Episode 207: AI Risk Management — A Trust Relationship
In episode 207 of Cybersecurity Where You Are, Sean Atkinson makes the case for treating artificial intelligence (AI) not as software but as an ongoing trust relationship. He highlights the value of integrating best practices from regulations like the EU AI Act, walks through the three stages of an AI governance lifecycle, and explains how AI risk management fits into organizational governance, change management, and other business processes.
Here are some highlights from our episode:
- 01:16. The trust component of AI governance
- 02:02. A need to align to regulatory best practices and bring them into AI risk management
- 03:47. Advice: Contextualize, don't generalize, your risks associated with AI use
- 04:40. Common questions that lead to AI governance as a requirement
- 06:59. Grounding an agile AI governance process on foundational principles
- 07:46. How the "fortress" approach overlooks the relationship element of AI security
- 09:51. A direct invitation: Listener feedback on AI governance thinking
- 11:44. Evaluating trust and relationship in machine learning and generative AI
- 14:04. The role of human oversight in realizing AI as a method that gets to a solution quicker
- 14:53. AI governance boards: A potential solution to elevating AI literacy internally
- 16:00. AI governance lifecycle: Three phases from current business processes to value generation
- 18:55. Overview of the future of AI security
- 23:16. The need for foundational security controls and AI-specific controls
- 25:00. AI governance assessment: Why it needs to happen across the organization
- 26:28. How AI governance ties into organizational governance
- 29:49. Ethics and responsible AI practice
- 29:57. Change management considerations with AI deployment
- 30:35. A concluding call to action to get stronger together
Resources
- CIS Critical Security Controls®
- Episode 198: AI Privacy from a Risk-Based Perspective
- Episode 122: DeepSeek AI Security and Utility Considerations
- Episode 120: How Contextual Awareness Drives AI Governance
- AI Playbooks for SLTT Cybersecurity Leaders
- CIS Controls v8.1.2 AI Security Guidance Workbook
- Guide to Implementation Groups (IG): CIS Critical Security Controls v8.1
- Mapping and Compliance with the CIS Controls
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing [email protected].
As of June 23, 2025, the MS-ISAC has introduced a fee-based membership. Any potential reference to no-cost MS-ISAC services no longer applies.