The Virtual CISO Podcast is a frank discussion that provides the very best information security advice and insights for Security, IT and Business leaders. If you’re looking for the latest strategies, tips, and trends from seasoned information security practitioners, want no-B.S. answers to your biggest security questions, need a perspective on how your peers are addressing the same issues, or just simply want to stay informed and proactive, welcome to the show.Our moderator, John Verry, chats with industry thought leaders to ensure you have what you need to be confident in your security and compliance. John will keep you informed, and perhaps even mildly entertained through topics like ISO 27001, breach avoidance, incident response, dealing with pesky security questionnaires, data privacy, and managing vendor risk.Think of it as security… with a smile.
In this episode of The Virtual CISO Podcast, your host, John Verry, engages in a conversation with Aviv Grafi, CTO and founder of Votiro, as they discuss innovative solutions to combat business email compromise. Join us as we discuss:
* The mechanisms of business email compromise
* How malicious files are used in cyberattacks
* The limitations of traditional security methods
* The benefits of malicious file reconstruction technology
And more! If you want to learn more about cybersecurity, follow The Virtual CISO Podcast on your favorite streaming platforms and subscribe to the Virtual CISO Podcast. For updates on cybersecurity, digital technology, and more, follow us on LinkedIn:https://www.linkedin.com/company/pivot-point-security/
Join us for an engaging episode of the Virtual CISO Podcast with host John Verry. This episode features Chris Petersen, co-founder of LogRhythm and current CEO of Radical. Chris brings over two decades of experience in cybersecurity, offering deep insights into the industry's challenges and advancements. In this episode, we'll explore:
If you want to learn more about cybersecurity, follow The Virtual CISO Podcast on your favorite streaming platforms and subscribe to the Virtual CISO Podcast. For updates on the state of cybersecurity, digital technology, and more, follow us on LinkedIn, https://www.linkedin.com/company/pivot-point-security/
Join us for an engaging episode of the Virtual CISO Podcast with host John Verry. This episode features Kevin Dinino, President of KCD PR, who delves into the critical aspects of crisis management and communications. Kevin brings over 20 years of experience in guiding companies through the complexities of strategic communications, particularly in the cybersecurity, financial, and technology sectors. In this episode, we'll explore:
If you want to learn more about cybersecurity, follow The Virtual CISO Podcast on your favorite streaming platforms and subscribe to the Virtual CISO Podcast. For updates on the state of cybersecurity, digital technology, and more, follow us on LinkedIn, / pivot-point-security .
In this episode of The Virtual CISO Podcast, your host, John Verry, engages in a conversation with guest Zenobia Godschalk, Senior Vice President of Hedera Hashgraph, as they discuss distributed ledger technology and its effects on privacy compliance.
Join us as we discuss the following:
* The erosion of Privacy Online
Distributed Ledger Technology (DLT) and how it enables Web 3
How DLT can be used to improve security and compliance with Privacy regulations
If you want to learn more about cybersecurity, follow The Virtual CISO Podcast on your favorite streaming platforms and subscribe to the Virtual CISO Podcast.
For updates on the state of cybersecurity, digital technology, and more, follow us on LinkedIn: https://www.linkedin.com/company/pivot-point-security/
In this episode of The Virtual CISO Podcast, your host, John Verry, engages in a conversation with guest Shauli Rozen, CEO and Co-Founder of ARMO, exploring the intricacies of Kubernetes, the orchestration tool that's reshaping how we deploy, scale, and manage containerized applications.
Join us as we discuss:
* What a container is
* Implications of containers on security
* How you can leverage Kubescape to improve application security
* And more!
If you want to learn more about cybersecurity, follow The Virtual CISO Podcast on your favorite streaming platforms and subscribe to the Virtual CISO Podcast.
For updates on the state of cybersecurity, digital technology, and more, follow us on LinkedIn, https://www.linkedin.com/company/pivot-point-security/
In this episode of The Virtual CISO Podcast, your host, John Verry, sits down with Andrew Frost and Leigh Ronczka of CBIZ Pivot Point Security to discuss the updates needed to successfully transition from ISO27001:2013 to ISO 27001:2022.
Join us as we discuss:
* How simplistic it is for a company to transition to ISO 27001:2022
* The level of effort required to implement the changes
* What auditors are looking for when organizations make an update
* And more!
If you want to learn more about the realm of cybersecurity, follow The Virtual CISO Podcast on your favorite streaming platforms and subscribe to the Virtual CISO Podcast.
For updates on the state of cybersecurity, digital technology, and more, follow us on LinkedIn, https://www.linkedin.com/company/pivot-point-security/
Tune into an insightful conversation with Jeremy Price, co-leader of a national cybersecurity practice. In this engaging discussion, Jermey explains the updated FTC safeguard rules that went into effect in June and what they’re intended to do. In this episode, your host, John Verry, and Jeremy Price discuss: - The Gramm Leach Bliley Act updates and how that affects financial institutions, and companies that offer things like consumer financial products and services - The extended and new definition of financial institutions - How to determine whether or not your company falls under the new definition of financial institutions and what that means for your business - And more!
Join us for an insightful conversation with Patricia Thaine, Founder and CEO of Private AI, as we delve into the world of artificial intelligence, language models, and data privacy. In this engaging discussion, Patricia sheds light on the transformative potential of AI, particularly language models like GPT-3.5, in various industries.
In this episode, your host, John Verry, and Patricia Thaine discuss:
* how specialized AI models are revolutionizing tasks such as sentiment analysis and personal information identification, all while ensuring data remains private and secure.
* responsible AI practices and preparing the next generation to harness AI's power responsibly.
* the potential of AI and the ethical considerations that accompany it.
* And more!
If you want to learn more about the realm of cybersecurity, follow The Virtual CISO Podcast on your favorite streaming platforms!
For weekly updates on the state of cybersecurity, digital technology, and more, follow us on LinkedIn, @pivot-point-security.
In this episode of the "Virtual CISO Podcast," your host John Verry speaks with guest Warren Hylton, a FedRisk consultant at CBIZ Pivot Point Security, to explore recent updates in cybersecurity regulations. The conversation revolves around the Cybersecurity Maturity Model Certification (CMMC) and the updated NIST Special Publication 800-171 (R2 to R3).
Join us in this week’s episode as we discuss
* The potential outcomes of the DOD’s rules package submission to OMB
* NIST 800-171's Revision 3 updates
* The transition from DoD-led to commercial-led assessments regarding CMMC
* And more!
To hear this episode and many more like it, we encourage you to subscribe to the Virtual CISO Podcast.
Just search for The Virtual CISO Podcast in your favorite podcast player or watch the Podcast on YouTube here.
To stay updated with the newest podcast releases, follow us on LinkedIn here.
Like many other businesses, law firms are at significant risk of cyber-attack and increasingly are turning to cyber liability insurance (CLI) to transfer some of their cyber risk. But many are being denied coverage or face high premiums due to shortfalls in their cybersecurity controls.
In this episode, your host John Verry, CBIZ Pivot Point Security Managing Director, sits down with Jack Liljeberg, Assistant Broker at Thompson Flanagan. Jack helps give business and security leaders in the legal vertical, as well as anyone seeking CLI coverage, a comprehensive update on the state of the CLI marketplace and critical issues to be aware of.
In this episode, join us as we discuss:
· Whether CLI premiums still increasingly rapidly or have stabilized
· Most critical information security controls that businesses need to obtain CLI coverage or avoid onerous premiums
· The importance of honesty, accuracy, and plenty of detail in CLI applications
· Exemptions and other issues to watch out for in CLI policies
· Other insurance coverage types that can bridge gaps in a firm’s CLI coverage
To hear this episode and many more like it, we encourage you to subscribe to the Virtual CISO Podcast.
Just search for The Virtual CISO Podcast in your favorite podcast player or watch the Podcast on YouTube here.
To stay updated with the newest podcast releases, follow us on LinkedIn here.
To do wide-scale business within the US federal government, cloud service providers (CSPs) need a FedRAMP ATO. The prospect can be daunting as few CSPs have federal cyber compliance expertise. Misconceptions and misinformation can create additional roadblocks.
In this episode, your host John Verry, CBIZ Pivot Point Security Managing Director , sits down with Mike Craig, CEO at Vanaheim Security, who gives clear guidance with business and security leaders on what it takes to get a FedRAMP ATO, including best practices and common mistakes.
In this episode, join us as we discuss:
• Key considerations to help decide if a FedRAMP ATO is worth pursuing
• How long a FedRAMP ATO really takes, how much it really costs, and why
• The three stages of the FedRAMP journey
• Key participants in the FedRAMP “dance” and how they relate
• Huge pros and cons of an agency sponsorship versus the JAB authorization path to a FedRAMP ATO
To hear this episode and many more like it, we encourage you to subscribe to the Virtual CISO Podcast.
Just search for The Virtual CISO Podcast in your favorite podcast player or watch the Podcast on YouTube here.
To stay updated with the newest podcast releases, follow us on LinkedIn here.
Whatever kind of software application a team is building, the identification and remediation of cybersecurity issues needs to be part of every stage of the software development lifecycle (SDLC). But making that happen takes a wealth of skills and approaches, as well as an eye on compliance and the ability to keep pace with the ever-changing online environment—microservices being a prime example.
In this episode, your host John Verry, Pivot Point Security CISO and Managing Partner, sits down with Laura Bell Main, CEO and Founder of SafeStack to give business and security leaders a clear and logical overview of microservice security issues and more.
In this episode, join us as we discuss:
• What constitutes a microservice architecture and how it relates to other design approaches, languages, and frameworks
• The microservice software supply chain and the limitations of a Software Bill of Materials in a microservices context
• How using microservices changes the approach of securing an application
• How zero trust concepts relate to microservice architectures
• How SafeStack is helping to educate developers about application security in organizations of all sizes
To hear this episode and many more like it, we encourage you to subscribe to the Virtual CISO Podcast.
Just search for The Virtual CISO Podcast in your favorite podcast player or watch the Podcast on YouTube here.
To stay updated with the newest podcast releases, follow us on LinkedIn here.
If you are ISO 27001 certified, or considering it, you are likely wondering how the transition from ISO 27001:2013 to ISO 27001:2022 affects you. With the notable changes, there are many uncertainties. For example, how soon can you get certified to ISO 27001:2022? Can you still get certified to 27001:2013? For anyone already certified, how soon can they transition to ISO 27001:2022?
In this episode, your host John Verry, Pivot Point Security CISO and Managing Partner, sits down with Andrew Frost, GRC Advisory Consultant at Pivot Point Security to explore the most effective and simplest practices for making the transition from ISO 27001:2013 to ISO 27001:2022.
In this episode, join us as we discuss:
• An overview of what changed and why from ISO 27001:2013 to ISO 27001:2022
• Timelines for certification to the new standard, including why it might be advisable to delay an ISO 27001:2022 certification audit until 2024
• The level of effort required for the transition to ISO 27001:2022
• Guidance on how to plan and execute the transition to ISO 27001:2022
• How auditors might use the new #hashtags in ISO 27001:2022
To hear this episode and many more like it, we encourage you to subscribe to the Virtual CISO Podcast.
Just search for The Virtual CISO Podcast in your favorite podcast player or watch the Podcast on YouTube here.
To stay updated with the newest podcast releases, follow us on LinkedIn here.
In this week's episode of the Virtual CISO podcast, your host John Verry, Pivot Point Security CISO and Managing Partner, shares his valuable insights from the 2023 RSA conference. As the security industry evolves, with an increasing number of vendors and products, John advises against adopting a product-based security strategy. Instead, he recommends having a clear plan to address specific security challenges.
Tune in to this episode to learn John's eight key takeaways, the latest developments from the 2023 RSA conference, and gain valuable insights to enhance your organization's security posture.
In this episode join us as we discuss:
· Privacy will drive data governance
· Data security posture management
· Zero trust: a model rather than a product
· AppSec and API security
· 90-day TLS certificates
To hear this episode and many more like it, we encourage you to subscribe to the Virtual CISO Podcast.
Just search for The Virtual CISO Podcast in your favorite podcast player or watch the Podcast on YouTube here.
To stay updated with the newest podcast releases, follow us on LinkedIn here.
With the release of President Biden’s Executive Order 14028 on “Improving the Nation’s Cybersecurity” from May 2021 the US public and private sectors have been alerted to the significant cybersecurity risks within our software supply chain. As of the March 2023 release of the National Cybersecurity Strategy, which will shift liability for software products and services to promote secure development practices, it’s evident that software security needs to be elevated across all organizations.
In this episode, your host John Verry, Pivot Point Security CISO and Managing Partner, sits down with Tim Mackey, Head of Software Supply Chain Risk Strategy at Synopsys, to explore what better software supply chain security means for software development and more.
In this episode, join us as we discuss:
· Defining an SBOM what it can include depending on stakeholder needs
· The value of SBOMs for both software developers and their clients
· Market drivers for improved software supply chain security
· Software composition analysis and its role in mapping dependencies and identifying vulnerabilities within code
· How the NIST Secure Software Development Framework (SSDF) supports initiatives to improve software supply security
To hear this episode and many more like it, we encourage you to subscribe to the Virtual CISO Podcast.
Just search for The Virtual CISO Podcast in your favorite podcast player or watch the Podcast on YouTube here.
To stay updated with the newest podcast releases, follow us on LinkedIn here.
Asset management is a crucial aspect of information security. It refers to the processes and procedures involved in identifying, organizing, tracking, and protecting an organization's assets. The security of these assets is paramount, as you can’t protect what you don’t know about.
To learn more about how to Fix Cyber Asset Management, your host John Verry, sits down with Huxley Barbee, Security Evangelist at runZero, to discuss the importance of Asset Management, how it’s a critical component of any organization's security strategy and much more.
In this episode, Join us as we discuss the following:
• Definition of an asset—the answer is surprising
• Top reasons why so many orgs are failing Asset Management 101
• Critical innovations of a modern asset management solution
• Asset management in the cloud and what teams really need to focus on
• How asset management failures killed Equifax
To hear this episode and many more like it, we encourage you to subscribe to the Virtual CISO Podcast.
Just search for The Virtual CISO Podcast in your favorite podcast player or watch the Podcast on YouTube here.
To stay updated with the newest podcast releases, follow us on LinkedIn here.
DevSecOps is the practice of integrating security testing at every stage of the software development process. With DevSecOps, training and educating all teams in risk, security, and mitigation at all stages of development is a top priority– traditionally, app developers don't pay much attention to security, which increases the risk of vulnerable code being deployed and the application being compromised.
To learn more about DevSecOps in this episode, your host John Verry, sits down with André Keartland, Solutions Architect with Netsurit Professional Services, to discuss tactical steps to implement DevSecOps in 2023.
In this episode, Join us as we discuss the following:
• What is DevSecOps and how does it differ from DevOps?
• Getting business stakeholder buy-in for application security
• The best way to get started with DevSecOps
• Who in your org needs application security training and why
• How to assess application risk and why it’s so important
To hear this episode and many more like it, we encourage you to subscribe to the Virtual CISO Podcast.
Just search for The Virtual CISO Podcast in your favorite podcast player or watch the Podcast on YouTube here.
To stay updated with the newest podcast releases, follow us on LinkedIn here.
Microsoft 365 was launched in 2011 in hopes of revolutionizing cloud-powered productivity platforms. Since then, Microsoft 365 has grown to the point where it is now one of the largest cloud-powered productivity platforms on the market, competing with the likes of Google and more.
To give organizations a clear picture of their Microsoft 365 options, your host John Verry sits down with Conrad Agramont, CEO of Agile IT, a top Microsoft Cloud Service Provider focusing on Microsoft 365, to discuss Microsoft Government Community Cloud (GCC), GCC High, and more.
In this episode, Join us as we discuss the following:
• How the three Microsoft 365 clouds differ in terms of key security capabilities
• The importance of communicating with your government program office about the cybersecurity requirements in your contract
• What migration from commercial Microsoft 365 to a "gov cloud" can look like in terms of time, cost, and effort
• The two most challenging aspects of any Microsoft 365 migration
• Pros and cons of a "hybrid approach" involving multiple Microsoft 365 environments
To hear this episode and many more like it, we encourage you to subscribe to the Virtual CISO Podcast. Just search for The Virtual CISO Podcast in your favorite podcast player or watch the Podcast on YouTube here.
To stay updated with the newest podcast releases, follow us on LinkedIn here.
ISO 27001:2022 is the first update to the global "gold standard" for provable cybersecurity in ten years. Notable changes from the 2013 version will likely significantly impact most organizations' Information Security Management Systems (ISMS).
In this episode, your host John Verry sits down with Ryan Mackie and Danny Manimbo from Schellman & Co. to explain the most significant changes in ISO 27001:2022 and their potential impacts.
Join us as we discuss the following:
* How to determine the optimal timeline to migrate your ISMS from 27001:2013 to ISO 27001:2022
* Top areas that auditors will focus on during your transition audit
* How moving to the new ISO 27001:2022 can benefit your cybersecurity program (and your marketing)
* The critical importance of risk assessment/risk management for ISO 27001:2022 certification
* The "ripple effect" of ISO 27001:2022 changes on related standards like ISO 27017, ISO 27701, and CSA STARS
To hear this episode and many more like it, we encourage you to subscribe to the Virtual CISO Podcast on YouTube here.
To stay updated with the newest podcast releases, follow us on LinkedIn here.
Listening on a desktop & can't see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.
The “buzz” in building more secure applications is “shift security left,” which means integrating security into and throughout the Software Development Lifecycle (SDLC).
The Software Assurance Maturity Model (SAMM) is an excellent tool from OWASP that provides a framework for assessing and improving your development processes, resulting in more secure applications. In this episode, your host, John Verry, CISO and Managing Partner at Pivot Point Security, sits down with Sebastien Deleersnyder, co-lead of the OWASP SAMM project, to discuss in depth how you can use SAMM to improve your application security program.
Join us as we discuss the following:
● The biggest challenge teams face in developing secure applications
● Using OWASP SAMM to assess your current security process
● Where most orgs really are today in terms of AppSec
● Identifying quick wins to improve web app security
● Leveraging SAMM alongside other security frameworks like NIST 800-218 and ISO 27001
To hear this episode and many more like it, we encourage you to subscribe to the Virtual CISO Podcast on our YouTubehere.
To Stay up to date with the newest podcast releases, follow us on LinkedInhere.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.
Trusted Information Security Assessment Exchange (TISAX) is a vendor due diligence standard used in the automotive industry to verify that third-party suppliers’ cybersecurity programs provide adequate protection for the information the automotive supplier shares.
In this episode, your host John Verry, CISO and Managing Partner at Pivot Point Security, sits down with Ed Chandler, Account Executive and Cybersecurity lead for TÜV SÜD America, who provides answers and explanations to what TISAX is, how it operates, and helps you better understand the implications surrounding it.
Join us as we discuss:
• Where did TISAX come from, why does it exist, and why is it increasingly important worldwide?
• Why so many North American firms are now facing TISAX requirements
• How the TISAX assessment/audit process works
• TISAX assessment objectives and assessment levels
• How aligning your org with comprehensive cybersecurity standards like ISO 27001 can also help with TISAX
To hear this episode, and many more like it, we would encourage you to subscribe to the Virtual CISO Podcast on our YouTube here.
To Stay up to date with the newest podcast releases, follow us on LinkedIn here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.
In today’s cyber landscape, business leaders and security professionals need every edge they can gain to better protect their organizations and plan their defense against attackers. . Why do hackers do what they do? What are they trying to steal from you? Who do they partner with to make money and avoid getting caught?
In this episode, hosted by John Verry, CISO and Managing Partner at Pivot Point Security, sits down with Raveed Laeb, Vice President of Product for KELA, who provides answers and explanations to explain the cybercrime business models, supply chains, and operational strategies.
Join us as we discuss:
· How understanding your financially motivated adversaries can directly benefit your cybersecurity posture, incident response, and executive decision-making
· “Business models” and “supply chains” that hackers use to monetize your assets (which can be a lot more than just your data)
· What you need to hear to dispel any lingering notion that your org has nothing hackers want
· How and why bad actors are increasingly specializing based on skill sets, and where and how they choose their business partners
· How forward-looking businesses are using cyber threat intelligence (CTI) to reduce cyber riskTo hear this episode, and many more like it, we would encourage you to follow the Virtual CISO Podcast here.
You can find all our full length and short form video episodes on our YouTube here.
To Stay up to date with the newest podcast releases, follow us on LinkedIn here.
Listening on a desktop & can't see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.
Orgs in the DIB need to protect CUI in alignment with the NIST 800-171 cybersecurity standard—and soon the Cybersecurity Maturity Model Certification (CMMC) requirements—or face legal and compliance penalties as well as potential lost business. To clarify the biggest questions and reveal the most dangerous unknowns in the convoluted realm of CUI, your host John Verry, Pivot Point Security CISO and Managing Partner, sits down with Stephanie Siegmann, Partner and Chair at Hinckley Allen to share her knowledge on the subject.
Join us as we discuss:
· The difference between CUI Basic and CUI Specified
· Criminal penalties for “export controlled” CUI violations that will probably shock you
· Sound advice on handling data subject to ITAR, NOFORM and other regulations
· How to get your CUI questions answered—and what to do if you’re still not sure
· The US Department of Justice Civil Cyber Fraud initiative, the False Claims Act, and why you don’t want to fire the whistleblower
To hear this episode, and many more like it, we would encourage you to subscribe to The Virtual CISO Podcast here.
You can find all our full length and short form episodes here.
Listening on a desktop & can't see the links? Just search for The Virtual CISO Podcast in your favorite podcast playerVCISO YouTube
Over 90% of security breaches in the public cloud stem from user error, and not the cloud service provider. Today, your host John Verry sat down with one of Amazon Web Services (AWS) own Temi Adebambo, to understand what is going wrong with public cloud security, and how you can eliminate your biggest risks. This episode features Temi Adebambo, Head of Security Solutions Architecture at Amazon Web Services (AWS), to explain exactly what’s going wrong with public cloud security, how users can eliminate their biggest risks, and much more.
Join us as we discuss:
• The 2 mistakes public cloud users make that cause the most security breaches
• How using “higher-level” services can reduce your security burden
• Ideas for baking security into your DevOps pipeline
• The critical importance of “guardrails” for your team and how to implement them
• The top AWS security tools all users should leverage
To hear this episode, and many more like it, we would encourage you to subscribe to The Virtual CISO Podcast here.
You can find all our full length and short form episodes here.
Listening on a desktop & can't see the links? Just search for The Virtual CISO Podcast in your favorite podcast playerhttps://www.pivotpointsecurity.com/
Managing Cybersecurity through an Economic downturn is no easy task. With increasing concerns on how to stay secure and compliant in a down economy, John Verry tackles this podcast himself giving you his ten best fundamental practices.
This episode features your host John Verry, CISO & Managing Partner, from Pivot Point Security, who provides answers and explanations to a variety of questions regarding how to stay compliant, secure, and budget in a down economy.
Join us as we discuss:
· How to be Strategic in a Down Economy
· How to leverage automation
· How to get more from your vendors
· Which security investments to maintain and eliminate
To hear this episode, and many more like it, we would encourage you to subscribe to The Virtual CISO Podcast here.
You can find all our full length and short form episodes here.
Listening on a desktop & can't see the links? Just search for The Virtual CISO Podcast in your favorite podcast player
Building Cloud Native Applications can bring about many operational and security problems. Today, we sat down with an expert in this field to talk about building cloud native applications, and deploying applications that are secure in the cloud.
This episode features Fausto Lendeborg, Co-Founder & CCO, from Secberus, who provides answers and explanations to a variety of questions regarding Building applications in the cloud, deploying applications securely in the cloud, and much more.
Join us as we discuss:
· Building Cloud Native Applications
· Deploying Applications Securely
· Managing a Cloud
· Security, Compliance, and Governance
· DevOps
To hear this episode, and many more like it, we would encourage you to subscribe to The Virtual CISO Podcast here.
You can find all our full length and short form episodes here.
Listening on a desktop & can't see the links? Just search for The Virtual CISO Podcast in your favorite podcast playerhttps://www.pivotpointsecurity.com/
Digital Business Risk Management helps companies track and disrupt the most advanced bad actors. Team Crymu specializes in Digital Business Risk Management & Attack Surface Management, giving clients insight and help relating to cyber threats.
This episode features David Monnier, Chief Evangelist and Team Cymru Fellow, from Team Cymru, who provides answers and explanations to a variety of questions regarding Business Risk Management, ASM (attack surface management), and much more.
Join us as we discuss:
● Attack Surface Management
● Digital Business Risk Management
● Electronic Assets
● Data Breaches/Exposures
● Discovering malevolent infrastructures
To hear this episode, and many more like it, we would encourage you to subscribe to The Virtual CISO Podcast here.
You can find all our full length and short form episodes here.
Listening on a desktop & can't see the links? Just search for The Virtual CISO Podcast in your favorite podcast player
Governance, Risk, and Compliance (GRC) platforms can be tricky to construct.
Today, we sat down with an expert in this field to talk about building and deploying secure applications in the cloud.
This episode features Jeff Schlauder, Information Security Executive, from Catalina Worldwide, who provides answers and explanations to a variety of questions regarding deploying applications securely in the cloud, using AWS (amazon web services), and much more.
Join us as we discuss:
· Building and deploying secure applications in the cloud
· The Logistics of Web Applications
· Building, operating, and maintaining secure Cloud applications
· Containerized vs Not-containerized applications
· How to keep applications deployed secure
To hear this episode, and many more like it, we would encourage you to subscribe to The Virtual CISO Podcast here.
You can find all our full length and short form episodes here .
Listening on a desktop & can't see the links? Just search for The Virtual CISO Podcast in your favorite podcast player
You cannot have privacy without security.
While they once existed quite distinct from one another, they are now so delicately woven that they are nearly indistinguishable.
Over time, the GDPR has cemented the relationship between physical security and information security, and now, it’s incorporating data privacy.
This compliance triad has become the new normal for businesses everywhere– but what does it mean?
Rosemary Martorana, Chief Privacy Officer at Corning, joined me to discuss the blurring line between privacy and security and why compliance may be more approachable than you thought.
A critical key to fostering a compliant security culture and enabling compliance is transparency.
Transparency does a few things for your business & security:
Increases trust
Decreases DSRs
Limits phishing attempts
Decreases likelihood of breaches
Follow the link below or find The Virtual CISO Podcast on your favorite streaming service to learn more about what compliance, information security, and data protection means for your business.
CMMC (Cybersecurity Maturity Model Certification) can raise many red flags and concerns - As CMMC rulemaking approaches in 2023, we take a break
from our normal podcast and answer the most asked CMMC questions to date to help ease the unknown.
This episode features George Perezdiaz, FedRisk Practice Lead, with Pivot Point
Security, who provides answers and explanations to a variety of questions we have received regarding CMMC. George is extremely knowledgeable on CMMC topics while being one of the top industry experts on the topic. During this episode, he helps answer our top 20 most asked questions regarding dates for rulemaking, achieving compliance for the DIB (Defense Industrial Base), the cost to become CMMC certified, and much more hopefully providing a path for those who need it.
Join us as we discuss:
· When CMMCV2 will become effective
· Who needs to be CMMC certified
· Can a small business affordably achieve CMC compliance
· CMMC Level 2 and 3 requirements
· And much more!+
To hear this episode, and many more like it, we would encourage you to subscribe to The Virtual CISO Podcast here.
You can find all our full length and short form episodes here .
Listening on a desktop & can't see the links? Just search for The Virtual CISO Podcast in your favorite podcast player
This marks our 100th episode of The Virtual CISO and an insightful journey into having the opportunity to have frank discussions with thought leaders that provide the very best information security advice and insights.
I am happy to have invited Dimitri Sirota, CEO & CoFounder of BigID, to walk through BigID’s approach to privacy, security, and data governance on this momentous episodic occasion.
Join us as we discuss:
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player
Supply chain risk management can prove to be a slippery slope—why should you take pains to conduct a proper risk assessment, and how do they impact IT and business continuity?
From international restrictions to balancing generic and specific risk assessments, any guidance is welcome in the world of supply chain management.
I invited Willy Fabritius, Global Head of Strategy & Business Development, Information Security Assurance at SGS, onto the show to provide insights into supply chain risk management. Including definitions, best practices, and where to turn for guidance.
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player
What are the merits of the Software Assurance Maturity Model (SAMM), and how does it differ from the Application Security Verification Standard (ASVS) model? And why should you care?
From design to operations, there are several crucial considerations to hold regarding business functions and use cases.
I invited Taylor Smith, Application Penetration Testing Lead at Pivot Point Security, onto the show to provide insights into SAMM. Including definitions, the differences between SAMM, ASVS, and BSIMM, and how these models are relevant in today’s software development environment.
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player
Application development is moving from a web-centric world to an API-centric world. If you’re wondering what that looks like, what the security implications are and what an API is, you’re in the right place.
There is no shortage of new application security strategies to familiarize ourselves with as cybersecurity adapts to changing times.
That’s why I invited Rob Dickinson, CTO at Resurface Labs, to explain APIs, continuous API operation observability, and prevalent challenges in the API economy.
Join us as we discuss:
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player
Most recognize the value preservation in cybersecurity. But forward thinking professionals also see the value creation in having a secure information posture.
Cybersecurity is the foundation of preserving sensitive data and providing peace of mind but does it create value for the organization and if so, how do we measure that value?
Tracking the return on investment on cyber security can be challenging. Much like auto insurance, you gain the most obvious value when something goes wrong—however, that doesn’t mean insurance isn’t valuable during smooth sailing.
I invited James Fair, Senior VP at Executech, to discuss the value of compliance, measuring ROSI, the Return on Security Investment, and budgetary considerations in cybersecurity.
Join us as we discuss:
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player
What exactly is a Software Development Life Cycle, and how does NIST’s Secure Software Development Framework impact that cycle and your organization?
Of note, the SSDF will definitely impact you if your software is used by the US Government and will likely impact you even if it isn’t. There are a few choice practices that can help make sense of these two critical processes and provide the highest chance for success.
I invited Elzar Camper, Director of Cyber Security Solutions & Practices at Pivot Point Security, onto the show to unpack SDLCs, the SSDF and lay out the shifting landscape of government regulations and software development.
Join us as we discuss:
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player
Today, information is worth more than riches. The new currency is data. With this being true, the state of cybersecurity within the upper branches of the government was shockingly under-prepared.
In this episode, I speak with Mark Montgomery, the former Executive Director of the Cyber Solarium Commission, about the report the commission published in March 2020 and how that document has influenced the US Government’s roadmap to improve cybersecurity, prevent cyber attacks, and protect the nation's data.
Join us as we discuss:
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.
Don’t wait for an emergency; secure your database correctly right out of the gate. Think of everything outside of your database as the wild west.
What can you do to create the most controlled environment possible for all of your most sensitive data?
I invited Robert Buda, President of Buda Consulting, Inc, and an expert in database technology, onto the show to help us learn the value of database security and what you can do today to improve your security measures.
Join us as we discuss:
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player
Ron Gula, President and Co-Founder of Gula Tech Adventures, has a very specific goal: To defend the country in cyberspace by investing in companies and nonprofits that help close the gap in technology and the workforce.
He also knows that in order to successfully achieve this goal, organizations must understand the basics of data protection.
Today, Ron joins the show to talk about the mindset shift that can start in the information security disciplines through communication.
Join us as we also discuss:
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.
There’s no denying that cybersecurity risks in the workplace have increased exponentially in recent years. From the pandemic causing employees to work from home to Russia’s invasion of Ukraine, organizations are more vulnerable than ever.
That’s why it’s crucial to understand how to best protect yourself and your business.
On this episode, Eric Jesse, Partner at Lowenstein Sandler LLP, joins the show to give an attorney's perspective on the importance of cyber liability insurance. Eric talks about protecting your company as a policyholder in today’s new landscape.
Join us as we discuss:
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.
To invest in CMMC or to not invest in CMMC, that is the question.
CMMC (Cybersecurity Maturity Model Certification) is a lofty yet necessary investment for the Defense Industrial Base. With all signs pointing to May 2023 for when we can expect CMMC to be included in contracts, anyone who is considering CMMC should do it sooner rather than later as implementing any comprehensive cyber security program could take a company 9 to 12 months.
On this episode, our host John Verry recaps his most important takeaways from the recent CMMC Day conference held in Washington DC on May 9, 2022.
Join us as we discuss:
Alberto Yépez joins the show to share his perspective as a venture capitalist working to help entrepreneurs build Cybersecurity businesses. He started his wildly successful career at Apple and he is now the Co-Founder and Managing Director at Forgepoint Capital.
Join us as we discuss:
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player
We’ve spent the last two and a half years with rapidly rising cloud adoption. It was a rocket ship before that, but the COVID-19 pandemic has only accelerated it and caused everybody to scramble.
We’re still trying to play catch up and get equivalent security treatments for people working remotely to the folks working in the office. Every client has concerns about their current exposure, which is why our guest on this episode of Virtual CISO is so important.
Michelangelo Sidagni is the Chief Technology Officer at NopSec, and he was on this episode to talk to us all about:
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player
As technology advances, there will always be new threats from malicious actors seeking to exploit these advancements — whether that be in the digital realm or physical.
With technologies increasingly blurring the lines between the two, today’s security professionals must adapt as the sectors of physical security and cyber security converge into one.
Today’s guest, Chris Ciabarra, Co-Founder and CTO of Athena Security, is one of the physical security experts leading the charge on this front and he joins the show to share his insights into the inevitable security convergence in our future.
Join us as we discuss:
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.
As the implementation of CMMC by the DIB picks up pace, the frequently shifting requirements can be daunting — especially when the guidance is already so complex.
And that’s doubly true for managed service providers (MSPs), who have to contend with some of the most confusing CUI requirements.
In today’s episode, making his 3rd guest appearance, I’m joined by Caleb Leidy, CUI Protection and CMMC Consultant at Pivot Point Security, who is here to clear up the confusion and share his insights into how the rollout of CMMC into the DIB impacts MSPs.
Join us as we discuss the current state of CUI for MSPs in the DIB, including:
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.
Inclusivity and diversity aren’t just about who you hire — it’s about the culture you create.
Sure, you can get talent from all walks of life, but if you haven’t built an inclusive culture…
Well, good luck getting them to stick around.
Today, I’m speaking with Deidre Diamond, Founder and CEO at CyberSN, who shares her 8-step framework for creating an inclusive culture in your organization.
Join us as we discuss each step and its importance, including:
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.
What if you could be proactive in your approach to cloud data security rather than a reactive one once the attack has been made?
This is exactly the solution our guest is providing at Panther Labs. We speak with Jack Naglieri, Founder & CEO, about the cloud-native approach and exactly why SIEMs are getting left behind.
Join us as we discuss:
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.
Even before the pandemic, the majority of businesses were already moving to the cloud.
Now, it seems you can’t do business without it.
Which means cloud security and compliance is more important than ever.
That’s why I’m speaking to one of the authorities on cloud security, John DiMaria, Assurance Investigatory Fellow at Cloud Security Alliance, in today’s episode — to demystify cloud security.
Join us as we discuss:
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.
CMMC has come a long way in recent years…
But organizations still face plenty of challenges navigating the guidance.
What are the biggest hurdles and how can we reduce the confusion?
To answer these questions, I’m joined by Kyle Lai, Founder and CISO of KLC Consulting, and Caleb Leidy, the CUI Protection and CMMC Consultant at Pivot Point Security.
Join us as we discuss:
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.
Open source is a transparency issue. Being able to see what code is running on your computer — as well as what’s being monitored — gives you practically SaaS-level visibility across data, apps, and usage.
In this episode, former open source developer Mike McNeil, CEO at Fleet Device Management, an open source company, talks with me about why open source is so imperative.
Join us as we discuss:
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Links here:
Mike McNeil, CEO at Fleet Device Management
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player
Traditionally, companies have relied on the promises of vendors when it comes to reaffirming their security stance.
However, LimaCharlie has a far more radical approach—provable security.
How are they doing it?
In this episode, Maxime Lamothe-Brassard, LimaCharlie’s founder, explains the “AWS approach” the company employs for cybersecurity and how being born in the cloud provides infinite scalability and enables them to deploy a wide range of security capabilities.
Join us as we discuss:
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player
After years, ISO 27002 is finally here.
What does that mean for your business?
Luckily, the transition should be pretty seamless…
But if you’re worried, have no fear because in today’s episode I’m joined by Danny Manimbo and Ryan Mackie, Company Principals at Schellman, who helped design the new standard.
Join us as we discuss:
What’s new with ISO 27002
What has stayed the same
The reasoning behind the update to the standard
The grace period for getting certified
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player
If you look around at what’s happening in the world of cybersecurity, you’ll notice one thing:
Security never stops…
Which means neither should compliance.
That’s why I invited Andrea Willis, Senior Product Manager at Exostar ,an expert in continuous compliance onto the show to help you figure out how to stay compliant.
Join us as we discuss:
-The importance of continuous compliance
-How CMMC 2.0 and continuous compliance interact
-How cybersecurity is like the immune system of your organization
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player
We’ve had another bumpy year in 2021. So, what’s coming down the pike in 2022? And what impact will the ongoing information security challenges of today have on the world of tomorrow?
In this episode, I answer those questions and more. Plus, I will assume the role of Nostradamus and make 8 information security predictions for 2022.
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.
NIST, ISO, CMMC…
If you’re beholden to government security guidance — and let’s face it, if you’re a company operating in the US, you very likely are — the list can be overwhelming at first.
So, it helps to look back on where we’ve been and how we got where we are today.
And in this solo episode, Our Host John Verry does exactly that — and hopefully, shine a light on what the guidance means and why you should care.
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.
You’ve probably heard the hype:
IoT is the next frontier in the information revolution that promises to make all our lives easier…
And that’s doubly true for hackers.
In this episode, I’m joined by Joe Grand, also known as Kingpin, a computer engineer, hardware hacker, product designer, teacher, advisor, daddy, honorary doctor, TV host, member of legendary hacker group L0pht Heavy Industries, proprietor of Grand Idea Studio (www.grandideastudio.com), and partner in offspec.io, a cryptocurrency wallet recovery service. He has been creating, exploring, and manipulating electronic systems since the 1980s and is hereto take a look at the vulnerabilities hackers exploit in IoT (and how you can defend against them).
Join us as we discuss:
Why, despite what many believe, hardware is no less vulnerable than software
The common vulnerabilities in IoT devices and what you can do about them
How security standards factor into IoT security
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.
There is an age-old conflict between security and development teams.
Development teams are focused on time-to-market and packing features into the product.
Security teams are often seen as speed bumps on the way to achieving those goals.
How can we bridge the gap between the two?
According to Harshil Parikh, CEO at Tromzo, new methodologies are presenting an incredible opportunity for security teams to get involved in the development process in a much more effective way.
Plus, there’s some exciting new software that is solving this challenge in interesting ways.
In this episode, we discuss:
Opportunities presented by agile development methodologies and DevSecOps
The root of the conflict between security and development
How to close the gaps between the two teams
How Tromso is solving the challenge through software
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.
What’s more secure? A cloud-based or on-prem document management system?
It’s a question that gets asked a lot in our industry.
So, I invited Mark Richman, Principal Product Manager at iManage, on to the show for a wide-ranging discussion on the topic.
In this episode, we discuss:
Why a SaaS-based document management system is more secure than on-prem
Implementing compensating controls to mitigate potential damages
iManage’s customer-managed encryption keys and threat manager
What a cloud provider should be doing from a security perspective
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.
Configuration management is the best kept secret in security.
Not only will it save time and money, it also helps you marry compliance and security — something we all need to get used to.
The question is: Why isn’t everyone using it?
Today’s guest, Brian Hajost, Founder and COO at SteelCloud, joins me on the show to give some compelling reasons why you should.
In this episode, we discuss:
What configuration management is
How it saves you time and effort
How it saves you money
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.
The US Department of Defense (DoD) has just announced CMMC 2.0, a new strategic direction for its cybersecurity program based on public comment and internal assessment. So what does it all mean?
Many sources say that CMMC 2.0 is about "less requirements,"—but it's really much more about changing how the DoD will hold defense contractors accountable to the NIST SP 800-171 requirements that have been in place all along.
We're speaking to two of our best Security Consultants from right here within our ranks at Pivot Point Security: George Perezdiaz, CMMC / NIST Security Consultant, and Caleb Leidy, CMMC Consultant/Provisional Assessor.
In this episode, we discuss:
What's new and what's not with CMMC Level 1 (for securing FCI) and what is now called CMMC Level 2 (for securing CUI)
The overall realignment of the US government's cybersecurity audit program with NIST 800-171
"Bifurcation" and who will and won't need a third-party audit if you handle CUI
How CMMC 2.0's new accountability process fits with the recent cybersecurity executive order, the Civil Cyber-Fraud Initiative, the False Claims Act, and upcoming rule changes to 32 CFR and 48 CFR
Why "letters of affirmation" are a boon to SMB security and IT leaders compared to the threat of a third-party audit
Mentioned during the podcast:
eCFR :: Home
To hear this episode and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don't use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can't see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.
A lot of people want to break into cybersecurity. And why not? Where else can you have a blast, work with really smart people, earn a great living, have awesome job security, and do something truly impactful for the company you work for.
However, it can be a particularly difficult industry to break into, especially if you don’t have the financial resources to pursue the education necessary to get hired.
Gerald Auger, Chief Content Creator at Simply Cyber, noticed this gap between the haves and the have nots and he’s been working hard to create a pool of resources that are accessible to anyone, anywhere, for free.
In this episode, we discuss:
Giving people access to a free cybersecurity education
The catch-22 of listing entry-level jobs that require 2-3 years of experience
Which cybersecurity roles serve as the best entry points into the industry
Where Simply Cyber will go over the next few years
Mentioned during the podcast:
Cybersecurity Career Master Plan
Simply Cyber YouTube Channel
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.
In a world where new vulnerabilities appear seemingly every minute, threat intelligence is more important than ever.
And one of the most intriguing approaches to threat intelligence is attack surface management.
To explain the ins and outs of attack surface management, I invited Steve Ginty, Director, Threat Intelligence at RiskIQ, onto the show. He shares the work RiskIQ is doing in the field and how it could benefit your organization.
In this episode, we discuss:
What attack surface management is and how RiskIQ can help
How RiskIQ can let you respond faster when new vulnerabilities arise
The importance of gaining visibility into not just your own attack surfaces, but those of your vendors
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.
As public trust in technology erodes — for the first time — it’s clear that we need to reevaluate our approaches to security and compliance.
The way we’ve been doing it is no longer working…
But continuous compliance might.
Today’s guest, Mosi Platt, Senior Security Governance, Risk, Compliance & Assurance Partner at Neflix, join s the show to explain why.
In this episode, we discuss:
The benefits of continuous compliance and what you need to know to implement it
The role continuous compliance can play in regaining trust
How continuous compliance factors into auditing
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.
When it comes to healthcare InfoSec, it’s the Wild West. Most healthcare organizations just don’t have the necessary IT budgets to make it a priority.
But it should be a priority. The truth is a large number of hospitals have been targeted by ransomware in the last few years.
Today’s guest, Hoala Greevy , Founder and CEO at Paubox , shares how his company is arming healthcare organizations with HIPAA-compliant email and APIs in their ongoing battle against cyber threats.
In this episode, we discuss:
The current state of information security in healthcare
How Paubox provides HIPAA-compliant email and APIs
Where security and privacy in healthcare is headed
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.
In the U.S., it’s easy to look at overseas privacy legislation like GDPR and conclude it’s a reaction to worrying data practices from today’s tech giants.
In reality, European privacy legislation can trace its roots back to the nightmarish authoritarian regimes of postwar Europe — and the necessity of securing a future free from repeating these governmental abuses.
That’s just one of the many privacy insights my latest guest, Jason Powell, GRC and Priv acy Consultant at Pivot Point Security, opened my eyes to. He joins the show to share more than just the history of privacy — he brings a ton of useful ways you can begin preparing for the future of privacy, too.
In this episode, we discuss:
Why GDPR is the granddaddy of privacy legislation
What you need to know to handle privacy — whether it’s for compliance or just good business practice
Why, despite some overlap, privacy and security are really their own domains and should be (ideally) treated as such
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.
Chess legend Bobby Fischer once said that winning tactics flow from a superior position.
Bobby Fischer would have made a great CISO.
That’s because information security strategy is all about steering your business to a winning position that makes tactics easy.
And it’s why your infosec and business strategies are entirely dependent on one another.
My guest today, Chris Dorr, Virtual Chief Information Security Officer (vCISO) at Pivot Point Security, is an expert at marrying security and business strategy. He joins the show to share his expertise and help you become one, too.
In this episode, we discuss:
Why business strategy and infosec strategy are inextricable
How frameworks can be used to shape effective infosec strategy
The 3 reasons why infosec strategy is more important than ever
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.
How well do you know what’s happening in your cloud?
With so many people in an organization able to access it, managing and tracking every change can be a Herculean task.
So, it’s no surprise that so many organizations need help tracking drift across their cloud networks.
And the best person they could turn to is today’s guest, John Grange, Co-Founder and CTO at OpsCompass, a company making software that offers centralized visibility for security, cost management, and compliance from a single dashboard.
In this episode, we discuss:
Why you need centralized visibility to track drift in the cloud
How security, compliance and cost management drift are tracked by OpsCompass
The kinds of users leveraging OpsCompass
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.
Every CISO’s dreams is moving from reactive security to purely proactive security posture.
In an era of big data and technological advancements in machine learning is this dream finally a reality?
To find out, we charged today’s guest, Johnna Verry, Intern at Pivot Point Security, with putting machine learning to the test to see if it can really be the breakthrough we need in predictive security. She joins me to share the results.
In this episode, we discuss:
The challenge of — and tools necessary for — scraping and cleaning data for use in machine learning
The types of machine learning algorithms and how they work
The results of Johnna’s research and what they mean for the future
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.
Just because ISO 27001 suggests a control, doesn’t mean you have to have it – in fact, you could be hurting yourself if you do by wasting money and have more trouble in an audit than you would otherwise.
Your controls depend on your risk — not ISO suggestions.
That’s just one of the many misunderstandings people have about the ISO 27001 standard.
In this solo episode, host John Verry, CISO & Managing Partner at Pivot Point Security goes in depth on the most common misperceptions around ISO 27001 compliance.
Some notable examples:
Why your controls need to be in accordance with your risk
Why you don’t need to go crazy documenting absolutely everything
Why you shouldn’t overcommit on controls
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.
Traditional compliance approaches have served us well for years…
But they just don’t cut it anymore.
We need an approach to compliance that moves at the speed of DevOps.
Our guest today, Raj Krishnamurthy, is Founder, CEO and Engineer at ContiNube, where he is helping to bridge the gap between traditional compliance techniques and the agile, fast-paced world of DevOps.
In this episode, we discuss:
Why traditional compliance tools are outdated to manage today’s rapidly shifting risks
The 5 pillars of bridging compliance and DevOps
How Raj and ContiNube are helping to tackle the problem
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.
In this special episode, we’re sharing a guest appearance John made on The Perfect Storm. During that episode, he shared how Pivot Point Security helps companies achieve security and compliance throughout different regulatory frameworks and a three-part process for validating your security processes.
Topics covered:
-What services Pivot Point Security offers
Helping clients understand the importance of cybersecurity
3-part framework to validate security
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Today’s special episode was inspired by a conversation we had with a then potential, now current client of ours at Pivot Point Security.
In discussing our Virtual CISO offering, we described our tried-and-true process for helping a client become provably secure and compliant. He loved it and wanted us to train him and his team on it. We've since had a similar conversation with a couple of boards.
What we've realized through these conversations is this process delivers a lot of value. So in this episode, we are going to share it with you.
Topics covered:
Defining a clear vision
Transforming a vision into an actionable plan
Validating your compliance
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
In the wake of the SolarWinds fiasco, a new executive order mandates practices to prevent future attacks…
How well does it address the threats?
And what does it mean for you?
To answer these questions, I invited Scott Sarris, Executive Vice President of Digital Transformation and Cybersecurity Advisory Services at Aprio, onto the show. Together, we break down the new EO into its most important components.
In this episode, we discuss:
Why the EO was necessary and what it means for cybersecurity
The role SolarWinds plays in the wording
The language acknowledging that Zero Trust is the most secure approach to cybersecurity
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
By the time you think of a ‘new’ password, attackers already have a way to crack it. Josh Amishav-Zlatin, Founder & Technical Director at BreachSense, is here to reveal the ugly truth about passwords, the risks they present, and how you can mitigate those risks.
What we talked about:
Breach timelines and scales of impact
How breaches work and how they’re identified
Is 2FA/MFA enough to protect you?
Protection vs. the right to privacy
Check out these resources we mentioned during the podcast:
Josh’s LinkedIn profile
BreachSense’s website
Have I Been Pwned website
The Infosec & OSINT Show (Josh’s podcast)
Josh’s Twitter profile
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.
Information governance is the solution to that irrational fear of deletion we all experience from time to time. Expert in the field and Chief Customer Officer at Encompaas, David Gould, breaks it down for us in the latest episode of Virtual CISO.
What we talked about:
What is information governance?
Data mapping potential and pitfalls.
The fear of deletion.
Value creation and information governance.
Check out these resources we mentioned during the podcast:
The California Consumer Privacy Act
David’s LinkedIn profile
Encompaas’ website - Encompaas.cloud
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.
Are you ready for your DIBCAC/CMMC audit? Let’s make sure.
We’re speaking to two of our best Security Consultants from right here within our ranks at Pivot Point Security. Joining me are George Perezdiaz, CMMC / NIST Security Consultant, & Caleb Leidy, CMMC Consultant/Provisional Assessor.
What we talked about:
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.
How do you quantify trust? Is it something that can be digitized?
In the world of cybersecurity, trust is a vulnerability.
What we need is Zero Trust.
That’s why I am so excited to speak with my latest guest, John Kindervag, Senior Vice President of Cybersecurity Strategy and Group Fellow at ON2IT Cybersecurity, who pioneered the concept of Zero Trust a decade ago — even if the world is only catching up to it now.
What we talk about:
What makes Zero Trust different from traditional security models
How Zero Trust easily solves the ransomware problem
The 5 steps to get to Zero Trust
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.
Whoever propagates the rumor that the goal of cybersecurity is to prevent all attacks deserves to be punched in the face.
The goal of cybersecurity is timely detection and damage control.
In this episode, we interview Dr. Eric Cole, Founder and CEO at Secure Anchor Consulting and author of, most recently, Cyber Crisis, about killing unprofitable cybersecurity myths.
We also discussed:
Believing that you are a target
Becoming aware of online danger
The law of cybersecurity
The 3 basic non-negotiable security rules
Dr. Cole’s parting advice to CISOs
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.
In the latest episode, Stacy High-Brinkley, VP of Compliance Solutions at Cask, shares what you need to know about the coming CMMC assessments.
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.
The federal government has FedRAMP to manage security authorizations for cloud service offerings. But cyber attacks don’t stop at the federal level. State and local governments are under attack too.
How can we create a process for cybersecurity verification of cloud service providers that lifts the cyber posture of state and local governments and the providers who serve them?
To answer that question, I just so happen to have Leah McGrath, Executive Director at StateRAMP, on the show today.
We discuss:
What StateRAMP is
How it works
Improving the StateRAMP process over time
Sign up to receive updates at StateRAMP.org.
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.
Remember those halcyon days when you could just stick an antivirus on your desktop and not worry — before all these confusing initialisms like EDR and NDR….
Well, turns out, they aren’t as complicated as you may think.
And I can’t think of anyone more qualified to explain why than Chris Nyhuis, President and CEO at Vigilant, who joins the show to shine some light on why the old-fashioned AV is seen as a relic of the past — and whether the new tools that have replaced it are buzzwords or brilliance.
We discuss:
How EDR differs from AV
What NDR and ENDR are
The pros and cons of automating security
Why compliance isn’t enough
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.
PreVeil Drive is a cloud service that lets users encrypt, store and share their files for CMMC Compliance and personal use. Unlike other cloud services such as Dropbox and OneDrive, PreVeil uses end-to-end encryption which ensures that only intended recipients can access their files.
In this episode of The Virtual CISO, we interview Sanjeev Verma, Co-Founder & Chairman at PreVeil, about using their tool as a mechanism to compress the timeframe and level of effort to move towards CMMC level three.
What we talked about:
PreVeil Drive as both a file exchange mechanism and a security mechanism.
How PreVeil Drive improves access control and configuration management.
How PreVeil Drive leads to greater improvement in security scores.
To hear this episode and more like it, subscribe to The Virtual CISO Podcast on Apple Podcasts, Spotify, or our website.
ISO-27701 is an exciting new standard. But it comes with a learning curve for all of us — clients, consultants, and auditors.
In this episode, we’ll discuss some of the lessons we’ve learned in our initial audits so you can, hopefully, benefit from our teething pains.
That’s why I invited today’s guests, Andrew Frost, GRC Consultant, and Aurore Watts, GRC and Privacy Consultant, here at Pivot Point Security, who have been working on the front lines of the auditing process.
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
John Laffey, Program Manager at Perry Johnson Registrars, Inc. discusses the cornerstones of an information security management system from the perspective of a management system auditor.
Context: the boundaries, the scope, the data, the people, the systems, and the stakeholders,
Leadership: driving the entire process, continuing to champion it and making sure resources are available.
Planning: documented processes, risk assessment and risk management
(Change = risk)
Support: budget, continuing training competencies, determining what is the required competencies, and then ensuring that those folks are meeting those.
Operation: Putting practices into action, verifying that you're doing what you say you do.
Performance Evaluation: “It's kind of the day to day, month to month, year to year maintenance of ensuring that things are staying on the rails and that nothing is slipping.”.
Improvement: Reaching expected, measurable outcomes and asking what can be improved in our organization
Not only are these valuable clauses in terms of passing your audit, but they're valuable in terms of reducing your organization's risk. This podcast can help you understand how your current management system can benefit you with your CMMC efforts.
OPTIONAL: Check out these resources we mentioned during the podcast:
- John Laffey, Program Manager at Perry Johnson Registrars, Inc.
Call our headquarters at 1-800-800-7910
Email John directly at JLafffey@PJR.com
PJR website
To ensure you never miss an episode, subscribe to the show on Apple Podcasts, Spotify, our website or wherever you get your podcasts.
Listening on a desktop & can’t see the links? Just search for [Virtual Ciso] in your favorite podcast player.
Have you ever wished that there was some sort of Star-Trek universal translator device for communicating your department’s needs to the C-Suite?
Well, the technology isn’t quite there yet, but today’s guest offers the next best thing. John Sheridan, Co-Founder at Agency Performance Systems, joins the show to share the secrets to interdepartmental communication.
What we talked about:
What your CFO cares about
How to communicate risk from a business perspective
Why you need to ditch the jargon and simplify your message
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.
Gone are the days when every company had their own internal IT department.
We’re well into the era of Managed Service Providers.
But how do you find the right one for your business?
In this episode, Host John Verry speaks with Charles Weaver, Co-Founder at MSP Alliance, covers everything you need to know about MSPs — and what to know if you are one.
They discuss:
The importance of validating your MSP
MSPs vs. MSSPs, and how each fits into a world with competing security standards
What MSPs need to know about the future
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.
With the proliferation of so many information security standards, are we nearing a breaking point?
In the end, which standard will win?
In this episode, John Verry, Founder of Pivot Point Security, answers these questions and more in a guest appearance on the Encrypted Economy Podcast.
John covers:
The basics of CMMC
Why CMMC is the most significant standard in InfoSec’s history
Whether we are reaching a saturation point for security standards
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.
Let’s talk about the Cybersecurity Maturity Model Certification, or CMMC.
What is it, why should you care about it, and how do you know if it’s going to impact your business?
While the industry has always known that CMMC certification was going to move beyond the Defense Industrial Base (DIB,) we assumed it was going to likely be towards the end of 2021, likely into 2022 and 2023.
But it’s growing at lightning speed, and more and more businesses that previously didn’t think they were going to have to worry about it are suddenly finding themselves in a position of needing to start seriously considering it in order to keep the contracts that they have with a myriad of third parties.
In this episode of The Virtual CISO Podcast, host John Verry, CISO and Managing Partner at Pivot Point Security goes over everything involved in CMMC level 1 certification, and what businesses need to know to get ahead of the game.
John outlines:
What exactly is CMMC?
Why it’s hitting more companies than you may think
How your company can get CMMC ready
-The time and resources needed to get CMMC certified
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.
Manufacturing tends to resist new technology. Not aerospace, though. It's on the cutting edge.
In this episode of The Virtual CISO Podcast, John Virgolino, President/CEO at Consul-vation, Inc. & CEO at SENT, discusses what makes the aerospace sector different from technology and security perspective.
John discusses:
Why making security part of your culture is key
The security challenges facing aerospace companies
The trouble with government contracts
Reasons why you shouldn't look for a loophole in aerospace security compliance
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.
In this episode of The Virtual CISO Podcast, host John Verry, CISO and Managing Partner at Pivot Point Security go over everything government staffing agencies need to know about CMMC Level 3 requirements.
John outlines:
How to tell if you have CUI in your environment
Whether your FCI can become CUI
If you need (or want) CMMC Level 3 compliance
The 3 steps to take when it comes to CMMC Level 3 compliance
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.
Keyword or phrase from headline CMMC Level 3 government staffing
These days, everything is connected to the internet. Whether it’s your car, your light bulbs, your microwave, your pacemaker, or your cochlear implant, it’s all being run and dictated by the internet.
And with that brings a whole new set of concerns.
Where you used to just have to worry about keeping your bank account secure, or your home wifi network secure, now all of a sudden you have to worry about your car or your pacemaker being hacked?
How do we even go about categorizing all the IoT devices, and how do we protect them?
On this episode of Virtual CISO, I chat with Aaron Guzman, who in addition to being the Product Security Lead at Cisco Meraki, is also the Project Lead for the IOT Security Verification Standard (ISVS) at the OWASP Foundation. And if that wasn’t enough, he’s the author of a number of books on IoT, including IoT Penetration Testing Cookbook.
He was kind enough to talk about:
OWASP
What the ISVS is
Who ISVS is intended for
And, how ISVS is categorized
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Are you looking to get your product authorized for use by federal agencies?
Then you probably need to understand FedRAMP, how it works, and, most importantly, whether it applies to you.
In this episode, I chat with Stephen Halbrook, Partner and Government Compliance Specialist at Schellman & Co, who answers the most common questions about the government security assessment.
He answers:
What is FedRAMP and who does it apply to?
What is a typical timeline for the ATO process?
Should you go through JAB or an agency?
How much does it cost?
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.
Privacy is changing. Across the globe, new standards are recognizing it as a fundamental human right.
But between GDPR, CCPA, and all the other standards popping up, figuring out all your data privacy obligations can be quite the challenge.
That’s why I invited Dyann Heward-Mills, Lawyer and CEO of HewardMills, onto the show to discuss the challenges data privacy standards present — and how you can overcome them.
We discuss:
The history of data privacy
How to meet your privacy obligations
The role a Data Privacy Officer plays (and whether you need one)
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Getting your ducks in a row for a GRC audit can be a huge undertaking.
Especially when you get compliant for the audit, then don’t look at it again until the next one rolls around.
If this sounds familiar, you may have wondered whether investing in a GRC tool is worth it.
In this episode, Craig Unger, Founder and CEO at HyperProof, shares all the information you need to decide whether investing GRC is right for you.
What we talked about:
The challenges a GRC tool should address
Whether continuous compliance means continuous security
When you should implement a GRC tool
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
The DFARS interim rule that went into effect on November 30th has a lot of nuances to it — and many out there have questions about how it applies to them.
In this episode, I sit down with Corbin Evans, Principal Director, Strategic Programs at National Defense Industrial Association, to get answers to some of the most common questions about these CMMC nuances, including:
What do DIB orgs with a 7012 clause in their contracts need to do now?
What happens if you submit a low SPRS score?
What are the different types of CUI?
Check out this resource we mentioned during the podcast:
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Should I migrate to GCC High? Do I have to? Are there alternatives?
If you’re a DIB member and you are using Office 365 — as so many do — reaching CMMC Level 3 compliance is going to force you to make some difficult decisions.
To help guide you through them, I invited Scott Edwards, President at Summit 7 Systems, onto the show to go over what CMMC Level 3 requires and how you can achieve it.
Scott explains:
The requirements for CMMC Level 3 compliance and what they mean for Office 365, G Suite, and in-house email companies
The process and expected costs of migrating to GCC High
How GCC High compares to alternatives
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
If you’ve taken the time to look through the DFARS Interim Rule…
All 80+ (potentially) confusing pages of it...
You might have some questions about how it applies to your business.
Luckily, Scott Armstrong, Sr. Director, Cyber Risk, Analytics, and Insights at Exostar, has answers.
In this episode, he and I discuss everything DIB firms need to know about the CMMC Interim Rule
What we talked about:
“Legalese to English” translations of the three new regulations
Best practices on how to score your self-assessment
How and when the DoD will start adding “CMMC language” to contracts
How the interim rule will impact new contracts and contract modifications/extensions
Why the interim rule will accelerate CMMC Level 3 compliance across the DIB
How Exostar can help your organization prepare for compliance
To hear this episode and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
SaaS is a great business to be in.
But whether you’re a startup or a mature company…
Your product is only as good as your security.
Today’s guest, Ryan Buckley, has advised SaaS firms for a number of years. He joins me to discuss how to address SaaS security and keep your product — and reputation — secure.
What we talked about:
Why code repositories are an issue
Why product security is as important as infrastructure security
Senior leadership’s role in security.
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
The internet of things is taking off.
IoT is bringing new innovations across the board…
But it’s also bringing a new set of vulnerabilities.
If you’re looking to make sure you’re secure in the world of IoT, I can’t think of anybody better to talk to than Aaron Guzman, Co Chair of the IoT Working Group, and John Yeoh, Global Vice President of Research, at Cloud Security Alliance.
So, in the latest episode of the Virtual CISO Podcast, I do exactly that.
We discuss (among MANY other things):
What CSA is and the guidance they offer developers and IoT consumers
The work they are doing in IoT
What implications 5G has for their work
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
ISO 27001, CMMC, NIST 800-53…
Keeping track of the myriad security guidelines can be tricky.
Especially when you don’t know the “why” behind them.
To help clear things up, in this episode, I speak with the preeminent expert on NIST guidelines, Dr. Ron Ross, Fellow at National Institute of Standards and Technology, and learn not just what the guidelines are — but how and why they came to be that way.
Ron and I discuss:
The “Why” behind NIST guidance
How certification standards like ISO 27001 relate to NIST 800-53 and map to each other
How NIST balances policy and technical-level considerations
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Preparing to achieve CMMC compliance may seem daunting.
Especially in 6 challenging components.
But we’re going to make them easy.
In the latest The Virtual CISO Podcast episode, the tables are turned and I’m the one being interviewed. I explain these 6 problem areas and offer ways you can solve them.
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Though 2020 has felt decades-long already…
We still haven’t had to deal with the long-term effects of the pandemic.
But we will. The question is: Can your security?
If you’re not sure, today’s guest will surely boost your confidence.
Reg Harnish, Founder and CEO at Slingshot Cyberventures and Founder at GreyCastle Security, joins the show to walk us through the threats and opportunities a post-pandemic world presents.
We discuss:
How the pandemic is impacting security
The threats companies face now and in the future
Finding opportunities post-COVID-19 world
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
CMMC is coming...
But that doesn’t mean 800-171 compliance is out the window.
In this episode, I catch up with John Ellis, Director of the Software Division at DCMA.
We discuss:
How DCMA is conducting assessments
Why 800-171 compliance doesn’t just go away until CMMC
Why CMMC is so needed
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Not too long ago, DevOps seemed like a fringe buzzword…
Now, it’s front-and-center.
So, what is DevOps and why should you care?
To answer, I invited Jon Bass, Co-Founder & CTO at Sym, onto the show. Jon’s expertise in the field makes him a perfect tour guide for the exciting — and often misunderstood — world of DevOps.
Jon explains:
How DevOps moved from the fringe to the mainstream
How agile comes into the picture
What SecDevOps is and why it’s used
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
When ISO 27001 is optimized for speed, it’s an amazingly effective and efficient way to manage security and compliance.
Today’s guest is one of our most seasoned ISO experts in both client-facing and training roles.
In this episode, I interview Rich Stever, IT Security Auditor at Pivot Point Security, about key artifacts for optimizing your ISMS.
What we talked about:
Key artifacts of the ISMS, including security management policy
Objectives during your ISMS refresh
Privacy, ISO 27701 extensions, and all about the Information Security Management Committee
Poe Dameron (yes, the Star Wars pilot)
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
If your organization is in the DIB, CMMC compliance is a big deal. It’s probably the biggest thing to happen to information security in history.
And you need to prepare. Your business could depend on it.
That’s why for this episode, I sat down with Chris Lank, Founder and CEO at Ivis, a company offering a solution for monitoring any compliance, not just CMMC, year-round. Chris goes over the ins-and-outs of the changes CMMC will bring for your business — especially for smaller DIB organizations — and how to prepare.
What we talked about:
Why CMMC is necessary
What your organization needs to start doing right now to prepare
How tools like Ivis’ can make the compliance process a whole lot easier
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Prepping for an ISO 27001 audit can be a nerve-wracking process.
But it doesn’t have to be.
You just need to know what you’re getting into.
And Ryan Mackie, as Principal and ISO Practice Director at Schellman & Company, is the perfect person to guide you through an audit.
In today’s episode, he covers:
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
If you have a growing SaaS company, security may be far down your list of priorities.
I’ll be blunt… it shouldn’t.
Security maturity can be make-or-break for SaaS clients and maybe even more importantly, SaaS investors.
As a Partner at Reitler Kailas & Rosenblatt, Jesse Nash has a wealth of experience representing early-stage SaaS companies and venture capital investors, so he’s seen how security helps and hurts deals from both sides.
He joined me today to go over:
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
If you are scrambling to figure out CMMC, you aren’t alone.
It’s perhaps the most sweeping information security change for DoD contractors in history…
And that comes with an assessment program dwarfing any other.
As Member of the Board of Directors for CMMC AB, the accreditation body for CMMC, Ben Tchoubineh is one of the minds behind these assessments… just don’t call it an audit :).
Ben came on the show to demystify the CMMC assessment and certification process.
He covered:
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
If your company works with the DoD.
You might be worried about CMMC compliance.
But it doesn’t have to be hard or expensive.
In this episode, I caught up with Sanjeev Verma, Co-Founder at PreVeil, a company offering one solution for CMMC’s requirement for encryption of email and file sharing that can save you money and hassle, while giving you unparalleled security.
What we talked about:
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Covid 19 has created lots and lots of challenges and opened our eyes to ones that lay dormant.
One of the most stark realizations is how much we rely on our critical vendors.
But how can you know a vendor is safe to work with, is reliable, and figure this out quickly and at a low cost?
Enter ARM. Accelerated Risk Management
Pivot Point Security’s answer to the need for rapid risk assessment.
If you are looking for a paradigm shift in the way you manage risk and assess your vendors this is the show you need to hear.
Kevin Hermosura, one of our Third Party Risk Management & Vendor Due DIlligence Security Consultants here at Pivot Point Security talks with John Verry about using ARM to assess vendor’s risk (in minutes, not days).
What we talked about:
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
If you’re a business leader, especially at a SaaS firm or if you’re a developer at a SaaS firm, this episode with Jim Manico will provide a ton of value.
You'll hear practical advice on how to approach application security that even the most technically un-savvy listeners can understand.
Joe Manico is an application security powerhouse. He is the Founder of an application security training company, Manicode Security, is a major contributor to a number of OWASP projects, and he has a really great passionate approach to his work.
What we talked about:
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Information security is a well easily fallen into.
There is so much on the market.
So many things to consider.
It’s hard to determine what you actually need, and sometimes companies tend to just grab everything in sight to assure themselves that they are on point…
Or not do enough for fear of wasting time and money on the wrong solutions.
There are plenty of ideas, platforms, papers, and regulations to keep in mind, but sometimes, less really is more.
Jose Ciriaco, Director of Sales and Marketing at Tekscape, Inc. shares some refreshing ideas about keeping things streamlined while promoting diverse product sets and services in the B2B marketplace.
What we talked about:
Real-world strategies around consolidation
Analyzing valuable streamlining on a case by case basis
Digging through vendor options (and how to get the most out of them)
Additional Resources:
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
If you want a glimpse into what one of your future CMMC audits will be like, this is the show for you.
On this episode of The Virtual CISO Podcast, we welcome Thomas Price, Client Manager/IT and Information Security Auditor/Quality Management Professional at BSI.
Working with clients to determine strategic direction, achieve objectives, and improve quality and service delivery, Thomas is one of the most accomplished and respected auditors in the security industry.
What we talked about:
The differences between ISO 27001 and CMMC
CMMC requirements- an in depth look
Insights from an auditor's perspective on how to prepare for certification
Real-life examples of how to leverage ISO 27001 to nail CMMC certification
Check out these resources we mentioned during the podcast:
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Who do you trust with your network?
Would you give a random person access to the infrastructure that runs your business?
Anyone with a computer and an Internet connection can set themselves up as a penetration testing or cyber incident response service provider.
But what methods does your organization have in place for vetting an individual or company that you are potentially allowing unfettered access to your entire network?
Ian Glover, President of CREST, is on the podcast to talk about how CREST provides internationally recognised accreditations for organisations, and professional level certifications for individuals providing penetration testing, incident response, threat intelligence and Security Operations Centre (SOC) services.
What we talked about:
CREST and a CISO’s decision making process
The rigorous process of CREST accreditation and certification - Why having a certifying body evens the playing field Check out these resources we mentioned during the podcast:
CREST
This post is based on The Virtual CISO podcast hosted by John Verry and featuring special guest, Ian Glover
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
We all have things we consider “the best”.
Things we look to.
Rely on.
What happens when one of those old reliable, gold standard things that have been our go-to for so long winds up being #2, instead of #1?
Andrew van der Stock, Senior Application Security Leader at OWASP Foundation stops by the podcast to dispel some industry myths about The OWASP Top 10.
What we talked about:
Is The OWASP Top 10 really the gold standard?
Next level considerations to take on as you progress on your journey
Risk assessment and threat modeling is just a game
Check out these resources we mentioned during the podcast:
The word forensics usually makes us think of homicide, but it applies to computers, too.
Computer forensics simply just means telling the story of what happened on a computer.
In this episode, we hear from Brian Dykstra, President and CEO of Atlantic Data Forensics, about who needs computer forensics, when, and why.
What we talked about:
The need for computer forensics is widespread and underrecognized
It gives you protection against future litigation, especially in IP and employment cases
50% of CISOs graduated at the bottom half of their class… and what that means
3 free, easy ways to reduce your attack surface
To hear this episode, and many more like it, you can subscribe to Virtual CISO here. If you don’t use Apple Podcasts, you can find all our episodes here.
As the first data privacy certification available, ISO 27701 can greatly reduce the complexity of managing privacy, risk and proving compliance with regulations like CCPA, GDPR.
Those organizations that already have a 27001 certification or are considering that certification can add on 27701 to change an Information Security Management System (ISMS) into an Information Security & Privacy Management System (ISPMS)
Debbie Zaller, Principal and co-owner at Schellman & Company, shares her in-depth knowledge of ISO 27701 on this episode of The Virtual CISO Podcast.
What we talked about:
Resources we mentioned:
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Getting a flat tire is a disaster.
Knowing where you keep the spare is disaster recovery.
Changing a tire in under 7 minutes to get right back on the road is business continuity.
In this episode, I interview Cosmo Gazzani, Director of Business Development at Continuity Centers and wekos, about information continuity and the importance of backing up your data.
What we talked about:
This post is based on a Virtual CISO podcast with Cosmo Gazzani. To hear this episode, and many more like it, you can subscribe to Virtual CISO here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Your application is probably vulnerable.
“But how?! We hired a company to pen test our application.
They did a thorough test against the OWASP top 10!”
On this episode of the Virtual CISO podcast, we talk with Daniel Cuthbert. He's one of the premier authors of the OWASP ASVS, and he says OWASP Top 10 is not enough.
We chat about:
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Is your organization ready for CMMC?
As CMMCs roll out over the next 6 years, it’s going to become a reality for more and more DoD subcontractors.
As many as 50,000 organizations by 2025.
Thankfully there are folks out there who are experts at this.
On this episode of The Virtual CISO podcast, we heard from Stuart Itkin. Stuart is the Vice President of Marketing & Product Management at Exostar, and he and his team are leading the charge when it comes to CMMC readiness.
We talk all about:
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
As an SMB, you’re probably thinking you’re too insignificant for a targeted cyberattack.
That’s not even a little bit true.
In this episode, I interview Danielle Russell, Director of Product Marketing Management at AT&T Cybersecurity, about SIEM solutions for SMBs.
What we talked about:
To hear this episode in its entirety and others like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
You’re a CISO at an SMB, and you see that the AUP is called the SCA now.
So now what?
Actually, there are 3 applications for this great tool alluded to by the relabeling.
In this episode, I interview Tom Garrubba, VP and CISO at The Shared Assessments Program, about applications for the SCA.
What we talked about:
To hear this episode in its entirety and others like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
If you thought this podcast was supposed to be about information security, you might be confused about why we’re featuring heart disease.
Bottom line: Dead CISOs don’t get bonuses.
On this episode, I interview Dr. Joel Kahn, triple-board certified cardiologist, author of 6 books, and restaurant owner — also my physician — about techniques for managing stress and preventing heart disease.
What we talked about:
Check out these resources we mentioned during the podcast:
Dr. Kahn’s website, which is full of free resources and articles
Dead Execs Don’t Get Bonuses
Forbes article on Cybersecurity Mental Health
To hear this episode, and many more like it, you can subscribe to Virtual CISO here.
If you don’t use Apple Podcasts, you can find all our episodes here.
In this world of remote work that we’ve found ourselves in, there are likely a lot of companies that are looking around and wondering if they’ve got the right staff.
With a fully remote workforce comes a lot of new challenges in the IT space, and if you’re a smaller company, you may not be in the space to bring on a full-time CIO, but you still need the governance and expertise of a CIO.
Cue the virtual CIO.
And there are a lot of managed IT service companies that offer some level of virtual CIO support.
That’s why on this episode of The Virtual CISO Podcast, we sat down with Darek Hahn, President & CEO at VelocIT, to discuss:
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Can we all agree that this is a strange, confusing, and stressful time to be living through? That none of us really know what’s going to happen, or what the future holds? While restaurants, airlines, cruise ships, and countless other businesses are struggling, there’s one group of people that don’t seem to be slowing down at all, and that’s cybercriminals.
They’re exploiting this crisis and taking full advantage of people’s fear and panic, often causing untold damage in the process.
We at Pivot Point have received countless calls from customers with questions about the changes that this pandemic has brought on. How do they stay safe? What should they be focused on? How do they keep their companies safe during these trying times?
While he’s usually the host of the show, on this episode John Verry, the CISO and Managing Partner here at Pivot Point Security, sat down to discuss a few of the biggest challenges he sees as companies try to stay safe in this current landscape.
He talked through:
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Trust, but verify.
These famous words of Ronald Reagan, who, incidentally, would make a fantastic CISO, are also the simplest explanation of what it’s like to work as a virtual CISO.
If step one is building trust and relationship with clients, step two is being let in to see all the inner workings and operations to make informed and strategic decisions.
In this episode, John interviews Andrew Farkas, Virtual CISO at Pivot Point Security, about his experience as a vCISO and why the need exists for such a role.
What we talked about:
You can reach out to Andrew via the Pivot Point Security website.
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Considering an ISO 27001 certification?
Wondering about SOC 2 attestation?
Trying to figure out the differences between the two? We got you covered.
We invited Dan Schroeder, Partner-in-Charge for Information Assurance Services at Aprio LLP, onto The Virtual CISO Podcast to explain attestation, certification, ISO 27001, and SOC 2.
What we talked about:
To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here. If you don’t use Apple Podcasts, you can find all our episodes here.
The cyber talent search feels like a global, dangerous game of Marco Polo.
We’re all looking for each other, but nobody can find anyone.
(And even if we do, it’ll only last 18 months or less.)
In this episode, I interview Deidre Diamond, Founder and CEO of CyberSN, about attracting and retaining cyber talent during the talent shortage.
What we talked about:
Check out these resources we mentioned during the podcast:
This post is based on a Virtual CISO podcast with Deidre Diamond. To hear this episode, and many more like it, you can subscribe to Virtual CISO here.
If you don’t use Apple Podcasts, you can find all our episodes here.
Katie Arrington is THE expert in the national cyber security battle.
As CISO for Acquisition and Sustainment at the United States Department of Defense, she’s well beyond needing analogies to understand cyber security news and trends.
Yet, she had the best one on hand to explain Cybersecurity Maturity Model Certification (CMMC, for short).
“At the end of the day, the CMMC is your cyber driver’s license to participate in the DoD supply chain.”
Katie is the very first guest of the Virtual CISO podcast. She joined John Verry to discuss recent changes to verifying contractors’ ability to protect unclassified information.
We also chat about:
Reach out to Katie: katherine.arrington.civ@mail.mil
You can find this interview (and many more to come) by subscribing to The Virtual CISO Podcast on Apple Podcasts or Spotify.
Information security is a serious topic.
However, the host of The Virtual CISO Podcast and managing partner at Pivot Point Security, John Verry, doesn’t think security pros always need to be so serious.
In this intro episode of The Virtual CISO Podcast, Logan Lyles of Sweet Fish Media catches up with John to find out what exactly the show’s going to be covering.
John offers up:
To hear this episode and more like it, subscribe to Virtual CISO on Apple Podcasts, Spotify, or wherever you get your podcasts.