George Ryan
Former Speaker of the Illinois House of Representatives
4
APPEARANCES
1
PODCASTS
012
DEC 30
JAN 6
JAN 13
JAN 20
JAN 27
FEB 3
FEB 10
FEB 17
FEB 24
MAR 3
MAR 10
MAR 17
MAR 24
MAR 31
APR 7
APR 14
APR 21
APR 28
MAY 5
MAY 12
MAY 19
MAY 26
JUN 2
JUN 9
JUN 16
JUN 23
JUN 30
JUL 7
JUL 14
JUL 21
JUL 28
AUG 4
AUG 11
AUG 18
AUG 25
SEP 1
SEP 8
SEP 15
SEP 22
SEP 29
OCT 6
OCT 13
OCT 20
OCT 27
NOV 3
NOV 10
NOV 17
NOV 24
DEC 1
DEC 8
DEC 15
DEC 22
DEC 29
JAN 5
JAN 12
JAN 19
JAN 26
FEB 2
FEB 9
FEB 16
FEB 23
MAR 2
MAR 9
MAR 16
MAR 23
MAR 30
APR 6
APR 13
APR 20
APR 27
MAY 4
MAY 11
MAY 18
MAY 25
JUN 1
JUN 8
JUN 15
JUN 22
JUN 29
JUL 6
JUL 13
JUL 20
JUL 27
AUG 3
AUG 10
AUG 17
AUG 24
AUG 31
SEP 7
SEP 14
SEP 21
SEP 28
Sep 17, 2026
Cyber Security Training, Awareness and Benefits of Tailored Training
13:43

Jack WoodsGUEST
If they are the CFO, for example, and they are a PCI DSS certified organisation, that CFO might have more focus training for his finance team or their finance team in PCI DSS requirements than the cto might have for their team in information security requirements the standards most in most cases frameworks and standards like that are aligned in terms of requirements for information security but the specifics and the nuances will be different and so you will want those training requirements to be different for those teams so that it's relevant to what they're doing and like George has mentioned so that they can apply it kind of immediately without needing to dig further into oh well that kind of applies to us so maybe we should delve deeper into that and do it off their own back if they have training provided to them that's clear and concise and is specific to what is required of them then it's going to be much more beneficial than just that generalized training that everyone will be completing
G
14:55George RyanGUEST
yeah and i think when it comes to the awareness again it's going on basic psychology principles isn't it a lot of people that are doing the awareness training it's well how does this kind of how does this impact me why is this relevant to me to my organization again we mentioned earlier you know if if you're coming in and you're getting awareness training And they're telling you, you know, this is going on in the finance sector.
G
15:24George RyanGUEST
But your education, you're going to be thinking, yeah, it's not relevant to me.
G
15:29George RyanGUEST
Likewise, if you're in finance and people are telling you about educational sector, you know, how they're getting here.
G
15:36George RyanGUEST
It's how can I take this home? One thing we kind of recommend when we do our awareness of training is we will tailor it.
8 MINS LATER
A
23:16AnnieHOST
how is it impacted by ai yeah
Physical Security Controls
A
10:31AnnieHOST
and i think i think you've maybe shared one or two examples already but what would you say is the most surprising physical security weakness that you've encountered which could have led to a major information security breach?
G
10:44George RyanGUEST
So I knew of one which was quite interesting because I just don't think it had been considered at the time but so organisation in a shared building so everyone was using the same supply of lanyards but actually what no one had checked was that the lanyards were set to have different access controls so Ultimately, if you had a lanyard, you could walk into any of the buildings, even the ones you're not supposed to, because actually it was just the binary.
G
11:10George RyanGUEST
You either got access or not, rather than this location is off guards unless you've got this in place.
G
11:17George RyanGUEST
Obviously, that was a panic when you go into the building, you see someone, you're like, I don't think you're supposed to be here.
10 MINS LATER
Establishing Control Over AI Usage
13:21

Jack WoodsGUEST
honesty around its usage is probably one of the key things um so if you if you are if you are using it and you are using it to generate documentation such as policies or procedures and things like that it is always worth ensuring that there's a review kind of conducted by a human before that's rolled out and shared with the rest of the organization and potentially externally as well in the in the in regards to if you're using 27001 for example and you used ai to write your information security policy making sure that it's actually appropriate to your organization before you share that with an organization that might have requested it is uh it's definitely worthwhile
G
14:01George RyanGUEST
yeah i think as well because externally what people may not be aware of is uh sometimes the word document information will actually show someone if they're looking in the right spot that it's been generated with ai which can be a very difficult conversation if you outright uh to come in there was um similar to the iso as well i think um Saw it the other day, someone was asking if they could do the whole ISO process through AI.
G
14:28George RyanGUEST
And actually there's the question of, is the AI deemed to be a competent persons for ISO 27001? And then you get into that kind of territory.
G
14:37George RyanGUEST
So yeah, transparency makes life a lot easier, even if at first it's a bit to own up to that.
G
14:49George RyanGUEST
So what, what can happen is you get kind of those that are really into AI and.
G
14:57George RyanGUEST
You know, let's say the organization said, okay, we're not using this AI tool and someone's got, oh, but it's so good.
A
18:48AnnieHOST
Yeah.
Unusual GRC Questions
A
10:10AnnieHOST
What's a security policy that everyone signs but nobody actually follows?
G
10:15George RyanGUEST
So I think from experience with clients, often it is what's in kind of the acceptable use.
G
10:22George RyanGUEST
Obviously, you've got the more niche policies where it's like, oh, I didn't even know we had one for that.
G
10:30George RyanGUEST
And again, with the operational drift, over time, you can actually forget what's acceptable and what's not as such.
20 MINS LATER