TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    News

    Enterprise Security Weekly (Audio)

    News, analysis, and insights into enterprise security. We put security vendors under the microscope, and explore the latest trends that can help defenders succeed. Hosted by Adrian Sanabria. Co hosts: Katie Teitler-Santullo, Ayman Elsawah, Jason Wood, Jackie McGuire, Sean Metcalf.

    Advertise

    Copyright: © Attribution-Noncommercial-Share Alike 2.5 Generic

    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    Cyber Resilience with Cohesity, When to use AI for Writing, and the News - Rob Sadowski - ESW #477 Sep 21, 2026
    Show notes

    Interview with Rob Sadowsky from Cohesity

    Global Cyber Resilience Report: Cyber Recovery Plans Weren't Designed for this Moment

    Cyber recovery plans weren't designed for this moment. Most were built around assumptions that made sense when they were written: incidents could be understood, dependencies mapped, recovery could follow a predictable sequence, and decision-makers would have enough information to act.

    In practice, major cyber incidents unravel those assumptions. AI and autonomous agents are creating new paths to compromise, while cloud and SaaS expansion increases the systems, services, and dependencies involved in recovery. Vulnerabilities are discovered and weaponized faster than ever, and AI is accelerating that cycle. As incidents unfold, scope expands, dependencies appear only when they break, and recovery plans no longer match reality.

    With assumptions under greater strain, confidence is beginning to erode. This year, the percentage of survey respondents reporting complete confidence in their cyber resilience strategy fell.

    To understand how recovery unfolds today, Cohesity commissioned Vanson Bourne to survey 3,200 IT and security decision-makers at organizations with 1,000 or more employees across 11 countries.

    This report examines where recovery becomes more difficult than expected, the obstacles organizations encounter, how they define and test a Minimum Viable Company (MVC), and how AI is reshaping cyber threats and cyber resilience.

    https://www.cohesity.com/dm/global-cyber-resilience-report/

    This segment is sponsored by Cohesity. Visit https://securityweekly.com/cohesity to learn more about them!

    Topic: When should we use AI for writing and when should we avoid it?

    I've had an essay in draft form for a month now, trying to get my feelings across on why AI writing drives me so crazy. I struggled to put it into words.

    Fortunately, Charity Majors figured out how to put it into words and I think she nailed not just how I feel about AI, but the reasons why I feel so strongly about it. She uses a scale to help explain this, with "personal" at one end and "functional" at the other.

    https://charity.wtf/p/confessions-of-an-unrepentant-slop

    When I ask AI to create a company profile for me, 10 minutes before I meet with them, I don't need poetry - just facts. But when I read something that is supposedly someone's opinions and analysis on a topic, and it's clearly 100% AI-generated, I angrily dismiss it.

    I love that this writeup isn't just an "I hate slop" rant - it actually quantifies why a personal touch matters and how to gauge when it is necessary and when outsourcing the task to AI is totally fine.

    In both cases, Charity notes that quality matters. My most recent complaints come from cases where things are not only clearly written by AI, but where quality went out the window and they're unrecognizable as a human-readable language.

    And yes, I brought an example: https://dispatch.cybersecurityhq.com/p/escalation-voided-on-construct-failure-timing-condition-placed-under-review

    Weekly Enterprise News

    Finally, in the enterprise security news,

    1. We check the vibes, funding, and acquisitions
    2. Tenable now has Mythos built-in???
    3. We check in on how vulnerability remediation is going
    4. Microsoft is creating a code of conduct for AI
    5. OpenAI just got called to the principal's office
    6. Booz Allen created new cybersecurity AI benchmarks
    7. 50% of CISOs see Mythos as a sign to resign???
    8. Ayman read the latest Anthropic AI misuse report
    9. MIT explains the 12 possible AI outcomes (very ominous)
    10. a 9-year old decided to promote his YouTube account… with his dad's corporate card

    All that and more, on this episode of Enterprise Security Weekly.

    Visit https://www.securityweekly.com/esw for all the latest episodes!

    Show Notes: https://securityweekly.com/esw-477


    Safely exploiting vulnerabilities at scale, TVs attack privacy, and the news. - Snehal Antani - ESW #476 Sep 14, 2026
    Show notes

    Interview with Snehal Antani

    Snehal Antani, CEO and co-founder of Horizon3 joins us to talk about how automated validation can help with exposure management. As vulnerability counts spike, security teams are looking for a way to prioritize. Automated penetration testing offers a way to quickly separate exploitable vulnerabilities from the rest.

    This segment is sponsored by Horizon3. Visit https://securityweekly.com/horizon3 to learn more about them!

    Topic Segment - SmartTVs and Privacy

    For this week's topic segment, we explore privacy and TVs. LG has been in the news for allegedly collecting data from its customers, but the facts are unclear.

    We share our recent experiences and dive into some of the primary concerns and theories about what's going on here.

    If you want to opt out of some of your TV's data collection, Consumer Reports has a collection of instructions for a variety of TV platforms.

    Weekly Enterprise News

    Finally, in the enterprise security news,

    1. We check the vibes
    2. We check finding and acquisitions
    3. Nightmare Eclipse or Good Night of Sleep Eclipse?
    4. Update on Anthropic's Glasswing project
    5. How long would it take for a mobile phone worm to spread?
    6. Don't expose SSH to the public Internet
    7. Massive amounts of cryptocurrency continue to get stolen
    8. Did you actually read your third party's SOC 2?
    9. Your boss may be reading your AI chat history

    All that and more, on this episode of Enterprise Security Weekly.

    Visit https://www.securityweekly.com/esw for all the latest episodes!

    Show Notes: https://securityweekly.com/esw-476


    Shadow AI Epidemic: Uncovering Agents on the Endpoint, British Library Breach, & News - Amit Assaraf - ESW #475 Sep 07, 2026
    Show notes

    Interview - Amit Assaraf

    As employees rapidly adopt local AI models, autonomous agents, and browser extensions to boost productivity, enterprise endpoints are quietly accumulating unchecked security risks. This episode explores how traditional EDR solutions miss non-binary software, leaving critical blind spots for prompt injection and data exfiltration. Discover how Cortex Agentic Endpoint Security (AES) uses LLM-based classifiers and an AI powered risk engine to surface shadow AI and protect the modern workspace without stalling innovation.

    This segment is sponsored by Palo Alto Networks. Visit https://securityweekly.com/paloalto to learn more about them!

    Topic - The British Library Cyber-Attack

    For this week's topic segment, we're discussing the British Library cyber-attack.

    In October 2023, the British Library, one of the largest libraries in the world, was breached by the Rhysida ransomware group. The attack encrypted systems across the organization, led to over 500,000 files being leaked, and set off a recovery effort that consumed a significant portion of the Library's £17.5 million cash reserves. With no clear end date, this is a story of what could happen when all of an organization's tech debt comes due at once.

    Resources

    • https://www.defendersinitiative.com/p/breach-lessons-the-2023-british-library
    The Weekly Enterprise News

    Finally, in the enterprise security news,

    1. We check the vibes
    2. the funding
    3. the acquisitions
    4. and the closures
    5. is the vulnpocalypse real, or not?
    6. TeamPCP finds out why being perpetually online isn't great if you're doing cybercrimes
    7. millions of IDs get leaked online
    8. What's the bigger story: Huggingface and NVIDIA or Microduck?
    9. Dyson enters a new product category. Try to guess what it is without cheating and looking it up before the end of the episode!

    All that and more, on this episode of Enterprise Security Weekly.

    Visit https://www.securityweekly.com/esw for all the latest episodes!

    Show Notes: https://securityweekly.com/esw-475


    Life as a CISO in Hollywood: Keeping New Films Leak-Free & 4 Black Hat Interviews - Dan Meacham, Ellen Boehm, Ronan Murphy, Frank Vukovits, John Hultquist - ESW #474 Aug 31, 2026
    Show notes

    Interview with Dan Meacham, CISO at Legendary Entertainment

    Dan Meacham joined us to share a preview of his leadership panel at InfoSec World. At this CRA event in October, Dan will be discussing The Augmented Defender - What AI Actually Changes on the Front Line with Daniel Bowden, the Global CISO at Marsh.

    Dan dives into the unique world of securing data and assets when film production is largely handled by partners and contractors, working from systems you'll likely have limited access to and definitely can't install agents on. It's a fascinating conversation you should check out!

    Visit https://securityweekly.com/infosecworld2026 and save 30% on your ISW pass with code: ISW26-SWSAVINGS

    Black Hat Interview 1 - Google Cloud

    Outpacing the Adversary with AI Threat Defense - Black Hat interview with John Hultquist, Chief Analyst, Google Threat Intelligence Group at Google

    The cybersecurity landscape is undergoing a radical shift. AI is no longer just a productivity accelerator for developers and analysts—it has become actively weaponized by sophisticated threat actors to discover and exploit vulnerabilities at unprecedented speed. We'll discuss Google's own approach to combating today's threats and the need for security teams to transform vulnerability management with machine-speed defense.

    Segment Resources:

    • https://cloud.google.com/blog/products/identity-security/introducing-google-ai-threat-defense
    • https://services.google.com/fh/files/misc/ebookgooglecloudsecurityaithreatdefense.pdf
    • https://services.google.com/fh/files/misc/whitepapercombatingaidriventhreatsgooglemachinespeed_defense.pdf

    This segment is sponsored by Google Cloud. Visit https://securityweekly.com/googlebh to learn more!

    Black Hat Interview 2 - Forcepoint

    Decoding Agentic: Securing the Data Layer AI Just Set on Fire - Black Hat interview with Ronan Murphy, Chief Data Strategy Officer of Forcepoint

    AI didn't ask permission — and it permanently changed what data risk looks like. Forcepoint Chief Data Strategy officer and member of the Artificial Intelligence Advisory Council in Ireland, shares insights on a clear call to action for agentic enterprises: stop locking AI down and start securing it where the risk actually lives, in the data itself. Learn why data trust is the foundation of the agentic era and how the world's leading enterprises are ending the false choice between AI innovation and data safety.

    Segment Resources:

    • https://www.forcepoint.com/resources/ebooks/enterprise-guide-ai-data-security
    • https://www.forcepoint.com/blog/insights/forcepoint-announces-ai-data-security

    This segment is sponsored by Forcepoint. Visit https://securityweekly.com/forcepointbh to learn more!

    Black Hat Interview 3 - Keyfactor

    From Secrets to Verified Workload Identity—at Enterprise Scale - Black Hat interview with Ellen Boehm, SVP, Strategy & AI Innovation at Keyfactor

    As AI agents become autonomous participants inside enterprise environments, organizations can no longer rely on static credentials and traditional identity models to establish trust. Enterprise AI is driving a shift from possession-based access to cryptographically verified identity, as AI agents, cloud-native workloads, and automated services increasingly make decisions and interact with critical systems. In this discussion, we'll discuss why organizations need to continuously establish trust, govern machine identities and cryptography, and build a resilient foundation for securing AI across increasingly dynamic environments.

    Segment Resources:

    • https://www.keyfactor.com/blog/ai-agents-the-identity-problem-nobody-owns-yet/
    • https://www.keyfactor.com/education-center/what-is-trust-infrastructure/
    • https://www.keyfactor.com/resources/topic/col/products/the-trust-control-plane?pflpid=60788&pfsid=HsCXvwPWB1

    This segment is sponsored by Keyfactor. Visit https://securityweekly.com/keyfactorbh to learn more!

    Black Hat Interview 4 - Delinea

    Delinea Delivers Runtime Authorization for AI Agents, Closing Access Control Gap - Black Hat interview with Frank Vukovits, Chief Security Scientist at Delinea

    As AI agents move from experiments to autonomous operators inside production databases, cloud consoles, and Kubernetes clusters, enterprises face a new problem: agents with legitimate credentials taking actions no one authorized. Frank breaks down why verifying access at connection time is no longer enough and what it takes to enforce policy on every agent action before it executes. He explains how runtime authorization closes the gap between hiding credentials and actually controlling what agents do once they're inside a session.

    This segment is sponsored by Delinea. Visit https://securityweekly.com/delineabh to learn more!

    Visit https://www.securityweekly.com/esw for all the latest episodes!

    Show Notes: https://securityweekly.com/esw-474


    Can employees safely use AI agents? AI pentesting agent liabilities, and the news - Rob Allen - ESW #473 Aug 24, 2026
    Show notes

    Interview with Rob Allen from Threatlocker

    Safely enabling agentic AI for Businesses

    OpenClaw was the wakeup call and businesses wanted to know how to block it. "Easy," Rob Allen said, "it's already blocked if you're using Threatlocker." Now that things have settled down a bit, those same businesses want to allow their employees to experiment with agents. We discuss how they can do it safely.

    This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them!

    Topic Segment

    For this week's topic segment, we're discussing AI pentesting agents and how likely they are to get you into big legal trouble. You came home from Black Hat with a new, shiny AI pentesting agent. How can you be sure it isn't hacking the wrong company?

    News Segment

    Finally, in the enterprise security news,

    1. we check the vibes
    2. New MCP standard and AI text watermarking
    3. what does combatting "cyber-enabled crime" mean?
    4. A closer look at Cl0p
    5. One 3rd party was responsible for all the AI sandbox escapes and hacking
    6. reports
    7. vulnerabilities
    8. Comcast can track your movements with WiFi
    9. A novel solution to the AI datacenter water use concerns

    All that and more, on this episode of Enterprise Security Weekly.

    Visit https://www.securityweekly.com/esw for all the latest episodes!

    Show Notes: https://securityweekly.com/esw-473


    Sandbox Escapes with Rubrik's Zero Labs, AI recorders eroding privacy, and the news - Joe Hladik - ESW #472 Aug 17, 2026
    Show notes

    Interview with Jon Hladik - ChatMate

    Imagine a user asks an LLM a question about a document. An attacker then gains an interactive prompt on the user's chat session, enabling the attacker to instruct the AI assistant to take actions on behalf of the victim. That is exactly the capability researchers at Rubrik Zero Labs were able to demonstrate in a recent study designed to test the bounds of LLM security.

    Join Joe Hladik, Head of Rubrik Zero Labs, as he breaks down the discovery of "Remote Prompt Execution," a novel vulnerability class that enabled full takeovers of Microsoft Copilot sessions through sandbox escapes. He explores the technical journey behind the eight critical CVEs uncovered by Rubrik Zero Labs and discusses the broader implications for securing generative AI assistants within enterprise environments. This interview highlights the groundbreaking research that earned a $48,000 bounty and featured as a premier briefing at Black Hat USA.

    Segment Resources:

    • Find more research from Rubrik Zero Labs
    • Rubrik Zero Labs' Black Hat session
    • Demo of the ChatMate attack in action

    This segment is sponsored by Rubrik. Visit https://securityweekly.com/rubrik to learn more about them!

    Topic Segment - AI Notetakers and Recorders

    AI notetakers are built into everything now, and hardware-based AI recorders are becoming mainstream as well. Is privacy over in the workplace? Adrian, Jackie, Katie, and Tyler discuss.

    Questions enterprises should be asking:

    1. Are employees recording or transcribing meetings?
    2. Does this policy change if non-employees (external parties) are present?
    3. Is consent asked for/given?
    4. Is the context of the conversation taken into consideration?
    5. Is the geographic/legal/political context of the external party taken into account?
    6. Have you done your due diligence on third parties hosting/storing these recordings and transcriptions?
    7. Was your due diligence a SOC 2, or real, actual evidence-based due diligence?
    8. Do these third parties have an option to allow you to store/manage your own recordings in a place of your choosing, or does it have to be hosted by the AI recording/transcription company?
    News Segment

    Finally, in the enterprise security news,

    1. we check the vibes
    2. and the funding, and the acquisitions
    3. seriously, don't mess with the wifi on planes
    4. 181,000 meetings were left wide open
    5. the sandbox escapes are getting ridiculous
    6. research on how reliable AI-generated patches are
    7. research on what attackers do after they get a shell
    8. research on how cybercriminals are using AI agents
    9. research on how vulnerable datacenters are
    10. and finally, what's a "mouthpad"?
    11. Stick around till the end of the news segment to find out!

    All that and more, on this episode of Enterprise Security Weekly.

    Visit https://www.securityweekly.com/esw for all the latest episodes!

    Show Notes: https://securityweekly.com/esw-472


    Three interviews: system fragility, operational clarity, and Identity for AI agents - Todd Thiemann, Robin Macfarlane, Kyle Sandy - ESW #471 Aug 10, 2026
    Show notes

    Interview 1: Robin Macfarlane from RRMac Associats

    The Mattress Money Principle: What a 50-Year Veteran Knows About System Fragility

    In this interview, Robin and Adrian discuss how technology has evolved over the past 50 years. Despite massive technological changes over the decades: the PC revolution, the Internet, smartphones, the Cloud, and now Generative AI - the majority of financial institutions still use mainframes and midrange machines. Why?

    We explore the reasons why older technology persists alongside the new and the lessons retiring technologists can pass on to new generations inheriting an increasingly diverse tech landscape.

    Interview 2 with Kyle Sandy from Logically

    Operational Clarity as the New Customer Experience

    Kyle Sandy joins Adrian to discuss how prioritizing resilience affects how organizations should plan for incident response. In the past, security teams were focused on prevention and limiting breach damage. Today, boards want to know how long it will take to recover operations.

    The interview wraps up with a discussion of the right and wrong way to handle a breach and the three most important things every company must get right in order to handle an incident well.

    Interview 3 with Todd Thiemann from Omdia

    AI Agents and Identity Security: How Enterprises Are Rewriting the Rules

    Todd joins ESW with some eye-opening survey insights on the topic of IAM for AI agents. While cybersecurity conversations about internal AI use often revolve around the SOC and security operations, Omdia surveyed identity professionals for a more holistic enterprise perspective.

    Unsurprisingly, AI agent use is as diverse as enterprise business units. The surprises are around where the budget comes from for these AI projects, and how authentication is handled.

    Visit https://www.securityweekly.com/esw for all the latest episodes!

    Show Notes: https://securityweekly.com/esw-471


    AppSec, Shopify-Style; State of Mobile Security; the News - Kern Smith, Andrew Dunbar - ESW #470 Aug 03, 2026
    Show notes

    Interview with Andrew Dunbar, CISO at Shopify

    After 13 years at Shopify, Andrew has some valuable insights to share on application security. In this episode, we discuss how AI has changed application security processes where bug bounty now fits in a post-Mythos, post-AI harness world.

    Andrew's Resources:

    • https://shopify.engineering/building-an-agentic-harness-that-outlasts-the-model
    Interview with Kern Smith

    Kern Smith, VP of Global Solutions at Zimperium, joins us to talk about the state of mobile security. This was a great conversation, talking about the history of mobile devices in the enterprise and how challenging securing mobile apps is in the age of vibe-coding.

    Segment Resources

    • https://zimperium.com/resources/new-zimperium-research-reveals-that-ai-based-attacks-are-targeting-and-succeeding-on-mobile
    • Global Mobile Threat Report 2026
    Enterprise Security News

    Finally, in the enterprise security news,

    1. Pre-black hat funding goes nuts
    2. we have 4 new cybersecurity unicorns!
    3. Cyera acquires Oasis for one BILLION dollars
    4. Lots of new product announcements with hacker summer camp next week
    5. Hugging Face got hacked by a competitor's agent and are cool with it?
    6. Finding out that wiping a burner phone is illegal the week before DEF CON is not ideal
    7. Are open, local models the future of AI?
    8. AI isn't coming for your job
    9. lots of vendor reports
    10. bad cybersecurity takes are apparently mainstream memes now???

    All that and more, on this episode of Enterprise Security Weekly.

    Visit https://www.securityweekly.com/esw for all the latest episodes!

    Show Notes: https://securityweekly.com/esw-470


    Exploring AI Network Protocols; Vulnerability Truths and Guarantees; and the News - Jeremiah Grossman, O'Shea Bowens - ESW #469 Jul 27, 2026
    Show notes

    Segment 1 - Interview with O'Shea Bowens

    What do we really know about "AI Network Protocols"? Network security is about to get popular all over again.

    Generative AI caused a disruptive explosion across all of tech and every company's roadmap. The move from chatbots to AI agents doubled down on that disruption. Now agents need to talk to each other?

    Boom: we have MCP. A2A. Universal Commerce Protocol. General purpose and specialized protocols for agent communication. What does this look like from the network perspective, though? O'Shea Bowen joins us to answer this question, and he thinks the results are interesting enough to spark a resurgence of interest in network security tooling.

    Segment Resources:

    1. https://www.nsa.gov/Portals/75/documents/Cybersecurity/CSIMCPSECURITY.pdf?ver=bmgiSbNQLP6Z_GiWtRt6bg%3D%3D
    2. https://labs.cloudsecurityalliance.org/research/csa-research-note-mcp-security-crisis-20260504-csa-styled/
    3. https://cyberone.security/blog/building-an-ai-security-strategy-without-stalling-business-growth
    Segment 2 - Interview with Jeremiah Grossman

    Jeremiah Grossman on why we've been measuring cyber risk wrong for 20 years

    After decades helping shape modern web security, and building companies that were ultimately acquired by Synopsys and Tenable, Jeremiah Grossman believes cybersecurity has arrived at an inflection point. His argument is a provocative one: for years, the industry has optimized around the wrong metrics. His latest venture, Root Evidence, aims to help security teams identify which risks are most likely to cause meaningful business loss, and he has the evidence - real-world breach data, cyber insurance claims, digital forensics intelligence, attack surface intelligence, and observed attacker behavior - to back it up.

    Find all of CyberRisk TV's Black Hat 2026 coverage at: https://www.securityweekly.com/blackhat

    Segment 3 - Weekly Enterprise News

    Finally, in the enterprise security news,

    1. We vibe check the AI model situation
    2. hidden devices in California cars causes concerns
    3. OpenAI's models escape sandboxes and breaches another AI company, totally by accident, they promise!
    4. Grok Build uploads all your files, totally by accident, they promise!
    5. Eclipsium debuts a firmware version of patch tuesday!
    6. HTTP gets a new method
    7. common problems with incident response
    8. Which one of the security weekly hosts would consider switching to a "dumb phone"?

    All that and more, on this episode of Enterprise Security Weekly.

    Visit https://www.securityweekly.com/esw for all the latest episodes!

    Show Notes: https://securityweekly.com/esw-469


    AI Security at Scale, CMMC phase II paused, and the Weekly Enterprise News - Keith Hollender - ESW #468 Jul 20, 2026
    Show notes

    Interview with Keith Hollender, CEO and Co-Founder of Arcova

    Why AI Security Is Becoming an Execution Problem, Not Just a Governance Problem

    As enterprises move from AI experimentation to adoption at scale, security leaders are under pressure to enable innovation without introducing unmanaged risk. The challenge is no longer whether organizations should pursue AI, but how they can govern it, secure it, and operationalize it in ways that stand up to real-world business and threat conditions.

    In this conversation, Keith Hollender discusses what Arcova is seeing across enterprise environments as organizations work to connect cybersecurity, AI governance, resilience, and broader transformation priorities. He explores where companies are getting stuck, why traditional siloed approaches are falling short, and what it takes to move from strategy decks to secure execution.

    Keith also shares how Arcova's practitioner-led, relationship-driven model helps organizations turn complexity into clarity by embedding with client teams, solving urgent problems hands-on, and building capabilities designed to last. The conversation also covers Arcova's continued growth, including expansion into the Middle East, and what global demand signals reveal about the next phase of cybersecurity and AI consulting.

    Segment Resources:

    • https://arcova.com/sectors/
    • https://arcova.com/category/blog/

    For more information about Arcova and how they can help your enterprise shape what's next, please visit:

    https://securityweekly.com/arcova

    Topic: CMMC Pause creating chaos among federal contractors

    This one sent some shockwaves through the CMMC community, particularly the hundreds or thousands of folks gearing up to assist with the validation that phase 2 aimed to provide. The TL;DR - defense contractors have been required to comply with CMMC controls for years, but self-attestation means that many probably haven't been meeting the requirements. Perhaps, rather than have tons of defense contractors fail the test, they just suspended the requirement for the test itself.

    I think Howard Holton nails it here when he says:

    "100,000 defense contractors needed third-party assessments. Roughly 100 authorized assessors exist. That's 1,000 assessments each, with the deadline in November."

    PCI already created a model that works for a scenario like this. If you're small, you self-assess. If you're big enough, an independent auditor comes to check you out once a year. I'm sure they were probably aware of this and chose not to go down that path for some reasons. I'm not aware of those reasons.

    What this means:

    • Phase II is paused
    • Phase I self-assessments still in place (note, however, that phase II existed, because self-attestation didn't work)
    • NIST SP 800-171 Rev 2 and DFARS 252.204-7012 compliance still required
    • 60-day review aims to reform CMMC
    • DoW opened an RFI for industry perspectives on what they should do
    • CMMC characterized as a "compliance burden" and "red tape"
    • False Claims Act and DOJ's cyber-fraud enforcement are still on the table

    More resources:

    • CIO Davies' post on Twitter
    • Administrator of the Small Business Administration, Kelly Loeffler's post
    • A useful LinkedIn post that breaks down a lot of what this really means (and doesn't)
    Weekly Enterprise News

    Finally, in the enterprise security news,

    1. will AI eliminate more cybersecurity jobs than it creates?
    2. Linus's law, amended
    3. the biggest patch Tuesday ever
    4. AI context bombs
    5. AI workflows are a security disaster
    6. people using AI in areas they don't understand
    7. ransomware crews are hitting legal firms hard
    8. lessons learned from CISA's recent github leak
    9. demystify your USB cables!

    All that and more, on this episode of Enterprise Security Weekly.

    Visit https://www.securityweekly.com/esw for all the latest episodes!

    Show Notes: https://securityweekly.com/esw-468


    1 2 3 50 Next

    Related Podcasts

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters

    1

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters Business
    WSJ Your Money Briefing

    2

    WSJ Your Money Briefing Business
    FORTUNE Unfiltered with Aaron Task

    3

    FORTUNE Unfiltered with Aaron Task Business
    FORTUNE OnStage Presents: The Most Powerful Women

    4

    FORTUNE OnStage Presents: The Most Powerful Women Business
    Slate Money

    5

    Slate Money Business
    In The Dark – The New Yorker

    6

    In The Dark – The New Yorker Business News
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights