Back

Explore every episode of the podcast Advancing Cyber

Dive into the complete episode list for Advancing Cyber. Each episode is cataloged with detailed descriptions, making it easy to find and explore specific topics. Keep track of all episodes from your favorite podcast and never miss a moment of insightful content.

Rows per page:

1–15 of 15

TitlePub. DateDuration
DeepSeek: AI’s Sputnik Moment or Not Good Enough for Prime Time?11 Feb 202500:08:26

In this episode of Advancing Cyber, Cristin Flynn Goodwin unpacks the growing concerns surrounding DeepSeek, a Chinese AI provider driving headlines for its powerful AI model built with cheaper and lower-power chips than its Western counterparts. While this breakthrough raises questions about AI efficiency and affordability, it sparks serious privacy concerns, and many have been quick to point out that DeepSeek’s Terms of Service clearly show compliance with laws and government requests in the People’s Republic of China. 

What hasn’t yet been explored are the impacts of Chinese cybersecurity laws on DeepSeek, particularly the Chinese regulation on vulnerability reporting. Cristin explores the implications of a DeepSeek “test bed” - vulnerabilities reported to the Chinese government, combined with US user data flowing into DeepSeek servers, accessible by the Chinese government. Cristin unpacks the potential that this is, indeed, a Sputnik moment. She challenges that even if DeepSeek isn’t “good enough” from a security perspective, industry and government must create better technical options for and policy protections in place for US users. 
 
Join the Advancing Cyber conversation on Spotify, Apple Podcasts, and on now on YouTube!

Europe’s Cyber Regulations Come into Force – and What It Means for US Companies03 Feb 202500:59:01

The EU has taken the lead in cybersecurity regulation, and the business impacts are already being felt worldwide. On this episode of Advancing Cyber, Cristin Flynn Goodwin is joined by Chris Hale, Senior Director for Cyber and National Security Law at Cisco, and Emily Lemaire, Financial Services Regulatory Lawyer at Covington & Burling, to unpack Europe’s leading cybersecurity regulations – the Digital Operational Resilience Act (DORA), Network Information Systems Directive (NIS) 2.0, and the Cyber Resilience Act (CRA), all of which have passed milestone dates in the past 4 months. Together, they explore how these landmark regulations are reshaping the global security landscape and causing companies—especially those in the U.S.—to think about their approach to compliance and resilience. 

DORA’s 4-hour incident reporting rule, NIS 2.0’s expanded scope, and CRA’s product-focused requirements impact how organizations manage cybersecurity and operational risk. Cristin, Chris, and Emily delve into the profound implications of these laws: whether short reporting timeframes increase risk, whether disclosures of newly detected exploitation of vulnerabilities amplifies risks, and whether the potential for billion-dollar penalties drives more effective compliance.  

The discussion doesn’t just stop at the rules. They tackle the deeper questions: Can the U.S. maintain its best-practice approach in a world where compliance is increasingly driven by law?  How will companies balance compliance obligations and business needs now that regulations include model contractual clauses?

This episode is essential listening for cybersecurity, legal, and policy experts navigating a world where the EU is rewriting the playbook—and daring the rest of the world to follow. 

The Evolution of Information Sharing in Cybersecurity27 Nov 202400:54:01

Information sharing used to be about trusted exchanges with those who had data to trade. Today, that information comes from the multi-billion-dollar threat intelligence industry and the experts who hunt threat actors and cyber criminals. On this episode of Advancing Cyber, Cyber Threat Alliance President and CEO Michael Daniel and Professor and cyber threat intelligence expert Sergio Caltagirone explore how threat intelligence has matured into one of the fastest growing segments of our industry with customer expectations for timely and actionable data. They unpack how that reality contrasts with the post-9/11 paradigm of information sharing and the insatiable demand for information from government, critical infrastructure, and organizations around the world.

Cristin, Michael, and Sergio wrestle with the reality that not every critical infrastructure owner or operator may need the same level of threat intelligence or priority treatment, particularly in times of crisis. The actual exchange of information, or giving information to those who can action it, requires a much smaller community of responders. Cristin, Michael, and Sergio also debate what a new executive order for information sharing and threat intelligence should include – regulation, threat intelligence marketplaces, tactical and strategic scoping requirements, clear articulations of legal and privacy obligations, and other important priorities - highlighting that information sharing is still a hard problem to solve, but there are options and solutions that can help.

Who’s in Charge? Restoring Cloud Services in a Major Incident or Disaster31 Oct 202400:46:08

Natural disasters have been hitting the United States hard in 2024, and programs designed to help ensure telecommunications resiliency have been working well in the background to keep people connected and facilitate response. In this episode of Advancing Cyber, host Cristin Flynn Goodwin, joined by telecommunications policy expert Kathryn Condello and telecommunications and cybersecurity veteran Marcus Sachs, addresses a critical problem: what happens when cloud services are taken offline at such a scale that customers and sectors compete to decide who gets restored first? As cloud infrastructure increasingly underpins vital sectors—finance, healthcare, utilities, and government—the question isn’t whether disruptions will happen but how devastating the impacts will be when they do.

 

The discussion dives into the structural and regulatory vulnerabilities in current cloud frameworks that sit at the intersection of cybersecurity and telecommunications, evaluating whether an approach like the telecom sector’s Telecommunications Service Priority (TSP) regime can be adapted for rapid cloud restoration in times of crisis. As data centers carry multiple tenants with differing priorities, the panel explores the impact of the lack of regulation on cloud services in times of crisis, in the US and internationally.

 

This episode challenges cybersecurity policy and tech leaders to reassess how regulation, prioritization, and strategic partnerships must evolve as we recognize the cloud’s role in national security, emergency response, and national resilience.

Artificial Intelligence: Critical Infrastructure, or too early to tell?20 Sep 202400:51:45

At the heart of the debate on this episode of Advancing Cyber is a fundamental question: Is “artificial intelligence” itself a critical infrastructure? Join host Cristin Flynn Goodwin, legal expert David Simon, policy leader Jason Healey, and technical expert Jesper Johanssen as they talk through a hypothetical nation state attack against AI to unpack how government and industry would respond. The experts weigh the risks and benefits of regulation, increased sector coordination and collaboration, and the need for an AI-ISAC to prepare for future attacks.

 

Given the diversity of uses for AI, the panel clashes over the notion that AI is critical infrastructure. The panel considers whether the issue rests with the now 25-year-old definition of “critical infrastructure” and whether it may need to be reconsidered for the new AI era.

 

This episode pushes boundaries, challenging the public and private sectors to prepare for the growing role AI is taking in our world. It’s clear from the debate that this is a question that needs to be answered – before the attackers answer it for us.

Blue Screens and Liability, Cyber and AI Regulation, and Disinformation Fails at the Olympics16 Aug 202400:57:18

The CrowdStrike aftermath, the rise of AI regulations that can’t keep pace with technical change, and nation state actors testing and using AI in cyberattacks.

In this premiere episode of Advancing Cyber, host Cristin Flynn Goodwin is joined by Jason Kikta, CISO at Automox, Jen Ellis, Founder of NextJen Security, and Jessica Herrera-Flanigan, Partner at Monument Advocacy, to dive deep and dissect recent cyber events. With differing points of views, they explore the implications of the CrowdStrike incident on software liability, the evolution of cybersecurity and AI technology and regulation, and the role of AI in threat intelligence and its use by nation states in attacks - including disinformation operations the Paris Olympics.

Tune in to this must-listen discussion—subscribe now on Apple Podcasts or Spotify! #AdvancingCyber #cybersecurity #AI #incidentresponse

Advancing Cyber12 Aug 202400:03:18

Advancing Cyber breaks down the leading issues in cybersecurity – incidents, law, public policy, and technology – from diverse expert perspectives to highlight what really matters. 

Hosted by Cristin Flynn Goodwin, cyber law and policy expert for 25 years with the world’s largest technology companies, Advancing Cyber brings together experts in cybersecurity technology, law, and policy to explore current issues and trends impacting cyber.  

© My Podcast Data · Independent project · Data from Apple & Spotify