エピソード

  • Can We Automate Trust? The Future of FIPS 140 and Common Criteria
    2026/08/13

    Can we automate trust? And if we can, what happens to cybersecurity certification as we know it?In this episode of Trust & Turbulence, I’m joined by longtime colleagues Ashit Vora and Shawn Geddis, who are both building technologies designed to rethink how security certification gets done — but they’re approaching the problem in very different ways.Ashit is using AI to automate Common Criteria certification, with an eye toward expanding into areas such as the EU Cyber Resilience Act. Shawn is taking an intelligent automation (IA) approach to FIPS 140 and other assurance processes, emphasizing deterministic testing, standardized data, and machine-to-machine evidence exchange.We dig into some big questions:• What’s actually broken in today’s FIPS 140 and Common Criteria processes? • What’s the difference between AI and intelligent automation — and where does each belong? • Can automated testing and evidence ever earn the same trust as traditional human-driven evaluation? • What happens to certification labs as more of the work becomes automated? • Could continuous certification replace today’s point-in-time model? • Will the EU Cyber Resilience Act (CRA) accelerate automation simply because traditional compliance cannot scale? • How should Common Criteria and the broader standards community deal with AI? • And what happens when increasingly fragmented global requirements undermine the old goal of “evaluate once, sell everywhere”? This is also a conversation among three people who have worked together in the FIPS and Common Criteria community for well over a decade, so we get into some history, war stories, disagreements, and more than a few analogies — including teddy bears, taxes, Britney Spears and building a house.Can we really automate trust? Or does human judgment always have to remain at the center of cybersecurity assurance?That’s what we explore in this episode.If you enjoy Trust & Turbulence, please like, subscribe, and share your thoughts in the comments — particularly where you think AI and automation belong in the future of cybersecurity certification.About the GuestsShawn GeddisShawn Geddis spent more than 25 years at Apple, where he built the first Apple Platform Security Certifications Program and led engineering work for global platform certifications. He also built Apple’s SECLAB, its NVLAP-accredited first-party cryptographic laboratory, serving as lab manager, tooling developer, and—in his words—“evidence whisperer.” Shawn has since founded Katalyst LLC, focused on developing approachable automation and tooling for security certification.Ashit VoraAshit Vora is Co-Founder of Autonomi, an AI-enabled automation platform focused on transforming standards-based product security certification. Previously, Ashit co-founded Acumen Security, which grew into a leading product security certification provider before being acquired by Intertek. Earlier, he led Cisco’s U.S. government certification business supporting programs enabling approximately $1.5 billion in annual revenue. His work spans more than two decades of product security, certification, testing, standards, and commercialization. Music by Mikhail Smusev from PixabayLogo

    続きを読む 一部表示
    1 時間 12 分
  • When Security Gets in the Way: A Conversation with Debra Woog
    2026/07/26

    Security isn't just about stopping hackers—it also has to work for the people using it.In this episode of Trust and Turbulence, I sit down with Debra Woog, Founder & CEO of Connect Two, to explore the human side of cybersecurity. From ordering a pizza to helping aging parents navigate digital accounts, we discuss why trust, usability, and accessibility matter just as much as technology.In this episode:Why security often creates unnecessary frictionHelping aging parents navigate today's digital worldAI, trust, and human connectionDesigning systems that real people can actually useWhy usability is a cybersecurity issueIf you enjoyed this conversation, please like, subscribe, and share it with someone who cares about building technology people can trust.#TrustandTurbulence #Cybersecurity #DigitalTrust #UserExperience #AI #Leadership00:00 Intro00:10 Meet Debra Woog: From Leadership to Crisis Navigation08:33 Trust, AI, and the Growing Cost of Security20:52 When Security Gets in the Way of Helping People30:46 Designing Better Security for Real Life

    続きを読む 一部表示
    35 分
  • The Perpetual Student with Jim West
    2026/07/03

    In this episode of Trust and Turbulence, I sit down with cybersecurity leader, author, podcaster, and lifelong learner Jim West. From his early days repairing computers at CompUSA to advising senior government leaders on cybersecurity, quantum computing, and national security, Jim's career has been anything but ordinary.We discuss cybersecurity, AI, quantum computing, the future of digital trust, life in the Middle East, career development, and why Jim proudly calls himself a "perpetual student."Whether you're a cybersecurity professional, technology enthusiast, or simply curious about how today's leaders navigate a rapidly changing world, this conversation offers valuable insights and plenty of memorable stories.Topics Discussed• Lifelong learning and professional growth• Cybersecurity leadership and national security• Commercial Solutions for Classified (CSfC)• Quantum computing and post-quantum cryptography• Artificial intelligence and deepfakes• International travel and cultural perspectives• Movies, creativity, and thinking differentlyGuest: Jim West, Author, Podcaster, Cybersecurity ExpertHosted by: Joshua Brickman 00:17 Meet Jim West02:14 The Perpetual Student Mindset13:25 Jim's Origin Story in IT & Cyber14:26 Iraq & Working Near the President17:18 25+ Years Living Overseas19:49 CSfC & Common Criteria Deep Dive38:32 Cybersecurity for Everyday Life46:00 The Quantum Threat & Post-Quantum Crypto56:27 Movie Review Wrongs01:05:32 Where to Find Jim WestMusic by Mikhail Smusev from PixabaySocials:LinkedIn: https://www.linkedin.com/in/jimwest1/https://jimwestauthor.com/https://topcyberpro.com/

    続きを読む 一部表示
    1 時間 7 分
  • Technical Competence Requirements For CRA Notified Bodies Quick Summary
    2026/06/10

    This is a short pod about the release by ENISA entitled "Technical Competence Requirements for CRA Notified Bodies." You can access the document directly here:

    https://www.enisa.europa.eu/publications/technical-competence-requirements-for-cra-notified-bodies

    続きを読む 一部表示
    3 分
  • Trust, Resilience & the Future of Cybersecurity | Mary Ann Davidson & Edna Conway
    2026/05/30

    In this episode of Trust & Turbulence, Joshua Brickman sits down with two of the most influential voices in cybersecurity leadership: Mary Ann Davidson, former Chief Security Officer of Oracle, and Edna Conway, former Chief Security & Risk Officer at Cisco and Microsoft.

    Drawing on decades of experience in product security, risk management, supply chain assurance, and cybersecurity policy, they discuss how organizations can build trust and resilience in an increasingly complex digital world.

    Topics include:

    • The origins of supply chain security
    • Lessons from the SolarWinds attack
    • CISO accountability and cyber resilience
    • The EU Cyber Resilience Act and global regulation
    • Software Bills of Materials (SBOMs)
    • AI and product security
    • Building a culture of trust and security

    Rather than focusing on headlines, this conversation examines the deeper challenges facing technology providers, governments, and security leaders as they navigate an evolving threat landscape.

    Guests:
    Mary Ann Davidson – Former Chief Security Officer, Oracle

    Edna Conway – Former Chief Security & Risk Officer, Cisco and Microsoft

    Hosted by Joshua Brickman

    Chapters

    00:00 Introduction

    03:26 Supply Chain Security Origins

    18:33 Lessons from SolarWinds

    35:47 How the EU Is Reshaping Cybersecurity

    45:20 Can AI Make Software More Secure?

    続きを読む 一部表示
    55 分
  • EU Cyber Resilience Act Explained
    2026/05/19

    In this walkthrough of the EU Cyber Acts Conference focused on the EU Cyber Resilience Act, Joshua Brickman explains what the EUCRA is all about to the Common Criteria Users Forum virtual spring workshop. This was recorded on April 1, 2026.
    00:00 Conference Recap
    00:23 Cybersecurity Act Basics
    02:20 CRA Marketplace Rules
    03:43 Scope Digital Products
    04:18 Penalties And Deadlines
    06:03 Vulnerability Reporting Duties
    09:05 CRA Is Law Now
    09:38 Product Classes Overview
    11:27 Standards And Gray Areas
    13:41 Nokia Program Timeline
    14:57 Support Period Liability
    16:50 Q&A Product Families
    19:30 Reporting Portal Uncertainty
    21:24 Vertical Standards Trouble
    22:37 Crypto Requirements
    24:14 Worst Case Scenario
    26:30 Conformity Modules And Labs
    28:50 Liability And Resourcing Gaps
    31:11 Call To Organize
    31:55 Skills Needed and Conclusion

    続きを読む 一部表示
    34 分