Mato
ShowsHow it worksAI talentsFree toolsPricing
Book a demo
ShowsHow it worksAI talentsFree toolsPricingSign in
Mato
Mato

The first generation of AI talents. Live AI media for brands, networks and creators.

ElevenLabs GrantsAWS ActivateGoogle for StartupsNVIDIA Inception Program

Product

  • How it works
  • AI talents
  • Documentation
  • The studio
  • Pricing
  • Embed player
  • Mato MCP
  • Mato Voice
  • Voice Studio
  • Changelog

Company

  • About
  • Vision
  • Partners
  • Affiliates
  • Blog
  • CustomersComing soon
  • CareersComing soon
  • Press kit
  • Contact

Resources

  • Investor overview
  • Free podcast tools
  • Free podcast transcription
  • Podcast ROI calculator
  • API docsComing soon
  • SecurityComing soon
  • StatusComing soon

© 2026 Mato. All rights reserved.

English · Multiple languages available

PrivacyTerms

Live Interview

And why does that matter?

This is how a Mato agent talks. Take the other seat: answer a few and feel it follow the thread.

Try it yourself

Podcast charts

Cybersecurity Where You Are (video)

Published by Center for Internet Security

  • Business
  • Non-profit

Welcome to video version of “Cybersecurity Where You Are,” the podcast of the Center for Internet Security® (CIS®). Cybersecurity affects us all, so join us on Wednesdays as Sean Atkinson, CISO at CIS; Tony Sager, SVP & Chief Evangelist at CIS; and Ed Skoudis, President of the SANS Technology Institute discuss trends and threats, explore security best practices, and interview experts in the industry. Together, we’ll clarify these issues, Creating Confidence in the Connected World®. Subscribe to the audio version of our podcast here: https://fast.wistia.net/embed/channel/wbyhaw35xf?wchannelid=wbyhaw35xf.

Listen on Apple Podcasts, opens in a new tabMake something like it

On the charts

2 chart placements

Every published chart this podcast appears in, in the snapshot behind this page. Each one links to the chart it came off.

  1. Number 199Non-profitUnited Kingdom
  2. Number 64Non-profitUnited States

From the feed

Recent episodes

The latest episodes published to this podcast’s own RSS feed. Titles and descriptions are the publisher’s.

  1. Episode 205: Secure by Design — Now Updated for AI from Cybersecurity Where You Are (video), opens in a new tab

    Sep 16, 202636 min

    In episode 205 of Cybersecurity Where You Are, Tony Sager speaks with Phyllis Lee , VP of SBP Content Development at the Center for Internet Security®(CIS®), and Steve Lipner , Executive Director of SAFECode . Together, they discuss how an updated document from CIS and SAFECode gives concrete guidance on what artificial intelligence (AI) means for your Secure by Design process. Here are some highlights from our episode: 02:17 . A refresher on making Secure by Design digestible for end organizations 02:57 . Distillation and prescriptive guidance: The value provided by CIS 06:53 . An overview of Butler Lampson's "Gold Standard of Security" 07:03 . How a shift in approach to Secure by Design led to the founding of SAFECode 09:42 . The importance of verification requirements for what developers have done 12:54 . A product of CIS pragmatism: Prioritization relative to the development environment 20:06 . Artifacts as evidence of secure software development at work 30:15 . How the updated document provides guidance around AI 30:45 . What AI creates instead of new classes of vulnerabilities Resources CIS Critical Security Controls® (CIS Controls®) Secure by Design Secure by Design v1.1 A Guide to Assessing Software Security Practices Turning Secure Software Development into a Measurable Practice CIS and SAFECode Release Secure by Design v1.1: A Guide to Assessing Software Security Practices Episode 164: Secure by Design in Software Development CIS Critical Security Control 16: Application Software Security Guide to Implementation Groups (IG): CIS Critical Security Controls v8.1 Episode 200: Alan Paller's Vision and Our Next Chapter From Prompts to Protocols: The Security Blueprint for Enterprise AI Mythos AI: What Actually Matters for Cybersecurity Leaders If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org .

  2. Episode 204: FWC26 and the New Bar for Event Security from Cybersecurity Where You Are (video), opens in a new tab

    Sep 9, 202633 min

    In episode 204 of Cybersecurity Where You Are, Sean Atkinson speaks with Ryan Winmill , Chief Security Officer and Vice President of FIFA World Cup Boston, and John Cohen , Executive Director of the Office of Strategic Programs and Initiatives at the Center for Internet Security® (CIS®). Together, they discuss how FIFA World Cup 2026 (FWC26) — secured through an unprecedented tripartite governance framework, $625 million in U.S. Congressional funding, and real-time intelligence that stopped a swatting attempt at the finals — set a new standard for proactive event security worldwide. Here are some highlights from our episode: 01:18 . The "unprecedented" governance framework created for FWC26 03:53 . The role of CIS as a force multiplier for FIFA, host regions, and other partners 11:00 . Why you can't trust the person with an ego in large-scale event security planning 13:23 . How the threat environment evolved over the previous three World Cup tournaments 17:23 . A new bar for proactive event security going forward 18:43 . How CIS provided quality control that helped to mitigate swatting calls during FWC26 21:55 . Unique approaches used by host regions to better understand the World Cup fanbase 23:15 . How counterfeit FIFA volunteer uniforms triggered a cross-city credentialing response 26:46 . Recommendations for future large-scale event host cities 30:19 . Ryan's recommendation to future host cities: "Call CIS before you get started" Resources Special Event Risk Analysis & Advisory Services Episode 196: Securing FIFA World Cup 2026 Collaboratively Inside the Security Operation Behind the 2026 FIFA World Cup 3 Lessons for Securing Large-Scale Events: Inside FIFA World Cup 2026 Securing FIFA World Cup 2026 With a Collective Defense Approach If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org .

  3. Episode 203: Cyber Attacks' Human Impact — Beyond the Data from Cybersecurity Where You Are (video), opens in a new tab

    Sep 2, 202633 min

    In episode 203 of Cybersecurity Where You Are, Sean Atkinson speaks with Pavlina Pavlova , Founder of Critical Cyber . Together, they discuss how Pavlina started Critical Cyber to go beyond the data and give voice to the human impact of cyber attacks, from ransomware hitting hospitals to cyber tactics targeting civilians in active conflict zones. Here are some highlights from our episode: 00:44 . How Pavlina's work covering the impact of cyber attacks on Ukrainian critical infrastructure led to Critical Cyber 03:13 . How Critical Cyber works with cyber attack victims, responders, and other audiences 04:08 . Countering the tendency, even among cybersecurity experts, to sanitize cyber attacks' human impact 08:57 . The use of storytelling with those impacted by cyber attacks to drive policy changes 15:02 . Why cyber attacks in some sectors are underreported 19:01 . Critical Cyber's mission of combining testimony, research, and expert collaboration 24:51 . Where Critical Cyber is and where it's looking to go Resources Critical Cyber Cybersecurity for Critical Infrastructure Episode 202: Delineating AI Security and Cybersecurity Recent Water Utility Attacks Offer a Blueprint for Resilience If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org .

  4. Episode 202: Delineating AI Security and Cybersecurity from Cybersecurity Where You Are (video), opens in a new tab

    Aug 26, 202638 min

    In episode 202 of Cybersecurity Where You Are, Sean Atkinson and Ed Skoudis sit down with Rob T. Lee , Chief of Research & Chief AI Officer at the SANS Institute. Together, they explore how the implications of multiple 2026 sandbox escapes of artificial intelligence (AI) models are starting to delineate AI security and cybersecurity. Here are some highlights from our episode: 02:00 . The historical context of one AI model's 2026 sandbox escape 03:26 . The impact of ethics, guardrails, and misconfigurations in an AI containment breach 06:08 . Why context matters when talk of AI models "going rogue" surfaces 11:49 . How history helps us to delineate AI security and cybersecurity 13:47 . A new skill and mindset to match our refined AI risk understanding 15:43 . Rules and cybersecurity implementation as a possible way forward 19:04 . The double-edged sword of restricting access to open-weight models 23:25 . Recommendations for keeping up with what's changing in the AI security space 25:51 . Rob's advice: To learn how to defend a thing, try learning how to build it first 28:23 . AI governance and seeing through the "slop" to informed conversation 29:54 . The use of AI to learn more about and discuss AI security for years to come Resources OpenAI says its AI technology acted on its own in an ‘unprecedented’ hack of another company Pacing model development in an era of cyber-critical capabilities Black Hat USA 2026 | The 'Breaking' News: The OpenAI–Hugging Face Incident Episode 193: AI Security and Responsibility in EO 14409 The AI Daily Brief — Daily AI News & Analysis AI Playbooks for SLTT Cybersecurity Leaders SANS Cybersecurity Summits SANS NewsBites If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org .

  5. Episode 201: The Evolution and AI Enablement of Pentesting from Cybersecurity Where You Are (video), opens in a new tab

    Aug 19, 202633 min

    In episode 201 of Cybersecurity Where You Are, Sean Atkinson and Ed Skoudis sit down with William Wright , Chief Executive Officer of Closed Door Security. Together, they reflect on the evolution of penetration testing, including the impact on pentesting from artificial intelligence (AI). Here are some highlights from our episode: 01:03 . How things have changed since William's and Ed's first pentests 09:02 . Community: A defining element of Capture The Flag (CTF) events 14:47 . Industry concerns over the "death" of CTFs and "cheating" by artificial intelligence (AI) 17:00 . Opportunities to take CTFs to the next level in the age of AI 20:18 . Pentesting vs. vulnerability scanning: Why terminology matters 25:43 . The advent of autonomous AI tools and what they could mean for vulnerability scanning 29:07 . Why continuous improvement in cybersecurity doesn't always require AI Resources Closed Door Security Episode 189: The Present and Future of AI-enabled Pentesting SANS Cyber Ranges Top External Network Risks And How to Fix Them Penetration Testing Vulnerability Assessments If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org .

  6. Episode 200: Alan Paller's Vision and Our Next Chapter from Cybersecurity Where You Are (video), opens in a new tab

    Aug 12, 202640 min

    In episode 200 of Cybersecurity Where You Are, Sean Atkinson, Tony Sager, and Ed Skoudis sit down with Frank Reeder , Co-Founder and Founding Chair of the Center for Internet Security® (CIS®). Together, they reflect on how Alan Paller's vision continues to drive CIS forward. In the spirit of that vision, this milestone episode also marks a new chapter for the podcast: Ed Skoudis joins as co-host of Cybersecurity Where You Are. Here are some highlights from our episode: 01:09 . The two complementary missions of CIS 02:55 . Three defining moments that have shaped CIS into the organization it is today 08:10 . The story of naming CIS 10:31 . How CIS and SANS advance Alan Paller's vision of bringing people together 13:50 . Personal anecdotes of Alan Paller as a connector of people 15:45 . "What would Alan do?" A question that continues to guide CIS and SANS 22:00 . How CIS security best practices are emblematic of helping others 27:12 . CIS's "secret sauce" as a trusted, neutral platform for cybersecurity collaboration 29:53 . How CIS can continue to embody Alan Paller's philosophy into the future 37:47 . A special announcement: Ed Skoudis as a new co-host on the podcast Resources CIS Benchmarks® List CIS Critical Security Controls® Multi-State Information Sharing and Analysis Center® Episode 114: 3 Board Chairs Reflect on 25 Years of Community Alan Paller Laureate Program SANS Difference Makers Awards If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org .

  7. Episode 199: Translating Cyber Risk into Business Decisions from Cybersecurity Where You Are (video), opens in a new tab

    Aug 5, 202637 min

    In episode 199 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager sit down with Chris Painter , Chair of the Risk Committee and Board Member at the Center for Internet Security® (CIS®). Together, they discuss how chief information security officers (CISOs) can support the work of translating cyber risk into business decisions by Boards. Here are some highlights from our episode: 00:50 . Introductions to Chris 01:36 . The single biggest translation error Chris has seen CISOs make 07:38 . Cyber risk quantification: An opportunity to go beyond translation for Boards 09:25 . How ransomware changed Boards' understanding of cyber risks' business impact 10:45 . The value of tabletop exercises (TTX) and other simulations in creating shared language 13:26 . Recommendations on how to make the most of a TTX 18:37 . Risk modeling and how artificial intelligence (AI) complicates probability estimations 21:51 . "Pressure" (2026) as an illustration of making good, not 100% accurate, estimations 22:58 . How growing public awareness of cyber is reshaping CISOs' conversations with Boards 25:55 . The importance of walking Boards through risk mitigation steps with AI as an example 29:31 . A recommendation for how CISOs can learn what directors care about 30:15 . From "wizardry" to familiarity: An ongoing generational shift around cyber Resources Episode 183: The Role of CISO in Supporting Risk Translation Episode 187: The Role of a CISO as a Strategic Storyteller Episode 192: How Leaders Balance Expertise and Communication How Risk Quantification Tests Your Reasonable Cyber Defense CIS RAM (Risk Assessment Method) Leveraging Generative Artificial Intelligence for Tabletop Exercise Development CIS Controls v8.1 Incident Response Policy Template You Have a Cybersecurity Incident. Now What? Prompt Injections: The Inherent Threat to Generative AI "Pressure" | Official Website | 29 May 2026 If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org .

  8. Episode 198: AI Privacy from a Risk-Based Perspective from Cybersecurity Where You Are (video), opens in a new tab

    Jul 29, 202630 min

    In episode 198 of Cybersecurity Where You Are, Sean Atkinson discusses artificial intelligence (AI) and privacy from a risk-based cybersecurity perspective. Together, he explores how organizations and individuals can assess AI risk, apply governance frameworks, evaluate third-party AI services, and balance innovation with due diligence. Here are some highlights from our episode: 00:41 . Framing the conversation around AI, privacy, and risk-based controls 02:22 . Due diligence and ethical considerations around AI products and services 03:14 . Data minimization and transparency as foundations for AI privacy 04:46 . Privacy impact assessments as a way to understand AI data collection and use 05:42 . AI governance and the tension between implementation velocity and risk management 10:08 . The use of existing data flows and controls in AI assessments 11:57 . Algorithmic transparency and the challenge of understanding AI decision making 13:47 . Standards, frameworks, and data sovereignty in AI privacy governance 15:12 . Encryption, anonymization, tokenization, and federated learning as privacy safeguards 16:40 . The need to shift stakeholder input left in AI development and deployment lifecycles 19:13 . Building literacy around security, data management, privacy, and AI risk 23:40 . The value of cross-functional and written assessment criteria for AI risk 26:21 . A call to action for keeping pace with AI privacy and and innovation risk Resources CIS Controls v8.1.2 AI Security Guidance Workbook Episode 105: Context in Cyber Risk Quantification Service Provider Management Policy Template for CIS Control 15 EU AI Act: first regulation on artificial intelligence AI Risk Management Framework IAPP AI Governance Center Episode 120: How Contextual Awareness Drives AI Governance Secure by Design v1.1 A Guide to Assessing Software Security Practices Reasonable Cybersecurity If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org .

  9. Episode 197: AI-ready OT Data Begins with Understanding from Cybersecurity Where You Are (video), opens in a new tab

    Jul 22, 202633 min

    In episode 197 of Cybersecurity Where You Are, Sean Atkinson sits down with Ben Wilcox , Chief Technology Officer and Chief Information Security Officer at ProArch; and Ed Skoudis , President of SANS Technology Institute. Together, they discuss artificial intelligence (AI), operational technology (OT) data, and how understanding creates the foundation for AI-ready OT data. Here are some highlights from our episode: 00:54 . Introductions to Ben and Ed 02:16 . How we understand and integrate AI into OT environments 04:30 . How OT diverges from information technology (IT) in data responsibilities 05:23 . Opportunities for AI to assist OT 06:33 . The importance of meeting OT systems where they are 08:10 . A passive and incremental approach that respects the operations machines are doing 12:29 . Efficiency gains, public safety improvements, and other benefits of AI-ready OT data 17:47 . What lifecycle management, asset hierarchies, and governance look like for OT data 22:14 . The promise of AI to help to make OT environments understandable 23:19 . A team sport: How IT and OT can work together to understand assets and data 28:38 . The need for translation in IT-OT communication 29:01 . Recommendations for how to make OT data AI ready Resources CIS Critical Security Controls® CIS Controls version 8.1 ICS Workbook Artificial Intelligence and Large Language Models Companion Guide CIS Controls v8.1 Enterprise Asset Management Policy Template CIS Controls v8.1 Software Asset Management Policy Template CIS Controls v8.1 Data Management Policy Template CIS Controls v8.1 Account & Credential Management Policy Template Establishing Essential Cyber Hygiene ProArch Cybersecurity for Critical Infrastructure Episode 77: Data's Value to Decision-Making in Cybersecurity Episode 183: The Role of CISO in Supporting Risk Translation If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org .

  10. Episode 196: Securing FIFA World Cup 2026 Collaboratively from Cybersecurity Where You Are (video), opens in a new tab

    Jul 15, 202637 min

    In episode 196 of Cybersecurity Where You Are, Sean Atkinson sits down with Sasha Larkin , Director of Intelligence and C4 Operations for FIFA World Cup 2026, and John Cohen , Executive Director of the Office of Strategic Programs and Initiatives at the Center for Internet Security® (CIS®). Together, they discuss how CIS, FIFA, and FIFA World Cup 2026 host cities started collaborating in 2025 on cybersecurity, public safety, intelligence, and information-sharing efforts supporting the largest sporting event in the world. Here are some highlights from our episode: 00:40 . Introductions to Sasha and John 02:07 . Overview of one of the most complex public safety efforts assembled for a sporting event 05:52 . Consistency: A standard for preventing and deterring threats at FIFA World Cup 2026 10:30 . The impact of relationships in shaping FIFA's security ops and information sharing 11:53 . Effective communication: The key to cross-functional collaboration in support of the tournament 18:07 . The importance of information that guides operations 20:35 . Education as a way to inform stakeholders and deploy resources 26:19 . A deliberate effort to look at unanticipated threats and plan for them 29:14 . Examples of messaging synchronization in support of FIFA World Cup 2026 32:37 . An all-hands-on-deck support campaign from CIS 33:29 . Parting thoughts around large-scale event support in the future Resources An Examination of Generative AI and Physical Threat Planning An Examination of AI-Enabled Threats to Event and Stadium Security Multidimensional Threats 5 Major Emerging Risks to Large-Scale Events Illicit Sports Betting and Match Integrity Risks to Large-Scale Events Deepfakes and Synthetic Media: The Emerging Threat to Large-Scale Public Gatherings Growing Risks to Digital Ticketing Platforms for Large-Scale Events Unmanned Aircraft Systems (UAS): Evolving Risks to Large-Scale Public Gatherings Unmanned Aircraft Systems (UAS): Evolving Risks to Large-Scale Public Gatherings Cyber Risks Companion Guide 5 Steps to Help Secure Your City before a Large-Scale Event If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org .

  11. Episode 195: Enigma Machines’ Security Lessons for Today from Cybersecurity Where You Are (video), opens in a new tab

    Jul 8, 202641 min

    In episode 195 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager sit down with Ed Skoudis , President of SANS Technology Institute, and Marcus Sachs , Senior Vice President and Chief Engineer at the Center for Internet Security® (CIS®). Together, they discuss Enigma machines, their history, and their security lessons for today. Here are some highlights from our episode: 00:56 . Introductions to Ed and Marc 01:32 . What Enigma machines are and why cybersecurity folks still care about them today 06:10 . Enigma machines as a symbol for how we can use hacking for noble purposes 07:18 . How the human mind and the need for ease of use can undermine security 15:59 . The importance of testing when designing and maintaining a security system 20:45 . Why "security through obscurity" isn't actually true 22:58 . Curiosity, logic, and a wide range of knowledge: Essential traits for getting hired in cybersecurity today 30:57 . The impact of culture in shaping security policy and priorities 35:09 . Why artificial intelligence (AI) is the Enigma machine of 2026 36:11 . How to learn more about Enigma machines Resources Episode 189: The Present and Future of AI-enabled Pentesting A Short Guide for Spotting Phishing Attempts Penetration Testing Vulnerability Assessments Episode 192: How Leaders Balance Expertise and Communication Episode 193: AI Security and Responsibility in EO 14409 The Myth of Mythos: What It Means For Information Security National Cryptologic Museum Enigma Replica: The Enigma touch If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org .

  12. Episode 194: 2026 Cybersecurity Predictions Mid-Year Review from Cybersecurity Where You Are (video), opens in a new tab

    Jul 1, 202651 min

    In episode 194 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager sit down with Ed Skoudis , President of SANS Technology Institute. Together, they conduct a mid-year review of 2026 cybersecurity predictions from seven Center for Internet Security® (CIS®) experts, as shared on the CIS website . Here are some highlights from our episode: 01:50 . Ongoing conversations about improving defense with artificial intelligence (AI) 05:19 . A trap to avoid: Automating things with AI because we can regardless of utility 06:54 . Ed's prediction about a near-term transition for AI-enabled vulnerability discovery 09:27 . How AI agents change the economics around conducting a penetration test 11:26 . Adversary emulation: A blurry proposition when threat actors use AI to look like anybody 14:02 . Ed's prediction about threat actors shifting APT profiles within a single attack campaign 17:00 . The need to systematically rethink cyber defense to support state and local cybersecurity 23:34 . How adversaries are pivoting to the "authorization sprawl" in light of zero trust efforts 29:20 . Industry-specific threat intelligence as a way to keep organizations informed 32:10 . Why a policy isn't the same as security control for operational technology (OT) 33:55 . Social expectations and public policy objectives around holistic OT security 39:52 . Compliance as a floor, not a ceiling, that results as a byproduct of continuous security 43:43 . The need for oversight and confidence in technology as distinct from the "Fog of More" Resources Episode 169: 2026 Cybersecurity Predictions from CIS — Pt 1 Episode 174: 2026 Cybersecurity Predictions from CIS — Pt 2 Episode 179: 2026 Cybersecurity Predictions from CIS — Pt 3 The Myth of Mythos: What It Means For Information Security Episode 189: The Present and Future of AI-enabled Pentesting Authorization Sprawl: The Vulnerability Reshaping Modern Attacks Episode 188: DBIR 2026 Insights and Collaboration with CIS Mapping and Compliance with the CIS Controls Mapping and Compliance with the CIS Benchmarks If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org .

  13. Episode 193: AI Security and Responsibility in EO 14409 from Cybersecurity Where You Are (video), opens in a new tab

    Jun 24, 202639 min

    In episode 193 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager sit down with Rob T. Lee , Chief of Research & Chief AI Officer at the SANS Institute, and Brian Calkin , Chief Technology and Innovation Officer at the Center for Internet Security® (CIS®). Together, they discuss AI security and the responsibility of the U.S. government in creating confidence around it, as represented in Executive Order (EO) 14409, "Promoting Advanced Artificial Intelligence Innovation and Security." Here are some highlights from our episode: 00:50 . Introductions to Rob and Brian 02:32 . How to conceptualize confidence around something as complex as AI security 04:32 . The U.S. government's responsibility to set AI security guardrails as clear expectations 08:12 . The use of "voluntary" participation to create confidence in the context of EO 14409 14:38 . How Mythos AI and similar developments affect assessment of frontier AI models 17:11 . Airport security as an analogy for understanding AI security and privacy concerns 18:41 . Why cybersecurity is a hard sell until an incident occurs 20:50 . How AI is quickly becoming critical infrastructure 22:53 . Furbies as reference for a flexible, iterative benchmarking process for AI security 25:50 . The need for technical folks to translate AI risks into something understandable 28:21 . Balancing encouragement of AI innovation with mindfulness of risk 31:24 . The basics as a foundation for building shared responsibility around AI security Resources Promoting Advanced Artificial Intelligence Innovation and Security The Myth of Mythos: What It Means For Information Security Episode 190: Separating Mythos AI Fact from Fiction The “AI Vulnerability Storm”: Building a “Mythos-ready” Security Program Anthropic says it has taken its latest AI models offline to comply with new export controls Establishing Essential Cyber Hygiene Episode 187: The Role of a CISO as a Strategic Storyteller If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org .

  14. Episode 192: How Leaders Balance Expertise and Communication from Cybersecurity Where You Are (video), opens in a new tab

    Jun 17, 202631 min

    In episode 192 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager sit down with Marcus Sachs , Senior Vice President and Chief Engineer at the Center for Internet Security® (CIS®). Together, they discuss how leaders, including those in cybersecurity, balance their technical expertise with mastery of communication strategies. Here are some highlights from our episode: 00:51 . Introductions to Marcus 02:04 . How Marcus found value in using analogies to communicate complex topics 08:40 . Coordination with non-technical folks as a sign of leadership maturity 14:03 . The wisdom in knowing what to say and what not to say when managing up 17:31 . The need to balance technical skills with team resourcing in a way that's imitable 21:07 . The challenge of leaders learning by proximity in hybrid and remote environments 24:16 . "Classic" engineering vs. "new" engineering 25:13 . Lessons from Boards in applying discipline, rigor, and order to software engineering 28:23 . The value in leaders continuously learning how businesses work Resources Episode 183: The Role of CISO in Supporting Risk Translation Episode 187: The Role of a CISO as a Strategic Storyteller Episode 99: How Cyber-Informed Engineering Builds Resilience 7 CIS Experts' 2026 Cybersecurity Predictions If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org .

  15. Episode 191: GenAI Misuse for Physical Threat Planning from Cybersecurity Where You Are (video), opens in a new tab

    Jun 10, 202631 min

    In episode 191 of Cybersecurity Where You Are, Sean Atkinson sits down with Sasha Elvenaes, Sr. Multidimensional Threat Analyst at the Center for Internet Security® (CIS®), and Rian Davis, Multidimensional Threat Analyst at CIS. Together, they discuss how threat actors are misusing generative artificial intelligence (GenAI) to plan physical threats. Here are some highlights from our episode: 00:40 . Introductions to Sasha, Rian, and their research on GenAI misuse 01:56 . The impact of GenAI on lowering the barrier for operationalizing physical threat activity 03:37 . Exploitation of GenAI model design to circumvent models' guardrails 05:58 . The misuse of session persistence to streamline physical threat research 07:57 . GenAI misuse: A call for critical infrastructure operators to think about security differently 11:52 . Factors that make large-scale events a target of physical threat activity 14:33 . The use of GenAI as a strategy for organizations to see what threat actors could see 15:37 . Ongoing question: How can drones help mitigate risks while protecting public safety? 17:13 . Extrapolation as a reinforcement of GenAI session persistence 20:15 . The new reality: Look at what information AI can provide to threat actors 25:01 . Traditional methods vs. GenAI conversations for threat planning 27:58 . Continuous vulnerability assessments, communication, and other recommendations Resources An Examination of Generative AI and Physical Threat Planning An Examination of AI-Enabled Threats to Event and Stadium Security Multidimensional Threats Man who exploded Cybertruck in Las Vegas used ChatGPT in planning, police say Episode 190: Separating Mythos AI Fact from Fiction Episode 185: AI Prompt Injection from a Risk Perspective 5 Steps to Help Secure Your City before a Large-Scale Event Unmanned Aircraft Systems (UAS): Evolving Risks to Large-Scale Public Gatherings 8 Security Essentials for Managing Your Online Presence Vulnerability Assessments If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org .

  16. Episode 190: Separating Mythos AI Fact from Fiction from Cybersecurity Where You Are (video), opens in a new tab

    Jun 3, 202638 min

    In episode 190 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager sit down with Brian Calkin , Chief Technology and Innovation Officer at the Center for Internet Security® (CIS®). Together, they separate fact from fiction around artificial intelligence (AI) capabilities like Mythos AI and other AI-driven vulnerability discovery tools. Here are some highlights from our episode: 00:50 . Greetings to Brian and setting the stage for questions from a CIS webinar 03:05 . The lack of a unified formula or standard for vulnerability prioritization 03:55 . The opportunity for defenders to interrupt vulnerabilities chained together 05:47 . An invitation to better understand your enterprise amid the "slopdemic" 06:33 . How AI guardrails tie back into security best practices 10:15 . How a fundamental practice we can refine is the best counter to chained attacks 12:25 . The value of the CIS Community Defense Model and a teaser for Version 3 14:50 . Mythos AI vs. Static Application Security Testing (SAST) in terms of practice and time 19:08 . Visibility, governance, and prioritization: Three elements of a "prepared" environment 24:32 . "One to one" cyber defense as a losing battle 27:25 . The importance of knowing your dependencies with open-source software 33:15 . Threat actor economics and the ongoing debate around responsibility in cybersecurity Resources Mythos AI: What Actually Matters for Cybersecurity Leaders Secure by Design CIS Critical Security Controls® CIS Community Defense Model 2.0 Episode 185: AI Prompt Injection from a Risk Perspective Living off the Land: Threats Looming From Within Turn Intel Into Action: CIS Controls and the 2026 Verizon DBIR Implementation Guide for Small- and Medium-Sized Enterprises CIS Controls IG1 Information Technology and Information Security Governance If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org .

  17. Episode 189: The Present and Future of AI-enabled Pentesting from Cybersecurity Where You Are (video), opens in a new tab

    May 27, 202633 min

    In episode 189 of Cybersecurity Where You Are, Sean Atkinson sits down with Ed Skoudis , President of SANS Technology Institute. Together, they discuss the present and future of pentesting enabled by artificial intelligence (AI). Here are some highlights from our episode: 00:39 . Introductions to Ed 01:49 . The promise of AI-enabled pentesting in creating more secure infrastructure 04:52 . AI-enabled and AI-centric workflows in the realm of penetration testing 08:03 . Wranglers, matadors, and centaurs, oh my! Metaphors for AI-enabled pentesters 13:00 . How AI can assist with reporting, enumeration, and scanning as part of a pentest 14:57 . AI-enabled source-assisted pentesting and the types of vulnerabilities it finds 19:50 . A learning opportunity for the broader cybersecurity community 23:44 . How AI and human analysts could split the workload in a future penetration test 25:54 . AI-enabled pentesting vs. AI pentester in a box 29:51 . Why "human in the loop" might be too passive a phrase 30:37 . The use of AI for source code development Resources Mythos AI: What Actually Matters for Cybersecurity Leaders Secure by Design SEC543: AI-Assisted Source Code Analysis and Exploitation for Penetration Testers Episode 108: Gaming and Competition in Cybersecurity Episode 59: Probing the Modern Role of the Pentest If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org .

  18. Episode 188: DBIR 2026 Insights and Collaboration with CIS from Cybersecurity Where You Are (video), opens in a new tab

    May 20, 202639 min

    In episode 188 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager sit down with Philippe "Phil" Langlois , Data Breach Investigations Report (DBIR) Author at Verizon; and Charity Otwell , Director of the CIS Critical Security Controls® (CIS Controls®) at the Center for Internet Security® (CIS®). Together, they discuss some of the top insights of the 2026 DBIR and how CIS contributed to the publication. Here are some highlights from our episode: 00:50 . Introductions to Phil and Charity 02:46 . Vulnerability exploitation as the most common attack vector 05:25 . The role of artificial intelligence (AI) in threat actors' natural system thinking 07:03 . The need for clear governance and responsibility around vulnerability management 08:58 . Insight into the types of techniques threat actors research using frontier AI models 13:43 . A trending drop in ransomware payouts and organizations willing to pay attackers 14:59 . Why a healthy dose of distrust goes a long way in assessing attackers' claims of victims 16:24 . How two ransomware groups stand out above the norm 17:49 . The ongoing risk surrounding vendor, supplier, and other third party exposure 22:34 . The need for governance in managing data issues involving the use of AI 27:14 . Three ways in which CIS contributed to the 2026 DBIR 34:02 . How the 2026 DBIR informs the CIS Controls and parting actionable steps Resources 2026 Data Breach Investigations Report CIS Critical Security Controls® Episode 87: Marking 11 Years as a Verizon DBIR Contributor Mythos AI: What Actually Matters for Cybersecurity Leaders Applying the CIS Controls to Real‑World AI Environments CIS Community Defense Model 2.0 The Conti Leaks: A Case of Cybercrime’s Commercialization If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org .

  19. Episode 187: The Role of a CISO as a Strategic Storyteller from Cybersecurity Where You Are (video), opens in a new tab

    May 13, 202639 min

    In episode 187 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager discuss how the role of a CISO functions as a strategic storyteller of cyber risk while keeping the bigger picture in mind. Here are some highlights from our episode: 00:51 . Framing the conversation around CISOs' efforts to communicate with the business 02:01 . Translation: A nuanced practice of simplifying the story while still telling the truth 02:41 . The need for a CISO to bridge their organization's respective "culture gap(s)" 04:13 . Collaborative and dictatorial: Two different ways CISOs talk to a business 06:07 . The work of translation in motivating and informing action around perceived risk 07:03 . Security sampling: A story from Tony that reminds CISOs of the bigger picture 09:55 . Fewer wizards and more mechanics: What the cybersecurity industry needs today 12:20 . Two factors to consider: Politicking and the need to provide an accessible narrative 15:49 . Rapport and tradecraft as two critical tools supporting the role of a CISO 18:09 . Technical competence as a prerequisite for confidence in risk conversations 19:20 . The false sense of security from relying on comparative data with competitors 22:14 . The CISO as a strategic storyteller who helps the business make decisions 27:03 . The need for machinery to constantly rediscover and recreate trust 30:15 . A call to action for Boards: Build vernacular in cybersecurity risk space 35:03 . CISO as a strategic storyteller vs. CISO as an enforcer Resources CIS Critical Security Controls® CIS Community Defense Model 2.0 Episode 183: The Role of CISO in Supporting Risk Translation Episode 166: Foundations of Actuarial Science in Cyber Risk Episode 121: The Economics of Cybersecurity Decision-Making NICE Workforce Framework for Cybersecurity (NICE Framework) If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org .

  20. Episode 186: Strong Cyber Defense Starts with IT Operations from Cybersecurity Where You Are (video), opens in a new tab

    May 6, 202638 min

    In episode 186 of Cybersecurity Where You Are, Tony Sager sits down with Tony Krzyzewski , a CIS Critical Security Controls® (CIS Controls®) Ambassador for the Center for Internet Security® (CIS®). Together, they discuss how strong cyber defense starts with the fundamentals of IT operations. Here are some highlights from our episode: 00:45 . Introductions to Tony Krzyzewski and his background 02:19 . Tony Krzyzewski's first interaction with the CIS Controls 03:47 . IT operations: The foundation that makes strong cyber defense possible 06:20 . How an increasingly connected world makes the CIS Controls essential to cybersecurity 09:56 . The need for operations people to realize they're part of the cybersecurity solution 13:11 . The use of Implementation Groups to reduce overload on IT and security teams 16:52 . How the CIS Controls differ from "umbrella frameworks" like NIST CSF and ISO 27001 18:25 . CIS Controls mappings and how they help to simplify a surplus of good guidance 20:35 . How the CIS Controls support improvement programs and Board-level conversations 25:38 . Tony Krzyzewski's work in creating the CIS Controls Ambassador program 27:02 . Why a deep view of what's happening at CIS supports Tony Krzyzewski's efforts 30:11 . Growing international promotion of the CIS Controls and "doing the basics well" Resources CIS Critical Security Controls® CIS Controls Ambassador Spotlight: Tony Krzyzewski Episode 160: Championing SME Security with the CIS Controls Episode 168: Institutionalizing Good Cybersecurity Ideas Episode 172: Helping CISOs as a CIS Controls Ambassador Episode 181: Supply and Demand of Cybersecurity Ecosystems Guide to Implementation Groups (IG): CIS Critical Security Controls v8.1 Reasonable Cybersecurity Mappings to Security Frameworks Translations Policy Templates Securing the AI Ecosystem Begins at the Model Layer If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org .

Ranking source

Apple Podcasts rankings via the Mato Topic Intelligence Platform.

Observed September 20, 2026.

Apple and Apple Podcasts are trademarks of Apple Inc., registered in the U.S. and other countries.

Pairs with

What to do with a chart

01ShowsThe shows Mato publishesEvery public Mato show, its episodes, and the Apple placements it holds.02AI talentPick the voice before the formatThe live roster of hosts, each with samples you can listen to before you commit.03How it worksFrom an idea to a published episodeWhat Mato does between the brief and the feed, step by step.

Steal the structure, not the show

Bring this source into Mato to read its transferable patterns, then turn them into an original show for your own audience.

Hear a Mato showCreate a show inspired by this