Retour

Explorez tous les épisodes du podcast CISO Series Podcast

Plongez dans la liste complète des épisodes de CISO Series Podcast. Chaque épisode est catalogué accompagné de descriptions détaillées, ce qui facilite la recherche et l'exploration de sujets spécifiques. Suivez tous les épisodes de votre podcast préféré et ne manquez aucun contenu pertinent.

Rows per page:

1–50 of 409

TitreDateDurée
Red Flag? My Vendor Just Asked for My Mother’s Maiden Name03 Sep 202400:37:50

All links and images for this episode can be found on CISO Series.

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Joining us is Bethany De Lude, CISO, the Carlyle Group.

In this episode:

  • CISOs as storytellers
  • Grinding a CISO’s gears
  • An evolving role
  • Earning trust with vendors

Thanks to our podcast sponsor, Scrut Automation!

Scrut Automation allows compliance and risk teams of any size to establish enterprise-grade security programs. Our best-in-class features like process automation, AI, and 75+ native integrations reverse compliance debt and help manage risk proactively as your business grows. Visit www.scrut.io to learn more or schedule a demo.

Well, I Think My Relationship With the CIO Improved When I Took Their Job27 Aug 202400:37:21

All links and images for this episode can be found on CISO Series.

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Joining us is Ty Sbano, CISO, Vercel.

In this episode:

  • Perception is the reality for insider threats
  • Coaching rather than shaming
  • Working to make DevOps redundant
  • Fixing a strained relationship

Thanks to our podcast sponsor, Backslash!

Backslash Security is your modern AppSec solution, focusing on what truly matters—real risks. Gain clear visibility into your applications and fix only the code and open-source software that’s actually in use, making your AppSec smarter and more efficient. Learn more at https://www.backslash.security/.

How About This? Only Attack the Endpoints We Configured25 Jun 202400:40:19

All links and images for this episode can be found on CISO Series.

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Joining us is our guest and winner of Season 2 of Capture the CISO, Russell Spitler, CEO and co-founder, Nudge Security.

In this episode:

  • The Gordian knot of EDR
  • Can we keep up with patching?
  • Making AI practical
  • Standardization or granularity?

Thanks to our podcast sponsor, ThreatLocker!

ThreatLocker® is a global leader in Zero Trust endpoint security offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.

But I Spent All This Money. Why Are You Still Ignoring Me?30 Aug 202200:37:22

All links and images for this episode can be found on CISO Series

Are RSA and other big conferences worth it? It seems that fewer CISOs are actually walk the floor at these big trade shows. The really big meetings are happening outside of the conference. Why would CISOs attend these big conferences with airfares costing over $1000 and hotel rooms costing $500 to $800 a night? Are the customers and vendors getting priced out?

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our guest is Jessica Ferguson, CISO, DocuSign.

Thanks to our podcast sponsor, SlashNext

SlashNext protects the modern workforce from phishing and human hacking across all digital channels. SlashNext Complete™ utilizes our patented AI SEER™ technology to detect zero-hour phishing threats by performing dynamic run-time analysis on billions of URLs a day through virtual browsers and machine learning. Take advantage of SlashNext's phishing defense services for email, browser, mobile, and API.

In this episode:

  • Are big conferences like RSA worth it? What's the value of the trade show floor at RSA?
  • Why would CISOs attend these big conferences with airfares costing over $1000 and hotel rooms costing $500 to $800 a night?
  • Are the customers and vendors getting priced out?
It’s OK to Look Like a Cyber Hero. Just Don’t Act Like One.23 Aug 202200:39:38

All links and images for this episode can be found on CISO Series

Security professionals should turn in the cyber hero mentality for the "sidekick" role. Many cybersecurity leaders believe they need to save the company from all the stupid users who can't protect themselves. The reality is security professionals should lose the saviour mentality for a supporting role where they're running alongside different business units trying to find a way to make their process run smoother and more secure.

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Our wponsored guest Clyde Williamson, product management, innovations, Protegrity.

Thanks to our podcast sponsor, Protegrity

Protegrity empowers intelligence-driven organizations to use data to drive innovation with secure analytics and artificial intelligence, without fear of violating compliance or jeopardizing privacy. To make this vision a reality, we protect sensitive data anywhere and everywhere to create secure data agility that aligns with the speed of modern business.

In this episode:

  • Is it OK if users see security as heroes but security professionals shouldn't see themselves that way?
  • What have you heard enough about when it comes to data protection, and what would you like to hear a lot more?
  • How can we best create a cyber risk balance sheet?
How to Market “Zero Trust” Without Making CISOs Cringe16 Aug 202200:33:40

All links and images for this episode can be found on CISO Series

Just the words "zero trust" often causes security professionals to shiver. In general, CISOs are on board with the concepts of "zero trust," we just think they're uncomfortable with how it's being used for branding and marketing efforts.

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our guest is David Cross (@mrdbcross), SVP/CISO for Oracle SaaS Cloud.

Thanks to our podcast sponsor, Protegrity

Protegrity empowers intelligence-driven organizations to use data to drive innovation with secure analytics and artificial intelligence, without fear of violating compliance or jeopardizing privacy. To make this vision a reality, we protect sensitive data anywhere and everywhere to create secure data agility that aligns with the speed of modern business.

In this episode:

  • Should certifications be a requirement on your job listings?
  • Are the SIEMs failing or do the users not know how to configure them? Or is it both?
  • Why do security professionals treat the term "zero trust" so negatively? How should vendors approach zero trust and how should the C-suite understand it?
When Good Decisions Go Bad09 Aug 202200:40:00

All links and images for this episode can be found on CISO Series

You can make the right decision given the information you have, but everything is a risk, so there are times those good decisions are going to result in not the result you were hoping for. In essence, plenty of good decisions result in poor outcomes.

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Our guest is Aviv Grafi, founder and CTO, Votiro and winner of season one of Capture the CISO.

In this episode:

  • We welcome the winner of “Capture The CISO!” How did they prepare in terms of making the demo and for appearing on the show? And what advice would they give for contestants in season 2?
  • What do employers look for or ask in an interview that would lead them to hire and promote someone into a CISO role in their company?
  • How can cybersecurity professionals improve their decision making over time?
When Does an Exaggeration Become a Lie?02 Aug 202200:38:32

All links and images for this episode can be found on CISO Series

We explore the world of dishonesty in cybersecurity. Practitioners know that marketers will stretch the truth, but how far are we willing to let that go? Isn't this industry built on trust? Can cybersecurity continue to thrive if we can't trust each other?

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our sponsored guest is Anna Belak (@aabelak), director of thought leadership, Sysdig.

Thanks to our podcast sponsor, Sysdig

Sysdig is driving the standard for cloud and container security. With Sysdig, teams find and prioritize software vulnerabilities, detect and respond to threats, and manage cloud configurations, permissions and compliance. Customers get a single view of risk from source to run, with no blind spots, no guesswork, no black boxes.

In this episode:

  • What are the questions a CISO should be able to answer?
  • How much dishonesty do you find in cybersecurity?
  • How does one LEAD a cloud migration?
  • What are some lies about machine learning that everyone needs to be aware of?
Yuck! Now Everyone Has Touched My Data.26 Jul 202200:33:47

All links and images for this episode can be found on CISO Series

What can you do when your data keeps passing through different third party applications? Your data is being accessed and manipulated by more people, more applications, and more security policies that may not be aligned with your security policies. It seems once it leaves your environment, it's out of your control.

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Our sponsored guest is Elliot Lewis (@ElliotDLewis), CEO, Keyavi.

Thanks to our podcast sponsor, Keyavi

Myth: Data can’t protect itself. Fact: Now it does! You control where your data goes in the world, who can access it and when. On any device. Anytime. Anywhere. FOREVER. Learn more at Keyavi.com.

In this episode:

  • Can the US government, through regulation, shift the tide of never-ending cybersecurity failures?
  • Your network was just hit with ransomware. What do you do in your environment?
  • What should we be discussing more of when it comes to protecting data in the supply chain?
  • What's the biggest security flaw you've seen in every environment you've ever worked?

 

“Bad” Security Practices That Really Aren’t All that Bad19 Jul 202200:36:01

All links and images for this episode can be found on CISO Series

If they can find flaws, security professionals are quick to label it as bad security behavior. But often, what is marked as "bad" may have problems, but when looked at from a reducing risk perspective it's actually a very good security behavior.

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our guest is Carla Sweeney, vp information security, Red Ventures.

Thanks to our podcast sponsor, Protegrity

Protegrity empowers intelligence-driven organizations to use data to drive innovation with secure analytics and artificial intelligence, without fear of violating compliance or jeopardizing privacy. To make this vision a reality, we protect sensitive data anywhere and everywhere to create secure data agility that aligns with the speed of modern business.

In this episode:

  • Is a CISO really an architect of choices, for themselves and the other business leaders?
  • Why and how can controls impose friction or drag on business velocity?
  • What are the types of questions you ask when you're referencing a resume and what are some examples of really impressive responses?
  • What are some things that get a bad rap, but are actually quite secure?
How Many Forms of ID Do I Need to Buy This Gift Card?12 Jul 202200:31:35

All links and images for this episode can be found on CISO Series

Getting someone to purchase gift cards is a popular vector for theft. Given that the gift card theft technique is so well known, many online sites have put up additional barriers to purchasing gift cards. Trying to buy them legitimately has become increasingly difficult.

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Our guest is Ariel Weintrab (@securitymermaid), CISO, MassMutual.

Thanks to our podcast sponsor, PlexTrac

PlexTrac is a powerful, yet simple, cybersecurity platform that centralizes all security assessments, pentest reports, audit findings, and vulnerabilities. PlexTrac transforms the risk management lifecycle, allowing security professionals to generate better reports faster, aggregate and visualize analytics, and collaborate on remediation in real-time.

Check out PlexTrac.com/CISOSeries to learn why PlexTrac is the perfect platform for CISOs!

In this episode:

  • What areas should we focus on improving the security user experience for non-security people?
  • Does it get easier at the top? What factors do you think result in the workload being tougher or easier for a CISO?
  • How can radical transparency help and where can it backfire?
  • What can we do to avoid poisoned systems and how can we tell if our systems have been poisoned?
Why Does Your Privacy Matter If I’m Paying You?05 Jul 202200:34:43

All links and images for this episode can be found on CISO Series

Should you monitor your staff? I mean reallymonitor them. Some bosses are installing screen grabbing and click tracking software to monitor employees and by most estimates employees hate it so much that half of them would quit if their supervisors installed monitoring software on their computers. But in some cases an employee's behavior may lend themselves to being monitored.

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our sponsored guest is Ian Hassard (@ihassard), director of product management, Okta.

Thanks to our podcast sponsor, Okta

Auth0 is the leading provider of customer identity solutions. Watch Jameeka Aaaron, CISO for Auth0, explain how to balance security with friction to create a safe authentication experience without compromising on privacy.

In this episode:

  • What are the real world positive impacts that result on the business in terms of risk reduction, product development, and prevention?
  • What are some alternatives to address the authentication problem?
  • What have you heard enough about with authentication, and what would you like to hear a lot more about?
  • To what level should you and shouldn't you monitor your staff? What cases do you feel you would have to install monitoring software?
It Sure Is Fun to Complain About Security Vendors28 Jun 202200:35:04

All links and images for this episode can be found on CISO Series

Next time you're annoyed by a security vendor's pitch, instead of firing back at them at what an idiot they are, or complaining about it on social media, why not see if you can find a friendly manager at the vendor company and explain what happened so they can actually address the problem appropriately?

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our guest is Rob Suarez, CISO, BD.

Thanks to our podcast sponsor, Trend Micro

Trend Micro Cloud One, a security services platform for cloud builders, delivers the broadest and deepest cloud security offering in one solution, enabling you to secure your cloud infrastructure with clarity and simplicity. Discover your dynamic attack surface, assess your risk, and respond with the right security at the right time. Discover more!

In this episode:

  • Where could we possibly draw the line of what can be known to the public, but at the same time not offering insight to the attackers?
  • We examine what makes medical establishments an attractive target. Why are medical records valuable and outside of havoc is there any other purpose of tampering with medical devices?
  • How do you use industry-specific threat information to make better security decisions?
  • Why do some cybersecurity companies succeed and others fail?
The Post-it Note Clearly Says “Don’t Share” Right Under My Password18 Jun 202400:37:19

All links and images for this episode can be found on CISO Series.

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson, CISO, Rivian. Joining us is our sponsored guest, Allan Alford, CISO, Eclypsium.

In this episode:

  • Evolving public-private partnerships
  • New technology, but not a new challenge
  • Securing the hidden layers of the supply chain
  • Balancing usability and control

Thanks to our podcast sponsor, Eclypsium

Eclypsium is helping enterprises and government agencies mitigate risks to their infrastructure from complex technology supply chains. Our cloud-based and on-premises platform provides digital supply chain security for software, firmware and hardware in enterprise infrastructure. Get started today at eclypsium.com/spark.

What Does It Cost to Prove Security Is Working?21 Jun 202200:37:12

All links and images for this episode can be found on CISO Series

I have no idea what I need to spend to demonstrate our security program is working. What's it going to take? Or maybe I need just others on my team to just validate that they truly do care about security.

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Our guest is John McClure (@johnmcclure00), CISO, Sinclair Broadcast Group.

Thanks to our podcast sponsor, Keyavi

Data that protects itself?  Now it does! We made data so smart it can think for itself. Secure itself. Stay continually aware of its surroundings. Control where, when and who is allowed access. And automatically report back to its owner. This changes the entire cybersecurity paradigm. Learn how.

In this episode:

  • What’s your best indicator that your security program is actually improving?
  • We examine certifications and separate myth from reality for those trying to get into cybersecurity and also for more seasoned professionals?
  • What security flaw often gets overlooked?
  • How does one go about asking for a team building budget for a remote team?
I Have So Little. Just Let Me Control Access to the Mail Server.14 Jun 202200:40:17

All links and images for this episode can be found on CISO Series

How dangerous is it for a cybersecurity professional to pull a G-d complex with the email server just because they didn't like the way one salesperson behaved?

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Our sponsored guest is Jadee Hanson (@jadeehanson), CIO/CISO, Code42.

Thanks to our podcast sponsor, Code42.

As the Insider Risk Management leader, Code42 helps security professionals protect corporate data and reduce insider risk while fostering an open and collaborative culture for employees. For security practitioners, it means speed to detection and response. For companies, it means a collaborative workforce that is productive and a business that is secure. Visit http://Code42.com/showme to learn more.

In this episode:

  • Is it alright to block a vendor because one salesperson is persistent and annoying?
  • How can one go about creating a cybersecurity report card?
  • Is it just inevitable that your staff is going to eventually violate policies?
  • How to determine a delicate balance between a complete non-tolerance policy versus complete tolerance?
Security as a Profit Center? You’re Kidding, Right?07 Jun 202200:35:11

All links and images for this episode can be found on CISO Series

What if we could convince management that security is not a cost center, but a means to actually make and save money for the business? The concept isn't so completely outrageous. Companies are using privacy and security as differentiators, and certain security tools such as single sign on, password managers, and passwordless reduce operational costs in support tickets.

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our guest is Mary Gardner, CISO, The Greenbrier Companies.

Thanks to our podcast sponsor, Buchanan Technologies

Short staffed and overworked IT groups can be overwhelmed by the massive scope of a comprehensive cybersecurity program. Buchanan Technologies makes the complex simple with our twenty-four by seven, customized, vetted strategies that identify risks, detect threats, implement security controls, and protect the confidentiality, availability, and integrity of your data. Discover more.

In this episode:

What are areas we should focus on improving the security user experience for non-security people?
We ask if CISOs have it easier than their middle managers.
We think about the factors that result in the workload being tougher or easier for a CISO.
And we examine how we can protect our machine learning algorithms and AI from absorbing poisoned data.

Finding That Perfect Time to Quit Your Job31 May 202200:39:59

To see the blog post and read the transcript, head over to CISO Series.

We don't celebrate quitting. Maybe we should. When should you do it when you don't have another offer?

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our guest is Hadas Cassorla, CISO, M1.

On this episode:

  • When a "good" security control is actually bad for business.
  • A "how to" engage with a CISO during a presentation meeting.
  • Losing your passion for cybersecurity. What next?
  • Building a budget for remote team building.

HUGE thanks to our sponsor, Keyavi

Data that protects itself?  Now it does! We made data so smart it can think for itself. Secure itself. Stay continually aware of its surroundings. Control where, when and who is allowed access. And automatically report back to its owner. This changes the entire cybersecurity paradigm. Learn how.

Gartner Creates Another Category for Everyone to Ignore24 May 202200:32:58
All links and images for this episode can be found on CISO Series

I have talked to vendors who get all excited about Gartner opening up a new category for them. All I can think is uggh, something new to confuse the security marketplace. I know there's a need to label products in categories to simplify sales. But the complexity is driving buyers nuts.

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Our sponsored guest is RJ Friedman, CISO, Buchanan Technologies.

Thanks to our podcast sponsor, Buchanan Technologies

Short staffed and overworked IT groups can be overwhelmed by the massive scope of a comprehensive cybersecurity program. Buchanan Technologies makes the complex simple with our twenty-four by seven, customized, vetted strategies that identify risks, detect threats, implement security controls, and protect the confidentiality, availability, and integrity of your data. Discover more.

In this episode: 

  • Do we need another industry-produced acronym?
  • How can a vendor better demonstrate they can become a partner?
  • With the list of security “minimum requirements” constantly growing, do you believe more and more organizations are falling below the security poverty line?
  • And we ask how best to reduce the amount of false positives?
A Look Back at Foolish Security Policies of Past and Present17 May 202200:39:57

All links and images for this episode can be found on CISO Series

Are bad security policies of yesteryear just because we didn't know any better at the time, or were they some bozos idea of legitimate security yet the rest of us knew it was just security theater?

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our guest is Dr. Diane M Janosek (@dm_janosek), deputy director of compliance, NSA and senior legal advisor for Women in Cybersecurity.

Thanks to our podcast sponsor, Code42

As the Insider Risk Management leader, Code42 helps security professionals protect corporate data and reduce insider risk while fostering an open and collaborative culture for employees. For security practitioners, it means speed to detection and response. For companies, it means a collaborative workforce that is productive and a business that is secure. Visit http://Code42.com/showme to learn more.

In this episode:

  • We highlight obsolete security policies to steer clear of.
  • We examine security in space and how can others who are not directly involved in these industries create some type of positive impact?
  • And we ask how we can improve inclusion by decrypting the lack of diversity in our industry.
Decommission Our Legacy Tech or Just Shut Down the Business?10 May 202200:37:18

All links and images for this episode can be found on CISO Series

Legacy tech can often be the anchor that prevents an organization from growing. Put the issue of dealing with legacy tech long enough and the problem could get bigger than the business itself.

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Our guest is TJ Mann (@teejaymann), CISO, Children's Mercy Kansas City.

Thanks to our podcast sponsor, CYREBRO

Ninety percent of post mortems show that the high cost of damage from a cyberattack was avoidable, but no one knew in time to stop it. CYREBRO's SOC Platform is your cybersecurity central command, integrating all your security events with 24/7 strategic monitoring, proactive threat intelligence, and rapid incident response. More from CYREBRO.

In this episode:

  • How legacy technology impedes business agility?
  • Are we doing anything better to deal with legacy technology
  • Is there anything that can be done at the purchase point to understand how you'll sunset equipment and technology
  • And we ask whether or not our industry is willing to take the time and effort to hire and train the talent they so desperately want and need.
Life’s Certainties: Death, Taxes, and Violating Security Policies03 May 202200:33:18

All links and images for this episode can be found on CISO Series

People violate cybersecurity policies at a rate of one out of every 20 job tasks. It's just a matter of time before all your employees are in violation.

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Our guest is Bruce Schneier (@schneierblog), chief of security architecture, Inrupt and fellow and lecturer and Harvard Kennedy School.

Thanks to our podcast sponsor, PlexTrac

PlexTrac is a powerful, yet simple, cybersecurity platform that centralizes all security assessments, pentest reports, audit findings, and vulnerabilities. PlexTrac transforms the risk management lifecycle, allowing security professionals to generate better reports faster, aggregate and visualize analytics, and collaborate on remediation in real-time.

Check out PlexTrac.com/CISOSeries to learn why PlexTrac is the perfect platform for CISOs!

In this episode:

  • Special tips for new CISOs just starting out and trying to establish their position.
  • We examine where there are market forces fighting the most against achieving societal values in the digital space?
  • What are signs that we're moving in the right direction of developing a digital social contract?
  • And we ask, is "employees violating security policies" the top issue that needs to be resolved?
Is It a Promotion or a Red Flag Telling You To Get Out?26 Apr 202200:39:41

All links and images for this episode can be found on CISO Series

A young woman is killing it in her first cybersecurity job out of college. Management is so thrilled with her that they want to give her a promotion. Problem is the promotion reveals a lot of other innerworkings that don't speak well of the company's culture.

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Davi Ottenheimer (@daviottenheimer), vp trust and digital ethics, Inrupt.

Thanks to our podcast sponsor, Code42

As the Insider Risk Management leader, Code42 helps security professionals protect corporate data and reduce insider risk while fostering an open and collaborative culture for employees. For security practitioners, it means speed to detection and response. For companies, it means a collaborative workforce that is productive and a business that is secure. Visit http://Code42.com/showme to learn more.

In this episode:

  • A student has some serious privacy concerns when they learn that "all data is being monitored and anonymously collected."
  • We examine how we can break from the Internet Oligarchs who appear to be consuming, selling, and using so much of our data.
  • How GDPR can benefit organizations to stay ahead of the competition.
  • A young recruit facing imposter syndrome after receiving a promotion with added responsibilities.
It’s a Great Job, But I’m Alone and Terrified19 Apr 202200:36:48

All links and images for this episode can be found on CISO Series

First job out of college and you get the cybersecurity job of your dreams... and nightmares. It's just too much, and you definitely don't have the experience to handle it all.

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our guest is Rick Doten (@rick_doten), CISO, Carolina Complete Health.

Check out Rick's Youtube channel with the CIS Critical Security Control videos.

Thanks to our podcast sponsor, Kenna Security

Kenna Security, now part of Cisco, is the pioneer of risk-based management. The Kenna Security Platform enables organizations to work cross-functionally to determine and remediate cyber risks. It leverages machine learning and data science to track and predict real-world exploitations, empowering security teams to focus on what matters most.

In this episode:

  • We look at the #1 job according to a U.S. News & World Report. Hint: It’s Information Security Analyst.
  • We examine the possibility & practicality of running a security program entirely based upon free and open-source software.
  • We break down how to help brand new recruits on the ground as they start their careers in cybersecurity.
Who You Gonna Call? LEGAL COUNSEL!11 Jun 202400:37:53

All links and images for this episode can be found on CISO Series.

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Joining us is our guest, Ryan Bachman, evp and global CISO, GM Financial.

In this episode:

  • A changing of the executive guard?

  • Playing nice with cyber insurance

  • What does leadership want out of a CISO?

  • Who does a CISO call first?

Thanks to our podcast sponsor, Vanta

Whether you’re starting or scaling your security program, Vanta helps you automate compliance across SOC 2, ISO 27001, and more. Streamline security reviews by automating questionnaires and demonstrating your security posture with a customer-facing Trust Center. Over 7,000 global companies use Vanta to manage risk and prove security.

Instead of Increased Cybersecurity, Could We Just Order Less Risk?12 Apr 202200:35:43
All links and images for this episode can be found on CISO Series

"No business wants more security, they want less risk," said a redditor on the cybersecurity subreddit. Executives seem to not care about cybersecurity because they're not talking in those terms. They talk in terms of managing risk. It's the InfoSec professional's job to do the translation.

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our guest is Tom Doughty, vp and CISO, Prudential Financial.

Thanks to our podcast sponsor, CYREBRO

Ninety percnet of post mortems show that the high cost of damage from a cyberattack was avoidable, but no one knew in time to stop it. CYREBRO's SOC Platform is your cybersecurity central command, integrating all your security events with 24/7 strategic monitoring, proactive threat intelligence, and rapid incident response. More from CYREBRO.

In this episode:

  • How do you discuss cybersecurity with executives who don’t care about cybersecurity?
  • Does cybersecurity insurance help motivate better cybersecurity awareness?
  • Why are we still struggling with cybersecurity hiring?
  • What does a great day in information security look like?
Why CISOs Avoid the Dreaded “Request a Demo” Button05 Apr 202200:39:06

All links and images for this episode can be found on CISO Series

A CISO hears about your company's product from some other CISOs. Eager to find more information like a video demo they could watch on their own, they visit your site. They can't find anything except a prominently placed "Request a Demo" button. Fearing the marketing and salespeople who will hound them if they fill out the information, they just bail.

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Our guest is Jim Routh (@jmrouth1), former CISO for MassMutual and CVS/Aetna.

Thanks to our podcast sponsor, Buchanan Technologies

Short staffed and overworked IT groups can be overwhelmed by the massive scope of a comprehensive cybersecurity program. Buchanan Technologies makes the complex simple with our twenty-four by seven, customized, vetted strategies that identify risks, detect threats, implement security controls, and protect the confidentiality, availability, and integrity of your data. Discover more.

In this episode:

  • Why do vendors put the product demo videos behind gated walls?
  • Tips for improving cybersecurity awareness within a large organization.
  • The annoying pains of the vendor ecosystem.
  • What are some really bad cybersecurity practices that need to be corrected right away?
What’s Next in Cybersecurity? Look at Last Year and Expect More29 Mar 202200:33:18

All links and images for this episode can be found on CISO Series

The web is awash with sites claiming they know what the security trends will be for 2022. All of them were filled with quotes from security experts at different vendors who "surprise" we're saying the big trend is what their product can fix. One publication, eWEEK, had probably the only logical set of trends and they look a lot like what happened in 2021.

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Our sponsored guest is Ori Arbel, CTO, CYREBRO.

Thanks to our podcast sponsor, CYREBRO

Ninety percent of post mortems show that the high cost of damage from a cyberattack was avoidable, but no one knew in time to stop it. CYREBRO's SOC Platform is your cybersecurity central command, integrating all your security events with 24/7 strategic monitoring, proactive threat intelligence, and rapid incident response. More from CYREBRO.

In this episode:

  • How should you be handling your security operations center (SOC)?
  • Tips for improving your incident response planning.
  • What are the cloud security trends of 2022?
Are You Attending the “What to Worry About Next” Security Conference?22 Mar 202200:35:58

All links and images for this episode can be found on CISO Series

Are security conferences really helpful in advising you on making your business more secure, or are they just adding more worries to your plate that aren't actually going to be threats your business is going to have to face?

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Our guest is Jason Witty, CSO, USAA.

Thanks to our podcast sponsor, CyCognito

By understanding risks, attacks, and behaviors from attack surface management data, CyCognito visualizes the pathways attackers will take to exploit your network enabling you the ability to see, understand and eradicate the threat. CyCognito is the only cyber risk intelligence platform that visualizes the attackers paths into your network.

In this episode:

  • What is the board’s risk appetite?
  • Is attending conferences helpful?
  • What can security vendors do to help with board-level communications?
It's BAAAACK! The Return of “We Could Have Stopped That Breach”15 Mar 202200:34:29

All links and images for this episode can be found on CISO Series

Our entire network launched because of the irritation CISOs had with vendors could have stopped some breach that happened to another company. Then the chest pounding subsided, and we thought we were making an impact, until Log4j appeared...

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our guest is Tim Rohrbaugh, CISO, JetBlue.

Thanks to our sponsor, CyCognito

By understanding risks, attacks, and behaviors from attack surface management data, CyCognito visualizes the pathways attackers will take to exploit your network enabling you the ability to see, understand and eradicate the threat. CyCognito is the only cyber risk intelligence platform that visualizes the attackers paths into your network.

In this episode:

  • Questionable vendor marketing tactics
  • Developing your threat intelligence
  • Valuable skills that hiring managers look for
How to Be So Awesome CISOs Can’t Ignore You08 Mar 202200:32:36

All links and images for this episode can be found on CISO Series

The trick to getting the attention of CISOs is to create an awesome company. Focus on that and the attention will follow.

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Our guest is Katie Stebbins (@ktlgs), board president, Global Epic.

Thanks to our podcast sponsor, Kenna Security

Kenna Security, now part of Cisco, is the pioneer of risk-based management. The Kenna Security Platform enables organizations to work cross-functionally to determine and remediate cyber risks. It leverages machine learning and data science to track and predict real-world exploitations, empowering security teams to focus on what matters most.

In this episode:

  • So, how do you become so awesome that you can't be  ignored?
  • What happens when you expand your view of the purpose of security metrics?
  • Is it possible to have a Digital Geneva Convention?
Attract the Best Candidates with Crappy Benefits and Low Pay01 Mar 202200:32:32

All links and images for this episode can be found on CISO Series

If you're up against Google, Facebook, or Apple for hiring talent, chances are pretty good that your company is not going to match their pay and benefits. So if they're the bar for salary and benefits, your business' offerings will inevitably be subpar. So how do you build your employer brand to contend in areas where you're deficient in areas you can't compete?

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our sponsored guest is Dan DeCloss (@wh33lhouse), CEO, PlexTrac.

Thanks to our podcast sponsor, PlexTrac

In this episode:

  • When setting up defenses against MITRE ATT&CK mappings, how much is enough?
  • What are you doing to build your employer brand and attract cyber talent to your business?
  • How should you review your pentest results?
If the Network Is Up, Somebody Is Violating Our Acceptable Use Policy22 Feb 202200:36:01

All links and images for this episode can be found on CISO Series

Every organization has an Acceptable Use Policy (AUP) for their computers and network. Nobody reads it and everybody violates it. How the heck do you enforce or discipline people who violate your company's AUP?

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Our sponsored guest is Matt Radolec, senior director, incident response and cloud operations, Varonis.

Thanks to our podcast sponsor, Varonis

On average, an employee can access 17 million files on day one. Varonis will show you where critical data is vulnerable, detect anomalies, and automatically right-size privileges to get you to “Zero Trust.” Their data security platform can test your ransomware readiness and show you where you stack up. Learn more at www.varonis.com/cisoseries.

In this episode:

  • Why do tabletop exercises fail?
  • How should we deal with AUPs that do not get read?
  • Is cyber resiliency an overused term?
  • How valuable are visual detection techniques?
What We Lack In Security We'll Make Up in School Spirit15 Feb 202200:32:57

All links and images for this episode can be found on CISO Series

Yikes, this security hole one concerned student found in the school's network is going to require one heck of a pep rally to fix.

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Our guest is Dave Stirling, CISO, Zions Bancorporation.

Thanks to our podcast sponsor, Varonis

On average, an employee can access 17 million files on day one. Varonis will show you where critical data is vulnerable, detect anomalies, and automatically right-size privileges to get you to “Zero Trust.” Their data security platform can test your ransomware readiness and show you where you stack up. Learn more at www.varonis.com/cisoseries.

In this episode:

  • Should the CISO position be seen as an organization in itself?
  • Is the current data loss prevention (DLP) model outdated?
  • How can an MSSP show its value?
  • What should a high school student do if they see that their school has horrible security practices?
What's the Least Annoying Way to Follow Up with a CISO?08 Feb 202200:34:13

All links and images for this episode can be found on CISO Series

If we had such a great conversation at the conference, why don't you want to respond to my emails?

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our guest is Julie Tsai (@446688), cybersecurity leader.

Thanks to our podcast sponsor, Varonis

What is your ransomware blast radius? The average user can access 17 million files. Varonis reduces your blast radius in days, not years. Combined with advanced detection that monitors every file touch, ransomware doesn’t stand a chance. Get a free risk assessment.

In this episode:

  • Is there a "right" management structure for cybersecurity?
  • Are there tools you can put in place to keep your DevOps program in check?
  • What are the questions to ask during an interview that reveal how a company handles and prioritizes cybersecurity?
  • How can we improve CISO / vendor relations?
I’m Rewarding Your Successful Use of the Security Budget by Giving You Less of It04 Jun 202400:37:25

All links and images for this episode can be found on CISO Series.

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Joining me is my guest, Aamir Niazi, executive director and CISO, SMBC Capital Markets.

In this episode:

  • Communicating security accomplishments

  • Spotting red flags in an interview

  • What does offensive security look like today?

  • Where Gen AI is fitting into cybersecurity

Thanks to our podcast sponsor, Cyera

Cyera’s AI-powered data security platform gives companies visibility over their sensitive data, context over the risk it represents, and actionable, prioritized remediation guidance.
 As a cloud-native, agentless platform, Cyera provides holistic data security coverage across SaaS, PaaS, IaaS and On-premise environments. Visit www.cyera.io to learn more.

Why Ignoring Most of Your Vulnerabilities Is the Best Strategy01 Feb 202200:34:16

All links and images for this episode can be found on CISO Series

Winning at vulnerability management is not a numbers game. It's a tactical exercise of what matters most in your environment. Surprisingly, experts tell us close to two thirds of your vulnerabilities can and should be ignored. Why and which ones are those?

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Our sponsored guest is Ed Bellis (@ebellis), co-founder and CTO, Kenna Security (now a part of Cisco).

Thanks to our podcast sponsor, Kenna Security

Kenna Security, now part of Cisco, is the pioneer of risk-based management. The Kenna Security Platform enables organizations to work cross-functionally to determine and remediate cyber risks. It leverages machine learning and data science to track and predict real-world exploitations, empowering security teams to focus on what matters most.

 In this episode:

  • What type of risk or compliance data should CISA collect for its proposed metrics?
  • Which metrics are most valuable to determine the health of a company?
  • Why the constant frustration with patch management?
  • How often should you be conducting vulnerability scans?
Why We Quickly Reject 95% of All Applicants25 Jan 202200:36:51

 All links and images for this episode can be found on CISO Series

If you're asking what certification you should go after to get the perfect cybersecurity job, you're asking the wrong question. Most hiring managers are inundated with resumes so they're looking for ways to get rid of yours. Don't be fooled thinking you're going to be seen because you have the "perfect" resume.

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our guest is Mike Hanley (@_mp4h), CSO, GitHub.

Thanks to our podcast sponsor, BitSight

These are challenging times for security professionals. From managing third party supply chain risk, to quantifying financial exposure, to reducing the likelihood of ransomware, BitSight helps security and risk professionals create more effective cybersecurity programs with cybersecurity ratings and analytics. Learn why Moody’s, the Department of Defense, and other leading institutions partner with BitSight at www.bitsight.com

In this episode:

  • What's the formula (experience vs testimonials) for hiring managers' attention?
  • What are the most effective techniques to building a resilient security team?
  • What are security vendors NOT doing now that would greatly improve their visibility?
  • Have you had to make any security exceptions just because an executive needed something?
Security So Good Your Users Won't Use It18 Jan 202200:35:35

All links and images for this episode can be found on CISO Series

CISOs agree that multi-factor authentication is the one security control that once deployed has the greatest impact to reduce security issues. Yet with all that agreement, it’s still so darn hard to get users to actually use it.

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our guest is Arvind Raman (@arvind78), CISO, Mitel.

Huge thanks to our sponsor, Horizon3.ai

See your enterprise through the eyes of the attacker, identify your ineffective security controls, and ensure your limited resources are spent fixing problems that can actually be exploited. More from Horizon3.ai.

In this episode:

  • If MFA is so great, why is it not more widespread?
  • Are high valuations for cloud security startups a vote against cloud providers doing cloud security well?
  • What is the biggest challenge in deploying zero trust on existing infrastructure?
  • Are there universal security red flags?
We've Never Taken On So Much Risk11 Jan 202200:35:24

All links and images for this episode can be found on CISO Series

It's all risk, all show, for the entire show. It's just the kind of risk we like to take.

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our sponsored guest is Derek Vadala (@derekvadala), chief risk officer, BitSight.

Thanks to our podcast sponsor, BitSight

These are challenging times for security professionals. From managing third party supply chain risk, to quantifying financial exposure, to reducing the likelihood of ransomware, BitSight helps security and risk professionals create more effective cybersecurity programs with cybersecurity ratings and analytics. Learn why Moody’s, the Department of Defense, and other leading institutions partner with BitSight at www.bitsight.com

In this episode:

  • What cybersecurity risk is currently the most severe?
  • What's important about of evaluating a startup's security protocols?
  • What about third party risk management?
  • Do you and your board know how resilient you are to a cyber attack?
The Perfect Gift for a Cyber Crook04 Jan 202200:33:15

All links and images for this episode can be found on CISO Series

What do you give to the person who wants to learn how to steal everything?

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Our sponsored guest Jim Wachhaus (@imanapt), risk intelligence evangelist, CyCognito.

Thanks to our podcast sponsor, CyCognito

By understanding risks, attacks, and behaviors from attack surface management data, CyCognito visualizes the pathways attackers will take to exploit your network enabling you the ability to see, understand and eradicate the threat. CyCognito is the only cyber risk intelligence platform that visualizes the attackers paths into your network.

In this episode:

  • How can we shore up our cybersecurity hygiene?
  • What have we heard enough about with risk intelligence ?
  • Gifts to buy someone who is looking into red teaming/vulnerability

 

"I Love Being Monitored Online," Said No Employee Ever21 Dec 202100:34:58

All links and images for this episode can be found on CISO Series

What do you do if your boss gave you a corporate laptop and you fear they installed some tracking software? Should you wipe the drive or simply quit?

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our sponsored guest is Purandar Das (@dasgp), co-founder and president, Sotero.

Thanks to our podcast sponsor, Sotero

Today’s compliance requirements require a security mindset that focuses on the data itself. We can’t truly protect sensitive data when our solutions only provide protection at the network, application or database level. The good news is that you can now protect the actual data itself. Click to learn how.

In this episode:

  • Did the pandemic lead to innovations in cybersecurity?
  • What should a company do when an employee makes a major mistake like emailing PII?
  • Have we all heard enough about encryption?
  • What do we do when the boss gives us a "new" computer with monitoring tech on board?
If We Don't Talk About Cyber Risk, Will It Go Away?14 Dec 202100:35:53

All links and images for this episode can be found on CISO Series

Risk is scary. Cyber risk is scarier. Not because it's worse, but mostly because we barely understand it. We've gone this long not understanding it. Maybe just ignoring it will allow us to wish it away.

On this week's episode of CISO/Security Vendor Relationship Podcast we have our first in-studio guest (since we moved the studio). Joining me, David Spark (@dspark), producer of CISO Series and Mike Johnson is our in-studio guest TJ Lingenfelter (@tj_555), sr. program manager, information security, Taylormade Golf.

Thanks to our podcast sponsor, BitSight

These are challenging times for security professionals. From managing third party supply chain risk, to quantifying financial exposure, to reducing the likelihood of ransomware, BitSight helps security and risk professionals create more effective cybersecurity programs with cybersecurity ratings and analytics. Learn why Moody’s, the Department of Defense, and other leading institutions partner with BitSight at www.bitsight.com

In this episode:

  • How can competitive companies can help each other be more secure?
  • What to do when you can't get time with your CIO to discuss plans?
  • Are we fooling ourselves to think we can maintain privacy for ourselves and that organizations can do it for us as well?
  • What new cybersecurity buzzwords should be put to rest?

 

After a Breach It's Really Easy to Calculate Risk07 Dec 202100:36:56

All links and images for this episode can be found on CISO Series

There's no question calculating risk is tricky. Because once you understand your risk then you can assign budget appropriately to reduce your risk. OR, you could just wait until you're breached and you'll know exactly what your risk is and how much it costs.

This week's episode of CISO/Security Vendor Relationship Podcast is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our guest is Dan Walsh, CISO, VillageMD.

Thanks to our podcast sponsor, deepwatch

Increasing ransomware attacks and their evolving sophistication have been putting more pressure on security teams than ever before. Luckily, managed detection and response (or MDR) has emerged as a critical component for improving security operations, reducing ransomware risk, and minimizing the overall impact an attack can have. Visit deepwatch.com to see how we help to prevent breaches for our customers, by working together.

In this episode:

  • What can we learn from a 10-year cybersecurity veteran?
  • What can state governments do to 'hire better' in cybersecurity?
  • What can companies do to attract cybersecurity professionals to their location?
  • What are ways to bring a clearer understanding of risk to the business without being alarmist?

 

 

I’ve Got Zero Trust In My Understanding of Zero Trust30 Nov 202100:46:08

All links and images for this episode can be found on CISO Series

Don't look at me to explain zero trust to you, because I'm just as confused. I've heard plenty of definitions, and they all sound good. I just don't know which one is right, or maybe they're all right.

This week's episode of CISO/Security Vendor Relationship Podcast was recorded in front of a live audience at KeyConf at the City Winery in New York City. My guest co-host for this special episode is JJ Agha, CISO, Compass. Joining us on stage were a host of guests, Admiral Rogers, former NSA director and Commander US Cyber Command, Oded Hareven, CEO and co-founder, Akeyless, and Dr. Zero Trust, Chase Cunningham (@cynjaChaseC).

Thanks to our podcast sponsor, Akeyless

As organizations embrace automation, they must control their secrets sprawl. Security teams must enable the transition with centralized access to secrets, and consistent policies to limit risk and maintain compliance. Akeyless provides a unified, SaaS based solution for Secrets Management, Secure Remote Access, and Data Protection. More about Akeyless

In this episode:

  • Is zero trust easy for organizations to deploy and control?
  • Are we taking zero trust too far?
  • Does it help to have more eyes on the problem?
  • What are the problems with secure remote access that we're still struggling with?
We’re Very Good at SAYING We Care About Diversity23 Nov 202100:38:48

All links and images for this episode can be found on CISO Series

It's extremely easy to say you want to diversify. In fact, I'll do it right now three times. We want diversity. We're very pro diversity and it's our focus for the next year. Diversity is a very important part of our security program.

Please don't ask to though look at the lack of diversity on our staff. It doesn't match our rhetoric.

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Our guest is Sujeet Bambawale (@sujeet), CISO, 7-11.

Thanks to our podcast sponsor, Vulcan Cyber

Vulnerability scanners are commoditized. Cloud service providers provide free scanners. Open source scanners are plentiful. Your team doesn’t need another scanner, but they need to get better at identifying and prioritizing the risk that is buried in that scan data. Attend the Vulcan Cyber virtual user conference and learn how to assess and mitigate risk across all of your surfaces. Go to vulcan.io and click the button at the top of the screen to register for the event.

In this episode:

  • How are you overcoming the challenges of diversity hiring?
  • Are robocalls defeating MFA?
  • Are you collaborative in cyber with your direct competitors?
  • Were you sold something differently when you started in cyber?

 

 

Ransomware? Why’d It Have to Be Ransomware? (Live in San Francisco)28 May 202400:44:03

All links and images for this episode can be found on CISO Series.

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson, CISO, Rivian. Joining us is Steve Zalewski, co-host, Defense in Depth. Recorded live at BSidesSF.

In this episode:

  • Are companies taking the air out of the open source balloon?

  • What’s broken about cybersecurity hiring?

  • Do we need minimum requirements for cybersecurity knowledge in sales?

Thanks to our podcast sponsors, Devo, Eclypsium & NetSPI

Devo replaces traditional SIEMs with a real-time security data platform.

Devo’s integrated platform serves as the foundation of your security operations and includes data-powered SIEM, SOAR, and UEBA. AI and intelligent automation help your SOC work faster and smarter so you can make the right decisions in real-time.

Eclypsium is helping enterprises and government agencies mitigate risks to their infrastructure from complex technology supply chains. Our cloud-based and on-premises platform provides digital supply chain security for software, firmware and hardware in enterprise infrastructure. Get started today at eclypsium.com/spark.

NetSPI ASM continuously scans your external perimeter to identify, inventory, and reduce risk to both known and unknown assets. It blends scanning methodology with our consultants' human intelligence to identify previously undiscovered data sources and vulnerabilities so you can remediate what matters most.

Chances Are We'll Be Attacked the Day Before Your Vacation16 Nov 202100:37:15

All links and images for this episode can be found on CISO Series

Do the cybercriminals know my vacation schedule? If they’re already in our network, they probably do. Why don’t they share their vacation schedule with me. That way we can all enjoy our time off.

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our guest is Patti Titus (@rusecur), CISO, Markel.

Thanks to our podcast sponsor, Sotero

Today’s compliance requirements require a security mindset that focuses on the data itself. We can’t truly protect sensitive data when our solutions only provide protection at the network, application or database level. The good news is that you can now protect the actual data itself. Click to learn how.

In this episode:

  • What role is the quickest to a CISO role?
  • How can we best correlate security behavior to business actions?
  • Are attacks more likely on Fridays, just before a long weekend or vacation?
  • Which breaches this year caused a shift in focus of your security program?

 

 

Did You Get My Last Email? This One Has a Joke In It.09 Nov 202100:50:07

All links and images for this episode can be found on CISO Series

At one point a sales representative will get so desperate trying to get a reply from a prospect that they'll resort to some tepid attempt a humor. We've all seen the email that is trying to understand why we're not replying. And the salesperson tries to make it easy for the recipient to respond by just pressing a single digit. 1: You're too busy, 2: You didn't see my email, 3: You really wanted to respond but you're stuck in a well.

This week's episode of CISO/Security Vendor Relationship Podcast was recorded in front of a live audience at the SF-ISACA conference in San Francisco. It features me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our guest is my other co-host Andy Ellis (@csoandy), operating partner, YL Ventures.

Huge thanks to our podcast sponsors, Code42, Sotero, and Constella Intelligence

As organizations gradually and cautiously move out of adapt-or-die mode into the post-pandemic era, we can expect a second phase of digital transformation: resilience building. This presents an opportunity for security teams. An opportunity to re-imagine data security. More from Code42.

Today’s compliance requirements require a security mindset that focuses on the data itself. We can’t truly protect sensitive data when our solutions only provide protection at the network, application or database level. The good news is that you can now protect the actual data itself. Click to learn how.

Threat actors target key employees due to their privileged access to sensitive data which can lead to credential theft, ATO, & ransomware attacks. Find out if your key employees and company have been exposed – without any obligation. More from Constella Intelligence.

In this episode:

  • How do you go about making a business case for further investment in cyber security initiatives?
  • Is it possible to get people to get security people change their behaviors?
  • Using humor in cold sales. Does it ever work?
  • ...and what happens when it backfires?

 

Hackers of the World Unite… When We Can Agree on a Time02 Nov 202100:37:56

All links and images for this episode can be found on CISO Series

"Look, you wanna be elite? You have to do a righteous hack."

This entire episode we pay tribute to the movie "Hackers" with quotes all throughout the programming. This episode is hosted by me, David Spark (@dspark), producer of CISO Series, and my guest co-host Roland Cloutier (@CSORoland), CISO, TikTok. Joining us in this discussion is Steve Tran (@steveishacking), CISO, MGM Studios.

Thanks to our podcast sponsor, Code42

In this episode:

  • Is it time to start thinking about protecting data differently?
  • What is the biggest scam in tech that is deemed acceptable?
  • Why is the convergence of security between physical and digital still not happening?
  • Which part of your role is science vs art?
© My Podcast Data