The Briefing with Dr. Tuboise Floyd

Dr. Tuboise Floyd

ABOUT THE PODCAST The Briefing with Dr. Tuboise Floyd The Briefing is for leaders who build, approve, procure, govern, or certify consequential technology. Hosted by Dr. Tuboise Floyd, Founder and Principal, Decision Assurance at Human Signal, the show examines the operating reality beneath technology strategy: decision authority, accountability, controls, evidence, critical infrastructure, and the conditions that produce institutional failure. The market is crowded with technology noise, checklists, and compliance theater. The Briefing focuses on the harder question: What governance infrastructure must exist before autonomous and emerging systems create exposure that leadership cannot explain, defend, or control? Episodes use Human Signal’s TAIMScore™, GASP™ Diagnostic, L.E.A.C. Protocol™, and Failure Files™ approaches to examine real-world failures, identify structural risk, and surface the decisions leaders must make before scrutiny arrives. Produced with Creative Director Jeremy Jarvis, The Briefing covers AI governance, cyber risk, post-quantum readiness, critical infrastructure, government contracting, and the builder economy. New episodes, visual briefings, and practical playbooks: https://humansignal.io/thebriefing The Briefing is a Human Signal production. Human Signal is an independent decision-assurance advisory and research platform. DISCLOSURE All episode content, including analysis, case studies, and framework applications, is provided for educational and informational purposes only. Nothing in this podcast constitutes legal, regulatory, compliance, financial, or professional advice. Listening to or engaging with this content does not create an advisory or consulting relationship. Guest opinions are their own and do not necessarily represent the views of Human Signal or Dr. Tuboise Floyd. Case studies and institutional-failure analyses use publicly available information and are presented as educational tools, not legal findings or regulatory determinations. This podcast uses OP3 for privacy-friendly audience measurement: https://op3.dev/privacy © 2026 Dr. Tuboise Floyd. All rights reserved. This podcast uses the following third-party services for analysis: OP3 - https://op3.dev/privacy

  1. Season 3 Trailer

    They're Already Stealing Your Encrypted Data. Q-Day Is When They Read It. | Katie Arrington, IonQ

    Your encrypted data is being copied right now. Not read — stored. Waiting for the machine that can open it. That machine has a date: Q-Day. Estimates land between 2027 and 2028. This is the trailer for Q-Day: Building the Quantum Future — the episode of The Briefing where Dr. Tuboise Floyd puts the hardest question in cybersecurity to Katie Arrington: you've got one budget and two bills. Do you pay to protect data against a threat that hasn't arrived, or buy into quantum computing that hasn't fully delivered? She has stood on both sides of that desk as the senior cyber official defending the Department of Defense, the largest enterprise on earth, and now as Quantum Technical Evangelist at IonQ, the company building the machines that change everything she used to defend. If you run a company, a security team, or a board agenda — this conversation is about you. 🎙️ FULL EPISODE: September 8, 2026 — The Briefing with Dr. Tuboise Floyd WHAT YOU'LL HEAR: • "Harvest now, decrypt later" — the attack happening today • The real timeline for quantum computers breaking RSA encryption • Post-quantum cryptography: what migrating actually costs • Quantum networking, quantum sensing, and what comes after • Why a top DoD cyber leader crossed over to IonQ SUBSCRIBE — full episode in 48 hours: ▶ YouTube: @RealHumanSignal ▶ Apple Podcasts / Spotify / Amazon Music: The Briefing with Dr. Tuboise Floyd GUEST: Katie Arrington — former DoW Chief Information Officer (performing the duties), former Deputy CIO for Cybersecurity, former CISO for Acquisition & Sustainment, former state legislator, and senior leader at Exiger, Booz Allen Hamilton, Centauri, and Dispersive Networks. Now Quantum Technical Evangelist at IonQ. The Katie Arrington episode of The Briefing is underwritten by Founding Decision Assurance Partner MCGlobalTech. Underwriting does not determine analysis, findings, or guest selection. #QDay #QuantumComputing #IonQ #Cybersecurity #Encryption #PostQuantumCryptography #KatieArrington #DataBreach #InfoSec #TheBriefing This podcast uses the following third-party services for analysis: OP3 - https://op3.dev/privacy

    They're Already Stealing Your Encrypted Data. Q-Day Is When They Read It. | Katie Arrington, IonQ
  2. Season 3 Trailer

    AI Writes Your Cybersecurity Policy in Seconds. It's Also Wrong. | William McBorrough, MCGlobalTech

    AI can produce a polished cybersecurity policy, control plan, or assessment response in seconds. But polished is not the same as correct. In this episode of The Briefing, Dr. Tuboise Floyd sits down with William McBorrough, founder of MCGlobalTech, to unpack why expertise still matters when an AI-generated answer looks convincing but is operationally wrong — and what that means for every leader approving, procuring, or certifying technology decisions that carry real consequences. ⚠️ THE CORE PROBLEM: Large language models optimize for fluency, not accuracy. When the output is a security control, a compliance response, or a risk assessment, a confident wrong answer doesn't just waste time — it creates exposure. 🎯 IN THIS EPISODE: • Why AI-generated cybersecurity policies look right but fail operationally • The expertise gap: what LLMs can't replicate about security judgment • Where AI actually helps in compliance, audits, and control development • How to vet AI output before it becomes policy, plan, or certification response • AI governance frameworks for leaders who approve consequential technology 👤 ABOUT THE GUEST: William McBorrough is the founder of MCGlobalTech, a cybersecurity and governance, risk, and compliance (GRC) firm. He works with organizations navigating security assessments, compliance frameworks, and the operational reality of turning policy into protection. 🔗 RESOURCES & LINKS: → Watch The Briefing: https://humansignal.io/thebriefing → Subscribe to The AI Governance Record (biweekly analysis for leaders who approve, procure, or certify consequential technology): https://www.linkedin.com/newsletters/the-ai-governance-record-7438000159642292225 📬 THE BRIEFING is the podcast for leaders making consequential technology decisions. Subscribe on Apple Podcasts, Spotify, Amazon Music, or wherever you listen. This Briefing is underwritten by Founding Decision Assurance Partner MCGlobalTech. Underwriting does not determine analysis, findings, or guest selection. #Cybersecurity #ArtificialIntelligence #AIGovernance #GRC #Compliance #RiskManagement #MCGlobalTech #TheBriefing This podcast uses the following third-party services for analysis: OP3 - https://op3.dev/privacy

    AI Writes Your Cybersecurity Policy in Seconds. It's Also Wrong. | William McBorrough, MCGlobalTech
  3. Sep 7

    Q-Day: Building the Quantum Future with Katie Arrington of IonQ

    Someone may already be copying your encrypted traffic. They cannot read it yet. Q-Day is when that could change. Katie Arrington, Quantum Technical Evangelist at IonQ and former senior technology and cybersecurity leader at the Department of War, joins Dr. Tuboise Floyd for a plainspoken conversation about the decisions leaders must make before cryptographically relevant quantum computing arrives. Katie has stood on both sides of the desk. She previously performed the duties of chief information officer for the Department of War and served as deputy chief information officer for cybersecurity, overseeing defense-wide cyber strategy, governance, and compliance. Today, she is helping explain the technology that could reshape the systems she once helped defend. In this episode: What Q-Day means for public-key encryptionWhy “harvest now, decrypt later” creates risk before quantum computers can break encryptionHow organizations should approach post-quantum cryptography and cryptographic inventoriesWhy leaders will have to decide what gets upgraded, rebuilt, or left behindHow quantum sensing, timing, and networking could reshape modern conflictThe difference between artificial intelligence and quantum computingHow trapped-ion quantum computers workWhy fidelity and fault tolerance matterWhere humans belong in an AI- and quantum-enabled futureWhat quantum and AI could mean for jobs and workforce development The hardest question is not whether quantum is coming. It is who decides what must be protected first—and what evidence supports that decision. About Katie ArringtonKatie Arrington is Quantum Technical Evangelist at IonQ. She previously performed the duties of chief information officer for the Department of War, advising the secretary on enterprise information management, cyber assurance, and emerging technology policy. She also served as deputy chief information officer for cybersecurity and as chief information security officer for acquisition and sustainment. Follow IonQ: https://www.ionq.com About The BriefingThe Briefing with Dr. Tuboise Floyd examines consequential technology decisions across artificial intelligence, cybersecurity, quantum technology, and emerging risk. Creative Director: Jeremy Jarvis. Find the decision. Follow the evidence. Name who owns it. Listen, watch, and follow the show: https://humansignal.io/thebriefing Partner disclosureThis episode is underwritten by Founding Decision Assurance Partner MCGlobalTech. MCGlobalTech built the CMMC Assured Enclave to help small and midsized defense contractors operate their cybersecurity and compliance obligations after the assessment. Learn more at https://cmmcassured.com The views expressed by the guest are her own. Discussion of companies, markets, or securities is for informational purposes only and is not investment advice. This podcast uses the following third-party services for analysis: OP3 - https://op3.dev/privacy

    Q-Day: Building the Quantum Future with Katie Arrington of IonQ
  4. Sep 15

    Passing the Test Is Not Staying Compliant | CMMC, AI & Governance with William McBorrough

    Passing the test and staying compliant are two different jobs. A defense contractor can spend months preparing for an assessment, pass it, and begin losing ground almost immediately. Why? Because assessment readiness is not the same thing as operating a sustainable compliance program. In this episode of The Briefing, Dr. Tuboise Floyd sits down with William McBorrough, CISO and Lead CMMC Assessor, MCGlobalTech for a conversation about what happens every day after assessment day. William has seen the problem from both sides: building cybersecurity compliance programs and assessing whether organizations can actually operate what they documented. The conversation starts with CMMC and the Defense Industrial Base, then moves into governance, evidence, executive accountability, technology procurement, and AI. Because whether the system is a cybersecurity compliance program or an AI use case, the underlying question is remarkably similar: Can you prove that what you say is happening is actually happening? FULL SHOW NOTES Passing the test is not staying compliant. A company can spend a year preparing for an assessment, pass it, and watch the program begin coming apart afterward. The people who built it return to their regular jobs. The documentation stops matching the work. The next assessor may discover an organization that was compliant once. That is the problem at the center of this episode of The Briefing. Dr. Tuboise Floyd sits down with William McBorrough, CISO and Lead CMMC Assessor, to examine what happens when organizations build cybersecurity compliance programs around assessment day instead of the operating capability required for every day after it. William describes this as a sustainability problem. Organizations frequently buy audit-readiness services, tools, consulting, and managed services designed to get them through a point-in-time assessment. But when the audit becomes the goal, organizations can immediately begin drifting once the assessment is over because the ongoing activities required by the compliance program were never built into normal operations. That leads to one of the central arguments of the conversation: CMMC is a governance problem. Cybersecurity compliance requires more than a mandate. Governance is a discipline requiring people, skills, processes, accountability, and the capability to perform the work repeatedly. And an assessor can see the difference. If an organization's policy says access is reviewed every month, an assessor doesn't simply want to read the policy. Where are the records? What process was followed? Who performed the work? Can the organization demonstrate that the activity actually occurred? An assessor is looking for evidence that the program is operating, not merely evidence that somebody documented one. Then the conversation crosses into AI. William explains why security leaders increasingly find themselves responsible for AI risk because AI is already entering organizations. Rather than serving as the traditional "voice of no," he describes the security leader's job as finding a secure path to legitimate business objectives. That raises another governance problem: How do you use AI without simply turning it loose? William explains how MCGLOBALTech approaches AI inside its compliance operations. The organization governs AI by use case, not simply by declaring a particular AI product acceptable. Different uses of the same tool can create very different risks. There are also boundaries. AI is not used on client data inside MCGLOBALTech's client environments. AI is instead used for specific approved operational purposes outside those prohibited uses. And there is an important operating rule: Do it manually first. William's team develops the process manually, operates it, validates that the process produces the desired outcome, and only then determines how AI can accelerate or automate it. The process is not created by AI. AI is applied after the organization understands the process and knows what a valid outcome should look like. That distinction matters because AI can produce something that looks convincing even when it is wrong. As William explains in the conversation, asking AI for a heart-surgery plan may produce something that looks excellent to someone who isn't a heart surgeon. Expertise is what allows someone to recognize whether the output is actually valid. The same discipline required for sustainable cybersecurity compliance begins appearing again in AI: Defined processes. Clear boundaries. Validated outputs. Evidence. Human judgment. Accountability. The episode also gets personal for executives. CMMC and federal cybersecurity requirements eventually reach the people whose names stand behind what the organization says is true. William advises CEOs operating in the federal space to examine their contracts, understand the security obligations contained in them, and determine whether their organizations actually possess the capability to meet those obligations. He also discusses the responsibility of the senior official affirming an organization's compliance information and the importance of having evidence behind what leadership is being asked to stand behind. The question isn't simply: Did we pass? It is: Can we prove we're still doing what we said we do? The assessment is a day. The program is every day after. IN THIS EPISODE • CMMC and the compliance sustainability gap • Passing an assessment versus sustaining compliance • CMMC Level 2 • What CMMC assessors actually look for • Evidence versus documentation • Governance versus audit readiness • NIST 800-171 requirements • Cybersecurity inside the Defense Industrial Base • Small-business compliance challenges • Governance as an operating discipline • Executive accountability and attestation • Security obligations inside federal contracts • AI governance • The CISO as an AI governance leader • Governing AI by use case • ChatGPT, Claude and Microsoft Copilot • Separating AI experimentation from controlled environments • Manual validation before AI automation • Validated outputs versus convincing outputs • Continuous review of AI use cases • Why technology-first procurement fails • What CEOs should examine now GUEST William McBorrough CISO, Lead CMMC Assessor MCGLOBALTech William McBorrough is a cybersecurity and compliance leader whose work spans building, operating, and assessing security governance programs. He has spent more than 16 years building security compliance programs and has supported defense contractors around NIST 800-171 requirements and cybersecurity compliance. His work has included organizations ranging from five employees to 5,000 employees, while MCGLOBALTech also serves federal government organizations. William is also an associate professor of cybersecurity at the University of Maryland Global Campus, serves on the EC-Council Global Advisory Board, publishes the SMB CISO Insights newsletter, and is the author of Beyond Compliance, a governance roadmap focused on sustainable CMMC. ABOUT THE BRIEFING The Briefing with Dr. Tuboise Floyd is independent media examining the decisions underneath consequential technology. AI. Quantum. Cyber. The technology is only the beginning of the story. Find the decision. Follow the evidence. Name who owns it. Independent media. Real conversations. Higher stakes. A Human Signal Production Hosted by Dr. Tuboise Floyd Creative Director: Jeremy Jarvis Watch and listen: humansignal.io/thebriefing EDITORIAL / PARTNER DISCLOSURE MCGLOBALTech is a paying Human Signal partner, and Dr. Tuboise Floyd has performed contract advisory work with the firm. The partnership does not determine guest selection, questions, editorial conclusions, favorable treatment, or endorsement. Editorial questions and conclusions remain independent. This podcast uses the following third-party services for analysis: OP3 - https://op3.dev/privacy

    Passing the Test Is Not Staying Compliant | CMMC, AI & Governance with William McBorrough
  5. 4d ago

    Post-Quantum Readiness: Can You Find Your Cryptography Before Quantum Does? | David Pollak

    Everybody keeps asking the same quantum question: When is Q-Day? But that may not be the question that matters to the person who eventually has to sign the migration plan. Before an organization can replace vulnerable cryptography, it has to know where that cryptography exists. And before leadership tells a board that the problem can be fixed, somebody has to determine whether a replacement actually exists. In this episode of The Briefing, Dr. Tuboise Floyd sits down with David Pollak, Founder and CEO of Spice Labs, for a practical examination of post-quantum readiness, cryptographic discovery, CBOMs, software supply-chain risk, and crypto agility. Pollak argues that traditional source-code and network scanning can reveal pieces of the problem without necessarily producing a complete, correlated view of the cryptography embedded across applications, libraries, containers, virtual machines, third-party components, certificates, and dependencies. The conversation gets to a larger leadership question: What evidence would you be willing to sign your name to? Pollak describes the role of a Cryptographic Bill of Materials (CBOM) in identifying cryptographic libraries, where cryptography is being invoked, how algorithms are configured, and the cryptographic material contained inside software. The discussion also examines why crypto agility matters. Pollak compares hard-coded cryptography to putting a jacuzzi motor behind drywall: when something changes, you have to tear into the system to replace it. Crypto agility creates the equivalent of an access door, allowing cryptographic algorithms to be changed with substantially less disruption. The conversation then moves from discovery to measurement. For Pollak, readiness cannot simply be a green spreadsheet or completed Jira burndown. Organizations need evidence of what has actually been compiled into software and a way to measure whether cryptographic posture changes as remediation proceeds. Floyd and Pollak also examine the procurement problem: an organization can address its own code and still inherit cryptographic exposure through someone else's software. That makes vendor evidence, supply-chain auditing, CBOMs, and third-party attestation increasingly important to buyers. And when the conversation reaches the decision a CISO, CIO, CTO, or board can make now, Pollak offers a deceptively difficult answer: Decide what can be dropped. Prioritization requires saying no. If everything is important, nothing is. Leadership therefore needs to know what matters, what does not, and document that decision. The result is a different way of thinking about post-quantum readiness. It does not begin with predicting Q-Day. It begins with knowing what you have, knowing what can be replaced, knowing what cannot, determining what evidence demonstrates that the work was actually completed, and putting a name next to the decision. IN THIS EPISODE • Why cryptographic discovery comes before post-quantum migration • Why source-code scanning alone cannot reveal the entire cryptographic estate • Why network scanning and application inventories must be correlated • SBOM vs. CBOM • What a Cryptographic Bill of Materials actually contains • Cryptography hidden inside third-party and open-source software • Software artifacts, JARs, containers, virtual machines, and dependencies • Cryptographic certificates, keys, algorithms, and material • Crypto agility and the cost of hard-coded cryptography • Measuring actual remediation instead of relying on compliance spreadsheets • Software supply-chain exposure • Vendor and procurement questions for post-quantum readiness • External auditing and third-party attestation • Why software must be treated as a dynamic asset • Long-term technology investment and short-term organizational incentives • What CISOs, CIOs, CTOs, and boards should prioritize now • Why every migration plan eventually requires someone to decide what does not get fixed first THE BUYER'S TEST A vendor tells you: “We're quantum safe.” What should you ask next? How are you managing certificates and cryptographic inputs? Have you tested the system without classical certificates, cryptography, or keys? How have you audited your software supply chain? What evidence demonstrates what exists inside third-party and open-source components? Who independently audited the claim? Mechanics. Process. Third-party attestation. CHAPTERS 00:00 — Q-Day May Be the Wrong Question 01:00 — Meet David Pollak, Founder & CEO of Spice Labs 02:00 — Do Organizations Know Where Their Cryptography Is? 03:00 — Why an Inventory Is Not Enough 05:00 — Inspecting the Build Artifact 07:00 — What Would You Be Willing to Sign? 08:00 — What's Actually Inside Modern Software? 10:00 — Decision Assurance and Cryptographic Evidence 11:00 — SBOM vs. CBOM 12:00 — What a CBOM Actually Tells You 14:00 — Cryptographic Material and Legacy Certificates 15:00 — Inside Spice Labs' Cryptographic Analysis 17:00 — Third-Party Software and Quantum Readiness 18:00 — Migration Deadlines and the Leadership Problem 19:00 — Why Post-Quantum Migration Takes Time 20:00 — Partner Message: MCGlobalTech CMMC Assured Enclave 21:00 — Harvest Now, Decrypt Later—and Digital Trust 23:00 — What Happens When Digital Signatures Cannot Be Trusted? 27:00 — What Crypto Agility Actually Means 31:00 — Discovery Is the Starting Line 32:00 — Measurement vs. Compliance Checklists 34:00 — Measuring Ground Truth 37:00 — Software Supply-Chain Visibility 38:00 — Should Buyers Require CBOM Evidence? 39:00 — The Buyer's Test for “Quantum Safe” Vendors 41:00 — What Executives Misunderstand About Software 43:00 — Short-Term Incentives vs. Long-Term Readiness 44:00 — The One Decision Leaders Can Make Monday Morning 45:00 — What Do You Drop on the Floor? GUEST David Pollak Founder & CEO, Spice Labs David Pollak has spent nearly two decades building open-source systems and examining how software is composed. He created Lift, one of the early major Scala web frameworks, helped advance Scala adoption across industry and academia, and later worked as a distinguished engineer on dependency analysis and enterprise software risk. At Spice Labs, Pollak is applying mathematical methods to software and cryptographic discovery to produce verifiable records of system composition and help organizations understand the software, dependencies, and cryptography their systems actually contain. ABOUT THE BRIEFING The Briefing with Dr. Tuboise Floyd is an independent Human Signal production examining consequential decisions across artificial intelligence, quantum technology, cybersecurity, governance, and emerging technology risk. Real conversations. Higher stakes. Find the decision. Follow the evidence. Name who owns it. Hosted by Dr. Tuboise Floyd Creative Director: Jeremy Jarvis A Human Signal Production PARTNER DISCLOSURE This episode includes a partner message from MCGlobalTech, a Human Signal partner, for the CMMC Assured Enclave. Commercial partnerships and underwriting do not determine guest selection, questions, analysis, or editorial conclusions. This podcast uses the following third-party services for analysis: OP3 - https://op3.dev/privacy

    Post-Quantum Readiness: Can You Find Your Cryptography Before Quantum Does? | David Pollak

Trailers

5
out of 5
3 Ratings

About

ABOUT THE PODCAST The Briefing with Dr. Tuboise Floyd The Briefing is for leaders who build, approve, procure, govern, or certify consequential technology. Hosted by Dr. Tuboise Floyd, Founder and Principal, Decision Assurance at Human Signal, the show examines the operating reality beneath technology strategy: decision authority, accountability, controls, evidence, critical infrastructure, and the conditions that produce institutional failure. The market is crowded with technology noise, checklists, and compliance theater. The Briefing focuses on the harder question: What governance infrastructure must exist before autonomous and emerging systems create exposure that leadership cannot explain, defend, or control? Episodes use Human Signal’s TAIMScore™, GASP™ Diagnostic, L.E.A.C. Protocol™, and Failure Files™ approaches to examine real-world failures, identify structural risk, and surface the decisions leaders must make before scrutiny arrives. Produced with Creative Director Jeremy Jarvis, The Briefing covers AI governance, cyber risk, post-quantum readiness, critical infrastructure, government contracting, and the builder economy. New episodes, visual briefings, and practical playbooks: https://humansignal.io/thebriefing The Briefing is a Human Signal production. Human Signal is an independent decision-assurance advisory and research platform. DISCLOSURE All episode content, including analysis, case studies, and framework applications, is provided for educational and informational purposes only. Nothing in this podcast constitutes legal, regulatory, compliance, financial, or professional advice. Listening to or engaging with this content does not create an advisory or consulting relationship. Guest opinions are their own and do not necessarily represent the views of Human Signal or Dr. Tuboise Floyd. Case studies and institutional-failure analyses use publicly available information and are presented as educational tools, not legal findings or regulatory determinations. This podcast uses OP3 for privacy-friendly audience measurement: https://op3.dev/privacy © 2026 Dr. Tuboise Floyd. All rights reserved. This podcast uses the following third-party services for analysis: OP3 - https://op3.dev/privacy