ADCG on Privacy & Cybersecurity

ADCG on Privacy & Cybersecurity

By Association for Data and Cyber GovernanceSociety & CultureTechnologyGovernment
Download on the App Store

ADCG on Privacy & Cybersecurity episodes

  • 106 | Challenges to Risk Management in Higher Education
    This episode features risk management leader Tracey Swift, Editor-in-Chief of a new publication, HigherEdRisk. Previously, Tracey was Executive Director of Risk Management at Arizona State University, where she led the university’s risk management and insurance functions. In this episode we explore the differences between academia and corporations in managing privacy, cybersecurity, and AI risks, the role of the board of trustees and university leadership, and the challenges associated with open networks, collaborative research, shadow IT, and resource pressures. AI has opened up new opportunities and challenges and academia has been one of the first to feel its impact, making higher education more advanced in AI governance than many private sector organizations. Tracey shares her thoughts on the role of insurance in higher ed risk management and the importance of cross-organizational teams in addressing privacy, cybersecurity, and AI risk management.
    42 min
  • 105 | AI Driving Legislative and Regulatory Action, Including Action from the Judiciary and Legal Ethics
    In this episode of the ADCG Privacy & Cybersecurity Podcast, host Jody Westby is joined by former Magistrate Judge Ronald J. Hedges, a legal thought leader in the areas of electronic discovery and artificial intelligence and the law. Jody and Ron discuss how AI is driving legislative and regulatory action, including action within the judiciary and ethics rules and guidance from bar associations. In addition to discussing issues with admissibility and discovery of evidence, Ron discusses how the work of three bar associations regarding the use of AI in the legal profession could be a model for professionals in other industry sectors. Ron is a member of the New York and New Jersey state bar associations’ AI Task Forces, and is Chair of the Court Technology Committee of the ABA Judicial Division. He is principal at Ronald J. Hedges LLC.
    36 min
  • 104 | Understanding Software Bill of Materials and Why They Are Crucial for Cybersecurity
    In this episode of ADCG’s Privacy and Cybersecurity Podcast, Jody Westby interviews Jean Camp, Director of the Center for Security and Privacy in Informatics, Computing, and Engineering and Professor of Informatics at University of Indiana. Prof. Camp is a renowned thought leader in privacy and cybersecurity and has conducted meaningful research on issues related to SBOMs and how they could be more effective. In this podcast, we explore the role of SBOMs in cybersecurity, what limits their effectiveness, and the Federal Government's role in advancing the use of SBOMs, developing tools to ease the use of SBOMs, and international efforts to create a harmonized approach to the development and use of SBOMs. Links to some of Prof. Camp’s work in this area is available on the ADCG website.
    32 min
  • 103 | Privacy & Diversity, Equity & Inclusion and the Impact on the Development and Use of AI
    This week the ADCG Privacy & Cybersecurity Podcast is pleased to have Shoshana Rosenberg, CEO and Founder of SafePorter and one of the most respected names in the field of privacy and a thought leader at the intersection of privacy and Diversity, Equity & Inclusion ("DEI"). We discuss her groundbreaking work analyzing how principles governing privacy and DEI can influence the development and use of AI technologies, including how privacy and bias concerns shape the conversation around AI, how the evolving landscape of AI is challenging our traditional understanding of privacy and inclusion, and how advancements in AI both challenge and embrace our ability to uphold DEI principles…and more!
    39 min
  • 102 | Tackling Data Deletion
    This week’s episode of ADCG’s Privacy & Cybersecurity Podcast features a discussion with Jeff Jockisch about his new company, Avantis Privacy, which specializes in data deletion services. Jeff is a renowned privacy researcher, the CEO of PrivacyPlan and CPO of Avantis Privacy. In this episode, we discuss the daunting prospect of managing one’s personal data, data brokers and what they do, and the process of requesting personal be deleted. Jeff discusses the approach taken by Avantis Privacy and offers thoughts on anonymization and what is driving this type of service.
    32 min
  • 101 | American Bar Association: Leading Resource and Policy Leader Through Its Cybersecurity Task Force
    This episode features Donata Stroink-Skillrud, Co-Founder and President of Termageddon, a software service that specializes in the identification of privacy laws applicable to an organization and the development of privacy policies, terms of service, and end user license agreements for that organization. Donata is an attorney who also represents the American Bar Association’s Section of Science and Technology Law on the ABA President’s Cybersecurity Legal Task Force (CLTF). In this episode, we discuss the CLTF, its purpose, topics and issue areas it addresses, and the cybersecurity resources the CLTF has created for attorneys and law firms (which are free and applicable to many other organizations). We also discuss recent Resolutions that CLTF has put forward for adoption by the ABA, including is AI Resolution. Links to CLTF resources are provided on the ADCG website for this episode.
    36 min
  • 100 | Looking at Cyber Risk Management: the Perspective Across the Pond
    This episode features Dr. Peter Trim, a Reader in Marketing and Security Management at the University of London’s Birkbeck Business School. Dr. Trim has published a dozen books, and his most recent (2023) focuses on Strategic Cyber Security Risk Management. Cybersecurity best practices began in the UK with British Standard 7799, which morphed into ISO 27001/002. Dr. Trim discusses the necessity for a collective approach in cybersecurity and the need to maintain an international perspective. His work endeavors to link cyber risk management theory with practical application through use cases and simulation exercises. We explore the need for improved private sector interaction with academia and the need to integrate cybersecurity risk management content in interdisciplinary curricula.
    37 min
  • 99 | The Power of Choice for Authentication
    In this episode of ADCG on Privacy & Security podcast, host Jody Westby is joined by Sabrina Gross, regional director of strategic partners at Veridas. Sabrina has worked globally and spent 15 years working with law enforcement agencies in Europe, the Middle East, and Africa. At Veridas, Sabrina focuses on cutting-edge technologies that are used for authentication and to prevent identity fraud. We discuss the importance of having a choice of authentication options, limitations of various devices, the pros and cons of facial recognition, fingerprints, and voice as authentication methods, what companies should look for in a biometrics provider, security factors, customer preferences, and more. We drill down into the role of state privacy laws and the circumstances under which a business should consider multiple, layered verification methods.
    27 min
  • 98 | The Importance of Digital Asset Inventories in Incident Response
    This episode of the ADCG Privacy and Cybersecurity Podcast features Ken Westin, Field CISO for Panther Labs. Ken has been in the cybersecurity field for over 15 years, working with companies to improve their security posture through threat hunting, insider threat programs, and vulnerability research. We discuss how the lack of good application and data inventories impact incident response. When data is spread across data centers, clouds, and SaaS providers, it becomes difficult to track and trace an incident and understand its impact, but it becomes especially hard if the data involves confidential or proprietary business data that is not tracked by privacy officers or if it includes sensitive data that may involve regulators. The recent MOVEit breach, which involved software used to transfer sensitive data between servers, systems, and applications, provided rich lessons in the need for data asset inventories and SIEMs that can correlate data across providers and platforms.
    30 min
  • 97 | The Race Between AI and Laws
    This episode features Scott Giordano, former vice president and general counsel for Spirion who has more than 25 years of legal, technology, and risk management expertise and was one of the first attorneys to jump into artificial intelligence. We will discuss the implications of AI for privacy and information security, current US state laws, the EU AI Act, and what companies can do to prepare for “AI everywhere.” Scott also discusses the recent “Career Essentials in Generative AI” course he took, which is offered by Microsoft and LinkedIn.
    30 min

About ADCG on Privacy & Cybersecurity

From the publisher's feed

“ADCG on Privacy & Cybersecurity” podcast brings together leaders in the privacy and cybersecurity arenas to discuss a wide range of issues ranging from the proposed federal and state regulations…