Back

Explore every episode of the podcast The Security Collective Podcast

Dive into the complete episode list for The Security Collective Podcast. Each episode is cataloged with detailed descriptions, making it easy to find and explore specific topics. Keep track of all episodes from your favorite podcast and never miss a moment of insightful content.

Rows per page:

1–50 of 126

TitlePub. DateDuration
‘In Case You Missed It’ - Season 11 mashup01 Feb 202300:28:51

Today we are recapping some of the great episodes from season 11 'In Case You Missed' them!

We have put together a snippet of the best parts from each guest for you, and if you like what you hear, click below to listen to the full episode, or head to wherever you enjoy our podcast, and check out the full back catalogue.

Links:

Marc Bown

Stephen Kennedy

Craig Ford

Naveen Chilamkurti

Paul McCarty

Yvette Lejins

Jamie Newman

Paul Wenham

Samm MacLeod

For the full episode, transcript please visit our website

113. Transforming with Samm MacLeod18 Jan 202300:23:39

It’s our last episode for the season, and we are joined by a very good friend of Claire’s and of the podcast, Samm MacLeod. Samm and Claire discuss what's been happening since we caught up with her 12 months ago in season eight, when Samm generously shared her CISO journey through burnout and recent sabbatical. She's now back CISO-ing, and this time they covered digital transformations and security transformations.

Samm MacLeod is an experienced Information Security Executive with experience across multiple industry verticals including tech, financial services, and critical infrastructure. Having led several cybersecurity transformation programs, Samm helps organisations imbed effective security practices through cyber security strategy, security operating models, and risk management frameworks.  Samm’s experience with boards, audit & risk committees, and executives allows her to bring a unique set of experiences and perspective to the management of technology and cyber risk and the delivery of security best practice. She is currently an appointed Netskope Security Board Advisor and has previously held non-executive positions on a critical infrastructure board (AEMO Cybersecurity Board), securitisation & financial services board (MEPM) and Information Security education and research board  (Deakin Executive Board). Based on the Bellarine Peninsula, Samm is an industry speaker and writer, and an advocate for diversity in cyber.

Links:

Samm LinkedIn

For the full episode transcript, please visit our website.

The Security Collective podcast is proudly brought to you in partnership with LastPass, the leading password manager.

104. The next frontier of cyber controls with Marc Bown26 Oct 202200:34:03

The first episode for this season we welcome Marc Bown the CISO and Enterprise Technology lead at Immutable, a web3 gaming scale up.  Claire and Marc discuss the culture versus tech debate, exactly what web3 gaming is, and Marc shared his thoughts on what we as a security industry are still trying to get right. 

Prior to Immutable, Marc helped found the security teams at Sportsbet, Fitbit and Afterpay. Passionate about building empowered, high-performing teams, he believes that good security is as much about culture as it is technology.

Links:

Marc LinkedIn

The Security Collective podcast is proudly brought to you in partnership with LastPass, the leading password manager.

For the full episode transcript please visit our website.

25. Paul Chapman, Global CIO, Box25 Mar 202000:19:51

Paul Chapman is the Global Chief Information Officer at Box, where he is responsible for leading the company’s global information technology strategy, cyber risk and compliance practices and customer advocacy. Prior to Box, Paul was the CIO of HP Software for HP. Paul also served as Vice President of Global Infrastructure and Cloud Operations and Vice President of Enterprise

In this episode, Paul will share his hiring process and describe the characteristics that make a good candidate. He’ll provide insight into the potential conflict between a CIO and CISO, and its necessity in managing an effective decision-making process. Paul discusses Box's requirements for candidates with a strong personal brand, reputation in the market and having the respect of others in the community and why this is critical to the role, as well as finding a good cultural fit. He also shares the ways that Box invests in a number of different dimensions in security to ensure the highest level of security function and structure.

Links:

Time Stamps:

  • 01:03 - Paul Chapman’s introduction and background
  • 06:01 - The process of hiring the proper candidate first
  • 08:25 - The characteristic that makes a good candidate
  • 10:32 - Hiring principle to follow when selecting new team members
  •  12:41 - What’s driving compliance and trust under the CIO?
  • 13:30 - “More and more security and compliance functions converging into the one notion of trust. Compliance is such a key component of the value we bring.” - Paul Chapman
  • 14:30 - The pressure to have the highest level of security function and structure
  • 16:16 - “It’s about being forward-thinking, innovative, and constantly evolving our own security posture to be our own best referenceable company in the market.” - Paul Chapman
  • 17:19 - Top advice for other aspiring CIOs

 

24. Finding Common Ground with Tamara Martin18 Mar 202000:17:00

Tamara Martin commenced her career as a qualified lawyer and then transitioned into consulting in Crisis, Emergency, and physical security management, servicing a broad range of global and domestic and critical infrastructure organisations. 

After gaining a well-rounded skill set through her consulting experience and first client-side role with Jemena, Tamara decided to take up a newly created full-time position within the AGL Energy Security team. Since commencing at AGL in mid-2017, Tamara has developed high-end skills and expertise in business resilience, specifically intelligence, strategic, physical security, crisis management, travel security, and aspects of cyber security

During this episode, Tamara will provide insights into finding common ground amongst those within your diverse organisation. Listen as she reveals the most valuable lessons she has learned through her transition into the cyber security industry. Tamara shares her knowledge on the skills gained in other industries and professions that are transferable to cyber security, as well as the traits that can identify a candidate that may be new to cyber but has the potential to enhance your team.

 

Link:

Time Stamps:

  • 00:34 - Tamara Martin’s introduction and background

  • 03:13 - What makes someone a good choice to come into a security team
?
  • 04:50 - Key skills from legal and consulting days that Tamara was able to bring into physical, security and resilience work

  • 06:55 - The role of diversity in the success of the team

  • 07:43 - “If you've got a really strong leader who can encourage the traits which motivate and drive you to work towards common goals and objectives, and the occasional giggle, it seems to work quite well.” - Tamara Martin

  • 08:15 - Finding the common ground and endearing trust

  • 08:49 - The importance of having support groups for a certain community

  • 10:50 - Gaining skills in other disciplines of the security industry

  • 12:23 - “We're all operating in roles that are inherently risk-based, and you will operate better and make more informed decisions if you're aware of those cross-functional cooperation opportunities and their impacts.” - Tamara Martin

  • 13:35 - Taking a chance on a not-so-obvious candidate who has the potential

  • 14:49 - “Self-driven learning manifests in a much more productive and enthusiastic team member.” - Tamara Martin

23. Damien Scalzo, CIO, Mercedes Benz Financial Services11 Mar 202000:19:43

Damien Scalzo is the CIO of Mercedes-Benz Financial Services Australia/New Zealand. For over 15 years, Damien has combined his business and technology experience as a CIO, Management Consultant, Systems Integrator and Chartered Accountant to help organisations use technology to add value to their core and new business processes across industries including Financial Services, Manufacturing, Utilities, and Public sector. Damien is passionate about technology and also spends time mentoring startups to grow and scale

In this episode, Damien will share his tips on managing cyber security at the executive level. As a mentor for startups, Damien is able to share with us exactly when startups should be considering their security strategy. Using his experiences from a combination tech leadership and security background, Damien shares various effective reporting structures for security leaders. Find out how Damien keeps his knowledge on current security trends updated, and how he uses this information to protect the organisation

Links:

Time Stamps:

  • 01:00 - Damien Scalzo’s introduction and background
  • 04:08 - How security organisations can obtain value and funding 
  • 05:55 - Your first hire when building a new team security team
  • 06:14 - “I always liked the idea, in anything, in hiring the talent that finds its own talent. It’s always been better to hire the leader first who then builds their team up.” - Damien Scalzo
  • 07:20 - Understanding how to take risk in a corporate environment
  • 08:10 - Should security leaders report directly to the CEO?
  • 09:22 - “Whether the CIO represents security at the board or the CISO comes into the board as a guest, the CEO has to be the person that sets the tone from the top for security.” - Damien Scalzo
  • 10:03 - Understanding cyber security at the executive level
  • 12:08 - How to stay current with updated knowledge on security trends to keep your team, peers and executives informed
  • 15:05 - When should a start up organisation consider a security strategy and dedicated security leaders? What can they do in the meantime?
  • 17:00 - Damien's best advice for CIOs from his unique experience combination of start-up mentoring, and being a leader in tech with a security background
22. Victoria Kluth, CEO, Araza04 Mar 202000:27:13

Victoria Kluth is the CEO of Araza, a technology company that specialises in the implementation of complex solutions including cloud-based applications and enterprise systems integration. 

Victoria is recognised as one of Australia’s most successful entrepreneurs and has won the Optus Business Leader of the Year award and ARN Entrepreneur of the Year.  Her organisation has been presented multiple technical awards, and is on multiple 'fast' lists in Asia and Australia.

During this episode, Victoria will share the guiding principles that have allowed Araza to achieve fast growth. Listen and learn about the Araza Women in Cyber program, developed to help address gender diversity within the cybersecurity industry. Discover how the program is providing entry-level female cybersecurity candidates with experience to launch their cyber careers.

Links:

Time Stamps:

  • 00:32 - Victoria Kluth’s background and introduction
  • 03:03 - “So many people just take clients for the sake of having that work. They are not looking at, well is this the type of company we should be partnering with. Are we both going to look good?” - Victoria Kluth
  • 04:20 - How to attract a diverse workforce of women
  • 06:43 - Principles to follow when building teams in the tech industry
  • 07:22 - “Be great and be grateful. Striving to be great is ensuring success for yourself, your client, and company.” - Victoria Kluth
  • 10:20 - The Araza Women in Cyber Program
  • 16:30 - Recruiting high-level cyber industry entry employees
  • 19:39 - Examples of training for program participants
  • 21:48 - Attracting diverse candidates for a successful team
  • 25:40 - “Diverse teams, whether it’s in cyber or anything, perform better. All the research shows it.” - Victoria Kluth

 

21. Anna Leibel, CIO, UniSuper18 Dec 201900:36:15

Anna Leibel is the Chief Information Officer of UniSuper, an Australian superannuation fund that provides superannuation services to employees of Australia's higher education and research sector. She has spent two decades building and leading teams to deliver business transformation, and has been successful in launching new businesses, expansion into Asia, enterprise technology, global sales, and start-ups.

During this episode, Anna will share her business technology and transformation strategy for Cyber Security leaders in this digital transformation age. Learn the non negotiable traits a successful security leader must have. Gain insight into the gender diversity in the workplace and the strategy for an internal or external security breach.

Links:

Time Stamps:

  • 01:10 - Anna Leibel introduction and background
  • 06:00 - The fundamental shift in the size and focus of security teams
  • 08:44 - Non Negotiable traits a security leader must have
  • 10:33 - Insight into gender diversity in the workplace
  • 11:09 - “I think we are missing a really big opportunity to help people understand why it’s so important to have diversity. And for me, it's diversity of thought.” - Anna Leibel
  • 12:09 - New cyber trends from the board perspective
  • 14:49 - Are board members proactively educating themselves around cyber?
  • 16:51 - The immediate strategy for an actual security breach
  • 23:13 - Building a relationship with your CISO
  • 26:53 - Adjusting to the security language within your organisation
  • 28:17 - The role of the cloud & protection methods
  • 32:52 - Learnings from working within the cyber security industry

 

20. Family Friendly Security Startups with Fatemah Beydoun11 Dec 201900:15:37

Fatemah Beydoun is a founding team member of Secure Code Warrior, a secure coding company with innovative solutions helping AppSec Managers and DevSecOps to not only shift left but start left. As VP of Customer Success and Operations, Fatemah is responsible for turning SCW’s customers into its biggest advocates, improving Customer Success maturity, and leading the Customer Success teams globally. 

During this episode, Fatemah will discuss a family-friendly policy that will allow you to finally find your work & family balance. You’ll also hear insight into why the organisation attracts so many passionate employees. Lastly, find out how to retain quality staff during the ‘skills crisis.’

Links:

Time Stamps:

  • 00:25 - Fatemah Beydoun introduction and background
  • 04:28 - “We really believe that diversity is what makes really strong teams.” - Fatemah Beydoun
  • 04:39 - What attracts passionate employees to your organisation
  • 06:26 - Secure code policies for maternity and maternity leave
  • 09:10 - A policy that allows you to not have to choose between work & family
  • 11:29 - Lessons learned from a family-friendly policy
  • 12:06 - “Everyone in the organisation can play a role in creating that non judgemental environment where people except children into the workspace.” - Fatemah Beydoun
  • 13:25 - Attract and retain the proper quality staff during the ‘skills crisis’
  • 14:59 - Best advice to those aspiring to be in a leadership position

 

19. Career Growth Through Industry Volunteering with Kathleen Smith04 Dec 201900:25:47

Kathleen Smith, CMO for CyberSecJobs.Com and ClearedJobs.Net, has coached thousands of job seekers and employers on how to better connect and work together to achieve the mutual goal of employment. 

Kathleen presents at several conferences each year on recruiting and job search. Some of the conferences she has presented at as a sole presenter or moderator include BSidesLV, BSidesTampa, BSidesSATX, DerbyCon, CircleCityCon, FedCyber, and CyberSecureGov. Kathleen is Director of HireGround, BSidesLV’s two-day career track. 

During this episode, Kathleen shares how industry volunteering can help career progression within your company. Learn to solve the cybersecurity skills shortage within your organization. Lastly, find out how to promote employee retention with quality security employees in the security market. 

Link:

Time Stamps:

  • 00:25 - Kathleen Smith’s introduction and background
  • 02:08 - Uniquely servicing the candidate community
  • 03:08 - Cyber security career survey overview: Talent Shortage
  • 03:34 - “We hear sometimes that there is this talent shortage, but there has not been a shortage of people who are constantly learning about finding better ways to be secure.” - Kathleen Smith
  • 06:49 - Four major job search methods
  • 07:25 - “Employee referrals and job boards are the number one and 2 ways of company’s finding their next candidate.” - Kathleen Smith
  • 10:01 - Why money is a driving force to join particular organisations
  • 12:53 - A survey around community volunteer work
  • 17:25 - Top skills that volunteer learn from volunteering 
  • 20:42 - Employee retention in the security industry
  • 22:59 - Advice to employers who are hiring and build new security teams

 

18. William Confalonieri, Chief Digital and Information Officer, Deakin University27 Nov 201900:16:29

William Confalonieri is Deakin University’s Chief Digital and Information Officer, appointed in January 2012. He has postgraduate qualifications in Computer Science, Business, Negotiation, and Economics, is a certified Enterprise Architect and a graduate from the Australian Institute of Company Directors. William was awarded Australian CIO of the Year by IT News in 2014 and 2018, and by the CEO Magazine in 2016 and 2018 (runner-up). 

During this episode, William will identify and overcome the challenges you may face when building a quality security team. Learn the strategies for developing a cohesive cyber security team including his best advice for aspiring security team leaders.

Links:

Time Stamps:

  • 00:27 - William’s background and introduction
  • 03:44 - Developing a cohesive security team
  • 06:34 - Managing internal and external teams for success
  • 08:05 - The effectiveness of the security function prior to the shield program
  • 09:32 - Overcoming challenges in efforts to build a quality security team
  • 11:11 - “In the past, cybersecurity was about protecting technical infrastructure. Today, it’s people.” - William Confalonieri
  • 12:10 - Are boards expecting more from security teams?
  • 13:30 - Best advice for aspiring security team leaders
  • 14:19 - “Most of the problems are coming from the weakest link in the chain… our staff. Work on education, mainly.” - William Confalonieri

 

17. Justin Davies, CIO, Ovato21 Nov 201900:16:10

Justin Davies is the CIO at Ovato, Australasia's leading media, marketing, and printing company. Justin has over 30 years of professional experience in the Media and IT industry, holding a broad mix of functional skills including business management, consulting, sales, product, project office, and IT management.  

During this episode, Justin will share how to get your network and security teams working together. Overcome common obstacles when building a security function and a secure way of doing business. Learn to find growth opportunities while understanding the different advantages of internal and external recruitment. 

Links:

Time Stamps:

  • 00:31 - Justin’s background and introduction
  • 06:00 - Bringing your network and security team together
  • 08:57 - “Although we can block things at the perimeter there is plenty that can still get in that looks legitimate.” - Justin Davies
  • 09:25 - Internal vs. external market network hires
  • 10:23 - “Just because you don’t have a budget to get those resources, it’s no excuse. You just need to find a way.” - Justin Davies
  • 10:36 - Observing your team to find the growth opportunity
  • 11:35 - “At the end of the day we are not a security company we’re a marketing services business. We are here to deliver marketing services to our customers but we have to do it in a secure manner.” - Justin Davies
  • 12:20 - Overcoming obstacles when building a security function
  • 13:51 - Best advice for aspiring security team leaders

 

16. Security Teams and the Board with Megan Haas13 Nov 201900:21:52

Megan Haas is a former Cyber and Forensic Services Partner at PricewaterhouseCoopers (PwC) with over 30 years’ experience in Information Risk Management and Assurance and core competencies centered around Governance, Risk, Information Technology and Cyber Security.  

After spending many years advising audit committees and specialising in business and Information Technology processes and controls, she turned her focus to increasing stakeholder confidence and governance of cyber security and privacy, anti-fraud and corruption risks, compliance and post-incident remediation. Her current board roles include RMIT University, Development Victoria and the Advisory Board of the University of Melbourne Academic Centre for Cyber Security Excellence.

During this episode, Megan will share insight into her 30+ years of experience working in the cyber security sector. Learn how organisations can retain long-term high caliber talent while attracting an appropriate level of gender diversity in the workplace. Find out ways board members can better understand security teams' roles and responsibilities.

 

Link:

 

Time Stamps:

  • 00:31 - Megan Haas background and introduction
  • 06:01 - What was security teams like for clients around the world
  • 07:21 - Hiring principles to follow for building the proper team
  • 10:27 - Gender diversity in the workplace
  • 11:27 - “Those individuals doing the interviewing need to reflect the diversity of thinking.” - Megan Haas
  • 14:29 - How organisations can retain long-term high caliber talent
  • 16:23 - Understanding what security teams are doing as a board member
  • 16:49 - “There's been a real shift in understanding the concepts around cyber risk.” - Megan Haas
  • 18:56 - Advice to those inspired to run a security team
  • 20:04 - “Recognize the need for this ongoing technical competency but equally integrate and align the humanistic skills.” - Megan Haas

 

Season 11 Teaser19 Oct 202200:01:15

Listen as Claire provides a quick overview of what to expect this upcoming season on The Security Collective podcast - kicking off next Thursday 27 October.

The Security Collective podcast is proudly brought to you in partnership with LastPass, the leading password manager.

You can read the full transcript on our website

15. Dan Giesen-White, CIO, McMillan Shakespeare06 Nov 201900:18:11

Dan Giesen-White is the Chief Information Officer at McMillan Shakespeare Limited, a trusted, market-leading provider of salary packaging, novated leasing, asset management, and related financial products and services. He has over 20 years’ experience in IT and 15 years’ strategic analysis and program management experience with a strong track record of leading change in IT and across the business.

During this episode, Dan will share how you can source the proper staff with the level of maturity your company needs to succeed. Find out what it means to build a security capability rather than just another team. Learn how ASIAL has helped lead his security team including the best advice for new security leaders.

 

Link:

 

Time Stamps:

  • 00:30 - Dan Giesen-White’s background and introduction
  • 02:31 - How security is different from other tech areas of business
  • 03:39 - Build a security capability rather than a just team
  • 05:13 - Sourcing the proper staff for your company
  • 06:45 - Managing capability vs capacity
  •  07:41 - “Get the fundamentals right. That’s where people seem to struggle.” - Dan Giesen-White
  • 08:40 - Common challenges to overcome when building a security team
  • 09:50 - Addressing customer driving forces and concerns
  • 12:22 - How ASIAL has helped lead a security team
  • 13:25 - ASIAL helps me stay in front of mind and informed on how the landscape is changing.” - Dan Giesen-White
  • 15:31 - Best advice for new security leaders
  • 15:42 - “Be clear on what the role of security in your organisation is.” - Dan Giesen-White

 

14. From Security Architecture to Senior Leadership with Dan Maslin30 Oct 201900:19:25

Dan Maslin is the Head of Cyber Security for RACV, a key strategic role with accountability across several functions including strategy, architecture, operations, audit, compliance, risk, advisory and awareness & outreach, in a diverse and rapidly changing business. He has two decades of enterprise IT experience across various roles and industries in Australia and the UK, and holds the Certified Information Systems Security Professional (CISSP), Certified in Risk and Information Systems Control (CRISC) and Certified Information Security Manager (CISM) security certifications.

During this episode, Dan will share the team management skills you need to lead and build your security team. Learn why your approach to hiring may be improved including a strategic diversity plan for new team hires. Find out how to strike a balance between your insource and outsource talent.

Links:

Time Stamps:

  • 00:33 - Dan’s introduction and background
  • 03:26 - Should an architect be your first hire when building a security team?
  • 06:06 - Qualities and principles to look for when hiring for new roles
  • 06:21 - “We don’t want any ‘brilliant jerks’. We don’t need talented people that are going to come at a high cost of the team and organisation.” - Dan Maslin
  • 08:05 - How to Address the ‘skills gap’ or ‘skills crises’
  • 09:11 - Insource and outsource - The balanced solution
  • 10:44 - How diversity plays a role in new team hires
  • 13:03 - “Different skill sets, backgrounds, they all come together and play a part. It’s important to have a good mix.” - Dan Maslin
  • 13:13 - Overcoming challenges when sourcing for teams
  • 14:34 - “Poor people leadership can lead to poor retention and poor reputation in the industry.” - Dan Maslin
  • 16:40 - Long term advice for new CIO leadership

 

 

13. Cameron McLean, CIO, Yarra Valley Water23 Oct 201900:19:56

Cameron McLean is the Chief Information Officer at Yarra Valley Water, Melbourne's largest retail water utility, providing essential water and sanitation services to more than 1.8 million people. He developed his knowledge of and passion for Cyber Security during his time as CTO and General Manager of a credit card payments organisation, and this has stood him in good stead for the challenges facing his current industry.

During this episode, Cameron will share how to implement new strategies without disrupting your organisation. Learn from his hands-on experiences with security breaches and bring your security team together while fitting the needs of the leader and organisation. Find out ways to accept ongoing challenges for long term success and apply practical yet powerful advice as a new Cyber Security leader.

 

Links:

 

Time Stamps:

  • 00:39 - Cameron’s background and introduction
  • 03:33 - Learning from hands-on experiences with security breaches
  • 04:30 - “Security is the number one issue for an organisation that relies on trust.” - Cameron McLean
  • 06:36 - Bringing your security team together while fitting the needs of the leader and organisation
  • 07:50 - Hiring your team internally vs external employments
  • 10:18 - Outsourcing working to a third party hire
  • 12:11 - Overcoming challenges when building a new security team
  • 12:32 - “The real challenge was gently but pointedly helping people understand that perhaps they didn’t know as much as they thought they did.” - Cameron McLean
  • 15:13 - Accepting ongoing challenges for long term success
  • 17:06 - Practical and powerful advice for new Cyber Security leaders
  • 17:35 - “Invest in yourself. Invest in your own learning.” - Cameron McLean

 

Season 2 is coming, and we are going LIVE!11 Oct 201900:01:15

On the back of the success of season 1 of The Secure CIO Podcast, host Claire Pales presents a quick taste of season 2, and shares information on the upcoming LIVE recording of The Secure CIO Podcast! Hitting the road in Melbourne on 23rd October 2019.

Secure your tickets at thesecurecio.com.

 

12. The Cybersecurity 'Roles' Crisis with Nick Ellsmore21 Aug 201900:32:02

Nick Ellsmore is Co-Founder of Hivint, now a part of Trustwave, an Optus company, and creator of cyber-security collaboration portal Security Colony. He was previously co-founder of SIFT and Stratsec, and has served on boards and forums including the Internet Industry Association, the NATA AAC for Software Testing, UNSW Advisory Boards, and the APEC TEL Security & Prosperity Steering Group. 

During this episode, Nick will share the component to selecting employees who will fit well in your organization. Find out how great leaders create and share a positive vision and successful team atmosphere. Learn the benefits of focusing on diversity in the workplace and what it takes to become a great Security Leader.

Links:

Discussed:

Time Stamps:

  • 00:30 - Nick’s introduction and background
  • 04:19 - Principles to follow to bring the right people together
  • 06:26 - Hiring those who have a proper attitude yet lack the proper skills
  • 07:35 - “We don’t have a skills crisis so much as we have a roles crisis.” - Nick Ellsmore
  • 10:06 - Focusing on diversity in the workplace
  • 13:13 - What roles are clients looking for?
  • 17:15 - Building a function within the organization
  • 18:54 - “Your first security manager in an organization is going to shift the way that function is perceived by the organization.” - Nick Ellsmore
  • 20:00 - The ultimate path for security leaders 
  • 25:29 - “If I am recruiting, the person that I want is the person who is clearly going to be passionate, do the right thing, and someone that’s  a nice person.” - Nick Ellsmore
  • 27:33 - Giving the best advice to your younger self

 

11. Skills, Capabilities and Benchmarking with Louise Smith14 Aug 201900:35:01

Louise Smith is the Australian computer society director for workforce development and education. She is a business capabilities specialist with over 15 years of experience consulting to individual businesses and governments on the skill needs within their organization. 

During this episode, Louise will discuss the SFIA Framework and its application to organizations. Find out how individuals can define their current skill set in the cybersecurity workforce. Learn if your organization can benefit from a variety of skills and experience amongst your team.

 

Links:

 

Time Stamps:

  • 00:32 - Louise introduction and background
  • 01:52 - The SFIA framework & how CIO’s can use it
  • 08:24 - SFIA's capability framework and assessment
  • 12:27 - What makes SFIA stand out from other frameworks?
  • 17:08 - Adjusting hiring practices to accommodate what's needed
  • 18:48 - “Truly understand the roles and define them effectively and consistently.” - Louise Smith
  • 22:12 - Successfully identifying skills of potential cyber security role
  • 27:27 - Do most teams have a specific set of diverse skills?
  • 31:34 - “There variation both in the depth and breath of the way in which skills are applied, adapted, and driven back into the business.“ - Louise Smith
  • 33:04 - “If you can refine and define your benchmarking it will ensure that you’re prepared for and supporting the depth and breath that you need across your workforce.” - Louise Smith
  • 34:00 - Skills you might need in the future - A self reflection

 

10. Cohesive Teams with David Jorm07 Aug 201900:26:11

David Jorm is the Senior Manager at Commonwealth Bank, a business that offers a full range of financial services to help all Australians build and manage their finances.

David has been working in the tech industry for 20 years, with a focus on managing security teams for the last 7 years. His experience has spanned government, corporate, and startup environments in several countries.

During this episode, David will talk about the skills a CIO should be looking for if they want to advance a technical person into a leadership role. Learn the challenges of hiring and retaining staff including ways to building an effective team through diversity. Find out what you need to know about working with a third-party recruiter.

 

Links:

 

Time Stamps:

  • 00:30 - David’s background and introduction
  • 03:06 - How the ‘skills crisis’ impacts vendors and in-house teams
  • 06:14 - Types of tasks and skills to outsource verse utilizing your team
  • 08:22 - The challenges of hiring and retaining staff
  • 10:40 - Building an effective team through diversity
  • 14:26 - “I can control the team culture and the way that we operate. It will attract people and candidates that other people wouldn’t get.” - David Jorm
  •  14:25 - The transition from a technical expert to becoming a leader
  • 18:18 - “You want to see evidence that they are acting in a senior capacity without having the title and the title or the pay rise follows.” - David Jorm
  • 19:59 - Using third-party recruiter when hiring new staff
  • 23:26 - David gives advice to his much younger self

 

9. Tuning In with Karen Worstell31 Jul 201900:29:38

Karen Worstell is the CEO of W Risk Group, a Denver based cybersecurity consultancy focused on helping companies demonstrate due diligence to a defensible standard of care. Karen has also been the CEO of AtomicTangerine, a Silicon Valley startup, and tenure as Chief Information Security Officer (CISO) at Microsoft Corporation, AT&T Wireless, and Russell Investments.

During this episode, Karen will share how leaders can build and cultivate a successful security team through her diversity and sourcing plans. Follow the discussed core principles when building and aligning your security team. Learn how the ‘skills crisis’ is effecting the hiring process and the impact the ‘Be an ally’ program has on the tech industry.

 

Links:


Time Stamps:

  • 00:31 - Karen’s background and introduction
  • 04:30 - Why there are so few women in cyber security
  • 09:05 - “A personal resilience, level of confidence, and ability to do self-advocacy outside of a formal environment are very important to women for being able to advance their career.” - Karen Worstell
  • 11:18 - The role diversity plays in hire practices and sourcing plans
  • 12:57 - “We want to create an environment that’s welcoming for everyone.” - Karen Worstell
  • 15:01 - Core principle to follow when building and aligning security teams
  • 17:57 - “In order for us to be successful in the long term, we have to have people that are really good at change.” - Karen Worstell
  • 18:53 - Which roles you may want to our course verse in-house employees
  • 20:23 - How the ‘skills crisis’ affects the hiring process
  • 23:06 - The impact that ‘Be an ally’ has on the tech industry
  • 27:12 - Karens best advice to her younger self

 

 

8. Lateral Career Moves with Craig Templeton24 Jul 201900:25:15

Craig Templeton is CISO at REA Group Limited, a leading digital business specializing in property.

Craig brings over 23 years experience in the security field, having worked for a variety of blue-chip organizations globally including IBM, Deloitte and ANZ Bank. He sits on a number of Executive Board advisory committees, has association with research institutes in London, Canberra, Sydney and Melbourne and also participates in several cyber security start-up mentoring programs including CyRise.

During this episode, Craig will share how to attract and retain high caliber talent to your organization. Learn what skills are needed to run a small business and what type of tasks to outsource. Listen to the end for crucial advice for new startups in the industry.

 

Links:

 

Time Stamps:

  • 00:31 - Craig's background and introduction
  • 04:11 - “You need to be resilient within yourself to withstand organizations and structural changes within businesses.” - Craig Templeton
  • 05:09 - Best hiring practices when building up a team
  • 09:26 - “By limiting yourself to somebody who has only ever worked in security you’re actually potentially sabotaging your own recruitment efforts.” - Craig Templeton
  • 09:41 - Skills or roles that should be within your business and what to leave for consultants
  • 12:08 - Attracting and retaining talent for internationally recognised organizations
  • 14:36 - Being affected by the supposed skills crises
  • 17:47 - Developing accountability outside your security team
  • 20:12 - “Experience is invaluable. You need to make mistakes to grow as a person.” - Craig Templeton
  • 20:38 - Advice to new startups in the industry

 

7. Security Leadership; Manager v Maker, with Caroline Wong17 Jul 201900:38:21

Caroline Wong is the Chief Security Strategist at Cobalt.io, a PTaaS platform that transforms yesterday's broken pen test model into a data-driven vulnerability management engine.

Caroline is a dynamic cybersecurity expert with more than a decade of industry experience as a day-to-day manager at eBay and Zynga, product manager at Symantec, and managing consultant at Cigital (now Synopsys). She also holds positions on multiple industry advisory boards, including the North American Advisory Council for ISC2 and the RSA Conference Advisory Board. 

During this episode, Caroline will share how to transition from managing yourself to managing others. Learn to become a great security leader and encourage others to grow and lead. Match potential candidates with jobs that need to be filled, work with remote teams, and address compensation expectations.

 

Links:

 

Time Stamps:

  • 00:29 - Caroline background and introduction
  • 04:08 - Will the skills crisis impact security teams and vendors?
  • 06:37 - Supplementing your in-house security team and possible outsourcing options
  • 10:21 - Do you really need a core security team?
  • 12:44 - Overcoming dev sec ops movement challenges
  • 16:18 - Transitioning into a great leader and encouraging others to grow
  • 19:10 - “A great leader lays out that path to allow that person to grow.” - Caroline Wong
  • 19:51 - Transitioning from a maker to a manager
  • 23:30 - “In order to be whatever you’re going to be tomorrow you have to let go of who you are today.” - Caroline Wong
  • 24:03 - Matching potential candidates with jobs that need to be filled
  • 25:30 - "Hiring managers often find themselves in a position where they may frankly struggle to write a job description because they are trying to figure out what should this person do?" - Caroline Wong
  • 30:38 - Working with remote teams + compensation expectations

 

'In Case You Missed It' - Season 10 mashup31 Aug 202200:16:45

We've taken some clips of wisdom from five of our guests this season and brought them together in a neat package for you. This season in partnership with LastPass, we focused heavily on third party risk and supply chain security.

For the full episode transcript, please visit our website.

The Security Collective podcast is proudly brought to you in partnership with LastPass, the leading password manager.

 

6. Growing Teams from Scratch, with Darren Argyle10 Jul 201900:40:49

Darren Argyle is the co-founder of Cyber Resilience which delivers executive cyber leadership programs to support the next generation of cyber leaders and emerging CISO’s.

Darren is an accomplished executive with close to 20 years of international cyber risk and security experience and broad expertise in providing hands-on leadership, strategic C-level/board direction and program execution. He was named in the top 100 Chief Information Security Officers globally in 2017 and the top 100 Global IT Security Influencers in 2018.

During this episode, Darren will share how to navigate the global skills crisis in search of highly experienced and well-rounded security team members. Learn when to utilize an outsourced model and when to work with permanent in-house hires. Listen for ways to overcome the biggest challenges in the cybersecurity space including his major lessons learned over his career.

 

Links:


Time Stamps:

  • 00:32 - Darren’s introduction and background
  • 05:13 - Analyzing the scope of security teams
  • 13:29 - Prioritizing the type of team you must hire
  • 14:44 - “The first role I would always employ is an enterprise security architect who thinks about business first and technology second.” - Darren Argyle
  • 16:39 - Utilizing the outsourced model versus permanent hires
  • 18:13 - “Anything that can be automated or highly specialized such as major breach response you could certainly outsource.” - Darren Argyle
  • 18:33 - Overcoming common hurdles when sourcing for the right people for your team
  • 21:38 - Navigating the global skills crisis
  • 24:48 - Searching for highly experienced & well-rounded team members
  • 29:53 - The role diversity plans in the hiring and sourcing plans
  • 30:39 - “For a senior leader to be successful: Recognize diversity.” - Darren Argyle
  • 34:51 - Sharing your successes and most importantly, your failures

 

 

 

5. You Can’t Teach Attitude, with Michelle Price03 Jul 201900:33:37

Michelle Price is the CEO at Aust Cyber, a company that supports the development of a vibrant and globally competitive cyber security sector. 

Before joining AustCyber, Michelle was the first Senior Adviser for Cyber Security at the National Security College within The Australian National University. In this role, she established an integrated approach to the College’s cyber security program across executive and postgraduate education and policy engagement.

During this episode, Michelle will discuss the skills and qualities that employers must look for in security staff in order to build a truly successful team. Listen as she encourages others to increase diversity in the cyber security workforce and continue to inspire people with the possibilities of cyber innovation.

 

Links:

AustCyber:

 

Time Stamps:

  • 00:30 - Michelle’s background and introduction 
  • 02:36 - Overcoming the challenges of hiring staff into cyber roles
  • 03:20 - “Nine times out of ten I was actually hiring for attitude.” - Michelle Price
  • 08:49 - Addressing the skills gap with a university course
  • 13:03 - Preparing for the demands on the future of the cyber workforce
  • 16:07 - The role diversity plays in the hiring process
  • 18:16 - “Diversity in ethnicity, diversity in age is just as important as diversity in gender. It’s all about diversity of thinking.” - Michelle Price
  • 21:23 - The future of startups and consultancies offering contract work
  • 26:47 - Key lessoned learned around building teams
  • 27:14 - “It’s just so hard to teach attitude. You can shape attitude but you really can’t necessarily fundamentally change the underlying attitude of someone.” - Michelle Price
  • 30:20 - Michelle’s advice to her younger self


4. Establishing Essential Hiring Criteria with Jo McCatty26 Jun 201900:24:14

Jo McCatty is a recruitment leader with expertise across different sectors serving the UK, EU and APAC markets. Her key interest is driving success and delivery of outcomes through people, technology and change/transformation (aka ambiguity).

Jo also has an interest in working on Complex People Projects , and she is passionate about Candidate Attraction , Engagement & Management, Acquisition as well as Coaching. Currently working onsite with ANZ in their NICHE Sourcing squad, Jo is working to attract engineering talent into the business during an exciting time of change in the world of Technology.

During this episode, Jo will share how to overcome the top challenges when hiring staff in cybersecurity including ways to build and grow your team. Learn the role diversity plays in your hiring and sourcing plans. Find out how leaders and employees should harness the power of mentorship for long term success.

 

Links:

 

Time Stamps:

  • 00:28 - Jo’s background and introduction
  • 03:09 - Overcoming the top challenges when hiring staff in cybersecurity
  • 04:52 - Taking recruitment on as a project
  • 05:52 - Transferring skills from other industry sectors
  • 05:59 - What recruiters can do to fill cyber-security roles
  • 08:13 - Setting the candidate up for success
  • 08:55 - Do industries experience a skills gap?
  • 09:20 - “The skills crisis comes about because everyone is trying to hire the same thing at the same time.” - Jo McCatty
  • 10:07 - The role diversity plays in your hiring and sourcing plans
  • 12:11 - Reaching success + the power of mentorships
  • 13:33 - “I have a coach for life because you can always step up, level up, and improve.” - Jo McCatty
  • 15:10 - Internal coaching and mentoring services
  • 15:58 - The fact and fiction of the recruitment industry + building a team
  • 18:18 - "Looking at the team dynamic and making sure you're hiring to complement it." -Jo McCatty
  • 18:41 - “Huge consideration is looking at development areas and strengths for every individual you’re bringing into the business verse what already exist in the business.” - Jo McCatty
  • 20:27 - Advice to your younger and less experienced self
  • 20:39 - "[Don't] rush with the haste of the business to hire the talent". - Jo McCatty

 

3. Security Sourcing: Cracking The Code with Craig Searle19 Jun 201900:30:53

Craig Searle is the co-founder of Australian cybersecurity consultancy, Hivint, and the security collaboration platform, Security Colony – both of which were acquired by Trustwave, an Optus company, in December 2018.

Craig has over 12 years of experience in the security industry, working in the finance, government, telecommunications and infrastructure sectors. He has been directly responsible for the delivery of a number of strategically-critical security programs for a range of clients, including a $10m PCI DSS compliance program for one of Australia’s leading health insurers, achieving compliance on-time and on budget.

During this episode, Craig offers a unique perspective on the shortage of talent in the cybersecurity industry and ways to create a proper solution. Find out if we are losing potential in house professionals to cybersecurity startups. Learn the best practices for new hire onboarding and enable your team to succeed long term.

 

Links:


Time Stamps:

  • 00:32 - Craig’s background and introduction
  • 02:45 - Transitioning from a technical to a leadership role
  • 06:39 - Attracting the proper work talent to your business
  • 08:07- “One of our big beliefs is that good people attract more good people.” - Craig Searle
  • 11:54 - The role diversity plans in the hiring and sourcing plan
  • 12:19 - “Diversity is an outcome of having a successful hiring and talent acquisition process.” - Craig Searle
  • 18:01 - Analyzing the ‘skills crisis’ and creating a proper solution
  • 19:08 - “We need to do better at looking at the outcome we want and find the right person for that outcome. Pay less attention to the university they went to or the certification they hold.” - Craig Searle
  • 20:13 - Are we losing potential in house professional to Cybersecurity startups?
  • 22:44 - Enabling a team to succeed long term
  • 23:57 - Overcoming obstacles when sourcing & best practices for new team hires
  • 28:19 - Wise and valuable words to tell your younger self

 

 

2. Finding the Time To Find the Talent with Samm MacLeod12 Jun 201900:36:30

Samm MacLeod is the CISO at AGL, Australia's leading energy company offering electricity, gas, solar and renewable energy services to homes and businesses.

Samantha is an accomplished professional with more than 20 years’ experience supporting business strategies through technology enablement, risk management, security, and governance. In her role as CISO at AGL, Samantha is accountable for aligning Cybersecurity strategy with business strategic initiatives and integrating security practices across the organization.

During this episode, Samantha will bring light to the obstacles you may face when sourcing for security teams. Listen for her suggested immediate hiring needs and why you should strategically create employee longevity. Find out if the cybersecurity talent gap is really an industry crisis and how encouraging a diverse team of talented professionals may be the solution to a successful team.

 

Links:

 

Time Stamps:

  • 00:32 - Samantha’s background, introduction, and journey to CISO
  • 03:20 - Immediate hiring needs for a new security team
  • 07:36 - Roles that must be outsourced or can be done in house
  • 09:59 - Is there a lack of skill crisis?
  • 10:24 - “I don’t think you need 25 years experience to make a difference in a security team” - Samantha MacLeod
  • 15:41 - Are we losing in-house security professionals to micro business?
  • 16:18 - “Step out of that mold and challenge the industry and status quo” - Samantha MacLeod
  • 18:25 - Why women aren’t prevalent in this industry
  • 22:07 - The role that diversity plays on a security team of professionals
  • 24:51 - Overcoming obstacles when sourcing for teams
  • 26:14 - “The hardest thing is finding the time to find the talent” - Samantha MacLeod
  • 28:29 - Key lessons learned around cybersecurity teams

 

1. Security in Context with Jonathan Werrett06 Jun 201900:26:35

Jonathan Werrett is the head of information security at FitBit and prior to that, he ran product security at Palantir. Jonathan has spent the last decade building infosec teams and maturing security operations. His roles have spanned security engineering in Silicon Valley, pentesting in APAC, and devops/SRE in Europe.

During this episode, Jonathan will share core principles to follow when hiring and building a team in information security. Learn to find ideal leadership even when the talent pool is subpar and explore the importance diversity plays in the hiring process. Listen to the end to hear some of Jonathan's hardest lessons learned during his 15+ years in the industry.

 

Links:

 

Time Stamps:

  • 00:27 - Jonathan’s background and introduction
  • 02:12 - Principles to follow when hiring a new team
  • 02:39 - “The team should reflect the risks that your particular organization faces” - Jonathan Werrett
  • 03:28 - Security teams role in proper context
  • 08:55 - Building and hiring a team in information security
  • 13:22 - Skills and roles that can be outsourced
  • 14:02 - “You don’t need a full-time red team even if your multinational” - Jonathan Werrett
  • 16:22 - The importance of diversity plays a role in the hiring process
  • 16:45 - “More diverse teams come up with better solutions over time” - Jonathan Werrett
  • 18:16 - Finding ideal leadership even when the talent pool is subpar
  • 23:55 - Hardest lessons learned in this industry

 

103. The Future of Third Party Cyber Risk with Alla Valente24 Aug 202200:27:31

Following the success of our recent webinar, Claire is again joined by Alla Valente, this time they discuss the role of procurement, talk about supply chain risk as an enterprise wide risk and discuss who might own this risk. They covered how businesses are struggling to give third parties limited access to data and systems, and the flow on effects of managing the right level of access to get the job done.

Alla Valente is a senior analyst at Forrester serving security and risk professionals. She covers GRC, third-party risk (TPRM), supply chain risk (SCRM), and contract lifecycle management (CLM) strategy, best practices, and technology. Her research includes coverage of key regulatory compliance issues; risk management, ethics, and trust in digital transformation; and operational resilience. In this role, she helps Forrester clients build and mature a comprehensive programs that maximises business opportunity and performance while minimising risk and protecting the organisation’s brand.

Links:

Alla LinkedIn

For the full episode transcript, please visit our website

The Security Collective podcast is proudly brought to you in partnership with LastPass, the leading password manager.

102. Cyber in local government with Paul Barrett17 Aug 202200:17:20

Claire is joined by Paul Barrett as they talk about cyber culture in local government, how the governance model for cyber is changing for the better, and Paul shares why he sees audits as a gift. It is great hearing Paul's view on cyber and getting a glimpse into being a CIO and local government.

Paul Barrett is an experienced an IT professional with nearly 15 years industry experience and 7 years local Government experience. His technical background is in network and security with a transition into people leadership, governance and information management over the last 6 years. Paul has a passion for implementing tangible change within organisations and place business process improvement at the core of technology solutions, and enjoys building high performing teams, hiring character ahead of technical ability.

Links:

Paul LinkedIn

For the full episode transcript, please visit our website

The Security Collective podcast is proudly brought to you in partnership with LastPass, the leading password manager.

101. Crisis Talks with Grant Chisnall10 Aug 202200:21:33

Claire is joined by Grant Chisnall a crisis trainer, advisor and podcaster, who has a passion for leadership communication and decision making. In this episode they covered a lot of ground including the escalation from incident response to crisis management, and talk about business collaboration before an incident, and how to plan for resilience while mopping up a cyber incident.

Grant has supported some of the world's leading organisations through crisis events ranging from cyber attacks to coronavirus; activism to air crashes; and from Natural disasters to workplace fatalities. His podcast ‘Crisis Talks’ tells the extraordinary stories of people who have led through crises and their stories of leadership and resilience in the face of adversity. Grant’s aim is to help leaders prepare for the worst-case scenarios and respond proactively and with confidence to any incidents that threaten their people, operations or reputation.

Links:

Grant LinkedIn

Left of Boom website

For full episode transcript please visit our website.

The Security Collective podcast is proudly brought to you in partnership with LastPass, the leading password manager.

100. Celebrating 100 episodes!03 Aug 202200:08:21

To celebrate the 100th episode and recently hitting 30,000 downloads, Claire wanted to honour some of the guests that have given their time and thought leadership so generously. So here's a little trip down memory lane, which we hope that you enjoy.

For the full episode transcript, please visit our website.

The Security Collective podcast is proudly brought to you in partnership with LastPass, the leading password manager.

99. The challenges & risks of supply chain security with Alla Valente & Vijay Krishnan - part 227 Jul 202200:25:25

In part 2 of Claire’s webinar with Alla Valente and Vijay Krishnan they cover software supply chain, how to navigate fourth party risk and talked about offshore supply chain risks such as privacy and data sovereignty, as well as some great audience questions.

they cover software supply chain, how to navigate fourth party risk and talked about offshore supply chain risks such as privacy and data sovereignty. They also covered some great audience questions.

Alla Valente is a senior analyst at Forrester serving security and risk professionals. She covers GRC, third-party risk (TPRM), supply chain risk (SCRM), and contract lifecycle management (CLM) strategy, best practices, and technology. Her research includes coverage of key regulatory compliance issues; risk management, ethics, and trust in digital transformation; and operational resilience. In this role, she helps Forrester clients build and mature a comprehensive programs that maximises business opportunity and performance while minimising risk and protecting the organisation’s brand.

Vijay Krishnan is the CISO at UniSuper leading Security Operations, Security Governance, Risk & Compliance, Security Strategy, Architecture & Design, Identity & Access Management, and Enterprise Observability.  In his role, he leads a multi-year security program to reduce UniSuper security risk thus protecting UniSuper members.  Vijay has extensive experience in negotiating clear and concise security and technology outcomes in regulatory, policy and outsourcing agreements delivering value creation opportunities.  He has large, diverse national and international experience with extensive executive and Board level exposure.

Links:

Alla LinkedIn

Vijay LinkedIn

Episode #48 The value of great boss with Vijay Krishnan+

Questions for Alla's upcoming recording with Claire

For the full episode transcript, please visit our website

The Security Collective podcast is brought to you in partnership with LastPass, the leading password manager.

98. The challenges and risks of supply chain security with Alla Valente and Vijay Krishnan -part 120 Jul 202200:27:10

Earlier this week Claire hosted a live webinar with Alla Valente and Vijay Krishnan as they shared their insights on supply chain security versus third party risk. In part 1 Vijay covers APRA's CPS234 and the need for effective security controls, not just compliant ones. We also cover the role of legal and procurement in the third party assurance process. There's a tonne of great insights to be gleaned from both Alla and Vijay in this ever present risk.

Alla Valente is a senior analyst at Forrester serving security and risk professionals. She covers GRC, third-party risk (TPRM), supply chain risk (SCRM), and contract lifecycle management (CLM) strategy, best practices, and technology. Her research includes coverage of key regulatory compliance issues; risk management, ethics, and trust in digital transformation; and operational resilience. In this role, she helps Forrester clients build and mature a comprehensive programs that maximises business opportunity and performance while minimising risk and protecting the organisation’s brand.

Vijay Krishnan is the CISO at UniSuper leading Security Operations, Security Governance, Risk & Compliance, Security Strategy, Architecture & Design, Identity & Access Management, and Enterprise Observability.  In his role, he leads a multi-year security program to reduce UniSuper security risk thus protecting UniSuper members.  Vijay has extensive experience in negotiating clear and concise security and technology outcomes in regulatory, policy and outsourcing agreements delivering value creation opportunities.  He has large, diverse national and international experience with extensive executive and Board level exposure.

Links:

Alla LinkedIn

Vijay LinkedIn

Episode #48 The value of great boss with Vijay Krishnan

Questions for Alla's upcoming recording with Claire

For the full episode transcript, please visit our website

The Security Collective podcast is brought to you in partnership with LastPass, the leading password manager.

The challenges and risks of supply chain security - webinar13 Jul 202200:01:23

Join us Tuesday 19 July 2022 at 10:30am (AEST) as we are going live for The Security Collective podcast in partnership with LastPass. We've invited Vijay Krishnan from UniSuper and Alla Valente from Forrester to join Claire in a conversation about supply chain security.

You can learn more on our website 

Register for the event here

112. Security as a differentiator with Jamie Newman11 Jan 202300:21:46

Jamie Newman has a refreshing take on security and joins Claire as they chat about understanding the security posture in diverse organisations, they discuss about third party contracts, how much money you should be spending on compliance and what meaningful metrics might look like.

Jamie is an experienced IT Leader with more than 20 years experience in applications and infrastructure transformation in varying national and regional roles. His career started in HR, but then quickly moved into a technology path in the late 90's and has worked predominantly in Manufacturing, Retail and B2B environments, working in Singapore, Japan and the Middle East. Jamie moved into senior management in 2008, and has been in C level roles for the last 10 years.

Links:

Jamie LinkedIn

Jamie Twitter

Episode 68

For the full episode transcript please visit our website

The Security Collective podcast is proudly brought to you in partnership with LastPass, the leading password manager.

97. The reality of cyber incident response with Ellis Brover06 Jul 202200:24:51

Claire chats with former Toyota Australia CIO Ellis Brover, as he shares his thoughts on incident response through the lens of the CIO. They discuss how security maturity can dictate reporting lines, how organisations should seek to test the reality of systems being shut down because of an incident, and really how moral support goes a long way during a cyber incident.

Ellis Brover is a recognised IT leader with a track record over three decades of building and leading world-class IT organisations, driving transformational change, and delivering tangible business value. His experience spans a range of roles and industries, across a range of organisational scales from startups to multi-nationals.

Most recently Ellis was CIO of Toyota Australia, where he led a transformation of the IT function from an internally-focussed service provider to a strategic enabler, driver of innovation, and role model for outstanding customer service. Ellis grew and led a team of 300+ that delivered an industry-leading digital business capability as well as a rapid transformation in cyber security maturity, whilst dramatically improving efficiency and contributing to business growth.

Ellis is now pursuing advisory and consulting opportunities, aiming to add value to the business success of organisations and the development of their people through his extensive experience.

Links:

Ellis LinkedIn

For the full episode transcript, please visit our website

The Security Collective podcast is proudly brought to you in partnership with LastPass, the leading password manager.

96. Securing managed IT services with Jeremy Herbert29 Jun 202200:23:14

Claire chats with Jeremy Herbert, the CIO of Premier Technology Solutions. They covered how small businesses were affected during COVID, and what organisations of all sizes need to consider when it comes to the partners they need to manage cyber risk. On the podcast, we don't often cover cyber risk for organisations as small as maybe just a handful of people, so it was so great to change things up a bit and hear about the challenges that Jeremy and the Premier team are managing for smaller business.

Jeremy Herbert is the CIO of Premier Technology Solutions with a unique approach to technology. As a CIO of a Technology Managed Service Provider, he is not only focused on the strategic business direction for Premier but also focused on the strategic direction for the clients that Premier support.

Links:

Premier Website
Premier - free cyber check
Premier Talk
Premier LinkedIn

For the full episode transcript, please visit our website.

The Security Collective podcast is proudly brought to you in partnership with LastPass, the leading password manager.

95. Build your third party cyber fitness with Susie Jones22 Jun 202200:30:20

We are back with our 10th season of the podcast, and to kick it off Claire is joined by Susie Jones from Cynch Security. Susie and Claire discuss supply chain risk, small business cyber fitness and the recent changes to security legislation. Susie also shared her thoughts on the role of government in securing all businesses.

Susie Jones is an experienced leader and risk manager who spent years specialising in the people and process elements of general and cyber risk management, and is passionate about bringing big solutions to the small business market. Before co-founding Cynch in 2018, Susie's previous roles included Head of Cyber Security Business Services at Australia Post.

Links:

Susie LinkedIn

Cynch Security website

Cynch Twitter

Cynch LinkedIn

For the full episode transcript, please see our website.

The Security Collective podcast is proudly brought to you in partnership with LastPass, the leading password manager.

Season 10 preview20 Jun 202200:01:21

We are thrilled to be bringing you Season 10 of The Security Collective podcast, with the first episode out this Thursday 23 June.  Take a listen for a preview of what is to come this season.

The Security Collective podcast is proudly brought to you in partnership with LastPass, the leading password manager.

In Case You Missed It - Season 9 mashup04 May 202200:14:20

This season on The Security Collective podcast we have invited guests to speak specifically about how we can change the behaviours of our staff when it comes to their cybersecurity habits and actions.

This is a mashup episode where Claire wanted to cover some really important points that some of the guests made, and encourage you to go back and listen to the full episodes if you find these nuggets of gold to be incredibly interesting, and you want to hear what else these guests had to say.

Quick link to guest episode:

Christie Wilson

Susan McLean

Erica Hardinge

Amy Ertan

Olivia Grandjean-Thompsen

For this full episode transcript, please visit our website

94. The role of technology in cyber culture change with Chris McNaughton27 Apr 202200:19:39

Closing out the theme of this season Claire is joined by Chris McNaughton and they discuss how data protection and security awareness are linked, the challenges of insider threat, and how leaders across your business can promote more secure behaviours.

Chris is a Director of SECMON1. Chris’ career commenced in law enforcement, where he was a recognised expert in digital forensics and management of electronic evidence. Moving into the corporate world in 2007, Chris accepted a global role with General Electric (GE) Capital where he was responsible for electronic discovery, digital forensics and investigations. In his position at GE, Chris implemented and managed a number of e-discovery platforms for GE Capital as well as reviewing and improving the Corporate e-discovery platform. In his current role Chris provides advisory services to Government and corporate clients in the cyber security areas of Insider Risk, Data Analytics, Digital Forensics and Workplace Investigations.

Chris LinkedIn

For full episode transcript, please visit our website

This season we have partnered with Lastpass -the leading password manager – and we are discussing behaviour and influence when it comes to cybersecurity.

93. Empowering the Board with Ian Yip20 Apr 202200:23:52

Claire is joined by Ian Yip, Founder and CEO of Avertro, the cyber-why company. They discuss cyber culture at the board level and talk about the impact of security leadership on the culture within cyber teams. Ian talks about the value of using the business's language in your cybersecurity discussions at the board level, and about bringing meaningful information to directors and doing so proactively. They also discuss that you have to rock the boat sometimes to make real change and the burnout that can come from this.

Avertro is a venture-backed cybersecurity software company based out of Sydney, Australia. Ian has two decades of cybersecurity experience in a variety of leadership, advisory, strategy, sales, marketing, product management and technical roles across Asia Pacific and Europe in some of the world’s leading companies including McAfee, Ernst & Young, and IBM.

Links:

Ian LinkedIn

Ian Twitter

Avertro Website

Avertro Twitter

For the full episode transcript please visit our website

This season we have partnered with Lastpass -the leading password manager – and we are discussing behaviour and influence when it comes to cybersecurity.

92. Cyber communications for the greater good with Olivia Grandjean-Thomsen13 Apr 202200:23:34

Olivia Grandjean-Thomsen is passionate about designing and implementing internal and external communication and stakeholder engagement strategies for the private, public and not-for-profit sectors. Olivia joins Claire and shares what good long-term communications planning can look like, how to measure cybersecurity communications programmes, and they talk about some of the grand scale comms activities Olivia has led.

Olivia currently works as the Head of Communication, Media, Events and Brand at Stone & Chalk Group, which includes AustCyber – an Industry Growth Centre aimed at driving innovation, productivity and competitiveness in the cyber security sector by focusing on areas of competitive strength and strategic priority. Previously, she was the Strategy Lead and Head of Content at My Health Record – a high profile digital transformation project at the Australian Digital Health Agency. She has worked as a Senior Communications Strategist at contentgroup, and for Global Access Partners – a public policy think-tank that initiates strategic discussions on pressing social, economic and structural issues to increase stakeholder participation in the development of government policy.

Links:

Olivia LinkedIn

Olivia Twitter

For the full episode transcript, please visit our website

This season we have partnered with Lastpass -the leading password manager – and we are discussing behaviour and influence when it comes to cybersecurity.

91. Communicating about Privacy (without the boring bits) with Kate Monckton06 Apr 202200:31:07

Claire talks with Kate Monckton, a Partner in Cyber Risk at Deloitte, about the difference between cyber and privacy, and why we should never apologise for cyber or privacy being boring.

Kate joined Deloitte in February 2022 as a Partner in Cyber Risk. Prior to this she spent over ten years as part of the Security Senior Leadership team at nbn. Before joining nbn, Kate held security roles at Symantec and Microsoft both in Australia and the UK. In December 2021 she was named 'Australia's Most Outstanding Woman in IT Security' at the Australian Women in Security Awards. Kate was a member of the Board of the International Association of Privacy Professionals ANZ for five years, including two as the President. She is also a co-founder of the Security Influence and Trust (SIT) Group.

Links:

Kate LinkedIn

IDCARE website

For the full episode transcript, please visit our website.

This season we have partnered with Lastpass -the leading password manager – and we are discussing behaviour and influence when it comes to cybersecurity.

90. The impact of COVID on cyber engagement with Amy Ertan30 Mar 202200:29:25

In Claire’s chat with Cyber Security Fellow Amy Ertan, whose research focus is on the security implications of emerging technologies as well as themes relating to the human aspects of cybersecurity, they talk about her recent findings post COVID lockdowns.

Amy shares the impact of COVID on security behaviours and her research into how psychological safety, company loyalty and culture all play a part. They talk about whether phishing exercises work, and who Amy believes is doing security influence well. Amy's commitment to cyber through her studies and what she gives back to the industry is commendable.

Amy Ertan is a Cybersecurity Fellow at the Harvard Kennedy School’s Belfer Center for Science and International Affairs, an Information Security Doctoral Candidate at Royal Holloway, University of London, and a Visiting Researcher at the NATO Cooperative Cyber Defence Centre of Excellence. Her research interests focus on the security implications of emerging technologies as well as themes relating to the human aspects of cybersecurity. Amy has published UK government-affiliated reports on organisational cybersecurity behaviours, engaging C-suite colleagues with cyber risk management themes, and on the impact of pandemic-driven remote working in organisations. She holds CISSP and CREST Threat Intelligence qualifications and has previously worked in roles in areas including cyber intelligence, strategy and policy research, cyber wargame design and execution, and security risk management.

Links:

Amy LinkedIn

Amy Twitter

Amy website

For the full episode transcript - please visit our website

This season we have partnered with Lastpass -the leading password manager – and we are discussing behaviour and influence when it comes to cybersecurity.

111. Modernising compliance with Paul Wenham14 Dec 202200:25:36

Paul Wenham joined Claire to talk about the what, how, and why he started Assurance Lab. They also cover the value of auditing, how compliance can be the foundation stone for startups and his new book, which he is making open source for others to contribute to; and talked about the fact that Assurance Lab is a B Corp, and why that is so important to Paul and his team.

Paul has worked in cybersecurity audits and compliance for over 11 years. His past roles have spanned professional services at PwC, leading the cybersecurity and compliance program for a global software company Qstream, and governance over third-party cyber standards at Westpac and Mercer.

Paul founded Assurance Lab in 2018, a Regtech software and audit services firm now working with over 150 cloud software companies across 12 countries. AssuranceLab supports their security and compliance programs to meet global standards (SOC 1, SOC 2, ISO 27001, HIPAA, Consumer Data Right, CSA STAR, GDPR, CCPA, and ESG reporting). Assurance Lab has a broad network of partners in the cybersecurity industry, leveraging the natural synergies of AssuranceLab's independence as an audit firm.

Links:

Website
Assurance Lab Linkedin
Paul LinkedIn

Episode 102. Cyber in Local Government with Paul Barrett

For the full episode transcript, please visit our website.

The Security Collective podcast is proudly brought to you in partnership with LastPass, the leading password manager.

© My Podcast Data