Podcast charts
Published by Center for Internet Security
Welcome to video version of “Cybersecurity Where You Are,” the podcast of the Center for Internet Security® (CIS®). Cybersecurity affects us all, so join us on Wednesdays as Sean Atkinson, CISO at CIS; Tony Sager, SVP & Chief Evangelist at CIS; and Ed Skoudis, President of the SANS Technology Institute discuss trends and threats, explore security best practices, and interview experts in the industry. Together, we’ll clarify these issues, Creating Confidence in the Connected World®. Subscribe to the audio version of our podcast here: https://fast.wistia.net/embed/channel/wbyhaw35xf?wchannelid=wbyhaw35xf.
On the charts
Every published chart this podcast appears in, in the snapshot behind this page. Each one links to the chart it came off.
From the feed
The latest episodes published to this podcast’s own RSS feed. Titles and descriptions are the publisher’s.
In episode 203 of Cybersecurity Where You Are, Sean Atkinson speaks with Pavlina Pavlova , Founder of Critical Cyber . Together, they discuss how Pavlina started Critical Cyber to go beyond the data and give voice to the human impact of cyber attacks, from ransomware hitting hospitals to cyber tactics targeting civilians in active conflict zones. Here are some highlights from our episode: 00:44 . How Pavlina's work covering the impact of cyber attacks on Ukrainian critical infrastructure led to Critical Cyber 03:13 . How Critical Cyber works with cyber attack victims, responders, and other audiences 04:08 . Countering the tendency, even among cybersecurity experts, to sanitize cyber attacks' human impact 08:57 . The use of storytelling with those impacted by cyber attacks to drive policy changes 15:02 . Why cyber attacks in some sectors are underreported 19:01 . Critical Cyber's mission of combining testimony, research, and expert collaboration 24:51 . Where Critical Cyber is and where it's looking to go Resources Critical Cyber Cybersecurity for Critical Infrastructure Episode 202: Delineating AI Security and Cybersecurity Recent Water Utility Attacks Offer a Blueprint for Resilience If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org .
In episode 202 of Cybersecurity Where You Are, Sean Atkinson and Ed Skoudis sit down with Rob T. Lee , Chief of Research & Chief AI Officer at the SANS Institute. Together, they explore how the implications of multiple 2026 sandbox escapes of artificial intelligence (AI) models are starting to delineate AI security and cybersecurity. Here are some highlights from our episode: 02:00 . The historical context of one AI model's 2026 sandbox escape 03:26 . The impact of ethics, guardrails, and misconfigurations in an AI containment breach 06:08 . Why context matters when talk of AI models "going rogue" surfaces 11:49 . How history helps us to delineate AI security and cybersecurity 13:47 . A new skill and mindset to match our refined AI risk understanding 15:43 . Rules and cybersecurity implementation as a possible way forward 19:04 . The double-edged sword of restricting access to open-weight models 23:25 . Recommendations for keeping up with what's changing in the AI security space 25:51 . Rob's advice: To learn how to defend a thing, try learning how to build it first 28:23 . AI governance and seeing through the "slop" to informed conversation 29:54 . The use of AI to learn more about and discuss AI security for years to come Resources OpenAI says its AI technology acted on its own in an ‘unprecedented’ hack of another company Pacing model development in an era of cyber-critical capabilities Black Hat USA 2026 | The 'Breaking' News: The OpenAI–Hugging Face Incident Episode 193: AI Security and Responsibility in EO 14409 The AI Daily Brief — Daily AI News & Analysis AI Playbooks for SLTT Cybersecurity Leaders SANS Cybersecurity Summits SANS NewsBites If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org .
In episode 201 of Cybersecurity Where You Are, Sean Atkinson and Ed Skoudis sit down with William Wright , Chief Executive Officer of Closed Door Security. Together, they reflect on the evolution of penetration testing, including the impact on pentesting from artificial intelligence (AI). Here are some highlights from our episode: 01:03 . How things have changed since William's and Ed's first pentests 09:02 . Community: A defining element of Capture The Flag (CTF) events 14:47 . Industry concerns over the "death" of CTFs and "cheating" by artificial intelligence (AI) 17:00 . Opportunities to take CTFs to the next level in the age of AI 20:18 . Pentesting vs. vulnerability scanning: Why terminology matters 25:43 . The advent of autonomous AI tools and what they could mean for vulnerability scanning 29:07 . Why continuous improvement in cybersecurity doesn't always require AI Resources Closed Door Security Episode 189: The Present and Future of AI-enabled Pentesting SANS Cyber Ranges Top External Network Risks And How to Fix Them Penetration Testing Vulnerability Assessments If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org .
In episode 200 of Cybersecurity Where You Are, Sean Atkinson, Tony Sager, and Ed Skoudis sit down with Frank Reeder , Co-Founder and Founding Chair of the Center for Internet Security® (CIS®). Together, they reflect on how Alan Paller's vision continues to drive CIS forward. In the spirit of that vision, this milestone episode also marks a new chapter for the podcast: Ed Skoudis joins as co-host of Cybersecurity Where You Are. Here are some highlights from our episode: 01:09 . The two complementary missions of CIS 02:55 . Three defining moments that have shaped CIS into the organization it is today 08:10 . The story of naming CIS 10:31 . How CIS and SANS advance Alan Paller's vision of bringing people together 13:50 . Personal anecdotes of Alan Paller as a connector of people 15:45 . "What would Alan do?" A question that continues to guide CIS and SANS 22:00 . How CIS security best practices are emblematic of helping others 27:12 . CIS's "secret sauce" as a trusted, neutral platform for cybersecurity collaboration 29:53 . How CIS can continue to embody Alan Paller's philosophy into the future 37:47 . A special announcement: Ed Skoudis as a new co-host on the podcast Resources CIS Benchmarks® List CIS Critical Security Controls® Multi-State Information Sharing and Analysis Center® Episode 114: 3 Board Chairs Reflect on 25 Years of Community Alan Paller Laureate Program SANS Difference Makers Awards If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org .
In episode 199 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager sit down with Chris Painter , Chair of the Risk Committee and Board Member at the Center for Internet Security® (CIS®). Together, they discuss how chief information security officers (CISOs) can support the work of translating cyber risk into business decisions by Boards. Here are some highlights from our episode: 00:50 . Introductions to Chris 01:36 . The single biggest translation error Chris has seen CISOs make 07:38 . Cyber risk quantification: An opportunity to go beyond translation for Boards 09:25 . How ransomware changed Boards' understanding of cyber risks' business impact 10:45 . The value of tabletop exercises (TTX) and other simulations in creating shared language 13:26 . Recommendations on how to make the most of a TTX 18:37 . Risk modeling and how artificial intelligence (AI) complicates probability estimations 21:51 . "Pressure" (2026) as an illustration of making good, not 100% accurate, estimations 22:58 . How growing public awareness of cyber is reshaping CISOs' conversations with Boards 25:55 . The importance of walking Boards through risk mitigation steps with AI as an example 29:31 . A recommendation for how CISOs can learn what directors care about 30:15 . From "wizardry" to familiarity: An ongoing generational shift around cyber Resources Episode 183: The Role of CISO in Supporting Risk Translation Episode 187: The Role of a CISO as a Strategic Storyteller Episode 192: How Leaders Balance Expertise and Communication How Risk Quantification Tests Your Reasonable Cyber Defense CIS RAM (Risk Assessment Method) Leveraging Generative Artificial Intelligence for Tabletop Exercise Development CIS Controls v8.1 Incident Response Policy Template You Have a Cybersecurity Incident. Now What? Prompt Injections: The Inherent Threat to Generative AI "Pressure" | Official Website | 29 May 2026 If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org .
In episode 198 of Cybersecurity Where You Are, Sean Atkinson discusses artificial intelligence (AI) and privacy from a risk-based cybersecurity perspective. Together, he explores how organizations and individuals can assess AI risk, apply governance frameworks, evaluate third-party AI services, and balance innovation with due diligence. Here are some highlights from our episode: 00:41 . Framing the conversation around AI, privacy, and risk-based controls 02:22 . Due diligence and ethical considerations around AI products and services 03:14 . Data minimization and transparency as foundations for AI privacy 04:46 . Privacy impact assessments as a way to understand AI data collection and use 05:42 . AI governance and the tension between implementation velocity and risk management 10:08 . The use of existing data flows and controls in AI assessments 11:57 . Algorithmic transparency and the challenge of understanding AI decision making 13:47 . Standards, frameworks, and data sovereignty in AI privacy governance 15:12 . Encryption, anonymization, tokenization, and federated learning as privacy safeguards 16:40 . The need to shift stakeholder input left in AI development and deployment lifecycles 19:13 . Building literacy around security, data management, privacy, and AI risk 23:40 . The value of cross-functional and written assessment criteria for AI risk 26:21 . A call to action for keeping pace with AI privacy and and innovation risk Resources CIS Controls v8.1.2 AI Security Guidance Workbook Episode 105: Context in Cyber Risk Quantification Service Provider Management Policy Template for CIS Control 15 EU AI Act: first regulation on artificial intelligence AI Risk Management Framework IAPP AI Governance Center Episode 120: How Contextual Awareness Drives AI Governance Secure by Design v1.1 A Guide to Assessing Software Security Practices Reasonable Cybersecurity If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org .
In episode 197 of Cybersecurity Where You Are, Sean Atkinson sits down with Ben Wilcox , Chief Technology Officer and Chief Information Security Officer at ProArch; and Ed Skoudis , President of SANS Technology Institute. Together, they discuss artificial intelligence (AI), operational technology (OT) data, and how understanding creates the foundation for AI-ready OT data. Here are some highlights from our episode: 00:54 . Introductions to Ben and Ed 02:16 . How we understand and integrate AI into OT environments 04:30 . How OT diverges from information technology (IT) in data responsibilities 05:23 . Opportunities for AI to assist OT 06:33 . The importance of meeting OT systems where they are 08:10 . A passive and incremental approach that respects the operations machines are doing 12:29 . Efficiency gains, public safety improvements, and other benefits of AI-ready OT data 17:47 . What lifecycle management, asset hierarchies, and governance look like for OT data 22:14 . The promise of AI to help to make OT environments understandable 23:19 . A team sport: How IT and OT can work together to understand assets and data 28:38 . The need for translation in IT-OT communication 29:01 . Recommendations for how to make OT data AI ready Resources CIS Critical Security Controls® CIS Controls version 8.1 ICS Workbook Artificial Intelligence and Large Language Models Companion Guide CIS Controls v8.1 Enterprise Asset Management Policy Template CIS Controls v8.1 Software Asset Management Policy Template CIS Controls v8.1 Data Management Policy Template CIS Controls v8.1 Account & Credential Management Policy Template Establishing Essential Cyber Hygiene ProArch Cybersecurity for Critical Infrastructure Episode 77: Data's Value to Decision-Making in Cybersecurity Episode 183: The Role of CISO in Supporting Risk Translation If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org .
In episode 196 of Cybersecurity Where You Are, Sean Atkinson sits down with Sasha Larkin , Director of Intelligence and C4 Operations for FIFA World Cup 2026, and John Cohen , Executive Director of the Office of Strategic Programs and Initiatives at the Center for Internet Security® (CIS®). Together, they discuss how CIS, FIFA, and FIFA World Cup 2026 host cities started collaborating in 2025 on cybersecurity, public safety, intelligence, and information-sharing efforts supporting the largest sporting event in the world. Here are some highlights from our episode: 00:40 . Introductions to Sasha and John 02:07 . Overview of one of the most complex public safety efforts assembled for a sporting event 05:52 . Consistency: A standard for preventing and deterring threats at FIFA World Cup 2026 10:30 . The impact of relationships in shaping FIFA's security ops and information sharing 11:53 . Effective communication: The key to cross-functional collaboration in support of the tournament 18:07 . The importance of information that guides operations 20:35 . Education as a way to inform stakeholders and deploy resources 26:19 . A deliberate effort to look at unanticipated threats and plan for them 29:14 . Examples of messaging synchronization in support of FIFA World Cup 2026 32:37 . An all-hands-on-deck support campaign from CIS 33:29 . Parting thoughts around large-scale event support in the future Resources An Examination of Generative AI and Physical Threat Planning An Examination of AI-Enabled Threats to Event and Stadium Security Multidimensional Threats 5 Major Emerging Risks to Large-Scale Events Illicit Sports Betting and Match Integrity Risks to Large-Scale Events Deepfakes and Synthetic Media: The Emerging Threat to Large-Scale Public Gatherings Growing Risks to Digital Ticketing Platforms for Large-Scale Events Unmanned Aircraft Systems (UAS): Evolving Risks to Large-Scale Public Gatherings Unmanned Aircraft Systems (UAS): Evolving Risks to Large-Scale Public Gatherings Cyber Risks Companion Guide 5 Steps to Help Secure Your City before a Large-Scale Event If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org .
In episode 195 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager sit down with Ed Skoudis , President of SANS Technology Institute, and Marcus Sachs , Senior Vice President and Chief Engineer at the Center for Internet Security® (CIS®). Together, they discuss Enigma machines, their history, and their security lessons for today. Here are some highlights from our episode: 00:56 . Introductions to Ed and Marc 01:32 . What Enigma machines are and why cybersecurity folks still care about them today 06:10 . Enigma machines as a symbol for how we can use hacking for noble purposes 07:18 . How the human mind and the need for ease of use can undermine security 15:59 . The importance of testing when designing and maintaining a security system 20:45 . Why "security through obscurity" isn't actually true 22:58 . Curiosity, logic, and a wide range of knowledge: Essential traits for getting hired in cybersecurity today 30:57 . The impact of culture in shaping security policy and priorities 35:09 . Why artificial intelligence (AI) is the Enigma machine of 2026 36:11 . How to learn more about Enigma machines Resources Episode 189: The Present and Future of AI-enabled Pentesting A Short Guide for Spotting Phishing Attempts Penetration Testing Vulnerability Assessments Episode 192: How Leaders Balance Expertise and Communication Episode 193: AI Security and Responsibility in EO 14409 The Myth of Mythos: What It Means For Information Security National Cryptologic Museum Enigma Replica: The Enigma touch If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org .
In episode 194 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager sit down with Ed Skoudis , President of SANS Technology Institute. Together, they conduct a mid-year review of 2026 cybersecurity predictions from seven Center for Internet Security® (CIS®) experts, as shared on the CIS website . Here are some highlights from our episode: 01:50 . Ongoing conversations about improving defense with artificial intelligence (AI) 05:19 . A trap to avoid: Automating things with AI because we can regardless of utility 06:54 . Ed's prediction about a near-term transition for AI-enabled vulnerability discovery 09:27 . How AI agents change the economics around conducting a penetration test 11:26 . Adversary emulation: A blurry proposition when threat actors use AI to look like anybody 14:02 . Ed's prediction about threat actors shifting APT profiles within a single attack campaign 17:00 . The need to systematically rethink cyber defense to support state and local cybersecurity 23:34 . How adversaries are pivoting to the "authorization sprawl" in light of zero trust efforts 29:20 . Industry-specific threat intelligence as a way to keep organizations informed 32:10 . Why a policy isn't the same as security control for operational technology (OT) 33:55 . Social expectations and public policy objectives around holistic OT security 39:52 . Compliance as a floor, not a ceiling, that results as a byproduct of continuous security 43:43 . The need for oversight and confidence in technology as distinct from the "Fog of More" Resources Episode 169: 2026 Cybersecurity Predictions from CIS — Pt 1 Episode 174: 2026 Cybersecurity Predictions from CIS — Pt 2 Episode 179: 2026 Cybersecurity Predictions from CIS — Pt 3 The Myth of Mythos: What It Means For Information Security Episode 189: The Present and Future of AI-enabled Pentesting Authorization Sprawl: The Vulnerability Reshaping Modern Attacks Episode 188: DBIR 2026 Insights and Collaboration with CIS Mapping and Compliance with the CIS Controls Mapping and Compliance with the CIS Benchmarks If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org .
In episode 193 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager sit down with Rob T. Lee , Chief of Research & Chief AI Officer at the SANS Institute, and Brian Calkin , Chief Technology and Innovation Officer at the Center for Internet Security® (CIS®). Together, they discuss AI security and the responsibility of the U.S. government in creating confidence around it, as represented in Executive Order (EO) 14409, "Promoting Advanced Artificial Intelligence Innovation and Security." Here are some highlights from our episode: 00:50 . Introductions to Rob and Brian 02:32 . How to conceptualize confidence around something as complex as AI security 04:32 . The U.S. government's responsibility to set AI security guardrails as clear expectations 08:12 . The use of "voluntary" participation to create confidence in the context of EO 14409 14:38 . How Mythos AI and similar developments affect assessment of frontier AI models 17:11 . Airport security as an analogy for understanding AI security and privacy concerns 18:41 . Why cybersecurity is a hard sell until an incident occurs 20:50 . How AI is quickly becoming critical infrastructure 22:53 . Furbies as reference for a flexible, iterative benchmarking process for AI security 25:50 . The need for technical folks to translate AI risks into something understandable 28:21 . Balancing encouragement of AI innovation with mindfulness of risk 31:24 . The basics as a foundation for building shared responsibility around AI security Resources Promoting Advanced Artificial Intelligence Innovation and Security The Myth of Mythos: What It Means For Information Security Episode 190: Separating Mythos AI Fact from Fiction The “AI Vulnerability Storm”: Building a “Mythos-ready” Security Program Anthropic says it has taken its latest AI models offline to comply with new export controls Establishing Essential Cyber Hygiene Episode 187: The Role of a CISO as a Strategic Storyteller If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org .
In episode 192 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager sit down with Marcus Sachs , Senior Vice President and Chief Engineer at the Center for Internet Security® (CIS®). Together, they discuss how leaders, including those in cybersecurity, balance their technical expertise with mastery of communication strategies. Here are some highlights from our episode: 00:51 . Introductions to Marcus 02:04 . How Marcus found value in using analogies to communicate complex topics 08:40 . Coordination with non-technical folks as a sign of leadership maturity 14:03 . The wisdom in knowing what to say and what not to say when managing up 17:31 . The need to balance technical skills with team resourcing in a way that's imitable 21:07 . The challenge of leaders learning by proximity in hybrid and remote environments 24:16 . "Classic" engineering vs. "new" engineering 25:13 . Lessons from Boards in applying discipline, rigor, and order to software engineering 28:23 . The value in leaders continuously learning how businesses work Resources Episode 183: The Role of CISO in Supporting Risk Translation Episode 187: The Role of a CISO as a Strategic Storyteller Episode 99: How Cyber-Informed Engineering Builds Resilience 7 CIS Experts' 2026 Cybersecurity Predictions If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org .
In episode 191 of Cybersecurity Where You Are, Sean Atkinson sits down with Sasha Elvenaes, Sr. Multidimensional Threat Analyst at the Center for Internet Security® (CIS®), and Rian Davis, Multidimensional Threat Analyst at CIS. Together, they discuss how threat actors are misusing generative artificial intelligence (GenAI) to plan physical threats. Here are some highlights from our episode: 00:40 . Introductions to Sasha, Rian, and their research on GenAI misuse 01:56 . The impact of GenAI on lowering the barrier for operationalizing physical threat activity 03:37 . Exploitation of GenAI model design to circumvent models' guardrails 05:58 . The misuse of session persistence to streamline physical threat research 07:57 . GenAI misuse: A call for critical infrastructure operators to think about security differently 11:52 . Factors that make large-scale events a target of physical threat activity 14:33 . The use of GenAI as a strategy for organizations to see what threat actors could see 15:37 . Ongoing question: How can drones help mitigate risks while protecting public safety? 17:13 . Extrapolation as a reinforcement of GenAI session persistence 20:15 . The new reality: Look at what information AI can provide to threat actors 25:01 . Traditional methods vs. GenAI conversations for threat planning 27:58 . Continuous vulnerability assessments, communication, and other recommendations Resources An Examination of Generative AI and Physical Threat Planning An Examination of AI-Enabled Threats to Event and Stadium Security Multidimensional Threats Man who exploded Cybertruck in Las Vegas used ChatGPT in planning, police say Episode 190: Separating Mythos AI Fact from Fiction Episode 185: AI Prompt Injection from a Risk Perspective 5 Steps to Help Secure Your City before a Large-Scale Event Unmanned Aircraft Systems (UAS): Evolving Risks to Large-Scale Public Gatherings 8 Security Essentials for Managing Your Online Presence Vulnerability Assessments If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org .
In episode 190 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager sit down with Brian Calkin , Chief Technology and Innovation Officer at the Center for Internet Security® (CIS®). Together, they separate fact from fiction around artificial intelligence (AI) capabilities like Mythos AI and other AI-driven vulnerability discovery tools. Here are some highlights from our episode: 00:50 . Greetings to Brian and setting the stage for questions from a CIS webinar 03:05 . The lack of a unified formula or standard for vulnerability prioritization 03:55 . The opportunity for defenders to interrupt vulnerabilities chained together 05:47 . An invitation to better understand your enterprise amid the "slopdemic" 06:33 . How AI guardrails tie back into security best practices 10:15 . How a fundamental practice we can refine is the best counter to chained attacks 12:25 . The value of the CIS Community Defense Model and a teaser for Version 3 14:50 . Mythos AI vs. Static Application Security Testing (SAST) in terms of practice and time 19:08 . Visibility, governance, and prioritization: Three elements of a "prepared" environment 24:32 . "One to one" cyber defense as a losing battle 27:25 . The importance of knowing your dependencies with open-source software 33:15 . Threat actor economics and the ongoing debate around responsibility in cybersecurity Resources Mythos AI: What Actually Matters for Cybersecurity Leaders Secure by Design CIS Critical Security Controls® CIS Community Defense Model 2.0 Episode 185: AI Prompt Injection from a Risk Perspective Living off the Land: Threats Looming From Within Turn Intel Into Action: CIS Controls and the 2026 Verizon DBIR Implementation Guide for Small- and Medium-Sized Enterprises CIS Controls IG1 Information Technology and Information Security Governance If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org .
In episode 189 of Cybersecurity Where You Are, Sean Atkinson sits down with Ed Skoudis , President of SANS Technology Institute. Together, they discuss the present and future of pentesting enabled by artificial intelligence (AI). Here are some highlights from our episode: 00:39 . Introductions to Ed 01:49 . The promise of AI-enabled pentesting in creating more secure infrastructure 04:52 . AI-enabled and AI-centric workflows in the realm of penetration testing 08:03 . Wranglers, matadors, and centaurs, oh my! Metaphors for AI-enabled pentesters 13:00 . How AI can assist with reporting, enumeration, and scanning as part of a pentest 14:57 . AI-enabled source-assisted pentesting and the types of vulnerabilities it finds 19:50 . A learning opportunity for the broader cybersecurity community 23:44 . How AI and human analysts could split the workload in a future penetration test 25:54 . AI-enabled pentesting vs. AI pentester in a box 29:51 . Why "human in the loop" might be too passive a phrase 30:37 . The use of AI for source code development Resources Mythos AI: What Actually Matters for Cybersecurity Leaders Secure by Design SEC543: AI-Assisted Source Code Analysis and Exploitation for Penetration Testers Episode 108: Gaming and Competition in Cybersecurity Episode 59: Probing the Modern Role of the Pentest If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org .
In episode 188 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager sit down with Philippe "Phil" Langlois , Data Breach Investigations Report (DBIR) Author at Verizon; and Charity Otwell , Director of the CIS Critical Security Controls® (CIS Controls®) at the Center for Internet Security® (CIS®). Together, they discuss some of the top insights of the 2026 DBIR and how CIS contributed to the publication. Here are some highlights from our episode: 00:50 . Introductions to Phil and Charity 02:46 . Vulnerability exploitation as the most common attack vector 05:25 . The role of artificial intelligence (AI) in threat actors' natural system thinking 07:03 . The need for clear governance and responsibility around vulnerability management 08:58 . Insight into the types of techniques threat actors research using frontier AI models 13:43 . A trending drop in ransomware payouts and organizations willing to pay attackers 14:59 . Why a healthy dose of distrust goes a long way in assessing attackers' claims of victims 16:24 . How two ransomware groups stand out above the norm 17:49 . The ongoing risk surrounding vendor, supplier, and other third party exposure 22:34 . The need for governance in managing data issues involving the use of AI 27:14 . Three ways in which CIS contributed to the 2026 DBIR 34:02 . How the 2026 DBIR informs the CIS Controls and parting actionable steps Resources 2026 Data Breach Investigations Report CIS Critical Security Controls® Episode 87: Marking 11 Years as a Verizon DBIR Contributor Mythos AI: What Actually Matters for Cybersecurity Leaders Applying the CIS Controls to Real‑World AI Environments CIS Community Defense Model 2.0 The Conti Leaks: A Case of Cybercrime’s Commercialization If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org .
In episode 187 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager discuss how the role of a CISO functions as a strategic storyteller of cyber risk while keeping the bigger picture in mind. Here are some highlights from our episode: 00:51 . Framing the conversation around CISOs' efforts to communicate with the business 02:01 . Translation: A nuanced practice of simplifying the story while still telling the truth 02:41 . The need for a CISO to bridge their organization's respective "culture gap(s)" 04:13 . Collaborative and dictatorial: Two different ways CISOs talk to a business 06:07 . The work of translation in motivating and informing action around perceived risk 07:03 . Security sampling: A story from Tony that reminds CISOs of the bigger picture 09:55 . Fewer wizards and more mechanics: What the cybersecurity industry needs today 12:20 . Two factors to consider: Politicking and the need to provide an accessible narrative 15:49 . Rapport and tradecraft as two critical tools supporting the role of a CISO 18:09 . Technical competence as a prerequisite for confidence in risk conversations 19:20 . The false sense of security from relying on comparative data with competitors 22:14 . The CISO as a strategic storyteller who helps the business make decisions 27:03 . The need for machinery to constantly rediscover and recreate trust 30:15 . A call to action for Boards: Build vernacular in cybersecurity risk space 35:03 . CISO as a strategic storyteller vs. CISO as an enforcer Resources CIS Critical Security Controls® CIS Community Defense Model 2.0 Episode 183: The Role of CISO in Supporting Risk Translation Episode 166: Foundations of Actuarial Science in Cyber Risk Episode 121: The Economics of Cybersecurity Decision-Making NICE Workforce Framework for Cybersecurity (NICE Framework) If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org .
In episode 186 of Cybersecurity Where You Are, Tony Sager sits down with Tony Krzyzewski , a CIS Critical Security Controls® (CIS Controls®) Ambassador for the Center for Internet Security® (CIS®). Together, they discuss how strong cyber defense starts with the fundamentals of IT operations. Here are some highlights from our episode: 00:45 . Introductions to Tony Krzyzewski and his background 02:19 . Tony Krzyzewski's first interaction with the CIS Controls 03:47 . IT operations: The foundation that makes strong cyber defense possible 06:20 . How an increasingly connected world makes the CIS Controls essential to cybersecurity 09:56 . The need for operations people to realize they're part of the cybersecurity solution 13:11 . The use of Implementation Groups to reduce overload on IT and security teams 16:52 . How the CIS Controls differ from "umbrella frameworks" like NIST CSF and ISO 27001 18:25 . CIS Controls mappings and how they help to simplify a surplus of good guidance 20:35 . How the CIS Controls support improvement programs and Board-level conversations 25:38 . Tony Krzyzewski's work in creating the CIS Controls Ambassador program 27:02 . Why a deep view of what's happening at CIS supports Tony Krzyzewski's efforts 30:11 . Growing international promotion of the CIS Controls and "doing the basics well" Resources CIS Critical Security Controls® CIS Controls Ambassador Spotlight: Tony Krzyzewski Episode 160: Championing SME Security with the CIS Controls Episode 168: Institutionalizing Good Cybersecurity Ideas Episode 172: Helping CISOs as a CIS Controls Ambassador Episode 181: Supply and Demand of Cybersecurity Ecosystems Guide to Implementation Groups (IG): CIS Critical Security Controls v8.1 Reasonable Cybersecurity Mappings to Security Frameworks Translations Policy Templates Securing the AI Ecosystem Begins at the Model Layer If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org .
In episode 185 of Cybersecurity Where You Are, Sean Atkinson sits down with Brian Calkin , Chief Technology and Innovation Officer at the Center for Internet Security® (CIS®); Theodore "TJ" Sayers, Senior Director of Threat Intelligence at CIS; and Kyle Leonard, Cyber Threat Intelligence Analyst at CIS. Together, they use a risk perspective to discuss artificial intelligence (AI) prompt injection and how to defend against it. Here are some highlights from our episode: 00:49 . A definition of AI prompt injection for businesses and executives 02:16 . Brian on his role of guiding AI implementation at CIS 03:12 . Understanding the urgency surrounding AI prompt injection as a security risk 05:32 . Signals and trends indicative of threat actors attempting to weaponize prompt injection 07:10 . How AI prompt injection differs from traditional input validation vulnerabilities 11:13 . Early indicators that cyber threat intelligence (CTI) teams can monitor 15:00 . The need to treat AI as a new identity in any enterprise implementation strategy 17:10 . Understanding the difference: AI safety vs. AI security 20:36 . Foundational, practical AI security that extends across all sectors 24:55 . How CIS manages risk and supports the opportunity around the use of AI 28:25 . The long-term promise of AI-driven vulnerability discovery grounded in fundamentals 34:48 . Recommendations for piercing through the marketing hype surrounding AI Resources Prompt Injections: The Inherent Threat to Generative AI New CIS Report Warns Prompt Injection Attacks Pose Growing Risk to Generative AI Episode 182: Striking a Balance on an AI Adoption Journey Episode 120: How Contextual Awareness Drives AI Governance Mythos AI: What Actually Matters for Cybersecurity Leaders Applying the CIS Controls to Real‑World AI Environments An Examination of Generative AI and Physical Threat Planning AI Playbooks for SLTT Cybersecurity Leaders If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org .
In episode 184 of Cybersecurity Where You Are, Sean Atkinson sits down with Brock Boggs, Director of Technology at Cityscape Schools and Multi-State Information Sharing and Analysis Center® (MS-ISAC®) member . Together, they discuss how Brock approaches cybersecurity policy development as a journey at his school. Here are some highlights from our episode: 01:21 . Brock's first attempt at drafting an IT security policy manual 04:17 . Fact or fiction? How the best "written" security program doesn't always translate 06:35 . A starting policy landscape of creating baselines for cybersecurity, ticketing, and more 08:40 . How Brock learned about a roadmap for his school at ISAC Annual Meeting 2023 11:07 . Lean and to the point: The second draft of Brock's IT security policy manual 12:37 . The use of Center for Internet Security® (CIS®) policy templates to write procedures 19:34 . How Brock used regular updates about his policy manual to secure stakeholder buy-in 28:42 . Openness, willingness to fail, and adaptability as strengths of the community 31:49 . Approaching cybersecurity policy development as an ever-changing journey Resources CIS Critical Security Controls® Policy Templates Formalizing K-12 Cybersecurity Policies in Less Time Episode 163: K-12 Cybersecurity Made Practical Episode 176: A Cybersecurity Journey of Incremental Wins Guide to Implementation Groups (IG): CIS Critical Security Controls v8.1 CIS SecureSuite® Membership If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org .
Ranking source
Apple Podcasts rankings via the Mato Topic Intelligence Platform.
Observed September 19, 2026.
Apple and Apple Podcasts are trademarks of Apple Inc., registered in the U.S. and other countries.
Pairs with
Bring this source into Mato to read its transferable patterns, then turn them into an original show for your own audience.