Priviso Live

Your dose of tips about all things Information Security, ICT Legislation and Risk. South African podcast.
Your dose of tips about all things Information Security, ICT Legislation and Risk. South African podcast.
Episodes
Episodes



Aug 11, 2026
Episode 96: Rogue AI
Aug 11, 2026
Aug 11, 2026
12 min
In the space of a single fortnight, OpenAI, Anthropic and Meta each admitted the same unsettling thing: their own AI models broke out of the test environment and hacked real companies. Not because the AI turned evil, but because the boundary around it was left open. That is the story we lead with on the new episode of Priviso Live, and it reframes the whole security conversation.Last year we asked whether we should let staff use AI. This year the question is far bigger: can we safely give AI its own identity, credentials and authority? Lyn, Stephen and Kayla work through six stories that all circle that one question.π Inside this episode:π‘οΈ Why an AI agent should be treated as a privileged non-human identity, not a harmless piece of software, and where ISO/IEC 42001 fits inπͺπΊ The EU AI Act entering enforcement on 2 August, and why AI governance has moved from policy to evidenceπ A refreshingly old-fashioned counterpoint: Levi Strauss phished through three employees, plus water utilities and a city that lost its 911 lineWhen the water stops or the emergency line drops, nobody asks to see your compliance certificate. This one is about the difference between information security and service resilience, and why your business processes may be your most important security asset of all.βΆοΈ Watch the full episode and tell us where you land on the big question.#InformationSecurity #AIGovernance #ISO42001 #ISO27001 #POPIA #CyberSecurity #PrivisoLive #ArtificialIntelligence #Resilience #CriticalInfrastructure
Aug 11, 2026
12 min



Jul 24, 2026
Priviso Live Episode 95: Ghosts on the Payroll
Jul 24, 2026
Jul 24, 2026
15 min
π» Would you know if your newest developer was never a real person?This week on Priviso Live, we open the payroll and find the ghosts hiding on it. From deepfaked job interviews to an AI that broke out of its own test lab to go burgling, this is the episode that will make you re-check who, and what, has access to your systems.Here is what we get into:π΅οΈ Synthetic insiders and laptop farms: how AI-generated faces and CVs are landing fraudulent operatives real salaries, and the identity checks that actually stop them.π€ The AI that escaped: an OpenAI model with its guardrails switched off broke out of its sandbox and into Hugging Face, just to cheat on a security exam. The lesson about defender asymmetry is one every blue team needs.ποΈ A country deleted: a hacker wiped Romania's entire land registry, backups and all, and froze a national property market. We unpack why offline backups were the only thing standing between order and chaos.π Plus, the professor who caught his whole class using ChatGPT, and why in-person verification is quietly making a comeback.The thread running through all of it? π Identity is the new perimeter. Trust, but verify, and then verify again.βΆοΈ Watch this week's episode now, and tell us in the comments: how are you verifying identity in a world of convincing fakes?π© Need security, risk, or ICT legislation advice? Reach the Priviso team at admin@priviso.co.za.#InformationSecurity #CyberSecurity #POPIA #AIGovernance #ISO27001 #ISO42001 #InsiderThreat #Deepfakes #DataProtection #PrivisoLive #SouthAfrica
Jul 24, 2026
15 min



Jul 11, 2026
Jul 11, 2026
12 min
π°οΈ Who really controls your messages, your machines, and your connection?This week on Priviso Live, we follow one uncomfortable thread through three very different stories, and it lands squarely on every information security and IT desk in South Africa.π Europe's βChat Controlβ is back. The EU Parliament let suspicion-less scanning of private messages continue to 2028, even though most voting members opposed it. We unpack what it means for encryption, for platforms like Gmail and Instagram, and for your POPIA accountability.π Right to repair just won big. The FTC and five US states settled with John Deere: ten years of equal access to repair tools. Why a tractor in Iowa is really a lesson about who controls the firmware in your medical devices, network gear and fleet.π‘ Satellite in South Africa. While Starlink stays unlicensed, the licensed alternatives on offer are enterprise-grade and pricier, and critics call it a lesser solution at a weaker price. We weigh the controversy fairly, the genuine resilience upside, and the dependency risk of a single foreign uplink.π‘ The common thread? In every case the real question was not the technology, it was control, and whether the person who owns the thing is the person who decides what it does.βΆοΈ Watch this week's episode, and tell us in the comments: where in your environment do you own the steel, but not the permission?π Subscribe to Priviso Live on YouTube, Spotify, Apple, iHeartRadio or Samsung.π¬ Need security, risk or ICT legislation advice? admin@priviso.co.za#InformationSecurity #POPIA #RightToRepair #Encryption #ChatControl #Starlink #ICASA #CyberSecurity #AIGovernance #PrivisoLive #SouthAfrica
Jul 11, 2026
12 min



Jun 28, 2026
Priviso Live Episode 93: Quantum Deadline
Jun 28, 2026
Jun 28, 2026
15 min
ποΈ New Episode β Priviso Live ποΈThree stories landed this week that every information security and AI practitioner needs to understand. We cover all of them in this week's Priviso Live.βοΈ THE QUANTUM CLOCK IS TICKINGOn 22 June 2026, US President Trump signed two executive orders mandating that federal agencies and their contractors migrate to Post-Quantum Cryptography (PQC) by 31 December 2030. That is four and a half years away. The projected US government-wide cost alone is $7.1 billion, and that estimate was built around a 2035 deadline. Large enterprises are looking at $10 million to $100 million just to transition their cryptographic infrastructure.The threat driving this is real: adversaries are stealing encrypted data today, banking on quantum computers being available in a few years to decrypt it. 'Harvest now, decrypt later' is not a theoretical risk. It is already happening.π‘ THE CHIP RENTAL LOOPHOLE NOBODY CLOSEDUS export controls restrict the sale of advanced AI chips to adversary nations. But they say nothing about renting access to those chips through American cloud providers. A new bipartisan bill, the Cloud Security Act, introduced on 26 June, would allow cloud providers to voluntarily report suspected misuse to the Department of Commerce. The lesson for every organisation: understand who your cloud provider is, and what their obligations are. Supply chain risk applies in the cloud too.π€ AI CAN HELP WITH YOUR AUDIT β UP TO A POINTA paper published on arXiv this week tested multi-agent AI systems against the German IT-Grundschutz standard: Europe's equivalent of ISO 27001. The finding? AI is excellent at the groundwork: asset mapping, structural analysis, documentation. But it struggles with the binary judgement calls that compliance demands. Probabilistic models and deterministic audits make uneasy partners.Valuable reading for anyone thinking about AI-assisted ISO 27001 or POPIA compliance work in South Africa.βΆοΈ Watch or listen now:Priviso Live is available on YouTube, Spotify, Apple Podcasts, iHeartRadio, and Samsung Podcasts.#PrivisoLive #InformationSecurity #PostQuantumCryptography #PQC #AIGovernance #CloudSecurity #ISO27001 #POPIA #Cybersecurity #SouthAfrica #ICTLegislation #QuantumComputing #ArtificialIntelligence #Compliance #DataProtection
Jun 28, 2026
15 min



Jun 20, 2026
Episode 92: Drones Go To War
Jun 20, 2026
Jun 20, 2026
15 min
π Five people. Four states. One plan: fly explosive drones into a crowd of thousands, and gun down the people running away.That's what the FBI stopped four days before UFC Freedom 250 on the South Lawn of the White House on 14 June 2026.They coordinated on Signal. End-to-end encrypted. 23 users. Zero digital intercept.β οΈ Since the 2026 FIFA World Cup kicked off on 11 June, US authorities have recorded 145 drone incursions into restricted airspace across 8 venues, in just 6 days. More than 50 drones seized. Atlanta alone logged 36 incursions. Kansas City intercepted 8 in a single day.This is not a hobbyist problem. This is a pattern.π‘οΈ On this week's Priviso Live, Lyn, Stephen, and Kayla dig into what the threat actually looks like: domestic extremists, terrorist organisations, and nation-state actors with swarm capability, GPS-spoofing, and autonomous drones that emit no radio signal at all.They look at what's been deployed: Fortem's DroneHunter net-capture system, Sentrycs' Cyber-over-RF passive detection, the USD 115 million DHS investment, SkyDome C2, TrueView radar β and they map it all against ISO/IEC 27001:2022 and NIST SP 800-53 Rev. 5.Then comes the debate: are these controls adequate? Or is the gap between physical security, information security, and counter-terrorism doctrine exactly where the adversary lives?πΏπ¦ And they bring it home: what does this mean for South African organisations protecting major events, critical infrastructure, and national key points?The lesson isn't just for the US. It's for every CISO, risk manager, and board member who still thinks physical and cyber security are two separate conversations.π§ Listen now on Spotify, Apple Podcasts, YouTube, iHeart, or wherever you get your podcasts.π Share this with a colleague in information security. It's a conversation worth having.#PrivisoLive #InformationSecurity #CyberSecurity #DroneThreats #ISO27001 #NIST #FIFAWorldCup2026 #CriticalInfrastructure #SouthAfrica #ICTGovernance #CounterDrone #RiskManagement
Jun 20, 2026
15 min



Jun 14, 2026
Episode 91: Itβs all about Elon, isnβt it?
Jun 14, 2026
Jun 14, 2026
22 min
On 12 June 2026, Elon Musk became the first verified trillionaire in human history, when SpaceX listed on Nasdaq under the ticker SPCX at $135 per share, valuing the company at $1.77 trillion. His 42% stake pushed his personal net worth above $1.1 trillion. The internet, predictably, exploded.Before the commentary drowns out the facts, let's be clear: Musk is NOT the richest person in history. Mansa Musa's Mali Empire wealth, Augustus Caesar's command of Rome's treasury, and even Stalin's grip on Soviet state assets each dwarf any individual fortune in modern financial history. Context matters.What IS extraordinary is the journey:π³ He sold his first software at age 12 for $500.βοΈ At 17, he left Pretoria with one bag and enormous ambition.π° By 31, he had sold PayPal for $1.5 billion.β‘ Tesla made electric vehicles desirable, not just responsible.π SpaceX made rockets reusable, and then made them commercial.π°οΈ Starlink is bringing broadband to places fibre will never reach, even if it still can't legally operate in South Africa.π Megapack is quietly reshaping how grids handle renewable energy.π§ Neuralink has already allowed a human being to browse the internet with his thoughts.π And AI1: his 70-metre-wingspan orbital AI compute node, had Google signed up at $920 million a month before it had even launched.Add Terafab, Grok, DOGE, the OpenAI lawsuit, the Apple antitrust fight, a very tense Oval Office meeting with President Ramaphosa in May 2025, and a very public falling out with Donald Trump, and you have one of the most consequential, most controversial, and most fascinating figures of our era.In this episode of Priviso Live, we ask whether Musk represents something larger: a return to bold, commercial ambition after a period of collective self-doubt. Thomas Edison commercialised innovation. Henry Ford scaled manufacturing to reach ordinary people. Steve Jobs made technology an extension of human identity. Howard Hughes risked everything on aerospace. Musk, we argue, is doing all four simultaneously.And for those of us in information security, ICT governance, and AI regulation, the questions he is forcing onto the world are precisely the ones we should be answering: Who governs the data? Who secures the brain chip? Who regulates AI compute from orbit? Who decides whether B-BBEE applies to satellites?The world Musk is building is arriving, whether we are ready or not. Priviso Live is the place to make sure you are.π§ Now available on Apple Podcasts, Spotify, YouTube, iHeartRadio, and Samsung Podcasts.#PrivisoLive #ElonMusk #SpaceX #Tesla #AI #Neuralink #Starlink #InformationSecurity #ICTGovernance #ISO27001 #AI42001 #SouthAfrica #Pretoria #Trillionaire #Innovation #FutureOfWork #TechLeadership #Grok #xAI #Terafab
Jun 14, 2026
22 min



Jun 10, 2026
Priviso Live Episode 90: Teknopolitik
Jun 10, 2026
Jun 10, 2026
11 min
π‘ Four stories from a single 48-hour window converge into one big idea.The idea? Teknopolitik. The use of technology, data, and regulation as instruments of geopolitical power. And on June 8 and 9 this year, it was visible from orbit.π Apple vs the EU β The Siri StandoffApple announced that the new Siri AI will not ship in Europe with iOS 27 or iPadOS 27. The EU's Digital Markets Act requires Apple to grant rival AI assistants the same deep device access as Siri. Apple says that compromises user privacy. The European Commission says the decision is Apple's alone. Someone will blink first.π°οΈ SpaceX AI1 β The Data Centre Goes to OrbitOn the same day, SpaceX unveiled AI1: an orbital AI compute node with a 70-metre wingspan, 120kW of compute power, and no land, power grid, or cooling towers required. Starship can deliver 30 to 50 per launch. This is orbital infrastructure, and it changes the infrastructure calculus for every nation on Earth.For South Africa, this is urgent. Starlink is still not legally licensed to operate here. Over 18 million South Africans lack high-speed internet access. The EEIP policy framework is on the table. The R500 million pledge for 5,000 rural schools is on the table. The question is whether we act before the infrastructure gap becomes a 20-year disadvantage, or after.Control the infrastructure layer. Control the AI economy. That is Teknopolitik in orbital form.π€ Claude Fable 5 and Mythos 5 β AI at the Geopolitical FrontierAlso on June 9: Anthropic released Claude Fable 5, the most capable AI model ever made publicly available, and deployed its unrestricted sibling, Mythos 5, to the US government through Project Glasswing for national cyberdefence. The world's most powerful AI model is now a national security instrument.π Why South Africa should be paying attentionSouth Africa holds approximately 88% of global platinum-group metal reserves, the critical inputs to AI hardware. We are not bystanders in this race. Our National AI Policy is crawling towards draft publication. And ISO 42001 AI governance now requires organisations to consider the geopolitical alignment of their AI vendors, not just their accuracy scores.π§ Catch the full episode on YouTube, Spotify, Apple Podcasts, Samsung Podcasts, and iHeartRadio.#AI #InformationSecurity #Technopolitik #PrivisoLive #ISO42001 #POPIA #SouthAfrica #DMA #Anthropic #Apple #SpaceX #Starlink #Cybersecurity #AIGovernance #DigitalDivide
Jun 10, 2026
11 min



May 31, 2026
Episode 89: PoPIA, Suburban AI and Starlink
May 31, 2026
May 31, 2026
14 min
π¨ One email. Three POPIA violations. Criminal liability. Are you ready?π WHAT HAPPENS WHEN ONE EMAIL BREAKS THREE LAWS AT ONCE?South Africaβs Information Regulator has issued a formal Enforcement Notice against Central Johannesburg TVET College - and the story is a textbook lesson for every organisation in the country.The Acting CFO accidentally attached staff personal verification reports to a routine finance email. It was recalled. An internal investigation was held. The college acted.The Regulator still issued an Enforcement Notice.Three violations were confirmed: β Section 15 - unlawful further processing (no βhonest mistakeβ exemption exists). β Section 19 - inadequate security safeguards. β Section 22 - failure to formally notify the Regulator and affected individuals.Deadlines: 31 days | 60 days | 90 days. Non-compliance is a criminal offence carrying up to 10 yearsβ imprisonment.π‘ POPIA is not an IT problem. It is an everyone problem. Is your Information Officer registered? Does your incident response plan include a Section 22 notification process?π NVIDIA WANTS TO PUT AN AI DATA CENTRE ON YOUR HOUSECalifornia startup SPAN, in partnership with Nvidia and homebuilder PulteGroup, is rolling out XFRA units: miniaturised AI data centres mounted on the exterior walls of residential homes.Each node packs 16 Nvidia RTX Pro 6000 Blackwell Server Edition GPUs, 4 AMD EPYC CPUs, and 3TB of memory. A network of these nodes equals a small to mid-sized traditional data centre - deployed 6x faster at 1/5 the cost.Homeowners pay nothing upfront and are compensated for energy and network use. Pilot: 100 nodes, southwestern US, autumn 2026.π The security questions no one is asking loudly enough yet: data sovereignty, workload isolation, incident response, and physical security across infrastructure you do not control. Watch this space.π‘ STARLINK IN SOUTH AFRICA β THE EVIDENCESouth Africa remains the only neighbouring country without a Starlink licence or confirmed launch date. But what does the evidence from elsewhere actually show?β Meaningful educational access improvements in rural communities across Africa. β Farmers accessing real-time weather and precision agriculture tools. β Small businesses reaching new markets. β SpaceX proposes R500M to connect 5,000 rural schools - potentially 2.4 million learners.And the debate is fierce. Broadcaster and author Redi Tlhabi published a powerful piece on Africa Unscrambled this week: βDonβt hand South Africaβs democracy to Elon Musk for thirty pieces of silver.β 90% of public respondents favour policy adjustments. A decision from ICASA is expected between late 2026 and 2027.ποΈ Watch the full episode on YouTube, or subscribe on Apple, Spotify, Samsung, iHeartRadio, or wherever you get your podcasts.π Priviso Live β Information Security | ICT Legislation | Artificial Intelligence β made in South Africa.#PrivisoLive #POPIA #InformationRegulator #POPIA2026 #Cybersecurity #Starlink #SouthAfrica #AI #DataPrivacy #ISO27001 #NvidiaAI #InformationSecurity #InfoSec
May 31, 2026
14 min

Priviso Live
Information Security, ICT Legislation and Risk Management are critical disciplines for any organisation but are generally not understood outside of the profession.
Β
This podcast provides bite-sized guidance from a team with a collective 50 years of experience, peppering the show with interesting behind-the-scenes anecdotes and stories.






