The Virtual CISO Podcast: Recent Episodes

Pivot Point Security

The Virtual CISO Podcast is a frank discussion that provides the very best information security advice and insights for Security, IT and Business leaders. If you’re looking for the latest strategies, tips, and trends from seasoned information security practitioners, want no-B.S. answers to your biggest security questions, need a perspective on how your peers are addressing the same issues, or just simply want to stay informed and proactive, welcome to the show.Our moderator, John Verry, chats with industry thought leaders to ensure you have what you need to be confident in your security and compliance. John will keep you informed, and perhaps even mildly entertained through topics like ISO 27001, breach avoidance, incident response, dealing with pesky security questionnaires, data privacy, and managing vendor risk.Think of it as security… with a smile.

View Details

In this episode of The Virtual CISO Podcast, your host, John Verry, engages in a conversation with Aviv Grafi, CTO and founder of Votiro, as they discuss innovative solutions to combat business email compromise. Join us as we discuss:
* The mechanisms of business email compromise * How malicious files are used in cyberattacks * The limitations of traditional security methods * The benefits of malicious file reconstruction technology

And more! If you want to learn more about cybersecurity, follow The Virtual CISO Podcast on your favorite streaming platforms and subscribe to the Virtual CISO Podcast. For updates on cybersecurity, digital technology, and more, follow us on LinkedIn:https://www.linkedin.com/company/pivot-point-security/

View Details

Join us for an engaging episode of the Virtual CISO Podcast with host John Verry. This episode features Chris Petersen, co-founder of LogRhythm and current CEO of Radical. Chris brings over two decades of experience in cybersecurity, offering deep insights into the industry's challenges and advancements. In this episode, we'll explore:

  • The surprising results from Radical’s DIB Cybersecurity Survey, including the incongruity between high self-assessed security skills and other survey responses.
  • The critical issue of poor scoping in System Security Plans (SSPs) and its impact on the effectiveness of security monitoring within the Defense Industrial Base (DIB).
  • The paradox of organizations delaying CMMC certification despite acknowledging the lengthy process and the looming enforcement deadline.

If you want to learn more about cybersecurity, follow The Virtual CISO Podcast on your favorite streaming platforms and subscribe to the Virtual CISO Podcast. For updates on the state of cybersecurity, digital technology, and more, follow us on LinkedIn, https://www.linkedin.com/company/pivot-point-security/

View Details

Join us for an engaging episode of the Virtual CISO Podcast with host John Verry. This episode features Kevin Dinino, President of KCD PR, who delves into the critical aspects of crisis management and communications. Kevin brings over 20 years of experience in guiding companies through the complexities of strategic communications, particularly in the cybersecurity, financial, and technology sectors. In this episode, we'll explore:

  • The nuances of differentiating between an incident and a crisis, and how to handle the transition from one to the other.
  • The essential components of a comprehensive crisis management plan and the importance of integrating cyber incident response with overall crisis communication strategies.
  • Real-world examples of effective crisis communication, including the famous Tylenol recall and modern-day cyber incidents.
  • The evolving landscape of cyber liability insurance and the role of PR firms in mitigating the reputational impact of security breaches.
  • Insights into the latest federal disclosure requirements and their implications for incident and crisis management.

If you want to learn more about cybersecurity, follow The Virtual CISO Podcast on your favorite streaming platforms and subscribe to the Virtual CISO Podcast. For updates on the state of cybersecurity, digital technology, and more, follow us on LinkedIn, / pivot-point-security .

View Details

In this episode of The Virtual CISO Podcast, your host, John Verry, engages in a conversation with guest Zenobia Godschalk, Senior Vice President of Hedera Hashgraph, as they discuss distributed ledger technology and its effects on privacy compliance.

Join us as we discuss the following:
* The erosion of Privacy Online

  • Distributed Ledger Technology (DLT) and how it enables Web 3

  • How DLT can be used to improve security and compliance with Privacy regulations

If you want to learn more about cybersecurity, follow The Virtual CISO Podcast on your favorite streaming platforms and subscribe to the Virtual CISO Podcast.

For updates on the state of cybersecurity, digital technology, and more, follow us on LinkedIn: https://www.linkedin.com/company/pivot-point-security/

View Details

In this episode of The Virtual CISO Podcast, your host, John Verry, engages in a conversation with guest Shauli Rozen, CEO and Co-Founder of ARMO, exploring the intricacies of Kubernetes, the orchestration tool that's reshaping how we deploy, scale, and manage containerized applications.

Join us as we discuss:
* What a container is * Implications of containers on security * How you can leverage Kubescape to improve application security * And more!

If you want to learn more about cybersecurity, follow The Virtual CISO Podcast on your favorite streaming platforms and subscribe to the Virtual CISO Podcast.

For updates on the state of cybersecurity, digital technology, and more, follow us on LinkedIn, https://www.linkedin.com/company/pivot-point-security/

View Details

In this episode of The Virtual CISO Podcast, your host, John Verry, sits down with Andrew Frost and Leigh Ronczka of CBIZ Pivot Point Security to discuss the updates needed to successfully transition from ISO27001:2013 to ISO 27001:2022.
Join us as we discuss:
* How simplistic it is for a company to transition to ISO 27001:2022 * The level of effort required to implement the changes * What auditors are looking for when organizations make an update * And more!

If you want to learn more about the realm of cybersecurity, follow The Virtual CISO Podcast on your favorite streaming platforms and subscribe to the Virtual CISO Podcast.
For updates on the state of cybersecurity, digital technology, and more, follow us on LinkedIn, https://www.linkedin.com/company/pivot-point-security/

View Details

Tune into an insightful conversation with Jeremy Price, co-leader of a national cybersecurity practice. In this engaging discussion, Jermey explains the updated FTC safeguard rules that went into effect in June and what they’re intended to do. In this episode, your host, John Verry, and Jeremy Price discuss: - The Gramm Leach Bliley Act updates and how that affects financial institutions, and companies that offer things like consumer financial products and services - The extended and new definition of financial institutions - How to determine whether or not your company falls under the new definition of financial institutions and what that means for your business - And more!

View Details

Join us for an insightful conversation with Patricia Thaine, Founder and CEO of Private AI, as we delve into the world of artificial intelligence, language models, and data privacy. In this engaging discussion, Patricia sheds light on the transformative potential of AI, particularly language models like GPT-3.5, in various industries.
In this episode, your host, John Verry, and Patricia Thaine discuss:
* how specialized AI models are revolutionizing tasks such as sentiment analysis and personal information identification, all while ensuring data remains private and secure. * responsible AI practices and preparing the next generation to harness AI's power responsibly. * the potential of AI and the ethical considerations that accompany it. * And more!

If you want to learn more about the realm of cybersecurity, follow The Virtual CISO Podcast on your favorite streaming platforms!
For weekly updates on the state of cybersecurity, digital technology, and more, follow us on LinkedIn, @pivot-point-security.

View Details

In this episode of the "Virtual CISO Podcast," your host John Verry speaks with guest Warren Hylton, a FedRisk consultant at CBIZ Pivot Point Security, to explore recent updates in cybersecurity regulations. The conversation revolves around the Cybersecurity Maturity Model Certification (CMMC) and the updated NIST Special Publication 800-171 (R2 to R3).

Join us in this week’s episode as we discuss
* The potential outcomes of the DOD’s rules package submission to OMB * NIST 800-171's Revision 3 updates * The transition from DoD-led to commercial-led assessments regarding CMMC * And more!

To hear this episode and many more like it, we encourage you to subscribe to the Virtual CISO Podcast.

Just search for The Virtual CISO Podcast in your favorite podcast player or watch the Podcast on YouTube here.

To stay updated with the newest podcast releases, follow us on LinkedIn here.

View Details

Like many other businesses, law firms are at significant risk of cyber-attack and increasingly are turning to cyber liability insurance (CLI) to transfer some of their cyber risk. But many are being denied coverage or face high premiums due to shortfalls in their cybersecurity controls.

In this episode, your host John Verry, CBIZ Pivot Point Security Managing Director, sits down with Jack Liljeberg, Assistant Broker at Thompson Flanagan. Jack helps give business and security leaders in the legal vertical, as well as anyone seeking CLI coverage, a comprehensive update on the state of the CLI marketplace and critical issues to be aware of.

In this episode, join us as we discuss:
· Whether CLI premiums still increasingly rapidly or have stabilized
· Most critical information security controls that businesses need to obtain CLI coverage or avoid onerous premiums
· The importance of honesty, accuracy, and plenty of detail in CLI applications
· Exemptions and other issues to watch out for in CLI policies
· Other insurance coverage types that can bridge gaps in a firm’s CLI coverage

To hear this episode and many more like it, we encourage you to subscribe to the Virtual CISO Podcast.

Just search for The Virtual CISO Podcast in your favorite podcast player or watch the Podcast on YouTube here.

To stay updated with the newest podcast releases, follow us on LinkedIn here.

View Details

To do wide-scale business within the US federal government, cloud service providers (CSPs) need a FedRAMP ATO. The prospect can be daunting as few CSPs have federal cyber compliance expertise. Misconceptions and misinformation can create additional roadblocks.

In this episode, your host John Verry, CBIZ Pivot Point Security Managing Director , sits down with Mike Craig, CEO at Vanaheim Security, who gives clear guidance with business and security leaders on what it takes to get a FedRAMP ATO, including best practices and common mistakes.

In this episode, join us as we discuss:

• Key considerations to help decide if a FedRAMP ATO is worth pursuing
• How long a FedRAMP ATO really takes, how much it really costs, and why
• The three stages of the FedRAMP journey
• Key participants in the FedRAMP “dance” and how they relate
• Huge pros and cons of an agency sponsorship versus the JAB authorization path to a FedRAMP ATO

To hear this episode and many more like it, we encourage you to subscribe to the Virtual CISO Podcast.

Just search for The Virtual CISO Podcast in your favorite podcast player or watch the Podcast on YouTube here.

To stay updated with the newest podcast releases, follow us on LinkedIn here.

View Details

Whatever kind of software application a team is building, the identification and remediation of cybersecurity issues needs to be part of every stage of the software development lifecycle (SDLC). But making that happen takes a wealth of skills and approaches, as well as an eye on compliance and the ability to keep pace with the ever-changing online environment—microservices being a prime example.
In this episode, your host John Verry, Pivot Point Security CISO and Managing Partner, sits down with Laura Bell Main, CEO and Founder of SafeStack to give business and security leaders a clear and logical overview of microservice security issues and more.

In this episode, join us as we discuss:
• What constitutes a microservice architecture and how it relates to other design approaches, languages, and frameworks
• The microservice software supply chain and the limitations of a Software Bill of Materials in a microservices context
• How using microservices changes the approach of securing an application
• How zero trust concepts relate to microservice architectures
• How SafeStack is helping to educate developers about application security in organizations of all sizes
To hear this episode and many more like it, we encourage you to subscribe to the Virtual CISO Podcast.

Just search for The Virtual CISO Podcast in your favorite podcast player or watch the Podcast on YouTube here.

To stay updated with the newest podcast releases, follow us on LinkedIn here.

View Details

If you are ISO 27001 certified, or considering it, you are likely wondering how the transition from ISO 27001:2013 to ISO 27001:2022 affects you. With the notable changes, there are many uncertainties. For example, how soon can you get certified to ISO 27001:2022? Can you still get certified to 27001:2013? For anyone already certified, how soon can they transition to ISO 27001:2022?

In this episode, your host John Verry, Pivot Point Security CISO and Managing Partner, sits down with Andrew Frost, GRC Advisory Consultant at Pivot Point Security to explore the most effective and simplest practices for making the transition from ISO 27001:2013 to ISO 27001:2022.

In this episode, join us as we discuss:

• An overview of what changed and why from ISO 27001:2013 to ISO 27001:2022
• Timelines for certification to the new standard, including why it might be advisable to delay an ISO 27001:2022 certification audit until 2024
• The level of effort required for the transition to ISO 27001:2022
• Guidance on how to plan and execute the transition to ISO 27001:2022
• How auditors might use the new #hashtags in ISO 27001:2022

To hear this episode and many more like it, we encourage you to subscribe to the Virtual CISO Podcast.

Just search for The Virtual CISO Podcast in your favorite podcast player or watch the Podcast on YouTube here.

To stay updated with the newest podcast releases, follow us on LinkedIn here.

View Details

In this week's episode of the Virtual CISO podcast, your host John Verry, Pivot Point Security CISO and Managing Partner, shares his valuable insights from the 2023 RSA conference. As the security industry evolves, with an increasing number of vendors and products, John advises against adopting a product-based security strategy. Instead, he recommends having a clear plan to address specific security challenges.
Tune in to this episode to learn John's eight key takeaways, the latest developments from the 2023 RSA conference, and gain valuable insights to enhance your organization's security posture.

In this episode join us as we discuss:
· Privacy will drive data governance
· Data security posture management
· Zero trust: a model rather than a product
· AppSec and API security
· 90-day TLS certificates

To hear this episode and many more like it, we encourage you to subscribe to the Virtual CISO Podcast.

Just search for The Virtual CISO Podcast in your favorite podcast player or watch the Podcast on YouTube here.

To stay updated with the newest podcast releases, follow us on LinkedIn here.

View Details

With the release of President Biden’s Executive Order 14028 on “Improving the Nation’s Cybersecurity” from May 2021 the US public and private sectors have been alerted to the significant cybersecurity risks within our software supply chain. As of the March 2023 release of the National Cybersecurity Strategy, which will shift liability for software products and services to promote secure development practices, it’s evident that software security needs to be elevated across all organizations.

In this episode, your host John Verry, Pivot Point Security CISO and Managing Partner, sits down with Tim Mackey, Head of Software Supply Chain Risk Strategy at Synopsys, to explore what better software supply chain security means for software development and more.

In this episode, join us as we discuss:

· Defining an SBOM what it can include depending on stakeholder needs
· The value of SBOMs for both software developers and their clients
· Market drivers for improved software supply chain security
· Software composition analysis and its role in mapping dependencies and identifying vulnerabilities within code
· How the NIST Secure Software Development Framework (SSDF) supports initiatives to improve software supply security

To hear this episode and many more like it, we encourage you to subscribe to the Virtual CISO Podcast.

Just search for The Virtual CISO Podcast in your favorite podcast player or watch the Podcast on YouTube here.

To stay updated with the newest podcast releases, follow us on LinkedIn here.

View Details

Asset management is a crucial aspect of information security. It refers to the processes and procedures involved in identifying, organizing, tracking, and protecting an organization's assets. The security of these assets is paramount, as you can’t protect what you don’t know about.

To learn more about how to Fix Cyber Asset Management, your host John Verry, sits down with Huxley Barbee, Security Evangelist at runZero, to discuss the importance of Asset Management, how it’s a critical component of any organization's security strategy and much more.

In this episode, Join us as we discuss the following:

• Definition of an asset—the answer is surprising
• Top reasons why so many orgs are failing Asset Management 101
• Critical innovations of a modern asset management solution
• Asset management in the cloud and what teams really need to focus on
• How asset management failures killed Equifax

To hear this episode and many more like it, we encourage you to subscribe to the Virtual CISO Podcast.

Just search for The Virtual CISO Podcast in your favorite podcast player or watch the Podcast on YouTube here.

To stay updated with the newest podcast releases, follow us on LinkedIn here.

View Details

DevSecOps is the practice of integrating security testing at every stage of the software development process. With DevSecOps, training and educating all teams in risk, security, and mitigation at all stages of development is a top priority– traditionally, app developers don't pay much attention to security, which increases the risk of vulnerable code being deployed and the application being compromised.

To learn more about DevSecOps in this episode, your host John Verry, sits down with André Keartland, Solutions Architect with Netsurit Professional Services, to discuss tactical steps to implement DevSecOps in 2023.

In this episode, Join us as we discuss the following:

• What is DevSecOps and how does it differ from DevOps?
• Getting business stakeholder buy-in for application security
• The best way to get started with DevSecOps
• Who in your org needs application security training and why
• How to assess application risk and why it’s so important

To hear this episode and many more like it, we encourage you to subscribe to the Virtual CISO Podcast.

Just search for The Virtual CISO Podcast in your favorite podcast player or watch the Podcast on YouTube here.

To stay updated with the newest podcast releases, follow us on LinkedIn here.

View Details

Microsoft 365 was launched in 2011 in hopes of revolutionizing cloud-powered productivity platforms. Since then, Microsoft 365 has grown to the point where it is now one of the largest cloud-powered productivity platforms on the market, competing with the likes of Google and more.

To give organizations a clear picture of their Microsoft 365 options, your host John Verry sits down with Conrad Agramont, CEO of Agile IT, a top Microsoft Cloud Service Provider focusing on Microsoft 365, to discuss Microsoft Government Community Cloud (GCC), GCC High, and more.

In this episode, Join us as we discuss the following:
• How the three Microsoft 365 clouds differ in terms of key security capabilities
• The importance of communicating with your government program office about the cybersecurity requirements in your contract
• What migration from commercial Microsoft 365 to a "gov cloud" can look like in terms of time, cost, and effort
• The two most challenging aspects of any Microsoft 365 migration
• Pros and cons of a "hybrid approach" involving multiple Microsoft 365 environments

To hear this episode and many more like it, we encourage you to subscribe to the Virtual CISO Podcast. Just search for The Virtual CISO Podcast in your favorite podcast player or watch the Podcast on YouTube here.

To stay updated with the newest podcast releases, follow us on LinkedIn here.

View Details

ISO 27001:2022 is the first update to the global "gold standard" for provable cybersecurity in ten years. Notable changes from the 2013 version will likely significantly impact most organizations' Information Security Management Systems (ISMS).

In this episode, your host John Verry sits down with Ryan Mackie and Danny Manimbo from Schellman & Co. to explain the most significant changes in ISO 27001:2022 and their potential impacts.

Join us as we discuss the following:
* How to determine the optimal timeline to migrate your ISMS from 27001:2013 to ISO 27001:2022 * Top areas that auditors will focus on during your transition audit * How moving to the new ISO 27001:2022 can benefit your cybersecurity program (and your marketing) * The critical importance of risk assessment/risk management for ISO 27001:2022 certification * The "ripple effect" of ISO 27001:2022 changes on related standards like ISO 27017, ISO 27701, and CSA STARS

To hear this episode and many more like it, we encourage you to subscribe to the Virtual CISO Podcast on YouTube here.

To stay updated with the newest podcast releases, follow us on LinkedIn here.

Listening on a desktop & can't see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.

View Details

The “buzz” in building more secure applications is “shift security left,” which means integrating security into and throughout the Software Development Lifecycle (SDLC).

The Software Assurance Maturity Model (SAMM) is an excellent tool from OWASP that provides a framework for assessing and improving your development processes, resulting in more secure applications. In this episode, your host, John Verry, CISO and Managing Partner at Pivot Point Security, sits down with Sebastien Deleersnyder, co-lead of the OWASP SAMM project, to discuss in depth how you can use SAMM to improve your application security program.

Join us as we discuss the following:

● The biggest challenge teams face in developing secure applications
● Using OWASP SAMM to assess your current security process
● Where most orgs really are today in terms of AppSec
● Identifying quick wins to improve web app security
● Leveraging SAMM alongside other security frameworks like NIST 800-218 and ISO 27001

To hear this episode and many more like it, we encourage you to subscribe to the Virtual CISO Podcast on our YouTubehere.

To Stay up to date with the newest podcast releases, follow us on LinkedInhere.

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.

View Details

Trusted Information Security Assessment Exchange (TISAX) is a vendor due diligence standard used in the automotive industry to verify that third-party suppliers’ cybersecurity programs provide adequate protection for the information the automotive supplier shares.

In this episode, your host John Verry, CISO and Managing Partner at Pivot Point Security, sits down with Ed Chandler, Account Executive and Cybersecurity lead for TÜV SÜD America, who provides answers and explanations to what TISAX is, how it operates, and helps you better understand the implications surrounding it.

Join us as we discuss:
• Where did TISAX come from, why does it exist, and why is it increasingly important worldwide?
• Why so many North American firms are now facing TISAX requirements
• How the TISAX assessment/audit process works
• TISAX assessment objectives and assessment levels
• How aligning your org with comprehensive cybersecurity standards like ISO 27001 can also help with TISAX

To hear this episode, and many more like it, we would encourage you to subscribe to the Virtual CISO Podcast on our YouTube here.

To Stay up to date with the newest podcast releases, follow us on LinkedIn here.

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.

View Details

In today’s cyber landscape, business leaders and security professionals need every edge they can gain to better protect their organizations and plan their defense against attackers. . Why do hackers do what they do? What are they trying to steal from you? Who do they partner with to make money and avoid getting caught?

In this episode, hosted by John Verry, CISO and Managing Partner at Pivot Point Security, sits down with Raveed Laeb, Vice President of Product for KELA, who provides answers and explanations to explain the cybercrime business models, supply chains, and operational strategies.

Join us as we discuss:

· How understanding your financially motivated adversaries can directly benefit your cybersecurity posture, incident response, and executive decision-making

· “Business models” and “supply chains” that hackers use to monetize your assets (which can be a lot more than just your data)

· What you need to hear to dispel any lingering notion that your org has nothing hackers want

· How and why bad actors are increasingly specializing based on skill sets, and where and how they choose their business partners

· How forward-looking businesses are using cyber threat intelligence (CTI) to reduce cyber riskTo hear this episode, and many more like it, we would encourage you to follow the Virtual CISO Podcast here.

You can find all our full length and short form video episodes on our YouTube here.

To Stay up to date with the newest podcast releases, follow us on LinkedIn here.

Listening on a desktop & can't see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.

View Details

Orgs in the DIB need to protect CUI in alignment with the NIST 800-171 cybersecurity standard—and soon the Cybersecurity Maturity Model Certification (CMMC) requirements—or face legal and compliance penalties as well as potential lost business. To clarify the biggest questions and reveal the most dangerous unknowns in the convoluted realm of CUI, your host John Verry, Pivot Point Security CISO and Managing Partner, sits down with Stephanie Siegmann, Partner and Chair at Hinckley Allen to share her knowledge on the subject.

Join us as we discuss:

· The difference between CUI Basic and CUI Specified

· Criminal penalties for “export controlled” CUI violations that will probably shock you

· Sound advice on handling data subject to ITAR, NOFORM and other regulations

· How to get your CUI questions answered—and what to do if you’re still not sure

· The US Department of Justice Civil Cyber Fraud initiative, the False Claims Act, and why you don’t want to fire the whistleblower

To hear this episode, and many more like it, we would encourage you to subscribe to The Virtual CISO Podcast here.

You can find all our full length and short form episodes here.

Listening on a desktop & can't see the links? Just search for The Virtual CISO Podcast in your favorite podcast playerVCISO YouTube  

View Details

Over 90% of security breaches in the public cloud stem from user error, and not the cloud service provider. Today, your host John Verry sat down with one of Amazon Web Services (AWS) own Temi Adebambo, to understand what is going wrong with public cloud security, and how you can eliminate your biggest risks. This episode features Temi Adebambo, Head of Security Solutions Architecture at Amazon Web Services (AWS), to explain exactly what’s going wrong with public cloud security, how users can eliminate their biggest risks, and much more.

Join us as we discuss:

• The 2 mistakes public cloud users make that cause the most security breaches

• How using “higher-level” services can reduce your security burden

• Ideas for baking security into your DevOps pipeline

• The critical importance of “guardrails” for your team and how to implement them

• The top AWS security tools all users should leverage

To hear this episode, and many more like it, we would encourage you to subscribe to The Virtual CISO Podcast here.

You can find all our full length and short form episodes here.

Listening on a desktop & can't see the links? Just search for The Virtual CISO Podcast in your favorite podcast playerhttps://www.pivotpointsecurity.com/

View Details

Managing Cybersecurity through an Economic downturn is no easy task. With increasing concerns on how to stay secure and compliant in a down economy, John Verry tackles this podcast himself giving you his ten best fundamental practices.

This episode features your host John Verry, CISO & Managing Partner, from Pivot Point Security, who provides answers and explanations to a variety of questions regarding how to stay compliant, secure, and budget in a down economy.

Join us as we discuss:

· How to be Strategic in a Down Economy

· How to leverage automation

· How to get more from your vendors

· Which security investments to maintain and eliminate

To hear this episode, and many more like it, we would encourage you to subscribe to The Virtual CISO Podcast here.

You can find all our full length and short form episodes here.

Listening on a desktop & can't see the links? Just search for The Virtual CISO Podcast in your favorite podcast player

View Details

Building Cloud Native Applications can bring about many operational and security problems. Today, we sat down with an expert in this field to talk about building cloud native applications, and deploying applications that are secure in the cloud.

This episode features Fausto Lendeborg, Co-Founder & CCO, from Secberus, who provides answers and explanations to a variety of questions regarding Building applications in the cloud, deploying applications securely in the cloud, and much more.

Join us as we discuss:

· Building Cloud Native Applications

· Deploying Applications Securely

· Managing a Cloud

· Security, Compliance, and Governance

· DevOps

To hear this episode, and many more like it, we would encourage you to subscribe to The Virtual CISO Podcast here.

You can find all our full length and short form episodes here.

Listening on a desktop & can't see the links? Just search for The Virtual CISO Podcast in your favorite podcast playerhttps://www.pivotpointsecurity.com/

View Details

Digital Business Risk Management helps companies track and disrupt the most advanced bad actors.  Team Crymu specializes in Digital Business Risk Management & Attack Surface Management, giving clients insight and help relating to cyber threats.

This episode features David Monnier, Chief Evangelist and Team Cymru Fellow, from Team Cymru, who provides answers and explanations to a variety of questions regarding Business Risk Management, ASM (attack surface management), and much more.

Join us as we discuss:

● Attack Surface Management

● Digital Business Risk Management

● Electronic Assets

● Data Breaches/Exposures

● Discovering malevolent infrastructures

To hear this episode, and many more like it, we would encourage you to subscribe to The Virtual CISO Podcast here.

You can find all our full length and short form episodes here.

Listening on a desktop & can't see the links? Just search for The Virtual CISO Podcast in your favorite podcast player

View Details

Governance, Risk, and Compliance (GRC) platforms can be tricky to construct. 

Today, we sat down with an expert in this field to talk about building and deploying secure applications in the cloud.

This episode features Jeff Schlauder, Information Security Executive, from Catalina Worldwide, who provides answers and explanations to a variety of questions regarding deploying applications securely in the cloud, using AWS (amazon web services), and much more.

Join us as we discuss:

· Building and deploying secure applications in the cloud

· The Logistics of Web Applications

· Building, operating, and maintaining secure Cloud applications

· Containerized vs Not-containerized applications

· How to keep applications deployed secure

To hear this episode, and many more like it, we would encourage you to subscribe to The Virtual CISO Podcast here.

You can find all our full length and short form episodes here .

Listening on a desktop & can't see the links? Just search for The Virtual CISO Podcast in your favorite podcast player

View Details

You cannot have privacy without security.

While they once existed quite distinct from one another, they are now so delicately woven that they are nearly indistinguishable.

Over time, the GDPR has cemented the relationship between physical security and information security, and now, it’s incorporating data privacy.

This compliance triad has become the new normal for businesses everywhere– but what does it mean?

Rosemary Martorana, Chief Privacy Officer at Corning, joined me to discuss the blurring line between privacy and security and why compliance may be more approachable than you thought.

A critical key to fostering a compliant security culture and enabling compliance is transparency.

Transparency does a few things for your business & security:

  • Increases trust

  • Decreases DSRs

  • Limits phishing attempts

  • Decreases likelihood of breaches

Follow the link below or find The Virtual CISO Podcast on your favorite streaming service to learn more about what compliance, information security, and data protection means for your business.

View Details

CMMC (Cybersecurity Maturity Model Certification) can raise many red flags and concerns - As CMMC rulemaking approaches in 2023, we take a break

from our normal podcast and answer the most asked CMMC questions to date to help ease the unknown.

This episode features George Perezdiaz, FedRisk Practice Lead, with Pivot Point

Security, who provides answers and explanations to a variety of questions we have received regarding CMMC. George is extremely knowledgeable on CMMC topics while being one of the top industry experts on the topic. During this episode, he helps answer our top 20 most asked questions regarding dates for rulemaking, achieving compliance for the DIB (Defense Industrial Base), the cost to become CMMC certified, and much more hopefully providing a path for those who need it.

Join us as we discuss:

· When CMMCV2 will become effective

· Who needs to be CMMC certified

· Can a small business affordably achieve CMC compliance

· CMMC Level 2 and 3 requirements

· And much more!+

To hear this episode, and many more like it, we would encourage you to subscribe to The Virtual CISO Podcast here.

You can find all our full length and short form episodes here .

Listening on a desktop & can't see the links? Just search for The Virtual CISO Podcast in your favorite podcast player

View Details

This marks our 100th episode of The Virtual CISO and an insightful journey into having the opportunity to have frank discussions with thought leaders that provide the very best information security advice and insights. 

I am happy to have invited Dimitri Sirota, CEO & CoFounder of BigID, to walk through BigID’s approach to privacy, security, and data governance on this momentous episodic occasion. 

Join us as we discuss:

  • The merits of gathering data beyond the usual locations
  • Why discovery is a foundational piece of BigID’s approach
  • How BigID supports efficient data collection

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player 

View Details

Supply chain risk management can prove to be a slippery slope—why should you take pains to conduct a proper risk assessment, and how do they impact IT and business continuity? 

From international restrictions to balancing generic and specific risk assessments, any guidance is welcome in the world of supply chain management.

I invited Willy Fabritius, Global Head of Strategy & Business Development, Information Security Assurance at SGS, onto the show to provide insights into supply chain risk management. Including definitions, best practices, and where to turn for guidance.

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player 

View Details

What are the merits of the Software Assurance Maturity Model (SAMM), and how does it differ from the Application Security Verification Standard (ASVS) model? And why should you care?

From design to operations, there are several crucial considerations to hold regarding business functions and use cases.

I invited Taylor Smith, Application Penetration Testing Lead at Pivot Point Security, onto the show to provide insights into SAMM. Including definitions, the differences between SAMM, ASVS, and BSIMM, and how these models are relevant in today’s software development environment. 

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player 

View Details

Application development is moving from a web-centric world to an API-centric world. If you’re wondering what that looks like, what the security implications are and what an API is, you’re in the right place.

There is no shortage of new application security strategies to familiarize ourselves with as cybersecurity adapts to changing times.

That’s why I invited Rob Dickinson, CTO at Resurface Labs, to explain APIs, continuous API operation observability, and prevalent challenges in the API economy.

Join us as we discuss:

  • Moving from a web-centric to an API-centric world
  • The value of opbersing API operation in production environment
  • Tackling security issues in the API economy

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player 

View Details

Most recognize the value preservation in cybersecurity. But forward thinking professionals also see the value creation in having a secure information posture.

Cybersecurity is the foundation of preserving sensitive data and providing peace of mind but does it create value for the organization and if so, how do we measure that value?

Tracking the return on investment on cyber security can be challenging. Much like auto insurance, you gain the most obvious value when something goes wrong—however, that doesn’t mean insurance isn’t valuable during smooth sailing.

I invited James Fair, Senior VP at Executech, to discuss the value of compliance, measuring ROSI, the Return on Security Investment, and budgetary considerations in cybersecurity.

Join us as we discuss:

  • The value of cybersecurity vs the costs of a breach
  • Convoluted cybersecurity budgets and industry averages
  • How compliance supports value preservation and value creation

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player

View Details

What exactly is a Software Development Life Cycle, and how does NIST’s Secure Software Development Framework impact that cycle and your organization?

Of note, the SSDF will definitely impact you if your software is used by the US Government and will likely impact you even if it isn’t. There are a few choice practices that can help make sense of these two critical processes and provide the highest chance for success.

I invited Elzar Camper, Director of Cyber Security Solutions & Practices at Pivot Point Security, onto the show to unpack SDLCs, the SSDF and lay out the shifting landscape of government regulations and software development.

Join us as we discuss:

  • Defining SDLC’s and the SSDF
  • Four core best practices in cybersecurity
  • Assessing existing procedures and adapting to the SSDF
  • How you can use the SSDF to your advantage

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player

View Details

Today, information is worth more than riches. The new currency is data. With this being true, the state of cybersecurity within the upper branches of the government was shockingly under-prepared.

In this episode, I speak with Mark Montgomery, the former Executive Director of the Cyber Solarium Commission, about the report the commission published in March 2020 and how that document has influenced the US Government’s roadmap to improve cybersecurity, prevent cyber attacks, and protect the nation's data.

Join us as we discuss:

  • Critical steps forward for cybersecurity
  • Six pillars of importance in federal circles
  • Challenges in the cybersecurity workforce

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here. 

If you don’t use Apple Podcasts, you can find all our episodes here.

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.

View Details

Don’t wait for an emergency; secure your database correctly right out of the gate. Think of everything outside of your database as the wild west. 

What can you do to create the most controlled environment possible for all of your most sensitive data? 

I invited Robert Buda, President of Buda Consulting, Inc, and an expert in database technology, onto the show to help us learn the value of database security and what you can do today to improve your security measures. 

Join us as we discuss:

  • Why database security is undervalued
  • Critical risks to be aware of regarding your database
  • Avoiding a sense of false security with the cloud
  • Ensuring your database is as secure as possible

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here. 

If you don’t use Apple Podcasts, you can find all our episodes here. 

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player 

View Details

Ron Gula, President and Co-Founder of Gula Tech Adventures, has a very specific goal: To defend the country in cyberspace by investing in companies and nonprofits that help close the gap in technology and the workforce. 

He also knows that in order to successfully achieve this goal, organizations must understand the basics of data protection. 

Today, Ron joins the show to talk about the mindset shift that can start in the information security disciplines through communication. 

Join us as we also discuss:

  • The importance of asking the right questions of business owners
  • Building a trusted ecosystem within the information security disciplines
  • Creating a measure of security to determine the safety of your company’s data
  • The small business IT shops defining corporate America

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.

View Details

There’s no denying that cybersecurity risks in the workplace have increased exponentially in recent years. From the pandemic causing employees to work from home to Russia’s invasion of Ukraine, organizations are more vulnerable than ever.

That’s why it’s crucial to understand how to best protect yourself and your business.

On this episode, Eric Jesse, Partner at Lowenstein Sandler LLP, joins the show to give an attorney's perspective on the importance of cyber liability insurance. Eric talks about protecting your company as a policyholder in today’s new landscape.

Join us as we discuss:

  • Why companies should have their cyber liability insurance policies reviewed by knowledgeable attorneys
  • Strategies for improving your security posture to reduce premiums
  • How best to ensure your Cyber Liability insurance dovetails with other insurance policies to confirm you are covered across all types of cyber incidents

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.

View Details

To invest in CMMC or to not invest in CMMC, that is the question.

CMMC (Cybersecurity Maturity Model Certification) is a lofty yet necessary investment for the Defense Industrial Base. With all signs pointing to May 2023 for when we can expect CMMC to be included in contracts, anyone who is considering CMMC should do it sooner rather than later as implementing any comprehensive cyber security program could take a company 9 to 12 months.

On this episode, our host John Verry recaps his most important takeaways from the recent CMMC Day conference held in Washington DC on May 9, 2022.

Join us as we discuss:

  • CMMC Level 2 and 3 requirements
  • CMMC’s three-year certification process
  • False claims acts and the impact CMMC will have on the review process by the Justice Department
  • Differing opinions of CMMC from conference attendees and CMMC experts

View Details

Alberto Yépez joins the show to share his perspective as a venture capitalist working to help entrepreneurs build Cybersecurity businesses. He started his wildly successful career at Apple and he is now the Co-Founder and Managing Director at Forgepoint Capital.  

Join us as we discuss:

  • Information security challenges from the 2000’s that we still face today
  • Alberto’s experience working at Apple
  • Criteria that makes investing in a company worthwhile
  • Three models of private equity

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here. 

If you don’t use Apple Podcasts, you can find all our episodes here. 

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player 

View Details

We’ve spent the last two and a half years with rapidly rising cloud adoption. It was a rocket ship before that, but the COVID-19 pandemic has only accelerated it and caused everybody to scramble. 

We’re still trying to play catch up and get equivalent security treatments for people working remotely to the folks working in the office. Every client has concerns about their current exposure, which is why our guest on this episode of Virtual CISO is so important. 

Michelangelo Sidagni is the Chief Technology Officer at NopSec, and he was on this episode to talk to us all about: 

  • Why his firm is all in on Attack Surface Management, and how it’s different than your standard vulnerability management
  • How ASM fits into current vulnerability & configuration management strategies
  • Attack Path Analysis, what it is and what it isn’t
  • The NopSec client customer journey

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here. 

If you don’t use Apple Podcasts, you can find all our episodes here. 

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player 

View Details

As technology advances, there will always be new threats from malicious actors seeking to exploit these advancements — whether that be in the digital realm or physical.

With technologies increasingly blurring the lines between the two, today’s security professionals must adapt as the sectors of physical security and cyber security converge into one.

Today’s guest, Chris Ciabarra, Co-Founder and CTO of Athena Security, is one of the physical security experts leading the charge on this front and he joins the show to share his insights into the inevitable security convergence in our future.

Join us as we discuss:

  • Why the lines between physical security and cybersecurity are increasingly blurred
  • The technologies Athena Security are advancing in the physical security domain
  • How Athena accidentally made a COVID-19 detector

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.

View Details

As the implementation of CMMC by the DIB picks up pace, the frequently shifting requirements can be daunting — especially when the guidance is already so complex.

And that’s doubly true for managed service providers (MSPs), who have to contend with some of the most confusing CUI requirements.

In today’s episode, making his 3rd guest appearance, I’m joined by Caleb Leidy, CUI Protection and CMMC Consultant at Pivot Point Security, who is here to clear up the confusion and share his insights into how the rollout of CMMC into the DIB impacts MSPs.

Join us as we discuss the current state of CUI for MSPs in the DIB, including:

  • The controls MSPs have responsibility for in a client’s environment
  • The controls clients have responsibility for in their environment
  • The controls MSPs have to implement in their own environment to meet DFARS flow down requirements

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.

View Details

Inclusivity and diversity aren’t just about who you hire — it’s about the culture you create.

Sure, you can get talent from all walks of life, but if you haven’t built an inclusive culture…

Well, good luck getting them to stick around.

Today, I’m speaking with Deidre Diamond, Founder and CEO at CyberSN, who shares her 8-step framework for creating an inclusive culture in your organization.

Join us as we discuss each step and its importance, including:

  • The need for emotionally intelligent managers
  • The power of positivity
  • The art of win-win communication

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.

View Details

What if you could be proactive in your approach to cloud data security rather than a reactive one once the attack has been made?

This is exactly the solution our guest is providing at Panther Labs. We speak with Jack Naglieri, Founder & CEO, about the cloud-native approach and exactly why SIEMs are getting left behind.

Join us as we discuss:

  • Developing Panther & taking a different cloud-native approach
  • Understanding Snowflake & data lakes
  • Creating a proactive security response rather than reactive
  • Interesting findings from the state of SIEM

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.

View Details

Even before the pandemic, the majority of businesses were already moving to the cloud.  

Now, it seems you can’t do business without it. 

Which means cloud security and compliance is more important than ever.  

That’s why I’m speaking to one of the authorities on cloud security, John DiMaria, Assurance Investigatory Fellow at Cloud Security Alliance, in today’s episode — to demystify cloud security. 

Join us as we discuss:

  • How CSA’s STAR program can help you strengthen your cloud security
  • The biggest vulnerabilities organizations face when operating in the cloud
  • How landing on CSA’s CCM registry can give your organization more visibility

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here. 

If you don’t use Apple Podcasts, you can find all our episodes here. 

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.

View Details

CMMC has come a long way in recent years…

But organizations still face plenty of challenges navigating the guidance.

What are the biggest hurdles and how can we reduce the confusion?

To answer these questions, I’m joined by Kyle Lai, Founder and CISO of KLC Consulting, and Caleb Leidy, the CUI Protection and CMMC Consultant at Pivot Point Security.

Join us as we discuss:

  • Why CMMC scoping continues to confuse organizations
  • How to accurately mark CUI
  • Contracts passing the buck and the costs associated with compliance

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.

View Details

Open source is a transparency issue. Being able to see what code is running on your computer — as well as what’s being monitored — gives you practically SaaS-level visibility across data, apps, and usage.

In this episode, former open source developer Mike McNeil, CEO at Fleet Device Management, an open source company, talks with me about why open source is so imperative.

Join us as we discuss:

  • The business impact of open source
  • Why open source grants such necessary visibility
  • How the open source community removes friction
  • Vulnerability management and automation
  • What’s next for Mike and Fleet

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

Links here:

Mike McNeil, CEO at Fleet Device Management

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player

View Details

Traditionally, companies have relied on the promises of vendors when it comes to reaffirming their security stance.

However, LimaCharlie has a far more radical approach—provable security.

How are they doing it?

In this episode, Maxime Lamothe-Brassard, LimaCharlie’s founder, explains the “AWS approach” the company employs for cybersecurity and how being born in the cloud provides infinite scalability and enables them to deploy a wide range of security capabilities.

Join us as we discuss:

  • Moving past promise-based security positions to knowable security
  • The extra level of control and breadth of security you receive with LimaCharlie
  • How infinite scalability enables support of both security and compliance
  • Doubling down on low-code approaches and integrations

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player

View Details

After years, ISO 27002 is finally here. 

What does that mean for your business? 

Luckily, the transition should be pretty seamless… 

But if you’re worried, have no fear because in today’s episode I’m joined by Danny Manimbo and Ryan Mackie, Company Principals at Schellman, who helped design the new standard. 

Join us as we discuss:

  • What’s new with ISO 27002

  • What has stayed the same

  • The reasoning behind the update to the standard

  • The grace period for getting certified

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player

View Details

If you look around at what’s happening in the world of cybersecurity, you’ll notice one thing:   

Security never stops…  

Which means neither should compliance.   

That’s why I invited Andrea Willis, Senior Product Manager at Exostar ,an expert in continuous compliance onto the show to help you figure out how to stay compliant.  

Join us as we discuss: 

-The importance of continuous compliance 

-How CMMC 2.0 and continuous compliance interact 

-How cybersecurity is like the immune system of your organization

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player

View Details

We’ve had another bumpy year in 2021. So, what’s coming down the pike in 2022? And what impact will the ongoing information security challenges of today have on the world of tomorrow?

In this episode, I answer those questions and more. Plus, I will assume the role of Nostradamus and make 8 information security predictions for 2022.

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.

View Details

NIST, ISO, CMMC…

If you’re beholden to government security guidance — and let’s face it, if you’re a company operating in the US, you very likely are — the list can be overwhelming at first.

So, it helps to look back on where we’ve been and how we got where we are today.

And in this solo episode, Our Host John Verry does exactly that — and hopefully, shine a light on what the guidance means and why you should care.

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.

View Details

You’ve probably heard the hype:

IoT is the next frontier in the information revolution that promises to make all our lives easier…

And that’s doubly true for hackers.

In this episode, I’m joined by Joe Grand, also known as Kingpin, a computer engineer, hardware hacker, product designer, teacher, advisor, daddy, honorary doctor, TV host, member of legendary hacker group L0pht Heavy Industries, proprietor of Grand Idea Studio (www.grandideastudio.com), and partner in offspec.io, a cryptocurrency wallet recovery service. He has been creating, exploring, and manipulating electronic systems since the 1980s and is hereto take a look at the vulnerabilities hackers exploit in IoT (and how you can defend against them).

Join us as we discuss:

  • Why, despite what many believe, hardware is no less vulnerable than software

  • The common vulnerabilities in IoT devices and what you can do about them

  • How security standards factor into IoT security

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.

View Details

There is an age-old conflict between security and development teams.

Development teams are focused on time-to-market and packing features into the product.

Security teams are often seen as speed bumps on the way to achieving those goals.

How can we bridge the gap between the two?

According to Harshil Parikh, CEO at Tromzo, new methodologies are presenting an incredible opportunity for security teams to get involved in the development process in a much more effective way.

Plus, there’s some exciting new software that is solving this challenge in interesting ways.

In this episode, we discuss:

  • Opportunities presented by agile development methodologies and DevSecOps

  • The root of the conflict between security and development

  • How to close the gaps between the two teams

  • How Tromso is solving the challenge through software

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.

View Details

What’s more secure? A cloud-based or on-prem document management system?

It’s a question that gets asked a lot in our industry.

So, I invited Mark Richman, Principal Product Manager at iManage, on to the show for a wide-ranging discussion on the topic.

In this episode, we discuss:

  • Why a SaaS-based document management system is more secure than on-prem

  • Implementing compensating controls to mitigate potential damages

  • iManage’s customer-managed encryption keys and threat manager

  • What a cloud provider should be doing from a security perspective

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.

View Details

Configuration management is the best kept secret in security.

Not only will it save time and money, it also helps you marry compliance and security — something we all need to get used to.

The question is: Why isn’t everyone using it?

Today’s guest, Brian Hajost, Founder and COO at SteelCloud, joins me on the show to give some compelling reasons why you should.

In this episode, we discuss:

  • What configuration management is

  • How it saves you time and effort

  • How it saves you money

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.

View Details

The US Department of Defense (DoD) has just announced CMMC 2.0, a new strategic direction for its cybersecurity program based on public comment and internal assessment. So what does it all mean?

Many sources say that CMMC 2.0 is about "less requirements,"—but it's really much more about changing how the DoD will hold defense contractors accountable to the NIST SP 800-171 requirements that have been in place all along.

We're speaking to two of our best Security Consultants from right here within our ranks at Pivot Point Security: George Perezdiaz, CMMC / NIST Security Consultant, and Caleb Leidy, CMMC Consultant/Provisional Assessor.

In this episode, we discuss:

  • What's new and what's not with CMMC Level 1 (for securing FCI) and what is now called CMMC Level 2 (for securing CUI)

  • The overall realignment of the US government's cybersecurity audit program with NIST 800-171

  • "Bifurcation" and who will and won't need a third-party audit if you handle CUI

  • How CMMC 2.0's new accountability process fits with the recent cybersecurity executive order, the Civil Cyber-Fraud Initiative, the False Claims Act, and upcoming rule changes to 32 CFR and 48 CFR

  • Why "letters of affirmation" are a boon to SMB security and IT leaders compared to the threat of a third-party audit

Mentioned during the podcast:

eCFR :: Home

To hear this episode and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don't use Apple Podcasts, you can find all our episodes here.

Listening on a desktop & can't see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.

View Details

A lot of people want to break into cybersecurity. And why not? Where else can you have a blast, work with really smart people, earn a great living, have awesome job security, and do something truly impactful for the company you work for.

However, it can be a particularly difficult industry to break into, especially if you don’t have the financial resources to pursue the education necessary to get hired.

Gerald Auger, Chief Content Creator at Simply Cyber, noticed this gap between the haves and the have nots and he’s been working hard to create a pool of resources that are accessible to anyone, anywhere, for free.

In this episode, we discuss:

  • Giving people access to a free cybersecurity education

  • The catch-22 of listing entry-level jobs that require 2-3 years of experience

  • Which cybersecurity roles serve as the best entry points into the industry

  • Where Simply Cyber will go over the next few years

Mentioned during the podcast:

  • Cybersecurity Career Master Plan

  • Simply Cyber YouTube Channel

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.

View Details

In a world where new vulnerabilities appear seemingly every minute, threat intelligence is more important than ever.

And one of the most intriguing approaches to threat intelligence is attack surface management.

To explain the ins and outs of attack surface management, I invited Steve Ginty, Director, Threat Intelligence at RiskIQ, onto the show. He shares the work RiskIQ is doing in the field and how it could benefit your organization.

In this episode, we discuss:

  • What attack surface management is and how RiskIQ can help

  • How RiskIQ can let you respond faster when new vulnerabilities arise

  • The importance of gaining visibility into not just your own attack surfaces, but those of your vendors

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.

View Details

As public trust in technology erodes — for the first time — it’s clear that we need to reevaluate our approaches to security and compliance.

The way we’ve been doing it is no longer working…

But continuous compliance might.

Today’s guest, Mosi Platt, Senior Security Governance, Risk, Compliance & Assurance Partner at Neflix, join s the show to explain why.

In this episode, we discuss:

  • The benefits of continuous compliance and what you need to know to implement it

  • The role continuous compliance can play in regaining trust

  • How continuous compliance factors into auditing

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.

View Details

When it comes to healthcare InfoSec, it’s the Wild West. Most healthcare organizations just don’t have the necessary IT budgets to make it a priority.

But it should be a priority. The truth is a large number of hospitals have been targeted by ransomware in the last few years. 

Today’s guest, Hoala Greevy , Founder and CEO at Paubox , shares how his company is arming healthcare organizations with HIPAA-compliant email and APIs in their ongoing battle against cyber threats.

In this episode, we discuss:

  • The current state of information security in healthcare

  • How Paubox provides HIPAA-compliant email and APIs

  • Where security and privacy in healthcare is headed

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here. 

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.

View Details

In the U.S., it’s easy to look at overseas privacy legislation like GDPR and conclude it’s a reaction to worrying data practices from today’s tech giants.

In reality, European privacy legislation can trace its roots back to the nightmarish authoritarian regimes of postwar Europe — and the necessity of securing a future free from repeating these governmental abuses.

That’s just one of the many privacy insights my latest guest, Jason Powell, GRC and Priv acy Consultant at Pivot Point Security, opened my eyes to. He joins the show to share more than just the history of privacy — he brings a ton of useful ways you can begin preparing for the future of privacy, too.

In this episode, we discuss:

  • Why GDPR is the granddaddy of privacy legislation

  • What you need to know to handle privacy — whether it’s for compliance or just good business practice

  • Why, despite some overlap, privacy and security are really their own domains and should be (ideally) treated as such

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.

View Details

Chess legend Bobby Fischer once said that winning tactics flow from a superior position.

Bobby Fischer would have made a great CISO.

That’s because information security strategy is all about steering your business to a winning position that makes tactics easy.

And it’s why your infosec and business strategies are entirely dependent on one another.

My guest today, Chris Dorr, Virtual Chief Information Security Officer (vCISO) at Pivot Point Security, is an expert at marrying security and business strategy. He joins the show to share his expertise and help you become one, too.

In this episode, we discuss:

  • Why business strategy and infosec strategy are inextricable

  • How frameworks can be used to shape effective infosec strategy

  • The 3 reasons why infosec strategy is more important than ever

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.

View Details

How well do you know what’s happening in your cloud?

With so many people in an organization able to access it, managing and tracking every change can be a Herculean task.

So, it’s no surprise that so many organizations need help tracking drift across their cloud networks.

And the best person they could turn to is today’s guest, John Grange, Co-Founder and CTO at OpsCompass, a company making software that offers centralized visibility for security, cost management, and compliance from a single dashboard.

In this episode, we discuss:

  • Why you need centralized visibility to track drift in the cloud

  • How security, compliance and cost management drift are tracked by OpsCompass

  • The kinds of users leveraging OpsCompass

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.

View Details

Every CISO’s dreams is moving from reactive security to purely proactive security posture.

In an era of big data and technological advancements in machine learning is this dream finally a reality?

To find out, we charged today’s guest, Johnna Verry, Intern at Pivot Point Security, with putting machine learning to the test to see if it can really be the breakthrough we need in predictive security. She joins me to share the results.

In this episode, we discuss:

  • The challenge of — and tools necessary for — scraping and cleaning data for use in machine learning

  • The types of machine learning algorithms and how they work

  • The results of Johnna’s research and what they mean for the future

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.

View Details

Just because ISO 27001 suggests a control, doesn’t mean you have to have it – in fact, you could be hurting yourself if you do by wasting money and have more trouble in an audit than you would otherwise.

Your controls depend on your risk — not ISO suggestions.

That’s just one of the many misunderstandings people have about the ISO 27001 standard.

In this solo episode, host John Verry, CISO & Managing Partner at Pivot Point Security goes in depth on the most common misperceptions around ISO 27001 compliance.

Some notable examples:

  • Why your controls need to be in accordance with your risk

  • Why you don’t need to go crazy documenting absolutely everything

  • Why you shouldn’t overcommit on controls

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.

View Details

Traditional compliance approaches have served us well for years…

But they just don’t cut it anymore.

We need an approach to compliance that moves at the speed of DevOps.

Our guest today, Raj Krishnamurthy, is Founder, CEO and Engineer at ContiNube, where he is helping to bridge the gap between traditional compliance techniques and the agile, fast-paced world of DevOps.

In this episode, we discuss:

  • Why traditional compliance tools are outdated to manage today’s rapidly shifting risks

  • The 5 pillars of bridging compliance and DevOps

  • How Raj and ContiNube are helping to tackle the problem

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.

View Details

In this special episode, we’re sharing a guest appearance John made on The Perfect Storm. During that episode, he shared how Pivot Point Security helps companies achieve security and compliance throughout different regulatory frameworks and a three-part process for validating your security processes.

Topics covered:

-What services Pivot Point Security offers

  • Helping clients understand the importance of cybersecurity

  • 3-part framework to validate security

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

View Details

Today’s special episode was inspired by a conversation we had with a then potential, now current client of ours at Pivot Point Security.

In discussing our Virtual CISO offering, we described our tried-and-true process for helping a client become provably secure and compliant. He loved it and wanted us to train him and his team on it. We've since had a similar conversation with a couple of boards.

What we've realized through these conversations is this process delivers a lot of value. So in this episode, we are going to share it with you.

Topics covered:

  • Defining a clear vision

  • Transforming a vision into an actionable plan

  • Validating your compliance

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

View Details

In the wake of the SolarWinds fiasco, a new executive order mandates practices to prevent future attacks…

How well does it address the threats?

And what does it mean for you?

To answer these questions, I invited Scott Sarris, Executive Vice President of Digital Transformation and Cybersecurity Advisory Services at Aprio, onto the show. Together, we break down the new EO into its most important components.

In this episode, we discuss:

  • Why the EO was necessary and what it means for cybersecurity

  • The role SolarWinds plays in the wording

  • The language acknowledging that Zero Trust is the most secure approach to cybersecurity

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

View Details

By the time you think of a ‘new’ password, attackers already have a way to crack it. Josh Amishav-Zlatin, Founder & Technical Director at BreachSense, is here to reveal the ugly truth about passwords, the risks they present, and how you can mitigate those risks.

What we talked about:

  • Breach timelines and scales of impact

  • How breaches work and how they’re identified

  • Is 2FA/MFA enough to protect you?

  • Protection vs. the right to privacy

Check out these resources we mentioned during the podcast:

  • Josh’s LinkedIn profile

  • BreachSense’s website

  • Have I Been Pwned website

  • The Infosec & OSINT Show (Josh’s podcast)

  • Josh’s Twitter profile

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.

View Details

Information governance is the solution to that irrational fear of deletion we all experience from time to time. Expert in the field and Chief Customer Officer at Encompaas, David Gould, breaks it down for us in the latest episode of Virtual CISO.

What we talked about:

  • What is information governance?

  • Data mapping potential and pitfalls.

  • The fear of deletion.

  • Value creation and information governance.

Check out these resources we mentioned during the podcast:

  • The California Consumer Privacy Act

  • David’s LinkedIn profile

  • Encompaas’ website - Encompaas.cloud

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.

View Details

Are you ready for your DIBCAC/CMMC audit? Let’s make sure.

We’re speaking to two of our best Security Consultants from right here within our ranks at Pivot Point Security. Joining me are George Perezdiaz, CMMC / NIST Security Consultant, & Caleb Leidy, CMMC Consultant/Provisional Assessor.

What we talked about:

  • How to prepare for your DIBCAC/CMMC audit.
  • What can you expect from an audit?
  • George & Caleb’s pearls of wisdom for your next audit

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.

View Details

How do you quantify trust? Is it something that can be digitized?

In the world of cybersecurity, trust is a vulnerability.

What we need is Zero Trust.

That’s why I am so excited to speak with my latest guest, John Kindervag, Senior Vice President of Cybersecurity Strategy and Group Fellow at ON2IT Cybersecurity, who pioneered the concept of Zero Trust a decade ago — even if the world is only catching up to it now.

What we talk about:

  • What makes Zero Trust different from traditional security models

  • How Zero Trust easily solves the ransomware problem

  • The 5 steps to get to Zero Trust

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.

View Details

Whoever propagates the rumor that the goal of cybersecurity is to prevent all attacks deserves to be punched in the face.

The goal of cybersecurity is timely detection and damage control.

In this episode, we interview Dr. Eric Cole, Founder and CEO at Secure Anchor Consulting and author of, most recently, Cyber Crisis, about killing unprofitable cybersecurity myths.

We also discussed:

  • Believing that you are a target

  • Becoming aware of online danger

  • The law of cybersecurity

  • The 3 basic non-negotiable security rules

  • Dr. Cole’s parting advice to CISOs

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.

View Details

In the latest episode, Stacy High-Brinkley, VP of Compliance Solutions at Cask, shares what you need to know about the coming CMMC assessments.

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.

View Details

The federal government has FedRAMP to manage security authorizations for cloud service offerings. But cyber attacks don’t stop at the federal level. State and local governments are under attack too.

How can we create a process for cybersecurity verification of cloud service providers that lifts the cyber posture of state and local governments and the providers who serve them?

To answer that question, I just so happen to have Leah McGrath, Executive Director at StateRAMP, on the show today.

We discuss:

  • What StateRAMP is

  • How it works

  • Improving the StateRAMP process over time

Sign up to receive updates at StateRAMP.org.

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.

View Details

Remember those halcyon days when you could just stick an antivirus on your desktop and not worry — before all these confusing initialisms like EDR and NDR….

Well, turns out, they aren’t as complicated as you may think.

And I can’t think of anyone more qualified to explain why than Chris Nyhuis, President and CEO at Vigilant, who joins the show to shine some light on why the old-fashioned AV is seen as a relic of the past — and whether the new tools that have replaced it are buzzwords or brilliance.

We discuss:

  • How EDR differs from AV

  • What NDR and ENDR are

  • The pros and cons of automating security

  • Why compliance isn’t enough

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.

View Details

PreVeil Drive is a cloud service that lets users encrypt, store and share their files for CMMC Compliance and personal use. Unlike other cloud services such as Dropbox and OneDrive, PreVeil uses end-to-end encryption which ensures that only intended recipients can access their files.

In this episode of The Virtual CISO, we interview Sanjeev Verma, Co-Founder & Chairman at PreVeil, about using their tool as a mechanism to compress the timeframe and level of effort to move towards CMMC level three.

What we talked about:

  • PreVeil Drive as both a file exchange mechanism and a security mechanism.

  • How PreVeil Drive improves access control and configuration management.

  • How PreVeil Drive leads to greater improvement in security scores.

To hear this episode and more like it, subscribe to The Virtual CISO Podcast on Apple Podcasts, Spotify, or our website.

View Details

ISO-27701 is an exciting new standard. But it comes with a learning curve for all of us — clients, consultants, and auditors.

In this episode, we’ll discuss some of the lessons we’ve learned in our initial audits so you can, hopefully, benefit from our teething pains.

That’s why I invited today’s guests, Andrew Frost, GRC Consultant, and Aurore Watts, GRC and Privacy Consultant, here at Pivot Point Security, who have been working on the front lines of the auditing process.

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

View Details

John Laffey, Program Manager at Perry Johnson Registrars, Inc. discusses the cornerstones of an information security management system from the perspective of a management system auditor.

  • Context: the boundaries, the scope, the data, the people, the systems, and the stakeholders,

  • Leadership: driving the entire process, continuing to champion it and making sure resources are available.

  • Planning: documented processes, risk assessment and risk management
    (Change = risk)

  • Support: budget, continuing training competencies, determining what is the required competencies, and then ensuring that those folks are meeting those.

  • Operation: Putting practices into action, verifying that you're doing what you say you do.

  • Performance Evaluation: “It's kind of the day to day, month to month, year to year maintenance of ensuring that things are staying on the rails and that nothing is slipping.”.

  • Improvement: Reaching expected, measurable outcomes and asking what can be improved in our organization

Not only are these valuable clauses in terms of passing your audit, but they're valuable in terms of reducing your organization's risk. This podcast can help you understand how your current management system can benefit you with your CMMC efforts.

OPTIONAL: Check out these resources we mentioned during the podcast:

- John Laffey, Program Manager at Perry Johnson Registrars, Inc.

  • Call our headquarters at 1-800-800-7910

  • Email John directly at JLafffey@PJR.com

  • PJR website

To ensure you never miss an episode, subscribe to the show on Apple Podcasts, Spotify, our website or wherever you get your podcasts.

Listening on a desktop & can’t see the links? Just search for [Virtual Ciso] in your favorite podcast player.

View Details

Have you ever wished that there was some sort of Star-Trek universal translator device for communicating your department’s needs to the C-Suite?

Well, the technology isn’t quite there yet, but today’s guest offers the next best thing. John Sheridan, Co-Founder at Agency Performance Systems, joins the show to share the secrets to interdepartmental communication.

What we talked about:

  • What your CFO cares about

  • How to communicate risk from a business perspective

  • Why you need to ditch the jargon and simplify your message

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.

View Details

Gone are the days when every company had their own internal IT department.

We’re well into the era of Managed Service Providers.

But how do you find the right one for your business?

In this episode, Host John Verry speaks with Charles Weaver, Co-Founder at MSP Alliance, covers everything you need to know about MSPs — and what to know if you are one.

They discuss:

  • The importance of validating your MSP

  • MSPs vs. MSSPs, and how each fits into a world with competing security standards

  • What MSPs need to know about the future

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.

View Details

With the proliferation of so many information security standards, are we nearing a breaking point?

In the end, which standard will win?

In this episode, John Verry, Founder of Pivot Point Security, answers these questions and more in a guest appearance on the Encrypted Economy Podcast.

John covers:

  • The basics of CMMC

  • Why CMMC is the most significant standard in InfoSec’s history

  • Whether we are reaching a saturation point for security standards

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.

View Details

Let’s talk about the Cybersecurity Maturity Model Certification, or CMMC.

What is it, why should you care about it, and how do you know if it’s going to impact your business?

While the industry has always known that CMMC certification was going to move beyond the Defense Industrial Base (DIB,) we assumed it was going to likely be towards the end of 2021, likely into 2022 and 2023.

But it’s growing at lightning speed, and more and more businesses that previously didn’t think they were going to have to worry about it are suddenly finding themselves in a position of needing to start seriously considering it in order to keep the contracts that they have with a myriad of third parties.

In this episode of The Virtual CISO Podcast, host John Verry, CISO and Managing Partner at Pivot Point Security goes over everything involved in CMMC level 1 certification, and what businesses need to know to get ahead of the game.

John outlines:

  • What exactly is CMMC?

  • Why it’s hitting more companies than you may think

  • How your company can get CMMC ready

-The time and resources needed to get CMMC certified

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.

View Details

Manufacturing tends to resist new technology. Not aerospace, though. It's on the cutting edge.

In this episode of The Virtual CISO Podcast, John Virgolino, President/CEO at Consul-vation, Inc. & CEO at SENT, discusses what makes the aerospace sector different from technology and security perspective.

John discusses:

  • Why making security part of your culture is key

  • The security challenges facing aerospace companies

  • The trouble with government contracts

  • Reasons why you shouldn't look for a loophole in aerospace security compliance

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.

View Details

In this episode of The Virtual CISO Podcast, host John Verry, CISO and Managing Partner at Pivot Point Security go over everything government staffing agencies need to know about CMMC Level 3 requirements.

John outlines:

  • How to tell if you have CUI in your environment

  • Whether your FCI can become CUI

  • If you need (or want) CMMC Level 3 compliance

  • The 3 steps to take when it comes to CMMC Level 3 compliance

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.

Keyword or phrase from headline CMMC Level 3 government staffing

View Details

These days, everything is connected to the internet. Whether it’s your car, your light bulbs, your microwave, your pacemaker, or your cochlear implant, it’s all being run and dictated by the internet.

And with that brings a whole new set of concerns.

Where you used to just have to worry about keeping your bank account secure, or your home wifi network secure, now all of a sudden you have to worry about your car or your pacemaker being hacked?

How do we even go about categorizing all the IoT devices, and how do we protect them?

On this episode of Virtual CISO, I chat with Aaron Guzman, who in addition to being the Product Security Lead at Cisco Meraki, is also the Project Lead for the IOT Security Verification Standard (ISVS) at the OWASP Foundation. And if that wasn’t enough, he’s the author of a number of books on IoT, including IoT Penetration Testing Cookbook.

He was kind enough to talk about:

  • OWASP

  • What the ISVS is

  • Who ISVS is intended for

  • And, how ISVS is categorized

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

View Details

Are you looking to get your product authorized for use by federal agencies?

Then you probably need to understand FedRAMP, how it works, and, most importantly, whether it applies to you.

In this episode, I chat with Stephen Halbrook, Partner and Government Compliance Specialist at Schellman & Co, who answers the most common questions about the government security assessment.

He answers:

  • What is FedRAMP and who does it apply to?

  • What is a typical timeline for the ATO process?

  • Should you go through JAB or an agency?

  • How much does it cost?

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.

View Details

Privacy is changing. Across the globe, new standards are recognizing it as a fundamental human right.

But between GDPR, CCPA, and all the other standards popping up, figuring out all your data privacy obligations can be quite the challenge.

That’s why I invited Dyann Heward-Mills, Lawyer and CEO of HewardMills, onto the show to discuss the challenges data privacy standards present — and how you can overcome them.

We discuss:

  • The history of data privacy

  • How to meet your privacy obligations

  • The role a Data Privacy Officer plays (and whether you need one)

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

View Details

Getting your ducks in a row for a GRC audit can be a huge undertaking.

Especially when you get compliant for the audit, then don’t look at it again until the next one rolls around.

If this sounds familiar, you may have wondered whether investing in a GRC tool is worth it.

In this episode, Craig Unger, Founder and CEO at HyperProof, shares all the information you need to decide whether investing GRC is right for you.

What we talked about:

  • The challenges a GRC tool should address

  • Whether continuous compliance means continuous security

  • When you should implement a GRC tool

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

View Details

The DFARS interim rule that went into effect on November 30th has a lot of nuances to it — and many out there have questions about how it applies to them.

In this episode, I sit down with Corbin Evans, Principal Director, Strategic Programs at National Defense Industrial Association, to get answers to some of the most common questions about these CMMC nuances, including:

  • What do DIB orgs with a 7012 clause in their contracts need to do now?

  • What happens if you submit a low SPRS score?

  • What are the different types of CUI?

Check out this resource we mentioned during the podcast:

  • https://www.dodcui.mil/

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

View Details

Should I migrate to GCC High? Do I have to? Are there alternatives?

If you’re a DIB member and you are using Office 365 — as so many do — reaching CMMC Level 3 compliance is going to force you to make some difficult decisions.

To help guide you through them, I invited Scott Edwards, President at Summit 7 Systems, onto the show to go over what CMMC Level 3 requires and how you can achieve it.

Scott explains:

  • The requirements for CMMC Level 3 compliance and what they mean for Office 365, G Suite, and in-house email companies

  • The process and expected costs of migrating to GCC High

  • How GCC High compares to alternatives

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

View Details

If you’ve taken the time to look through the DFARS Interim Rule…

All 80+ (potentially) confusing pages of it...

You might have some questions about how it applies to your business.

Luckily, Scott Armstrong, Sr. Director, Cyber Risk, Analytics, and Insights at Exostar, has answers.

In this episode, he and I discuss everything DIB firms need to know about the CMMC Interim Rule

What we talked about:

  • “Legalese to English” translations of the three new regulations

  • Best practices on how to score your self-assessment

  • How and when the DoD will start adding “CMMC language” to contracts

  • How the interim rule will impact new contracts and contract modifications/extensions

  • Why the interim rule will accelerate CMMC Level 3 compliance across the DIB

  • How Exostar can help your organization prepare for compliance

To hear this episode and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

View Details

SaaS is a great business to be in.

But whether you’re a startup or a mature company…

Your product is only as good as your security.

Today’s guest, Ryan Buckley, has advised SaaS firms for a number of years. He joins me to discuss how to address SaaS security and keep your product — and reputation — secure.

What we talked about:

  • Why code repositories are an issue

  • Why product security is as important as infrastructure security

  • Senior leadership’s role in security.

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

View Details

The internet of things is taking off.

IoT is bringing new innovations across the board…

But it’s also bringing a new set of vulnerabilities.

If you’re looking to make sure you’re secure in the world of IoT, I can’t think of anybody better to talk to than Aaron Guzman, Co Chair of the IoT Working Group, and John Yeoh, Global Vice President of Research, at Cloud Security Alliance.

So, in the latest episode of the Virtual CISO Podcast, I do exactly that.

We discuss (among MANY other things):

  • What CSA is and the guidance they offer developers and IoT consumers

  • The work they are doing in IoT

  • What implications 5G has for their work

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

View Details

ISO 27001, CMMC, NIST 800-53…

Keeping track of the myriad security guidelines can be tricky.

Especially when you don’t know the “why” behind them.

To help clear things up, in this episode, I speak with the preeminent expert on NIST guidelines, Dr. Ron Ross, Fellow at National Institute of Standards and Technology, and learn not just what the guidelines are — but how and why they came to be that way.

Ron and I discuss:

  • The “Why” behind NIST guidance

  • How certification standards like ISO 27001 relate to NIST 800-53 and map to each other

  • How NIST balances policy and technical-level considerations

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

View Details

Preparing to achieve CMMC compliance may seem daunting.

Especially in 6 challenging components. 

But we’re going to make them easy.  

In the latest The Virtual CISO Podcast episode, the tables are turned and I’m the one being interviewed. I explain these 6 problem areas and offer ways you can solve them. 

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

View Details

Though 2020 has felt decades-long already…

We still haven’t had to deal with the long-term effects of the pandemic.

But we will. The question is: Can your security?

If you’re not sure, today’s guest will surely boost your confidence.

Reg Harnish, Founder and CEO at Slingshot Cyberventures and Founder at GreyCastle Security, joins the show to walk us through the threats and opportunities a post-pandemic world presents.

We discuss:

  • How the pandemic is impacting security

  • The threats companies face now and in the future

  • Finding opportunities post-COVID-19 world

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

View Details

CMMC is coming...

But that doesn’t mean 800-171 compliance is out the window.

In this episode, I catch up with John Ellis, Director of the Software Division at DCMA.

We discuss:

  • How DCMA is conducting assessments

  • Why 800-171 compliance doesn’t just go away until CMMC

  • Why CMMC is so needed

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

View Details

Not too long ago, DevOps seemed like a fringe buzzword…

Now, it’s front-and-center.

So, what is DevOps and why should you care?

To answer, I invited Jon Bass, Co-Founder & CTO at Sym, onto the show. Jon’s expertise in the field makes him a perfect tour guide for the exciting — and often misunderstood — world of DevOps.

Jon explains:

  • How DevOps moved from the fringe to the mainstream

  • How agile comes into the picture

  • What SecDevOps is and why it’s used

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

View Details

When ISO 27001 is optimized for speed, it’s an amazingly effective and efficient way to manage security and compliance.

Today’s guest is one of our most seasoned ISO experts in both client-facing and training roles.

In this episode, I interview Rich Stever, IT Security Auditor at Pivot Point Security, about key artifacts for optimizing your ISMS.

What we talked about:

  • Key artifacts of the ISMS, including security management policy

  • Objectives during your ISMS refresh

  • Privacy, ISO 27701 extensions, and all about the Information Security Management Committee

  • Poe Dameron (yes, the Star Wars pilot)

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

View Details

If your organization is in the DIB, CMMC compliance is a big deal. It’s probably the biggest thing to happen to information security in history.

And you need to prepare. Your business could depend on it.

That’s why for this episode, I sat down with Chris Lank, Founder and CEO at Ivis, a company offering a solution for monitoring any compliance, not just CMMC, year-round. Chris goes over the ins-and-outs of the changes CMMC will bring for your business — especially for smaller DIB organizations — and how to prepare.

What we talked about:

  • Why CMMC is necessary

  • What your organization needs to start doing right now to prepare

  • How tools like Ivis’ can make the compliance process a whole lot easier

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

View Details

Prepping for an ISO 27001 audit can be a nerve-wracking process.

But it doesn’t have to be.

You just need to know what you’re getting into.

And Ryan Mackie, as Principal and ISO Practice Director at Schellman & Company, is the perfect person to guide you through an audit.

In today’s episode, he covers:

  • Both stages of the ISO 27001 audit process
  • What to expect on the day of the audit
  • What to look for in a registrar (and what to avoid)

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

View Details

If you have a growing SaaS company, security may be far down your list of priorities.

I’ll be blunt… it shouldn’t.

Security maturity can be make-or-break for SaaS clients and maybe even more importantly, SaaS investors.

As a Partner at Reitler Kailas & Rosenblatt, Jesse Nash has a wealth of experience representing early-stage SaaS companies and venture capital investors, so he’s seen how security helps and hurts deals from both sides.

He joined me today to go over:

  • How he counsels SaaS on security matters
  • How he counsels venture capital & private equity firms when approaching a SaaS
  • Why security has become such an important part of the investment process

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

View Details

If you are scrambling to figure out CMMC, you aren’t alone.

It’s perhaps the most sweeping information security change for DoD contractors in history…

And that comes with an assessment program dwarfing any other.

As Member of the Board of Directors for CMMC AB, the accreditation body for CMMC, Ben Tchoubineh is one of the minds behind these assessments… just don’t call it an audit :).

Ben came on the show to demystify the CMMC assessment and certification process.

He covered:

  • The challenge of assessments and training
  • How competition will help with scalability of getting qualified people in the market
  • Types of certifications and careers

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

View Details

If your company works with the DoD.

You might be worried about CMMC compliance.

But it doesn’t have to be hard or expensive.

In this episode, I caught up with Sanjeev Verma, Co-Founder at PreVeil, a company offering one solution for CMMC’s requirement for encryption of email and file sharing that can save you money and hassle, while giving you unparalleled security.

What we talked about:

  • The stakes of migrating from O365 Enterprise to O365 GCC High
  • How a simple end-to-end encryption solution can save you big
  • How to be as secure as the U.S. nuclear arsenal
  • Why we are all active combatants in a new kind of war

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

View Details

Covid 19 has created lots and lots of challenges and opened our eyes to ones that lay dormant.

One of the most stark realizations is how much we rely on our critical vendors.

But how can you know a vendor is safe to work with, is reliable, and figure this out quickly and at a low cost?

Enter ARM. Accelerated Risk Management

Pivot Point Security’s answer to the need for rapid risk assessment.

If you are looking for a paradigm shift in the way you manage risk and assess your vendors this is the show you need to hear.

Kevin Hermosura, one of our Third Party Risk Management & Vendor Due DIlligence Security Consultants here at Pivot Point Security talks with John Verry about using ARM to assess vendor’s risk (in minutes, not days).

What we talked about:

  • Third party risk management is generally lousy.
  • Thanks to Covid, businesses are relying on vendors more than ever.
  • Vendors are a massive security risk!
  • There is a better way to assess and manage vendor risk

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

View Details

If you’re a business leader, especially at a SaaS firm or if you’re a developer at a SaaS firm, this episode with Jim Manico will provide a ton of value.

You'll hear practical advice on how to approach application security that even the most technically un-savvy listeners can understand.

Joe Manico is an application security powerhouse. He is the Founder of an application security training company, Manicode Security, is a major contributor to a number of OWASP projects, and he has a really great passionate approach to his work.

What we talked about:

  • ASVS 101
  • Where should you start when addressing your security needs?
  • Comprehensive tips and advice for application security business leaders

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

View Details

Information security is a well easily fallen into.

There is so much on the market.

So many things to consider.

It’s hard to determine what you actually need, and sometimes companies tend to just grab everything in sight to assure themselves that they are on point…

Or not do enough for fear of wasting time and money on the wrong solutions.

There are plenty of ideas, platforms, papers, and regulations to keep in mind, but sometimes, less really is more.

Jose Ciriaco, Director of Sales and Marketing at Tekscape, Inc. shares some refreshing ideas about keeping things streamlined while promoting diverse product sets and services in the B2B marketplace.

What we talked about:

  • Real-world strategies around consolidation

  • Analyzing valuable streamlining on a case by case basis

  • Digging through vendor options (and how to get the most out of them)

Additional Resources:

  • https://www.linkedin.com/in/jose-ciriaco-b57b0b6/
  • https://www.tekscape.com/

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

View Details

If you want a glimpse into what one of your future CMMC audits will be like, this is the show for you.

On this episode of The Virtual CISO Podcast, we welcome Thomas Price, Client Manager/IT and Information Security Auditor/Quality Management Professional at BSI.

Working with clients to determine strategic direction, achieve objectives, and improve quality and service delivery, Thomas is one of the most accomplished and respected auditors in the security industry.

What we talked about:

  • The differences between ISO 27001 and CMMC

  • CMMC requirements- an in depth look

  • Insights from an auditor's perspective on how to prepare for certification

  • Real-life examples of how to leverage ISO 27001 to nail CMMC certification

Check out these resources we mentioned during the podcast:

  • DOD on CMMC

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

View Details

Who do you trust with your network?

Would you give a random person access to the infrastructure that runs your business?

Anyone with a computer and an Internet connection can set themselves up as a penetration testing or cyber incident response service provider.

But what methods does your organization have in place for vetting an individual or company that you are potentially allowing unfettered access to your entire network?

Ian Glover, President of CREST, is on the podcast to talk about how CREST provides internationally recognised accreditations for organisations, and professional level certifications for individuals providing penetration testing, incident response, threat intelligence and Security Operations Centre (SOC) services.

What we talked about:

  • CREST and a CISO’s decision making process

  • The rigorous process of CREST accreditation and certification - Why having a certifying body evens the playing field Check out these resources we mentioned during the podcast:

  • CREST

  • Sir Ranulph Fiennes
  • Bloodhound SSC 1k

This post is based on The Virtual CISO podcast hosted by John Verry and featuring special guest, Ian Glover

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

View Details

We all have things we consider “the best”.

Things we look to.

Rely on.

What happens when one of those old reliable, gold standard things that have been our go-to for so long winds up being #2, instead of #1?

Andrew van der Stock, Senior Application Security Leader at OWASP Foundation stops by the podcast to dispel some industry myths about The OWASP Top 10.

What we talked about:

  • Is The OWASP Top 10 really the gold standard?

  • Next level considerations to take on as you progress on your journey

  • Risk assessment and threat modeling is just a game

Check out these resources we mentioned during the podcast:

  • Cornucopia-the game
  • The OWASP Foundation

View Details

The word forensics usually makes us think of homicide, but it applies to computers, too.

Computer forensics simply just means telling the story of what happened on a computer.

In this episode, we hear from Brian Dykstra, President and CEO of Atlantic Data Forensics, about who needs computer forensics, when, and why.

What we talked about:

  • The need for computer forensics is widespread and underrecognized

  • It gives you protection against future litigation, especially in IP and employment cases

  • 50% of CISOs graduated at the bottom half of their class… and what that means

  • 3 free, easy ways to reduce your attack surface

To hear this episode, and many more like it, you can subscribe to Virtual CISO here. If you don’t use Apple Podcasts, you can find all our episodes here.

View Details

As the first data privacy certification available, ISO 27701 can greatly reduce the complexity of managing privacy, risk and proving compliance with regulations like CCPA, GDPR.

Those organizations that already have a 27001 certification or are considering that certification can add on 27701 to change an Information Security Management System (ISMS) into an Information Security & Privacy Management System (ISPMS)

Debbie Zaller, Principal and co-owner at Schellman & Company, shares her in-depth knowledge of ISO 27701 on this episode of The Virtual CISO Podcast.

What we talked about:

  • Unpacking the this new certifiable extension
  • Why “ISO 27701 Certified” and “GDPR fully compliant” are not the same (but VERY clos)
  • Why 27701 is the answer to reputable privacy compliance

Resources we mentioned:

  • https://www.aicpa.org/
  • https://gdpr-info.eu/
  • https://oag.ca.gov/privacy/ccpa

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

View Details

Getting a flat tire is a disaster.

Knowing where you keep the spare is disaster recovery.

Changing a tire in under 7 minutes to get right back on the road is business continuity.

In this episode, I interview Cosmo Gazzani, Director of Business Development at Continuity Centers and wekos, about information continuity and the importance of backing up your data.

What we talked about:

  • The nuance between disaster recovery and business continuity
  • How SMBs can know whether they should have an information continuity plan
  • 3 buckets for planning for business continuity
  • How & why to backup your data, even if you’re a one-man show

This post is based on a Virtual CISO podcast with Cosmo Gazzani. To hear this episode, and many more like it, you can subscribe to Virtual CISO here.

If you don’t use Apple Podcasts, you can find all our episodes here.

View Details

Your application is probably vulnerable.

“But how?! We hired a company to pen test our application.

They did a thorough test against the OWASP top 10!”

On this episode of the Virtual CISO podcast, we talk with Daniel Cuthbert. He's one of the premier authors of the OWASP ASVS, and he says OWASP Top 10 is not enough.

We chat about:

  • Why the ASVS is so important
  • Why we shouldn’t be putting all our faith in the OWASP top 10 (only)
  • How to incorporate threat modelling into your assessments and your ASVS test

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

View Details

Is your organization ready for CMMC?

As CMMCs roll out over the next 6 years, it’s going to become a reality for more and more DoD subcontractors.

As many as 50,000 organizations by 2025.

Thankfully there are folks out there who are experts at this.

On this episode of The Virtual CISO podcast, we heard from Stuart Itkin. Stuart is the Vice President of Marketing & Product Management at Exostar, and he and his team are leading the charge when it comes to CMMC readiness.

We talk all about:

  • The need for robust CMMC readiness
  • Why your organization may need to adhere to several different certifications depending on the specific project or RFP
  • How Exostar can help get your organization CMMC ready

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

View Details

As an SMB, you’re probably thinking you’re too insignificant for a targeted cyberattack.

That’s not even a little bit true.

In this episode, I interview Danielle Russell, Director of Product Marketing Management at AT&T Cybersecurity, about SIEM solutions for SMBs.

What we talked about:

  • Why an organization needs a SIEM
  • Small orgs are definitely a target
  • How to get started with a SIEM
  • The #1 characteristic of a good SIEM for SMBs

To hear this episode in its entirety and others like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

View Details

You’re a CISO at an SMB, and you see that the AUP is called the SCA now.

So now what?

Actually, there are 3 applications for this great tool alluded to by the relabeling.

In this episode, I interview Tom Garrubba, VP and CISO at The Shared Assessments Program, about applications for the SCA.

What we talked about:

  • SCA application
  • Resilience Guidance and the SCA
  • 3 ways for SMBs to use the SCA
  • How the SCA compares to SOC 2 and ISO 27001

To hear this episode in its entirety and others like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

View Details

If you thought this podcast was supposed to be about information security, you might be confused about why we’re featuring heart disease.

Bottom line: Dead CISOs don’t get bonuses.

On this episode, I interview Dr. Joel Kahn, triple-board certified cardiologist, author of 6 books, and restaurant owner — also my physician — about techniques for managing stress and preventing heart disease.

What we talked about:

  • The truth about stress
  • 3 techniques and tools to invest in your health
  • How to uncover silent health risks
  • What Dr. Kahn is excited about for the future of preventative medicine

Check out these resources we mentioned during the podcast:

  • kahnchronicle

  • Dr. Kahn’s website, which is full of free resources and articles

  • Dead Execs Don’t Get Bonuses

  • Forbes article on Cybersecurity Mental Health

To hear this episode, and many more like it, you can subscribe to Virtual CISO here.

If you don’t use Apple Podcasts, you can find all our episodes here.

View Details

In this world of remote work that we’ve found ourselves in, there are likely a lot of companies that are looking around and wondering if they’ve got the right staff.

With a fully remote workforce comes a lot of new challenges in the IT space, and if you’re a smaller company, you may not be in the space to bring on a full-time CIO, but you still need the governance and expertise of a CIO.

Cue the virtual CIO.

And there are a lot of managed IT service companies that offer some level of virtual CIO support.

That’s why on this episode of The Virtual CISO Podcast, we sat down with Darek Hahn, President & CEO at VelocIT, to discuss:

  • The role of the CIO vs the CTO
  • What makes a good virtual CIO
  • When you know you need one
  • The difference between a virtual CIO and a traditional MSP consultant.

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

View Details

Can we all agree that this is a strange, confusing, and stressful time to be living through? That none of us really know what’s going to happen, or what the future holds? While restaurants, airlines, cruise ships, and countless other businesses are struggling, there’s one group of people that don’t seem to be slowing down at all, and that’s cybercriminals.

They’re exploiting this crisis and taking full advantage of people’s fear and panic, often causing untold damage in the process.

We at Pivot Point have received countless calls from customers with questions about the changes that this pandemic has brought on. How do they stay safe? What should they be focused on? How do they keep their companies safe during these trying times?

While he’s usually the host of the show, on this episode John Verry, the CISO and Managing Partner here at Pivot Point Security, sat down to discuss a few of the biggest challenges he sees as companies try to stay safe in this current landscape.

He talked through:

  • Why all the people working from home could present a challenge
  • How to safeguard against increased social engineering and phishing attacks.
  • What to do if vendors start closing up shop

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

View Details

Trust, but verify.

These famous words of Ronald Reagan, who, incidentally, would make a fantastic CISO, are also the simplest explanation of what it’s like to work as a virtual CISO.

If step one is building trust and relationship with clients, step two is being let in to see all the inner workings and operations to make informed and strategic decisions.

In this episode, John interviews Andrew Farkas, Virtual CISO at Pivot Point Security, about his experience as a vCISO and why the need exists for such a role.

What we talked about:

  • What is a vCISO and why you (probably) need one
  • Working with a vCISO to create a security plan
  • Real examples of what a vCISO does
  • Scope vs Risk vs Gaps

You can reach out to Andrew via the Pivot Point Security website.

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here.

If you don’t use Apple Podcasts, you can find all our episodes here.

View Details

Considering an ISO 27001 certification?

Wondering about SOC 2 attestation?

Trying to figure out the differences between the two? We got you covered.

We invited Dan Schroeder, Partner-in-Charge for Information Assurance Services at Aprio LLP, onto The Virtual CISO Podcast to explain attestation, certification, ISO 27001, and SOC 2.

What we talked about:

  • What is attestation?
  • ISO 27001 certification v. SOC 2 attestation
  • Which does my company need: ISO 27001 or SOC 2?

To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here. If you don’t use Apple Podcasts, you can find all our episodes here.

View Details

The cyber talent search feels like a global, dangerous game of Marco Polo.

We’re all looking for each other, but nobody can find anyone.

(And even if we do, it’ll only last 18 months or less.)

In this episode, I interview Deidre Diamond, Founder and CEO of CyberSN, about attracting and retaining cyber talent during the talent shortage.

What we talked about:

  • How the fact that we are short 500K information security pros in the US impacts attracting and retaining them
  • How career planning is the #1 way to retain talent
  • Why job searching should be like using a dating app

Check out these resources we mentioned during the podcast:

  • Deidre’s not for profit, Secure Diversity
  • Get better at recruiting (CyberSN blog)
  • KnowMore talent search

This post is based on a Virtual CISO podcast with Deidre Diamond. To hear this episode, and many more like it, you can subscribe to Virtual CISO here.

If you don’t use Apple Podcasts, you can find all our episodes here.

View Details

Katie Arrington is THE expert in the national cyber security battle.

As CISO for Acquisition and Sustainment at the United States Department of Defense, she’s well beyond needing analogies to understand cyber security news and trends.

Yet, she had the best one on hand to explain Cybersecurity Maturity Model Certification (CMMC, for short).

“At the end of the day, the CMMC is your cyber driver’s license to participate in the DoD supply chain.”

Katie is the very first guest of the Virtual CISO podcast. She joined John Verry to discuss recent changes to verifying contractors’ ability to protect unclassified information.

We also chat about:

  • How the Department of Defense CMMC program will ensure the supply chain is properly protecting unclassified sensitive information
  • When RFP’s will begin requiring CMMC certification
  • How and when CMMC audits will begin
  • What companies should do now to remain viable and competitive

Reach out to Katie: katherine.arrington.civ@mail.mil

You can find this interview (and many more to come) by subscribing to The Virtual CISO Podcast on Apple Podcasts or Spotify.

View Details

Information security is a serious topic. 

However, the host of The Virtual CISO Podcast and managing partner at Pivot Point Security, John Verry, doesn’t think security pros always need to be so serious. 

In this intro episode of The Virtual CISO Podcast, Logan Lyles of Sweet Fish Media catches up with John to find out what exactly the show’s going to be covering. 

John offers up: 

  • His mantra that he shares with the great Tyrion Lannister
  • The challenges a CISO and managing partner faces every day
  • How the podcast will help to simplify information security processes
  • How the podcast will help Pivot Point’s customers (and their customers, too)

To hear this episode and more like it, subscribe to Virtual CISO on Apple Podcasts, Spotify, or wherever you get your podcasts.