220 episodes
- Your firewalls, access rules, and least privilege all assume software behaves the same way every time. AI models don't. So what still works, what breaks, and what should you build next? Our guest Dan Stocker, Principal Cybersecurity Architect at JPMorgan Chase and a Cloud Security Alliance contributor, explains why every AI agent needs its own identity, what your assistant's memory costs you in privacy, and where human judgment still matters most. Your hosts are Kip Boyle, CISO with Cyber Risk Opportunities, and Jake Bernstein, Partner with K&L Gates.
LinkedIn: https://www.linkedin.com/in/danielastocker/
"Fire Doesn't Innovate" by Kip Boyle:https://a.co/d/0bYatohy - Every system you've ever governed is a gear. Same input, same output. AI is the first system that guesses back, and that's why your management instincts misfire on it. Kip's new book, Gears Don't Guess, is out Sept 28th. Jake interviews him on why he wrote it, who it's for (the CFO, the general counsel, the risk manager, and the CISO), and the practical tasks, templates, and self-assessment that make it work on the job. The Kindle version is free through Oct 2. Your hosts are Kip Boyle, CISO with Cyber Risk Opportunities, and Jake Bernstein, Partner with K&L Gates.
"Gears Don't Guess" by Kip Boyle (paperback and Kindle):https://www.amazon.com/dp/B0HHTKN8BZ
Free self-assessment and templates:https://gearsdontguess.com
"Fire Doesn't Innovate" by Kip Boyle:https://a.co/d/0bYatohy - Tired of swinging the “compliance hammer” and hitting people until they submit to you? Would you rather be influential, and not dictatorial? Let's find out how you can with your hosts Kip Boyle, CISO with Cyber Risk Opportunities, and Jake Bernstein, Partner with K&L Gates.
See our previous episode on the subject of "buy-in" with our guest Michael Gregg, the CISO of North Dakota -- https://cr-map.com/podcast/171/ - When a hospital's systems go down, care does not stop. It goes back to pen and paper, and the first sign is quiet, because the alerts stop. Physician and CISSP Mark Yoffe explains clinical compensating controls: the steps clinicians take to keep patients safe during downtime. He covers who owns the clinical workflow, how to make controls workable and tested, how to recover information lost in the "memory hole," and what leaders should demand as proof. Paper is not the same as proof. Your hosts are Kip Boyle, CISO with Cyber Risk Opportunities, and Jake Bernstein, Partner with K&L Gates.
LinkedIn: https://www.linkedin.com/in/mark-yoffe-md-cissp-a9927956/
"Fire Doesn't Innovate" by Kip Boyle: https://a.co/d/0bYatohy
LinkedIn post:
Questions:
Here are audience engagement questions for this episode, organized by segment:
Segment 1 – When the Hospital Goes Analog
Have you ever worked through a system outage — at a hospital or anywhere else? What was the first thing that broke down?
Does your organization have any setting where "no news is bad news" during downtime — where information stops coming to you and you don't immediately notice?
Segment 2 – Ownership
Who owns your clinical downtime workflow right now — not IT, but the clinical side? Can you name them?
If your systems went down tonight, is there a single person accountable for whether patient care workflows hold up — or would people be figuring it out as they go?
Segment 3 – Workability
Does your downtime policy actually get used, or does it live in a binder somewhere? When did anyone last open it?
What's one task your team assumes staff can improvise during downtime — that they probably can't?
Segment 4 – The Memory Hole
After your last outage, how confident are you that everything documented on paper actually made it into the record? Did anyone check?
Has a gap in documentation during downtime ever affected a patient's care — or nearly did?
Segment 5 – Leadership Oversight
If your CEO asked today, "Can you show me that our clinical downtime controls actually work?" — what would you hand them?
When did your organization last run a tabletop exercise specifically for clinical downtime — not just IT recovery?
Closing poll question:
Does your organization have a named, clinically credible owner for downtime workflows — yes, no, or "I genuinely don't know"? - After a breach, you either pay the fine, or fight the regulator and lose. There's a third path. It comes down to one word: reasonable. A method called DoCRA turns that question into something a court can use. DoCRA is short for Duty of Care Risk Analysis. Our guest Chris Cronin of HALOCK Security Labs helped build it. Now it's in standards and law. And it shaped a real case where a breached company spent its money on cybersecurity, not fines. Your hosts are Kip Boyle, CISO with Cyber Risk Opportunities, and Jake Bernstein, Partner with K&L Gates.
LinkedIn: https://www.linkedin.com/in/chris-cronin-351416/
"Fire Doesn't Innovate" by Kip Boyle:
https://a.co/d/0bYatohy
Learn more about DoCRA: https://docra.org
More Business podcasts
Trending Business podcasts
About Cyber Risk Management Podcast
Cyber risk made clear for busy leaders. Cyber threats move fast. Your business must move faster. In every episode, Kip Boyle—author of "Fire Doesn’t Innovate" and CISO at Cyber Risk Opportunities—joins cybersecurity attorney and CISSP Jake Bernstein to break down the latest cyber risk. You’ll hear plain-English explanations of what's going on and what you need to do about it. No jargon. No doom. Just clear steps you can use today to save money, win buy-in, and stay out of the headlines.
Podcast websiteListen to Cyber Risk Management Podcast, The Diary Of A CEO with Steven Bartlett and many other podcasts from around the world with the radio.net app

Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features


Cyber Risk Management Podcast
Scan code,
download the app,
start listening.
download the app,
start listening.
Cyber Risk Management Podcast: Podcasts in Family




















