Trust and Turbulence

Josh Brickman

Joshua Brickman spent more than 20 years working in cybersecurity certifications, government assurance, and global security regulation. This podcast explores the intersection of security, AI, regulation, and trust — from Common Criteria and FIPS 140 to post-quantum cryptography, supply chain security, cloud assurance, and the EU Cyber Resilience Act. The show turns complex technical and policy issues into practical conversations for businesses, policymakers, technologists, and consumers.

エピソード

  1. 8月13日

    Can We Automate Trust? The Future of FIPS 140 and Common Criteria

    Can we automate trust? And if we can, what happens to cybersecurity certification as we know it?In this episode of Trust & Turbulence, I’m joined by longtime colleagues Ashit Vora and Shawn Geddis, who are both building technologies designed to rethink how security certification gets done — but they’re approaching the problem in very different ways.Ashit is using AI to automate Common Criteria certification, with an eye toward expanding into areas such as the EU Cyber Resilience Act. Shawn is taking an intelligent automation (IA) approach to FIPS 140 and other assurance processes, emphasizing deterministic testing, standardized data, and machine-to-machine evidence exchange.We dig into some big questions:• What’s actually broken in today’s FIPS 140 and Common Criteria processes? • What’s the difference between AI and intelligent automation — and where does each belong? • Can automated testing and evidence ever earn the same trust as traditional human-driven evaluation? • What happens to certification labs as more of the work becomes automated? • Could continuous certification replace today’s point-in-time model? • Will the EU Cyber Resilience Act (CRA) accelerate automation simply because traditional compliance cannot scale? • How should Common Criteria and the broader standards community deal with AI? • And what happens when increasingly fragmented global requirements undermine the old goal of “evaluate once, sell everywhere”? This is also a conversation among three people who have worked together in the FIPS and Common Criteria community for well over a decade, so we get into some history, war stories, disagreements, and more than a few analogies — including teddy bears, taxes, Britney Spears and building a house.Can we really automate trust? Or does human judgment always have to remain at the center of cybersecurity assurance?That’s what we explore in this episode.If you enjoy Trust & Turbulence, please like, subscribe, and share your thoughts in the comments — particularly where you think AI and automation belong in the future of cybersecurity certification.About the GuestsShawn GeddisShawn Geddis spent more than 25 years at Apple, where he built the first Apple Platform Security Certifications Program and led engineering work for global platform certifications. He also built Apple’s SECLAB, its NVLAP-accredited first-party cryptographic laboratory, serving as lab manager, tooling developer, and—in his words—“evidence whisperer.” Shawn has since founded Katalyst LLC, focused on developing approachable automation and tooling for security certification.Ashit VoraAshit Vora is Co-Founder of Autonomi, an AI-enabled automation platform focused on transforming standards-based product security certification. Previously, Ashit co-founded Acumen Security, which grew into a leading product security certification provider before being acquired by Intertek. Earlier, he led Cisco’s U.S. government certification business supporting programs enabling approximately $1.5 billion in annual revenue. His work spans more than two decades of product security, certification, testing, standards, and commercialization. Music by Mikhail Smusev from PixabayLogo

  2. 7月3日

    The Perpetual Student with Jim West

    In this episode of Trust and Turbulence, I sit down with cybersecurity leader, author, podcaster, and lifelong learner Jim West. From his early days repairing computers at CompUSA to advising senior government leaders on cybersecurity, quantum computing, and national security, Jim's career has been anything but ordinary.We discuss cybersecurity, AI, quantum computing, the future of digital trust, life in the Middle East, career development, and why Jim proudly calls himself a "perpetual student."Whether you're a cybersecurity professional, technology enthusiast, or simply curious about how today's leaders navigate a rapidly changing world, this conversation offers valuable insights and plenty of memorable stories.Topics Discussed• Lifelong learning and professional growth• Cybersecurity leadership and national security• Commercial Solutions for Classified (CSfC)• Quantum computing and post-quantum cryptography• Artificial intelligence and deepfakes• International travel and cultural perspectives• Movies, creativity, and thinking differentlyGuest: Jim West, Author, Podcaster, Cybersecurity ExpertHosted by: Joshua Brickman 00:17 Meet Jim West02:14 The Perpetual Student Mindset13:25 Jim's Origin Story in IT & Cyber14:26 Iraq & Working Near the President17:18 25+ Years Living Overseas19:49 CSfC & Common Criteria Deep Dive38:32 Cybersecurity for Everyday Life46:00 The Quantum Threat & Post-Quantum Crypto56:27 Movie Review Wrongs01:05:32 Where to Find Jim WestMusic by Mikhail Smusev from PixabaySocials:LinkedIn: https://www.linkedin.com/in/jimwest1/https://jimwestauthor.com/https://topcyberpro.com/

番組について

Joshua Brickman spent more than 20 years working in cybersecurity certifications, government assurance, and global security regulation. This podcast explores the intersection of security, AI, regulation, and trust — from Common Criteria and FIPS 140 to post-quantum cryptography, supply chain security, cloud assurance, and the EU Cyber Resilience Act. The show turns complex technical and policy issues into practical conversations for businesses, policymakers, technologists, and consumers.