<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="/stylesheet.xsl" type="text/xsl"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:podcast="https://podcastindex.org/namespace/1.0">
  <channel>
    <atom:link rel="self" type="application/rss+xml" href="https://feeds.transistor.fm/cyber-ai-perspectives-insights-on-cybersecurity-and-ai-governance" title="MP3 Audio"/>
    <atom:link rel="hub" href="https://pubsubhubbub.appspot.com/"/>
    <podcast:podping usesPodping="true"/>
    <title>Cyber &amp; AI Perspectives — Insights on Cybersecurity and AI Governance</title>
    <generator>Transistor (https://transistor.fm)</generator>
    <itunes:new-feed-url>https://feeds.transistor.fm/cyber-ai-perspectives-insights-on-cybersecurity-and-ai-governance</itunes:new-feed-url>
    <description>Cyber &amp; AI Perspectives is a podcast for cybersecurity and AI governance professionals, covering the most important trends, risks, and strategic developments shaping organizations today.

Hosted by Dejan Kosutic, one of the leading experts in cybersecurity and AI governance, each episode delivers deep insights and independent analysis you are unlikely to hear elsewhere — helping you understand what matters now and what is coming next.

To provide feedback or suggest topics for future episodes, contact us at: podcast@advisera.com</description>
    <copyright>©2026 Advisera Expert Solutions</copyright>
    <podcast:guid>dcce0367-a3af-5225-998f-86aefd4a59ff</podcast:guid>
    <podcast:locked>yes</podcast:locked>
    <podcast:person role="Host">Dejan Kosutic</podcast:person>
    <language>en</language>
    <pubDate>Fri, 21 Aug 2026 13:30:04 +0200</pubDate>
    <lastBuildDate>Fri, 21 Aug 2026 13:31:10 +0200</lastBuildDate>
    <link>https://advisera.com</link>
    <image>
      <url>https://img.transistorcdn.com/qKizfjePB2voI-I9OAAdo8B1HBtASKurXbijpFomu5k/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS84MzQ4/YTBiMzkwMjQzZGU3/YWZmOTRkZmJkZGJm/OTVhMC5wbmc.jpg</url>
      <title>Cyber &amp; AI Perspectives — Insights on Cybersecurity and AI Governance</title>
      <link>https://advisera.com</link>
    </image>
    <itunes:category text="Technology"/>
    <itunes:category text="Business"/>
    <itunes:type>episodic</itunes:type>
    <itunes:author>Dejan Kosutic</itunes:author>
    <itunes:image href="https://img.transistorcdn.com/qKizfjePB2voI-I9OAAdo8B1HBtASKurXbijpFomu5k/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS84MzQ4/YTBiMzkwMjQzZGU3/YWZmOTRkZmJkZGJm/OTVhMC5wbmc.jpg"/>
    <itunes:summary>Cyber &amp; AI Perspectives is a podcast for cybersecurity and AI governance professionals, covering the most important trends, risks, and strategic developments shaping organizations today.

Hosted by Dejan Kosutic, one of the leading experts in cybersecurity and AI governance, each episode delivers deep insights and independent analysis you are unlikely to hear elsewhere — helping you understand what matters now and what is coming next.

To provide feedback or suggest topics for future episodes, contact us at: podcast@advisera.com</itunes:summary>
    <itunes:subtitle>Cyber &amp; AI Perspectives is a podcast for cybersecurity and AI governance professionals, covering the most important trends, risks, and strategic developments shaping organizations today.</itunes:subtitle>
    <itunes:keywords>cybersecurity governance, AI governance, strategy, insights, perspectives, trends, risks</itunes:keywords>
    <itunes:owner>
      <itunes:name>Dejan Kosutic</itunes:name>
    </itunes:owner>
    <itunes:complete>No</itunes:complete>
    <itunes:explicit>No</itunes:explicit>
    <item>
      <title>Stop Preparing Evidence for Your ISO 27001 Audit</title>
      <itunes:episode>8</itunes:episode>
      <podcast:episode>8</podcast:episode>
      <itunes:title>Stop Preparing Evidence for Your ISO 27001 Audit</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">1b10dee6-f047-4138-80d7-0549b97ffb31</guid>
      <link>https://share.transistor.fm/s/5e9de25d</link>
      <description>
        <![CDATA[<p>If you’re preparing for ISO 27001 certification, shift your focus from asking “How do we prepare the evidence?” to “Are our security processes actually working?” When risks are properly assessed, controls are appropriate, people know their responsibilities, and controls are consistently performed and monitored, the evidence will largely already exist. Build and strengthen the security processes first, and let the evidence follow - because security is about becoming more secure, not about creating documentation for its own sake.</p><p>LINK FROM THE VIDEO<br>► ISO 27001 Certification: What Will the Auditor Look For? | Interview with Aron Lange | EP36 <a href="https://www.youtube.com/watch?v=4HNwmgCiKyU">https://www.youtube.com/watch?v=4HNwmgCiKyU</a></p>
<ul><li>(00:00) - Stop Preparing Evidence for Your ISO 27001 Audit</li>
<li>(00:17) - How ISO 27001 Certification Audit Works</li>
<li>(01:35) - How Auditors Collect Evidence</li>
<li>(02:27) - Three Things Companies Get Wrong</li>
<li>(04:04) - “Push” vs “Pull” Approach</li>
<li>(04:30) - Evidence Does Not Improve Your Security</li>
<li>(05:01) - Build Security Processes Not Evidence</li>
<li>(06:14) - Let The Evidence Follow</li>
</ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>If you’re preparing for ISO 27001 certification, shift your focus from asking “How do we prepare the evidence?” to “Are our security processes actually working?” When risks are properly assessed, controls are appropriate, people know their responsibilities, and controls are consistently performed and monitored, the evidence will largely already exist. Build and strengthen the security processes first, and let the evidence follow - because security is about becoming more secure, not about creating documentation for its own sake.</p><p>LINK FROM THE VIDEO<br>► ISO 27001 Certification: What Will the Auditor Look For? | Interview with Aron Lange | EP36 <a href="https://www.youtube.com/watch?v=4HNwmgCiKyU">https://www.youtube.com/watch?v=4HNwmgCiKyU</a></p>
<ul><li>(00:00) - Stop Preparing Evidence for Your ISO 27001 Audit</li>
<li>(00:17) - How ISO 27001 Certification Audit Works</li>
<li>(01:35) - How Auditors Collect Evidence</li>
<li>(02:27) - Three Things Companies Get Wrong</li>
<li>(04:04) - “Push” vs “Pull” Approach</li>
<li>(04:30) - Evidence Does Not Improve Your Security</li>
<li>(05:01) - Build Security Processes Not Evidence</li>
<li>(06:14) - Let The Evidence Follow</li>
</ul>]]>
      </content:encoded>
      <pubDate>Fri, 21 Aug 2026 13:30:00 +0200</pubDate>
      <author>Dejan Kosutic</author>
      <enclosure url="https://media.transistor.fm/5e9de25d/79ef7b70.mp3" length="6871527" type="audio/mpeg"/>
      <itunes:author>Dejan Kosutic</itunes:author>
      <itunes:duration>426</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>If you’re preparing for ISO 27001 certification, shift your focus from asking “How do we prepare the evidence?” to “Are our security processes actually working?” When risks are properly assessed, controls are appropriate, people know their responsibilities, and controls are consistently performed and monitored, the evidence will largely already exist. Build and strengthen the security processes first, and let the evidence follow - because security is about becoming more secure, not about creating documentation for its own sake.</p><p>LINK FROM THE VIDEO<br>► ISO 27001 Certification: What Will the Auditor Look For? | Interview with Aron Lange | EP36 <a href="https://www.youtube.com/watch?v=4HNwmgCiKyU">https://www.youtube.com/watch?v=4HNwmgCiKyU</a></p>
<ul><li>(00:00) - Stop Preparing Evidence for Your ISO 27001 Audit</li>
<li>(00:17) - How ISO 27001 Certification Audit Works</li>
<li>(01:35) - How Auditors Collect Evidence</li>
<li>(02:27) - Three Things Companies Get Wrong</li>
<li>(04:04) - “Push” vs “Pull” Approach</li>
<li>(04:30) - Evidence Does Not Improve Your Security</li>
<li>(05:01) - Build Security Processes Not Evidence</li>
<li>(06:14) - Let The Evidence Follow</li>
</ul>]]>
      </itunes:summary>
      <itunes:keywords>cybersecurity governance, AI governance, strategy, insights, perspectives, trends, risks</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:person role="Host">Dejan Kosutic</podcast:person>
      <podcast:chapters url="https://share.transistor.fm/s/5e9de25d/chapters.json" type="application/json+chapters"/>
    </item>
    <item>
      <title>Cybersecurity is More Than AI: 3 Trends You Shouldn’t Ignore</title>
      <itunes:episode>7</itunes:episode>
      <podcast:episode>7</podcast:episode>
      <itunes:title>Cybersecurity is More Than AI: 3 Trends You Shouldn’t Ignore</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">ed7f02ea-1e70-443b-9311-3d7a76e30865</guid>
      <link>https://share.transistor.fm/s/a06a5c97</link>
      <description>
        <![CDATA[<p>Dejan Kosutic argues that a major cybersecurity mistake today is focusing so much on AI that companies overlook other critical trends. He highlights three non-AI areas that need attention: quantum computing and post-quantum cryptography, emphasizing the “harvest now, decrypt later” threat and why PQC matters now; supply chain security, noting that breaches often occur through vendors and that third-party risk management is difficult because it is technical, organizational, and legal; and a shift from pure prevention to cyber resilience, meaning companies must assume serious incidents will happen and prepare to continue operating and recover after attacks. He concludes that AI is important but shouldn’t become a blind spot, and points listeners to a podcast episode with Andrew Gault for more on quantum.</p><p>LINK FROM THE VIDEO<br>► What CISOs Must Do Now About Quantum? | Interview with Andrew Gault | EP34 <a href="https://www.youtube.com/watch?v=QEwaCY1OPhY">https://www.youtube.com/watch?v=QEwaCY1OPhY</a></p>
<ul><li>(00:00) - Cybersecurity is More Than AI</li>
<li>(01:03) - 1. Quantum Computing and Post-Quantum Cryptography</li>
<li>(02:19) - 2. Supply Chain Security and Third-Party Risk</li>
<li>(03:44) - 3. From Cybersecurity to Cyber Resilience</li>
<li>(04:39) - The Bigger Picture</li>
</ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Dejan Kosutic argues that a major cybersecurity mistake today is focusing so much on AI that companies overlook other critical trends. He highlights three non-AI areas that need attention: quantum computing and post-quantum cryptography, emphasizing the “harvest now, decrypt later” threat and why PQC matters now; supply chain security, noting that breaches often occur through vendors and that third-party risk management is difficult because it is technical, organizational, and legal; and a shift from pure prevention to cyber resilience, meaning companies must assume serious incidents will happen and prepare to continue operating and recover after attacks. He concludes that AI is important but shouldn’t become a blind spot, and points listeners to a podcast episode with Andrew Gault for more on quantum.</p><p>LINK FROM THE VIDEO<br>► What CISOs Must Do Now About Quantum? | Interview with Andrew Gault | EP34 <a href="https://www.youtube.com/watch?v=QEwaCY1OPhY">https://www.youtube.com/watch?v=QEwaCY1OPhY</a></p>
<ul><li>(00:00) - Cybersecurity is More Than AI</li>
<li>(01:03) - 1. Quantum Computing and Post-Quantum Cryptography</li>
<li>(02:19) - 2. Supply Chain Security and Third-Party Risk</li>
<li>(03:44) - 3. From Cybersecurity to Cyber Resilience</li>
<li>(04:39) - The Bigger Picture</li>
</ul>]]>
      </content:encoded>
      <pubDate>Fri, 07 Aug 2026 16:32:20 +0200</pubDate>
      <author>Dejan Kosutic</author>
      <enclosure url="https://media.transistor.fm/a06a5c97/f31d2382.mp3" length="5819647" type="audio/mpeg"/>
      <itunes:author>Dejan Kosutic</itunes:author>
      <itunes:duration>360</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>Dejan Kosutic argues that a major cybersecurity mistake today is focusing so much on AI that companies overlook other critical trends. He highlights three non-AI areas that need attention: quantum computing and post-quantum cryptography, emphasizing the “harvest now, decrypt later” threat and why PQC matters now; supply chain security, noting that breaches often occur through vendors and that third-party risk management is difficult because it is technical, organizational, and legal; and a shift from pure prevention to cyber resilience, meaning companies must assume serious incidents will happen and prepare to continue operating and recover after attacks. He concludes that AI is important but shouldn’t become a blind spot, and points listeners to a podcast episode with Andrew Gault for more on quantum.</p><p>LINK FROM THE VIDEO<br>► What CISOs Must Do Now About Quantum? | Interview with Andrew Gault | EP34 <a href="https://www.youtube.com/watch?v=QEwaCY1OPhY">https://www.youtube.com/watch?v=QEwaCY1OPhY</a></p>
<ul><li>(00:00) - Cybersecurity is More Than AI</li>
<li>(01:03) - 1. Quantum Computing and Post-Quantum Cryptography</li>
<li>(02:19) - 2. Supply Chain Security and Third-Party Risk</li>
<li>(03:44) - 3. From Cybersecurity to Cyber Resilience</li>
<li>(04:39) - The Bigger Picture</li>
</ul>]]>
      </itunes:summary>
      <itunes:keywords>cybersecurity governance, AI governance, strategy, insights, perspectives, trends, risks</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:person role="Host">Dejan Kosutic</podcast:person>
      <podcast:chapters url="https://share.transistor.fm/s/a06a5c97/chapters.json" type="application/json+chapters"/>
    </item>
    <item>
      <title>Who Will Win the Software Vulnerability Race? Five Scenarios  </title>
      <itunes:episode>6</itunes:episode>
      <podcast:episode>6</podcast:episode>
      <itunes:title>Who Will Win the Software Vulnerability Race? Five Scenarios  </itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">5886e7e6-ccac-4460-a1ad-20b11e7bd5a6</guid>
      <link>https://share.transistor.fm/s/0fcaf2c4</link>
      <description>
        <![CDATA[<p>Dejan Kosutic explains how increasingly powerful AI models will be accessible to both attackers and defenders, accelerating the software vulnerability race. He outlines five scenarios: permanent defender advantage, permanent attacker advantage, a two-tier world where well-resourced organizations improve while SMEs and under-resourced sectors become prime targets, a “catch-up” period where breaches spike then decline as patching catches up, and “drowning the defenders,” where AI-generated code, more low-skill attackers, and overwhelming vulnerability reports strain weak teams. He concludes AI changes speed, not fundamentals, and recommends a related podcast episode on Mythos and vulnerability management.</p><p>LINK FROM THE VIDEO<br>► Anthropic’s Mythos and the Future of Vulnerability Management | Interview with Thom Langford | EP35 <a href="https://www.youtube.com/watch?v=axLwXoUYOak">https://www.youtube.com/watch?v=axLwXoUYOak</a></p>
<ul><li>(00:00) - Who Will Win the Software Vulnerability Race?</li>
<li>(00:19) - Five Key Trends</li>
<li>(01:32) - Permanent Defender Edge Scenario</li>
<li>(01:50) - Permanent Attacker Edge Scenario</li>
<li>(02:10) - Two-Tier Security Scenario</li>
<li>(02:48) - Catch Up Scenario</li>
<li>(03:28) - Drowning Defenders Scenario</li>
<li>(04:18) - Takeaways and Wrap Up</li>
</ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Dejan Kosutic explains how increasingly powerful AI models will be accessible to both attackers and defenders, accelerating the software vulnerability race. He outlines five scenarios: permanent defender advantage, permanent attacker advantage, a two-tier world where well-resourced organizations improve while SMEs and under-resourced sectors become prime targets, a “catch-up” period where breaches spike then decline as patching catches up, and “drowning the defenders,” where AI-generated code, more low-skill attackers, and overwhelming vulnerability reports strain weak teams. He concludes AI changes speed, not fundamentals, and recommends a related podcast episode on Mythos and vulnerability management.</p><p>LINK FROM THE VIDEO<br>► Anthropic’s Mythos and the Future of Vulnerability Management | Interview with Thom Langford | EP35 <a href="https://www.youtube.com/watch?v=axLwXoUYOak">https://www.youtube.com/watch?v=axLwXoUYOak</a></p>
<ul><li>(00:00) - Who Will Win the Software Vulnerability Race?</li>
<li>(00:19) - Five Key Trends</li>
<li>(01:32) - Permanent Defender Edge Scenario</li>
<li>(01:50) - Permanent Attacker Edge Scenario</li>
<li>(02:10) - Two-Tier Security Scenario</li>
<li>(02:48) - Catch Up Scenario</li>
<li>(03:28) - Drowning Defenders Scenario</li>
<li>(04:18) - Takeaways and Wrap Up</li>
</ul>]]>
      </content:encoded>
      <pubDate>Fri, 24 Jul 2026 13:30:00 +0200</pubDate>
      <author>Dejan Kosutic</author>
      <enclosure url="https://media.transistor.fm/0fcaf2c4/77ce1ae3.mp3" length="5228444" type="audio/mpeg"/>
      <itunes:author>Dejan Kosutic</itunes:author>
      <itunes:duration>323</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>Dejan Kosutic explains how increasingly powerful AI models will be accessible to both attackers and defenders, accelerating the software vulnerability race. He outlines five scenarios: permanent defender advantage, permanent attacker advantage, a two-tier world where well-resourced organizations improve while SMEs and under-resourced sectors become prime targets, a “catch-up” period where breaches spike then decline as patching catches up, and “drowning the defenders,” where AI-generated code, more low-skill attackers, and overwhelming vulnerability reports strain weak teams. He concludes AI changes speed, not fundamentals, and recommends a related podcast episode on Mythos and vulnerability management.</p><p>LINK FROM THE VIDEO<br>► Anthropic’s Mythos and the Future of Vulnerability Management | Interview with Thom Langford | EP35 <a href="https://www.youtube.com/watch?v=axLwXoUYOak">https://www.youtube.com/watch?v=axLwXoUYOak</a></p>
<ul><li>(00:00) - Who Will Win the Software Vulnerability Race?</li>
<li>(00:19) - Five Key Trends</li>
<li>(01:32) - Permanent Defender Edge Scenario</li>
<li>(01:50) - Permanent Attacker Edge Scenario</li>
<li>(02:10) - Two-Tier Security Scenario</li>
<li>(02:48) - Catch Up Scenario</li>
<li>(03:28) - Drowning Defenders Scenario</li>
<li>(04:18) - Takeaways and Wrap Up</li>
</ul>]]>
      </itunes:summary>
      <itunes:keywords>cybersecurity governance, AI governance, strategy, insights, perspectives, trends, risks</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:person role="Host">Dejan Kosutic</podcast:person>
      <podcast:chapters url="https://share.transistor.fm/s/0fcaf2c4/chapters.json" type="application/json+chapters"/>
    </item>
    <item>
      <title>Security vs. Compliance: Are We Asking the Wrong Question?  </title>
      <itunes:episode>5</itunes:episode>
      <podcast:episode>5</podcast:episode>
      <itunes:title>Security vs. Compliance: Are We Asking the Wrong Question?  </itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">788e23f9-aa54-45b5-b25b-96e8d1cd5db9</guid>
      <link>https://share.transistor.fm/s/a1b20b57</link>
      <description>
        <![CDATA[<p>Dejan Kosutic discusses whether security or compliance is more important and argues that this is the wrong question. He explains how compliance can support security through three “Bs”: acting as a booster by unlocking budgets when regulations or client requirements make security obligatory; providing a baseline via standards like ISO 27001 and technical security standards; and enabling a business case when ROI is hard to measure by showing avoided penalties, reduced liability, and potential revenue gains. He concludes that security is the ultimate goal while compliance is an enabler.</p><p>LINK FROM THE VIDEO<br>► Report: Compliance and information security - How are they related? https://advisera.co/InfoSecCompliance</p>
<ul><li>(00:00) - Security vs. Compliance Are We Asking the Wrong Question?</li>
<li>(00:12) - Different People See Security Differently</li>
<li>(01:07) - How Compliance Helps Security</li>
<li>(02:35) - Compliance as Enabler, Security as a Goal</li>
</ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Dejan Kosutic discusses whether security or compliance is more important and argues that this is the wrong question. He explains how compliance can support security through three “Bs”: acting as a booster by unlocking budgets when regulations or client requirements make security obligatory; providing a baseline via standards like ISO 27001 and technical security standards; and enabling a business case when ROI is hard to measure by showing avoided penalties, reduced liability, and potential revenue gains. He concludes that security is the ultimate goal while compliance is an enabler.</p><p>LINK FROM THE VIDEO<br>► Report: Compliance and information security - How are they related? https://advisera.co/InfoSecCompliance</p>
<ul><li>(00:00) - Security vs. Compliance Are We Asking the Wrong Question?</li>
<li>(00:12) - Different People See Security Differently</li>
<li>(01:07) - How Compliance Helps Security</li>
<li>(02:35) - Compliance as Enabler, Security as a Goal</li>
</ul>]]>
      </content:encoded>
      <pubDate>Fri, 10 Jul 2026 14:15:00 +0200</pubDate>
      <author>Dejan Kosutic</author>
      <enclosure url="https://media.transistor.fm/a1b20b57/b568c314.mp3" length="3385794" type="audio/mpeg"/>
      <itunes:author>Dejan Kosutic</itunes:author>
      <itunes:duration>208</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>Dejan Kosutic discusses whether security or compliance is more important and argues that this is the wrong question. He explains how compliance can support security through three “Bs”: acting as a booster by unlocking budgets when regulations or client requirements make security obligatory; providing a baseline via standards like ISO 27001 and technical security standards; and enabling a business case when ROI is hard to measure by showing avoided penalties, reduced liability, and potential revenue gains. He concludes that security is the ultimate goal while compliance is an enabler.</p><p>LINK FROM THE VIDEO<br>► Report: Compliance and information security - How are they related? https://advisera.co/InfoSecCompliance</p>
<ul><li>(00:00) - Security vs. Compliance Are We Asking the Wrong Question?</li>
<li>(00:12) - Different People See Security Differently</li>
<li>(01:07) - How Compliance Helps Security</li>
<li>(02:35) - Compliance as Enabler, Security as a Goal</li>
</ul>]]>
      </itunes:summary>
      <itunes:keywords>cybersecurity governance, AI governance, strategy, insights, perspectives, trends, risks</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:person role="Host">Dejan Kosutic</podcast:person>
      <podcast:chapters url="https://share.transistor.fm/s/a1b20b57/chapters.json" type="application/json+chapters"/>
    </item>
    <item>
      <title>The Missing Half of Cybersecurity: Security Management</title>
      <itunes:episode>4</itunes:episode>
      <podcast:episode>4</podcast:episode>
      <itunes:title>The Missing Half of Cybersecurity: Security Management</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">dc2c3d59-d78e-4395-a492-e5a5001ec936</guid>
      <link>https://share.transistor.fm/s/02cbe70b</link>
      <description>
        <![CDATA[<p>Dejan Kosutic explains a common bias in cybersecurity: focusing on implementing controls but not managing them. Using backups as an example, he outlines why effective security requires planning (e.g., setting objectives like RPO and backup frequency), monitoring to ensure controls work in production, internal audits to verify tasks are performed, continual improvement to prevent recurring issues, and management review to escalate unresolved problems, funding needs, or rule changes. He notes these elements reflect security management practices described in ISO standards such as ISO 27001 and ISO 42001, which he argues help organizations understand how to manage security beyond implementation. He adds that security management will become increasingly important due to regulations like NIS2 and DORA, rising cybersecurity complexity, and incidents caused by overlooked details or trends.</p><p>LINK FROM THE VIDEO<br>► What is an Information Security Management System (ISMS)? <a href="https://advisera.com/27001academy/blog/2016/05/23/information-security-management-system-isms-according-iso-27001/">https://advisera.com/27001academy/blog/2016/05/23/information-security-management-system-isms-according-iso-27001/</a></p>
<ul><li>(00:00) - The Missing Half of Cybersecurity: Security Management</li>
<li>(00:14) - Cybersecurity implementation vs management</li>
<li>(02:02) - The missing piece: Security management</li>
<li>(02:43) - The rising importance of security management</li>
<li>(03:27) - Further reading</li>
</ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Dejan Kosutic explains a common bias in cybersecurity: focusing on implementing controls but not managing them. Using backups as an example, he outlines why effective security requires planning (e.g., setting objectives like RPO and backup frequency), monitoring to ensure controls work in production, internal audits to verify tasks are performed, continual improvement to prevent recurring issues, and management review to escalate unresolved problems, funding needs, or rule changes. He notes these elements reflect security management practices described in ISO standards such as ISO 27001 and ISO 42001, which he argues help organizations understand how to manage security beyond implementation. He adds that security management will become increasingly important due to regulations like NIS2 and DORA, rising cybersecurity complexity, and incidents caused by overlooked details or trends.</p><p>LINK FROM THE VIDEO<br>► What is an Information Security Management System (ISMS)? <a href="https://advisera.com/27001academy/blog/2016/05/23/information-security-management-system-isms-according-iso-27001/">https://advisera.com/27001academy/blog/2016/05/23/information-security-management-system-isms-according-iso-27001/</a></p>
<ul><li>(00:00) - The Missing Half of Cybersecurity: Security Management</li>
<li>(00:14) - Cybersecurity implementation vs management</li>
<li>(02:02) - The missing piece: Security management</li>
<li>(02:43) - The rising importance of security management</li>
<li>(03:27) - Further reading</li>
</ul>]]>
      </content:encoded>
      <pubDate>Fri, 26 Jun 2026 13:30:00 +0200</pubDate>
      <author>Dejan Kosutic</author>
      <enclosure url="https://media.transistor.fm/02cbe70b/ebc30600.mp3" length="3667165" type="audio/mpeg"/>
      <itunes:author>Dejan Kosutic</itunes:author>
      <itunes:duration>225</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>Dejan Kosutic explains a common bias in cybersecurity: focusing on implementing controls but not managing them. Using backups as an example, he outlines why effective security requires planning (e.g., setting objectives like RPO and backup frequency), monitoring to ensure controls work in production, internal audits to verify tasks are performed, continual improvement to prevent recurring issues, and management review to escalate unresolved problems, funding needs, or rule changes. He notes these elements reflect security management practices described in ISO standards such as ISO 27001 and ISO 42001, which he argues help organizations understand how to manage security beyond implementation. He adds that security management will become increasingly important due to regulations like NIS2 and DORA, rising cybersecurity complexity, and incidents caused by overlooked details or trends.</p><p>LINK FROM THE VIDEO<br>► What is an Information Security Management System (ISMS)? <a href="https://advisera.com/27001academy/blog/2016/05/23/information-security-management-system-isms-according-iso-27001/">https://advisera.com/27001academy/blog/2016/05/23/information-security-management-system-isms-according-iso-27001/</a></p>
<ul><li>(00:00) - The Missing Half of Cybersecurity: Security Management</li>
<li>(00:14) - Cybersecurity implementation vs management</li>
<li>(02:02) - The missing piece: Security management</li>
<li>(02:43) - The rising importance of security management</li>
<li>(03:27) - Further reading</li>
</ul>]]>
      </itunes:summary>
      <itunes:keywords>cybersecurity governance, AI governance, strategy, insights, perspectives, trends, risks</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:person role="Host">Dejan Kosutic</podcast:person>
      <podcast:chapters url="https://share.transistor.fm/s/02cbe70b/chapters.json" type="application/json+chapters"/>
    </item>
    <item>
      <title>The Dangerous Illusion of Cyber Readiness | Cyber &amp; AI Perspectives</title>
      <itunes:episode>3</itunes:episode>
      <podcast:episode>3</podcast:episode>
      <itunes:title>The Dangerous Illusion of Cyber Readiness | Cyber &amp; AI Perspectives</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">38dad83c-09ab-4526-b657-c18d40b06672</guid>
      <link>https://share.transistor.fm/s/64cec0a7</link>
      <description>
        <![CDATA[<p>Dejan Kosutic explains that while many companies believe they are prepared for disruptive incidents, their continuity and recovery plans alone are often insufficient. He argues that plans cannot replace missing resources such as redundant systems, properly secured backups, or replacement staff, and that unclear recovery time and data loss tolerances lead to misaligned preparations. He also notes that complex dependencies across people and systems can cause recovery steps to fail, and that real incidents create chaos where people may react irrationally. Kosutic recommends defining business continuity strategies using RTOs and RPOs, mapping dependencies across processes, systems, suppliers, and regularly exercising plans with realistic scenarios involving senior management and key suppliers, referencing frameworks like ISO 22301.</p><p>LINKS FROM THE EPISODE: <br>► Responding to Ransomware Attack [Case Study] | Interview with Yannick Hirt | EP29 <a href="https://www.youtube.com/watch?v=V3DhNF9-wfc">https://www.youtube.com/watch?v=V3DhNF9-wfc</a><br>► Cyber Ranges, Attack Simulations &amp; AI: Proving Cyber Readiness | Interview with Lee Rossey | EP32 <a href="https://www.youtube.com/watch?v=zId18MlZeKM">https://www.youtube.com/watch?v=zId18MlZeKM</a></p>
<ul><li>(00:00) - The Dangerous Illusion of Cyber Readiness</li>
<li>(00:45) - Why plans alone are not enough?</li>
<li>(03:09) - How to build true cyber resilience</li>
<li>(04:21) - The real goal: Resilience</li>
</ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Dejan Kosutic explains that while many companies believe they are prepared for disruptive incidents, their continuity and recovery plans alone are often insufficient. He argues that plans cannot replace missing resources such as redundant systems, properly secured backups, or replacement staff, and that unclear recovery time and data loss tolerances lead to misaligned preparations. He also notes that complex dependencies across people and systems can cause recovery steps to fail, and that real incidents create chaos where people may react irrationally. Kosutic recommends defining business continuity strategies using RTOs and RPOs, mapping dependencies across processes, systems, suppliers, and regularly exercising plans with realistic scenarios involving senior management and key suppliers, referencing frameworks like ISO 22301.</p><p>LINKS FROM THE EPISODE: <br>► Responding to Ransomware Attack [Case Study] | Interview with Yannick Hirt | EP29 <a href="https://www.youtube.com/watch?v=V3DhNF9-wfc">https://www.youtube.com/watch?v=V3DhNF9-wfc</a><br>► Cyber Ranges, Attack Simulations &amp; AI: Proving Cyber Readiness | Interview with Lee Rossey | EP32 <a href="https://www.youtube.com/watch?v=zId18MlZeKM">https://www.youtube.com/watch?v=zId18MlZeKM</a></p>
<ul><li>(00:00) - The Dangerous Illusion of Cyber Readiness</li>
<li>(00:45) - Why plans alone are not enough?</li>
<li>(03:09) - How to build true cyber resilience</li>
<li>(04:21) - The real goal: Resilience</li>
</ul>]]>
      </content:encoded>
      <pubDate>Fri, 12 Jun 2026 13:30:00 +0200</pubDate>
      <author>Dejan Kosutic</author>
      <enclosure url="https://media.transistor.fm/64cec0a7/85dc7a0c.mp3" length="5088081" type="audio/mpeg"/>
      <itunes:author>Dejan Kosutic</itunes:author>
      <itunes:duration>314</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>Dejan Kosutic explains that while many companies believe they are prepared for disruptive incidents, their continuity and recovery plans alone are often insufficient. He argues that plans cannot replace missing resources such as redundant systems, properly secured backups, or replacement staff, and that unclear recovery time and data loss tolerances lead to misaligned preparations. He also notes that complex dependencies across people and systems can cause recovery steps to fail, and that real incidents create chaos where people may react irrationally. Kosutic recommends defining business continuity strategies using RTOs and RPOs, mapping dependencies across processes, systems, suppliers, and regularly exercising plans with realistic scenarios involving senior management and key suppliers, referencing frameworks like ISO 22301.</p><p>LINKS FROM THE EPISODE: <br>► Responding to Ransomware Attack [Case Study] | Interview with Yannick Hirt | EP29 <a href="https://www.youtube.com/watch?v=V3DhNF9-wfc">https://www.youtube.com/watch?v=V3DhNF9-wfc</a><br>► Cyber Ranges, Attack Simulations &amp; AI: Proving Cyber Readiness | Interview with Lee Rossey | EP32 <a href="https://www.youtube.com/watch?v=zId18MlZeKM">https://www.youtube.com/watch?v=zId18MlZeKM</a></p>
<ul><li>(00:00) - The Dangerous Illusion of Cyber Readiness</li>
<li>(00:45) - Why plans alone are not enough?</li>
<li>(03:09) - How to build true cyber resilience</li>
<li>(04:21) - The real goal: Resilience</li>
</ul>]]>
      </itunes:summary>
      <itunes:keywords>cybersecurity governance, AI governance, strategy, insights, perspectives, trends, risks</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:person role="Host">Dejan Kosutic</podcast:person>
      <podcast:chapters url="https://share.transistor.fm/s/64cec0a7/chapters.json" type="application/json+chapters"/>
    </item>
    <item>
      <title>Lessons From the C-I-A Triad to Build Trustworthy AI | Cyber &amp; AI Perspectives</title>
      <itunes:episode>2</itunes:episode>
      <podcast:episode>2</podcast:episode>
      <itunes:title>Lessons From the C-I-A Triad to Build Trustworthy AI | Cyber &amp; AI Perspectives</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">6a167997-f586-42dd-b454-52577ee98261</guid>
      <link>https://share.transistor.fm/s/d2a3ad55</link>
      <description>
        <![CDATA[<p>Dejan Kosutic explains how cybersecurity’s CIA Triad—confidentiality, integrity, and availability—has guided risk identification, prioritization, and control selection for decades, and argues that AI governance needs a similarly clear guiding principle: trustworthiness. Citing the OECD AI Principles, the EU AI Act, and the NIST AI Risk Management Framework, he describes trustworthiness as central to broader AI adoption because AI systems are non-deterministic and can produce different outputs from the same inputs. He shows how trustworthiness can steer AI risk management by helping organizations identify risks like biased outputs, assess impact through trust and reputational damage, and choose controls such as trusted training data or human review. </p><p>LINK FROM THE EPISODE<br>► AI Goals and Objectives: Why is Trustworthiness Important? | AI Literacy Series https://www.youtube.com/watch?v=AnZLw9IRh4E</p>
<ul><li>(00:00) - What the C-I-A Triad can teach us about AI</li>
<li>(00:32) - Why is the C-I-A Triad important for cybersecurity?</li>
<li>(02:15) - Importance of trustworthiness for AI</li>
<li>(03:30) - Applying cyber logic to AI</li>
<li>(04:56) - Addressing larger AI challenges</li>
</ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Dejan Kosutic explains how cybersecurity’s CIA Triad—confidentiality, integrity, and availability—has guided risk identification, prioritization, and control selection for decades, and argues that AI governance needs a similarly clear guiding principle: trustworthiness. Citing the OECD AI Principles, the EU AI Act, and the NIST AI Risk Management Framework, he describes trustworthiness as central to broader AI adoption because AI systems are non-deterministic and can produce different outputs from the same inputs. He shows how trustworthiness can steer AI risk management by helping organizations identify risks like biased outputs, assess impact through trust and reputational damage, and choose controls such as trusted training data or human review. </p><p>LINK FROM THE EPISODE<br>► AI Goals and Objectives: Why is Trustworthiness Important? | AI Literacy Series https://www.youtube.com/watch?v=AnZLw9IRh4E</p>
<ul><li>(00:00) - What the C-I-A Triad can teach us about AI</li>
<li>(00:32) - Why is the C-I-A Triad important for cybersecurity?</li>
<li>(02:15) - Importance of trustworthiness for AI</li>
<li>(03:30) - Applying cyber logic to AI</li>
<li>(04:56) - Addressing larger AI challenges</li>
</ul>]]>
      </content:encoded>
      <pubDate>Fri, 29 May 2026 13:30:00 +0200</pubDate>
      <author>Dejan Kosutic</author>
      <enclosure url="https://media.transistor.fm/d2a3ad55/d1dc25cb.mp3" length="6300760" type="audio/mpeg"/>
      <itunes:author>Dejan Kosutic</itunes:author>
      <itunes:duration>390</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>Dejan Kosutic explains how cybersecurity’s CIA Triad—confidentiality, integrity, and availability—has guided risk identification, prioritization, and control selection for decades, and argues that AI governance needs a similarly clear guiding principle: trustworthiness. Citing the OECD AI Principles, the EU AI Act, and the NIST AI Risk Management Framework, he describes trustworthiness as central to broader AI adoption because AI systems are non-deterministic and can produce different outputs from the same inputs. He shows how trustworthiness can steer AI risk management by helping organizations identify risks like biased outputs, assess impact through trust and reputational damage, and choose controls such as trusted training data or human review. </p><p>LINK FROM THE EPISODE<br>► AI Goals and Objectives: Why is Trustworthiness Important? | AI Literacy Series https://www.youtube.com/watch?v=AnZLw9IRh4E</p>
<ul><li>(00:00) - What the C-I-A Triad can teach us about AI</li>
<li>(00:32) - Why is the C-I-A Triad important for cybersecurity?</li>
<li>(02:15) - Importance of trustworthiness for AI</li>
<li>(03:30) - Applying cyber logic to AI</li>
<li>(04:56) - Addressing larger AI challenges</li>
</ul>]]>
      </itunes:summary>
      <itunes:keywords>cybersecurity governance, AI governance, strategy, insights, perspectives, trends, risks</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:person role="Host">Dejan Kosutic</podcast:person>
      <podcast:chapters url="https://share.transistor.fm/s/d2a3ad55/chapters.json" type="application/json+chapters"/>
    </item>
    <item>
      <title>How Apple Uses Cybersecurity as a Competitive Advantage</title>
      <itunes:episode>1</itunes:episode>
      <podcast:episode>1</podcast:episode>
      <itunes:title>How Apple Uses Cybersecurity as a Competitive Advantage</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">7acab35a-3f71-4e7a-885d-28235acc6e8d</guid>
      <link>https://share.transistor.fm/s/502fd603</link>
      <description>
        <![CDATA[<p>Dejan Kosutic explains how cybersecurity can create a real competitive advantage and uses Apple as a key example. He notes many companies pursue ISO 27001 and similar certifications mainly for sales and market access, but questions whether certificates provide a lasting advantage since competitors can obtain them with relatively little time and money. He defines competitive advantage as having something competitors lack and find hard to replicate, illustrating this with SpaceX’s reusable rocket technology. Kosutic argues long-term advantage comes from integrating security and privacy into product design and brand, as Apple has done through features like advanced biometric authentication, built-in malware protection, and resisting government access to user data. He concludes that cybersecurity must be driven strategically, with CISO involvement in business strategy and security embedded throughout product development.</p><p>LINK FROM THE EPISODE<br>► How to achieve sustainable competitive advantage through cybersecurity <a href="https://advisera.co/CyberSecAdvantage">https://advisera.co/CyberSecAdvantage</a></p>
<ul><li>(00:00) - How Apple Uses Cybersecurity as a Competitive Advantage</li>
<li>(00:11) - Do certificates provide a competitive advantage?</li>
<li>(01:01) - An example of a competitive advantage</li>
<li>(02:12) - How Apple uses cybersecurity?</li>
<li>(03:52) - What should you do?</li>
</ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Dejan Kosutic explains how cybersecurity can create a real competitive advantage and uses Apple as a key example. He notes many companies pursue ISO 27001 and similar certifications mainly for sales and market access, but questions whether certificates provide a lasting advantage since competitors can obtain them with relatively little time and money. He defines competitive advantage as having something competitors lack and find hard to replicate, illustrating this with SpaceX’s reusable rocket technology. Kosutic argues long-term advantage comes from integrating security and privacy into product design and brand, as Apple has done through features like advanced biometric authentication, built-in malware protection, and resisting government access to user data. He concludes that cybersecurity must be driven strategically, with CISO involvement in business strategy and security embedded throughout product development.</p><p>LINK FROM THE EPISODE<br>► How to achieve sustainable competitive advantage through cybersecurity <a href="https://advisera.co/CyberSecAdvantage">https://advisera.co/CyberSecAdvantage</a></p>
<ul><li>(00:00) - How Apple Uses Cybersecurity as a Competitive Advantage</li>
<li>(00:11) - Do certificates provide a competitive advantage?</li>
<li>(01:01) - An example of a competitive advantage</li>
<li>(02:12) - How Apple uses cybersecurity?</li>
<li>(03:52) - What should you do?</li>
</ul>]]>
      </content:encoded>
      <pubDate>Thu, 14 May 2026 13:30:00 +0200</pubDate>
      <author>Dejan Kosutic</author>
      <enclosure url="https://media.transistor.fm/502fd603/30b3d07b.mp3" length="4686142" type="audio/mpeg"/>
      <itunes:author>Dejan Kosutic</itunes:author>
      <itunes:duration>289</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>Dejan Kosutic explains how cybersecurity can create a real competitive advantage and uses Apple as a key example. He notes many companies pursue ISO 27001 and similar certifications mainly for sales and market access, but questions whether certificates provide a lasting advantage since competitors can obtain them with relatively little time and money. He defines competitive advantage as having something competitors lack and find hard to replicate, illustrating this with SpaceX’s reusable rocket technology. Kosutic argues long-term advantage comes from integrating security and privacy into product design and brand, as Apple has done through features like advanced biometric authentication, built-in malware protection, and resisting government access to user data. He concludes that cybersecurity must be driven strategically, with CISO involvement in business strategy and security embedded throughout product development.</p><p>LINK FROM THE EPISODE<br>► How to achieve sustainable competitive advantage through cybersecurity <a href="https://advisera.co/CyberSecAdvantage">https://advisera.co/CyberSecAdvantage</a></p>
<ul><li>(00:00) - How Apple Uses Cybersecurity as a Competitive Advantage</li>
<li>(00:11) - Do certificates provide a competitive advantage?</li>
<li>(01:01) - An example of a competitive advantage</li>
<li>(02:12) - How Apple uses cybersecurity?</li>
<li>(03:52) - What should you do?</li>
</ul>]]>
      </itunes:summary>
      <itunes:keywords>cybersecurity governance, AI governance, strategy, insights, perspectives, trends, risks</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:person role="Host">Dejan Kosutic</podcast:person>
      <podcast:chapters url="https://share.transistor.fm/s/502fd603/chapters.json" type="application/json+chapters"/>
    </item>
  </channel>
</rss>
