ISACA Podcast
ISACA Podcast
0
The ISACA Podcast offers insights into the latest regulations, trends, and threats facing information systems auditors and governance and security professionals. Experts share valuable perspectives from their years of experience in the field. Whether you are starting your career or have decades of experience, this podcast helps you address industry challenges and embrace opportunities.
Epizode
-
Your Containers Are Probably Full of Holes: Fixing Docker Security with AI 21.07.2026 28minContainers run much of the software we depend on, and many are shipped with security problems that no one noticed. Traditional container scanning tools can miss important vulnerabilities, insecure configurations, embedded secrets, and risky Dockerfile patterns before they reach production. In this episode, ISACA’s Adedayo Ojo, Principal, Emerging Technologies and Professional Practices, Research Development, speaks with Advait Patel, Senior Site Reliability Engineer at Broadcom, Docker Captain, and Google Developer Expert in Google Cloud, about why traditional container scanning misses so much and what it takes to identify the issues that matter most. Advait shares lessons from running containers at scale on a large cloud platform and explains how he built DockSec, an open-source tool that uses AI to identify insecure Dockerfile patterns, embedded secrets, and misconfigurations that signature-based scanners tend to overlook. The conversation offers practical guidance that developers and security teams can apply immediately, along with an honest look at where AI can strengthen container security—and where it cannot. Related Resources & Stay Connected Explore DockSec on GitHub: Review the open-source DockSec project, explore its features, and learn how it uses AI to identify insecure Dockerfile patterns, embedded secrets, and container misconfigurations.https://github.com/OWASP/DockSec Learn More About DockSec from OWASP: Discover more about the DockSec project, its approach to container security, and how it helps developers identify risks that traditional signature-based scanners may miss.https://owasp.org/DockSec/ Connect with Advait Patel on LinkedIn: Follow Advait for insights on container security, cloud infrastructure, site reliability engineering, Docker, and AI-powered security.https://www.linkedin.com/in/advaitpatel93/ Explore Advait Patel’s GitHub: View Advait’s open-source projects, technical work, and contributions to cloud and container security.https://github.com/advaitpatel Explore More ISACA Podcast Episodes: Dive deeper into cybersecurity, governance, risk, privacy, and emerging technology insights.https://www.isaca.org/resources/news-and-trends/isaca-podcast-library Subscribe to ISACA on YouTube: Stay ahead with expert interviews, industry analysis, and cybersecurity leadership insights.https://www.youtube.com/@IsacaHq Don’t forget to like, comment, and subscribe for more conversations shaping the future of IT, cybersecurity, governance, risk, and emerging technology. -
Modern Approach to Identity Security 14.07.2026 30minAs threats have evolved, so too has the approach to modern identity security. A privilege-centric approach must be adopted to address this evolution. Identity management for all accounts within an organization must mature to meet the demands of the cloud, nonhuman identities (NHIs), agentic AI, and modern attack vectors. Your strategy must now manage and mitigate not only traditional privileged access (root and administrator accounts), but also attacks targeting modern identities with paths to privileged access. These paths to privilege remain one of the most valuable targets for cybercriminals because many organizations continue to defend their environments with fragmented or siloed security strategies and solutions. Security gaps and risks exist across endpoints, cloud environments, SaaS applications, third-party access, and now agentic AI and NHIs, making today's threat landscape more complex than ever. In this episode, ISACA's Donnie Carpenter, Principal, Information Security and Professional Practices Research Development, speaks with Christopher Hills, Chief Security Strategist at BeyondTrust, about the evolution of identity security and why organizations must rethink how they protect privileged access in today's rapidly changing technology landscape. Related Resources & Stay Connected Learn more about BeyondTrust: Discover how BeyondTrust helps organizations protect identities, manage privileged access, and reduce cyber risk across cloud, endpoint, SaaS, and hybrid environments.BeyondTrust Additional Resources from BeyondTrust: Shadow AI Governance: How to Detect Shadow AI Governance Microsoft Vulnerability Report: Microsoft Vulnerability Report Explore More ISACA Podcast Episodes: Dive deeper into cybersecurity, governance, risk, and emerging technology insights.ISACA Podcast Library Subscribe to ISACA on YouTube: Stay ahead with expert interviews, industry analysis, and cybersecurity leadership insights.ISACA YouTube Channel Don't forget to like, comment, and subscribe for more conversations shaping the future of IT, cybersecurity, governance, and risk. -
ISACA Podcast: Why You Should Use the F Word More 30.06.2026 23minFedRAMP 20x is redefining what federal compliance looks like. Designed to modernize the authorization process, this bold initiative is moving cybersecurity governance toward automation while reducing the lengthy timelines and documentation burdens that have traditionally defined FedRAMP. Join host Safia Kazi as she speaks with Jake Bernardes, CISO at Anecdotes, about what FedRAMP 20x is, why it matters, and how this transformation will reshape governance, risk, and compliance (GRC) automation. Together, they explore what organizations can expect as federal compliance evolves and what the changes mean for enterprise customers navigating the future of cybersecurity governance.Related Resources & Stay Connected Learn more about Anecdotes: Discover how Anecdotes is helping organizations transform governance, risk, and compliance with AI-powered automation, continuous monitoring, and audit-grade data that enables faster, smarter, and more scalable GRC programs. https://www.anecdotes.ai/ Explore More ISACA Podcast Episodes: Dive deeper into cybersecurity, governance, risk, and emerging tech insights. https://www.isaca.org/resources/news-and-trends/isaca-podcast-library Subscribe to ISACA on YouTube: Stay ahead with expert interviews, industry analysis, and cybersecurity leadership insights. https://www.youtube.com/@IsacaHq Don’t forget to like, comment, and subscribe for more conversations shaping the future of IT and cybersecurity. -
The Future of IT Audit: Key Changes in ITAF 5 28.05.2026 29minTechnology is transforming how organizations operate — and IT audit and assurance must evolve alongside it. In this episode, Paul Phillips sits down with Mary Carmichael, contributor to the newly updated IT Audit and Assurance Framework (ITAF 5), to discuss how audit professionals can adapt to today’s increasingly complex digital enterprise. Together, they explore the major shifts shaping modern audit, including AI governance, digital ecosystems, automation, evolving risk landscapes, cloud environments, and the growing need for stronger data literacy within audit teams. Mary also shares practical guidance on how organizations can begin modernizing their audit approach without overhauling everything overnight. Key discussion topics include: The evolution from traditional control testing to outcome-based assurance Why audit teams need stronger technology and data capabilities AI governance, automation, and digital risk considerations Building practical audit modernization strategies How ITAF 5 supports governance, credibility, and audit relevance in modern enterprises Whether you're an auditor, governance professional, cybersecurity leader, or risk practitioner, this conversation provides valuable insight into the future of audit and assurance in a technology-driven world. Related Resources & Stay Connected Download ITAF 5: https://www.isaca.org/resources/itaf-is-a-framework Explore More ISACA Podcast Episodes: Dive deeper into cybersecurity, governance, risk, and emerging tech insights. https://www.isaca.org/resources/news-and-trends/isaca-podcast-library ▶️Subscribe to ISACA on YouTube: Stay ahead with expert interviews, industry analysis, and cybersecurity leadership insights. https://www.youtube.com/@IsacaHq 🔔 Don’t forget to like, comment, and subscribe for more conversations shaping the future of IT audit, governance, risk, and cybersecurity. #ITAudit #ITAF5 #AuditAndAssurance #Cybersecurity #Governance #RiskManagement #AI #ISACA #DigitalTransformation #InternalAudit -
Breaking the Compliance Mentality 21.05.2026 23minIn today’s evolving cybersecurity landscape, strong leadership is the foundation of an effective security posture. Yet many agencies struggle when a “compliance mentality” takes hold, where meeting minimum requirements overshadows proactive risk management. In this ISACA Podcast episode, Lisa Cook, ISACA's Principal Research Analyst, sits down with Patrick Bevill, Chief Information Security Officer (CISO) at the Federal Retirement Thrift Investment Board, to explore how agency leaders can establish a strong tone at the top and foster a culture that prioritizes security resilience over check-the-box compliance. Related Resources & Stay Connected Learn more about Williams Adley: Discover how Williams Adley helps organizations navigate audit, assurance, cybersecurity, risk, and advisory services with a focus on integrity and innovation. https://www.williamsadley.com/ Explore More ISACA Podcast Episodes: Dive deeper into cybersecurity, governance, risk, and emerging tech insights. https://www.isaca.org/resources/news-and-trends/isaca-podcast-library Subscribe to ISACA on YouTube: Stay ahead with expert interviews, industry analysis, and cybersecurity leadership insights. https://www.youtube.com/@IsacaHq Don’t forget to like, comment, and subscribe for more conversations shaping the future of IT and cybersecurity. -
Audit-Ready by Design: How AI Powers Smarter Identity Security 19.05.2026 25minCompliance does not have to be a stressful, last-minute scramble. In this episode, we explore how AI-driven control and automation transforms identity security from a costly headache into an audit-ready powerhouse. We break down the steps to simplify your regulatory processes, reduce operational costs, and enhance security by effectively managing human and non-human identities. You will learn why gaining centralized visibility is your crucial first step, how to instantly spot and remediate risky orphan accounts, and the secret to running seamless, automated access certifications. Join our identity security experts as they share practical strategies to strengthen your defenses without draining your IT resources. Expect actionable tips that will help you build a sustainable, AI-powered compliance process tailored to your organization. Related Resources & Stay Connected Learn more about SailPoint:Explore how SailPoint is helping organizations modernize identity security, strengthen governance, and simplify compliance in an AI-driven world.https://www.sailpoint.com/ Explore More ISACA Podcast Episodes:Dive deeper into cybersecurity, governance, risk, and emerging tech insights.https://www.isaca.org/resources/news-and-trends/isaca-podcast-library Subscribe to ISACA on YouTube:Stay ahead with expert interviews, industry analysis, and cybersecurity leadership insights.https://www.youtube.com/@IsacaHq Don’t forget to like, comment, and subscribe for more conversations shaping the future of IT and cybersecurity. -
SheLeadsTech Fireside Chat: Celebrating Women in Cybersecurity 04.03.2026 51minWomen in cybersecurity leaders share their stories and career advice in this SheLeadsTech fireside chat celebrating International Women’s Day. In celebration of International Women’s Day and Women’s History Month, ISACA’s SheLeadsTech initiative brings together three inspiring leaders in cybersecurity for a special fireside conversation. Join Debbie Lew and Jo Stewart-Rattray, both ISACA Hall of Fame inductees and recipients of the Eugene Frank Founders Award, as they sit down with Gail Coury, who will be inducted into the ISACA Hall of Fame in 2026. In this warm and engaging discussion, they reflect on their journeys into cybersecurity, the evolving role of women in technology, and the power of mentorship, leadership, and community in shaping the future of the profession. In this episode, they discuss:• Their personal paths into cybersecurity and IT• How opportunities for women in tech have evolved over time• Lessons learned from leadership and service within the ISACA community• Advice for the next generation of women entering the field The conversation wraps up with a fun rapid-fire round that offers a glimpse into the personalities behind these accomplished careers. Whether you're an experienced professional or just beginning your journey in technology, this fireside chat offers inspiration, insight, and encouragement from women helping shape the future of cybersecurity. 🔗 Learn more about ISACA’s SheLeadsTech initiative:https://www.isaca.org/membership/sheleadstech 🎧 Explore more ISACA Podcasts:https://www.isaca.org/resources/news-and-trends/isaca-podcast-library 📺 Subscribe to ISACA on YouTube:https://www.youtube.com/@IsacaHq #WomenInCybersecurity#SheLeadsTech#WomenInTech -
Humans Are IT Security’s Weakest Link 03.03.2026 49minOn this episode of the ISACA Podcast, host Chris McGowan is joined by Amit Patel, Senior Vice President at Consulting Solutions, to explore one of the most underestimated threats in cybersecurity: the human element. From accidental errors to insider breaches, they discuss why employee behavior is at the heart of most security incidents—and what organizations can do about it. Amit shares insights on how ongoing training, strong policies, and AI-powered tools like behavior analytics can help bridge the gap between tech and human responsibility. Whether you're a cybersecurity leader or simply navigating today’s digital landscape, this episode offers practical strategies to strengthen your organization’s human-centric security posture. 📚 Related Resources & Stay Connected 📖 Read the full article:Humans Are IT Security’s Weakest Linkhttps://www.isaca.org/resources/news-and-trends/industry-news/2024/humans-are-it-securitys-weakest-link 🎙 Explore More ISACA Podcast Episodes:Dive deeper into cybersecurity, governance, risk, and emerging tech insights.https://www.isaca.org/resources/news-and-trends/isaca-podcast-library ▶️ Subscribe to ISACA on YouTube:Stay ahead with expert interviews, industry analysis, and cybersecurity leadership insights.https://www.youtube.com/@IsacaHq 🔔 Don’t forget to like, comment, and subscribe for more conversations shaping the future of IT and cybersecurity. -
Secure Your Privacy: A security and privacy podcast: real conversations, real consequences, real solutions? 19.02.2026 1h 14minYou’re listening to Secure Your Privates™ brought to you by ISACA Podcasts - where security meets privacy, risk meets reality, and governance finally makes sense. We’re here to cut through the noise and get real about what’s actually happening in cyber. The no-BS podcast on security and privacy. We talk about what’s broken, what’s working, and what nobody’s telling you in between. -
Securing Data in the Age of AI with DSPM: Lessons from a High-Impact ISACA Webinar 12.02.2026 25minIn this ISACA Podcast episode, host Safia Kazi, Principal Research Analyst – Privacy, is joined by Dirk Schrader, VP of Security Research at Netwrix, to discuss how generative AI is revealing long-standing gaps in enterprise data security and governance. This episode builds on insights from a recent ISACA webinar that explored how generative AI is exposing weaknesses in enterprise data security and governance. The discussion examines why many organizations lack visibility into where sensitive data resides and who can access it, particularly across hybrid and cloud environments. The conversation also addresses emerging risks introduced by AI tools, including non-human access and overexposed data. Listeners will gain practical, governance-focused guidance on how DSPM helps organizations assess risk, support compliance, and prepare data responsibly for AI initiatives. Related Resources: Watch the ISACA Webinar from the ISACA Virtual Summit 2025: “Securing Data in the Age of AI with DSPM”https://www.isaca.org/training-and-events/online-training/virtual-summits/ai-governance-strategies Learn more from Netwrix:https://netwrix.com/en/resources/ Explore more ISACA Podcasts:https://www.isaca.org/resources/news-and-trends/isaca-podcast-library ISACA on YouTube:https://www.youtube.com/@IsacaHq -
Elevate Your Career with Lauren Hasson 04.09.2025 18minLauren Hasson is the Founder of DevelopHer, an award-winning career development platform. In this podcast, she'll share a bit about her background and give a sneak peek at her upcoming CPE-eligible event. -
Cyberrisk Quantification: Strengthening Financial Resilience 04.06.2025 35minIn this episode, ISACA's Lisa Cook engages with Yakir Golan, Executive Officer (CEO) and Co-Founder of Kovrr, to explore the critical role of Cyberrisk Quantification (CRQ) in enhancing organizational financial resilience. They discuss how CRQ solutions provide objective assessments of an organization's cybersecurity posture, enabling leaders to make informed decisions that align risk mitigation strategies with business objectives. The conversation also highlights the importance of translating cyberrisk exposure into monetary terms to facilitate high-level discussions and protect shareholder confidence.Listen & Subscribe Catch this episode—and more—on the ISACA Podcast Library: https://www.isaca.org/resources/news-and-trends/isaca-podcast-library or on your favorite podcast platform. -
Securing Desktops and Data from Ransomware Attacks 15.05.2025 39minRansomware remains one of the most formidable cybersecurity threats facing organizations worldwide. In this episode of the ISACA Podcast, host Chris McGowan speaks with Netwrix endpoint protection expert Jeremy Moskowitz, who explains how ransomware infiltrates and cripples desktop environments. He explains cybercriminals' tactics to exploit social engineering and system misconfigurations to gain unauthorized access, offering actionable insights on the most effective prevention and mitigation strategies. Additionally, Jeremy delivers practical advice that security teams can use to resist ransomware. He shares tips on safeguarding locally stored data, implementing robust backup solutions, enforcing strict access controls and system patching, and educating staff on common red flags associated with ransomware. Listen & Subscribe to ISACA Podcast Catch this episode—and more—on the ISACA Podcast Libraryor on your favorite podcast platform. Connect & Learn More about Netwrix Netwrix Data Loss Prevention Solution: Learn more Follow Netwrix on LinkedIn: Netwrix Corporation: Posts | LinkedIn Additional Resources Provided by Netwrix: CISA’s Ransomware Guidance SANS Institute White Papers on Ransomware NIST SP 800-61 Rev. 2 – Incident Handling Guide Krebs on Security – Ransomware Articles -
Cyberresilience and Cybersecurity 11.03.2025 24minCybersecurity and the role of internal audit, an urgent call to action: The forces driving business growth and efficiency contribute to a broad attack surface for cyber assaults. How is the end user protected with good service while not being compromised? First Line includes internet, cloud, mobile, and social technologies, now mainstream, are platforms inherently oriented for sharing. Outsourcing, contracting, and remote workforces are shifting operational control. Second line includes information and technology risk management leaders who establish governance and oversight, monitor security operations, and take-action as needed, often under the direction of the chief information security officer (CISO) Third line of cyber defense—independent review of security measures and performance by the internal audit function. Internal audit should play an integral role in assessing and identifying opportunities to strengthen enterprise security. At the same time, internal audit has a duty to inform the audit committee and board of directors that the controls for which they are responsible are in place and functioning correctly, a growing concern across boardrooms as directors face potential legal and financial liabilities. -
Cybersecurity Predictions for 2025 07.01.2025 26minThe prevalence of ransomware and the security concerns associated with AI have made the role of cybersecurity professionals vital for enterprise success. The complex security landscape can make cybersecurity jobs stressful, but enterprises can take steps to retain cybersecurity talent and ensure enterprise assets are protected. In this podcast, Justin Rende, founder and CEO at Rhymetec, shares insight on the top concerns for cybersecurity professionals, the most in-demand skills, and the impact of AI on cybersecurity. -
Examining Authentication in the Deepfake Era with Dr. Chase Cunningham 10.12.2024 38minGiven the dynamic nature of cyberthreats and the ever-expanding digital ecosystem, authentication is more critical than ever. In this episode, ISACA director of professional practices and innovation discusses a new content piece titled, "Examining Authentication in the Deepfake Era" with author Dr. Chase Cunningham. Their conversation of the paper explores the evolution, current state, and future trajectory of authentication technologies. -
Safely and Responsibly Using Emerging Health Technology 05.12.2024 25minEmerging healthcare technologies have the potential to revolutionize healthcare and accessibility-related concerns, but these advancements are not without risk. To maximize the value and minimize the harms associated with emerging health technologies, it is critical to address ethical, privacy, and societal concerns to ensure that these technologies help rather than hurt humanity. In this ISACA Podcast, join Safia Kazi and Collin Bedder as they explore the applications and risks associated with emerging healthcare technologies. -
Addressing SAP Security Gaps 17.09.2024 25minSAP systems are treated differently than many other enterprise applications from a cybersecurity perspective. Most SAP security teams are siloed and left to meet security objectives on their own. Since SAP is so integral to organizations, it is unusual for SAP security objectives to not be on the radar of an existing 24/7 cybersecurity team executing response actions for Linux or Microsoft environments. SAP teams must be integrated w SAP systems are treated differently than many other enterprise applications from a cybersecurity perspective. Most SAP security teams are siloed and left to meet security objectives on their own. Since SAP is so integral to organizations, it is unusual for SAP security objectives to not be on the radar of an existing 24/7 cybersecurity team executing response actions for Linux or Microsoft environments. SAP teams must be integrated with other cybersecurity groups within an organization to empower them with a security approach that unifies the entire enterprise landscape. A chief information security officer (CISO) has many priorities, but when it comes to SAP environments, CISOs must fully understand how SAP applies to the IT enterprise and organizational environment to help them achieve all security goals. In addition, CISOs need to know their SAP team members personally so they can integrate them rather than contain them in silos. Finally, SAP must be secured to the same degree as other enterprise applications. When there is a Linux, Microsoft, or even a hybrid cloud incident, cybersecurity teams have a detailed plan of action upon which they are ready to act. SAP requires high-level consideration, or critical elements of the business will be vulnerable to malicious cyber actors—with no apparent response. -
What Enterprises Need to Know About ChatGPT and Cybersecurity 24.07.2024 21minMany people are pondering whether generative artificial intelligence (AI) tool ChatGPT is a friend or a foe. In this ISACA podcast episode, Camelot Secure Director of Solutions Engineering Zachary Folks discusses not only his view of how ChatGPT can be considered an evolution of the encyclopedia, but importantly how it is aiding cybersecurity professionals and the overall goal of enterprise security, as well as how cybercriminals who want to exploit it can leverage it as well. He believes the world is entering a time when AI is fighting AI, and security professionals must focus on feeding ChatGPT technology more relevant data faster than the adversary. Folk also addresses how AI is affecting social engineering and his predictions for upcoming AI developments. -
The Cyber Standard Podcast - Episode 4 30.05.2024 48minWelcome to Episode 4 of "The Cyber Standard Podcast"! Join host Ameet Jugnauth, Vice President of the London Chapter of ISACA, as he delves into the world of cybersecurity standardization. In this episode, titled "Becoming a License Body," Ameet is joined by esteemed guests Bryan Lillie, Strategic Technical Lead at the UK Cyber Security Council, and Peter Leitch, Co-Founder and Managing Partner at ANSEC. Together, they explore the intricacies of licensed bodies in shaping the cyber profession. Don't miss this insightful conversation! Explore Further: Delve deeper into the subject with additional resources provided in the episode description. https://www.isaca.org/about-us/newsroom/press-releases/2023/uk-cyber-security-council-partners-with-isaca-for-audit-and-assurance-pilot-scheme
Priljubljen v
Ta podkast je tudi v lestvicah podkastov teh držav.