Welcome to the Cybersecurity Readiness Podcast Site

Episodes

109
July 22, 2026

Episode 109 - From Alert Fatigue to Agentic Defense: Redesigning the Human Role in the AI-Native SOC

In Episode 109 of the Cybersecurity Readiness Podcast Series, Dr. Dave Chatterjee is joined by Joshua Weinick, AI Automation Engineer at Blink Ops, to examine a question every security leader is now facing: what happens when the volume, velocity, and variety of cyber threats exceed what any human-staffed security operations center (SOC) can handle, and what role do humans play in a security function that increasingly depends on AI agents executing at machine speed. Analyzed through Dr. Chatterjee's Commitment–Preparedness–Discipline (CPD) Framework, the episode reframes the SOC transformation not as a story about replacing security professionals, but about redesigning where human judgment adds the most value once the mundane, repetitive, and time-critical work is handled by governed AI systems. To access and download the entire podcast summary with discussion highlights: https://www.dchatte.com/episode-109-agentic-ai-in-the-security-operations-center-redesigning-the-human-role-in-a…
108
July 8, 2026

Episode 108 -- The Invisible Foundation: Why DNS Security Is the Governance Gap No One Is Watching

In Episode 108 of the Cybersecurity Readiness Podcast Series, Dr. Dave Chatterjee is joined by Scott Harrell, President and Chief Executive Officer of Infoblox and former leader of Cisco's $20 billion enterprise networking business — to examine one of the most consequential security blind spots in modern enterprise governance: the foundational network infrastructure layer that every other security investment depends on, and that almost no organization actively governs. The conversation addresses how to make the governance case for foundational infrastructure investment, what differentiated DNS security looks like, how agentic AI is about to make network complexity exponentially harder to manage, and what three metrics every senior leader should be demanding from their security teams. Analyzed through Dr. Chatterjee's Commitment–Preparedness–Discipline (CPD) Framework, the episode reframes network infrastructure security from an IT operational matter into a board-level governance im…
107
June 24, 2026

Episode 107 -- Compliant but Exposed: Rethinking GRC for Real Security

In Episode 107 of the Cybersecurity Readiness Podcast Series, Dr. Dave Chatterjee is joined by Richa Kaul, Founder and CEO of Complyance, to address one of the most consequential misunderstandings in enterprise security governance: the assumption that compliance equals security. Two recent incidents frame the discussion — the May 2025 ransomware attack on Marks & Spencer, which generated estimated losses exceeding £300 million, and a concurrent third-party compromise exposing customer data across platforms including Discord. The central premise: organizations with robust GRC platforms and formal compliance certifications can still be catastrophically breached. The gap between compliance and security is structural — and that is where attackers operate. Kaul explains that traditional GRC tools were built to reduce administrative burden, not risk. The result is compliance theater: organizations check boxes, pass audits, and receive certifications that say little about actual security p…
106
June 10, 2026

Episode 106 -- The Invisible Attack Surface: Zero Trust for SAP and ERP Environments

Here's the version at ~1500 characters: In Episode 106 of the Cybersecurity Readiness Podcast Series, Dr. Dave Chatterjee is joined by Holger Hügel — CTO of SecurityBridge and SAP cybersecurity authority with over 26 years of experience — to expose a governance blind spot hiding inside even the most mature enterprise security perimeters: the SAP environment. The August 2024 ransomware attack on Stoli Group USA sets the stage: attackers targeted the company's SAP ERP system directly, disrupting financial operations and contributing to a bankruptcy filing within three months. The hard truth — organizations can have zero trust, network segmentation, and identity governance fully deployed and still be critically exposed, because most CISOs have never claimed accountability for SAP security. Hügel identifies the structural gap: SAP systems are the most business-critical yet least security-governed assets in large organizations. SAP and security teams speak different languages, operate…
105
May 20, 2026

Episode 105 -- The Invisible Layer: Governing Routing Security as a Supply Chain Risk

In Episode 105 of the Cybersecurity Readiness Podcast Series, Dr. Dave Chatterjee is joined by Andrei Robachevsky — Technical Director of the Internet Integrity Program at the Global Cyber Alliance, founding contributor to MANRS (Mutually Agreed Norms for Routing Security), former CTO of RIPE NCC, and former Senior Director of Technology Programs at the Internet Society — to examine a cybersecurity risk that almost no enterprise security team is governing: the internet routing layer. Analyzed through Dr. Chatterjee’s Commitment–Preparedness–Discipline (CPD) framework, the conversation delivers a clear and actionable message: routing security is not a network engineering problem — it is a supply chain governance problem. The tools already exist. RPKI exists. MANRS exists. MANRS+ is nearly here. The gap is entirely on the governance side, and it is closeable. The organizations that will not find themselves in the next routing incident are the ones that start with a map of their conne…
104
May 11, 2026

Episode 104 -- Hidden Fault Lines: Why Modern Security Breaks Under Pressure

In Episode 104 of the Cybersecurity Readiness Podcast Series, Dr. Dave Chatterjee, Ph.D., is joined by Khalid Kark, Field CIO at Cloudflare, a network handling over 20% of global Internet traffic, and a 20-year veteran of advising Fortune 500 boards and C-suites at Deloitte and Forrester, to examine six hidden fault lines threatening organizational resilience in an AI-driven, hyperconnected world. Opening with the 2024 CrowdStrike incident, where a single misconfigured content file simultaneo...
103
April 29, 2026

The Clock Is Ticking: Navigating Quantum Risk and the Path to Crypto Agility

In Episode 103 of the Cybersecurity Readiness Podcast Series, Dr. Dave Chatterjee is joined by Peterson Gutierrez—Vice President of Information Security at Barracuda Networks and a 28-year cybersecurity veteran with experience spanning private industry, the Big Four, and New York City Cyber Command—to examine one of the most consequential and underestimated challenges facing security leaders today: the quantum computing threat and what it truly means to become cryptographically agile. Opening with a vivid scenario—a healthcare organization whose encrypted data is exfiltrated today and decrypted after a quantum breakthrough years from now—Dr. Chatterjee introduces the concept of Q Day risk: the danger is not a dramatic breach tomorrow, but decisions made today that leave organizations exposed later. The episode moves beyond the industry’s fixation on which post-quantum algorithm to adopt, making the case that algorithm selection is the wrong problem to solve. The right goal is crypto …
102
April 15, 2026

AI Is Rewriting the Threat Model: Are Security Leaders Keeping Up?

In Episode 102 of the Cybersecurity Readiness Podcast Series, Dr. Dave Chatterjee is joined by Chris Cochran—Field CISO and VP of AI Security at the SANS Institute, and a veteran of the U.S. Marine Corps, NSA, and U.S. Cyber Command—to examine how artificial intelligence is fundamentally rewriting the cybersecurity threat model, and whether security leaders are evolving fast enough to keep pace. From the rapid and largely ungoverned adoption of AI across enterprises, to the collapse of traditional threat modeling assumptions, to the rise of autonomous agentic systems operating without human intervention, the episode surfaces a stark reality: AI is no longer a future risk—it is an active, present-tense governance challenge that most organizations are still approaching reactively. Framed through Dr. Chatterjee’s Commitment–Preparedness–Discipline (CPD) lens, the conversation delivers a clear and urgent message: security leaders must establish AI asset visibility, embed security in…
101
Feb. 27, 2026

Episode 101: AI vs. AI in Cybersecurity: Why Continuous Validation Is Now Essential

In this forward-looking Episode 101 of the Cybersecurity Readiness Podcast Series, Dr. Dave Chatterjee is joined by Snehal Antani—CEO and Co-Founder of Horizon3.ai and former Chief Technology Officer at Joint Special Operations Command (JSOC)—to examine the rapidly emerging reality of AI-versus-AI cyber warfare. As AI dramatically compresses attacker dwell time and lowers the skill barrier for sophisticated intrusions, traditional defensive postures are proving insufficient. Drawing on real-world demonstrations and national-security-grade operational experience, Antani explains how offensive AI is transforming cyber risk by enabling attackers to move at machine speed, scale attacks indiscriminately, and expose systemic weaknesses in organizational defenses. Framed through Dr. Chatterjee’s Commitment–Preparedness–Discipline (CPD) lens, the episode reframes cybersecurity readiness as a continuous validation discipline—one that demands organizations train like they fight, reduce bl…
100
Jan. 28, 2026

Episode 100: From Cyber Defense to Trust Governance

In this milestone 100th episode of the Cybersecurity Readiness Podcast Series, Dr. Dave Chatterjee reflects on nearly one hundred conversations that collectively reveal a hard-earned truth: cybersecurity has crossed a point of no return. It is no longer a technical function or an episodic response to crises—it has become a trust discipline. Rather than celebrating longevity, Episode 100 serves as a moment of synthesis and reckoning. Drawing on insights from global practitioners, scholars, regulators, and executives, Chatterjee distills why trust collapses, why recovery is slow, and why organizations that invest in readiness consistently outperform those that rely on reaction. Tracing the podcast’s origins—from an experimental idea inspired by a University of Georgia undergraduate to a globally recognized platform reaching listeners in over 117 countries—this episode reframes cybersecurity as a leadership, governance, and enterprise resilience challenge. Through the lens of the C…
99
Jan. 14, 2026

Episode 99: Access Control Reimagined — Why Identity, Devices, and Zero Trust Must Converge

In this landmark 99th episode of the Cybersecurity Readiness Podcast Series, Dr. Dave Chatterjee is joined by Denny LeCompte—CEO of Portnox (https://www.portnox.com/) and a former SolarWinds executive—to examine one of cybersecurity’s oldest yet most persistently exploited challenges: access control. Despite decades of investment in passwords, MFA, and perimeter defenses, breaches rooted in access failures continue to dominate headlines. Drawing on firsthand experience—including lessons learned from the SolarWinds Sunburst breach—LeCompte explains why password-centric security models are fundamentally misaligned with human behavior and modern digital environments. Together, Chatterjee and LeCompte argue for a decisive shift toward passwordless, device-centric, zero-trust access models that assume human fallibility, eliminate implicit trust, and dramatically reduce attack surfaces. Framed through Dr. Chatterjee’s Commitment–Preparedness–Discipline (CPD) lens, the episode reframes…
98
Dec. 30, 2025

Episode 98 -- Beyond Certification — Turning Compliance into Competitive Firepower

In this timely and hard-hitting episode, Dr. Dave Chatterjee is joined by Sandeep Pauddar—an accomplished global auditor with over 30 years of experience—to challenge a deeply entrenched misconception: that cybersecurity certifications and compliance are merely regulatory checkboxes. Instead, the conversation reframes compliance as a strategic asset—one that can strengthen trust, resilience, and competitive positioning in an era defined by AI, global regulations, and escalating cyber risk. Drawing on real-world breach examples, audit insights, and cross-industry comparisons, Pauddar explains why organizations that treat compliance reactively often pay a steep price—financially, operationally, and reputationally. Dr. Chatterjee integrates his Commitment–Preparedness–Discipline (CPD) governance framework to demonstrate how leadership mindset, continuous audit readiness, and disciplined execution transform certifications from defensive necessities into engines of strategic value. T…
97
Dec. 16, 2025

Episode 97 -- AI’s Missing Puzzle Piece — Why Information Readiness Determines AI Success

In this insightful episode, Dr. Dave Chatterjee speaks with Greg Clark—longtime enterprise content management and cybersecurity leader—about a foundational but overlooked ingredient of AI success: information readiness. While organizations rush to implement artificial intelligence, many neglect the quality, governance, security, and contextual integrity of the data fueling these systems. As Clark notes, without clean, curated, and governed information, even the most advanced AI models will misfire—sometimes with damaging or legally significant consequences. Together, they explore why “garbage in, garbage out” is more relevant than ever in the AI era, especially as enterprises confront fragmented data, weak metadata, inconsistent governance, and high regulatory scrutiny. Dr. Chatterjee weaves in his Commitment–Preparedness–Discipline (CPD) governance framework, demonstrating why information readiness must be treated as a strategic capability, not a technical afterthought. The conver…
96
Dec. 1, 2025

Episode 96 -- The Man Behind the Hollywood Movie Breach: Cyber Lessons from a Real FBI Ghost

In this riveting episode, Dave Chatterjee, Ph.D., sits down with Eric O’Neill, a legendary FBI undercover operative whose real-life spy hunt inspired the Hollywood thriller Breach. O’Neill recounts how he helped capture Robert Hanssen, one of the most damaging spies in U.S. history, and how the counterintelligence mindset he cultivated at the FBI now forms the foundation of his cybersecurity strategy work. Together, they explore how spycraft translates to the digital age—from insider threats and virtual trusted insiders to AI-driven deception, deepfakes, and nation-state infiltration. Through real-world stories, hard-won lessons, and O’Neill’s PAID (Prepare–Assess–Investigate–Decide) methodology, listeners learn why thinking like a spy is essential for defending organizations, families, and individuals in a hyperconnected world. Dr. Chatterjee connects these insights to his Commitment–Preparedness–Discipline (CPD) framework, emphasizing the strategic value of leadership, culture, a…
95
Nov. 19, 2025

Episode 95 -- Defending Digital Trust – Battling the Deepfake Surge with AI-Powered Detection

In this episode, Dave Chatterjee, Ph.D. sits down with Sandy Kronenberg, Founder and CEO of Netarx, an AI-driven platform designed to detect and prevent synthetic impersonation across video, voice, and email. With deepfake fraud incidents skyrocketing by 3,000 percent and costing organizations an average of $500,000 per attack, Kronenberg and Chatterjee unpack how AI can now help defeat AI—turning defense innovation into a frontline imperative. Together, they explore the evolution of deepfake technology, the psychology of digital deception, and how organizations can safeguard their people and data from real-time manipulation. Through the Commitment–Preparedness–Discipline (CPD) framework, Dr. Chatterjee emphasizes the importance of leadership discipline, continuous monitoring, and technology integration in establishing a high-performance cybersecurity culture in the era of generative AI threats. To access and download the entire podcast summary with discussion highlights - https…
94
Nov. 4, 2025

Guardians of Trust: The CISO’s Strategic Role in Global Non-Profits

In this episode, Dr. Dave Chatterjee sits down with Pam Lindemoen, Chief Security Officer and Vice President of Strategy at the Retail & Hospitality Information Sharing and Analysis Center (RH-ISAC), to explore the CISO’s evolving role in global nonprofit organizations. Moving beyond traditional corporate metrics of cost and compliance, Lindemoen reveals how cybersecurity leadership in the nonprofit sector is ultimately about preserving trust, protecting donor data, and sustaining mission-driven operations. Drawing on three decades of experience across healthcare, finance, and retail, Lindemoen shares how RH-ISAC has become a collaborative force multiplier, enabling member companies to detect, respond, and adapt collectively to cyber threats. Through the Commitment–Preparedness–Discipline (CPD) framework, Dr. Chatterjee and Lindemoen illustrate how leadership, empathy, and shared intelligence drive resilience across the nonprofit ecosystem. To access and download the entire podcast…
93
Oct. 19, 2025

Episode 93 -- The New Browser Wars: Why the Enterprise Browser Has Become Cybersecurity’s Next Battleground

In this episode, Dr. Dave Chatterjee speaks with Anupam Upadhyay, Senior Vice President, Product Management, Palo Alto Networks, a seasoned product and cybersecurity leader, to unpack the “new browser wars” and why enterprise browsers are fast becoming a core battleground in the fight for digital trust. Drawing on over two decades of experience spanning Cisco, startups, and Palo Alto, Upadhyay traces the evolution of the humble browser from a passive content viewer into the primary interface for cloud applications, collaboration tools, and sensitive business data. The conversation examines the browser’s expanding role as both a productivity hub and a primary attack vector—accounting for over 90 percent of initial intrusions via phishing, malicious extensions, or session hijacking. Through the lens of the Commitment-Preparedness-Discipline (CPD) Framework, Dr. Chatterjee and Anupam Upadhyay emphasize that securing the enterprise browser is not merely a technical exercise but a gover…
92
Oct. 8, 2025

The AI Augmented SOC: Balancing Technology, Talent, and Trust

In this episode, Dr. Dave Chatterjee speaks with Will Ledesma, Director of MDR Cybersecurity Operations at Adlumin, a veteran SOC leader and cyber defender with over two decades of experience in enterprise security and the U.S. Air Force Reserves. Ledesma shares his journey from IT systems administration to frontline cyber defense, and offers hard-earned insights into the realities of Security Operations Centers (SOCs) in the age of artificial intelligence. The conversation explores how AI is...
91
Sept. 23, 2025

Leading Under Fire: Legal and Leadership Lessons from Cyber Crises

In this episode, Dr. Dave Chatterjee speaks with Josh Cook, a seasoned cybersecurity and privacy attorney who has guided multinational corporations and mid-sized businesses through high-stakes cyber crises. Drawing on his experience as the first Global Cyber Counsel for a Fortune Global 500 company, Cook shares how he built a global cyber legal function from scratch and why legal teams must be engaged long before an incident occurs. Together, they explore the human, organizational, and legal dynamics of crisis leadership: from building attorney-client privilege into preparation, to developing muscle memory through tabletop exercises, to ensuring the C-suite speaks with one unified voice when every second counts. Anchored in Dr. Chatterjee’s Commitment–Preparedness–Discipline (CPD) framework, the discussion underscores how legal, leadership, and security functions must converge to preserve trust and resilience in the face of relentless cyber threats.
90
Sept. 8, 2025

AI vs. AI: Automating Defense to Outpace Automated Attacks

In this episode, Dr. Dave Chatterjee speaks with Roi Cohen, CEO and Co-Founder of Vicarius, about the urgent need to counter AI-driven attacks with equally automated defenses. Cohen, who began his career managing mission-critical systems in the military, shares his journey through leadership roles at CyberArk and the launch of Vicarius. Drawing from real-world penetration tests at hospitals and Ivy League institutions, he illustrates how attackers exploit simple misconfigurations to access sensitive data. Together, they examine why defenders must move beyond manual, ticket-based remediation to keep pace with adversaries leveraging agentic AI. The conversation highlights that automation, while essential, is insufficient without human oversight and governance discipline. Anchored in Dr. Chatterjee’s Commitment–Preparedness–Discipline (CPD) framework, the discussion highlights the organizational mindsets and technological building blocks needed to sustain resilience. Cohen emphasizes …
89
Aug. 26, 2025

Beyond Passwords: Making Identity-Based Attacks Impossible in the Age of AI

In this episode, Dr. Dave Chatterjee sits down with Jasson Casey, CEO & Co-Founder @ Beyond Identity, to dissect the growing threat of identity-based attacks, which now account for nearly 80% of breaches. Casey explains how adversaries increasingly “log in” instead of breaking in, leveraging techniques such as MFA fatigue, session hijacking, and phishing kits. He shares lessons from his professional journey—ranging from building telco networks to advising the U.S. Government and launching Beyond...
88
July 21, 2025

Closing the Remediation Gap with Agentic AI

In this compelling episode, Dr. Dave Chatterjee engages with John Amaral, a serial entrepreneur and cybersecurity innovator, to explore how his company Root is using agentic AI to tackle one of cybersecurity’s biggest challenges—remediation delay. The conversation unpacks the dangers of security debt, the power of human-AI collaboration in patching vulnerabilities, and how organizations can evolve from reactive to proactive postures. The discussion also explores the limitations of AI, the critic...
87
June 17, 2025

AI Security in the Public Sector: Balancing Innovation and Risk

In this episode, Dr. Dave Chatterjee is joined by Burnie Legette, Director of IoT and AI at Intel Corporation and former professional football player. Their conversation explores the evolving landscape of AI deployment within the public sector, with a particular focus on the security challenges and governance strategies required to harness AI responsibly. Drawing on his cross-sectoral experience, Burnie offers insights into the cultural, technical, and ethical nuances of AI adoption. Dr. Chatter...
86
May 17, 2025

Holistic Identity Security: Shifting the Paradigm from Reactive to Proactive

In this compelling episode, Dr. Dave Chatterjee is joined by Damon Fleury, Chief Product Officer, SpyCloud to dissect one of cybersecurity’s most exploited and least understood attack surfaces—identity. With nearly three decades of experience in security, Damon shares real-world insights into how identity compromises serve as the entry point for major breaches, why a holistic approach to identity security is urgent, and how organizations can move from reactive defense to proactive resilience. Th...