Episode 186: Strong Cyber Defense Starts with IT Operations

 

 

In episode 186 of Cybersecurity Where You Are, Tony Sager sits down with Tony Krzyzewski, a CIS Critical Security Controls® (CIS Controls®) Ambassador for the Center for Internet Security® (CIS®). Together, they discuss how strong cyber defense starts with the fundamentals of IT operations.

Here are some highlights from our episode:

  • 00:45. Introductions to Tony Krzyzewski and his background
  • 02:19. Tony Krzyzewski's first interaction with the CIS Controls
  • 03:47. IT operations: The foundation that makes strong cyber defense possible
  • 06:20. How an increasingly connected world make the CIS Controls essential to cybersecurity
  • 09:56. The need for operations people to realize they're part of the cybersecurity solution
  • 13:11. The use of Implementation Groups to reduce overload on IT and security teams
  • 16:52. How the CIS Controls differ from "umbrella frameworks" like NIST CSF and ISO 27001
  • 18:25. CIS Controls mappings and how they help to simplify a surplus of good guidance
  • 20:35. How the CIS Controls support improvement programs and Board-level conversations
  • 25:38. Tony Krzyzewski's work in creating the CIS Controls Ambassador program
  • 27:02. Why a deep view of what's happening at CIS supports Tony Krzyzewski's efforts
  • 30:11. Growing international promotion of the CIS Controls and "doing the basics well"

Resources

If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing [email protected].

As of June 23, 2025, the MS-ISAC has introduced a fee-based membership. Any potential reference to no-cost MS-ISAC services no longer applies.