SEI Webcasts
SEI experts offer a scheduled presentation and Q&A as a webinar that is recorded live and later offered as a webcast.
info_outline
Rethinking and Maturing AI Adoption
06/10/2026
Rethinking and Maturing AI Adoption
Many organizations are discovering, as they accelerate adoption of artificial intelligence (AI), that business and operational success with AI depends on far more than deploying AI models or experimenting with generative AI tools. Successful AI adoption occurs at the intersection of software engineering practices, the realities of system and enterprise architecture modernization, governance, cybersecurity, workforce readiness, workflow reengineering, operational integration, and enterprise strategy. Organizations must manage technological challenges that have intensified with AI adoption, including growing dependencies, vendor lock-in, and the imperative to innovate and scale quickly. Leaders must also adapt to new emerging realities, from the operational and financial demands of supporting multiple frontier models to the novel security and governance risks introduced by agentic AI approaches. Traditional approaches to technology transformation are no longer sufficient to thrive in this environment. To address these emerging complexities and drive success, Carnegie Mellon University’s Software Engineering Institute (SEI) collaborated with Accenture to develop the AI Adoption Maturity Model—an evidence-backed, field-tested instrument that provides a structured, yet agile, pathway for scaling AI capabilities across enterprises to ensure value and return on investment (ROI). This approach is designed for today’s realities, including fast-paced technological change, limited time and resources, and the need for lightweight, actionable methods rather than burdensome documentation. In this webcast, experts from the SEI and Accenture share technical insights and lessons learned from maturing AI adoption in complex environments. They will demonstrate how a nimble assessment instrument such as the road-tested AI Adoption Maturity Model fills critical gaps faced by organizations adopting AI. What Will Attendees Learn? • How AI maturity extends beyond isolated experimentation to encompass scalable, repeatable, measurable, and governed organizational capabilities. • How common pitfalls and strengths that we observed in early adopter organizations during AI Adoption Maturity Assessments can influence AI adoption. • How certain approaches to integrating existing risk management routines and security processes can support AI adoption. • How an agile, lightweight maturity assessment approach can enable organizations to rapidly prioritize activities, align efforts, and make targeted progress.
/episode/index/show/cmu-sei-webcasts/id/41596790
info_outline
AI-Native Software Engineering: Enduring Principles, New Pace
05/22/2026
AI-Native Software Engineering: Enduring Principles, New Pace
AI is rapidly changing how software is produced but not the need to engineer software to meet business and mission goals. AI is enabling developers to move from idea to implementation at incredible speeds. However, this fast pace has implications that teams must manage. Product quality does not come for free, and there is some tendency for AI to accelerate the accumulation of technical debt. In addition, what works well on small code bases doesn't always work as well on large code bases. So, what's a good software engineer to do? Software engineering principles and practices are essential in guiding software engineers to use AI to achieve production-ready outcomes. In this webcast, experienced software engineers discuss their observations and lessons from applying AI-native software engineering and studying its use across multiple projects. What Will Attendees Learn? • Distinguish between “vibe coding” and software engineering • Understand how software engineering principles improve the use of AI and where these principles need to be adapted to be used with AI • Recognize the different criteria that can be used to assess the benefits of AI-native software engineering (e.g., productivity and software quality) and their potential tradeoffs
/episode/index/show/cmu-sei-webcasts/id/41386990
info_outline
Software Acquisition Go Bag: Pack Light, Measure Right
05/19/2026
Software Acquisition Go Bag: Pack Light, Measure Right
Metrics are about more than just compliance. They ground you in fact, enable informed decision making, and help your team understand performance while providing insight into program health. By understanding the why, what, and how behind metrics, your team can move from “just collecting data” to using metrics that enable better decision making, improve program outcomes, and deliver mission value. Get ready to hear all about our new Tactical Guide called Pack Light, Measure Right and Supplement called Decoding SWP Metrics. What Will Attendees Learn? • How to select a minimal but sufficient set of measures to get the insight you need • How to implement measurement approaches that are compatible with iterative delivery • The hidden value in the metrics that you’re already collecting if you are on the Software Acquisition Pathway
/episode/index/show/cmu-sei-webcasts/id/41347605
info_outline
When Performance Isn’t Enough: Ensuring the Safety and Security of AI Systems
04/29/2026
When Performance Isn’t Enough: Ensuring the Safety and Security of AI Systems
Artificial intelligence (AI) systems offer tremendous potential, but compared to traditional software, they introduce novel safety and security risks. System theory provides a powerful lens for understanding these risks and developing effective mitigations. In this webcast, we’ll introduce System Theoretic Process Analysis (STPA), a system-theory-based approach to safety analysis. We’ll explain how STPA helps organizations build stronger assurances about the safety and security of complex systems, including those that incorporate AI. What Will Attendees Learn? • How complex systems fail due to design flaws and unsafe interactions—not just component failures • How these types of accidents can occur in AI-enabled systems • How to apply a system-theoretic perspective, including System Theoretic Process Analysis (STPA), to analyzing AI systems • Practical insights into improving the design, testing, and operational use of AI systems to strengthen safety and security
/episode/index/show/cmu-sei-webcasts/id/41059905
info_outline
Tools for Building an AI-Enabled Security Operations Center (SOC)
04/09/2026
Tools for Building an AI-Enabled Security Operations Center (SOC)
Building an effective security operations capability such as a security operations center (SOC) has always been a challenging endeavor. Balancing the need to successfully integrate the people, processes, and technologies required to support your mission requires a deep understanding of your network and your threat landscape. New AI tools and technologies present both challenges and opportunities. These tools can complicate your operational environment but might be used by malicious actors to enhance their attacks. But AI can also be leveraged to build out and enable your SOC by covering gaps in tools, your workforce, and automation. What Will Attendees Learn? • How AI has changed the way SOC teams operate • Ways to deploy AI tools in security operations settings • How the SEI is using structured knowledge to build more effective SOCs
/episode/index/show/cmu-sei-webcasts/id/40790580
info_outline
Software Acquisition Go Bag: Cracking the CNS Code
03/19/2026
Software Acquisition Go Bag: Cracking the CNS Code
Are you confused about what should be in your Software Acquisition Pathway program’s Capability Needs Statement (CNS)? You are not alone! One of the most frequent requests we receive is for a sample CNS. If only it was that easy! Never fear; our recently released Tactical Guide called will provide you with the practical insight you need to develop a CNS that will be effective for your program. We’ll also talk about the Cracking the CNS Code’s complementary supplement called What Will Attendees Learn? • What a CNS is • Strategies for and approaches to creating a CNS • How to break down your approved CNS into backlog items
/episode/index/show/cmu-sei-webcasts/id/40541930
info_outline
Acquisition Oversight for Software Assurance
03/12/2026
Acquisition Oversight for Software Assurance
Software management is too frequently ignored or addressed piecemeal in systems. Cyber threat actors take advantage of gaps and errors in their attacks, which they can accomplish throughout the lifecycle. Exploiting these gaps and errors allows them to compromise processes, practices, and procedures that touch a system’s design, component development, and supply chain to bypass controls and leverage available vulnerabilities. Key software assurance activities must be embedded within the acquisition lifecycle to effectively combat these threat actors. What Will Attendees Learn? How software assurance can be addressed with limited cost and schedule impact if it is effectively integrated into the acquisition lifecycle Which knowledge and resources are critical to software assurance and the risks that can be missed if they are underrepresented Key aspects of managing acquisition and development that are critical to software assurance and why they are important
/episode/index/show/cmu-sei-webcasts/id/40411150
info_outline
Leveraging AI to Build Cyber Capacity
03/05/2026
Leveraging AI to Build Cyber Capacity
AI is transforming both the threat landscape and our defensive capabilities. What does cyber mission readiness mean in this new environment? A researcher from the CERT Division of Carnegie Mellon University's (CMU’s) Software Engineering Institute (SEI) describes the current challenges and emerging solutions that individuals and teams can use to build and sustain their cyber and AI-readiness. The webcast showcases Crucible, an open source framework that integrates learning management, hands-on labs, team exercises, competitions, threat sharing, and AI models into a unified cyber readiness platform. What Will Attendees Learn? How to leverage AI to build cyber capacity and effectively share threat information across organizations Techniques for motivating performance through cyber challenge competitions Methods for using AI to assist in developing cyber-skills mastery via guided self-assessment AI-driven strategies for forging elite teams that are prepared for cyber and cognitive operations amid nation-state competitions
/episode/index/show/cmu-sei-webcasts/id/40327120
info_outline
Software Acquisition Pathway: Ready, Set, Go!
01/13/2026
Software Acquisition Pathway: Ready, Set, Go!
Is your program really ready to adopt the SWP? Next in the Software Acquisition Go Bag series, we’ll walk you through our new Tactical Guide called SWP: Ready, Set, Go! This guide provides proven techniques to assess the project’s readiness to adopt the SWP; identify any shortfalls; and obtain the resources, information, and support needed for success. What Will Attendees Learn? • How to know if your acquisition program is really ready to adopt the SWP • What “Instill an Agile Culture” actually means for your program • How programs enter or transition to the SWP • A dispelled myth about adopting SWP
/episode/index/show/cmu-sei-webcasts/id/39718130
info_outline
Right-Sized DevSecOps: How Tooling Complexity Breaks Modern Pipelines
01/13/2026
Right-Sized DevSecOps: How Tooling Complexity Breaks Modern Pipelines
Many organizations practicing DevSecOps have collapsed under the weight of their own tooling. These organizations tried to solve delivery problems by stacking Kubernetes, Helm, GitOps controllers, scanners, and templating systems until no one can explain their own deployment path. This webcast cuts through that complexity and shows how right-sizing DevSecOps—reproducible environments, deterministic builds, type-safe configuration, and small iterative releases—restores velocity and reliability. We focus on what high-stakes teams actually need, not what vendors or compliance frameworks prescribe. What Will Attendees Learn? • Why complexity, not capability, is the primary barrier to fast, secure delivery • How reproducibility, pre-rendering, and type-safe configuration eliminate entire categories of deployment failure • How to design a “paved road” that scales across teams without drowning them in tooling • How to move from episodic, end-state-driven integration to continuous, incremental delivery
/episode/index/show/cmu-sei-webcasts/id/39718045
info_outline
How to Address the Problem of Poorly-Defined Requirements in Software System Design
11/13/2025
How to Address the Problem of Poorly-Defined Requirements in Software System Design
This webcast offers a solution to the problem of poorly defined requirements in system design that can lead to software flaws, cost and time overruns, and stakeholder dissatisfaction. We will tell you how to use a structured process called the ATAM (architectural tradeoffs analysis method) to develop a system design by eliciting requirements, scenarios, and priorities from stakeholders. Then, we will explain how to measure compliance with those requirements during testing using DevSecOps principles and tools, such as the SEI’s Silent Sentinel. What Will Attendees Learn? What software quality attributes are and why they are important How to prioritize competing requirements How to ensure architectural requirements are satisfied during development in a DevSecOps toolchain
/episode/index/show/cmu-sei-webcasts/id/39022050
info_outline
5 Essential Questions for Implementing the Software Acquisition Pathway and the Tools to Tackle Them
10/23/2025
5 Essential Questions for Implementing the Software Acquisition Pathway and the Tools to Tackle Them
The SEI contributed its expertise to the development of the Software Acquisition Pathway (SWP), which the Department of Defense (DoD) issued in 2020 as DoD Instruction 5000.87. Since the SWP’s issuance, SEI researchers have collaborated with DoD program teams and policy owners to effectively implement the pathway in different program contexts, identify barriers and challenges, and monitor outcomes. Throughout that work, we’ve identified common questions and stumbling blocks that programs encounter as they adopt the SWP. Answering these questions often warrants additional tools and resources that enable programs to position their SWP programs for success. With that in mind, the SEI announces the launch of the Software Acquisition Go Bag. Our SEI team has helped hundreds of DoD programs deliver software-enabled capability through our unique integration of data-driven insights, software engineering research, and acquisition science. We’re “packing” that experience into Go Bag kits so program teams can implement proven practices.
/episode/index/show/cmu-sei-webcasts/id/38755250
info_outline
Q-Day Countdown: Are You Prepared?
10/15/2025
Q-Day Countdown: Are You Prepared?
Experts agree that quantum computing will likely become powerful enough to break modern-day encryption within the next 10–15 years on “Q Day.” Once encryption is defeated, the computing world will never be the same. Organizations need to identify the correct courses of action to take today so that the sudden onset of quantum computing does not threaten their critical assets. In this webcast, Brett Tucker, Dan Justice, and Matthew Butkovic discuss the challenges expected with the realization of quantum computing capabilities. Furthermore, the group will provide possible responses to mitigate future impacts from the onset of quantum computing. What Will Attendees Learn? what Q Day is events that may occur leading up to the actual day itself challenges that must be overcome in quantum computing (attendees need to learn and appreciate the factors that may influence the successful emergence of quantum computing) actions that can be taken today to build resilience from this technological disruption
/episode/index/show/cmu-sei-webcasts/id/38595055
info_outline
Using LLMs to Evaluate Code
10/02/2025
Using LLMs to Evaluate Code
Finding and fixing weaknesses and vulnerabilities in source code has been an ongoing challenge. There is a lot of excitement about the ability of large language models (LLMs, e.g., GenAI) to produce and evaluate programs. One question related to this ability is: Do these systems help in practice? We ran experiments with various LLMs to see if they could correctly identify problems with source code or determine that there were no problems. This webcast will provide background on our methods and a summary of our results. What Will Attendees Learn? • how well LLMs can evaluate source code • evolution of capability as new LLMs are released • how to address potential gaps in capability
/episode/index/show/cmu-sei-webcasts/id/38437950
info_outline
Achieving Balance: Agility, MBSE, and Architecture
08/01/2025
Achieving Balance: Agility, MBSE, and Architecture
Often, agile implementations are a struggle. Dedicated agile teams focus hard and deliver value on a regular cadence. But when results are tallied, the value teams produce may not fit neatly into the expectations of senior stakeholders. Why? In this webcast, Peter Capell addresses the importance of a practical vision to express outcomes, so that the program's “target picture” is clear to all parties involved. Peter highlights the value of tools such as Model-Based Systems Engineering (MBSE) in engineering processes, and how the combination of architecture and MBSE can anchor the implementation within those expectations. What Attendees Will Learn: • The concept of “just enough” • How speed of delivery is only relevant when delivery is on target • How the “targets” for team success begin with the program vision • How modeling and architecture can serve as valuable tools to accomplish a practical vision
/episode/index/show/cmu-sei-webcasts/id/37637445
info_outline
Identifying AI Talent for the DoD Workforce
07/18/2025
Identifying AI Talent for the DoD Workforce
Finding and growing AI and Data talent is essential for mission success, but many skilled workers remain unseen because they lack traditional credentials. This session introduces practical strategies and prototype tools that help individuals demonstrate what they know while helping managers identify and evaluate emerging talent in these fields. Attendees will explore micro-assessments reflecting real data science and AI workflows, see how skills can be measured meaningfully at scale, and gain insights on fostering AI and Data readiness across the federal workforce. Whether you’re building your career or building your team, come learn how to connect talent with opportunity in the evolving AI landscape. What Attendees Will Learn: • Common barriers to finding and recognizing hidden AI and Data talent. • The role of a practical work role rubric in aligning skills with mission needs. • How prototype assessments and discovery tools can help surface and showcase talent.
/episode/index/show/cmu-sei-webcasts/id/37455765
info_outline
Model Your Way to Better Cybersecurity
07/10/2025
Model Your Way to Better Cybersecurity
Threat modeling is intended to help defend a system from attack. It tops the list of techniques recommended by the National Institute of Standards and Technology (NIST) to secure critical systems. In a world where people with malicious intent have deadlier tools at their disposal, defenders need to take advantage of Model-Based Systems Engineering (MBSE) to form mitigation strategies effective from early in the systems engineering lifecycle. This webcast will preview a workshop to be held during the 2025 Secure Software by Design conference to be held on August 19 and 20. What Attendees Will Learn: How MBSE can aid cybersecurity analysis and design The value of MBSE for cyber threat modeling An overview of threat modeling techniques using MBSE
/episode/index/show/cmu-sei-webcasts/id/37360335
info_outline
DevSecOps: See, Use, Succeed
06/27/2025
DevSecOps: See, Use, Succeed
DevSecOps generates a lot of data valuable for better decision making. However, decision makers may not see all they need to in order to make best use of the data for continuous improvement. The SEI open source Polar tool unlocks the data, giving DevSecOps teams greater capability to automate, which in turn means they can innovate rapidly – without lessening quality or reducing security. What Attendees Will Learn: Issues from complex DevSecOps pipelines What observability adds for DevSecOps efforts The way in which a new open-source tool, Polar, helps
/episode/index/show/cmu-sei-webcasts/id/37181660
info_outline
An Introduction to the MLOps Tool Evaluation Rubric
06/18/2025
An Introduction to the MLOps Tool Evaluation Rubric
Organizations looking to build and adopt artificial intelligence (AI)–enabled systems face the challenge of identifying the right capabilities and tools to support Machine Learning Operations (MLOps) pipelines. Navigating the wide range of available tools can be especially difficult for organizations new to AI or those that have not yet deployed systems at scale. This webcast introduces the MLOps Tool Evaluation Rubric, designed to help acquisition teams pinpoint organizational priorities for MLOps tooling, customize rubrics to evaluate those key capabilities, and ultimately select tools that will effectively support ML developers and systems throughout the entire lifecycle, from exploratory data analysis to model deployment and monitoring. This webcast will walk viewers through the rubric’s design and content, share lessons learned from applying the rubric in practice, and conclude with a brief demo. What Attendees Will Learn: • How to identify and prioritize key capabilities for MLOps tooling within their organizations • How to customize and apply the MLOps Tool Evaluation Rubric to evaluate potential tools effectively • Best practices and lessons learned from real-world use of the rubric in AI projects
/episode/index/show/cmu-sei-webcasts/id/37055375
info_outline
The State of DevSecOps in the DoD: Where We Are, and What’s Next
05/20/2025
The State of DevSecOps in the DoD: Where We Are, and What’s Next
DevSecOps practices foster collaboration among software development, security, and operations teams to build, test, and release software quickly and reliably. A high-stakes, high-security environment has challenged the implementation of these practices within the Department of Defense (DoD). The DoD Chief Information Officer (CIO) organization partnered with the Software Engineering Institute (SEI) to conduct the first study to baseline the state of DoD DevSecOps, highlight successes, and offer insights for next steps. George Lamb, DoD’s Director of Cloud and Software Modernization, joins the SEI team to discuss key results and how they will help the DoD ensure that its software ecosystem is effective, scalable, and adaptable to meet the challenges of today and tomorrow. What Attendees Will Learn: Highlights from important success stories in DoD’s DevSecOps journey How the DoD is harvesting grassroot successes by individual software organizations to implement those successes at scale Keys to using data and building effective measurement strategies to enable optimization of software delivery
/episode/index/show/cmu-sei-webcasts/id/36642540
info_outline
I Spy with My Hacker Eye: How Hackers Use Public Info to Crack Your Creds
05/15/2025
I Spy with My Hacker Eye: How Hackers Use Public Info to Crack Your Creds
Did you know there are 500 million tweets per day? 3 billion monthly active Facebook users? 1 billion LinkedIn members? Are you one of them? In this webcast, Destiney Marie Plaza reveals how a hacker can use seemingly benign public information to customize an attack on a victim by showing a scenario-based attack and demo (using free and open-source tools). Additionally, you will learn how hackers can gather information about you, common mistakes that put your information at risk, and how to protect yourself. What Attendees Will Learn: how to use open-source tools used to crack passwords, along with a methodology for how hackers may gain access to your accounts what makes a strong password and how such passwords can stave off automated cracking tools how a hacker sees you, so that you can take appropriate steps to protect yourself
/episode/index/show/cmu-sei-webcasts/id/36582050
info_outline
A New Performance Zone for Software for National Security
05/08/2025
A New Performance Zone for Software for National Security
Today, we have seen our national security organizations working to adopt modern software practices, particularly Agile methods and DevSecOps practices, efforts challenged by a mismatch of tempos between operational needs and development processes. The newly mandated Software Acquisition Pathway helps to align those tempos. However, to sustain a competitive advantage through software, we need to see our defense organizations recall and reapply disciplined engineering practices. What Attendees Will Learn: An assessment of current efforts to adopt modern software practices Why and where the pace of adoption faces challenges Characteristics of the needed new level of performance
/episode/index/show/cmu-sei-webcasts/id/36486290
info_outline
Identifying and Mitigating Cyber Risk
04/25/2025
Identifying and Mitigating Cyber Risk
An organization’s cyber risk management practices must be rooted in organizational goals to be truly effective. In this webcast, Matt Butkovic, Greg Crabbe and Beth-Anne Bygum explore how best to align business and resilience objectives.
/episode/index/show/cmu-sei-webcasts/id/36309015
info_outline
Malware Research: If You Cannot Replicate it, You Will Not Use It
04/25/2025
Malware Research: If You Cannot Replicate it, You Will Not Use It
Why aren't malware analysis practitioners making more use academic research results? In this webcast, we suggest that one reason is the general difficulty of replicating and reproducing research results in this field. We randomly selected 100 papers on "malware classification" from Google Scholar results and attempted to replicate each one. We were only able to find released code for 6 of these 100 papers, and what's worse, only 6 of the 88 remaining papers contained a specific listing for the algorithm. We offer suggestions for improving the state of the field and end with a call to action for researchers to improve their methods so that their work will be useful for everyone. What Attendees Will Learn: Why replication and reproduction are important topics in malware research The problems with data in malware research and suggestions to fix them The basics of using science in the field
/episode/index/show/cmu-sei-webcasts/id/36308935
info_outline
Cyber Maturity Model Certification (CMMC): Protecting the Nation’s Defense Industrial Base
04/11/2025
Cyber Maturity Model Certification (CMMC): Protecting the Nation’s Defense Industrial Base
The Defense Industrial Base (DIB) is a core element of the national security ecosystem. This point of intersection between private industry and the Department of Defense is a perpetual target for the Nation’s adversaries. In this Intersect, Matthew Butkovic and John Haller explore the development, and implementation, of the Cyber Maturity Model Certification (CMMC) as a means to better protect the DIB.
/episode/index/show/cmu-sei-webcasts/id/36097985
info_outline
Threat Hunting: What Should Keep All of Us Up at Night
03/27/2025
Threat Hunting: What Should Keep All of Us Up at Night
When it comes to recognizing threats, cybersecurity professionals may become distracted by big promises or ignore some obvious inspections. New claims made by the latest and greatest new apps draw attention away from network situational awareness best practices—like a dog distracted when it spots a squirrel. We also may deviate from making routine inspections that point toward further investigation—overlooking obvious needs right under our noses. Either becoming distracted or missing obvious inspections can cause us not to detect threats. What Attendees Will Learn: • The distinction between anomalies and threats • Steps to analyze data to detect a threat • The benefits of completing work on one threat
/episode/index/show/cmu-sei-webcasts/id/35886080
info_outline
Can a Cybersecurity Parametric Cost Model be Developed?
03/17/2025
Can a Cybersecurity Parametric Cost Model be Developed?
Can a cybersecurity parametric cost estimation model be developed? Every Department of Defense (DoD) program needs to account for, credibly estimate, budget/plan for, and assess the performance of its cybersecurity activities. Creating a cybersecurity parametric model would allow DoD programs to reliably estimate the effort and cost of cybersecurity activities, estimate an overall cybersecurity cost for a program, and obtain a defined and normalized set of cybersecurity data. In this webcast, Christopher Miller shares insights from a Carnegie Mellon University Software Engineering Institute study on cybersecurity cost estimating that can help national security organizations successfully deploy parametric cost modeling. What Attendees Will Learn: • a proposed work breakdown structure identifying cybersecurity-related activities and cost items, and existing descriptions of secure coding practices and levels of rigor for those practices based on data availability • an approach to develop a cybersecurity parametric cost model • a methodology to develop the cost model
/episode/index/show/cmu-sei-webcasts/id/35722930
info_outline
Elements of Effective Communications for Cybersecurity Teams
03/03/2025
Elements of Effective Communications for Cybersecurity Teams
Communications, both in times of crisis and during normal operations, are essential to the overall success and sustainability of an incident response or security operations team. How you plan for and manage these communications and how they are received and actioned by your audience will influence your trustworthiness, reputation, and ultimately your ability to perform incident management services effectively. This webcast leverages the National Institute of Standards and Technology (NIST) Cybersecurity Framework and the Forum of Incident Response and Security Teams (FIRST) CSIRT Services Framework to present communications responsibilities as part of both the standard incident management lifecycle and as an integral piece of crisis management support. What Attendees Will Learn: • various communication types or mechanisms for normal and crisis situations • foundational aspects of managing communications with constituents, the public, and the media • building blocks for an effective communications plan
/episode/index/show/cmu-sei-webcasts/id/35517100
info_outline
Operational Resilience Fundamentals: Building Blocks of a Survivable Enterprise
02/13/2025
Operational Resilience Fundamentals: Building Blocks of a Survivable Enterprise
Surviving disruptive cyber events requires a specific form of planning. One must strike a balance between defending against threats (e.g., managing conditions) and effectively handling the effects of disruption (e.g., managing consequences). Employing a model (such as the CERT Resilience Management Model) provides a catalog of practices and a system of measurement. Focusing on key attributes of performance permits a level of prediction not possible with a basic checklist. In this webcast, Greg Crabbe and Matt Butkovic share their experiences in establishing and maintaining operational resilience programs. What Attendees Will Learn: • how to link mission outcome with asset resilience • how managing for security differs from managing for resilience • how to apply a capability maturity model to the challenge • how to begin analyzing requirements and constructing an operational resilience management program
/episode/index/show/cmu-sei-webcasts/id/35270865
info_outline
Cybersecurity Priorities in 2025
02/07/2025
Cybersecurity Priorities in 2025
Chief Information Security Officers (CISOs) perpetually navigate a dynamic set of challenges. Applying focus and aligning resources is imperative for success. In this Intersect, Matthew Butkovic and Gregory Touhill, reflect on 2024 and explore the topics that should be front of mind for CISOs in 2025. They provide insights and advice for those contemplating cybersecurity priorities.
/episode/index/show/cmu-sei-webcasts/id/35190455