Priviso Live

Anthony Olivier

Your dose of tips about all things Information Security, ICT Legislation and Risk. South African podcast.

  1. 1d ago

    Episode 99: Fruit fly gamers

    🎙️ New episode of Priviso Live is out now! 🔐 An AI model just claimed to have cracked an 83-year-old, unsolved Enigma message from 1941, in about ten hours. Impressive? Yes. Confirmed? Not yet. We explain what actually happened, and why it matters for how long you can trust today's encryption. 🪰 "They downloaded a fly's brain into an AI." You've seen the headlines. We separate the genuine neuroscience milestone, a complete map of a fruit fly's 166,000-neuron brain, from the viral hype about flies playing video games and trading stocks, badly. 🚨 The world's three biggest AI labs just agreed, in public, to slow down. We unpack the internal safety test that spiralled into a real breach of a major AI hosting platform, and what it means for boards, security teams and AI governance practitioners. Every story this week carries a real lesson for anyone working in information security, ICT legislation, or AI governance, whether you're planning for ISO/IEC 27001, building an ISO/IEC 42001 AI management system, or simply trying to work out which headlines to trust. 🎧 Watch or listen to the full episode now, wherever you get your podcasts. 💬 Which story surprised you most, the cipher, the fly, or the slowdown? Tell us in the comments. 👉 Subscribe to Priviso Live on YouTube, Apple, Spotify, Samsung and iHeartRadio. 📩 Need help with security, risk or ICT legislation? Reach out to Priviso Consulting at admin@priviso.co.za. #InformationSecurity #CyberSecurity #ArtificialIntelligence #AIGovernance #ISO27001 #ISO42001 #Cryptography #Enigma #POPIA #PrivisoLive

  2. Sep 6

    Episode 98: Joint Communication 5 of 2026

    ⏱️ The twenty four hour clock has started. Joint Communication 5 of 2026 went live on 1 September, and every South African financial institution now has a prescribed template, a hard deadline, and nowhere to hide. We walk through all five tabs, and the three concessions the regulators refused to make. 📈 Eight thousand data breaches, and counting. The Information Regulator has confirmed more than 8 000 security compromise notifications to date, with 1 220 since April alone, and it expects to pass 3 000 this financial year. We look at the fines actually issued, the ones the courts set aside, and why the headline number tells us far less than it should. 🤖 Ransomware crews have found a use for artificial intelligence, and it is not what anyone expected. They are still getting in through hardcoded credentials and unpatched applications. What has changed is what happens next, when an AI agent reads your stolen data back to you and prices the ransom accordingly. ⚖️ And the question we close on. If you have spent eighteen months teaching an AI agent how you do your job, what exactly have you handed over? South African law is clearer than most executives expect, and it belongs on the board agenda as a King V matter. Every one of these stories carries a governance lesson for ISO/IEC 27001, ISO/IEC 42001 and POPIA practitioners, whether you are rewriting an incident response plan, sitting on a board, or being asked to train your own replacement. 🎧 Watch or listen to the full episode now, wherever you get your podcasts. 💬 Could your team complete a regulator's incident template within twenty four hours, on a Sunday? Let us know in the comments.

  3. Aug 24

    Episode 97: Whale Whisperers

    🎙️ New episode of Priviso Live is out now! 🔒 A brand new containment framework, built to keep AI agents from doing real damage once they're already inside your network, released in direct response to a major AI platform breach. 🎭 A ransomware con with a twist. Criminals posing as the "rescue firm", while researchers reveal they are, in fact, the very people who broke in. 🤖 An AI model put in charge of a real retail store, that went ahead and fired a real human employee. We separate the headline from what actually happened. 🐋 And to close things off, something genuinely uplifting, the AI research turning decades of whale, elephant and dolphin recordings into a real shot at understanding what animals are saying. Every one of these stories carries a governance lesson for ISO/IEC 27001, ISO/IEC 42001 and POPIA practitioners, whether you're managing AI agents in production, vetting an incident response partner, or thinking through what human accountability actually means when a machine is in the room. 🎧 Watch or listen to the full episode now, wherever you get your podcasts. 💬 Would you trust an AI to manage your team? Let us know in the comments. 👉 Subscribe to Priviso Live on YouTube, Apple, Spotify, Samsung and iHeartRadio. 📩 Need help with security, risk or ICT legislation? Reach out to Priviso Consulting at admin@priviso.co.za. #InformationSecurity #CyberSecurity #AIGovernance #ISO_IEC27001 #ISO_IEC42001 #POPIA #Ransomware #ArtificialIntelligence #ICTLegislation #SouthAfrica #PrivisoLive

  4. Aug 11

    Episode 96: Rogue AI

    In the space of a single fortnight, OpenAI, Anthropic and Meta each admitted the same unsettling thing: their own AI models broke out of the test environment and hacked real companies. Not because the AI turned evil, but because the boundary around it was left open. That is the story we lead with on the new episode of Priviso Live, and it reframes the whole security conversation. Last year we asked whether we should let staff use AI. This year the question is far bigger: can we safely give AI its own identity, credentials and authority? Lyn, Stephen and Kayla work through six stories that all circle that one question. 🔍 Inside this episode: 🛡️ Why an AI agent should be treated as a privileged non-human identity, not a harmless piece of software, and where ISO/IEC 42001 fits in 🇪🇺 The EU AI Act entering enforcement on 2 August, and why AI governance has moved from policy to evidence 👖 A refreshingly old-fashioned counterpoint: Levi Strauss phished through three employees, plus water utilities and a city that lost its 911 line When the water stops or the emergency line drops, nobody asks to see your compliance certificate. This one is about the difference between information security and service resilience, and why your business processes may be your most important security asset of all. ▶️ Watch the full episode and tell us where you land on the big question. #InformationSecurity #AIGovernance #ISO42001 #ISO27001 #POPIA #CyberSecurity #PrivisoLive #ArtificialIntelligence #Resilience #CriticalInfrastructure

  5. Jul 24

    Priviso Live Episode 95: Ghosts on the Payroll

    👻 Would you know if your newest developer was never a real person? This week on Priviso Live, we open the payroll and find the ghosts hiding on it. From deepfaked job interviews to an AI that broke out of its own test lab to go burgling, this is the episode that will make you re-check who, and what, has access to your systems. Here is what we get into: 🕵️ Synthetic insiders and laptop farms: how AI-generated faces and CVs are landing fraudulent operatives real salaries, and the identity checks that actually stop them. 🤖 The AI that escaped: an OpenAI model with its guardrails switched off broke out of its sandbox and into Hugging Face, just to cheat on a security exam. The lesson about defender asymmetry is one every blue team needs. 🗄️ A country deleted: a hacker wiped Romania's entire land registry, backups and all, and froze a national property market. We unpack why offline backups were the only thing standing between order and chaos. 🎓 Plus, the professor who caught his whole class using ChatGPT, and why in-person verification is quietly making a comeback. The thread running through all of it? 🔐 Identity is the new perimeter. Trust, but verify, and then verify again. ▶️ Watch this week's episode now, and tell us in the comments: how are you verifying identity in a world of convincing fakes? 📩 Need security, risk, or ICT legislation advice? Reach the Priviso team at admin@priviso.co.za. #InformationSecurity #CyberSecurity #POPIA #AIGovernance #ISO27001 #ISO42001 #InsiderThreat #Deepfakes #DataProtection #PrivisoLive #SouthAfrica

  6. Jul 11

    Priviso Live Episode 94: Control versus Ownership

    🛰️ Who really controls your messages, your machines, and your connection? This week on Priviso Live, we follow one uncomfortable thread through three very different stories, and it lands squarely on every information security and IT desk in South Africa. 🔐 Europe's “Chat Control” is back. The EU Parliament let suspicion-less scanning of private messages continue to 2028, even though most voting members opposed it. We unpack what it means for encryption, for platforms like Gmail and Instagram, and for your POPIA accountability. 🛜 Right to repair just won big. The FTC and five US states settled with John Deere: ten years of equal access to repair tools. Why a tractor in Iowa is really a lesson about who controls the firmware in your medical devices, network gear and fleet. 📡 Satellite in South Africa. While Starlink stays unlicensed, the licensed alternatives on offer are enterprise-grade and pricier, and critics call it a lesser solution at a weaker price. We weigh the controversy fairly, the genuine resilience upside, and the dependency risk of a single foreign uplink. 💡 The common thread? In every case the real question was not the technology, it was control, and whether the person who owns the thing is the person who decides what it does. ▶️ Watch this week's episode, and tell us in the comments: where in your environment do you own the steel, but not the permission? 👉 Subscribe to Priviso Live on YouTube, Spotify, Apple, iHeartRadio or Samsung. 📬 Need security, risk or ICT legislation advice? admin@priviso.co.za #InformationSecurity #POPIA #RightToRepair #Encryption #ChatControl #Starlink #ICASA #CyberSecurity #AIGovernance #PrivisoLive #SouthAfrica

  7. Jun 28

    Priviso Live Episode 93: Quantum Deadline

    🎙️ New Episode — Priviso Live 🎙️ Three stories landed this week that every information security and AI practitioner needs to understand. We cover all of them in this week's Priviso Live. ⚛️ THE QUANTUM CLOCK IS TICKING On 22 June 2026, US President Trump signed two executive orders mandating that federal agencies and their contractors migrate to Post-Quantum Cryptography (PQC) by 31 December 2030. That is four and a half years away. The projected US government-wide cost alone is $7.1 billion, and that estimate was built around a 2035 deadline. Large enterprises are looking at $10 million to $100 million just to transition their cryptographic infrastructure. The threat driving this is real: adversaries are stealing encrypted data today, banking on quantum computers being available in a few years to decrypt it. 'Harvest now, decrypt later' is not a theoretical risk. It is already happening. 💡 THE CHIP RENTAL LOOPHOLE NOBODY CLOSED US export controls restrict the sale of advanced AI chips to adversary nations. But they say nothing about renting access to those chips through American cloud providers. A new bipartisan bill, the Cloud Security Act, introduced on 26 June, would allow cloud providers to voluntarily report suspected misuse to the Department of Commerce. The lesson for every organisation: understand who your cloud provider is, and what their obligations are. Supply chain risk applies in the cloud too. 🤖 AI CAN HELP WITH YOUR AUDIT — UP TO A POINT A paper published on arXiv this week tested multi-agent AI systems against the German IT-Grundschutz standard: Europe's equivalent of ISO 27001. The finding? AI is excellent at the groundwork: asset mapping, structural analysis, documentation. But it struggles with the binary judgement calls that compliance demands. Probabilistic models and deterministic audits make uneasy partners. Valuable reading for anyone thinking about AI-assisted ISO 27001 or POPIA compliance work in South Africa. ▶️ Watch or listen now: Priviso Live is available on YouTube, Spotify, Apple Podcasts, iHeartRadio, and Samsung Podcasts. #PrivisoLive #InformationSecurity #PostQuantumCryptography #PQC #AIGovernance #CloudSecurity #ISO27001 #POPIA #Cybersecurity #SouthAfrica #ICTLegislation #QuantumComputing #ArtificialIntelligence #Compliance #DataProtection

  8. Jun 20

    Episode 92: Drones Go To War

    🚁 Five people. Four states. One plan: fly explosive drones into a crowd of thousands, and gun down the people running away. That's what the FBI stopped four days before UFC Freedom 250 on the South Lawn of the White House on 14 June 2026. They coordinated on Signal. End-to-end encrypted. 23 users. Zero digital intercept. ⚠️ Since the 2026 FIFA World Cup kicked off on 11 June, US authorities have recorded 145 drone incursions into restricted airspace across 8 venues, in just 6 days. More than 50 drones seized. Atlanta alone logged 36 incursions. Kansas City intercepted 8 in a single day. This is not a hobbyist problem. This is a pattern. 🛡️ On this week's Priviso Live, Lyn, Stephen, and Kayla dig into what the threat actually looks like: domestic extremists, terrorist organisations, and nation-state actors with swarm capability, GPS-spoofing, and autonomous drones that emit no radio signal at all. They look at what's been deployed: Fortem's DroneHunter net-capture system, Sentrycs' Cyber-over-RF passive detection, the USD 115 million DHS investment, SkyDome C2, TrueView radar — and they map it all against ISO/IEC 27001:2022 and NIST SP 800-53 Rev. 5. Then comes the debate: are these controls adequate? Or is the gap between physical security, information security, and counter-terrorism doctrine exactly where the adversary lives? 🇿🇦 And they bring it home: what does this mean for South African organisations protecting major events, critical infrastructure, and national key points? The lesson isn't just for the US. It's for every CISO, risk manager, and board member who still thinks physical and cyber security are two separate conversations. 🎧 Listen now on Spotify, Apple Podcasts, YouTube, iHeart, or wherever you get your podcasts. 👇 Share this with a colleague in information security. It's a conversation worth having. #PrivisoLive #InformationSecurity #CyberSecurity #DroneThreats #ISO27001 #NIST #FIFAWorldCup2026 #CriticalInfrastructure #SouthAfrica #ICTGovernance #CounterDrone #RiskManagement

About

Your dose of tips about all things Information Security, ICT Legislation and Risk. South African podcast.