Cybersecurity Where You Are (audio)

Center for Internet Security

Welcome to audio version of “Cybersecurity Where You Are,” the podcast of the Center for Internet Security® (CIS®). Cybersecurity affects us all, so join us on Wednesdays as Sean Atkinson, CISO at CIS; Tony Sager, SVP & Chief Evangelist at CIS; and Ed Skoudis, President of the SANS Technology Institute discuss trends and threats, explore security best practices, and interview experts in the industry. Together, we’ll clarify these issues, Creating Confidence in the Connected World®. Subscribe to the video version of our podcast here: https://fast.wistia.net/embed/channel/0l9fss300m?wchannelid=0l9fss300m.

  1. 1h ago

    Episode 204: FWC26 and the New Bar for Event Security

    In episode 204 of Cybersecurity Where You Are, Ryan Winmill, Chief Security Officer and Vice President of FIFA World Cup Boston, and John Cohen, Executive Director of the Office of Strategic Programs and Initiatives at the Center for Internet Security® (CIS®). Together, they discuss how FIFA World Cup 2026 (FWC26) — secured through an unprecedented tripartite governance framework, $625 million in U.S. Congressional funding, and real-time intelligence that stopped a swatting attempt at the finals — set a new standard for proactive event security worldwide. Here are some highlights from our episode: 01:18. The "unprecedented" governance framework created for FWC2603:53. The role of CIS as a force multiplier for FIFA, host regions, and other partners11:00: Why you can't trust the person with an ego in large-scale event security planning13:23. How the threat environment evolved over the previous three World Cup tournaments17:23. A new bar for proactive event security going forward18:43. How CIS provided quality control that helped to mitigate swatting calls during FWC2621:55. Unique approaches used by host regions to better understand the World Cup fanbase23:15: How counterfeit FIFA volunteer uniforms triggered a cross-city credentialing response26:46. Recommendations for future large-scale event host cities30:19: Ryan's recommendation to future host cities: "Call CIS before you get started"Resources Special Event Risk Analysis & Advisory ServicesEpisode 196: Securing FIFA World Cup 2026 CollaborativelyInside the Security Operation Behind the 2026 FIFA World Cup3 Lessons for Securing Large-Scale Events: Inside FIFA World Cup 2026Securing FIFA World Cup 2026 With a Collective Defense ApproachIf you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.

  2. Aug 26

    Episode 202: Delineating AI Security and Cybersecurity

    In episode 202 of Cybersecurity Where You Are, Sean Atkinson and Ed Skoudis sit down with Rob T. Lee, Chief of Research & Chief AI Officer at the SANS Institute. Together, they explore how the implications of multiple 2026 sandbox escapes of artificial intelligence (AI) models are starting to delineate AI security and cybersecurity. Here are some highlights from our episode: 02:00. The historical context of one AI model's 2026 sandbox escape03:26. The impact of ethics, guardrails, and misconfigurations in an AI containment breach06:08. Why context matters when talk of AI models "going rogue" surfaces11:49. How history helps us to delineate AI security and cybersecurity13:47. A new skill and mindset to match our refined AI risk understanding15:43. Rules and cybersecurity implementation as a possible way forward19:04. The double-edged sword of restricting access to open-weight models23:25. Recommendations for keeping up with what's changing in the AI security space25:51. Rob's advice: To learn how to defend a thing, try learning how to build it first28:23. AI governance and seeing through the "slop" to informed conversation29:54. The use of AI to learn more about and discuss AI security for years to comeResources OpenAI says its AI technology acted on its own in an ‘unprecedented’ hack of another companyPacing model development in an era of cyber-critical capabilitiesBlack Hat USA 2026 | The 'Breaking' News: The OpenAI–Hugging Face IncidentEpisode 193: AI Security and Responsibility in EO 14409The AI Daily Brief — Daily AI News & AnalysisAI Playbooks for SLTT Cybersecurity LeadersSANS Cybersecurity SummitsSANS NewsBitesIf you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.

  3. Aug 12

    Episode 200: Alan Paller's Vision and Our Next Chapter

    In episode 200 of Cybersecurity Where You Are, Sean Atkinson, Tony Sager, and Ed Skoudis sit down with Frank Reeder, Co-Founder and Founding Chair of the Center for Internet Security® (CIS®). Together, they reflect on how Alan Paller's vision continues to drive CIS forward. In the spirit of that vision, this milestone episode also marks a new chapter for the podcast: Ed Skoudis joins as co-host of Cybersecurity Where You Are. Here are some highlights from our episode: 01:09. The two complementary missions of CIS02:55. Three defining moments that have shaped CIS into the organization it is today08:10. The story of naming CIS10:31. How CIS and SANS advance Alan Paller's vision of bringing people together13:50. Personal anecdotes of Alan Paller as a connector of people15:45. "What would Alan do?" A question that continues to guide CIS and SANS22:00. How CIS security best practices are emblematic of helping others27:12. CIS's "secret sauce" as a trusted, neutral platform for cybersecurity collaboration29:53. How CIS can continue to embody Alan Paller's philosophy into the future37:47. A special announcement: Ed Skoudis as a new co-host on the podcastResources CIS Benchmarks® ListCIS Critical Security Controls®Multi-State Information Sharing and Analysis Center®Episode 114: 3 Board Chairs Reflect on 25 Years of CommunityAlan Paller Laureate ProgramSANS Difference Makers AwardsIf you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.

  4. Aug 5

    Episode 199: Translating Cyber Risk into Business Decisions

    In episode 199 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager sit down with Chris Painter, Chair of the Risk Committee and Board Member at the Center for Internet Security® (CIS®). Together, they discuss how chief information security officers (CISOs) can support the work of translating cyber risk into business decisions by Boards. Here are some highlights from our episode: 00:50. Introductions to Chris01:36. The single biggest translation error Chris has seen CISOs make07:38. Cyber risk quantification: An opportunity to go beyond translation for Boards09:25. How ransomware changed Boards' understanding of cyber risks' business impact10:45. The value of tabletop exercises (TTX) and other simulations in creating shared language13:26. Recommendations on how to make the most of a TTX18:37. Risk modeling and how artificial intelligence (AI) complicates probability estimations21:51. "Pressure" (2026) as an illustration of making good, not 100% accurate, estimations22:58. How growing public awareness of cyber is reshaping CISOs' conversations with Boards25:55. The importance of walking Boards through risk mitigation steps with AI as an example29:31. A recommendation for how CISOs can learn what directors care about30:15. From "wizardry" to familiarity: An ongoing generational shift around cyberResources Episode 183: The Role of CISO in Supporting Risk TranslationEpisode 187: The Role of a CISO as a Strategic StorytellerEpisode 192: How Leaders Balance Expertise and CommunicationHow Risk Quantification Tests Your Reasonable Cyber DefenseCIS RAM (Risk Assessment Method)Leveraging Generative Artificial Intelligence for Tabletop Exercise DevelopmentCIS Controls v8.1 Incident Response Policy TemplateYou Have a Cybersecurity Incident. Now What?Prompt Injections: The Inherent Threat to Generative AI"Pressure" | Official Website | 29 May 2026If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.

  5. Jul 29

    Episode 198: AI Privacy from a Risk-Based Perspective

    In episode 198 of Cybersecurity Where You Are, Sean Atkinson discusses artificial intelligence (AI) and privacy from a risk-based cybersecurity perspective. Together, he explores how organizations and individuals can assess AI risk, apply governance frameworks, evaluate third-party AI services, and balance innovation with due diligence. Here are some highlights from our episode: 00:41. Framing the conversation around AI, privacy, and risk-based controls02:22. Due diligence and ethical considerations around AI products and services03:14. Data minimization and transparency as foundations for AI privacy04:46. Privacy impact assessments as a way to understand AI data collection and use05:42. AI governance and the tension between implementation velocity and risk management10:08. The use of existing data flows and controls in AI assessments11:57. Algorithmic transparency and the challenge of understanding AI decision making13:47. Standards, frameworks, and data sovereignty in AI privacy governance15:12. Encryption, anonymization, tokenization, and federated learning as privacy safeguards16:40. The need to shift stakeholder input left in AI development and deployment lifecycles19:13. Building literacy around security, data management, privacy, and AI risk23:40. The value of cross-functional and written assessment criteria for AI risk26:21. A call to action for keeping pace with AI privacy and and innovation riskResources CIS Controls v8.1.2 AI Security Guidance WorkbookEpisode 105: Context in Cyber Risk QuantificationService Provider Management Policy Template for CIS Control 15EU AI Act: first regulation on artificial intelligenceAI Risk Management FrameworkIAPP AI Governance CenterEpisode 120: How Contextual Awareness Drives AI GovernanceSecure by Design v1.1 A Guide to Assessing Software Security PracticesReasonable CybersecurityIf you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.

  6. Jul 22

    Episode 197: AI-ready OT Data Begins with Understanding

    In episode 197 of Cybersecurity Where You Are, Sean Atkinson sits down with Ben Wilcox, Chief Technology Officer and Chief Information Security Officer at ProArch; and Ed Skoudis, President of SANS Technology Institute. Together, they discuss artificial intelligence (AI), operational technology (OT) data, and how understanding creates the foundation for AI-ready OT data. Here are some highlights from our episode: 00:54. Introductions to Ben and Ed02:16. How we understand and integrate AI into OT environments04:30. How OT diverges from information technology (IT) in data responsibilities05:23. Opportunities for AI to assist OT06:33. The importance of meeting OT systems where they are08:10. A passive and incremental approach that respects the operations machines are doing12:29. Efficiency gains, public safety improvements, and other benefits of AI-ready OT data17:47. What lifecycle management, asset hierarchies, and governance look like for OT data22:14. The promise of AI to help to make OT environments understandable23:19. A team sport: How IT and OT can work together to understand assets and data28:38. The need for translation in IT-OT communication29:01. Recommendations for how to make OT data AI readyResources CIS Critical Security Controls®CIS Controls version 8.1 ICS WorkbookArtificial Intelligence and Large Language Models Companion GuideCIS Controls v8.1 Enterprise Asset Management Policy TemplateCIS Controls v8.1 Software Asset Management Policy TemplateCIS Controls v8.1 Data Management Policy TemplateCIS Controls v8.1 Account & Credential Management Policy TemplateEstablishing Essential Cyber HygieneProArchCybersecurity for Critical InfrastructureEpisode 77: Data's Value to Decision-Making in CybersecurityEpisode 183: The Role of CISO in Supporting Risk TranslationIf you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.

About

Welcome to audio version of “Cybersecurity Where You Are,” the podcast of the Center for Internet Security® (CIS®). Cybersecurity affects us all, so join us on Wednesdays as Sean Atkinson, CISO at CIS; Tony Sager, SVP & Chief Evangelist at CIS; and Ed Skoudis, President of the SANS Technology Institute discuss trends and threats, explore security best practices, and interview experts in the industry. Together, we’ll clarify these issues, Creating Confidence in the Connected World®. Subscribe to the video version of our podcast here: https://fast.wistia.net/embed/channel/0l9fss300m?wchannelid=0l9fss300m.

You Might Also Like