
Cyber Risk Management Podcast
Kip Boyle
Cyber risk made clear for busy leaders. Cyber threats move fast. Your business must move faster. In every episode, Kip Boyle—author of "Fire Doesn’t Innovate" and CISO at Cyber Risk Opportunities—joins cybersecurity attorney and CISSP Jake Bernstein to break down the latest cyber risk. You’ll hear plain-English explanations of what's going on and what you need to do about it. No jargon. No doom. Just clear steps you can use today to save money, win buy-in, and stay out of the headlines.
- 22 episodes
- fortnightly
- Avg 44 min
- English
#218Tuesday · 45 min- CR
#217August 25 · 48 minEP 217: When Hospital Systems Go Down, Who Keeps Patients Safe?
When a hospital's systems go down, care does not stop. It goes back to pen and paper, and the first sign is quiet, because the alerts stop. Physician and CISSP Mark Yoffe explains clinical compensating controls: the steps clinicians take to keep patients safe during downtime. He covers who owns the clinical workflow, how to make controls workable and tested, how to recover information lost in the "memory hole," and what leaders should demand as proof. Paper is not the same as proof. Your hosts are Kip Boyle, CISO with Cyber Risk Opportunities, and Jake Bernstein, Partner with K&L Gates. LinkedIn: https://www.linkedin.com/in/mark-yoffe-md-cissp-a9927956/ "Fire Doesn't Innovate" by Kip Boyle: https://a.co/d/0bYatohy LinkedIn post: Questions: Here are audience engagement questions for this episode, organized by segment: Segment 1 – When the Hospital Goes Analog Have you ever worked through a system outage — at a hospital or anywhere else? What was the first thing that broke down? Does your organization have any setting where "no news is bad news" during downtime — where information stops coming to you and you don't immediately notice? Segment 2 – Ownership Who owns your clinical downtime workflow right now — not IT, but the clinical side? Can you name them? If your systems went down tonight, is there a single person accountable for whether patient care workflows hold up — or would people be figuring it out as they go? Segment 3 – Workability Does your downtime policy actually get used, or does it live in a binder somewhere? When did anyone last open it? What's one task your team assumes staff can improvise during downtime — that they probably can't? Segment 4 – The Memory Hole After your last outage, how confident are you that everything documented on paper actually made it into the record? Did anyone check? Has a gap in documentation during downtime ever affected a patient's care — or nearly did? Segment 5 – Leadership Oversight If your CEO asked today, "Can you show me that our clinical downtime controls actually work?" — what would you hand them? When did your organization last run a tabletop exercise specifically for clinical downtime — not just IT recovery? Closing poll question: Does your organization have a named, clinically credible owner for downtime workflows — yes, no, or "I genuinely don't know"?
- CR
#216August 11 · 53 minEP 216: When Reasonable Beats Bankrupt
After a breach, you either pay the fine, or fight the regulator and lose. There's a third path. It comes down to one word: reasonable. A method called DoCRA turns that question into something a court can use. DoCRA is short for Duty of Care Risk Analysis. Our guest Chris Cronin of HALOCK Security Labs helped build it. Now it's in standards and law. And it shaped a real case where a breached company spent its money on cybersecurity, not fines. Your hosts are Kip Boyle, CISO with Cyber Risk Opportunities, and Jake Bernstein, Partner with K&L Gates. LinkedIn: https://www.linkedin.com/in/chris-cronin-351416/ "Fire Doesn't Innovate" by Kip Boyle: https://a.co/d/0bYatohy Learn more about DoCRA: https://docra.org
- CR
#215July 28 · 51 minEP 215: Is Your AI Strategy a Risk Decision in Disguise?
There's a popular new playbook for running an "AI-native" company. Record everything, put all your data in one place, and let an AI agent reach all of it. The productivity story is real. New hires ramp up in days, and the whole company can ask questions it never could before. But the same moves that create the speed also switch off safeguards that some businesses are not allowed to switch off. So, which controls are we turning off to get this speed, and are we allowed to? Your hosts are Kip Boyle, CISO with Cyber Risk Opportunities, and Jake Bernstein, Partner with K&L Gates. Y Combinator's AI native playbook video -- https://youtu.be/B246K_G7mHU AIR-MAP website -- https://air-map.io/
- CR
#214July 14 · 39 minEP 214: AI Agents Don't Behave Like Humans
Your cybersecurity tools were built for people: a login, a single sign-on, an email address. But the AI agents now showing up inside your company don't work that way, and most of them slip right past your controls. So how do you find the "Shadow AI" already running in your business, and get a handle on it? Let's find out with our guest Nancy Wang, Chief Technology Officer at 1Password, who works at the front edge of how machines get access to systems. Your hosts are Kip Boyle, CISO with Cyber Risk Opportunities, and Jake Bernstein, Partner with K&L Gates. LinkedIn profile profile: https://www.linkedin.com/in/wangnancy/ 1Password: https://1password.com/
- CR
#213June 30 · 47 minEP 213: The Group Writing the Rules for AI Trust
Would you know if the AI tools your team is buying are actually trustworthy to use? Who gets to decide what trustworthy AI even means? Let's find out with our guest Jim Reavis, CEO of the Cloud Security Alliance, the group that helped the world learn to trust the cloud and is now building the standards for trusting AI. Jim explains how AI is changing what attackers, defenders, and governments can do, and walks through the tools his team built so you can adopt AI without guessing. Your hosts are Kip Boyle, CISO with Cyber Risk Opportunities, and Jake Bernstein, Partner with K&L Gates. Cloud Security Alliance: https://cloudsecurityalliance.org/
- CR
#212June 16 · 47 minEP 212: The AI Worked. The Process Didn't.
Anthropic, the company that built Claude, just accidentally published the full source code of their most important product. And it was their second data exposure in five days. What does this teach every organization buying AI tools right now? Kip Boyle shares the best takeaways from CRO's AI governance training and explains why the risk of AI isn't the AI itself. Your host is Kip Boyle, CISO with Cyber Risk Opportunities. Subscribe to Inflection Point -- https://cr-map.com/inflectionpoint/ SecureWorld AI Security PLUS course -- https://www.secureworld.io/events "Gears Don’t Guess: The Executive’s Practical Guide to Thriving in the Face of AI Hype and Risk" (forthcoming book, Fall 2026) AIR-MAP AI Risk Assessment -- https://air-map.io
- CR
#211June 2 · 47 minEP 211: What Sea-Tac’s Ransomware Revealed
In August 2024, a ransomware attack shut down baggage systems, flight displays, and Wi-Fi at Sea-Tac Airport. What did it reveal about how executives think about cyber investment? And why is “how much more security do we need?” the wrong question to ask after a major incident? Let’s find out with our guest Stephanie Warren, Assistant Director of Information Security at the Port of Seattle, who lived through that attack and came out the other side with hard-won lessons about executive decision-making under pressure. Your hosts are Kip Boyle, CISO with Cyber Risk Opportunities, and Jake Bernstein, Partner with K&L Gates. LinkedIn profile – https://www.linkedin.com/in/stephanie-warren-0746343/
- CR
#210May 19 · 46 minEP 210: How Boards of Directors Are Thinking About Generative AI
What does the generative AI conversation actually sound like inside a boardroom? Is the board ready to govern it? And what do board members wish CISOs understood about how they make decisions? Let’s find out with our guest, Vanessa Pegueros, former CISO at Docusign and U.S. Bank, and current board member at LivePerson and BECU. Your hosts are Kip Boyle, CISO with Cyber Risk Opportunities, and Jake Bernstein, Partner with K&L Gates. LinkedIn profile – https://www.linkedin.com/in/vanessapegueros Website – https://vanessapegueros.com
- CR
#209May 5 · 52 minEP 209: Mythos: When AI Finds More Than We Can Fix
Anthropic released Claude Mythos Preview. The headline is "AI can now find zero-days." Yes, but the real story is the gap between what AI finds and what organizations can fix. About 99 percent of Mythos findings are still unpatched. We cover what Mythos is in plain English, why the patching gap matters most, what duty of care means when your board knows these tools exist, where AIR-MAP fits, and why most advisors skip data sovereignty. Hosts: Kip Boyle, CISO, Cyber Risk Opportunities; Jake Bernstein, Partner, K&L Gates. Anthropic Claude Mythos Preview https://red.anthropic.com/2026/mythos-preview/ AISLE / Stanislav Fort, "AI Cybersecurity After Mythos: The Jagged Frontier" https://aisle.com/blog/ai-cybersecurity-after-mythos-the-jagged-frontier AIR-MAP overview https://air-map.io/
- CR
#208April 21 · 52 minEP 208: Flan Recipes and Prompt Injection
A Stripe employee hid a message in his LinkedIn profile telling any AI that read it to include a flan recipe. A month later, an AI recruiter emailed him one. It's funny until you realize the same technique can exfiltrate data, generate phishing content, or hijack automated business processes. What is prompt injection, why does OWASP rank it as the number one risk to large language models, and what should you do about it? Let's find out. Your hosts are Kip Boyle, CISO with Cyber Risk Opportunities, and Jake Bernstein, Partner with K&L Gates. OWASP Top 10 for LLM Applications -- https://genai.owasp.org
- CR
#207April 7 · 45 minEP 207: Defend the Business from Cybersecurity
What happens when a cybersecurity team designs controls without asking the business what they need? And what role exists specifically to prevent that? Let's find out with our guests Brian Shea and Maggie Amato, former Business Information Security Officers at Salesforce. Your hosts are Kip Boyle, CISO with Cyber Risk Opportunities, and Jake Bernstein, Partner with K&L Gates. Brian Shea's LinkedIn profile -- https://www.linkedin.com/in/brianshea/ Maggie Amato's LinkedIn profile -- https://www.linkedin.com/in/maggie-amato-021624164/
- CR
#206March 24 · 31 minEP 206: Fire Doesn't Innovate. AI Does. Are You Ready?
Fire hasn't changed since the dawn of humanity, but our cyber adversaries evolve every single day. What happens when organizations spend $10 on AI transformation for every $1 on cybersecurity? In this special ROCon 2025 keynote replay, Kip shares two stories that changed how he thinks about risk: a "perfect" employee who became an insider threat in four weeks, and a $12M deepfake that defeated every technical control on the dashboard. Your hosts are Kip Boyle, CISO with Cyber Risk Opportunities, and Jake Bernstein, Partner with K&L Gates. Get Kip's book, "Fire Doesn't Innovate" 2nd Edition -- https://a.co/d/0bYatohy
- CR
#205March 10 · 42 minEP 205: Making Privacy Compliance Sustainable
Privacy laws keep multiplying, regulations keep changing, and AI is making everything more complex. How do businesses build privacy compliance that actually sticks instead of just checking a box? Let's find out with our guest Jordan Fischer, Founder and Partner at Fischer Law and Cybersecurity Lecturer at UC Berkeley. Your hosts are Kip Boyle, CISO with Cyber Risk Opportunities, and Jake Bernstein, Partner with K&L Gates. Jordan Fischer's website: https://jordanfischerlaw.com Shoshana Zuboff's book: https://en.wikipedia.org/wiki/The_Age_of_Surveillance_Capitalism
- CR
#204February 24 · 50 minEP 204: Carpets and Diamonds
Most cybersecurity people talk at CFOs instead of with them. What if there were a simple test to know when a CFO wants to learn about cyber risk versus when they just need someone to trust? Let's find out with our guest James Wheeler, a highly experienced CFO who now runs kept.pro, providing fractional accounting teams to businesses across the country. Your hosts are Kip Boyle, CISO with Cyber Risk Opportunities, and Jake Bernstein, Partner with K&L Gates. LinkedIn: https://www.linkedin.com/in/jamesdavidwheeler/ "Fire Doesn't Innovate" by Kip Boyle: https://a.co/d/0bYatohy
- CR
#203February 10 · 48 minEP 203: Cyber Risk Quantification
Can cyber risk actually be measured in dollars? How do you know if your risk data vendor is any good? And is cyber insurance really worth the investment? Let's find out with our guest Scott Stransky, who leads the Cyber Risk Intelligence Center at Marsh and was named 2023 Cyber Risk Industry Person of the Year. Your hosts are Kip Boyle, CISO with Cyber Risk Opportunities, and Jake Bernstein, Partner with K&L Gates. LinkedIn profile -- https://www.linkedin.com/in/scott-stransky-92659095/ Top 12 Report -- https://www.marsh.com/en/services/cyber-risk/insights/cybersecurity-signals.html Marsh Cyber Risk Intelligence Center -- https://www.corporate.marsh.com/solutions/cyber-resilience/cyber-risk-intelligence-center.html
- CR
#202January 27 · 38 minEP 202: Why Fortune 500s Still Run on Windows 2003
Why do IT organizations cling to ancient technology like Windows 2003, creating dangerous technical debt they don't even recognize? And how do they get out of this trap? Let's find out with our guest Anton Chuvakin, who advises the biggest customers of Google's Cloud services. Your hosts are Kip Boyle, CISO with Cyber Risk Opportunities, and Jake Bernstein, Partner with K&L Gates. LinkedIn profile -- https://www.linkedin.com/in/chuvakin/ Podcast -- https://cloud.withgoogle.com/cloudsecurity/podcast/
- CR
#201January 13 · 44 minEP 201: AI Powered Espionage
AI-driven attacks aren't coming; they're here. A Chinese state-sponsored group just ran cyber espionage operations that were 80 to 90 percent autonomous. What does this means for defenders? Your hosts are Kip Boyle, CISO with Cyber Risk Opportunities, and Jake Bernstein, Partner with K&L Gates. Here's Anthropic's report -- https://www.anthropic.com/news/disrupting-AI-espionage
- CR
#200Dec 30, 2025 · 45 minEP200: Future of Cyber Defense
AI can supercharge your security team. But it can also supercharge attackers. So how do you stay ahead in an AI-powered threat landscape? Let's find out in our special 200th episode! Your hosts are Kip Boyle, CISO with Cyber Risk Opportunities, and Jake Bernstein, Partner with K&L Gates. Kip's keynote address -- https://youtu.be/DNRNbT0IaKM "Fire Doesn’t Innovate: Thriving in the Face of Evolving Cyber Risks" In this ROCon 2025 keynote, Kip Boyle challenges audiences to rethink how they approach modern threats in the age of AI. Using the metaphor of fire — a static risk that hasn’t changed for millennia — Kip explores how cyber adversaries are innovating daily while many organizations remain trapped in outdated mindsets. He closes with a compelling call to action: adapt like firefighters did with fire — or risk being left behind.
- CR
#199Dec 16, 2025 · 19 minEP 199: AI Phishing at SecureWorld Seattle
How has GenAI turned phishing Into a speed war? And what should we do about it? Let's find out with your hosts are Kip Boyle, CISO with Cyber Risk Opportunities, and Jake Bernstein, Partner with K&L Gates.