Cybersecurity Today TV - Ep 66 - Practical Generative AI Risk & Compliance: A CISO’s Playbook

Cybersecurity Today TV - Ep 66 - Practical Generative AI Risk & Compliance: A CISO’s Playbook

🎙 CybersecurityToday 👥 492 📅 October 27, 2025 ⏱ 27 min 👁 93 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

generative AIriskcomplianceCISOplaybook

Summary

In this episode of Cybersecurity Today, host Jim Wiggins interviews Supro Ghose, CISO at Graphene Security, on practical strategies for managing generative AI risk and compliance. The show begins with a news segment covering recent cybersecurity incidents: CISA ordered federal agencies to patch Cisco ASA vulnerabilities exploited by state actors, a ransomware attack on Collins Aerospace disrupted European airports, and Salesforce faced lawsuits over a breach involving compromised OAuth tokens. The main interview focuses on defining generative AI and its business applications, highlighting risks such as hallucination, bias, and data poisoning. Ghose emphasizes the importance of not putting sensitive data into public LLMs and recommends enterprise options with contractual guarantees. He introduces the concept of RAG (retrieval-augmented generation) for private data integration. The discussion covers prompt injection as a security concern, the need for input validation, and the emerging threat of malware in uploaded documents. On compliance, Ghose references NIST AI RMF and EU regulations, advocating for a simplified approach based on ’three V’s’ (value, viability, vigilance). He stresses the importance of data classification and protection strategies before AI adoption. The conversation also touches on intellectual property issues, third-party LLM selection, and the evolving role of humans in AI workflows. Ghose concludes by sharing his contact information and encouraging viewers to reach out.

213 words

Critical Evaluation

Value of the Information & Strength of the Argument

The value of the information lies in its practical, experience-based insights from a senior CISO. Ghose provides actionable advice on data governance, enterprise LLM usage, and compliance frameworks, illustrated with relatable analogies (e.g., spreadsheet validation, car shopping). The argumentation is coherent and logical, building from risk identification to mitigation strategies. However, the discussion remains at a high level, lacking deep technical detail or quantitative evidence. The claims are plausible and align with industry best practices, but they are not supported by specific data or case studies, limiting the strength of the argumentation.

Scientific Rigor, Source Quality, Title Accuracy

The scientific rigor is moderate. The content is based on the speaker’s professional experience rather than peer-reviewed research. The only explicit references are to NIST AI RMF and EU regulations, which are mentioned but not detailed. The title accurately reflects the content, and the show’s structure (news segment + interview) is clear. The lack of citations and the conversational tone reduce the overall rigor, but the information is consistent with current industry knowledge. No comments were provided, so no analysis of public reception is possible.

192 words

Title / Content Match

The title accurately reflects the content: the episode focuses on practical generative AI risk and compliance from a CISO's perspective, and the interview with Supro Ghose delivers on this promise.

Quality & Reliability

7/10

The content is based on the expert opinion of a seasoned CISO with 28 years of experience. The discussion is practical and grounded in real-world examples, but lacks formal citations or references to specific studies or frameworks beyond general mentions of NIST AI RMF and EU regulations. The information is presented in an accessible manner, but the lack of verifiable sources and the conversational format limit its scientific rigor.

Key Moments

Contribution & Novelties

The episode provides a practical, CISO-level perspective on generative AI risk and compliance, offering a structured approach (three V’s) and emphasizing data governance as a prerequisite. It highlights emerging threats like prompt injection and data poisoning in training data, which are less commonly discussed in mainstream media. The discussion on intellectual property and the evolving role of humans adds value for practitioners.

Pour aller plus loin :

  • NIST AI Risk Management Framework — Official framework for AI risk management, referenced in the episode.
  • Retrieval-Augmented Generation (RAG) — Concept of RAG, explained as a method to enhance LLM outputs with private data.
  • Prompt injection — OWASP resource on prompt injection attacks, a key security concern discussed.
  • EU AI Act — Overview of the European Union’s AI regulation, relevant to compliance discussions.

130 words

Radar Profile

The radar profile shows a balanced but moderate performance across all dimensions, with slightly higher scores in information quantity and quality, reflecting the practical insights provided. The technical level is moderate, suitable for a general audience, and the overall reliability is acceptable given the expert opinion nature of the content.

Reliability 6/10