What the ISM AI Update Actually Means for Cyber Teams episode artwork

EPISODE · Apr 1, 2026 · 33 MIN

What the ISM AI Update Actually Means for Cyber Teams

from Day One®

Episode SummaryThe ISM has been updated again, and this time AI is front and centre. In this episode of Secured, Cole Cornford is joined by returning guest Toby Amodio, Practice Lead at Fujitsu Cybersecurity Services, for another instalment of Policy Wonks and Gronks, cutting through the vendor noise to talk about what the March 2026 update actually means in practice.They explore where AI is genuinely delivering value for cyber professionals, from automating compliance mapping and vendor assessments to streamlining pen test reporting and SOC triage. But they are equally candid about the risks: the erosion of foundational skills as junior roles get outsourced to AI, the creeping fatigue of reviewing outputs at scale, and the danger of skipping straight to full automation without the expertise to validate what the machine is doing.The conversation also tackles bigger picture concerns unique to Australia, sovereign AI capability, the risk of a brain drain to the US, and whether a small country can afford to decentralise its AI infrastructure. Toby closes with a sharp reminder for government CISOs: AI is just another system, and how people use it matters far more than the certifications attached to it.Timestamps00:00 Episode Trailer01:01 Chainguard ad01:28 Intro and the March 2026 ISM update03:00 AI hype vs real world utility05:00 Governance and compliance use cases08:00 Vendor assessments and knowledge base automation11:00 Skill erosion and the junior roles question14:00 AI in pen testing: reporting, scoping and customer experience17:30 The maturity model for AI adoption21:00 Vibe coding, slop assurance and fatigue at scale25:00 Agents watching agents and the bot vs bot future28:30 Australian AI sovereignty and the brain drain risk32:00 Top tip for government CISOs on AI risk35:00 Shadow AI and DNS log visibility37:00 Closing remarks🐙 Secured is grateful to be sponsored and supported by Chainguard.Chainguard is the trusted source for open source. Get hardened, secure, production-ready builds so your team can ship faster, stay compliant, and reduce risk. Download your free CVE Reduction Assessment at https://dayone.fm/chainguardSecured is part of Day One.Day One helps founders and startup operators make better business decisions more often. To learn more, join our newsletter to be notified of new First Cheque episodes and upcoming shows.This podcast uses the following third-party services for analysis: Podtrac - https://analytics.podtrac.com/privacy-policy-gdrpSpotify Ad Analytics - https://www.spotify.com/us/legal/ad-analytics-privacy-policy/

Episode metadata supplied by the publisher feed · Published Apr 1, 2026

Embed this episode

Ready to play

What the ISM AI Update Actually Means for Cyber Teams

0:00 33:44

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

Frequently Asked Questions

How long is this episode of Day One®?

This episode is 33 minutes long.

When was this Day One® episode published?

This episode was published on April 1, 2026.

Can I download this Day One® episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!