Secure Talk Podcast

Justin Beals

Secure Talk reviews the latest threats, tips, and trends on security, innovation, and compliance. Host Justin Beals interviews leading privacy, security and technology executives to discuss best practices related to IT security, data protection and compliance. Based in Seattle, he previously served as the CTO of NextStep and Koru, which won the 2018 Most Impactful Startup award from Wharton People Analytics. He is the creator of the patented Training, Tracking & Placement System and the author of “Aligning curriculum and evidencing learning effectiveness using semantic mapping of learning assets,” published in the International Journal of Emerging Technologies in Learning (iJet). Justin earned a BA from Fort Lewis College.

  1. 4d ago

    CMMC After the 60-Day Review: What DOD Decided, What It Didn’t, and What to Do Now

    CMMC wasn't suspended. Only one piece of it was, and the defense contractors acting like the whole program went away are the ones taking on the most risk. Eighty days after the DoD CIO paused CMMC Phase 2, the 60-day review has closed, a class deviation has written the pause into contracts, and the Reform Task Force's recommendations are still not public. Contracting officers and primes aren't waiting. Some solicitations now require a posted SPRS score before you can even open the RFP. In this SecureTalk panel, host Justin Beals sits down with three NIST SP 800-171 practitioners (a C3PAO strategist, a lead CCA and instructor, and a former Navy cryptologist turned enclave provider) to separate what DoD actually decided from what the internet decided for it. WHO THIS IS FOR Defense contractors and subcontractors, compliance and IT leaders preparing Level 1 or Level 2 self-assessments, MSPs and MSSPs serving the DIB, and anyone trying to make sense of CMMC after the Phase 2 pause. TIMESTAMPS 00:00 Why this episode is a panel 00:39 Meet the guests 04:11 "We're NIST 800-171 experts, not CMMC experts" 05:16 80 days after the pause: where things stand 07:21 What hasn't changed: Level 1 and Level 2 self-assessments 08:26 Myth: "CMMC was suspended" 11:33 No SPRS score, no RFP documents 14:08 CMMC is a floor, not a ceiling 14:26 The FAR overhaul and retired clauses still in contracts 18:29 Myth: "CMMC got pushed to November 2028" 22:02 The class deviation most people misread 24:14 What a defensible self-assessment looks like 29:06 Reddit, Discord and the misinformation problem 33:30 Myth: "My MSSP handles CMMC for me" 36:40 Myth: "Our policies prove we're compliant" 40:32 Myth: "We bought an enclave, so we're done" 44:07 Where the real risk lies now 51:13 How to choose outside help SOURCES REFERENCED - DoD CIO memo suspending CMMC Phase 2 (July 13, 2026), via Federal News Network: https://federalnewsnetwork.com/cybersecurity/2026/07/pentagon-suspends-cmmc-phase-two-requirements-launches-review-of-program/ - Sept. 3 acquisition memo codifying the pause, via MeriTalk: https://www.meritalk.com/articles/dod-codifies-pause-of-cmmc-phase-2-dod-cio-says-more-work-needed-on-cmmc/ - 32 CFR Part 170, the CMMC Program rule (phased rollout in §170.3): https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-G/part-170 - NIST SP 800-171 Rev. 2: https://csrc.nist.gov/pubs/sp/800/171/r2/upd1/final - NIST SP 800-171A, the assessment methodology: https://csrc.nist.gov/pubs/sp/800/171/a/final - CMMC Program Final Rule: https://www.federalregister.gov/d/2024-22905/p-1876 - Free executive level class: https://www.evolvedcyberacademy.com/courses/Rev3Leadership - CMMC Level 2 Self- Assessment: Step-by-step with Templates: https://www.strikegraph.com/blog/conduct-cmmc-level-2-self-assessment WHAT YOU'LL LEARN The requirement never moved. The pause hit third-party C3PAO assessments, not NIST SP 800-171 compliance and not Level 1 or Level 2 self-assessments. Brian Hubbard sets the bar at a self-assessment you could defend "if the DIBCAC walked in the next day after you posted your score." November 2028 is not a new deadline. Logan Therrien explains it has always been the end of CMMC's four-year phased rollout. Reading it as a two-year reprieve is one of the costliest misreadings in the market. The market is moving faster than the policy. Vince Scott compares it to oil moving through the Strait of Hormuz: there are months of supply in the system before anyone feels the change. Primes are already asking to see SSPs and SPRS scores. GUESTS Logan Therrien, Chief Strategy Officer, Kieri Solutions (C3PAO); 24-year military veteran Brian Hubbard, President, Evolve Cyber; Lead CCA and CMMC instructor; 40+ years in cybersecurity Vince Scott, CEO, Defense Cybersecurity Group; retired Navy cryptologist HOST Justin Beals, founder of Strike Graph and host of SecureTalk, a podcast focused on security news, innovation, and excellence. 🔔 Subscribe for conversations where cybersecurity, compliance and national security meet. #CMMC #NIST800171 #DefenseIndustrialBase

    CMMC After the 60-Day Review: What DOD Decided, What It Didn’t, and What to Do Now
  2. Sep 22

    NIST's Victoria Yan Pillitteri: "Compliance Won't Save You" — Inside NIST 800-171

    She helps write the rules the entire U.S. defense industrial base gets assessed against — and she's telling you compliance is the floor, not the finish line. Victoria Yan Pillitteri leads the Risk Management Framework/FISMA team at NIST and co-chairs the Joint Task Force uniting DoD, the Intelligence Community, and civilian agencies on one cybersecurity framework. In this episode, she and Justin Beals go inside how NIST actually builds SP 800-53 and 800-171 — what gets cut, what stays, and why "just copy the control language" is a losing strategy for anyone trying to pass an assessment. In this episode:Why 853 is "the Cheesecake Factory menu" of cybersecurity controls — and why that's a feature, not a bugThe real difference between NIST 800-171 Rev 2 and Rev 3, and why "organization-defined parameters" changed everythingWhy writing your own control (not just quoting NIST's language) is the only way to actually pass an assessmentHow FedRAMP 20x, OSCAL, and continuous monitoring are quietly replacing the point-in-time ATONIST's upcoming AI control overlays for predictive, generative, and agentic AI systems Chapters00:00 Introduction00:34 The purpose of NIST standards and measurement science02:24 Cybersecurity outcomes as a Rosetta Stone03:14 The challenge of measuring risk in cybersecurity04:55 Frameworks as operating systems for risk management06:58 The iterative process of developing cybersecurity standards08:11 Interpreting control statements for organizations09:36 The importance of tailoring controls to risk profiles12:30 The relationship between compliance and good risk management14:37 The development process of cybersecurity standards17:27 Differences between Rev2 and Rev3 of NIST 800-17120:01 Broad versus specific requirements in cybersecurity controls22:36 Supporting small businesses with guidance and tools27:23 The balance between prescriptive and flexible standards30:24 Cybersecurity in public-private partnerships34:53 Moving from point-in-time to continuous authorization40:23 AI risks and the development of tailored controls44:53 The future of cybersecurity standards and AI security Resources referenced:NIST SP 800-53 (Security and Privacy Controls) — [link]NIST SP 800-171 Rev 2 & Rev 3 (Protecting CUI) — [link]NIST Risk Management Framework — [link]NIST Cybersecurity Framework — [link]NIST AI Risk Management Framework — [link]FedRAMP 20x Program — [link]OSCAL (Open Security Controls Assessment Language) — [link] #NIST80053 #NIST800171 #CMMC #FedRAMP #CyberCompliance #RiskManagement #CUI #SecureTalk

    NIST's Victoria Yan Pillitteri: "Compliance Won't Save You" — Inside NIST 800-171
  3. Aug 25

    AI Agent Hacks Another AI Agent Inside Google — An Agentic Supply Chain Bomb

    An agent anyone could talk to just pulled the levers on one almost nobody could reach — and it happened inside the crown jewels: a live code repository. Google gave its AI agent human-level trust — and paid for it.When Dan Lisichkin, a researcher at Pillar Security, started mapping every Google repository running an embedded coding agent, he wasn't hunting for prompt injection — he was hunting classic CI/CD bugs. The AI angle showed up almost by accident, flagged by his own automation. What he found inside Google's Agent Development Kit repository was a low-privilege issue-triaging bot commenting on GitHub *as a trusted collaborator* — a status that should be reserved for humans the maintainers know. As Dan puts it, describing the moment his manager pushed back on downplaying the find: *"this is an agent triggering another agent... this is like no one talked about this before."* The prompt injection wasn't the hard part — weaponizing it was.Dan walks through Pillar's CFS framework (Context, Format awareness, instruction Salience) and how he literally used Google's own CONTRIBUTING.md file as the blueprint for the injection that would slip past the triage agent undetected. From there, one gated comment — normally reserved for trusted maintainers — was enough to trigger a second, far more privileged agent. This isn't a bug you patch once — it's a new attack surface.Dan's read is blunt: multi-agent systems create "weird machine" behavior — undefined states nobody designed for, not flaws in a specific line of code. He and Justin dig into why bolting more rules onto a non-deterministic system is Sisyphean, why bot identities need database-row-level granularity instead of human-style trust, and why Dan — a former malware researcher — thinks mandatory human-in-the-loop is often the wrong answer at scale. Chapters:  00:00: Cold Open: The Agent That Wasn't Supposed to Talk**- Google's public triage bot and the collaborator-status anomaly- Why "an agent triggering another agent" had never been formally described before 04:12:  Building the Hunt: Automation Over Manual Bug-Hunting**- Dan's CI/CD vulnerability scanner, built on top of Claude Code- How an AI-generated "AI agent injection" tag became the whole story- Reference: [Simon Willison — "The Lethal Trifecta for AI Agents"] 14:30: The Exploit: Contribution Guidelines as an Attack Roadmap**- Google ADK repository, the PR-triaging agent, and the CONTRIBUTING.md file used as a weapon- Pillar Security's CFS framework for indirect prompt injection (Context, Format awareness, Salience) — [Pillar Security Blog: Autonomy of Indirect Prompt Injection]- Why jailbreaking ≠ what Dan is doing — "I'm not trying to break the wall, I'm trying to walk through the door it left open" 28:05: Impact: Two Bugs, Two Verdicts**- GitHub token exfiltration, PR/issue metadata manipulation, and the fake "looks good to merge" trail- The second bug: a GCP service account and code-execution potential — "there was more juice on that one"- Why Google didn't pay a bounty — and why that answer is more interesting than the bug itself 38:50:  Identity, Granularity, and the Human-in-the-Loop Debate**- Why bot identities need GitHub App/Actions scoping, not personal-access-token trust- The case *against* blanket human-in-the-loop — review fatigue, OpenClaw, and "people are going to do this anyway"- SolarWinds, CryptoLocker, and why Dan thinks this is a closed-gap problem, not an open one Resources: Lisichkin, D. (2026, August 3). I'll just call you: Agent-to-agent privilege boundary failures in CI/CD on Google's ADK repository. Pillar Security. https://www.pillar.security/blog/ill-just-call-you-agent-to-agent-privilege-boundary-failures-in-ci-cd-on-googles-adk-repository https://danusminimus.github.io/ #aiagents #security #promptinjection #google #defcon #vulnerability---

    AI Agent Hacks Another AI Agent Inside Google — An Agentic Supply Chain Bomb
  4. Aug 11

    AI Is Eating Our Young: Data Center Revolts, Vanishing Junior Jobs & the EU AI Act

    Communities are blocking $130 billion in AI data centers while the entry-level jobs that used to train the next generation of engineers quietly disappear. Chapters:  00:00:  The Backlash: 800 Groups, 49 States, $130B BlockedGallup: 71% of Americans don't want a data center built near them (Gallup)Data center opposition tracker, Q1 2026 filings (referenced industry opposition data)CMMC as precedent for regulating critical infrastructure (DoW CMMC Phase 2 program) 04:30:  Why AI Is "Eating Our Young" in Education**Fran Berman & co-author's unpublished piece on the fraying mid-career pipelineBetter Tech (MIT Press) — Chapter appendix: AI classroom syllabus and exercises 14:00:  Tech as Critical Infrastructure, Not a ReligionBetter Tech prologue: treating tech like food, water, roads, and the power gridGDPR (EU, 2018) as a case study in regulation done right — and its limitsVermont's data broker law as a case study in weak enforcement 26:00: Design Can't Be Bolted On Later**Self-driving cars and the hidden environmental cost of full autonomyAttack surface risk: denial-of-service on connected, self-driving fleets 34:00: Governing the Hybrid Human-AI Society**EU AI Act — risk-tiered regulation: unacceptable, high-risk, low-risk categoriesU.S. Equal Employment Opportunity Commission guidance on algorithmic hiring 41:00: The Hype Curve and the Data Center Reckoning**Western Massachusetts communities rejecting new AI data centersEfficiency vs. quality of life — Berman's closing argument Communities are saying no to AI's biggest infrastructure bet.In the first quarter of 2026 alone, local opposition blocked or delayed 75 data center projects worth roughly $130 billion — nearly matching all of 2025's total in a single quarter. Dr. Fran Berman, former head of the San Diego Supercomputer Center, argues the fix isn't more hype, it's precedent we already have. She points to CMMC itself: "If we can look at the defense supply chain and say this is critical infrastructure, it has to meet a bar, then we can look at the trillion dollars of compute being built into the middle of American life and say the same thing." AI isn't just displacing jobs.  It's starving the pipeline that builds senior engineers. Berman's sharpest warning is about who trains the next generation of professionals when entry-level coding and writing jobs — the ones junior people used to cut their teeth on — get automated away. She compares it to a surgeon who's never had supervised time in the operating room: "Unless you have that experience and the mentorship of more senior professionals, it's really hard" to develop the judgment senior engineers rely on. Good regulation needs more than a law on the books. Drawing on her book Better Tech (MIT Press), Berman walks through why GDPR worked where Vermont's data broker law didn't — and previews how the EU AI Act's risk-tiered approach (unacceptable, high-risk, low-risk) could become the model for governing hybrid human-AI decision-making, where, as she puts it, "the only accountable entities are humans." ✍️ About the AuthorDr. Fran Berman is an award winning-data scientist, pioneer in public interesttechnology, and community leader and builder. She directs the Public InterestTechnology Initiative at UMass Amherst and is a Faculty Associate at the BerkmanKlein Center for Internet and Society at Harvard. Berman is former head the SanDiego Supercomputer Center and served as Vice President for Research atRensselaer Polytechnic Institute. She currently serves as a Trustee of the AlfredP. Sloan Foundation and is a popular regular panelist on public radio’s WAMCRoundtable with 400,000 monthly listeners in seven states. For more information,see https://www.franberman.com. Link to the book: https://mitpress.mit.edu/978026205488...

    AI Is Eating Our Young: Data Center Revolts, Vanishing Junior Jobs & the EU AI Act
  5. Jun 16

    Considering Security, Compliance and Revenue with David Grazer

    Most companies chase certifications to win deals — but what actually keeps customers is something no audit can measure. In this episode, vCISO David Grazer makes the case that trust is a measurable economic asset hiding in plain sight: your customer retention rate. Drawing on 15+ years inside high-growth tech companies, David explains why compliance frameworks are customer acquisition tools, not retention strategies — and how the gap between the two is costing businesses more than they realize. This episode is for founders, security leaders, and C-suite executives who want to connect their security and privacy programs to real business outcomes. You'll learn: → Why a SOC 2 or ISO 27001 certification is only the beginning of earning customer trust → How customer churn functions as one of the most honest security metrics available → Why MFA and common security controls often fail the users who need them most → What "Trust by Design" looks like in product development and AI programs → How to translate security risk into language that resonates with your CFO Chapters 00:00 Introduction to Secure Talk and Trust 03:42 David Grazer's Journey into Security and Privacy 08:09 Navigating Compliance and Customer Trust 12:49 The Role of Consulting in Security 18:07 Trust as a Measurable Economic Asset 23:42 Identity Management in the Entertainment Industry 26:09 The VC SO Model and Its Impact 29:13 The Evolution of Compliance Conversations 33:17 Exploring the Intersection of Technology and Society 🔔 Subscribe to SecureTalk for weekly conversations at the intersection of cybersecurity, compliance, and business strategy. #cybersecurity #compliance #CISO #trustbydesign #vciso #informationsecurity #GRC #dataprivacy

    Considering Security, Compliance and Revenue with David Grazer
4.8
out of 5
39 Ratings

About

Secure Talk reviews the latest threats, tips, and trends on security, innovation, and compliance. Host Justin Beals interviews leading privacy, security and technology executives to discuss best practices related to IT security, data protection and compliance. Based in Seattle, he previously served as the CTO of NextStep and Koru, which won the 2018 Most Impactful Startup award from Wharton People Analytics. He is the creator of the patented Training, Tracking & Placement System and the author of “Aligning curriculum and evidencing learning effectiveness using semantic mapping of learning assets,” published in the International Journal of Emerging Technologies in Learning (iJet). Justin earned a BA from Fort Lewis College.

You Might Also Like