Podcasts
Two shows about the same stubborn problem: how the world decides which technology it can trust.
Certification and compliance get decided in rooms most people never see: standards committees, technical working groups, regulator consultations. Josh spent nearly 20 years in those rooms. The debates that happen there — over risk, evidence, practicality, and what “trusted” really means — are more interesting, and more consequential, than the documents that eventually come out of them.
That’s what both shows are for: bringing those conversations out from behind closed doors, with the people actually shaping them.
Trust and turbulence
Hosted by Josh · New episodes regularly
Joshua Brickman spent more than two decades inside the world of cybersecurity certifications, government assurance programs, and global security regulation. Now he’s bringing those conversations out from behind closed industry meetings and into the public.
This podcast explores the collision between security, innovation, AI, regulation, and trust. Why do governments require certifications like Common Criteria and FIPS 140? Why are they often slow and expensive? Why do some regulators trust vendor declarations while others demand independent testing? And can AI and automation finally modernize the system?
From post-quantum cryptography and supply chain security to the EU Cyber Resilience Act and cloud assurance, the show translates highly technical topics into practical conversations that matter to businesses, policymakers, technologists, and consumers alike.
Because in a world run by software, the real question is no longer just “does it work?” — it’s “who decided we can trust it?”
Trust and Turbulence is on Spotify, Apple Podcasts, YouTube and iHeartRadio. Follow it wherever you already listen and new episodes turn up on their own.
ICT Compliance
The ICT Compliance Pod is a monthly podcast serving the cybersecurity compliance ecosystem across commercial, federal, and defense markets. The podcast addresses the ICT compliance needs of the entire industry value chain, including ICT product developers, component suppliers, commercial testing laboratories, trusted integrators, standards organizations, and government agencies.