SEI Members of Technical Staff
Software Engineering Institute (SEI) Webcast Series
Each webinar features an SEI researcher discussing their research on software and cybersecurity problems of considerable complexity. The webinar series is a way for the SEI to accomplish its core purpose of improving the state-of-the-art in software engineering and cybersecurity and transitioning this work to the community. The SEI is a federally funded research and development center sponsored by the U.S. Department of Defense and operated by Carnegie Mellon University. The SEI Webinar Series is produced by SEI Communications Outreach.
Author
SEI Members of Technical Staff
Category
Podcast website
Latest episode
Jun 10, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Can a Cybersecurity Parametric Cost Model be Developed? Video 17.03.2025 56:25
Can a cybersecurity parametric cost estimation model be developed? Every Department of Defense (DoD) program needs to account for, credibly estimate, budget/plan for, and assess the performance of its cybersecurity activities. Creating a cybersecurity parametric model would allow DoD programs to reliably estimate the effort and cost of cybersecurity activities, estimate an overall cybersecurity co...
Elements of Effective Communications for Cybersecurity Teams Video 03.03.2025 34:00
Communications, both in times of crisis and during normal operations, are essential to the overall success and sustainability of an incident response or security operations team. How you plan for and manage these communications and how they are received and actioned by your audience will influence your trustworthiness, reputation, and ultimately your ability to perform incident management services...
Operational Resilience Fundamentals: Building Blocks of a Survivable Enterprise Video 13.02.2025 52:07
Surviving disruptive cyber events requires a specific form of planning. One must strike a balance between defending against threats (e.g., managing conditions) and effectively handling the effects of disruption (e.g., managing consequences). Employing a model (such as the CERT Resilience Management Model) provides a catalog of practices and a system of measurement. Focusing on key attributes of pe...
Cybersecurity Priorities in 2025 Video 07.02.2025 32:21
Chief Information Security Officers (CISOs) perpetually navigate a dynamic set of challenges. Applying focus and aligning resources is imperative for success. In this Intersect, Matthew Butkovic and Gregory Touhill, reflect on 2024 and explore the topics that should be front of mind for CISOs in 2025. They provide insights and advice for those contemplating cybersecurity priorities.
Understanding the Need for Cyber Resilience: A Conversation with Ray Umerley Video 07.01.2025 53:02
No organization can comprehensively avoid disruptive cyber events. All must strive to maintain operational resilience during times of organizational stress. Ransomware incidents create disruption that can be fatal to the unprepared. In this webcast, we explore how to maintain operational resilience during a ransomware incident. Experts with varied backgrounds provide practical advice for improving...
Exploring the Fundamentals of Counter AI Video 03.01.2025 27:57
As the strategic importance of AI increases, so too does the importance of defending those AI systems. To understand AI defense, it is necessary to understand AI offense—that is, counter AI. In this session, Matthew Butkovic, CISA, CISSP, technical director for risk and resilience, and Nathan VanHoudnos, senior machine learning researcher explore the fundamentals of counter AI.
Cyber Challenges in Health Care: Managing for Operational Resilience Video 31.10.2024 53:37
Health-care organizations are seemingly besieged by a complex set of cyber threats. The consequences of disruptive cyber events in health care are in many ways uniquely troubling. Health-care organizations often face these challenges with modest resources. In this webcast, Matthew Butkovic and Darrell Keeling will explore approaches to maximize return on cybersecurity investment in the health-car...
Independent Verification and Validation for Agile Projects Video 30.10.2024 1:02:23
Traditionally, independent verification and validation (IV&V) is performed by an independent team throughout a program's milestones or once the software is formally delivered. This approach allows the IV&V team to provide input at the various milestone gates. As more programs move to an Agile approach, those milestones aren't as clearly defined since requirements, design, implementation, and testi...
Generative AI and Software Engineering Education Video 28.06.2024 1:02:05
Within a very short amount of time, the productivity and creativity improvements envisioned by generative artificial intelligence (AI), such as using tools based on large language models (LLMs), have taken the software engineering community by storm. The industry is in a race to develop your next best software development tool. Organizations are perplexed by trying to find the right balance betwee...
Secure Systems Don't Happen by Accident Video 13.06.2024 59:08
Traditionally, cybersecurity has focused on finding and removing vulnerabilities. This is like driving backward down the highway using your rearview mirror. Most breaches are due to defects in design or code; thus, the only way to truly address the issue is to design and build more secure solutions. In this webcast, Tim Chick discusses how security is an integral aspect of the entire software life...
Can You Rely on Your AI? Applying the AIR Tool to Improve Classifier Performance Video 31.05.2024 38:50
Modern analytic methods, including artificial intelligence (AI) and machine learning (ML) classifiers, depend on correlations; however, such approaches fail to account for confounding in the data, which prevents accurate modeling of cause and effect and often leads to prediction bias. The Software Engineering Institute (SEI) has developed a new AI Robustness (AIR) tool that allows users to gauge A...
Using a Scenario to Reason About Implementing a Zero Trust Strategy Video 02.05.2024 1:02:22
There is a lot of documentation about a zero trust architecture, as well as directives that it be used for U.S. federal agencies and the Department of Defense (DoD), but little information on how to go about implementing it to improve an organization's enterprise or DoD weapon system security. Use cases typically describe requirements for these systems, but they do not provide the contextual aware...
Ask Us Anything: Supply Chain Risk Management Video 01.02.2024 41:11
According to the Verizon Data Breach Report , Log4j-related exploits have occurred less frequently over the past year. However, this Common Vulnerabilities and Exposures (CVE) flaw was originally documented in 2021. The threat still exists despite increased awareness. Over the past few years, the Software Engineering Institute (SEI) has developed guidance and practices to help organizations reduc...
The Future of Software Engineering and Acquisition with Generative AI Video 25.01.2024 1:32:10
We stand at a pivotal moment in software engineering, with artificial intelligence (AI) playing a crucial role in driving approaches poised to enhance software acquisition, analysis, verification, and automation. While generative AI tools initially sparked excitement for their potential to reduce errors, scale changes effortlessly, and drive innovation, concerns have emerged. These concerns encomp...
Cyber Supply Chain Risk Management: No Silver Bullet Video 04.10.2023 38:40
Compliance standards, privileged access management, software bills of materials (SBOMs), maturity models, cloud services, vulnerability management, etc. The list of potential solutions to supply chain risk management (SCRM) challenges seems unending as much as it is daunting to address. In this webcast, Brett Tucker explores some of these solutions. More importantly, he renews an emphasis on using...
Ask Us Anything: Generative AI Edition Video 29.09.2023 1:30:37
Generative AI (GenAI) has been around for decades, but the latest leap in progress, fueled by high-capability large language models (LLMs), image and video generators, and AI pair programmers, has captivated audiences across a variety of disciplines. What can GenAI do well? What are the risks and opportunities of using GenAI? SEI experts Doug Schmidt, Rachel Dzombak, Jasmine Ratchford, Matt Walsh,...
Evaluating Trustworthiness of AI Systems Video 14.09.2023 1:02:08
AI system trustworthiness is dependent on end users' confidence in the system's ability to augment their needs. This confidence is gained through evidence of the system's capabilities. Trustworthy systems are designed with an understanding of the context of use and careful attention to end-user needs. In this webcast, SEI researchers discuss how to evaluate trustworthiness of AI systems given thei...
Leveraging Software Bill of Materials Practices for Risk Reduction Video 07.09.2023 1:02:03
A Software Bill of Materials (SBOM) is a comprehensive list of software components involved in the development of a software product. While recently gaining attention in the context of security, SBOMs have limited value unless properly integrated into effective cyber risk management processes and practices. The SEI SBOM Framework compiles a set of leading practices for building an SBOM and using i...
Institutionalizing the Fundamentals of Insider Risk Management Video 23.08.2023 56:33
Insider threats pose an enduring, ever-evolving risk to an organization's critical assets that require enterprise-wide participation to manage effectively. Many organizations struggle to make critical tasks in insider risk management "stick," relying on several crutches to drive temporary organizational change, only to see those changes come undone and have incidents slip through the cracks. In th...
What's Wrong with ROI for Model-Based Analysis of Cyber-Physical Systems? Video 11.08.2023 56:06
In this webcast, Fred Schenker, Jerome Hugues, and Linda Parker Gates discuss the benefits of using a model-based approach to improve the design of a CPS' embedded computing resources. This is accomplished by (1) building virtual architectural models of the CPS' embedded computing resources early in the system development lifecycle and (2) using these models to predict computing system constraints...
Will Rust Solve Software Security? Video 27.07.2023 53:38
The Rust programming language makes some strong claims about the security of Rust code. In this webcast, David Svoboda and Joe Sible will evaluate the Rust programming language from a cybersecurity perspective. They will examine Rust's security model, both in what it promises and its limitations. They will also examine how secure Rust code has been seen in practice and conclude with discussing the...
Top 5 Challenges to Overcome on Your DevSecOps Journey Video 03.05.2023 1:00:36
Historically, a lot of discussion in software security focused on the project level, emphasizing code scanning, penetration testing, reactive approaches for incident response, and so on. Today, the discussion has shifted to the program level to align with business objectives. In the ideal outcome of such a shift, software teams would act in alignment with business goals, organizational risk, and s...
Improving Analytics Using Enriched Network Flow Data Video 26.04.2023 1:02:25
Classic tool suites that are used to process network flow records deal with very limited detail on the network connections they summarize. These tools limit detail for several reasons: (1) to maintain long-baseline data, (2) to focus on security-indicative data fields, and (3) to support data collection across large or complex infrastructures. However, a consequence of this limited detail is that...
How Can Data Science Solve Cybersecurity Challenges? Video 29.03.2023 1:00:01
In this webcast, Tom Scanlon, Matthew Walsh and Jeffrey Mellon discuss approaches to using data science and machine learning to address cybersecurity challenges. They provide an overview of data science, including a discussion of what constitutes a good problem to solve with data science. They also discuss applying data science to cybersecurity challenges, highlighting specific challenges such as...
AI Next Generation Architecture Video 17.03.2023 1:01:44
As Artificial Intelligence permeates mission-critical capabilities, it is paramount to design modular solutions to ensure rapid evolution and interoperability. During this webcast, we'll discuss some of the primary quality attributes guiding such design, and how a Next Generation Architecture can facilitate an integrated future state. What attendees will learn: current challenges facing AI enginee...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.