Welcome to video version of “Cybersecurity Where You Are,” the podcast of the Center for Internet Security® (CIS®). Cybersecurity affects us all — whether we’re online at home, managing a company, supporting clients, or running a state or local government. Join us on Wednesdays as Sean Atkinson, CISO at CIS, and Tony Sager, SVP & Chief Evangelist at CIS, discuss trends and threats, explore security best practices, and interview experts in the industry. Together, we’ll clarify these issues, c ...
…
continue reading
A pair study podcast on the new work of Ethical Creativity with hosts Nicholas Cole-Farrell, Dr. Dan Glass, and Sandee Bisson.
…
continue reading

1
Episode 132: Day One, Step One, Dollar One for Cybersecurity
34:35
34:35
Play later
Play later
Lists
Like
Liked
34:35In episode 132 of Cybersecurity Where You Are, Sean Atkinson is joined by Valecia Stocchetti, Sr. Cybersecurity Engineer of the CIS Critical Security Controls (CIS Controls) at the Center for Internet Security® (CIS®). Together, they discuss what the first day, step, and dollar of implementing a controls framework look like for organizations steppi…
…
continue reading

1
Episode 131: It Takes a Village to 'Reasonably' Secure SoCal
32:52
32:52
Play later
Play later
Lists
Like
Liked
32:52In episode 131 of Cybersecurity Where You Are, Tony Sager is joined by Stan Stahl, PhD, Founder and President of SecureTheVillage. Together, they discuss how SecureTheVillage, a nonprofit and inaugural Alan Paller Laureate Program awardee, is using a collaboration-driven approach to enhance reasonable cybersecurity awareness and practices within So…
…
continue reading

1
Episode 130: The Story and Future of CIS Thought Leadership
32:38
32:38
Play later
Play later
Lists
Like
Liked
32:38In episode 130 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager are joined by John Gilligan, President and Chief Executive Officer (CEO) of the Center for Internet Security® (CIS®). Set against the backdrop of the 2025 CIS Annual Full Staff Meeting, they celebrate 25 years of CIS, including the "serendipity" by which the company became …
…
continue reading

1
Episode 129: Embedding Cybersecurity in Project Management
32:18
32:18
Play later
Play later
Lists
Like
Liked
32:18In episode 129 of Cybersecurity Where You Are, Sean Atkinson discusses best practices for embedding cybersecurity in project management. Here are some highlights from our episode: 01:34. Elements for connecting the dots between cybersecurity risk assessment and project risk assessment 03:06. How our conceptualization of a project changes under a ze…
…
continue reading

1
Episode 128: How Cryptocurrency Is Used for Financial Fraud
35:17
35:17
Play later
Play later
Lists
Like
Liked
35:17In episode 128 of Cybersecurity Where You Are, Sean Atkinson is joined by Joshua Palsgraf, Senior Cyber Threat Intelligence (CTI) Analyst at the Center for Internet Security® (CIS®). Together, they examine how cyber threat actors use cryptocurrency for financial fraud and how professionals like Joshua track this illicit activity. Here are some high…
…
continue reading

1
Episode 127: Visible Ops as a Cybersecurity Foundation
37:45
37:45
Play later
Play later
Lists
Like
Liked
37:45In episode 127 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager are joined by Scott Alldridge, President and CEO of IP Services and the IT Process Institute. Together, they use Scott's book, "Visible Ops Cybersecurity: Enhancing Your Cybersecurity Posture with Practical Guidance," to discuss how visible IT operations (Visible Ops) provi…
…
continue reading

1
Episode 126: A Day in the Life of a CTI Analyst
36:28
36:28
Play later
Play later
Lists
Like
Liked
36:28In episode 126 of Cybersecurity Where You Are, Sean Atkinson is joined by Casey Cannon, Lead Cyber Threat Intelligence (CTI) Analyst at the Center for Internet Security® (CIS®). Together, they review what a regular day looks like for a CTI analyst. Here are some highlights from our episode: 01:46. How a service-oriented mindset factors into a CTI c…
…
continue reading

1
Episode 125: How Leadership Principles Influence CIS Culture
33:02
33:02
Play later
Play later
Lists
Like
Liked
33:02In episode 125 of Cybersecurity Where You Are, Sean Atkinson is joined by Waldo Perez, Human Resources Support Specialist at the Center for Internet Security® (CIS®); and Penny Davis, Sr. Manager of Leadership Development at CIS. Together, they use the CIS Leadership Principles and other examples from CIS to understand how leadership influences and…
…
continue reading

1
Episode 124: The Many Layers of a Malware Takedown Operation
32:43
32:43
Play later
Play later
Lists
Like
Liked
32:43In episode 124 of Cybersecurity Where You Are, Sean Atkinson is joined by Timothy Davis, Lead Cyber Threat Intelligence (CTI) Analyst at the Center for Internet Security® (CIS®). Together, they explore the many layers of a malware takedown operation. Here are some highlights from our episode: 01:58. A high-level overview of what a malware takedown …
…
continue reading

1
Episode 123: An Operational Playbook for Security Impact
43:59
43:59
Play later
Play later
Lists
Like
Liked
43:59In episode 123 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager are joined by Gina Chapman, Chief Operating Officer (COO) at the Center for Internet Security® (CIS®). Together, they use examples from CIS to identify elements of an operational playbook for making an impact in the cybersecurity industry. Here are some highlights from our …
…
continue reading

1
Episode 122: DeepSeek AI Security and Utility Considerations
37:12
37:12
Play later
Play later
Lists
Like
Liked
37:12In episode 122 of Cybersecurity Where You Are, Sean Atkinson is joined by Rian Davis, Associate Hybrid Threat Intelligence Analyst at the Center for Internet Security® (CIS®); and Timothy Davis, Lead Cyber Threat Intelligence (CTI) Analyst at CIS. Together, they discuss security and utility considerations surrounding the DeepSeek AI model. Here are…
…
continue reading

1
Episode 121: The Economics of Cybersecurity Decision-Making
40:50
40:50
Play later
Play later
Lists
Like
Liked
40:50In episode 121 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager are joined by Tyler Moore, Ph.D., Chair of Cyber Studies at the University of Tulsa. Together, they discuss the role of economics in cyber risk quantification and cybersecurity decision-making. Here are some highlights from our episode: 01:55. How incentives, market failure…
…
continue reading

1
Episode 120: How Contextual Awareness Drives AI Governance
32:22
32:22
Play later
Play later
Lists
Like
Liked
32:22In episode 120 of Cybersecurity Where You Are, Sean Atkinson explores how contextual awareness of generative artificial intelligence (GenAI) deployment in the business creates a foundation for AI governance strategy. Here are some highlights from our episode: 01:58. Why specificity is important when we use the term "AI" in the governance space 04:1…
…
continue reading

1
Episode 119: Multidimensional Threat Defense at Large Events
35:04
35:04
Play later
Play later
Lists
Like
Liked
35:04In episode 119 of Cybersecurity Where You Are, Sean Atkinson is joined by John Cohen, Executive Director of Countering Hybrid Threats at the Center for Internet Security® (CIS®). Together, they discuss the importance and provide examples of multidimensional threat defense as a means of securing large events. Here are some highlights from our episod…
…
continue reading

1
Episode 118: Preparing for Post-Quantum Cryptography
36:46
36:46
Play later
Play later
Lists
Like
Liked
36:46In episode 118 of Cybersecurity Where You Are, Sean Atkinson is joined by Andy Smith, Security Architect for BP and Instructor at the SANS Institute. Together, they review the state of post-quantum cryptography as well as share recommendations for how organizations and individuals can prepare to move into the post-quantum era. Here are some highlig…
…
continue reading

1
Episode 117: 2025 Cybersecurity Predictions from CIS Experts
33:43
33:43
Play later
Play later
Lists
Like
Liked
33:43In episode 117 of Cybersecurity Where You Are, Sean Atkinson reflects on the 2025 cybersecurity predictions of 12 experts at the Center for Internet Security® (CIS®), as shared on the CIS website. Here are some highlights from our episode: 01:40. Artificial intelligence (AI) as a means for crafting higher quality phishing emails 04:24. Zero trust w…
…
continue reading

1
Episode 116: AI-Enhanced Ransomware and Defending Against It
33:38
33:38
Play later
Play later
Lists
Like
Liked
33:38In episode 116 of Cybersecurity Where You Are, Sean Atkinson discusses the threat of AI-enhanced ransomware along with the use of generative artificial intelligence (GenAI) to defend against it. Here are some highlights from our episode: 02:10. How AI in the cybersecurity space has advanced over the past few years 05:12. Why cybercriminals are inco…
…
continue reading

1
Episode 115: Continuous Feedback as CIS Employee Culture
32:03
32:03
Play later
Play later
Lists
Like
Liked
32:03In episode 115 of Cybersecurity Where You Are, Sean Atkinson is joined by Carolyn Comer, Chief Human Resources Officer at the Center for Internet Security® (CIS®); Heidi Gonzalez, Sr. Employee Experience Specialist at CIS; and Jennifer Myers, Sr. Director of Learning and Development at CIS. With an in-person holiday open house and office party as t…
…
continue reading

1
Episode 114: 3 Board Chairs Reflect on 25 Years of Community
48:53
48:53
Play later
Play later
Lists
Like
Liked
48:53In episode 114 of Cybersecurity Where You Are, Tony Sager is joined by three past and current Board Chairs of the Center for Internet Security® (CIS®): Frank Reeder, CIS Director Emeritus and Founding Chair as well as Director of the National Cybersecurity Scholarship Foundation; John Gilligan, President and Chief Executive Officer of CIS; and Bobb…
…
continue reading

1
Episode 113: Cyber Risk Prioritization as Ransomware Defense
41:17
41:17
Play later
Play later
Lists
Like
Liked
41:17In episode 113 of Cybersecurity Where You Are, Tony Sager is joined by Phyllis Lee, VP of SBP Content Development at the Center for Internet Security® (CIS®); Adam Bobrow, Co-Founder and President of Veribo Analytics; and Sridevi Joshi, Co-Founder and CEO of Veribo Analytics. Together, they discuss how the Business Impact Analysis tool created by C…
…
continue reading

1
Episode 112: How SANS Fosters Action on Cybersecurity Trends
46:56
46:56
Play later
Play later
Lists
Like
Liked
46:56In episode 112 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager are joined by Rob T. Lee, Chief of Research and Head of Faculty at SANS Institute. Together, they discuss how SANS Institute applies an operational or "do" model of leadership to gather expertise, build shared purpose, and foster action on evolving cybersecurity trends. Her…
…
continue reading

1
Episode 111: Distilling a First Principle of Cybersecurity
47:04
47:04
Play later
Play later
Lists
Like
Liked
47:04In episode 111 of Cybersecurity Where You Are, Tony Sager is joined by Rick Howard, N2K Chief Security Officer and the Chief Analyst and Senior Fellow at The Cyberwire. Together, they discuss a first principle of cybersecurity proposed by Rick in his book, Cybersecurity First Principles: A Reboot of Strategy and Tactics. Here are some highlights fr…
…
continue reading

1
Episode 110: How Security Culture and Corporate Culture Mesh
41:38
41:38
Play later
Play later
Lists
Like
Liked
41:38In episode 110 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager are joined by Lee Noriega, Executive Director of the Cybersecurity Services Organization and Acting General Manager of Sales and Business Services at the Center for Internet Security® (CIS®); and Jerry Gitchel, founder of Leverage Unlimited and listener to Cybersecurity Whe…
…
continue reading

1
Episode 109: The Scariest Malware of 2024
38:42
38:42
Play later
Play later
Lists
Like
Liked
38:42In episode 109 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager are joined by Randy Rose, VP of Security Operations & Intelligence at the Center for Internet Security® (CIS®); and Theodore "TJ" Sayers, Director of Intelligence & Incident Response at CIS. Together, they examine the scariest malware of 2024 and share some recommendations …
…
continue reading

1
Episode 108: Gaming and Competition in Cybersecurity
40:48
40:48
Play later
Play later
Lists
Like
Liked
40:48In episode 108 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager are joined by Ed Skoudis, CEO of Counter Hack Challenges and President of SANS Technology Institute. Together, they discuss the evolution of gaming and competition in cybersecurity and how these activities help to make the industry stronger. Here are some highlights from ou…
…
continue reading

1
Episode 107: Continuous Improvement via Secure by Design
37:36
37:36
Play later
Play later
Lists
Like
Liked
37:36In episode 107 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager are joined by Steve Lipner, Executive Director of SAFECode. Together, they discuss how software development organizations can use principles of "secure by design" to get on a track of continuous improvement. Here are some highlights from our episode: 01:38. Steve's backgrou…
…
continue reading

1
Episode 106: How to Avoid Falling for a Donation Scam
32:05
32:05
Play later
Play later
Lists
Like
Liked
32:05In episode 106 of Cybersecurity Where You Are, Sean Atkinson is joined by Chris Smith, Social Media Specialist at the Center for Internet Security® (CIS®). Together, they use a donation scam about a natural disaster to advise how you can stay safe against this type of cyber threat. Here are some highlights from our episode: 00:49. Why it's importan…
…
continue reading

1
Episode 105: Context in Cyber Risk Quantification
33:19
33:19
Play later
Play later
Lists
Like
Liked
33:19In episode 105 of Cybersecurity Where You Are, Sean Atkinson discusses the importance of context in maturing how you use cyber risk quantification to build cases for risk treatment strategies. Here are some highlights from our episode: 01:56. The inspiration for an episode on cyber risk quantification 02:38. How to situate risk quantification in yo…
…
continue reading

1
Episode 104: Inside the First Year of a Cybersecurity Career
32:56
32:56
Play later
Play later
Lists
Like
Liked
32:56In episode 104 of Cybersecurity Where You Are, Sean Atkinson is joined by Kennidi Ortega, Information Security Analyst at the Center for Internet Security® (CIS®). Together, they explore the experience of a first-year analyst and how they might make the most of getting started in a cybersecurity career. Here are some highlights from our episode: 01…
…
continue reading

1
Episode 103: Education vs. Experience in Cybersecurity
31:16
31:16
Play later
Play later
Lists
Like
Liked
31:16In episode 103 of Cybersecurity Where You Are, Sean Atkinson examines education and experience as pathways for new professionals to enter the cybersecurity industry. Here are some highlights from our episode: 01:42. What's motivating Sean to talk about this topic 03:32. The value of cybersecurity degrees 05:17. The pros and cons of degree programs …
…
continue reading

1
Episode 102: The Sporty Rigor of CIS Controls Accreditation
36:34
36:34
Play later
Play later
Lists
Like
Liked
36:34In episode 102 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager are joined by the following guests: Charity Otwell, Director of the CIS Critical Security Controls® (CIS Controls®) at the Center for Internet Security® (CIS®) Lawrence Cruciana, President of Corporate Information Technologies (CorpInfoTech) Together, they discuss the "spor…
…
continue reading

1
Episode 101: Visualizing Attack Paths in Active Directory
34:14
34:14
Play later
Play later
Lists
Like
Liked
34:14In episode 101 of Cybersecurity Where You Are, Sean Atkinson is joined by Justin Kohler, Vice President of Products at SpecterOps, and Jonathan Parfait, Technical Account Manager at SpecterOps. Together, they discuss how the visualization of attack paths in Active Directory helps organizations to better contextualize risks to their enterprise secur…
…
continue reading

1
Episode 100: Celebrating 100 Episodes and Looking Ahead
41:59
41:59
Play later
Play later
Lists
Like
Liked
41:59In episode 100 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager are joined by David Bisson, Sr. Content Marketing Strategist at the Center for Internet Security® (CIS®). Together, they celebrate the first 100 episodes of Cybersecurity Where You Are and discuss where the podcast might go in the future. Here are some highlights from our e…
…
continue reading

1
Episode 99: How Cyber-Informed Engineering Builds Resilience
34:23
34:23
Play later
Play later
Lists
Like
Liked
34:23In episode 99 of Cybersecurity Where You Are, Sean Atkinson is joined by Marcus Sachs, SVP and Chief Engineer at the Center for Internet Security® (CIS®). Together, they discuss how cyber-informed engineering builds resilience to the potential failure of a digital system into new and existing engineering products. Here are some highlights from our …
…
continue reading

1
Episode 98: Transparency as a Tool to Combat Insider Threats
35:50
35:50
Play later
Play later
Lists
Like
Liked
35:50In episode 98 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager are joined by Roger Grimes, Data-Driven Defense Evangelist at KnowBe4. Together, they embrace transparency as a vehicle for the cybersecurity industry to better defend against insider threats. Here are some highlights from our episode: 01:28. How KnowBe4 detected an insider …
…
continue reading

1
Episode 97: How Far We've Come preceding CIS's 25th Birthday
51:00
51:00
Play later
Play later
Lists
Like
Liked
51:00In episode 97 of Cybersecurity Where You Are, Tony Sager is joined by the following guests: Dr. Ramon Barquin, Board Member at the Center for Internet Security® (CIS®) and President and Chief Executive Officer at Barquin International Franklin Reeder, Director Emeritus and Founding Chair of CIS as well as Director of the National Cybersecurity Scho…
…
continue reading

1
Episode 96: Making Continuous Compliance Actionable for SMBs
43:09
43:09
Play later
Play later
Lists
Like
Liked
43:09In episode 96 of Cybersecurity Where You Are, co-hosts Sean Atkinson and Tony Sager are joined by Tarah Wheeler, CEO of Red Queen Dynamics. Together, they discuss ongoing efforts to translate continuous compliance into something actionable for small- to medium-sized businesses (SMBs). Here are some highlights from our episode: 03:11. The philosophy…
…
continue reading

1
Episode 95: AI Augmentation and Its Impact on Cyber Defense
34:59
34:59
Play later
Play later
Lists
Like
Liked
34:59In episode 95 of Cybersecurity Where You Are, Sean Atkinson is joined by Randy Rose, VP of Security Operations & Intelligence at the Center for Internet Security® (CIS®). Together, they discuss AI augmentation in terms of how cyber defenders are using generative artificial intelligence to enhance their capabilities. Here are some highlights from ou…
…
continue reading

1
Episode 94: Community Defense at the ISAC Annual Meeting
37:06
37:06
Play later
Play later
Lists
Like
Liked
37:06In episode 94 of Cybersecurity Where You Are, Tony Sager is joined by the following guests from the Center for Internet Security® (CIS®): Carlos Kizzee, SVP of Multi-State Information Sharing and Analysis Center® (MS-ISAC®) Strategy & Plans Karen Sorady, VP of MS-ISAC Strategy & Plans Greta Noble, Director of Community Engagement Together, they dis…
…
continue reading

1
Episode 93: Keeping Societal Confidence in a Connected World
29:27
29:27
Play later
Play later
Lists
Like
Liked
29:27In episode 93 of Cybersecurity Where You Are, co-hosts Sean Atkinson and Tony Sager are joined once again by John Cohen, Executive Director of Countering Hybrid Threats at the Center for Internet Security® (CIS®). Together, they discuss a whole-of-society approach to help make the U.S. public resilient against multidimensional threats in our connec…
…
continue reading

1
Episode 92: A Framework to Counter Evolving Cyber Threats
33:19
33:19
Play later
Play later
Lists
Like
Liked
33:19In episode 92 of Cybersecurity Where You Are, co-hosts Sean Atkinson and Tony Sager are joined by John Cohen, Executive Director of Countering Hybrid Threats at the Center for Internet Security® (CIS®). Together, they discuss "Enhancing Safety in the Connected World — A National Framework for Action," a multi-year project to help law enforcement an…
…
continue reading

1
Episode 91: What You Need to Know about CIS Controls v8.1
33:07
33:07
Play later
Play later
Lists
Like
Liked
33:07In episode 91 of Cybersecurity Where You Are, Sean Atkinson is joined by Charity Otwell, Director of the CIS Critical Security Controls® (CIS Controls®) at the Center for Internet Security® (CIS®). Together, they discuss what you need to know about the release of CIS Controls v8.1. Here are some highlights from our episode: 01:17. What you can expe…
…
continue reading

1
Episode 90: Migrating to the Cloud with Control Continuity
31:05
31:05
Play later
Play later
Lists
Like
Liked
31:05In episode 90 of Cybersecurity Where You Are, co-hosts Sean Atkinson and Tony Sager are joined by the following guests: Charity Otwell, Director of the CIS Critical Security Controls® (CIS Controls®) at the Center for Internet Security® (CIS®) Mia LaVada, Product Manager of CIS Benchmarks and Cloud at CIS Don Freeley, VP of IT Services at CIS Toget…
…
continue reading

1
Episode 89: How Threat Actors Are Using GenAI as an Enabler
31:17
31:17
Play later
Play later
Lists
Like
Liked
31:17In episode 89 of Cybersecurity Where You Are, co-host Sean Atkinson is joined by the following guests: Rian Davis, Elections Cyber Threat Intelligence Intern at the Center for Internet Security® (CIS®) Timothy Davis, Sr. Elections Cyber Threat Intelligence Analyst at CIS Together, they discuss how cyber threat actors (CTAs) are using generative art…
…
continue reading

1
Episode 88: The Evolution of the Role of a CISO
30:02
30:02
Play later
Play later
Lists
Like
Liked
30:02In episode 88 of Cybersecurity Where You Are, co-host Sean Atkinson discusses the evolving role of a chief information security officer (CISO). Here are some highlights from our episode: 02:47. Why communication is a core competency for CISOs 08:35. How to take a balanced approach when evaluating an organization's implementation of artificial intel…
…
continue reading

1
Episode 87: Marking 11 Years as a Verizon DBIR Contributor
38:41
38:41
Play later
Play later
Lists
Like
Liked
38:41In episode 87 of Cybersecurity Where You Are, co-host Tony Sager is joined by the following guests: Charity Otwell, Director of the CIS Critical Security Controls® (CIS Controls®) at the Center for Internet Security® (CIS®) Philippe Langlois, Senior Principal, Security Risk Management and Author of the Verizon Data Breach Investigations Report (DBI…
…
continue reading

1
Episode 86 Evangelizing CIS's Message at RSAC 2024
34:07
34:07
Play later
Play later
Lists
Like
Liked
34:07In episode 86 of Cybersecurity Where You Are, co-host Sean Atkinson is live once again from Booth 4319 at RSA Conference (RSAC) 2024. 00:57. Sean chats with Mat Everman, Information Security Operations Manager, about his talk, "Shades of Purple: Getting Started and Making Purple Teaming Possible." They discuss some of the questions Mat received fol…
…
continue reading

1
Episode 85: Reenergizing Collective Action at RSAC 2024
50:51
50:51
Play later
Play later
Lists
Like
Liked
50:51In episode 85 of Cybersecurity Where You Are, co-hosts Sean Atkinson and Tony Sager are live from Booth 4319 at RSA Conference (RSAC) 2024. Together, they discuss how events like RSAC 2024 reenergize collective action in the cybersecurity industry. They begin by noting how resources such as the CIS Community Defense Model (CDM) bring more data and …
…
continue reading

1
Episode 84: Why We Need to Define Reasonable Cybersecurity
40:08
40:08
Play later
Play later
Lists
Like
Liked
40:08In episode 84 of Cybersecurity Where You Are, co-host Tony Sager is joined by Brian de Vallance, Senior Advisor at Cambridge Global Advisors; and Phyllis Lee, VP of Security Best Practices (SBP) Content Development at the Center for Internet Security® (CIS®). Together, they discuss the notion of reasonable cybersecurity. They begin by providing som…
…
continue reading

1
Episode 83: Why Meeting in Person Matters to CIS Employees
29:46
29:46
Play later
Play later
Lists
Like
Liked
29:46In episode 83 of Cybersecurity Where You Are, co-host Sean Atkinson is joined by nearly 20 employees at the Center for Internet Security® (CIS®). Together, they discuss the value of meeting in person to CIS workplace culture. With the company's 2024 Annual Full Staff Meeting in Orlando, FL, as their backdrop, they explore how personal relationships…
…
continue reading