Yossy's Security & AI Lab _Global
Making Information Security Practical and Easy to Understand
This podcast shares practical insights on information security, privacy protection, corporate IT, and AI governance, based on real experience supporting small and mid-sized companies in Japan. Topics include ISMS (ISO/IEC 27001), AIMS (AI Management Systems), incident response, and responsible AI use — all explained from an operational, in-house perspective rather than theory alone. One unique focus of this podcast is Japan’s Privacy Mark (P-Mark), a Japanese privacy management system that is widely used in Japan but not well known internationally. In this podcast, I explain what P-Mark is,
Author
Yossy's Security & AI Lab _Global
Category
Podcast website
Latest episode
Jun 14, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
SEC-12. What Is ISMS? The Real Picture of How It Works 04.03.2026 4:54
“What exactly is ISMS?” Many people think it means strict rules, heavy documents, and audits. But ISMS is not just about rules. It is about building a system that keeps running and improving. In this episode, we explain the real meaning of ISMS in simple terms. What ISMS actually stands for Why “Plan–Do–Check–Act” is the heart of the system The common reality of one-person management in small comp...
AIMS-09. Governance and Organizational Structure 01.03.2026 4:21
As AI use grows inside companies, many organizations face this situation: The IT team handles everything. Each department uses AI differently. Rules exist, but no one clearly checks them. In this episode, we talk about governance and organizational structure , a key part of AIMS (AI Management Systems). Governance does not mean complex management theory. It simply means: 👉 Deciding direction and...
SEC-11. What Should You Do First When You Start? 25.02.2026 6:24
When you start ISMS or the Privacy Mark, it’s easy to jump into tasks like policies, documents, and risk assessments. But before that, there is one important first step. In this episode, we talk about what to do first when you’re ready to begin . The answer is simple: Find your “partners” first. You can create rules on paper, but operations only work when people move. Why “one-person security” oft...
AIMS-08. Basics of Risk Assessment 22.02.2026 4:40
When using AI at work, have you ever felt, “AI sounds useful, but it feels a little scary”? What if sensitive information is entered? What if AI gives wrong answers? What if we share something outside the company by mistake? In this episode, we talk about risk assessment , an important concept in AIMS (AI Management Systems). Risk assessment does not mean complex documents. It simply means: 👉 Thi...
SEC-10. How Do Other Companies Do It? The Real Story in Small and Mid-Sized Businesses 18.02.2026 4:21
Many people in small and mid-sized companies wonder: “How do other companies handle ISMS or the Privacy Mark in real life?” In this episode, we share the real-world situation we often see in the field. This is not about finding the “perfect answer.” The key message is: “Not the perfect answer, but the best fit.” One-person security roles are common Many companies run ISMS or P-Mark as a side task...
AIMS-07. What Is Accountability? 15.02.2026 4:26
As AI becomes part of daily work, questions like these often appear: If AI makes a mistake, who is responsible? Is it the staff member? Is it the company? Is it the tool or the vendor? In this episode, we explore accountability , an important concept in AIMS (AI Management Systems). Accountability does not mean legal language. It simply means: 👉 Being clear about who takes responsibility. Who is...
SEC-09. How Do We Get Management Involved? 11.02.2026 5:28
Many people working in IT or administration feel this challenge: “I understand the importance of information security, but top management doesn’t seem very interested.” In this episode, we talk about how to involve executives in information security , from a practical, real-world perspective. This is not about explaining detailed rules or standards. Instead, we focus on how to speak in the languag...
AIMS-06. What Is Transparency? 08.02.2026 4:38
As AI becomes more common in the workplace, questions like these often come up: “Was this created by AI?” “How much should we explain?” In this episode, we explore transparency , a key concept in AIMS (AI Management Systems), from a practical, real-world perspective. Transparency does not mean technical explanations. It simply means being able to explain how AI is used . Where AI is used Where hum...
SEC-08.Can one IT person really do it all? 05.02.2026 2:59
“Can one IT person really handle ISMS or the Privacy Mark?” This is a very common question. In this episode, I talk about this issue from a key risk perspective: over-reliance on one person . You’ll hear about: Why running security certification alone is risky What actually happens when knowledge stays with one person How to build a more sustainable, shared security setup Information security is n...
SEC-07.How Do You Get Management Approval for Security? 28.01.2026 3:41
Security is important — but explaining it to management is often the hardest part. In this episode, I talk about how to communicate information security in a way that actually makes sense to executives. We cover: How to frame security as a business topic Questions that really get management thinking A realistic, step-by-step way to get approval This episode is for anyone who feels “stuck in the mi...
A05. What Is AIMS?A Beginner’s Guide to AI Management 25.01.2026 4:48
AI is becoming part of everyday work. But many people feel unsure and think: “AI is useful, but is it really safe to use this way?” In this episode, I explain what AIMS (AI Management System) is in a simple and practical way. You’ll learn: What AIMS actually means Why companies are starting to care about ISO/IEC 42001 How AIMS helps organizations use AI safely and responsibly AIMS is not about res...
SEC-06 “Is Security Certification Still Too Early for Us?” — What to Think About First 21.01.2026 4:03
Many companies think about security certifications like ISMS or the Privacy Mark and wonder: “Isn’t this still too early for a company our size?” In this episode, Yoshida shares a practical, real-world perspective on that question. Instead of focusing on certification requirements, this episode explores: Why “too early” is often a misunderstanding Why small and mid-sized companies can actually mov...
AIMS-04. How Do We Create Internal AI Rules? 18.01.2026 7:52
As AI use grows inside companies, many people start asking: “Do we need internal AI rules?” “But where should we even start?” In this episode, we build on the previous discussion about making AI risks visible , and focus on the next step: how to turn those risks into simple, practical internal AI rules . This is not about creating long or strict policies. Instead, we talk about a realistic approac...
SEC-05 How does your company change after getting ISMS or PrivacyMark? 15.01.2026 5:16
What actually changes in a company after getting ISMS, the Privacy Mark, or PIMS? In this episode, I talk about the real changes that happen after certification , based on practical experience with ISMS, the Privacy Mark, and PIMS (ISO/IEC 27701) . Getting certified does not suddenly change everything overnight. But over time, clear and meaningful changes begin to appear. For example: Less uncerta...
AIMS-03. Making AI Risks Visible 11.01.2026 4:24
in this episode, we talk about how to make AI risks visible in daily work. Many people use AI tools like ChatGPT or Copilot at work, but often feel unsure: “Is this safe?” “Are we using AI in the right way?” In this episode, we explain AI risk in a simple and practical way , from an information security point of view. You will learn: Where AI is being used in your work What kind of data is involve...
SEC-04.How hard are ISMS, the Privacy Mark, or PIMS in real life? 07.01.2026 5:46
How hard are ISMS, the Privacy Mark, or PIMS in real life? In this episode, I talk about the real effort behind security and privacy certifications , based on practical experience. I often hear questions like: Can one IT person handle ISMS or the Privacy Mark? How long does it take to get certified? How much work is required to keep it running? And can you actually fail the audit? Instead of theor...
AIMS-02. What Is AIMS? 04.01.2026 4:05
As more companies start using AI in their daily work, have you ever felt this way? “It looks useful, but… is this really okay?” In this episode, we explain what AIMS (AI Management System) is in a simple and practical way, avoiding unnecessary technical jargon as much as possible. AIMS is not a set of rules to control or restrict AI. It is a way of thinking that helps people and organizations use...
SEC-03.ISMS or Privacy Mark: Which One Fits Your Company? 31.12.2025 3:17
ISMS or the Privacy Mark — which one fits your company? In this episode, I explain the practical differences between ISMS and the Privacy Mark , especially for small and mid-sized companies in Japan. ISMS is based on an international standard and focuses on managing all types of information , including business data, IT systems, and internal documents. The Privacy Mark, on the other hand, is a Jap...
AIMS-01. Balancing AI Use and Security 29.12.2025 4:54
In this episode, we talk about how to start using AI at work without breaking information security. Many people feel excited about AI, but at the same time, they feel worried or unsure. Questions like: How much can we use AI at work? Is there a risk of data leakage? What if the AI gives the wrong answer? These are very natural concerns. In this episode, I explain AI usage from an information secur...
Sec-02.Why do companies in Japan need ISMS, the Privacy Mark, or PIMS? 28.12.2025 3:01
Why do companies need ISMS or the Privacy Mark , or ISO27701 PIMS ? In this episode, I talk about why information security certifications matter , not as a formality, but as a way to protect trust. Many companies start thinking about ISMS or the Privacy Mark or PIMS because of outside pressure: A client asks about security certification Other companies already have it Or there is a vague feeling o...
Sec-01.Where should we start when a data breach happens? 28.12.2025 4:30
When an information leak happens, many teams feel overwhelmed and don’t know where to start. Confusion and anxiety often come before clear action. In this episode, we focus on the very first step of information leakage response , explained from a small and mid-sized business perspective. This is not about technical details or scary incident stories. Instead, we talk about how to stay calm and make...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.