Critical Security Controls®
- CIS Benchmarks® List
- CIS Hardened Images®
- Meet the Shared Responsibility Model with New CIS Resources
- Cloud Companion Guide for CIS Controls v8.1
- Security in the Cloud with More Automation
- Implementation Guide for Small- and Medium-Sized Enterprises CIS Controls IG1
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 179 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager conclude their discussion of 2026 cybersecurity predictions from seven CIS experts, as shared on the CIS website.
Here are some highlights from our episode:
- 01:09. How threat actors' adoption of Agentic AI is reshaping the defender's dilemma
- 06:28. Public confidence: The primary focus for attackers seeking to undermine U.S. elections
- 10:43. The surge in threat actors targeting operational technology and critical infrastructure
- 12:29. Responsibility and the cost of fixing flawed things instead of secure by design
- 16:29. Secure by design: An invitation to rethink architecture and plan for future adaptability
- 17:24. Meeting cloud service prioritization with a foundation of defense for all things
- 25:44. Supporting state and local cybersecurity maturity with both competence and character
- 41:00. Feedback: The key to adapting security controls to evolving threats and technology use
- 50:23. Embedding security into the heart of a business
Resources
- Episode 169: 2026 Cybersecurity Predictions from CIS — Pt 1
- Episode 174: 2026 Cybersecurity Predictions from CIS — Pt 2
- Multi-State Information Sharing and Analysis Center®
- CIS Critical Security Controls®
- How to Defend Against Iran's Cyber Retaliation Playbook
- Episode 178: Appropriate Defense to Iranian Threat Activity
- Secure by Design
- Collective SLTT Cyber Defense
- Episode 144: Carrying on the MS-ISAC's Character and Culture
- Monitoring and Support During the CrowdStrike Falcon Outage
- Episode 110: How Security Culture and Corporate Culture Mesh
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 178 of Cybersecurity Where You Are, Sean Atkinson sits down with Theodore "TJ" Sayers, Senior Director of Threat Intelligence at the Center for Internet Security® (CIS®). Together, they discuss how to mount an appropriate defense to Iranian threat activity observed in February and March 2026.
Here are some highlights from our episode:
- 00:58. Iran's historical tit-for-tat style of cyber operations
- 02:50. Regional targets: A primary focus of Iran's state-sponsored threat actors
- 04:05. What the CIS Cyber Threat Intelligence (CTI) team is watching for
- 05:19. Contextualizing a drop in precursor-related threat activity from Iran
- 06:59. Sectors directly and indirectly affected by observed Iranian threat activity
- 09:12. Password spraying, data wipers, and more: Common TTPs of Iranian threat groups
- 11:50. The importance of cybersecurity awareness training in countering TTPs that still work
- 16:07. Advice to SOC managers: How to detect what CIS CTI is expecting the most
- 21:25. NASCIO's Top 10 Priorities as a guide for framing strategic risk of Iran's threat activity
- 26:39. What an effective threat intel team does and does not do
- 29:29. Community defense for U.S. State, Local, Tribal, and Territorial (SLTT) organizations
Resources
- Multi-State Information Sharing and Analysis Center®
- Snap Call: Public Sector Threat Update Amid Conflict in Iran
- How to Defend Against Iran's Cyber Retaliation Playbook
- Cloudflare | Traffic in Iran
- Episode 143: Iran's Growing Multidimensional Threat Activity
- Episode 142: SLTTs and Their Nuanced Cybersecurity Needs
- MS-ISAC Guide to DDoS Attacks
- Exploited Protocols: Remote Desktop Protocol (RDP)
- Commonly Exploited Protocols: Server Message Block (SMB)
- State CIO Top Ten Policy and Technology Priorities for 2026
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 177 of Cybersecurity Where You Are, Tony Sager sits down with Bob Gendler, IT Specialist at the National Institute of Standards and Technology (NIST), and Edward Byrd, Senior Cybersecurity Engineer of the CIS Benchmarks® at the Center for Internet Security® (CIS®). Together, they use the open-source macOS Security Compliance Project to discuss the power of community-developed security content.
Here are some highlights from our episode:
- 01:15. Introductions to Bob and Edward along with their first Mac devices
- 03:24. Why CIS Benchmarks are needed for macOS
- 05:49. The need to make security guidance a collaborative, ongoing exercise
- 11:06. Inside the expanding community supporting the macOS Security Compliance Project
- 16:59. A practical win: making daily security operations easier to manage
- 21:40. An operational feedback loop of improving the CIS Benchmarks
- 25:25. The implications of compliance pointing to assurance, not security
- 30:53. Advice on how to prepare for an audit using the CIS Benchmarks
- 34:18. The importance of rationale in defining reasonable cybersecurity behavior
- 35:30. A teaser of upcoming changes and how to get involved
Resources
- CIS Benchmarks List
- Mapping and Compliance with the CIS Benchmarks
- Apple macOS
- CIS WorkBench
- CIS Communities
- Episode 156: How CIS Uses CIS Products and Services
- Reasonable Cybersecurity
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 176 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager sit down with Brock Boggs, Director of Technology at Cityscape Schools and Multi-State Information Sharing and Analysis Center® (MS-ISAC®) member, and Maureen Kunac, Senior Product Manager at the Center for Internet Security® (CIS®). Together, they discuss Brock's story of using incremental wins to advance his organization on its cybersecurity journey.
Here are some highlights from our episode:
- 02:10. Getting started making the largest measurable impact with CIS-CAT® Pro Assessor
- 03:52. Implementation Group 1: A filter for prioritizing secure configuration management efforts
- 09:16. The use of essential cyber hygiene to build an on-ramp to a security controls program
- 11:18. Navigating breakage, dependency, and other principles of change management
- 13:37. Lessons learned from beta testing and enterprise rollout of security changes
- 22:24. Advice: How to start on a journey of system hardening with measurable impact
Resources
- Episode 163: K-12 Cybersecurity Made Practical
- Formalizing K-12 Cybersecurity Policies in Less Time
- CIS-CAT® Pro Assessor
- CIS-CAT Pro Results Focus on CIS Controls IG1
- CIS Critical Security Controls®
- Guide to Implementation Groups (IG): CIS Critical Security Controls v8.1
- What SLTTs Should Know About the FREE CIS SecureSuite Membership
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 175 of Cybersecurity Where You Are, Tony Sager sits down with Phil Reitinger, Chair and Senior Advisor of Global Cyber Alliance. Together, they look back on Phil's career and his dedication to exploring how to practically solve cyber problems at scale.
Here are some highlights from our episode:
- 00:57. How Phil got started in cybersecurity during the "infosec" era
- 04:51. Old wine in new bottles: trust exploitation, authentication failures, and update challenges
- 06:14. The lack of political will, not technology, in solving fundamental cyber problems
- 07:33. How industry and government share similar challenges in cybersecurity
- 10:09. The importance of metrics in incentivizing the right actions
- 12:33. Scale: the biggest obstacle to collective cyber defense there ever was or will be
- 22:50. The Global Cyber Alliance and a focus on practically solving cyber problems at scale
Resources
- Episode 30: Solving Cybersecurity at Scale with Nonprofits
- Episode 79: Advancing Common Good in Cybersecurity – Part 1
- Episode 80: Advancing Common Good in Cybersecurity – Part 2
- Quad9
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 174 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager sit down with Kyle Leonard, Cyber Threat Intelligence Analyst at the Center for Internet Security® (CIS®), and Randy Rose, VP of Security Operations & Intelligence at CIS. Together, they continue their discussion of 2026 cybersecurity predictions from seven CIS experts, as shared on the CIS website.
Here are some highlights from our episode:
- 02:00. How cross-platform campaigns are becoming the norm
- 03:09. Threat actors' use of generative artificial intelligence (GenAI) to expand their attacks and gain efficiencies
- 05:08. The blurring line of what separates today's script kiddies from nation-state threat actors
- 07:47. Fully autonomous malware: in the realm of possibility but not here yet
- 13:19. How specialization in the criminal ecosystem requires us to rethink analysis itself
- 16:07. Shrinking dwell time: a product of the democratization of complex tools' availability
- 18:02. The effective use of social engineering to lower threat actors' operational costs
- 19:20. Malware's increasing use of trusted infrastructure to thwart cyber defenses
- 20:25. The use of behavioral analysis to apply bottleneck security mechanisms
- 22:40. Evolving threat actors' tradecraft: pseudo-random subdomains, GenAI models, and SEO poisoning
- 26:39. What trust looks like today: something that's dynamic and negotiated at a moment's notice
- 31:25. Supply chain attackers' pivot to edge device vendors and security appliance makers
- 33:43. The ongoing work of CIS to support state and local governments' cybersecurity efforts
Resources
- Episode 169: 2026 Cybersecurity Predictions from CIS — Pt 1
- The Evolving Role of Generative Artificial Intelligence in the Cyber Threat Landscape
- Surge of QakBot Activity Using Malspam, Malicious XLSB Files
- Active Lumma Stealer Campaign Impacting U.S. SLTTs
- Episode 173: Scammer Jousting as Human Risk Management
- ClickFix: An Adaptive Social Engineering Technique
- Impact of Federal Funding Cuts to the Value of MS-ISAC CTI
- Episode 157: How a Modern, Mission-Driven CIRT Operates
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 173 of Cybersecurity Where You Are, Sean Atkinson is joined by Roger Grimes, CISO Advisor at KnowBe4. Together, they discuss "scammer jousting," a term coined by Tony Sager which describes empowering organizations to manage human risk using simulated phishing.
Here are some highlights from our episode:
- 01:05. How simulated phishing and scammer jousting manage human risk
- 03:48. The shift in perception of security awareness training over the past 20 years
- 06:19. The need for testing to build capability and resiliency amongst employees
- 09:27. The many faces of phishing attacks and the impact of generative artificial intelligence
- 15:00. How gamification is proven to help users learn more in their cybersecurity training
- 16:57. How data empowers organizations to communicate the potential impact of a phish
- 19:57. The use of behavior engineering to foster a stronger security culture
- 23:56. The value of customer feedback in continuously enhancing phishing training
- 29:52. Continuous and hyper-personalized training as the future of spammer jousting
Resources
- Episode 77: Data's Value to Decision-Making in Cybersecurity
- Episode 98: Transparency as a Tool to Combat Insider Threats
- A Short Guide for Spotting Phishing Attempts
- CIS Controls v8.1 Security Awareness Skills Training Policy Template
- SANS Workforce Security and Risk Training
- The Evolving Role of Generative Artificial Intelligence in the Cyber Threat Landscape
- Episode 110: How Security Culture and Corporate Culture Mesh
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 172 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager sit down with Chirag Arora, Cyber Security Executive Advisor and CISO at Dorf Nelson & Zauderer LLP. Together, they discuss how Chirag draws upon his experience as a CISO and his community work as a CIS Critical Security Controls® (CIS Controls®) Ambassador to help other CISOs with their cybersecurity programs.
Here are some highlights from our episode:
- 00:51. Introduction to Chirag and the early years of his work as a CIS Controls Ambassador
- 06:03. The value of measurement and psychology when discussing assessments with CISOs
- 09:00. Chirag's work on a CISO certification and vision for aligning it to the CIS Controls
- 12:31. How open sharing of wisdom between CISOs makes the world more secure
- 20:57. The importance of storytelling for CISOs, CIS Controls Ambassadors, and other leaders
- 24:29. Chirag's use of law school to take his understanding of reasonableness up a level
- 28:13. Regular opportunities for CIS Controls Ambassadors to discuss universal issues
- 31:08. The heightened importance of nonprofit organizations bringing people together
Resources
- CIS Critical Security Controls®
- Episode 160: Championing SME Security with the CIS Controls
- Episode 168: Institutionalizing Good Cybersecurity Ideas
- Reasonable Cybersecurity Guide
- Simplify Security Management with CIS SecureSuite Platform
- CISO Certification by GlobalCISO Leadership Foundation™
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 171 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager sit down with Soledad Antelada Toledano, Security Advisor, Office of the CISO, Google Cloud at Google. Together, they discuss securing critical national infrastructure (CNI) in U.S. State, Local, Tribal, and Territorial (SLTT) government organizations through artificial intelligence (AI) adoption.
Here are some highlights from our episode:
- 00:50. Introduction to Soledad
- 02:48. How the convergence of informational technology (IT) and operational technology (OT) has created bigger attack surfaces
- 04:10. The proliferation of threat actors targeting critical infrastructure sectors
- 07:24. The challenge of legacy systems for U.S. SLTT owners of CNI
- 08:13. Alert fatigue, limited visibility, and other challenges facing OT networks
- 13:22. The value of automated cyber threat intelligence (CTI)
- 24:46. Building strategic AI implementation around human in the loop (HITL)
- 33:17. U.S. SLTTs' use of the cloud to test and build trust for securing CNI
Resources
- The Changing Landscape of Security Operations and Its Impact on Critical Infrastructure
- Cybersecurity for Critical Infrastructure
- Episode 139: Community Building for the Cyber-Underserved
- Episode 119: Multidimensional Threat Defense at Large Events
- Leveraging Generative Artificial Intelligence for Tabletop Exercise Development
- The Evolving Role of Generative Artificial Intelligence in the Cyber Threat Landscape
- Episode 148: How MDR Helps Shine a Light on Zero-Day Attacks
- Vulnerability Management Policy Template for CIS Control 7
- CIS Critical Security Controls v8.1 Industrial Control Systems (ICS) Guide
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In Episode 170 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager sit down with Douglas Holland, Senior Solutions Engineer at Akamai Technologies. Together, they discuss how U.S. State, Local, Tribal, and Territorial (SLTT) government organizations can increase their visibility to obstruct the attack attempts of Typhoon advanced persistent threat (APT) groups.
Here are some highlights from our episode:
- 00:49. Introduction to Douglas
- 02:16. How Typhoon APTs are using trusted tools to target critical infrastructure
- 08:30. Professionalism as a tell of sophisticated nation-state threat actors
- 09:15. How U.S. SLTTs come up with creative solutions despite budgeting and staffing limits
- 14:14. The "big credential playground" that is U.S. SLTTs' expanded attack surface
- 16:46. Visibility into network activity as a way to continuously build defensive capability
- 19:11. The use of context to connect technical visibility to defensive action
- 23:20. Identity as the new perimeter, cloud and SaaS posture, and micro-segmentation
- 29:18. One piece of advice: assume an attacker is already in the network or will be
Resources
- Malicious Domain Blocking and Reporting (MDBR)
- Living off the Land: The Power Behind PowerShell
- Cybersecurity for Critical Infrastructure
- Build a Zero Trust Roadmap for FinServ with CIS SecureSuite
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In Episode 169 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager begin their discussion of 2026 cybersecurity predictions from seven experts at the Center for Internet Security® (CIS®), as shared on the CIS website.
Here are some highlights from our episode:
- 01:05. The impact and promise of artificial intelligence on cyber defense
- 05:37. Collective action as an answer to the constraints facing the "cyber-underserved"
- 12:52. Zero trust and security best practices as functions of managing cycles of time
- 21:22. How tailored threat intelligence can help to frame cybersecurity around mission
- 31:18. The convergence of cybersecurity and privacy as a necessity for governance
Resources
- An Introduction to Artificial Intelligence
- Cybersecurity for Critical Infrastructure
- Episode 144: Carrying on the MS-ISAC's Character and Culture
- Episode 142: SLTTs and Their Nuanced Cybersecurity Needs
- Collective SLTT Cyber Defense
- Guide to Implementation Groups (IG): CIS Critical Security Controls v8.1
- Episode 90: Migrating to the Cloud with Control Continuity
- Build a Zero Trust Roadmap for FinServ with CIS SecureSuite
- Secure by Design: A Guide to Assessing Software Security Practices
- Episode 110: How Security Culture and Corporate Culture Mesh
- Episode 147: Actualizing Threat Intel for Effective Defense
- Law Enforcement
- Reasonable Cybersecurity Guide
- NIST SP 800-207: Zero Trust Architecture
- Episode 74: The Nexus of Cybersecurity & Privacy Legislation
- Mapping and Compliance with the CIS Controls
- Mapping and Compliance with the CIS Benchmarks
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In Episode 168 of Cybersecurity Where You Are, Tony Sager sits down with Tony Rutkowski, one of the CIS Critical Security Controls® (CIS Controls®) Ambassadors of the Center for Internet Security® (CIS®). Together, they discuss what Tony Rutkowski has learned in his efforts to institutionalize good cybersecurity ideas like the CIS Controls.
Here are some highlights from our episode:
- 01:48. Introductions to Tony Rutkowski and his career in technology
- 06:06. The evolution of the CIS Controls and how Tony Rutkowski came to advocate for them
- 12:50. The "Fog of More" as a metaphor to focus attention, not create new solutions
- 17:50. How institutionalizing good cybersecurity ideas is like conducting an orchestra
- 21:44. The use of timing and the right security content to help people clarify their intentions
- 24:25. The value of industry mappings in reducing duplicate implementation efforts
- 26:41. Secure by design: a 2025 example of creating a new formal global technical standard
Resources
- Episode 160: Championing SME Security with the CIS Controls
- Episode 167: Volunteers as a Critical Cybersecurity Resource
- Reasonable Cybersecurity Guide
- Cybersecurity at Scale: Piercing the Fog of More
- Mapping and Compliance with the CIS Controls
- Secure by Design: A Guide to Assessing Software Security Practices
- Episode 164: Secure by Design in Software Development
- CIS Critical Security Controls Implementation Groups
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In Episode 167 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager sit down with Kelley Misata, Ph.D., Chief Trailblazer and Founder at Sightline Security. Together, they discuss how volunteers constitute a critical cybersecurity resource for the Center for Internet Security® (CIS®). Along the way, they explore the nature of volunteerism, the role of volunteers at CIS, and how CIS is looking to mature its engagement with volunteers going forward.
Here are some highlights from our episode:
- 01:37. Introductions to Kelley and her experience with cybersecurity volunteers
- 03:09. Kelley's use of research, expertise, and an open mind to check in with CIS volunteers
- 04:50. How volunteers have deepened their passion and dedication with CIS for 25 years
- 06:55. Volunteers as a critical cybersecurity resource for "One CIS" going forward
- 10:51. Commitment, conflict resolution, and openness to formal process in CIS Communities
- 14:39. The use of directionality and accolades to encourage different types of contributors
- 19:43. The importance of flexibility in management to meet volunteers where they are
- 20:30. Leadership, storytelling, and recruitment as opportunities for volunteerism at CIS
- 24:37. The risk of volunteer burnout and how to protect against it
- 26:00. Collaboration with employers to treat volunteerism as a growth experience
- 30:09. A balancing act of making volunteers useful without depleting the mission
- 34:51. Sean's take: volunteer management as the original Large Language Model (LLM)
- 38:32. Other observations and final thoughts
Resources
- 25 Years of Creating Confidence in the Connected World
- CIS Communities
- Episode 160: Championing SME Security with the CIS Controls
- StoryCorps
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In Episode 166 of Cybersecurity Where You Are, Sean Atkinson sits down with Tyler Moore, Ph.D., Chair of Cyber Studies at the University of Tulsa, and Daniel Woods, Lecturer at the University of Edinburgh. Together, they review the foundations of actuarial science in cyber risk.
Here are some highlights from our episode:
- 00:48. Introductions to Tyler and Daniel
- 01:22. How actuarial science fits into a traditional approach of risk modeling
- 02:20. Why cyber risk has historically been difficult to quantify
- 04:01. How data sources available to insurers and individual organizations have evolved
- 07:21. Adaptability as a key principle to model risk for an evolving cyber threat landscape
- 08:58. Loss distribution modeling for different types of cyber threats
- 11:38. Similarities and differences between how actuaries and frameworks view risks
- 13:10. Quantifying severity, frequency, and resilience to different cyber risks
- 14:31. How insurers differ from underwriters in their view of risk
- 17:43. Ransomware as a case study where actuarial modeling improved risk management
- 22:30. The value of translating cyber risk to business risk for CISOs like Sean
- 26:20. Why data on which security controls matter most remains elusive
- 32:33. The biggest misconceptions of using actuarial models in cybersecurity
- 36:09. How cyber actuarial science can help to determine what works in cybersecurity
Resources
- Episode 121: The Economics of Cybersecurity Decision-Making
- Episode 105: Context in Cyber Risk Quantification
- Episode 77: Data's Value to Decision-Making in Cybersecurity
- How Risk Quantification Tests Your Reasonable Cyber Defense
- Episode 113: Cyber Risk Prioritization as Ransomware Defense
- Episode 65: Making Cyber Risk Analysis Practical with QRA
- FAIR: A Framework for Revolutionizing Your Risk Analysis
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In Episode 165 of Cybersecurity Where You Are, Tony Sager sits down with Valecia Stocchetti, Senior Cybersecurity Engineer at the Center for Internet Security® (CIS®), and Charity Otwell, Director of Critical Security Controls at CIS. Together, they take an in-depth look at implementing the CIS Critical Security Controls® (CIS Controls®), including what you need to know to begin your own CIS Controls implementation efforts.
Here are some highlights from our episode:
- 00:53. Introductions to Valecia and Charity
- 02:48. How the CIS Controls ecosystem answers the deeper question of how to implement
- 06:42. The importance of clear strategy, business priorities, and a realistic timeline
- 09:56. How the CIS Community Defense Model (CDM) clarifies cyber defense priorities
- 13:01. The use of calculations around costing to make a security program achievable
- 15:31. Bringing IT and the Board of Directors together through governance
- 20:36. "Herding cats" as a metaphor for navigating different compliance frameworks
- 23:17. Why one prescriptive ask per CIS Safeguard starts cybersecurity workflows
- 25:30. "Why" vs. "how" communication, accountability, staffing, budget, and continuous improvement as keys to success for CIS Controls implementation
- 42:03. CIS Controls Assessment Specification as an answer to implementation subjectivity
- 47:21. Parting thoughts around team effort, change, and CIS Controls Accreditation
Resources
- Cloud Companion Guide for CIS Controls v8.1
- CIS Community Defense Model 2.0
- The Cost of Cyber Defense CIS Controls IG1
- Episode 132: Day One, Step One, Dollar One for Cybersecurity
- Policy Templates
- Episode 107: Continuous Improvement via Secure by Design
- Reasonable Cybersecurity Guide
- CIS Controls Resources
- CIS Controls Assessment Specification
- Episode 156: How CIS Uses CIS Products and Services
- CIS Controls Accreditation
- Controls Accreditation
- Episode 102: The Sporty Rigor of CIS Controls Accreditation
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In Episode 164 of Cybersecurity Where You Are, Tony Sager sits down with Curt Dukes, EVP and General Manager of Security Best Practices at the Center for Internet Security® (CIS®), and Steve Lipner, Executive Director of SAFECode.org. Together, they explore the evolution of secure software development and why secure by design is critical for reducing risk in today’s complex environments.
Here are some highlights from our episode:
- 01:08. Introductions to Curt and Steve
- 04.01. The historical challenge of implementation errors in software security
- 08:41. The emergence of secure by design and the need to measure against specified criteria
- 14:39. The value of artifacts as evidence of secure software development
- 28:52: How the CIS Critical Security Controls® (CIS Controls®) support secure software
- 39:59. The use of community projects to address challenges like secure by design
Resources
- Secure by Design: A Guide to Assessing Software Security Practices
- How Secure by Design Helps Developers Build Secure Software
- CIS, SAFECode Launch Secure by Design Guide to Help Developers Meet National Software Security Expectations
- Episode 107: Continuous Improvement via Secure by Design
- Secure by Design
- Secure Software Development Framework
- Episode 63: Building Capability and Integration with SBOMs
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In Episode 163 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager sit down with Brock Boggs, Director of Technology at Cityscape Schools, and Maureen Kunac, Senior Product Manager at the Center for Internet Security® (CIS®). They dive into the realities and challenges of K-12 cybersecurity, including limited budgets, small teams, and growing threats.
Brock shares how a ransomware incident at a neighboring school district and new state requirements pushed his district to take K-12 cybersecurity more seriously. He explains how CIS SecureSuite® tools gave him a clear starting point and helped him transform panic into progress. Maureen highlights how CIS continues to adapt its cybersecurity solutions for K-12 schools and why simplicity matters when resources are tight.
Here are some highlights from our episode:
- 00:47. Introductions to Brock and Maureen
- 02:50. What prompted Cityscape Schools to prioritize cybersecurity and how Brock found CIS
- 11:50. The importance of simplicity in making K-12 cybersecurity practical
- 12:39. A collaborative journey of helping Brock get comfortable learning about cybersecurity
- 22:52. A look back at Cityscape Schools pivoted to remote education during COVID-19
- 34:20. Brock's advice for other school districts to get started with a cybersecurity program
Resources
- Formalizing K-12 Cybersecurity Policies in Less Time
- How to Plan a Cybersecurity Roadmap in 4 Steps
- 2025 K-12 State of Cybersecurity Report: Where Education Meets Community Resilience
- Episode 142: SLTTs and Their Nuanced Cybersecurity Needs
- 25 Years of Creating Confidence in the Connected World
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In Episode 162 of Cybersecurity Where You Are, Tony Sager sits down with Tina Williams-Koroma, Founder and CEO of TCecure, LLC and CyDeploy, Inc. Together, they discuss why "cyber insecurity is not inevitable" and how organizations can take a managed approach to attack surface management.
Along the way, Tina shares her journey from software development to cybersecurity entrepreneurship and explains why proactive measures like hardening systems and automating patching are critical for reducing risk. Here are some highlights from our episode:
- 00:50. Introductions to Tina, her career pivot, and her entrepreneurial path
- 03:35. The value of the secure configuration guidance provided by the CIS Benchmarks®
- 07:35. Why a well-managed system makes for a hard target
- 11:00. Marketing against “magic” in a hype-driven cybersecurity market
- 13:44. The translative work of moving well-managed infrastructure beyond "mere hygiene"
- 19:14. Tina's faith-based inspiration for helping others get as far as she's gotten
- 27:23. Soccer analogies for a managed attack surface
- 33:54. Tina's pep talk: "Why cyber insecurity is not inevitable"
- 38:38. Free cybersecurity resources for small businesses
Resources
- Mapping and Compliance with the CIS Benchmarks
- Guide to Asset Classes: CIS Critical Security Controls v8.1
- Gartner Says That in the Age of GenAI, Preemptive Capabilities, Not Detection and Response, Are the Future of Cybersecurity
- CIS Community Defense Model 2.0
- OwlThis — Powered By CyDeploy
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In Episode 161 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager are joined by Mishal Makshood, Azure Partner Alliance Manager at the Center for Internet Security® (CIS®), and David Kalish, Sr. Cybersecurity Solutions Engineer at CIS. Together, they explore how CIS Hardened Images® help to secure cloud environments and strengthen critical national infrastructure (CNI) resilience through collaboration.
Mishal and David explain how these virtual machine images, which are pre-configured to the CIS Benchmarks®, serve as secure, scalable blueprints for cloud deployments. They highlight how CIS Hardened Images reduce human error, accelerate compliance, and foster trust across a global cybersecurity ecosystem that includes hyperscalers, supply chains, and public-private partnerships.
Tony shares the origin story of the CIS Hardened Images and reflects on the evolution of cybersecurity from isolated efforts to a cooperative model built on shared standards and integrated tooling. The group also discusses how CIS Hardened Images align to frameworks and how they help organizations navigate multi-cloud environments while maintaining consistent security postures. Here are some highlights from our episode:
- 00:50. Introductions to Mishal and David
- 01:36. What CIS Hardened Images are and why they matter
- 03:14. Why CIS Hardened Images are uniquely suited to strengthening CNI resilience
- 04:24. The cultural shift toward working as an ecosystem to start from secure baselines
- 06:34. The origin story of the CIS Hardened Images
- 10:32. The value of taking guesswork out of secure configuration management in the cloud
- 13:44. How CIS Hardened Images support compliance directly and through the CIS Critical Security Controls® (CIS Controls®)
- 20:39. Building trust through cloud partnerships and collaboration
- 28:50. The foundational role of configuration management in cybersecurity
- 34:35. Getting started with strengthening your cloud security foundation
Resources
- CIS Hardened Images® List
- Secure by Design: A Guide to Assessing Software Security Practices
- Software Supply Chain Security
- 25 Years of Creating Confidence in the Connected World
- Mapping and Compliance with the CIS Controls
- Guide to Implementation Groups (IG): CIS Critical Security Controls v8.1
- Build a Zero Trust Roadmap for FinServ with CIS SecureSuite
- Episode 154: Integration of Incident Response into DevSecOps
- How to Construct a Sustainable GRC Program in 8 Steps
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In Episode 160 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager sit down with Alan Watkins, CIS Controls Ambassador, to explore how the CIS Critical Security Controls® (CIS Controls®) empower small and medium-sized enterprises (SMEs) to build practical, scalable cybersecurity programs.
Alan shares his journey from law enforcement to IT leadership in the City of San Diego and how his passion for supporting SME security led him to become a champion of the CIS Controls. The episode highlights the importance of translating complex cybersecurity guidance into actionable steps that SMEs can realistically implement even with limited resources.
Here are some highlights from our episode:
- 00:49. Introductions to Alan, his career path, and his connection to the CIS Controls
- 11:43. How Alan supports SMEs to mature their cybersecurity postures
- 18:04. The work of CIS Controls Ambassadors to "memorialize" security best practices
- 22:23. The need to translate how cyber hygiene supports business success
- 25:31. CIS WorkBench and in-person communities as avenues to get involved
Resources
- Implementation Guide for Small- and Medium-Sized Enterprises CIS Controls IG1
- Establishing Essential Cyber Hygiene
- Episode 132: Day One, Step One, Dollar One for Cybersecurity
- Episode 97: How Far We've Come preceding CIS's 25th Birthday
- PCI & CIS: Partners in Data Security
- 2024 DBIR Findings & How the CIS Critical Security Controls Can Help to Mitigate Risk to Your Organization
- Policy Templates
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 159 of Cybersecurity Where You Are, Sean Atkinson is joined by Joshua Palsgraf, Sr. Cyber Threat Intelligence Analyst at the Center for Internet Security® (CIS®), and Randy Rose, Vice President of Security Operations & Intelligence at CIS. Together, they dive into the scariest malware of 2025 in this special Halloween edition.
The conversation explores what makes today’s malware truly terrifying, from stealthy threats that hide in plain sight to modular malware that evolves faster than defenses can adapt. The trio also discusses the corporatization of cybercrime, the rise of Malware as a Service, and how generative artificial intelligence (GenAI) is lowering the barrier to entry for cybercriminals.
Here are some highlights from our episode:
- 00:42. Introductions to Josh and Randy
- 02:21. What makes the scariest malware of 2025 truly "scary"
- 05:42. Evolution of malware: people, process, and technology
- 09:33. How the corporatization of malware helps to democratize cybercrime
- 11:25. The most "terrifying" malware strains of 2025
- 15:49. Malware reincarnation: Old threats with new masks
- 17:20. GenAI as the great equalizer for cybercriminals, especially social engineers
- 23:32. Defense-in-depth and threat-informed strategies
- 24:45. Why incident response playbooks must evolve and become living documents
- 27:02. What incident response looks like for cloud assets in the Fourth Industrial Revolution
- 29:27. Naming malware after horror movie icons
Resources
- Multi-State Information Sharing and Analysis Center®
- Episode 144: Carrying on the MS-ISAC's Character and Culture
- Episode 126: A Day in the Life of a CTI Analyst
- A Short Guide for Spotting Phishing Attempts
- The CIS Security Operations Center (SOC): The Key to Growing Your SLTT's Cyber Maturity
- Episode 157: How a Modern, Mission-Driven CIRT Operates
- Living Off the Land: Scheduled Tasks
- Cyber defenders sound the alarm as F5 hack exposes broad risks
- Episode 134: How GenAI Lowers Bar for Cyber Threat Actors
- Active Lumma Stealer Campaign Impacting U.S. SLTTs
- MS-ISAC Member-Reported Phishing Likely from Tycoon2FA PhaaS
- ClickFix: An Adaptive Social Engineering Technique
- Top 10 Malware Q1 2025
- CTAs Leveraging Fake Browser Updates in Malware Campaigns
- Italian police freeze cash from AI-voice scam that targeted business leaders
- CornCon Cybersecurity Conference
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 158 of Cybersecurity Where You Are, Sean Atkinson is joined by Andy Weidner, Product Manager at Nerdio, and Jason Ingalls, Chief Cybersecurity Officer at C3 Integrated Solutions. Together, they explore how organizations can navigate the complexities of Cybersecurity Maturity Model Certification (CMMC) compliance using automation, scalable infrastructure, and hardened cloud environments.
The conversation dives into the challenges faced by managed service providers (MSPs) and defense contractors, the importance of baking in security from the start, and how Nerdio’s platform acts as a force multiplier for compliance and operational efficiency. Jason shares a compelling anecdote from his time in a security operations center (SOC), illustrating the real-world stakes of cybersecurity and the origins of CMMC.
Here are some highlights from our episode:
- 00:44. Introductions to Andy and Jason
- 01:17. How to address common challenges of CMMC compliance
- 03:40. A real-world story of data exfiltration and its national security impact
- 08:34. How Nerdio and CIS Hardened Images® help organizations in their CMMC journey
- 12:15. Understanding the vision to scale configuration management
- 18:14. Strategy and automation as key elements to approaching CMMC Level 2
- 25:19. The value of baking scalability in vs. bolting it on
- 26:38. Segregation of duties as a means of pursuing dual-scope CMMC certification
- 29:22. Where to learn more about Nerdio and C3 Integrated Solutions
Resources
- Nerdio
- C3 Integrated Solutions
- CIS Hardened Images®
- How to Plan a Cybersecurity Roadmap in 4 Steps
- CIS Controls v8.1 Mapping to CMMC 2.0
- CIS Controls v8.1 Mapping to NIST SP 800-53 Rev 5
- CIS Controls v8.1 Mapping to NIST SP 800-171 Rev 3
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 157 of Cybersecurity Where You Are, Sean Atkinson sits down with Matthew Grieco, Cyber Incident Response Team (CIRT) Principal Analyst at the Center for Internet Security® (CIS®), and Dustin Cox, CIRT Analyst at CIS. Together, they explore the unpredictable world of cyber incident response. From ransomware investigations to digital forensics, the team shares how they adapt to evolving threats, leverage open-source tools, and collaborate to support state and local governments. The conversation highlights the mission-driven mindset that fuels their work and the importance of continuous learning, effective communication, and teamwork in cybersecurity. Here are some highlights from our episode:
- 00:44. Introductions to Matt and Dustin
- 01:20. Inside the typically untypical day of a CIRT analyst
- 05:33. Continuous learning and teamwork as ways to keep up with evolving threats
- 07:38. Inside the cybersecurity tooling used by CIRT to support state and local governments
- 14:51. How different skillsets on the team produce a unified incident response methodology
- 19:26. The work of a mission-driven team to uncover root causes for security incidents
- 25:52. An example of a case handled by Matt and Dustin
- 30:16. How CIRT assesses potential talent and looks for problem solvers
Resources
- Multi-State Information Sharing and Analysis Center®
- The CIS Security Operations Center (SOC): The Key to Growing Your SLTT's Cyber Maturity
- Episode 152: Driving Response Time While Enriching Telemetry
- Episode 126: A Day in the Life of a CTI Analyst
- Combatting Ransomware
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 156 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager are joined by Stephanie Gass, Sr. Director of Information Security at Center for Internet Security® (CIS®), and Angelo Marcotullio, Chief Information Officer at CIS. Together, they explore how CIS practices what it preaches by using CIS products and services internally, which includes implementation of the CIS Critical Security Controls® (CIS Controls®) and CIS Benchmarks®, automation, and alignment to compliance frameworks. Their discussion highlights how CIS builds a strong cybersecurity foundation while adapting to evolving threats and regulatory requirements.
The conversation dives into practical applications, cultural alignment, and the importance of repeatable processes for scaling security across new products and services. It also touches on the role of privacy regulations, cyber risk quantification, and the community-driven approach that underpins CIS best practices. Here are some highlights from our episode:
- 01:12. Why CIS “drinks its own champagne” when it comes to cybersecurity
- 02:56. Three ways the CIS Controls help modern enterprises defend against threat actors
- 04:02. The importance of pulling together security lessons learned in a way that's translatable
- 10:03. Our use of the CIS Controls to align to SOC 2, ISO 27001, and other frameworks
- 12:01. How governance, risk, and compliance (GRC) engineering works with automation to help build repeatable processes
- 22:43. The role of collaboration and communication in building a cybersecurity program
- 27:17. Privacy regulations as a catalyst for security innovation
- 30:24. The CIS Community Defense Model and evidence-based practices
- 32:40. How CIS leverages lessons learned to improve our security best practices
Resources
- Episode 146: What Security Looks Like for a Security Company
- Implementation Guide for Small and Medium-Sized Enterprises CIS Controls IG1
- How to Construct a Sustainable GRC Program in 8 Steps
- Mapping and Compliance with the CIS Controls
- CIS Completes SOC 2 Type II Audit Using CIS Best Practices
- Episode 74: The Nexus of Cybersecurity & Privacy Legislation
- CIS Community Defense Model 2.0
- Episode 121: The Economics of Cybersecurity Decision-Making
- Episode 77: Data's Value to Decision-Making in Cybersecurity
- CIS Communities
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 155 of Cybersecurity Where You Are, Tony Sager is joined by John Gilligan, President and Chief Executive Officer (CEO) of the Center for Internet Security® (CIS®). Together, they reflect on 25 years of progress for CIS and look ahead to the future. They explore the driving forces behind "CIS 2.0," including the shift toward addressing multidimensional threats, expanding CIS’s audience, and leveraging tools driven by generative artificial intelligence (GenAI). Their discussion highlights how CIS is adapting to a new era while staying true to its mission-driven roots and foundational principles. Here are some highlights from our episode:
- 01:11. The need for a mission-driven nonprofit to support the role of government
- 04:28. Understanding the primary catalyst behind CIS 2.0
- 05:53. Multidimensional threats, expanded audiences, and revamped tools as adaptive opportunities
- 12:57. The challenge of linking technology risk to operational risk
- 13:45. How attackers tend to be more systems-level thinkers than defenders
- 15:50. Culture as a support system for navigating the evolving skills and processes of CIS 2.0
- 22:24. Collaboration, partnerships, mission focus, and culture as foundational CIS elements
- 31:11. How our engagement with state and local governments, thought leadership, and products and services will change going forward
- 40:47. Parting thoughts and an important reminder
Resources
- 25 Years of Creating Confidence in the Connected World
- Episode 119: Multidimensional Threat Defense at Large Events
- Strengthening Critical Infrastructure: SLTT Progress & Priorities
- Enhanced Cyber Resilience as a Secure Cyber City
- The CIS Security Operations Center (SOC): The Key to Growing Your SLTT's Cyber Maturity
- Episode 115: Continuous Feedback as CIS Employee Culture
- Episode 125: How Leadership Principles Influence CIS Culture
- CIS Culture
- CIS Communities
- Episode 97: How Far We've Come preceding CIS's 25th Birthday
- Why Whole-of-State Cybersecurity Is the Way Forward
- An Introduction to Artificial Intelligence
- Reasonable Cybersecurity
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 154 of Cybersecurity Where You Are, Sean Atkinson discusses incident response in DevSecOps, exploring challenges and solutions in modern software development. He emphasizes the importance of integrating security into development processes and speaks about common issues like alert fatigue and software supply chain vulnerabilities. Here are some highlights from our episode:
- 01:32. Common challenges with modern software development
- 03:54. High-speed and continuous deployment
- 07:08. Incident correlation with cloud deployment strategies
- 10:00. Software supply chain vulnerabilities
- 12:45. Alert fatigue and false positives
- 14:30. Testing and automation as enablers of real-time anomaly detection
- 17:40. The responsibility of incident responders to understand what they see
- 18:58. Automated control and a projectized approach to implementing zero trust
- 21:26. Oversight and governance with artificial intelligence and machine learning
- 23:24. Continuous improvement and early detection
- 28:08. Continuous monitoring and logging, automation, and incident response drills
- 30:03. Moving down a path of helping incident responders become culturally aware
Resources
- Cloud Security and the Shared Responsibility Model
- CIS Software Supply Chain Security Guide
- An Introduction to Artificial Intelligence
- Defense-in-Depth: A Necessary Approach to Cloud Security
- Episode 63: Building Capability and Integration with SBOMs
- Episode 44: A Zero Trust Framework Knows No End
- Leveraging Generative Artificial Intelligence for Tabletop Exercise Development
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 153 of Cybersecurity Where You Are, Sean Atkinson is joined by Jason Ashong, IT Support Specialist at the Center for Internet Security® (CIS®). Jason shares his journey from tinkering with tech as a kid to working in IT and pursuing cybersecurity research. The conversation covers education, mentorship, hands-on experience, and advice for newcomers entering the field. Here are some highlights from our episode:
- 01:10. Jason’s early days in IT of fixing devices and breaking things to learn
- 02:14. First professional IT/helpdesk experience at Dutchess Community College
- 03:48. The importance of mentors pushing you to grow
- 06:02. Jason’s advice to students of understanding foundational computing knowledge
- 08:45. The value of technical skills in networking, cryptography, and coding
- 11:00. Hands-on experience through labs, competitions, and research projects
- 16:08. Self-confidence, practice, and dedicated time as tips for navigating the job market
- 19:29. The role of attitude in opening up new opportunities
- 24:40. Jason flips the script and interviews Sean
- Mistakes to avoid when entering the field: imposter syndrome and perfectionism
- Cybersecurity as a path of continuous learning
- Opportunities for newcomers with experience in artificial intelligence and data science
Resources
- Episode 129: Embedding Cybersecurity in Project Management
- Episode 95: AI Augmentation and Its Impact on Cyber Defense
- Episode 44: A Zero Trust Framework Knows No End
- TryHackMe
- Hack The Box
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 152 of Cybersecurity Where You Are, Sean Atkinson is joined by Cliff Moten, Manager, Cybersecurity Solutions Engineering at the Center for Internet Security® (CIS®); and Richard Vargas, Security Operations Center Manager at CIS. Together, they discuss how the 24x7x365 CIS Security Operations Center (SOC) and CIS Managed Detection and Response™ (CIS MDR™) work together to accelerate response time while enriching telemetry. Here are some highlights from our episode:
- 01:40. Demystifying SOCs and MDR as cybersecurity concepts
- 02:52. How the CIS SOC works to provide information, context, and next steps for an event
- 05:04. Artificial intelligence and automation as ways to accelerate response time
- 10:20. Real-world instances where a fast response time made a difference
- 13:10. What it means to support underfunded organizations with the resources they need
- 17:22. The role of contextual cyber threat intelligence in accelerating response times
- 19:01. The value of security orchestration, automation, and response (SOAR) in helping defenders move quickly
- 27:33. Lessons that organizations can use to cut down on their incident response times
Resources
- The CIS Security Operations Center (SOC): The Key to Growing Your SLTT's Cyber Maturity
- Episode 148: How MDR Helps Shine a Light on Zero-Day Attacks
- Episode 144: Carrying on the MS-ISAC's Character and Culture
- Episode 137: National Cybersecurity Through SLTT Resilience
- Combatting Ransomware
- Establishing Essential Cyber Hygiene
- CIS Community Defense Model 2.0
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 151 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager conclude their mid-year review of 12 Center for Internet Security® (CIS®) experts' cybersecurity predictions for 2025. Here are some highlights from our episode:
- 01:12. The importance of consolidating security operations and using what already exists
- 03:18. The promise of generative artificial intelligence (GenAI) in relieving grunt work
- 08:26. The great responsibility and burden of integrating GenAI into business operations
- 10:53. How control and inspection generate trust in systems
- 17:57. Post-quantum cryptography, IoT in edge computing, and GenAI's sociopolitical risks
- 30:21. The need for a more holistic understanding of compliance
- 33:34. Why zero trust doesn't mean "no trust"
- 36:56. The need for AI as an element of critical security control
- 41:33. The dynamic challenge of protecting all assets with varying levels of security
Resources
- 12 CIS Experts' Cybersecurity Predictions for 2025
- Episode 145: 2025 Cybersecurity Predictions H2 Review — Pt 1
- Episode 135: Five Lightning Chats at RSAC Conference 2025
- Establishing Essential Cyber Hygiene
- Episode 95: AI Augmentation and Its Impact on Cyber Defense
- Guide to Asset Classes: CIS Critical Security Controls v8.1
- An Examination of How Cyber Threat Actors Can Leverage Generative AI Platforms
- An Introduction to Artificial Intelligence
- Episode 120: How Contextual Awareness Drives AI Governance
- Episode 118: Preparing for Post-Quantum Cryptography
- Episode 63: Building Capability and Integration with SBOMs
- Episode 99: How Cyber-Informed Engineering Builds Resilience
- Mapping and Compliance with the CIS Controls
- Mapping and Compliance with the CIS Benchmarks
- CIS Community Defense Model 2.0
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 150 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager are joined by Chad Rogers, Sr. Manager, Digital Media Services, at the Center for Internet Security® (CIS®); Rudy Uhde, Video Editor at CIS; and David Bisson, Sr. Content Strategist at CIS. Together, they use a roundtable chat to celebrate 150 episodes of Cybersecurity Where You Are. Here are some highlights from our episode:
- 01:33. How the cybersecurity landscape and podcast have changed since Episode 100
- 05:40. The "labor of love" that goes into editing and preparing an episode for publication
- 12:13. Memorable guests and moments that changed the team's thinking about cybersecurity
- 25:45. How the larger podcast team drives continuous improvement and innovation
- 30:13. Parting thoughts for the audience
Resources
- Episode 100: Celebrating 100 Episodes and Looking Ahead
- Episode 149: Human Error, AI Missteps, and Other VM Risks
- Episode 9: Mitigating Risk: Information Security Governance
- Episode 96: Making Continuous Compliance Actionable for SMBs
- Episode 121: The Economics of Cybersecurity Decision-Making
- Episode 114: 3 Board Chairs Reflect on 25 Years of Community
- Episode 136: How WiCyS Advances Women in Cybersecurity
- Episode 120: How Contextual Awareness Drives AI Governance
- Episode 116: AI-Enhanced Ransomware and Defending Against It
- Episode 146: What Security Looks Like for a Security Company
- Episode 110: How Security Culture and Corporate Culture Mesh
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 149 of Cybersecurity Where You Are, Sean Atkinson is joined by Chris McCullar, Director of Sales, Cloud Security, at the Center for Internet Security® (CIS®); and Mishal Makshood, Sr. Cloud Security Account Executive at CIS. Together, they discuss how to navigate human error, artificial intelligence (AI) missteps, and other landmarks in a new frontier of virtual machine (VM) risks. Here are some highlights from our episode:
- 00:50. Introductions with Chris and Mishal
- 02:20. The ongoing need to address the risk of human error when configuring VMs
- 04:55. The value of building trusted security into a VM image by design
- 07:28. A reality check of what the shared responsibility model means to an organization
- 13:06. How the integration of AI into DevOps accelerates both automation and mistakes
- 15:21. The importance of a secure foundation in the cloud on which you can build with AI
- 18:19. Automated enforcement and AI's role in complementing human judgment
- 21:03. Two examples how CIS resources can drive governance and policy integration
- 28:05. Cybersecurity as a community-driven team sport
- 30:33. Lifecycle management as a way of addressing organizations' security needs
Resources
- Keep the Cloud Secure with CIS after Migrating to the Cloud
- Automated Compliance: The Byproduct of Holistic Hardening
- Meet the Shared Responsibility Model with New CIS Resources
- Episode 135: Five Lightning Chats at RSAC Conference 2025
- 2025 Data Breach Investigations Report
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 148 of Cybersecurity Where You Are, Sean Atkinson is joined by Rob Reese, Cyber Incident Response Team Manager at the Center for Internet Security® (CIS®); Dustin Cox, Cyber Incident Response Team Analyst at CIS; and Cliff Moten, Manager, Cybersecurity Solutions Engineering at CIS. Together, they discuss how organizations can use Managed Detection and Response (MDR) tools to help defend against zero-day attacks. Here are some highlights from our episode:
- 01.06. Demystifying zero-day vulnerabilities with a definition
- 02:36. Why zero-day attacks are some of the most serious threats facing organizations today
- 04:19. Examples of zero-day exploits and how these threats affect Incident Response (IR)
- 10:06. The importance of understanding your environment and patch management
- 13:58. How MDR assists with behavioral analysis, assembling holistic inventories, and IR
- 20:02. The role of asset inventories in determining scope and containing a zero-day incident
- 24:08. Why it's important to have humans managing and monitoring an MDR solution
- 27:11. MDR as a means of centralizing evidence of a zero-day attack
- 30:05. Parting thoughts for those concerned with their endpoint security posture
Resources
- CIS Managed Detection and Response™ (CIS MDR)
- Multi-State Information Sharing and Analysis Center®
- CIS Critical Security Control 1: Inventory and Control of Enterprise Assets
- CIS Critical Security Control 2: Inventory and Control of Software Assets
- The CIS Security Operations Center (SOC): The Key to Growing Your SLTT's Cyber Maturity
- Real-Time Indicator Feeds
- Incident Response Policy Template for CIS Control 17
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 147 of Cybersecurity Where You Are, Sean Atkinson is joined by John Cohen, Executive Director of the Program for Countering Hybrid Threats at the Center for Internet Security® (CIS®); and Kaitlin Drape, Hybrid Threat Intelligence Analyst at CIS. Together, they discuss how to actualize threat intel for the purpose of building effective defense programs and operational response plans. Here are some highlights from our episode:
- 01:27. Which two questions you want to answer when providing intelligence on a threat
- 05:19. How to avoid underutilizing or misunderstanding the utility of threat intel
- 13.18. A real-life story from John of when intelligence made a difference in a security incident
- 17:05. The foundation and building blocks of maturing your threat intelligence program
- 22:14. The value of working with non-intelligence groups to formulate effective response plans
- 24:22. CIS's ongoing work to help organizations proactively ingest and use threat intel
- 28:24. How cross-collaboration across an organization brings threat intel into a lifecycle
- 31:01. Kaitlin's work as an exemplar of how to make threat intelligence operational
- 36:20. The ongoing evolution of hybrid threat intel to inform meaningful operational responses
Resources
- ThreatWA™
- How Threat Modeling, Actor Attribution Grow Cyber Defenses
- Countering Multidimensional Threats: Lessons Learned from the 2024 Election
- Episode 119: Multidimensional Threat Defense at Large Events
- Sinaloa cartel used phone data and surveillance cameras to find FBI informants, DOJ says
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 146 of Cybersecurity Where You Are, Tony Sager is joined by Angelo Marcotullio, Chief Information Officer at the Center for Internet Security®(CIS®); and Stephanie Gass, Sr. Director of Information Security at CIS. Together, they look back on periods of transition at CIS to discuss what security looks like for a security company. Here are some highlights from our episode:
- 00:58. Introductions with Angelo and Stephanie
- 02:07. A pro and a con of IT consulting work
- 04:12. The importance of soft skills in bringing the Multi-State Information Sharing and Analysis Center® into CIS
- 06:12. Looking at security from a corporate perspective with the CIS Critical Security Controls
- 07:08. How IT and IT security are essential to corporate strategy
- 07:45. The use of governance to support merging three business units into an integrated security company
- 12:04. The value of security champions in adapting to regulatory and business changes
- 15:15. What IT and Security teams can accomplish when they work as partners
- 17:18. The use of data to inform Board decisions and conversations around risk
- 20:38. How getting a seat at the table helps with understanding a Board's risk appetite and communicating that out to teams
- 25:01. How infrastructure built for growth, not the smallest business case, produced a smooth transition to work from home in March 2020
- 29:30. Advice for folks starting out in security
- 31.28. The importance of collaboration and culture in implementing security as an organization
Resources
- Episode 144: Carrying on the MS-ISAC's Character and Culture
- The CIS Security Operations Center (SOC): The Key to Growing Your SLTT's Cyber Maturity
- Guide to Implementation Groups (IG): CIS Critical Security Controls v8.1
- CIS Controls v8.1 Mapping to ISO/IEC 27001:2022
- CIS Controls v8.1 Mapping to SOC2
- CIS Controls v8.1 Mapping to NIST SP 800-171 Rev 3
- Reasonable Cybersecurity
- Episode 110: How Security Culture and Corporate Culture Mesh
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 145 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager begin their mid-year review of 12 Center for Internet Security® (CIS®) experts' cybersecurity predictions for 2025. Here are some highlights from our episode:
- 01:14. Verizon's Data Breach Investigations Report as a source of enlightenment and humility
- 02:28. The use of generative artificial intelligence (GenAI) to finely tune phishing emails
- 06:31. Cyber threat actors' Darwinian efficiency in adopting new technology
- 07:50. Policies, oversight, and compliance in slowing defenders' adoption of technology
- 10:30. The two-sided, dynamic challenge of managing supply chain risk
- 18:23. Cybersecurity as a strategic business investment in protecting revenue
- 20:40. The value of partnerships in determining rational social expectations for cybersecurity
- 26:45. Rapid recap of several of our 2025 cybersecurity predictions
- 28:43. Designing technology with human awareness to create a culture of responsibility
- 32:29. The need to rethink what "connected" means in our complex world
Resources
- 12 CIS Experts' Cybersecurity Predictions for 2025
- Episode 117: 2025 Cybersecurity Predictions from CIS Experts
- 2025 Data Breach Investigations Report
- 2024 DBIR Findings & How the CIS Critical Security Controls Can Help to Mitigate Risk to Your Organization
- Episode 119: Multidimensional Threat Defense at Large Events
- How to Construct a Sustainable GRC Program in 8 Steps
- Society of Information Risk Analysts
- Reasonable Cybersecurity
- Episode 135: Five Lightning Chats at RSAC Conference 2025
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 144 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager are joined by Carlos Kizzee, Senior Vice President of Multi-State Information Sharing and Analysis Center® (MS-ISAC®) at the Center for Internet Security®(CIS®). Together, they discuss how the MS-ISAC's new funding model helps to carry on the character and culture of this collaborative cyber defense community. Here are some highlights from our episode:
- 01:11. The unique mission, history, and value of building community at the MS-ISAC
- 05:36. A new fee-based model to preserve services and support amid federal funding changes
- 07:08. Service continuity as a commitment to U.S. State, Local, Tribal, and Territorial entities
- 09:45. Initial feedback and considerations heard at the 2025 ISAC Annual Meeting
- 11:40. The new membership funding model and how it preserves SLTT collaboration
- 15:25. A cost-effective approach to securing the "cyber-underserved"
- 19:31. The range of U.S. SLTT government organizations who can enroll as members now
- 21:59. The illusion of "free" in helping U.S. SLTTs to strengthen their cyber defenses
- 22:55. Why U.S. SLTTs need to enroll in paid MS-ISAC membership before October 1, 2025
- 28:03. Scale as the key to making MS-ISAC activities as cost-effective as possible
- 30:05. The essential need for U.S. SLTT government organizations to invest in the MS-ISAC
Resources
- Multi-State Information Sharing and Analysis Center®
- Episode 142: SLTTs and Their Nuanced Cybersecurity Needs
- Episode 137: National Cybersecurity Through SLTT Resilience
- ISAC Annual Meeting
- MS-ISAC Membership Resources
- Become an MS-ISAC Member
- Episode 30: Solving Cybersecurity at Scale with Nonprofits
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 143 of Cybersecurity Where You Are, Sean Atkinson is joined by John Cohen, Executive Director of the Program for Countering Hybrid Threats at the Center for Internet Security®(CIS®). Together, they discuss Iran's evolving multidimensional threat activity following U.S. airstrikes on Iranian nuclear facilities in June 2025. Here are some highlights from our episode:
- 00:49. Lessons from the past on how Iran might respond to the U.S. airstrikes in June 2025
- 04:56. The use of informed practice and continuous awareness to better prepare defenders
- 06:41. Recap of Iranian multidimensional threat activity observed between 2024 and 2025
- 11:53. The impact of contextual intelligence and education in driving threat awareness
- 19:17. Why understanding of impact is critical to addressing a business risk
- 23:09. Three things you need to do to be an effective threat briefer
- 25:07. The use of tabletop exercises (TTXs) to promote incident response
- 26:56. The 2024 General Election as a case study of what threat preparedness can do
Resources
- ThreatWA™
- US hits 3 Iranian nuclear sites, Trump says, plunging America into conflict
- Are national security threats a concern after U.S. military strike on Iranian nuclear sites?
- New report: Hacker for El Chapo helped boss hunt and kill FBI informants
- MS-ISAC Guide to DDoS Attacks
- With July 4 just days away, US law enforcement on high alert for Iran retaliation
- Iran-linked hackers threaten to release Trump aides' emails
- Iranian-aligned hackers claim responsibility for Truth Social cyberattack
- Iranian-Aligned Hackers Claim Responsibility for Attack on Trump’s Truth Social Platform
- States and Congress wrestle with cybersecurity after Iran attacks small town water utilities
- NYPD deploying additional resources across city following US strikes on Iran
- CIS Critical Security Controls v8.1 Industrial Control Systems (ICS) Guide
- Enhancing Safety in the Connected World — A National Framework for Action
- Episode 138: The Use of GenAI to Refine Your TTX Development
- Countering Multidimensional Threats: Lessons Learned from the 2024 Election
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 142 of Cybersecurity Where You Are, Sean Atkinson is joined by Anthony Essmaker, former Product Marketing Manager at the Center for Internet Security®(CIS®); and Randy Rose, VP of Security Operations & Intelligence at CIS. Together, they discuss the nuanced, empathetic approach that's required to help U.S. State, Local, Tribal, and Territorial (SLTT) government organizations to address their cybersecurity needs. Here are some highlights from our episode:
- 01.10. What the acronym "SLTT" means to CIS's operational mission
- 05:39. Using a flexible approach to support the different cybersecurity needs of the 50 states
- 09:43. How different resources and experiences contextualize "best practices" at the local level
- 11:49. Trivia question: Which two U.S. states don't have counties?
- 13:20. The complexity of cybersecurity challenges and resources for U.S. tribal entities
- 20:11. A 20-year history of working with U.S. SLTTs to meet them where they are
- 21:30. Relationships as the bedrock for a community model of SLTT cyber defense
- 26:29. Geographical isolation and other factors affecting U.S. territories' cybersecurity needs
- 32:42. A closing fun fact about the first U.S. fire district
Resources
- Episode 123: An Operational Playbook for Security Impact
- The CIS Security Operations Center (SOC): The Key to Growing Your SLTT's Cyber Maturity
- 2024 MS-ISAC Tribal Sector Cybersecurity Report
- Multi-State Information Sharing and Analysis Center®
- Nationwide Cybersecurity Review (NCSR)
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 141 of Cybersecurity Where You Are, Tony Sager is joined by Phyllis Lee, VP of SBP Content Development at the Center for Internet Security®(CIS®); and Julie Haney, Computer Scientist & Human-Centered Cybersecurity Researcher at the National Institute of Standards and Technology (NIST). Together, they use a human-centered understanding of security to discuss password policies, including their benefits, drawbacks, and efficacy. Here are some highlights from our episode:
- 01:03. Introductions to Phyllis and Julie
- 03:34. How "human-centered cybersecurity" goes beyond just usability
- 05:35. The use of NIST and other authoritative sources to dispel confusion in cybersecurity
- 09:09. How password policies positively and negatively impact human behavior
- 15:06. Three anecdotes that showcase the importance of context when enacting security policy
- 21:49. The process of using NIST SP 800-63 to recommend password security best practices
- 27:11. Our changing understanding of "the human element"
- 29:23. The need to do cybersecurity awareness training "right" and measure its effectiveness
- 31:30. Recognition of the absence of natural systems thinking in cybersecurity
- 33:14. Psychological safety, feedback, and trust as foundations of security culture
- 39:03. Human touchpoints as a starting point to help usability and security work together
Resources
- CIS Password Policy Guide
- NIST SP 800-63 Digital Identity Guidelines
- Episode 98: Transparency as a Tool to Combat Insider Threats
- Episode 110: How Security Culture and Corporate Culture Mesh
- Why Employee Cybersecurity Awareness Training Is Important
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 140 of Cybersecurity Where You Are, Sean Atkinson is joined by John Cohen, Executive Director of the Program for Countering Hybrid Threats at the Center for Internet Security®(CIS®). Together, they discuss travel safety tips informed by today's evolving multidimensional threat environment. Here are some highlights from our episode:
- 01:30. The most overlooked security risks we need to take seriously whenever we travel
- 03:42. How threat actors can exploit our tendency to overshare online
- 07:25. Top security practices you can use to safely plan your next trip
- 12:28. The value of playing out your travels' worst-case scenario before you leave
- 16:02. The benefits and drawbacks of using electronic navigations systems while traveling
- 18:00. Videos as a means of attuning to the "flow" of a different place and/or culture
- 24:10. Which types of people make attractive targets for foreign intelligence services
- 25:05. Honeypot operations in the physical and digital worlds
- 27:24. Opportunities to protect the technology on which we rely
Resources
- ThreatWA™
- Travel.State.Gov
- A Short Guide for Spotting Phishing Attempts
- 8 Security Essentials for Managing Your Online Presence
- Election Security Spotlight – Social Engineering
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 139 of Cybersecurity Where You Are, Tony Sager is joined by Amelia Gifford, Sr. Manager, Administration, at the Center for Internet Security®(CIS®); and George Bailey, Director of Purdue cyberTAP. Together, they discuss how the 2025 grant from the Alan Paller Laureate Program will support Purdue cyberTAP's mission of community building for the cyber-underserved. Here are some highlights from our episode:
- 01:02. Honoring a legacy of making cybersecurity practical and accessible
- 03:34. The business of giving products away to benefit the cybersecurity community
- 05:00. The use of the CIS Critical Security Controls (CIS Controls) to help rural electricity cooperatives in Indiana
- 11:00. Methodology, tooling, and repeatability as part of a lifecycle of realizing a good idea
- 11:56. Cross-Mapping as a means to help people live with so many security frameworks
- 12:59. Accountability and re-assessment as methods for measuring program success
- 14:59. The power of community in prioritizing the CIS Controls
- 16:38. Community building as a way to navigate the cybersecurity business together
- 17:42. A controlled Controls experiment to generate data, learn lessons, and create feedback
- 19:03. Progress reporting as a way to foster connections
- 24:39. Feedback on the Alan Paller Laureate Program application process
- 26:30. Focus on cybersecurity community impact as a consideration for future applicants
- 30:31. Parting thoughts about the grant program and an invitation to reach out to George
Resources
- Center for Internet Security Awards Nearly $250,000 to Purdue University’s Technical Assistance Program
- Episode 114: 3 Board Chairs Reflect on 25 Years of Community
- Episode 97: How Far We've Come preceding CIS's 25th Birthday
- CIS Critical Security Controls v8.1 Industrial Control Systems (ICS) Guide
- SEC366: CIS Implementation Group 1™
- How to Plan a Cybersecurity Roadmap in 4 Steps
- CIS SecureSuite® Membership
- Mapping and Compliance with the CIS Controls
- Reasonable Cybersecurity Guide
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 138 of Cybersecurity Where You Are, Sean Atkinson is joined by Timothy Davis, Lead Cyber Threat Intelligence (CTI) Analyst at the Center for Internet Security®(CIS®). Together, they discuss how organizations can use Generative Artificial Intelligence (GenAI) to refine how they develop Tabletop Exercises (TTXs). Here are some highlights from our episode:
- 01:49. Why TTXs function as a "blue sky" opportunity for crisis management and preparedness
- 04:33. A quick recap of how GenAI stands apart from traditional AI
- 06:19. The direct relationship between input and output when measuring GenAI content quality
- 07:36. TTXs as a use case for GenAI to help the "cyber-underserved"
- 10:14. How GenAI can quickly customize TTXs for different organizations and threat models
- 13:56. The use of GenAI to improve TTX facilitation, regularity, and cost
- 17:22. GenAI as an inspiration to act on the findings of a simulation
- 18:26. Risks and ethical concerns to keep in mind for GenAI-enhanced TTX development
- 24:46. Where humans can still play a part in augmented exercises
- 30:08. Closing thoughts about the future of GenAI
Resources
- Leveraging Generative Artificial Intelligence for Tabletop Exercise Development
- Episode 134: How GenAI Lowers Bar for Cyber Threat Actors
- Episode 89: How Threat Actors Are Using GenAI as an Enabler
- DeepSeek: A New Player in the Global AI Race
- Multi-State Information Sharing and Analysis Center®
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 137 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager are joined by Terry Loftus, Assistant Superintendent (Chief Information Officer) of Integrated Technology Services at the San Diego County Office of Education (SDCOE); and Netta Squires, President of Government Affairs, Cybersecurity, & Resilience at Open District Solutions (ODS). Together, they discuss how the Multi-State Information Sharing and Analysis Center® (MS-ISAC®) functions as a space for U.S. State, Local, Tribal, and Territorial (SLTT) entities to collectively strengthen their cyber resilience in support of U.S. national cybersecurity. Here are some highlights from our episode:
- 01:15. A study to understand the cybersecurity perspectives of the MS-ISAC community
- 03:24. The need for sustained cyber defense accelerators to drive U.S. SLTT resilience
- 07:31. How surveys and focus groups uncovered U.S. SLTT cybersecurity funding, staffing, and governance challenges
- 13:06. The superpower of cyber threat intelligence driven, tailored, and provided via community
- 17:41. Trust as a foundation for building relationships among MS-ISAC members and partners
- 21:26. How the MS-ISAC moved community cyber defense from conversational to operational
- 22:22. The role of trust in making membership affordable and solutions at scale possible
- 25:00. Opportunities for relationship building, training, and access to services in the MS-ISAC
- 30:00. Examples of MS-ISAC success stories and the need to share them
- 33:40. The MS-ISAC as a space to craft a strategic path for national cybersecurity
- 36:29. Closing thoughts on how members value and can get involved in the MS-ISAC
Resources
- Strengthening Critical Infrastructure: SLTT Progress & Priorities
- Malicious Domain Blocking and Reporting (MDBR)
- Episode 126: A Day in the Life of a CTI Analyst
- Why Whole-of-State Cybersecurity Is the Way Forward
- MS-ISAC: Defending America’s Critical Infrastructure
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 136 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager are joined live by Lynn Dohm, Executive Director of Women in CyberSecurity (WiCyS). Together, they discuss how WiCyS works to advance women in cybersecurity. Here are some highlights from our episode:
- 01:03. A mission of recruiting, retaining, and advancing women in cybersecurity
- 05:38. How community-focused conferences and scholarships promote community growth
- 06:25. The need to celebrate the work of and encourage support among cyber defenders
- 08:52. Four strategic pillars as a foundation for navigating COVID, societal change, and more
- 13:50. The importance of laying out cybersecurity career paths outside of individual companies
- 15:15. How a foundation of inclusion enables diversity to expand
- 19:45. The use of strategic partners to anticipate changing cybersecurity and hiring needs
- 22:38. Inside the successes of the mentorships and other WiCyS programs
- 28:22. The impact of Alan Paller on opening doors for WiCyS
- 32:35. How volunteerism supports retention in cybersecurity through inclusion and satisfaction
Resources
- Episode 77: Data's Value to Decision-Making in Cybersecurity
- Episode 120: How Contextual Awareness Drives AI Governance
- Alan Paller Laureate Program
- Episode 30: Solving Cybersecurity at Scale with Nonprofits
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 135 of Cybersecurity Where You Are, Sean Atkinson is joined live at RSAC Conference 2025 by five attendees, including two Center for Internet Security® (CIS®) employees. He conducts a lightning chat with each attendee to get their thoughts about the conference, how it reflects the changing cybersecurity industry, and the role CIS plays in this ongoing evolution. Here are some highlights from our episode:
00:40. Stephanie Gass, Sr. Director of Information Security at CIS
- How to start creating a policy and make it effective through implementation processes
- A transition to an approach integrating mappings for CIS security best practices
- The use of GenAI and security champions to make this transition
04:08. Brad Bock, Director of Product Management at Chainguard
- Building and compiling security from the ground up in open-source container images
- Trusting pre-packaged software in an increasingly complex world
- Support of customer compliance with attestation, SBOMs, and vulnerability remediation
07:43. Stephane Auger, Vice President Technologies and CISO at Équipe Microfix
- Customer awareness and other top challenges for MSPs and MSSPs
- The use of case studies and referrals to communicate the importance of cybersecurity
- A growing emphasis on cyber risk insurance as media attention around breaches grows
11:36. Brent Holt, Director of Cybersecurity Technology at Edge Solutions LLC
- How the CIS Critical Security Controls facilitates a consultative approach to customers
- The importance of knowing where each company is in their use of GenAI
- Mapping elements of a portfolio to CIS security best practices
17:23. Mishal Makshood, Sr. Cloud Security Account Executive at CIS
- The use of learning and research to investigate GenAI's utility for CIS
- An aspiration to scale efficiency and drive improvements with GenAI training
- A reminder to augment human thought, not replace it, with GenAI
Resources
- Episode 63: Building Capability and Integration with SBOMs
- Mapping and Compliance
- Cybersecurity for MSPs, MSSPs, & Consultants
- Episode 130: The Story and Future of CIS Thought Leadership
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 134 of Cybersecurity Where You Are, Sean Atkinson is joined by Randy Rose, VP of Security Operations & Intelligence at the Center for Internet Security® (CIS®); and Timothy Davis, Lead Cyber Threat Intelligence (CTI) Analyst at CIS. Together, they discuss how generative artificial intelligence (GenAI) lowers the barrier of entry for cyber threat actors (CTAs). Here are some highlights from our episode:
- 01:37. CTAs' use of GenAI to improve their existing campaigns
- 03:38. The need for CTI teams to look beyond language in analyzing GenAI-enabled threats
- 07:22. The evolving impact of GenAI on phishing campaigns, malware development, deepfakes, and malicious Artificial Intelligence as a Service (AIaaS) offerings
- 12:28. How GenAI increases the the speed at which CTAs can scale their efforts
- 17:29. Technical barriers and other limitations that shape CTAs' use of GenAI
- 22:46. A historical perspective of AI-enabled cybersecurity and how GenAI can support cybersecurity awareness training
- 26:50. The cybersecurity benefits of AI and machine learning (ML) capabilities for clustering data
- 29:05. What the future might hold for GenAI from an offensive and defensive perspective
Resources
- The Evolving Role of Generative Artificial Intelligence in the Cyber Threat Landscape
- Episode 89: How Threat Actors Are Using GenAI as an Enabler
- Episode 95: AI Augmentation and Its Impact on Cyber Defense
- 12 CIS Experts' Cybersecurity Predictions for 2025
- CIS Critical Security Controls®
- Multi-State Information Sharing and Analysis Center®
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 133 of Cybersecurity Where You Are, Sean Atkinson is joined by Lauren McFayden, Threat Intelligence Analyst at the Center for Internet Security® (CIS®). Together, they discuss the Distributed Denial of Service (DDoS) hacktivism of DieNet and how the group continues to evolve its Tactics, Techniques, and Procedures (TTPs). Here are some highlights from our episode:
- 01:22. An overview of DieNet and its emergence on Telegram
- 01:55. DDoS attacks and the potential for service disruptions
- 02:55. DieNet's pro-Palestinian ideology and opposition to the 47th U.S. Presidential Administration
- 05:00. U.S. and foreign targets claimed by the group
- 06:30. DieNet's history of claiming attacks against U.S. critical national infrastructure (CNI)
- 10:33. Two pieces of evidence used to partially assess the credibility of a claimed attack
- 15:16. How DieNet v2 suggests an escalation of attack strategies
- 20:43. How the DDoS hacktivist group may continue to evolve its TTPs in subsequent versions
- 23:48. The use of the CIS Critical Security Controls (CIS Controls) to reduce an attack surface
- 25:56. How ThreatWA stands out in keeping you informed about emerging threats
Resources
- Hacktivist Group DieNet Claims DDoS Attacks against U.S. CNI
- MS-ISAC Guide to DDoS Attacks
- ThreatWA
- CIS Critical Security Control 1: Inventory and Control of Enterprise Assets
- CIS Critical Security Control 2: Inventory and Control of Software Assets
- CIS Critical Security Control 3: Data Protection
- Episode 44: A Zero Trust Framework Knows No End
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 132 of Cybersecurity Where You Are, Sean Atkinson is joined by Valecia Stocchetti, Sr. Cybersecurity Engineer of the CIS Critical Security Controls (CIS Controls) at the Center for Internet Security® (CIS®). Together, they discuss what the first day, step, and dollar of implementing a controls framework look like for organizations stepping into their cybersecurity journey. Here are some highlights from our episode:
- 01:54. Building and improving a cybersecurity program through the power of consensus
- 04:55. The use of an assessment to determine where you are and where you're going
- 09:15. How cross-mapping to multiple frameworks simplifies regulatory compliance efforts
- 12:00. The use of governance to secure leadership buy-in for your cybersecurity program
- 13:33. Continuous auditing and monitoring as tools for adapting to change
- 15:10. How Controls prioritization flows through the Implementation Groups (IGs)
- 19:39. Leadership as the backbone for getting any business program off the ground
- 22:59. Calculating the cost of cyber defense as a preventative action
- 24:55. Tradeoffs with security tools to keep in mind so that you can budget efficiently
- 30:00. Qualifications when using security offerings of MSPs and CSPs
Resources
- CIS Community Defense Model 2.0
- How Risk Quantification Tests Your Reasonable Cyber Defense
- CIS Controls Self Assessment Tool (CIS CSAT)
- Guide to Implementation Groups (IG): CIS Critical Security Controls v8.1
- How to Plan a Cybersecurity Roadmap in 4 Steps
- The Cost of Cyber Defense: CIS Controls IG1
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 131 of Cybersecurity Where You Are, Tony Sager is joined by Stan Stahl, PhD, Founder and President of SecureTheVillage. Together, they discuss how SecureTheVillage, a nonprofit and inaugural Alan Paller Laureate Program awardee, is using a collaboration-driven approach to enhance reasonable cybersecurity awareness and practices within Southern California (SoCal). Here are some highlights from our episode:
- 01:07. An introduction to Stan and how he came to champion small business cybersecurity
- 04:28. How SecureTheVillage emerged to support small businesses' cybersecurity needs using the power of community
- 07:15. The need for nonprofits to play a strong role in addressing cybersecurity challenges
- 12:01. How Stan drew inspiration from Alan Paller and support from the Alan Paller Laureate Program to advance SecureTheVillage's work
- 17:57. Reasonable cybersecurity as part of SecureTheVillage's foundation story
- 22.13. Aligning cybersecurity needs to the goals of public policy
- 25:33. What's next for SecureTheVillage
- 29:52. Closing thoughts on why a "village" model for cybersecurity is so important
Resources
- Alan Paller Laureate Program
- Implementation Guide for Small- and Medium-Sized Enterprises CIS Controls IG1
- Episode 30: Solving Cybersecurity at Scale with Nonprofits
- Reasonable Cybersecurity Guide
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 130 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager are joined by John Gilligan, President and Chief Executive Officer (CEO) of the Center for Internet Security® (CIS®). Set against the backdrop of the 2025 CIS Annual Full Staff Meeting, they celebrate 25 years of CIS, including the "serendipity" by which the company became a global cybersecurity thought leader. They also discuss how this thought leadership may evolve over the next 25 years. Here are some highlights from our episode:
- 01:30. How CIS started along with how John and Tony initially got involved
- 07:12. How CIS thought leadership changed with the absorption of the "SANS Top 20," the precursor of the CIS Critical Security Controls
- 11:04. The "serendipity" through which CIS grew and formalized its sales, funding, support, and other operations in the 2010s
- 15:18. How mission and culture advanced CIS to its 25th anniversary in 2025
- 22:52. What the future might hold for "CIS 2.0"
Resources
- 25 Years of Creating Confidence in the Connected World
- Episode 97: How Far We've Come preceding CIS's 25th Birthday
- Episode 114: 3 Board Chairs Reflect on 25 Years of Community
- Episode 76: The Role of Thought Leadership in Cybersecurity
- Episode 125: How Leadership Principles Influence CIS Culture
- Episode 120: How Contextual Awareness Drives AI Governance
- Episode 119: Multidimensional Threat Defense at Large Events
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 129 of Cybersecurity Where You Are, Sean Atkinson discusses best practices for embedding cybersecurity in project management. Here are some highlights from our episode:
- 01:34. Elements for connecting the dots between cybersecurity risk assessment and project risk assessment
- 03:06. How our conceptualization of a project changes under a zero trust implementation
- 04:02. What security may look like in a Waterfall vs. Agile approach to project management
- 06:26. The importance of resources and stakeholders in managing any project
- 08:34. Scope creep and other challenges of embedding cybersecurity in project management
- 15:45. How continuous monitoring and other best practices can help us to overcome these hurdles
- 25:30. How cybersecurity can inform projects involving generative artificial intelligence
Resources
- Episode 105: Context in Cyber Risk Quantification
- Quantitative Risk Analysis: Its Importance and Implications
- How Risk Quantification Tests Your Reasonable Cyber Defense
- Episode 44: A Zero Trust Framework Knows No End
- How to Construct a Sustainable GRC Program in 8 Steps
- Episode 33: The Shift-Left of IoT Security to Vendors
- Episode 120: How Contextual Awareness Drives AI Governance
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 128 of Cybersecurity Where You Are, Sean Atkinson is joined by Joshua Palsgraf, Senior Cyber Threat Intelligence (CTI) Analyst at the Center for Internet Security® (CIS®). Together, they examine how cyber threat actors use cryptocurrency for financial fraud and how professionals like Joshua track this illicit activity. Here are some highlights from our episode:
- 01:35. What a data-driven approach to CTI looks like
- 02:47. What makes cryptocurrency useful in the digital economy, including for financial fraud
- 06:50. How cryptocurrency-related financial crime compares to traditional forms of fraud
- 13:20. Examples of cryptocurrency theft and its use in facilitating ransomware attacks
- 27:24. Tooling and forensic methods that are being used to track crypto fraud/scams
- 31:40. The need to build awareness around financial crime in the digital economy
Resources
- Episode 77: Data's Value to Decision-Making in Cybersecurity
- 2023 Cryptocurrency Fraud Report Released
- 2025 Crypto Crime Trends: Illicit Volumes Portend Record Year as On-Chain Crime Becomes Increasingly Diverse and Professionalized
- Suspected Lazarus subgroup behind DMM crypto heist
- Episode 126: A Day in the Life of a CTI Analyst
- Combatting Ransomware
- Episode 124: The Many Layers of a Malware Takedown Operation
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 127 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager are joined by Scott Alldridge, President and CEO of IP Services and the IT Process Institute. Together, they use Scott's book, "Visible Ops Cybersecurity: Enhancing Your Cybersecurity Posture with Practical Guidance," to discuss how visible IT operations (Visible Ops) provide a foundation for cybersecurity. Here are some highlights from our episode:
- 01:31. How Visible Ops reflect an appreciation for the original config change release processes
- 10:19. The limitations of treating security as a silo and "new toys" as security cure-alls
- 15:23. How to embrace a dynamic view of visibility and configuration management
- 24:50. The importance of leadership buy-in when shifting left to a security-first mindset
- 27:10. What an effective change configuration management system looks like and how it changes people's view of IT
- 30:20. Parting thoughts and where to find more of Scott's work
Resources
- IT Process Institute
- What is ITIL? Your guide to the IT Infrastructure Library
- CIS Critical Security Controls (CIS Controls) Resources
- An Examination of How Cyber Threat Actors Can Leverage Generative AI Platforms
- Episode 44: A Zero Trust Framework Knows No End
- Why Employee Cybersecurity Awareness Training Is Important
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 126 of Cybersecurity Where You Are, Sean Atkinson is joined by Casey Cannon, Lead Cyber Threat Intelligence (CTI) Analyst at the Center for Internet Security® (CIS®). Together, they review what a regular day looks like for a CTI analyst. Here are some highlights from our episode:
- 01:46. How a service-oriented mindset factors into a CTI career
- 03:55. What task prioritization looks like at the beginning of a CTI analyst's day
- 06:50. How bedrock CTI principles and threat actor matrices help to counter information overload and filter out noise
- 10:45. The value of an "eclectic" set of intelligence sources
- 25:50. How the CIS CTI team works with the 24x7x365 CIS Security Operations Center (SOC), the Cyber Incident Response Team (CIRT), and others
- 31:27. Advice for getting into CTI as a career path
Resources
- Episode 124: The Many Layers of a Malware Takedown Operation
- Episode 62: Inside the 'Spidey Sense' of a Pentester
- Combatting Ransomware
- The CIS Security Operations Center (SOC): The Key to Growing Your SLTT's Cyber Maturity
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 125 of Cybersecurity Where You Are, Sean Atkinson is joined by Waldo Perez, Human Resources Support Specialist at the Center for Internet Security® (CIS®); and Penny Davis, Sr. Manager of Leadership Development at CIS. Together, they use the CIS Leadership Principles and other examples from CIS to understand how leadership influences and nurtures the organization's workplace culture.
Here are some highlights from our episode:
- 02:00. The human aspect in defining workplace culture
- 03:55. How leadership principles directly shape company culture
- 05:40. Key indicators of a strong company culture and one that can improve
- 16:31. Examples where company culture has made an impact on a CIS employee's experience
- 21:59. The importance of feedback in supporting positive cultural change
- 25:41. How leadership training programs help employees to grow
Resources
- CIS Culture
- Episode 115: Continuous Feedback as CIS Employee Culture
- The Envelope, Please! The CIS 2024 President’s Award Goes to…
- Center for Internet Security Named Among 2024 Top Workplaces
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 124 of Cybersecurity Where You Are, Sean Atkinson is joined by Timothy Davis, Lead Cyber Threat Intelligence (CTI) Analyst at the Center for Internet Security® (CIS®). Together, they explore the many layers of a malware takedown operation.
Here are some highlights from our episode:
- 01:58. A high-level overview of what a malware takedown might involve
- 04:11. Some of the key players who help to disrupt known malware infrastructure
- 07:35. Which operational functionalities make malware infrastructure and tactics difficult to dismantle
- 10:56. Jurisdictional and legal challenges of a takedown operation
- 14:53. What goes into identifying malware networks and infected end-user devices
- 20:47. The technical strategies used for disrupting malware
- 24:13. How cyber threat actors respond differently to a takedown effort
Resources
- Phobos Ransomware Affiliates Arrested in Coordinated International Disruption
- Qakbot Malware Disrupted in International Cyber Takedown
- Episode 89: How Threat Actors Are Using GenAI as an Enabler
- Renew Your Ransomware Defense with CISA's Updated Guidance
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 123 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager are joined by Gina Chapman, Chief Operating Officer (COO) at the Center for Internet Security® (CIS®). Together, they use examples from CIS to identify elements of an operational playbook for making an impact in the cybersecurity industry.
Here are some highlights from our episode:
- 01:21. Business development and organizational change over the course of 12 years at CIS
- 13:49. Change management and communication as means for preserving company culture
- 23:08. The importance of context in developing an operational playbook for a business
- 32:49. The use of operational understanding to create effective cybersecurity business models
Resources
- Gina Chapman
- CIS Culture
- CIS Leadership Principles
- Episode 82: How CIS Leadership Values Team Building Events
- Cybersecurity at Scale: Piercing the Fog of More
- Combatting Ransomware
- Episode 68: Designing Cyber Defense as a Partnership Effort
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 122 of Cybersecurity Where You Are, Sean Atkinson is joined by Rian Davis, Associate Hybrid Threat Intelligence Analyst at the Center for Internet Security® (CIS®); and Timothy Davis, Lead Cyber Threat Intelligence (CTI) Analyst at CIS. Together, they discuss security and utility considerations surrounding the DeepSeek AI model.
Here are some highlights from our episode:
- 01:31. What enterprises and individuals can do before they start deploying foreign-developed, open-source large language models (LLMs)
- 08:48. How DeepSeek fits into evolving adversarial tactics and techniques involving AI
- 25:15. The impact on threat assessments and where we see controls built around AI
- 31:45. Parting thoughts on approaching newer technologies like DeepSeek
Resources
- DeepSeek hit by cyberattack as users flock to Chinese AI startup
- A 9th telecoms firm has been hit by a massive Chinese espionage campaign, the White House says
- TikTok: Influence Ops, Data Practices Threaten U.S. Security
- Wiz Research Uncovers Exposed DeepSeek Database Leaking Sensitive Information, Including Chat History
- Episode 89: How Threat Actors Are Using GenAI as an Enabler
- ODNI Releases 2024 Annual Threat Assessment of the U.S. Intelligence Community
- The Strava Heat Map and the End of Secrets
- Man who exploded Cybertruck in Las Vegas used ChatGPT in planning, police say
- Episode 120: How Contextual Awareness Drives AI Governance
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 121 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager are joined by Tyler Moore, Ph.D., Chair of Cyber Studies at the University of Tulsa. Together, they discuss the role of economics in cyber risk quantification and cybersecurity decision-making.
Here are some highlights from our episode:
- 01:55. How incentives, market failures, and other economic principles intersect with cybersecurity
- 08:39. A model of translating shared information as a way to capture complexity in cybersecurity decision-making
- 13:20. Pressing issues when making decisions about cybersecurity
- 18:08. How to have enough confidence and a cyber risk quantification model that's useful
- 23:45. How rigorous recommendations can help to match modeling and techniques like minimization
- 29:23. The role of the Board in making cybersecurity decisions and how to speak its language
- 34:57. Parting thoughts about risk quantification in cybersecurity
Resources
- Episode 105: Context in Cyber Risk Quantification
- 2024 DBIR Findings & How the CIS Critical Security Controls Can Help to Mitigate Risk to Your Organization
- CIS Community Defense Model 2.0
- FAIR: A Framework for Revolutionizing Your Risk Analysis
- Society of Information Risk Analysts
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 120 of Cybersecurity Where You Are, Sean Atkinson explores how contextual awareness of generative artificial intelligence (GenAI) deployment in the business creates a foundation for AI governance strategy.
Here are some highlights from our episode:
- 01:58. Why specificity is important when we use the term "AI" in the governance space
- 04:10. Two AI distributions and how contextual function varies between them
- 13:52. The importance of engagement and asking the right questions
- 18:28. The role of lifecycle approaches and risk tolerance in understanding AI integration
- 23:45. Navigating two common questions that arise when governing AI
Resources
- Episode 116: AI-Enhanced Ransomware and Defending Against It
- EU AI Act: first regulation on artificial intelligence
- AI Risk Management Framework
- IAPP AI Governance Center
- How to Construct a Sustainable GRC Program in 8 Steps
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 119 of Cybersecurity Where You Are, Sean Atkinson is joined by John Cohen, Executive Director of Countering Hybrid Threats at the Center for Internet Security® (CIS®). Together, they discuss the importance and provide examples of multidimensional threat defense as a means of securing large events.
Here are some highlights from our episode:
- 01:42. An overview of the multidimensional threat landscape from 2024 going into 2025
- 07:00. The shift to multidimensional threat analysis in crisis management
- 10:52. The importance of a sustainable, actionable approach to addressing today's threats
- 16:10. How CIS is working to help organizations build safety against multidimensional threats, including at large events
Resources
- 2024 Election Threat Landscape
- Election Security Spotlight — Prep for Election Disruptions
- Episode 93: Building Public Resilience in a Connected World
- ThreatWA™
- Countering Multidimensional Threats: Lessons Learned from the 2024 Election
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 118 of Cybersecurity Where You Are, Sean Atkinson is joined by Andy Smith, Security Architect for BP and Instructor at the SANS Institute. Together, they review the state of post-quantum cryptography as well as share recommendations for how organizations and individuals can prepare to move into the post-quantum era.
Here are some highlights from our episode:
- 02:55. What post-quantum cryptography is and why we need to pay attention
- 04:11. The impact of a cryptographically relevant quantum computer on symmetric vs. asymmetric cryptography
- 08:58. How media attention contributes to preparedness from an infrastructure perspective
- 14:30. The importance of a cryptography bill of materials (CBOM)
- 21:58. How organizations can prepare against quantum-enabled cyber attacks
- 29:05. How individuals need to understand quantum infrastructure in order to protect it
- 32:24. Optimism for the future of post-quantum cryptography
Resources
- Episode 48: 3 Trends to Watch in the Cybersecurity Industry
- Post Quantum Cryptography by Attack Detect Defend (rot169)
- NIST Releases First 3 Finalized Post-Quantum Encryption Standards
- Episode 75: How GenAI Continues to Reshape Cybersecurity
- Internet of Things: Embedded Security Guidance
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 117 of Cybersecurity Where You Are, Sean Atkinson reflects on the 2025 cybersecurity predictions of 12 experts at the Center for Internet Security® (CIS®), as shared on the CIS website.
Here are some highlights from our episode:
- 01:40. Artificial intelligence (AI) as a means for crafting higher quality phishing emails
- 04:24. Zero trust with identity as a catalyst in 2025
- 07:55. A governance focus for K-12 school districts
- 12:37. Secure by design as part of the DNA of IT departments
- 14:22. The need for continuous patching with Internet of Things (IoT) devices
- 15:27. Training and adherence to basic cybersecurity practices as ongoing emphases
- 17:15. Consolidation from an operations perspective
- 20:40. The integration of AI into business operations
- 24:07. The socio-political impacts of emerging technologies on multidimensional threats
- 26:46. Growing attention on cloud security and data location
- 29:13. Cybercriminal markets and Phishing as a Service models
- 32:16. The benefit of AI to organizations
Resources
- Episode 75: How GenAI Continues to Reshape Cybersecurity
- An Examination of How Cyber Threat Actors Can Leverage Generative AI Platforms
- How to Deter Multidimensional Threats in the Connected World
- Episode 116: AI-Enhanced Ransomware and Defending Against It
- Episode 44: A Zero Trust Framework Knows No End
- Episode 107: Continuous Improvement via Secure by Design
- Episode 76: The Role of Thought Leadership in Cybersecurity
- Episode 63: Building Capability and Integration with SBOMs
- Episode 95: AI Augmentation and Its Impact on Cyber Defense
- Why Employee Cybersecurity Awareness Training Is Important
- Episode 110: How Security Culture and Corporate Culture Mesh
- Episode 99: How Cyber-Informed Engineering Builds Resilience
- Episode 87: Marking 11 Years as a Verizon DBIR Contributor
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 116 of Cybersecurity Where You Are, Sean Atkinson discusses the threat of AI-enhanced ransomware along with the use of generative artificial intelligence (GenAI) to defend against it.
Here are some highlights from our episode:
- 02:10. How AI in the cybersecurity space has advanced over the past few years
- 05:12. Why cybercriminals are incorporating artificial intelligence into their attacks
- 19:24. The application of AI in various stages of a ransomware attack
- 26:10. How AI can inform different aspects of a ransomware defense strategy
Resources
- Episode 89: How Threat Actors Are Using GenAI as an Enabler
- Episode 95: AI Augmentation and Its Impact on Cyber Defense
- Episode 44: A Zero Trust Framework Knows No End
- The State of Ransomware 2024
- Ransomware: The Data Exfiltration and Double Extortion Trends
- Episode 113: Cyber Risk Prioritization as Ransomware Defense
- Security Chaos Engineering: Sustaining Resilience in Software and Systems
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 115 of Cybersecurity Where You Are, Sean Atkinson is joined by Carolyn Comer, Chief Human Resources Officer at the Center for Internet Security® (CIS®); Heidi Gonzalez, Sr. Employee Experience Specialist at CIS; and Jennifer Myers, Sr. Director of Learning and Development at CIS. With an in-person holiday open house and office party as their backdrop, they celebrate the continuous feedback that sustains and grows the employee culture at CIS.
Here are some highlights from our episode:
- 02:35. How the holiday open house and office party celebrate CIS employee culture
- 04:11. How the workforce culture at CIS has changed over time
- 07:57. What types of employee feedback CIS obtains after in-person events
- 09:33. How in-person interactions guide a continuous learning program for CIS employees
- 10:55. How events such as the holiday open house and office party continue to evolve
- 16:48. Why CIS has been so successful in helping employees to navigate remote work
- 20:04. The impact of an engaged Board of Directors on workplace culture
- 21:40. Celebrations and upcoming plans for culture and learning at CIS
Resources
- Episode 83: Why Meeting in Person Matters to CIS Employees
- Episode 58: Inside CIS's Award-Winning Workplace Culture
- Center for Internet Security Named Among 2024 Best Companies to Work for in New York
- Center for Internet Security Named Among 2024 Top Workplaces
- IDEA Alliance
- CIS Cares
- Episode 114: 3 Board Chairs Reflect on 25 Years of Community
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 114 of Cybersecurity Where You Are, Tony Sager is joined by three past and current Board Chairs of the Center for Internet Security® (CIS®): Frank Reeder, CIS Director Emeritus and Founding Chair as well as Director of the National Cybersecurity Scholarship Foundation; John Gilligan, President and Chief Executive Officer of CIS; and Bobbie Stempfley, CIS Board Chair and Business Security Officer of the Infrastructure Solutions Group at Dell Technologies. Together, they reflect on 25 years of CIS building community in the cybersecurity space.
Here are some highlights from our episode:
- 07:04. Perception of the problem that led to the idea of CIS
- 10:18. The value of building community outside of government
- 17:31. A sustainable and powerful business model for CIS
- 21:28. John's priorities during his transition from Board Chair to CEO
- 34:38. What CIS will focus on next
- 39:00. Parting thoughts for the future
Resources
- Episode 35: Remembering the Late Alan Paller
- Episode 97: How Far We've Come preceding CIS's 25th Birthday
- Episode 79: Advancing Common Good in Cybersecurity – Part 1
- Episode 76: The Role of Thought Leadership in Cybersecurity
- Episode 58: Inside CIS's Award-Winning Workplace Culture
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 113 of Cybersecurity Where You Are, Tony Sager is joined by Phyllis Lee, VP of SBP Content Development at the Center for Internet Security® (CIS®); Adam Bobrow, Co-Founder and President of Veribo Analytics; and Sridevi Joshi, Co-Founder and CEO of Veribo Analytics. Together, they discuss how the Business Impact Analysis tool created by CIS and Veribo Analytics empowers individuals and organizations to use cyber risk prioritization as a basis for their ransomware defense strategy.
Here are some highlights from our episode:
- 04:35. Background on the impetus for the tool's development
- 07:57. How our understanding of cybersecurity risk differs from other areas of risk
- 12:21. Insight into Sridevi's learning process about cyber risk prioritization as a technologist
- 18:23. How the development process of the Business Impact Analysis tool got underway
- 21:05. What went into the process of translating the goal into tooling
- 31:34. Reflections on the tool's reception and what's next
Resources
- CIS Critical Security Controls Implementation Groups
- CIS Community Defense Model 2.0
- CIS Controls Self Assessment Tool (CIS CSAT)
- SEC Adopts Rules on Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure by Public Companies
- 4.3 Establish a Bureau of Cyber Statistics
- FAIR: A Framework for Revolutionizing Your Risk Analysis
- Reasonable Cybersecurity
- How to Measure Anything in Cybersecurity
- Episode 107: Continuous Improvement via Secure by Design
- Episode 105: Context in Cyber Risk Quantification
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 112 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager are joined by Rob T. Lee, Chief of Research and Head of Faculty at SANS Institute. Together, they discuss how SANS Institute applies an operational or "do" model of leadership to gather expertise, build shared purpose, and foster action on evolving cybersecurity trends.
Here are some highlights from our episode:
- 05:47. How Rob ended up teaching at SANS Institute
- 08:49. Rob's first experience meeting and working with the late Alan Paller
- 12:07. How Rob's responsibility at SANS Institute has expanded
- 20:02. Key cybersecurity trends on Rob's agenda as Chief of Research
- 23:52. The need to refine our understanding of AI based on its different applications
- 36:28. Guidance for the 47th U.S. Presidential Administration
Resources
- Episode 35: Remembering the Late Alan Paller
- The Cyber Security Hall of Fame Announces 2024 Honorees
- Episode 76: The Role of Thought Leadership in Cybersecurity
- Episode 75: How GenAI Continues to Reshape Cybersecurity
- CrowdStrike Falcon Outage Exploited for Social Engineering
- Why Whole-of-State Cybersecurity Is the Way Forward
- From Both Sides: A Parental Guide to Protecting Your Child's Online Activity
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 111 of Cybersecurity Where You Are, Tony Sager is joined by Rick Howard, N2K Chief Security Officer and the Chief Analyst and Senior Fellow at The Cyberwire. Together, they discuss a first principle of cybersecurity proposed by Rick in his book, Cybersecurity First Principles: A Reboot of Strategy and Tactics.
Here are some highlights from our episode:
- 04:30. What drove the need to formulate a foundational cybersecurity assumption
- 07:44. How other "first" principles of cybersecurity have failed
- 14:13. The three elements of Rick's first principle of cybersecurity
- 25:55. How to derive action and improvements from Rick's first principle
- 40:34. Tips on getting started with a risk forecasting strategy
Resources
- Episode 105: Context in Cyber Risk Quantification
- FAIR: A Framework for Revolutionizing Your Risk Analysis
- Election Security Spotlight – CIA Triad
- Episode 44: A Zero Trust Framework Knows No End
- Executive Order on Improving the Nation’s Cybersecurity
- Cybersecurity Canon
- Superforecasting: The Art and Science of Prediction
- How to Measure Anything in Cybersecurity Risk
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 110 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager are joined by Lee Noriega, Executive Director of the Cybersecurity Services Organization and Acting General Manager of Sales and Business Services at the Center for Internet Security® (CIS®); and Jerry Gitchel, founder of Leverage Unlimited and listener to Cybersecurity Where You Are. Together, they examine a question sent in by Jerry: if a corporate culture is lacking, can a security culture exist?
Here are some highlights from our episode:
- 01:33. What security culture is and how it differs from corporate culture
- 05:30. What elements factor into a strategy to drive corporate culture
- 09:30. The importance of a feedback loop for culture
- 15:43. How to cultivate "institutional ownership" in an organization's workforce
- 19:03. What goes into fostering security consciousness in support of security champions
- 25:14. The challenges of engaging corporate culture to think about security culture
- 29:13. Examples and takeaways for listeners
Resources
- Why Employee Cybersecurity Awareness Training Is Important
- Episode 107: Continuous Improvement via Secure by Design
- Seth Godin | Why People Like Us Do This
- The Cuckoo's Egg: Tracking a Spy Through the Maze of Computer Espionage
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 109 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager are joined by Randy Rose, VP of Security Operations & Intelligence at the Center for Internet Security® (CIS®); and Theodore "TJ" Sayers, Director of Intelligence & Incident Response at CIS. Together, they examine the scariest malware of 2024 and share some recommendations for how organizations can keep up with the changing cyber threat landscape.
Here are some highlights from our episode:
- 01:32. What makes certain malware strains "scarier" than others
- 05:37. What trends shaped the cyber threat landscape in 2024
- 14:25. The most terrifying cyber threat actor sphere in 2024
- 19:41. How malware tactics and techniques from 2024 will continue to evolve
- 25:04. How individuals and organizations can proactively defend themselves
- 29:52. National strategies that are shaping malware defense and incident response
Resources
- Top 10 Malware Q3 2024
- Election Security Spotlight – What Is Misinformation?
- Salt Typhoon Hacks of Telecommunications Companies and Federal Response Implications
- Episode 107: Continuous Improvement via Secure by Design
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 108 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager are joined by Ed Skoudis, CEO of Counter Hack Challenges and President of SANS Technology Institute. Together, they discuss the evolution of gaming and competition in cybersecurity and how these activities help to make the industry stronger.
Here are some highlights from our episode:
- 02:04. What goes into creating a game environment that attracts all kinds of skill levels
- 04:43. A multi-disciplinary approach to creating a game environment
- 16:14. How gaming and competition help to spot people with talent and potential
- 23:32. The challenges of keeping pace with new technology
- 32:03. The biggest challenges of putting a game environment together
- 36:47. How to keep track of characters, situations, and story elements of a game
Resources
- SANS Cyber Ranges
- SANS Holiday Hack Challenge
- Episode 59: Probing the Modern Role of the Pentest
- Episode 95: AI Augmentation and Its Impact on Cyber Defense
- LockBit 3.0 RaaS Gang Incorporates BlackMatter Capabilities
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 107 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager are joined by Steve Lipner, Executive Director of SAFECode. Together, they discuss how software development organizations can use principles of "secure by design" to get on a track of continuous improvement.
Here are some highlights from our episode:
- 01:38. Steve's background and thoughts on the emergence of secure by design
- 14:04. Three guiding principles of secure software development
- 16:13. The impact of security awareness from a developer's perspective
- 22:22. How threat modeling helps to address security as a system problem
- 25:37. The effect of modern software development methodologies like Agile and DevSecOps
- 30:29. What CISA's activity around secure by design means for the industry
Resources
- SAFECode
- Secure Software Development Framework (SSDF)
- Embedded IoT Security: Helping Vendors in the Design Process
- Episode 95: AI Augmentation and Its Impact on Cyber Defense
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 106 of Cybersecurity Where You Are, Sean Atkinson is joined by Chris Smith, Social Media Specialist at the Center for Internet Security® (CIS®).
Together, they use a donation scam about a natural disaster to advise how you can stay safe against this type of cyber threat.
Here are some highlights from our episode:
- 00:49. Why it's important to talk about donation scams and why they're so prevalent
- 05:13. Recounting a real-world example of a donation scam
- 10:43. Common tactics leveraged by online scammers
- 13:27. Guidance for defending against a donation scam
- 16:48. The rise of checks and balances to defend against crowdfunding scams
- 20:59. How research can help you to verify before you donate
- 29:11. What to do if you have fallen for a scam
Resources
- Episode 27: Cyber Scams
- October: Cybersecurity Awareness Month
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 105 of Cybersecurity Where You Are, Sean Atkinson discusses the importance of context in maturing how you use cyber risk quantification to build cases for risk treatment strategies.
Here are some highlights from our episode:
- 01:56. The inspiration for an episode on cyber risk quantification
- 02:38. How to situate risk quantification in your business processes
- 08:56. Traps to avoid when quantifying cyber risks
- 12:12. How the quantification process relates to controls implementation
- 16:50. Why the right people and data can help you build something sustainable
- 23:19. Three lenses for examining cyber risk
- 26:50. Different means for communicating risk to stakeholders
Resources
- Quantitative Risk Analysis: Its Importance and Implications
- FAIR: A Framework for Revolutionizing Your Risk Analysis
- CIS Critical Security Controls®
- CIS Risk Assessment Method
- 6 Truths of Cyber Risk Quantification
- Society of Information Risk Analysts
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 104 of Cybersecurity Where You Are, Sean Atkinson is joined by Kennidi Ortega, Information Security Analyst at the Center for Internet Security® (CIS®).
Together, they explore the experience of a first-year analyst and how they might make the most of getting started in a cybersecurity career.
Here are some highlights from our episode:
- 01:07. How Kennidi got started in cybersecurity and what led her to the field
- 03:44. What the beginning of Sean's cybersecurity career looked like
- 04:23. The biggest challenges a first-year analyst may face
- 07:56. Helpful resources for getting started in the cybersecurity industry
- 11:58. Which technical skills Kennidi sharpened the quickest in her role
- 16:05. The most important business skills for planning a future in cybersecurity
- 20:13. How an agile mindset in cybersecurity supports career growth
- 23:00. Recommendations on career mapping for first-year analysts
- 28:13. The value of mentorships in cybersecurity
Resources
- Episode 103: Education vs. Experience in Cybersecurity
- Episode 54: How to Get Started in Cybersecurity
- Episode 15: Cybersecurity Success Takes Soft Skills
- Episode 45: The Importance of Mentorship
- TryHackMe
- SANS Cyber Security Summits
- PancakesCon
- Trace Labs
- Backdoors & Breaches
- Raices Cyber
- CyberWarrior
- Cyber.org
- Women in CyberSecurity
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 103 of Cybersecurity Where You Are, Sean Atkinson examines education and experience as pathways for new professionals to enter the cybersecurity industry.
Here are some highlights from our episode:
- 01:42. What's motivating Sean to talk about this topic
- 03:32. The value of cybersecurity degrees
- 05:17. The pros and cons of degree programs in cybersecurity
- 07:47. How a cybersecurity certification compares to a degree
- 10:57. Considerations for pursuing a certification in cybersecurity
- 14:00. Using certifications to learn new technology paradigms
- 16:54. Why a breadth of practical experience is important
- 22:49. Pathways for gaining experience in cybersecurity
Resources
- Episode 75: How GenAI Continues to Reshape Cybersecurity
- Episode 59: Probing the Modern Role of the Pentest
- Outliers: The Story of Success
- Hack The Box
- TryHackMe
- David Bombal
- IppSec
- PortSwigger
- John Hammond
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 102 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager are joined by the following guests:
- Charity Otwell, Director of the CIS Critical Security Controls® (CIS Controls®) at the Center for Internet Security® (CIS®)
- Lawrence Cruciana, President of Corporate Information Technologies (CorpInfoTech)
Together, they discuss the "sporty" rigor underlying the process and value of achieving CIS Controls Accreditation.
Here are some highlights from our episode:
- 01:36. What is meant by CIS Controls Accreditation, as certified by CREST
- 03:32. What motivated CorpInfoTech to pursue accreditation
- 07:47. The importance of CIS Controls Accreditation to the cybersecurity ecosystem
- 20:07. The business value of accreditation for recipients
Resources
- CIS Controls Accreditation
- CorpInfoTech Receives First CIS Controls Accreditation
- CorpInfoTech
- Top Hurdles for MSSPs and One Shining Solution
- CIS Community Defense Model 2.0
- Episode 44: A Zero Trust Framework Knows No End
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 101 of Cybersecurity Where You Are, Sean Atkinson is joined by Justin Kohler, Vice President of Products at SpecterOps, and Jonathan Parfait, Technical Account Manager at SpecterOps.
Together, they discuss how the visualization of attack paths in Active Directory helps organizations to better contextualize risks to their enterprise security.
Here are some highlights from our episode:
- 01:54. What Bloodhound is and how it assists organizations in assessing risks in their Active Directory environments
- 05:08. Why have organizations look at their Active Directory environments
- 11:15. Common vulnerabilities and misconfigurations identified by Bloodhound
- 21:21. How organizations can best use Bloodhound as part of their cyber defensive strategy
- 29:18. How Bloodhound is adapting to keep up with evolving Active Directory environments
Resources
- Bloodhound Community Edition
- Episode 62: Inside the 'Spidey Sense' of a Pentester
- What You Need to Know About Hybrid Cloud Environments
- Vulnerability Management Policy Template for CIS Control 7
- CIS Benchmarks List
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 100 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager are joined by David Bisson, Sr. Content Marketing Strategist at the Center for Internet Security® (CIS®).
Together, they celebrate the first 100 episodes of Cybersecurity Where You Are and discuss where the podcast might go in the future.
Here are some highlights from our episode:
- 01:14. How the podcast's approach and content have changed since the first episode
- 04:19. What surprised the team about the "machinery" of putting on a cybersecurity podcast
- 07:53. A look back at some of our favorite guests and types of podcast episodes
- 27:20. How the podcast can continue to support the cybersecurity industry going forward
Resources
- Episode 1: Welcome to the Basics
- Episode 7: CIS Controls v8…It’s Not About the List
- Episode 9: Mitigating Risk: Information Security Governance
- Episode 24: How Do I Start a Career in Cybersecurity?
- Episode 59: Probing the Modern Role of the Pentest
- Episode 96: Making Continuous Compliance Actionable for SMBs
- Episode 97: How Far We've Come preceding CIS's 25th Birthday
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 99 of Cybersecurity Where You Are, Sean Atkinson is joined by Marcus Sachs, SVP and Chief Engineer at the Center for Internet Security® (CIS®).
Together, they discuss how cyber-informed engineering builds resilience to the potential failure of a digital system into new and existing engineering products.
Here are some highlights from our episode:
- 03:51. What cyber-informed engineering is and how this paradigm has emerged
- 11:39. What CIS is doing to emphasize cyber-informed engineering among U.S. State, Local, Tribal, and Territorial (SLTT) government organizations
- 16:25. Why resilience requires everyone to be "cyber-informed"
- 20:50. The need for boards of directors and C-Suite leaders to understand cybersecurity risk
- 25:30. What preparations help to lay the foundation for cyber-informed engineering
Resources
- Cyber-Informed Engineering
- National Cyber-Informed Engineering Strategy
- Cyber-Informed Engineering Implementation Guide
- Episode 75: How GenAI Continues to Reshape Cybersecurity
- Smart Cities Need Smarter Security
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 98 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager are joined by Roger Grimes, Data-Driven Defense Evangelist at KnowBe4.
Together, they embrace transparency as a vehicle for the cybersecurity industry to better defend against insider threats.
Here are some highlights from our episode:
- 01:28. How KnowBe4 detected an insider threat from North Korea
- 09:09. How the Center for Internet Security® (CIS®) responded to news of this incident
- 21:02. The role of technical controls in detecting these types of threats
- 23:56. Common signs you can use to detect fake employees in your hiring process
- 29:22. How cybersecurity companies can use this incident to improve their defenses
Resources
- How a North Korean Fake IT Worker Tried to Infiltrate Us
- North Korean Fake IT Worker FAQ
- Episode 77: Data's Value to Decision-Making in Cybersecurity
- Defense-in-Depth: A Necessary Approach to Cloud Security
- eBook: A CISO’s Guide to Bolstering Cybersecurity Posture
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 97 of Cybersecurity Where You Are, Tony Sager is joined by the following guests:
- Dr. Ramon Barquin, Board Member at the Center for Internet Security® (CIS®) and President and Chief Executive Officer at Barquin International
- Franklin Reeder, Director Emeritus and Founding Chair of CIS as well as Director of the National Cybersecurity Scholarship Foundation
- Clint Kreitner, Founding President/CEO and Former Board Member at CIS
Together, they look back at how much CIS has accomplished as an organization in the leadup to its 25th birthday.
Here are some highlights from our episode:
- 06:04. What brought everyone to CIS's founding meeting at the Cosmos Club
- 16:08. The first steps to operationalizing the takeaways of the Cosmos Club meeting
- 25:40. How CIS's business model came to be
- 34:24. The events that brought the Multi-State Information Sharing and Analysis Center® (MS-ISAC®) into CIS
- 42:42. Tracing the past forward to where we are now
Resources
- 20 Years of Creating Confidence in the Connected World
- Episode 35: Remembering the Late Alan Paller
- Reasonable Cybersecurity Guide
- Episode 79: Advancing Common Good in Cybersecurity – Part 1
- MS-ISAC: 20 Years as Your Trusted Cyber Defense Community
- Dr. Ramon Barquin
- Franklin Reeder
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 96 of Cybersecurity Where You Are, co-hosts Sean Atkinson and Tony Sager are joined by Tarah Wheeler, CEO of Red Queen Dynamics.
Together, they discuss ongoing efforts to translate continuous compliance into something actionable for small- to medium-sized businesses (SMBs).
Here are some highlights from our episode:
- 03:11. The philosophy behind a business model focused on continuous compliance for SMBs
- 17:44. How the Fog of More complicates security and compliance for the "cyber-underserved"
- 30:56. How the industry can navigate the multiple-framework issue and streamline compliance
Resources
- Follow Tarah on LinkedIn
- Episode 95: AI Augmentation and Its Impact on Cyber Defense
- Implementation Guide for Small- and Medium-Sized Enterprises CIS Controls IG1
- Build a Robust Continuous Audit Program in 10 Steps
- How Prioritized Security Controls Break Through the Fog of More
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 95 of Cybersecurity Where You Are, Sean Atkinson is joined by Randy Rose, VP of Security Operations & Intelligence at the Center for Internet Security® (CIS®).
Together, they discuss AI augmentation in terms of how cyber defenders are using generative artificial intelligence to enhance their capabilities.
Here are some highlights from our episode:
- 01:16. How artificial intelligence has changed the landscape for cybersecurity defenders
- 03:49. How AI is starting to augment threat detection
- 10:12. What security researchers are exploring around AI and cyber defense
- 20:54. Key challenges and limitations for AI-based cyber defense
- 30:54. Future trends and innovations for cybersecurity defenders' use of AI
Resources
- Episode 56: Cybersecurity Risks and Rewards of LLMs
- Episode 59: Probing the Modern Role of the Pentest
- SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals
- fr0gger / Awesome-GPT-Agents
- The LLM Misinformation Problem I Was Not Expecting
- Separating FUD from Practical for Post-Quantum Cryptography
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 94 of Cybersecurity Where You Are, Tony Sager is joined by the following guests from the Center for Internet Security® (CIS®):
- Carlos Kizzee, SVP of Multi-State Information Sharing and Analysis Center® (MS-ISAC®) Strategy & Plans
- Karen Sorady, VP of MS-ISAC Strategy & Plans
- Greta Noble, Director of Community Engagement
Together, they discuss how the ISAC Annual Meeting supports the 24x7x365 community defense efforts of the MS-ISAC and Elections Infrastructure Information Sharing and Analysis Center® (EI-ISAC®).
Here are some highlights from our episode:
- 02:30. Background information on ISACs in general and the role of the MS-ISAC
- 04:17. Why it's an annual meeting and not a conference
- 06:40. What made the 2024 ISAC Annual Meeting the largest of its kind so far
- 08:43. How the human dimension drives our yearly meeting
- 15:44. The role of the MS- and EI-ISACs in CIS's broader strategy
- 19:42. How our yearly meeting improves what CIS does
- 29:57. What's next for the ISAC Annual Meeting
Resources
- MS-ISAC: 20 Years as Your Trusted Cyber Defense Community
- Episode 76: The Role of Thought Leadership in Cybersecurity
- Reasonable Cybersecurity Guide
- Cybersecurity at Scale: Piercing the Fog of More
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 93 of Cybersecurity Where You Are, co-hosts Sean Atkinson and Tony Sager are joined once again by John Cohen, Executive Director of Countering Hybrid Threats at the Center for Internet Security® (CIS®).
Together, they discuss a whole-of-society approach to help make the U.S. public resilient against multidimensional threats in our connected world.
Here are some highlights from our episode:
- 01:52. What the U.S. public needs to consider in order to strengthen its resilience
- 06:04. How a national framework addresses the need for organizations to build resilience and intercommunication in the face of increasingly sophisticated threats
- 11:41. Identifying who key partners are in a complex, hybrid world
- 16:49. How people are responding to the national framework and where they are seeing value
- 21:50. Clarifying hopes for the national framework going forward
Resources
- John D. Cohen
- Enhancing Safety in the Connected World — A National Framework for Action
- Episode 92: A Framework to Counter Evolving Cyber Threats
- Why Whole-of-State Cybersecurity Is the Way Forward
- Public Water and Wastewater Sector Face Mounting Cyber Threat
- The National Cybersecurity Strategy
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 92 of Cybersecurity Where You Are, co-hosts Sean Atkinson and Tony Sager are joined by John Cohen, Executive Director of Countering Hybrid Threats at the Center for Internet Security® (CIS®).
Together, they discuss "Enhancing Safety in the Connected World — A National Framework for Action," a multi-year project to help law enforcement and security professionals better contextualize and respond to evolving cyber threats.
Here are some highlights from our episode:
- 02:01. Why the current threat environment necessitates a framework that accounts for "cyber physical," "cyber safety," and other considerations
- 08:48. How entities at the federal level and local law enforcement approach evolving cyber threats differently
- 16:34. The different types of threats that characterize the evolving cyber threat environment
- 22:05. How the Federalist Papers inform the Framework's "whole-of-society" approach
Resources
- John D. Cohen
- Enhancing Safety in the Connected World
- Episode 75: How GenAI Continues to Reshape Cybersecurity
- Why Whole-of-State Cybersecurity Is the Way Forward
- Establishing Essential Cyber Hygiene
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 91 of Cybersecurity Where You Are, Sean Atkinson is joined by Charity Otwell, Director of the CIS Critical Security Controls® (CIS Controls®) at the Center for Internet Security® (CIS®).
Together, they discuss what you need to know about the release of CIS Controls v8.1.
Here are some highlights from our episode:
- 01:17. What you can expect to see in version 8.1 of the Controls
- 06:19. How CIS Controls v8.1 helps you to integrate other governance structures
- 09:23. How version 8.0 and version 8.1 of the Controls differ
- 14:19. What goes into creating a new version of the Controls
- 21:06. Which resources you can use to guide your implementation plan
- 26:39. A sneak peek into the development of version 9.0
Resources
- Follow Charity on LinkedIn
- CIS Critical Security Controls v8.1
- CIS Critical Security Controls v8.1 Change Log
- How to Construct a Sustainable GRC Program in 8 Steps
- CIS Controls v8.1 Mapping to NIST CSF 2.0
- CIS Critical Security Controls Navigator
- Episode 87: Marking 11 Years as a Verizon DBIR Contributor
- Cybersecurity at Scale: Piercing the Fog of More
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 90 of Cybersecurity Where You Are, co-hosts Sean Atkinson and Tony Sager are joined by the following guests:
- Charity Otwell, Director of the CIS Critical Security Controls® (CIS Controls®) at the Center for Internet Security® (CIS®)
- Mia LaVada, Product Manager of CIS Benchmarks and Cloud at CIS
- Don Freeley, VP of IT Services at CIS
Together, they discuss how you can use CIS resources to ensure control continuity when migrating to the cloud.
Here are some highlights from our episode:
- 01:35. The biggest drivers for why organizations are moving to the cloud
- 02:42. Foundational factors to consider as part of your cloud migration
- 07:24. Resources from CIS designed to help you in your transition to the cloud
- 11:00. Common challenges of migrating to the cloud
- 14:37. The importance of three CIS Controls to your cloud security program
- 18:35. The value of partnerships and community in driving cloud security improvements
- 19:32. How you can use the CIS Foundations Benchmarks to get started in the cloud
- 23:06. Inside the human and process side of moving to the cloud
Resources
- Follow Charity, Mia, and Don on LinkedIn
- Keep the Cloud Secure with CIS after Migrating to the Cloud
- Cloud Security
- CIS Software Supply Chain Security Guide
- Cloud Security and the Shared Responsibility Model
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 89 of Cybersecurity Where You Are, co-host Sean Atkinson is joined by the following guests:
- Rian Davis, Elections Cyber Threat Intelligence Intern at the Center for Internet Security® (CIS®)
- Timothy Davis, Sr. Elections Cyber Threat Intelligence Analyst at CIS
Together, they discuss how cyber threat actors (CTAs) are using generative artificial intelligence (GenAI) as an enabler of their attacks.
Here are some highlights from our episode:
- 01:04. Why it's important to raise awareness of how CTAs are using GenAI
- 01:59. How the CIS Cyber Threat Intelligence (CTI) team is seeing generative AI in CTAs' attack methodology
- 03:50. The types of attacks that are using this technology and how the frequency of those attacks is changing
- 05:46. Some notable attacks that have used GenAI in their methodology
- 16:10. The ways in which CTAs are incorporating generative AI into social engineering
- 24:17. What defenders can do in response to CTAs' use of GenAI
Resources
- An Examination of How Cyber Threat Actors Can Leverage Generative AI Platforms
- Episode 56: Cybersecurity Risks and Rewards of LLMs
- Election Security Spotlight – Generative AI and Elections
- MS-ISAC Security Primer – Spear Phishing
- Why Employee Cybersecurity Awareness Training Is Important
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 88 of Cybersecurity Where You Are, co-host Sean Atkinson discusses the evolving role of a chief information security officer (CISO).
Here are some highlights from our episode:
- 02:47. Why communication is a core competency for CISOs
- 08:35. How to take a balanced approach when evaluating an organization's implementation of artificial intelligence (AI) and machine learning (ML)
- 11:47. The role a CISO plays in integrating privacy requirements into the organization
- 15:35. Thoughts on how you can start preparing for or moving into a CISO position
- 19:12. A future outlook of the CISO role
- 26:40. Average longevity of CISOs in their roles and how this affects a security posture
Resources
- Episode 75: How GenAI Continues to Reshape Cybersecurity
- Reasonable Cybersecurity Guide
- Episode 74: The Nexus of Cybersecurity & Privacy Legislation
- CIS Critical Security Controls® (CIS Controls®)
- Cybersecurity at Scale: Piercing the Fog of More
- CIS Software Supply Chain Security Guide
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 87 of Cybersecurity Where You Are, co-host Tony Sager is joined by the following guests:
- Charity Otwell, Director of the CIS Critical Security Controls® (CIS Controls®) at the Center for Internet Security® (CIS®)
- Philippe Langlois, Senior Principal, Security Risk Management and Author of the Verizon Data Breach Investigations Report (DBIR)
- Theodore "TJ" Sayers, Director of Intelligence & Incident Response at CIS
Together, they celebrate 11 years of CIS and Verizon working together to contextualize the threat activity security teams are seeing and to help teams use the Controls as an improvement framework.
Here are some highlights from our episode:
- 02:00. How the Multi-State and Elections Infrastructure Information Sharing and Analysis Centers (MS-ISAC® and EI-ISAC®) contribute anonymized data to the Verizon DBIR
- 07.27. The two types of data that Verizon uses as input for its report
- 13:50. The ways CIS uses the content of Verizon's DBIR to help people embrace programs of security improvement
- 24:48. A glimpse at what goes into producing the DBIR
- 28.33. The importance of leadership in guiding team dynamics and fun
- 32.07. Reception of the 2024 DBIR and exploration of what's next for the Verizon DBIR team
Resources
- 2024 DBIR Findings & How the CIS Critical Security Controls Can Help to Mitigate Risk to Your Organization
- CIS Controls Featured as Recommended Defenses in Verizon's 2024 Data Breach Investigations Report
- 2024 Data Breach Investigations Report
- The VERIS Framework
- CIS Community Defense Model 2.0
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 86 of Cybersecurity Where You Are, co-host Sean Atkinson is live once again from Booth 4319 at RSA Conference (RSAC) 2024.
00:57. Sean chats with Mat Everman, Information Security Operations Manager, about his talk, "Shades of Purple: Getting Started and Making Purple Teaming Possible." They discuss some of the questions Mat received following his talk and how they can put purple teaming into practice at the Center for Internet Security® (CIS®).
Sean asks passersby what they're looking to get out of RSAC 2024 and what stood out to them at the conference.
- 13:56. José Mena, Founder of Digital Twin Networks
- 20:34. Jonathan Kern, CEO of Castile Defense
- 25:42. Ken Klestinec, Regional Sales Manager at Akamai
Finally, Sean talks to fellow team members about CIS's objective for RSAC 2024.
- 18:10. Aaron Perkins, Director of Communications
- 23:25. Nick Rust, Director of Reseller & Channel Partners
- 27:04. Jeff Sparks, CIS Services Sr. Account Executive
- 28:08. Mia LaVada, Product Manager of CIS Benchmarks and Cloud
- 30:01. Mishal Makshood, Sr. Cloud Security Account Executive
Resources
- Episode 85: Reenergizing Collective Action at RSAC 2024
- Episode 75: How GenAI Continues to Reshape Cybersecurity
- How to Construct a Sustainable GRC Program in 8 Steps
- Tabletop Exercises (TTX)
- CIS Critical Security Controls
- CIS Benchmarks
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 85 of Cybersecurity Where You Are, co-hosts Sean Atkinson and Tony Sager are live from Booth 4319 at RSA Conference (RSAC) 2024. Together, they discuss how events like RSAC 2024 reenergize collective action in the cybersecurity industry. They begin by noting how resources such as the CIS Community Defense Model (CDM) bring more data and transparency to security recommendations for the cybersecurity industry. They then look back on some of Tony's presentations at prior years of RSAC before looking at the interest surrounding supply chain security, zero trust, and artificial intelligence (AI). To address these developments, organizations must create a foundation for defense and scale rapid improvements, needs which Tony and Sean see as opportunities for collective action in the industry.
Resources
- From Attacks to Action: An Open Community Model to Drive Defensive Choices
- The "Fog of More" - A CyberSecurity Community Challenge
- CIS Community Defense Model 2.0
- Episode 77: Data's Value to Decision-Making in Cybersecurity
- Foundational Security for Your Software Supply Chain
- Episode 44: A Zero Trust Framework Knows No End
- CIS Critical Security Controls Implementation Groups
- Episode 75: How GenAI Continues to Reshape Cybersecurity
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 84 of Cybersecurity Where You Are, co-host Tony Sager is joined by Brian de Vallance, Senior Advisor at Cambridge Global Advisors; and Phyllis Lee, VP of Security Best Practices (SBP) Content Development at the Center for Internet Security® (CIS®). Together, they discuss the notion of reasonable cybersecurity. They begin by providing some background about reasonableness in cybersecurity and identifying the problem we need to solve — namely, the lack of a definition of reasonableness around which organizations can build their cybersecurity program. They then discuss how a definition for reasonable cybersecurity needs to include security best practices that are doable. They conclude by exploring how CIS's work around this topic may influence its content development going forward.
Resources
- Follow Brian and Phyllis on LinkedIn
- Reasonable Cybersecurity Guide
- Reasonable Cybersecurity
- CIS Critical Security Controls
- CIS Critical Security Controls Implementation Groups
- CIS Community Defense Model 2.0
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 83 of Cybersecurity Where You Are, co-host Sean Atkinson is joined by nearly 20 employees at the Center for Internet Security® (CIS®). Together, they discuss the value of meeting in person to CIS workplace culture. With the company's 2024 Annual Full Staff Meeting in Orlando, FL, as their backdrop, they explore how personal relationships create a foundation for building effective teams, more agile workflows, and a sustainable sense of engagement and motivation at CIS. Along the way, they reflect on how much the company has changed since before the pandemic.
Resources
- Episode 82: How CIS Leadership Values Team Building Events
- Episode 58: Inside CIS's Award-Winning Workplace Culture
- Center for Internet Security Named Among 2024 Top Workplaces
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 82 of Cybersecurity Where You Are, co-hosts Sean Atkinson and Tony Sager are joined by John Gilligan, President and CEO at the Center for Internet Security® (CIS®); and Gina Chapman, Chief Operating Officer at CIS. Together, they discuss the importance of in-person team building events. They use the pandemic as a frame to understand how events such as the 2024 Annual Full Staff Meeting preserve and cultivate CIS's workplace culture. They also look to other ongoing initiatives at the company, such as CIS Cares and the IDEA Alliance, as efforts to sustain employee engagement both in person and virtually.
Resources
- Follow John and Gina on LinkedIn
- Center for Internet Security Named Among 2024 Best Companies to Work for in New York
- CIS Leadership Principles
- Episode 43: Giving Back Through CIS CARES
- IDEA Alliance
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 81 of Cybersecurity Where You Are, co-host Sean Atkinson is joined by Daniel McIntyre, Identity and Access Management (IAM) Manager at the Center for Internet Security® (CIS®). Together, they acknowledge Identity Management Day 2024 with a discussion of IAM. They begin by looking at how IAM as a concept has changed over the years. They then explore current challenges in the modern environment and strategies for IAM to keep up with emerging threats. After emphasizing the importance of training in an effective IAM program, they conclude their conversation by sharing best practices for getting started in IAM and cybersecurity more broadly.
Resources
- Identity Management Day
- Why Are Authentication and Authorization So Difficult?
- Tracing the Evolving Levels of Support for WebAuthn
- Episode 44: A Zero Trust Framework Knows No End
- Election Security Spotlight – Password Attacks
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 80 of Cybersecurity Where You Are, co-host Tony Sager is once again joined by Philip Reitinger, President and CEO of Global Cyber Alliance. Together, they continue their discussion around Common Good Cyber. Tony and Philip begin by recapping the events of the Common Good Cyber Workshop on February 26–27, 2024. From there, they explore the perspective of IT companies and governments in supporting common good solutions for the cybersecurity industry. They conclude their conversation by looking to the future of Common Good Cyber and explaining how you can get involved.
Resources
- Follow Philip on LinkedIn
- Common Good Cyber Workshop: February 26–27, 2024
- Episode 75: How GenAI Continues to Reshape Cybersecurity
- Episode 60: Guiding Vendors to IoT Security by Design
- Establishing Essential Cyber Hygiene
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 79 of Cybersecurity Where You Are, co-host Tony Sager is joined by Philip Reitinger, President and CEO of Global Cyber Alliance. Together, they discuss the Common Good Cyber cybersecurity initiative. Tony and Philip begin by sharing the paths that brought them to the nonprofit sector. From there, Philip recounts the events and needs that led to the formation of Common Good Cyber. They end the first part of their conversation by exploring the nature of "common good" in relation to internet technology. Both agree that common good efforts must include more than just money to produce meaningful change in the cybersecurity industry.
Resources
- Follow Philip on LinkedIn
- Episode 30: Solving Cybersecurity at Scale with Nonprofits
- Global Cyber Alliance
- Foundational Security for Your Software Supply Chain
- The Cost of Ignoring the Log4j Vulnerability
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 78 of Cybersecurity Where You Are, co-hosts Tony Sager and Sean Atkinson are joined by Lisa Young, Senior Metrics Engineer at Netflix. Lisa is a long-time practitioner in the cybersecurity risk, risk quantification, and metrics field. She has a rich career and experience of putting resources towards practices that will protect, sustain, make organizations resilient over time. In her current role, Lisa helps Netflix measure what works, what doesn't work, and how to optimize practices and controls that help enhance coverage and efficacy of things that need to be done. Together, the three discuss the hurdles of harmonizing teams to determine acceptable risk in the cybersecurity ecosystem.
Resources:
- Follow Lisa on LinkedIn
- Quantitative Risk Analysis: Its Importance and Implications
- Episode 65: Making Cyber Risk Analysis Practical with QRA
- FAIR: A Framework for Revolutionizing Your Risk Analysis
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 77 of Cybersecurity Where You Are, co-hosts Sean Atkinson and Tony Sager are joined by Roger Grimes, Data-Driven Defense Evangelist at KnowBe4. Together, they discuss how to use data to inform your decision-making in cybersecurity. They begin by discussing the cybersecurity industry's lack of maturity in its use of data. From there, they explore the risks of not using data to make cybersecurity decisions. In Tony's words, the cybersecurity industry doesn't have to accept "perfection is the enemy of the good" as its paradigm. When we understand the data with which we can work, we can frame the information in a way to strengthen the cybersecurity posture of our respective organizations.
Resources
- Follow Roger on LinkedIn
- A Data-Driven Computer Security Defense: THE Computer Security Defense You Should Be Using
- Cybersecurity at Scale: Piercing the Fog of More
- Known Exploited Vulnerabilities Catalog
- Episode 60: Guiding Vendors to IoT Security by Design
- Episode 75: How GenAI Continues to Reshape Cybersecurity
- Fighting Phishing: Everything You Can Do to Fight Social Engineering and Phishing
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 76 of Cybersecurity Where You Are, co-host Tony Sager is joined by Julie Morris, CEO and Co-Founder of Persona Media. Together, they discuss the role of thought leadership in cybersecurity. They begin by discussing misconceptions surrounding the notion of thought leadership. Next, they explore what thought leadership looks like in the context of an industry like cybersecurity and a company like the Center for Internet Security® (CIS®). Their conversation concludes with some advice on how individuals, especially senior leaders, can get started with thought leadership.
Resources
- Follow Julie on LinkedIn
- Episode 30: Solving Cybersecurity at Scale with Nonprofits
- Episode 75: How GenAI Continues to Reshape Cybersecurity
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 75 of Cybersecurity Where You Are, co-hosts Sean Atkinson and Tony Sager discuss how generative artificial intelligence (GenAI) continues to reshape cybersecurity. They begin by using Episodes 48, 49, and 56 to consider the ongoing impact of GenAI on confidence, trust, and consistency as elements of a mature cybersecurity program. After reflecting on how confidence has shaped the work of the Center for Internet Security® (CIS®) more generally, Sean and Tony conclude by revisiting the verification challenge of GenAI.
Resources
- Episode 48: 3 Trends to Watch in the Cybersecurity Industry
- Episode 49: Artificial Intelligence and Cybersecurity = Minutes 26:00 and 31:00
- Episode 56: Cybersecurity Risks and Rewards of LLMs = Minute 8:00
- The LLM Misinformation Problem I Was Not Expecting
- Episode 44: A Zero Trust Framework Knows No End
- Defining "Reasonable" Security with a Risk Assessment Method
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 74 of Cybersecurity Where You Are, co-host Sean Atkinson is joined by Brian de Vallance, Senior Advisor at Cambridge Global Advisors; and Carlos Kizzee, Senior Vice President (SVP) for Multi-State Information Sharing and Analysis Center® (MS-ISAC®) Strategy & Plans at the Center for Internet Security® (CIS®). In recognition of Data Privacy Week on January 21-27, 2024, they discuss the nexus of cybersecurity and privacy legislation in the United States. They begin by reviewing how the privacy laws passed by U.S. states over the past several years all include a cybersecurity element – namely, the effort to implement "reasonable" cybersecurity around protecting consumers' data. They then look to the future and consider how the laws will lead to regulations and, in turn, enforcement actions that will help raise our understanding of consumer privacy rights and how they can be defended.
Resources
- CIS Controls v8 Privacy Companion Guide
- What is Cyber Threat Intelligence?
- Defining "Reasonable" Security with a Risk Assessment Method
- Episode 49: Artificial Intelligence and Cybersecurity
- Cybersecurity at Scale: Piercing the Fog of More
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 73 of Cybersecurity Where You Are, co-hosts Sean Atkinson and Tony Sager use our 2023 cybersecurity predictions to understand how the industry changed last year. They discuss progress and challenges around Artificial Intelligence (AI), zero trust, and other key trends they and others brought up in our blog post, "Our Experts' Top Cybersecurity Predictions for 2023." They also promise a similar year in review (YIR) for our 2024 cybersecurity predictions, for which 17 experts at the Center for Internet Security® (CIS®) contributed their thoughts.
Resources
- Episode 56: Cybersecurity Risks and Rewards of LLMs
- Episode 44: A Zero Trust Framework Knows No End
- Embedded IoT Security: Helping Vendors in the Design Process
- Cyber Insurance Price Increases Highlight Ransomware Defense
- Episode 63: Building Capability and Integration with SBOMs
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 72 of Cybersecurity Where You Are, co-host Tony Sager is joined by Phyllis Lee, VP of Security Best Practices (SBP) Content Development at the Center for Internet Security® (CIS®). Together, they discuss "Cybersecurity: Practice What, and While, We Teach," a keynote panel where they discussed cybersecurity in education during Tech Tactics in Education: Data and IT Security in the New Now. Throughout this episode, they pull in recorded snippets from their panel. They use those recordings to reflect on IT operational challenges and the need to balance different interests in education organizations, including K-12 schools and higher education institutions. They also highlight commonalities that present not only opportunities for collaboration in the education sector but also instances where CIS can help advance cybersecurity in education through the content it produces.
Resources
- Follow Phyllis on LinkedIn
- Cybersecurity for Educational Institutions
- Episode 71: Advancing K-12 Cybersecurity Through Community
- The Cost of Cyber Defense: CIS Controls IG1
- CIS Critical Security Controls Version 8
- U.S. Cyber Challenge
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 71 of Cybersecurity Where You Are, co-hosts Sean Atkinson and Tony Sager are joined by Carlos Kizzee, SVP for the Multi-State Information Sharing and Analysis Center® (MS-ISAC®) Strategy & Plans at the Center for Internet Security® (CIS®); Dr. Bhargav Vyas, Assistant Superintendent for Compliance and Information Systems as well as Data Protection Officer at Monroe-Woodbury Central School District; and Terry Loftus, Assistant Superintendent & Chief Information Officer of Integrated Technology Services for the San Diego County Office of Education.
Together, they discuss how our publication, "K-12 Report: A Cybersecurity Assessment of the 2021-2022 School Year," facilitates better decision-making around K-12 cybersecurity. They begin by considering some common cybersecurity challenges for K-12 organizations, most notably a lack of funding and skilled personnel. From there, they reflect on how entities in this sector have grown their cybersecurity maturity despite those obstacles over the past few years. Their conversation ends with guidance for getting started with a K-12 cybersecurity program.
Resources
- Follow Carlos, Bhargav, and Terry on LinkedIn
- K-12 Report: A Cybersecurity Assessment of the 2021-2022 School Year
- Multi-State Information Sharing and Analysis Center®
- Episode 69: How the NCSR Assessment Sows SLTT Cyber Maturity
- How the Foundational Assessment Makes Starting or Improving a Cybersecurity Program Easier
- Establishing Essential Cyber Hygiene
- Ransomware Defense-in-Depth
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 70 of Cybersecurity Where You Are, co-host Sean Atkinson is joined by Mathew Schwartz, Executive Editor for DataBreachToday & Europe at the Information Security Media Group (ISMG). Together, they discuss the media's role in shaping public understanding and perception of infosec. They begin by considering the idea of media channels helping to educate the public about cybersecurity matters, including data breaches and digital threats. From there, they go on to talk about how the language that the media uses to report on cybersecurity affects its ability to build trust with the public. Their conversation ends by reviewing tips for how members of the public can find trustworthy media channels in the infosec space.
Resources
- Follow Mathew on LinkedIn
- DataBreachToday.com
- Killnet Group Targeting Ukraine Supporters with DDoS Attacks
- Protecting Against Potential Russian Cyber Attacks
- Episode 68: Designing Cyber Defense as a Partnership Effort
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 69 of Cybersecurity Where You Are, co-host Sean Atkinson is joined by Tyler Scarlotta, Manager of Member Programs at the Center for Internet Security (CIS). Together, they discuss how the Nationwide Cybersecurity Review (NCSR) helps U.S. State, Local, Tribal, and Territorial (SLTT) government organizations evaluate their cyber maturity. They begin by reviewing what the NCSR assessment program entails and identifying trends from previous years. They then explore the lessons learned by SLTTs through participating in the NCSR, the steps to getting involved with the program, as well as the resources from CIS and the Multi-State and Elections Infrastructure Information Sharing and Analysis Centers (MS- and EI-ISACs) that a participant can use to strengthen their cyber maturity.
Resources
- Follow Tyler on LinkedIn
- Nationwide Cybersecurity Review (NCSR)
- MS-ISAC Services
- Establishing Essential Cyber Hygiene
- Episode 61: Overcoming Pre-Audit Scaries Through Governance
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 68 of Cybersecurity Where You Are, co-hosts Sean Atkinson and Tony Sager are joined by James Yeager, VP of Public Sector and Healthcare at CrowdStrike. Together, they discuss designing cyber defense as a partnership effort. They begin by reflecting on the ongoing work of CIS and CrowdStrike to advance cyber defense together. After touching on some of the biggest trends they've seen in the threat landscape, they note how giving advice to customers around cyber defense requires partnership activity. They observe that cybersecurity companies like CIS and CrowdStrike must continue to work together, and they highlight the importance of working with customers directly to identify new angles, new challenges, and new ways of providing help.
Resources
- Follow James on LinkedIn
- CrowdStrike Partner Page
- Expanded Cybersecurity Partnership with CrowdStrike Further Protects the Public Against Potential Attacks
- Endpoint Security: The Key to Combatting Sophisticated CTAs
- Episode 56: Cybersecurity Risks and Rewards of LLMs
- CrowdStrike 2023 Global Threat Report
- SEC Adopts Rules on Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure by Public Companies
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 67 of Cybersecurity Where You Are, co-host Sean Atkinson is joined by Stephanie Gass, Director of Governance, Risk, and Compliance at the Center for Internet Security (CIS). Together, they discuss how to seize the moment once you've completed a cybersecurity audit. They explore the types of questions that you need to think about and the challenges you might encounter when acting upon a cybersecurity audit's findings. Additionally, they walk through a few examples of how you might consider responding to certain audit findings within your organization. Throughout the entire episode, they cite the importance of using business context to determine your priorities and a way for achieving them.
Resources
- Follow Stephanie on LinkedIn
- 6 Mitigation Strategies to Make the Most of Audit Results
- Build a Robust Continuous Audit Program in 10 Steps
- Episode 65: Making Cyber Risk Analysis Practical with QRA
- Episode 61: Overcoming Pre-Audit Scaries Through Governance
- How to Navigate the Cybersecurity Audit Cycle with CIS SecureSuite
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 66 of Cybersecurity Where You Are, co-hosts Sean Atkinson and Tony Sager are joined by Mike Garcia, Senior Cybersecurity Advisor at the Center for Internet Security (CIS), and Jared Dearing, Sr. Director of Elections Best Practices at CIS. Together, they discuss the Rapid Architecture-Based Election Technology Verification (RABET-V) program. They begin by noting how the lack of a standardized verification process for non-voting election systems warranted the creation of a holistic testing approach for these technologies. From there, they explain how RABET-V differs from traditional testing methodologies by verifying non-voting election systems using a three-pronged approach. They conclude by sharing their ongoing work to improve RABET-V.
Resources
- RABET-V
- RABET-V Launch Event
- RABET-V Final Pilot Summary and Next Steps
- Episode 63: Building Capability and Integration with SBOMs
- CIS Software Supply Chain Security Guide
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 65 of Cybersecurity Where You Are, co-host Sean Atkinson is joined by Christopher Painter, Board Member of the Center for Internet Security (CIS) and President of the Global Forum on Cyber Expertise Foundation. Together, they discuss cybersecurity risk management. They begin by discussing how cyber risk analysis fits into a business risk management program in general. From there, they explore quantitative risk analysis (QRA), including its benefits for understanding cyber risk and the challenges of getting started. Their conversation then gets into how the CIS Board of Directors, specifically the Risk Committee, is using different methods of QRA to achieve CIS's business goals and objectives.
Resources
- Follow Christopher on LinkedIn.
- Quantitative Risk Analysis: Its Importance and Implications
- FAIR: A Framework for Revolutionizing Your Risk Analysis
- CIS RAM v2.1: A Way to Demonstrate Reasonable Security
- Episode 61: Overcoming Pre-Audit Scaries Through Governance
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 64 of Cybersecurity Where You Are, co-host Sean Atkinson initiates a series around establishing an underlying policy for your organization's cybersecurity program. He begins by discussing how a policy provides an overview of the business rules, or standards, that will feature in the program. With each standard, he clarifies that you can take a procedural approach to upholding supporting elements. He then narrows his focus to managing data and information, including different types of data management considerations for your organization. Along the way, he points out how you can use resources from the Center for Internet Security (CIS) to drive continuous improvement in this space.
Resources
- Data Management Policy Template for CIS Control 3
- The Cost of Cyber Defense: CIS Controls IG1
- Prioritizing a Zero Trust Journey Using CIS Controls v8
- Episode 61: Overcoming Pre-Audit Scaries Through Governance
- How to Navigate the Cybersecurity Audit Cycle with CIS SecureSuite
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 63 of Cybersecurity Where You Are, co-host Sean Atkinson discusses software bills of materials (SBOMs). He uses CISA and other resources to contextualize key considerations of an SBOM, including how you can use one to understand your organization's underlying risks. From there, Sean explores how to build capability in the SBOM space. He urges a judicious approach that follows practice and builds on resiliency.
Resources
- Episode 22: CIS Behind the Veil: Log4j
- CIS Software Supply Chain Security Guide
- Episode 56: Cybersecurity Risks and Rewards of LLMs
- Software Bill of Materials (SBOM)
- Executive Order on Improving the Nation’s Cybersecurity
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 62 of Cybersecurity Where You Are, co-host Sean Atkinson sits down with Chris Elgee, Senior Security Analyst at Counter Hack; and Erik Pursley, Technical Engineer at Counter Hack. Together, they discuss the "spidey sense" that goes into being a penetration tester. They reflect on key skills and certifications that help to make a successful pentester, review some of the methodologies that go into pentesting, and consider how specialization might be inevitable in an evolving technology landscape. They conclude by offering advice to organizations that are looking to engage in a pentest.
Resources
- Follow Chris and Erik on LinkedIn
- Counter Hack
- A CISO's Best Friend: The Pentester
- Episode 59: Probing the Modern Role of the Pentest
- Episode 49: Artificial Intelligence and Cybersecurity
- Episode 55: Live at RSA Conference 2023
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 61 of Cybersecurity Where You Are, co-hosts Sean Atkinson and Tony Sager are joined by Stephanie Gass, Director of Governance, Risk, and Compliance. Together, they discuss the components of an effective cybersecurity risk governance program. They explore how to represent technical security questions to others, how to overcome challenges associated with changing the way a company makes decisions related to risk, and how culture plays into these types of shifts. They also reflect on how quantification, supply chain security, and other issues factor into a modern-day approach to governance.
Resources
- Follow Stephanie on LinkedIn
- How to Navigate the Cybersecurity Audit Cycle with CIS SecureSuite
- Episode 9: Mitigating Risk – Information Security Governance
- Remote Attestation Enabling Posture Assessment for Automated GRC
- CIS Software Supply Chain Security Guide
- Service Provider Management Policy Template for CIS Control 15
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 60 of Cybersecurity Where You Are, co-host Sean Atkinson is joined by Kathleen Moriarty, CTO at the Center for Internet Security (CIS); Ben Carter, Internet of Things (IoT) specialist at CIS; and Kaitlin Drape, Research and Innovation Process Lead at CIS. Together, they discuss a white paper they recently released that guides IoT vendors on how to build security into their products by default and by design. Kathleen, Ben, and Kaitlin begin by reflecting on why they created such a document in the first place. After explaining some of what went into drafting the white paper, they look to the future and note how IoT frameworks such as theirs helps to shift left IoT security toward purchasing decisions.
Resources
- Follow Kathleen and Ben on LinkedIn
- Embedded IoT Security: Helping Vendors in the Design Process
- Episode 33: The Shift-Left of IoT Security to Vendors
- CIS Controls v8 Internet of Things & Mobile Companion Guides
- Making Security Simpler for Organizations Big and Small
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 59 of Cybersecurity Where You Are, co-hosts Sean Atkinson and Tony Sager are joined by Ed Skoudis, founder of the SANS Penetration Testing Curriculum and Counter Hack. Together, they discuss the value of penetration testing – all while CIS as an organization is undergoing a pentest! They begin by considering the historical perspective of pentests. (In Tony's words, "the foundational perspective for testing back then was to create drama.") They then reflect on how penetration tests excel when they prioritize education using a process of feedback. During the course of the conversation, Sean and Ed draw upon their years of collaboration to explain what this process can look like. They conclude by providing advice on how less mature organizations can get value from a penetration test.
Resources
- Follow Ed on LinkedIn
- Counter Hack
- CIS Critical Security Control 18: Penetration Testing
- Penetration Testing
- Episode 35: Remembering the Late Alan Paller
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 58 of Cybersecurity Where You Are, co-host Sean Atkinson is joined by more than a dozen Center for Internet Security (CIS) employees during the company's 2023 Full Staff Meeting at the Sagamore Resort. Together, they discuss the collaborative nature of CIS's award-winning workplace culture. Using the Full Staff Meeting as a lens, each employee reflects on the importance of an annual in-person meeting for all employees. Their responses highlight how colleagues, teams, and business units alike focus on building relationships. Doing so empowers CIS to engage with partners, members, and the cybersecurity community writ large as a cohesive whole.
Resources
- Center for Internet Security Earns 2023 Top Workplace Awards
- Decision Mojo
- Toister Solutions
- Our Ability, Inc.
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 57 of Cybersecurity Where You Are, co-hosts Sean Atkinson and Tony Sager are joined by the following guests: William Pelgrin, Founder and Former Chair of the MS-ISAC; Thomas Duffy, Former Senior VP Of Operations and Services at the MS-ISAC; and Karen Sorady, VP of MS-ISAC Stakeholder Engagement Division. Together, they celebrate the 20th anniversary of the Multi-State Information Sharing and Analysis Center (MS-ISAC). They look back on the past two decades and reminisce on pivotal moments in the MS-ISAC's history, including when it became a division of the Center for Internet Security (CIS). After discussing how much it's grown in that time, they turn their eyes to the future and explore the MS-ISAC's plans to continue to serve its membership.
Resources
- Episode 49: Artificial Intelligence and Cybersecurity
- Episode 48: 3 Trends to Watch in the Cybersecurity Industry
- Episode 35: Remembering the Late Alan Paller
- Episode 31: To Achieve ICS Security Today, Look to Yesterday
- 8 Cyber Thought Leaders Share Security Trends for the New Year
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 56 of Cybersecurity Where You Are, co-host Sean Atkinson is joined by Dr. Paulo Shakarian, Associate Professor at the School of Computing, Informatics, and Decision Systems Engineering (CIDSE) at Arizona State University. Together, they discuss the cybersecurity implications of large language models (LLMs) like ChatGPT-3. They first look back on how deep learning has enabled machine learning (ML) and artificial intelligence (AI) to reach new levels of accuracy. Next, they discuss how ChatGPT-3 and other new AI models, which are designed to mimic human language, may have inaccuracies. This possibility opens up new vulnerabilities, such as the ability to scale information operations, along with new challenges from a cybersecurity perspective. They conclude by sharing their thoughts about the future of the AI and LLM space.
Resources
- Follow Dr. Shakarian on LinkedIn
- Neuro Symbolic YouTube Channel
- Neuro Symbolic AI
- MITRE ATLAS™
- Episode 49: Artificial Intelligence and Cybersecurity
- Episode 48: 3 Trends to Watch in the Cybersecurity Industry
- Episode 33: The Shift-Left of IoT Security to Vendors
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 55 of Cybersecurity Where You Are, co-host Sean Atkinson speaks with experts in attendance at RSA Conference 2023. He asks nearly a dozen different attendees to share their impressions of the event. They explain how someone can get the most out of being at RSA and what made this year's conference stand out compared to previous years. (Spoiler alert: "AI" as a buzzword was everywhere.) They also discuss just some of the different topics you can learn about at RSA, such as the opportunity for partnerships between red teams and blue teams as well as the cybersecurity impact of AI on the music industry.
Resources
- Episode 49: Artificial Intelligence and Cybersecurity
- Episode 48: 3 Trends to Watch in the Cybersecurity Industry
- Episode 52: Back in the Buzz of RSA Conference
- Episode 34: A Survey of Hacking in Hollywood
- Episode 42: Advocacy for the Underserved
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 54 of Cybersecurity Where You Are, co-host Sean Atkinson addresses how to get started in cybersecurity. He begins by looking at the different types of hard skills and soft skills that form the foundation of any cybersecurity career. Next, he draws upon his expertise to offer advice around certifications, learning a programming language, using a training provider, and building a portfolio. He also shares key insights into how you can make cybersecurity a rewarding career choice for years to come.
Resources
- Why Consider a Career in Cybersecurity?
- 7 Women in Tech Share Career Advice
- Pursuing a Career in Cybersecurity? Three Tips from an Industry Veteran
- Cybersecurity Career Q&A with CIS’ CISO
- Episode 24: How Do I Start a Career in Cybersecurity?
- Episode 45: The Importance of Mentorship
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 53 of Cybersecurity Where You Are, co-host Tony Sager is joined by Ron Gula, President and Co-Founder of Gula Tech Foundation. Together, they acknowledge Autism and Neurodiversity Awareness Month by discussing the need to create more opportunities in cybersecurity for neurodiverse individuals. They point out that there's no one way for all employers and supervisors to support employees with different abilities. It's up to the employers and supervisors to decide where those efforts fit into their culture and what each victory looks like.
Attending RSA Conference 2023? Make sure you visit the main conference hall at 12:00 P.M. PT on Wednesday, April 26. At that time and place, Gula Tech Foundation will announce the four winners of its Spring 2023 grant campaign, "Expanding Opportunities in Cyber for the Neurodivergent." As part of the ceremony, you'll have a chance to speak with the winners about engaging neurodiverse individuals in your organization.
Resources
- Follow Ron Gula on LinkedIn.
- Gula Tech Foundation
- Episode 30: Solving Cybersecurity at Scale with Nonprofits
- Episode 52: Back in the Buzz of RSA Conference
- TikTok: Influence Ops, Data Practices Threaten U.S. Security
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 52 of Cybersecurity Where You Are, co-hosts Sean Atkinson and Tony Sager discuss RSA Conference 2023. Together, they point out that the annual conference is more than just a trade show. They use that lens to identify some tips and tricks that attendees can use to get the most out of their time there. Additionally, they discuss what themes and activities you can expect to see at RSA Conference 2023. Their conversation ends with a teaser of Sean's talk at the event.
Resources
- A CISO's Best Friend: The Pentester
- Episode 49: Artificial Intelligence and Cybersecurity
- Episode 48: 3 Trends to Watch in the Cybersecurity Industry
- Episode 34: A Survey of Hacking in Hollywood
- Episode 30: Solving Cybersecurity at Scale with Nonprofits
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 51 of Cybersecurity Where You Are, co-hosts Sean Atkinson and Tony Sager discuss the strategic importance of using a roadmap to navigate your cybersecurity journey. Together, they point out that this journey is like many others. You need to know how to get packing, plan your route, hit the road, and take a snapshot of how far you've come and where you're going next. Sean and Tony identify some important considerations to keep in mind for each leg of your trip, and they note that the Center for Internet Security shares your journey and supports you along it.
One of the ways it does this is through CIS SecureSuite. Members gain access to benefits, tools, and resources that help them, their clients, and their customers navigate the different stages of their respective cybersecurity journeys. Now through April 30, you can save up to 20% on a new CIS SecureSuite Membership using promo code CYBER2023.
Resources
- Why Your Organization Needs a Cybersecurity Roadmap
- Episode 49: Artificial Intelligence and Cybersecurity
- Separating FUD from Practical for Post-Quantum Cryptography
- Episode 47: How Security and Compliance Support Each Other
- Episode 22: CIS Behind the Veil: Log4j
- CIS SecureSuite® Promo Terms
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 50 of Cybersecurity Where You Are, co-hosts Sean Atkinson and Tony Sager are joined by Randy Rose, Sr. Director of Security Operations & Intel for the MS-ISAC, and Kathleen Moriarty, Chief Technology Officer at CIS. Together, they celebrate Cybersecurity Where You Are reaching Episode 50. To mark this milestone, they look back on some of their favorite moments in the podcast's history. They also share how those moments tie back not only to the maturation of the podcast but also to CIS's ethos as a "platform for activism." (Thanks, Tony.)
Thank you to all our listeners for helping us reach Episode 50. We couldn't have done it without you. More laughter and learning to come!
Resources
- Episode 11: Remote Attestation Helps Zero Trust
- Episode 18: Top 5 Scariest Malware
- Episode 22: CIS Behind the Veil: Log4j
- Episode 29: Conceptualizing Reasonableness for Risk Analysis
- Episode 44: A Zero Trust Framework Knows No End
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 49 of Cybersecurity Where You Are, co-hosts Tony Sager and Sean Atkinson discuss artificial intelligence (AI) and cybersecurity. The two review the relationship, specifically how AI and cybersecurity meet, enhance each other, and ways AI could be a detriment.
Resources:
- Episode 48: 3 Trends to Watch in the Cybersecurity Industry
- LinkedIn Poll: What topic are you interested in learning more about?
View Details
In episode 48 of Cybersecurity Where You Are, co-host Sean Atkinson introduces three trends within the cybersecurity industry that we'll discuss in upcoming episodes. He first touches on how new developments in artificial intelligence, particularly ChatGPT, might affect cybersecurity processes like incident response. Next, Sean reflects on what widespread layoffs in big tech mean for cybersecurity, especially when set against an ongoing cybersecurity skills gap. Finally, he provides an overview of the legislation and preparations for securing a post-quantum world.
Resources
- 5 Big Pros And Cons Of ChatGPT For Cybersecurity
- The Real Reasons For Big Tech Layoffs At Google, Microsoft, Meta, And Amazon
- Biden Signs Post-Quantum Cybersecurity Guidelines Into Law
- Did China Break The Quantum Barrier?
- Breaking RSA with a Quantum Computer
- Episode 25 - Building an Internal Incident Response Team
- Election Security Spotlight – Encryption
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.
View Details
In episode 45 of Cybersecurity Where You Are, co-hosts Sean Atkinson and Tony Sager are joined by Valecia Stocchetti who is a Sr. Cybersecurity Engineer on the CIS Critical Security Controls team here at CIS. Valecia and Sean discuss how their mentorship took shape and how it worked as a partnership from the very beginning. Together with Tony, they go over mentorship vs. career counseling and note that a vetting process can help you spot the difference. They conclude by exploring why it's important to pay it forward whether you're a mentor or mentee.
Resources:
- Security Pros Need a Mentor: Here’s Why and How
- MS-ISAC Members: The Most Valuable MS-ISAC Resource
- CIS Leadership Principles
View Details
In episode 44 of Cybersecurity Where You Are, co-host Sean Atkinson is joined by Scott Hall, Security Architect at the Center for Internet Security (CIS). Together, they identify resources and buy-in as some of the key elements for implementing a zero trust framework. So begins a journey that evolves with your organization's changing business processes and functions. To be successful, it's important to accept that you'll always be tweaking things to fit your needs. It's also invaluable to take a business-centered approach. This includes maintaining an inventory of what you have so that your zero trust journey can drive, not inhibit, business growth.
Resources
- Follow Scott on LinkedIn
- Prioritizing a Zero Trust Journey Using CIS Controls v8
- Where Does Zero Trust Begin and Why is it Important?
- Episode 11: Remote Attestation Helps Zero Trust
- Simplifying Security
View Details
In episode 43 of Cybersecurity Where You Are, co-hosts Sean Atkinson and Tony Sager are joined by Amanda Flynn, Manager of Admin Services and Board Relations at the Center for Internet Security (CIS), and Elijah Cedeno, Sr. Account Management Specialist at CIS. Together, they discuss the work of CIS CARES, a CIS program that gives back to the community every year through campaigns focused on community, animals, resource conservation, and education. Their conversation looks back at the evolution of CIS CARES over the past 11 years, explores the program's focus for Q4 2022, and teases what's to come next year and beyond.
Resources
- Help CIS CARES support Middle Earth in Q4 2022
- Follow Amanda and Elijah on LinkedIn
- Learn more about CIS CARES
- CIS Cares Helps 15 Organizations in 2021, With More to Come
- A push for cybersecurity philanthropic giving launches
- CIS, Partners Donate Emergency Kits to Children in Need
View Details
In episode 42 of Cybersecurity Where You Are, co-host Sean Atkinson is joined by Mat Everman, Information Security Operations Manager at the Center for Internet Security (CIS). Together, they discuss the topic of advocating for the underserved. Both agree that there's no silver bullet that a person or business can use to minimize all cyber risk. In the absence of a cure-all solution, however, there are opportunities for improving the security maturity of the underserved more broadly. This process begins with a discussion of where the underserved are. It then focuses on security measures that they can use to establish a baseline and create a foundation for an ever-evolving security journey.
Resources
- Protect Your Identity This Cybersecurity Awareness Month
- Making Time for Ongoing Security Awareness Training
- Election Security Spotlight – Common Cyber Hoax Scams
- CIS Critical Security Controls Implementation Group 1
- CIS Software Supply Chain Security Guide
View Details
In episode 41 of Cybersecurity Where You Are, co-host Sean Atkinson is joined by Valecia Stocchetti, Sr. Cybersecurity Engineer of the CIS Critical Security Controls (CIS Controls); Megan Stifel, Chief Strategy Officer for the Institute for Security and Technology; and Davis Hake, Co-Founder and Vice President of Policy at Resilience Insurance. Together, they discuss their collaboration as members of the Ransomware Task Force to create the "Blueprint for Ransomware Defense." After situating this effort within the evolving ransomware landscape, they explain how organizations can best use the Blueprint as an internal and external resource to minimize their ransomware risk. They also offer insight into how the Blueprint stands apart from other anti-ransomware guides that are currently available.
Resources
- Follow Megan on LinkedIn
- Follow Davis on LinkedIn
- Register for the webinar: Foundational Safeguards: Building Your Cybersecurity Foundation
- A Blueprint for Ransomware Defense Using the CIS Controls
- Cybersecurity at Scale: Piercing the Fog of More
- CIS Software Supply Chain Security Guide
- CIS Community Defense Model 2.0
View Details
In episode 40 of Cybersecurity Where You Are, co-host Tony Sager is joined by Murray Kenyon, Vice Cybersecurity Partnerships Executive at U.S. Bank. Together, they discuss the human dimension of cybersecurity, that is, bringing people with different talents together to understand common problems and help both organizations and individuals make informed choices. This is the philosophy behind Cybersecurity Awareness Month, an initiative which Kenyon helps organize as a Board member of the National Cybersecurity Alliance. The purpose of this year's theme, "See Yourself in Cyber," is not to make users into cybersecurity experts, as Sager and Kenyon point out. It's to create resources and lines of communication for sharing basic steps that everyone can take to better protect themselves online.
Resources
- Follow Murray Kenyon on LinkedIn.
- Cybersecurity Awareness Month – National Cybersecurity Alliance
- Jumpstart Your Security Program with Essential Cyber Hygiene
- CIS Communities
View Details
In episode 39 of Cybersecurity Where You Are, CIS's Chief Information Security Officer Sean Atkinson discusses the importance of scaling in relation to cybersecurity. A business needs to be able to manage growth without risking security, while also managing security without hindering growth. Atkinson offers guidance on how to go about this and highlights the benefits organizations will see when scaling their cybersecurity strategy.
Resources
- How to Scale Cybersecurity for Your Business
- Jumpstart Your Security Program with Essential Cyber Hygiene
- How to Implement & Assess Your Cyber Hygiene
- CIS Critical Security Controls Implementation Group 1
View Details
In episode 38 of Cybersecurity Where You Are, co-host Sean Atkinson is joined by Theodore "TJ" Sayers, Manager of the Cyber Threat Intelligence (CTI) team at the Multi-State and Elections Infrastructure Information Sharing and Analysis Centers (MS-ISAC and EI-ISAC), and Aaron Zaleski, Sr. Cyber Incident Response Team Analyst at the MS-ISAC. Together, they discuss how the cyber threat landscape is changing. Some cyber threat actors (CTAs) are now writing their payloads in different programming languages, for instance, while others are employing new types of delivery vectors. Their conversation wraps up by identifying steps that organizations can take to defend themselves against these and other developments going forward.
Resources
- What is Cyber Threat Intelligence?
- Breaking Down the BlackCat Ransomware Operation
- Brute Ratel: The New Red Teaming Tool Coopted by CTAs
- The Conti Leaks: A Case of Cybercrime’s Commercialization
- Real-Time Indicator Feeds
- Report an Incident
View Details
In episode 37 of Cybersecurity Where You Are, co-hosts Tony Sager and Sean Atkinson are joined by Carlos Kizzee, SVP of CIS Stakeholder Engagement Operations at the Multi-State Information Sharing and Analysis Center (MS-ISAC). Together, they discuss how the 15th Annual ISAC Meeting – held recently in Baltimore – gives an opportunity for representatives of U.S. State, Local, Tribal, and Territorial (SLTT) government organizations to network, share best practices, and learn from one another's experiences. Tony then takes us to the ISAC Meeting, connects with a couple of attendees on the floor, and explores what the event means to them.
Resources
- Follow Carlos on LinkedIn
- Follow the MS-ISAC on LinkedIn
- MS-ISAC Charter
- MS-ISAC Members
- Join the MS-ISAC
View Details
In episode 36 of Cybersecurity Where You Are, co-host Sean Atkinson is joined by Marci Andino, Sr. Director of the Elections Infrastructure Information Sharing and Analysis Center (EI-ISAC), and Trevor Timmons, EI-ISAC Executive Committee Chair and Chief Information Officer at Colorado Department of State. Together, they discuss Cyber STRONG, a campaign launched by the EI-ISAC that encourages election officials to take decisive and deliberate steps towards improving their cybersecurity posture. Cyber STRONG provides officials with actionable guidance that they can use to further protect the security and integrity of their elections.
Resources
- Follow Marci and Trevor on LinkedIn
- Strong Elections Are Cyber STRONG…Are You?
- The 2020 Elections Year in Review
- Best practices for election systems security
- Episode 20: The State of Election Cybersecurity
- How to Improve Election Technology Verification
View Details
In episode 35 of Cybersecurity Where You Are, co-hosts Tony Sager and Sean Atkinson are joined by Bobbie Stempfley, Board Chair at the Center for Internet Security (CIS). Together, they remember the late Alan Paller, a CIS co-founder and former Board member. Each of them recalls when they first met Alan, and exchange stories of how his passion for bringing people together and solving big challenges helped change their lives, drive CIS's mission, and reshape the cybersecurity industry.
Resources
- Follow Bobbie on LinkedIn
- Remembering Alan Paller, CIS Co-Founder and Board Member
- At Long Last, CIS Will Be Back at RSA Conference in 2022
- CIS Controls Volunteer Spotlight: James and Kelli Tarala
- CIS Board of Directors
View Details
In episode 34 of Cybersecurity Where You Are, co-host Sean Atkinson and Chris Elgee, a senior security analyst and Core NetWars Tournament design lead for Counter Hack, look back at how Hollywood has portrayed hacking over the years. They cover long-standing crowd favorites like Hackers, Sneakers, and Mr. Robot along with some lesser-known gems. The overarching trend? Viewers are getting more computer-literate, so the way in which Hollywood portrays hacking is evolving in a way that not only satisfies audiences but also raises their awareness of cybersecurity.
Resources
- Follow Chris on LinkedIn.
- Election Security Spotlight – Black, Gray, & White Hat Hackers
- CIS Critical Security Control 18: Penetration Testing
- Election Security Spotlight – Social Engineering
- Hack the Human: End-User Training and Tips to Combat Social Engineering
- MS-ISAC Security Primer – Spear Phishing
View Details
In episode 33 of Cybersecurity Where You Are, co-host Sean Atkinson and Ben Carter, IoT Specialist for CIS’s Chief Technology Officer, discuss the need to secure IoT devices at the vendor level. This is impossible without taking a high-level view and ensuring that all protocols used by IoT devices and vendors are taken into account. Only by ensuring security by design can organizations in healthcare, manufacturing, government, and other sectors accomplish security at scale for IoT management – all while preserving interoperability between their connected devices.
Resources
- Follow Ben Carter on LinkedIn
- CIS Controls v8 Internet of Things Companion Guide
- 6 Simple Tips for Securing IoT Devices
- Smart Devices, Smart Users – How to Stay Secure in an IoT World
- “Internet of Things” Needs to be More Secure
View Details
In episode 32 of Cybersecurity Where You Are, co-hosts Sean Atkinson and Tony Sager discuss RSA 2022 — which is always a highlight of our conference calendar. Tony gives a preview of three sessions in which he'll present on cybersecurity nonprofits, incentivizing the adoption of cybersecurity best practices, and securing the supply chain. He also provides tips and best practices that can help RSA newbies, individual teams, and general attendees make the most of the conference.
Resources
- Complete your registration for RSA Conference 2022
- At Long Last, CIS Will Be Back at RSA Conference in 2022
- Episode 30: Solving Cybersecurity at Scale with Nonprofits
- Making Security Simpler for Organizations Big and Small
View Details
In episode 31 of Cybersecurity Where You Are, co-host Sean Atkinson is joined by Karen Sorady, VP for Multi-State Information Sharing and Analysis Center (MS-ISAC) Member Engagement at the Center for Internet Security (CIS). Their discussion focuses on industrial control system (ICS) security, some of the threats they're susceptible to, and what goes into making a good operational technology (OT) security program. Looking back over the past 20 years, the security community has learned some valuable lessons on the information technology (IT) side of things. But we won't be able to apply those lessons to OT and ICS without communication and collaboration. This isn't just about fostering conversations between OT and IT teams. It's also a call to action for organizations to work with public-private partnerships and communities like the MS-ISAC so that they don't have to go it alone.
View Details
In episode 30 of Cybersecurity Where You Are, co-host Tony Sager is joined by Philip Reitinger, President and CEO of the Global Cyber Alliance. Their discussion focuses on the role that nonprofits play in solving cybersecurity problems at scale. In today's mutually dependent technology landscape, nonprofits' resources and expertise remove the need for enterprises to solve cybersecurity issues on their own. This is especially true given initiatives like Nonprofit Cyber, a "collective effort of equals" for which Philip and Tony are Executive Committee Co-chairs.
Resources
- Follow Philip Reitinger on Twitter
- How to Protect Your Nonprofit from Phishing Cyber-Attacks
- The Cybersecurity 202: A Nonprofit is Providing Free Ransomware Protection to Private U.S. Hospitals
- Faith-based Nonprofit Uses CIS Controls as the Baseline Framework
- Modern CTO Podcast | The Role of Nonprofits in Cyber Defense
- Maximizing Our Cyber Non-Profits
View Details
In episode 29 of Cybersecurity Where You Are, co-hosts Tony Sager and Sean Atkinson are joined by Chris Cronin, ISO 27001 Auditor and Partner at HALOCK, a leading information security consultancy. Their discussion focuses on "reasonableness" as it relates to cybersecurity risk management. This topic isn't just about proving to regulators, litigators, and others that security controls were in place prior to an incident. It also considers how to implement safeguards without overburdening users and executives.
Resources
- Follow Chris Cronin on LinkedIn
- The Risk Conversation
- Manage Cybersecurity Risk with the CIS Controls
- Third-party Risk Management – Beyond the Questionnaire
- 3 Things You’ll Learn Conducting a Cyber Risk Assessment with CIS RAM
View Details
In episode 28 of Cybersecurity Where You Are, co-hosts Tony Sager and Sean Atkinson are joined by Brian Ray, Director of the Center for Cybersecurity and Privacy Protection, and Leon and Gloria Professor of Law at the Cleveland-Marshall College of Law at Cleveland State University. Together, the three discuss the convergence of cybersecurity and public policy with an emphasis on the concept of 'reasonable' security measures affording a data breach safe harbor for businesses.
View Details
In this episode of Cybersecurity Where You Are, co-hosts Tony Sager and Sean Atkinson are joined by Stacey Wright, former CIS employee and current Vice President of Cyber Resiliency Services at the Cybercrime Support Network. The discussion focuses on the common cyber scams malicious actors have been using for decades and offer advice for dealing with them.
Resources
- Cybercrime Support Network
- How to Protect Seniors Against Cybercrimes and Scams
- Common Cyber Hoax Scams
- Tech Support Call Scams
View Details
Resources
- Follow Brian Hajost on LinkedIn
- Prioritizing a Zero Trust Journey Using CIS Controls v8
- Webinar | Align and Achieve CMMC Compliance Utilizing CIS Best Practices
- Episode 11: Remote Attestation Helps Zero Trust
- CIS Critical Security Controls v8 Cybersecurity Maturity Model Certification Mapping
- Where Does Zero Trust Begin and Why is it Important?
In episode 26 of Cybersecurity Where You Are, co-host Tony Sager is joined by Brian Hajost, Chief Operating Officer at SteelCloud. They discuss some of the common issues around secure configuration management, the struggles that organizations face, and ways to overcome those challenges.
View Details
In this episode of Cybersecurity Where You Are, co-host Sean Atkinson is joined by Lou Smith, a Senior Information Security Intrusion Analyst at the Center for Internet Security. Smith has a background in Digital Forensics and previously worked for New York State's Cyber Command Center. The two discuss building digital forensics and incident response capabilities in-house. Tune in to learn about the skills you need and the tactics you can use to successfully implement an incident response plan at your organization.
Resources
- Six Tabletop Exercises to Help Prepare Your Cybersecurity Team
- Tabletop Exercises (TTX)
- 7 Reasons Tabletop Exercises Are A Must
- Incident Response Tabletop: Working with Law Enforcement and Insurers
- SANS Training via CIS CyberMarket
View Details
Resources
- Follow Guest Linnie Meehan on Twitter and Twitch
- US Cyber Challenge (USCC)
- CyberStart America
- Career Opportunities at CIS
- 11 of the Coolest Technical Jobs at CIS
In episode 24 of Cybersecurity Where You Are, co-host Tony Sager poses the question that many people interested in the industry ask: How do I start a career in cybersecurity?
To offer some insight, co-host Sean Atkinson joins cybersecurity professionals Linnie Meehan and Thomas Sager. Together, the three share their personal experiences, offer advice to those interested in a cybersecurity career, and remind listeners that persistence is key.
View Details
In Episode 23 of Cybersecurity Where You Are, hosts Tony Sager and Sean Atkinson are joined by our Vice President of Operations and Security Services, Josh Moulin. Together, the three share their thoughts on some of the topics that were discussed in our recent blog post, 2022 Cybersecurity Predictions to Watch Out For.
Resources
- 2022 Cybersecurity Predictions to Watch Out For
- Log4j Zero-Day Vulnerability Response
- Sign up for the MS-ISAC
- Establishing Basic Cyber Hygiene Through a Managed Service Provider
View Details
Resources:
- Information on Log4j
- CIS Critical Security Controls
- Essential Cyber Hygiene
In early January, the cybersecurity world was introduced to a new foe when researchers discovered a vulnerability in the code of a software library called Log4j. In the latest episode of Cybersecurity Where You Are, CIS CISO, Sean Atkinson, and CIS Chief Evangelist, Tony Sager, were joined by two colleagues who walked them through the steps CIS took to address the Log4j vulnerability.
View Details
In this edition of Cybersecurity Where You Are, CIS CISO, Sean Atkinson, and CIS Senior VP and Chief Evangelist, Tony Sager are joined by two members of the CIS podcast production team, Jason Forget, VP of Communications, and Chad Rogers, Digital Media Program Manager. Together they discuss this past year in cybersecurity, creating this podcast, and their favorite episodes.
View Details
Resources:
- Learn more about the EI-ISAC
- Election security tools and resources
In this edition of Cybersecurity Where You Are, CIS Senior VP and Chief Evangelist, Tony Sager welcomes Kathy Boockvar, Vice President of Election Operations and Support and Marci Andino, Director of the Elections Infrastructure Information Sharing and Analysis Center, or EI-ISAC. Together, they discuss the state of election security for state and local governments.
View Details
Resources:
- CIS Critical Security Controls
- About Panaseer
In this edition of Cybersecurity Where You Are, CIS Senior VP and Chief Evangelist, Tony Sager welcomes Thordis Stella Thorsteins, Senior Data Scientist at Panaseer. Panaseer provides a controls monitoring platform and has played a valuable role in the development of the CIS Critical Security Controls, as well as the implementation of the CIS Controls Assessment Specification. Together, Tony and Thordis discuss the role that data collection and automation play in cybersecurity.
View Details
Resources:
- Monthly Top 10 Malware
- CIS Critical Security Controls
- About the MS-ISAC
In this edition of Cybersecurity Where You Are, CIS Chief Information Security Officer (CISO), Sean Atkinson welcomes Randy Rose, CIS Sr. Director of Cyber Threat Intelligence. In the spirit of Halloween, they list the top five3 (and some honorable mentions) malware of all time – so far!
View Details
Resources
- Cybersecurity Awareness Month
- CIS Community Defense Model 2.0
- Verizon Data Breach Investigations Report
- SANS Security Awareness Training
- MITRE ATT&CK
Discussed in this podcast:
- Cybersecurity Awareness Month
- Psychology of cybersecurity
- Evolution of common cyber threats
- "Big picture" resources
In this edition of Cybersecurity Where You Are, CIS Chief Information Security Officer (CISO), Sean Atkinson welcomes Philippe Langlois of the Verizon Business Group and co-author of the Verizon Data Breach Investigations Report (DBIR). In celebration of Cybersecurity Awareness Month, the duo discuss the DBIR and version 2.0 of the CIS Critical Security Controls (CIS Controls) Community Defense Model (CDM). Both reports pull data from a community of experts and many different resources to provide a more holistic picture of cybersecurity.
View Details
Resources:
- About Kathleen Moriarty
- CIS Benchmarks
- CIS Critical Security Controls
- Tools for Vendors and Consultants
In this edition of Cybersecurity Where You Are, CIS Senior VP and Chief Evangelist, Tony Sager welcomes back Kathleen Moriarty, Chief Technology Officer for CIS. Together they discuss the role service providers play in the future of cybersecurity.
View Details
Episode Highlights:
- Why soft skills are important
- Top soft skills
- Building a company culture
Resources:
- CIS Careers
- Publication: Cybersecurity Quarterly
In this edition of Cybersecurity Where You Are, CIS Chief Information Security Officer (CISO), Sean Atkinson, and CIS Senior VP and Chief Evangelist, Tony Sager discuss soft skills and how they pertain to the the cybersecurity industry. Whether it is an an employee wanting to expand their career or an employer seeking a new hire, soft skills are just as important as technical knowledge.
View Details
Resources:
- Useapassphrase.com
- Password Policy Guide
- Related Blog: Password Policy Guide: Passphrases, Monitoring and More
- National Cybersecurity Awareness Month: MS-ISAC Tool Kit and Poster Contest
- Free to download: MS-ISAC 2021 Kids Safe Online Activity Book
In this edition of Cybersecurity Where You Are, CIS Chief Information Security Officer (CISO), Sean Atkinson counts down the top five ways families can be cyber smart. CIS Content Marketing Manager, Danielle Koonce, stops by to talk about what she does as a parent to keep her child safe from cyber-attackers.
View Details
Resources:
- CIS Twitter
- CIS LinkedIn
- CIS Critical Security Controls
- Related podcast: RC Manager at Frame.io, Mosi Platt answers the Atkinson 9
In this edition of Cybersecurity Where You Are, CIS Chief Information Security Officer (CISO), Sean Atkinson, and CIS Senior VP and Chief Evangelist, Tony Sager share part of themselves in this intimate episode. Taking a guest-free moment of asking them the 'Atkison 9', hosts turn the questions on themselves. Listen to them discuss their favorite CIS Critical Security Controls, the biggest waste of time in cybersecurity, and how they want to be remembered in the industry.
View Details
This week’s Cybersecurity Where You Are podcast highlights:
- The problem regulating cybersecurity
- Cybersecurity is currently the "Wild West"
- What makes cybersecurity different than other industries
- What roles different levels of government are taking
- Dispelling the mystery behind cybersecurity
Episode Resources
- CIS Controls
- Basic Cyber Hygiene
- Press Release
It can appear that cybersecurity practices are being built on the creative wizardry of technical experts rather than referential universal policy that everyone can abide by. In this edition of Cybersecurity Where You Are, host and Senior Vice President and Chief Evangelist Tony Sager for CIS welcomes guest Brian de Vallance, Alliance Outreach Coordinator for CIS. Together, they discuss the role government and technology experts play in the building of universal cybersecurity best practices and policy.
View Details
This week’s Cybersecurity Where You Are podcast highlights:
- Automated attestation processes
- Vendor attestation capabilities
- Root of trust via Trusted Platform Module (TPM)
- Method of verification for zero trust
Episode Resources
- Visit the CIS Website
- CIS Controls List
- About Kathleen Moriarty, Chief Technology Officer, CIS
- Related Blog on Zero Trust: Where Does Zero Trust Begin and Why is it Important?
In this edition of Cybersecurity Where You Are, host and CIS Chief Information Security Officer (CISO), Sean Atkinson welcomes guest Kathleen Moriarty, Chief Technology Officer (CTO) at CIS. Together, the duo discuss attestation in terms of hardware and software, and the process of performing a posture assessment.
View Details
This week’s Cybersecurity Where You Are podcast highlights:
- Why the medical industry is so appealing to attackers
- The challenges of protecting medical facilities
- How a defense-in-depth strategy plays a role in a hospital’s cybersecurity plan
- Malicious Domain Blocking and Reporting (MDBR) for hospitals
Episode Resources
- Visit the CIS Website
- The American Hospital Association
- Learn more about MDBR for hospitals
In this edition of Cybersecurity Where You Are, host and CIS Chief Information Security Officer (CISO), Sean Atkinson welcomes guests John Riggi and Ed Mattison. Riggi is the Senior Advisor for Cybersecurity for the American Hospital Association (AHA) and Mattison is the Executive Vice President of Operations and Security Services at CIS. Together they discuss how hospitals and other medical facilities can protect themselves against cyber-attacks.
View Details
Resources:
Highlights:
- The importance of information security governance
- Security vs. compliance
- Data – determining what you need and where to find it
- Understanding risk from a decision-basis
- Critical elements to fulfill business requirements
- Producing value in a compliance program
- Applying agility for continuous improvement
Good compliance = good security
Security is the practice of implementing effective technical controls to protect an organization’s digital assets. Compliance, on the other hand, is the application of that practice to meet regulatory or contractual requirements. Unfortunately, more often than not, organizations focus on compliance once a year when it’s time to certify that their “security is good.” The process of being compliant and secure should be a continuous process.
View Details
Resources:
- Visit the CIS Website
- Download the CIS Controls v8
- Download CIS Controls v8 Change Log
- Join a CIS Controls Community
Highlights:
- Everything has to be measurable
- Everything has to be achievable
- CIS Controls v8 must have a peaceful coexistence with cybersecurity frameworks
- The Controls need to be backed by data and able to defend against real-world threats
First Impressions Matter
The CIS Controls team and volunteers pretty much rewrote every word of v8 in an effort to modernize and consolidate the document. CIS Controls v8 is a lot more focused and less redundant than previous versions. Find out what people are saying about this new Version!
Feedback: Request, Manage, Gather, & Use for the Greater Good
Organizations big and small rely on the CIS Controls to defend against the most prevalent cyber-attacks against systems and networks. And, they count on the Controls team to do the best job they can for the greater good of the cybersecurity community.
View Details
Resources:
- What are the CIS Controls
- Learn more about CIS Controls v8
- Free Webinar | May 18, 2021: Sign up to hear about all the changes to the CIS Controls
- Frequently Asked Questions
In this edition of Cybersecurity Where You Are, host and CIS Senior Vice President and Chief Evangelist, Tony Sager welcomes guests Randy Marchany and Phyllis Lee. Marchany is the Chief Information Security Officer (CISO) at Virginia Tech, and Lee serves as Senior Director of the CIS Controls. The connection between the two guests is the CIS Controls – a prioritized set of Safeguards to mitigate the most prevalent cyber-attacks against systems and networks.
Highlights:
- History of the CIS Controls
- Guiding principles for CIS Controls v8
- CIS Controls ecosystem
- Practical implications for the Controls and real-world applications
- CIS Controls life cycle
Remember to subscribe to get the latest cybersecurity news and updates to Start Secure and Stay Secure.
View Details
Resources:
- EI-ISAC
- Elections Security Tools & Resources
-
PROTECT2020
In this edition of Cybersecurity Where You Are, host and CISO at the Center for Internet Security (CIS), Sean Atkinson welcomes guests Geoff Hale and Lew Robinson. Hale leads the Election Security Initiative at the Cybersecurity and Infrastructure Security Agency (CISA), while Robinson serves as CIS Vice President of Election Operations. Both agencies and both men, respectively, played a big role in the success of the 2020 General Election, which has been deemed the most secure election in American history.
Highlights:
- Elections...A Critical Infrastructure
- Strong Partnerships Make for Strong Collaborative Efforts
- Technical and physical controls that contributed to the 2020 General Election being the most secure election in history
- Steps taken to enhance communications and provide threat intelligence to state and local entities
- Collaborative process to provide stakeholder input to influence the approach to election security
- Strategies and techniques used to manage mis- and disinformation
- Efforts made to assist state and local election offices with best practice guidance
- Lessons learned from the 2020 General Election
Remember to subscribe to get the latest cybersecurity news and updates to Start Secure and Stay Secure.
View Details
Part 2 of a 2-part series
Resources:
- Listen to Part 1
- CIS website
- CIS SecureSuite Tools and Resources
- CIS Benchmarks
- CIS Controls (v8 coming Spring 2021)
- CIS CSAT (CIS Controls Self Assessment Tool)
- Community Defense Model (v2 coming Spring 2021)
In this week’s Cybersecurity Where You Are podcast, hosts Tony Sager and Sean Atkinson continue their conversation on cyber defense as a risk-based process. They discuss the actions and resources that help build and implement “defensive machinery” that support an organization’s current cyber defense plan and help it mature.
Highlights:
- A CISO’s First 90 days
- The Importance of a Strong Foundation
- Knowing Your Lineage
- Mapping to Regulatory Frameworks
- Tools: From Spreadsheets to CIS CSAT
- Sharing with the Group
Remember to subscribe to get the latest cybersecurity news and updates to Start Secure and Stay Secure.
View Details
Episode Resources:
- Blog: Assess, Remediate, and Implement with CIS SecureSuite: https://www.cisecurity.org/blog/assess-remediate-and-implement-with-cis-securesuite/
- Free Webinar: CIS Benchmarks and CIS-CAT Pro Tool Demo: https://www.cisecurity.org/webinar/cis-benchmarks-demo/
Part 1 of a 2-part series
Technology is ever-changing AND ever-evolving, creating an uncertainty amongst cybersecurity professionals – the defenders – in their pursuit of an effective cyber defense strategy. The uncertainty of the defender can justifiably be attributed to the uncertainty of the attacker. In this week’s Cybersecurity Where You Are podcast, hosts Tony Sager and Sean Atkinson introduce cyber defense as a risk-based process to reduce the overall probability and impact that a cyber-attack will have on an organization.
Cyber defense never ends
Cyber defense refers to the ability to prevent cyber-attacks from infecting a computer system or device; it involves anticipating adversarial cyber actions and countering intrusions. There’s no “one-size-fits-all” when it comes to cyber defense protocol or strategy. However, a good cyber defense strategy should aim to protect, prevent, detect, respond to, and recover from external and internal attacks. As technology expands, the complexity of cyber-attacks also evolves, forcing cyber defense initiatives and defenders of such, to do whatever they can to keep up.
OODA loop process
The OODA (Observe, Orient, Decide, Act) loop is a repetitive four-step decision-making process that focuses on gathering information, putting that information into context, making the most appropriate decision while also understanding that changes can be made as more data becomes available, and then taking action. The OODA loop is especially applicable to cybersecurity and cyber defense where agility and repetition (by the defender) potentially overcomes that of the attacker.
Fog of More
While cyber defense is an abstract model, cybersecurity defenders have to actually do concrete things. It initially comes down to having a plan in place and asking the right questions: What data do we have? Where is it? What do we do with it?
Asking the right questions (for clarity) eliminates the Fog of More (coined by Tony Sager, of all people) – the overload of defensive support (i.e., more options, more tools, more knowledge, more advice, and more requirements, but not always more security).
An effective cyber defense program requires defenders to gather information and data, put that data into context, make decisions, take action, and then REPEAT, REPEAT, REPEAT.
View Details
Resources:
- Find us at https://www.cisecurity.org/
- Third-party Risk Association: https://www.tprassociation.org/
- National Institute of Standards and Technology (NIST): https://www.nist.gov/
- CIS Controls: https://www.cisecurity.org/controls/
Can a risk assessment questionnaire be the catalyst for true change to the entire vendor cybersecurity ecosystem? Cybersecurity Where You Are podcast host Sean Atkinson welcomes guest Ryan Spelman, former CIS employee, and now Managing Director at Duff & Phelps on their CYBERCLARITY360 team. Together, Sean and Ryan discuss tactics companies can use to better understand their cyber-risk posture and how stronger relationships between companies and their third parties impact the industry as a whole.
Better use of the third-party risk assessment questionnaire
The go-to “third-party risk assessment questionnaire” being used as a one-and-done exercise is an all too common practice. While completing these questionnaires meets certain regulatory requirements, truly managing risk is about acting on the data collected - not just collecting it.
There is a misconception that the questionnaire is for general information collection and that the same questions can apply to all vendors. Some questions, such as those about overseas relations or services, may be applicable to all vendors. But to more accurately assess a third party’s risk it is important to customize the questions to match the vendor's use case and scope.
This episode shares how an organization can start drafting these inquiries.
Once the questionnaire is crafted, completed, and returned, a plan should also be in place for how to address the issues that arise from the submitted answers.
Beyond the questionnaire – communication is key
The issue of third-party management rests in the hands of both the company and the vendor. Clear, accurate, and truthful communication between both parties makes both entities ultimately stronger.
Building a stronger security ecosystem
This is an “area where the common good can happen,” says Ryan. If a company can make the third party’s security posture better, then everyone else who uses this third party is made better. It ultimately makes a measurable difference in the entire vendor ecosystem.
The Atkinson 9
In the vein of another famous interviewer, Sean asked Ryan his “Atkinson 9,” a quick Q&A about security. Listen now to find out what our guest said!
View Details
Resources
- Find us at https://www.cisecurity.org/
- Blog: 2021 Cybersecurity Trends to Prepare For: https://www.cisecurity.org/blog/2021-cybersecurity-trends-to-prepare-for/
- Blog: Where Does Zero Trust Begin and Why is it Important?: https://www.cisecurity.org/blog/where-does-zero-trust-begin-and-why-is-it-important/
- CIS Controls: https://www.cisecurity.org/controls/
- Cybercrime Support Network (CSN: https://cybercrimesupport.org/
2020 was considered “the year like no other”. The industry saw a mass convergence of social issues with cyber issues due to the pandemic, the elections, and the SolarWinds supply chain issue. Cybersecurity resilience was tested and it was crucial that the industry adapt quickly.
With the onset of the COVID-19 pandemic in March of 2020 many organizations went fully remote, including CIS. CIS had to be agile and the cybersecurity industry had to adapt to new challenges with a growing remote workforce.
The Trends
Risk management strategies such as ways to identify gaps, how to best implement the CIS Controls, data management, and privacy requirements were the foundations for crisis management.
Ransomware is here to stay as a top cyber threat. It moved from the lone hacker to a capitalist business structure where the software just needs to be purchased and used as opposed to needing to build it yourself.
Zero Trust: Sean uses the analogy of “the castle and the moat”. Today the drawbridge is always open and things are going in and out without the ability to monitor it all. Zero Trust is setting the new tone for security practices.
What the Future (May) Hold
Small Businesses need support: The weight of responsibility to small businesses to accommodate the assessment evaluations for risk management is a huge burden.
A Diminishing Cyber Workforce: There is a growing concern about the shortage of cybersecurity professionals.
The Role of Government: With the change in government, like we have in 2021, there is a change in the way government thinks about priorities.
View Details
Co-hosts Sean Atkinson and Tony Sager welcome you to the CIS podcast Cybersecurity Where you Are.
This episode gives you an overview of what the Center for Internet Security is, how the co-hosts grew with the industry, and the importance of basic cyber hygiene.
- Find us at www.cisecurity.org
- Check out the CIS Controls: https://www.cisecurity.org/controls/cis-controls-list/
- Learn more about Basic Cyber Hygiene: https://www.cisecurity.org/blog/cleaning-up-a-definition-of-basic-cyber-hygiene/
The Center for Internet Security is a community-driven nonprofit, responsible for the CIS Controls® and CIS Benchmarks™, globally recognized best practices for securing IT systems and data. We lead a global community of IT professionals to continuously evolve these standards to proactively safeguard against emerging threats.
CIS is home to the Multi-State Information Sharing and Analysis Center® (MS-ISAC®), the trusted resource for cyber threat prevention, protection, response, and recovery for U.S. State, Local, Tribal, and Territorial government entities, and the Elections Infrastructure Information Sharing and Analysis Center® (EI-ISAC®), which supports the rapidly changing cybersecurity needs of U.S. elections offices.
Meet co-host Tony Sager - Tony has over 43 years of experience in the industry most of which was with the National Security Agency (NSA). With a background as a mathematician, he worked at the NSA in the Communications Security Interim Program focusing on the security of U.S. systems. He worked mostly on cryptography and confidentiality in the interest of the country’s defense. He then moved to Computer Science when computers began to move from large systems in buildings to at home workstations (do you remember the Apple2+?). Tony witnessed the transition of cybersecurity from mathematics to information and communications and found himself in great company helping to develop CIS over the passed 20 years.
Meet co-host Sean Atkinson – Sean lived in England for about 20 years before moving back to the U.S. His background was not actually in computer science but carried an MBA in Business but with a concentration in Technology Management. He credit the book “A Business Data Networks and Telecommunications” by Raymond Panko for getting him into Network and Technology Specialization. He then worked as a IT Auditor and in 2004 found himself working on Section 404 projects. He then worked in State Government moving his way up to security Manager implementing PeopleSoft when adding security to the software lifecycle was in its infancy. He then moved to the Dept of Defense and now has worked with CIS as CISO to frame best practices and implementation.
Basic Cyber Hygiene - We know cybersecurity is an issue for any business, but where do you start? By looking at your data, networks, and systems from a risk perspective you can then implement means to protect it. There are foundational best practices that everyone can do and should do. Tony and Sean will touch on the CIS Controls – the prioritized set of actions to protect your organization and data from known cyberattack vectors – and what actions to take first.