- EP013: You Outsourced the Service, Not the Risk
In EP013 of The InfoSec Control Room, I look at one of the most common misconceptions in modern cybersecurity and business operations: the idea that outsourcing a service also outsources the risk.
Organizations rely on cloud providers, SaaS platforms, MSSPs, payroll processors, payment providers, telecom operators, external developers, consultants, and many other partners. That is normal. The problem begins when the organization starts treating the supplier’s responsibility as if it removed its own accountability.
This episode explores what really changes when a service is outsourced and what does not. I talk about supplier dependency, shared responsibility, third-party access, contractual obligations, incident notification, concentration risk, subcontractors, exit planning, offboarding, data handling, recovery, and the need to maintain enough internal capability to challenge and govern a provider effectively.
I also look at why third-party risk cannot be reduced to questionnaires and certificates. A supplier may have strong controls and still create major exposure if your business becomes heavily dependent on it. The real question is not only whether the provider is secure. It is what that provider means to your organization if something goes wrong.
One of the core ideas from EP013 is simple: you can outsource the service, but you do not outsource the consequences.
Customers still call you. Regulators still call you. The board still calls you. Your business still absorbs the disruption. Outsourcing can transfer operational responsibility, but it does not make accountability disappear.
S1E13 - 17m - Sep 12, 2026 - EP012: Cyber Resilience — What Happens After Prevention Fails
In EP012 of The InfoSec Control Room, I explore what happens when prevention is no longer enough.
Security programs spend enormous effort trying to stop incidents, outages, compromises, and failures before they happen. That work matters. But no control is perfect, no environment is static, and eventually something will get through, break, fail, or become unavailable.
The real question then becomes: can the organization still function?
This episode looks at cyber resilience as more than backups, disaster recovery, incident response, or business continuity. It is about the organization’s ability to absorb disruption, keep essential services running, adapt under pressure, recover deliberately, and improve afterward instead of simply rebuilding the same weaknesses.
I discuss critical services, hidden dependencies, realistic recovery expectations, graceful degradation, manual workarounds, supplier dependency, recovery sequencing, people as part of resilience, and why the business should test services rather than simply servers.
The episode also explores why “returning to normal” is not always the right objective. Sometimes normal was the problem. A serious disruption should create an opportunity to change architecture, remove weak dependencies, improve access, replace poor suppliers, and strengthen the way the organization operates.
One of the main ideas from EP012 is this: resilience is not invulnerability. It is the ability to take a hit without losing the organization’s ability to function.
Strong organizations are not the ones that never experience disruption. They are the ones that know what matters, understand what they depend on, keep essential operations moving, recover with intention, and learn enough from disruption to come back stronger.
S1E12 - 17m - Sep 7, 2026 - EP011: ISO 27001 Is Not the Certificate on the Wall
In EP011 of The InfoSec Control Room, I look at what happens after an organization earns its ISO/IEC 27001 certificate.
Certification can be valuable. It can bring structure, discipline, credibility, and a much clearer way to manage information security. But problems begin when the certificate becomes the objective instead of the result of a functioning management system.
This episode explores the difference between maintaining an ISMS because an audit is approaching and actually using it throughout the year. I discuss risk ownership that exists only in spreadsheets, Statements of Applicability that stop reflecting reality, internal audits treated as rehearsals for certification, corrective actions that close tickets without fixing problems, and management reviews where everybody says “noted” but no real decision is made.
I also look at the role of consultants, auditors, control owners, risk owners, and senior management in making ISO 27001 useful rather than ceremonial. A good ISMS should survive the consultant, adapt when the business changes, learn from incidents and findings, challenge old assumptions, and help people make better security decisions even when no auditor is watching.
One of the main ideas from EP011 is simple: there is a huge difference between an organization that documents how it manages information security and one that manages documents about information security.
The certificate matters, but the real value is underneath it: the decisions, ownership, corrections, useful findings, changing risks, and improvements that happen between audits.
S1E11 - 15m - Sep 5, 2026 - EP010: The Board Does Not Need Another Cyber Dashboard
In EP010 of The InfoSec Control Room, I look at a problem that appears in almost every cybersecurity program: organizations produce more security data than ever, yet leadership still struggles to understand what actually matters.
Boards are shown vulnerabilities, alerts, patch percentages, phishing results, incidents, audit findings, risk scores, trend lines, heat maps, and plenty of red, amber, and green boxes. But more information does not automatically mean better decisions.
This episode explores the difference between operational security reporting and executive decision support. A board does not need to know everything the security team knows. It needs a clear view of what changed, where the business is genuinely exposed, which weaknesses matter most, what uncertainty remains, and where leadership needs to make a decision.
I discuss why totals and averages can hide serious risk, why a “green” metric may still conceal an unacceptable exposure, why repeatedly presenting red issues without action makes dashboards meaningless, and why cybersecurity reporting should connect technical weaknesses to business consequences rather than simply presenting activity.
We also look at why board reporting should focus more on movement than status, why security leaders should be comfortable saying “we do not know” when assurance is incomplete, and how to turn reporting into a conversation about priorities, trade-offs, investment, risk acceptance, and accountability.
One of the central ideas from EP010 is simple: the purpose of board reporting is not to demonstrate how busy cybersecurity has been. It is to help leadership make better decisions.
The board does not need another dashboard. It needs clarity about what matters, what changed, what could hurt the business, and what leadership needs to do next.
S1E10 - 17m - Sep 4, 2026 - EP009: Your CSIRT Is Not Ready Just Because It Exists
In EP009 of The InfoSec Control Room, I look beyond the simple statement, “We have a CSIRT,” and ask the question that actually matters: what can that team really do when something serious happens?
A CSIRT can exist on the organization chart, have assigned staff, procedures, tooling, and even a dedicated mailbox, while still being poorly prepared for a real incident. Readiness comes from much more practical things: knowing exactly what the team is responsible for, who it serves, how people reach it, what happens outside business hours, what access responders already have, how cases are handed over, how other departments work with the team, and where outside help is needed.
This episode looks at the difference between a CSIRT that exists and one that can actually function under pressure. I discuss service boundaries, availability, access to systems and logs, case management, practical exercises, relationships with legal and business teams, communication during uncertain situations, team skills, external support, incident closure, lessons learned, and the danger of depending too heavily on a few individuals who hold everything together.
I also explore why a CSIRT should not simply process incidents and move on. A strong response team notices patterns, exposes recurring weaknesses, feeds lessons back into the organization, and helps improve the environment that keeps producing those incidents.
One of the main ideas from EP009 is simple: a CSIRT is not ready because management created one. It is ready when people know how to use it, when the team knows what it owns, when it can reach the right systems and people, and when it can work effectively under pressure.
If you work in CSIRT, SOC, DFIR, SecOps, cybersecurity leadership, IT operations, GRC, risk, audit, business continuity, or incident management, this episode is designed to challenge the difference between having a team and having a real response capability.
S1E9 - 25m - Sep 3, 2026 - EP008: Stop Lying to Yourself About Cyber Maturity
In EP008 of The InfoSec Control Room, Taher Amine ELHOUARI takes on one of cybersecurity’s favorite activities:
Measuring maturity.
Organizations love maturity scores.
3.4 out of 5.
Level 4.
Managed.
Optimized.
Green dashboard.
Everything looks reassuring.
But what does the score actually mean?
Can the organization detect an attacker?
Can it restore a critical service?
Can it revoke privileged access quickly?
Can it prove its controls are operating?
Can management make a cyber-risk decision under pressure?
If not, the maturity score may be measuring confidence rather than capability.
This episode explores the gap between claimed maturity and proven capability and why cybersecurity maturity assessments can become dangerously optimistic when scoring becomes the objective.
Taher examines why documentation alone does not equal maturity, why self-assessments naturally drift toward generous scoring, why averages can hide dangerous weaknesses, and why technology, certifications, headcount, and dashboards should never be mistaken for real capability.
Topics include:
• What cybersecurity maturity should actually measure
• Claimed maturity versus demonstrated capability
• Why maturity scores need evidence
• Documentation versus operating effectiveness
• The optimism problem in self-assessments
• Why averaging maturity scores can hide serious risk
• Risk-based target maturity
• Why not every capability needs to reach Level 5
• Maturity by procurement
• SIEM, EDR, PAM, GRC tools and false confidence
• Metrics that measure activity instead of outcomes
• The danger of dependency on “heroic employees”
• Certification versus operational maturity
• Why completely green dashboards should make you nervous
• Independent challenge and professional skepticism
• Evidence-based maturity assessment
• Control design versus control operation
• Translating maturity findings into real improvement
• Using maturity as governance rather than scoring
One of the central ideas from EP008:
A maturity claim without evidence is an opinion.
And perhaps the most mature statement an organization can make is:
“We are not as good at this as we thought.”
Because cybersecurity maturity is not about looking advanced.
It is about understanding reality well enough to improve capability, reliability, resilience, and decision-making.
S1E8 - 26m - Aug 22, 2026 - EP007: Incident Response Starts Before the Incident
In EP007 of The InfoSec Control Room, Taher Amine ELHOUARI explores a simple but often misunderstood reality:
Incident response does not begin when the incident happens.
By the time the first serious alert fires, many of the decisions that will determine the quality of the response have already been made.
- Who has authority to isolate a critical system?
- Who can declare a major incident?
- Who decides whether a business service should be interrupted?
- Who contacts legal, privacy, communications, executive management, customers, regulators, or external responders?
- Can the organization communicate if its primary collaboration platform is compromised?
- Can critical systems actually be restored from backup?
- Does the SOC know which assets matter most?
- And has anyone tested all of this before the pressure becomes real?
This episode moves beyond the traditional detect-contain-eradicate-recover diagram and looks at incident response as an organizational capability, not simply a technical SOC function.
Taher discusses how authority, escalation, asset visibility, logging, communications, crisis management, business continuity, supplier arrangements, executive decision-making, and organizational culture all shape the outcome of a cyber incident.
The episode also examines why tabletop exercises should create uncomfortable decisions rather than simply confirm that a plan exists, and why serious incidents often expose weaknesses far beyond the initial technical compromise.
Topics include:
• Why incident response begins before detection
• Decision authority during cyber incidents
• Technical containment versus business impact
• The hidden cost of organizational decision latency
• Incident severity and escalation criteria
• SOC, CSIRT, management, legal, privacy, and communications coordination
• Out-of-band communications during compromised environments
• Asset inventory and business criticality during investigation
• Logging and visibility as incident-response capabilities
• Backup restoration versus simply having backups
• Connecting incident response with business continuity and disaster recovery
• Supplier and third-party incident preparedness
• Executive decision-making under uncertainty
• Why employees must feel safe reporting mistakes quickly
• Tabletop exercises that actually test the organization
• Turning incident lessons into real control improvements
• Feeding incidents back into GRC and risk management
• Why repeated incidents reveal governance problems
• Building resilience before the crisis
One of the central ideas of EP007: Your response capability is built before the incident. The alert only reveals what you already prepared.
Because a good incident response capability is not defined by how impressive the plan looks.
It is defined by how effectively the organization can decide, coordinate, contain, communicate, recover, and learn when reality refuses to follow the plan.
S1E7 - 28m - Aug 16, 2026 - EP006: Your Policy Is Not a Control
In EP006 of The InfoSec Control Room, Taher Amine ELHOUARI takes on one of the most common misconceptions in information security governance:
Having a policy does not mean you have a control.
An organization can have approved information security policies, access control requirements, data classification rules, acceptable-use standards, incident procedures, and beautifully version-controlled documents — while real behavior tells a completely different story.
A policy may say privileged access must be restricted.
But who enforces it?
A policy may say confidential information must be protected.
But do employees know what that means when they actually handle the data?
A policy may say incidents must be reported immediately.
But does everyone know where, how, and to whom?
This episode explores the gap between management intent and operational reality.
Taher discusses why security policies only create value when they are translated into usable processes, technical controls, ownership, monitoring, evidence, enforcement, and behavior.
The episode also challenges the tendency to respond to every security problem by creating yet another document.
Because sometimes the organization does not need another policy.
It needs to enforce the ones it already has.
Topics include:
• Why a policy is not automatically a control
• Turning policy requirements into operational mechanisms
• The difference between documented intent and real behavior
• Why secure behavior must also be practical behavior
• Policy requirements versus technical enforcement
• Data classification beyond labels
• Acceptable-use policies people actually understand
• Why leadership behavior can override written policy
• Policy inflation and document overload
• Security culture and management accountability
• Why exceptions need governance and expiry dates
• Enforcement without creating a fear culture
• Evidence that proves policies are actually implemented
• Testing policies through audits, sampling, metrics, incidents, and exercises
• Making secure behavior easier than insecure workarounds
• Why control ownership matters
• Moving from policy → control → evidence → monitoring → governance
One of the core ideas of this episode:
A policy tells the organization what it expects. A control makes that expectation real.
And when the policy says one thing while systems, processes, incentives, and management behavior say another, operational reality will win every time.
S1E6 - 24m - Aug 15, 2026 - EP005: GRC and SecOps Are Speaking Different Languages
In EP005 of The InfoSec Control Room, Taher Amine ELHOUARI explores one of the most important — and often underestimated — relationships inside a cybersecurity program: the connection between GRC and Security Operations.
In many organizations, GRC and SecOps behave like two neighboring countries.
GRC speaks in controls, policies, risk registers, audit findings, evidence, compliance obligations, and assurance.
SecOps speaks in alerts, detections, incidents, vulnerabilities, threat intelligence, EDR, SIEM, containment, and response.
Both teams may be doing good work.
But if they are not exchanging context, evidence, and operational reality, the organization never gets a complete picture of its cyber risk.
This episode looks at what happens when governance is disconnected from operations — and when security operations operate without enough business and risk context.
Taher explains why operational telemetry should become governance evidence, why GRC should consume real SOC and CSIRT data, and why SecOps needs business criticality, asset classification, risk appetite, regulatory obligations, and control objectives to properly prioritize what matters.
The episode also explores how this relationship improves audit quality, incident response, risk assessment, control effectiveness, management reporting, and cybersecurity decision-making.
Topics include:
• Why GRC and SecOps often operate in separate worlds
• The difference between operational data and governance information
• Turning SOC telemetry into control-effectiveness evidence
• Why GRC needs operational reality
• Why SecOps needs business and risk context
• Connecting incidents with risk management
• Using detection and response data during audits
• Asset criticality and business impact in SOC prioritization
• Logging and monitoring as living controls
• GRC, SOC and CSIRT alignment during incidents
• Why “92% compliant” can still hide serious exposure
• Translating technical findings into management decisions
• Metrics that support decisions instead of decorating dashboards
• Evidence generated by normal operations
• Integrating audit findings, incidents, vulnerabilities and risk
• Building a common language between technical and governance teams
• Why cybersecurity reporting should become one shared picture
One of the central ideas of this episode is simple:
GRC provides context. SecOps provides reality. Mature cybersecurity happens when the two meet.
Because a governance team without operational visibility is partially blind.
And a SOC without governance context may be incredibly busy while still struggling to determine what matters most.
S1E5 - 25m - Aug 14, 2026 - EP004: The CISO Is Not a Superhero
In EP004 of The InfoSec Control Room, Taher Amine ELHOUARI challenges one of the most common and damaging assumptions in cybersecurity governance:
“We have a CISO. Cybersecurity is their responsibility.”
It sounds reasonable until you start asking who actually creates, owns, accepts, and manages cyber risk across an organization.
A business unit launches an application without involving security. Procurement signs a critical supplier contract without proper security requirements. Finance delays funding for a legacy-system replacement. HR does not trigger offboarding quickly enough. A business owner decides that remediation can wait because downtime would affect operations.
And when something eventually goes wrong, everyone turns toward the CISO.
This episode explores why that model is not cybersecurity governance — it is accountability concentrated in a job title.
Taher explains the difference between leading a cybersecurity program and personally owning every cyber risk, and why mature organizations distribute responsibility across executives, business owners, technology teams, control owners, risk owners, HR, procurement, legal, operations, and security.
The CISO’s role is not to become the organization’s cybersecurity superhero.
It is to help design the system through which cybersecurity is governed.
Topics include:
• What a CISO should actually be accountable for
• The difference between security leadership and risk ownership
• Why business owners must own business risk
• Responsibility without authority
• Control ownership versus security oversight
• Why CISOs become convenient cybersecurity scapegoats
• Building cybersecurity as an organizational capability
• The CISO as a governance architect
• Translating technical findings into executive decisions
• Risk acceptance and escalation
• Why security should not approve everything
• Distributed ownership and scalable security
• Board and executive responsibilities for cyber risk
• Incident governance and decision authority
• Why mature security programs should survive without individual heroes
One of the central ideas of the episode:
The CISO does not own every cyber risk. The CISO helps the organization understand, govern, and manage cyber risk.
Because if one person is responsible for everything while controlling almost nothing, that is not governance.
That is a very stressed person with an impressive job title.
S1E4 - 24m - Aug 13, 2026 - EP003: Compliance Is Not Control
In EP003 of The InfoSec Control Room, Taher Amine ELHOUARI explores the uncomfortable gap between being compliant and actually being in control.
An organization can have approved policies, completed audits, risk registers, procedures, evidence, management reviews, and even certifications on the wall; while still struggling to answer very simple questions:
- Can we actually restore our critical systems?
- Who really owns this risk?
- Are our controls operating consistently?
- Does our evidence reflect reality, or was it prepared because an audit was coming?
This episode is not an argument against compliance. Quite the opposite.
Compliance, standards, audits, certification, and structured management systems can create tremendous value when they support real governance, risk management, accountability, and continuous improvement.
The problem starts when the objective quietly changes from:
“Are we improving security?”
to:
“Will we pass the audit?”
Taher discusses what he calls audit-season security, why a policy is not automatically a control, why evidence should be produced by normal operations rather than reconstructed before an audit, and why certification should be understood as part of a living management system rather than the finish line.
The episode also explores the practical relationship between compliance, audit, GRC, SecOps, management, and technical teams; and why all of them need to work from the same operational reality.
Topics include:
• Compliance versus control
• Conformity versus operating effectiveness
• Audit-season security
• Why documentation alone does not create maturity
• Evidence by design
• Control ownership and risk ownership
• Internal audit as a tool for improvement
• Repeated findings and root-cause thinking
• Making management reviews actually produce decisions
• Connecting GRC with SOC, CSIRT, and operational security
• Why compliance percentages can create false comfort
• Turning certification into continuous assurance
• Moving from requirements to control, evidence, assurance, and resilience
The key question of the episode is simple:
Compliance can tell you what should happen. Control tells you what happens.
So the next time someone says, “We are compliant,” ask one more question:
“How do we know we are actually in control?”
S1E3 - 33m - Aug 12, 2026 - EP002: The Real Reason Security Programs Fail
In this episode of The InfoSec Control Room, Taher Amine ELHOUARI explores one of the core ideas behind the podcast: many security programs do not fail because there is no cybersecurity activity. They fail because that activity is not governed, owned, measured, or improved properly.
The episode explains why security failures are often symptoms of deeper structural issues: unclear accountability, weak ownership, poor risk decisions, ineffective controls, disconnected teams, compliance theater, weak escalation, and the gap between documentation and real operational capability.
Rather than blaming tools, users, auditors, SOC teams, or CISOs alone, this episode looks at the full system behind security programs and asks a more important question: why did the organization allow the weakness to exist, persist, and become dangerous?
Topics include:
• Why security failures are rarely purely technical
• The difference between security activity and security capability
• Governance gaps behind incidents and audit failures
• Ownership, accountability, and risk decisions
• Why tools cannot compensate for weak governance
• Compliance theater and false maturity
• The gap between policies, controls, and real behavior
• How technical, GRC, SOC, CSIRT, management, and executive teams become disconnected
• What security programs need in order to actually work
No noise. No fake maturity. No checkbox security.
Just practical conversations on how security is governed, controlled, measured, and improved.
S1E2 - 30m - Aug 12, 2026 - EP001: Welcome to The InfoSec Control Room
In this first original episode of The InfoSec Control Room, Taher Amine ELHOUARI formally introduces the podcast, the story behind it, and the core philosophy that will guide future episodes.
This opening episode explains why The InfoSec Control Room exists, who it is for, and why cybersecurity must be understood beyond tools, incidents, vulnerabilities, frameworks, and technical controls.
Taher introduces his background across information security, cybersecurity governance, GRC, SecOps, CSIRT, audit, risk management, resilience, advisory, training, public speaking, and CISO-level decision-making. He also explains why many security programs fail not because they lack activity, but because they lack governance, ownership, accountability, evidence, discipline, and real control.
The episode sets the tone for the original series: practical, strategic, field-based, and built for engineers, experts, managers, auditors, GRC professionals, SOC and CSIRT teams, CISOs, executives, students, and decision-makers.
Topics include:
• The purpose behind The InfoSec Control Room
• Who Taher Amine ELHOUARI is and why he created the podcast
• Why cybersecurity is more than a technical discipline
• The difference between security activity and real security capability
• Governance as the root cause behind many security failures
• The gap between engineers, managers, auditors, executives, GRC, SOC, and CSIRT teams
• Why compliance, documentation, and tools are not enough
• What future original episodes will cover
• The mission of building security that is governed, controlled, measured, and improved
No noise. No fake maturity. No checkbox security.
Just practical conversations on how security is governed, controlled, measured, and improved.
https://www.taheramine.org/podcast.html
S1E1 - 31m - Aug 10, 2026 - Media Archive: Building Cyber Resilience Beyond Compliance | Full Webinar | Taher Amine ELHOUARI - iExperts
Compliance may demonstrate that security requirements have been addressed. Cyber resilience demonstrates that governance, people, processes, and technology can continue to operate under real pressure.
This special webinar edition of The InfoSec Control Room presents the complete audio recording of my latest iExperts session: BUILDING CYBER RESILIENCE BEYOND COMPLIANCE.
During this session, I examine why organizations can remain operationally fragile despite having policies, certifications, risk registers, control frameworks, and extensive compliance documentation.
The webinar explores how organizations can move beyond checkbox compliance and connect leadership accountability, cybersecurity governance, enterprise risk management, GRC, SOC and CSIRT operations, incident response, crisis management, business continuity, recovery, and continuous improvement within one coherent cyber-resilience model.
KEY TOPICS:
• The real difference between cybersecurity compliance and cyber resilience
• Why apparently compliant organizations may still fail during serious incidents
• Moving from documented controls to operational capability
• Executive accountability and cyber-risk ownership
• Transforming standards and frameworks into practical operating models
• Connecting GRC with SOC, CSIRT, and incident-response operations
• Business continuity, crisis management, recovery, and lessons learned
• Testing controls through simulations, exercises, and realistic scenarios
• Common cyber-resilience failure patterns
• Indicators and metrics that demonstrate genuine resilience
• A practical operating model and improvement roadmap
• Priority actions organizations can initiate during their first 30 days
EPISODE TIMESTAMPS:
00:00 Webinar Opening and Host Introduction
01:45 About Taher Amine ELHOUARI
03:36 Why Cyber Resilience Matters
06:55 The Compliance Trap
12:13 Compliance Mindset vs Resilience Mindset
16:01 What Cyber Resilience Really Means
19:59 Governance and Executive Accountability
23:28 Risk Management and Framework Operationalization
30:17 Incident Response, SOC, CSIRT, and GRC
36:42 Continuity, Recovery, Crisis Management, and Testing
41:35 Failure Patterns and the Resilience Maturity Curve
48:47 Practical Resilience Operating Model and Roadmap
52:03 Priority Actions for the First 30 Days
55:35 Key Takeaways
58:10 Audience Questions and Answers
65:19 Closing Remarks
ABOUT THE SPEAKER:
Taher Amine ELHOUARI is a Global Cyber Leader, Senior Advisor, Accredited Auditor, Certified Trainer, and holds over 300 certifications. He serves as CISO and Head of Advisory & CSIRT at UNIDEES, with expertise spanning cybersecurity governance, GRC, risk management, auditing, advisory, security operations, incident response, SOC and CSIRT development, business continuity, operational resilience, and professional training.
ORIGINAL WEBINAR:
The session was originally hosted and publicly presented by iExperts on 29 July 2026.
Watch the complete video:
https://www.youtube.com/watch?v=qtqgWRv_qUI
Learn more about the speaker:
https://www.taheramine.org
THE INFOSEC CONTROL ROOM
The InfoSec Control Room explores cybersecurity governance, accountability, risk decisions, control effectiveness, resilience, leadership, and the operational realities behind information-security programs.
My sincere appreciation goes to the entire iExperts team for hosting the webinar and to every professional who attended, contributed questions, and enriched the discussion.
S1 - 1h 6m - Jul 30, 2026 - Media Archive: Conformity Assessment Meets Cybersecurity | FIRST & AfricaCERT Symposium 2025
In this Media Archive episode of The InfoSec Control Room, Taher Amine ELHOUARI shares his conference session from the FIRST & AfricaCERT Symposium 2025 in Mauritius: “Conformity Assessment Meets Cybersecurity: Building a Common Language Between Auditors and Analysts.”
This session explores one of the most important gaps in cybersecurity assurance: why organizations can appear compliant on paper while still struggling to detect, respond to, and contain real attacks. The discussion connects conformity assessment, certification audits, SOC operations, CSIRT response, security metrics, incident evidence, and governance maturity into one practical conversation. It shows how auditors, assessors, regulators, SOC analysts, and incident response teams can work from a shared language instead of operating in disconnected worlds.
Rather than treating compliance as a periodic checkbox exercise, this talk argues for continuous, evidence-driven cyber assurance — where operational telemetry, incident tickets, detection metrics, audit evidence, and control effectiveness become part of the same governance model.
Original session: FIRST & AfricaCERT Symposium 2025, Mauritius.
Topics include:
- Conformity assessment and cybersecurity
- Audit and certification assurance
- SOC and CSIRT alignment
- ISO/IEC 27001, ISO/IEC 27006, ISO/IEC 27007, ISO/IEC 27008, and ISO/IEC 19011
- ISO/IEC 27035 incident management lifecycle
- Translating SOC telemetry into audit evidence
- Measuring real control effectiveness
- Mapping detection and incident response metrics to governance requirements
- Continuous assurance models
- Bridging GRC, SecOps, auditors, and analysts
- AfricaCERT 3CF and regional cyber maturity
Note: This episode is adapted from a public conference session featuring Taher Amine ELHOUARI. All rights to the original recording remain with their respective owners.
S1 - 27m - Jun 23, 2026 - Media Archive: The Hidden Face of Cyber Extortion on Algerian National TV
In this Media Archive episode of The InfoSec Control Room, Taher Amine ELHOUARI shares a national television intervention from Taqassi — Season Five, produced by Algerian National Television, focused on cyber extortion and online blackmail. This episode explores one of the most dangerous and rapidly growing crimes in the digital space: how attackers exploit psychology, privacy gaps, digital habits, and weak awareness to pressure, manipulate, and harm individuals.
The discussion reflects one of the core missions of The InfoSec Control Room: making cybersecurity, governance, risk, compliance, and resilience practical, understandable, and connected to real-world impact. Rather than treating cybersecurity as only a technical discipline, this intervention highlights the importance of awareness, digital responsibility, online safety, privacy protection, family education, national cyber maturity, and collective defense.
Original appearance: Algerian National Television — Taqassi, Season Five, November 2025.
Topics include:
- Cyber extortion
- Online blackmail
- Digital safety
- Privacy risks
- Social engineering
- Security awareness
- Family and public cyber education
- Digital responsibility
- National cyber maturity
- Collective cyber defense
Note: This episode is adapted from a public media appearance featuring Taher Amine ELHOUARI. All rights to the original recording remain with their respective owners.
S1 - 9m - Jun 23, 2026 - Media Archive: From Chaos to Control — Building and Maturing CERT/CSIRT Teams
In this Media Archive episode of The InfoSec Control Room, Taher Amine ELHOUARI shares a full masterclass titled “From Chaos to Control: Understanding, Building, and Maturing Your Cyber Response Team.” This session focuses on the fundamentals, structure, and maturity of cyber response teams, including CERTs, CSIRTs, operational readiness, field tactics, and the architecture of cyber resilience.
The episode reflects one of the core missions of The InfoSec Control Room: moving beyond theory and showing how cybersecurity governance, incident response, operational structure, and resilience come together in practice. Rather than treating incident response as a purely technical activity, this masterclass highlights the importance of team design, clear roles, governance, escalation, preparedness, coordination, continuous improvement, and the ability to move from reactive chaos to controlled cyber response.
Original session: CyberSecurity DZ & WW, Algeria, August 2025.
Topics include:
- CERT and CSIRT fundamentals
- Cyber response team design
- Incident response maturity
- Operational readiness
- Cyber resilience architecture
- Field tactics for response teams
- Governance of cyber response capabilities
- Building structure from operational chaos
- Practical lessons for security leaders and practitioners
Note: This episode is adapted from a public masterclass featuring Taher Amine ELHOUARI. All rights to the original recording remain with their respective owners.
S1 - 1h 3m - Jun 23, 2026 - Media Archive: Cybersecurity Challenges, Certifications, and Career Lessons
In this Media Archive episode of The InfoSec Control Room, Taher Amine ELHOUARI shares a guest podcast interview originally featured on Lweirday Experience.
This conversation explores cybersecurity from multiple angles: fundamentals, career development, certifications, ethical hacking, development security, red/blue/purple teaming, cybersecurity teams, ICS and SCADA security, standards, and the challenges organizations face when building serious security capabilities.
The episode reflects one of the core missions of The InfoSec Control Room: making cybersecurity, governance, risk, compliance, and resilience practical, understandable, and connected to real professional experience.
Rather than treating cybersecurity as only a technical field, this discussion highlights the importance of mindset, continuous learning, structured teams, secure development, governance, and the ability to connect security knowledge with real organizational needs.
Original appearance: Lweirday Experience, September 2025.
Topics include:
- Introduction to cybersecurity
- Career journey in cybersecurity
- Certifications and professional mindset
- Security in development processes
- Ethical hacking
- Cybersecurity challenges
- Red, blue, and purple teams
- Cybersecurity team structures
- ICS and SCADA security
- Cybersecurity standards
- Building cybersecurity departments in startups
Chapters:
- 00:00 — Introduction to Cybersecurity
- 02:57 — Career Journey in Cybersecurity
- 06:03 — Impact of Certifications on Security Mindset
- 08:59 — Integrating Security in Development Processes
- 12:02 — Understanding Ethical Hacking
- 18:00 — Challenges in Cybersecurity
- 25:07 — Red, Blue, and Purple Teams in Cybersecurity
- 32:29 — Understanding Cybersecurity Teams
- 34:33 — The Importance of ICS and SCADA Security
- 39:02 — Exploring Cybersecurity Standards
- 45:38 — Building a Cybersecurity Department in Startups
- 49:08 — Quiz
Note: This episode is adapted from a public guest podcast interview featuring Taher Amine ELHOUARI. All rights to the original recording remain with their respective owners.
S1 - 51m - Jun 23, 2026 - Media Archive: Information Security — A Leading Experience
In this Media Archive episode of The InfoSec Control Room, Taher Amine ELHOUARI shares a long-form interview hosted by Adel BOUROUIS for Algerian Tech Makers.
This discussion explores Taher’s journey in information security and cybersecurity, including career development, lessons learned, certifications, challenges, field experience, community contribution, and the mindset required to grow seriously in the cybersecurity field.
The episode reflects one of the core missions of The InfoSec Control Room: connecting cybersecurity knowledge, governance thinking, professional growth, and practical field experience in a way that is useful for students, practitioners, leaders, and the wider cybersecurity community.
Rather than presenting cybersecurity as only a technical career path, this conversation highlights the importance of discipline, continuous learning, ethical practice, community building, leadership, and the ability to turn knowledge into real impact.
Original appearance: Algerian Tech Makers, April 2025.
Topics include:
- Information security career journey
- Cybersecurity professional growth
- Certifications and lessons learned
- Field experience and challenges
- Cybersecurity community building
- Ethical hacking and practical learning
- Leadership and mindset
- Advice for students and aspiring practitioners
Note: This episode is adapted from a public interview featuring Taher Amine ELHOUARI. All rights to the original recording remain with their respective owners.
S1 - 2h 13m - Jun 23, 2026 - Media Archive: Cybersecurity & Data Protection Panel at CTO Forum 2025
In this Media Archive episode of The InfoSec Control Room, Taher Amine ELHOUARI shares his intervention during the Cybersecurity & Data Protection Panel at CTO Forum 2025 in Algiers.
This panel focused on key challenges facing organizations in today’s evolving threat landscape, including cybersecurity strategy, risk management, cloud security, data protection, governance, regulatory alignment, and secure development.
The discussion reflects one of the core missions of The InfoSec Control Room: connecting cybersecurity, governance, risk, compliance, and resilience with real-world leadership decisions.
Rather than treating cybersecurity as a purely technical topic, this episode highlights the importance of strategic security governance, cross-sector collaboration, cloud security maturity, privacy alignment, and the role of practitioners in helping organizations build secure and resilient digital ecosystems.
Original appearance: CTO Forum 2025, Algiers, March 2025.
Topics include:
- Cybersecurity strategy
- Risk management
- Cloud security and compliance
- Data protection and governance
- Regulatory alignment
- Secure development
- Cyber resilience
- Cross-sector collaboration
- Security leadership and digital trust
Note: This episode is adapted from a public panel appearance featuring Taher Amine ELHOUARI. All rights to the original recording remain with their respective owners.
S1 - 12m - Jun 23, 2026
