Explore every episode of the podcast Caffeinated Risk
| Title | Pub. Date | Duration | |
|---|---|---|---|
| Deviance Normalization & Risk Management with Marco Ayala | 24 Oct 2024 | 00:34:05 | |
Technological change is inevitable and often one of the aspects that attracts people toward careers in information and operational technology. Although risk management is a part of navigating advancement in any area, the fundamental flaw in any management system is our human tendencies. | |||
| Managing Supply Chain Risk Management - with Darren Gallop | 26 Sep 2024 | 00:32:34 | |
Whether it's the NIST CSF, 8276 or the new European Cyber Resilience Act there is no denying the expectation that supply chain management (SCM) is a risk management area no organization can ignore. While SolarWinds is recent common reference in many SCM discussions, this episode's guest takes us back to Target's major data breach that resulted in significant changes to the PCI-DSS standard. | |||
| ESRM a Decade In and The Emergent Threat Landscape | 28 Sep 2023 | 00:29:52 | |
Post GSX conference, which included an in-depth review of ESRM and an interview with former U.S. president George W Bush, this episode considers how enterprise security risk management has stood the test of time as well as how risk analysis will need to evolve . | |||
| Business Enablement using Converged Risk Management with Michael Lashlee | 24 Aug 2023 | 00:36:20 | |
The convergence buzzword has come and gone and some organizations have struggled to reap the benefits of physical and cyber security departments working in tandem toward common goals. Michael Lashlee, deputy Chief Security Officer at Mastercard, shares security insights from the US Marines, secret service and financial services tech giant Mastercard, illustrating how principles from very different missions overlap surprisingly often. Mr. Lashlee also discusses how technology supports the physical, intelligence and fraud specialists working to keep Mastercard customers client data safe as well as steps they are taking to resolve the cyber skills talent shortage. | |||
| Interpreting Risk within a Regulatory Context with Terry Freestone | 27 Jul 2023 | 00:32:28 | |
Calgary was an ICS cyber hub before most knew such measures were necessary, Terry Freestone was one of the ICT specialists from those early days who now applies his decades of hard-won knowledge in the offices of the Canadian Energy Regulator. | |||
| 2023 Summer Show | 29 Jun 2023 | 00:30:56 | |
Keeping up the accidental annual tradition Tim and Doug take a retrospective look at risk management as a mid-year pulse. The 10th annual Cyberthreat Defense report forms the underlying theme but digging under the statistics to analyze how these might pertain to ESRM. Communication also popped up as a topic, and Tim shares some lessons learned from the field as well as a professional development resource. | |||
| ESRM and Data Science with Rachelle Loyear | 25 May 2023 | 00:31:28 | |
One of the original authors of the ESRM framework, now in it's tenth year, and Caffeinated Risk's first guest returns to discuss how data science is changing security and risk management. While alchemy may be a bit of a stretch, Ms. Loyear ongoing focus of including human behaviour in the risk equation is leading to the development of data science based detection capabilities that would have appeared magical even 5-10 years ago. | |||
| Attack Tree Calibration with Terry Ingoldsby | 23 Mar 2023 | 00:07:30 | |
Threat modeling expert and inventor of one of the world's first attack tree modeling products talks about how to integrate subject matter expertise into the risk equation, the answer may be surprising. | |||
| FAIR and ESRM, exploring common ground with Jack Freund | 23 Feb 2023 | 00:38:12 | |
Factor Analysis of Information Risk (FAIR) and Enterprise Security Risk Management (ESRM) took different evolutionary paths yet share a lot more commonality than catchy 4 letter acronyms and mainstream adoption by notable organizations like NIST, The Open Group and ASIS international. Jack Freund personifies the term "risk management thought leader" with professional qualifications and public recognitions too long to list, but co-author of Measuring and Managing Information Risk can't go unmentioned since industry peers inducted this seminal title into the Cybersecurity Cannon. | |||
| Cyber-Physical Convergence Revisited | 19 Jan 2023 | 00:34:40 | |
In addition to hybrid work and regular time in the office being the new normal, 2023 marks the year Caffeinated Risk's co-host Tim McCreight serves as the president of ASIS international. ASIS has long been a proponent of both physical and cyber security professionalism and one of the first organizations to explore and embrace Enterprise Security Risk Management (ESRM) as an integral element of security. | |||
| ESRM Enablement via Location Intelligence with Alex Martonik | 15 Dec 2022 | 00:31:55 | |
Realtors have long advocated "location, location, location" as a path to investment success. Fast forwarding a few generations, location intelligence applied to risk management is paying dividends well beyond real-estate and Esri is a world leader in this fascinating application of geo-spatial information. Esri business solutions leader Alex Martonik shares examples of businesses making improvements to resilience and the bottom line by combining GIS, financial, technological and political data into risk calculations. Mr. Martonik also shares Esri's approach to "democratizing risk insights", helping solve the all to common problem of procuring buy-in. | |||
| Privacy & Toxic Data with Michelle Finneran Dennedy | 17 Nov 2022 | 00:06:00 | |
A great discussion point that didn't make it to air from the original 2021. Not all data is of equal value to the organization and the viable shelf life is seldom tracked or even discussed. | |||
| Metawar and Fostering Resilience with Winn Schwartau | 29 Aug 2024 | 00:34:51 | |
Long before the Matrix captured peoples imaginations, Winn Schwartau was steadily offering red pills for those reading his many books on information warfare. A scholastic level researcher without the pretense, Mr. Schwartau has been recognized internationally as one of the leading security thinkers of our time and has a special capability for distilling complex security concepts into every day language and metaphor. | |||
| Classifying and effectively communicating enterprise security risk with Paul Mercer | 20 Oct 2022 | 00:31:15 | |
Communication isn't effective until the receiver understands the message well enough to take action. That pretty much sums up the challenge facing many risk professionals today, something Paul Mercer resolved, out of necessity, by building risk management software that is proving to be a welcome solution for many notable customers. | |||
| Redefining the risk management business partnership with Rachelle Loyear | 08 Sep 2022 | 00:06:50 | |
Co-author of the original book on Enterprise Security Risk Management, it only made sense to have Rachelle be the first Caffeinated Risk guest. Like many guests, there was just too much material for a 30 minute episode. This espresso shot encore digs into that nuanced topic of truly partnering with business stakeholders. | |||
| Resilience as a Risk Management Strategy | 18 Aug 2022 | 00:32:57 | |
Anyone with a bit of time in the security industry is well acquainted with Murphy's law but crisis management specialists are who you call when things suddenly get very real. While common security guidance advocates protection, readying your organization to weather the inevitable failure in prevention measures starts with resilience. | |||
| Infrastructure Resilience and Ethical Considerations | 21 Jul 2022 | 00:31:48 | |
Recorded two days after the July 2022 nationwide telecom outage, co-hosts Tim and Doug explore the deeper ramifications of losing access to the very services that are so tightly integrated into our lifestyle. While the complete root cause of the Rogers' outage may never be publicly shared, most organizations face similar constraints, leading to a discussion about ethics and our shared commitment to the common good. | |||
| GRC Program Development and Implementation with Josh Sokol | 16 Jun 2022 | 00:31:10 | |
Sooner or later every risk management professional faces the hard reality that comprehensive risk management programs can't be implemented on spreadsheets. A corporate vice president mandate, minus the funding, started Josh Sokol on a journey that turned his initial platform solution into an opensource project that morphed into a commercial venture. | |||
| Strategies for meeting the cyber skill set challenge with Martin Dinel | 19 May 2022 | 00:32:26 | |
Chief Information Security Officer Martin Dinel has all the same technology challenges of every other large organization. Placing Alberta in front of that CISO title brings the additional requirements of protecting government secrets, interfacing with national security, protecting financial and health information of more than 4 million people as well as the infrastructure of a province almost the size of Texas. | |||
| Risk management in the cloud with Illena Armstrong | 21 Apr 2022 | 00:32:32 | |
Very few organizations, from three letter agencies to the local brew pub are not using cloud services to some degree and those previously resistant had no choice once Covid 19 hit. In 2022, with global conflict, organized crime, multiple supply chain and service concerns, what is required of a security professional responsible for navigating risk for their enterprise which invariably includes "Cloud"? | |||
| Cyber Crime and Risk Management Strategies with Cara Wolf | 17 Mar 2022 | 00:32:31 | |
Acknowledged by IT World Canada as one of the top 20 women in cyber, Cara Wolf shares insights into the Canadian tech industry , the need for innovation and tactics for drawing senior leadership's attention to cyber security issues during a candid discussion on the changing aspects of cyber crime . Long before cyber crime was a mainstream concept Ms. Wolf was a seasoned fraud investigator with American Express travel, setting the stage for a number of entrepreneurial ventures combining technology and risk management. Cara Wolf's latest company, Ammolite Analytx specializes in complex information security problems and threat centric solutions, whether those threats are physical, cyber or a hybrid. | |||
| Continuous Authentication and Risk Management with Ian Paterson | 16 Feb 2022 | 00:32:34 | |
The threat landscape is evolving, if your security controls are not, the outcome is all but assured. | |||
| Castles and Network Management with Winn Schwartau | 03 Feb 2022 | 00:05:33 | |
A light hearted espresso shot with renowned information security writer Winn Schwartau and Tim McCreight discussing the serious and all too common problem of uncontrolled ingress and egress. | |||
| Resilience and I.R. Lessons Learned (the hard way) - with Adam McMath | 11 Jul 2024 | 00:34:31 | |
Almost all incident response plans include a "lessons learned" step, and in the post adrenalin phase that follows many breaches, reviewing what worked and what needs improving doesn't excite a lot of people. Adam McMath is clearly the exception, leading incident response activities in both the cyber realm and physical. How do resilience and incident response lessons learned while literally fighting fires translate into risk management practices within cyber security, is a good question explored in depth with this month's guest. | |||
| Unpacking the Security Value Chain - Dave Tyson | 20 Jan 2022 | 00:07:21 | |
An espresso shot covering a great idea Dave Tyson originally shared in his book and discussed during our 2021 interview on identifying where security can contribute to the business value chain and some strategies for selling the benefits. | |||
| Innovation and Influence | 16 Dec 2021 | 00:34:09 | |
The year end episode does some comparing and contrasting of risk management in different areas, including things outside of cyber. Ironically, recorded just a couple days before most of the world learned about a module design choice in Java that suddenly makes logging dangerous, it brings home the point that our cyber threat landscape is complex . | |||
| Applying Scientific Principles to Risk Management - With Doug Millward | 18 Nov 2021 | 00:33:12 | |
While many in risk management or cyber security reference standards and leading practices, it can often be based on tacit acceptance, rather than deep research. There is an argument that that research is too slow compared to commercial solutions, especially considering our current threat landscape and resource constraints. | |||
| Risk and Kinetic Consequences - with Paul Smith | 21 Oct 2021 | 00:31:08 | |
Skilled penetration testers are some of the more specialized people within the information security industry. When it comes to safely testing kinetic systems the pool of talented ethical hackers shrinks again but does include Paul Smith who has written a brand new book on the subject. | |||
| Privacy Engineering, Manifesto & Beyond with Michelle Finneran Dennedy | 16 Sep 2021 | 00:31:10 | |
Formerly vice president and chief privacy office at Cisco, CEO of Drumwave and a licensed attorney, Michelle Finneran Dennedy is recognized as a visionary leader in information systems privacy. Currently the co-founder of Privatus Consulting supporting clients working through the wicked problem of privacy in this digital age. | |||
| Following the Money in Cybersecurity with Larry Whiteside Jr. | 19 Aug 2021 | 00:35:46 | |
A business without cash flow isn't a business for long and security solutions are seldom free yet cyber security is a line item that business owners ignore at their peril. Cost management and risk management come together in this lively podcast with special guest Larry Whiteside Jr. a former US Air Force division chief who has held a number of senior cyber security executive positions since returning to civilian life in 2002. | |||
| Back to work, just in time for summer | 22 Jul 2021 | 00:28:01 | |
Cohosts Tim and Doug explore the security implications of workers returning to the corporate networks after over a year working remotely. | |||
| A Business First Security Focus with Dave Tyson | 16 Jun 2021 | 00:30:04 | |
Dave Tyson literally wrote the book on Managing Enterprise Security Risk through converged security while serving as the CSO for the City of Vancouver during the winter Olympic games. A practitioner rather than a theorist, Tyson has held senior security leadership positions at multiple major organizations including eBay, Pacific Gas and Electric and SC Johnson. | |||
| Security risk analysis using attack trees with Terry Ingoldsby | 19 May 2021 | 00:34:42 | |
"We need more science in Cyber Security" David Hechler, TAG Cyber Law Journal | |||
| Transitions and transformation within the security industry with Scott Klososky | 14 Apr 2021 | 00:34:41 | |
Serial entrepreneur, author and futurist Scott Klososky explores some new approaches to physical and cyber security that are innovative, potentially controversial and necessary as more and more of our daily way of life is affected by these security problems. | |||
| ESRM a Transformation Catalyst with Radek Havlis | 30 May 2024 | 00:29:47 | |
Amongst the industry verticals classified as critical infrastructure, few would argue that telecommunications belongs in the top that list, placing even more weight on a risk management program due to cascading impacts. Consequently, safe reliable operations are essential for success while continuing to grow in a highly competitive marketplace. A security risk management challenge across many dimensions that has become an ESRM success story. | |||
| Security through management of time and trust with Winn Schwartau | 18 Mar 2021 | 00:30:42 | |
A security luminary before such a title was even coined, Winn Schwartau's predictions about the internet and global security problems have been scarily spot on for more than 30 years. Named the “Civilian Architect of Information Warfare” by Admiral Patrick Tyrrell of the British Ministry of Defense, Schwartau also testified before Congress in 1991 and showed the world how and why massive identify theft, cyber-espionage, nation-state hacking and cyber-terrorism would be an integral part of our future. | |||
| Rethinking Security Control Design with Rachelle Loyear | 17 Feb 2021 | 00:30:11 | |
Co-author of Enterprise Security Risk Management: Concepts and Applications , Rachelle Loyear has spent her career managing programs in corporate security organizations. Focusing strongly on security risk management, she has been responsible for ensuring enterprise resilience in the face of many different types of risks, both physical and cyber. | |||
| Preview Trailer: ESRM & Critical Infrastructure | 17 Jan 2021 | 00:06:05 | |
The first full episode is scheduled for release February 18th. The trailer includes a few conversation segments between the cohosts on enterprise security risk management and critical infrastructure. Visit CaffeinatedRisk.com for more articles on the intersection of risk management and technology. | |||
| Contingency Planning, Cyber Resilience and Incident Response | 28 Mar 2024 | 00:28:33 | |
Regulatory frameworks from PCI-DSS to NERC-CIP to the newly minted NIST CSF 2.0 each require organizations of all sizes to have cyber incident response plans. Most of us who have spent any time in cubicle filled office towers are familiar with fire drills to clear the building and gather staff at muster points, and that is as close as we get to the real thing. Unfortunately that same lucky streak will Unlike a fire drill, recent research estimates 85% of businesses will expereince a cyber incident annually, and many will find short-comings in their incident response plan. | |||
| The Business Context of Cyber Resilience with Steven J Ross | 22 Feb 2024 | 00:30:51 | |
Those running a business today who have not experienced disruption due to cyber issues or attacks know it is only a matter of time. Even if their organization is not directly targeted, the modern marketplace comprised of multiple, interconnected supply chains, means impact is unavoidable but this episode's guest, Steven J Ross contends planning, design and clear priorities can provide mitigating resilience. | |||
| Building a Cyber Risk Management Program with Brian Allen | 25 Jan 2024 | 00:30:03 | |
The U.S. Security Exchange Commission defined new rules for cyber risk matters facing publicly traded corporations in July of 2023. Although the SEC's mandate is limited to publicly traded companies in the United States, where one regulator goes others are apt to follow. Brian Allen is the co-author of a brand new book putting form, structure and traceability around the SEC mandated requirement for a Cyber Risk Management Program. Mr. Allen was on of the original creators and advocates of the ESRM framework first published in 2013, and has been practicing security risk management throughout his career. | |||
| CyberPHA - OT Risk management With John Cusimano | 14 Dec 2023 | 00:31:59 | |
The ISA 99 standards body is one of the most recognized authorities on cyber physical security covering many aspects of a cyber security management system for industrial control systems including risk management. This episode features John Cusimano, former chairman of the ISA subcommittee responsible for authoring the risk management portion of the standard 62443-3-2:2020 Mr. Cusimano takes us back to the origins of the OT specific risk assessment process, originally dubbed CyberPHA, we also explore how the methodology can be managed and percieved at different levels of the organization as well as how this approach can safely carry organizations into a future that includes cloud computing. | |||
| Science, Crime and Workforce Development with Dr. Martin Gill | 23 Nov 2023 | 00:31:52 | |
Security and crime are often in close proximity but not always studied together. This month's episode features Martin Gill a criminologist who made the study of crime and security his life's work. After a decade as a lecturing professor at the University of Leichester, Mr. Gill started Perpetuity Research in 2002 and continues to provide very high quality research, both qualitiative and quantitiative, on what works -- and more importantly what does not -- on many different areas of the security field. | |||
| Engineering, Risk Management for Cyber-Physical Systems with Andrew Ginter | 30 Nov 2024 | 00:29:25 | |
The practice of engineering dates back thousands of years, incorporating science and mathematics to solve problems in the ancient world, and remains a key requirement for developing the complex digital systems controlling the physical systems core to our modern way of life. Unfortunately connectivity and complexity have created a vulnerability we must now engineer our way out of, and just like risk management, engineering is about balancing constraints. | |||
| Security Risk Management in an Open Data Environment with Michael Spaling | 09 Jan 2025 | 00:36:26 | |
Ever wondered how top universities protect their cutting-edge research from prying eyes while ensuring seamless access for their scholars? Join us as Michael Spaling, Principal Security Architect at the University of Alberta, takes us behind the scenes of this high-stakes balancing act. Just like any other large organization, research universities have many different stakeholder, operational and regulatory requirements, thousands of employees and tens of thousands of customers. | |||
| Global Risk Management as Strategic Advantage with Dominic Bowen | 19 Jun 2025 | 00:35:50 | |
The Caffeinated Risk hosts navigate time zones and catch up with Dominic Bowen traveling between meetings to discuss risk management with an international expert on the subject. Mr. Bowen is a partner and Head of Strategic Advisory at 2Secure, one of Europe's leading risk management consulting firms, as well as the host of the International Risk Podcast. Political tensions are higher than they have been for years and there is seldom a month that goes by without a technical disruption that affects numerous businesses and services due to the interconnected nature of our modern world. Despite the serious topics covered, Dominic Bowen offers some practical solutions based on experience in the business world , the higher stakes of military service and humanitarian relief offering an unexpected, potentially positive outcome. I.E., accepting the tempo of constant crisis and becoming and effective manager of those risks can actually accelerate success. | |||
| Simplifying risk analysis using FAIR and Wiley Coyote with Jack Freund | 24 Apr 2025 | 00:08:35 | |
A while back we were fortunate enough to spend time with Jack Freund, coauthor and thought leader responsible for bring the FAIR methodology and practice into the main stream. A bonus from that original recording is now an espresso shot discussing how to fast track an assessment when the threat vectors are numerous. While the metaphor Jack used is somewhat unexpected it's both memorable and an excellent approach to dealing with an entire class of attacks in a single assessment. A pro tip from one of the original practitioners of the FAIR methodology well worth a listen. | |||
| SMB Resilience and lessons for larger organizations with Rochelle Clarke | 27 Mar 2025 | 00:30:44 | |
At 45-50%, depending on your statistical source, there is no denying that small to medium sized businesses are a significant economic engine from both an employment and innovation perspective. In 1978 Microsoft numbered 11 people. Unfortunately small businesses are also the least likely to survive a major disruption, an experience that changed Rochelle Clarke's corporate leadership trajectory to a business founder. The Continuity Strength founder shares insights on the needs of small to medium businesses and how to develop resilience plans while simultaneously addressing the two biggest concerns of most SMB owners, time and money. Prior to founding Continuity Strength, Ms. Clarke was the Country Manager, Global Strategy for Heineken, a management consultant and is on multiple board and academic committees. | |||
| Addressing Risk and Cyber Resilience, the Alberta Approach - with Rachel Hayward | 20 Feb 2025 | 00:36:13 | |
A surprising number of digital innovations began in Alberta, be it the world's first public digital cellular network in 1985, the DNP3 industrial controls protocol and becoming the first Google international research lab in 2017. CyberAlberta is another innovative collaboration focused on strengthening the cyber resilience of Alberta organizations. At almost 330 billion annually, protecting the Alberta economy and it's citizens from digital attacks is an important mission. In a very candid conversation, Rachel Hayward, Executive Director of CyberAlberta shares both successes and challenges observed with cyber workforces and organizational readiness. Her previous tenure with the Alberta Privacy commissioner adds some additional nuance in these times of ever greater tests of personal rights. | |||
| ESRM roots, revelations & resilience with John Petruzzi | 31 Jul 2025 | 00:35:49 | |
Enterprise Security Risk Management (ESRM) principles appear in almost every episode and this one is a bit more overt because it features two of the three people responsible for promoting ESRM in the early days of it's reintroduction through ASIS. John Petruzzi is now the CEO of Unlimited Technology and leading them toward an expanded influence in the enterprise security industry, sharing insights for what works with fortune 250 organizations, government and even local school boards. As the title implies, resilience is the discipline most organizations need to improve upon, and Mr. Petruzzi's personal and professional opinions on this gap may surprise some. The threat landscape is changing at a pace and breadth few could have predicted, those that navigate it well will prosper. | |||