Cybersecurity Where You Are (video)

Center for Internet Security

Welcome to video version of “Cybersecurity Where You Are,” the podcast of the Center for Internet Security® (CIS®). Cybersecurity affects us all, so join us on Wednesdays as Sean Atkinson, CISO at CIS; Tony Sager, SVP & Chief Evangelist at CIS; and Ed Skoudis, President of the SANS Technology Institute discuss trends and threats, explore security best practices, and interview experts in the industry. Together, we’ll clarify these issues, Creating Confidence in the Connected World®. Subscribe to the audio version of our podcast here: https://fast.wistia.net/embed/channel/wbyhaw35xf?wchannelid=wbyhaw35xf.

  1. 4d ago ·  Video

    Episode 207: AI Risk Management — A Trust Relationship

    In episode 207 of Cybersecurity Where You Are, Sean Atkinson makes the case for treating artificial intelligence (AI) not as software but as an ongoing trust relationship. He highlights the value of integrating best practices from regulations like the EU AI Act, walks through the three stages of an AI governance lifecycle, and explains how AI risk management fits into organizational governance, change management, and other business processes. Here are some highlights from our episode: 01:16. The trust component of AI governance02:02. A need to align to regulatory best practices and bring them into AI risk management03:47. Advice: Contextualize, don't generalize, your risks associated with AI use04:40. Common questions that lead to AI governance as a requirement06:59. Grounding an agile AI governance process on foundational principles07:46. How the "fortress" approach overlooks the relationship element of AI security09:51. A direct invitation: Listener feedback on AI governance thinking11:44. Evaluating trust and relationship in machine learning and generative AI14:04. The role of human oversight in realizing AI as a method that gets to a solution quicker14:53. AI governance boards: A potential solution to elevating AI literacy internally16:00. AI governance lifecycle: Three phases from current business processes to value generation18:55. Overview of the future of AI security23:16. The need for foundational security controls and AI-specific controls25:00. AI governance assessment: Why it needs to happen across the organization26:28. How AI governance ties into organizational governance29:49. Ethics and responsible AI practice29:57. Change management considerations with AI deployment30:35. A concluding call to action to get stronger togetherResources CIS Critical Security Controls®Episode 198: AI Privacy from a Risk-Based PerspectiveEpisode 122: DeepSeek AI Security and Utility ConsiderationsEpisode 120: How Contextual Awareness Drives AI GovernanceAI Playbooks for SLTT Cybersecurity LeadersCIS Controls v8.1.2 AI Security Guidance WorkbookGuide to Implementation Groups (IG): CIS Critical Security Controls v8.1Mapping and Compliance with the CIS ControlsIf you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.

    Episode 207: AI Risk Management — A Trust Relationship
  2. Sep 23 ·  Video

    Episode 206: Trust and Influence as CISO Survival Skills

    In episode 206 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager speak with Julie Morris, Founder and Head of Thought Leadership at Persona Media, about why trust and influence have become survival skills for today's CISOs. Julie breaks down three types of organizational power, explains why the "good guys" resist the language of influence, and offers a practical starting point for anyone who's ever felt like PowerShell was the only power they understood. Here are some highlights from our episode: 02:13. From old to new: A shift in how trust and influence factor into organizational structures04:24. The three kinds of power in an organization: hard, soft, and network09:59. Wise advice: Build your personal and professional network first11:07. How influence multiplies confidence with network power12:03. Inertia, fear, and status quo: overcoming the emotional reactions that oppose change18:12. How Sean uses the power of "slow down," not "no," to support AI transformation20:49. Why good thought leadership starts with empathy and self awareness24:32. Building organizational processes that "trigger" a change in CISOs' trust and influence26:30. Hugging Face as an example of how triggering moments become lessons27:42. What Tony Soprano has to do with measuring trust and influence30:47. Reality check: Every information gap gets filled one way or another32:15. The power of community and shared ideas in figuring out thought leadership together36:09: Advice: Be in the "river" of your network to go where you want to go37:34. How understanding of shared values helps to overcome imposter's syndromeResources CIS Critical Security Controls®Episode 183: The Role of CISO in Supporting Risk TranslationEpisode 187: The Role of a CISO as a Strategic StorytellerEpisode 192: How Leaders Balance Expertise and CommunicationEpisode 199: Translating Cyber Risk into Business DecisionsThe Myth of Mythos: What It Means For Information SecurityEpisode 202: Delineating AI Security and CybersecurityIf you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.

    Episode 206: Trust and Influence as CISO Survival Skills
  3. Sep 16 ·  Video

    Episode 205: Secure by Design — Now Updated for AI

    In episode 205 of Cybersecurity Where You Are, Tony Sager speaks with Phyllis Lee, VP of SBP Content Development at the Center for Internet Security®(CIS®), and Steve Lipner, Executive Director of SAFECode. Together, they discuss how an updated document from CIS and SAFECode gives concrete guidance on what artificial intelligence (AI) means for your Secure by Design process. Here are some highlights from our episode: 02:17. A refresher on making Secure by Design digestible for end organizations02:57. Distillation and prescriptive guidance: The value provided by CIS06:53. An overview of Butler Lampson's "Gold Standard of Security"07:03. How a shift in approach to Secure by Design led to the founding of SAFECode09:42. The importance of verification requirements for what developers have done12:54. A product of CIS pragmatism: Prioritization relative to the development environment20:06. Artifacts as evidence of secure software development at work30:15. How the updated document provides guidance around AI30:45. What AI creates instead of new classes of vulnerabilitiesResources CIS Critical Security Controls® (CIS Controls®)Secure by DesignSecure by Design v1.1 A Guide to Assessing Software Security PracticesTurning Secure Software Development into a Measurable PracticeCIS and SAFECode Release Secure by Design v1.1: A Guide to Assessing Software Security PracticesEpisode 164: Secure by Design in Software DevelopmentCIS Critical Security Control 16: Application Software SecurityGuide to Implementation Groups (IG): CIS Critical Security Controls v8.1Episode 200: Alan Paller's Vision and Our Next ChapterFrom Prompts to Protocols: The Security Blueprint for Enterprise AIMythos AI: What Actually Matters for Cybersecurity LeadersIf you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.

    Episode 205: Secure by Design — Now Updated for AI
  4. Sep 9 ·  Video

    Episode 204: FWC26 and the New Bar for Event Security

    In episode 204 of Cybersecurity Where You Are, Sean Atkinson speaks with Ryan Winmill, Chief Security Officer and Vice President of FIFA World Cup Boston, and John Cohen, Executive Director of the Office of Strategic Programs and Initiatives at the Center for Internet Security® (CIS®). Together, they discuss how FIFA World Cup 2026 (FWC26) — secured through an unprecedented tripartite governance framework, $625 million in U.S. Congressional funding, and real-time intelligence that stopped a swatting attempt at the finals — set a new standard for proactive event security worldwide. Here are some highlights from our episode: 01:18. The "unprecedented" governance framework created for FWC2603:53. The role of CIS as a force multiplier for FIFA, host regions, and other partners11:00. Why you can't trust the person with an ego in large-scale event security planning13:23. How the threat environment evolved over the previous three World Cup tournaments17:23. A new bar for proactive event security going forward18:43. How CIS provided quality control that helped to mitigate swatting calls during FWC2621:55. Unique approaches used by host regions to better understand the World Cup fanbase23:15. How counterfeit FIFA volunteer uniforms triggered a cross-city credentialing response26:46. Recommendations for future large-scale event host cities30:19. Ryan's recommendation to future host cities: "Call CIS before you get started"Resources Special Event Risk Analysis & Advisory ServicesEpisode 196: Securing FIFA World Cup 2026 CollaborativelyInside the Security Operation Behind the 2026 FIFA World Cup3 Lessons for Securing Large-Scale Events: Inside FIFA World Cup 2026Securing FIFA World Cup 2026 With a Collective Defense ApproachIf you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.

    Episode 204: FWC26 and the New Bar for Event Security
  5. Aug 26 ·  Video

    Episode 202: Delineating AI Security and Cybersecurity

    In episode 202 of Cybersecurity Where You Are, Sean Atkinson and Ed Skoudis sit down with Rob T. Lee, Chief of Research & Chief AI Officer at the SANS Institute. Together, they explore how the implications of multiple 2026 sandbox escapes of artificial intelligence (AI) models are starting to delineate AI security and cybersecurity. Here are some highlights from our episode: 02:00. The historical context of one AI model's 2026 sandbox escape03:26. The impact of ethics, guardrails, and misconfigurations in an AI containment breach06:08. Why context matters when talk of AI models "going rogue" surfaces11:49. How history helps us to delineate AI security and cybersecurity13:47. A new skill and mindset to match our refined AI risk understanding15:43. Rules and cybersecurity implementation as a possible way forward19:04. The double-edged sword of restricting access to open-weight models23:25. Recommendations for keeping up with what's changing in the AI security space25:51. Rob's advice: To learn how to defend a thing, try learning how to build it first28:23. AI governance and seeing through the "slop" to informed conversation29:54. The use of AI to learn more about and discuss AI security for years to comeResources OpenAI says its AI technology acted on its own in an ‘unprecedented’ hack of another companyPacing model development in an era of cyber-critical capabilitiesBlack Hat USA 2026 | The 'Breaking' News: The OpenAI–Hugging Face IncidentEpisode 193: AI Security and Responsibility in EO 14409The AI Daily Brief — Daily AI News & AnalysisAI Playbooks for SLTT Cybersecurity LeadersSANS Cybersecurity SummitsSANS NewsBitesIf you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.

    Episode 202: Delineating AI Security and Cybersecurity
  6. Aug 12 ·  Video

    Episode 200: Alan Paller's Vision and Our Next Chapter

    In episode 200 of Cybersecurity Where You Are, Sean Atkinson, Tony Sager, and Ed Skoudis sit down with Frank Reeder, Co-Founder and Founding Chair of the Center for Internet Security® (CIS®). Together, they reflect on how Alan Paller's vision continues to drive CIS forward. In the spirit of that vision, this milestone episode also marks a new chapter for the podcast: Ed Skoudis joins as co-host of Cybersecurity Where You Are. Here are some highlights from our episode: 01:09. The two complementary missions of CIS02:55. Three defining moments that have shaped CIS into the organization it is today08:10. The story of naming CIS10:31. How CIS and SANS advance Alan Paller's vision of bringing people together13:50. Personal anecdotes of Alan Paller as a connector of people15:45. "What would Alan do?" A question that continues to guide CIS and SANS22:00. How CIS security best practices are emblematic of helping others27:12. CIS's "secret sauce" as a trusted, neutral platform for cybersecurity collaboration29:53. How CIS can continue to embody Alan Paller's philosophy into the future37:47. A special announcement: Ed Skoudis as a new co-host on the podcastResources CIS Benchmarks® ListCIS Critical Security Controls®Multi-State Information Sharing and Analysis Center®Episode 114: 3 Board Chairs Reflect on 25 Years of CommunityAlan Paller Laureate ProgramSANS Difference Makers AwardsIf you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.

    Episode 200: Alan Paller's Vision and Our Next Chapter

Ratings & Reviews

5
out of 5
13 Ratings

About

Welcome to video version of “Cybersecurity Where You Are,” the podcast of the Center for Internet Security® (CIS®). Cybersecurity affects us all, so join us on Wednesdays as Sean Atkinson, CISO at CIS; Tony Sager, SVP & Chief Evangelist at CIS; and Ed Skoudis, President of the SANS Technology Institute discuss trends and threats, explore security best practices, and interview experts in the industry. Together, we’ll clarify these issues, Creating Confidence in the Connected World®. Subscribe to the audio version of our podcast here: https://fast.wistia.net/embed/channel/wbyhaw35xf?wchannelid=wbyhaw35xf.

You Might Also Like