Beyond Best Practice: How We Really Build a Safer Digital World with Curtis Dukes

Beyond Best Practice: How We Really Build a Safer Digital World with Curtis Dukes

🎙 Curtis Dukes 👥 70K 📅 December 5, 2025 ⏱ 37 min 👁 404 📄 expert opinion 🧭 2026-08-15
Available in: English (current) Français

Keywords

best practicesecure by designreasonable cybersecurityCISsafe harbor

Summary

In this episode of Cyber Leaders, hosts Kieran Martin and James Line interview Curtis Dukes, Executive Vice President of the Center for Internet Security (CIS). Dukes shares his career journey from the US Air Force to the NSA, where he led the Information Assurance Directorate, and then to CIS. He explains the origins and mission of CIS, which includes developing the CIS Benchmarks and Critical Security Controls, and providing threat intelligence to state and local governments. The conversation focuses on the concept of ‘reasonable cybersecurity’, a guide developed by CIS to help organizations and the legal system determine what constitutes reasonable security measures, particularly in the context of safe harbor laws. Dukes discusses the genesis of the guide, which involved collaboration with legal experts, and its growing adoption in training for lawyers. The discussion also covers the broader topic of ‘secure by design’, highlighting initiatives like the EU’s Cyber Resilience Act and frameworks from NIST, CISA, Microsoft, and Google. Dukes expresses optimism about the future of cybersecurity, emphasizing the importance of making secure by design practical and measurable for all organizations.

181 words

Critical Evaluation

Value of the Information & Strength of the Argument

The podcast provides valuable insights into the practical application of cybersecurity best practices, particularly the concept of ‘reasonable cybersecurity’ and its legal implications. Curtis Dukes’ extensive experience lends credibility to his arguments, which are well-structured and grounded in real-world examples. He effectively argues that cybersecurity cannot be perfect and that a standard of reasonableness is necessary for legal and practical purposes. The discussion on secure by design is also valuable, highlighting the shift from voluntary to mandatory requirements and the need for practical implementation. The argumentation is solid, though it relies heavily on personal experience and expert opinion rather than empirical data.

Scientific Rigor, Source Quality, Title Accuracy

The scientific rigor is moderate; the discussion is based on expert opinion and references to well-known frameworks and initiatives, but lacks formal citations or data. The sources mentioned (CIS, NIST, CISA, EU CRA) are credible and relevant. The title accurately reflects the content, which goes beyond best practices to discuss practical and legal aspects of cybersecurity. No comments were provided, so no analysis of public reception is included.

185 words

Title / Content Match

The title accurately reflects the content, which discusses moving beyond best practices to practical approaches like reasonable cybersecurity and secure by design.

Quality & Reliability

8/10

The speaker is a highly credible expert with extensive experience at the NSA and CIS. The discussion is grounded in practical experience and references specific frameworks and initiatives. However, it is primarily an opinion-based discussion without formal citations or data.

Key Moments

Cited Sources

Concurring Sources

Contribution & Novelties

The podcast provides a unique perspective on cybersecurity by focusing on the legal and practical concept of ‘reasonable cybersecurity’, which is often overlooked in technical discussions. It bridges the gap between technical best practices and legal liability, offering a framework that can be used by organizations and the judicial system. The discussion also highlights the evolution of secure by design from voluntary to mandatory, and the need for practical implementation.

Pour aller plus loin :

126 words

Radar Profile

The radar profile shows high scores in quality of information and global reliability, reflecting the expert's credibility and the relevance of the content. The quantity of information is moderate, and the technical level is accessible to a broad audience, making it valuable for security leaders.

Reliability 8/10