Cybersecurity Where You Are (audio)
In episode 188 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager sit down with Philippe "Phil" Langlois [https://www.linkedin.com/in/infosec-philippe-langlois], Data Breach Investigations Report (DBIR) Author at Verizon; and Charity Otwell [https://www.linkedin.com/in/charity-otwell], Director of the CIS Critical Security Controls® (CIS Controls®) at the Center for Internet Security® (CIS®). Together, they discuss some of the top insights of the 2026 DBIR and how CIS contributed to the publication. Here are some highlights from our episode: * 00:50. Introductions to Phil and Charity * 02:46. Vulnerability exploitation as the most common attack vector * 05:25. The role of artificial intelligence (AI) in threat actors' natural system thinking * 07:03. The need for clear governance and responsibility around vulnerability management * 08:58. Insight into the types of techniques threat actors research using frontier AI models * 13:43. A trending drop in ransomware payouts and organizations willing to pay attackers * 14:59. Why a healthy dose of distrust goes a long way in assessing attackers' claims of victims * 16:24. How two ransomware groups stand out above the norm * 17:49. The ongoing risk surrounding vendor, supplier, and other third party exposure * 22:34. The need for governance in managing data issues involving the use of AI * 27:14. Three ways in which CIS contributed to the 2026 DBIR * 34:02. How the 2026 DBIR informs the CIS Controls and parting actionable steps Resources * 2026 Data Breach Investigations Report [https://www.verizon.com/business/resources/reports/dbir/] * CIS Critical Security Controls® [https://www.cisecurity.org/controls?utm_source=cwya&utm_medium=audio&utm_campaign=cis&utm_content=26-cis-episode_188-0520_podcast] * Episode 87: Marking 11 Years as a Verizon DBIR Contributor [https://www.cisecurity.org/insights/podcast/episode-87-marking-11-years-as-a-verizon-dbir-contributor?utm_source=cwya&utm_medium=audio&utm_campaign=cis&utm_content=26-cis-episode_188-0520_podcast] * Mythos AI: What Actually Matters for Cybersecurity Leaders [https://www.cisecurity.org/insights/blog/mythos-ai-what-actually-matters-for-cybersecurity-leaders?utm_source=cwya&utm_medium=audio&utm_campaign=cis&utm_content=26-cis-episode_188-0520_podcast] * Applying the CIS Controls to Real‑World AI Environments [https://www.cisecurity.org/insights/blog/applying-controls-real-world-ai-environments?utm_source=cwya&utm_medium=audio&utm_campaign=cis&utm_content=26-cis-episode_188-0520_podcast] * CIS Community Defense Model 2.0 [https://www.cisecurity.org/insights/white-papers/cis-community-defense-model-2-0?utm_source=cwya&utm_medium=audio&utm_campaign=cis&utm_content=26-cis-episode_188-0520_podcast] * The Conti Leaks: A Case of Cybercrime’s Commercialization [https://www.cisecurity.org/insights/blog/the-conti-leaks-a-case-of-cybercrimes-commercialization?utm_source=cwya&utm_medium=audio&utm_campaign=cis&utm_content=26-cis-episode_188-0520_podcast] If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org [podcast@cisecurity.org].
189 episodios
Comentarios
0Sé la primera persona en comentar
¡Regístrate ahora y únete a la comunidad de Cybersecurity Where You Are (audio)!