The InfoSec Control Room

Taher Amine ELHOUARI

The InfoSec Control Room is a podcast by Taher Amine ELHOUARI about cybersecurity, governance, risk, compliance, resilience, and CISO-level decision-making. This show goes beyond buzzwords, checklists, and surface-level security advice. Each episode explores the gap between what organizations believe they have in place and what actually works when incidents happen, audits begin, regulators ask questions, or leadership needs to make risk-based decisions. Hosted from the perspective of a CISO/DSSI, cybersecurity governance practitioner, auditor, advisor, speaker, and community builder, The InfoSec Control Room covers practical topics across information security, GRC, CISO leadership, ISO standards, cyber resilience, privacy, incident response, CSIRT operations, security awareness, regulatory expectations, and lessons from the field. The core idea is simple: most organizations do not have a security problem. They have a governance problem that manifests as security. This podcast is for CISOs, security leaders, GRC professionals, auditors, consultants, executives, aspiring cybersecurity leaders, and practitioners who want clearer thinking, stronger controls, and governance that actually works. No noise. No checkbox compliance. No fake maturity. Just practical conversations on how security is governed, controlled, measured, and improved. https://www.TaherAmine.org/

  1. 5d ago

    EP008: Stop Lying to Yourself About Cyber Maturity

    In EP008 of The InfoSec Control Room, Taher Amine ELHOUARI takes on one of cybersecurity’s favorite activities: Measuring maturity. Organizations love maturity scores. 3.4 out of 5. Level 4. Managed. Optimized. Green dashboard. Everything looks reassuring. But what does the score actually mean? Can the organization detect an attacker? Can it restore a critical service? Can it revoke privileged access quickly? Can it prove its controls are operating? Can management make a cyber-risk decision under pressure? If not, the maturity score may be measuring confidence rather than capability. This episode explores the gap between claimed maturity and proven capability and why cybersecurity maturity assessments can become dangerously optimistic when scoring becomes the objective. Taher examines why documentation alone does not equal maturity, why self-assessments naturally drift toward generous scoring, why averages can hide dangerous weaknesses, and why technology, certifications, headcount, and dashboards should never be mistaken for real capability. Topics include: • What cybersecurity maturity should actually measure • Claimed maturity versus demonstrated capability • Why maturity scores need evidence • Documentation versus operating effectiveness • The optimism problem in self-assessments • Why averaging maturity scores can hide serious risk • Risk-based target maturity • Why not every capability needs to reach Level 5 • Maturity by procurement • SIEM, EDR, PAM, GRC tools and false confidence • Metrics that measure activity instead of outcomes • The danger of dependency on “heroic employees” • Certification versus operational maturity • Why completely green dashboards should make you nervous • Independent challenge and professional skepticism • Evidence-based maturity assessment • Control design versus control operation • Translating maturity findings into real improvement • Using maturity as governance rather than scoring One of the central ideas from EP008: A maturity claim without evidence is an opinion. And perhaps the most mature statement an organization can make is: “We are not as good at this as we thought.” Because cybersecurity maturity is not about looking advanced. It is about understanding reality well enough to improve capability, reliability, resilience, and decision-making.

    EP008: Stop Lying to Yourself About Cyber Maturity
  2. Aug 16

    EP007: Incident Response Starts Before the Incident

    In EP007 of The InfoSec Control Room, Taher Amine ELHOUARI explores a simple but often misunderstood reality: Incident response does not begin when the incident happens. By the time the first serious alert fires, many of the decisions that will determine the quality of the response have already been made. Who has authority to isolate a critical system?Who can declare a major incident?Who decides whether a business service should be interrupted?Who contacts legal, privacy, communications, executive management, customers, regulators, or external responders?Can the organization communicate if its primary collaboration platform is compromised?Can critical systems actually be restored from backup?Does the SOC know which assets matter most?And has anyone tested all of this before the pressure becomes real?This episode moves beyond the traditional detect-contain-eradicate-recover diagram and looks at incident response as an organizational capability, not simply a technical SOC function. Taher discusses how authority, escalation, asset visibility, logging, communications, crisis management, business continuity, supplier arrangements, executive decision-making, and organizational culture all shape the outcome of a cyber incident. The episode also examines why tabletop exercises should create uncomfortable decisions rather than simply confirm that a plan exists, and why serious incidents often expose weaknesses far beyond the initial technical compromise. Topics include: • Why incident response begins before detection • Decision authority during cyber incidents • Technical containment versus business impact • The hidden cost of organizational decision latency • Incident severity and escalation criteria • SOC, CSIRT, management, legal, privacy, and communications coordination • Out-of-band communications during compromised environments • Asset inventory and business criticality during investigation • Logging and visibility as incident-response capabilities • Backup restoration versus simply having backups • Connecting incident response with business continuity and disaster recovery • Supplier and third-party incident preparedness • Executive decision-making under uncertainty • Why employees must feel safe reporting mistakes quickly • Tabletop exercises that actually test the organization • Turning incident lessons into real control improvements • Feeding incidents back into GRC and risk management • Why repeated incidents reveal governance problems • Building resilience before the crisis One of the central ideas of EP007: Your response capability is built before the incident. The alert only reveals what you already prepared. Because a good incident response capability is not defined by how impressive the plan looks. It is defined by how effectively the organization can decide, coordinate, contain, communicate, recover, and learn when reality refuses to follow the plan.

    EP007: Incident Response Starts Before the Incident
  3. Aug 15

    EP006: Your Policy Is Not a Control

    In EP006 of The InfoSec Control Room, Taher Amine ELHOUARI takes on one of the most common misconceptions in information security governance: Having a policy does not mean you have a control. An organization can have approved information security policies, access control requirements, data classification rules, acceptable-use standards, incident procedures, and beautifully version-controlled documents — while real behavior tells a completely different story. A policy may say privileged access must be restricted. But who enforces it? A policy may say confidential information must be protected. But do employees know what that means when they actually handle the data? A policy may say incidents must be reported immediately. But does everyone know where, how, and to whom? This episode explores the gap between management intent and operational reality. Taher discusses why security policies only create value when they are translated into usable processes, technical controls, ownership, monitoring, evidence, enforcement, and behavior. The episode also challenges the tendency to respond to every security problem by creating yet another document. Because sometimes the organization does not need another policy. It needs to enforce the ones it already has. Topics include: • Why a policy is not automatically a control • Turning policy requirements into operational mechanisms • The difference between documented intent and real behavior • Why secure behavior must also be practical behavior • Policy requirements versus technical enforcement • Data classification beyond labels • Acceptable-use policies people actually understand • Why leadership behavior can override written policy • Policy inflation and document overload • Security culture and management accountability • Why exceptions need governance and expiry dates • Enforcement without creating a fear culture • Evidence that proves policies are actually implemented • Testing policies through audits, sampling, metrics, incidents, and exercises • Making secure behavior easier than insecure workarounds • Why control ownership matters • Moving from policy → control → evidence → monitoring → governance One of the core ideas of this episode: A policy tells the organization what it expects. A control makes that expectation real. And when the policy says one thing while systems, processes, incentives, and management behavior say another, operational reality will win every time.

    EP006: Your Policy Is Not a Control
  4. Aug 14

    EP005: GRC and SecOps Are Speaking Different Languages

    In EP005 of The InfoSec Control Room, Taher Amine ELHOUARI explores one of the most important — and often underestimated — relationships inside a cybersecurity program: the connection between GRC and Security Operations. In many organizations, GRC and SecOps behave like two neighboring countries. GRC speaks in controls, policies, risk registers, audit findings, evidence, compliance obligations, and assurance. SecOps speaks in alerts, detections, incidents, vulnerabilities, threat intelligence, EDR, SIEM, containment, and response. Both teams may be doing good work. But if they are not exchanging context, evidence, and operational reality, the organization never gets a complete picture of its cyber risk. This episode looks at what happens when governance is disconnected from operations — and when security operations operate without enough business and risk context. Taher explains why operational telemetry should become governance evidence, why GRC should consume real SOC and CSIRT data, and why SecOps needs business criticality, asset classification, risk appetite, regulatory obligations, and control objectives to properly prioritize what matters. The episode also explores how this relationship improves audit quality, incident response, risk assessment, control effectiveness, management reporting, and cybersecurity decision-making. Topics include: • Why GRC and SecOps often operate in separate worlds • The difference between operational data and governance information • Turning SOC telemetry into control-effectiveness evidence • Why GRC needs operational reality • Why SecOps needs business and risk context • Connecting incidents with risk management • Using detection and response data during audits • Asset criticality and business impact in SOC prioritization • Logging and monitoring as living controls • GRC, SOC and CSIRT alignment during incidents • Why “92% compliant” can still hide serious exposure • Translating technical findings into management decisions • Metrics that support decisions instead of decorating dashboards • Evidence generated by normal operations • Integrating audit findings, incidents, vulnerabilities and risk • Building a common language between technical and governance teams • Why cybersecurity reporting should become one shared picture One of the central ideas of this episode is simple: GRC provides context. SecOps provides reality. Mature cybersecurity happens when the two meet. Because a governance team without operational visibility is partially blind. And a SOC without governance context may be incredibly busy while still struggling to determine what matters most.

    EP005: GRC and SecOps Are Speaking Different Languages
  5. Aug 13

    EP004: The CISO Is Not a Superhero

    In EP004 of The InfoSec Control Room, Taher Amine ELHOUARI challenges one of the most common and damaging assumptions in cybersecurity governance: “We have a CISO. Cybersecurity is their responsibility.” It sounds reasonable until you start asking who actually creates, owns, accepts, and manages cyber risk across an organization. A business unit launches an application without involving security. Procurement signs a critical supplier contract without proper security requirements. Finance delays funding for a legacy-system replacement. HR does not trigger offboarding quickly enough. A business owner decides that remediation can wait because downtime would affect operations. And when something eventually goes wrong, everyone turns toward the CISO. This episode explores why that model is not cybersecurity governance — it is accountability concentrated in a job title. Taher explains the difference between leading a cybersecurity program and personally owning every cyber risk, and why mature organizations distribute responsibility across executives, business owners, technology teams, control owners, risk owners, HR, procurement, legal, operations, and security. The CISO’s role is not to become the organization’s cybersecurity superhero. It is to help design the system through which cybersecurity is governed. Topics include: • What a CISO should actually be accountable for • The difference between security leadership and risk ownership • Why business owners must own business risk • Responsibility without authority • Control ownership versus security oversight • Why CISOs become convenient cybersecurity scapegoats • Building cybersecurity as an organizational capability • The CISO as a governance architect • Translating technical findings into executive decisions • Risk acceptance and escalation • Why security should not approve everything • Distributed ownership and scalable security • Board and executive responsibilities for cyber risk • Incident governance and decision authority • Why mature security programs should survive without individual heroes One of the central ideas of the episode: The CISO does not own every cyber risk. The CISO helps the organization understand, govern, and manage cyber risk. Because if one person is responsible for everything while controlling almost nothing, that is not governance. That is a very stressed person with an impressive job title.

    EP004: The CISO Is Not a Superhero
  6. Aug 12

    EP003: Compliance Is Not Control

    In EP003 of The InfoSec Control Room, Taher Amine ELHOUARI explores the uncomfortable gap between being compliant and actually being in control. An organization can have approved policies, completed audits, risk registers, procedures, evidence, management reviews, and even certifications on the wall; while still struggling to answer very simple questions: Can we actually restore our critical systems? Who really owns this risk? Are our controls operating consistently? Does our evidence reflect reality, or was it prepared because an audit was coming?This episode is not an argument against compliance. Quite the opposite. Compliance, standards, audits, certification, and structured management systems can create tremendous value when they support real governance, risk management, accountability, and continuous improvement. The problem starts when the objective quietly changes from: “Are we improving security?” to: “Will we pass the audit?” Taher discusses what he calls audit-season security, why a policy is not automatically a control, why evidence should be produced by normal operations rather than reconstructed before an audit, and why certification should be understood as part of a living management system rather than the finish line. The episode also explores the practical relationship between compliance, audit, GRC, SecOps, management, and technical teams; and why all of them need to work from the same operational reality. Topics include: • Compliance versus control • Conformity versus operating effectiveness • Audit-season security • Why documentation alone does not create maturity • Evidence by design • Control ownership and risk ownership • Internal audit as a tool for improvement • Repeated findings and root-cause thinking • Making management reviews actually produce decisions • Connecting GRC with SOC, CSIRT, and operational security • Why compliance percentages can create false comfort • Turning certification into continuous assurance • Moving from requirements to control, evidence, assurance, and resilience The key question of the episode is simple: Compliance can tell you what should happen. Control tells you what happens. So the next time someone says, “We are compliant,” ask one more question: “How do we know we are actually in control?”

    EP003: Compliance Is Not Control
  7. Aug 12

    EP002: The Real Reason Security Programs Fail

    In this episode of The InfoSec Control Room, Taher Amine ELHOUARI explores one of the core ideas behind the podcast: many security programs do not fail because there is no cybersecurity activity. They fail because that activity is not governed, owned, measured, or improved properly. The episode explains why security failures are often symptoms of deeper structural issues: unclear accountability, weak ownership, poor risk decisions, ineffective controls, disconnected teams, compliance theater, weak escalation, and the gap between documentation and real operational capability. Rather than blaming tools, users, auditors, SOC teams, or CISOs alone, this episode looks at the full system behind security programs and asks a more important question: why did the organization allow the weakness to exist, persist, and become dangerous? Topics include: • Why security failures are rarely purely technical • The difference between security activity and security capability • Governance gaps behind incidents and audit failures • Ownership, accountability, and risk decisions • Why tools cannot compensate for weak governance • Compliance theater and false maturity • The gap between policies, controls, and real behavior • How technical, GRC, SOC, CSIRT, management, and executive teams become disconnected • What security programs need in order to actually work No noise. No fake maturity. No checkbox security. Just practical conversations on how security is governed, controlled, measured, and improved.

    EP002: The Real Reason Security Programs Fail
  8. Aug 10

    EP001: Welcome to The InfoSec Control Room

    In this first original episode of The InfoSec Control Room, Taher Amine ELHOUARI formally introduces the podcast, the story behind it, and the core philosophy that will guide future episodes. This opening episode explains why The InfoSec Control Room exists, who it is for, and why cybersecurity must be understood beyond tools, incidents, vulnerabilities, frameworks, and technical controls. Taher introduces his background across information security, cybersecurity governance, GRC, SecOps, CSIRT, audit, risk management, resilience, advisory, training, public speaking, and CISO-level decision-making. He also explains why many security programs fail not because they lack activity, but because they lack governance, ownership, accountability, evidence, discipline, and real control. The episode sets the tone for the original series: practical, strategic, field-based, and built for engineers, experts, managers, auditors, GRC professionals, SOC and CSIRT teams, CISOs, executives, students, and decision-makers. Topics include: • The purpose behind The InfoSec Control Room • Who Taher Amine ELHOUARI is and why he created the podcast • Why cybersecurity is more than a technical discipline • The difference between security activity and real security capability • Governance as the root cause behind many security failures • The gap between engineers, managers, auditors, executives, GRC, SOC, and CSIRT teams • Why compliance, documentation, and tools are not enough • What future original episodes will cover • The mission of building security that is governed, controlled, measured, and improved No noise. No fake maturity. No checkbox security. Just practical conversations on how security is governed, controlled, measured, and improved. https://www.taheramine.org/podcast.html

    EP001: Welcome to The InfoSec Control Room

About

The InfoSec Control Room is a podcast by Taher Amine ELHOUARI about cybersecurity, governance, risk, compliance, resilience, and CISO-level decision-making. This show goes beyond buzzwords, checklists, and surface-level security advice. Each episode explores the gap between what organizations believe they have in place and what actually works when incidents happen, audits begin, regulators ask questions, or leadership needs to make risk-based decisions. Hosted from the perspective of a CISO/DSSI, cybersecurity governance practitioner, auditor, advisor, speaker, and community builder, The InfoSec Control Room covers practical topics across information security, GRC, CISO leadership, ISO standards, cyber resilience, privacy, incident response, CSIRT operations, security awareness, regulatory expectations, and lessons from the field. The core idea is simple: most organizations do not have a security problem. They have a governance problem that manifests as security. This podcast is for CISOs, security leaders, GRC professionals, auditors, consultants, executives, aspiring cybersecurity leaders, and practitioners who want clearer thinking, stronger controls, and governance that actually works. No noise. No checkbox compliance. No fake maturity. Just practical conversations on how security is governed, controlled, measured, and improved. https://www.TaherAmine.org/