Skip to content
TrackPodcasts
technologySep 3, 202621:59

CISO DIY: Building the Sovereign AI Security Department

About this episode

Welcome to the definitive audio guide for security leaders, engineers, and fractional CISOs who want to construct, own, and maintain their cybersecurity programs internally. Each episode breaks down the technical blueprints needed to transform static compliance checklists into active, open-source defenses, spanning continuous asset discovery, tuned monitoring stacks, and phishing-resilient identity perimeters. We explore how to navigate the 2026 regulatory landscape—including the EU AI Act and ISO 42001—using local, hardware-isolated command nodes that guarantee absolute data sovereignty.

 

Sponsors:

https://ciso.diy -> 20% off 

https://cisomarketplace.services -> offensive security & Ai Services

Get every episode summarized

Each time CISO Insights: Voices in Cybersecurity publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

Hosts & guests

Transcript ready

248 searchable segments. Every word is indexed and playable.

CISO DIY: Building the Sovereign AI Security Department

CISO Insights: Voices in Cybersecurity

0:00
21:59

Full transcript

CISO Insights: Voices in CybersecurityCISO DIY: Building the Sovereign AI Security Department. Machine-transcribed; use the interactive transcript above to jump the player to any line.

You know when you walk onto a movie set and you see this incredibly beautiful elaborate house, it looks totally real, right? Like the brickwork has texture, the oak doors looks super heavy. Oh yeah, totally convincing. Right. But then you accidentally lean on one of those walls and the entire structure just wobbles because you look behind it and it's literally just like two by fours and some sandbags holding the whole thing up. Exactly. It's all built for the camera lens. It is not built for a category five hurricane. Yeah, which is a terrifying thought when you realize that you just perfectly describe the actual network architecture of honestly thousands of companies operating right now. It's so true. And that is exactly what we are looking at in today's deep dive. We got our hands on this massive stack of architectural guides, build blueprints and product catalogs from a platform called siso.i. Yeah, this stack was fascinating to go through. It really was. Yeah. And what these documents lay out is basically the democratization of enterprise grade cybersecurity. It's a guide on how to rip down that

wobbly movie set and pour a real concrete foundation for a security program. And that's whether you're a giant enterprise, you know, or a solo consultancy or even just trying to keep your family's home network safe. The scale changes but the physics of the defense really don't. Right. So our mission today is to give you a shortcut to understanding how real security practitioners build these defensible systems. But before we tear down the boardroom walls, we should definitely give a massive shout out to the sponsor making this deep dive possible. Oh, absolutely. The folks over at www.siso.di. They're actually running a 20% off sale across their entire DIY catalog right now, which is awesome. And for those who maybe don't want to build themselves, we'll also be talking about siso marketplace dot services, which is their managed service arm for offensive security and AI services. It's lots of cool stuff there. Yeah, definitely check that out because to really understand the blueprints they've drawn up, we first have to look at what they are actively trying to replace, right? The movie sets. Exactly. The sources actually call it

security theater, which is just a great term for it. It's so accurate. For years, the industry has just sort of coasted on these deliverables that look great, but produce zero technical defense. And the siso.di catalogs specifically target three variations of this theater. Right. I saw this. The first one is the compliance spreadsheet, right? Yeah. A team might spend, I don't know, 20 hours building this massive matrix of controls from scratch in Excel. But it's just text in a cell. It doesn't actually connect to anything real on the network. Just a wish list, basically. Pretty much. Yeah. And then you have the absolute bottom of the barrel, which they describe as these generic like $15 Etsy checklists. Oh, man, the Etsy templates. Right. Someone just buys a PDF template, fills in their company name, and thinks they magically have an incident response plan. Even though there's literally no underlying logic to it for their specific business. Exactly. And then the third culprit is on the complete opposite end of the spectrum, which is the massive overkill of the $500 a month sauce platform. Oh, this one gets me companies will buy this

super expensive recurring software subscription to manage compliance tasks that honestly just require one time structural fix. It's like paying for a really high end luxury gym membership, taking selfies in the mirror and then being shocked that you aren't getting stronger. That's a perfect analogy. Right. The membership card doesn't build the muscle. You still have to actually pick up the heavy things. Take that gym analogy further, Cizodotty's whole approach is to just cancel the fancy membership and focus entirely on the weights. They prioritize tangible outputs, things you can confidently hand to an auditor or a board. Like if we look at their build series foundation bundle, they map out how to build a real defense engine using open-source tools instead of these crazy expensive commercial licenses. Right. And they specifically integrate Wazoo, Surakata and Zeke, I think. Yes. Wazoo, Surakata and Zeke. Okay, let's unpack this for a second because I see those names thrown around a lot in security forms. If we break those down for someone who isn't living in command lines all day, how do those three actually work together?

Okay, so think of them as a physical security team for a building. Wazoo is essentially your network of security cameras. It's an endpoint agent sitting on the actual laptops and servers, watching what's happening internally. Okay, got it. Then Surakata acts as your perimeter alarm system. It's an intrusion detection engine that's basically looking for known malicious signatures trying to break in through the doors and windows. Like someone picking a lock. Exactly. And then Zeke is the meticulous ledger at the front desk. It doesn't necessarily block things, but it keeps a highly detailed record of exactly who talked to whom for how long and what language they were speaking. Wow. Okay. So you have the cameras, the alarms, and a logbook. And they provide the blueprints to assemble that entire engine. So a single practitioner can actually run it. But looking at build series volume 0 2, which is one that focuses on discovering assets. The introduces a concept that totally flips how most people think about keeping track of their network. They basically say a static spreadsheet

of your inventory is completely useless. It is because a modern network is a living organism. You know, if you save a spreadsheet at 9000 by 9505 AM, an employee has connected a personal iPad or some marketing team has spun up a new cloud server with a corporate credit card. Right. The list is instantly outdated the second you save it. Exactly. So they mandate active discovery. You need a tool constantly pinging the environment to see what is physically plugged in and running at that exact moment. But the insight here that really stuck with me is that the security control itself isn't just the active scan and isn't the registry of what you think you have either. The actual control is the friction between the two. Yes, the continuous reconciliation. Exactly. You have a list that says we own 100 servers. Your active scan comes back and says, I currently see 100 to 2 servers running. The actual security work happens in investigating those two rogue servers. That gap is where shadow it hides. It's where the marketing departments completely unsecured cloud database lives. Right. And by focusing on that gap, you shift from just being a

passive record keeper to an active investigator. And that fundamental shift is really how they structure the entire modern security department. The architecture they lay out is called the AI security department. And it operates like a funnel rather than a list of isolated tasks. It all begins with phase zero, which is mapping the estate. You have to know your footprint, especially your shadow AI footprint before you buy a single tool. Right. And once you map the estate, you move into the actual defense structure. They break this down into six pillars. But rather than just reading down a list, it helps to look at how a threat actually flows through them. It seems to start with preparation. The preparation phase is where your first two pillars live. So pillars zero one is compliance. But again, not the static spreadsheet kind. It's mapping your controls to frameworks like the new ISO 42, 2001, which is huge right now for anyone unfamiliar. ISO 42, 2001 is basically becoming the universal translator for artificial intelligence management. It proves to regulators that you have a formal documented system for governing how your company uses

AI. Right. Then you have pillar 02, which is DevSecOps. This is where a solo engineer can scan literally hundreds of applications for vulnerabilities while they're being built using cloud AI to triage the code. It speeds things up massively. But this flows right into the active defense phase, which is where I really stumble when reading these blueprints. Yeah. pillar 03 is penetration testing as a service or p-test. Yeah. And they describe it as an autonomous offense lane. Yes. It acts as an automated red team. It doesn't just span for a bug. It actively tries to prove the bug exists by deploying a live exploit chain against your network. And then it actually drafts the code to patch it. Okay. Let me stop you there because of autonomous penetration testing sounds like a complete disaster waiting to ask. It does sound risky. Yeah. I mean, if I have an artificial intelligence actively firing exploits into my live network just to see what breaks. How do we know it won't accidentally take down the payroll server on a Friday afternoon? Aren't we just handing a loaded gun to an algorithm? It sounds terrifying if you assume the AI is just running wild, right?

But the architecture explicitly prevents that. And this is where we look at pillar 04, the AI SOC or security operations center. The alert reducer. Exactly. All of this autonomy operates under a strict, defensible ceiling. The AI is doing the exhausting, high volume data correlation. It reads the thousands of daily alerts, connects the dots across Wazoo, Siracada and Zeke. And it resolves the routine noise that normally causes human engineers to experience severe alert fatigue. But it isn't making the final call and like pulling the plug on a critical server. Never. The blueprints demand a human gatekeeper. Always. The AI acts as the ultimate filter and researcher. But the moment it detects a critical anomaly or before it launches a potentially disruptive exploit test, it packages all the context and presents it to a human for approval. So the autonomy is capped at analysis and routine remediation. It does not extend to critical infrastructure decisions. Okay, that makes a lot more sense. The human is still driving. The AI is just the navigation system pointing out the traffic jams. Right. Exactly. And if things

go completely off the rails, you flow into the worst case scenario pillars. Pillar 05 is incident response. They describe it as having one room, one clock and 90% of the hard choices pre-made. So you aren't debating corporate policy while ransomware is literally locking your files. Yeah, you do not want to be making those decisions during a crisis. And pillar 06 is the capstone. It's the fractional CISO. This is a human leader who takes all the data from the active defense and the incident preparations and translates it into a financial risk metric that the board of directors can actually understand. Because the board doesn't care about firewall logs. They care about financial exposure. So you have this massive funnel, AI scanning code, automated penetration tests, finding exploits and AI SOC filtering thousands of alerts. The amount of data flying between these six pillars is just staggering. How do they communicate without turning into a chaotic noisy mess that frankly leaks sensitive data everywhere? That is handled by the brain of the operation, which the blueprints call the C2 command layer

or the operator seat. And this isn't some size application sitting in an Amazon data center somewhere. The C2 layer runs on a piece of local hardware called an operator node. And the specs for this hardware are wild. They specifically call out using a core boot NUC anchored to nitricy hardware roots. Let's translate that into plain English for a second. Sure. So what NUC is just a very small, powerful mini computer, but the core boot part is critical. Most commercial computer chips come with hidden management software baked into the silicon by the manufacturer stuff you can't even see. Right. Software that hackers absolutely love to exploit because it runs underneath your operating system. Core boot is an open source firmware that completely neutralizes those hidden vulnerabilities. It strips the computer down to its bear verifiable essentials and nitric key. The nitric key acts as a physical cryptographic key that proves the hardware hasn't been tampered with. So you have this highly hardened mini computer just sitting on your physical desk. Here's where it gets really interesting to me. It's like

the command center of an air gap submarine. That is the perfect visualization. The blueprints design this operator node with zero inbound traffic literally nothing from the outside internet can reach in and talk to it. And more importantly, it is built with one step physical severability, which means if you are experiencing a massive catastrophic breach, like let's say a nation state actor is tearing through your cloud infrastructure. You don't have to navigate through five different admin portals to lock down your master control. You reach out, grab a physical cable and you just unplug it. You physically severed the brain from the network, preserving the sovereignty of your evidence vault. Because you can't hack a severed wire. Right. But this brings up a massive technical hurdle. If the operator node is so isolated, how does the local AI agent living on it actually read your sensitive internal data like your governance policies or your vulnerability scans without sending that data out to an external brain like chat GPT because the moment you send your proprietary source

code to a public cloud AI to ask a question, you've compromised your own data precisely to solve this. The architecture uses something called mcp or the model context protocol. mcp is a framework that allows an AI model to connect to local data sources securely in these blueprints. The c2 layer uses 11 specific JSON schemas to wire the AI to your internal databases, what they call the living ISMS. Let's break down a JSON schema because that sounds like heavy programming terminology. It does, but think of a JSON schema like a highly structured index card that serves as a translator. The local AI agent doesn't just rummage through your entire database like a messy teenager looking for a shirt. Right. The schema acts as a strict set of rules that says you are only allowed to ask these specific questions and I will hand you the answer in this specific formatted box. So the AI can ask the database. Did the server pass its compliance check today? Yeah. And the schema ensures the database safely hands back just the word yes or no. The AI gets the context it needs, but your

deepest corporate secrets never actually leave the physical hardware on your desk. Exactly. It is sovereign by construction. Now obviously sourcing a core boot and you see establishing hardware routes of trust and programming 11 different JSON schemas for local AI context is a highly advanced engineering project. Yeah, that is not a weekend hobby project, which perfectly sets up the build versus buy dilemma. If you were listening to this deep dive and thinking I absolutely need that level of sovereign, unplugable security, but I barely have time to check my email, let alone flash custom firmware out to a micro computer that is exactly where Cecil Marketplace.Services they take this exact architecture, the same operator node, the same six pillars that AI SOC and they run it for you as a managed program. You get the concrete foundation without having to mix the cement yourself. And honestly, whether you build it or buy it, this level of rigor isn't just a fun thought experiment anymore. The sources make it very clear that the regulatory landscape is shifting aggressively as we head into 2026. Oh, yeah. The era of best effort security is officially dead.

The workbooks outlined several 2026 mandates that are going to catch a lot of companies flatfooted. We're talking about the 2026 high P.O. final rule, which adds 12 new mandatory requirements for anyone touching healthcare data. You have CMMC 2.0 hitting defense contractors. But the truly terrifying mandates are coming out of Europe. The Digital Operational Resilience Act or Dora, and the NIS2 directive are completely changing the math on risk. The penalties are insane. They really are. If a company fails to secure its critical infrastructure under NIS2, regulators can love you fines of up to 10 million euros or 2% of global revenue. That is company ending money right there. You can't just hand an auditor a generic $15 checklist when a 10 million euro fine is on the table. No, you definitely can't. And the scrutiny isn't just on traditional servers anymore either. The most complex regulatory shift detail in the sources is the 2026 AI risk register. Regulators are now demanding that organizations not only inventory every single AI tool they use, but mathematically score them. Right. They scored them based on two factors. I think

it was operational autonomy and blast radius. But I have to ask on behalf of everyone listening, how do you actually measure the blast radius of a rogue AI tool? Let's say a marketing manager secretly uses a corporate credit card to buy a subscription to an AI video generator. How do you quantify that risk? Well, you can't just guess, which is why the Sizzle.DI blueprints include a shadow AI inventory workbook that uses a 10 factor risk model. The map actually looks at specific mechanisms. For example, one factor asks, does this AI process personally identifiable information? Another factor asks, does this AI have the ability to execute code independently or does it only generate text? So if the marketing AI is just generating video clips and has literally no access to customer data, its blast radius is relatively low. Exactly. But if a hospital administrator downloads an unauthorized AI transcription tool to summarize patient notes, that tool is processing highly sensitive medical data. Its blast radius is massive. Oh, wow. And the 10 factor model is

tunable, meaning you adjust the mathematical weight of those questions based on what industry you are in. So when the regulators show up, you don't just shrug your shoulders. You hand them a mathematically defensible model that explains exactly why the hospital AI triggered an immediate incident response. It's all about having a defensible system. But we have spent this entire time dissecting massive enterprise architectures, 10 million euro fines and sovereign hardware. But the fascinating twist in the Sizzle.DID catalogs is how they apply this exact same ruthless practitioner grade logic to everyday consumer protection. Yes. The security of a home network in your family's identity is treated with the same structural engineering as a Fortune 500 company. It's amazing. Let's talk about the identity theft recovery binder. Because most advice online just says, Oh, if your identity is stolen, call your bank and freeze your credit, which is incredibly unhelpful when someone has already opened three credit cards in your name. Generic and vice fails under pressure. The recovery binder from Sizzle.DID doesn't just tell you

to complain to a credit bureau. It gives you an operational runbook built around FCRA section 605B. Let's explain what that statute actually does because it's powerful. The Fair Credit Reporting Act section 605B is a specific legal mechanism. When you cite this exact statute and provide a police report, the credit bureau is legally mandated to block the fraudulent information from your credit report within four business days, four days, four business days. You don't ask them nicely to investigate. You use the specific legal lever that forces compliance. That is the difference between security, theater, and a functional system. I love that. And they apply that same structural thinking to the digital estate planning workbook. People think they're doing their family a huge favor by putting a master list of their passwords or their crypto wallet keys into their will, which is a catastrophic mistake. Because the moment a will enters probate court after you die, it becomes a public document. Anyone can go down to the courthouse and read it. You are literally publishing your passwords to the public record. To solve this, the workbook leverages something

called Rui Aura. Rui Aura, right? Yeah. The revised Uniform Fiduciary Access to Digital Assets Act. It's a legal framework that allows you to grant your executor the legal right to access your digital accounts using built-in manager succession features at the tech companies, completely by passing the public probate process. It keeps your data out of the courtroom. So smart. Which brings us to my absolute favorite piece of this entire deep dive. They have a senior cyber safety workbook for adult children trying to protect their aging parents from modern threats like AI voice cloning. Scammers can pull literally three seconds of your voice from a social media video, clone it, and call your grandmother sounding exactly like you, begging for bail money. It is one of the most effective and devastating scams operating right now because it bypasses all logical defenses by attacking the emotional center of the brain. And what does the counter measure included in these highly advanced tabletop cyber drills? A family safe word card. Think about the incredible irony here. We have spent this deep dive talking about AI driven security

operation centers, core root firmware, 10 factor mathematical risk models, and JSON schemas. Yet the absolute best defense against a highly sophisticated AI driven voice clone attack in your family is a low tech analog safe word that you agree on over a plate of spaghetti at the dinner table. It's brilliant engineering, honestly. When that cloned voice calls and asks for money, the grandparent simply asks for the safe word. If the voice doesn't know it, they hang up. You defeat millions of dollars of cloud computing power by moving the authentication out of band to a physical human memory. You completely bypass the software and that perfectly synthesizes everything we've explored today, whether you are an enterprise mapping out your ISO 42,000 one AI compliance across a global network, or you are a grandson trying to protect your grandmother from elder fraud. True security is about actionable, defensible systems. It is about pulling down the movie set, stop buying tools just for the optics, understand the mechanism of the threat, establish a real control in the physical world, and build a system that actually does the heavy

lifting. It is about building the load bearing walls. Thank you to everyone for joining us on this deep dive. And one final huge thank you to our sponsors. Make sure to head over to www.seizo.di to take advantage of that 20% off sale across their entire catalog from the enterprise build series we talked about to those family safety packs. Or if you want the ultimate shortcut and just want the experts to run the offensive security and AI programs for you visit sysomarketplace.services. So I want to leave you with one final thing to ponder. We just talk about how a personal analog safe word is currently the absolute best defense against advanced AI voice cloning. If a simple analog memory defeats advanced AI at home, I wonder will the future of enterprise cybersecurity also eventually abandon the software arms race? Will we see giant tech companies relying on physical analog fail sace? Like the literal unplugged severability of the operator node? Just to guarantee that their most precious data survives. It makes you wonder how much of the future is going to rely on the past. Until next time.

More episodes

More from CISO Insights: Voices in Cybersecurity

View all episodes →