Imagen de portada del espectáculo Secure Talk Podcast

Secure Talk Podcast

Podcast de Justin Beals

inglés

Technology

Disfruta 30 días gratis

4,99 € / mes después de la prueba.Cancela cuando quieras.

  • 20 horas de audiolibros / mes
  • Podcasts exclusivos
  • Podcast gratuitos
Prueba gratis

Sobre Secure Talk Podcast

Secure Talk reviews the latest threats, tips, and trends on security, innovation, and compliance. Host Justin Beals interviews leading privacy, security and technology executives to discuss best practices related to IT security, data protection and compliance. Based in Seattle, he previously served as the CTO of NextStep and Koru, which won the 2018 Most Impactful Startup award from Wharton People Analytics. He is the creator of the patented Training, Tracking & Placement System and the author of “Aligning curriculum and evidencing learning effectiveness using semantic mapping of learning assets,” published in the International Journal of Emerging Technologies in Learning (iJet). Justin earned a BA from Fort Lewis College.

Todos los episodios

260 episodios

Portada del episodio AI Is Eating Our Young: Data Center Revolts, Vanishing Junior Jobs & the EU AI Act

AI Is Eating Our Young: Data Center Revolts, Vanishing Junior Jobs & the EU AI Act

Communities are blocking $130 billion in AI data centers while the entry-level jobs that used to train the next generation of engineers quietly disappear. Chapters:  00:00:  The Backlash: 800 Groups, 49 States, $130B Blocked Gallup: 71% of Americans don't want a data center built near them (Gallup) Data center opposition tracker, Q1 2026 filings (referenced industry opposition data) CMMC as precedent for regulating critical infrastructure (DoW CMMC Phase 2 program) 04:30:  Why AI Is "Eating Our Young" in Education** Fran Berman & co-author's unpublished piece on the fraying mid-career pipeline Better Tech (MIT Press) — Chapter appendix: AI classroom syllabus and exercises 14:00:  Tech as Critical Infrastructure, Not a Religion Better Tech prologue: treating tech like food, water, roads, and the power grid GDPR (EU, 2018) as a case study in regulation done right — and its limits Vermont's data broker law as a case study in weak enforcement 26:00: Design Can't Be Bolted On Later** Self-driving cars and the hidden environmental cost of full autonomy Attack surface risk: denial-of-service on connected, self-driving fleets 34:00: Governing the Hybrid Human-AI Society** EU AI Act — risk-tiered regulation: unacceptable, high-risk, low-risk categories U.S. Equal Employment Opportunity Commission guidance on algorithmic hiring 41:00: The Hype Curve and the Data Center Reckoning** Western Massachusetts communities rejecting new AI data centers Efficiency vs. quality of life — Berman's closing argument Communities are saying no to AI's biggest infrastructure bet.In the first quarter of 2026 alone, local opposition blocked or delayed 75 data center projects worth roughly $130 billion — nearly matching all of 2025's total in a single quarter. Dr. Fran Berman, former head of the San Diego Supercomputer Center, argues the fix isn't more hype, it's precedent we already have. She points to CMMC itself: "If we can look at the defense supply chain and say this is critical infrastructure, it has to meet a bar, then we can look at the trillion dollars of compute being built into the middle of American life and say the same thing." AI isn't just displacing jobs.  It's starving the pipeline that builds senior engineers. Berman's sharpest warning is about who trains the next generation of professionals when entry-level coding and writing jobs — the ones junior people used to cut their teeth on — get automated away. She compares it to a surgeon who's never had supervised time in the operating room: "Unless you have that experience and the mentorship of more senior professionals, it's really hard" to develop the judgment senior engineers rely on. Good regulation needs more than a law on the books. Drawing on her book Better Tech (MIT Press), Berman walks through why GDPR worked where Vermont's data broker law didn't — and previews how the EU AI Act's risk-tiered approach (unacceptable, high-risk, low-risk) could become the model for governing hybrid human-AI decision-making, where, as she puts it, "the only accountable entities are humans." ✍️ About the Author Dr. Fran Berman is an award winning-data scientist, pioneer in public interest technology, and community leader and builder. She directs the Public Interest Technology Initiative at UMass Amherst and is a Faculty Associate at the Berkman Klein Center for Internet and Society at Harvard. Berman is former head the San Diego Supercomputer Center and served as Vice President for Research at Rensselaer Polytechnic Institute. She currently serves as a Trustee of the Alfred P. Sloan Foundation and is a popular regular panelist on public radio’s WAMC Roundtable with 400,000 monthly listeners in seven states. For more information, see https://www.franberman.com. Link to the book: https://mitpress.mit.edu/978026205488...

11 de ago de 2026 - 48 min
Portada del episodio Okta's Identity Chief: Most CISOs Can't Answer This AI Question

Okta's Identity Chief: Most CISOs Can't Answer This AI Question

Which AI agents can access what? Are those permissions even right? And can you stop a compromised agent mid-action? Okta's Dan Cinnamon says most enterprises can't answer any of the three. Dan Cinnamon has built software, run SAP GRC without an implementation partner, and now architects identity for one of the industry's biggest players. In this conversation with Justin Beals, he lays out why "discoverability" — simply knowing what agents exist and what they're touching — is the single biggest blind spot in enterprise AI right now, and why there's no silver bullet coming to fix it. They also dig into passkeys as a rare win-win security standard, the maturing MCP spec, and where the hard line on agent containment should actually sit. **Timestamps:** 0:00 Intro 1:20 From writing code to securing identity 4:45 Passkeys: the security/usability unicorn 8:30 The SAP GRC re-implementation story 14:10 Attribution and the agentic AI identity gap 18:55 How fast MCP has matured—and what's next 23:40 The 3 unanswered questions every enterprise faces 27:15 Granular identity vs. inherited permissions 32:00 Containment: moving controls closer to the data 36:45 Consent, provenance, and healthcare AI 40:30 Closing thoughts #CISO #AIstrategy, #enterprise #AIsecurity, #agentic #AIgovernance, #Okta #MCPstandard,  #zerotrust #AI agents

28 de jul de 2026 - 42 min
Portada del episodio Special Episode: CMMC Phase 2 SUSPENDED: What DOD Just Did, What It Really Means, and Why Little Changed

Special Episode: CMMC Phase 2 SUSPENDED: What DOD Just Did, What It Really Means, and Why Little Changed

The Pentagon paused CMMC Phase 2 with zero warning — and half the defense industrial base is celebrating for the wrong reason. When the Department of War suspended CMMC Phase 2 rollout with no notice, panic spread fast across the defense contractor community — but the requirement to secure CUI never went away. In this special roundtable, host Justin Beals brings together three CMMC insiders — Logan Therrien (C3PAO Chief Strategy Officer, retired Navy submariner), Lance Arnold (30-year industry veteran, just completed his own CMMC Level 2 journey), and Brian Hubbard (President, Evolved Cyber Solutions, CMMC assessor since 2015) — to separate what actually changed from what didn't. They break down the difference between the assessment requirement (paused) and the security implementation requirement (still very much alive under NIST 800-171), why "self-assessment" doesn't mean "no requirement," and what small businesses and primes should do right now instead of waiting for clarity that may not come for months. Sources Referenced:  DFARS 252.204-7021 (CMMC assessment clause) DFARS 252.204-7012 (NIST 800-171 compliance clause) DFARS 252.204-7019 (SPRS scoring requirement) 32 CFR Part 170 (CMMC Program Rule) 32 CFR Part 48 NIST SP 800-171 / NIST SP 800-172

17 de jul de 2026 - 46 min
Portada del episodio Considering Security, Compliance and Revenue with David Grazer

Considering Security, Compliance and Revenue with David Grazer

Most companies chase certifications to win deals — but what actually keeps customers is something no audit can measure. In this episode, vCISO David Grazer makes the case that trust is a measurable economic asset hiding in plain sight: your customer retention rate. Drawing on 15+ years inside high-growth tech companies, David explains why compliance frameworks are customer acquisition tools, not retention strategies — and how the gap between the two is costing businesses more than they realize. This episode is for founders, security leaders, and C-suite executives who want to connect their security and privacy programs to real business outcomes. You'll learn: → Why a SOC 2 or ISO 27001 certification is only the beginning of earning customer trust → How customer churn functions as one of the most honest security metrics available → Why MFA and common security controls often fail the users who need them most → What "Trust by Design" looks like in product development and AI programs → How to translate security risk into language that resonates with your CFO Chapters 00:00 Introduction to Secure Talk and Trust 03:42 David Grazer's Journey into Security and Privacy 08:09 Navigating Compliance and Customer Trust 12:49 The Role of Consulting in Security 18:07 Trust as a Measurable Economic Asset 23:42 Identity Management in the Entertainment Industry 26:09 The VC SO Model and Its Impact 29:13 The Evolution of Compliance Conversations 33:17 Exploring the Intersection of Technology and Society 🔔 Subscribe to SecureTalk for weekly conversations at the intersection of cybersecurity, compliance, and business strategy. #cybersecurity #compliance #CISO #trustbydesign #vciso #informationsecurity #GRC #dataprivacy

16 de jun de 2026 - 41 min
Soy muy de podcasts. Mientras hago la cama, mientras recojo la casa, mientras trabajo… Y en Podimo encuentro podcast que me encantan. De emprendimiento, de salid, de humor… De lo que quiera! Estoy encantada 👍
Soy muy de podcasts. Mientras hago la cama, mientras recojo la casa, mientras trabajo… Y en Podimo encuentro podcast que me encantan. De emprendimiento, de salid, de humor… De lo que quiera! Estoy encantada 👍
MI TOC es feliz, que maravilla. Ordenador, limpio, sugerencias de categorías nuevas a explorar!!!
Me suscribi con los 14 días de prueba para escuchar el Podcast de Misterios Cotidianos, pero al final me quedo mas tiempo porque hacia tiempo que no me reía tanto. Tiene Podcast muy buenos y la aplicación funciona bien.
App ligera, eficiente, encuentras rápido tus podcast favoritos. Diseño sencillo y bonito. me gustó.
contenidos frescos e inteligentes
La App va francamente bien y el precio me parece muy justo para pagar a gente que nos da horas y horas de contenido. Espero poder seguir usándola asiduamente.

Elige tu suscripción

Más populares

Premium

20 horas de audiolibros

  • Podcasts exclusivos

  • Disfruta los podcast de Podimo sin anuncios

  • Cancela cuando quieras

Disfruta 30 días gratis
Después 4,99 € / mes

Prueba gratis

Premium Plus

100 horas de audiolibros

  • Podcasts exclusivos

  • Disfruta los podcast de Podimo sin anuncios

  • Cancela cuando quieras

Disfruta 30 días gratis
Después 9,99 € / mes

Prueba gratis

Sólo en Podimo

Audiolibros populares

Preguntas frecuentes

Más preguntas y respuestas
Prueba 30 días gratis

Disfruta 30 días gratis. 4,99 € / mes después de la prueba. Cancela cuando quieras.