Home Podcasts The InfoSec Control Room
The InfoSec Control Room

The InfoSec Control Room

Taher Amine ELHOUARI 24 Episodes Aug 22, 2026

The InfoSec Control Room is a cybersecurity podcast hosted by Taher Amine ELHOUARI, focusing on governance, risk, compliance, resilience, and CISO-level decision-making. It explores the gap between what organizations believe they have in place and what actually works during incidents, audits, regulatory questions, and risk-based decisions. Topics include information security, GRC, CISO leadership, ISO standards, cyber resilience, privacy, incident response, CSIRT operations, security awareness, and regulatory expectations. The core premise is that most organizations have a governance problem that manifests as security. The show targets CISOs, security leaders, GRC professionals, auditors, consultants, and practitioners.

Episodes

EP008: Stop Lying to Yourself About Cyber Maturity
EP008: Stop Lying to Yourself About Cyber Maturity Aug 22, 2026 1562 In EP008 of The InfoSec Control Room, Taher Amine ELHOUARI takes on one of cybersecurity’s favorite activities:Measuring maturity.Organizations love maturity scores.3.4 out of 5. Level 4. Managed. Optimized. Green dashboard.Everything looks reassuring.But what does the score actually mean?Can the organization detect an attacker?Can it restore a critical service?Can it revoke privileged access quic
EP007: Incident Response Starts Before the Incident
EP007: Incident Response Starts Before the Incident Aug 16, 2026 1733 In EP007 of The InfoSec Control Room, Taher Amine ELHOUARI explores a simple but often misunderstood reality:Incident response does not begin when the incident happens.By the time the first serious alert fires, many of the decisions that will determine the quality of the response have already been made.Who has authority to isolate a critical system?Who can declare a major incident?Who decides whet
EP006: Your Policy Is Not a Control
EP006: Your Policy Is Not a Control Aug 15, 2026 1464 In EP006 of The InfoSec Control Room, Taher Amine ELHOUARI takes on one of the most common misconceptions in information security governance:Having a policy does not mean you have a control.An organization can have approved information security policies, access control requirements, data classification rules, acceptable-use standards, incident procedures, and beautifully version-controlled documen
EP005: GRC and SecOps Are Speaking Different Languages
EP005: GRC and SecOps Are Speaking Different Languages Aug 14, 2026 1559 In EP005 of The InfoSec Control Room, Taher Amine ELHOUARI explores one of the most important — and often underestimated — relationships inside a cybersecurity program: the connection between GRC and Security Operations.In many organizations, GRC and SecOps behave like two neighboring countries.GRC speaks in controls, policies, risk registers, audit findings, evidence, compliance obligations, and
EP004: The CISO Is Not a Superhero
EP004: The CISO Is Not a Superhero Aug 13, 2026 1451 In EP004 of The InfoSec Control Room, Taher Amine ELHOUARI challenges one of the most common and damaging assumptions in cybersecurity governance:“We have a CISO. Cybersecurity is their responsibility.”It sounds reasonable until you start asking who actually creates, owns, accepts, and manages cyber risk across an organization.A business unit launches an application without involving security. Pro
EP003: Compliance Is Not Control
EP003: Compliance Is Not Control Aug 12, 2026 2015 In EP003 of The InfoSec Control Room, Taher Amine ELHOUARI explores the uncomfortable gap between being compliant and actually being in control.An organization can have approved policies, completed audits, risk registers, procedures, evidence, management reviews, and even certifications on the wall; while still struggling to answer very simple questions:Can we actually restore our critical systems
EP002: The Real Reason Security Programs Fail
EP002: The Real Reason Security Programs Fail Aug 12, 2026 1801 In this episode of The InfoSec Control Room, Taher Amine ELHOUARI explores one of the core ideas behind the podcast: many security programs do not fail because there is no cybersecurity activity. They fail because that activity is not governed, owned, measured, or improved properly.The episode explains why security failures are often symptoms of deeper structural issues: unclear accountability, we
EP001: Welcome to The InfoSec Control Room
EP001: Welcome to The InfoSec Control Room Aug 10, 2026 1902 In this first original episode of The InfoSec Control Room, Taher Amine ELHOUARI formally introduces the podcast, the story behind it, and the core philosophy that will guide future episodes.This opening episode explains why The InfoSec Control Room exists, who it is for, and why cybersecurity must be understood beyond tools, incidents, vulnerabilities, frameworks, and technical controls.Taher int
Media Archive: Building Cyber Resilience Beyond Compliance | Full Webinar | Taher Amine ELHOUARI - iExperts
Media Archive: Building Cyber Resilience Beyond Compliance | Full Webinar | Taher Amine ELHOUARI - iExperts Jul 30, 2026 3991 Compliance may demonstrate that security requirements have been addressed. Cyber resilience demonstrates that governance, people, processes, and technology can continue to operate under real pressure.This special webinar edition of The InfoSec Control Room presents the complete audio recording of my latest iExperts session: BUILDING CYBER RESILIENCE BEYOND COMPLIANCE.During this session, I examine
Media Archive:  Conformity Assessment Meets Cybersecurity | FIRST & AfricaCERT Symposium 2025
Media Archive: Conformity Assessment Meets Cybersecurity | FIRST & AfricaCERT Symposium 2025 Jun 23, 2026 1625 In this Media Archive episode of The InfoSec Control Room, Taher Amine ELHOUARI shares his conference session from the FIRST & AfricaCERT Symposium 2025 in Mauritius: “Conformity Assessment Meets Cybersecurity: Building a Common Language Between Auditors and Analysts.”This session explores one of the most important gaps in cybersecurity assurance: why organizations can appear compliant on pape
Media Archive: The Hidden Face of Cyber Extortion on Algerian National TV
Media Archive: The Hidden Face of Cyber Extortion on Algerian National TV Jun 23, 2026 598 In this Media Archive episode of The InfoSec Control Room, Taher Amine ELHOUARI shares a national television intervention from Taqassi — Season Five, produced by Algerian National Television, focused on cyber extortion and online blackmail. This episode explores one of the most dangerous and rapidly growing crimes in the digital space: how attackers exploit psychology, privacy gaps, digital habits
Media Archive: From Chaos to Control — Building and Maturing CERT/CSIRT Teams
Media Archive: From Chaos to Control — Building and Maturing CERT/CSIRT Teams Jun 23, 2026 3836 In this Media Archive episode of The InfoSec Control Room, Taher Amine ELHOUARI shares a full masterclass titled “From Chaos to Control: Understanding, Building, and Maturing Your Cyber Response Team.” This session focuses on the fundamentals, structure, and maturity of cyber response teams, including CERTs, CSIRTs, operational readiness, field tactics, and the architecture of cyber resilience.The

Recommended