Find partners
Secure Talk Podcast

Secure Talk Podcast

Hosted by Justin Beals

TechnologyInterviews guests

Episodes

259

Latest episode

Aug 2026

Language

EN

About the show

Secure Talk reviews the latest threats, tips, and trends on security, innovation, and compliance. Host Justin Beals interviews leading privacy, security and technology executives to discuss best practices related to IT security, data protection and compliance. Based in Seattle, he previously served as the CTO of NextStep and Koru, which won the 2018 Most Impactful Startup award from Wharton People Analytics. He is the creator of the patented Training, Tracking & Placement System and the author of “Aligning curriculum and evidencing learning effectiveness using semantic mapping of learning assets,” published in the International Journal of Emerging Technologies in Learning (iJet). Justin earned a BA from Fort Lewis College.

Listen to episodes

60 recent
August 11, 2026Episode 25948 min

AI Is Eating Our Young: Data Center Revolts, Vanishing Junior Jobs & the EU AI Act

Communities are blocking $130 billion in AI data centers while the entry-level jobs that used to train the next generation of engineers quietly disappear. Chapters: 00:00: The Backlash: 800 Groups, 49 States, $130B Blocked Gallup: 71% of Americans don't want a data center built near them (Gallup) Data center opposition tracker, Q1 2026 filings (referenced industry opposition data) CMMC as precedent for regulating critical infrastructure (DoW CMMC Phase 2 program) 04:30: Why AI Is "Eating Our Young" in Education** Fran Berman & co-author's unpublished piece on the fraying mid-career pipeline Better Tech (MIT Press) — Chapter appendix: AI classroom syllabus and exercises 14:00: Tech as Critical Infrastructure, Not a Religion Better Tech prologue: treating tech like food, water, roads, and the power grid GDPR (EU, 2018) as a case study in regulation done right — and its limits Vermont's data broker law as a case study in weak enforcement 26:00: Design Can't Be Bolted On Later** Self-driving cars and the hidden environmental cost of full autonomy Attack surface risk: denial-of-service on connected, self-driving fleets 34:00: Governing the Hybrid Human-AI Society** EU AI Act — risk-tiered regulation: unacceptable, high-risk, low-risk categories U.S. Equal Employment Opportunity Commission guidance on algorithmic hiring 41:00: The Hype Curve and the Data Center Reckoning** Western Massachusetts communities rejecting new AI data centers Efficiency vs. quality of life — Berman's closing argument Communities are saying no to AI's biggest infrastructure bet.In the first quarter of 2026 alone, local opposition blocked or delayed 75 data center projects worth roughly $130 billion — nearly matching all of 2025's total in a single quarter. Dr. Fran Berman, former head of the San Diego Supercomputer Center, argues the fix isn't more hype, it's precedent we already have. She points to CMMC itself: "If we can look at the defense supply chain and say this is critical infrastructure, it has to meet a bar, then we can look at the trillion dollars of compute being built into the middle of American life and say the same thing." AI isn't just displacing jobs. It's starving the pipeline that builds senior engineers. Berman's sharpest warning is about who trains the next generation of professionals when entry-level coding and writing jobs — the ones junior people used to cut their teeth on — get automated away. She compares it to a surgeon who's never had supervised time in the operating room: "Unless you have that experience and the mentorship of more senior professionals, it's really hard" to develop the judgment senior engineers rely on. Good regulation needs more than a law on the books. Drawing on her book Better Tech (MIT Press), Berman walks through why GDPR worked where Vermont's data broker law didn't — and previews how the EU AI Act's risk-tiered approach (unacceptable, high-risk, low-risk) could become the model for governing hybrid human-AI decision-making, where, as she puts it, "the only accountable entities are humans." ✍️ About the Author Dr. Fran Berman is an award winning-data scientist, pioneer in public interest technology, and community leader and builder. She directs the Public Interest Technology Initiative at UMass Amherst and is a Faculty Associate at the Berkman Klein Center for Internet and Society at Harvard. Berman is former head the San Diego Supercomputer Center and served as Vice President for Research at Rensselaer Polytechnic Institute. She currently serves as a Trustee of the Alfred P. Sloan Foundation and is a popular regular panelist on public radio’s WAMC Roundtable with 400,000 monthly listeners in seven states. For more information, see https://www.franberman.com. Link to the book: https://mitpress.mit.edu/978026205488...

July 28, 2026Episode 25842 min

Okta's Identity Chief: Most CISOs Can't Answer This AI Question

Which AI agents can access what? Are those permissions even right? And can you stop a compromised agent mid-action? Okta's Dan Cinnamon says most enterprises can't answer any of the three. Dan Cinnamon has built software, run SAP GRC without an implementation partner, and now architects identity for one of the industry's biggest players. In this conversation with Justin Beals, he lays out why "discoverability" — simply knowing what agents exist and what they're touching — is the single biggest blind spot in enterprise AI right now, and why there's no silver bullet coming to fix it. They also dig into passkeys as a rare win-win security standard, the maturing MCP spec, and where the hard line on agent containment should actually sit. **Timestamps:** 0:00 Intro 1:20 From writing code to securing identity 4:45 Passkeys: the security/usability unicorn 8:30 The SAP GRC re-implementation story 14:10 Attribution and the agentic AI identity gap 18:55 How fast MCP has matured—and what's next 23:40 The 3 unanswered questions every enterprise faces 27:15 Granular identity vs. inherited permissions 32:00 Containment: moving controls closer to the data 36:45 Consent, provenance, and healthcare AI 40:30 Closing thoughts #CISO #AIstrategy, #enterprise #AIsecurity, #agentic #AIgovernance, #Okta #MCPstandard, #zerotrust #AI agents

July 17, 2026Episode 25746 min

Special Episode: CMMC Phase 2 SUSPENDED: What DOD Just Did, What It Really Means, and Why Little Changed

The Pentagon paused CMMC Phase 2 with zero warning — and half the defense industrial base is celebrating for the wrong reason. When the Department of War suspended CMMC Phase 2 rollout with no notice, panic spread fast across the defense contractor community — but the requirement to secure CUI never went away. In this special roundtable, host Justin Beals brings together three CMMC insiders — Logan Therrien (C3PAO Chief Strategy Officer, retired Navy submariner), Lance Arnold (30-year industry veteran, just completed his own CMMC Level 2 journey), and Brian Hubbard (President, Evolved Cyber Solutions, CMMC assessor since 2015) — to separate what actually changed from what didn't. They break down the difference between the assessment requirement (paused) and the security implementation requirement (still very much alive under NIST 800-171), why "self-assessment" doesn't mean "no requirement," and what small businesses and primes should do right now instead of waiting for clarity that may not come for months. Sources Referenced: DFARS 252.204-7021 (CMMC assessment clause) DFARS 252.204-7012 (NIST 800-171 compliance clause) DFARS 252.204-7019 (SPRS scoring requirement) 32 CFR Part 170 (CMMC Program Rule) 32 CFR Part 48 NIST SP 800-171 / NIST SP 800-172

July 14, 2026Episode 25641 min

An AI Security Maturity Model for CISOs, with Chris Cochran (SANS)

Half the room at Chris Cochran's leadership dinners still calls themselves AI skeptics. He argues they can't afford to be — because the adversary already isn't. Chapters: 00:00 — Intro 02:49 — NSA/threat intel → AI security, storytelling 09:55 — Why leaders feel stuck / no roadmap 14:41 — Three pillars (Protect/Utilize/Govern) 17:00 — Governance as the real foundation / shadow AI 21:37 — Evidence-based scoring vs. pass/fail 26:27 — EU AI Act 28:44 — Fable/Mythos, Project Glasswing access controls 33:18 — Token subsidies, self-hosted models 37:52 — Data poisoning & context poisoning 40:12 — Iron Man suit framing 42:38 — Close: what's next

June 16, 2026Episode 25541 min

Considering Security, Compliance and Revenue with David Grazer

Most companies chase certifications to win deals — but what actually keeps customers is something no audit can measure. In this episode, vCISO David Grazer makes the case that trust is a measurable economic asset hiding in plain sight: your customer retention rate. Drawing on 15+ years inside high-growth tech companies, David explains why compliance frameworks are customer acquisition tools, not retention strategies — and how the gap between the two is costing businesses more than they realize. This episode is for founders, security leaders, and C-suite executives who want to connect their security and privacy programs to real business outcomes. You'll learn: → Why a SOC 2 or ISO 27001 certification is only the beginning of earning customer trust → How customer churn functions as one of the most honest security metrics available → Why MFA and common security controls often fail the users who need them most → What "Trust by Design" looks like in product development and AI programs → How to translate security risk into language that resonates with your CFO Chapters 00:00 Introduction to Secure Talk and Trust 03:42 David Grazer's Journey into Security and Privacy 08:09 Navigating Compliance and Customer Trust 12:49 The Role of Consulting in Security 18:07 Trust as a Measurable Economic Asset 23:42 Identity Management in the Entertainment Industry 26:09 The VC SO Model and Its Impact 29:13 The Evolution of Compliance Conversations 33:17 Exploring the Intersection of Technology and Society 🔔 Subscribe to SecureTalk for weekly conversations at the intersection of cybersecurity, compliance, and business strategy. #cybersecurity #compliance #CISO #trustbydesign #vciso #informationsecurity #GRC #dataprivacy

June 2, 2026Episode 25453 min

Why you could fail your CMMC Level 2 C3PAO audit | Secure Talk with Logan Therrien

You did your self assessment and received a perfect 110 score, congratulations! You met with your C3PAO and scored less than 0. What happened! How can two CMMC assessors examine the same defense contractor and arrive at completely different scores? A lack of rigor in assessment methodology could mean the entire certification system is measuring the assessor — not your security. Logan Therrien, Chief Strategy Officer at Kieri Solutions and one of the original C3PAO lead assessors in the U.S., joins Justin Beals to expose a critical flaw in how CMMC Level 2 assessments are conducted today: no standardized evidence sampling methodology. This episode is for DoD contractors, compliance consultants, and defense industry executives who want to understand what's at stake — and how to navigate assessments before the rules tighten further. What you'll learn: Why NIST 800-171 was intentionally vague — and how that backfired for assessors How one assessor might review a single evidence point while another reviews 100% What ISO 17020 accreditation will require of C3PAOs and why it matters now What the 48 CFR expansion means for 118,000+ contractors in the supply chain How to prepare for an assessment so it feels like an open-book test Logan also co-authored the peer-reviewed paper "The Need for Standardized Evidence Sampling in CMMC Assessments: A Survey-Based Analysis of Assessor Practices" (with John Hastings) — one of the first data-driven studies of assessment methodology in the CMMC ecosystem. Chapters 00:00 Introduction to Secure Talk and Psychometrics 01:45 Understanding CMMC and Its Implications 05:32 Logan Therian's Background and Insights 09:16 The Challenges of Assessment Methodologies 16:10 The Scale and Impact of CMMC Assessments 20:31 Navigating Standards in Cybersecurity 23:53 Evidence Testing in CMMC Assessments 27:43 The Importance of Reliable and Accurate Assessments 36:22 Building Trust Between Industry and Defense 41:46 Future Directions in CMMC Research Resources: Therrien, Logan and Hastings, John. (2026, February 10). The need for standardized evidence sampling in CMMC assessments: A survey-based analysis of assessor practices. arXiv. https://arxiv.org/abs/2602.09905

May 19, 2026Episode 25347 min

Mark Zuckerberg has an AI twin. Who Is Mark Zuckerberg?

Mark Zuckerberg built an AI version of himself that attends meetings and approves budgets while he's elsewhere. That's not science fiction — it's happening now. But when an AI replica makes a consequential decision, who's legally responsible? Who owns it when you die? Dr. Candi Cann, Thanatologist and professor at Baylor University, joins SecureTalk host Justin Beals to explore the uncomfortable intersection of technology, mortality, and identity — and what it means for data governance, digital rights, and the future of enterprise accountability. In this episode: Key topics: digital identity, AI accountability, data governance, CMMC compliance, death technology, digital ethics, AI agents, enterprise security If your organization is deploying AI agents that act on behalf of humans — approving transactions, attending meetings, representing employees — this episode raises the governance questions your security and legal teams need to be asking right now. Subscribe to SecureTalk for weekly conversations at the edge of cybersecurity, compliance, and technology culture. Resources: Book: Augmented: Life and Death as a Cyborg by Candy Cann, MIT Press, 2026. Link: https://mitpress.mit.edu/9780262051118/augmented/

May 5, 2026Episode 25251 min

CMMC Is an HR Problem, Not an Enclave Problem — Here's the Proof

The biggest cybersecurity failures in recent memory — Raytheon, Penn State, Georgia Tech — weren't caused by missing software. They were caused by the wrong people being assigned the wrong tasks, with no shared language to connect the rules to the work. This SecureTalk episode with Dorian Cougias (MoxyWolf, former Unified Compliance Framework CEO) is one of the most systems-level conversations we've had on the show. Dorian spent decades building the infrastructure that compliance programs run on — and he's now rebuilding it from scratch, in the open. What you'll hear: → Why the compliance industry is structurally fragmented across three authority domains that don't communicate → How Bloom's Taxonomy — a tool from education — maps directly to which compliance tasks belong to which roles → Why the Oxford English Dictionary doesn't have "personal data" in it, and what that tells us about regulatory language → The O*NET framework and why the Department of Labor might be the most underused tool in cybersecurity → Shannon's entropy theory, applied to compliance and cognitive load → A new open-source STIG API infrastructure that StrikeGraph is integrating as a launch partner Whether you're deep in the compliance trenches or just fascinated by how complex systems fail — and how to redesign them — this is worth your time. 🔗 strikegraph.com | stigviewer.com Chapters: 00:00 Introduction and Background 02:43 Exploring Compliance and Natural Language Processing 05:15 Military Experience and Signal Intelligence 08:01 Cognitive Load and Compliance Frameworks 10:49 The Importance of Language in Compliance 13:39 The Evolution of Dictionaries and Lexicons 16:16 Bridging Gaps in Compliance Communication 18:47 Innovations at MoxieWolf and Future Directions 22:04 Mapping Skills and Regulatory Guidelines 25:05 Job Applicability and Knowledge Requirements 28:02 The Importance of O*NET in Cybersecurity 29:21 Challenges in CMMC Compliance 33:23 The Role of Technology in Compliance 35:38 Horizontal Practices in Compliance 38:15 Building Effective Teams for Compliance 42:21 Introduction to Compliance Failures 45:19 The Human Element in Compliance 48:10 Navigating Compliance Complexity with Technology 48:57 Introduction to Cybersecurity Compliance Challenges 54:09 The Role of People in Compliance Success 56:01 Guest Introduction: Dorian Cougas 01:00:48 Exploring Bloom's Taxonomy in Compliance 01:05:48 The Importance of Shared Lexicons 01:09:32 Navigating Compliance with Technology 01:15:11 MoxieWolf's Approach to Compliance 01:20:49 The Interconnectedness of Compliance Tasks 01:27:51 Real-World Compliance Challenges 01:33:57 Building Effective Teams for Compliance #Cybersecurity #ComplianceCulture #CMMC #HumanFactors #GRC #TechPolicy #SecureTalk

April 21, 2026Episode 25147 min

The ROI of Security Tested: What a new paper reveals about security value | Secure Talk with Minh Nguyen and Thi Tran

Why do most cybersecurity investments feel impossible to justify? Because the measurement tools are broken — built on gut instinct, not research. Researchers Minh Nguyen (Florida Atlantic University) and Thi Tran (Binghamton University) set out to fix that. In this episode, they break down their landmark paper "Effects of Cybersecurity Readiness on Firm Performance: Evidence from Conference Calls" — the first study to systematically measure cybersecurity readiness at the firm level and link it directly to financial performance. What they found will change how you think about security budgets: → Outsider mentions of cybersecurity in earnings calls are 100x more predictive of firm performance than insider mentions → Even a single co-occurrence of security-related language drives measurable returns on assets the following year → Companies that act proactively - not reactively - earn greater market trust This is the episode for CISOs who need real data to justify investment, security leaders tired of folklore-based decision-making, and anyone curious about how AI, NLP, and causal inference are reshaping the business case for cybersecurity. Chapters 00:00 Introduction to the Guests and Their Backgrounds 02:34 The Intersection of AI, Business, and Cybersecurity 05:32 Understanding Cybersecurity Readiness 08:31 The Importance of Measurement in Cybersecurity 11:16 Developing a Cybersecurity Dictionary 14:16 The Impact of Outsider Perspectives on Firm Performance 16:51 The Role of Transparency in Cybersecurity 19:40 Future Research Directions in Cybersecurity 22:37 Conclusion and Final Thoughts 🔗 Paper: "Effects of Cybersecurity Readiness on Firm Performance: Evidence from Conference Calls" https://scholarspace.manoa.hawaii.edu/server/api/core/bitstreams/b098c310-db83-42cc-8932-852ef7ebcc86/content #Cybersecurity #CyberROI #CISO #FirmPerformance #CybersecurityResearch #NLP #CausalInference #InfoSec #SecurityLeadership #ConferenceCall``

April 7, 2026Episode 25053 min

They Sold AI to Play God. China Never Got That Memo.

The West has been building AI like it's the apocalypse. China has been building it like it's a tool. That one difference — rooted in centuries of philosophy, theology, and cultural storytelling — may be the most important thing nobody is talking about in the AI debate right now. SecureTalk host Justin Beals sits down with scholars Bogna Konior (NYU Shanghai), Mi You (University of Kassel), and Vincent Garton to explore their co-edited book "Machine Decision Is Not Final: China and the History and Future of Artificial Intelligence" — and what it reveals about the hidden assumptions driving the decisions we make about AI governance, security, and society. What this conversation unpacks: → Why Western AI fear traces back to Christian theology — not rational risk analysis → How the Chinese term for AI literally means "human-made wisdom ability" — no alien mind implied → The 2019 Elon Musk vs. Jack Ma exchange that exposed the cultural divide in real time → What DeepSeek's open-source breakthrough says about innovation, restriction, and creative problem-solving → Why this debate matters far beyond the US and China — and who else is watching closely If you work in cybersecurity, tech leadership, or AI policy, the cultural lens on this technology isn't a soft question. It shapes real architectural, governance, and regulatory decisions. Chapters 00:00 Introduction and Perspectives on AI in China 02:41 The Meaning Behind the Claw Machine Image 05:33 The Book's Creation and Collaborative Efforts 08:32 Cultural Perspectives on AI: East vs. West 11:06 The Impact of Open Source AI Models 13:45 Innovation in a Controlled Environment 16:20 Human-Made vs. Artificial Intelligence 19:23 The Philosophical Underpinnings of AI 22:06 The Role of Human Agency in AI Decisions 24:54 Exploring the Future of AI and Society 27:26 The Synthesis of Technology and Society 30:22 Conclusion and Final Thoughts 44:17 Understanding Artificial Intelligence: A Cultural Perspective 47:08 Machine Decision: The Chinese Perspective on AI 49:59 Innovation and Openness in AI Development 50:27 Global Implications of AI Beyond Superpowers 50:37 Introduction and Context of AI Governance 01:00:53 The Role of Computers in Decision Making 01:08:26 Transparency in AI and Governance 01:17:58 Cultural Perspectives on AI: East vs. West 01:23:46 The Singularity and Its Philosophical Implications 01:27:15 Simulation and Reality in AI Discourse 01:35:14 Social Implications of Large Language Models 🎙️ SecureTalk is hosted by Justin Beals, CEO of Strike Graph. 🔔 Subscribe for weekly conversations at the intersection of cybersecurity, technology, and leadership. #ArtificialIntelligence #AIPolicy #ChinaAI #DeepSeek #Cybersecurity #AIGovernance #TechLeadership #OpenSourceAI ```

Is this your show?

Claim this listing to keep it up to date, reach guests who want to pitch you, and manage bookings with Guestify.

Claim this listing

More Technology podcasts