Cybersecurity Where You Are (audio) - podcast cover

Cybersecurity Where You Are (audio)

Center for Internet Securityfast.wistia.net
Welcome to audio version of “Cybersecurity Where You Are,” the podcast of the Center for Internet Security® (CIS®). Cybersecurity affects us all — whether we’re online at home, managing a company, supporting clients, or running a state or local government. Join us on Wednesdays as Sean Atkinson, CISO at CIS, and Tony Sager, SVP & Chief Evangelist at CIS, discuss trends and threats, explore security best practices, and interview experts in the industry. Together, we’ll clarify these issues, creating confidence in the connected world. Subscribe to the video version of our podcast here: https://fast.wistia.net/embed/channel/0l9fss300m?wchannelid=0l9fss300m.
Last refreshed:
Follow this podcast in the Metacast mobile app to refresh it and see new episodes.
Download Metacast podcast app
Podcasts are better in Metacast mobile app
Don't just listen to podcasts. Learn from them with transcripts, summaries, and chapters for every episode. Skim, search, and bookmark insights. Learn more

Episodes

Episode 32: What You Need to Know Ahead of RSA 2022

In episode 32 of Cybersecurity Where You Are , co-hosts Sean Atkinson and Tony Sager discuss RSA 2022 — which is always a highlight of our conference calendar. Tony gives a preview of three sessions in which he'll present on cybersecurity nonprofits, incentivizing the adoption of cybersecurity best practices, and securing the supply chain. He also provides tips and best practices that can help RSA newbies, individual teams, and general attendees make the most of the conference. Resources Complet...

Jun 03, 202240 minEp. 32

Episode 31: To Achieve ICS Security Today, Look to Yesterday

In episode 31 of Cybersecurity Where You Are, co-host Sean Atkinson is joined by Karen Sorady, VP for Multi-State Information Sharing and Analysis Center (MS-ISAC) Member Engagement at the Center for Internet Security (CIS). Their discussion focuses on industrial control system (ICS) security, some of the threats they're susceptible to, and what goes into making a good operational technology (OT) security program. Looking back over the past 20 years, the security community has learned some valua...

May 19, 202247 minEp. 31

Episode 30: Solving Cybersecurity at Scale with Nonprofits

In episode 30 of Cybersecurity Where You Are, co-host Tony Sager is joined by Philip Reitinger, President and CEO of the Global Cyber Alliance. Their discussion focuses on the role that nonprofits play in solving cybersecurity problems at scale. In today's mutually dependent technology landscape, nonprofits' resources and expertise remove the need for enterprises to solve cybersecurity issues on their own. This is especially true given initiatives like Nonprofit Cyber, a "collective effort of eq...

May 06, 202247 minEp. 30

Episode 29: Conceptualizing Reasonableness for Risk Analysis

In episode 29 of Cybersecurity Where You Are, co-hosts Tony Sager and Sean Atkinson are joined by Chris Cronin, ISO 27001 Auditor and Partner at HALOCK, a leading information security consultancy. Their discussion focuses on "reasonableness" as it relates to cybersecurity risk management. This topic isn't just about proving to regulators, litigators, and others that security controls were in place prior to an incident. It also considers how to implement safeguards without overburdening users and...

Apr 28, 202252 minEp. 29

Episode 28: The Convergence of Cybersecurity and Public Policy

In episode 28 of Cybersecurity Where You Are, co-hosts Tony Sager and Sean Atkinson are joined by Brian Ray, Director of the Center for Cybersecurity and Privacy Protection, and Leon and Gloria Professor of Law at the Cleveland-Marshall College of Law at Cleveland State University. Together, the three discuss the convergence of cybersecurity and public policy with an emphasis on the concept of 'reasonable' security measures affording a data breach safe harbor for businesses.

Apr 08, 202253 minEp. 28

Episode 27: Cyber Scams

In this episode of Cybersecurity Where You Are, co-hosts Tony Sager and Sean Atkinson are joined by Stacey Wright, former CIS employee and current Vice President of Cyber Resiliency Services at the Cybercrime Support Network. The discussion focuses on the common cyber scams malicious actors have been using for decades and offer advice for dealing with them. Resources Cybercrime Support Network How to Protect Seniors Against Cybercrimes and Scams Common Cyber Hoax Scams Tech Support Call Scams...

Mar 29, 202250 minEp. 27

Episode 26: Automating the Secure Configuration Management Process

Resources Follow Brian Hajost on LinkedIn Prioritizing a Zero Trust Journey Using CIS Controls v8 Webinar | Align and Achieve CMMC Compliance Utilizing CIS Best Practices Episode 11: Remote Attestation Helps Zero Trust CIS Critical Security Controls v8 Cybersecurity Maturity Model Certification Mapping Where Does Zero Trust Begin and Why is it Important? In episode 26 of Cybersecurity Where You Are, co-host Tony Sager is joined by Brian Hajost, Chief Operating Officer at SteelCloud. They discuss...

Mar 11, 202241 minEp. 26

Episode 25: Building an Internal Incident Response Team

In this episode of Cybersecurity Where You Are , co-host Sean Atkinson is joined by Lou Smith, a Senior Information Security Intrusion Analyst at the Center for Internet Security. Smith has a background in Digital Forensics and previously worked for New York State's Cyber Command Center. The two discuss building digital forensics and incident response capabilities in-house. Tune in to learn about the skills you need and the tactics you can use to successfully implement an incident response plan ...

Feb 25, 202247 minEp. 23

Episode 24: How Do I Start a Career in Cybersecurity?

Resources Follow Guest Linnie Meehan on Twitter and Twitch US Cyber Challenge (USCC) CyberStart America Career Opportunities at CIS 11 of the Coolest Technical Jobs at CIS In episode 24 of Cybersecurity Where You Are, co-host Tony Sager poses the question that many people interested in the industry ask: How do I start a career in cybersecurity? To offer some insight, co-host Sean Atkinson joins cybersecurity professionals Linnie Meehan and Thomas Sager. Together, the three share their personal e...

Feb 11, 202251 minEp. 24

Episode 23: Cybersecurity Predictions for 2022

In Episode 23 of Cybersecurity Where You Are, hosts Tony Sager and Sean Atkinson are joined by our Vice President of Operations and Security Services, Josh Moulin. Together, the three share their thoughts on some of the topics that were discussed in our recent blog post, 2022 Cybersecurity Predictions to Watch Out For. Resources 2022 Cybersecurity Predictions to Watch Out For Log4j Zero-Day Vulnerability Response Sign up for the MS-ISAC Establishing Basic Cyber Hygiene Through a Managed Service ...

Jan 31, 202249 minEp. 23

Episode 22: CIS Behind the Veil: Log4j

Resources: Information on Log4j CIS Critical Security Controls Essential Cyber Hygiene In early January, the cybersecurity world was introduced to a new foe when researchers discovered a vulnerability in the code of a software library called Log4j. In the latest episode of Cybersecurity Where You Are, CIS CISO, Sean Atkinson, and CIS Chief Evangelist, Tony Sager, were joined by two colleagues who walked them through the steps CIS took to address the Log4j vulnerability....

Jan 21, 202256 minEp. 22

Episode 21: Year In Review; A List of our Favorite Episodes

In this edition of Cybersecurity Where You Are, CIS CISO, Sean Atkinson, and CIS Senior VP and Chief Evangelist, Tony Sager are joined by two members of the CIS podcast production team, Jason Forget, VP of Communications, and Chad Rogers, Digital Media Program Manager. Together they discuss this past year in cybersecurity, creating this podcast, and their favorite episodes.

Dec 28, 202153 minEp. 21

Episode 20: The State of Election Cybersecurity

Resources: Learn more about the EI-ISAC Election security tools and resources In this edition of Cybersecurity Where You Are, CIS Senior VP and Chief Evangelist, Tony Sager welcomes Kathy Boockvar, Vice President of Election Operations and Support and Marci Andino, Director of the Elections Infrastructure Information Sharing and Analysis Center, or EI-ISAC. Together, they discuss the state of election security for state and local governments....

Dec 13, 202141 minEp. 20

Episode 19: For Data Compliance, Automation is Key

Resources: CIS Critical Security Controls About Panaseer In this edition of Cybersecurity Where You Are, CIS Senior VP and Chief Evangelist, Tony Sager welcomes Thordis Stella Thorsteins, Senior Data Scientist at Panaseer. Panaseer provides a controls monitoring platform and has played a valuable role in the development of the CIS Critical Security Controls, as well as the implementation of the CIS Controls Assessment Specification. Together, Tony and Thordis discuss the role that data collectio...

Nov 15, 202141 minEp. 19

Episode 18: Top 5 Scariest Malware

Resources: Monthly Top 10 Malware CIS Critical Security Controls About the MS-ISAC In this edition of Cybersecurity Where You Are, CIS Chief Information Security Officer (CISO), Sean Atkinson welcomes Randy Rose, CIS Sr. Director of Cyber Threat Intelligence. In the spirit of Halloween, they list the top five3 (and some honorable mentions) malware of all time – so far!...

Oct 29, 202150 minEp. 21

Episode 17: Cybersecurity Awareness Month: It's All About the Big Picture

Resources Cybersecurity Awareness Month CIS Community Defense Model 2.0 Verizon Data Breach Investigations Report SANS Security Awareness Training MITRE ATT&CK Discussed in this podcast: Cybersecurity Awareness Month Psychology of cybersecurity Evolution of common cyber threats "Big picture" resources In this edition of Cybersecurity Where You Are, CIS Chief Information Security Officer (CISO), Sean Atkinson welcomes Philippe Langlois of the Verizon Business Group and co-author of the Verizo...

Oct 13, 202149 minEp. 17

Episode 16: Cybersecurity: Think INSIDE the Box

Resources: About Kathleen Moriarty CIS Benchmarks CIS Critical Security Controls Tools for Vendors and Consultants In this edition of Cybersecurity Where You Are, CIS Senior VP and Chief Evangelist, Tony Sager welcomes back Kathleen Moriarty, Chief Technology Officer for CIS. Together they discuss the role service providers play in the future of cybersecurity....

Sep 27, 202140 minEp. 16

Episode 15: Cybersecurity Success Takes Soft Skills

Episode Highlights: Why soft skills are important Top soft skills Building a company culture Resources: CIS Careers Publication: Cybersecurity Quarterly In this edition of Cybersecurity Where You Are, CIS Chief Information Security Officer (CISO), Sean Atkinson, and CIS Senior VP and Chief Evangelist, Tony Sager discuss soft skills and how they pertain to the the cybersecurity industry. Whether it is an an employee wanting to expand their career or an employer seeking a new hire, soft skills are...

Sep 10, 202156 minEp. 15

Episode 14: The Top 5 Cybersecurity Tips for the Family

Resources: Useapassphrase.com Password Policy Guide Related Blog: Password Policy Guide: Passphrases, Monitoring and More National Cybersecurity Awareness Month: MS-ISAC Tool Kit and Poster Contest Free to download: MS-ISAC 2021 Kids Safe Online Activity Book In this edition of Cybersecurity Where You Are, CIS Chief Information Security Officer (CISO), Sean Atkinson counts down the top five ways families can be cyber smart. CIS Content Marketing Manager, Danielle Koonce, stops by to talk about w...

Sep 01, 202151 minEp. 14

Episode 13: What's Important to You in Cybersecurity? A Host Q&A

Resources: CIS Twitter CIS LinkedIn CIS Critical Security Controls Related podcast: RC Manager at Frame.io, Mosi Platt answers the Atkinson 9 In this edition of Cybersecurity Where You Are, CIS Chief Information Security Officer (CISO), Sean Atkinson, and CIS Senior VP and Chief Evangelist, Tony Sager share part of themselves in this intimate episode. Taking a guest-free moment of asking them the 'Atkison 9', hosts turn the questions on themselves. Listen to them discuss their favorite CIS Criti...

Aug 23, 20211 hrEp. 13

Episode 12: Cybersecurity and Government: Less Wizardry, More Policy

This week’s Cybersecurity Where You Are podcast highlights: The problem regulating cybersecurity Cybersecurity is currently the "Wild West" What makes cybersecurity different than other industries What roles different levels of government are taking Dispelling the mystery behind cybersecurity Episode Resources CIS Controls Basic Cyber Hygiene Press Release It can appear that cybersecurity practices are being built on the creative wizardry of technical experts rather than referential universal po...

Jul 30, 202140 minEp. 12

Episode 11: Remote Attestation Helps Zero Trust

This week’s Cybersecurity Where You Are podcast highlights: Automated attestation processes Vendor attestation capabilities Root of trust via Trusted Platform Module (TPM) Method of verification for zero trust Episode Resources Visit the CIS Website CIS Controls List About Kathleen Moriarty, Chief Technology Officer, CIS Related Blog on Zero Trust: Where Does Zero Trust Begin and Why is it Important? In this edition of Cybersecurity Where You Are, host and CIS Chief Information Security Officer ...

Jul 16, 202132 minEp. 11

Episode 10: Hospitals in Need of Cybersecurity STAT!

This week’s Cybersecurity Where You Are podcast highlights: Why the medical industry is so appealing to attackers The challenges of protecting medical facilities How a defense-in-depth strategy plays a role in a hospital’s cybersecurity plan Malicious Domain Blocking and Reporting (MDBR) for hospitals Episode Resources Visit the CIS Website The American Hospital Association Learn more about MDBR for hospitals In this edition of Cybersecurity Where You Are, host and CIS Chief Information Security...

Jun 28, 202142 minEp. 10

Episode 9: Mitigating Risk: Information Security Governance

Resources: Visit the CIS Website Highlights: The importance of information security governance Security vs. compliance Data – determining what you need and where to find it Understanding risk from a decision-basis Critical elements to fulfill business requirements Producing value in a compliance program Applying agility for continuous improvement Good compliance = good security Security is the practice of implementing effective technical controls to protect an organization’s digital assets. Comp...

Jun 11, 202157 minEp. 9

Episode 8: CIS Controls v8...First Impressions

Resources: Visit the CIS Website Download the CIS Controls v8 Download CIS Controls v8 Change Log Join a CIS Controls Community Highlights: Everything has to be measurable Everything has to be achievable CIS Controls v8 must have a peaceful coexistence with cybersecurity frameworks The Controls need to be backed by data and able to defend against real-world threats First Impressions Matter The CIS Controls team and volunteers pretty much rewrote every word of v8 in an effort to modernize and con...

May 28, 202153 minEp. 8

Episode 7: CIS Controls v8...It’s Not About the List

Resources: What are the CIS Controls Learn more about CIS Controls v8 Free Webinar | May 18, 2021: Sign up to hear about all the changes to the CIS Controls Frequently Asked Questions In this edition of Cybersecurity Where You Are, host and CIS Senior Vice President and Chief Evangelist, Tony Sager welcomes guests Randy Marchany and Phyllis Lee. Marchany is the Chief Information Security Officer (CISO) at Virginia Tech, and Lee serves as Senior Director of the CIS Controls. The connection betwee...

May 14, 202157 minEp. 7

Episode 6: 2020 Elections Year in Review

Resources: EI-ISAC Elections Security Tools & Resources #PROTECT2020 In this edition of Cybersecurity Where You Are, host and CISO at the Center for Internet Security (CIS), Sean Atkinson welcomes guests Geoff Hale and Lew Robinson. Hale leads the Election Security Initiative at the Cybersecurity and Infrastructure Security Agency (CISA), while Robinson serves as CIS Vice President of Election Operations. Both agencies and both men, respectively, played a big role in the success of the 2020 ...

Apr 23, 202138 minEp. 6

Episode 5: The Tools of Cyber Defense...an Ongoing, Repetitive Process

Part 2 of a 2-part series Resources: Listen to Part 1 CIS website CIS SecureSuite Tools and Resources CIS Benchmarks CIS Controls (v8 coming Spring 2021) CIS CSAT (CIS Controls Self Assessment Tool) Community Defense Model (v2 coming Spring 2021) In this week’s Cybersecurity Where You Are podcast, hosts Tony Sager and Sean Atkinson continue their conversation on cyber defense as a risk-based process. They discuss the actions and resources that help build and implement “defensive machinery” that ...

Apr 12, 202157 minEp. 5

Episode 4: Dynamics of Cyber Defense...an Ongoing, Repetitive Process

Episode Resources: Blog: Assess, Remediate, and Implement with CIS SecureSuite: https://www.cisecurity.org/blog/assess-remediate-and-implement-with-cis-securesuite/ Free Webinar: CIS Benchmarks and CIS-CAT Pro Tool Demo: https://www.cisecurity.org/webinar/cis-benchmarks-demo/ Part 1 of a 2-part series Technology is ever-changing AND ever-evolving, creating an uncertainty amongst cybersecurity professionals – the defenders – in their pursuit of an effective cyber defense strategy. The uncertainty...

Mar 26, 202141 minEp. 4

Episode 3: Third-party Risk Management – Beyond the Questionnaire

Resources: Find us at https://www.cisecurity.org/ Third-party Risk Association: https://www.tprassociation.org/ National Institute of Standards and Technology (NIST): https://www.nist.gov/ CIS Controls: https://www.cisecurity.org/controls/ Can a risk assessment questionnaire be the catalyst for true change to the entire vendor cybersecurity ecosystem? Cybersecurity Where You Are podcast host Sean Atkinson welcomes guest Ryan Spelman, former CIS employee, and now Managing Director at Duff & P...

Mar 12, 202144 minEp. 3
For the best experience, listen in Metacast app for iOS or Android