Cybersecurity Where You Are (video) - podcast cover

Cybersecurity Where You Are (video)

Center for Internet Securityfast.wistia.net
Welcome to video version of “Cybersecurity Where You Are,” the podcast of the Center for Internet Security® (CIS®). Cybersecurity affects us all — whether we’re online at home, managing a company, supporting clients, or running a state or local government. Join us on Wednesdays as Sean Atkinson, CISO at CIS, and Tony Sager, SVP & Chief Evangelist at CIS, discuss trends and threats, explore security best practices, and interview experts in the industry. Together, we’ll clarify these issues, creating confidence in the connected world. Subscribe to the audio version of our podcast here: https://fast.wistia.net/embed/channel/wbyhaw35xf?wchannelid=wbyhaw35xf.
Last refreshed:
Follow this podcast in the Metacast mobile app to refresh it and see new episodes.
Download Metacast podcast app
Podcasts are better in Metacast mobile app
Don't just listen to podcasts. Learn from them with transcripts, summaries, and chapters for every episode. Skim, search, and bookmark insights. Learn more

Episodes

Episode 115: Continuous Feedback as CIS Employee Culture

In episode 115 of Cybersecurity Where You Are, Sean Atkinson is joined by Carolyn Comer , Chief Human Resources Officer at the Center for Internet Security® (CIS®); Heidi Gonzalez , Sr. Employee Experience Specialist at CIS; and Jennifer Myers, Sr. Director of Learning and Development at CIS. With an in-person holiday open house and office party as their backdrop, they celebrate the continuous feedback that sustains and grows the employee culture at CIS. Here are some highlights from our episode...

Dec 25, 202432 minEp. 115

Episode 114: 3 Board Chairs Reflect on 25 Years of Community

In episode 114 of Cybersecurity Where You Are, Tony Sager is joined by three past and current Board Chairs of the Center for Internet Security® (CIS®): Frank Reeder , CIS Director Emeritus and Founding Chair as well as Director of the National Cybersecurity Scholarship Foundation; John Gilligan , President and Chief Executive Officer of CIS; and Bobbie Stempfley , CIS Board Chair and Business Security Officer of the Infrastructure Solutions Group at Dell Technologies. Together, they reflect on 2...

Dec 18, 202449 minEp. 114

Episode 113: Cyber Risk Prioritization as Ransomware Defense

In episode 113 of Cybersecurity Where You Are, Tony Sager is joined by Phyllis Lee , VP of SBP Content Development at the Center for Internet Security® (CIS®); Adam Bobrow , Co-Founder and President of Veribo Analytics; and Sridevi Joshi , Co-Founder and CEO of Veribo Analytics. Together, they discuss how the Business Impact Analysis tool created by CIS and Veribo Analytics empowers individuals and organizations to use cyber risk prioritization as a basis for their ransomware defense strategy. H...

Dec 11, 202441 minEp. 113

Episode 112: How SANS Fosters Action on Cybersecurity Trends

In episode 112 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager are joined by Rob T. Lee , Chief of Research and Head of Faculty at SANS Institute. Together, they discuss how SANS Institute applies an operational or "do" model of leadership to gather expertise, build shared purpose, and foster action on evolving cybersecurity trends. Here are some highlights from our episode: 05:47 . How Rob ended up teaching at SANS Institute 08:49 . Rob's first experience meeting and working with t...

Dec 04, 202447 minEp. 112

Episode 111: Distilling a First Principle of Cybersecurity

In episode 111 of Cybersecurity Where You Are, Tony Sager is joined by Rick Howard, N2K Chief Security Officer and the Chief Analyst and Senior Fellow at The Cyberwire. Together, they discuss a first principle of cybersecurity proposed by Rick in his book, Cybersecurity First Principles: A Reboot of Strategy and Tactics . Here are some highlights from our episode: 04:30 . What drove the need to formulate a foundational cybersecurity assumption 07:44 . How other "first" principles of cybersecurit...

Nov 27, 202447 minEp. 111

Episode 110: How Security Culture and Corporate Culture Mesh

In episode 110 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager are joined by Lee Noriega , Executive Director of the Cybersecurity Services Organization and Acting General Manager of Sales and Business Services at the Center for Internet Security® (CIS®); and Jerry Gitchel , founder of Leverage Unlimited and listener to Cybersecurity Where You Are. Together, they examine a question sent in by Jerry: if a corporate culture is lacking, can a security culture exist? Here are some highl...

Nov 20, 202442 minEp. 110

Episode 109: The Scariest Malware of 2024

In episode 109 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager are joined by Randy Rose, VP of Security Operations & Intelligence at the Center for Internet Security® (CIS®); and Theodore "TJ" Sayers, Director of Intelligence & Incident Response at CIS. Together, they examine the scariest malware of 2024 and share some recommendations for how organizations can keep up with the changing cyber threat landscape. Here are some highlights from our episode: 01:32 . What makes cert...

Nov 13, 202439 minEp. 109

Episode 108: Gaming and Competition in Cybersecurity

In episode 108 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager are joined by Ed Skoudis , CEO of Counter Hack Challenges and President of SANS Technology Institute. Together, they discuss the evolution of gaming and competition in cybersecurity and how these activities help to make the industry stronger. Here are some highlights from our episode: 02:04 . What goes into creating a game environment that attracts all kinds of skill levels 04:43 . A multi-disciplinary approach to creati...

Nov 06, 202441 minEp. 108

Episode 107: Continuous Improvement via Secure by Design

In episode 107 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager are joined by Steve Lipner , Executive Director of SAFECode. Together, they discuss how software development organizations can use principles of "secure by design" to get on a track of continuous improvement. Here are some highlights from our episode: 01:38 . Steve's background and thoughts on the emergence of secure by design 14:04 . Three guiding principles of secure software development 16:13 . The impact of security ...

Oct 30, 202438 minEp. 107

Episode 106: How to Avoid Falling for a Donation Scam

In episode 106 of Cybersecurity Where You Are, Sean Atkinson is joined by Chris Smith , Social Media Specialist at the Center for Internet Security® (CIS®). Together, they use a donation scam about a natural disaster to advise how you can stay safe against this type of cyber threat. Here are some highlights from our episode: 00:49 . Why it's important to talk about donation scams and why they're so prevalent 05:13 . Recounting a real-world example of a donation scam 10:43 . Common tactics levera...

Oct 23, 202432 minEp. 106

Episode 105: Context in Cyber Risk Quantification

In episode 105 of Cybersecurity Where You Are, Sean Atkinson discusses the importance of context in maturing how you use cyber risk quantification to build cases for risk treatment strategies. Here are some highlights from our episode: 01:56 . The inspiration for an episode on cyber risk quantification 02:38 . How to situate risk quantification in your business processes 08:56 . Traps to avoid when quantifying cyber risks 12:12 . How the quantification process relates to controls implementation ...

Oct 16, 202433 minEp. 105

Episode 104: Inside the First Year of a Cybersecurity Career

In episode 104 of Cybersecurity Where You Are, Sean Atkinson is joined by Kennidi Ortega, Information Security Analyst at the Center for Internet Security® (CIS®). Together, they explore the experience of a first-year analyst and how they might make the most of getting started in a cybersecurity career. Here are some highlights from our episode: 01:07 . How Kennidi got started in cybersecurity and what led her to the field 03:44 . What the beginning of Sean's cybersecurity career looked like 04:...

Oct 09, 202433 minEp. 104

Episode 103: Education vs. Experience in Cybersecurity

In episode 103 of Cybersecurity Where You Are, Sean Atkinson examines education and experience as pathways for new professionals to enter the cybersecurity industry. Here are some highlights from our episode: 01:42 . What's motivating Sean to talk about this topic 03:32 . The value of cybersecurity degrees 05:17 . The pros and cons of degree programs in cybersecurity 07:47 . How a cybersecurity certification compares to a degree 10:57 . Considerations for pursuing a certification in cybersecurit...

Oct 02, 202431 minEp. 103

Episode 102: The Sporty Rigor of CIS Controls Accreditation

In episode 102 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager are joined by the following guests: Charity Otwell , Director of the CIS Critical Security Controls® (CIS Controls®) at the Center for Internet Security® (CIS®) Lawrence Cruciana , President of Corporate Information Technologies (CorpInfoTech) Together, they discuss the "sporty" rigor underlying the process and value of achieving CIS Controls Accreditation. Here are some highlights from our episode: 01:36 . What is meant...

Sep 25, 202437 minEp. 102

Episode 101: Visualizing Attack Paths in Active Directory

In episode 101 of Cybersecurity Where You Are, Sean Atkinson is joined by Justin Kohler , Vice President of Products at SpecterOps, and Jonathan Parfait , Technical Account Manager at SpecterOps. Together, they discuss how the visualization of attack paths in Active Directory helps organizations to better contextualize risks to their enterprise security. Here are some highlights from our episode: 01:54 . What Bloodhound is and how it assists organizations in assessing risks in their Active Direc...

Sep 18, 202434 minEp. 101

Episode 100: Celebrating 100 Episodes and Looking Ahead

In episode 100 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager are joined by David Bisson, Sr. Content Marketing Strategist at the Center for Internet Security® (CIS®). Together, they celebrate the first 100 episodes of Cybersecurity Where You Are and discuss where the podcast might go in the future. Here are some highlights from our episode: 01:14 . How the podcast's approach and content have changed since the first episode 04:19 . What surprised the team about the "machinery" of p...

Sep 11, 202442 minEp. 100

Episode 99: How Cyber-Informed Engineering Builds Resilience

In episode 99 of Cybersecurity Where You Are, Sean Atkinson is joined by Marcus Sachs, SVP and Chief Engineer at the Center for Internet Security® (CIS®). Together, they discuss how cyber-informed engineering builds resilience to the potential failure of a digital system into new and existing engineering products. Here are some highlights from our episode: 03:51 . What cyber-informed engineering is and how this paradigm has emerged 11:39 . What CIS is doing to emphasize cyber-informed engineerin...

Sep 04, 202434 minEp. 99

Episode 98: Transparency as a Tool to Combat Insider Threats

In episode 98 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager are joined by Roger Grimes , Data-Driven Defense Evangelist at KnowBe4. Together, they embrace transparency as a vehicle for the cybersecurity industry to better defend against insider threats. Here are some highlights from our episode: 01:28 . How KnowBe4 detected an insider threat from North Korea 09:09 . How the Center for Internet Security® (CIS®) responded to news of this incident 21:02 . The role of technical contro...

Aug 28, 202436 minEp. 98

Episode 97: How Far We've Come preceding CIS's 25th Birthday

In episode 97 of Cybersecurity Where You Are, Tony Sager is joined by the following guests: Dr. Ramon Barquin , Board Member at the Center for Internet Security® (CIS®) and President and Chief Executive Officer at Barquin International Franklin Reeder , Director Emeritus and Founding Chair of CIS as well as Director of the National Cybersecurity Scholarship Foundation Clint Kreitner , Founding President/CEO and Former Board Member at CIS Together, they look back at how much CIS has accomplished ...

Aug 21, 202451 minEp. 97

Episode 96: Making Continuous Compliance Actionable for SMBs

In episode 96 of Cybersecurity Where You Are, co-hosts Sean Atkinson and Tony Sager are joined by Tarah Wheeler, CEO of Red Queen Dynamics. Together, they discuss ongoing efforts to translate continuous compliance into something actionable for small- to medium-sized businesses (SMBs). Here are some highlights from our episode: 03:11 . The philosophy behind a business model focused on continuous compliance for SMBs 17:44 . How the Fog of More complicates security and compliance for the "cyber-und...

Aug 14, 202443 minEp. 96

Episode 95: AI Augmentation and Its Impact on Cyber Defense

In episode 95 of Cybersecurity Where You Are, Sean Atkinson is joined by Randy Rose, VP of Security Operations & Intelligence at the Center for Internet Security® (CIS®). Together, they discuss AI augmentation in terms of how cyber defenders are using generative artificial intelligence to enhance their capabilities. Here are some highlights from our episode: 01:16 . How artificial intelligence has changed the landscape for cybersecurity defenders 03:49 . How AI is starting to augment threat ...

Aug 07, 202435 minEp. 95

Episode 94: Community Defense at the ISAC Annual Meeting

In episode 94 of Cybersecurity Where You Are, Tony Sager is joined by the following guests from the Center for Internet Security® (CIS®): Carlos Kizzee, SVP of Multi-State Information Sharing and Analysis Center® (MS-ISAC®) Strategy & Plans Karen Sorady, VP of MS-ISAC Strategy & Plans Greta Noble, Director of Community Engagement Together, they discuss how the ISAC Annual Meeting supports the 24x7x365 community defense efforts of the MS-ISAC and Elections Infrastructure Information Shari...

Jul 31, 202437 minEp. 94

Episode 93: Keeping Societal Confidence in a Connected World

In episode 93 of Cybersecurity Where You Are, co-hosts Sean Atkinson and Tony Sager are joined once again by John Cohen, Executive Director of Countering Hybrid Threats at the Center for Internet Security® (CIS®). Together, they discuss a whole-of-society approach to help make the U.S. public resilient against multidimensional threats in our connected world. Here are some highlights from our episode: 01:52 . What the U.S. public needs to consider in order to strengthen its resilience 06:04 . How...

Jul 24, 202429 minEp. 93

Episode 92: A Framework to Counter Evolving Cyber Threats

In episode 92 of Cybersecurity Where You Are, co-hosts Sean Atkinson and Tony Sager are joined by John Cohen, Executive Director of Countering Hybrid Threats at the Center for Internet Security® (CIS®). Together, they discuss "Enhancing Safety in the Connected World — A National Framework for Action," a multi-year project to help law enforcement and security professionals better contextualize and respond to evolving cyber threats. Here are some highlights from our episode: 02:01 . Why the curren...

Jul 17, 202433 minEp. 92

Episode 91: What You Need to Know about CIS Controls v8.1

In episode 91 of Cybersecurity Where You Are, Sean Atkinson is joined by Charity Otwell, Director of the CIS Critical Security Controls® (CIS Controls®) at the Center for Internet Security® (CIS®). Together, they discuss what you need to know about the release of CIS Controls v8.1. Here are some highlights from our episode: 01:17 . What you can expect to see in version 8.1 of the Controls 06:19 . How CIS Controls v8.1 helps you to integrate other governance structures 09:23 . How version 8.0 and...

Jul 10, 202433 minEp. 91

Episode 90: Migrating to the Cloud with Control Continuity

In episode 90 of Cybersecurity Where You Are, co-hosts Sean Atkinson and Tony Sager are joined by the following guests: Charity Otwell, Director of the CIS Critical Security Controls® (CIS Controls®) at the Center for Internet Security® (CIS®) Mia LaVada, Product Manager of CIS Benchmarks and Cloud at CIS Don Freeley, VP of IT Services at CIS Together, they discuss how you can use CIS resources to ensure control continuity when migrating to the cloud. Here are some highlights from our episode: 0...

Jul 03, 202431 minEp. 90

Episode 89: How Threat Actors Are Using GenAI as an Enabler

In episode 89 of Cybersecurity Where You Are, co-host Sean Atkinson is joined by the following guests: Rian Davis, Elections Cyber Threat Intelligence Intern at the Center for Internet Security® (CIS®) Timothy Davis, Sr. Elections Cyber Threat Intelligence Analyst at CIS Together, they discuss how cyber threat actors (CTAs) are using generative artificial intelligence (GenAI) as an enabler of their attacks. Here are some highlights from our episode: 01:04 . Why it's important to raise awareness ...

Jun 26, 202431 minEp. 89

Episode 88: The Evolution of the Role of a CISO

In episode 88 of Cybersecurity Where You Are, co-host Sean Atkinson discusses the evolving role of a chief information security officer (CISO). Here are some highlights from our episode: 02:47 . Why communication is a core competency for CISOs 08:35 . How to take a balanced approach when evaluating an organization's implementation of artificial intelligence (AI) and machine learning (ML) 11:47 . The role a CISO plays in integrating privacy requirements into the organization 15:35 . Thoughts on h...

Jun 19, 202430 minEp. 88

Episode 87: Marking 11 Years as a Verizon DBIR Contributor

In episode 87 of Cybersecurity Where You Are, co-host Tony Sager is joined by the following guests: Charity Otwell, Director of the CIS Critical Security Controls® (CIS Controls®) at the Center for Internet Security® (CIS®) Philippe Langlois, Senior Principal, Security Risk Management and Author of the Verizon Data Breach Investigations Report (DBIR) Theodore "TJ" Sayers, Director of Intelligence & Incident Response at CIS Together, they celebrate 11 years of CIS and Verizon working together...

Jun 05, 202439 minEp. 87

Episode 86 Evangelizing CIS's Message at RSAC 2024

In episode 86 of Cybersecurity Where You Are, co-host Sean Atkinson is live once again from Booth 4319 at RSA Conference (RSAC) 2024. 00:57 . Sean chats with Mat Everman, Information Security Operations Manager, about his talk, " Shades of Purple: Getting Started and Making Purple Teaming Possible ." They discuss some of the questions Mat received following his talk and how they can put purple teaming into practice at the Center for Internet Security® (CIS®). Sean asks passersby what they're loo...

May 29, 202434 minEp. 86
For the best experience, listen in Metacast app for iOS or Android