<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:podcast="https://podcastindex.org/namespace/1.0">
    <channel>
        <generator>RedCircle VERIFY_TOKEN_fc21c6d7-1e7a-4dbc-8956-2b0bc8789231  -- Rendered At Wed, 26 Aug 2026 06:50:56 &#43;0000</generator>
        <title>The InfoSec Control Room</title>
        <link>https://redcircle.com/shows/the-infosec-control-room-tae</link>
        <language>en-US</language>
        <copyright>All rights reserved.</copyright>
        <itunes:author>Taher Amine ELHOUARI</itunes:author>
        <itunes:summary>The InfoSec Control Room is a podcast by *Taher Amine ELHOUARI* about cybersecurity, governance, risk, compliance, resilience, and CISO-level decision-making.

This show goes beyond buzzwords, checklists, and surface-level security advice. Each episode explores the gap between what organizations believe they have in place and what actually works when incidents happen, audits begin, regulators ask questions, or leadership needs to make risk-based decisions.

Hosted from the perspective of a CISO/DSSI, cybersecurity governance practitioner, auditor, advisor, speaker, and community builder, The InfoSec Control Room covers practical topics across information security, GRC, CISO leadership, ISO standards, cyber resilience, privacy, incident response, CSIRT operations, security awareness, regulatory expectations, and lessons from the field.

The core idea is simple: most organizations do not have a security problem. They have a governance problem that manifests as security.

This podcast is for CISOs, security leaders, GRC professionals, auditors, consultants, executives, aspiring cybersecurity leaders, and practitioners who want clearer thinking, stronger controls, and governance that actually works.

No noise. No checkbox compliance. No fake maturity.

Just practical conversations on how security is governed, controlled, measured, and improved.

https://www.TaherAmine.org/</itunes:summary>
        <podcast:guid>fc21c6d7-1e7a-4dbc-8956-2b0bc8789231</podcast:guid>
        
        <description><![CDATA[<p>The InfoSec Control Room is a podcast by <strong>Taher Amine ELHOUARI </strong>about cybersecurity, governance, risk, compliance, resilience, and CISO-level decision-making.</p><p>This show goes beyond buzzwords, checklists, and surface-level security advice. Each episode explores the gap between what organizations believe they have in place and what actually works when incidents happen, audits begin, regulators ask questions, or leadership needs to make risk-based decisions.</p><p>Hosted from the perspective of a CISO/DSSI, cybersecurity governance practitioner, auditor, advisor, speaker, and community builder, The InfoSec Control Room covers practical topics across information security, GRC, CISO leadership, ISO standards, cyber resilience, privacy, incident response, CSIRT operations, security awareness, regulatory expectations, and lessons from the field.</p><p>The core idea is simple: most organizations do not have a security problem. They have a governance problem that manifests as security.</p><p>This podcast is for CISOs, security leaders, GRC professionals, auditors, consultants, executives, aspiring cybersecurity leaders, and practitioners who want clearer thinking, stronger controls, and governance that actually works.</p><p>No noise. No checkbox compliance. No fake maturity.</p><p>Just practical conversations on how security is governed, controlled, measured, and improved.</p><p>https://www.TaherAmine.org/</p>]]></description>
        
        <itunes:type>episodic</itunes:type>
        <podcast:locked>no</podcast:locked>
        <itunes:owner>
            <itunes:name>Taher Amine ELHOUARI</itunes:name>
            <itunes:email>contact@taheramine.org</itunes:email>
        </itunes:owner>
        
        <itunes:image href="https://media.redcircle.com/images/2026/6/23/13/dd438c9e-1499-4569-86f0-47cd6562a26b_the_infosec_control_room.jpg"/>
        
        
        
            
            <itunes:category text="Technology" />

            

        
        
            
            <itunes:category text="Arts">

            
                <itunes:category text="Books"/>
            

        </itunes:category>
        
            
            <itunes:category text="Business">

            
                <itunes:category text="Careers"/>
            
                <itunes:category text="Entrepreneurship"/>
            
                <itunes:category text="Management"/>
            

        </itunes:category>
        
            
            <itunes:category text="Education">

            
                <itunes:category text="Courses"/>
            
                <itunes:category text="How To"/>
            
                <itunes:category text="Self-Improvement"/>
            

        </itunes:category>
        
            
            <itunes:category text="News">

            
                <itunes:category text="Tech News"/>
            
                <itunes:category text="Business News"/>
            

        </itunes:category>
        
            
            <itunes:category text="Science">

            
                <itunes:category text="Mathematics"/>
            

        </itunes:category>
        

        
        <itunes:explicit>false</itunes:explicit>
        
        
        
        
        
        
            <item>
                <itunes:episodeType>full</itunes:episodeType>
                <itunes:title>EP008: Stop Lying to Yourself About Cyber Maturity</itunes:title>
                <title>EP008: Stop Lying to Yourself About Cyber Maturity</title>

                <itunes:episode>8</itunes:episode>
                <itunes:season>1</itunes:season>
                <itunes:author>Taher Amine ELHOUARI</itunes:author>
                <itunes:subtitle>Why maturity scores mean nothing if the organization cannot prove the capability behind them.</itunes:subtitle>
                <itunes:summary>Taher Amine ELHOUARI examines why cybersecurity maturity scores can create false confidence and explains how organizations should measure real capability through evidence, operating effectiveness, risk context, testing, metrics, and independent challenge.</itunes:summary>
                <description><![CDATA[<p>In EP008 of <strong>The InfoSec Control Room</strong>, Taher Amine ELHOUARI takes on one of cybersecurity’s favorite activities:</p><p><strong>Measuring maturity.</strong></p><p>Organizations love maturity scores.</p><p>3.4 out of 5.</p><p> Level 4.</p><p> Managed.</p><p> Optimized.</p><p> Green dashboard.</p><p>Everything looks reassuring.</p><p>But what does the score actually mean?</p><p>Can the organization detect an attacker?</p><p>Can it restore a critical service?</p><p>Can it revoke privileged access quickly?</p><p>Can it prove its controls are operating?</p><p>Can management make a cyber-risk decision under pressure?</p><p>If not, the maturity score may be measuring confidence rather than capability.</p><p>This episode explores the gap between <strong>claimed maturity and proven capability</strong> and why cybersecurity maturity assessments can become dangerously optimistic when scoring becomes the objective.</p><p>Taher examines why documentation alone does not equal maturity, why self-assessments naturally drift toward generous scoring, why averages can hide dangerous weaknesses, and why technology, certifications, headcount, and dashboards should never be mistaken for real capability.</p><p><strong><u>Topics include:</u></strong></p><p>• What cybersecurity maturity should actually measure</p><p> • Claimed maturity versus demonstrated capability</p><p> • Why maturity scores need evidence</p><p> • Documentation versus operating effectiveness</p><p> • The optimism problem in self-assessments</p><p> • Why averaging maturity scores can hide serious risk</p><p> • Risk-based target maturity</p><p> • Why not every capability needs to reach Level 5</p><p> • Maturity by procurement</p><p> • SIEM, EDR, PAM, GRC tools and false confidence</p><p> • Metrics that measure activity instead of outcomes</p><p> • The danger of dependency on “heroic employees”</p><p> • Certification versus operational maturity</p><p> • Why completely green dashboards should make you nervous</p><p> • Independent challenge and professional skepticism</p><p> • Evidence-based maturity assessment</p><p> • Control design versus control operation</p><p> • Translating maturity findings into real improvement</p><p> • Using maturity as governance rather than scoring</p><p>One of the central ideas from EP008:</p><p><strong>A maturity claim without evidence is an opinion.</strong></p><p>And perhaps the most mature statement an organization can make is:</p><p><strong>“We are not as good at this as we thought.”</strong></p><p>Because cybersecurity maturity is not about looking advanced.</p><p>It is about understanding reality well enough to improve capability, reliability, resilience, and decision-making.</p>]]></description>
                <content:encoded>&lt;p&gt;In EP008 of &lt;strong&gt;The InfoSec Control Room&lt;/strong&gt;, Taher Amine ELHOUARI takes on one of cybersecurity’s favorite activities:&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Measuring maturity.&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;Organizations love maturity scores.&lt;/p&gt;&lt;p&gt;3.4 out of 5.&lt;/p&gt;&lt;p&gt; Level 4.&lt;/p&gt;&lt;p&gt; Managed.&lt;/p&gt;&lt;p&gt; Optimized.&lt;/p&gt;&lt;p&gt; Green dashboard.&lt;/p&gt;&lt;p&gt;Everything looks reassuring.&lt;/p&gt;&lt;p&gt;But what does the score actually mean?&lt;/p&gt;&lt;p&gt;Can the organization detect an attacker?&lt;/p&gt;&lt;p&gt;Can it restore a critical service?&lt;/p&gt;&lt;p&gt;Can it revoke privileged access quickly?&lt;/p&gt;&lt;p&gt;Can it prove its controls are operating?&lt;/p&gt;&lt;p&gt;Can management make a cyber-risk decision under pressure?&lt;/p&gt;&lt;p&gt;If not, the maturity score may be measuring confidence rather than capability.&lt;/p&gt;&lt;p&gt;This episode explores the gap between &lt;strong&gt;claimed maturity and proven capability&lt;/strong&gt; and why cybersecurity maturity assessments can become dangerously optimistic when scoring becomes the objective.&lt;/p&gt;&lt;p&gt;Taher examines why documentation alone does not equal maturity, why self-assessments naturally drift toward generous scoring, why averages can hide dangerous weaknesses, and why technology, certifications, headcount, and dashboards should never be mistaken for real capability.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;u&gt;Topics include:&lt;/u&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;• What cybersecurity maturity should actually measure&lt;/p&gt;&lt;p&gt; • Claimed maturity versus demonstrated capability&lt;/p&gt;&lt;p&gt; • Why maturity scores need evidence&lt;/p&gt;&lt;p&gt; • Documentation versus operating effectiveness&lt;/p&gt;&lt;p&gt; • The optimism problem in self-assessments&lt;/p&gt;&lt;p&gt; • Why averaging maturity scores can hide serious risk&lt;/p&gt;&lt;p&gt; • Risk-based target maturity&lt;/p&gt;&lt;p&gt; • Why not every capability needs to reach Level 5&lt;/p&gt;&lt;p&gt; • Maturity by procurement&lt;/p&gt;&lt;p&gt; • SIEM, EDR, PAM, GRC tools and false confidence&lt;/p&gt;&lt;p&gt; • Metrics that measure activity instead of outcomes&lt;/p&gt;&lt;p&gt; • The danger of dependency on “heroic employees”&lt;/p&gt;&lt;p&gt; • Certification versus operational maturity&lt;/p&gt;&lt;p&gt; • Why completely green dashboards should make you nervous&lt;/p&gt;&lt;p&gt; • Independent challenge and professional skepticism&lt;/p&gt;&lt;p&gt; • Evidence-based maturity assessment&lt;/p&gt;&lt;p&gt; • Control design versus control operation&lt;/p&gt;&lt;p&gt; • Translating maturity findings into real improvement&lt;/p&gt;&lt;p&gt; • Using maturity as governance rather than scoring&lt;/p&gt;&lt;p&gt;One of the central ideas from EP008:&lt;/p&gt;&lt;p&gt;&lt;strong&gt;A maturity claim without evidence is an opinion.&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;And perhaps the most mature statement an organization can make is:&lt;/p&gt;&lt;p&gt;&lt;strong&gt;“We are not as good at this as we thought.”&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;Because cybersecurity maturity is not about looking advanced.&lt;/p&gt;&lt;p&gt;It is about understanding reality well enough to improve capability, reliability, resilience, and decision-making.&lt;/p&gt;</content:encoded>
                
                <enclosure length="24998974" type="audio/mpeg" url="https://audio4.redcircle.com/episodes/b13f3f16-1449-413f-8951-1a2f7beb1f05/stream.mp3"/>
                
                <guid isPermaLink="false">cc4a7bda-9b85-4d2b-8ff1-a7d5bf666fe4</guid>
                <link>https://taheramine.org/podcast</link>
                <pubDate>Sat, 22 Aug 2026 01:17:42 &#43;0000</pubDate>
                <itunes:image href="https://media.redcircle.com/images/2026/8/22/1/c71d089f-9f19-4115-94df-2ce4d12a5beb_ing_to_yourself_about_cyber_maturity_2400x2400.jpg"/>
                <itunes:duration>1562</itunes:duration>
                
                
                <itunes:explicit>false</itunes:explicit>
                
            </item>
        
            <item>
                <itunes:episodeType>full</itunes:episodeType>
                <itunes:title>EP007: Incident Response Starts Before the Incident</itunes:title>
                <title>EP007: Incident Response Starts Before the Incident</title>

                <itunes:episode>7</itunes:episode>
                <itunes:season>1</itunes:season>
                <itunes:author>Taher Amine ELHOUARI</itunes:author>
                <itunes:subtitle>Why the quality of your response is decided long before the first alert fires.</itunes:subtitle>
                <itunes:summary>Taher Amine ELHOUARI explains why incident response begins long before the first alert fires, exploring authority, escalation, communications, SOC and CSIRT coordination, backups, business continuity, executive decision-making, exercises, and the organizational preparation required for real cyber resilience.</itunes:summary>
                <description><![CDATA[<p>In EP007 of <strong>The InfoSec Control Room</strong>, Taher Amine ELHOUARI explores a simple but often misunderstood reality:</p><p><strong>Incident response does not begin when the incident happens.</strong></p><p>By the time the first serious alert fires, many of the decisions that will determine the quality of the response have already been made.</p><ul><li>Who has authority to isolate a critical system?</li><li>Who can declare a major incident?</li><li>Who decides whether a business service should be interrupted?</li><li>Who contacts legal, privacy, communications, executive management, customers, regulators, or external responders?</li><li>Can the organization communicate if its primary collaboration platform is compromised?</li><li>Can critical systems actually be restored from backup?</li><li>Does the SOC know which assets matter most?</li><li>And has anyone tested all of this before the pressure becomes real?</li></ul><p>This episode moves beyond the traditional detect-contain-eradicate-recover diagram and looks at incident response as an <strong>organizational capability</strong>, not simply a technical SOC function.</p><p>Taher discusses how authority, escalation, asset visibility, logging, communications, crisis management, business continuity, supplier arrangements, executive decision-making, and organizational culture all shape the outcome of a cyber incident.</p><p>The episode also examines why tabletop exercises should create uncomfortable decisions rather than simply confirm that a plan exists, and why serious incidents often expose weaknesses far beyond the initial technical compromise.</p><p><br></p><p><strong><u>Topics include:</u></strong></p><p>• Why incident response begins before detection</p><p> • Decision authority during cyber incidents</p><p> • Technical containment versus business impact</p><p> • The hidden cost of organizational decision latency</p><p> • Incident severity and escalation criteria</p><p> • SOC, CSIRT, management, legal, privacy, and communications coordination</p><p> • Out-of-band communications during compromised environments</p><p> • Asset inventory and business criticality during investigation</p><p> • Logging and visibility as incident-response capabilities</p><p> • Backup restoration versus simply having backups</p><p> • Connecting incident response with business continuity and disaster recovery</p><p> • Supplier and third-party incident preparedness</p><p> • Executive decision-making under uncertainty</p><p> • Why employees must feel safe reporting mistakes quickly</p><p> • Tabletop exercises that actually test the organization</p><p> • Turning incident lessons into real control improvements</p><p> • Feeding incidents back into GRC and risk management</p><p> • Why repeated incidents reveal governance problems</p><p> • Building resilience before the crisis</p><p><br></p><p>One of the central ideas of EP007: <strong>Your response capability is built before the incident. The alert only reveals what you already prepared.</strong></p><p>Because a good incident response capability is not defined by how impressive the plan looks.</p><p>It is defined by how effectively the organization can <strong>decide, coordinate, contain, communicate, recover, and learn when reality refuses to follow the plan.</strong></p>]]></description>
                <content:encoded>&lt;p&gt;In EP007 of &lt;strong&gt;The InfoSec Control Room&lt;/strong&gt;, Taher Amine ELHOUARI explores a simple but often misunderstood reality:&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Incident response does not begin when the incident happens.&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;By the time the first serious alert fires, many of the decisions that will determine the quality of the response have already been made.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Who has authority to isolate a critical system?&lt;/li&gt;&lt;li&gt;Who can declare a major incident?&lt;/li&gt;&lt;li&gt;Who decides whether a business service should be interrupted?&lt;/li&gt;&lt;li&gt;Who contacts legal, privacy, communications, executive management, customers, regulators, or external responders?&lt;/li&gt;&lt;li&gt;Can the organization communicate if its primary collaboration platform is compromised?&lt;/li&gt;&lt;li&gt;Can critical systems actually be restored from backup?&lt;/li&gt;&lt;li&gt;Does the SOC know which assets matter most?&lt;/li&gt;&lt;li&gt;And has anyone tested all of this before the pressure becomes real?&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;This episode moves beyond the traditional detect-contain-eradicate-recover diagram and looks at incident response as an &lt;strong&gt;organizational capability&lt;/strong&gt;, not simply a technical SOC function.&lt;/p&gt;&lt;p&gt;Taher discusses how authority, escalation, asset visibility, logging, communications, crisis management, business continuity, supplier arrangements, executive decision-making, and organizational culture all shape the outcome of a cyber incident.&lt;/p&gt;&lt;p&gt;The episode also examines why tabletop exercises should create uncomfortable decisions rather than simply confirm that a plan exists, and why serious incidents often expose weaknesses far beyond the initial technical compromise.&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;u&gt;Topics include:&lt;/u&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;• Why incident response begins before detection&lt;/p&gt;&lt;p&gt; • Decision authority during cyber incidents&lt;/p&gt;&lt;p&gt; • Technical containment versus business impact&lt;/p&gt;&lt;p&gt; • The hidden cost of organizational decision latency&lt;/p&gt;&lt;p&gt; • Incident severity and escalation criteria&lt;/p&gt;&lt;p&gt; • SOC, CSIRT, management, legal, privacy, and communications coordination&lt;/p&gt;&lt;p&gt; • Out-of-band communications during compromised environments&lt;/p&gt;&lt;p&gt; • Asset inventory and business criticality during investigation&lt;/p&gt;&lt;p&gt; • Logging and visibility as incident-response capabilities&lt;/p&gt;&lt;p&gt; • Backup restoration versus simply having backups&lt;/p&gt;&lt;p&gt; • Connecting incident response with business continuity and disaster recovery&lt;/p&gt;&lt;p&gt; • Supplier and third-party incident preparedness&lt;/p&gt;&lt;p&gt; • Executive decision-making under uncertainty&lt;/p&gt;&lt;p&gt; • Why employees must feel safe reporting mistakes quickly&lt;/p&gt;&lt;p&gt; • Tabletop exercises that actually test the organization&lt;/p&gt;&lt;p&gt; • Turning incident lessons into real control improvements&lt;/p&gt;&lt;p&gt; • Feeding incidents back into GRC and risk management&lt;/p&gt;&lt;p&gt; • Why repeated incidents reveal governance problems&lt;/p&gt;&lt;p&gt; • Building resilience before the crisis&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;One of the central ideas of EP007: &lt;strong&gt;Your response capability is built before the incident. The alert only reveals what you already prepared.&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;Because a good incident response capability is not defined by how impressive the plan looks.&lt;/p&gt;&lt;p&gt;It is defined by how effectively the organization can &lt;strong&gt;decide, coordinate, contain, communicate, recover, and learn when reality refuses to follow the plan.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
                
                <enclosure length="27743712" type="audio/mpeg" url="https://audio4.redcircle.com/episodes/6dafbf9a-90c9-4415-98d1-006654025739/stream.mp3"/>
                
                <guid isPermaLink="false">9cc89047-dee6-43d6-bd78-3057b10a42c2</guid>
                <link>https://www.taheramine.org/podcast.html</link>
                <pubDate>Sun, 16 Aug 2026 07:30:52 &#43;0000</pubDate>
                <itunes:image href="https://media.redcircle.com/images/2026/8/15/1/45ed84af-bf68-4e98-833d-316c1bedae7e__response_starts_before_the_incident_2400x2400.jpg"/>
                <itunes:duration>1733</itunes:duration>
                
                
                <itunes:explicit>false</itunes:explicit>
                
            </item>
        
            <item>
                <itunes:episodeType>full</itunes:episodeType>
                <itunes:title>EP006: Your Policy Is Not a Control</itunes:title>
                <title>EP006: Your Policy Is Not a Control</title>

                <itunes:episode>6</itunes:episode>
                <itunes:season>1</itunes:season>
                <itunes:author>Taher Amine ELHOUARI</itunes:author>
                <itunes:subtitle>Why security policies fail when they never become behavior, enforcement, evidence, and accountability.</itunes:subtitle>
                <itunes:summary>Taher Amine ELHOUARI explores why having an approved security policy does not automatically mean an organization has control, and how policies must be translated into real behavior, ownership, technical enforcement, evidence, monitoring, and accountability.</itunes:summary>
                <description><![CDATA[<p>In EP006 of <strong>The InfoSec Control Room</strong>, Taher Amine ELHOUARI takes on one of the most common misconceptions in information security governance:</p><p><strong>Having a policy does not mean you have a control.</strong></p><p>An organization can have approved information security policies, access control requirements, data classification rules, acceptable-use standards, incident procedures, and beautifully version-controlled documents — while real behavior tells a completely different story.</p><p>A policy may say privileged access must be restricted.</p><p>But who enforces it?</p><p>A policy may say confidential information must be protected.</p><p>But do employees know what that means when they actually handle the data?</p><p>A policy may say incidents must be reported immediately.</p><p>But does everyone know where, how, and to whom?</p><p>This episode explores the gap between <strong>management intent and operational reality</strong>.</p><p>Taher discusses why security policies only create value when they are translated into usable processes, technical controls, ownership, monitoring, evidence, enforcement, and behavior.</p><p>The episode also challenges the tendency to respond to every security problem by creating yet another document.</p><p>Because sometimes the organization does not need another policy.</p><p>It needs to enforce the ones it already has.</p><p><strong><u>Topics include:</u></strong></p><p>• Why a policy is not automatically a control</p><p> • Turning policy requirements into operational mechanisms</p><p> • The difference between documented intent and real behavior</p><p> • Why secure behavior must also be practical behavior</p><p> • Policy requirements versus technical enforcement</p><p> • Data classification beyond labels</p><p> • Acceptable-use policies people actually understand</p><p> • Why leadership behavior can override written policy</p><p> • Policy inflation and document overload</p><p> • Security culture and management accountability</p><p> • Why exceptions need governance and expiry dates</p><p> • Enforcement without creating a fear culture</p><p> • Evidence that proves policies are actually implemented</p><p> • Testing policies through audits, sampling, metrics, incidents, and exercises</p><p> • Making secure behavior easier than insecure workarounds</p><p> • Why control ownership matters</p><p> • Moving from policy → control → evidence → monitoring → governance</p><p>One of the core ideas of this episode:</p><p><strong>A policy tells the organization what it expects. A control makes that expectation real.</strong></p><p>And when the policy says one thing while systems, processes, incentives, and management behavior say another, operational reality will win every time.</p>]]></description>
                <content:encoded>&lt;p&gt;In EP006 of &lt;strong&gt;The InfoSec Control Room&lt;/strong&gt;, Taher Amine ELHOUARI takes on one of the most common misconceptions in information security governance:&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Having a policy does not mean you have a control.&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;An organization can have approved information security policies, access control requirements, data classification rules, acceptable-use standards, incident procedures, and beautifully version-controlled documents — while real behavior tells a completely different story.&lt;/p&gt;&lt;p&gt;A policy may say privileged access must be restricted.&lt;/p&gt;&lt;p&gt;But who enforces it?&lt;/p&gt;&lt;p&gt;A policy may say confidential information must be protected.&lt;/p&gt;&lt;p&gt;But do employees know what that means when they actually handle the data?&lt;/p&gt;&lt;p&gt;A policy may say incidents must be reported immediately.&lt;/p&gt;&lt;p&gt;But does everyone know where, how, and to whom?&lt;/p&gt;&lt;p&gt;This episode explores the gap between &lt;strong&gt;management intent and operational reality&lt;/strong&gt;.&lt;/p&gt;&lt;p&gt;Taher discusses why security policies only create value when they are translated into usable processes, technical controls, ownership, monitoring, evidence, enforcement, and behavior.&lt;/p&gt;&lt;p&gt;The episode also challenges the tendency to respond to every security problem by creating yet another document.&lt;/p&gt;&lt;p&gt;Because sometimes the organization does not need another policy.&lt;/p&gt;&lt;p&gt;It needs to enforce the ones it already has.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;u&gt;Topics include:&lt;/u&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;• Why a policy is not automatically a control&lt;/p&gt;&lt;p&gt; • Turning policy requirements into operational mechanisms&lt;/p&gt;&lt;p&gt; • The difference between documented intent and real behavior&lt;/p&gt;&lt;p&gt; • Why secure behavior must also be practical behavior&lt;/p&gt;&lt;p&gt; • Policy requirements versus technical enforcement&lt;/p&gt;&lt;p&gt; • Data classification beyond labels&lt;/p&gt;&lt;p&gt; • Acceptable-use policies people actually understand&lt;/p&gt;&lt;p&gt; • Why leadership behavior can override written policy&lt;/p&gt;&lt;p&gt; • Policy inflation and document overload&lt;/p&gt;&lt;p&gt; • Security culture and management accountability&lt;/p&gt;&lt;p&gt; • Why exceptions need governance and expiry dates&lt;/p&gt;&lt;p&gt; • Enforcement without creating a fear culture&lt;/p&gt;&lt;p&gt; • Evidence that proves policies are actually implemented&lt;/p&gt;&lt;p&gt; • Testing policies through audits, sampling, metrics, incidents, and exercises&lt;/p&gt;&lt;p&gt; • Making secure behavior easier than insecure workarounds&lt;/p&gt;&lt;p&gt; • Why control ownership matters&lt;/p&gt;&lt;p&gt; • Moving from policy → control → evidence → monitoring → governance&lt;/p&gt;&lt;p&gt;One of the core ideas of this episode:&lt;/p&gt;&lt;p&gt;&lt;strong&gt;A policy tells the organization what it expects. A control makes that expectation real.&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;And when the policy says one thing while systems, processes, incentives, and management behavior say another, operational reality will win every time.&lt;/p&gt;</content:encoded>
                
                <enclosure length="23424104" type="audio/mpeg" url="https://audio4.redcircle.com/episodes/3a8743d0-8801-4204-ab5f-3e216ea3e457/stream.mp3"/>
                
                <guid isPermaLink="false">8143864c-be11-4f3d-b9fd-d46e633903ca</guid>
                <link>https://www.taheramine.org/podcast.html</link>
                <pubDate>Sat, 15 Aug 2026 08:30:32 &#43;0000</pubDate>
                <itunes:image href="https://media.redcircle.com/images/2026/8/14/23/eb27bcf0-250b-47d8-ac4f-9f011ec89fb0_ep006_your_policy_is_not_a_control_2400x2400.jpg"/>
                <itunes:duration>1464</itunes:duration>
                
                
                <itunes:explicit>false</itunes:explicit>
                
            </item>
        
            <item>
                <itunes:episodeType>full</itunes:episodeType>
                <itunes:title>EP005: GRC and SecOps Are Speaking Different Languages</itunes:title>
                <title>EP005: GRC and SecOps Are Speaking Different Languages</title>

                <itunes:episode>5</itunes:episode>
                <itunes:season>1</itunes:season>
                <itunes:author>Taher Amine ELHOUARI</itunes:author>
                <itunes:subtitle>Why governance without operational reality is blind — and security operations without governance loses context.</itunes:subtitle>
                <itunes:summary>Taher Amine ELHOUARI explores why GRC and SecOps must stop operating as separate worlds, and how connecting governance context with SOC and CSIRT operational evidence can improve control effectiveness, risk management, audit assurance, incident response, and executive decision-making.</itunes:summary>
                <description><![CDATA[<p>In EP005 of <strong>The InfoSec Control Room</strong>, Taher Amine ELHOUARI explores one of the most important — and often underestimated — relationships inside a cybersecurity program: the connection between <strong>GRC and Security Operations</strong>.</p><p><br></p><p>In many organizations, GRC and SecOps behave like two neighboring countries.</p><p>GRC speaks in controls, policies, risk registers, audit findings, evidence, compliance obligations, and assurance.</p><p>SecOps speaks in alerts, detections, incidents, vulnerabilities, threat intelligence, EDR, SIEM, containment, and response.</p><p>Both teams may be doing good work.</p><p>But if they are not exchanging context, evidence, and operational reality, the organization never gets a complete picture of its cyber risk.</p><p>This episode looks at what happens when governance is disconnected from operations — and when security operations operate without enough business and risk context.</p><p>Taher explains why operational telemetry should become governance evidence, why GRC should consume real SOC and CSIRT data, and why SecOps needs business criticality, asset classification, risk appetite, regulatory obligations, and control objectives to properly prioritize what matters.</p><p>The episode also explores how this relationship improves audit quality, incident response, risk assessment, control effectiveness, management reporting, and cybersecurity decision-making.</p><p><br></p><p><strong><u>Topics include:</u></strong></p><p>• Why GRC and SecOps often operate in separate worlds</p><p> • The difference between operational data and governance information</p><p> • Turning SOC telemetry into control-effectiveness evidence</p><p> • Why GRC needs operational reality</p><p> • Why SecOps needs business and risk context</p><p> • Connecting incidents with risk management</p><p> • Using detection and response data during audits</p><p> • Asset criticality and business impact in SOC prioritization</p><p> • Logging and monitoring as living controls</p><p> • GRC, SOC and CSIRT alignment during incidents</p><p> • Why “92% compliant” can still hide serious exposure</p><p> • Translating technical findings into management decisions</p><p> • Metrics that support decisions instead of decorating dashboards</p><p> • Evidence generated by normal operations</p><p> • Integrating audit findings, incidents, vulnerabilities and risk</p><p> • Building a common language between technical and governance teams</p><p> • Why cybersecurity reporting should become one shared picture</p><p><br></p><p>One of the central ideas of this episode is simple:</p><p><strong>GRC provides context. SecOps provides reality. Mature cybersecurity happens when the two meet.</strong></p><p><br></p><p>Because a governance team without operational visibility is partially blind.</p><p>And a SOC without governance context may be incredibly busy while still struggling to determine what matters most.</p>]]></description>
                <content:encoded>&lt;p&gt;In EP005 of &lt;strong&gt;The InfoSec Control Room&lt;/strong&gt;, Taher Amine ELHOUARI explores one of the most important — and often underestimated — relationships inside a cybersecurity program: the connection between &lt;strong&gt;GRC and Security Operations&lt;/strong&gt;.&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;In many organizations, GRC and SecOps behave like two neighboring countries.&lt;/p&gt;&lt;p&gt;GRC speaks in controls, policies, risk registers, audit findings, evidence, compliance obligations, and assurance.&lt;/p&gt;&lt;p&gt;SecOps speaks in alerts, detections, incidents, vulnerabilities, threat intelligence, EDR, SIEM, containment, and response.&lt;/p&gt;&lt;p&gt;Both teams may be doing good work.&lt;/p&gt;&lt;p&gt;But if they are not exchanging context, evidence, and operational reality, the organization never gets a complete picture of its cyber risk.&lt;/p&gt;&lt;p&gt;This episode looks at what happens when governance is disconnected from operations — and when security operations operate without enough business and risk context.&lt;/p&gt;&lt;p&gt;Taher explains why operational telemetry should become governance evidence, why GRC should consume real SOC and CSIRT data, and why SecOps needs business criticality, asset classification, risk appetite, regulatory obligations, and control objectives to properly prioritize what matters.&lt;/p&gt;&lt;p&gt;The episode also explores how this relationship improves audit quality, incident response, risk assessment, control effectiveness, management reporting, and cybersecurity decision-making.&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;u&gt;Topics include:&lt;/u&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;• Why GRC and SecOps often operate in separate worlds&lt;/p&gt;&lt;p&gt; • The difference between operational data and governance information&lt;/p&gt;&lt;p&gt; • Turning SOC telemetry into control-effectiveness evidence&lt;/p&gt;&lt;p&gt; • Why GRC needs operational reality&lt;/p&gt;&lt;p&gt; • Why SecOps needs business and risk context&lt;/p&gt;&lt;p&gt; • Connecting incidents with risk management&lt;/p&gt;&lt;p&gt; • Using detection and response data during audits&lt;/p&gt;&lt;p&gt; • Asset criticality and business impact in SOC prioritization&lt;/p&gt;&lt;p&gt; • Logging and monitoring as living controls&lt;/p&gt;&lt;p&gt; • GRC, SOC and CSIRT alignment during incidents&lt;/p&gt;&lt;p&gt; • Why “92% compliant” can still hide serious exposure&lt;/p&gt;&lt;p&gt; • Translating technical findings into management decisions&lt;/p&gt;&lt;p&gt; • Metrics that support decisions instead of decorating dashboards&lt;/p&gt;&lt;p&gt; • Evidence generated by normal operations&lt;/p&gt;&lt;p&gt; • Integrating audit findings, incidents, vulnerabilities and risk&lt;/p&gt;&lt;p&gt; • Building a common language between technical and governance teams&lt;/p&gt;&lt;p&gt; • Why cybersecurity reporting should become one shared picture&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;One of the central ideas of this episode is simple:&lt;/p&gt;&lt;p&gt;&lt;strong&gt;GRC provides context. SecOps provides reality. Mature cybersecurity happens when the two meet.&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;Because a governance team without operational visibility is partially blind.&lt;/p&gt;&lt;p&gt;And a SOC without governance context may be incredibly busy while still struggling to determine what matters most.&lt;/p&gt;</content:encoded>
                
                <enclosure length="24952163" type="audio/mpeg" url="https://audio4.redcircle.com/episodes/a7811e5e-c4ba-4167-a798-3f0ddf7d20a3/stream.mp3"/>
                
                <guid isPermaLink="false">1cf6e43d-de01-41a2-92e3-6b7cb5ba951d</guid>
                <link>https://www.taheramine.org/podcast.html</link>
                <pubDate>Fri, 14 Aug 2026 16:00:30 &#43;0000</pubDate>
                <itunes:image href="https://media.redcircle.com/images/2026/8/13/1/290e714b-e71c-4b0b-a2cc-fbcaba37a0de_ops_are_speaking_different_languages_2400x2400.jpg"/>
                <itunes:duration>1559</itunes:duration>
                
                
                <itunes:explicit>false</itunes:explicit>
                
            </item>
        
            <item>
                <itunes:episodeType>full</itunes:episodeType>
                <itunes:title>EP004: The CISO Is Not a Superhero</itunes:title>
                <title>EP004: The CISO Is Not a Superhero</title>

                <itunes:episode>4</itunes:episode>
                <itunes:season>1</itunes:season>
                <itunes:author>Taher Amine ELHOUARI</itunes:author>
                <itunes:subtitle>Why cyber accountability cannot sit with one person.</itunes:subtitle>
                <itunes:summary>Cybersecurity cannot be owned by one job title. Taher Amine ELHOUARI explores what a CISO should actually be responsible for, why business and risk ownership must remain distributed across the organization, and how the CISO can act as a governance architect connecting security, operations, management, and executive decision-making.</itunes:summary>
                <description><![CDATA[<p>In EP004 of <strong>The InfoSec Control Room</strong>, Taher Amine ELHOUARI challenges one of the most common and damaging assumptions in cybersecurity governance:</p><p><strong>“We have a CISO. Cybersecurity is their responsibility.”</strong></p><p>It sounds reasonable until you start asking who actually creates, owns, accepts, and manages cyber risk across an organization.</p><p>A business unit launches an application without involving security. Procurement signs a critical supplier contract without proper security requirements. Finance delays funding for a legacy-system replacement. HR does not trigger offboarding quickly enough. A business owner decides that remediation can wait because downtime would affect operations.</p><p>And when something eventually goes wrong, everyone turns toward the CISO.</p><p>This episode explores why that model is not cybersecurity governance — it is accountability concentrated in a job title.</p><p>Taher explains the difference between <strong>leading a cybersecurity program and personally owning every cyber risk</strong>, and why mature organizations distribute responsibility across executives, business owners, technology teams, control owners, risk owners, HR, procurement, legal, operations, and security.</p><p>The CISO’s role is not to become the organization’s cybersecurity superhero.</p><p>It is to help design the system through which cybersecurity is governed.</p><p><br></p><p><strong><u>Topics include:</u></strong></p><p>• What a CISO should actually be accountable for</p><p> • The difference between security leadership and risk ownership</p><p> • Why business owners must own business risk</p><p> • Responsibility without authority</p><p> • Control ownership versus security oversight</p><p> • Why CISOs become convenient cybersecurity scapegoats</p><p> • Building cybersecurity as an organizational capability</p><p> • The CISO as a governance architect</p><p> • Translating technical findings into executive decisions</p><p> • Risk acceptance and escalation</p><p> • Why security should not approve everything</p><p> • Distributed ownership and scalable security</p><p> • Board and executive responsibilities for cyber risk</p><p> • Incident governance and decision authority</p><p> • Why mature security programs should survive without individual heroes</p><p><br></p><p>One of the central ideas of the episode:</p><p><strong>The CISO does not own every cyber risk. The CISO helps the organization understand, govern, and manage cyber risk.</strong></p><p>Because if one person is responsible for everything while controlling almost nothing, that is not governance.</p><p>That is a very stressed person with an impressive job title.</p>]]></description>
                <content:encoded>&lt;p&gt;In EP004 of &lt;strong&gt;The InfoSec Control Room&lt;/strong&gt;, Taher Amine ELHOUARI challenges one of the most common and damaging assumptions in cybersecurity governance:&lt;/p&gt;&lt;p&gt;&lt;strong&gt;“We have a CISO. Cybersecurity is their responsibility.”&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;It sounds reasonable until you start asking who actually creates, owns, accepts, and manages cyber risk across an organization.&lt;/p&gt;&lt;p&gt;A business unit launches an application without involving security. Procurement signs a critical supplier contract without proper security requirements. Finance delays funding for a legacy-system replacement. HR does not trigger offboarding quickly enough. A business owner decides that remediation can wait because downtime would affect operations.&lt;/p&gt;&lt;p&gt;And when something eventually goes wrong, everyone turns toward the CISO.&lt;/p&gt;&lt;p&gt;This episode explores why that model is not cybersecurity governance — it is accountability concentrated in a job title.&lt;/p&gt;&lt;p&gt;Taher explains the difference between &lt;strong&gt;leading a cybersecurity program and personally owning every cyber risk&lt;/strong&gt;, and why mature organizations distribute responsibility across executives, business owners, technology teams, control owners, risk owners, HR, procurement, legal, operations, and security.&lt;/p&gt;&lt;p&gt;The CISO’s role is not to become the organization’s cybersecurity superhero.&lt;/p&gt;&lt;p&gt;It is to help design the system through which cybersecurity is governed.&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;u&gt;Topics include:&lt;/u&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;• What a CISO should actually be accountable for&lt;/p&gt;&lt;p&gt; • The difference between security leadership and risk ownership&lt;/p&gt;&lt;p&gt; • Why business owners must own business risk&lt;/p&gt;&lt;p&gt; • Responsibility without authority&lt;/p&gt;&lt;p&gt; • Control ownership versus security oversight&lt;/p&gt;&lt;p&gt; • Why CISOs become convenient cybersecurity scapegoats&lt;/p&gt;&lt;p&gt; • Building cybersecurity as an organizational capability&lt;/p&gt;&lt;p&gt; • The CISO as a governance architect&lt;/p&gt;&lt;p&gt; • Translating technical findings into executive decisions&lt;/p&gt;&lt;p&gt; • Risk acceptance and escalation&lt;/p&gt;&lt;p&gt; • Why security should not approve everything&lt;/p&gt;&lt;p&gt; • Distributed ownership and scalable security&lt;/p&gt;&lt;p&gt; • Board and executive responsibilities for cyber risk&lt;/p&gt;&lt;p&gt; • Incident governance and decision authority&lt;/p&gt;&lt;p&gt; • Why mature security programs should survive without individual heroes&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;One of the central ideas of the episode:&lt;/p&gt;&lt;p&gt;&lt;strong&gt;The CISO does not own every cyber risk. The CISO helps the organization understand, govern, and manage cyber risk.&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;Because if one person is responsible for everything while controlling almost nothing, that is not governance.&lt;/p&gt;&lt;p&gt;That is a very stressed person with an impressive job title.&lt;/p&gt;</content:encoded>
                
                <enclosure length="23220976" type="audio/mpeg" url="https://audio4.redcircle.com/episodes/0f3df11a-24fb-41d6-b8f6-4ba2492294f7/stream.mp3"/>
                
                <guid isPermaLink="false">35ae623e-e034-4257-bb8a-8b790cc7d6ad</guid>
                <link>https://www.taheramine.org/podcast.html</link>
                <pubDate>Thu, 13 Aug 2026 09:00:30 &#43;0000</pubDate>
                <itunes:image href="https://media.redcircle.com/images/2026/8/12/21/31355fa6-43ff-44e4-9173-068ba816fcd7_ep004_the_ciso_is_not_a_superhero_2400x2400.jpg"/>
                <itunes:duration>1451</itunes:duration>
                
                
                <itunes:explicit>false</itunes:explicit>
                
            </item>
        
            <item>
                <itunes:episodeType>full</itunes:episodeType>
                <itunes:title>EP003: Compliance Is Not Control</itunes:title>
                <title>EP003: Compliance Is Not Control</title>

                <itunes:episode>3</itunes:episode>
                <itunes:season>1</itunes:season>
                <itunes:author>Taher Amine ELHOUARI</itunes:author>
                <itunes:subtitle>Why passing an audit does not always mean you are in control.</itunes:subtitle>
                <itunes:summary>Compliance is not the same as control. Taher Amine ELHOUARI explores why passing audits, maintaining policies, and achieving certification do not automatically prove security effectiveness; and how organizations can move from checkbox compliance to real control, evidence, assurance, and resilience.</itunes:summary>
                <description><![CDATA[<p>In EP003 of <strong>The InfoSec Control Room</strong>, Taher Amine ELHOUARI explores the uncomfortable gap between being compliant and actually being in control.</p><p>An organization can have approved policies, completed audits, risk registers, procedures, evidence, management reviews, and even certifications on the wall; while still struggling to answer very simple questions:</p><ul><li>Can we actually restore our critical systems?</li><li> Who really owns this risk?</li><li> Are our controls operating consistently?</li><li> Does our evidence reflect reality, or was it prepared because an audit was coming?</li></ul><p>This episode is not an argument against compliance. Quite the opposite.</p><p>Compliance, standards, audits, certification, and structured management systems can create tremendous value when they support real governance, risk management, accountability, and continuous improvement.</p><p>The problem starts when the objective quietly changes from:</p><p><strong>“Are we improving security?”</strong></p><p>to:</p><p><strong>“Will we pass the audit?”</strong></p><p>Taher discusses what he calls <strong>audit-season security</strong>, why a policy is not automatically a control, why evidence should be produced by normal operations rather than reconstructed before an audit, and why certification should be understood as part of a living management system rather than the finish line.</p><p>The episode also explores the practical relationship between compliance, audit, GRC, SecOps, management, and technical teams; and why all of them need to work from the same operational reality.</p><p><br></p><p><strong><u>Topics include:</u></strong></p><p>• Compliance versus control</p><p> • Conformity versus operating effectiveness</p><p> • Audit-season security</p><p> • Why documentation alone does not create maturity</p><p> • Evidence by design</p><p> • Control ownership and risk ownership</p><p> • Internal audit as a tool for improvement</p><p> • Repeated findings and root-cause thinking</p><p> • Making management reviews actually produce decisions</p><p> • Connecting GRC with SOC, CSIRT, and operational security</p><p> • Why compliance percentages can create false comfort</p><p> • Turning certification into continuous assurance</p><p> • Moving from requirements to control, evidence, assurance, and resilience</p><p><br></p><p>The key question of the episode is simple:</p><p><strong>Compliance can tell you what should happen. Control tells you what happens.</strong></p><p>So the next time someone says, <em>“We are compliant,”</em> ask one more question:</p><p><strong>“How do we know we are actually in control?”</strong></p>]]></description>
                <content:encoded>&lt;p&gt;In EP003 of &lt;strong&gt;The InfoSec Control Room&lt;/strong&gt;, Taher Amine ELHOUARI explores the uncomfortable gap between being compliant and actually being in control.&lt;/p&gt;&lt;p&gt;An organization can have approved policies, completed audits, risk registers, procedures, evidence, management reviews, and even certifications on the wall; while still struggling to answer very simple questions:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Can we actually restore our critical systems?&lt;/li&gt;&lt;li&gt; Who really owns this risk?&lt;/li&gt;&lt;li&gt; Are our controls operating consistently?&lt;/li&gt;&lt;li&gt; Does our evidence reflect reality, or was it prepared because an audit was coming?&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;This episode is not an argument against compliance. Quite the opposite.&lt;/p&gt;&lt;p&gt;Compliance, standards, audits, certification, and structured management systems can create tremendous value when they support real governance, risk management, accountability, and continuous improvement.&lt;/p&gt;&lt;p&gt;The problem starts when the objective quietly changes from:&lt;/p&gt;&lt;p&gt;&lt;strong&gt;“Are we improving security?”&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;to:&lt;/p&gt;&lt;p&gt;&lt;strong&gt;“Will we pass the audit?”&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;Taher discusses what he calls &lt;strong&gt;audit-season security&lt;/strong&gt;, why a policy is not automatically a control, why evidence should be produced by normal operations rather than reconstructed before an audit, and why certification should be understood as part of a living management system rather than the finish line.&lt;/p&gt;&lt;p&gt;The episode also explores the practical relationship between compliance, audit, GRC, SecOps, management, and technical teams; and why all of them need to work from the same operational reality.&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;u&gt;Topics include:&lt;/u&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;• Compliance versus control&lt;/p&gt;&lt;p&gt; • Conformity versus operating effectiveness&lt;/p&gt;&lt;p&gt; • Audit-season security&lt;/p&gt;&lt;p&gt; • Why documentation alone does not create maturity&lt;/p&gt;&lt;p&gt; • Evidence by design&lt;/p&gt;&lt;p&gt; • Control ownership and risk ownership&lt;/p&gt;&lt;p&gt; • Internal audit as a tool for improvement&lt;/p&gt;&lt;p&gt; • Repeated findings and root-cause thinking&lt;/p&gt;&lt;p&gt; • Making management reviews actually produce decisions&lt;/p&gt;&lt;p&gt; • Connecting GRC with SOC, CSIRT, and operational security&lt;/p&gt;&lt;p&gt; • Why compliance percentages can create false comfort&lt;/p&gt;&lt;p&gt; • Turning certification into continuous assurance&lt;/p&gt;&lt;p&gt; • Moving from requirements to control, evidence, assurance, and resilience&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;The key question of the episode is simple:&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Compliance can tell you what should happen. Control tells you what happens.&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;So the next time someone says, &lt;em&gt;“We are compliant,”&lt;/em&gt; ask one more question:&lt;/p&gt;&lt;p&gt;&lt;strong&gt;“How do we know we are actually in control?”&lt;/strong&gt;&lt;/p&gt;</content:encoded>
                
                <enclosure length="32254746" type="audio/mpeg" url="https://audio4.redcircle.com/episodes/568794b7-c866-4f02-8a4b-ef8f5e60841e/stream.mp3"/>
                
                <guid isPermaLink="false">9dc311d0-1f15-4fb7-9a51-e361afe6bd30</guid>
                <link>https://www.taheramine.org/podcast.html</link>
                <pubDate>Wed, 12 Aug 2026 20:05:03 &#43;0000</pubDate>
                <itunes:image href="https://media.redcircle.com/images/2026/8/12/20/ce3044c5-b80e-4866-9a36-bb4c6764f17d_ep003_compliance_is_not_control_2400x2400.jpg"/>
                <itunes:duration>2015</itunes:duration>
                
                
                <itunes:explicit>false</itunes:explicit>
                
            </item>
        
            <item>
                <itunes:episodeType>full</itunes:episodeType>
                <itunes:title>EP002: The Real Reason Security Programs Fail</itunes:title>
                <title>EP002: The Real Reason Security Programs Fail</title>

                <itunes:episode>2</itunes:episode>
                <itunes:season>1</itunes:season>
                <itunes:author>Taher Amine ELHOUARI</itunes:author>
                <itunes:subtitle>Why governance failures become security failures.</itunes:subtitle>
                <itunes:summary>Taher Amine ELHOUARI explains why many security programs fail for reasons that are not purely technical, exploring governance gaps, weak ownership, poor risk decisions, ineffective controls, compliance theater, and the difference between security activity and real security capability.</itunes:summary>
                <description><![CDATA[<p>In this episode of The InfoSec Control Room, Taher Amine ELHOUARI explores one of the core ideas behind the podcast: many security programs do not fail because there is no cybersecurity activity. They fail because that activity is not governed, owned, measured, or improved properly.</p><p><br></p><p>The episode explains why security failures are often symptoms of deeper structural issues: unclear accountability, weak ownership, poor risk decisions, ineffective controls, disconnected teams, compliance theater, weak escalation, and the gap between documentation and real operational capability.</p><p><br></p><p>Rather than blaming tools, users, auditors, SOC teams, or CISOs alone, this episode looks at the full system behind security programs and asks a more important question: why did the organization allow the weakness to exist, persist, and become dangerous?</p><p><br></p><p>Topics include:</p><p>• Why security failures are rarely purely technical</p><p>• The difference between security activity and security capability</p><p>• Governance gaps behind incidents and audit failures</p><p>• Ownership, accountability, and risk decisions</p><p>• Why tools cannot compensate for weak governance</p><p>• Compliance theater and false maturity</p><p>• The gap between policies, controls, and real behavior</p><p>• How technical, GRC, SOC, CSIRT, management, and executive teams become disconnected</p><p>• What security programs need in order to actually work</p><p><br></p><p>No noise. No fake maturity. No checkbox security.</p><p><br></p><p>Just practical conversations on how security is governed, controlled, measured, and improved.</p>]]></description>
                <content:encoded>&lt;p&gt;In this episode of The InfoSec Control Room, Taher Amine ELHOUARI explores one of the core ideas behind the podcast: many security programs do not fail because there is no cybersecurity activity. They fail because that activity is not governed, owned, measured, or improved properly.&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;The episode explains why security failures are often symptoms of deeper structural issues: unclear accountability, weak ownership, poor risk decisions, ineffective controls, disconnected teams, compliance theater, weak escalation, and the gap between documentation and real operational capability.&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;Rather than blaming tools, users, auditors, SOC teams, or CISOs alone, this episode looks at the full system behind security programs and asks a more important question: why did the organization allow the weakness to exist, persist, and become dangerous?&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;Topics include:&lt;/p&gt;&lt;p&gt;• Why security failures are rarely purely technical&lt;/p&gt;&lt;p&gt;• The difference between security activity and security capability&lt;/p&gt;&lt;p&gt;• Governance gaps behind incidents and audit failures&lt;/p&gt;&lt;p&gt;• Ownership, accountability, and risk decisions&lt;/p&gt;&lt;p&gt;• Why tools cannot compensate for weak governance&lt;/p&gt;&lt;p&gt;• Compliance theater and false maturity&lt;/p&gt;&lt;p&gt;• The gap between policies, controls, and real behavior&lt;/p&gt;&lt;p&gt;• How technical, GRC, SOC, CSIRT, management, and executive teams become disconnected&lt;/p&gt;&lt;p&gt;• What security programs need in order to actually work&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;No noise. No fake maturity. No checkbox security.&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;Just practical conversations on how security is governed, controlled, measured, and improved.&lt;/p&gt;</content:encoded>
                
                <enclosure length="28823301" type="audio/mpeg" url="https://audio4.redcircle.com/episodes/318ec9a2-90a1-4680-b2bf-c4eb5282cd67/stream.mp3"/>
                
                <guid isPermaLink="false">e8cdc653-41cb-4d59-afea-1890561a8521</guid>
                <link>https://www.taheramine.org/podcast.html</link>
                <pubDate>Wed, 12 Aug 2026 01:20:20 &#43;0000</pubDate>
                <itunes:image href="https://media.redcircle.com/images/2026/8/12/1/97c06d02-b9b4-44d2-b90e-5a5d0b40ebd7_al_reason_security_programs_fail_2400x2400__1_.jpg"/>
                <itunes:duration>1801</itunes:duration>
                
                
                <itunes:explicit>false</itunes:explicit>
                
            </item>
        
            <item>
                <itunes:episodeType>full</itunes:episodeType>
                <itunes:title>EP001: Welcome to The InfoSec Control Room</itunes:title>
                <title>EP001: Welcome to The InfoSec Control Room</title>

                <itunes:episode>1</itunes:episode>
                <itunes:season>1</itunes:season>
                <itunes:author>Taher Amine ELHOUARI</itunes:author>
                <itunes:subtitle>The official opening episode introducing the podcast, the host, the mission, and the governance-first view behind The InfoSec Control Room.</itunes:subtitle>
                <itunes:summary>The official opening episode of The InfoSec Control Room, where Taher Amine ELHOUARI introduces the podcast, his background, the governance-first philosophy behind the show, and the mission of helping professionals understand how cybersecurity is governed, controlled, measured, and improved.</itunes:summary>
                <description><![CDATA[<p>In this first original episode of The InfoSec Control Room, Taher Amine ELHOUARI formally introduces the podcast, the story behind it, and the core philosophy that will guide future episodes.</p><p><br></p><p>This opening episode explains why The InfoSec Control Room exists, who it is for, and why cybersecurity must be understood beyond tools, incidents, vulnerabilities, frameworks, and technical controls.</p><p><br></p><p>Taher introduces his background across information security, cybersecurity governance, GRC, SecOps, CSIRT, audit, risk management, resilience, advisory, training, public speaking, and CISO-level decision-making. He also explains why many security programs fail not because they lack activity, but because they lack governance, ownership, accountability, evidence, discipline, and real control.</p><p><br></p><p>The episode sets the tone for the original series: practical, strategic, field-based, and built for engineers, experts, managers, auditors, GRC professionals, SOC and CSIRT teams, CISOs, executives, students, and decision-makers.</p><p><br></p><p><strong><u>Topics include:</u></strong></p><p>• The purpose behind The InfoSec Control Room</p><p>• Who Taher Amine ELHOUARI is and why he created the podcast</p><p>• Why cybersecurity is more than a technical discipline</p><p>• The difference between security activity and real security capability</p><p>• Governance as the root cause behind many security failures</p><p>• The gap between engineers, managers, auditors, executives, GRC, SOC, and CSIRT teams</p><p>• Why compliance, documentation, and tools are not enough</p><p>• What future original episodes will cover</p><p>• The mission of building security that is governed, controlled, measured, and improved</p><p><br></p><p>No noise. No fake maturity. No checkbox security.</p><p><br></p><p>Just practical conversations on how security is governed, controlled, measured, and improved.</p><p><br></p><p>https://www.taheramine.org/podcast.html</p>]]></description>
                <content:encoded>&lt;p&gt;In this first original episode of The InfoSec Control Room, Taher Amine ELHOUARI formally introduces the podcast, the story behind it, and the core philosophy that will guide future episodes.&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;This opening episode explains why The InfoSec Control Room exists, who it is for, and why cybersecurity must be understood beyond tools, incidents, vulnerabilities, frameworks, and technical controls.&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;Taher introduces his background across information security, cybersecurity governance, GRC, SecOps, CSIRT, audit, risk management, resilience, advisory, training, public speaking, and CISO-level decision-making. He also explains why many security programs fail not because they lack activity, but because they lack governance, ownership, accountability, evidence, discipline, and real control.&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;The episode sets the tone for the original series: practical, strategic, field-based, and built for engineers, experts, managers, auditors, GRC professionals, SOC and CSIRT teams, CISOs, executives, students, and decision-makers.&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;u&gt;Topics include:&lt;/u&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;• The purpose behind The InfoSec Control Room&lt;/p&gt;&lt;p&gt;• Who Taher Amine ELHOUARI is and why he created the podcast&lt;/p&gt;&lt;p&gt;• Why cybersecurity is more than a technical discipline&lt;/p&gt;&lt;p&gt;• The difference between security activity and real security capability&lt;/p&gt;&lt;p&gt;• Governance as the root cause behind many security failures&lt;/p&gt;&lt;p&gt;• The gap between engineers, managers, auditors, executives, GRC, SOC, and CSIRT teams&lt;/p&gt;&lt;p&gt;• Why compliance, documentation, and tools are not enough&lt;/p&gt;&lt;p&gt;• What future original episodes will cover&lt;/p&gt;&lt;p&gt;• The mission of building security that is governed, controlled, measured, and improved&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;No noise. No fake maturity. No checkbox security.&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;Just practical conversations on how security is governed, controlled, measured, and improved.&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;https://www.taheramine.org/podcast.html&lt;/p&gt;</content:encoded>
                
                <enclosure length="30440803" type="audio/mpeg" url="https://audio4.redcircle.com/episodes/f740c96b-224c-40cf-8100-2e27b567b870/stream.mp3"/>
                
                <guid isPermaLink="false">0ab211ea-8a47-421b-8393-a90e23d234c0</guid>
                <link>https://www.taheramine.org/podcast.html</link>
                <pubDate>Mon, 10 Aug 2026 23:50:47 &#43;0000</pubDate>
                <itunes:image href="https://media.redcircle.com/images/2026/8/10/23/7267fc45-2b7f-4669-9d8a-23b518336a9f_ep001_welcome_infosec_control_room_2400x2400.jpg"/>
                <itunes:duration>1902</itunes:duration>
                
                
                <itunes:explicit>false</itunes:explicit>
                
            </item>
        
            <item>
                <itunes:episodeType>bonus</itunes:episodeType>
                <itunes:title>Media Archive: Building Cyber Resilience Beyond Compliance | Full Webinar | Taher Amine ELHOUARI - iExperts</itunes:title>
                <title>Media Archive: Building Cyber Resilience Beyond Compliance | Full Webinar | Taher Amine ELHOUARI - iExperts</title>

                
                <itunes:season>1</itunes:season>
                <itunes:author>Taher Amine ELHOUARI</itunes:author>
                <itunes:summary>Compliance may demonstrate that cybersecurity controls exist, but resilience demonstrates that they work under pressure. In this complete iExperts webinar, Taher Amine ELHOUARI explains how organizations can connect governance, GRC, risk management, SOC and CSIRT operations, incident response, business continuity, recovery, and executive accountability within one practical cyber-resilience model.</itunes:summary>
                <description><![CDATA[<p>Compliance may demonstrate that security requirements have been addressed. Cyber resilience demonstrates that governance, people, processes, and technology can continue to operate under real pressure.</p><p>This special webinar edition of The InfoSec Control Room presents the complete audio recording of my latest iExperts session: <strong>BUILDING CYBER RESILIENCE BEYOND COMPLIANCE</strong>.</p><p>During this session, I examine why organizations can remain operationally fragile despite having policies, certifications, risk registers, control frameworks, and extensive compliance documentation.</p><p>The webinar explores how organizations can move beyond checkbox compliance and connect leadership accountability, cybersecurity governance, enterprise risk management, GRC, SOC and CSIRT operations, incident response, crisis management, business continuity, recovery, and continuous improvement within one coherent cyber-resilience model.</p><p><br></p><p><strong><u>KEY TOPICS:</u></strong></p><p>• The real difference between cybersecurity compliance and cyber resilience</p><p>• Why apparently compliant organizations may still fail during serious incidents</p><p>• Moving from documented controls to operational capability</p><p>• Executive accountability and cyber-risk ownership</p><p>• Transforming standards and frameworks into practical operating models</p><p>• Connecting GRC with SOC, CSIRT, and incident-response operations</p><p>• Business continuity, crisis management, recovery, and lessons learned</p><p>• Testing controls through simulations, exercises, and realistic scenarios</p><p>• Common cyber-resilience failure patterns</p><p>• Indicators and metrics that demonstrate genuine resilience</p><p>• A practical operating model and improvement roadmap</p><p>• Priority actions organizations can initiate during their first 30 days</p><p><br></p><p><strong><u>EPISODE TIMESTAMPS:</u></strong></p><p>00:00 Webinar Opening and Host Introduction</p><p>01:45 About Taher Amine ELHOUARI</p><p>03:36 Why Cyber Resilience Matters</p><p>06:55 The Compliance Trap</p><p>12:13 Compliance Mindset vs Resilience Mindset</p><p>16:01 What Cyber Resilience Really Means</p><p>19:59 Governance and Executive Accountability</p><p>23:28 Risk Management and Framework Operationalization</p><p>30:17 Incident Response, SOC, CSIRT, and GRC</p><p>36:42 Continuity, Recovery, Crisis Management, and Testing</p><p>41:35 Failure Patterns and the Resilience Maturity Curve</p><p>48:47 Practical Resilience Operating Model and Roadmap</p><p>52:03 Priority Actions for the First 30 Days</p><p>55:35 Key Takeaways</p><p>58:10 Audience Questions and Answers</p><p>65:19 Closing Remarks</p><p><br></p><p><strong><u>ABOUT THE SPEAKER:</u></strong></p><p>Taher Amine ELHOUARI is a Global Cyber Leader, Senior Advisor, Accredited Auditor, Certified Trainer, and holds over 300 certifications. He serves as CISO and Head of Advisory &amp; CSIRT at UNIDEES, with expertise spanning cybersecurity governance, GRC, risk management, auditing, advisory, security operations, incident response, SOC and CSIRT development, business continuity, operational resilience, and professional training.</p><p><br></p><p><strong><u>ORIGINAL WEBINAR:</u></strong></p><p>The session was originally hosted and publicly presented by iExperts on 29 July 2026.</p><p><br></p><p><strong><u>Watch the complete video:</u></strong></p><p>https://www.youtube.com/watch?v=qtqgWRv_qUI</p><p><br></p><p><strong><u>Learn more about the speaker:</u></strong></p><p>https://www.taheramine.org</p><p><br></p><p><strong><u>THE INFOSEC CONTROL ROOM</u></strong></p><p>The InfoSec Control Room explores cybersecurity governance, accountability, risk decisions, control effectiveness, resilience, leadership, and the operational realities behind information-security programs.</p><p><br></p><p>My sincere appreciation goes to the entire iExperts team for hosting the webinar and to every professional who attended, contributed questions, and enriched the discussion.</p>]]></description>
                <content:encoded>&lt;p&gt;Compliance may demonstrate that security requirements have been addressed. Cyber resilience demonstrates that governance, people, processes, and technology can continue to operate under real pressure.&lt;/p&gt;&lt;p&gt;This special webinar edition of The InfoSec Control Room presents the complete audio recording of my latest iExperts session: &lt;strong&gt;BUILDING CYBER RESILIENCE BEYOND COMPLIANCE&lt;/strong&gt;.&lt;/p&gt;&lt;p&gt;During this session, I examine why organizations can remain operationally fragile despite having policies, certifications, risk registers, control frameworks, and extensive compliance documentation.&lt;/p&gt;&lt;p&gt;The webinar explores how organizations can move beyond checkbox compliance and connect leadership accountability, cybersecurity governance, enterprise risk management, GRC, SOC and CSIRT operations, incident response, crisis management, business continuity, recovery, and continuous improvement within one coherent cyber-resilience model.&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;u&gt;KEY TOPICS:&lt;/u&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;• The real difference between cybersecurity compliance and cyber resilience&lt;/p&gt;&lt;p&gt;• Why apparently compliant organizations may still fail during serious incidents&lt;/p&gt;&lt;p&gt;• Moving from documented controls to operational capability&lt;/p&gt;&lt;p&gt;• Executive accountability and cyber-risk ownership&lt;/p&gt;&lt;p&gt;• Transforming standards and frameworks into practical operating models&lt;/p&gt;&lt;p&gt;• Connecting GRC with SOC, CSIRT, and incident-response operations&lt;/p&gt;&lt;p&gt;• Business continuity, crisis management, recovery, and lessons learned&lt;/p&gt;&lt;p&gt;• Testing controls through simulations, exercises, and realistic scenarios&lt;/p&gt;&lt;p&gt;• Common cyber-resilience failure patterns&lt;/p&gt;&lt;p&gt;• Indicators and metrics that demonstrate genuine resilience&lt;/p&gt;&lt;p&gt;• A practical operating model and improvement roadmap&lt;/p&gt;&lt;p&gt;• Priority actions organizations can initiate during their first 30 days&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;u&gt;EPISODE TIMESTAMPS:&lt;/u&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;00:00 Webinar Opening and Host Introduction&lt;/p&gt;&lt;p&gt;01:45 About Taher Amine ELHOUARI&lt;/p&gt;&lt;p&gt;03:36 Why Cyber Resilience Matters&lt;/p&gt;&lt;p&gt;06:55 The Compliance Trap&lt;/p&gt;&lt;p&gt;12:13 Compliance Mindset vs Resilience Mindset&lt;/p&gt;&lt;p&gt;16:01 What Cyber Resilience Really Means&lt;/p&gt;&lt;p&gt;19:59 Governance and Executive Accountability&lt;/p&gt;&lt;p&gt;23:28 Risk Management and Framework Operationalization&lt;/p&gt;&lt;p&gt;30:17 Incident Response, SOC, CSIRT, and GRC&lt;/p&gt;&lt;p&gt;36:42 Continuity, Recovery, Crisis Management, and Testing&lt;/p&gt;&lt;p&gt;41:35 Failure Patterns and the Resilience Maturity Curve&lt;/p&gt;&lt;p&gt;48:47 Practical Resilience Operating Model and Roadmap&lt;/p&gt;&lt;p&gt;52:03 Priority Actions for the First 30 Days&lt;/p&gt;&lt;p&gt;55:35 Key Takeaways&lt;/p&gt;&lt;p&gt;58:10 Audience Questions and Answers&lt;/p&gt;&lt;p&gt;65:19 Closing Remarks&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;u&gt;ABOUT THE SPEAKER:&lt;/u&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;Taher Amine ELHOUARI is a Global Cyber Leader, Senior Advisor, Accredited Auditor, Certified Trainer, and holds over 300 certifications. He serves as CISO and Head of Advisory &amp;amp; CSIRT at UNIDEES, with expertise spanning cybersecurity governance, GRC, risk management, auditing, advisory, security operations, incident response, SOC and CSIRT development, business continuity, operational resilience, and professional training.&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;u&gt;ORIGINAL WEBINAR:&lt;/u&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;The session was originally hosted and publicly presented by iExperts on 29 July 2026.&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;u&gt;Watch the complete video:&lt;/u&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;https://www.youtube.com/watch?v=qtqgWRv_qUI&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;u&gt;Learn more about the speaker:&lt;/u&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;https://www.taheramine.org&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;u&gt;THE INFOSEC CONTROL ROOM&lt;/u&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;The InfoSec Control Room explores cybersecurity governance, accountability, risk decisions, control effectiveness, resilience, leadership, and the operational realities behind information-security programs.&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;My sincere appreciation goes to the entire iExperts team for hosting the webinar and to every professional who attended, contributed questions, and enriched the discussion.&lt;/p&gt;</content:encoded>
                
                <enclosure length="63871686" type="audio/mpeg" url="https://audio4.redcircle.com/episodes/0817777e-ed5c-49b1-b71b-d694be0ac064/stream.mp3"/>
                
                <guid isPermaLink="false">98c911e4-db98-4bde-b046-7fe1f772e3ba</guid>
                <link>https://www.youtube.com/watch?v=K3r6vzl0ajk</link>
                <pubDate>Thu, 30 Jul 2026 14:00:32 &#43;0000</pubDate>
                <itunes:image href="https://media.redcircle.com/images/2026/7/30/16/a4899936-9c4c-47e2-9bc1-68d05f6b8857_the_infosec_control_room.jpg"/>
                <itunes:duration>3991</itunes:duration>
                
                
                <itunes:explicit>false</itunes:explicit>
                
            </item>
        
            <item>
                <itunes:episodeType>bonus</itunes:episodeType>
                <itunes:title>Media Archive:  Conformity Assessment Meets Cybersecurity | FIRST &amp; AfricaCERT Symposium 2025</itunes:title>
                <title>Media Archive:  Conformity Assessment Meets Cybersecurity | FIRST &amp; AfricaCERT Symposium 2025</title>

                
                <itunes:season>1</itunes:season>
                <itunes:author>Taher Amine ELHOUARI</itunes:author>
                <itunes:subtitle>A FIRST &amp; AfricaCERT Symposium talk on bridging auditors, analysts, assurance, SOC operations, and cyber resilience.</itunes:subtitle>
                <itunes:summary>A Media Archive episode featuring Taher Amine ELHOUARI’s FIRST &amp; AfricaCERT Symposium 2025 session in Mauritius, covering conformity assessment, cybersecurity assurance, audit evidence, SOC and CSIRT alignment, ISO standards, incident metrics, control effectiveness, and continuous cyber assurance.</itunes:summary>
                <description><![CDATA[<p>In this Media Archive episode of The InfoSec Control Room, Taher Amine ELHOUARI shares his conference session from the FIRST &amp; AfricaCERT Symposium 2025 in Mauritius: “Conformity Assessment Meets Cybersecurity: Building a Common Language Between Auditors and Analysts.”</p><p>This session explores one of the most important gaps in cybersecurity assurance: why organizations can appear compliant on paper while still struggling to detect, respond to, and contain real attacks. The discussion connects conformity assessment, certification audits, SOC operations, CSIRT response, security metrics, incident evidence, and governance maturity into one practical conversation. It shows how auditors, assessors, regulators, SOC analysts, and incident response teams can work from a shared language instead of operating in disconnected worlds.</p><p>Rather than treating compliance as a periodic checkbox exercise, this talk argues for continuous, evidence-driven cyber assurance — where operational telemetry, incident tickets, detection metrics, audit evidence, and control effectiveness become part of the same governance model.</p><p><strong><em>Original session:</em></strong><em> FIRST &amp; AfricaCERT Symposium 2025, Mauritius.</em></p><p><strong>Topics include:</strong></p><ul><li>Conformity assessment and cybersecurity</li><li>Audit and certification assurance</li><li>SOC and CSIRT alignment</li><li>ISO/IEC 27001, ISO/IEC 27006, ISO/IEC 27007, ISO/IEC 27008, and ISO/IEC 19011</li><li>ISO/IEC 27035 incident management lifecycle</li><li>Translating SOC telemetry into audit evidence</li><li>Measuring real control effectiveness</li><li>Mapping detection and incident response metrics to governance requirements</li><li>Continuous assurance models</li><li>Bridging GRC, SecOps, auditors, and analysts</li><li>AfricaCERT 3CF and regional cyber maturity</li></ul><p><strong><em>Note: </em></strong><em>This episode is adapted from a public conference session featuring Taher Amine ELHOUARI. All rights to the original recording remain with their respective owners.</em></p>]]></description>
                <content:encoded>&lt;p&gt;In this Media Archive episode of The InfoSec Control Room, Taher Amine ELHOUARI shares his conference session from the FIRST &amp;amp; AfricaCERT Symposium 2025 in Mauritius: “Conformity Assessment Meets Cybersecurity: Building a Common Language Between Auditors and Analysts.”&lt;/p&gt;&lt;p&gt;This session explores one of the most important gaps in cybersecurity assurance: why organizations can appear compliant on paper while still struggling to detect, respond to, and contain real attacks. The discussion connects conformity assessment, certification audits, SOC operations, CSIRT response, security metrics, incident evidence, and governance maturity into one practical conversation. It shows how auditors, assessors, regulators, SOC analysts, and incident response teams can work from a shared language instead of operating in disconnected worlds.&lt;/p&gt;&lt;p&gt;Rather than treating compliance as a periodic checkbox exercise, this talk argues for continuous, evidence-driven cyber assurance — where operational telemetry, incident tickets, detection metrics, audit evidence, and control effectiveness become part of the same governance model.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;em&gt;Original session:&lt;/em&gt;&lt;/strong&gt;&lt;em&gt; FIRST &amp;amp; AfricaCERT Symposium 2025, Mauritius.&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Topics include:&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Conformity assessment and cybersecurity&lt;/li&gt;&lt;li&gt;Audit and certification assurance&lt;/li&gt;&lt;li&gt;SOC and CSIRT alignment&lt;/li&gt;&lt;li&gt;ISO/IEC 27001, ISO/IEC 27006, ISO/IEC 27007, ISO/IEC 27008, and ISO/IEC 19011&lt;/li&gt;&lt;li&gt;ISO/IEC 27035 incident management lifecycle&lt;/li&gt;&lt;li&gt;Translating SOC telemetry into audit evidence&lt;/li&gt;&lt;li&gt;Measuring real control effectiveness&lt;/li&gt;&lt;li&gt;Mapping detection and incident response metrics to governance requirements&lt;/li&gt;&lt;li&gt;Continuous assurance models&lt;/li&gt;&lt;li&gt;Bridging GRC, SecOps, auditors, and analysts&lt;/li&gt;&lt;li&gt;AfricaCERT 3CF and regional cyber maturity&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;&lt;em&gt;Note: &lt;/em&gt;&lt;/strong&gt;&lt;em&gt;This episode is adapted from a public conference session featuring Taher Amine ELHOUARI. All rights to the original recording remain with their respective owners.&lt;/em&gt;&lt;/p&gt;</content:encoded>
                
                <enclosure length="26004166" type="audio/mpeg" url="https://audio4.redcircle.com/episodes/22236a8f-ed99-4ed2-bc59-aa0d69be9353/stream.mp3"/>
                
                <guid isPermaLink="false">233c6040-56de-4557-8eed-0837aa39e333</guid>
                <link>https://www.youtube.com/watch?v=_VMaHDLFSFk</link>
                <pubDate>Tue, 23 Jun 2026 16:00:59 &#43;0000</pubDate>
                <itunes:duration>1625</itunes:duration>
                
                
                <itunes:explicit>false</itunes:explicit>
                
            </item>
        
            <item>
                <itunes:episodeType>bonus</itunes:episodeType>
                <itunes:title>Media Archive: The Hidden Face of Cyber Extortion on Algerian National TV</itunes:title>
                <title>Media Archive: The Hidden Face of Cyber Extortion on Algerian National TV</title>

                
                <itunes:season>1</itunes:season>
                <itunes:author>Taher Amine ELHOUARI</itunes:author>
                <itunes:subtitle>A national TV intervention on cyber extortion, online blackmail, privacy risks, and digital safety.</itunes:subtitle>
                <itunes:summary>A Media Archive episode featuring Taher Amine ELHOUARI’s Algerian National TV intervention on cyber extortion and online blackmail, covering privacy risks, social engineering, digital safety, public awareness, family education, and collective cyber defense.</itunes:summary>
                <description><![CDATA[<p>In this Media Archive episode of The InfoSec Control Room, Taher Amine ELHOUARI shares a national television intervention from Taqassi — Season Five, produced by Algerian National Television, focused on cyber extortion and online blackmail. This episode explores one of the most dangerous and rapidly growing crimes in the digital space: how attackers exploit psychology, privacy gaps, digital habits, and weak awareness to pressure, manipulate, and harm individuals.</p><p>The discussion reflects one of the core missions of The InfoSec Control Room: making cybersecurity, governance, risk, compliance, and resilience practical, understandable, and connected to real-world impact. Rather than treating cybersecurity as only a technical discipline, this intervention highlights the importance of awareness, digital responsibility, online safety, privacy protection, family education, national cyber maturity, and collective defense.</p><p><strong><em>Original appearance: </em></strong><em>Algerian National Television — Taqassi, Season Five, November 2025.</em></p><p><strong>Topics include:</strong></p><ul><li>Cyber extortion</li><li>Online blackmail</li><li>Digital safety</li><li>Privacy risks</li><li>Social engineering</li><li>Security awareness</li><li>Family and public cyber education</li><li>Digital responsibility</li><li>National cyber maturity</li><li>Collective cyber defense</li></ul><p><strong>Note: </strong>This episode is adapted from a public media appearance featuring Taher Amine ELHOUARI. All rights to the original recording remain with their respective owners.</p>]]></description>
                <content:encoded>&lt;p&gt;In this Media Archive episode of The InfoSec Control Room, Taher Amine ELHOUARI shares a national television intervention from Taqassi — Season Five, produced by Algerian National Television, focused on cyber extortion and online blackmail. This episode explores one of the most dangerous and rapidly growing crimes in the digital space: how attackers exploit psychology, privacy gaps, digital habits, and weak awareness to pressure, manipulate, and harm individuals.&lt;/p&gt;&lt;p&gt;The discussion reflects one of the core missions of The InfoSec Control Room: making cybersecurity, governance, risk, compliance, and resilience practical, understandable, and connected to real-world impact. Rather than treating cybersecurity as only a technical discipline, this intervention highlights the importance of awareness, digital responsibility, online safety, privacy protection, family education, national cyber maturity, and collective defense.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;em&gt;Original appearance: &lt;/em&gt;&lt;/strong&gt;&lt;em&gt;Algerian National Television — Taqassi, Season Five, November 2025.&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Topics include:&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Cyber extortion&lt;/li&gt;&lt;li&gt;Online blackmail&lt;/li&gt;&lt;li&gt;Digital safety&lt;/li&gt;&lt;li&gt;Privacy risks&lt;/li&gt;&lt;li&gt;Social engineering&lt;/li&gt;&lt;li&gt;Security awareness&lt;/li&gt;&lt;li&gt;Family and public cyber education&lt;/li&gt;&lt;li&gt;Digital responsibility&lt;/li&gt;&lt;li&gt;National cyber maturity&lt;/li&gt;&lt;li&gt;Collective cyber defense&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Note: &lt;/strong&gt;This episode is adapted from a public media appearance featuring Taher Amine ELHOUARI. All rights to the original recording remain with their respective owners.&lt;/p&gt;</content:encoded>
                
                <enclosure length="9576698" type="audio/mpeg" url="https://audio4.redcircle.com/episodes/939c4abe-1fae-4d25-916a-802e33d6a854/stream.mp3"/>
                
                <guid isPermaLink="false">cd3a5e00-da4d-4fec-bc0b-e657928e6728</guid>
                <link>https://www.youtube.com/watch?v=35RkPr_kdyc</link>
                <pubDate>Tue, 23 Jun 2026 15:50:38 &#43;0000</pubDate>
                <itunes:duration>598</itunes:duration>
                
                
                <itunes:explicit>false</itunes:explicit>
                
            </item>
        
            <item>
                <itunes:episodeType>bonus</itunes:episodeType>
                <itunes:title>Media Archive: From Chaos to Control — Building and Maturing CERT/CSIRT Teams</itunes:title>
                <title>Media Archive: From Chaos to Control — Building and Maturing CERT/CSIRT Teams</title>

                
                <itunes:season>1</itunes:season>
                <itunes:author>Taher Amine ELHOUARI</itunes:author>
                <itunes:subtitle>A masterclass on building effective cyber response teams, CERT/CSIRT maturity, field tactics, and cyber resilience.</itunes:subtitle>
                <itunes:summary>A Media Archive episode featuring Taher Amine ELHOUARI’s masterclass “From Chaos to Control,” covering CERT/CSIRT fundamentals, cyber response team design, incident response maturity, operational readiness, field tactics, governance, and cyber resilience.</itunes:summary>
                <description><![CDATA[<p>In this Media Archive episode of The InfoSec Control Room, Taher Amine ELHOUARI shares a full masterclass titled “From Chaos to Control: Understanding, Building, and Maturing Your Cyber Response Team.” This session focuses on the fundamentals, structure, and maturity of cyber response teams, including CERTs, CSIRTs, operational readiness, field tactics, and the architecture of cyber resilience.</p><p>The episode reflects one of the core missions of The InfoSec Control Room: moving beyond theory and showing how cybersecurity governance, incident response, operational structure, and resilience come together in practice. Rather than treating incident response as a purely technical activity, this masterclass highlights the importance of team design, clear roles, governance, escalation, preparedness, coordination, continuous improvement, and the ability to move from reactive chaos to controlled cyber response.</p><p><strong><em>Original session:</em></strong><em> CyberSecurity DZ &amp; WW, Algeria, August 2025.</em></p><p><strong>Topics include:</strong></p><ul><li>CERT and CSIRT fundamentals</li><li>Cyber response team design</li><li>Incident response maturity</li><li>Operational readiness</li><li>Cyber resilience architecture</li><li>Field tactics for response teams</li><li>Governance of cyber response capabilities</li><li>Building structure from operational chaos</li><li>Practical lessons for security leaders and practitioners</li></ul><p><strong>Note: </strong>This episode is adapted from a public masterclass featuring Taher Amine ELHOUARI. All rights to the original recording remain with their respective owners.</p>]]></description>
                <content:encoded>&lt;p&gt;In this Media Archive episode of The InfoSec Control Room, Taher Amine ELHOUARI shares a full masterclass titled “From Chaos to Control: Understanding, Building, and Maturing Your Cyber Response Team.” This session focuses on the fundamentals, structure, and maturity of cyber response teams, including CERTs, CSIRTs, operational readiness, field tactics, and the architecture of cyber resilience.&lt;/p&gt;&lt;p&gt;The episode reflects one of the core missions of The InfoSec Control Room: moving beyond theory and showing how cybersecurity governance, incident response, operational structure, and resilience come together in practice. Rather than treating incident response as a purely technical activity, this masterclass highlights the importance of team design, clear roles, governance, escalation, preparedness, coordination, continuous improvement, and the ability to move from reactive chaos to controlled cyber response.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;em&gt;Original session:&lt;/em&gt;&lt;/strong&gt;&lt;em&gt; CyberSecurity DZ &amp;amp; WW, Algeria, August 2025.&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Topics include:&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;CERT and CSIRT fundamentals&lt;/li&gt;&lt;li&gt;Cyber response team design&lt;/li&gt;&lt;li&gt;Incident response maturity&lt;/li&gt;&lt;li&gt;Operational readiness&lt;/li&gt;&lt;li&gt;Cyber resilience architecture&lt;/li&gt;&lt;li&gt;Field tactics for response teams&lt;/li&gt;&lt;li&gt;Governance of cyber response capabilities&lt;/li&gt;&lt;li&gt;Building structure from operational chaos&lt;/li&gt;&lt;li&gt;Practical lessons for security leaders and practitioners&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Note: &lt;/strong&gt;This episode is adapted from a public masterclass featuring Taher Amine ELHOUARI. All rights to the original recording remain with their respective owners.&lt;/p&gt;</content:encoded>
                
                <enclosure length="61386501" type="audio/mpeg" url="https://audio4.redcircle.com/episodes/3af2248f-1784-4b81-b189-30f124eb284c/stream.mp3"/>
                
                <guid isPermaLink="false">73f676fd-2ef5-49e7-a47b-48fa6e0d1141</guid>
                <link>https://www.youtube.com/watch?v=-odfvRUpCYY</link>
                <pubDate>Tue, 23 Jun 2026 15:47:55 &#43;0000</pubDate>
                <itunes:duration>3836</itunes:duration>
                
                
                <itunes:explicit>false</itunes:explicit>
                
            </item>
        
            <item>
                <itunes:episodeType>bonus</itunes:episodeType>
                <itunes:title>Media Archive: Cybersecurity Challenges, Certifications, and Career Lessons</itunes:title>
                <title>Media Archive: Cybersecurity Challenges, Certifications, and Career Lessons</title>

                
                <itunes:season>1</itunes:season>
                <itunes:author>Taher Amine ELHOUARI</itunes:author>
                <itunes:subtitle>A guest podcast interview on cybersecurity fundamentals, certifications, ethical hacking, teams, standards, and career growth.</itunes:subtitle>
                <itunes:summary>A Media Archive episode featuring Taher Amine ELHOUARI’s guest interview on Lweirday Experience, covering cybersecurity fundamentals, career growth, certifications, ethical hacking, development security, red/blue/purple teams, ICS and SCADA security, standards, and cybersecurity challenges.</itunes:summary>
                <description><![CDATA[<p>In this Media Archive episode of The InfoSec Control Room, Taher Amine ELHOUARI shares a guest podcast interview originally featured on Lweirday Experience.</p><p>This conversation explores cybersecurity from multiple angles: fundamentals, career development, certifications, ethical hacking, development security, red/blue/purple teaming, cybersecurity teams, ICS and SCADA security, standards, and the challenges organizations face when building serious security capabilities.</p><p>The episode reflects one of the core missions of The InfoSec Control Room: making cybersecurity, governance, risk, compliance, and resilience practical, understandable, and connected to real professional experience.</p><p>Rather than treating cybersecurity as only a technical field, this discussion highlights the importance of mindset, continuous learning, structured teams, secure development, governance, and the ability to connect security knowledge with real organizational needs.</p><p><br></p><p><strong><em>Original appearance: </em></strong><em>Lweirday Experience, September 2025.</em></p><p><br></p><p><strong>Topics include:</strong></p><ul><li>Introduction to cybersecurity</li><li>Career journey in cybersecurity</li><li>Certifications and professional mindset</li><li>Security in development processes</li><li>Ethical hacking</li><li>Cybersecurity challenges</li><li>Red, blue, and purple teams</li><li>Cybersecurity team structures</li><li>ICS and SCADA security</li><li>Cybersecurity standards</li><li>Building cybersecurity departments in startups</li></ul><p><br></p><p><strong>Chapters:</strong></p><ol><li>00:00 — Introduction to Cybersecurity</li><li>02:57 — Career Journey in Cybersecurity</li><li>06:03 — Impact of Certifications on Security Mindset</li><li>08:59 — Integrating Security in Development Processes</li><li>12:02 — Understanding Ethical Hacking</li><li>18:00 — Challenges in Cybersecurity</li><li>25:07 — Red, Blue, and Purple Teams in Cybersecurity</li><li>32:29 — Understanding Cybersecurity Teams</li><li>34:33 — The Importance of ICS and SCADA Security</li><li>39:02 — Exploring Cybersecurity Standards</li><li>45:38 — Building a Cybersecurity Department in Startups</li><li>49:08 — Quiz</li></ol><p><br></p><p><strong>Note: </strong>This episode is adapted from a public guest podcast interview featuring Taher Amine ELHOUARI. All rights to the original recording remain with their respective owners.</p>]]></description>
                <content:encoded>&lt;p&gt;In this Media Archive episode of The InfoSec Control Room, Taher Amine ELHOUARI shares a guest podcast interview originally featured on Lweirday Experience.&lt;/p&gt;&lt;p&gt;This conversation explores cybersecurity from multiple angles: fundamentals, career development, certifications, ethical hacking, development security, red/blue/purple teaming, cybersecurity teams, ICS and SCADA security, standards, and the challenges organizations face when building serious security capabilities.&lt;/p&gt;&lt;p&gt;The episode reflects one of the core missions of The InfoSec Control Room: making cybersecurity, governance, risk, compliance, and resilience practical, understandable, and connected to real professional experience.&lt;/p&gt;&lt;p&gt;Rather than treating cybersecurity as only a technical field, this discussion highlights the importance of mindset, continuous learning, structured teams, secure development, governance, and the ability to connect security knowledge with real organizational needs.&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;em&gt;Original appearance: &lt;/em&gt;&lt;/strong&gt;&lt;em&gt;Lweirday Experience, September 2025.&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Topics include:&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Introduction to cybersecurity&lt;/li&gt;&lt;li&gt;Career journey in cybersecurity&lt;/li&gt;&lt;li&gt;Certifications and professional mindset&lt;/li&gt;&lt;li&gt;Security in development processes&lt;/li&gt;&lt;li&gt;Ethical hacking&lt;/li&gt;&lt;li&gt;Cybersecurity challenges&lt;/li&gt;&lt;li&gt;Red, blue, and purple teams&lt;/li&gt;&lt;li&gt;Cybersecurity team structures&lt;/li&gt;&lt;li&gt;ICS and SCADA security&lt;/li&gt;&lt;li&gt;Cybersecurity standards&lt;/li&gt;&lt;li&gt;Building cybersecurity departments in startups&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Chapters:&lt;/strong&gt;&lt;/p&gt;&lt;ol&gt;&lt;li&gt;00:00 — Introduction to Cybersecurity&lt;/li&gt;&lt;li&gt;02:57 — Career Journey in Cybersecurity&lt;/li&gt;&lt;li&gt;06:03 — Impact of Certifications on Security Mindset&lt;/li&gt;&lt;li&gt;08:59 — Integrating Security in Development Processes&lt;/li&gt;&lt;li&gt;12:02 — Understanding Ethical Hacking&lt;/li&gt;&lt;li&gt;18:00 — Challenges in Cybersecurity&lt;/li&gt;&lt;li&gt;25:07 — Red, Blue, and Purple Teams in Cybersecurity&lt;/li&gt;&lt;li&gt;32:29 — Understanding Cybersecurity Teams&lt;/li&gt;&lt;li&gt;34:33 — The Importance of ICS and SCADA Security&lt;/li&gt;&lt;li&gt;39:02 — Exploring Cybersecurity Standards&lt;/li&gt;&lt;li&gt;45:38 — Building a Cybersecurity Department in Startups&lt;/li&gt;&lt;li&gt;49:08 — Quiz&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Note: &lt;/strong&gt;This episode is adapted from a public guest podcast interview featuring Taher Amine ELHOUARI. All rights to the original recording remain with their respective owners.&lt;/p&gt;</content:encoded>
                
                <enclosure length="49013655" type="audio/mpeg" url="https://audio4.redcircle.com/episodes/1161a5c7-6d4b-4baa-8b53-52f450c2396c/stream.mp3"/>
                
                <guid isPermaLink="false">0860c490-16c7-41bc-b788-7b7fd1a19f59</guid>
                <link>https://www.youtube.com/watch?v=hoP4bZabCT0</link>
                <pubDate>Tue, 23 Jun 2026 15:45:15 &#43;0000</pubDate>
                <itunes:duration>3063</itunes:duration>
                
                
                <itunes:explicit>false</itunes:explicit>
                
            </item>
        
            <item>
                <itunes:episodeType>bonus</itunes:episodeType>
                <itunes:title>Media Archive: Information Security — A Leading Experience</itunes:title>
                <title>Media Archive: Information Security — A Leading Experience</title>

                
                <itunes:season>1</itunes:season>
                <itunes:author>Taher Amine ELHOUARI</itunes:author>
                <itunes:subtitle>A long-form interview on cybersecurity journey, career-building, certifications, field experience, and community contribution.</itunes:subtitle>
                <itunes:summary>A Media Archive episode featuring Taher Amine ELHOUARI’s long-form interview with Adel BOUROUIS for Algerian Tech Makers, covering information security career growth, certifications, lessons learned, field experience, ethical hacking, community building, leadership, and advice for aspiring cybersecurity professionals.</itunes:summary>
                <description><![CDATA[<p>In this Media Archive episode of The InfoSec Control Room, Taher Amine ELHOUARI shares a long-form interview hosted by Adel BOUROUIS for Algerian Tech Makers.</p><p>This discussion explores Taher’s journey in information security and cybersecurity, including career development, lessons learned, certifications, challenges, field experience, community contribution, and the mindset required to grow seriously in the cybersecurity field.</p><p>The episode reflects one of the core missions of The InfoSec Control Room: connecting cybersecurity knowledge, governance thinking, professional growth, and practical field experience in a way that is useful for students, practitioners, leaders, and the wider cybersecurity community.</p><p>Rather than presenting cybersecurity as only a technical career path, this conversation highlights the importance of discipline, continuous learning, ethical practice, community building, leadership, and the ability to turn knowledge into real impact.</p><p><em>Original appearance: Algerian Tech Makers, April 2025.</em></p><p>Topics include:</p><ul><li>Information security career journey</li><li>Cybersecurity professional growth</li><li>Certifications and lessons learned</li><li>Field experience and challenges</li><li>Cybersecurity community building</li><li>Ethical hacking and practical learning</li><li>Leadership and mindset</li><li>Advice for students and aspiring practitioners</li></ul><p><br></p><p>Note: This episode is adapted from a public interview featuring Taher Amine ELHOUARI. All rights to the original recording remain with their respective owners.</p>]]></description>
                <content:encoded>&lt;p&gt;In this Media Archive episode of The InfoSec Control Room, Taher Amine ELHOUARI shares a long-form interview hosted by Adel BOUROUIS for Algerian Tech Makers.&lt;/p&gt;&lt;p&gt;This discussion explores Taher’s journey in information security and cybersecurity, including career development, lessons learned, certifications, challenges, field experience, community contribution, and the mindset required to grow seriously in the cybersecurity field.&lt;/p&gt;&lt;p&gt;The episode reflects one of the core missions of The InfoSec Control Room: connecting cybersecurity knowledge, governance thinking, professional growth, and practical field experience in a way that is useful for students, practitioners, leaders, and the wider cybersecurity community.&lt;/p&gt;&lt;p&gt;Rather than presenting cybersecurity as only a technical career path, this conversation highlights the importance of discipline, continuous learning, ethical practice, community building, leadership, and the ability to turn knowledge into real impact.&lt;/p&gt;&lt;p&gt;&lt;em&gt;Original appearance: Algerian Tech Makers, April 2025.&lt;/em&gt;&lt;/p&gt;&lt;p&gt;Topics include:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Information security career journey&lt;/li&gt;&lt;li&gt;Cybersecurity professional growth&lt;/li&gt;&lt;li&gt;Certifications and lessons learned&lt;/li&gt;&lt;li&gt;Field experience and challenges&lt;/li&gt;&lt;li&gt;Cybersecurity community building&lt;/li&gt;&lt;li&gt;Ethical hacking and practical learning&lt;/li&gt;&lt;li&gt;Leadership and mindset&lt;/li&gt;&lt;li&gt;Advice for students and aspiring practitioners&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;Note: This episode is adapted from a public interview featuring Taher Amine ELHOUARI. All rights to the original recording remain with their respective owners.&lt;/p&gt;</content:encoded>
                
                <enclosure length="127695725" type="audio/mpeg" url="https://audio4.redcircle.com/episodes/83927f19-c4cd-4aa4-9f71-559ad00558fc/stream.mp3"/>
                
                <guid isPermaLink="false">5f3ed327-cba8-465e-9649-c45279099d9d</guid>
                <link>https://www.youtube.com/watch?v=ohsplatHmak</link>
                <pubDate>Tue, 23 Jun 2026 15:42:54 &#43;0000</pubDate>
                <itunes:duration>7980</itunes:duration>
                
                
                <itunes:explicit>false</itunes:explicit>
                
            </item>
        
            <item>
                <itunes:episodeType>bonus</itunes:episodeType>
                <itunes:title>Media Archive: Cybersecurity &amp; Data Protection Panel at CTO Forum 2025</itunes:title>
                <title>Media Archive: Cybersecurity &amp; Data Protection Panel at CTO Forum 2025</title>

                
                <itunes:season>1</itunes:season>
                <itunes:author>Taher Amine ELHOUARI</itunes:author>
                <itunes:subtitle>A panel discussion on cybersecurity strategy, cloud security, data protection, governance, and cyber resilience.</itunes:subtitle>
                <itunes:summary>A Media Archive episode featuring Taher Amine ELHOUARI’s intervention during the Cybersecurity &amp; Data Protection Panel at CTO Forum 2025 in Algiers, covering cybersecurity strategy, cloud security, data protection, governance, risk management, regulatory alignment, secure development, and cyber resilience.</itunes:summary>
                <description><![CDATA[<p>In this Media Archive episode of The InfoSec Control Room, Taher Amine ELHOUARI shares his intervention during the Cybersecurity &amp; Data Protection Panel at CTO Forum 2025 in Algiers.</p><p>This panel focused on key challenges facing organizations in today’s evolving threat landscape, including cybersecurity strategy, risk management, cloud security, data protection, governance, regulatory alignment, and secure development.</p><p>The discussion reflects one of the core missions of The InfoSec Control Room: connecting cybersecurity, governance, risk, compliance, and resilience with real-world leadership decisions.</p><p>Rather than treating cybersecurity as a purely technical topic, this episode highlights the importance of strategic security governance, cross-sector collaboration, cloud security maturity, privacy alignment, and the role of practitioners in helping organizations build secure and resilient digital ecosystems.</p><p><em>Original appearance: CTO Forum 2025, Algiers, March 2025.</em></p><p>Topics include:</p><ul><li>Cybersecurity strategy</li><li>Risk management</li><li>Cloud security and compliance</li><li>Data protection and governance</li><li>Regulatory alignment</li><li>Secure development</li><li>Cyber resilience</li><li>Cross-sector collaboration</li><li>Security leadership and digital trust</li></ul><p><br></p><p>Note: This episode is adapted from a public panel appearance featuring Taher Amine ELHOUARI. All rights to the original recording remain with their respective owners.</p>]]></description>
                <content:encoded>&lt;p&gt;In this Media Archive episode of The InfoSec Control Room, Taher Amine ELHOUARI shares his intervention during the Cybersecurity &amp;amp; Data Protection Panel at CTO Forum 2025 in Algiers.&lt;/p&gt;&lt;p&gt;This panel focused on key challenges facing organizations in today’s evolving threat landscape, including cybersecurity strategy, risk management, cloud security, data protection, governance, regulatory alignment, and secure development.&lt;/p&gt;&lt;p&gt;The discussion reflects one of the core missions of The InfoSec Control Room: connecting cybersecurity, governance, risk, compliance, and resilience with real-world leadership decisions.&lt;/p&gt;&lt;p&gt;Rather than treating cybersecurity as a purely technical topic, this episode highlights the importance of strategic security governance, cross-sector collaboration, cloud security maturity, privacy alignment, and the role of practitioners in helping organizations build secure and resilient digital ecosystems.&lt;/p&gt;&lt;p&gt;&lt;em&gt;Original appearance: CTO Forum 2025, Algiers, March 2025.&lt;/em&gt;&lt;/p&gt;&lt;p&gt;Topics include:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Cybersecurity strategy&lt;/li&gt;&lt;li&gt;Risk management&lt;/li&gt;&lt;li&gt;Cloud security and compliance&lt;/li&gt;&lt;li&gt;Data protection and governance&lt;/li&gt;&lt;li&gt;Regulatory alignment&lt;/li&gt;&lt;li&gt;Secure development&lt;/li&gt;&lt;li&gt;Cyber resilience&lt;/li&gt;&lt;li&gt;Cross-sector collaboration&lt;/li&gt;&lt;li&gt;Security leadership and digital trust&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;Note: This episode is adapted from a public panel appearance featuring Taher Amine ELHOUARI. All rights to the original recording remain with their respective owners.&lt;/p&gt;</content:encoded>
                
                <enclosure length="11968679" type="audio/mpeg" url="https://audio4.redcircle.com/episodes/0f22ef5c-f2f4-4c7d-8354-7bdef5679a3f/stream.mp3"/>
                
                <guid isPermaLink="false">6ed5da1e-afa7-401f-a0c3-f11487de04a2</guid>
                <link>https://www.youtube.com/watch?v=ueegvOwwc8I</link>
                <pubDate>Tue, 23 Jun 2026 15:41:13 &#43;0000</pubDate>
                <itunes:duration>748</itunes:duration>
                
                
                <itunes:explicit>false</itunes:explicit>
                
            </item>
        
            <item>
                <itunes:episodeType>bonus</itunes:episodeType>
                <itunes:title>Media Archive: Electronic Flies and Cybersecurity on Algerian National TV</itunes:title>
                <title>Media Archive: Electronic Flies and Cybersecurity on Algerian National TV</title>

                
                <itunes:season>1</itunes:season>
                <itunes:author>Taher Amine ELHOUARI</itunes:author>
                <itunes:subtitle>A national TV appearance on electronic flies, online manipulation, cyber awareness, and digital security culture.</itunes:subtitle>
                <itunes:summary>A Media Archive episode featuring Taher Amine ELHOUARI’s Algerian National TV appearance on electronic flies, cybersecurity awareness, online manipulation, digital safety, information integrity, and responsible digital behavior.</itunes:summary>
                <description><![CDATA[<p>In this Media Archive episode of The InfoSec Control Room, Taher Amine ELHOUARI shares a national television appearance on the topic of electronic flies, cybersecurity, online manipulation, and digital awareness.</p><p>This discussion focuses on how digital platforms can be misused to influence, manipulate, mislead, or attack individuals and communities, and why cybersecurity awareness must go beyond passwords, devices, and technical controls.</p><p>The episode reflects one of the core missions of The InfoSec Control Room: helping people understand the real-world impact of cybersecurity, governance, risk, trust, and resilience in daily digital life.</p><p>Rather than treating cybersecurity as only a technical subject, this session highlights the importance of awareness, digital responsibility, online verification, information integrity, and the role of experts in strengthening cyber maturity across society.</p><p><em>Original appearance: National Television of Algeria, March 2025.</em></p><p>Topics include:</p><ul><li>Electronic flies and online manipulation</li><li>Cybersecurity awareness</li><li>Digital safety</li><li>Information integrity</li><li>Online trust</li><li>Public cyber education</li><li>Responsible digital behavior</li><li>The role of experts in strengthening security culture</li></ul><p><br></p><p>Note: This episode is adapted from a public media appearance featuring Taher Amine ELHOUARI. All rights to the original recording remain with their respective owners.</p>]]></description>
                <content:encoded>&lt;p&gt;In this Media Archive episode of The InfoSec Control Room, Taher Amine ELHOUARI shares a national television appearance on the topic of electronic flies, cybersecurity, online manipulation, and digital awareness.&lt;/p&gt;&lt;p&gt;This discussion focuses on how digital platforms can be misused to influence, manipulate, mislead, or attack individuals and communities, and why cybersecurity awareness must go beyond passwords, devices, and technical controls.&lt;/p&gt;&lt;p&gt;The episode reflects one of the core missions of The InfoSec Control Room: helping people understand the real-world impact of cybersecurity, governance, risk, trust, and resilience in daily digital life.&lt;/p&gt;&lt;p&gt;Rather than treating cybersecurity as only a technical subject, this session highlights the importance of awareness, digital responsibility, online verification, information integrity, and the role of experts in strengthening cyber maturity across society.&lt;/p&gt;&lt;p&gt;&lt;em&gt;Original appearance: National Television of Algeria, March 2025.&lt;/em&gt;&lt;/p&gt;&lt;p&gt;Topics include:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Electronic flies and online manipulation&lt;/li&gt;&lt;li&gt;Cybersecurity awareness&lt;/li&gt;&lt;li&gt;Digital safety&lt;/li&gt;&lt;li&gt;Information integrity&lt;/li&gt;&lt;li&gt;Online trust&lt;/li&gt;&lt;li&gt;Public cyber education&lt;/li&gt;&lt;li&gt;Responsible digital behavior&lt;/li&gt;&lt;li&gt;The role of experts in strengthening security culture&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;Note: This episode is adapted from a public media appearance featuring Taher Amine ELHOUARI. All rights to the original recording remain with their respective owners.&lt;/p&gt;</content:encoded>
                
                <enclosure length="12165955" type="audio/mpeg" url="https://audio4.redcircle.com/episodes/be8cb9be-2c68-410e-8467-57f90921c414/stream.mp3"/>
                
                <guid isPermaLink="false">7221fc0b-5fa8-46f1-b676-605f5ac181ec</guid>
                <link>https://www.youtube.com/watch?v=Rs1bqNVFDq0</link>
                <pubDate>Tue, 23 Jun 2026 15:40:11 &#43;0000</pubDate>
                <itunes:duration>760</itunes:duration>
                
                
                <itunes:explicit>false</itunes:explicit>
                
            </item>
        
            <item>
                <itunes:episodeType>bonus</itunes:episodeType>
                <itunes:title>Media Archive: IT/OT Convergence at North Africa OT Security Forum</itunes:title>
                <title>Media Archive: IT/OT Convergence at North Africa OT Security Forum</title>

                
                <itunes:season>1</itunes:season>
                <itunes:author>Taher Amine ELHOUARI</itunes:author>
                <itunes:subtitle>A forum intervention on IT/OT convergence, cybersecurity risk, operational resilience, and industrial security opportunities.</itunes:subtitle>
                <itunes:summary>A Media Archive episode featuring Taher Amine ELHOUARI’s intervention at the North Africa OT Security Forum on IT/OT convergence, OT cybersecurity, industrial cyber risk, operational resilience, business continuity, and governance lessons.</itunes:summary>
                <description><![CDATA[<p>In this Media Archive episode of The InfoSec Control Room, Taher Amine ELHOUARI shares an intervention from the North Africa OT Security Forum, originally featured on ExpressFM.</p><p>This discussion focuses on IT/OT convergence, cybersecurity risks, operational resilience, and the opportunities created when industrial environments, critical systems, and digital technologies become increasingly connected.</p><p>The episode reflects one of the core missions of The InfoSec Control Room: looking beyond technical security controls and asking what cyber risk means for governance, continuity, resilience, accountability, and decision-making in real operational environments.</p><p>Rather than treating OT security as only a technical challenge, this session highlights the importance of risk ownership, industrial cybersecurity maturity, executive awareness, business continuity, and collaboration between IT, OT, security, and leadership teams.</p><p><em>Original appearance: North Africa OT Security Forum, ExpressFM, December 2024.</em></p><p>Topics include:</p><ul><li>IT/OT convergence</li><li>OT cybersecurity</li><li>Industrial cyber risk</li><li>Critical systems and operational resilience</li><li>Cybersecurity governance</li><li>Business continuity</li><li>Risk ownership</li><li>Opportunities and challenges in connected industrial environments</li></ul><p><br></p><p>Note: This episode is adapted from a public event/media appearance featuring Taher Amine ELHOUARI. All rights to the original recording remain with their respective owners.</p>]]></description>
                <content:encoded>&lt;p&gt;In this Media Archive episode of The InfoSec Control Room, Taher Amine ELHOUARI shares an intervention from the North Africa OT Security Forum, originally featured on ExpressFM.&lt;/p&gt;&lt;p&gt;This discussion focuses on IT/OT convergence, cybersecurity risks, operational resilience, and the opportunities created when industrial environments, critical systems, and digital technologies become increasingly connected.&lt;/p&gt;&lt;p&gt;The episode reflects one of the core missions of The InfoSec Control Room: looking beyond technical security controls and asking what cyber risk means for governance, continuity, resilience, accountability, and decision-making in real operational environments.&lt;/p&gt;&lt;p&gt;Rather than treating OT security as only a technical challenge, this session highlights the importance of risk ownership, industrial cybersecurity maturity, executive awareness, business continuity, and collaboration between IT, OT, security, and leadership teams.&lt;/p&gt;&lt;p&gt;&lt;em&gt;Original appearance: North Africa OT Security Forum, ExpressFM, December 2024.&lt;/em&gt;&lt;/p&gt;&lt;p&gt;Topics include:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;IT/OT convergence&lt;/li&gt;&lt;li&gt;OT cybersecurity&lt;/li&gt;&lt;li&gt;Industrial cyber risk&lt;/li&gt;&lt;li&gt;Critical systems and operational resilience&lt;/li&gt;&lt;li&gt;Cybersecurity governance&lt;/li&gt;&lt;li&gt;Business continuity&lt;/li&gt;&lt;li&gt;Risk ownership&lt;/li&gt;&lt;li&gt;Opportunities and challenges in connected industrial environments&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;Note: This episode is adapted from a public event/media appearance featuring Taher Amine ELHOUARI. All rights to the original recording remain with their respective owners.&lt;/p&gt;</content:encoded>
                
                <enclosure length="2955389" type="audio/mpeg" url="https://audio4.redcircle.com/episodes/bb9c3d01-5612-477c-b650-5165957deee5/stream.mp3"/>
                
                <guid isPermaLink="false">3dc41699-86dc-45d1-8218-360351b6385e</guid>
                <link>https://www.youtube.com/watch?v=kFNmbplZ47Q</link>
                <pubDate>Tue, 23 Jun 2026 15:39:31 &#43;0000</pubDate>
                <itunes:duration>184</itunes:duration>
                
                
                <itunes:explicit>false</itunes:explicit>
                
            </item>
        
            <item>
                <itunes:episodeType>bonus</itunes:episodeType>
                <itunes:title>Media Archive: Cybersecurity and Digital Awareness at Médiatics Radio</itunes:title>
                <title>Media Archive: Cybersecurity and Digital Awareness at Médiatics Radio</title>

                
                <itunes:season>1</itunes:season>
                <itunes:author>Taher Amine ELHOUARI</itunes:author>
                <itunes:subtitle>A public radio discussion on cybersecurity, digital awareness, online risk, and practical security culture.</itunes:subtitle>
                <itunes:summary>A Media Archive episode featuring Taher Amine ELHOUARI’s public radio appearance with Médiatics, covering cybersecurity awareness, digital safety, online risk, information security culture, public education, and digital trust.</itunes:summary>
                <description><![CDATA[<p>In this Media Archive episode of The InfoSec Control Room, Taher Amine ELHOUARI shares a public radio appearance originally recorded with Médiatics, an Algeria-based radio program.</p><p>This episode focuses on cybersecurity, digital awareness, online risk, and the importance of making information security accessible to a wider audience beyond technical teams.</p><p>The discussion reflects one of the core missions of The InfoSec Control Room: making cybersecurity, governance, risk, compliance, and resilience practical, understandable, and connected to real-world impact.</p><p>Rather than treating cybersecurity as only a technical discipline, this session highlights the importance of awareness, responsible digital behavior, digital trust, and public education in strengthening cyber maturity.</p><p>Topics include:</p><ul><li>Cybersecurity awareness</li><li>Digital safety</li><li>Online risk</li><li>Information security culture</li><li>Public cyber education</li><li>Digital trust</li><li>Responsible digital behavior</li><li>The role of experts in strengthening cyber maturity</li></ul><p><br></p><p>Note: This episode is adapted from a public radio/media appearance featuring Taher Amine ELHOUARI. All rights to the original recording remain with their respective owners.</p>]]></description>
                <content:encoded>&lt;p&gt;In this Media Archive episode of The InfoSec Control Room, Taher Amine ELHOUARI shares a public radio appearance originally recorded with Médiatics, an Algeria-based radio program.&lt;/p&gt;&lt;p&gt;This episode focuses on cybersecurity, digital awareness, online risk, and the importance of making information security accessible to a wider audience beyond technical teams.&lt;/p&gt;&lt;p&gt;The discussion reflects one of the core missions of The InfoSec Control Room: making cybersecurity, governance, risk, compliance, and resilience practical, understandable, and connected to real-world impact.&lt;/p&gt;&lt;p&gt;Rather than treating cybersecurity as only a technical discipline, this session highlights the importance of awareness, responsible digital behavior, digital trust, and public education in strengthening cyber maturity.&lt;/p&gt;&lt;p&gt;Topics include:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Cybersecurity awareness&lt;/li&gt;&lt;li&gt;Digital safety&lt;/li&gt;&lt;li&gt;Online risk&lt;/li&gt;&lt;li&gt;Information security culture&lt;/li&gt;&lt;li&gt;Public cyber education&lt;/li&gt;&lt;li&gt;Digital trust&lt;/li&gt;&lt;li&gt;Responsible digital behavior&lt;/li&gt;&lt;li&gt;The role of experts in strengthening cyber maturity&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;Note: This episode is adapted from a public radio/media appearance featuring Taher Amine ELHOUARI. All rights to the original recording remain with their respective owners.&lt;/p&gt;</content:encoded>
                
                <enclosure length="39882501" type="audio/mpeg" url="https://audio4.redcircle.com/episodes/9649fafe-bb6f-482a-b1ba-b64c6fdef39e/stream.mp3"/>
                
                <guid isPermaLink="false">50c4ad21-e0ba-4821-9c42-fa968a26b19b</guid>
                <link>https://www.youtube.com/watch?v=JAEXGyk8LBI</link>
                <pubDate>Tue, 23 Jun 2026 15:37:17 &#43;0000</pubDate>
                <itunes:duration>2492</itunes:duration>
                
                
                <itunes:explicit>false</itunes:explicit>
                
            </item>
        
            <item>
                <itunes:episodeType>bonus</itunes:episodeType>
                <itunes:title>Media Archive: Cybersecurity Awareness Session on Radio Médéa</itunes:title>
                <title>Media Archive: Cybersecurity Awareness Session on Radio Médéa</title>

                
                <itunes:season>1</itunes:season>
                <itunes:author>Taher Amine ELHOUARI</itunes:author>
                <itunes:subtitle>A public radio awareness session on cybersecurity, online risk, digital safety, and security culture.</itunes:subtitle>
                <itunes:summary>A Media Archive episode featuring Taher Amine ELHOUARI’s cybersecurity awareness session on Radio Médéa, covering online risk, digital safety, public cyber education, security culture, responsible digital behavior, and digital trust.</itunes:summary>
                <description><![CDATA[<p>In this Media Archive episode of The InfoSec Control Room, Taher Amine ELHOUARI shares a cybersecurity awareness session originally recorded at Radio Médéa.</p><p>This episode focuses on public cybersecurity education, online risk, digital safety, and the importance of making security awareness accessible beyond technical teams. It reflects the role of media, experts, and local initiatives in helping people better understand cyber threats and adopt safer digital behavior.</p><p>The discussion aligns with the mission of The InfoSec Control Room: making cybersecurity, governance, risk, compliance, and resilience practical, understandable, and connected to real-world impact.</p><p>Rather than treating cybersecurity as only a technical discipline, this session highlights the importance of awareness, responsibility, digital trust, and security culture in strengthening cyber maturity.</p><p>Topics include:</p><ul><li>Cybersecurity awareness</li><li>Online risk</li><li>Digital safety</li><li>Public cyber education</li><li>Security culture</li><li>Responsible digital behavior</li><li>Digital trust</li><li>The role of experts in strengthening cyber maturity</li></ul><p><br></p><p>Note: This episode is adapted from a public radio/media appearance featuring Taher Amine ELHOUARI. All rights to the original recording remain with their respective owners.</p>]]></description>
                <content:encoded>&lt;p&gt;In this Media Archive episode of The InfoSec Control Room, Taher Amine ELHOUARI shares a cybersecurity awareness session originally recorded at Radio Médéa.&lt;/p&gt;&lt;p&gt;This episode focuses on public cybersecurity education, online risk, digital safety, and the importance of making security awareness accessible beyond technical teams. It reflects the role of media, experts, and local initiatives in helping people better understand cyber threats and adopt safer digital behavior.&lt;/p&gt;&lt;p&gt;The discussion aligns with the mission of The InfoSec Control Room: making cybersecurity, governance, risk, compliance, and resilience practical, understandable, and connected to real-world impact.&lt;/p&gt;&lt;p&gt;Rather than treating cybersecurity as only a technical discipline, this session highlights the importance of awareness, responsibility, digital trust, and security culture in strengthening cyber maturity.&lt;/p&gt;&lt;p&gt;Topics include:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Cybersecurity awareness&lt;/li&gt;&lt;li&gt;Online risk&lt;/li&gt;&lt;li&gt;Digital safety&lt;/li&gt;&lt;li&gt;Public cyber education&lt;/li&gt;&lt;li&gt;Security culture&lt;/li&gt;&lt;li&gt;Responsible digital behavior&lt;/li&gt;&lt;li&gt;Digital trust&lt;/li&gt;&lt;li&gt;The role of experts in strengthening cyber maturity&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;Note: This episode is adapted from a public radio/media appearance featuring Taher Amine ELHOUARI. All rights to the original recording remain with their respective owners.&lt;/p&gt;</content:encoded>
                
                <enclosure length="30444982" type="audio/mpeg" url="https://audio4.redcircle.com/episodes/093aee12-847c-49bf-862a-70275fc8a08b/stream.mp3"/>
                
                <guid isPermaLink="false">f33d1d15-69e5-4b11-95b2-b8367b816318</guid>
                <link>https://www.youtube.com/watch?v=_y0yCcTjMRk</link>
                <pubDate>Tue, 23 Jun 2026 15:34:03 &#43;0000</pubDate>
                <itunes:duration>1902</itunes:duration>
                
                
                <itunes:explicit>false</itunes:explicit>
                
            </item>
        
            <item>
                <itunes:episodeType>bonus</itunes:episodeType>
                <itunes:title>Media Archive: CrowdStrike Global Incident Analysis on Algerian National TV</itunes:title>
                <title>Media Archive: CrowdStrike Global Incident Analysis on Algerian National TV</title>

                
                <itunes:season>1</itunes:season>
                <itunes:author>Taher Amine ELHOUARI</itunes:author>
                <itunes:subtitle>A national TV analysis of the CrowdStrike global incident, cyber resilience, operational risk, and digital dependency.</itunes:subtitle>
                <itunes:summary>A Media Archive episode featuring Taher Amine ELHOUARI’s Algerian National Television analysis of the CrowdStrike global incident, covering cyber resilience, operational risk, technology dependency, business continuity, crisis communication, and governance lessons.</itunes:summary>
                <description><![CDATA[<p>In this Media Archive episode of The InfoSec Control Room, Taher Amine ELHOUARI shares a national television appearance analyzing the CrowdStrike global incident and its wider impact on cybersecurity, operational resilience, digital trust, and organizational dependency on critical technology providers.</p><p>This episode reflects one of the core missions of The InfoSec Control Room: looking beyond the technical headline and asking what major cyber and technology incidents reveal about governance, risk, continuity, accountability, and resilience.</p><p>Rather than treating the incident as only a technical failure, this discussion highlights the importance of preparedness, crisis management, third-party risk, business continuity, communication, and the ability of organizations to maintain control when digital systems fail at scale.</p><p><em>Original appearance: Algerian National Television, August 2024.</em></p><p>Topics include:</p><ul><li>CrowdStrike global incident analysis</li><li>Cyber resilience</li><li>Operational risk</li><li>Business continuity</li><li>Third-party and technology dependency</li><li>Crisis communication</li><li>Digital trust</li><li>Governance lessons from large-scale incidents</li></ul><p><br></p><p>Note: This episode is adapted from a public media appearance featuring Taher Amine ELHOUARI. All rights to the original recording remain with their respective owners.</p>]]></description>
                <content:encoded>&lt;p&gt;In this Media Archive episode of The InfoSec Control Room, Taher Amine ELHOUARI shares a national television appearance analyzing the CrowdStrike global incident and its wider impact on cybersecurity, operational resilience, digital trust, and organizational dependency on critical technology providers.&lt;/p&gt;&lt;p&gt;This episode reflects one of the core missions of The InfoSec Control Room: looking beyond the technical headline and asking what major cyber and technology incidents reveal about governance, risk, continuity, accountability, and resilience.&lt;/p&gt;&lt;p&gt;Rather than treating the incident as only a technical failure, this discussion highlights the importance of preparedness, crisis management, third-party risk, business continuity, communication, and the ability of organizations to maintain control when digital systems fail at scale.&lt;/p&gt;&lt;p&gt;&lt;em&gt;Original appearance: Algerian National Television, August 2024.&lt;/em&gt;&lt;/p&gt;&lt;p&gt;Topics include:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;CrowdStrike global incident analysis&lt;/li&gt;&lt;li&gt;Cyber resilience&lt;/li&gt;&lt;li&gt;Operational risk&lt;/li&gt;&lt;li&gt;Business continuity&lt;/li&gt;&lt;li&gt;Third-party and technology dependency&lt;/li&gt;&lt;li&gt;Crisis communication&lt;/li&gt;&lt;li&gt;Digital trust&lt;/li&gt;&lt;li&gt;Governance lessons from large-scale incidents&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;Note: This episode is adapted from a public media appearance featuring Taher Amine ELHOUARI. All rights to the original recording remain with their respective owners.&lt;/p&gt;</content:encoded>
                
                <enclosure length="4801933" type="audio/mpeg" url="https://audio4.redcircle.com/episodes/2e6ee40a-d6e4-4109-bda0-660a9ade1226/stream.mp3"/>
                
                <guid isPermaLink="false">d389ebde-f12f-4899-b0b9-3cd96372ee6b</guid>
                <link>https://www.youtube.com/watch?v=RrFVrKZ-lds</link>
                <pubDate>Tue, 23 Jun 2026 15:33:12 &#43;0000</pubDate>
                <itunes:duration>300</itunes:duration>
                
                
                <itunes:explicit>false</itunes:explicit>
                
            </item>
        
            <item>
                <itunes:episodeType>bonus</itunes:episodeType>
                <itunes:title>Media Archive: OWASP Algiers on Radio Médéa — Information &amp; Cyber Security</itunes:title>
                <title>Media Archive: OWASP Algiers on Radio Médéa — Information &amp; Cyber Security</title>

                
                <itunes:season>1</itunes:season>
                <itunes:author>Taher Amine ELHOUARI</itunes:author>
                <itunes:subtitle>A public radio appearance on information security, cybersecurity awareness, community building, and digital trust.</itunes:subtitle>
                <itunes:summary>A Media Archive episode featuring Taher Amine ELHOUARI’s OWASP Algiers Chapter appearance on Radio Médéa, covering information security, cybersecurity awareness, community building, digital trust, and public cyber education.</itunes:summary>
                <description><![CDATA[<p>In this Media Archive episode of The InfoSec Control Room, Taher Amine ELHOUARI shares a public radio appearance connected to OWASP Algiers Chapter on Radio Médéa.</p><p>This episode focuses on information security, cybersecurity awareness, community engagement, and the role of local initiatives in helping students, professionals, developers, and the wider public better understand digital risk.</p><p>The discussion reflects one of the core missions of The InfoSec Control Room: making cybersecurity, governance, risk, and resilience practical, accessible, and connected to real communities.</p><p>Rather than treating cybersecurity as a closed technical discipline, this episode highlights the importance of public awareness, responsible digital behavior, community-driven learning, and the role of professional initiatives such as OWASP Algiers in strengthening cybersecurity maturity.</p><p>Topics include:</p><ul><li>Information security</li><li>Cybersecurity awareness</li><li>OWASP Algiers</li><li>Community building</li><li>Public cyber education</li><li>Digital trust</li><li>Online risk</li><li>The role of local initiatives in strengthening cyber maturity</li></ul><p><br></p><p>Note: This episode is adapted from a public radio/media appearance featuring Taher Amine ELHOUARI. All rights to the original recording remain with their respective owners.</p>]]></description>
                <content:encoded>&lt;p&gt;In this Media Archive episode of The InfoSec Control Room, Taher Amine ELHOUARI shares a public radio appearance connected to OWASP Algiers Chapter on Radio Médéa.&lt;/p&gt;&lt;p&gt;This episode focuses on information security, cybersecurity awareness, community engagement, and the role of local initiatives in helping students, professionals, developers, and the wider public better understand digital risk.&lt;/p&gt;&lt;p&gt;The discussion reflects one of the core missions of The InfoSec Control Room: making cybersecurity, governance, risk, and resilience practical, accessible, and connected to real communities.&lt;/p&gt;&lt;p&gt;Rather than treating cybersecurity as a closed technical discipline, this episode highlights the importance of public awareness, responsible digital behavior, community-driven learning, and the role of professional initiatives such as OWASP Algiers in strengthening cybersecurity maturity.&lt;/p&gt;&lt;p&gt;Topics include:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Information security&lt;/li&gt;&lt;li&gt;Cybersecurity awareness&lt;/li&gt;&lt;li&gt;OWASP Algiers&lt;/li&gt;&lt;li&gt;Community building&lt;/li&gt;&lt;li&gt;Public cyber education&lt;/li&gt;&lt;li&gt;Digital trust&lt;/li&gt;&lt;li&gt;Online risk&lt;/li&gt;&lt;li&gt;The role of local initiatives in strengthening cyber maturity&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;Note: This episode is adapted from a public radio/media appearance featuring Taher Amine ELHOUARI. All rights to the original recording remain with their respective owners.&lt;/p&gt;</content:encoded>
                
                <enclosure length="29715644" type="audio/mpeg" url="https://audio4.redcircle.com/episodes/e2d533df-7271-4787-93b2-963340158a17/stream.mp3"/>
                
                <guid isPermaLink="false">fe211bc2-3492-4ec5-9271-7374e710c3fd</guid>
                <link>https://www.youtube.com/watch?v=fcZ6ZeTCEBY</link>
                <pubDate>Tue, 23 Jun 2026 15:30:50 &#43;0000</pubDate>
                <itunes:duration>1857</itunes:duration>
                
                
                <itunes:explicit>false</itunes:explicit>
                
            </item>
        
            <item>
                <itunes:episodeType>bonus</itunes:episodeType>
                <itunes:title>Media Archive: OWASP Algiers &amp; TechVerse Club on Radio Médéa</itunes:title>
                <title>Media Archive: OWASP Algiers &amp; TechVerse Club on Radio Médéa</title>

                
                <itunes:season>1</itunes:season>
                <itunes:author>Taher Amine ELHOUARI</itunes:author>
                <itunes:subtitle>A public radio appearance on cybersecurity awareness, community building, and the role of local tech initiatives.</itunes:subtitle>
                <itunes:summary>A Media Archive episode featuring Taher Amine ELHOUARI’s public radio appearance connected to the TID event, OWASP Algiers, and TechVerse Club on Radio Médéa, covering cybersecurity awareness, community building, public education, and local cybersecurity maturity.</itunes:summary>
                <description><![CDATA[<p>In this Media Archive episode of The InfoSec Control Room, Taher Amine ELHOUARI shares a public radio appearance connected to the TID event, OWASP Algiers, and TechVerse Club on Radio Médéa.</p><p>This episode highlights the community and awareness side of cybersecurity: bringing security knowledge closer to students, young professionals, developers, and the wider public through local initiatives, events, and public discussion.</p><p>The discussion reflects one of the core missions of The InfoSec Control Room: making cybersecurity, governance, risk, and resilience practical, accessible, and connected to real communities.</p><p>Rather than treating cybersecurity as a closed technical discipline, this episode emphasizes the importance of community building, public awareness, responsible digital behavior, and the role of local cybersecurity initiatives in strengthening national cyber maturity.</p><p>Topics include:</p><ul><li>Cybersecurity awareness</li><li>Community building</li><li>OWASP Algiers</li><li>TechVerse Club</li><li>Public cyber education</li><li>Local tech initiatives</li><li>Digital trust</li><li>The role of communities in strengthening cybersecurity maturity</li></ul><p><br></p><p>Note: This episode is adapted from a public radio/media appearance featuring Taher Amine ELHOUARI. All rights to the original recording remain with their respective owners.</p>]]></description>
                <content:encoded>&lt;p&gt;In this Media Archive episode of The InfoSec Control Room, Taher Amine ELHOUARI shares a public radio appearance connected to the TID event, OWASP Algiers, and TechVerse Club on Radio Médéa.&lt;/p&gt;&lt;p&gt;This episode highlights the community and awareness side of cybersecurity: bringing security knowledge closer to students, young professionals, developers, and the wider public through local initiatives, events, and public discussion.&lt;/p&gt;&lt;p&gt;The discussion reflects one of the core missions of The InfoSec Control Room: making cybersecurity, governance, risk, and resilience practical, accessible, and connected to real communities.&lt;/p&gt;&lt;p&gt;Rather than treating cybersecurity as a closed technical discipline, this episode emphasizes the importance of community building, public awareness, responsible digital behavior, and the role of local cybersecurity initiatives in strengthening national cyber maturity.&lt;/p&gt;&lt;p&gt;Topics include:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Cybersecurity awareness&lt;/li&gt;&lt;li&gt;Community building&lt;/li&gt;&lt;li&gt;OWASP Algiers&lt;/li&gt;&lt;li&gt;TechVerse Club&lt;/li&gt;&lt;li&gt;Public cyber education&lt;/li&gt;&lt;li&gt;Local tech initiatives&lt;/li&gt;&lt;li&gt;Digital trust&lt;/li&gt;&lt;li&gt;The role of communities in strengthening cybersecurity maturity&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;Note: This episode is adapted from a public radio/media appearance featuring Taher Amine ELHOUARI. All rights to the original recording remain with their respective owners.&lt;/p&gt;</content:encoded>
                
                <enclosure length="32524329" type="audio/mpeg" url="https://audio4.redcircle.com/episodes/fd5c8a80-ae0b-4814-9559-94e0139857fa/stream.mp3"/>
                
                <guid isPermaLink="false">b4a71209-dab8-4608-9750-549b8f608000</guid>
                <link>https://www.youtube.com/watch?v=RagJQTKc89I</link>
                <pubDate>Tue, 23 Jun 2026 15:25:22 &#43;0000</pubDate>
                <itunes:duration>2032</itunes:duration>
                
                
                <itunes:explicit>false</itunes:explicit>
                
            </item>
        
            <item>
                <itunes:episodeType>bonus</itunes:episodeType>
                <itunes:title>Media Archive: Cybersecurity Awareness Session on Algerian National TV</itunes:title>
                <title>Media Archive: Cybersecurity Awareness Session on Algerian National TV</title>

                
                <itunes:season>1</itunes:season>
                <itunes:author>Taher Amine ELHOUARI</itunes:author>
                <itunes:subtitle>A public awareness session on cybersecurity, digital safety, online risk, and security culture.</itunes:subtitle>
                <itunes:summary>A Media Archive episode featuring Taher Amine ELHOUARI’s cybersecurity awareness session on Algerian National Television, covering digital safety, online risk, public education, security culture, and digital trust.</itunes:summary>
                <description><![CDATA[<p>In this Media Archive episode of The InfoSec Control Room, Taher Amine ELHOUARI shares a cybersecurity awareness session originally featured on Algerian National Television.</p><p>This episode focuses on making cybersecurity understandable for a wider public audience, connecting technical security concepts with everyday digital behavior, online risk, awareness, and the role of experts in helping society build stronger cyber maturity.</p><p>The discussion reflects one of the core missions of The InfoSec Control Room: turning cybersecurity, governance, risk, and resilience into practical knowledge that people, organizations, and decision-makers can actually use.</p><p>Rather than treating cybersecurity as only a technical discipline, this session highlights the importance of awareness, responsibility, digital trust, and security culture in reducing cyber risk.</p><p>Topics include:</p><ul><li>Cybersecurity awareness</li><li>Digital safety</li><li>Online risk</li><li>Public cyber education</li><li>Security culture</li><li>Digital trust</li><li>The role of experts in strengthening cyber maturity</li></ul><p><br></p><p>Note: This episode is adapted from a public media appearance featuring Taher Amine ELHOUARI. All rights to the original recording remain with their respective owners.</p>]]></description>
                <content:encoded>&lt;p&gt;In this Media Archive episode of The InfoSec Control Room, Taher Amine ELHOUARI shares a cybersecurity awareness session originally featured on Algerian National Television.&lt;/p&gt;&lt;p&gt;This episode focuses on making cybersecurity understandable for a wider public audience, connecting technical security concepts with everyday digital behavior, online risk, awareness, and the role of experts in helping society build stronger cyber maturity.&lt;/p&gt;&lt;p&gt;The discussion reflects one of the core missions of The InfoSec Control Room: turning cybersecurity, governance, risk, and resilience into practical knowledge that people, organizations, and decision-makers can actually use.&lt;/p&gt;&lt;p&gt;Rather than treating cybersecurity as only a technical discipline, this session highlights the importance of awareness, responsibility, digital trust, and security culture in reducing cyber risk.&lt;/p&gt;&lt;p&gt;Topics include:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Cybersecurity awareness&lt;/li&gt;&lt;li&gt;Digital safety&lt;/li&gt;&lt;li&gt;Online risk&lt;/li&gt;&lt;li&gt;Public cyber education&lt;/li&gt;&lt;li&gt;Security culture&lt;/li&gt;&lt;li&gt;Digital trust&lt;/li&gt;&lt;li&gt;The role of experts in strengthening cyber maturity&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;Note: This episode is adapted from a public media appearance featuring Taher Amine ELHOUARI. All rights to the original recording remain with their respective owners.&lt;/p&gt;</content:encoded>
                
                <enclosure length="14349374" type="audio/mpeg" url="https://audio4.redcircle.com/episodes/638bdad7-6733-4158-bd4b-a405f2090d74/stream.mp3"/>
                
                <guid isPermaLink="false">c609fc56-f6f8-4c4b-90da-03f86cfe01ea</guid>
                <link>https://www.youtube.com/watch?v=OXWxCCP7Yrg</link>
                <pubDate>Tue, 23 Jun 2026 15:19:46 &#43;0000</pubDate>
                <itunes:duration>896</itunes:duration>
                
                
                <itunes:explicit>false</itunes:explicit>
                
            </item>
        
            <item>
                <itunes:episodeType>bonus</itunes:episodeType>
                <itunes:title>Media Archive: Cybersecurity Zero to Hero with The Algerian Developer</itunes:title>
                <title>Media Archive: Cybersecurity Zero to Hero with The Algerian Developer</title>

                
                <itunes:season>1</itunes:season>
                <itunes:author>Taher Amine ELHOUARI</itunes:author>
                <itunes:subtitle>A community live show on cybersecurity fundamentals, learning paths, awareness, and professional growth.</itunes:subtitle>
                <itunes:summary>A Media Archive episode featuring Taher Amine ELHOUARI’s Cybersecurity Zero to Hero live show with The Algerian Developer, covering cybersecurity fundamentals, learning paths, awareness, ethical practice, community learning, and professional growth.</itunes:summary>
                <description><![CDATA[<p>In this Media Archive episode of The InfoSec Control Room, Taher Amine ELHOUARI shares a cybersecurity live show originally hosted by TAD — The Algerian Developer.</p><p>This session focuses on the journey from cybersecurity fundamentals to professional growth, helping learners, students, developers, and aspiring security practitioners understand how to approach the field with the right mindset, discipline, and practical learning path.</p><p>The discussion reflects one of the core missions of The InfoSec Control Room: making cybersecurity, governance, risk, and resilience understandable, practical, and connected to real-world professional development.</p><p>Rather than presenting cybersecurity as only a technical skillset, this episode highlights the importance of awareness, ethics, structured learning, continuous practice, community engagement, and the ability to connect technical expertise with real organizational needs.</p><p>Topics include:</p><ul><li>Cybersecurity fundamentals</li><li>Cybersecurity career development</li><li>Learning paths for beginners</li><li>Ethical hacking and responsible practice</li><li>Security awareness</li><li>Community learning</li><li>Professional growth in information security</li><li>The role of practitioners in strengthening cyber maturity</li></ul><p><br></p><p>Note: This episode is adapted from a public live show featuring Taher Amine ELHOUARI. All rights to the original recording remain with their respective owners.</p>]]></description>
                <content:encoded>&lt;p&gt;In this Media Archive episode of The InfoSec Control Room, Taher Amine ELHOUARI shares a cybersecurity live show originally hosted by TAD — The Algerian Developer.&lt;/p&gt;&lt;p&gt;This session focuses on the journey from cybersecurity fundamentals to professional growth, helping learners, students, developers, and aspiring security practitioners understand how to approach the field with the right mindset, discipline, and practical learning path.&lt;/p&gt;&lt;p&gt;The discussion reflects one of the core missions of The InfoSec Control Room: making cybersecurity, governance, risk, and resilience understandable, practical, and connected to real-world professional development.&lt;/p&gt;&lt;p&gt;Rather than presenting cybersecurity as only a technical skillset, this episode highlights the importance of awareness, ethics, structured learning, continuous practice, community engagement, and the ability to connect technical expertise with real organizational needs.&lt;/p&gt;&lt;p&gt;Topics include:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Cybersecurity fundamentals&lt;/li&gt;&lt;li&gt;Cybersecurity career development&lt;/li&gt;&lt;li&gt;Learning paths for beginners&lt;/li&gt;&lt;li&gt;Ethical hacking and responsible practice&lt;/li&gt;&lt;li&gt;Security awareness&lt;/li&gt;&lt;li&gt;Community learning&lt;/li&gt;&lt;li&gt;Professional growth in information security&lt;/li&gt;&lt;li&gt;The role of practitioners in strengthening cyber maturity&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;Note: This episode is adapted from a public live show featuring Taher Amine ELHOUARI. All rights to the original recording remain with their respective owners.&lt;/p&gt;</content:encoded>
                
                <enclosure length="85674945" type="audio/mpeg" url="https://audio4.redcircle.com/episodes/661df340-e2c3-42a5-ac46-4498dd28342e/stream.mp3"/>
                
                <guid isPermaLink="false">07e023e1-c372-4bfa-8793-77ca9a4477ef</guid>
                <link>https://www.youtube.com/watch?v=jqGHwSMRd4I</link>
                <pubDate>Tue, 23 Jun 2026 15:18:28 &#43;0000</pubDate>
                <itunes:duration>5354</itunes:duration>
                
                
                <itunes:explicit>false</itunes:explicit>
                
            </item>
        
            <item>
                <itunes:episodeType>bonus</itunes:episodeType>
                <itunes:title>Media Archive: Cybersecurity Interview at Eco-Podcast</itunes:title>
                <title>Media Archive: Cybersecurity Interview at Eco-Podcast</title>

                
                <itunes:season>1</itunes:season>
                <itunes:author>Taher Amine ELHOUARI</itunes:author>
                <itunes:subtitle>A public interview on cybersecurity, information security leadership, digital trust, and professional growth.</itunes:subtitle>
                <itunes:summary>A Media Archive episode featuring Taher Amine ELHOUARI’s cybersecurity interview on EcoPodcast, discussing cybersecurity, information security leadership, digital trust, professional growth, awareness, and cyber maturity.</itunes:summary>
                <description><![CDATA[<p>In this Media Archive episode of The InfoSec Control Room, Taher Amine ELHOUARI shares a public cybersecurity interview originally featured on Eco-Podcast.</p><p>The discussion explores cybersecurity, information security leadership, digital trust, professional development, and the role of security practitioners in helping organizations and society better understand cyber risk.</p><p>This episode reflects the broader mission of The InfoSec Control Room: connecting cybersecurity, governance, risk, resilience, and field experience in a practical way for professionals, students, leaders, and decision-makers.</p><p>Topics include:</p><ul><li>Cybersecurity and information security</li><li>Digital trust</li><li>Security leadership</li><li>Professional growth in cybersecurity</li><li>Awareness and public education</li><li>The role of practitioners in strengthening cyber maturity</li></ul><p><br></p><p>Note: This episode is adapted from a public interview featuring Taher Amine ELHOUARI. All rights to the original recording remain with their respective owners.</p>]]></description>
                <content:encoded>&lt;p&gt;In this Media Archive episode of The InfoSec Control Room, Taher Amine ELHOUARI shares a public cybersecurity interview originally featured on Eco-Podcast.&lt;/p&gt;&lt;p&gt;The discussion explores cybersecurity, information security leadership, digital trust, professional development, and the role of security practitioners in helping organizations and society better understand cyber risk.&lt;/p&gt;&lt;p&gt;This episode reflects the broader mission of The InfoSec Control Room: connecting cybersecurity, governance, risk, resilience, and field experience in a practical way for professionals, students, leaders, and decision-makers.&lt;/p&gt;&lt;p&gt;Topics include:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Cybersecurity and information security&lt;/li&gt;&lt;li&gt;Digital trust&lt;/li&gt;&lt;li&gt;Security leadership&lt;/li&gt;&lt;li&gt;Professional growth in cybersecurity&lt;/li&gt;&lt;li&gt;Awareness and public education&lt;/li&gt;&lt;li&gt;The role of practitioners in strengthening cyber maturity&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;Note: This episode is adapted from a public interview featuring Taher Amine ELHOUARI. All rights to the original recording remain with their respective owners.&lt;/p&gt;</content:encoded>
                
                <enclosure length="24856868" type="audio/mpeg" url="https://audio4.redcircle.com/episodes/8583e4d9-ff7b-43fb-8d16-fbbf69dc4608/stream.mp3"/>
                
                <guid isPermaLink="false">335ee615-ba59-4cfc-b6f3-cfbf812e807b</guid>
                <link>https://www.youtube.com/watch?v=SRKU7K7UQWI</link>
                <pubDate>Tue, 23 Jun 2026 12:55:40 &#43;0000</pubDate>
                <itunes:duration>1553</itunes:duration>
                
                
                <itunes:explicit>false</itunes:explicit>
                
            </item>
        
            <item>
                <itunes:episodeType>bonus</itunes:episodeType>
                <itunes:title>Media Archive: Cybersecurity and Privacy at JilTech 3rd Edition</itunes:title>
                <title>Media Archive: Cybersecurity and Privacy at JilTech 3rd Edition</title>

                
                <itunes:season>1</itunes:season>
                <itunes:author>Taher Amine ELHOUARI</itunes:author>
                <itunes:subtitle>A public talk on cybersecurity, privacy, digital trust, and practical security awareness.</itunes:subtitle>
                <itunes:summary>APPLE SUMMARY:
A Media Archive episode featuring Taher Amine ELHOUARI’s cybersecurity and privacy intervention at JilTech 3rd Edition in Ghardaia, Algeria, covering awareness, privacy, digital trust, online risk, and practical security culture.</itunes:summary>
                <description><![CDATA[<p>In this Media Archive episode of The InfoSec Control Room, Taher Amine ELHOUARI shares a public cybersecurity and privacy intervention delivered during JilTech 3rd Edition in Ghardaia, Algeria.</p><p>This session reflects the educational and awareness side of cybersecurity: helping audiences understand how information security, privacy, digital behavior, and cyber risk connect in real-world environments.</p><p>The discussion aligns with the mission of The InfoSec Control Room: making cybersecurity, governance, risk, compliance, and resilience practical, understandable, and relevant for professionals, students, leaders, and the wider public.</p><p>Rather than treating cybersecurity as only a technical discipline, this episode highlights the importance of awareness, privacy protection, responsible digital behavior, security culture, and the role of practitioners in strengthening cyber maturity.</p><p>Topics include:</p><ul><li>Cybersecurity awareness</li><li>Privacy and data protection</li><li>Digital trust</li><li>Online risk</li><li>Responsible security behavior</li><li>Public cyber education</li><li>The role of experts in strengthening cybersecurity maturity</li></ul><p><br></p><p>Note: This episode is adapted from a public event appearance featuring Taher Amine ELHOUARI. All rights to the original recording remain with their respective owners.</p>]]></description>
                <content:encoded>&lt;p&gt;In this Media Archive episode of The InfoSec Control Room, Taher Amine ELHOUARI shares a public cybersecurity and privacy intervention delivered during JilTech 3rd Edition in Ghardaia, Algeria.&lt;/p&gt;&lt;p&gt;This session reflects the educational and awareness side of cybersecurity: helping audiences understand how information security, privacy, digital behavior, and cyber risk connect in real-world environments.&lt;/p&gt;&lt;p&gt;The discussion aligns with the mission of The InfoSec Control Room: making cybersecurity, governance, risk, compliance, and resilience practical, understandable, and relevant for professionals, students, leaders, and the wider public.&lt;/p&gt;&lt;p&gt;Rather than treating cybersecurity as only a technical discipline, this episode highlights the importance of awareness, privacy protection, responsible digital behavior, security culture, and the role of practitioners in strengthening cyber maturity.&lt;/p&gt;&lt;p&gt;Topics include:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Cybersecurity awareness&lt;/li&gt;&lt;li&gt;Privacy and data protection&lt;/li&gt;&lt;li&gt;Digital trust&lt;/li&gt;&lt;li&gt;Online risk&lt;/li&gt;&lt;li&gt;Responsible security behavior&lt;/li&gt;&lt;li&gt;Public cyber education&lt;/li&gt;&lt;li&gt;The role of experts in strengthening cybersecurity maturity&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;Note: This episode is adapted from a public event appearance featuring Taher Amine ELHOUARI. All rights to the original recording remain with their respective owners.&lt;/p&gt;</content:encoded>
                
                <enclosure length="117586964" type="audio/mpeg" url="https://audio4.redcircle.com/episodes/bc9ede55-c7f8-4455-9823-c5f0aad2eacf/stream.mp3"/>
                
                <guid isPermaLink="false">04cdd9c5-783c-4a45-98ab-124bc35d3267</guid>
                <link>https://www.youtube.com/watch?v=-rIfne2rswE</link>
                <pubDate>Tue, 23 Jun 2026 12:10:54 &#43;0000</pubDate>
                <itunes:duration>7349</itunes:duration>
                
                
                <itunes:explicit>false</itunes:explicit>
                
            </item>
        
            <item>
                <itunes:episodeType>bonus</itunes:episodeType>
                <itunes:title>Media Archive: Cybersecurity Fundamentals Masterclass with GoMyCode</itunes:title>
                <title>Media Archive: Cybersecurity Fundamentals Masterclass with GoMyCode</title>

                
                <itunes:season>1</itunes:season>
                <itunes:author>Taher Amine ELHOUARI</itunes:author>
                <itunes:subtitle>A cybersecurity masterclass on fundamentals, awareness, career development, and practical security thinking.</itunes:subtitle>
                <itunes:summary>A Media Archive episode featuring Taher Amine ELHOUARI’s cybersecurity fundamentals masterclass with GoMyCode, covering awareness, ethical practice, digital safety, career development, and practical security thinking.</itunes:summary>
                <description><![CDATA[<p>In this Media Archive episode of The InfoSec Control Room, Taher Amine ELHOUARI shares a cybersecurity fundamentals masterclass originally delivered with GoMyCode.</p><p>This session focuses on making cybersecurity more accessible, practical, and understandable for learners, students, professionals, and anyone interested in entering or strengthening their path in information security.</p><p>The discussion reflects one of the core missions of The InfoSec Control Room: connecting cybersecurity knowledge with practical thinking, governance awareness, digital trust, and real-world security maturity.</p><p>Rather than treating cybersecurity as a purely technical subject, this masterclass highlights the importance of understanding risk, responsible behavior, ethical practice, continuous learning, and the mindset required to build a serious career in the field.</p><p>Topics include:</p><ul><li>Cybersecurity fundamentals</li><li>Information security awareness</li><li>Ethical hacking and responsible practice</li><li>Cybersecurity career development</li><li>Digital safety and online risk</li><li>Practical learning paths</li><li>The role of education in strengthening cyber maturity</li></ul><p><br></p><p>Note: This episode is adapted from a public masterclass featuring Taher Amine ELHOUARI. All rights to the original recording remain with their respective owners.</p>]]></description>
                <content:encoded>&lt;p&gt;In this Media Archive episode of The InfoSec Control Room, Taher Amine ELHOUARI shares a cybersecurity fundamentals masterclass originally delivered with GoMyCode.&lt;/p&gt;&lt;p&gt;This session focuses on making cybersecurity more accessible, practical, and understandable for learners, students, professionals, and anyone interested in entering or strengthening their path in information security.&lt;/p&gt;&lt;p&gt;The discussion reflects one of the core missions of The InfoSec Control Room: connecting cybersecurity knowledge with practical thinking, governance awareness, digital trust, and real-world security maturity.&lt;/p&gt;&lt;p&gt;Rather than treating cybersecurity as a purely technical subject, this masterclass highlights the importance of understanding risk, responsible behavior, ethical practice, continuous learning, and the mindset required to build a serious career in the field.&lt;/p&gt;&lt;p&gt;Topics include:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Cybersecurity fundamentals&lt;/li&gt;&lt;li&gt;Information security awareness&lt;/li&gt;&lt;li&gt;Ethical hacking and responsible practice&lt;/li&gt;&lt;li&gt;Cybersecurity career development&lt;/li&gt;&lt;li&gt;Digital safety and online risk&lt;/li&gt;&lt;li&gt;Practical learning paths&lt;/li&gt;&lt;li&gt;The role of education in strengthening cyber maturity&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;Note: This episode is adapted from a public masterclass featuring Taher Amine ELHOUARI. All rights to the original recording remain with their respective owners.&lt;/p&gt;</content:encoded>
                
                <enclosure length="111488104" type="audio/mpeg" url="https://audio4.redcircle.com/episodes/e9f09135-29c7-45ec-8cff-21de76881946/stream.mp3"/>
                
                <guid isPermaLink="false">069262f6-2db9-423e-8526-3f4405473a9b</guid>
                <link>https://www.youtube.com/watch?v=RwTmHW6hPQM</link>
                <pubDate>Tue, 23 Jun 2026 12:04:30 &#43;0000</pubDate>
                <itunes:duration>6968</itunes:duration>
                
                
                <itunes:explicit>false</itunes:explicit>
                
            </item>
        
            <item>
                <itunes:episodeType>bonus</itunes:episodeType>
                <itunes:title>Media Archive: Cybersecurity Experts Panel at ICT Maghreb 2023</itunes:title>
                <title>Media Archive: Cybersecurity Experts Panel at ICT Maghreb 2023</title>

                
                <itunes:season>1</itunes:season>
                <itunes:author>Taher Amine ELHOUARI</itunes:author>
                <itunes:subtitle>A public panel discussion on cybersecurity, expertise, awareness, and the role of security leaders.</itunes:subtitle>
                <itunes:summary>A Media Archive episode featuring Taher Amine ELHOUARI’s cybersecurity experts panel intervention at ICT Maghreb 2023, discussing cyber awareness, security leadership, digital trust, expert perspectives, and the role of practitioners in strengthening cybersecurity maturity.</itunes:summary>
                <description><![CDATA[<p>In this Media Archive episode of The InfoSec Control Room, Taher Amine ELHOUARI shares a recorded cybersecurity experts panel intervention from ICT Maghreb 2023.</p><p>This discussion reflects the public speaking and industry-engagement side of cybersecurity: exchanging perspectives with experts, addressing real-world cyber challenges, and helping a wider audience understand the role of security leadership, awareness, governance, and technical expertise in building safer digital ecosystems.</p><p>The episode fits the mission of The InfoSec Control Room: connecting cybersecurity, governance, risk, resilience, and practical field experience in a way that is useful for professionals, students, leaders, and decision-makers.</p><p>Original appearance: ICT Maghreb 2023.</p><p>Topics include:</p><ul><li>Cybersecurity awareness</li><li>Expert perspectives on cyber risk</li><li>Security leadership</li><li>Public and professional cyber education</li><li>Industry challenges</li><li>Digital trust</li><li>The role of practitioners in strengthening cybersecurity maturity</li></ul><p><br></p><p>Note: This episode is adapted from a public media/panel appearance by Taher Amine ELHOUARI. All rights to the original recording remain with their respective owners.</p>]]></description>
                <content:encoded>&lt;p&gt;In this Media Archive episode of The InfoSec Control Room, Taher Amine ELHOUARI shares a recorded cybersecurity experts panel intervention from ICT Maghreb 2023.&lt;/p&gt;&lt;p&gt;This discussion reflects the public speaking and industry-engagement side of cybersecurity: exchanging perspectives with experts, addressing real-world cyber challenges, and helping a wider audience understand the role of security leadership, awareness, governance, and technical expertise in building safer digital ecosystems.&lt;/p&gt;&lt;p&gt;The episode fits the mission of The InfoSec Control Room: connecting cybersecurity, governance, risk, resilience, and practical field experience in a way that is useful for professionals, students, leaders, and decision-makers.&lt;/p&gt;&lt;p&gt;Original appearance: ICT Maghreb 2023.&lt;/p&gt;&lt;p&gt;Topics include:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Cybersecurity awareness&lt;/li&gt;&lt;li&gt;Expert perspectives on cyber risk&lt;/li&gt;&lt;li&gt;Security leadership&lt;/li&gt;&lt;li&gt;Public and professional cyber education&lt;/li&gt;&lt;li&gt;Industry challenges&lt;/li&gt;&lt;li&gt;Digital trust&lt;/li&gt;&lt;li&gt;The role of practitioners in strengthening cybersecurity maturity&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;Note: This episode is adapted from a public media/panel appearance by Taher Amine ELHOUARI. All rights to the original recording remain with their respective owners.&lt;/p&gt;</content:encoded>
                
                <enclosure length="11868369" type="audio/mpeg" url="https://audio4.redcircle.com/episodes/9135f170-1c58-42a7-a22f-eecb653f8693/stream.mp3"/>
                
                <guid isPermaLink="false">e3fdbe9f-d062-4dac-837f-e16b6ffdd4fc</guid>
                <link>https://www.youtube.com/watch?v=8auU8SkpZZo</link>
                <pubDate>Tue, 23 Jun 2026 12:00:55 &#43;0000</pubDate>
                <itunes:duration>741</itunes:duration>
                
                
                <itunes:explicit>false</itunes:explicit>
                
            </item>
        
            <item>
                <itunes:episodeType>bonus</itunes:episodeType>
                <itunes:title>Media Archive: Cybersecurity Awareness on Algerian National Television</itunes:title>
                <title>Media Archive: Cybersecurity Awareness on Algerian National Television</title>

                
                <itunes:season>1</itunes:season>
                <itunes:author>Taher Amine ELHOUARI</itunes:author>
                <itunes:subtitle>A media archive episode on cybersecurity awareness, ethical hacking, digital safety, and public cyber education.</itunes:subtitle>
                <itunes:summary>A Media Archive episode featuring Taher Amine ELHOUARI’s public appearance as a cybersecurity expert on Algerian National Television, discussing cybersecurity awareness, ethical hacking, digital safety, online risk, and the importance of building a stronger security culture.</itunes:summary>
                <description><![CDATA[<p>In this Media Archive episode of The InfoSec Control Room, Taher Amine ELHOUARI shares a public media appearance as a cybersecurity expert on Algerian National Television.</p><p>The discussion focuses on cybersecurity awareness, ethical hacking, online risk, digital safety, and the importance of helping the public understand how cyber threats affect individuals, organizations, and society.</p><p>This episode reflects one of the core missions of The InfoSec Control Room: making cybersecurity, governance, risk, and resilience understandable, practical, and connected to real-world impact.</p><p><em>Original appearance: May 10, 2023.</em></p><p>Topics include:</p><ul><li>Cybersecurity awareness</li><li>Ethical hacking</li><li>Digital safety</li><li>Online risk</li><li>Public education</li><li>Security culture</li><li>The role of experts in strengthening cyber awareness</li></ul><p><br></p><p><strong>Note:</strong> This episode is adapted from a public media appearance by Taher Amine ELHOUARI. All rights to the original broadcast remain with their respective owners.</p>]]></description>
                <content:encoded>&lt;p&gt;In this Media Archive episode of The InfoSec Control Room, Taher Amine ELHOUARI shares a public media appearance as a cybersecurity expert on Algerian National Television.&lt;/p&gt;&lt;p&gt;The discussion focuses on cybersecurity awareness, ethical hacking, online risk, digital safety, and the importance of helping the public understand how cyber threats affect individuals, organizations, and society.&lt;/p&gt;&lt;p&gt;This episode reflects one of the core missions of The InfoSec Control Room: making cybersecurity, governance, risk, and resilience understandable, practical, and connected to real-world impact.&lt;/p&gt;&lt;p&gt;&lt;em&gt;Original appearance: May 10, 2023.&lt;/em&gt;&lt;/p&gt;&lt;p&gt;Topics include:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Cybersecurity awareness&lt;/li&gt;&lt;li&gt;Ethical hacking&lt;/li&gt;&lt;li&gt;Digital safety&lt;/li&gt;&lt;li&gt;Online risk&lt;/li&gt;&lt;li&gt;Public education&lt;/li&gt;&lt;li&gt;Security culture&lt;/li&gt;&lt;li&gt;The role of experts in strengthening cyber awareness&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; This episode is adapted from a public media appearance by Taher Amine ELHOUARI. All rights to the original broadcast remain with their respective owners.&lt;/p&gt;</content:encoded>
                
                <enclosure length="6172839" type="audio/mpeg" url="https://audio4.redcircle.com/episodes/b0a3c60d-67e9-4a01-9fb1-0c68974a16d0/stream.mp3"/>
                
                <guid isPermaLink="false">5c462bbe-6c53-4f2d-92b7-a9adb4f7a579</guid>
                <link>https://www.youtube.com/watch?v=EAihPhYsEcw</link>
                <pubDate>Wed, 10 May 2023 12:00:58 &#43;0000</pubDate>
                <itunes:duration>385</itunes:duration>
                
                
                <itunes:explicit>false</itunes:explicit>
                
            </item>
        
    </channel>
</rss>
