The InfoSec Control Room

The InfoSec Control Room

Taher Amine ELHOUARI
Maa Yhdysvallat
Kieli EN-US
Jaksot 24
Viimeisin 12.09.2026

The InfoSec Control Room is a cybersecurity podcast hosted by Taher Amine ELHOUARI, focusing on governance, risk, compliance, resilience, and CISO-level decision-making. It explores the gap between what organizations believe they have in place and what actually works during incidents, audits, regulatory questions, and risk-based decisions. Topics include information security, GRC, CISO leadership, ISO standards, cyber resilience, privacy, incident response, CSIRT operations, security awareness, and regulatory expectations. The core premise is that most organizations have a governance problem that manifests as security. The show targets CISOs, security leaders, GRC professionals, auditors, consultants, and practitioners.

Jaksot

  • EP013: You Outsourced the Service, Not the Risk 12.09.2026 17min
    Taher Amine ELHOUARI explores why outsourcing a service does not outsource the associated risk, covering supplier dependency, shared responsibility, third-party access, contracts, incident handling, concentration risk, offboarding, and the internal capability needed to govern providers effectively.
  • EP012: Cyber Resilience — What Happens After Prevention Fails 07.09.2026 17min
    Taher Amine ELHOUARI explores cyber resilience beyond prevention, examining how organizations can keep critical services functioning, manage dependencies, recover effectively, adapt during disruption, and improve after failures and incidents.
  • EP011: ISO 27001 Is Not the Certificate on the Wall 05.09.2026 15min
    Taher Amine ELHOUARI explores why ISO/IEC 27001 certification should be the result of a functioning ISMS rather than the end goal, and examines risk ownership, internal audit, corrective action, management review, control implementation, and continuous improvement beyond audit day.
  • EP010: The Board Does Not Need Another Cyber Dashboard 04.09.2026 17min
    Taher Amine ELHOUARI explores why cybersecurity dashboards often overwhelm boards with activity instead of helping them make decisions, and explains how executive reporting should connect cyber risk, uncertainty, business impact, priorities, and required leadership action.
  • EP009: Your CSIRT Is Not Ready Just Because It Exists 03.09.2026 25min
    In EP009 of The InfoSec Control Room, I look beyond the simple statement, “We have a CSIRT,” and ask the question that actually matters: what can that team really do when something serious happens?A CSIRT can exist on the organization chart, have assigned staff, procedures, tooling, and even a dedicated mailbox, while still being poorly prepared for a real incident. Readiness comes from much more practical things: knowing exactly what the team is responsible for, who it serves, how people reach it, what happens outside business hours, what access responders already have, how cases are handed over, how other departments work with the team, and where outside help is needed.This episode looks at the difference between a CSIRT that exists and one that can actually function under pressure. I discuss service boundaries, availability, access to systems and logs, case management, practical exercises, relationships with legal and business teams, communication during uncertain situations, team skills, external support, incident closure, lessons learned, and the danger of depending too heavily on a few individuals who hold everything together.I also explore why a CSIRT should not simply process incidents and move on. A strong response team notices patterns, exposes recurring weaknesses, feeds lessons back into the organization, and helps improve the environment that keeps producing those incidents.One of the main ideas from EP009 is simple: a CSIRT is not ready because management created one. It is ready when people know how to use it, when the team knows what it owns, when it can reach the right systems and people, and when it can work effectively under pressure.If you work in CSIRT, SOC, DFIR, SecOps, cybersecurity leadership, IT operations, GRC, risk, audit, business continuity, or incident management, this episode is designed to challenge the difference between having a team and having a real response capability.
  • EP008: Stop Lying to Yourself About Cyber Maturity 22.08.2026 26min
    Taher Amine ELHOUARI examines why cybersecurity maturity scores can create false confidence and explains how organizations should measure real capability through evidence, operating effectiveness, risk context, testing, metrics, and independent challenge.
  • EP007: Incident Response Starts Before the Incident 16.08.2026 28min
    Taher Amine ELHOUARI explains why incident response begins long before the first alert fires, exploring authority, escalation, communications, SOC and CSIRT coordination, backups, business continuity, executive decision-making, exercises, and the organizational preparation required for real cyber resilience.
  • EP006: Your Policy Is Not a Control 15.08.2026 24min
    Taher Amine ELHOUARI explores why having an approved security policy does not automatically mean an organization has control, and how policies must be translated into real behavior, ownership, technical enforcement, evidence, monitoring, and accountability.
  • EP005: GRC and SecOps Are Speaking Different Languages 14.08.2026 25min
    Taher Amine ELHOUARI explores why GRC and SecOps must stop operating as separate worlds, and how connecting governance context with SOC and CSIRT operational evidence can improve control effectiveness, risk management, audit assurance, incident response, and executive decision-making.
  • EP004: The CISO Is Not a Superhero 13.08.2026 24min
    Cybersecurity cannot be owned by one job title. Taher Amine ELHOUARI explores what a CISO should actually be responsible for, why business and risk ownership must remain distributed across the organization, and how the CISO can act as a governance architect connecting security, operations, management, and executive decision-making.
  • EP003: Compliance Is Not Control 12.08.2026 33min
    Compliance is not the same as control. Taher Amine ELHOUARI explores why passing audits, maintaining policies, and achieving certification do not automatically prove security effectiveness; and how organizations can move from checkbox compliance to real control, evidence, assurance, and resilience.
  • EP002: The Real Reason Security Programs Fail 12.08.2026 30min
    Taher Amine ELHOUARI explains why many security programs fail for reasons that are not purely technical, exploring governance gaps, weak ownership, poor risk decisions, ineffective controls, compliance theater, and the difference between security activity and real security capability.
  • EP001: Welcome to The InfoSec Control Room 10.08.2026 31min
    The official opening episode of The InfoSec Control Room, where Taher Amine ELHOUARI introduces the podcast, his background, the governance-first philosophy behind the show, and the mission of helping professionals understand how cybersecurity is governed, controlled, measured, and improved.
  • Media Archive: Building Cyber Resilience Beyond Compliance | Full Webinar | Taher Amine ELHOUARI - iExperts 30.07.2026 1t 6min
    Compliance may demonstrate that cybersecurity controls exist, but resilience demonstrates that they work under pressure. In this complete iExperts webinar, Taher Amine ELHOUARI explains how organizations can connect governance, GRC, risk management, SOC and CSIRT operations, incident response, business continuity, recovery, and executive accountability within one practical cyber-resilience model.
  • Media Archive: Conformity Assessment Meets Cybersecurity | FIRST & AfricaCERT Symposium 2025 23.06.2026 27min
    A Media Archive episode featuring Taher Amine ELHOUARI’s FIRST & AfricaCERT Symposium 2025 session in Mauritius, covering conformity assessment, cybersecurity assurance, audit evidence, SOC and CSIRT alignment, ISO standards, incident metrics, control effectiveness, and continuous cyber assurance.
  • Media Archive: The Hidden Face of Cyber Extortion on Algerian National TV 23.06.2026 9min
    A Media Archive episode featuring Taher Amine ELHOUARI’s Algerian National TV intervention on cyber extortion and online blackmail, covering privacy risks, social engineering, digital safety, public awareness, family education, and collective cyber defense.
  • Media Archive: From Chaos to Control — Building and Maturing CERT/CSIRT Teams 23.06.2026 1t 3min
    A Media Archive episode featuring Taher Amine ELHOUARI’s masterclass “From Chaos to Control,” covering CERT/CSIRT fundamentals, cyber response team design, incident response maturity, operational readiness, field tactics, governance, and cyber resilience.
  • Media Archive: Cybersecurity Challenges, Certifications, and Career Lessons 23.06.2026 51min
    A Media Archive episode featuring Taher Amine ELHOUARI’s guest interview on Lweirday Experience, covering cybersecurity fundamentals, career growth, certifications, ethical hacking, development security, red/blue/purple teams, ICS and SCADA security, standards, and cybersecurity challenges.
  • Media Archive: Information Security — A Leading Experience 23.06.2026 2t 13min
    A Media Archive episode featuring Taher Amine ELHOUARI’s long-form interview with Adel BOUROUIS for Algerian Tech Makers, covering information security career growth, certifications, lessons learned, field experience, ethical hacking, community building, leadership, and advice for aspiring cybersecurity professionals.
  • Media Archive: Cybersecurity & Data Protection Panel at CTO Forum 2025 23.06.2026 12min
    A Media Archive episode featuring Taher Amine ELHOUARI’s intervention during the Cybersecurity & Data Protection Panel at CTO Forum 2025 in Algiers, covering cybersecurity strategy, cloud security, data protection, governance, risk management, regulatory alignment, secure development, and cyber resilience.

Suosittu maassa

Tämä podcast esiintyy myös näiden maiden podcast-listoilla.