Cybersecurity Where You Are (audio)

Cybersecurity Where You Are (audio)

By Center for Internet SecurityBusinessNon-Profit
Download on the App Store

Cybersecurity Where You Are (audio) episodes

  • Episode 208: Secure Harness Engineering for Agentic AI

    In episode 208 of Cybersecurity Where You Are, Sean Atkinson breaks down secure harness engineering for agentic artificial intelligence (AI). Noting the risks posed by AI agents acting without oversight, he highlights "episodes" as auditable elements that help to provide feedback, and he walks through 15 controls spread across five stages as a way to engineer an AI harness with security in mind. He also differentiates secure harness engineering from prompt engineering, guardrails, frameworks, logs, and universal wrappers for AI agents.

    Here are some highlights from our episode:

    • 01:23. The need for a control system in light of agent escape incidents
    • 02:19. Analogy of a financial analyst to understand why separation of duties is important
    • 02:57. Revolution and then evolution: How AI models have changed exponentially since 2022
    • 04:54. Where secure harness engineering has a capability
    • 05:42. Making decisions traceable: The need for an evidence chain to build controls effectively
    • 07:15. Smartphones: A parallel for understanding the value of each new AI model
    • 11:20. Engineering controls, not standard policies for all models
    • 12:22. Secure harness engineering vs. prompt engineering
    • 12:51. Models' evolving role: How it invites new security questions to be posed
    • 15:16. AI agents without oversight: The insider persona with which defenders need to contend
    • 16:02. The need for determinism and an effective diagram to build for it
    • 18:22. Definition of secure harness engineering
    • 19:36. Episodes and the importance of log assessment in mediating model capability
    • 20:42. Reality verification: A feedback loop that gets into the concept of forensic assessment
    • 21:27. Questions to ask as you get into an AI agent's evidence chain
    • 22:56. Moving through intent, authority, reasoning, synthesis, decision, and enforcement
    • 25:38. Side effects: What they are and how they actualize risk
    • 27:16. Verification and audit: How they empower you to look at control opportunities
    • 28:49. Five stages and 15 controls for secure harness engineering
    • 29:47. What secure harness engineering is and is not
    • 32:11. Three questions to help you get started
    • 32:52. An important question for the future

    Resources

    • Artificial Intelligence (AI) Agents Companion Guide
    • The Secure Harness: A Governance Architecture for Agentic AI
    • When Agent Capability Outruns Control: Lessons from the July 2026 OpenAI and Hugging Face Incident
    • Episode 202: Delineating AI Security and Cybersecurity
    • Harness Engineering & Agent Orchestration
    • OWASP Top 10 for Large Language Model Applications

    If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing [email protected].

    35 min
  • Episode 207: AI Risk Management — A Trust Relationship

    In episode 207 of Cybersecurity Where You Are, Sean Atkinson makes the case for treating artificial intelligence (AI) not as software but as an ongoing trust relationship. He highlights the value of integrating best practices from regulations like the EU AI Act, walks through the three stages of an AI governance lifecycle, and explains how AI risk management fits into organizational governance, change management, and other business processes.

    Here are some highlights from our episode:

    • 01:16. The trust component of AI governance
    • 02:02. A need to align to regulatory best practices and bring them into AI risk management
    • 03:47. Advice: Contextualize, don't generalize, your risks associated with AI use
    • 04:40. Common questions that lead to AI governance as a requirement
    • 06:59. Grounding an agile AI governance process on foundational principles
    • 07:46. How the "fortress" approach overlooks the relationship element of AI security
    • 09:51. A direct invitation: Listener feedback on AI governance thinking
    • 11:44. Evaluating trust and relationship in machine learning and generative AI
    • 14:04. The role of human oversight in realizing AI as a method that gets to a solution quicker
    • 14:53. AI governance boards: A potential solution to elevating AI literacy internally
    • 16:00. AI governance lifecycle: Three phases from current business processes to value generation
    • 18:55. Overview of the future of AI security
    • 23:16. The need for foundational security controls and AI-specific controls
    • 25:00. AI governance assessment: Why it needs to happen across the organization
    • 26:28. How AI governance ties into organizational governance
    • 29:49. Ethics and responsible AI practice
    • 29:57. Change management considerations with AI deployment
    • 30:35. A concluding call to action to get stronger together

    Resources

    • CIS Critical Security Controls®
    • Episode 198: AI Privacy from a Risk-Based Perspective
    • Episode 122: DeepSeek AI Security and Utility Considerations
    • Episode 120: How Contextual Awareness Drives AI Governance
    • AI Playbooks for SLTT Cybersecurity Leaders
    • CIS Controls v8.1.2 AI Security Guidance Workbook
    • Guide to Implementation Groups (IG): CIS Critical Security Controls v8.1
    • Mapping and Compliance with the CIS Controls

    If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing [email protected].

    33 min
  • Episode 206: Trust and Influence as CISO Survival Skills

    In episode 206 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager speak with Julie Morris, Founder and Head of Thought Leadership at Persona Media, about why trust and influence have become survival skills for today's CISOs. Julie breaks down three types of organizational power, explains why the "good guys" resist the language of influence, and offers a practical starting point for anyone who's ever felt like PowerShell was the only power they understood.

    Here are some highlights from our episode:

    • 02:13. From old to new: A shift in how trust and influence factor into organizational structures
    • 04:24. The three kinds of power in an organization: hard, soft, and network
    • 09:59. Wise advice: Build your personal and professional network first
    • 11:07. How influence multiplies confidence with network power
    • 12:03. Inertia, fear, and status quo: overcoming the emotional reactions that oppose change
    • 18:12. How Sean uses the power of "slow down," not "no," to support AI transformation
    • 20:49. Why good thought leadership starts with empathy and self awareness
    • 24:32. Building organizational processes that "trigger" a change in CISOs' trust and influence
    • 26:30. Hugging Face as an example of how triggering moments become lessons
    • 27:42. What Tony Soprano has to do with measuring trust and influence
    • 30:47. Reality check: Every information gap gets filled one way or another
    • 32:15. The power of community and shared ideas in figuring out thought leadership together
    • 36:09: Advice: Be in the "river" of your network to go where you want to go
    • 37:34. How understanding of shared values helps to overcome imposter's syndrome

    Resources

    • CIS Critical Security Controls®
    • Episode 183: The Role of CISO in Supporting Risk Translation
    • Episode 187: The Role of a CISO as a Strategic Storyteller
    • Episode 192: How Leaders Balance Expertise and Communication
    • Episode 199: Translating Cyber Risk into Business Decisions
    • The Myth of Mythos: What It Means For Information Security
    • Episode 202: Delineating AI Security and Cybersecurity

    If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing [email protected].

    41 min
  • Episode 205: Secure by Design — Now Updated for AI

    In episode 205 of Cybersecurity Where You Are, Tony Sager speaks with Phyllis Lee, VP of SBP Content Development at the Center for Internet Security®(CIS®), and Steve Lipner, Executive Director of SAFECode. Together, they discuss how an updated document from CIS and SAFECode gives concrete guidance on what artificial intelligence (AI) means for your Secure by Design process.

    Here are some highlights from our episode:

    • 02:17. A refresher on making Secure by Design digestible for end organizations
    • 02:57. Distillation and prescriptive guidance: The value provided by CIS
    • 06:53. An overview of Butler Lampson's "Gold Standard of Security"
    • 07:03. How a shift in approach to Secure by Design led to the founding of SAFECode
    • 09:42. The importance of verification requirements for what developers have done
    • 12:54. A product of CIS pragmatism: Prioritization relative to the development environment
    • 20:06. Artifacts as evidence of secure software development at work
    • 30:15. How the updated document provides guidance around AI
    • 30:45. What AI creates instead of new classes of vulnerabilities

    Resources

    • CIS Critical Security Controls® (CIS Controls®)
    • Secure by Design
    • Secure by Design v1.1 A Guide to Assessing Software Security Practices
    • Turning Secure Software Development into a Measurable Practice
    • CIS and SAFECode Release Secure by Design v1.1: A Guide to Assessing Software Security Practices
    • Episode 164: Secure by Design in Software Development
    • CIS Critical Security Control 16: Application Software Security
    • Guide to Implementation Groups (IG): CIS Critical Security Controls v8.1
    • Episode 200: Alan Paller's Vision and Our Next Chapter
    • From Prompts to Protocols: The Security Blueprint for Enterprise AI
    • Mythos AI: What Actually Matters for Cybersecurity Leaders

    If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing [email protected].

    37 min
  • Episode 204: FWC26 and the New Bar for Event Security

    In episode 204 of Cybersecurity Where You Are, Sean Atkinson speaks with Ryan Winmill, Chief Security Officer and Vice President of FIFA World Cup Boston, and John Cohen, Executive Director of the Office of Strategic Programs and Initiatives at the Center for Internet Security® (CIS®). Together, they discuss how FIFA World Cup 2026 (FWC26) — secured through an unprecedented tripartite governance framework, $625 million in U.S. Congressional funding, and real-time intelligence that stopped a swatting attempt at the finals — set a new standard for proactive event security worldwide.

    Here are some highlights from our episode:

    • 01:18. The "unprecedented" governance framework created for FWC26
    • 03:53. The role of CIS as a force multiplier for FIFA, host regions, and other partners
    • 11:00. Why you can't trust the person with an ego in large-scale event security planning
    • 13:23. How the threat environment evolved over the previous three World Cup tournaments
    • 17:23. A new bar for proactive event security going forward
    • 18:43. How CIS provided quality control that helped to mitigate swatting calls during FWC26
    • 21:55. Unique approaches used by host regions to better understand the World Cup fanbase
    • 23:15. How counterfeit FIFA volunteer uniforms triggered a cross-city credentialing response
    • 26:46. Recommendations for future large-scale event host cities
    • 30:19. Ryan's recommendation to future host cities: "Call CIS before you get started"

    Resources

    • Special Event Risk Analysis & Advisory Services
    • Episode 196: Securing FIFA World Cup 2026 Collaboratively
    • Inside the Security Operation Behind the 2026 FIFA World Cup
    • 3 Lessons for Securing Large-Scale Events: Inside FIFA World Cup 2026
    • Securing FIFA World Cup 2026 With a Collective Defense Approach

    If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing [email protected].

    34 min
  • Episode 203: Cyber Attacks' Human Impact — Beyond the Data

    In episode 203 of Cybersecurity Where You Are, Sean Atkinson speaks with Pavlina Pavlova, Founder of Critical Cyber. Together, they discuss how Pavlina started Critical Cyber to go beyond the data and give voice to the human impact of cyber attacks, from ransomware hitting hospitals to cyber tactics targeting civilians in active conflict zones.

    Here are some highlights from our episode:

    • 00:44. How Pavlina's work covering the impact of cyber attacks on Ukrainian critical infrastructure led to Critical Cyber
    • 03:13. How Critical Cyber works with cyber attack victims, responders, and other audiences
    • 04:08. Countering the tendency, even among cybersecurity experts, to sanitize cyber attacks' human impact
    • 08:57. The use of storytelling with those impacted by cyber attacks to drive policy changes
    • 15:02. Why cyber attacks in some sectors are underreported
    • 19:01. Critical Cyber's mission of combining testimony, research, and expert collaboration
    • 24:51. Where Critical Cyber is and where it's looking to go

    Resources

    • Critical Cyber
    • Cybersecurity for Critical Infrastructure
    • Episode 202: Delineating AI Security and Cybersecurity
    • Recent Water Utility Attacks Offer a Blueprint for Resilience

    If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing [email protected].

    34 min
  • Episode 202: Delineating AI Security and Cybersecurity

    In episode 202 of Cybersecurity Where You Are, Sean Atkinson and Ed Skoudis sit down with Rob T. Lee, Chief of Research & Chief AI Officer at the SANS Institute. Together, they explore how the implications of multiple 2026 sandbox escapes of artificial intelligence (AI) models are starting to delineate AI security and cybersecurity.

    Here are some highlights from our episode:

    • 02:00. The historical context of one AI model's 2026 sandbox escape
    • 03:26. The impact of ethics, guardrails, and misconfigurations in an AI containment breach
    • 06:08. Why context matters when talk of AI models "going rogue" surfaces
    • 11:49. How history helps us to delineate AI security and cybersecurity
    • 13:47. A new skill and mindset to match our refined AI risk understanding
    • 15:43. Rules and cybersecurity implementation as a possible way forward
    • 19:04. The double-edged sword of restricting access to open-weight models
    • 23:25. Recommendations for keeping up with what's changing in the AI security space
    • 25:51. Rob's advice: To learn how to defend a thing, try learning how to build it first
    • 28:23. AI governance and seeing through the "slop" to informed conversation
    • 29:54. The use of AI to learn more about and discuss AI security for years to come

    Resources

    • OpenAI says its AI technology acted on its own in an ‘unprecedented’ hack of another company
    • Pacing model development in an era of cyber-critical capabilities
    • Black Hat USA 2026 | The 'Breaking' News: The OpenAI–Hugging Face Incident
    • Episode 193: AI Security and Responsibility in EO 14409
    • The AI Daily Brief — Daily AI News & Analysis
    • AI Playbooks for SLTT Cybersecurity Leaders
    • SANS Cybersecurity Summits
    • SANS NewsBites

    If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing [email protected].

    39 min
  • Episode 201: The Evolution and AI Enablement of Pentesting

    In episode 201 of Cybersecurity Where You Are, Sean Atkinson and Ed Skoudis sit down with William Wright, Chief Executive Officer of Closed Door Security. Together, they reflect on the evolution of penetration testing, including the impact on pentesting from artificial intelligence (AI).

    Here are some highlights from our episode:

    • 01:03. How things have changed since William's and Ed's first pentests
    • 09:02. Community: A defining element of Capture The Flag (CTF) events
    • 14:47. Industry concerns over the "death" of CTFs and "cheating" by artificial intelligence (AI)
    • 17:00. Opportunities to take CTFs to the next level in the age of AI
    • 20:18. Pentesting vs. vulnerability scanning: Why terminology matters
    • 25:43. The advent of autonomous AI tools and what they could mean for vulnerability scanning
    • 29:07. Why continuous improvement in cybersecurity doesn't always require AI

    Resources

    • Closed Door Security
    • Episode 189: The Present and Future of AI-enabled Pentesting
    • SANS Cyber Ranges
    • Top External Network Risks And How to Fix Them
    • Penetration Testing
    • Vulnerability Assessments

    If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing [email protected].

    34 min
  • Episode 200: Alan Paller's Vision and Our Next Chapter

    In episode 200 of Cybersecurity Where You Are, Sean Atkinson, Tony Sager, and Ed Skoudis sit down with Frank Reeder, Co-Founder and Founding Chair of the Center for Internet Security® (CIS®). Together, they reflect on how Alan Paller's vision continues to drive CIS forward. In the spirit of that vision, this milestone episode also marks a new chapter for the podcast: Ed Skoudis joins as co-host of Cybersecurity Where You Are.

    Here are some highlights from our episode:

    • 01:09. The two complementary missions of CIS
    • 02:55. Three defining moments that have shaped CIS into the organization it is today
    • 08:10. The story of naming CIS
    • 10:31. How CIS and SANS advance Alan Paller's vision of bringing people together
    • 13:50. Personal anecdotes of Alan Paller as a connector of people
    • 15:45. "What would Alan do?" A question that continues to guide CIS and SANS
    • 22:00. How CIS security best practices are emblematic of helping others
    • 27:12. CIS's "secret sauce" as a trusted, neutral platform for cybersecurity collaboration
    • 29:53. How CIS can continue to embody Alan Paller's philosophy into the future
    • 37:47. A special announcement: Ed Skoudis as a new co-host on the podcast

    Resources

    • CIS Benchmarks® List
    • CIS Critical Security Controls®
    • Multi-State Information Sharing and Analysis Center®
    • Episode 114: 3 Board Chairs Reflect on 25 Years of Community
    • Alan Paller Laureate Program
    • SANS Difference Makers Awards

    If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing [email protected].

    41 min
  • Episode 199: Translating Cyber Risk into Business Decisions

    In episode 199 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager sit down with Chris Painter, Chair of the Risk Committee and Board Member at the Center for Internet Security® (CIS®). Together, they discuss how chief information security officers (CISOs) can support the work of translating cyber risk into business decisions by Boards.

    Here are some highlights from our episode:

    • 00:50. Introductions to Chris
    • 01:36. The single biggest translation error Chris has seen CISOs make
    • 07:38. Cyber risk quantification: An opportunity to go beyond translation for Boards
    • 09:25. How ransomware changed Boards' understanding of cyber risks' business impact
    • 10:45. The value of tabletop exercises (TTX) and other simulations in creating shared language
    • 13:26. Recommendations on how to make the most of a TTX
    • 18:37. Risk modeling and how artificial intelligence (AI) complicates probability estimations
    • 21:51. "Pressure" (2026) as an illustration of making good, not 100% accurate, estimations
    • 22:58. How growing public awareness of cyber is reshaping CISOs' conversations with Boards
    • 25:55. The importance of walking Boards through risk mitigation steps with AI as an example
    • 29:31. A recommendation for how CISOs can learn what directors care about
    • 30:15. From "wizardry" to familiarity: An ongoing generational shift around cyber

    Resources

    • Episode 183: The Role of CISO in Supporting Risk Translation
    • Episode 187: The Role of a CISO as a Strategic Storyteller
    • Episode 192: How Leaders Balance Expertise and Communication
    • How Risk Quantification Tests Your Reasonable Cyber Defense
    • CIS RAM (Risk Assessment Method)
    • Leveraging Generative Artificial Intelligence for Tabletop Exercise Development
    • CIS Controls v8.1 Incident Response Policy Template
    • You Have a Cybersecurity Incident. Now What?
    • Prompt Injections: The Inherent Threat to Generative AI
    • "Pressure" | Official Website | 29 May 2026

    If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing [email protected].

    41 min

About Cybersecurity Where You Are (audio)

From the publisher's feed

Welcome to audio version of “Cybersecurity Where You Are,” the podcast of the Center for Internet Security® (CIS®). Cybersecurity affects us all, so join us on Wednesdays as Sean Atkinson, CISO at…