Skip to content
Artwork for Secure Talk Podcast
TechnologyNewsTech News

Secure Talk Podcast

Justin Beals

Secure Talk reviews the latest threats, tips, and trends on security, innovation, and compliance.

Host Justin Beals interviews leading privacy, security and technology executives to discuss best practices related to IT security, data protection and compliance. Based in Seattle, he previously served as the CTO of NextStep and Koru, which won the 2018 Most Impactful Startup award from Wharton People Analytics. He is the creator of the patented Training, Tracking & Placement System and the author of “Aligning curriculum and evidencing learning effectiveness using semantic mapping of learning assets,” published in the International Journal of Emerging Technologies in Learning (iJet). Justin earned a BA from Fort Lewis College.

Play
  • 21 episodes
  • fortnightly
  • Avg 47 min
  • English
Counted on this page — what you have heard stays on this device, so it is not something the list can be paged by.
  • #260
    Tuesday · 50 min

    AI Agent Hacks Another AI Agent Inside Google — An Agentic Supply Chain Bomb

    An agent anyone could talk to just pulled the levers on one almost nobody could reach — and it happened inside the crown jewels: a live code repository. Google gave its AI agent human-level trust — and paid for it. When Dan Lisichkin, a researcher at Pillar Security, started mapping every Google repository running an embedded coding agent, he wasn't hunting for prompt injection — he was hunting classic CI/CD bugs. The AI angle showed up almost by accident, flagged by his own automation. What he found inside Google's Agent Development Kit repository was a low-privilege issue-triaging bot commenting on GitHub *as a trusted collaborator* — a status that should be reserved for humans the maintainers know. As Dan puts it, describing the moment his manager pushed back on downplaying the find: *"this is an agent triggering another agent... this is like no one talked about this before."* The prompt injection wasn't the hard part — weaponizing it was. Dan walks through Pillar's CFS framework (Context, Format awareness, instruction Salience) and how he literally used Google's own CONTRIBUTING.md file as the blueprint for the injection that would slip past the triage agent undetected. From there, one gated comment — normally reserved for trusted maintainers — was enough to trigger a second, far more privileged agent. This isn't a bug you patch once — it's a new attack surface. Dan's read is blunt: multi-agent systems create "weird machine" behavior — undefined states nobody designed for, not flaws in a specific line of code. He and Justin dig into why bolting more rules onto a non-deterministic system is Sisyphean, why bot identities need database-row-level granularity instead of human-style trust, and why Dan — a former malware researcher — thinks mandatory human-in-the-loop is often the wrong answer at scale. Chapters: 00:00: Cold Open: The Agent That Wasn't Supposed to Talk** - Google's public triage bot and the collaborator-status anomaly - Why "an agent triggering another agent" had never been formally described before 04:12: Building the Hunt: Automation Over Manual Bug-Hunting** - Dan's CI/CD vulnerability scanner, built on top of Claude Code - How an AI-generated "AI agent injection" tag became the whole story - Reference: [Simon Willison — "The Lethal Trifecta for AI Agents"] 14:30: The Exploit: Contribution Guidelines as an Attack Roadmap** - Google ADK repository, the PR-triaging agent, and the CONTRIBUTING.md file used as a weapon - Pillar Security's CFS framework for indirect prompt injection (Context, Format awareness, Salience) — [Pillar Security Blog: Autonomy of Indirect Prompt Injection] - Why jailbreaking ≠ what Dan is doing — "I'm not trying to break the wall, I'm trying to walk through the door it left open" 28:05: Impact: Two Bugs, Two Verdicts** - GitHub token exfiltration, PR/issue metadata manipulation, and the fake "looks good to merge" trail - The second bug: a GCP service account and code-execution potential — "there was more juice on that one" - Why Google didn't pay a bounty — and why that answer is more interesting than the bug itself 38:50: Identity, Granularity, and the Human-in-the-Loop Debate** - Why bot identities need GitHub App/Actions scoping, not personal-access-token trust - The case *against* blanket human-in-the-loop — review fatigue, OpenClaw, and "people are going to do this anyway" - SolarWinds, CryptoLocker, and why Dan thinks this is a closed-gap problem, not an open one Resources: Lisichkin, D. (2026, August 3). I'll just call you: Agent-to-agent privilege boundary failures in CI/CD on Google's ADK repository. Pillar Security. https://www.pillar.security/blog/ill-just-call-you-agent-to-agent-privilege-boundary-failures-in-ci-cd-on-googles-adk-repository https://danusminimus.github.io/ #aiagents #security #promptinjection #google #defcon #vulnerability ---

    • Transcript
  • #259
    August 11 · 48 min

    AI Is Eating Our Young: Data Center Revolts, Vanishing Junior Jobs & the EU AI Act

    Communities are blocking $130 billion in AI data centers while the entry-level jobs that used to train the next generation of engineers quietly disappear. Chapters: 00:00: The Backlash: 800 Groups, 49 States, $130B Blocked Gallup: 71% of Americans don't want a data center built near them (Gallup) Data center opposition tracker, Q1 2026 filings (referenced industry opposition data) CMMC as precedent for regulating critical infrastructure (DoW CMMC Phase 2 program) 04:30: Why AI Is "Eating Our Young" in Education** Fran Berman & co-author's unpublished piece on the fraying mid-career pipeline Better Tech (MIT Press) — Chapter appendix: AI classroom syllabus and exercises 14:00: Tech as Critical Infrastructure, Not a Religion Better Tech prologue: treating tech like food, water, roads, and the power grid GDPR (EU, 2018) as a case study in regulation done right — and its limits Vermont's data broker law as a case study in weak enforcement 26:00: Design Can't Be Bolted On Later** Self-driving cars and the hidden environmental cost of full autonomy Attack surface risk: denial-of-service on connected, self-driving fleets 34:00: Governing the Hybrid Human-AI Society** EU AI Act — risk-tiered regulation: unacceptable, high-risk, low-risk categories U.S. Equal Employment Opportunity Commission guidance on algorithmic hiring 41:00: The Hype Curve and the Data Center Reckoning** Western Massachusetts communities rejecting new AI data centers Efficiency vs. quality of life — Berman's closing argument Communities are saying no to AI's biggest infrastructure bet.In the first quarter of 2026 alone, local opposition blocked or delayed 75 data center projects worth roughly $130 billion — nearly matching all of 2025's total in a single quarter. Dr. Fran Berman, former head of the San Diego Supercomputer Center, argues the fix isn't more hype, it's precedent we already have. She points to CMMC itself: "If we can look at the defense supply chain and say this is critical infrastructure, it has to meet a bar, then we can look at the trillion dollars of compute being built into the middle of American life and say the same thing." AI isn't just displacing jobs. It's starving the pipeline that builds senior engineers. Berman's sharpest warning is about who trains the next generation of professionals when entry-level coding and writing jobs — the ones junior people used to cut their teeth on — get automated away. She compares it to a surgeon who's never had supervised time in the operating room: "Unless you have that experience and the mentorship of more senior professionals, it's really hard" to develop the judgment senior engineers rely on. Good regulation needs more than a law on the books. Drawing on her book Better Tech (MIT Press), Berman walks through why GDPR worked where Vermont's data broker law didn't — and previews how the EU AI Act's risk-tiered approach (unacceptable, high-risk, low-risk) could become the model for governing hybrid human-AI decision-making, where, as she puts it, "the only accountable entities are humans." ✍️ About the Author Dr. Fran Berman is an award winning-data scientist, pioneer in public interest technology, and community leader and builder. She directs the Public Interest Technology Initiative at UMass Amherst and is a Faculty Associate at the Berkman Klein Center for Internet and Society at Harvard. Berman is former head the San Diego Supercomputer Center and served as Vice President for Research at Rensselaer Polytechnic Institute. She currently serves as a Trustee of the Alfred P. Sloan Foundation and is a popular regular panelist on public radio’s WAMC Roundtable with 400,000 monthly listeners in seven states. For more information, see https://www.franberman.com. Link to the book: https://mitpress.mit.edu/978026205488...

    • Transcript
  • #258
    July 28 · 42 min

    Okta's Identity Chief: Most CISOs Can't Answer This AI Question

    Which AI agents can access what? Are those permissions even right? And can you stop a compromised agent mid-action? Okta's Dan Cinnamon says most enterprises can't answer any of the three. Dan Cinnamon has built software, run SAP GRC without an implementation partner, and now architects identity for one of the industry's biggest players. In this conversation with Justin Beals, he lays out why "discoverability" — simply knowing what agents exist and what they're touching — is the single biggest blind spot in enterprise AI right now, and why there's no silver bullet coming to fix it. They also dig into passkeys as a rare win-win security standard, the maturing MCP spec, and where the hard line on agent containment should actually sit. **Timestamps:** 0:00 Intro 1:20 From writing code to securing identity 4:45 Passkeys: the security/usability unicorn 8:30 The SAP GRC re-implementation story 14:10 Attribution and the agentic AI identity gap 18:55 How fast MCP has matured—and what's next 23:40 The 3 unanswered questions every enterprise faces 27:15 Granular identity vs. inherited permissions 32:00 Containment: moving controls closer to the data 36:45 Consent, provenance, and healthcare AI 40:30 Closing thoughts #CISO #AIstrategy, #enterprise #AIsecurity, #agentic #AIgovernance, #Okta #MCPstandard, #zerotrust #AI agents

    • Transcript
  • #257
    July 17 · 46 min

    Special Episode: CMMC Phase 2 SUSPENDED: What DOD Just Did, What It Really Means, and Why Little Changed

    The Pentagon paused CMMC Phase 2 with zero warning — and half the defense industrial base is celebrating for the wrong reason. When the Department of War suspended CMMC Phase 2 rollout with no notice, panic spread fast across the defense contractor community — but the requirement to secure CUI never went away. In this special roundtable, host Justin Beals brings together three CMMC insiders — Logan Therrien (C3PAO Chief Strategy Officer, retired Navy submariner), Lance Arnold (30-year industry veteran, just completed his own CMMC Level 2 journey), and Brian Hubbard (President, Evolved Cyber Solutions, CMMC assessor since 2015) — to separate what actually changed from what didn't. They break down the difference between the assessment requirement (paused) and the security implementation requirement (still very much alive under NIST 800-171), why "self-assessment" doesn't mean "no requirement," and what small businesses and primes should do right now instead of waiting for clarity that may not come for months. Sources Referenced: DFARS 252.204-7021 (CMMC assessment clause) DFARS 252.204-7012 (NIST 800-171 compliance clause) DFARS 252.204-7019 (SPRS scoring requirement) 32 CFR Part 170 (CMMC Program Rule) 32 CFR Part 48 NIST SP 800-171 / NIST SP 800-172

    • Transcript
  • #256
    July 14 · 41 min

    An AI Security Maturity Model for CISOs, with Chris Cochran (SANS)

    Half the room at Chris Cochran's leadership dinners still calls themselves AI skeptics. He argues they can't afford to be — because the adversary already isn't. Chapters: 00:00 — Intro 02:49 — NSA/threat intel → AI security, storytelling 09:55 — Why leaders feel stuck / no roadmap 14:41 — Three pillars (Protect/Utilize/Govern) 17:00 — Governance as the real foundation / shadow AI 21:37 — Evidence-based scoring vs. pass/fail 26:27 — EU AI Act 28:44 — Fable/Mythos, Project Glasswing access controls 33:18 — Token subsidies, self-hosted models 37:52 — Data poisoning & context poisoning 40:12 — Iron Man suit framing 42:38 — Close: what's next

    • Transcript
  • #255
    June 16 · 41 min

    Considering Security, Compliance and Revenue with David Grazer

    Most companies chase certifications to win deals — but what actually keeps customers is something no audit can measure. In this episode, vCISO David Grazer makes the case that trust is a measurable economic asset hiding in plain sight: your customer retention rate. Drawing on 15+ years inside high-growth tech companies, David explains why compliance frameworks are customer acquisition tools, not retention strategies — and how the gap between the two is costing businesses more than they realize. This episode is for founders, security leaders, and C-suite executives who want to connect their security and privacy programs to real business outcomes. You'll learn: → Why a SOC 2 or ISO 27001 certification is only the beginning of earning customer trust → How customer churn functions as one of the most honest security metrics available → Why MFA and common security controls often fail the users who need them most → What "Trust by Design" looks like in product development and AI programs → How to translate security risk into language that resonates with your CFO Chapters 00:00 Introduction to Secure Talk and Trust 03:42 David Grazer's Journey into Security and Privacy 08:09 Navigating Compliance and Customer Trust 12:49 The Role of Consulting in Security 18:07 Trust as a Measurable Economic Asset 23:42 Identity Management in the Entertainment Industry 26:09 The VC SO Model and Its Impact 29:13 The Evolution of Compliance Conversations 33:17 Exploring the Intersection of Technology and Society 🔔 Subscribe to SecureTalk for weekly conversations at the intersection of cybersecurity, compliance, and business strategy. #cybersecurity #compliance #CISO #trustbydesign #vciso #informationsecurity #GRC #dataprivacy

    • Transcript
  • #254
    June 2 · 53 min

    Why you could fail your CMMC Level 2 C3PAO audit | Secure Talk with Logan Therrien

    You did your self assessment and received a perfect 110 score, congratulations! You met with your C3PAO and scored less than 0. What happened! How can two CMMC assessors examine the same defense contractor and arrive at completely different scores? A lack of rigor in assessment methodology could mean the entire certification system is measuring the assessor — not your security. Logan Therrien, Chief Strategy Officer at Kieri Solutions and one of the original C3PAO lead assessors in the U.S., joins Justin Beals to expose a critical flaw in how CMMC Level 2 assessments are conducted today: no standardized evidence sampling methodology. This episode is for DoD contractors, compliance consultants, and defense industry executives who want to understand what's at stake — and how to navigate assessments before the rules tighten further. What you'll learn: Why NIST 800-171 was intentionally vague — and how that backfired for assessors How one assessor might review a single evidence point while another reviews 100% What ISO 17020 accreditation will require of C3PAOs and why it matters now What the 48 CFR expansion means for 118,000+ contractors in the supply chain How to prepare for an assessment so it feels like an open-book test Logan also co-authored the peer-reviewed paper "The Need for Standardized Evidence Sampling in CMMC Assessments: A Survey-Based Analysis of Assessor Practices" (with John Hastings) — one of the first data-driven studies of assessment methodology in the CMMC ecosystem. Chapters 00:00 Introduction to Secure Talk and Psychometrics 01:45 Understanding CMMC and Its Implications 05:32 Logan Therian's Background and Insights 09:16 The Challenges of Assessment Methodologies 16:10 The Scale and Impact of CMMC Assessments 20:31 Navigating Standards in Cybersecurity 23:53 Evidence Testing in CMMC Assessments 27:43 The Importance of Reliable and Accurate Assessments 36:22 Building Trust Between Industry and Defense 41:46 Future Directions in CMMC Research Resources: Therrien, Logan and Hastings, John. (2026, February 10). The need for standardized evidence sampling in CMMC assessments: A survey-based analysis of assessor practices. arXiv. https://arxiv.org/abs/2602.09905

    • Transcript
  • #253
    May 19 · 47 min

    Mark Zuckerberg has an AI twin. Who Is Mark Zuckerberg?

    Mark Zuckerberg built an AI version of himself that attends meetings and approves budgets while he's elsewhere. That's not science fiction — it's happening now. But when an AI replica makes a consequential decision, who's legally responsible? Who owns it when you die? Dr. Candi Cann, Thanatologist and professor at Baylor University, joins SecureTalk host Justin Beals to explore the uncomfortable intersection of technology, mortality, and identity — and what it means for data governance, digital rights, and the future of enterprise accountability. In this episode: Key topics: digital identity, AI accountability, data governance, CMMC compliance, death technology, digital ethics, AI agents, enterprise security If your organization is deploying AI agents that act on behalf of humans — approving transactions, attending meetings, representing employees — this episode raises the governance questions your security and legal teams need to be asking right now. Subscribe to SecureTalk for weekly conversations at the edge of cybersecurity, compliance, and technology culture. Resources: Book: Augmented: Life and Death as a Cyborg by Candy Cann, MIT Press, 2026. Link: https://mitpress.mit.edu/9780262051118/augmented/

    • Transcript
  • #252
    May 5 · 51 min

    CMMC Is an HR Problem, Not an Enclave Problem — Here's the Proof

    The biggest cybersecurity failures in recent memory — Raytheon, Penn State, Georgia Tech — weren't caused by missing software. They were caused by the wrong people being assigned the wrong tasks, with no shared language to connect the rules to the work. This SecureTalk episode with Dorian Cougias (MoxyWolf, former Unified Compliance Framework CEO) is one of the most systems-level conversations we've had on the show. Dorian spent decades building the infrastructure that compliance programs run on — and he's now rebuilding it from scratch, in the open. What you'll hear: → Why the compliance industry is structurally fragmented across three authority domains that don't communicate → How Bloom's Taxonomy — a tool from education — maps directly to which compliance tasks belong to which roles → Why the Oxford English Dictionary doesn't have "personal data" in it, and what that tells us about regulatory language → The O*NET framework and why the Department of Labor might be the most underused tool in cybersecurity → Shannon's entropy theory, applied to compliance and cognitive load → A new open-source STIG API infrastructure that StrikeGraph is integrating as a launch partner Whether you're deep in the compliance trenches or just fascinated by how complex systems fail — and how to redesign them — this is worth your time. 🔗 strikegraph.com | stigviewer.com Chapters: 00:00 Introduction and Background 02:43 Exploring Compliance and Natural Language Processing 05:15 Military Experience and Signal Intelligence 08:01 Cognitive Load and Compliance Frameworks 10:49 The Importance of Language in Compliance 13:39 The Evolution of Dictionaries and Lexicons 16:16 Bridging Gaps in Compliance Communication 18:47 Innovations at MoxieWolf and Future Directions 22:04 Mapping Skills and Regulatory Guidelines 25:05 Job Applicability and Knowledge Requirements 28:02 The Importance of O*NET in Cybersecurity 29:21 Challenges in CMMC Compliance 33:23 The Role of Technology in Compliance 35:38 Horizontal Practices in Compliance 38:15 Building Effective Teams for Compliance 42:21 Introduction to Compliance Failures 45:19 The Human Element in Compliance 48:10 Navigating Compliance Complexity with Technology 48:57 Introduction to Cybersecurity Compliance Challenges 54:09 The Role of People in Compliance Success 56:01 Guest Introduction: Dorian Cougas 01:00:48 Exploring Bloom's Taxonomy in Compliance 01:05:48 The Importance of Shared Lexicons 01:09:32 Navigating Compliance with Technology 01:15:11 MoxieWolf's Approach to Compliance 01:20:49 The Interconnectedness of Compliance Tasks 01:27:51 Real-World Compliance Challenges 01:33:57 Building Effective Teams for Compliance #Cybersecurity #ComplianceCulture #CMMC #HumanFactors #GRC #TechPolicy #SecureTalk

    • Transcript
  • #251
    April 21 · 47 min

    The ROI of Security Tested: What a new paper reveals about security value | Secure Talk with Minh Nguyen and Thi Tran

    Why do most cybersecurity investments feel impossible to justify? Because the measurement tools are broken — built on gut instinct, not research. Researchers Minh Nguyen (Florida Atlantic University) and Thi Tran (Binghamton University) set out to fix that. In this episode, they break down their landmark paper "Effects of Cybersecurity Readiness on Firm Performance: Evidence from Conference Calls" — the first study to systematically measure cybersecurity readiness at the firm level and link it directly to financial performance. What they found will change how you think about security budgets: → Outsider mentions of cybersecurity in earnings calls are 100x more predictive of firm performance than insider mentions → Even a single co-occurrence of security-related language drives measurable returns on assets the following year → Companies that act proactively - not reactively - earn greater market trust This is the episode for CISOs who need real data to justify investment, security leaders tired of folklore-based decision-making, and anyone curious about how AI, NLP, and causal inference are reshaping the business case for cybersecurity. Chapters 00:00 Introduction to the Guests and Their Backgrounds 02:34 The Intersection of AI, Business, and Cybersecurity 05:32 Understanding Cybersecurity Readiness 08:31 The Importance of Measurement in Cybersecurity 11:16 Developing a Cybersecurity Dictionary 14:16 The Impact of Outsider Perspectives on Firm Performance 16:51 The Role of Transparency in Cybersecurity 19:40 Future Research Directions in Cybersecurity 22:37 Conclusion and Final Thoughts 🔗 Paper: "Effects of Cybersecurity Readiness on Firm Performance: Evidence from Conference Calls" https://scholarspace.manoa.hawaii.edu/server/api/core/bitstreams/b098c310-db83-42cc-8932-852ef7ebcc86/content #Cybersecurity #CyberROI #CISO #FirmPerformance #CybersecurityResearch #NLP #CausalInference #InfoSec #SecurityLeadership #ConferenceCall``

    • Transcript
  • #250
    April 7 · 53 min

    They Sold AI to Play God. China Never Got That Memo.

    The West has been building AI like it's the apocalypse. China has been building it like it's a tool. That one difference — rooted in centuries of philosophy, theology, and cultural storytelling — may be the most important thing nobody is talking about in the AI debate right now. SecureTalk host Justin Beals sits down with scholars Bogna Konior (NYU Shanghai), Mi You (University of Kassel), and Vincent Garton to explore their co-edited book "Machine Decision Is Not Final: China and the History and Future of Artificial Intelligence" — and what it reveals about the hidden assumptions driving the decisions we make about AI governance, security, and society. What this conversation unpacks: → Why Western AI fear traces back to Christian theology — not rational risk analysis → How the Chinese term for AI literally means "human-made wisdom ability" — no alien mind implied → The 2019 Elon Musk vs. Jack Ma exchange that exposed the cultural divide in real time → What DeepSeek's open-source breakthrough says about innovation, restriction, and creative problem-solving → Why this debate matters far beyond the US and China — and who else is watching closely If you work in cybersecurity, tech leadership, or AI policy, the cultural lens on this technology isn't a soft question. It shapes real architectural, governance, and regulatory decisions. Chapters 00:00 Introduction and Perspectives on AI in China 02:41 The Meaning Behind the Claw Machine Image 05:33 The Book's Creation and Collaborative Efforts 08:32 Cultural Perspectives on AI: East vs. West 11:06 The Impact of Open Source AI Models 13:45 Innovation in a Controlled Environment 16:20 Human-Made vs. Artificial Intelligence 19:23 The Philosophical Underpinnings of AI 22:06 The Role of Human Agency in AI Decisions 24:54 Exploring the Future of AI and Society 27:26 The Synthesis of Technology and Society 30:22 Conclusion and Final Thoughts 44:17 Understanding Artificial Intelligence: A Cultural Perspective 47:08 Machine Decision: The Chinese Perspective on AI 49:59 Innovation and Openness in AI Development 50:27 Global Implications of AI Beyond Superpowers 50:37 Introduction and Context of AI Governance 01:00:53 The Role of Computers in Decision Making 01:08:26 Transparency in AI and Governance 01:17:58 Cultural Perspectives on AI: East vs. West 01:23:46 The Singularity and Its Philosophical Implications 01:27:15 Simulation and Reality in AI Discourse 01:35:14 Social Implications of Large Language Models 🎙️ SecureTalk is hosted by Justin Beals, CEO of Strike Graph. 🔔 Subscribe for weekly conversations at the intersection of cybersecurity, technology, and leadership. #ArtificialIntelligence #AIPolicy #ChinaAI #DeepSeek #Cybersecurity #AIGovernance #TechLeadership #OpenSourceAI ```

    • Transcript
  • #249
    March 24 · 48 min

    The DOGE data breach at the Social Security Administration with Whistleblower Chuck Borges

    Every American has a Social Security number. Most assume it's protected. Chuck Borges was the person responsible for that protection at the SSA — and what he discovered from the inside is something every American deserves to know. Chuck is a combat veteran, MIT graduate, and the Social Security Administration's first dedicated Chief Data Officer. He arrived two weeks before the 2025 administration change, watched data governance requests get denied and sensitive work get siloed away from the officials responsible for protecting it, and when the risk became too great to ignore, he spoke up. It cost him his job. In this episode of SecureTalk, Chuck and host Justin Beals cover: - Why NUMIDENT data breach goes far beyond a typical data breach - How shadow IT and unchecked access created a governance nightmare inside the SSA - The national security implications of 550 million identity records at risk - What it actually takes to blow the whistle when the stakes are this high This is one of the most important cybersecurity conversations of 2025, not because of the technology involved, but because of what it reveals about the systems we trust to protect us. Chapters 00:00 From Dreams to Data: A Unique Journey 02:47 Navigating the Data Landscape: Challenges and Innovations 05:41 The Role of Governance in Data Management 08:20 Civil Service and the Mission Mindset 11:16 Chaos and Change: The Impact of Administration Shifts 13:52 Empathy in Leadership: The Human Element 16:51 Life Experience and Effective Governance 21:16 Siloing and Data Manipulation in Government 23:30 The Risks of Shadow IT and Data Security 27:39 The Dangers of Numident Data 30:08 The Nightmare of Data Exfiltration 31:52 The Courage to Blow the Whistle 36:19 Transitioning to Political Service 38:24 Challenges of Running for Office 41:36 Building Community Through Problem Solving 43:05 Introduction to Data Sensitivity and Governance 44:33 The Risks of Data Exposure 45:55 Chuck Borges: A Profile in Data Leadership 46:46 Introduction to SecureTalk and Data Security 47:37 The Role of the Social Security Administration 48:35 Chuck Borges: A Journey Through Data Governance 50:28 The Impact of Administration Changes on Governance 56:14 Challenges in Data Management and Governance 01:00:58 The Risks of Data Exposure and Mismanagement 01:05:37 Whistleblowing and Ethical Responsibilities 01:14:56 Running for Office: A New Chapter in Public Service Resources: Chuck Borges Website - https://chuck4md.com Twitter - https://twitter.com/Chuck4MD 🔔 Subscribe to SecureTalk for weekly conversations on cybersecurity, leadership, and the technology shaping our world. #SocialSecurity #DataGovernance #Cybersecurity #DataBreach #NationalSecurity #Whistleblower #FederalCybersecurity #IdentityTheft #SecureTalk #CDO

    • Transcript
  • #248
    March 10 · 40 min

    From 9/11 to Salt Typhoon: Why Backdoors Always Betray Us | Secure Talk with John Ackerly

    On the morning of September 11th, 2001, John Ackerly was briefing White House officials on federal privacy legislation. Hours later, everything changed — and those two realities, data that wasn't shared when it should have been, and data that was exposed when it shouldn't have been, became the founding idea behind Virtru. In this episode of SecureTalk, host Justin Beals sits down with John Ackerly, CEO and co-founder of Virtru and former White House technology policy adviser, to explore why perimeter security alone is broken — and what data-centric, cryptographic control means for the future of cybersecurity. They cover: 00:00 Introduction to SecureTalk and Data Security 02:28 John Ackerly's Experience and Insights on Privacy Legislation 05:05 The Dichotomy of Privacy and Security 09:12 Public-Private Partnerships in National Security 12:24 Navigating Compliance and Security in Business 15:26 The Role of Technology in Security Solutions 18:40 Family Ties and Military Background in Cybersecurity 20:41 Insider Threats and Data Security Innovations 23:29 The Importance of Data Management and Audits 26:12 Cultural Impact on Security Practices 29:19 Future Challenges: Quantum Computing and Security 32:52 The Evolution of AI and Data Science in Security Whether you work in cybersecurity, government, or technology policy, this conversation connects the policy decisions of the past 25 years to the architectural challenges we face today. 🔒 Learn more about Virtru: https://www.virtru.com 🎙️ Subscribe to SecureTalk for weekly conversations at the intersection of technology, security, and society.

    • Transcript
  • #247
    February 24 · 46 min

    A Con Artist Expert Explains Why Smart People Still Get Scammed | Secure Talk with Robert Siciliano

    You consider yourself pretty tech-savvy. You know not to click suspicious links. You've heard the warnings. So why are more people losing more money to online scams than ever before? Robert Siciliano has spent 30 years as a private investigator, appearing on CNN, The Today Show, and Fox News to explain exactly how con artists and cybercriminals think — and why your brain is actually working against you. In this eye-opening conversation with SecureTalk host Justin Beals, Robert reveals: - The psychological reason almost everyone falls for scams eventually - How criminals use loneliness to build fake relationships and drain bank accounts - Why your parents are the #1 target for the $124 trillion wealth transfer underway - What a deepfake video call cost one company $25 million — in a single afternoon - The one habit that would protect 80% of people — and almost nobody does it This isn't a tech talk. It's a human talk. And it might be the most important conversation you have about your money, your family, and your identity this year. Chapters 00:00 Introduction to Cybersecurity Challenges 02:44 The Human Blind Spot in Cybersecurity 05:30 Engaging Employees in Security Practices 08:44 Understanding Cybercrime Trends 11:30 The Psychological Aspects of Trust and Security 14:03 Personalizing Security Awareness Training 17:01 The Role of AI in Cybersecurity Threats 23:46 The Dark Reality of Human Trafficking and Cyber Crime 25:55 The Evolution of Cyber Crime Tactics 27:37 Understanding Human Behavior in Cybersecurity 29:54 The Impact of Loneliness on Cyber Vulnerability 31:58 The Kitchen Table Effect in Security Training 34:20 The Importance of Human Connection in Security Awareness 37:40 Empathy and Responsibility in Cybersecurity 39:47 Personal Stories Shaping a Security Perspective 🔔 Subscribe to SecureTalk — new episodes every week. #ScamAlert #OnlineScams #IdentityTheft #CyberSafety #DeepFake #FinancialSecurity #PersonalFinance #TechForEveryone #StayProtected #CyberAware

    • Transcript
  • #246
    February 10 · 44 min

    When Federal Agents Ignore Court Orders: What Happens to Democracy? | Secure Talk with Claire Finkelstein

    What happens when federal law enforcement refuses to follow court orders? In Minneapolis, ICE agents denied state investigators access to crime scenes despite court-issued warrants—a breakdown that national security experts had been warning about for months. Dr. Claire Finkelstein, Professor of Law at University of Pennsylvania and Director of the Center for Ethics and the Rule of Law, saw this coming. In October 2024, she ran a tabletop exercise with over 30 retired military leaders simulating exactly this scenario: federal forces confronting state National Guard during civil unrest. The simulation escalated to violence faster than anyone expected, with few off-ramps once momentum built. Now that simulation is playing out in real time. Dr. Finkelstein has been on the legal front lines, representing 155 members of Congress before the Supreme Court. When the Court ruled the administration couldn't use National Guard troops as they intended, ICE agents surged instead—creating the confrontation we're seeing today. The questions are urgent: Can states prosecute federal agents who commit crimes in their jurisdiction? What happens when federal authorities claim immunity? How do soldiers follow orders when they can't trust those orders are lawful? The Supreme Court's immunity decision has made these questions harder to answer. This conversation explores what happens when rule of law meets political will, and what remains when the institutions designed to protect democracy face their greatest test. #CyberSecurity #NationalSecurity #Democracy #RuleOfLaw #Minnesota #Minneapolis Resources: Finkelstein, Claire. (2026, January 21). We ran high-level US civil war simulations. Minessota is exactly how they start. The Guardian. https://www.theguardian.com/commentisfree/2026/jan/21/ice-minnesota-trump

    • Transcript
  • #245
    January 27 · 55 min

    Shared Wisdom: Why AI Should Enhance Human Judgment, Not Replace It | Secure Talk with Alex Pentland

    Most AI discourse swings between paradise and doom—but the real question is how we architect these systems to enhance human understanding rather than replace decision-making. MIT Professor Alex "Sandy" Pentland reveals why treating AI as an information tool instead of an authority is critical for cybersecurity teams, business leaders, and anyone navigating the intersection of technology and culture. The math is stark: 90% of social media users are represented by only 3% of tweets. We're making decisions based on algorithmic extremes, not community wisdom. Pentland shows how Taiwan used the Polis platform to restore government trust from 7% to 70% by eliminating follower counts and visualizing the full spectrum of opinion—proving most people agree more than they think. For security professionals, the implications are profound: culture drives security outcomes more than controls. The stories your team shares about breaches, vulnerabilities, and response protocols create the shared wisdom that determines whether you're actually secure. AI can help synthesize context and surface patterns across distributed organizations, but cannot replace the human judgment needed when edge cases and outliers occur. Drawing parallels to the Enlightenment—when letter-writing networks sparked unprecedented collaboration among scholars—Pentland argues we stand at a similar inflection point. We have tools that let us share information at unprecedented scale, yet our digital systems amplify loud voices and create echo chambers instead of fostering collective wisdom. His book "Shared Wisdom" offers a pragmatic framework for cultural evolution in the age of AI, recognizing we'll take steps forward, make mistakes, and need to choose our direction deliberately. Key insights include understanding AI as a statistical repackaging of human stories, recognizing how four waves of AI development have each failed in predictable ways, and learning why loyal agents—systems legally bound to serve your interests like doctors and lawyers—represent the future of trustworthy AI. Pentland also explains why audit trails and liability matter more than premature regulation, and how communities need local governance that's interoperable but not uniform. Alex "Sandy" Pentland is Stanford HAI Fellow, MIT Toshiba Professor, and member of the US National Academy of Engineering. Named one of "100 People to Watch This Century" by Newsweek and one of "seven most powerful data scientists in the world" by Forbes, his work established authentication standards for digital networks and contributed to pioneering EU privacy law. Episode Resources: Pentland, Alex. (2025). Shared Wisdom: Cultural Evolution in the Age of AI. The MIT Press. https://mitpress.mit.edu/9780262050999/shared-wisdom/

    • Transcript
  • #244
    January 13 · 46 min

    The 2026 Planning Episode: 5 key security imperatives.

    While most organizations treat security as a cost center, a select group is using it to win enterprise deals, open new markets, and outpace competitors. The difference? They've stopped asking "how much does security cost?" and started asking "how much value does security create?" This strategic edition synthesizes lessons from security leaders at Walmart, PayPal, Postman, and the defense industrial base to reveal the playbook for 2026: treating security as a business function that enables velocity, builds trust, and creates competitive moats. Five Strategic Imperatives for 2026: 1. Architect for the AI Identity Explosion When AI agents access your CRM, email, and databases on behalf of humans, who's accountable? Walmart's 10,000+ developers faced this at scale. Learn how to govern probabilistic, non-deterministic systems before deployment breaks. 2. Turn Supply Chain Security Into Competitive Advantage CMMC enforcement is here—Raytheon paid $8.4M, Penn State $1.25M. But smart contractors are leading with certification to win contracts. See how quantitative security standards are reshaping business relationships between primes and subs. 3. Extract Intelligence From Your Own Logs One organization prevented $3M in fraud using internal threat intelligence. Learn why focused AI models that analyze your specific environment outperform generic vendor feeds. 4. Make Security Your Primary Differentiator When SOC 2 Type II certification wins you three enterprise customers worth $2M ARR, security spending looks very different to the CFO. Discover how to position security as the reason customers choose you. 5. Build Culture, Not Tool Stacks The oil & gas industry made safety everyone's responsibility through culture, not technology. Apply the same principles to solve cybersecurity's 65% turnover crisis. Expert Insights From: Rishi Bhargava (Descope) | Tobias Yergin (Walmart) | Bob Kolasky (Exiger) | Chris Wysopal (Veracode) | Bill Anderson (Mattermost) | Satyam Patel (Kandji) | Sam Chehab (Postman) | Brian Wagner | Dimitry Shvartsman (PayPal) The Meta-Pattern: Organizations winning in 2026 measure security in business terms—revenue enabled, customers won, time to market reduced. They're not the "department of no" blocking progress—they're the team enabling fast, safe movement. 🎙️ SecureTalk: Strategic conversations with security leaders, hosted by Justin Beals 🔔 Subscribe for insights on AI security, CMMC, threat intelligence & security ROI

  • #243
    Dec 30, 2025 · 31 min

    Secure Talk Special Episode: "Building Secure Societies in the Age of Division: The Seven Lessons for Humanity Heading Into 2026"

    "In 20 years, we transformed food allergy awareness from nonexistent to universal—no law required. What if we could do the same for data security and AI governance?" This special episode reveals how grassroots cultural shifts create lasting change, and why 2026 might be the year cybersecurity professionals become architects of something bigger than defenses. We've distilled 2025's conversations with experts from Harvard, MIT, NYU, Brown, and the AI development frontlines into seven actionable lessons that reframe security from technical problem to human opportunity. From understanding the 800 billion AI agents already in our systems, to recognizing why your most valuable threat intelligence is already in your logs, to building the communities that make external defenses less necessary. Here's what successful security leaders are realizing: The organizations thriving in 2026 aren't just protecting systems—they're creating conditions where humans and AI can flourish together. THE SEVEN LESSONS: • Social division is our greatest vulnerability (and connection is our strength) • Technology won't save us from ourselves (but we can) • Real change happens through grassroots cultural shifts • AI demands fundamentally different thinking (here's how) • Our values can blind us (when to trust them, when not to) • The weakest links are often invisible (where to look) • Context matters more than technology (your advantage is closer than you think) FEATURING INSIGHTS FROM: Dr. Claire Robertson (NYU) | Greg Epstein (Harvard/MIT) | Dr. De Kai | Rishi Bhargava (Descope) | Tobias Yergin (Walmart AI) | Prof. Steven Sloman (Brown) | Lars Kruse | Brian Wagner | Dr. Aram Sinnreich | Jesse Gilbert PERFECT FOR: Security leaders building resilient organizations | Professionals navigating AI transformation | Anyone ready to move beyond purely technical solutions 🔗 StrikeGraph: https://strikegraph.com Which lesson will change how you approach security in 2026? #Cybersecurity #AIGovernance #SecurityLeadership #CyberResilience #AIEthics #CISO #ThreatIntelligence #FutureOfWork

  • #242
    Dec 16, 2025 · 56 min

    Building a Thriving Future: AI Ethics & Security in Virtual Worlds | Dr. Paola Cecchi - Dimeglio

    The mistakes we made building the internet don't have to be repeated in the metaverse—if we act now. Join SecureTalk host Justin Beals for an essential conversation with Dr. Paola Cecchi-Dimeglio about building secure, ethical virtual worlds. Dr. Cecchi-Dimeglio brings 25 years of experience advising governments, Fortune 500 companies, and global institutions on AI ethics and technology governance. Her new book "Building a Thriving Future: Metaverse and Multiverse" (MIT Press, 2025) provides frameworks for building virtual spaces that serve humanity rather than exploit it. CORE THEMES: • Security by design vs. security bolted on after problems emerge • How biases get encoded into AI systems—and prevention strategies • The critical role of "human in the loop" for AI oversight • Why good regulation creates business stability • Digital identity systems for global inclusion • Authentication and verification in virtual spaces • Cross-border legal frameworks for technology governance REAL-WORLD IMPACT: Over 1 billion people globally lack legal identification—virtual worlds could solve this through blockchain-based digital identity, or create new exclusions if built poorly. The standards we set now for authentication, verification, and identity control will determine whether these spaces become tools for human flourishing or mechanisms for surveillance. WHY THIS MATTERS NOW: Virtual worlds already exist—gaming platforms host billions of users AI is accelerating everything, including security vulnerabilities Deepfake technology is improving faster than detection methods The decisions made today will shape digital society for decades SURPRISING INSIGHTS: → Children currently detect deepfakes better than adults (but not for long) → Major consulting firms have sold governments expensive reports full of AI errors → Voice recognition systems historically failed on non-Western accents due to training data bias → Email autocorrect defaults "Paola" to "Paolo" because datasets contained more men than women ABOUT THE GUEST: Dr. Paola Cecchi-Dimeglio is a globally recognized expert in AI, big data, and behavioral science. She holds dual appointments at Harvard Law School and Kennedy School of Government, co-chairs the UN ITU Global Initiative on AI and Virtual Worlds, and has authored 70+ peer-reviewed publications. Her work advises the World Bank, European Commission, and Fortune 500 executives on ethical AI implementation. THE OPTIMISTIC VISION: Virtual worlds can tap talent anywhere, breaking geographic barriers. They can connect separated families, provide legal identity to excluded populations, and create opportunities we can't yet imagine—but only if we build them with security, ethics, and human values as foundational requirements. ABOUT SECURETALK: SecureTalk ranks in the top 2.5% of podcasts globally, making cybersecurity and compliance topics accessible to business leaders. Hosted by Justin Beals, CEO of Strike Graph and former network security engineer. Perfect for: Security professionals, technology leaders, business executives, policy makers, anyone concerned about building ethical AI systems and secure virtual worlds. 📚 "Building a Thriving Future: Metaverse and Multiverse" by Dr. Paola Cecchi-Dimeglio (MIT Press, 2025) #AIEthics #Cybersecurity #VirtualWorlds #TechnologyGovernance #MetaverseSecurity #DigitalEthics #AIRegulation #SecureByDesign

  • #241
    Dec 2, 2025 · 55 min

    Why Security Leaders Struggle With Security Culture | Steven Sloman on Secure Talk

    Brown University cognitive scientist Steven Sloman reveals the hidden mechanism driving cultural division—and why it matters for security leadership. In this wide-ranging conversation, Sloman explains the fundamental tension between sacred values and consequentialist thinking, and how understanding this dynamic transforms how leaders communicate risk and build organizational culture. Justin Beals opens with a personal story about leaving a religious environment defined by absolute values, setting the stage for an exploration of how cognitive science explains why extremists control discourse, why outrage dominates social media, and why having strong values might actually be essential for good decision-making. KEY TOPICS: • The two systems humans use for decision-making and why both matter • Why simplified positions dominate complex policy debates • How humor breaks through absolutist thinking • The critical difference between AI association and human deliberation • Why communities radicalize when they become too insular • Practical frameworks for leadership teams navigating value conflicts Sloman, author of "The Cost of Conviction: How Our Deepest Values Lead Us Astray," shares insights from decades of research on cognition, reasoning, and collective thinking. The conversation moves from abstract cognitive science to immediate applications for security professionals operating in organizations where tribal loyalties threaten evidence-based decision-making. Whether you're presenting risk assessments to boards, building security culture, or helping organizations function during divisive times, this episode offers frameworks for understanding when values serve us and when consequentialist analysis becomes essential. Resources: Sloman, S. (2025). The cost of conviction: How our deepest values lead us astray. MIT Press. (https://mitpress.mit.edu/9780262049825/the-cost-of-conviction/)

Showing 1–20 of 21 episodes