Secure Talk Podcast
Justin Beals
0
Secure Talk Podcast covers the latest threats, tips, and trends in security, innovation, and compliance. Host Justin Beals interviews privacy, security, and technology executives about best practices for IT security, data protection, and compliance. Based in Seattle, the show features insights from industry leaders on protecting data and meeting regulatory requirements. Justin brings his background as a former CTO of NextStep and Koru to the discussions, adding a practical, entrepreneurial perspective.
Episode
-
AI Is Eating Our Young: Data Center Revolts, Vanishing Junior Jobs & the EU AI Act 11.08.2026 48mntCommunities are blocking $130 billion in AI data centers while the entry-level jobs that used to train the next generation of engineers quietly disappear.Chapters: 00:00: The Backlash: 800 Groups, 49 States, $130B BlockedGallup: 71% of Americans don't want a data center built near them (Gallup)Data center opposition tracker, Q1 2026 filings (referenced industry opposition data)CMMC as precedent for regulating critical infrastructure (DoW CMMC Phase 2 program)04:30: Why AI Is "Eating Our Young" in Education**Fran Berman & co-author's unpublished piece on the fraying mid-career pipelineBetter Tech (MIT Press) — Chapter appendix: AI classroom syllabus and exercises14:00: Tech as Critical Infrastructure, Not a ReligionBetter Tech prologue: treating tech like food, water, roads, and the power gridGDPR (EU, 2018) as a case study in regulation done right — and its limitsVermont's data broker law as a case study in weak enforcement26:00: Design Can't Be Bolted On Later**Self-driving cars and the hidden environmental cost of full autonomyAttack surface risk: denial-of-service on connected, self-driving fleets34:00: Governing the Hybrid Human-AI Society**EU AI Act — risk-tiered regulation: unacceptable, high-risk, low-risk categoriesU.S. Equal Employment Opportunity Commission guidance on algorithmic hiring41:00: The Hype Curve and the Data Center Reckoning**Western Massachusetts communities rejecting new AI data centersEfficiency vs. quality of life — Berman's closing argumentCommunities are saying no to AI's biggest infrastructure bet.In the first quarter of 2026 alone, local opposition blocked or delayed 75 data center projects worth roughly $130 billion — nearly matching all of 2025's total in a single quarter. Dr. Fran Berman, former head of the San Diego Supercomputer Center, argues the fix isn't more hype, it's precedent we already have. She points to CMMC itself: "If we can look at the defense supply chain and say this is critical infrastructure, it has to meet a bar, then we can look at the trillion dollars of compute being built into the middle of American life and say the same thing."AI isn't just displacing jobs. It's starving the pipeline that builds senior engineers. Berman's sharpest warning is about who trains the next generation of professionals when entry-level coding and writing jobs — the ones junior people used to cut their teeth on — get automated away. She compares it to a surgeon who's never had supervised time in the operating room: "Unless you have that experience and the mentorship of more senior professionals, it's really hard" to develop the judgment senior engineers rely on.Good regulation needs more than a law on the books. Drawing on her book Better Tech (MIT Press), Berman walks through why GDPR worked where Vermont's data broker law didn't — and previews how the EU AI Act's risk-tiered approach (unacceptable, high-risk, low-risk) could become the model for governing hybrid human-AI decision-making, where, as she puts it, "the only accountable entities are humans."✍️ About the AuthorDr. Fran Berman is an award winning-data scientist, pioneer in public interesttechnology, and community leader and builder. She directs the Public InterestTechnology Initiative at UMass Amherst and is a Faculty Associate at the BerkmanKlein Center for Internet and Society at Harvard. Berman is former head the SanDiego Supercomputer Center and served as Vice President for Research atRensselaer Polytechnic Institute. She currently serves as a Trustee of the AlfredP. Sloan Foundation and is a popular regular panelist on public radio’s WAMCRoundtable with 400,000 monthly listeners in seven states. For more information,see https://www.franberman.com.Link to the book: https://mitpress.mit.edu/978026205488... -
Okta's Identity Chief: Most CISOs Can't Answer This AI Question 28.07.2026 42mntWhich AI agents can access what? Are those permissions even right? And can you stop a compromised agent mid-action? Okta's Dan Cinnamon says most enterprises can't answer any of the three.Dan Cinnamon has built software, run SAP GRC without an implementation partner, and now architects identity for one of the industry's biggest players. In this conversation with Justin Beals, he lays out why "discoverability" — simply knowing what agents exist and what they're touching — is the single biggest blind spot in enterprise AI right now, and why there's no silver bullet coming to fix it. They also dig into passkeys as a rare win-win security standard, the maturing MCP spec, and where the hard line on agent containment should actually sit.**Timestamps:**0:00 Intro1:20 From writing code to securing identity4:45 Passkeys: the security/usability unicorn8:30 The SAP GRC re-implementation story14:10 Attribution and the agentic AI identity gap18:55 How fast MCP has matured—and what's next23:40 The 3 unanswered questions every enterprise faces27:15 Granular identity vs. inherited permissions32:00 Containment: moving controls closer to the data36:45 Consent, provenance, and healthcare AI40:30 Closing thoughts#CISO #AIstrategy, #enterprise #AIsecurity, #agentic #AIgovernance, #Okta #MCPstandard, #zerotrust #AI agents -
Special Episode: CMMC Phase 2 SUSPENDED: What DOD Just Did, What It Really Means, and Why Little Changed 17.07.2026 46mntThe Pentagon paused CMMC Phase 2 with zero warning — and half the defense industrial base is celebrating for the wrong reason.When the Department of War suspended CMMC Phase 2 rollout with no notice, panic spread fast across the defense contractor community — but the requirement to secure CUI never went away. In this special roundtable, host Justin Beals brings together three CMMC insiders — Logan Therrien (C3PAO Chief Strategy Officer, retired Navy submariner), Lance Arnold (30-year industry veteran, just completed his own CMMC Level 2 journey), and Brian Hubbard (President, Evolved Cyber Solutions, CMMC assessor since 2015) — to separate what actually changed from what didn't.They break down the difference between the assessment requirement (paused) and the security implementation requirement (still very much alive under NIST 800-171), why "self-assessment" doesn't mean "no requirement," and what small businesses and primes should do right now instead of waiting for clarity that may not come for months.Sources Referenced: DFARS 252.204-7021 (CMMC assessment clause)DFARS 252.204-7012 (NIST 800-171 compliance clause)DFARS 252.204-7019 (SPRS scoring requirement)32 CFR Part 170 (CMMC Program Rule)32 CFR Part 48NIST SP 800-171 / NIST SP 800-172 -
An AI Security Maturity Model for CISOs, with Chris Cochran (SANS) 14.07.2026 41mntHalf the room at Chris Cochran's leadership dinners still calls themselves AI skeptics. He argues they can't afford to be — because the adversary already isn't.Chapters: 00:00 — Intro02:49 — NSA/threat intel → AI security, storytelling09:55 — Why leaders feel stuck / no roadmap14:41 — Three pillars (Protect/Utilize/Govern)17:00 — Governance as the real foundation / shadow AI21:37 — Evidence-based scoring vs. pass/fail26:27 — EU AI Act28:44 — Fable/Mythos, Project Glasswing access controls33:18 — Token subsidies, self-hosted models37:52 — Data poisoning & context poisoning40:12 — Iron Man suit framing42:38 — Close: what's next -
Considering Security, Compliance and Revenue with David Grazer 16.06.2026 41mntMost companies chase certifications to win deals — but what actually keeps customers is something no audit can measure.In this episode, vCISO David Grazer makes the case that trust is a measurable economic asset hiding in plain sight: your customer retention rate. Drawing on 15+ years inside high-growth tech companies, David explains why compliance frameworks are customer acquisition tools, not retention strategies — and how the gap between the two is costing businesses more than they realize.This episode is for founders, security leaders, and C-suite executives who want to connect their security and privacy programs to real business outcomes.You'll learn:→ Why a SOC 2 or ISO 27001 certification is only the beginning of earning customer trust→ How customer churn functions as one of the most honest security metrics available→ Why MFA and common security controls often fail the users who need them most→ What "Trust by Design" looks like in product development and AI programs→ How to translate security risk into language that resonates with your CFOChapters00:00 Introduction to Secure Talk and Trust03:42 David Grazer's Journey into Security and Privacy08:09 Navigating Compliance and Customer Trust12:49 The Role of Consulting in Security18:07 Trust as a Measurable Economic Asset23:42 Identity Management in the Entertainment Industry26:09 The VC SO Model and Its Impact29:13 The Evolution of Compliance Conversations33:17 Exploring the Intersection of Technology and Society🔔 Subscribe to SecureTalk for weekly conversations at the intersection of cybersecurity, compliance, and business strategy.#cybersecurity #compliance #CISO #trustbydesign #vciso #informationsecurity #GRC #dataprivacy -
Why you could fail your CMMC Level 2 C3PAO audit | Secure Talk with Logan Therrien 02.06.2026 53mntYou did your self assessment and received a perfect 110 score, congratulations! You met with your C3PAO and scored less than 0. What happened!How can two CMMC assessors examine the same defense contractor and arrive at completely different scores? A lack of rigor in assessment methodology could mean the entire certification system is measuring the assessor — not your security. Logan Therrien, Chief Strategy Officer at Kieri Solutions and one of the original C3PAO lead assessors in the U.S., joins Justin Beals to expose a critical flaw in how CMMC Level 2 assessments are conducted today: no standardized evidence sampling methodology.This episode is for DoD contractors, compliance consultants, and defense industry executives who want to understand what's at stake — and how to navigate assessments before the rules tighten further.What you'll learn:Why NIST 800-171 was intentionally vague — and how that backfired for assessorsHow one assessor might review a single evidence point while another reviews 100%What ISO 17020 accreditation will require of C3PAOs and why it matters nowWhat the 48 CFR expansion means for 118,000+ contractors in the supply chainHow to prepare for an assessment so it feels like an open-book testLogan also co-authored the peer-reviewed paper "The Need for Standardized Evidence Sampling in CMMC Assessments: A Survey-Based Analysis of Assessor Practices" (with John Hastings) — one of the first data-driven studies of assessment methodology in the CMMC ecosystem.Chapters00:00 Introduction to Secure Talk and Psychometrics01:45 Understanding CMMC and Its Implications05:32 Logan Therian's Background and Insights09:16 The Challenges of Assessment Methodologies16:10 The Scale and Impact of CMMC Assessments20:31 Navigating Standards in Cybersecurity23:53 Evidence Testing in CMMC Assessments27:43 The Importance of Reliable and Accurate Assessments36:22 Building Trust Between Industry and Defense41:46 Future Directions in CMMC ResearchResources: Therrien, Logan and Hastings, John. (2026, February 10). The need for standardized evidence sampling in CMMC assessments: A survey-based analysis of assessor practices. arXiv. https://arxiv.org/abs/2602.09905 -
Mark Zuckerberg has an AI twin. Who Is Mark Zuckerberg? 19.05.2026 47mntMark Zuckerberg built an AI version of himself that attends meetings and approves budgets while he's elsewhere. That's not science fiction — it's happening now. But when an AI replica makes a consequential decision, who's legally responsible? Who owns it when you die?Dr. Candi Cann, Thanatologist and professor at Baylor University, joins SecureTalk host Justin Beals to explore the uncomfortable intersection of technology, mortality, and identity — and what it means for data governance, digital rights, and the future of enterprise accountability.In this episode:Key topics: digital identity, AI accountability, data governance, CMMC compliance, death technology, digital ethics, AI agents, enterprise securityIf your organization is deploying AI agents that act on behalf of humans — approving transactions, attending meetings, representing employees — this episode raises the governance questions your security and legal teams need to be asking right now.Subscribe to SecureTalk for weekly conversations at the edge of cybersecurity, compliance, and technology culture.Resources: Book: Augmented: Life and Death as a Cyborg by Candy Cann, MIT Press, 2026. Link: https://mitpress.mit.edu/9780262051118/augmented/ -
CMMC Is an HR Problem, Not an Enclave Problem — Here's the Proof 05.05.2026 51mntThe biggest cybersecurity failures in recent memory — Raytheon, Penn State, Georgia Tech — weren't caused by missing software. They were caused by the wrong people being assigned the wrong tasks, with no shared language to connect the rules to the work.This SecureTalk episode with Dorian Cougias (MoxyWolf, former Unified Compliance Framework CEO) is one of the most systems-level conversations we've had on the show. Dorian spent decades building the infrastructure that compliance programs run on — and he's now rebuilding it from scratch, in the open.What you'll hear:→ Why the compliance industry is structurally fragmented across three authority domains that don't communicate→ How Bloom's Taxonomy — a tool from education — maps directly to which compliance tasks belong to which roles→ Why the Oxford English Dictionary doesn't have "personal data" in it, and what that tells us about regulatory language→ The O*NET framework and why the Department of Labor might be the most underused tool in cybersecurity→ Shannon's entropy theory, applied to compliance and cognitive load→ A new open-source STIG API infrastructure that StrikeGraph is integrating as a launch partnerWhether you're deep in the compliance trenches or just fascinated by how complex systems fail — and how to redesign them — this is worth your time.🔗 strikegraph.com | stigviewer.comChapters:00:00 Introduction and Background02:43 Exploring Compliance and Natural Language Processing05:15 Military Experience and Signal Intelligence08:01 Cognitive Load and Compliance Frameworks10:49 The Importance of Language in Compliance13:39 The Evolution of Dictionaries and Lexicons16:16 Bridging Gaps in Compliance Communication18:47 Innovations at MoxieWolf and Future Directions22:04 Mapping Skills and Regulatory Guidelines25:05 Job Applicability and Knowledge Requirements28:02 The Importance of O*NET in Cybersecurity29:21 Challenges in CMMC Compliance33:23 The Role of Technology in Compliance35:38 Horizontal Practices in Compliance38:15 Building Effective Teams for Compliance42:21 Introduction to Compliance Failures45:19 The Human Element in Compliance48:10 Navigating Compliance Complexity with Technology48:57 Introduction to Cybersecurity Compliance Challenges54:09 The Role of People in Compliance Success56:01 Guest Introduction: Dorian Cougas01:00:48 Exploring Bloom's Taxonomy in Compliance01:05:48 The Importance of Shared Lexicons01:09:32 Navigating Compliance with Technology01:15:11 MoxieWolf's Approach to Compliance01:20:49 The Interconnectedness of Compliance Tasks01:27:51 Real-World Compliance Challenges01:33:57 Building Effective Teams for Compliance#Cybersecurity #ComplianceCulture #CMMC #HumanFactors #GRC #TechPolicy #SecureTalk -
The ROI of Security Tested: What a new paper reveals about security value | Secure Talk with Minh Nguyen and Thi Tran 21.04.2026 47mntWhy do most cybersecurity investments feel impossible to justify? Because the measurement tools are broken — built on gut instinct, not research.Researchers Minh Nguyen (Florida Atlantic University) and Thi Tran (Binghamton University) set out to fix that. In this episode, they break down their landmark paper "Effects of Cybersecurity Readiness on Firm Performance: Evidence from Conference Calls" — the first study to systematically measure cybersecurity readiness at the firm level and link it directly to financial performance.What they found will change how you think about security budgets:→ Outsider mentions of cybersecurity in earnings calls are 100x more predictive of firm performance than insider mentions→ Even a single co-occurrence of security-related language drives measurable returns on assets the following year→ Companies that act proactively - not reactively - earn greater market trustThis is the episode for CISOs who need real data to justify investment, security leaders tired of folklore-based decision-making, and anyone curious about how AI, NLP, and causal inference are reshaping the business case for cybersecurity.Chapters00:00 Introduction to the Guests and Their Backgrounds02:34 The Intersection of AI, Business, and Cybersecurity05:32 Understanding Cybersecurity Readiness08:31 The Importance of Measurement in Cybersecurity11:16 Developing a Cybersecurity Dictionary14:16 The Impact of Outsider Perspectives on Firm Performance16:51 The Role of Transparency in Cybersecurity19:40 Future Research Directions in Cybersecurity22:37 Conclusion and Final Thoughts🔗 Paper: "Effects of Cybersecurity Readiness on Firm Performance: Evidence from Conference Calls" https://scholarspace.manoa.hawaii.edu/server/api/core/bitstreams/b098c310-db83-42cc-8932-852ef7ebcc86/content#Cybersecurity #CyberROI #CISO #FirmPerformance #CybersecurityResearch #NLP #CausalInference #InfoSec #SecurityLeadership #ConferenceCall`` -
They Sold AI to Play God. China Never Got That Memo. 07.04.2026 53mntThe West has been building AI like it's the apocalypse. China has been building it like it's a tool.That one difference — rooted in centuries of philosophy, theology, and cultural storytelling — may be the most important thing nobody is talking about in the AI debate right now.SecureTalk host Justin Beals sits down with scholars Bogna Konior (NYU Shanghai), Mi You (University of Kassel), and Vincent Garton to explore their co-edited book "Machine Decision Is Not Final: China and the History and Future of Artificial Intelligence" — and what it reveals about the hidden assumptions driving the decisions we make about AI governance, security, and society.What this conversation unpacks:→ Why Western AI fear traces back to Christian theology — not rational risk analysis→ How the Chinese term for AI literally means "human-made wisdom ability" — no alien mind implied→ The 2019 Elon Musk vs. Jack Ma exchange that exposed the cultural divide in real time→ What DeepSeek's open-source breakthrough says about innovation, restriction, and creative problem-solving→ Why this debate matters far beyond the US and China — and who else is watching closelyIf you work in cybersecurity, tech leadership, or AI policy, the cultural lens on this technology isn't a soft question. It shapes real architectural, governance, and regulatory decisions.Chapters00:00 Introduction and Perspectives on AI in China02:41 The Meaning Behind the Claw Machine Image05:33 The Book's Creation and Collaborative Efforts08:32 Cultural Perspectives on AI: East vs. West11:06 The Impact of Open Source AI Models13:45 Innovation in a Controlled Environment16:20 Human-Made vs. Artificial Intelligence19:23 The Philosophical Underpinnings of AI22:06 The Role of Human Agency in AI Decisions24:54 Exploring the Future of AI and Society27:26 The Synthesis of Technology and Society30:22 Conclusion and Final Thoughts44:17 Understanding Artificial Intelligence: A Cultural Perspective47:08 Machine Decision: The Chinese Perspective on AI49:59 Innovation and Openness in AI Development50:27 Global Implications of AI Beyond Superpowers50:37 Introduction and Context of AI Governance01:00:53 The Role of Computers in Decision Making01:08:26 Transparency in AI and Governance01:17:58 Cultural Perspectives on AI: East vs. West01:23:46 The Singularity and Its Philosophical Implications01:27:15 Simulation and Reality in AI Discourse01:35:14 Social Implications of Large Language Models🎙️ SecureTalk is hosted by Justin Beals, CEO of Strike Graph.🔔 Subscribe for weekly conversations at the intersection of cybersecurity, technology, and leadership.#ArtificialIntelligence #AIPolicy #ChinaAI #DeepSeek #Cybersecurity #AIGovernance #TechLeadership #OpenSourceAI``` -
The DOGE data breach at the Social Security Administration with Whistleblower Chuck Borges 24.03.2026 48mntEvery American has a Social Security number. Most assume it's protected. Chuck Borges was the person responsible for that protection at the SSA — and what he discovered from the inside is something every American deserves to know.Chuck is a combat veteran, MIT graduate, and the Social Security Administration's first dedicated Chief Data Officer. He arrived two weeks before the 2025 administration change, watched data governance requests get denied and sensitive work get siloed away from the officials responsible for protecting it, and when the risk became too great to ignore, he spoke up. It cost him his job.In this episode of SecureTalk, Chuck and host Justin Beals cover:- Why NUMIDENT data breach goes far beyond a typical data breach- How shadow IT and unchecked access created a governance nightmare inside the SSA- The national security implications of 550 million identity records at risk- What it actually takes to blow the whistle when the stakes are this highThis is one of the most important cybersecurity conversations of 2025, not because of the technology involved, but because of what it reveals about the systems we trust to protect us.Chapters00:00 From Dreams to Data: A Unique Journey02:47 Navigating the Data Landscape: Challenges and Innovations05:41 The Role of Governance in Data Management08:20 Civil Service and the Mission Mindset11:16 Chaos and Change: The Impact of Administration Shifts13:52 Empathy in Leadership: The Human Element16:51 Life Experience and Effective Governance21:16 Siloing and Data Manipulation in Government23:30 The Risks of Shadow IT and Data Security27:39 The Dangers of Numident Data30:08 The Nightmare of Data Exfiltration31:52 The Courage to Blow the Whistle36:19 Transitioning to Political Service38:24 Challenges of Running for Office41:36 Building Community Through Problem Solving43:05 Introduction to Data Sensitivity and Governance44:33 The Risks of Data Exposure45:55 Chuck Borges: A Profile in Data Leadership46:46 Introduction to SecureTalk and Data Security47:37 The Role of the Social Security Administration48:35 Chuck Borges: A Journey Through Data Governance50:28 The Impact of Administration Changes on Governance56:14 Challenges in Data Management and Governance01:00:58 The Risks of Data Exposure and Mismanagement01:05:37 Whistleblowing and Ethical Responsibilities01:14:56 Running for Office: A New Chapter in Public ServiceResources: Chuck Borges Website - https://chuck4md.comTwitter - https://twitter.com/Chuck4MD🔔 Subscribe to SecureTalk for weekly conversations on cybersecurity, leadership, and the technology shaping our world.#SocialSecurity #DataGovernance #Cybersecurity #DataBreach #NationalSecurity #Whistleblower #FederalCybersecurity #IdentityTheft #SecureTalk #CDO -
From 9/11 to Salt Typhoon: Why Backdoors Always Betray Us | Secure Talk with John Ackerly 10.03.2026 40mntOn the morning of September 11th, 2001, John Ackerly was briefing White House officials on federal privacy legislation. Hours later, everything changed — and those two realities, data that wasn't shared when it should have been, and data that was exposed when it shouldn't have been, became the founding idea behind Virtru.In this episode of SecureTalk, host Justin Beals sits down with John Ackerly, CEO and co-founder of Virtru and former White House technology policy adviser, to explore why perimeter security alone is broken — and what data-centric, cryptographic control means for the future of cybersecurity.They cover:00:00 Introduction to SecureTalk and Data Security02:28 John Ackerly's Experience and Insights on Privacy Legislation05:05 The Dichotomy of Privacy and Security09:12 Public-Private Partnerships in National Security12:24 Navigating Compliance and Security in Business15:26 The Role of Technology in Security Solutions18:40 Family Ties and Military Background in Cybersecurity20:41 Insider Threats and Data Security Innovations23:29 The Importance of Data Management and Audits26:12 Cultural Impact on Security Practices29:19 Future Challenges: Quantum Computing and Security32:52 The Evolution of AI and Data Science in SecurityWhether you work in cybersecurity, government, or technology policy, this conversation connects the policy decisions of the past 25 years to the architectural challenges we face today.🔒 Learn more about Virtru: https://www.virtru.com 🎙️ Subscribe to SecureTalk for weekly conversations at the intersection of technology, security, and society. -
A Con Artist Expert Explains Why Smart People Still Get Scammed | Secure Talk with Robert Siciliano 24.02.2026 46mntYou consider yourself pretty tech-savvy. You know not to click suspicious links. You've heard the warnings. So why are more people losing more money to online scams than ever before?Robert Siciliano has spent 30 years as a private investigator, appearing on CNN, The Today Show, and Fox News to explain exactly how con artists and cybercriminals think — and why your brain is actually working against you.In this eye-opening conversation with SecureTalk host Justin Beals, Robert reveals:- The psychological reason almost everyone falls for scams eventually- How criminals use loneliness to build fake relationships and drain bank accounts- Why your parents are the #1 target for the $124 trillion wealth transfer underway- What a deepfake video call cost one company $25 million — in a single afternoon- The one habit that would protect 80% of people — and almost nobody does itThis isn't a tech talk. It's a human talk. And it might be the most important conversation you have about your money, your family, and your identity this year.Chapters00:00 Introduction to Cybersecurity Challenges02:44 The Human Blind Spot in Cybersecurity05:30 Engaging Employees in Security Practices08:44 Understanding Cybercrime Trends11:30 The Psychological Aspects of Trust and Security14:03 Personalizing Security Awareness Training17:01 The Role of AI in Cybersecurity Threats23:46 The Dark Reality of Human Trafficking and Cyber Crime25:55 The Evolution of Cyber Crime Tactics27:37 Understanding Human Behavior in Cybersecurity29:54 The Impact of Loneliness on Cyber Vulnerability31:58 The Kitchen Table Effect in Security Training34:20 The Importance of Human Connection in Security Awareness37:40 Empathy and Responsibility in Cybersecurity39:47 Personal Stories Shaping a Security Perspective🔔 Subscribe to SecureTalk — new episodes every week.#ScamAlert #OnlineScams #IdentityTheft #CyberSafety #DeepFake #FinancialSecurity #PersonalFinance #TechForEveryone #StayProtected #CyberAware -
When Federal Agents Ignore Court Orders: What Happens to Democracy? | Secure Talk with Claire Finkelstein 10.02.2026 44mntWhat happens when federal law enforcement refuses to follow court orders? In Minneapolis, ICE agents denied state investigators access to crime scenes despite court-issued warrants—a breakdown that national security experts had been warning about for months.Dr. Claire Finkelstein, Professor of Law at University of Pennsylvania and Director of the Center for Ethics and the Rule of Law, saw this coming. In October 2024, she ran a tabletop exercise with over 30 retired military leaders simulating exactly this scenario: federal forces confronting state National Guard during civil unrest. The simulation escalated to violence faster than anyone expected, with few off-ramps once momentum built.Now that simulation is playing out in real time.Dr. Finkelstein has been on the legal front lines, representing 155 members of Congress before the Supreme Court. When the Court ruled the administration couldn't use National Guard troops as they intended, ICE agents surged instead—creating the confrontation we're seeing today.The questions are urgent: Can states prosecute federal agents who commit crimes in their jurisdiction? What happens when federal authorities claim immunity? How do soldiers follow orders when they can't trust those orders are lawful? The Supreme Court's immunity decision has made these questions harder to answer.This conversation explores what happens when rule of law meets political will, and what remains when the institutions designed to protect democracy face their greatest test.#CyberSecurity #NationalSecurity #Democracy #RuleOfLaw #Minnesota #MinneapolisResources: Finkelstein, Claire. (2026, January 21). We ran high-level US civil war simulations. Minessota is exactly how they start. The Guardian. https://www.theguardian.com/commentisfree/2026/jan/21/ice-minnesota-trump -
Shared Wisdom: Why AI Should Enhance Human Judgment, Not Replace It | Secure Talk with Alex Pentland 27.01.2026 55mntMost AI discourse swings between paradise and doom—but the real question is how we architect these systems to enhance human understanding rather than replace decision-making. MIT Professor Alex "Sandy" Pentland reveals why treating AI as an information tool instead of an authority is critical for cybersecurity teams, business leaders, and anyone navigating the intersection of technology and culture.The math is stark: 90% of social media users are represented by only 3% of tweets. We're making decisions based on algorithmic extremes, not community wisdom. Pentland shows how Taiwan used the Polis platform to restore government trust from 7% to 70% by eliminating follower counts and visualizing the full spectrum of opinion—proving most people agree more than they think.For security professionals, the implications are profound: culture drives security outcomes more than controls. The stories your team shares about breaches, vulnerabilities, and response protocols create the shared wisdom that determines whether you're actually secure. AI can help synthesize context and surface patterns across distributed organizations, but cannot replace the human judgment needed when edge cases and outliers occur.Drawing parallels to the Enlightenment—when letter-writing networks sparked unprecedented collaboration among scholars—Pentland argues we stand at a similar inflection point. We have tools that let us share information at unprecedented scale, yet our digital systems amplify loud voices and create echo chambers instead of fostering collective wisdom. His book "Shared Wisdom" offers a pragmatic framework for cultural evolution in the age of AI, recognizing we'll take steps forward, make mistakes, and need to choose our direction deliberately.Key insights include understanding AI as a statistical repackaging of human stories, recognizing how four waves of AI development have each failed in predictable ways, and learning why loyal agents—systems legally bound to serve your interests like doctors and lawyers—represent the future of trustworthy AI. Pentland also explains why audit trails and liability matter more than premature regulation, and how communities need local governance that's interoperable but not uniform.Alex "Sandy" Pentland is Stanford HAI Fellow, MIT Toshiba Professor, and member of the US National Academy of Engineering. Named one of "100 People to Watch This Century" by Newsweek and one of "seven most powerful data scientists in the world" by Forbes, his work established authentication standards for digital networks and contributed to pioneering EU privacy law.Episode Resources: Pentland, Alex. (2025). Shared Wisdom: Cultural Evolution in the Age of AI. The MIT Press. https://mitpress.mit.edu/9780262050999/shared-wisdom/ -
The 2026 Planning Episode: 5 key security imperatives. 13.01.2026 46mntWhile most organizations treat security as a cost center, a select group is using it to win enterprise deals, open new markets, and outpace competitors. The difference? They've stopped asking "how much does security cost?" and started asking "how much value does security create?"This strategic edition synthesizes lessons from security leaders at Walmart, PayPal, Postman, and the defense industrial base to reveal the playbook for 2026: treating security as a business function that enables velocity, builds trust, and creates competitive moats.Five Strategic Imperatives for 2026:1. Architect for the AI Identity Explosion When AI agents access your CRM, email, and databases on behalf of humans, who's accountable? Walmart's 10,000+ developers faced this at scale. Learn how to govern probabilistic, non-deterministic systems before deployment breaks.2. Turn Supply Chain Security Into Competitive AdvantageCMMC enforcement is here—Raytheon paid $8.4M, Penn State $1.25M. But smart contractors are leading with certification to win contracts. See how quantitative security standards are reshaping business relationships between primes and subs.3. Extract Intelligence From Your Own Logs One organization prevented $3M in fraud using internal threat intelligence. Learn why focused AI models that analyze your specific environment outperform generic vendor feeds.4. Make Security Your Primary Differentiator When SOC 2 Type II certification wins you three enterprise customers worth $2M ARR, security spending looks very different to the CFO. Discover how to position security as the reason customers choose you.5. Build Culture, Not Tool Stacks The oil & gas industry made safety everyone's responsibility through culture, not technology. Apply the same principles to solve cybersecurity's 65% turnover crisis.Expert Insights From:Rishi Bhargava (Descope) | Tobias Yergin (Walmart) | Bob Kolasky (Exiger) | Chris Wysopal (Veracode) | Bill Anderson (Mattermost) | Satyam Patel (Kandji) | Sam Chehab (Postman) | Brian Wagner | Dimitry Shvartsman (PayPal)The Meta-Pattern: Organizations winning in 2026 measure security in business terms—revenue enabled, customers won, time to market reduced. They're not the "department of no" blocking progress—they're the team enabling fast, safe movement.🎙️ SecureTalk: Strategic conversations with security leaders, hosted by Justin Beals🔔 Subscribe for insights on AI security, CMMC, threat intelligence & security ROI -
Secure Talk Special Episode: "Building Secure Societies in the Age of Division: The Seven Lessons for Humanity Heading Into 2026" 30.12.2025 31mnt"In 20 years, we transformed food allergy awareness from nonexistent to universal—no law required. What if we could do the same for data security and AI governance?"This special episode reveals how grassroots cultural shifts create lasting change, and why 2026 might be the year cybersecurity professionals become architects of something bigger than defenses.We've distilled 2025's conversations with experts from Harvard, MIT, NYU, Brown, and the AI development frontlines into seven actionable lessons that reframe security from technical problem to human opportunity. From understanding the 800 billion AI agents already in our systems, to recognizing why your most valuable threat intelligence is already in your logs, to building the communities that make external defenses less necessary.Here's what successful security leaders are realizing: The organizations thriving in 2026 aren't just protecting systems—they're creating conditions where humans and AI can flourish together.THE SEVEN LESSONS: • Social division is our greatest vulnerability (and connection is our strength) • Technology won't save us from ourselves (but we can) • Real change happens through grassroots cultural shifts • AI demands fundamentally different thinking (here's how) • Our values can blind us (when to trust them, when not to) • The weakest links are often invisible (where to look) • Context matters more than technology (your advantage is closer than you think)FEATURING INSIGHTS FROM: Dr. Claire Robertson (NYU) | Greg Epstein (Harvard/MIT) | Dr. De Kai | Rishi Bhargava (Descope) | Tobias Yergin (Walmart AI) | Prof. Steven Sloman (Brown) | Lars Kruse | Brian Wagner | Dr. Aram Sinnreich | Jesse GilbertPERFECT FOR: Security leaders building resilient organizations | Professionals navigating AI transformation | Anyone ready to move beyond purely technical solutions🔗 StrikeGraph: https://strikegraph.comWhich lesson will change how you approach security in 2026? #Cybersecurity #AIGovernance #SecurityLeadership #CyberResilience #AIEthics #CISO #ThreatIntelligence #FutureOfWork -
Building a Thriving Future: AI Ethics & Security in Virtual Worlds | Dr. Paola Cecchi - Dimeglio 16.12.2025 56mntThe mistakes we made building the internet don't have to be repeated in the metaverse—if we act now.Join SecureTalk host Justin Beals for an essential conversation with Dr. Paola Cecchi-Dimeglio about building secure, ethical virtual worlds. Dr. Cecchi-Dimeglio brings 25 years of experience advising governments, Fortune 500 companies, and global institutions on AI ethics and technology governance.Her new book "Building a Thriving Future: Metaverse and Multiverse" (MIT Press, 2025) provides frameworks for building virtual spaces that serve humanity rather than exploit it.CORE THEMES: • Security by design vs. security bolted on after problems emerge • How biases get encoded into AI systems—and prevention strategies • The critical role of "human in the loop" for AI oversight • Why good regulation creates business stability • Digital identity systems for global inclusion • Authentication and verification in virtual spaces • Cross-border legal frameworks for technology governanceREAL-WORLD IMPACT: Over 1 billion people globally lack legal identification—virtual worlds could solve this through blockchain-based digital identity, or create new exclusions if built poorly. The standards we set now for authentication, verification, and identity control will determine whether these spaces become tools for human flourishing or mechanisms for surveillance.WHY THIS MATTERS NOW:Virtual worlds already exist—gaming platforms host billions of usersAI is accelerating everything, including security vulnerabilitiesDeepfake technology is improving faster than detection methodsThe decisions made today will shape digital society for decadesSURPRISING INSIGHTS: → Children currently detect deepfakes better than adults (but not for long) → Major consulting firms have sold governments expensive reports full of AI errors → Voice recognition systems historically failed on non-Western accents due to training data bias→ Email autocorrect defaults "Paola" to "Paolo" because datasets contained more men than womenABOUT THE GUEST: Dr. Paola Cecchi-Dimeglio is a globally recognized expert in AI, big data, and behavioral science. She holds dual appointments at Harvard Law School and Kennedy School of Government, co-chairs the UN ITU Global Initiative on AI and Virtual Worlds, and has authored 70+ peer-reviewed publications. Her work advises the World Bank, European Commission, and Fortune 500 executives on ethical AI implementation.THE OPTIMISTIC VISION: Virtual worlds can tap talent anywhere, breaking geographic barriers. They can connect separated families, provide legal identity to excluded populations, and create opportunities we can't yet imagine—but only if we build them with security, ethics, and human values as foundational requirements.ABOUT SECURETALK: SecureTalk ranks in the top 2.5% of podcasts globally, making cybersecurity and compliance topics accessible to business leaders. Hosted by Justin Beals, CEO of Strike Graph and former network security engineer.Perfect for: Security professionals, technology leaders, business executives, policy makers, anyone concerned about building ethical AI systems and secure virtual worlds.📚 "Building a Thriving Future: Metaverse and Multiverse" by Dr. Paola Cecchi-Dimeglio (MIT Press, 2025)#AIEthics #Cybersecurity #VirtualWorlds #TechnologyGovernance #MetaverseSecurity #DigitalEthics #AIRegulation #SecureByDesign -
Why Security Leaders Struggle With Security Culture | Steven Sloman on Secure Talk 02.12.2025 55mntBrown University cognitive scientist Steven Sloman reveals the hidden mechanism driving cultural division—and why it matters for security leadership. In this wide-ranging conversation, Sloman explains the fundamental tension between sacred values and consequentialist thinking, and how understanding this dynamic transforms how leaders communicate risk and build organizational culture.Justin Beals opens with a personal story about leaving a religious environment defined by absolute values, setting the stage for an exploration of how cognitive science explains why extremists control discourse, why outrage dominates social media, and why having strong values might actually be essential for good decision-making.KEY TOPICS: • The two systems humans use for decision-making and why both matter • Why simplified positions dominate complex policy debates • How humor breaks through absolutist thinking • The critical difference between AI association and human deliberation • Why communities radicalize when they become too insular • Practical frameworks for leadership teams navigating value conflictsSloman, author of "The Cost of Conviction: How Our Deepest Values Lead Us Astray," shares insights from decades of research on cognition, reasoning, and collective thinking. The conversation moves from abstract cognitive science to immediate applications for security professionals operating in organizations where tribal loyalties threaten evidence-based decision-making.Whether you're presenting risk assessments to boards, building security culture, or helping organizations function during divisive times, this episode offers frameworks for understanding when values serve us and when consequentialist analysis becomes essential.Resources: Sloman, S. (2025). The cost of conviction: How our deepest values lead us astray. MIT Press. (https://mitpress.mit.edu/9780262049825/the-cost-of-conviction/) -
From Punk Rock Anarchist to Bank Security Leader: An Unlikely Journey in Threat Intelligence | SecureTalk with Joe Rossi 18.11.2025 51mntMost threat intelligence programs can't prove their value. Joe Rossi's team at Zions Bank did the opposite—preventing $3 million in fraud annually while actually attracting new customers to the bank.In this episode, former punk rock kid turned threat intelligence leader Joe Rossi reveals why your most valuable security intelligence isn't from expensive vendor feeds—it's sitting in your own logs right now. He shares the hard lessons learned building CTI programs from scratch, why most organizations focus on the wrong threats, and how to make security a competitive advantage instead of just a cost center.Key insights:• Why your firewall logs are more valuable than threat intelligence feeds• The cultural mindset required before you invest in CTI• How to quantify security program ROI in terms leadership actually cares about• Dark web monitoring: reality vs. Hollywood expectations• When your organization is actually ready for threat intelligenceWhether you're a CISO considering a CTI program or a security professional trying to prove value, this conversation offers practical frameworks for building security capabilities that directly impact the bottom line.
Populer di
Podcast ini juga muncul di daftar podcast negara-negara ini.