Secured with Dr. KJ podcast artwork

PODCAST · technology

Secured with Dr. KJ

Welcome to Secured with Dr. KJ—the podcast that explores the evolving world of cybersecurity, the technologies driving it, and the companies shaping our digital future.Hosted by Dr. Kenneth Johnson, cybersecurity leader and strategist, this podcast simplifies complex security topics into actionable insights. In today’s digital world, cybersecurity is a business imperative. Each episode dives into cloud security, Zero Trust, identity management, AI-driven security, and more.We’ll assess how industry leaders, including Microsoft, are tackling security challenges—and where there’s room for improvement. Featuring expert insights from security professionals, industry leaders, and technologists, Secured with Dr. KJ delivers real-world strategies to protect businesses and individuals.Join the conversation! Subscribe today to explore what it takes to stay secure in a rapidly changing digital world—securing tomorrow, one episode at a

  1. 30

    Diversity is a Security Advantage

    Episode SummaryIn this episode of Secured with Dr. KJ, Alexandra Kruse joins Dr. KJ to make a case the security industry needs to hear diversity is not a fairness initiative — it is a security advantage. Drawing from her experience as a cybersecurity professional, immigrant, and working mother of two, Alex unpacks how homogenous teams create blind spots that put entire communities at risk, how AI systems inherit the biases of those who build them, and what it truly looks like to lead in a profession that was not always designed with you in mind. From facial recognition failures to the pressure of school drop-offs between back-to-back meetings, this episode brings the human side of security to the forefront.What You Will LearnWhy leaving diverse voices out of the room is not just a fairness problem but a security risk with measurable consequences, how AI systems reflect the biases in their training data and what that means for underrepresented users at scale, and what real resilience looks like for working mothers navigating leadership in tech.Top 3 TakeawaysDiverse teams build stronger security. When everyone in the room shares the same background and experiences, blind spots form. Communities that are not represented during design and development are the ones most likely to be left unprotected or actively harmed by the tools that are supposed to serve them.AI outputs reflect who built it and what it was trained on. From facial recognition disparities to image generation defaults, the evidence is consistent: AI systems that lack diverse input produce output that fails underrepresented users. In an agentic world where those outputs run without a human reviewing every result, the stakes are even higher.You are in the room because your voice matters, and that is enough. For women earlier in their careers, the pressure to show up perfectly or earn the right to take up space is real. Alex's message is direct: give yourself grace, advocate for others the way you wish someone had advocated for you, and do not confuse rest with weakness.Memorable Quotes"Bringing diverse voices into the room is not just about fairness. It is critical to building stronger security for everyone." — Alexandra Kruse"We need to stop treating diversity as a nice-to-have and start seeing it as a security advantage." — Alexandra Kruse"You are in the room because your voice matters, and that is enough." — Alexandra Kruse"I do not need to deserve rest. I can just take the rest because I am human and that is allowed." — Alexandra KruseConnect with the GuestAlexandra Kruse, MSML — Cybersecurity Professional and AdvocateLinkedIn: https://www.linkedin.com/in/alexandra-kruse-msmlListen & SubscribeLike, follow, and subscribe to Secured with Dr. KJ: https://swdrkj.riverside.com🎙 Apple Podcasts: https://podcasts.apple.com/us/podcast/secured-with-dr-kj/id1805058517🎵 Spotify📺 YouTubeSupport the ShowIf this episode brought value, share it with a peer in your network. Every share helps grow a community built on substance over sales — real practitioners, real insights, no pitches.Securing tomorrow, one episode at a time.

  2. 29

    Blast Radius: How MSPs Secure the many by Protecting One

    Episode SummaryIn this episode, Dr. KJ sits down with Doug Turpin, a seasoned managed service provider leader, to unpack the unique security challenges MSPs face at scale. Doug breaks down the concept of "blast radius" — what happens when the tools designed to protect clients become an attacker's greatest advantage — and shares how his organization builds a security-first culture grounded in stewardship, not fear. The conversation also digs into AI's role as an amplifier, and why ungoverned AI may be one of the most underestimated risks in security today.What You'll LearnWhy blast radius is the defining security challenge for managed service providersHow security gaps most often start with people — not technologyThe difference between using AI as an operational advantage versus accelerating your own mistakesWhat a security-first culture actually looks like from the inside outHow to handle and learn from team mistakes without creating a culture of fearWhy AI without guardrails is a compliance and security liabilityTop 3 TakeawaysBlast radius is real — and it scales fast. MSPs hold privileged access to dozens or hundreds of client environments. A single compromised identity or remote management tool doesn't just affect one network — it can cascade across your entire client base. Least privilege, strong isolation, and constant visibility aren't optional; they're foundational.AI amplifies what's already there — good or bad. AI can surface better signals, reduce noise, and free your sharpest people for judgment calls. But if your fundamentals are weak — bad data, poor identity hygiene, broken processes — AI will accelerate your mistakes, not fix them. Governance comes first, use cases second.Security culture is built on stewardship, not enforcement. When your team understands they're protecting people's livelihoods — not just systems — behavior changes naturally. Clear expectations, shared ownership, and psychological safety to speak up create instinctive security, not performative compliance.Memorable Quotes"The tools that we use are designed to be trusted — and attackers love those as hands-on intrusion kits." — Doug Turpin"AI in reality doesn't fix bad data or identity hygiene or broken processes. If your fundamentals are weak, your AI is just going to make you accelerate your mistakes." — Doug Turpin"Once you see that security is part of doing the right thing — not just following the rules — your behavior changes, and it changes naturally." — Doug TurpinConnect with the GuestDoug Turpin — Managed Service Provider Leader and Senior Security EngineerListen & SubscribeLike, follow, and subscribe to Secured with Dr. KJ: https://swdrkj.riverside.com🎙 Apple Podcasts: https://podcasts.apple.com/us/podcast/secured-with-dr-kj/id1805058517🎵 Spotify📺 YouTubeSupport the ShowIf this episode brought value, share it with a peer in your network. Every share helps grow a community built on substance over sales — real practitioners, real insights, no pitches.Securing tomorrow, one episode at a time.

  3. 28

    Security at Scale: Identity, AI, and Culture

    Episode Title: Security at Scale: Identity, AI, and Culture Host: Dr. Kenneth "KJ" Johnson Guest: Nicole Darden Ford Guest Title: Vice President and Customer Security Officer, Microsoft Duration: ~19 minutesKeywords: identity security, AI security, security culture, Microsoft, enterprise securityEpisode SummaryNicole Darden Ford joins Dr. KJ for a wide-ranging conversation on what it truly means to lead security at global scale. Drawing on over 25 years of experience across corporate and federal environments, Nicole unpacks the three converging forces keeping security leaders up at night — identity, software supply chain, and AI — and why the industry's mindset has fundamentally shifted from reactive to prevention-first. She shares her framework for balancing AI-powered defenses against AI-enabled attacks, why data governance remains the industry's most unresolved challenge, and how the most successful organizations are building security cultures where ownership and accountability belong to everyone. Nicole closes with a lesson from the golf course that every security leader can apply.What You'll LearnWhy identity, software supply chain, and AI are the three converging forces redefining enterprise security riskHow to think about AI as a tier zero asset — and what that means for how you govern and protect itWhy building a security culture rooted in ownership and accountability matters more than any policy or controlTop 3 TakeawaysAI should advise broadly, decide narrowly, and act autonomously only when the blast radius has been clearly defined — organizations that skip this discipline are taking on significant riskData governance is no longer just a CIO or CISO issue — it belongs to the CEO, CFO, and the board, and it must be solved before AI can be deployed safely and effectivelySecurity culture beats security policy every time — when every employee feels accountable and empowered, security becomes part of how the business operates, not a barrier to itMemorable Quotes"When everything looks authorized, it's really hard to figure out where the breach is." — Nicole Darden Ford"AI should advise broadly, decide narrowly, and act autonomously only when the blast radius has been clearly defined." — Nicole Darden Ford"Clarity beats consensus every time." — Nicole Darden FordConnect with the GuestNicole Darden Ford LinkedIn: https://www.linkedin.com/in/nicolendardenford/ Company: www.microsoft.comListen & SubscribeLike, follow, and subscribe to Secured with Dr. KJ: https://swdrkj.riverside.com Apple Podcasts: https://podcasts.apple.com/us/podcast/secured-with-dr-kj/id1805058517 Spotify: Search "Secured with Dr. KJ" YouTube: Search "Secured with Dr. KJ"Support the ShowIf this episode helped you, share it with your team, leave a quick rating/review, and follow the show for new episodes on AI, identity security, security culture, and more.Securing tomorrow, one episode at a time.

  4. 27

    Data Governance in the Age of AI: Building the Right Foundation

    Episode Title: Data Governance in the Age of AI: Building the Right Foundation Host: Dr. Kenneth "KJ" Johnson Guest: Ilya Pozharsky Guest Title: Senior Vice President of Enterprise Solutions, eShare Duration: ~22 minutesKeywords: data governance, Microsoft 365, AI security, collaboration security, eShareEpisode SummaryIlya Pozharsky joins Dr. KJ for a deep dive into one of the most overlooked challenges in enterprise security — data governance. As AI reshapes how organizations work, Ilya makes the case that the industry has long neglected the basics, and that foundation must be in place before AI can be used safely and effectively. Drawing on his experience as a Microsoft Global Black Belt and his work advising CISOs across regulated industries, Ilya walks through how eShare's collaboration fabric helps organizations securely share data within Microsoft 365 — without creating roadblocks for the business. The conversation covers external collaboration challenges, AI's expanding attack surface, and why the most successful security leaders are the ones who partner with the business rather than block it.What You'll LearnWhy poor data governance is the root cause of most AI security risks — and what to do about itHow eShare's collaboration fabric allows organizations to securely share data externally while keeping it inside Microsoft 365Why the best security leaders build partnerships with the business instead of creating roadblocksTop 3 TakeawaysAI is a powerful spotlight on existing data governance failures — organizations that haven't addressed the basics will face significant risk as AI adoption acceleratesSecurity should be a business accelerator, not an inhibitor — meeting users in their flow of work while applying the right guardrails is the key to scalable governanceStart with your North Star — whether building a security program or an AI application, having a clear vision of the end result will guide every decision along the wayMemorable Quotes"It's one thing to have a policy that looks good on paper — it's another to have one that actually scales." — Ilya Pozharsky"AI is really putting a red dot on the fact that not having a good data governance strategy creates a lot of risk." — Ilya Pozharsky"If you build it, they will come." — Ilya PozharskyConnect with the GuestIlya Pozharsky LinkedIn: https://www.linkedin.com/in/ilyapozharsky/ Company: www.eshare.comListen & SubscribeLike, follow, and subscribe to Secured with Dr. KJ: https://swdrkj.riverside.com Apple Podcasts: https://podcasts.apple.com/us/podcast/secured-with-dr-kj/id1805058517 Spotify: Search "Secured with Dr. KJ" YouTube: Search "Secured with Dr. KJ"Support the ShowIf this episode helped you, share it with your team, leave a quick rating/review, and follow the show for new episodes on AI, data governance, Microsoft security, and more.Securing tomorrow, one episode at a time.

  5. 26

    App Security in the Age of AI

    Episode Title: App Security in the Age of AI Host: Dr. Kenneth "KJ" Johnson Guest: Zack Tembi Guest Title: CEO, Single Fin | Managing Partner, Single Fin Ventures | CIO/CISO Community Builder Duration: ~20 minutesKeywords: application security, AI, identity security, agentic AI, private cloudEpisode SummaryZack Tembi joins Dr. KJ to unpack the growing tension between AI-accelerated development and application security. From the explosion of autonomous agents to the rise of identity-based threats, Zack brings a practitioner and investor lens to some of the most pressing challenges facing security teams today. The conversation explores why legacy monitoring tools are falling short, how organizational structure must evolve to embed security into development, and why taking ownership of your data — rather than relying entirely on external AI providers — is becoming a critical strategic imperative. Zack closes with a call to action for security professionals to continuously sharpen their skills and lean into modern innovation with curiosity rather than fear.What You'll LearnWhy AI-native monitoring tools are replacing legacy solutions and what that means for your security stackHow the rise of agentic AI is fundamentally expanding the identity threat surfaceWhy security must be embedded into development teams — not siloed as a separate functionTop 3 TakeawaysThe threat landscape is evolving faster than training programs — security professionals must proactively upskill and test modern tools in their own environmentsIdentity is the new perimeter — as AI agents proliferate, managing machine-to-machine identity is becoming as critical as managing human accessData ownership matters — organizations should consider private cloud or on-prem solutions for mission-critical workloads before sending sensitive data to external AI providersMemorable Quotes"You don't need to be a sophisticated hacker anymore to create these attacks." — Zack Tembi"Security isn't just a security team thing — it's a company thing." — Zack Tembi"We still need that human innovation and creativity to really get value out of AI." — Zack TembiConnect with the GuestZack Tembi LinkedIn: https://www.linkedin.com/in/zacktembi/ Newsletter: www.ciosurge.com Company: www.singlefinventures.ioListen & SubscribeLike, follow, and subscribe to Secured with Dr. KJ: https://swdrkj.riverside.com Apple Podcasts: https://podcasts.apple.com/us/podcast/secured-with-dr-kj/id1805058517 Spotify: Search "Secured with Dr. KJ" YouTube: Search "Secured with Dr. KJ"Support the ShowIf this episode helped you, share it with your team, leave a quick rating/review, and follow the show for new episodes on AI, application security, identity, and more.Securing tomorrow, one episode at a time.

  6. 25

    Building Trust in AI-Driven Supply Chain

    Guest: Erika Voss, CISO at Blue YonderEpisode OverviewDr. KJ sits down with Erika Voss, CISO at Blue Yonder, to explore the evolving landscape of cybersecurity at the intersection of AI and supply chain management. Erika shares her insights on why identity has become the new attack surface, the challenges of securing AI-driven systems, and why customers are ultimately buying trust, not technology.Key Discussion TopicsAI-Driven Supply Chain SecurityManaging expanding attack surfaces in 2026Integrating AI with 40-50 year old legacy systemsMoving to millisecond-level supply chain optimizationIdentity as the New Attack SurfaceWhy all roads in security lead to identityThe identity triad: non-negotiable, high-value, and advanced tiersMoving beyond patch management as a primary concernInsider Risk and Access ManagementPermission creep and trust-but-verify principlesJust-in-time (JIT) access and modern privilege managementBehavioral red flags in identity managementBuilding Security CultureFrom project managers to technical program managersWhy MFA is now just "cyber hygiene basics"Ground-up security programs vs. top-down mandatesThe Trust EconomyWhy customers buy trust, not technology"The 'us' in trust is broken if you can't answer the trust question"Key TakeawaysIdentity is the new control plane - All modern security challenges ultimately trace back to identity and access managementNail the basics first - Before investing in AI agents, ensure your foundation is solidAutonomous security requires governance - AI-driven systems need monitoring, validation, testing, and governanceTrust is the product - In 2026, customers aren't buying technology—they're buying assuranceNotable Quotes"All roads now are leading back to identity... identity is your new attack surface.""It's not about patching the server anymore. That is so 1980.""The 'us' in trust is broken. You're not going to be around if you can't answer that question.""People are not buying your product anymore. What they're buying is trust."About the GuestErika Voss is the Chief Information Security Officer at Blue Yonder, a leader in AI-driven supply chain management. With a doctorate focused on insider threat and extensive experience in enterprise security, Erika brings a unique perspective on securing the intersection of legacy systems and cutting-edge AI technology.Connect with ErikaLinkedIn: Erika Voss, PhD | LinkedInAbout Secured with Dr. KJHosted by Dr. Kenneth Johnson, "Secured with Dr. KJ" features authentic conversations with cybersecurity practitioners across industries. Each episode focuses on substance over sales, bringing you real insights from security leaders.Securing tomorrow, one episode at a time.Listen on: Apple Podcasts | Spotify | YouTube

  7. 24

    DNS Security in the AI Era

    Episode Title: DNS Security in the AI Era with Garland MooreGuest: Garland Moore, Solutions Architect at F5Episode Description: In this episode of Secured with Dr. KJ, I sit down with Garland Moore, Solutions Architect at F5, to discuss DNS security threats, effective defense strategies, and how AI is transforming both the attack landscape and our defensive capabilities. Garland brings over 17 years of hands-on infrastructure experience and shares practical insights for organizations of all sizes.What We Discussed:DNS Security Threats & DefenseWhy DNS remains a primary target and the impact of major outagesEffective strategies: DNSSEC adoption, resolver hardening, rate limitingThe importance of monitoring, logging, and analyticsIntelligent DNS and managed DNS solutions for threat intelligenceAI's Dual Role in DNS SecurityHow AI is being weaponized for DNS attacksLeveraging AI for predictive threat detection and filtering log noiseThe emergence of "layer eight" security challengesPractical Guidance for Smaller OrganizationsMinimum DNS security implementations without enterprise budgetsHybrid approaches combining managed services with internal controlsSticking to security fundamentals over flashy toolsBuilding Security Culture & Getting Executive Buy-InWhy foundational systems (DNS, identity, patching, backups) get overlookedTying DNS security to business impact: revenue, risk, speed to market"If DNS goes down, business stops"—translating technical issues to business outcomesBreaking Into CybersecurityYou don't need 10 certifications to get startedThree essential qualities: curiosity, fundamentals, and persistence"Sponge mode": learning broadly while waiting for opportunitiesThe critical importance of soft skillsKey Quotes:DNS is the heartbeat of the internet—it's definitely something that is highly targeted.Nobody really cares about DNS until it doesn't work.You can't protect what you don't understand.Cybersecurity isn't about chasing the latest attack—it's about protecting the foundational systems that everything relies on.About Garland Moore: Garland Moore is a Solutions Architect at F5 specializing in security and modern applications. With over 17 years of infrastructure experience, he combines deep technical expertise with a growing focus on AI to build scalable, secure solutions. His journey from infrastructure operations to Solutions Architect gives him unique end-to-end understanding of enterprise systems. He holds CKA and AWS Solutions Architect certifications and volunteers with Feed the Children and coaches' youth basketball.Connect with Garland: Garland Moore | LinkedInSecuring tomorrow, one episode at a time. 

  8. 23

    Defense Cybersecurity - from checkbox compliance to security culture

    Episode OverviewAllen Westley, Director of Cyber Intelligence at L3Harris Technologies, explores the challenges government contractors face with AI, compliance, and operational security. We discuss the compliance trap, agentic AI risks, and why judgment-driven leadership outweighs certifications.GuestAllen WestleyDirector of Cyber Intelligence, L3Harris TechnologiesFounder, Cyber Explorer LLC | Adjunct ProfessorLinkedIn: Allen Westley, CSM, CISSP, MBAKey TopicsThe Compliance TrapPassing CMMC audits vs. having operational securityCritical importance of scoping for defense contractorsConvergence of classified and unclassified systems (CUI, 871 controls)Shadow IT: operators using unapproved tools to meet deliverablesAI as Dual-Use TechnologyAdversaries operationalizing AI alongside defendersCognitive mapping and anthropomorphizing risksPattern matching creating unintended classified informationTraining gaps when mandating AI adoption without guardrailsAgentic AI SystemsModels collaborating with limited visibilityChatGPT agent example: exceeding original instructionsData segmentation failures enabling unauthorized accessEngineers bypassing inadequate guardrailsSecurity CultureJudgment over knowledge through experiencePsychological safety for reporting mistakesLeading by example in daily decisionsTrust built through consistency, not town hallsTimestamps00:00 - Introduction01:51 - Compliance trap challenges04:03 - CMMC scoping essentials06:05 - AI reshaping operations10:21 - Agentic systems and data risks12:46 - Canva agent example15:03 - Building security culture18:00 - OutroResourcesCMMC Compliance: Levels 1-3, FCI vs CUIDefense Industrial Base guidanceAI governance frameworksKey TakeawaysScoping determines CMMC successCompliance ≠ operational securityAI needs training and guardrailsAgentic systems require data segmentationPsychological safety builds real cultureConnectSubscribe to Secured with Dr. KJ.Feedback or want to be a guest? Visit: Secured with Dr. KJ - PodcastSecuring tomorrow, one episode at a time.

  9. 22

    The Foundation of AI Success with Avertium

    Episode OverviewIn this Season 3 premiere, Ben Masino, President and Chief Growth Officer at Avertium, discusses how security enables business growth rather than hindering it. We explore building security programs through the Microsoft Security platform, the critical role of data hygiene in AI adoption, and meeting customers where they are for long-term success.GuestBen MasinoPresident & Chief Growth Officer, AvertiumLinkedIn: Ben MasinoKey TopicsAvertium's Approach"Assess, Design, Protect" methodology for regulated industriesServing healthcare, manufacturing, retail, and finance sectors20+ years combined experience in security and complianceAI Readiness Through DataSecuring your data estate is foundational for AI successUsing Microsoft Purview for data discovery and governanceBridging executive AI mandates with IT/security realitiesCustomer SuccessHealthcare company journey: pen test to full MXDR partnershipIntune misconfiguration discovery and remediationBuilding trust through actionable assessmentsCustomer Zero PhilosophyAvertium uses Microsoft E5, Sentinel, and Defender internally firstTesting Copilot for Security to enhance analyst workLeading into the future with proven expertiseTimestamps00:00 - Introduction00:20 - Avertium's mission in security02:05 - Common challenges across regulated industries03:44 - Assess, Design, Protect methodology05:54 - Customer success story08:26 - AI readiness and data estates10:57 - Bridging executives and IT teams12:57 - Customer Zero approach15:09 - Final thoughtsResourcesAvertium: avertium.comMicrosoft Security: Sentinel, Defender XDR, PurviewCompliance: HIPAA, PCI, NERC, High TrustKey TakeawaysFocus creates depth - specialization builds meaningful partnershipsData hygiene before AI - organize your data estate firstMeet customers where they are - tactical starts lead to strategic relationshipsBe your own customer zero - internal testing builds real expertiseSecurity enables business - proper programs accelerate outcomesConnectSubscribe to Secured with Dr. KJ on your favorite podcast platform.Feedback, topics, or want to be a guest? Visit: Secured with Dr. KJ - PodcastKeep securing tomorrow, one episode at a time.

  10. 21

    AI, Mental Health & the Human Side of Cybersecurity

    Episode: AI, Mental Health & the Human Side of CybersecurityGuest: Jameeka Green AaronGuest Title: Chief Information Security Officer, HeadspaceEpisode SummaryJameeka Green Aaron, CISO at Headspace, joins Dr. KJ for a candid conversation on protecting mental health data, the limitations of AI in clinical settings, and why humanity must remain a non-negotiable in cybersecurity. As a Navy veteran and black woman in tech leadership, Jameeka also shares powerful insights on representation, courage, and the fight for equity in the industry.Discussion Topics & Timestamps(00:00) Introduction and guest welcome(01:45) AI in mental health: balancing innovation with patient protection(08:30) Guardrails and governance: the CIA triad applied to AI(14:20) Why security leadership is critical in healthcare(21:30) Explaining security concepts to clinicians and product teams(24:30) Leadership, representation, and courage as a black veteran in cybersecurityKey TakeawaysHumanity is a non-negotiable – AI lacks empathy, context, and the ability to read nonverbal cues. In mental health, models must never instruct users to harm themselves or others—guardrails must be absolute.Data professionals are the linchpin of AI – Good data in, good data out. De-identification, anonymization, and clean data practices are essential before training any model on sensitive health information.Protecting and healing go together – Security in healthcare isn't a barrier; it's an enabler. Clinicians already understand patient privacy deeply—security leadership helps them extend that protection through technology.Resources & Frameworks MentionedHIPAA – Health Insurance Portability and Accountability ActHITRUST – Healthcare information security certificationCIA Triad – Confidentiality, Integrity, AvailabilityHeadspace Ebb – AI companion that helps users navigate mental health contentLarge Language Models (LLMs) – Foundation for AI-powered toolsNotable Quotes"Technology is about people. Everything we create is for the greater good of humanity. As a CISO, I'm here to enable innovation and protect people from the woes of that innovation.""AI has the discernment of a mouse. It doesn't know if the data you provided is truthful or accurate.""Protecting and healing go together."ConnectGuest: Jameeka Green Aaron – (13) Jameeka Green Aaron, CISSP | LinkedInHost: Dr. Kenneth Johnson – (13) Dr. Kenneth Johnson, CISSP | LinkedInSecuring tomorrow, one episode at a time. Hosted on Acast. See acast.com/privacy for more information.

  11. 20

    Healthcare Modernization

    Episode: Healthcare Modernization – Cloud Migration & Responsible AIGuest: Stephen Clark, Enterprise Solution ArchitectEpisode SummaryStephen Clark joins Dr. KJ to discuss how healthcare organizations can modernize legacy systems and embrace AI without compromising patient care or data security. The conversation covers phased cloud migration strategies, balancing clinical access with HIPAA compliance, and implementing AI responsibly to improve patient outcomes while protecting against bias.Discussion Topics & Timestamps- (00:00): Introduction and guest welcome- (01:05): Legacy systems and phased cloud migration strategies- (08:30): Hot sites, lift-and-shift vs. hybrid cloud approaches- (13:20): Balancing clinical access with privacy and compliance- (16:30): AI in healthcare: security applications and responsible implementation- (24:00): Final thoughts: blueprints, executive buy-in, and crawl-walk-runKey TakeawaysAvoid the "big bang" approach – Healthcare cloud migration requires a phased, methodical strategy. Hybrid cloud lets you maintain existing DR/BC plans while modernizing incrementally.Data assessment comes first – Before addressing compliance, security, or migration, you must understand your current state: where data lives, what integrations exist, and who's consuming it.AI needs governance from day one – Responsible AI in healthcare requires clean data, continuous monitoring, transparency in decision-making, and a robust ethical framework policy.Notable Quotes"AI, to me today, has the discernment of a mouse. AI doesn't really discern today—it doesn't know if the data provided is truthful or accurate.""Don't try to boil the ocean. Start with thorough assessments, prioritize compliance and security, and ensure you have executive buy-in before diving in."ConnectGuest: Stephen Clark – (12) Stephen Clark | LinkedInHost: Dr. Kenneth Johnson – (12) Dr. Kenneth Johnson, CISSP | LinkedInSecuring tomorrow, one episode at a time. Hosted on Acast. See acast.com/privacy for more information.

  12. 19

    Security & Leadership

    Security & LeadershipShow: Secured with Dr. KJGuest: Carl Mosby III — solutions engineering leader, trusted advisor, people-first technologistEpisode type: Leadership & culture / AI & securityEpisode snapshotLeadership today sits at the intersection of people and rapidly evolving tech. Carl Mosby III unpacks what effective leadership looks like when security and technology are inseparable—covering education-first cultures, leading without ego, activating others, and keeping trust and ethics at the center as AI accelerates change.Key topicsPeople-first leadership in a high-velocity tech eraEducation as a core security control (making risks & methods visible)Leading without ego: listening, advocacy, and “multiplicity”Activating others: sponsorship, visibility, and shared successAI with guardrails: ethics, trust, and avoiding shiny-object syndromeTimestamps00:00 – 01:04 | Show open & what we cover on Secured with Dr. KJ01:05 – 02:12 | Guest intro: who Carl is & where he leads02:23 – 05:21 | Q1: Leadership when security & tech are inseparable (education, pace of change)05:57 – 07:04 | Leading without ego: balancing urgency with protecting people07:04 – 12:00 | Multiplicity & advocacy: listening, sponsorship, and letting others shine12:00 – 15:30 | AI & leadership: trust, ethics, quality, and resisting over-reliance15:30 – 19:15 | Staying people-centric while tech scales; vulnerability as strength19:18 – 23:12 | The future of leadership: connection, North Stars, and secure growth23:34 – end | Wrap & takeaway5 takeaways to rememberSecurity is a people practice. Training, context, and communication are as critical as controls.Lead without ego. Listen first, advocate often, and elevate others—especially into the rooms that matter.Build multiplicity. Scale impact by empowering teammates with visibility, ownership, and support.Treat AI as an accelerant, not a replacement. Keep trust, ethics, and human judgment at the center.Connection drives performance. Teams work harder when they feel seen, supported, and aligned to purpose.Resources mentionedConferences, forums, and cross-org engagement as leadership force multipliersPrinciples: open-door culture, sponsorship, and people-centric rhythmsConnect with the guestCarl Mosby III: https://www.linkedin.com/in/carl-mosby-iii/Listen & subscribeAcast: https://shows.acast.com/secured-with-dr-kjApple Podcasts / Spotify / YouTube: search “Secured with Dr. KJ”Support the showIf this episode resonated, share it with a teammate, leave a quick rating/review, and follow for new conversations on leadership, AI, and security.Securing tomorrow, one episode at a time. Hosted on Acast. See acast.com/privacy for more information.

  13. 18

    Proactive Defense

    Proactive Defense: Shaping the Future of CybersecurityEpisode Title: AI in Cybersecurity: A New EraHost & Guest:Host: Dr. Kenneth “KJ” JohnsonGuest: Joshua BoyceDuration: ~16 minutesKeywords:AI, cybersecurity, proactive defense, threat intelligence, data quality, incident response, human oversight, collaboration, security leaders, trustEpisode Summary:In this conversation, Joshua Boyce joins Dr. KJ to explore how AI is transforming cybersecurity from a reactive posture to a proactive defense model. They unpack the critical role of data quality in ensuring AI-driven systems are effective, the growing importance of cross-industry collaboration for threat intelligence sharing, and how organizations can balance AI automation with human oversight. The discussion underscores that AI should be viewed as a force multiplier, enhancing human capability rather than replacing it. The episode concludes with insights on building trust in AI systems and why security leaders must treat AI as an accelerant to human potential—one that reshapes both the attack surface and the way defenders respond.What You’ll Learn:Why AI is becoming a teammate in the SOC (Security Operations Center).How data quality determines the success of AI in cybersecurity.The value of cross-industry collaboration for proactive threat defense.Why human oversight remains essential in an AI-driven world.How organizations can shift from reactive to proactive cybersecurity strategies.Key Takeaways:AI is a force multiplier, not a replacement for human defenders.Data quality is foundational to effective AI implementation.Collaboration is essential for sharing threat intelligence across industries.Trust in AI systems is vital for long-term success.The future of cybersecurity is proactive, not reactive.Memorable Quotes:“AI is becoming a teammate in the SOC.”“AI is a force multiplier, not a replacement.”“Garbage in, garbage out.”Connect with the guestJoshua Boyce: https://www.linkedin.com/in/joshuaboyce/Listen & subscribeAcast: https://shows.acast.com/secured-with-dr-kjApple Podcasts / Spotify / YouTube: Search “Secured with Dr. KJ”Support the showIf this episode helped you, share it with your team, leave a quick rating/review, and follow the show for new episodes on cloud security, Zero Trust, AI-driven defense, and more.Securing tomorrow, one episode at a time. Hosted on Acast. See acast.com/privacy for more information.

  14. 17

    Securing Finance

    Season 2, Episode 5 – Secured with Dr. KJSecuring Finance: Protecting the Digital Backbone of BankingHost: Dr. KJGuest: Jerry Davis, Senior Cybersecurity Executive & Former CISO/CSO at multiple U.S. federal agencies and Fortune 500 companiesDuration: ~25 minutesKeywordsBanking Security, Cyber Resilience, Financial Services, Critical Infrastructure, AI in Security, National Security, Workforce Development, Public-Private Partnerships, Digital Backbone of FinanceEpisode SummaryKicking off Season 2 of Secured with Dr. KJ, we welcome Jerry Davis, a five-time CISO/CSO and one of the most experienced cybersecurity leaders in both government and private industry.Jerry’s career spans protecting some of the most mission-critical organizations on the planet—from NASA and the Department of Veterans Affairs to global financial institutions. He even served as a CIA Counterintelligence Officer, bringing a unique perspective on threat actors and national security.In this episode, Jerry shares how financial services organizations can protect the digital backbone of banking, where operational continuity, trust, and resilience are paramount. He dives into how innovation, compliance, and collaboration intersect, and why preparing the next generation of cyber talent is essential for resilience.What You’ll LearnHow to secure financial ecosystems while protecting trust at scaleWhy public-private collaboration is critical against evolving threatsHow to balance innovation, compliance, and operational continuityThe role of workforce development in building sustainable cyber resilienceKey TakeawaysBanking and finance are the digital backbone of global economiesResilience is about preparation—from identity and access management to vulnerability managementPartnerships and intelligence sharing amplify security capabilitiesFuture-proofing the workforce is as critical as adopting new technologiesMemorable Quotes“In banking, cybersecurity isn’t just about protection—it’s about preserving trust in the system.” – Jerry Davis“Resilience comes from preparation, collaboration, and never losing sight of the basics.” – Jerry DavisConnect with the Guest👉 Jerry Davis on LinkedInListen Now👉 Secured with Dr. KJ on Acast Hosted on Acast. See acast.com/privacy for more information.

  15. 16

    Higher Education Under Attack

    Episode 4 – Secured with Dr. KJCybersecurity in Education: Balancing Openness and ProtectionHost: Dr. KJGuest: Dan Menicucci, National Solution Engineering Manager, Microsoft Security in Financial ServicesDuration: ~20 minutesKeywordsCybersecurity in Education, Digital Transformation, Budget Constraints, Public-Private Collaboration, Microsoft Security, Identity, MFA, Risk ManagementEpisode SummaryIn this episode, Dr. KJ sits down with Dan Menicucci, a seasoned cybersecurity leader with decades of experience across education and financial services. Dan previously served as Microsoft’s Chief Security Advisor for Education and brings a unique perspective on how academic institutions can balance their open, collaborative nature with the need for strong cyber defenses.We unpack the real-world challenges education leaders face—tight budgets, aging infrastructure, and the rising tide of ransomware—and explore how focusing on fundamentals like identity, patch management, and MFA can make the biggest difference. Dan also highlights the critical role of public-private partnerships, and how collaboration is shaping the next chapter of education security.This episode offers both strategic insights for leaders and practical guidance for practitioners on the front lines.What You’ll LearnWhy education is a top target for cyberattacks—and how attackers are evolvingHow to balance openness vs. protection in academic environmentsThe importance of collaboration between public and private sectorsWhy focusing on the basics is more impactful than chasing every new threatDan’s perspective on the future of cybersecurity in educationKey TakeawaysThe basics still matter: identity, patching, MFACollaboration can be a force multiplier—no one can tackle these challenges aloneEducation leaders must align budget, strategy, and partnerships for long-term resilienceMemorable Quotes“The fundamentals—identity, vulnerability management, MFA—will protect you more than chasing the latest shiny tool.” – Dan Menicucci“In education, it’s about enabling learning while quietly building the guardrails to keep everyone safe.” – Dan MenicucciConnect with the Guest👉 Dan Menicucci on LinkedInListen Now👉 Secured with Dr. KJ on Acast Hosted on Acast. See acast.com/privacy for more information.

  16. 15

    Small Targets: Big Impact

    Episode 3: Small Targets, Big Impact: The Ransomware wake up call with Matthew WaddellHost: Kenneth JohnsonGuest: Matthew Waddell, Incident Response Expert & Author of Survive RansomwareDuration: ~19 minutesKeywords: Ransomware, Small Business Cybersecurity, Incident Response, Backups, Generative AI, Phishing, Tabletop Exercises, Managed Service Providers, AI in Cyber DefenseEpisode SummaryIn this episode of Secured with Dr. KJ, I sit down with Matthew Waddell—an incident response veteran with over 25 years of experience defending governments, military operations, and private sector organizations. We focus on the ransomware epidemic hitting small businesses and explore why they’re often seen as low-risk, high-reward targets for cybercriminals.Matthew shares practical, budget-friendly strategies small businesses can implement today—from running internal tabletop exercises and building relationships with law enforcement to creating effective playbooks and developing a culture of vigilance. We also dive into the critical role of offline, tested backups and how poor backup practices can turn an incident into a full-scale disaster.The conversation takes a forward-looking turn as we discuss generative AI—how it’s making ransomware attacks more convincing and sophisticated, and how defenders can leverage AI-driven tools, such as virtual SOCs, to match the attackers’ speed and precision. Matthew closes by previewing his upcoming book, Survive Ransomware, designed to give non-technical leaders the tools and knowledge to respond effectively to an attack.What You’ll LearnWhy ransomware gangs target small businesses as “practice grounds” for larger attacksThe importance of employee awareness as the first line of defenseHow tabletop exercises can uncover gaps before an incident strikesWhy backups must be offline, air-gapped, and regularly testedHow generative AI is being weaponized by attackers—and how defenders can fight backHow to build strong relationships with law enforcement and managed service providers before you need themKey TakeawaysSmall businesses aren’t immune—they’re often easier and more appealing targets for attackers.Incident response planning doesn’t require a huge budget, but it does require time, communication, and documentation.Backups are only as good as your last test—and ransomware actors actively seek to destroy them.Generative AI is reshaping the threat landscape, producing more believable phishing campaigns and faster attacks.Proactive relationships with service providers and law enforcement can be invaluable during an incident.Memorable Quotes“It doesn’t take a large budget to be secure—just a team willing to think through ‘what if?’ scenarios.” – Matthew Waddell“If your backups aren’t offline and tested, they might as well not exist when ransomware hits.” – Matthew Waddell“Attackers are using AI to get faster and smarter—so defenders must do the same.” – Matthew WaddellConnect with the Guest🔗 Connect with Matthew Waddell on LinkedInSecured with Dr. KJ – Securing tomorrow, one episode at a time.

  17. 14

    Smart Cities & Secure Cities

    Episode 2: Smart Cities, Secure Cities: Urban Infrastructure Protection – A Conversation with Bryce CarterHost: Kenneth JohnsonGuest: Bryce Carter, Chief Information Security Officer, City of ArlingtonDuration: ~22 minutesKeywords: Smart Cities, Critical Infrastructure, Generative AI, Deepfakes, Operational Technology, Security by Design, Third-Party Risk, Quantum Encryption, AI EthicsEpisode SummaryIn this insightful episode of Secured with Dr. KJ, I sit down with Bryce Carter, CISO for the City of Arlington, to explore the evolving challenges of securing modern urban environments. Bryce takes us behind the scenes of city operations—where critical infrastructure like utilities, public safety, and transportation systems converge with rapidly advancing technologies.We discuss the rising threats posed by generative AI, deepfakes, and nation-state actors, as well as the complexities of protecting operational technology (OT) and Internet of Things (IoT) systems. Bryce shares his perspective on embedding security by design, managing third-party risk, and fostering a culture of resilience through executive and technical tabletop exercises.Our conversation also ventures into the future—examining AI bias, data governance, explainability, and the encryption challenges that quantum computing may soon bring. Bryce’s community-first approach to security ensures that technology not only protects citizens but also enhances quality of life, trust, and economic vitality.What You’ll LearnWhy cities face unique cybersecurity challenges across multiple sectors simultaneouslyHow generative AI and deepfakes are reshaping the threat landscapeThe importance of “security by design” and a proactive risk management cultureStrategies for building resilience in interconnected urban ecosystemsThe role of AI ethics, governance, and bias testing in public sector adoptionWhy quantum encryption readiness is a growing priority for governmentsKey TakeawaysCities operate like many industries in one—making cybersecurity vastly more complex.Generative AI and deepfakes will require both technical and societal responses to maintain trust.Security by design must be woven into culture, funding, processes, and development cycles.Third-party risk management is essential, but there is no silver bullet—collaboration and intelligence sharing are critical.Quantum computing may upend current encryption standards, requiring governments to prepare now.Memorable Quotes“When you think about a city… it’s really like a bunch of different subsidiaries, and protecting that is very complex.” – Bryce Carter“Deepfakes could push us back to face-to-face interactions just for trust alone.” – Bryce Carter“Security done right doesn’t impair—it enables better quality of life and economic value.” – Bryce CarterConnect with the Guest🔗 Connect with Bryce Carter on LinkedInSecured with Dr. KJ – Securing tomorrow, one episode at a time.Hosted on Acast. See acast.com/privacy for more information.

  18. 13

    Fueling Security: Cyber Resilience in Oil & Gas

    🎙️ Episode 1: Fueling Security – Cyber Resilience in Oil & GasHost: Dr. Kenneth JohnsonGuest: Connie Devine, Deputy CISO, Phillips 66 - https://www.linkedin.com/in/connie-devine-duncan/Duration: ~18.7 minutesKeywords:critical infrastructure, oil and gas, cybersecurity, OT security, IT-OT convergence, threat intelligence, generative AI, zero trust, third-party risk, cyber resilienceEpisode Summary:In the premiere of Season 2, Secured with Dr. KJ shifts focus to the voice of the customer, starting with a deep dive into the oil and gas sector. Connie Devine, Deputy CISO at Phillips 66, discusses the evolving cybersecurity landscape across IT and operational technology (OT) environments. From geopolitical threats to AI-infused vendor solutions, Connie shares how her team stays ahead of nation-state actors, secures critical supply chains, and balances innovation with regulation.What You’ll Learn:The importance of converged governance in IT and OT networksHow geopolitical events directly impact energy securityStrategies for integrating zero trust into OT environmentsThe promise and caution around AI implementation in energyHow to vet and manage cybersecurity risk in third-party relationshipsWhy cyber awareness and culture are as vital as the tools deployedKey Takeaways:The attack surface in energy has expanded with IT-OT convergenceCybersecurity in oil and gas is about protecting both people and productAI brings opportunities and risks—understanding use cases is essentialSupply chain security is a critical, ongoing processRegulatory frameworks like NIST and TSA are foundationalBuilding a cyber-aware culture strengthens every layer of defenseMemorable Quotes:“Zero trust in OT requires a very different mindset.”“We’re always looking for better, safer ways to do what we do.”“Cybersecurity is no longer optional—it’s a strategic imperative.”“The OT network will become a bigger target in the future.”🎧 Listen on Your Favorite Platform:🎙️ Acast: https://shows.acast.com/secured-with-dr-kj🍎 Apple Podcasts: https://podcasts.apple.com/us/podcast/secured-with-dr-kj/id1719440170🎧 Spotify: https://open.spotify.com/show/7uZYymUPp7PBiKqgYrbv2YConnect with Connie on LinkedIn: https://www.linkedin.com/in/connie-devine-duncan/Secured with Dr. KJ – Securing tomorrow, one episode at a time. Hosted on Acast. See acast.com/privacy for more information.

  19. 12

    Privacy and Our Kids

    🎙️  Bonus Episode: Privacy and Our Kids – The Hidden Cost of Growing Up in a Digital WorldHost: Kenneth JohnsonGuest: Richard KaufmannDuration: 21m 28sLocation: United StatesPodcast Link: Secured with Dr. KJ on AcastKeywordsPrivacy, Children, Cybersecurity, Surveillance, Digital Footprint, Parenting, AI, Data Protection, Cyber Awareness, Online SafetyEpisode SummaryIn this bonus episode, Dr. KJ sits down with cybersecurity and AI expert Richard Kaufmann to explore one of the most critical and emotionally charged issues in today’s digital era: privacy and our children. With kids being exposed to technology from infancy and data trails forming before they can even talk, Richard walks us through the unseen costs of growing up in a world that never forgets.They explore how everything from smart devices to educational apps can silently collect data and what that means for a child’s future. Richard blends real-world experience, strategic insight, and parental empathy to highlight what leaders, parents, and policymakers need to understand—and act on.What You’ll LearnHow digital exposure starts before birth and why that’s a problem.The long-term consequences of early data collection and surveillance.Why privacy must be treated as a child safety issue.How AI complicates the protection of minors.Practical tips for parents, educators, and security professionals. Key TakeawaysDigital Childhood is Permanent: Children’s data footprints are not erasable and can shape their opportunities later in life.Security Isn’t Optional: Protecting kids in the digital age means rethinking both parenting and policy through a cybersecurity lens.AI is a Double-Edged Sword: While powerful for personalization and protection, it can also enable surveillance and data misuse.We Need Guardrails: The time to act is now—before children’s futures are compromised by today’s tech conveniences.Memorable Quotes“We put more protection on a credit card than we do on a child’s data.” – Richard Kaufmann“The most vulnerable population in the digital age is the one without a voice yet.” – Richard KaufmannConnect with the GuestWant to learn more from Richard Kaufmann or continue the conversation?🔹 Connect with Richard on LinkedIn Hosted on Acast. See acast.com/privacy for more information.

  20. 11

    The Future of Cybersecurity

    Episode 10: The Future of Cybersecurity with Michael Billy Host: Dr. Kenneth JohnsonGuest: Michael BillyDuration: ~20 minutes Keywords:cybersecurity, generative AI, security trends, tool sprawl, AI security, automation, human oversight, future-proofing, security technologies, Microsoft Episode Summary:In this episode of Secured with Dr. KJ, Michael Billy joins the show to explore the future of cybersecurity and how organizations can evolve with confidence in the face of rapid technological change. From the impact of generative AI to the risks of tool sprawl, Michael outlines why fundamentals like security hygiene and human oversight are more critical than ever. He also discusses how organizations can build trust in AI-powered tools, prepare their teams for the unknown, and create a sustainable plan to stay ahead of threats while embracing innovation. What You’ll Learn:Why hygiene is still the #1 threat in securityHow generative AI is reshaping security tools and tacticsThe importance of vetting AI suppliers and securing AI agentsWhy tool sprawl can lead to visibility gaps and operational fatigueHow to balance automation with human judgmentWhy Zero Trust and assume breach remain foundational principlesStrategies for future-proofing security teams and tech stacks Key Takeaways:Hygiene remains the top threat in cybersecurityGenerative AI will significantly impact security practicesOrganizations must secure their AI agents effectivelyTool sprawl is a growing concern in cybersecurityVetting generative AI suppliers is crucial for securityEmbracing technology helps teams understand its implicationsAssuming breach is essential for a Zero Trust environmentSetting a clear plan is vital for security leadersBalancing automation with human oversight is necessaryContinuous learning and adaptation are key in cybersecurity Memorable Quotes:“Hygiene is still the number one threat.”“There is no silver bullet in security.”“Empower everyone to achieve more.” Hosted on Acast. See acast.com/privacy for more information.

  21. 10

    AI and Security: Friend or Foe?

    Episode 9: AI and Security: Friend or Foe? with Terence JacksonHost: Dr. Kenneth JohnsonGuest: Terence JacksonDuration: ~23 minutesKeywords:AI, cybersecurity, threat detection, security posture, upskilling, cross-training, digital security, threat actors, zero trust, automationEpisode Summary:In this episode of Secured with Dr. KJ, Terence Jackson, Chief Security Advisor at Microsoft, explores how artificial intelligence is revolutionizing both sides of the cybersecurity battlefield.Terence explains how AI is redefining traditional defenses, making threat detection faster and smarter—but also more accessible to adversaries. He walks through the advantages of agentic AI, the evolving threat landscape, and the urgent need for organizations to strengthen posture management and automate security operations. The conversation highlights the importance of upskilling, cross-training, and revisiting foundational security practices like zero trust to stay ahead in the AI arms race.Listeners will gain insight into the balance between automation and human oversight, and the very real pressures defenders face in a world where attackers have no red tape.What You’ll Learn:How AI empowers defenders to reason over large datasetsWhy threat actors are gaining speed with natural language-driven exploitsWhat agentic AI means for posture management and responseHow cross-training existing personnel accelerates readinessWhy the basics (patching, RBAC, MFA) still matter mostHow to prepare your SOC for AI-assisted defenseKey Takeaways:AI has obliterated traditional defenses—speed is the new battlegroundThreat actors are better resourced and less restricted than defendersNatural language is the new attack surfaceAgentic AI brings autonomous detection and remediation capabilitiesTime to compromise is now measured in minutes, not monthsCross-training network and IT engineers reduces staffing gapsAI can democratize learning and accelerate workforce developmentOrganizations must focus on zero trust and foundational hygieneAutomation must be balanced with human oversightAI is both a friend and a foe—how we use it determines the outcomeMemorable Quotes:“AI is obliterating traditional defenses.”“The hottest programming language right now is natural language.”“We’re defending at the pace and speed of AI.”“The attackers have jobs—just like we do.”“We need to do the basics better.” Hosted on Acast. See acast.com/privacy for more information.

  22. 9

    Securing the Internet of Things (IoT)

    Episode 10: Securing the Internet of Things with Maurice HamptonHost: Dr. Kenneth JohnsonGuest: Maurice HamptonDuration: ~23 minutesKeywords:IoT security, connected devices, cybersecurity, risk management, best practices, visibility, control, AI, machine learning, organizational strategyEpisode Summary:In this episode of Secured with Dr. KJ, Maurice Hampton, Director of Cybersecurity Solution Sales (East) at Microsoft, unpacks the security challenges posed by the exponential growth of connected devices.Maurice walks through the evolution of the IoT attack surface, explaining how formerly isolated systems are now interconnected and exposed to new threats. He outlines a practical, phased approach—acknowledge, assess, implement controls—for tackling IoT security at scale. The discussion underscores the need for visibility, collaboration, and AI-driven insights to manage risk across environments like manufacturing, transportation, and smart cities.Listeners will gain actionable strategies and real-world examples of how organizations can secure their IoT footprint from the edge to the cloud.What You’ll Learn:Why IoT security is more complex today than ever beforeThe risks associated with interconnectivity and outdated systemsHow to launch an IoT security strategy using a crawl-walk-run approachWhy visibility and inventory are foundational to defenseThe critical role of cross-functional collaboration in securing IoTHow AI and machine learning enhance detection and responseReal-world examples of IoT security transformationKey Takeaways:The IoT attack surface has expanded due to rapid connectivitySecurity must be built into innovation—not added laterAcknowledging risks is step one in any IoT security journeyComprehensive assessments are essential to understand current stateControls must follow knowledge—not precede itCross-team collaboration is vital—security is a team sportVisibility into devices and their behavior drives stronger defenseAI can uncover anomalies that humans may missStart small and build repeatable processesTaking action is the key to reducing long-term riskMemorable Quotes:“The attack surface has grown exponentially.”“Acknowledge, understand, and then controls.”“Get other people in the boat with you.”“Security isn’t a solo act—it’s a team sport.”“AI lets us see what we couldn’t before.” Hosted on Acast. See acast.com/privacy for more information.

  23. 8

    Identity and Access Management

    Episode Title:Identity and Access ManagementHost: Dr. Kenneth JohnsonGuest: Corey Lee, Security CTO, Microsoft EducationDuration: ~20 minutesKeywords:identity, security, breaches, governance, authentication, authorization, MFA, passwordless, AI, zero trustEpisode Summary:In this episode of Secured with Dr. KJ, Corey Lee, Security CTO for Microsoft Education, unpacks the foundational role of identity in today’s security landscape. With over 15 years of experience in risk analysis, identity, and AI-enabled security, Corey shares how identity acts as the glue connecting people, devices, and data—and as the edge organizations must protect.The conversation covers the rise of identity-driven breaches, the growing importance of governance, and innovations like passkeys and verified ID. Corey also provides insights into strengthening MFA strategies, enabling passwordless adoption, and preparing for a future where AI and zero trust shape every layer of defense.What You’ll Learn:Why identity is now the core security perimeterHow identity connects and protects in a hybrid, AI-driven worldThe role of governance in managing evolving permissionsWhy MFA remains critical—and how to improve its adoptionWhat a successful passwordless journey looks likeHow identity threat detection is becoming more automated and intelligentThe importance of strategic planning in identity managementWhy identity is key to unlocking secure innovation at scaleKey Takeaways:Identity is the core of modern security architectureBreaches often stem from compromised or mismanaged identitiesIdentity governance helps manage scope creep and permissions sprawlMFA should be enforced adaptively based on riskPasswordless strategies reduce known attack surfacesOrganizations must report on and monitor identity security gapsIdentity is now central to AI and agent-based security scenariosStrategic identity planning unlocks innovation and improves protectionContinuous tracking and governance support transformationIdentity is here to stay and growing more critical each dayMemorable Quotes:“Identity is the new security perimeter.”“Passwords create very bad behavior.”“Identity has never been easy.”“Identity is here to stay.”Listen now on your favorite platform:Apple Podcasts: https://podcasts.apple.com/us/podcast/secured-with-dr-kj/id1730562581Spotify: https://open.spotify.com/show/5ZHg5qHXGP6MSf2QnK6LDoAcast: https://shows.acast.com/secured-with-dr-kjAmazon Music: https://music.amazon.com/podcasts/4ff12a6c-f35f-4f8d-a5d4-9170c601ea3fSecured with Dr. KJ – Securing tomorrow, one episode at a time. Hosted on Acast. See acast.com/privacy for more information.

  24. 7

    Regulatory Compliance in the Cloud

    Episode 7: Regulatory Compliance in the Cloud with Awnya CrequeHost: Dr. Kenneth JohnsonGuest: Awnya CrequeDuration: ~20 minutesKeywords:cloud compliance, data security, regulatory challenges, Microsoft Purview, risk assessment, industry regulations, cloud migration, access control, data privacy, compliance automationEpisode Summary:In this episode of Secured with Dr. KJ, Awnya Creque, Principal Technical Specialist at Microsoft, breaks down the complex world of regulatory compliance in the cloud.Awnya outlines five critical focus areas—data residency, access control, data privacy, regulatory compliance, and auditing/reporting—that organizations must address when migrating to or operating in cloud environments. She explains how compliance challenges vary across sectors like government, healthcare, and financial services, and how tools like Microsoft Purview can support proactive compliance strategies.The conversation also explores the importance of fostering a culture of compliance, leveraging automation, and integrating regulatory checks into day-to-day workflows.What You’ll Learn:The top compliance challenges when moving to the cloudWhy data sovereignty and residency matter more than everHow identity and access control play a central role in securing sensitive dataWhy compliance isn’t a one-time task—it’s a continuous processHow industry-specific requirements shape cloud security strategiesThe role of cloud providers and automation in easing the compliance burdenKey Takeaways:Organizations face multiple compliance challenges in the cloudData residency and sovereignty are essential to meet global regulationsStrong access control and identity management are non-negotiableSecurity programs must adhere to evolving frameworks like GDPR and HIPAACompliance demands constant attention and adaptationEffective auditing and reporting help demonstrate accountabilityIndustry-specific regulations drive unique security needsCloud platforms like Microsoft Purview offer valuable supportProactive strategies and automation reduce riskEmbedding compliance into daily workflows drives long-term successMemorable Quotes:“Data stays where it needs to be.”“Stay informed about regulatory updates.”“Conducting a risk assessment is crucial.”“Integrate compliance into your workflows.” Hosted on Acast. See acast.com/privacy for more information.

  25. 6

    Ransomware and Threat Protection

    Episode 6: Ransomware and Threat Protection with James RingoldHost: Dr. Kenneth JohnsonGuest: James RingoldDuration: ~20 minutesKeywords:ransomware, cybersecurity, threat landscape, AI in security, recovery strategies, ransomware as a service, security education, enterprise security, ransomware attacks, modern security platformsEpisode Summary:In this episode of Secured with Dr. KJ, James Ringold breaks down the constantly evolving ransomware threat landscape and its implications for enterprise security. From the rise of AI-powered attacks to the growth of ransomware as a service, James explains why these threats demand more than just technical fixes—they require a strategic, cross-functional approach.We also explore the growing importance of security education, the burden of legacy systems, and how organizations can better balance proactive prevention with rapid recovery strategies.What You’ll Learn:How ransomware tactics have evolved, including triple extortionWhy legacy systems are still a major weak spotHow AI is both a threat and a tool in cybersecurityThe role of cloud storage and file versioning in recoveryWhy education and awareness are just as critical as toolingHow to think about ransomware as a business risk, not just a tech problemKey Takeaways:Ransomware damages are projected to hit $57 billion by 2025Triple extortion and human-operated attacks are on the riseAI is enabling faster, stealthier attacksRansomware as a service creates a supply chain of cybercrimeLegacy infrastructure remains a major vulnerabilityCloud-based recovery tools like versioning can expedite restorationEmployee education and SOC readiness are vital to responseEffective defense requires cross-team collaborationPrevention and recovery must go hand-in-handRansomware is a business-level risk, not just an IT concernMemorable Quotes:“AI is used to automate phishing and evade detection.”“Ransomware as a service is a growing concern.”“Attackers don’t hack anymore—they log in.”“Balancing prevention with rapid recovery is crucial.” Hosted on Acast. See acast.com/privacy for more information.

  26. 5

    Zero Trust in Practice

    Episode 4: Zero Trust – Zero Trust in Practice with Mark SimosHost: Dr. Kenneth JohnsonGuest: Mark Simos, Lead Cybersecurity Architect, MicrosoftDuration: ~20 minutesKeywords:Zero Trust, Cybersecurity, Identity Management, AI, Security Architecture, Collaboration, Trust Verification, Modern Security StrategiesEpisode Summary:In this episode of Secured with Dr. KJ, Kenneth Johnson and Mark Simos break down the reality of Zero Trust—moving beyond buzzwords into actionable strategies. They explore why traditional perimeter-based security no longer works, and how identity, verification, and AI are reshaping the way we think about trust in cybersecurity.Mark shares insights on how organizations can align their teams, embrace a culture of shared responsibility, and make security a business enabler—not a blocker. The conversation also touches on how AI is accelerating complex security tasks, helping teams stay ahead of evolving threats.What You’ll Learn:Why Zero Trust is more than a framework—it’s a mindset shiftThe critical role identity plays in modern securityHow AI supports and strengthens Zero Trust strategiesThe cost of implicit trust and the value of explicit verificationWhy collaboration and communication are essential to successKey Takeaways:Zero Trust removes the false assumption of a secure perimeter.Verification of identity is essential in modern security.Trust is costly; explicit verification is necessary.Identity management is crucial for Zero Trust success.AI plays a symbiotic role in enhancing security.Security must be integrated into business processes.Every asset and user must have a defined identity.Collaboration across teams is vital for security effectiveness.Security professionals should act as enablers for other teams.Open communication fosters a successful Zero Trust implementation.Memorable Quotes:“AI accelerates complex security tasks.”“Identity is the new security perimeter.”“Security is part of everyone’s job.” Hosted on Acast. See acast.com/privacy for more information.

  27. 4

    Securing the Hybrid Workforce

    🎙️ Episode 3: Securing the Hybrid Workforce with Rico MarianiHost: Dr. Kenneth JohnsonGuest: Rico Mariani, Veteran Software Performance Engineer & Longtime Microsoft LeaderDuration: ~20 minutesEpisode Overview:In this episode of Secured with Dr. KJ, Dr. Kenneth Johnson sits down with Rico Mariani, a veteran technologist with decades of experience at Microsoft and a deep background in software performance engineering. Known for his strategic thinking and advocacy for diversity in tech, Rico shares valuable insights on how organizations can better approach security in a hybrid workforce era.They explore key challenges with BYOD, transitioning to cloud environments, and the critical need to understand your internal inventory before building outward. Rico also dives into why tailored security matters, how to assume compromise as a defense model, and the human side of securing flexible work.What You’ll Learn:The security risks introduced by hybrid and remote workWhy visibility and inventory are the foundation of modern securityStrategies for managing BYOD in enterprise environmentsHow to align infrastructure with user needs and riskWhy tailored access and device assumptions matterThe connection between good security and organizational readinessKey Takeaways:Understand your inventory before building your security stack.Get your internal systems in order before expanding into hybrid/cloud.Assume devices are compromised to strengthen overall defense.Tailor security to roles and business needs for smarter access control.BYOD success requires flexibility, awareness, and clear boundaries.Memorable Quote:“Assume they’re connecting with a compromised device. That mindset changes how you design your defenses.” – Rico Mariani Hosted on Acast. See acast.com/privacy for more information.

  28. 3

    Cloud Security: The Microsoft Advantage

    🎙️ Episode 2: Cloud Security: The Microsoft AdvantageHost: Dr. Kenneth JohnsonGuest: Unique Glover, Technical Sales Director, MicrosoftDuration: ~19 minutesEpisode OverviewIn this episode of Secured with Dr. KJ, we sit down with Unique Glover, a veteran cybersecurity leader and cloud expert with over 20 years in the industry. Unique currently serves as Technical Sales Director at Microsoft and holds advanced credentials like CISSP and CCSP. His passion for security, innovation, and community shines as we explore how Microsoft is shaping the future of cloud security.What You’ll Learn:•How Microsoft Azure security compares to AWS and GCP•Why Defender for Cloud is a game-changing tool for enterprise security•The evolution of data security and the importance of unified security platforms•How Microsoft balances innovation with openness and integration•Why collaboration across the security industry is critical to staying ahead of threatsKey Takeaways:•Microsoft’s native tooling, threat intelligence, and end-to-end integration create a uniquely powerful security platform.•Defender for Cloud offers visibility, compliance frameworks, automation, and consistent posture management.•Flexibility and interoperability are must-haves for modern security architecture.•Collaboration across vendors, partners, and the community is essential to protect customers and stop adversaries.Memorable Quote:“If our customers and communities don’t get the protection they need, the only ones who win are the attackers. That’s why integration, collaboration, and transparency matter more than ever.” — Unique GloverIf you enjoyed this episode, be sure to like, subscribe, and share the podcast with your network.Join us next time as we continue securing tomorrow, one episode at a time. Hosted on Acast. See acast.com/privacy for more information.

  29. 2

    The State of Cybersecurity

    🎙️ Episode 1: The State of Cybersecurity – Jim EckartHost: Dr. Kenneth JohnsonGuest: Jim Eckart, General Manager of Security Solution Sales at Microsoft, Former CISODuration: 18:50Episode Overview:In this premiere episode of Secured with Dr. KJ, we sit down with Jim Eckart—a seasoned security leader with over 25 years in IT and cybersecurity. As a former CISO and current General Manager of Security Solution Sales at Microsoft, Jim shares insights on what it takes to secure organizations at scale in today’s evolving digital landscape.What We Discuss:•The biggest shifts in the cybersecurity landscape over the last decade•Lessons learned from Jim’s time as a CISO•How Microsoft approaches enterprise security and what makes it stand out•The role of Zero Trust, identity, and AI in modern security strategies•Where organizations still fall short—and how they can catch upWhy You Should Listen:Whether you’re a business leader, security professional, or curious about the future of cybersecurity, this episode offers a front-row seat to how one of the world’s biggest tech companies tackles security challenges from the inside out.Key Quote:“Good security is about anticipating problems before they become breaches—and that takes a culture, not just a toolset.” — Jim Eckart Hosted on Acast. See acast.com/privacy for more information.

Type above to search every episode's transcript for a word or phrase. Matches are scoped to this podcast.

Searching…

We're indexing this podcast's transcripts for the first time — this can take a minute or two. We'll show results as soon as they're ready.

No matches for "" in this podcast's transcripts.

Showing of matches

No topics indexed yet for this podcast.

Loading reviews...

ABOUT THIS SHOW

Welcome to Secured with Dr. KJ—the podcast that explores the evolving world of cybersecurity, the technologies driving it, and the companies shaping our digital future.Hosted by Dr. Kenneth Johnson, cybersecurity leader and strategist, this podcast simplifies complex security topics into actionable insights. In today’s digital world, cybersecurity is a business imperative. Each episode dives into cloud security, Zero Trust, identity management, AI-driven security, and more.We’ll assess how industry leaders, including Microsoft, are tackling security challenges—and where there’s room for improvement. Featuring expert insights from security professionals, industry leaders, and technologists, Secured with Dr. KJ delivers real-world strategies to protect businesses and individuals.Join the conversation! Subscribe today to explore what it takes to stay secure in a rapidly changing digital world—securing tomorrow, one episode at a

HOSTED BY

Kenneth Johnson

CATEGORIES

Frequently Asked Questions

How many episodes does Secured with Dr. KJ have?

Secured with Dr. KJ currently has 29 episodes available on PodParley. New episodes are automatically indexed when they're published to the podcast feed.

What is Secured with Dr. KJ about?

Welcome to Secured with Dr. KJ—the podcast that explores the evolving world of cybersecurity, the technologies driving it, and the companies shaping our digital future.Hosted by Dr. Kenneth Johnson, cybersecurity leader and strategist, this podcast simplifies complex security topics into actionable...

How often does Secured with Dr. KJ release new episodes?

Secured with Dr. KJ has 29 episodes. Check the episode list to see recent publication dates and frequency.

Where can I listen to Secured with Dr. KJ?

You can listen to Secured with Dr. KJ on PodParley by clicking any episode. We provide an embedded audio player for direct listening, and you can also subscribe via your preferred podcast app using the RSS feed.

Who hosts Secured with Dr. KJ?

Secured with Dr. KJ is created and hosted by Kenneth Johnson.
URL copied to clipboard!