Techstrong interview on IANS new MCP

Archive for the ‘Videos’ Category

Techstrong interview on IANS new MCP

Posted by

The first cybersecurity MCP server is here. Wolfgang Goerlich, IANS faculty member and public sector CISO, joins Alan Shimel on how IANS now surfaces peer research inside Claude and other AI clients. Furthermore, Wolfgang and Alan unpack whether AI is really rotting our brains or quietly sharpening the pros who use it well.

Wolfgang came up in the golden age of security alongside Alan. Consequently, he brings decades of hands-on CISO perspective across healthcare, financial services, tech and public sector engagements. Meanwhile, his IANS faculty seat gives him a front row view of what practitioners are shipping today.

Inside the first cybersecurity MCP server IANS is a practitioner-led research and intelligence network for CISOs. As a result, its new MCP server lets clients pull that research directly into a Claude prompt while they draft a policy or standard. Meanwhile, one of Wolfgang’s own runbooks got refreshed in minutes rather than weeks.

Alan pushes on the details. In addition, the cybersecurity MCP server is scoped to IANS clients and faculty, and it feeds real quotes, insights and polls back into the prompt. Therefore, teams stop guessing what generic AI thinks and start acting on what their peers actually did, whether they are updating a runbook, a policy or a fresh standard.

Why every CISO should watch the cybersecurity MCP server story Alan and Wolfgang widen the lens to the de skilling debate. Meanwhile, the latest studies suggest AI power users sharpen their thinking by interrogating outputs rather than accepting them. Consequently, the gap between passive and active AI users is widening across security teams.

Wolfgang also weighs in on MCP protocol security, comparing today’s posture to the early days of API security. Furthermore, he explains why 170 practitioner-faculty members give the platform an edge as vulnerabilities surface. Learn more at iansresearch.com.

Frameworks and Relationships

Posted by

“Today we welcome J Wolfgang Goerlich, an advisory CISO, mentor, and strategist. We delve into the intricacies of security design frameworks and the importance of building and maintaining relationships in the cybersecurity field. Wolfgang shares his expertise on creating effective security programs, fostering trust within teams, and navigating the challenges of the CISO role. Tune in to gain valuable insights on cybersecurity strategy and the significance of collaborative relationships in achieving security goals.”

Pre-mortems – #2 on SDxCentral’s Top 10 Stories

Posted by

SDxCentral posted the top ten stories of  2023. I was surprised and pleased my pre-mortem on Zero Trust came in at number two on the list. I’m not tagging this as news, as I covered the story when it came out here: https://jwgoerlich.com/a-pre-mortem-on-zero-trust/

But! That did remind me. Since the original article came out, the video came out. If you want to see the RSA talk that landed the second spot on SDxCentral’s top ten, you can see it now. Right here. Right now. So much fun.

Joining Midori on the Consent Dojo

Posted by

We “Value” Your Privacy: Digital Consent with J Wolfgang Goerlich + Midori

  • How has consent been co-opted with things like end user agreements and cookies, and what can we do about it?
  • What can we consent to when it comes to digital toys and tech, including sex toys and sex tech?
  • What are consent technologies, and are there new developments, innovative technologies, or new approaches?
  • How are people advocating for themselves, individually or collectively, to take back control over our tech?

Nudge and Sludge: Driving DevOps Security with Design

Posted by

 

Nudge and Sludge: Driving DevOps Security with Design

Security people say users are the weakest link. When security becomes burdensome, users take shortcuts jeopardizing security. Design offers a solution. We will walk through affordances, nudges, sludge and principles to inform and direct our design. Come learn how better usability leads to DevOps security.

This talk was given at DevOpsDay Tel Aviv 2021.

We got it wrong! – Great Lakes Security Conference

Posted by

This session is on all the things we all say all the time, about all the things we call know. Security through obscurity is bad. Defense in depth is good. Stop clicking things. Next generation is bad, or maybe, next generation is good. The list goes on and on. The resulting rules of thumb are sometimes contradictory and often misleading. With war stories and anecdotes, we’ll explore what happens when teams run security by tribal knowledge instead of research and reason. Spoiler alert: they get pwned. Turns out, we were wrong.

Presented for Great Lakes Security Conference (GLSC) 2021.

Watch more videos on my YouTube channel.