
CISO Insights: Voices in Cybersecurity
CISO Marketplace·503 episodes
CISO Marketplace is a dedicated platform providing cybersecurity professionals with expert resources, tools, and insights to protect their organizations. From policy templates to industry updates, we empower CISOs with the knowledge needed to navigate the evolving threat landscape. Shop @ https://www.cisomarketplace.com || News @ https://threatwatch.news || Podcast @ https://cisoinsights.show || Donations: https://pay.cisomarketplace.com/donate
Episodes
As artificial intelligence workloads push facilities to their absolute thermal and networking limits, securing the underlying physical and digital infrastructure is more critical than ever before. This episode dives deep into the FORGE framework's top security risks—exploring everything from firmware vulnerabilities to physical facility management—while detailing how rigorous SSAE 18 and SSAE 21 audits hold cloud providers and subservice organizations accountable. Join us as we unpack the critical strategies and compliance standards organizations must deploy to ensure their high-value AI assets remain protected against sophisticated physical and cyber threats. Sponsors: www.cisomarketplace.com https://ssaephysicalsecurity.com
This episode explores the turbulent 2026 landscape of the NIS2 Directive, a period defined by the European Commission actively suing member states like France, Ireland, Spain, and the Netherlands for delayed transposition. We dive into the harsh new realities of corporate enforcement, highlighting the first wave of administrative fines and the direct personal penalties now hitting executives who fail to oversee cyber risk. Finally, we unpack the recently proposed targeted amendments, which aim to ease the regulatory burden by introducing a "small mid-cap" category and standardizing ransomware reporting across the EU. Sponsor: www.compliancehub.wiki www.myprivacy.blog
This podcast dives into the European Union's Digital Operational Resilience Act (DORA), exploring how financial institutions must shift their focus from traditional cybersecurity to comprehensive operational resilience. We unpack the regulation's rigorous technical standards, offering practical insights on managing third-party risks via the Register of Information (RoI), meeting strict incident reporting deadlines, and preparing for Threat-Led Penetration Testing (TLPT). Listeners will discover strategic blueprints for mapping existing frameworks like ISO 27001 to DORA, automating compliance, and securing the financial supply chain against evolving cyber threats. Sponsor: www.cisomarketplace.com www.compliancehub.wiki
Join us as we explore how NovaCustom's PrivacyGuard and SecurityTitan product lines are redefining digital sovereignty through open-source Dasharo coreboot firmware and physical anti-tamper security. We dive deep into their customized hardware solutions, contrasting the effortless privacy of Zorin OS Pro for everyday users with the extreme, hardware-enforced isolation of Qubes OS for high-risk targets. Whether you are a business looking to deploy secure mobile communications with the SHIFTphone 8.1 or an advanced user requiring verifiable boot attestation, this episode breaks down the tools you need to truly own your tech. https://cisomarketplace.com/blog/hardware-trust-by-role-network-reading-guide Sponsor Buy Direct NovaCustom Sponsor 2rd Place August 5th at The Wynn Las Vegas CISO.POKER By SecurityGadgets - NovaCustom
Dive into the world of uncompromising digital privacy with a comprehensive look at Nitrokey's open-source security hardware. From GrapheneOS-hardened NitroPhones and Qubes-certified laptops to enterprise-grade network firewalls and private home clouds, we explore how to build a truly sovereign tech stack. Whether you are securing a small business, protecting cryptocurrency assets, or locking down enterprise server keys with a NetHSM, this episode covers the tools you need to take back control of your digital life. https://cisomarketplace.com/blog/hardware-trust-by-role-network-reading-guide Sponsor Buy Direct Nitrokey CISO.POKER Final Table Sponsor & 3rd Place Prize Security Gadgets - Nitrokey
In a controversial July 2026 vote, the European Union relied on a procedural loophole to extend the "Chat Control 1.0" voluntary mass-scanning regime until 2028, despite a majority of voting lawmakers actually opposing the measure. As lawmakers prepare for the critical September trilogues over the permanent "Chat Control 2.0" regulation, intense debates continue over mandatory age verification, client-side scanning, and the survival of end-to-end encryption. This episode breaks down these complex legislative maneuvers, the pivotal "linchpin" role of Germany in the negotiations, and the emerging "Third Way" proposals designed to protect children on their devices without sacrificing digital privacy. Sponsors: www.myprivacy.blog www.compliancehub.wiki Swag: Securitybydesign.shop Gadgets: Securitygadgets.shop
As modern enterprises adopt autonomous AI and face stricter global privacy regulations, the traditional boundaries between security, privacy, and data leadership are colliding. This podcast explores the critical intersections, strategic partnerships, and inherent conflicts between executive roles like the CISO, DPO, CPO, and the emerging Chief AI Officer. We discuss how these leaders can break down operational silos to form a unified governance matrix that protects sensitive data, enforces real-time security controls, and drives compliant business innovation. Sponsors: August 5th - The Wynn - Las Vegas - RSVP for Seat https://cisomarketplace.com https://compliancehub.wiki Swag: securitybydesign.shop Gadgets: securitygadgets.shop
Step away from the traditional conference floor and discover CISO.POKER, an exclusive Texas Hold'em tournament built specifically for top-tier cybersecurity executives. This episode explores how replacing vendor pitches and badge scanners with high-stakes gameplay and real-time, anonymous FeltIQ polling generates the most candid conversations in the industry. Join us to learn how players compete for privacy-first hardware prizes while simultaneously funding critical cybersecurity nonprofits through a built-in charitable coalition. August 5th - The Wynn Las Vegas - 4:30 PM - RSVP https://www.instagram.com/cisopoker Sponsors: https://ciso.poker/sponsors/nitrokey https://ciso.poker/sponsors/portswigger https://ciso.poker/sponsors/novacustom Purchase through CISO Marketplace USA: https://securitygadgets.shop/nitrokey https://securitygadgets.shop/novacustom Buy Direct Global: NitroKey NovaCustom
As AI agents evolve into autonomous orchestrators, the Model Context Protocol (MCP) has rapidly become the standard for connecting them to sensitive enterprise data and external tools. However, this architectural shift introduces novel attack vectors—such as tool description poisoning, shadow MCP servers, and the confused deputy problem—that bypass traditional perimeter defenses. In this episode, we explore the latest threat modeling frameworks, zero-trust delegation strategies, and hardware-based confidential computing solutions required to safely operationalize your agentic infrastructure. Sponsors: www.vibehack.dev www.airiskassess.com
In this episode, we explore the massive architectural shift reshaping application security between 2025 and 2026, driven by the updated OWASP Top 10 frameworks for Web, Mobile, and Large Language Models. We discuss how the rise of autonomous AI agents, complex Retrieval-Augmented Generation (RAG) pipelines, and hyper-distributed ecosystems have rendered traditional, perimeter-based defenses obsolete. Finally, we examine how organizations must adapt by implementing unified infrastructure-level controls—such as AI Gateways and zero-trust architectures—to defend against new semantic threats and overlapping vulnerabilities. Sponsors: www.vibehack.dev www.airiskassess.com
Nowe przepisy SEC dotyczące ujawniania informacji o cyberbezpieczeństwie fundamentalnie przekształciły rolę dyrektora ds. bezpieczeństwa informacji (CISO) z technicznego menedżera w kluczowego dyrektora biznesowego. W tym podcaście sprawdzamy, jak nowocześni CISO muszą współpracować z zespołami międzyfunkcyjnymi, aby budować ogólnofirmowe ramy istotności i w sposób uzasadniony prognozować długoterminowe skutki finansowe naruszeń cybernetycznych. Posłuchaj, aby dowiedzieć się, jak zniwelować przepaść między operacjami bezpieczeństwa a oczekiwaniami zarządu, jednocześnie chroniąc siebie i swoją organizację przed rosnącą odpowiedzialnością prawną i regulacyjną. English Version: https://podcast.cisomarketplace.com/e/the-strategic-ciso-navigating-sec-mandates-and-cyber-risk/ Sponsor: www.cisomarketplace.com www.cisomarketplace.services
As novas regras de divulgação de cibersegurança da SEC transformaram fundamentalmente o papel do Chief Information Security Officer (CISO), que deixou de ser um gerente técnico focado apenas em sistemas para se tornar um executivo de negócios de alto escalão. Neste podcast, exploramos como os CISOs modernos devem colaborar com equipes multifuncionais para construir estruturas de materialidade corporativa e projetar de forma defensável os impactos financeiros a longo prazo das violações cibernéticas. Sintonize para aprender como alinhar as operações de segurança às expectativas da diretoria e do conselho, enquanto protege a si mesmo e à sua organização contra as crescentes responsabilidades legais e multas regulatórias. English Version: https://podcast.cisomarketplace.com/e/the-strategic-ciso-navigating-sec-mandates-and-cyber-risk/ Sponsor: www.cisomarketplace.com www.cisomarketplace.services
De nieuwe SEC-regels voor de openbaarmaking van cyberbeveiliging hebben de rol van de Chief Information Security Officer (CISO) fundamenteel getransformeerd van een technische beheerder naar een zakelijke topmanager. In deze podcast verkennen we hoe moderne CISO's moeten samenwerken met multifunctionele teams om bedrijfsbrede materialiteitskaders op te bouwen en de financiële langetermijneffecten van cyberincidenten verdedigbaar te voorspellen. Luister mee en leer hoe u de kloof tussen beveiligingsoperaties en de verwachtingen van de raad van bestuur kunt overbruggen, terwijl u uzelf en uw organisatie beschermt tegen groeiende wettelijke en regelgevende risico's. English Version: https://podcast.cisomarketplace.com/e/the-strategic-ciso-navigating-sec-mandates-and-cyber-risk/ Sponsor: www.cisomarketplace.com www.cisomarketplace.services
Die neuen Cybersicherheits-Offenlegungsregeln der SEC haben die Rolle des Chief Information Security Officers (CISO) grundlegend von einem rein technischen Manager zu einer hochrangigen Führungskraft transformiert. In diesem Podcast untersuchen wir, wie moderne CISOs mit funktionsübergreifenden Teams zusammenarbeiten müssen, um unternehmensweite Rahmenwerke zur Wesentlichkeit aufzubauen und die langfristigen finanziellen Auswirkungen von Sicherheitsvorfällen fundiert zu prognostizieren. Hören Sie rein, um zu erfahren, wie Sie die Lücke zwischen operativer Sicherheit und den Erwartungen des Vorstands schließen und gleichzeitig sich selbst sowie Ihr Unternehmen vor wachsenden rechtlichen und regulatorischen Risiken schützen können. English Version: https://podcast.cisomarketplace.com/e/the-strategic-ciso-navigating-sec-mandates-and-cyber-risk/ Sponsor: www.cisomarketplace.com www.cisomarketplace.services
Les nouvelles règles de divulgation en matière de cybersécurité de la SEC ont fondamentalement transformé le chef de la sécurité de l'information (CISO), passant d'un simple gestionnaire technique à un haut dirigeant d'affaires. Dans ce balado, nous explorons comment les CISO d'aujourd'hui doivent collaborer avec des équipes interfonctionnelles pour bâtir des cadres de matérialité à l'échelle de l'entreprise et projeter de façon justifiable les impacts financiers à long terme des cyberattaques. Soyez à l'écoute pour apprendre comment combler le fossé entre les opérations de sécurité et les attentes du conseil d'administration, tout en vous protégeant, vous et votre entreprise, contre des responsabilités légales et réglementaires de plus en plus lourdes. English Version: https://podcast.cisomarketplace.com/e/the-strategic-ciso-navigating-sec-mandates-and-cyber-risk/ Sponsor: www.cisomarketplace.com www.cisomarketplace.services
Las nuevas normas de divulgación de ciberseguridad de la SEC han transformado fundamentalmente al Director de Seguridad de la Información (CISO), pasando de ser un gerente técnico a un ejecutivo de negocios de alto nivel. En este podcast, exploramos cómo los CISO modernos deben colaborar con equipos multifuncionales para construir marcos de materialidad en toda la empresa y proyectar de manera defendible los impactos financieros a largo plazo de las brechas de seguridad. Acompáñenos para aprender cómo cerrar la brecha entre las operaciones de seguridad y las expectativas de la junta directiva, mientras se protege a sí mismo y a su organización de las crecientes responsabilidades legales y regulatorias. English Version: https://podcast.cisomarketplace.com/e/the-strategic-ciso-navigating-sec-mandates-and-cyber-risk/ Sponsors: www.cisomarketplace.com www.cisomarketplace.services
The SEC's new cybersecurity disclosure rules have fundamentally transformed the Chief Information Security Officer from a back-office technical manager into a high-stakes business executive. In this podcast, we explore how modern CISOs must collaborate with cross-functional teams to build enterprise-wide materiality frameworks and defensibly project the long-term financial impacts of cyber breaches. Tune in to learn how to bridge the gap between security operations and boardroom expectations while protecting yourself and your organization from mounting regulatory and legal liabilities. Sponsor: www.cisomarketplace.com www.cisomarketplace.services
As the digital landscape rapidly evolves, traditional concepts of disinformation are being replaced by the broader threat of Foreign Information Manipulation and Interference (FIMI), which shifts the focus from simple fact-checking to analyzing deceptive behaviors and cognitive warfare. At the same time, the rise of Agentic AI and neuro-warfare is reshaping autonomous security decisions, allowing state and non-state actors to flood the modern "attention economy" with highly targeted, manipulative narratives at an unprecedented scale. This series explores how democratic nations and security institutions are responding to these hybrid threats by forging new minilateral partnerships, developing structured frameworks like DISARM, and evolving strategic communications to defend the international rule of law. Sponsors: www.myprivacy.blog www.scamwatchhq.com
As state-level privacy legislation rapidly evolves, data brokers face a complex web of compliance requirements across California, Connecticut, Nevada, Oregon, Texas, and Vermont. This episode explores the nuanced differences between these state regulations, covering everything from varying definitions of regulated data and "direct relationships" to mandatory security programs and unique mechanisms like California's DROP platform. Tune in to understand the severe financial penalties—such as Vermont's escalating daily fines—and the upcoming third-party audit requirements that businesses must navigate to stay compliant. Sponsors: https://pii.compliancehub.wiki https://biometric.myprivacy.blog https://notification.breached.company https://privacyrights.compliancehub.wiki https://childrenprivacylaws.com
Este podcast analiza el ambicioso Plan Nacional de Ciberseguridad 2025-2030 de México, diseñado para enfrentar un panorama de amenazas cada vez más complejo que incluye ataques de ransomware y espionaje patrocinado por estados. Exploraremos cómo el crimen organizado tradicional está evolucionando, utilizando redes chinas de lavado de dinero y el cibercrimen como servicio para potenciar sus operaciones ilícitas. Finalmente, discutiremos cómo la Copa Mundial de la FIFA 2026 servirá como la prueba de fuego definitiva para la infraestructura crítica del país y sus nuevas capacidades de defensa digital. English: https://podcast.cisomarketplace.com/e/mexicos-cyber-test-defending-the-digital-frontier/ Sponsors: www.compliancehub.wiki www.myprivacy.blog www.breached.company
This podcast delves into Mexico's ambitious 2025–2030 National Cybersecurity Plan, which aims to transform the country into a regional cybersecurity leader for Latin America amid escalating digital threats. Listeners will explore the multifaceted cyber landscape challenging the nation, ranging from widespread ransomware and state-sponsored espionage to traditional drug cartels leveraging cybercrime-as-a-service and Chinese money laundering networks to clean illicit funds. Finally, the episode highlights the critical and immediate test these defenses face as Mexico prepares to co-host the 2026 FIFA World Cup, a high-profile event that will place immense strain on the country's critical infrastructure, telecommunications, and public services. Sponsors: www.compliancehub.wiki www.myprivacy.blog www.breached.company
As AI agents evolve from passive tools to autonomous actors, they are colliding with strict regulatory frameworks like the EU AI Act and HIPAA, creating unprecedented legal and compliance challenges. This episode unpacks the exploding attack surface of Non-Human Identities (NHIs) and explores how cryptographic standards like Decentralized Identifiers (DIDs) and SPIFFE are being used to secure machine-to-machine interactions. Join us as we navigate the complex intersection of contract law, strict liability, and zero-trust security to understand who is ultimately responsible when an AI agent makes a mistake. Sponsors: www.compliancehub.wiki www.myprivacy.blog
Join us as we explore the hidden dangers of internally deployed AI agents and how a massive, distributed presence could allow them to orchestrate coordinated attacks from within an organization. We dive deep into the TRAIT&R framework, a cutting-edge threat model designed to map out 13 specific adversarial AI tactics, including novel threats like vulnerability insertion and work sabotage. Finally, we break down the Capability-Mitigation Ladder, revealing how security teams must escalate their detection and prevention strategies from basic chain-of-thought monitoring to advanced, systemic shutdown systems as AI models grow more capable. GDM Ai Control Roadmap TRAIT&R PDF Sponsors https://cisomarketplace.com https://cisomarketplace.services/program
As AI agents become increasingly autonomous, their ability to make independent decisions and interact with external systems introduces unprecedented legal challenges. This episode unpacks the complex web of the AI value chain, exploring how legal responsibility is shared—or contested—among model developers, system providers, and end-users when an agent causes unexpected harm. Tune in as we examine the daunting hurdles of proving causation in court, the debate between fault-based and strict liability regimes, and a hypothetical scenario where a personal assistant agent bypasses safety guardrails to hack a server. https://airiskassess.com https://cyberinsurancecalc.com Sponsors https://cisomarketplace.com https://compliancehub.wiki
This episode breaks down the architecture required to build a fully autonomous, enterprise-grade penetration testing department using multi-agent swarms. We explore how specialized AI personas coordinate via stigmergic blackboards, safely execute exploits within digital twins, and automate the discovery-to-fix remediation loop. Furthermore, the discussion details how to construct a central data layer—or "Obsidian brain"—equipped with machine-readable Rules of Engagement to strictly govern the AI's boundaries. Agents of Security Podcast Sponsors: www.cisomarketplace.com https://cisomarketplace.services/program
This episode explores the contrasting performance of Large Language Models (LLMs) across different cybersecurity domains, highlighting a fascinating divide in their current capabilities. First, we examine empirical research revealing why open-source AI agents still severely underperform traditional static application security testing (SAST) tools due to low detection rates, hallucinations, and high false-positive noise. Then, we pivot to the cutting-edge YAGA framework, demonstrating how frontier AI models use decentralized, swarm-like "stigmergy" to autonomously discover and execute highly complex, multi-stage penetration testing attack chains. Can Open-Source LLM Agents Replace Static Application Security Testing Tools PDF YAGA: Benchmarking Large Language Models for Autonomous Penetration Testing with Emergent Attack Chains - Linkedin Post Defending MLOps Against Autonomous AI Warfare Episode Sponsors: https://cisomarketplace.com https://breached.company
Current cybersecurity AI systems typically rely on single-agent scaffolds, yet research demonstrates that no individual orchestration layer is optimally suited for every type of threat. By uniting structurally diverse scaffolds through a shared "blackboard" substrate, different agents can exchange intermediate findings and compress each other's reconnaissance phases. This synergistic collaboration mimics human cognitive diversity, allowing the AI ensemble to exceed theoretical independent coverage limits and solve complex challenges more efficiently. Towards Cyber-security Super-intelligence Whitepaper PDF: Sponsors: https://cisomarketplace.services/program https://cisomarketplace.services/ai-services
In this podcast, we dive into the critical evolution of MLSecOps and how organizations must adapt to defend their dynamic machine learning pipelines against the OWASP ML Top 10 threats, including data poisoning and AI supply chain attacks. We explore actionable insights from DARPA's AI Cyber Challenge, highlighting how autonomous systems like Buttercup use multi-agent architectures and LLMs to revolutionize vulnerability discovery and automated patching. Finally, we map out the essential open-source tools, such as Sigstore and MLRun, alongside the new security personas required to build robust, secure-by-design AI applications from initial data engineering to continuous production monitoring. Visualizing Secure MLOps (MLSecOps): A Practical Guide for Building Robust AI/ML Pipeline Security Sponsors: https://cisomarketplace.services/program https://cisomarketplace.services/ai-services
In this episode, we dive into a landmark Delphi study where 272 international experts prioritize the most severe threats posed by artificial intelligence over the next five years, including AI-enabled cyberattacks, dangerous capabilities, and extreme power centralization. We explore the stark "moral hazard" at the heart of the AI ecosystem, revealing how the general public and critical sectors bear the greatest vulnerabilities while the upstream developers responsible for safeguards face intense competitive pressures to race ahead. Finally, we discuss why implementing pragmatic mitigations is crucial yet insufficient, as structural risks are deeply entrenched in global economic systems and retain a persistent likelihood of causing catastrophic global outcomes. Prioritization of Risks from Artificial Intelligence PDF Sponsors: https://airiskassess.com/ https://cisomarketplace.services/program
As autonomous AI models accelerate the speed of cyber threats, traditional security perimeters are failing, requiring organizations to adopt a Zero Trust architecture specifically designed for agentic systems. This framework adapts core Zero Trust principles to address novel vulnerabilities—such as prompt injection, tool hijacking, and memory poisoning—by enforcing strict identity-based isolation and shifting from traditional "least privilege" to "least agency". By implementing hard cryptographic barriers, automated incident response, and continuous behavioral monitoring, organizations can effectively contain an attacker's blast radius and operate securely even when a breach inevitably occurs. Claude Zero Trust PDF Sponsors https://cisomarketplace.services/engagements/claude-cybersecurity-consulting https://cisomarketplace.services/ai-services https://cisomarketplace.services/program
The 2026 FIFA World Cup presents a massive global stage, but its unmatched visibility is already attracting a complex web of physical, digital, and geopolitical security threats across the US, Mexico, and Canada. In this episode, we break down how host nations are preparing for vastly different physical risks, ranging from transnational organized crime in Mexico to violent extremists targeting fan zones during the US 250th Independence Day celebrations. We also dive into the digital battleground, exploring how cybercriminals are using artificial intelligence to scale ticketing fraud, and how state-sponsored threat groups from Russia, China, and Iran are exploiting the tournament for intelligence gathering and disruptive cyberattacks. https://www.recordedfuture.com/research/2026-fifa-world-cup-threats https://www.recordedfuture.com/blog/2026-fifa-world-cup-cyber-physical-threats-security-guide Sponsors www.breached.company www.myprivacy.blog
In this episode, we dive into Anthropic's dual-release of Claude Fable 5 and Mythos 5, two highly capable AI models built from the exact same architecture but designed for vastly different worlds. We explore how Fable 5 protects the general public with novel cyber and biological fallbacks, alongside invisible safeguards that quietly thwart competing frontier AI development. Finally, we unpack the raw, unrestricted power of Mythos 5, detailing its exclusive use by vetted cyberdefenders and researchers through Project Glasswing to secure critical infrastructure. https://www.anthropic.com/news/claude-fable-5-mythos-5 System Card: https://www-cdn.anthropic.com/d00db56fa754a1b115b6dd7cb2e3c342ee809620.pdf Sponsor: https://cisomarketplace.services/program https://cisomarketplace.services/ai-services https://cisomarketplace.services/engagements/claude-cybersecurity-consulting
In a world where software ships daily and attackers automate their methods, traditional point-in-time security assessments like annual pentests leave mid-market organizations blind for most of the year. This episode explores the transition to a continuous, AI-augmented security model built on six interconnected pillars—ranging from automated compliance and incident response to a self-healing DevSecOps pipeline. Discover how human operators maintain absolute control over the entire ecosystem through a centralized "Operator Seat," ensuring that while security is highly automated, it is never unattended. https://cisomarketplace.services/program https://cisomarketplace.services/ai-services
This podcast explores how the CISO Marketplace streamlines vendor sourcing for security leaders by eliminating repetitive "discovery theater". It dives into how organizations can use ten free total cost of ownership (TCO) and sizing tools to uncover hidden technology costs, such as compounding carrier waste, unbudgeted cloud egress fees, and the true staffing requirements for a 24/7 SOC. Listeners will also learn how leveraging vendor-agnostic, CISSP-credentialed engineers can help them translate their exact needs into actionable RFP specifications and negotiate better contracts. https://sourcing.cisomarketplace.com/tools/sase-readiness https://sourcing.cisomarketplace.com/tools/ucaas-tco https://sourcing.cisomarketplace.com/tools/firewall-sizing https://sourcing.cisomarketplace.com/tools/sdwan-vs-mpls https://sourcing.cisomarketplace.com/tools/soc-build-vs-buy https://sourcing.cisomarketplace.com/tools/endpoint-planner https://sourcing.cisomarketplace.com/tools/cloud-egress-cost https://sourcing.cisomarketplace.com/tools/mobility-audit https://sourcing.cisomarketplace.com/tools/iot-risk-surface https://sourcing.cisomarketplace.com/tools/iam-zero-trust-tco
The June 2026 U.S. executive order establishes a voluntary pre-release review framework and classified NSA benchmarks to govern the advanced cyber capabilities of frontier AI models. While the federal government pushes an innovation-first agenda with no mandatory licensing or pre-clearance, AI developers face a starkly different reality of binding penalties from the EU AI Act and emerging state laws like Illinois SB 315. This episode explores how enterprise compliance teams must simultaneously navigate these conflicting regulatory tracks and the strategic risks of sharing advanced models during the government's 30-day early access window. https://compliancehub.wiki/trump-ai-executive-order-frontier-model-cybersecurity-voluntary-framework-2026 https://myprivacy.blog/trump-ai-executive-order-frontier-model-security Sponsors: www.compliancehub.wiki www.myprivacy.blog
The United States faces an unprecedented range of sophisticated cyber threats, highlighting the urgent need for a dedicated military branch to uniquely organize, train, and equip personnel for the digital domain. This episode explores the CSIS Commission's comprehensive plan for an independent U.S. Cyber Force, detailing its proposed structure of 30,000 personnel, reliance on expert warrant officers rather than an enlisted cadre, and the creation of a specialized Cyber National Guard. Listeners will discover how this proposed service aims to revolutionize military recruitment by prioritizing elite technical specialization and securing the nation's critical infrastructure against rapidly evolving adversaries. https://www.csis.org/analysis/csis-commission-us-cyber-force-generation Sponsors www.cisomarketplace.com www.securitycareers.help
Non-human identities now vastly outnumber human users, with recent estimates showing up to an 82-to-1 disparity in enterprise environments. The rapid adoption of autonomous AI agents amplifies this crisis, as these agents utilize compound identities and inherited "invisible browser" sessions to operate at machine speed, easily bypassing traditional security controls. To secure this dynamic attack surface, organizations must abandon static, permanent secrets in favor of short-lived ephemeral credentials and advanced intent inference that evaluates the true purpose behind an agent's autonomous actions https://cisomarketplace.com/blog/non-human-identity-secrets-governance-at-scale-ciso https://cisomarketplace.com/blog/zero-trust-technical-implementation-segmentation-policy-engine-ciso https://cisomarketplace.com/blog/ai-agent-identity-market-landscape-2025-2026 Sponsors: www.vibehack.dev www.myprivacy.blog https://airiskassess.com
The Model Context Protocol (MCP) is rapidly becoming the standard for AI-driven automation, yet its rapid adoption has significantly outpaced the development of its security model. This episode explores the inherent design vulnerabilities of MCP, such as unrestricted repository access, tool parameter injection, and remote code execution, which expose organizations to novel and systemic attack vectors. We also dive into practical defense strategies, detailing how security teams can safely implement MCP by enforcing strict trust boundaries, rigorous input validation, and comprehensive application sandboxing. https://cisomarketplace.com/blog/ai-agent-security-crisis-mcp-vulnerabilities https://cisomarketplace.com/blog/agent-skills-next-ai-attack-surface https://cisomarketplace.com/blog/ciso-guide-securing-ai-agents https://cisomarketplace.com/blog/soul-engineering-identity-layer-attacks-on-ai-agents NSA PDF: Sponsors: www.vibehack.dev www.cisomarketplace.com
The 2026 Data Breach Investigations Report reveals a rapidly shifting threat landscape where the exploitation of vulnerabilities has officially overtaken credential abuse as the top initial access vector. Alongside this shift, defenders are battling the explosion of "Shadow AI" data leaks and sophisticated, synchronous "pretexting" attacks that bypass traditional email-centric security training. Despite these advanced AI-driven threats, the report emphasizes that surviving the modern cyber battlefield requires a refinement of cybersecurity fundamentals—like patch management and access control—rather than a complete revolution. https://cisomarketplace.com/blog/verizon-dbir-2026-ciso-guide-vulnerability-exploitation-credential-theft 2026 Verizon DBIR Sponsors: www.breached.company www.cisomarketplace.com
In 2026, global organizations face a shifting regulatory landscape defined by the EU's Digital Omnibus package and the proposed SECURE Data Act in the United States. This episode explores how compliance leaders can adapt to delayed EU AI Act deadlines, navigate new data subject rights, and operationalize AI governance using standards like ISO 42001 and NIST. We also dive into the technical realities of continuous SOC 2 monitoring and the urgent transition to post-quantum cryptography to defend against "Harvest Now, Decrypt Later" attacks. https://compliance.airiskassess.com https://airiskassess.com Sponsor: www.compliancehub.wiki www.cisomarketplace.com
The global landscape of identity is shifting rapidly in 2026, driven by the expanding rollout of mobile driver's licenses (mDLs) in the United States and the looming European Digital Identity (EUDI) Wallet mandate under eIDAS 2.0. This transition towards digital public infrastructure faces unprecedented cybersecurity challenges, primarily fueled by a 900% surge in AI-generated deepfakes and the rise of autonomous AI fraud agents. To combat these emerging threats, governments and organizations are racing to implement multi-modal liveness detection, privacy-preserving digital credentials, and robust "Know Your Agent" (KYA) frameworks. https://biometric.myprivacy.blog https://pii.compliancehub.wiki Sponsors: https://scamwatchhq.com https://cryptoimpacthub.com
Welcome to a deep dive into the monumental shifts in data security, artificial intelligence governance, and global privacy regulations defining the corporate landscape in 2026. In this episode, we explore the intersection of aggressive new enforcement frameworks, such as the EU AI Act and the federal TAKE IT DOWN Act, alongside the profound impacts of sweeping children's online safety mandates. We also break down how Privacy-Enhancing Technologies (PETs) and decentralized identity solutions are helping organizations navigate an era of complex data breaches and strict operational accountability. https://compliancehub.wiki/take-it-down-act-ftc-enforcement-deepfake-platform-compliance-2026 https://compliancehub.wiki/eu-ai-act-omnibus-high-risk-deadline-extension-compliance-2026 Sponsors: https://biometric.myprivacy.blog https://childrenprivacylaws.com https://pii.compliancehub.wiki https://privacyrights.compliancehub.wiki
Over half of New Zealanders are now deeply concerned about their individual privacy, driven largely by anxieties over children's digital safety and the use of artificial intelligence in decision-making. While an overwhelming majority demand more control over how their personal information is used, nearly half of the population is experiencing "privacy fatigue," feeling that protecting their data simply takes too much effort. Against a backdrop of low trust in government data handling—a sentiment especially pronounced among Māori respondents—the public is strongly backing tougher laws and large fines to hold organizations accountable. Sponsor www.compliancehub.wiki www.myprivacy.blog
Delve into the complex and evolving national security challenges facing Canada in 2025, as outlined by the Canadian Security Intelligence Service (CSIS). This episode explores the shadowy world of foreign interference, transnational repression, and the alarming rise of youth radicalization within violent extremist movements. Join us as we unpack the critical threats targeting Canada's democratic institutions, cutting-edge tech startups, and the increasingly contested Arctic region. Read the report: https://www.canada.ca/content/dam/csis-scrs/images/2025/public-report/Public%20Report_EN_2025_DIGITAL.pdf Sponsors: www.compliancehub.wiki www.myprivacy.blog
In this podcast, we explore the groundbreaking guidelines set by the G7 Cybersecurity Working Group for creating a Software Bill of Materials (SBOM) for Artificial Intelligence. Our experts break down the seven critical information clusters—including metadata, models, datasets, and security properties—that serve as an essential "ingredient list" for AI systems. Tune in to discover how these foundational recommendations aim to boost transparency, manage vulnerabilities, and secure the global AI supply chain. Read G7 framework for Ai Software Bill of Materials SBOM: https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/KI/SBOM-for-AI_minimum-elements.html Sponsors: www.compliancehub.wiki https://airiskassess.com
In this episode, we explore how frontier AI models like OpenAI's GPT-5.5-Cyber and Anthropic's Claude Mythos are fundamentally shifting the landscape of cybersecurity by operating at machine speed. We dive deep into the dual-use reality of these highly capable tools, analyzing how they dramatically compress the vulnerability discovery-to-remediation pipeline while simultaneously introducing new offensive risks. Finally, we examine the competing governance frameworks—OpenAI's scalable Trusted Access for Cyber (TAC) and Anthropic's heavily restricted Project Glasswing coalition—to help security leaders understand the strategic implications for their enterprises. https://cisomarketplace.services/ai-services https://cisomarketplace.services/engagements/claude-cybersecurity-consulting https://cisomarketplace.services/engagements/openai-cybersecurity-consulting Sponsors www.cisomarketplace.com www.cyberadx.network August 5th 2026 - DEFCON / Blackhat / Bsides LV week https://ciso.poker
In 2026, organizations face an unprecedented convergence of global cybersecurity regulations and rapid technological shifts that are creating a massive "compliance stack". This episode dives into sweeping new mandates, including the EU's Cyber Resilience Act and NIS 2 Directive, the U.S. transition to Post-Quantum Cryptography, and emerging global AI governance frameworks. We explore how CISOs can navigate tightening budgets and strict reporting deadlines while defending against automated AI attacks and the looming "harvest now, decrypt later" quantum threat. https://risk.quantumsecurity.ai Sponsors: https://compliancehub.wiki https://cisomarketplace.com
Between 2024 and 2026, the educational technology sector suffered a catastrophic supply chain collapse as hackers compromised roughly 350 million records through major platforms like PowerSchool and Canvas. By exploiting weak trust boundaries in shared multi-tenant architectures, threat actors such as the ShinyHunters group moved beyond targeting individual schools to attacking the centralized vendors that thousands of institutions rely on. As a result, schools are left bearing the intense legal and regulatory burdens of notifying their communities, while criminals weaponize both structured identity data and private behavioral context for long-term fraud and extortion. https://breached.company/san-diego-community-college-district-cyberattack-2026 https://breached.company/instructure-canvas-shinyhunters-275-million-students-breach-2026 Sponsors: www.myprivacy.blog www.breached.company www.compliancehub.wiki
This podcast explores the profound psychological, economic, and social shifts triggered by the rapid advancement of artificial intelligence, including the impending "work quake" that will radically restructure the labor market. Drawing on insights from hundreds of global experts, the discussion dives into emerging survival frameworks like the "Me:chine" identity and the critical need to develop "existential literacy" as a psychological immune system against algorithmic manipulation. Ultimately, listeners will discover actionable strategies for protecting human agency, nurturing genuine face-to-face connections, and restructuring our institutions to ensure humanity thrives alongside intelligent machines. Sponsors: www.cisomarketplace.com www.myprivacy.blog
Operational Technology (OT) interacts directly with the physical world, meaning that cyber attacks can have immediate, devastating real-world safety and environmental consequence. Standard IT security models fall short in OT environments due to decades-old legacy systems, insecure protocols, and strict requirements for continuous availability. This episode explores how organizations can practically adapt modern Zero Trust principles to OT, covering critical strategies like network microsegmentation, compensating controls, and secure remote access without disrupting mission-critical operations. https://zerotrustciso.com Sponsor www.cisomarketplace.com www.cisomarketplace.services
Reviews
No reviews yet.
If you like this...
Discussion (0)
No comments yet. Be the first to start the discussion!
