<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:media="http://search.yahoo.com/mrss/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <atom:link href="https://feeds.megaphone.fm/IDG8824901907" rel="self" type="application/rss+xml"/>
    <title>Cyber Sessions with Joan Goodchild</title>
    <link>https://www.csoonline.com/videos/cyber-sessions-with-joan-goodchild/</link>
    <language>en</language>
    <copyright></copyright>
    <description>Cybersecurity is constantly evolving, and so are the leaders who shape it. Hosted by veteran journalist Joan Goodchild, Cyber Sessions brings candid conversations with top CISOs, strategists, and industry influencers. Each episode cuts through the noise to explore the trends, challenges, and leadership insights that define the future of security.</description>
    <image>
      <url>https://megaphone.imgix.net/podcasts/236ad03a-c00a-11f0-b8e9-bfca83d56252/image/5e5014283e8ba78b99d4a70b8e4d8432.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress</url>
      <title>Cyber Sessions with Joan Goodchild</title>
      <link>https://www.csoonline.com/videos/cyber-sessions-with-joan-goodchild/</link>
    </image>
    <itunes:type>episodic</itunes:type>
    <itunes:subtitle></itunes:subtitle>
    <itunes:author>Foundry</itunes:author>
    <itunes:summary>Cybersecurity is constantly evolving, and so are the leaders who shape it. Hosted by veteran journalist Joan Goodchild, Cyber Sessions brings candid conversations with top CISOs, strategists, and industry influencers. Each episode cuts through the noise to explore the trends, challenges, and leadership insights that define the future of security.</itunes:summary>
    <content:encoded>
      <![CDATA[<p>Cybersecurity is constantly evolving, and so are the leaders who shape it. Hosted by veteran journalist Joan Goodchild, Cyber Sessions brings candid conversations with top CISOs, strategists, and industry influencers. Each episode cuts through the noise to explore the trends, challenges, and leadership insights that define the future of security.</p>]]>
    </content:encoded>
    <itunes:owner>
      <itunes:name>Foundry</itunes:name>
      <itunes:email>podcasts@foundryco.com</itunes:email>
    </itunes:owner>
    <itunes:image href="https://megaphone.imgix.net/podcasts/236ad03a-c00a-11f0-b8e9-bfca83d56252/image/5e5014283e8ba78b99d4a70b8e4d8432.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
    <itunes:category text="Technology">
    </itunes:category>
    <itunes:category text="Business">
    </itunes:category>
    <item>
      <title>Identity Has Become the New Security Perimeter</title>
      <description>The traditional network perimeter has largely dissolved, replaced
by a security landscape centered around identity, cloud access, machine
interactions, and third-party connectivity. In this conversation, Dustin Wilcox
examines why identity has become foundational to modern security architecture
and why many organizations still struggle to govern it effectively at scale.
The interview also explores executive communication, balancing usability with
security controls, and the operational risks organizations continue creating in
the pursuit of speed and convenience.



https://www.linkedin.com/in/dustin-wilcox-4896614/</description>
      <pubDate>Thu, 08 Oct 2026 18:43:00 -0000</pubDate>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:author>Foundry</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/2de42a74-c348-11f1-9507-438a277370de/image/2084086c90295572c690c35414ae67fc.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle></itunes:subtitle>
      <itunes:summary>The traditional network perimeter has largely dissolved, replaced
by a security landscape centered around identity, cloud access, machine
interactions, and third-party connectivity. In this conversation, Dustin Wilcox
examines why identity has become foundational to modern security architecture
and why many organizations still struggle to govern it effectively at scale.
The interview also explores executive communication, balancing usability with
security controls, and the operational risks organizations continue creating in
the pursuit of speed and convenience.



https://www.linkedin.com/in/dustin-wilcox-4896614/</itunes:summary>
      <content:encoded>
        <![CDATA[<p>
The traditional network perimeter has largely dissolved, replaced
by a security landscape centered around identity, cloud access, machine
interactions, and third-party connectivity. In this conversation, Dustin Wilcox
examines why identity has become foundational to modern security architecture
and why many organizations still struggle to govern it effectively at scale.
The interview also explores executive communication, balancing usability with
security controls, and the operational risks organizations continue creating in
the pursuit of speed and convenience.</p>
<p><br></p>
<p>https://www.linkedin.com/in/dustin-wilcox-4896614/




</p>]]>
      </content:encoded>
      <itunes:duration>487</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[2de42a74-c348-11f1-9507-438a277370de]]></guid>
      <enclosure url="https://traffic.megaphone.fm/FCI8250644303.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Why Email Still Works for Attackers</title>
      <description>Despite years of awareness training and security investment, email
remains one of the most effective attack vectors in cybersecurity. In this
conversation, Ryan Toscano discusses why organizations continue struggling with
phishing, impersonation, and social engineering at scale. The interview
examines the tension between security, usability, and customer trust, the
operational fatigue created by overwhelming security telemetry, and whether
organizations are still treating email security too much as a technical problem
instead of a human one.</description>
      <pubDate>Wed, 30 Sep 2026 17:46:00 -0000</pubDate>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:author>Foundry</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/ef595b64-bcf6-11f1-b0f2-873d7e60be80/image/2084086c90295572c690c35414ae67fc.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle></itunes:subtitle>
      <itunes:summary>Despite years of awareness training and security investment, email
remains one of the most effective attack vectors in cybersecurity. In this
conversation, Ryan Toscano discusses why organizations continue struggling with
phishing, impersonation, and social engineering at scale. The interview
examines the tension between security, usability, and customer trust, the
operational fatigue created by overwhelming security telemetry, and whether
organizations are still treating email security too much as a technical problem
instead of a human one.</itunes:summary>
      <content:encoded>
        <![CDATA[<p>Despite years of awareness training and security investment, email
remains one of the most effective attack vectors in cybersecurity. In this
conversation, Ryan Toscano discusses why organizations continue struggling with
phishing, impersonation, and social engineering at scale. The interview
examines the tension between security, usability, and customer trust, the
operational fatigue created by overwhelming security telemetry, and whether
organizations are still treating email security too much as a technical problem
instead of a human one.</p>
<p>




</p>]]>
      </content:encoded>
      <itunes:duration>371</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[ef595b64-bcf6-11f1-b0f2-873d7e60be80]]></guid>
      <enclosure url="https://traffic.megaphone.fm/FCI3148394442.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>The Evolving CISO: AI, Leadership and the Future of Cybersecurity</title>
      <description>Gary Harbison, CISO at Johnson &amp; Johnson and CSO Hall of Fame inductee, joins CSO’s Joan Goodchild to discuss how the CISO role has evolved, the growing importance of cybersecurity in business decision-making, and how AI is reshaping the industry. He shares his perspective on using AI to strengthen security, address emerging threats, and help cybersecurity teams work more effectively while keeping human talent at the center. https://www.linkedin.com/in/garyharbison/</description>
      <pubDate>Thu, 24 Sep 2026 17:33:00 -0000</pubDate>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:author>Foundry</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/148cd5e0-b83e-11f1-bd04-17d019259f63/image/2084086c90295572c690c35414ae67fc.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle></itunes:subtitle>
      <itunes:summary>Gary Harbison, CISO at Johnson &amp; Johnson and CSO Hall of Fame inductee, joins CSO’s Joan Goodchild to discuss how the CISO role has evolved, the growing importance of cybersecurity in business decision-making, and how AI is reshaping the industry. He shares his perspective on using AI to strengthen security, address emerging threats, and help cybersecurity teams work more effectively while keeping human talent at the center. https://www.linkedin.com/in/garyharbison/</itunes:summary>
      <content:encoded>
        <![CDATA[<p>Gary Harbison, CISO at Johnson &amp; Johnson and CSO Hall of Fame inductee, joins CSO’s Joan Goodchild to discuss how the CISO role has evolved, the growing importance of cybersecurity in business decision-making, and how AI is reshaping the industry. He shares his perspective on using AI to strengthen security, address emerging threats, and help cybersecurity teams work more effectively while keeping human talent at the center. https://www.linkedin.com/in/garyharbison/

</p>]]>
      </content:encoded>
      <itunes:duration>386</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[148cd5e0-b83e-11f1-bd04-17d019259f63]]></guid>
      <enclosure url="https://traffic.megaphone.fm/FCI7715213772.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Why Security Debt May Be a Bigger Risk Than Security Spend</title>
      <description>Organizations continue investing heavily in cybersecurity, yet many are simultaneously increasing operational complexity and long-term security fragility. In this interview, Selim Aissi explains the concept of security debt and why it may be a more meaningful measure of cyber risk than security budget size alone. The conversation explores how organizations unintentionally create risk through tool sprawl and operational complexity, how boards should think about long-term cyber resilience, and why AI and cloud expansion are accelerating security debt faster than many enterprises can manage.Nominate the companies setting the standard for innovation, resilience, and leadership in security. Submit your CSO Awards nominations by September 16 and celebrate the organizations shaping the future of cybersecurity at the 2026 CSO Cybersecurity Awards &amp; Conference.Follow CSO for more Business IT and Web Security News!</description>
      <pubDate>Thu, 10 Sep 2026 17:36:00 -0000</pubDate>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:author>Foundry</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/32b20f32-ad3e-11f1-81fd-030567c83754/image/2084086c90295572c690c35414ae67fc.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle></itunes:subtitle>
      <itunes:summary>Organizations continue investing heavily in cybersecurity, yet many are simultaneously increasing operational complexity and long-term security fragility. In this interview, Selim Aissi explains the concept of security debt and why it may be a more meaningful measure of cyber risk than security budget size alone. The conversation explores how organizations unintentionally create risk through tool sprawl and operational complexity, how boards should think about long-term cyber resilience, and why AI and cloud expansion are accelerating security debt faster than many enterprises can manage.Nominate the companies setting the standard for innovation, resilience, and leadership in security. Submit your CSO Awards nominations by September 16 and celebrate the organizations shaping the future of cybersecurity at the 2026 CSO Cybersecurity Awards &amp; Conference.Follow CSO for more Business IT and Web Security News!</itunes:summary>
      <content:encoded>
        <![CDATA[<p>
Organizations continue investing heavily in cybersecurity, yet many are simultaneously increasing operational complexity and long-term security fragility. In this interview, Selim Aissi explains the concept of security debt and why it may be a more meaningful measure of cyber risk than security budget size alone. The conversation explores how organizations unintentionally create risk through tool sprawl and operational complexity, how boards should think about long-term cyber resilience, and why AI and cloud expansion are accelerating security debt faster than many enterprises can manage.<br>Nominate the companies setting the standard for innovation, resilience, and leadership in security. Submit your CSO Awards nominations by September 16 and celebrate the organizations shaping the future of cybersecurity at the 2026 CSO Cybersecurity Awards &amp; Conference.<br>Follow CSO for more Business IT and Web Security News!

</p>]]>
      </content:encoded>
      <itunes:duration>951</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[32b20f32-ad3e-11f1-81fd-030567c83754]]></guid>
      <enclosure url="https://traffic.megaphone.fm/FCI6491269160.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Cybersecurity on the Front Lines of Critical Infrastructure</title>
      <description>Critical infrastructure operators are facing a rapidly evolving threat landscape where cyberattacks can create real-world operational disruption with national and economic consequences. In this conversation, Vaughn Hazen explores the growing convergence of cybercrime, geopolitics, and operational technology risk across transportation and logistics environments. The discussion examines the unique security challenges of protecting large-scale operational systems, the realities of resilience and incident response in critical infrastructure, and whether private industry is truly prepared for its expanding role in national cyber defense.Nominate the companies setting the standard for innovation, resilience, and leadership in security. Submit your CSO Awards nominations by September 16 and celebrate the organizations shaping the future of cybersecurity at the 2026 CSO Cybersecurity Awards &amp; Conference. #CSOconference #cybersecurity #csoonlineLearn more and submit a nomination today.&amp;nbsp;2026 CSO Conference: Awards</description>
      <pubDate>Wed, 12 Aug 2026 13:58:00 -0000</pubDate>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:author>Foundry</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/d84264ba-9655-11f1-8506-63ca7545dc10/image/2084086c90295572c690c35414ae67fc.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle></itunes:subtitle>
      <itunes:summary>Critical infrastructure operators are facing a rapidly evolving threat landscape where cyberattacks can create real-world operational disruption with national and economic consequences. In this conversation, Vaughn Hazen explores the growing convergence of cybercrime, geopolitics, and operational technology risk across transportation and logistics environments. The discussion examines the unique security challenges of protecting large-scale operational systems, the realities of resilience and incident response in critical infrastructure, and whether private industry is truly prepared for its expanding role in national cyber defense.Nominate the companies setting the standard for innovation, resilience, and leadership in security. Submit your CSO Awards nominations by September 16 and celebrate the organizations shaping the future of cybersecurity at the 2026 CSO Cybersecurity Awards &amp; Conference. #CSOconference #cybersecurity #csoonlineLearn more and submit a nomination today.&amp;nbsp;2026 CSO Conference: Awards</itunes:summary>
      <content:encoded>
        <![CDATA[<p>Critical infrastructure operators are facing a rapidly evolving threat landscape where cyberattacks can create real-world operational disruption with national and economic consequences. In this conversation, Vaughn Hazen explores the growing convergence of cybercrime, geopolitics, and operational technology risk across transportation and logistics environments. The discussion examines the unique security challenges of protecting large-scale operational systems, the realities of resilience and incident response in critical infrastructure, and whether private industry is truly prepared for its expanding role in national cyber defense.<br>Nominate the companies setting the standard for innovation, resilience, and leadership in security. Submit your CSO Awards nominations by September 16 and celebrate the organizations shaping the future of cybersecurity at the 2026 CSO Cybersecurity Awards &amp; Conference. #CSOconference #cybersecurity #csoonline<br>Learn more and submit a nomination today.&nbsp;<a href="https://url.usb.m.mimecastprotect.com/s/tutoC1Vo9oc5vXP5iLfkfV3nrE?domain=event.foundryco.com/">2026 CSO Conference: Awards</a>

</p>]]>
      </content:encoded>
      <itunes:duration>582</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[d84264ba-9655-11f1-8506-63ca7545dc10]]></guid>
      <enclosure url="https://traffic.megaphone.fm/FCI8216243061.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Cloud Security at a Breaking Point: AI, Complexity, and the Future of Trust</title>
      <description>As enterprises race to integrate AI, SaaS, APIs, and multi-cloud environments, cloud security complexity is accelerating faster than many organizations can realistically govern. In this conversation, Jim Reavis discusses where enterprise cloud strategy continues to break down, why shared responsibility models still create dangerous accountability gaps, and how AI adoption is exposing weaknesses in identity, trust, and risk management. The discussion also explores the long-term implications of increasingly interconnected cloud ecosystems and the security debt organizations may be unknowingly accumulating. Nominate the companies setting the standard for innovation, resilience, and leadership in security. Submit your CSO Awards nominations by September 16 and celebrate the organizations shaping the future of cybersecurity at the 2026 CSO Cybersecurity Awards &amp; Conference. #CSOconference #cybersecurity #csoonline</description>
      <pubDate>Thu, 06 Aug 2026 17:13:00 -0000</pubDate>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:author>Foundry</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/2efbe952-91ba-11f1-98f8-fb9db00a629b/image/2084086c90295572c690c35414ae67fc.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle></itunes:subtitle>
      <itunes:summary>As enterprises race to integrate AI, SaaS, APIs, and multi-cloud environments, cloud security complexity is accelerating faster than many organizations can realistically govern. In this conversation, Jim Reavis discusses where enterprise cloud strategy continues to break down, why shared responsibility models still create dangerous accountability gaps, and how AI adoption is exposing weaknesses in identity, trust, and risk management. The discussion also explores the long-term implications of increasingly interconnected cloud ecosystems and the security debt organizations may be unknowingly accumulating. Nominate the companies setting the standard for innovation, resilience, and leadership in security. Submit your CSO Awards nominations by September 16 and celebrate the organizations shaping the future of cybersecurity at the 2026 CSO Cybersecurity Awards &amp; Conference. #CSOconference #cybersecurity #csoonline</itunes:summary>
      <content:encoded>
        <![CDATA[<p>As enterprises race to integrate AI, SaaS, APIs, and multi-cloud environments, cloud security complexity is accelerating faster than many organizations can realistically govern. In this conversation, Jim Reavis discusses where enterprise cloud strategy continues to break down, why shared responsibility models still create dangerous accountability gaps, and how AI adoption is exposing weaknesses in identity, trust, and risk management. The discussion also explores the long-term implications of increasingly interconnected cloud ecosystems and the security debt organizations may be unknowingly accumulating. Nominate the companies setting the standard for innovation, resilience, and leadership in security. <br>Submit your CSO Awards nominations by September 16 and celebrate the organizations shaping the future of cybersecurity at the 2026 CSO Cybersecurity Awards &amp; Conference. #CSOconference #cybersecurity #csoonline

</p>]]>
      </content:encoded>
      <itunes:duration>1041</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[2efbe952-91ba-11f1-98f8-fb9db00a629b]]></guid>
      <enclosure url="https://traffic.megaphone.fm/FCI6932248430.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Moving Beyond the Checkbox in Human Risk Management</title>
      <description>Security awareness programs are evolving beyond compliance
exercises into broader human risk management strategies designed to change
behavior and reduce organizational exposure. In this conversation, Jason Harper
discusses the goals behind Uber’s Beyond the Checkbox program, the problems the
organization was trying to solve, and the lessons learned during
implementation. The interview also explores leadership feedback, employee
engagement, and how organizations can rethink security awareness as a measurable
business risk reduction strategy.</description>
      <pubDate>Thu, 30 Jul 2026 15:09:00 -0000</pubDate>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:author>Foundry</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/bb29196e-8c28-11f1-ad17-eb6f16ccbabb/image/2084086c90295572c690c35414ae67fc.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle></itunes:subtitle>
      <itunes:summary>Security awareness programs are evolving beyond compliance
exercises into broader human risk management strategies designed to change
behavior and reduce organizational exposure. In this conversation, Jason Harper
discusses the goals behind Uber’s Beyond the Checkbox program, the problems the
organization was trying to solve, and the lessons learned during
implementation. The interview also explores leadership feedback, employee
engagement, and how organizations can rethink security awareness as a measurable
business risk reduction strategy.</itunes:summary>
      <content:encoded>
        <![CDATA[<p>Security awareness programs are evolving beyond compliance
exercises into broader human risk management strategies designed to change
behavior and reduce organizational exposure. In this conversation, Jason Harper
discusses the goals behind Uber’s Beyond the Checkbox program, the problems the
organization was trying to solve, and the lessons learned during
implementation. The interview also explores leadership feedback, employee
engagement, and how organizations can rethink security awareness as a measurable
business risk reduction strategy.</p>
<p>




</p>]]>
      </content:encoded>
      <itunes:duration>516</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[bb29196e-8c28-11f1-ad17-eb6f16ccbabb]]></guid>
      <enclosure url="https://traffic.megaphone.fm/FCI2477703682.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>The Security Debt Crisis Inside AI-Generated Code</title>
      <description>AI coding assistants are rapidly changing how software is built,
but they are also introducing new forms of application risk and technical debt.
In this interview, John Strait examines how organizations are adopting
AI-generated code, the impact on software quality and vulnerability management,
and the growing challenge of balancing development speed with secure coding
practices. The conversation also explores governance gaps, remediation
limitations, and the blind spots many CISOs still have around application
security in the age of AI-assisted development.</description>
      <pubDate>Mon, 20 Jul 2026 18:25:00 -0000</pubDate>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:author>Foundry</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/67b55026-8468-11f1-bf50-bb60178b87a3/image/2084086c90295572c690c35414ae67fc.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle></itunes:subtitle>
      <itunes:summary>AI coding assistants are rapidly changing how software is built,
but they are also introducing new forms of application risk and technical debt.
In this interview, John Strait examines how organizations are adopting
AI-generated code, the impact on software quality and vulnerability management,
and the growing challenge of balancing development speed with secure coding
practices. The conversation also explores governance gaps, remediation
limitations, and the blind spots many CISOs still have around application
security in the age of AI-assisted development.</itunes:summary>
      <content:encoded>
        <![CDATA[<p>AI coding assistants are rapidly changing how software is built,
but they are also introducing new forms of application risk and technical debt.
In this interview, John Strait examines how organizations are adopting
AI-generated code, the impact on software quality and vulnerability management,
and the growing challenge of balancing development speed with secure coding
practices. The conversation also explores governance gaps, remediation
limitations, and the blind spots many CISOs still have around application
security in the age of AI-assisted development.</p>
<p>




</p>]]>
      </content:encoded>
      <itunes:duration>468</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[67b55026-8468-11f1-bf50-bb60178b87a3]]></guid>
      <enclosure url="https://traffic.megaphone.fm/FCI2613052028.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>AI-Generated Code and the Expanding Application Security Challenge</title>
      <description>Development teams are increasingly relying on AI coding tools to
accelerate software delivery, but many organizations still lack visibility into
the risks introduced by AI-assisted development. In this conversation, Sohail
Iqbal discusses how AI-generated code is changing software quality,
vulnerability detection, and application security governance. The interview
also explores remediation challenges, growing security debt, and the leadership
decisions CISOs must make to prevent application risk from compounding over
time.</description>
      <pubDate>Wed, 15 Jul 2026 20:17:00 -0000</pubDate>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:author>Foundry</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/37f4e2c0-808a-11f1-a5e6-838617150a64/image/2084086c90295572c690c35414ae67fc.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle></itunes:subtitle>
      <itunes:summary>Development teams are increasingly relying on AI coding tools to
accelerate software delivery, but many organizations still lack visibility into
the risks introduced by AI-assisted development. In this conversation, Sohail
Iqbal discusses how AI-generated code is changing software quality,
vulnerability detection, and application security governance. The interview
also explores remediation challenges, growing security debt, and the leadership
decisions CISOs must make to prevent application risk from compounding over
time.</itunes:summary>
      <content:encoded>
        <![CDATA[<p>Development teams are increasingly relying on AI coding tools to
accelerate software delivery, but many organizations still lack visibility into
the risks introduced by AI-assisted development. In this conversation, Sohail
Iqbal discusses how AI-generated code is changing software quality,
vulnerability detection, and application security governance. The interview
also explores remediation challenges, growing security debt, and the leadership
decisions CISOs must make to prevent application risk from compounding over
time.</p>
<p>




</p>]]>
      </content:encoded>
      <itunes:duration>881</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[37f4e2c0-808a-11f1-a5e6-838617150a64]]></guid>
      <enclosure url="https://traffic.megaphone.fm/FCI1953226270.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>The AI Security Problem Most Organizations Still Aren’t Talking About</title>
      <description>AI adoption is accelerating inside enterprises, but many organizations are still struggling to define what a mature AI security program actually looks like. Lamont Orange discusses the foundational principles of AI security, the risks hiding in plain sight, and the governance decisions organizations need to make now to reduce exposure before AI risk compounds. The conversation also examines practical controls, organizational accountability, and how CISOs can prioritize action when time and resources are limited.</description>
      <pubDate>Thu, 02 Jul 2026 16:24:00 -0000</pubDate>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:author>Foundry</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/83f46a72-7632-11f1-a03f-c7786b61ec8a/image/2084086c90295572c690c35414ae67fc.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle></itunes:subtitle>
      <itunes:summary>AI adoption is accelerating inside enterprises, but many organizations are still struggling to define what a mature AI security program actually looks like. Lamont Orange discusses the foundational principles of AI security, the risks hiding in plain sight, and the governance decisions organizations need to make now to reduce exposure before AI risk compounds. The conversation also examines practical controls, organizational accountability, and how CISOs can prioritize action when time and resources are limited.</itunes:summary>
      <content:encoded>
        <![CDATA[<p>AI adoption is accelerating inside enterprises, but many organizations are still struggling to define what a mature AI security program actually looks like. Lamont Orange discusses the foundational principles of AI security, the risks hiding in plain sight, and the governance decisions organizations need to make now to reduce exposure before AI risk compounds. The conversation also examines practical controls, organizational accountability, and how CISOs can prioritize action when time and resources are limited.</p>]]>
      </content:encoded>
      <itunes:duration>463</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[83f46a72-7632-11f1-a03f-c7786b61ec8a]]></guid>
      <enclosure url="https://traffic.megaphone.fm/FCI8731798115.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Defining Trustworthy AI Before AI Scales Beyond Control</title>
      <description>As enterprises move rapidly toward AI and agentic systems, questions around governance, trust, and accountability are becoming increasingly urgent. In this interview, Malcolm Harkins explores what trustworthy AI actually means, what organizations need to achieve it, and how existing cybersecurity and compliance frameworks are struggling to address the realities of AI model security. The discussion also examines the gaps emerging around governance, risk management, and accountability as organizations deploy increasingly autonomous systems.</description>
      <pubDate>Thu, 18 Jun 2026 15:38:00 -0000</pubDate>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:author>Foundry</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/d260172c-6b2b-11f1-ac51-9bf406c64553/image/2084086c90295572c690c35414ae67fc.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle></itunes:subtitle>
      <itunes:summary>As enterprises move rapidly toward AI and agentic systems, questions around governance, trust, and accountability are becoming increasingly urgent. In this interview, Malcolm Harkins explores what trustworthy AI actually means, what organizations need to achieve it, and how existing cybersecurity and compliance frameworks are struggling to address the realities of AI model security. The discussion also examines the gaps emerging around governance, risk management, and accountability as organizations deploy increasingly autonomous systems.</itunes:summary>
      <content:encoded>
        <![CDATA[<p>As enterprises move rapidly toward AI and agentic systems, questions around governance, trust, and accountability are becoming increasingly urgent. In this interview, Malcolm Harkins explores what trustworthy AI actually means, what organizations need to achieve it, and how existing cybersecurity and compliance frameworks are struggling to address the realities of AI model security. The discussion also examines the gaps emerging around governance, risk management, and accountability as organizations deploy increasingly autonomous systems.

</p>]]>
      </content:encoded>
      <itunes:duration>837</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[d260172c-6b2b-11f1-ac51-9bf406c64553]]></guid>
      <enclosure url="https://traffic.megaphone.fm/FCI1407603561.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Rethinking Security Awareness Through Human Risk Management</title>
      <description>Traditional security awareness programs often struggle to create lasting behavioral change inside organizations. In this interview, Missy Bentzen discusses how Docusign approached security awareness and human risk management through its partnership with Hoxhunt. The conversation explores the organizational challenges the program was designed to address, the results that stood out most during implementation, and how leadership and employees responded to a more behavior-focused approach to cybersecurity education.</description>
      <pubDate>Thu, 11 Jun 2026 19:23:00 -0000</pubDate>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:author>Foundry</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/0bed23ec-65cb-11f1-a993-cfa636dffea5/image/2084086c90295572c690c35414ae67fc.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle></itunes:subtitle>
      <itunes:summary>Traditional security awareness programs often struggle to create lasting behavioral change inside organizations. In this interview, Missy Bentzen discusses how Docusign approached security awareness and human risk management through its partnership with Hoxhunt. The conversation explores the organizational challenges the program was designed to address, the results that stood out most during implementation, and how leadership and employees responded to a more behavior-focused approach to cybersecurity education.</itunes:summary>
      <content:encoded>
        <![CDATA[<p>Traditional security awareness programs often struggle to create lasting behavioral change inside organizations. In this interview, Missy Bentzen discusses how Docusign approached security awareness and human risk management through its partnership with Hoxhunt. The conversation explores the organizational challenges the program was designed to address, the results that stood out most during implementation, and how leadership and employees responded to a more behavior-focused approach to cybersecurity education.

</p>]]>
      </content:encoded>
      <itunes:duration>491</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[0bed23ec-65cb-11f1-a993-cfa636dffea5]]></guid>
      <enclosure url="https://traffic.megaphone.fm/FCI5749875116.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Why AI Is Forcing a Rethink of Data Security</title>
      <description>Traditional security models were not designed for environments where AI systems continuously access, process, and learn from enterprise data. In this interview, Todd Moore explains why organizations are shifting toward more data-centric security strategies and what that change means in practice. The conversation explores unified data awareness, the growing importance of crypto-agility, and why organizations need to prepare now for both AI-driven risk and the coming realities of post-quantum security.</description>
      <pubDate>Thu, 04 Jun 2026 19:17:00 -0000</pubDate>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:author>Foundry</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/170d9454-604a-11f1-abe0-5b2ea0a9b462/image/2084086c90295572c690c35414ae67fc.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle></itunes:subtitle>
      <itunes:summary>Traditional security models were not designed for environments where AI systems continuously access, process, and learn from enterprise data. In this interview, Todd Moore explains why organizations are shifting toward more data-centric security strategies and what that change means in practice. The conversation explores unified data awareness, the growing importance of crypto-agility, and why organizations need to prepare now for both AI-driven risk and the coming realities of post-quantum security.</itunes:summary>
      <content:encoded>
        <![CDATA[<p>Traditional security models were not designed for environments where AI systems continuously access, process, and learn from enterprise data. In this interview, Todd Moore explains why organizations are shifting toward more data-centric security strategies and what that change means in practice. The conversation explores unified data awareness, the growing importance of crypto-agility, and why organizations need to prepare now for both AI-driven risk and the coming realities of post-quantum security.</p>]]>
      </content:encoded>
      <itunes:duration>416</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[170d9454-604a-11f1-abe0-5b2ea0a9b462]]></guid>
      <enclosure url="https://traffic.megaphone.fm/FCI6998023725.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Security Blind Spots: What the Louvre Heist Reveals About Your Organization</title>
      <description>What happens when the risks you ignore become the ones that hurt you most? In this episode of Cyber Sessions, Foundry’s Joan Goodchild is joined by Colin Zick, partner at Foley Hoag, to unpack two headline-making examples of security blind spots: The Louvre museum heist, including the now-infamous “Louvre” password The rise of AI note-takers inside sensitive corporate meetings Together, they explore how convenience, default settings, and overlooked fundamentals create security liabilities for organizations of every size. Colin explains why these incidents were predictable, preventable, and rooted in leadership decisions, culture gaps, and under-prioritized investments. What You’ll Learn in This Episode: - Why attackers always target your slowest control - How “kicking the can down the road” creates cumulative security failures - The cost of treating security as a “cost center” instead of loss prevention - Why AI note-takers are a litigation and confidentiality minefield How management blind spots—not technology—cause the biggest breaches Practical guidance on MFA adoption, accountability, and security culture How to redesign processes for hybrid/remote work so nothing “falls through the cracks” If you’re a CISO, CSO, security leader, or IT decision maker, this episode delivers actionable lessons on strengthening organizational resilience before the next attack. Like, comment, and subscribe for future episodes of Cyber Sessions, where we break down the technologies, trends, and threats shaping today’s security landscape. Follow CSO for more Business IT and Web Security News!</description>
      <pubDate>Thu, 21 May 2026 17:04:00 -0000</pubDate>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:author>Foundry</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/85bf943e-5536-11f1-856d-2b4ae44cfbe0/image/2084086c90295572c690c35414ae67fc.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle></itunes:subtitle>
      <itunes:summary>What happens when the risks you ignore become the ones that hurt you most? In this episode of Cyber Sessions, Foundry’s Joan Goodchild is joined by Colin Zick, partner at Foley Hoag, to unpack two headline-making examples of security blind spots: The Louvre museum heist, including the now-infamous “Louvre” password The rise of AI note-takers inside sensitive corporate meetings Together, they explore how convenience, default settings, and overlooked fundamentals create security liabilities for organizations of every size. Colin explains why these incidents were predictable, preventable, and rooted in leadership decisions, culture gaps, and under-prioritized investments. What You’ll Learn in This Episode: - Why attackers always target your slowest control - How “kicking the can down the road” creates cumulative security failures - The cost of treating security as a “cost center” instead of loss prevention - Why AI note-takers are a litigation and confidentiality minefield How management blind spots—not technology—cause the biggest breaches Practical guidance on MFA adoption, accountability, and security culture How to redesign processes for hybrid/remote work so nothing “falls through the cracks” If you’re a CISO, CSO, security leader, or IT decision maker, this episode delivers actionable lessons on strengthening organizational resilience before the next attack. Like, comment, and subscribe for future episodes of Cyber Sessions, where we break down the technologies, trends, and threats shaping today’s security landscape. Follow CSO for more Business IT and Web Security News!</itunes:summary>
      <content:encoded>
        <![CDATA[<p>
What happens when the risks you ignore become the ones that hurt you most? In this episode of Cyber Sessions, Foundry’s Joan Goodchild is joined by Colin Zick, partner at Foley Hoag, to unpack two headline-making examples of security blind spots: The Louvre museum heist, including the now-infamous “Louvre” password The rise of AI note-takers inside sensitive corporate meetings Together, they explore how convenience, default settings, and overlooked fundamentals create security liabilities for organizations of every size. Colin explains why these incidents were predictable, preventable, and rooted in leadership decisions, culture gaps, and under-prioritized investments. What You’ll Learn in This Episode: - Why attackers always target your slowest control - How “kicking the can down the road” creates cumulative security failures - The cost of treating security as a “cost center” instead of loss prevention - Why AI note-takers are a litigation and confidentiality minefield How management blind spots—not technology—cause the biggest breaches Practical guidance on MFA adoption, accountability, and security culture How to redesign processes for hybrid/remote work so nothing “falls through the cracks” If you’re a CISO, CSO, security leader, or IT decision maker, this episode delivers actionable lessons on strengthening organizational resilience before the next attack. Like, comment, and subscribe for future episodes of Cyber Sessions, where we break down the technologies, trends, and threats shaping today’s security landscape. Follow CSO for more Business IT and Web Security News!

</p>
<p><br></p>]]>
      </content:encoded>
      <itunes:duration>2026</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[85bf943e-5536-11f1-856d-2b4ae44cfbe0]]></guid>
      <enclosure url="https://traffic.megaphone.fm/FCI1568607674.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>How Intelligence and AI Are Changing Cyber Defense | Erin Whitmore, Former CIA</title>
      <description>What if you could stop cyberattacks before they happen? In this episode of Cyber Sessions, host Joan Goodchild sits down with Erin Whitmore, former CIA case officer and current Head of The Cipher division at Cynturion Group, to discuss how her team uses intelligence and AI to anticipate and prevent attacks before adversaries strike.



Whitmore reveals how proactive cybersecurity is blending human intuition, artificial intelligence, and offensive tactics to predict threats — while balancing the line between privacy and protection.</description>
      <pubDate>Wed, 04 Feb 2026 16:13:00 -0000</pubDate>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:author>Foundry</itunes:author>
      <itunes:subtitle></itunes:subtitle>
      <itunes:summary>What if you could stop cyberattacks before they happen? In this episode of Cyber Sessions, host Joan Goodchild sits down with Erin Whitmore, former CIA case officer and current Head of The Cipher division at Cynturion Group, to discuss how her team uses intelligence and AI to anticipate and prevent attacks before adversaries strike.



Whitmore reveals how proactive cybersecurity is blending human intuition, artificial intelligence, and offensive tactics to predict threats — while balancing the line between privacy and protection.</itunes:summary>
      <content:encoded>
        <![CDATA[<p>What if you could stop cyberattacks before they happen? In this episode of Cyber Sessions, host Joan Goodchild sits down with Erin Whitmore, former CIA case officer and current Head of The Cipher division at Cynturion Group, to discuss how her team uses intelligence and AI to anticipate and prevent attacks before adversaries strike.</p>
<p><br></p>
<p>Whitmore reveals how proactive cybersecurity is blending human intuition, artificial intelligence, and offensive tactics to predict threats — while balancing the line between privacy and protection.</p>]]>
      </content:encoded>
      <itunes:duration>1650</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[7b223d74-01e4-11f1-bbf0-5b655b5f1746]]></guid>
      <enclosure url="https://traffic.megaphone.fm/IDG7252325031.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Inside the SMB Threat Landscape: AT&amp;T’s Senthil Ramakrishnan on Why Small Businesses Are Cybercrime’s Favorite Target	</title>
      <description>In this episode of Cyber Sessions, Senthil Ramakrishnan, Head of Cyber Product Strategy at AT&amp;T, talks about why small and midsize businesses have become prime - and often unprepared - targets for cyberattacks and what they can do to improve their security posture.</description>
      <pubDate>Tue, 13 Jan 2026 20:10:00 -0000</pubDate>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:author>Foundry</itunes:author>
      <itunes:subtitle></itunes:subtitle>
      <itunes:summary>In this episode of Cyber Sessions, Senthil Ramakrishnan, Head of Cyber Product Strategy at AT&amp;T, talks about why small and midsize businesses have become prime - and often unprepared - targets for cyberattacks and what they can do to improve their security posture.</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this episode of Cyber Sessions, Senthil Ramakrishnan, Head of Cyber Product Strategy at AT&amp;T, talks about why small and midsize businesses have become prime - and often unprepared - targets for cyberattacks and what they can do to improve their security posture.</p>]]>
      </content:encoded>
      <itunes:duration>1361</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[e68af23e-f0bb-11f0-82ae-e36b399486d8]]></guid>
      <enclosure url="https://traffic.megaphone.fm/IDG1130069429.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Inside Visa’s Cyber Defense:  CISO Subra Kumaraswamy on blending AI and Human Defense</title>
      <description>In this episode of Cyber Sessions, Visa CISO Subra Kumaraswamy takes us inside the company’s 24/7 Cyber Fusion Centers, where AI-driven defenses block 90 million attacks and 11 million phishing emails each month. He shares how his team achieves “zero breach, zero disruption” across 200+ countries—and what lessons other security leaders can learn from Visa’s global</description>
      <pubDate>Mon, 15 Dec 2025 18:23:00 -0000</pubDate>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:author>Foundry</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/2e3f31ca-d9e3-11f0-9f01-a32c1c18f174/image/4f820cce5aff3b2376ffa1ed3213d153.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle></itunes:subtitle>
      <itunes:summary>In this episode of Cyber Sessions, Visa CISO Subra Kumaraswamy takes us inside the company’s 24/7 Cyber Fusion Centers, where AI-driven defenses block 90 million attacks and 11 million phishing emails each month. He shares how his team achieves “zero breach, zero disruption” across 200+ countries—and what lessons other security leaders can learn from Visa’s global</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this episode of Cyber Sessions, Visa CISO Subra Kumaraswamy takes us inside the company’s 24/7 Cyber Fusion Centers, where AI-driven defenses block 90 million attacks and 11 million phishing emails each month. He shares how his team achieves “zero breach, zero disruption” across 200+ countries—and what lessons other security leaders can learn from Visa’s global </p>]]>
      </content:encoded>
      <itunes:duration>1532</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[2e3f31ca-d9e3-11f0-9f01-a32c1c18f174]]></guid>
      <enclosure url="https://traffic.megaphone.fm/IDG5654740553.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>CISO Reality: Record Pay, Rising Pressure, and Retention Risk	</title>
      <description>In this edition of Cyber Sessions, host Joan Goodchild talks with IANS researcher Nick Kakolowski about why midmarket CISOs now earn record-high pay but are still are stretched thin by expanding responsibilities and limited resources.</description>
      <pubDate>Wed, 10 Dec 2025 20:37:00 -0000</pubDate>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:author>Foundry</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/fdfa42fe-d607-11f0-8c11-cfb775b16d00/image/4f820cce5aff3b2376ffa1ed3213d153.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle></itunes:subtitle>
      <itunes:summary>In this edition of Cyber Sessions, host Joan Goodchild talks with IANS researcher Nick Kakolowski about why midmarket CISOs now earn record-high pay but are still are stretched thin by expanding responsibilities and limited resources.</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this edition of Cyber Sessions, host Joan Goodchild talks with IANS researcher Nick Kakolowski about why midmarket CISOs now earn record-high pay but are still are stretched thin by expanding responsibilities and limited resources.</p>]]>
      </content:encoded>
      <itunes:duration>1592</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[fdfa42fe-d607-11f0-8c11-cfb775b16d00]]></guid>
      <enclosure url="https://traffic.megaphone.fm/IDG7176262347.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Ep. 2: The Future of Cybersecurity Leadership: AI, Governance &amp; Education | Kevin Powers, Boston College</title>
      <description>How is cybersecurity education changing — and what skills do tomorrow’s security leaders really need? In this episode of Security Sessions, host Joan Goodchild talks with Kevin Powers, Faculty Director and Lecturer at Boston College Law School, about how cybersecurity has evolved from a technical problem to a core business and legal function.</description>
      <pubDate>Wed, 19 Nov 2025 20:47:00 -0000</pubDate>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:author>Foundry</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/fa4225ee-c588-11f0-a49c-ff3d386f8d24/image/4f820cce5aff3b2376ffa1ed3213d153.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle></itunes:subtitle>
      <itunes:summary>How is cybersecurity education changing — and what skills do tomorrow’s security leaders really need? In this episode of Security Sessions, host Joan Goodchild talks with Kevin Powers, Faculty Director and Lecturer at Boston College Law School, about how cybersecurity has evolved from a technical problem to a core business and legal function.</itunes:summary>
      <content:encoded>
        <![CDATA[<p>How is cybersecurity education changing — and what skills do tomorrow’s security leaders really need? In this episode of Security Sessions, host Joan Goodchild talks with Kevin Powers, Faculty Director and Lecturer at Boston College Law School, about how cybersecurity has evolved from a technical problem to a core business and legal function.</p>
<p><br></p>]]>
      </content:encoded>
      <itunes:duration>1358</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[fa4225ee-c588-11f0-a49c-ff3d386f8d24]]></guid>
      <enclosure url="https://traffic.megaphone.fm/IDG6615460723.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Ep. 1: Inside Black Hat: Andy Ellis on vendor buzzwords, AI hype, and the future of the CISO role</title>
      <description>In this debut episode of Cyber Sessions, host Joan Goodchild sits down with Andy Ellis, veteran CSO and member of the CSO Hall of Fame, to learn about his State of the Security Vendor report from the Black Hat show floor. From AI flooding vendor taglines to the real challenges of code security and identity, Ellis shares sharp insights on what’s hype, what matters, and where the CISO role is headed next.</description>
      <pubDate>Wed, 12 Nov 2025 21:27:00 -0000</pubDate>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:author>Foundry</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/62e05916-c00e-11f0-acd8-ffd5386dce66/image/4f820cce5aff3b2376ffa1ed3213d153.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle></itunes:subtitle>
      <itunes:summary>In this debut episode of Cyber Sessions, host Joan Goodchild sits down with Andy Ellis, veteran CSO and member of the CSO Hall of Fame, to learn about his State of the Security Vendor report from the Black Hat show floor. From AI flooding vendor taglines to the real challenges of code security and identity, Ellis shares sharp insights on what’s hype, what matters, and where the CISO role is headed next.</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this debut episode of Cyber Sessions, host Joan Goodchild sits down with Andy Ellis, veteran CSO and member of the CSO Hall of Fame, to learn about his State of the Security Vendor report from the Black Hat show floor. From AI flooding vendor taglines to the real challenges of code security and identity, Ellis shares sharp insights on what’s hype, what matters, and where the CISO role is headed next.</p>]]>
      </content:encoded>
      <itunes:duration>1829</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[62e05916-c00e-11f0-acd8-ffd5386dce66]]></guid>
      <enclosure url="https://traffic.megaphone.fm/IDG8958688545.mp3" length="0" type="audio/mpeg"/>
    </item>
  </channel>
</rss>
